/ Default setup: A new way to enable GitHub code scanning
https://github.blog/2023-01-09-default-setup-a-new-way-to-enable-github-code-scanning/
https://github.blog/2023-01-09-default-setup-a-new-way-to-enable-github-code-scanning/
The GitHub Blog
Default setup: A new way to enable GitHub code scanning
Default setup is a new way to automatically set up code scanning on your repository, without the use of a .yaml file.
/ Zoom Multiple Vulnerabilities
Path traversal, privilege escalation…
Patches:
— https://explore.zoom.us/en/trust/security/security-bulletin/
Path traversal, privilege escalation…
Patches:
— https://explore.zoom.us/en/trust/security/security-bulletin/
Zoom
Zoom Security Bulletins
View the latest Zoom Security Bulletins and make sure to update your Zoom app to the latest version in order to get the latest fixes and security improvements.
/ StrongPity espionage campaign targeting Android users
https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users/
https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users/
WeLiveSecurity
StrongPity espionage campaign targeting Android users
ESET researchers uncover an active StrongPity campaign that spreads a trojanized version of the Android Telegram app posing as the Shagle video chat app.
/ Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4294
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4294
cve.mitre.org
CVE -
CVE-2022-4294
CVE-2022-4294
The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.
/ Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5
Cisco
Cisco Security Advisory: Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow a remote attacker to bypass authentication or execute arbitrary commands on the underlying operating system…
/ Microsoft Exchange Server Elevation of Privilege Vulnerability
Released: 8 Nov 2022 Last updated: 15 Dec 2022:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41080
Released: 8 Nov 2022 Last updated: 15 Dec 2022:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41080
/ Vulnerability Spotlight: Asus router access, information disclosure, denial of service vulnerabilities discovered
https://blog.talosintelligence.com/vulnerability-spotlight-asus-router-access-information-disclosure-denial-of-service-vulnerabilities-discovered/
https://blog.talosintelligence.com/vulnerability-spotlight-asus-router-access-information-disclosure-denial-of-service-vulnerabilities-discovered/
Cisco Talos Blog
Vulnerability Spotlight: Asus router access, information disclosure, denial of service vulnerabilities discovered
Cisco Talos recently discovered three vulnerabilities in Asus router software.
The Asus RT-AX82U router is one of the newer Wi-Fi 6 (802.11ax)-enabled routers that also supports mesh networking with other Asus routers. Like other routers, it is configurable…
The Asus RT-AX82U router is one of the newer Wi-Fi 6 (802.11ax)-enabled routers that also supports mesh networking with other Asus routers. Like other routers, it is configurable…
/ Linux kernel stack buffer overflow in nftables
https://www.openwall.com/lists/oss-security/2023/01/13/2
https://www.openwall.com/lists/oss-security/2023/01/13/2
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
1300+ domains are hosting a webpage that impersonates the official AnyDesk website (added to Open BLD)
— https://www.bleepingcomputer.com/news/security/over-1-300-fake-anydesk-sites-push-vidar-info-stealing-malware/
— https://www.bleepingcomputer.com/news/security/over-1-300-fake-anydesk-sites-push-vidar-info-stealing-malware/
lab.sys-adm.in
Sys-Admin Laboratory
Open Sys-Admin BLD DNS - Focus on information for free with adblocking and implicit cybersecurity threat prevention.
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Bitdefender-PR-Whitepaper-EyeSpyVPN-creat625-en-EN.pdf
8.6 MB
EyeSpy - Spyware Delivered in VPN Installers
https://www.bitdefender.com/blog/labs/eyespy-iranian-spyware-delivered-in-vpn-installers/
https://www.bitdefender.com/blog/labs/eyespy-iranian-spyware-delivered-in-vpn-installers/
/ Decrypted: BianLian Ransomware
The team at Avast has developed a decryptor for the BianLian ransomware and released it for public download. The BianLian ransomware emerged in August 2022:
https://decoded.avast.io/threatresearch/decrypted-bianlian-ransomware/
The team at Avast has developed a decryptor for the BianLian ransomware and released it for public download. The BianLian ransomware emerged in August 2022:
https://decoded.avast.io/threatresearch/decrypted-bianlian-ransomware/
Avast Threat Labs
Decrypted: BianLian Ransomware - Avast Threat Labs
The team at Avast has developed a decryptor for the BianLian ransomware and released it for public download. The BianLian ransomware emerged in August 2022, performing targeted attacks in various industries, such as the media and entertainment, manufacturing…
/ Git security vulnerabilities announced
Git users are encouraged to upgrade to the latest version, especially if they use
https://github.blog/2023-01-17-git-security-vulnerabilities-announced-2/
Git users are encouraged to upgrade to the latest version, especially if they use
git archive, work in untrusted repositories, or use Git GUI on Windowshttps://github.blog/2023-01-17-git-security-vulnerabilities-announced-2/
The GitHub Blog
Git security vulnerabilities announced
Git users are encouraged to upgrade to the latest version, especially if they use `git archive`, work in untrusted repositories, or use Git GUI on Windows.
