Posts
2521
Following
647
Followers
1462
"I'm interested in all kinds of astronomy."
repeated
repeated
Edited 1 year ago

JetBrains security advisory: Updates for security issue affecting IntelliJ-based IDEs 2023.1+ and JetBrains GitHub Plugin
A new security issue was discovered that affects the JetBrains GitHub plugin on the IntelliJ Platform, which could lead to disclosure of access tokens to third-party sites. CVE-2024-37051 (CVSSv3: 9.3 CRITICAL) GitHub access token could be exposed to third-party sites in JetBrains IDEs. No mention of exploitation.

h/t: @serghei See related Bleeping Computer reporting: JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens

0
1
0
repeated

Happy Patch Tuesday from Adobe:

  • APSB24-27 : Security update available for Adobe Photoshop (1)
  • APSB24-28 : Security update available for Adobe Experience Manager (144 CVEs!! Someone's EXPERIENCING a lot of vulnerabilities if you know what I mean)
  • APSB24-32 : Security update available for Adobe Audition (2)
  • APSB24-34 : Security update available for Adobe Media Encoder (1)
  • APSB24-38 : Security update available for Adobe FrameMaker Publishing Server (2, and CVE-2024-30299 is a perfect 10.0 🥳)
  • APSB24-40 : Security update available for Adobe Commerce (10)
  • APSB24-41 : Security update available for Adobe ColdFusion (2)
  • APSB24-43 : Security update available for Adobe Substance 3D Stager (1)
  • APSB24-44 : Security update available for Adobe Creative Cloud Desktop (1)
  • APSB24-50 : Security update available for Adobe Acrobat Android (2)

No mention of exploitation.

1
1
0
repeated

You’d really think that the top seven blocked domains on @KagiHQ being @Pinterest indicate that a functional Google would have deboosted them years ago.

(I’m loving Kagi)

0
1
2
repeated

Trend Zero Day Initiative

School's out, and so are the latest patches from . We're still waiting on the updates from . Check out the analysis from @TheDustinChilds as he breaks down the small release from Redmond. https://www.zerodayinitiative.com/blog/2024/6/11/the-june-2024-security-update-review

1
1
0
repeated

patches are out. Another small release. Still waiting on :-[ Let them patches out! I'll have my full analysis out soon.

0
1
0
repeated

Trend Zero Day Initiative

[ZDI-24-598] (0Day) Microsoft Windows Incorrect Permission Assignment Information Disclosure Vulnerability (CVSS 7.7; Credit: Uncodable)
https://www.zerodayinitiative.com/advisories/ZDI-24-598/

0
2
0
repeated

Mozilla Foundation security advisories:

  • 2024-25 Security Vulnerabilities fixed in Firefox 127
  • 2024-26 Security Vulnerabilities fixed in Firefox ESR 115.12

15 vulnerabilities in Firefox 127. 8 vulnerabilities in Firefox ESR 115.12. No mention of exploitation

0
1
0
repeated

Friendly reminder to submit to GreHack conference: https://grehack.fr/2024/cfp

What's different about GreHack?

- It's a simple one-track conference, but with large audience (usually sold out)
- There's usually a mixture between academic and non-academic presentations. This is enlightening.

On the non-technical side: people are very welcoming, the food is nice (especially for vegetarians), you'll see the snowy Alps, there's an excellent CTF.

0
2
0
repeated
repeated
repeated

I’ve said before and saying again. This is a common problem in vendors - the lack of understandings of the importance/value of new attack vector discovery research.

https://x.com/l33d0hyun/status/1800299745623367867

https://bird.makeup/@l33d0hyun/1800299745623367867

1
2
0
repeated

it has been nearly three months since the last valid report against

Just saying.

I bet you can't find anything to report.

🤠

0
2
0
repeated
repeated

Did anyone realize that already had a feature? 👀

0
1
0
repeated

good morning!
my talk from securityfest has been published!

if you have ~35 minutes and want to learn some stuff about adversarial defenses, have a peek!
https://www.youtube.com/watch?v=ShSR0c81h5U&ab_channel=SecurityFest

1
4
0
repeated

Google asks every app to have a Privacy Policy to be accepted in the Play Store. So, xScreenSaver had to write a privacy policy.

Here you go:

https://www.jwz.org/xscreensaver/google.html

16
19
0
repeated

NEW, by me: Mandiant says cybercriminals stole a "significant volume of data" from Snowflake customers.

Mandiant and Snowflake say they've notified 165 affected customers so far that their cloud-stored data may have been stolen.

Mandiant said the threat campaign was "ongoing," suggesting more victims to come.

More: https://techcrunch.com/2024/06/10/mandiant-hackers-snowflake-stole-significant-volume-data-customers/

0
3
0
repeated

A proof-of-concept (PoC) exploit for a Veeam Backup Enterprise Manager authentication bypass flaw tracked as CVE-2024-29849 is now publicly available, making it urgent that admins apply the latest security updates.

https://www.bleepingcomputer.com/news/security/exploit-for-critical-veeam-auth-bypass-available-patch-now/

0
2
0
repeated

Uncovering a Critical Vulnerability in Authentik's PKCE Implementation (CVE-2023-48228) | Offensity https://www.offensity.com/en/blog/uncovering-a-critical-vulnerability-in-authentiks-pkce-implementation-cve-2023-48228/

0
1
0
Show older