/ New high-severity vulnerability (CVE-2023-29552) discovered in the Service Location Protocol (SLP)
https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp
https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp
Bitsight
New high-severity vulnerability (CVE-2023-29552) discovered in the Service Location Protocol (SLP) | Bitsight
Researchers from Bitsight and Curesec have jointly discovered a high-severity vulnerability — tracked as CVE-2023-29552 — in the Service Location Protocol (SLP).
Открытые практикумы DevOps, Linux, Networks и Golang by Rebrain (расписание на май)
• 2 мая DevOps: Использование регулярных выражений на примере анализа логов
• 3 мая Linux: Виртуальные интерфейсы и канальный уровень в Linux
• 4 мая Networks: Traffic Engineering (TE)
• 10 мая Linux: ФСТЭК для Linux (часть 2)
• 16 мая DevOps: Введение в Docker
• 17 мая Linux: ФСТЭК для Linux
• 18 мая Networks: Segment Routing (SR)
• 23 мая DevOps by Rebrain
• 24 мая Linux: Сертификат WEB-сервера
• 25 мая Golang by Rebrain
• 30 мая DevOps: Шифрование секретов в GitOps
• 31 мая Linux: Реализации протоколов маршрутизации для Linux
Подключиться можно Здесь
• 2 мая DevOps: Использование регулярных выражений на примере анализа логов
• 3 мая Linux: Виртуальные интерфейсы и канальный уровень в Linux
• 4 мая Networks: Traffic Engineering (TE)
• 10 мая Linux: ФСТЭК для Linux (часть 2)
• 16 мая DevOps: Введение в Docker
• 17 мая Linux: ФСТЭК для Linux
• 18 мая Networks: Segment Routing (SR)
• 23 мая DevOps by Rebrain
• 24 мая Linux: Сертификат WEB-сервера
• 25 мая Golang by Rebrain
• 30 мая DevOps: Шифрование секретов в GitOps
• 31 мая Linux: Реализации протоколов маршрутизации для Linux
Подключиться можно Здесь
/ Threat Actor Selling New Atomic macOS (AMOS) Stealer on Telegram
https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/
https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/
/ Never Connect to RDP Servers Over Untrusted Networks
Demonstration - why connecting using the Remote Desktop Protocol (RDP) must be avoided on untrusted networks like in hotels, conferences, or public Wi-Fi. Protecting the connection with a VPN or a Remote Desktop Gateway is the only safe alternative:
https://www.gosecure.net/blog/2023/04/26/never-connect-to-rdp-servers-over-untrusted-networks/
Demonstration - why connecting using the Remote Desktop Protocol (RDP) must be avoided on untrusted networks like in hotels, conferences, or public Wi-Fi. Protecting the connection with a VPN or a Remote Desktop Gateway is the only safe alternative:
https://www.gosecure.net/blog/2023/04/26/never-connect-to-rdp-servers-over-untrusted-networks/
GoSecure
Never Connect to RDP Servers Over Untrusted Networks
Did you know that RDP is unsafe without the use of additional protection like a VPN? In this blog post we will explain why and demonstrate the impact.
/ Elastic Security Labs discovers the LOBSHOT malware
Adversaries continue to abuse and increase reach through malvertising such as Google Ads by impersonating legitimate software..
Deep dive research and protection steps:
— https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware
🥋 Malware domains already blocked in Sys-Admin BLD DNS
Adversaries continue to abuse and increase reach through malvertising such as Google Ads by impersonating legitimate software..
Deep dive research and protection steps:
— https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware
🥋 Malware domains already blocked in Sys-Admin BLD DNS
/ RTM Locker Ransomware as a Service (RaaS) Now Suits Up for Linux Architecture
ESXi servers under attack..:
https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux
ESXi servers under attack..:
https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux
Uptycs
RTM Locker Ransomware as a Service (RaaS) Now on Linux - Uptycs
Uptycs threat research team discovered a new ransomware Linux binary attributed to the RTM group Locker, a known Ransomware-as-a-Service (RaaS) provider.
/ Zyxel has released patches for an OS command injection vulnerability
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
Zyxel
Zyxel security advisory for OS command injection vulnerability of firewalls | Zyxel Networks
CVE: CVE-2023-28771 Summary Zyxel has released patches for an OS command injection vulnerability found by TRAPA Security and urges users to install them for optimal protection. What is the vulnerabilities? Improper error message handling in some firewall…
OpenBLD - Next Stage to Growth with ClouDNS
GeoDNS and Global Anycast DNS features from ClouDNS - it as a brilliant opportunity for additional OpenBLD Performance and Availability
Today ClouDNS supported OpenBLD DNS and provided own features for free:
• Anycast DNS service and Anycast GeoDNS servers
• DDoS Protection
• DNS Failover checks
• EDNS-client-subnet support
• and more...
ClouDNS providing flexible tools for managements services and very affordable pricing plans and it is I like it very much.
This can be a key milestone in the development phase of the OpenBLD project, it is a next stage for growth. I have special domain name for OpenBLD DNS project, may be it is a "that very moment"...