Open BLD DNS Updates: Site platform / Web UI
I finally got to the Sys-Admin Lab web site UI, I haven't planned interfaces and colors like HTML body background or link colors for a long time, and today I want to introduce you:
• ☀️ Light/ 🌑 Dark themed site
• Multi-language site
• Documentation Wiki space
• Fully migrated from scratch from Vue Nuxt2 > Nuxt3 engine
• More speed from Nitro engine and UI flexability form Bulma framework
• "Thanks" section legend - Who help testing: 💪 and Contribute: ⚡️
Of course, there is still a lot to do, and I don't know how yet, but I am sure that with your help I will be able to go further and develop the project further and more 🙂
• check and see: https://lab.sys-adm.in
I finally got to the Sys-Admin Lab web site UI, I haven't planned interfaces and colors like HTML body background or link colors for a long time, and today I want to introduce you:
• ☀️ Light/ 🌑 Dark themed site
• Multi-language site
• Documentation Wiki space
• Fully migrated from scratch from Vue Nuxt2 > Nuxt3 engine
• More speed from Nitro engine and UI flexability form Bulma framework
• "Thanks" section legend - Who help testing: 💪 and Contribute: ⚡️
Of course, there is still a lot to do, and I don't know how yet, but I am sure that with your help I will be able to go further and develop the project further and more 🙂
• check and see: https://lab.sys-adm.in
/ Vulnerabilities in TP-Link routers
TP-Link and their latest firmware available as of January 11, 2023, have two vulnerabilities DoS, RCE..:
https://kb.cert.org/vuls/id/572615
TP-Link and their latest firmware available as of January 11, 2023, have two vulnerabilities DoS, RCE..:
https://kb.cert.org/vuls/id/572615
kb.cert.org
CERT/CC Vulnerability Note VU#572615
Vulnerabilities in TP-Link routers, WR710N-V1-151022 and Archer C5 V2
/ Detecting Fake Events in Azure Sign-in Logs
— https://www.inversecos.com/2023/01/detecting-fake-events-in-azure-sign-in.html
— https://www.inversecos.com/2023/01/detecting-fake-events-in-azure-sign-in.html
Inversecos
Detecting Fake Events in Azure Sign-in Logs
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Sudoedit allowing a local attacker to append arbitrary entries to the list of files to process
https://ubuntu.com/security/CVE-2023-22809
P.S. thx for the link @clevergod : ✌️
https://ubuntu.com/security/CVE-2023-22809
P.S. thx for the link @clevergod : ✌️
Ubuntu
CVE-2023-22809 | Ubuntu
Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.
/ Client-Side SSRF to Google Cloud Project Takeover [Google VRP]
https://blog.geekycat.in/client-side-ssrf-to-google-cloud-project-takeover/
https://blog.geekycat.in/client-side-ssrf-to-google-cloud-project-takeover/
/ Yum! Brands, Inc. announced a ransomware attack
January 18, 2023... that impacted certain information technology systems..:
— Yum! Brands, Inc. announced a ransomware attack
— United States Securities And Exchange Commission Report
January 18, 2023... that impacted certain information technology systems..:
— Yum! Brands, Inc. announced a ransomware attack
— United States Securities And Exchange Commission Report
/ Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475)
https://www.mandiant.com/resources/blog/chinese-actors-exploit-fortios-flaw
https://www.mandiant.com/resources/blog/chinese-actors-exploit-fortios-flaw
Google Cloud Blog
Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) | Mandiant | Google Cloud Blog