Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.55K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
/ High Vulnerability – Dahua – CVE-2022-30564

Redinent Researchers discovered unauthorised device timestamp modification vulnerability in Dahua products.

https://www.redinent.com/blog/dahua-cve-2022-30564/
/ Reddit was hacked

Reddit systems were hacked as a result of a sophisticated and highly-targeted phishing attack. They gained access to some internal documents, code, and some internal business systems..:

https://www.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
/ Globalping CLI

This CLI tool provide access a global network of probes without leaving console. In short: this tool allow use ping from different regions from the world, example:

globalping ping lab.sys-adm.in --from "Paris"

Tool supplied in docker, or pre-builded packages, or own build binary which can build with Go. Repo:

https://github.com/jsdelivr/globalping-cli

Tis project has API, which can try on link: https://api.globalping.io/demo/
/ iOS, iPadOS, macOS, and Safari Under Attack with New Zero-Day

CVE-2023-23529 - bug in the WebKit browser engine that could be activated when processing maliciously crafted web content, culminating in arbitrary code execution:

— macOS: https://support.apple.com/en-us/HT213633
— iOS: https://support.apple.com/en-us/HT213635
— Safari: https://support.apple.com/en-us/HT213638
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Network Pentesting MindMap

https://github.com/c4s73r/NetworkNightmare
/ Windows Graphics Component Remote Code Execution Vulnerability

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21823
/ Citrix Releases Security Updates for Workspace Apps, Virtual Apps and Desktops

Emergency note from CISA:

https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/citrix-releases-security-updates-workspace-apps-virtual-apps-and
/ Dirty bug in HAProxy's headers processing, and that, when properly exploited, this bug allows to build an HTTP content smuggling attack

HAProxy Security Update (CVE-2023-25725)

https://www.mail-archive.com/haproxy@formilux.org/msg43229.html