• All ClouDNS features you can found on ClouDNS Site
• How to protect for your self and family with OpenBLD Here
Sys-Admin InfoSec pinned « OpenBLD - Next Stage to Growth with ClouDNS GeoDNS and Global Anycast DNS features from ClouDNS - it as a brilliant opportunity for additional OpenBLD Performance and Availability Today ClouDNS supported OpenBLD DNS and provided own features for free:…»
/ Three New BGP Message Parsing Vulnerabilities Disclosed in FRRouting Software
https://www.forescout.com/blog/three-new-bgp-message-parsing-vulnerabilities-disclosed-in-frrouting-software/
https://www.forescout.com/blog/three-new-bgp-message-parsing-vulnerabilities-disclosed-in-frrouting-software/
Forescout
3 New BGP Message Parsing Vulnerabilties in FRRouting Software - Forescout
Security of the ubiquitous BGP protocol has long been studied, but analysis of FRRouting and other popular BGP implementation finds 3 new vulnerabilities.
/ Netgear User Management Remote Credentials Disclosur,e Remote Restriction Bypass
https://flashpoint.io/resources/research/fp-2023-01-netgear-prosafe-network-management-system/
https://flashpoint.io/resources/research/fp-2023-01-netgear-prosafe-network-management-system/
Flashpoint
FP-2023-01 - NETGEAR’s ProSAFE® Network Management System NMS300
Flashpoint disclosed a new vulnerability affecting NETGEAR's ProSAFE® Network Management System NMS300.
/ The LockBit ransomware (kinda) comes for macOS
Detailed research:
https://objective-see.org/blog/blog_0x75.html
Detailed research:
https://objective-see.org/blog/blog_0x75.html
objective-see.org
The LockBit ransomware (kinda) comes for macOS
Analyzing an arm64 mach-O version of LockBit
Открытый практикум Linux by Rebrain: ФСТЭК для Linux. Часть 2
• 10 Мая (Среда) в 20:00 по МСК. Детали
Программа:
• Продолжаем выполнять требования
• Что нужно поправить в работе ядра
• Что может быть если это не исправить
Ведет:
• Андрей Буранов - Специалист по UNIX-системам в компании VK. Опыт работы с ОС Linux более 7 лет.
• 10 Мая (Среда) в 20:00 по МСК. Детали
Программа:
• Продолжаем выполнять требования
• Что нужно поправить в работе ядра
• Что может быть если это не исправить
Ведет:
• Андрей Буранов - Специалист по UNIX-системам в компании VK. Опыт работы с ОС Linux более 7 лет.
OpenBLD Pre-release Testing Program
I'm working on new OpenBLD DoH/DoT release with Anycast DNS, GeoDNS (Europe, Asia locations) functionality.
I think this or next month, I'll start the new faster DoH/DoT OpenBLD testing release with automatic identification of the closest server location continent and network route detection for OpenBLD clients.
You can fill this form in, after review I'll "ping" you with testing as soon as possible:
🔶 REQUEST PARTICIPATION
Let's make internet surfing faster and safer together. Peace ✌️
I'm working on new OpenBLD DoH/DoT release with Anycast DNS, GeoDNS (Europe, Asia locations) functionality.
I think this or next month, I'll start the new faster DoH/DoT OpenBLD testing release with automatic identification of the closest server location continent and network route detection for OpenBLD clients.
You can fill this form in, after review I'll "ping" you with testing as soon as possible:
🔶 REQUEST PARTICIPATION
Let's make internet surfing faster and safer together. Peace ✌️
When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities
Vulnerabilities in the Azure API Management service. These included two SSRF (Server-Side Request Forgery) vulnerabilities and a file upload path traversal on an internal Azure workload:
— Read more…
Vulnerabilities in the Azure API Management service. These included two SSRF (Server-Side Request Forgery) vulnerabilities and a file upload path traversal on an internal Azure workload:
— Read more…
Tenable®
Uncovering 3 Azure API Management Vulnerabilities – When Good APIs Go Bad
Learn how now-patched Azure API Management service vulnerabilities revealed by our research team enabled malicious actions.
GitLab Critical Security Release: 15.11.2, 15.10.6, and 15.9.7
GitLab Community Edition (CE) and Enterprise Edition (EE) - Malicious Runner Attachment via GraphQL:
— https://about.gitlab.com/releases/2023/05/05/critical-security-release-gitlab-15-11-2-released/
GitLab Community Edition (CE) and Enterprise Edition (EE) - Malicious Runner Attachment via GraphQL:
— https://about.gitlab.com/releases/2023/05/05/critical-security-release-gitlab-15-11-2-released/
[CVE-2023-32233] Linux kernel use-after-free in Netfilter nf_tables
https://www.openwall.com/lists/oss-security/2023/05/08/4
https://www.openwall.com/lists/oss-security/2023/05/08/4
New Akira Ransomware Operation Hits Corporate Networks
https://www.blackhatethicalhacking.com/news/new-akira-ransomware-operation-hits-corporate-networks/
https://www.blackhatethicalhacking.com/news/new-akira-ransomware-operation-hits-corporate-networks/
Black Hat Ethical Hacking
New Akira Ransomware Operation Hits Corporate Networks | Black Hat Ethical Hacking
A new ransomware operation named Akira has been quietly and systematically infiltrating corporate networks worldwide since its launch in March 2023.