Posts
2529
Following
647
Followers
1459
"I'm interested in all kinds of astronomy."
[RSS] Microsoft CLIPSP.SYS License update privilege escalation vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-1966
0
1
0
repeated

Taylorism is a management philosophy based on using scientific optimization to maximize labor productivity and economic efficiency.

Here's the result of making the false Taylorist assumption that the output of scientific research is scientific papers—the more, faster, and cheaper, the better.

1
2
0
repeated

Me to Microsoft: You can avoid a whole class of vulnerability if non-admin users can't create subdirectories off of the root directory. You should fix this.

MS: Nah.

Me: Well, you folks should probably at least run Crassus on your code.

MS: Nah.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38098

3
4
0
repeated

Reminder that my book—Rust Atomics and Locks—is freely available online: https://marabos.nl/atomics/ 😊

(If you read it, please leave a review on https://www.goodreads.com/book/show/63291820-rust-atomics-and-locks)

2
6
0
repeated

This is cool! https://quic.xargs.org/ [if you’re a security geek.]

Click on a few bubbles.

h/t @nelson

4
2
0
repeated

In our writeup https://sector7.computest.nl/post/2024-06-cve-2024-20693-windows-cached-code-signature-manipulation/ about CVE-2024-20693, we noted that Microsoft did not structurally address the trust of "$KERNEL.*" Extended Attributes on SMB shares. Today's Patch Tuesday addresses -2024-38133, doing the same thing again, but in this case even an USB disk would work!

I think this may be the first time we got an "Exploitation More Likely", so achievement unlocked I guess?

0
1
0
repeated

Better late than never, patches from and are finally out - and 6 bugs are under active attack. Check out all the details, including some wormable bugs, as @TheDustinChilds breaks down the release. https://www.zerodayinitiative.com/blog/2024/8/13/the-august-2024-security-update-review

0
1
0
repeated
Edited 10 months ago

Happy Patch Tuesday from Microsoft: 87 vulnerabilities, 7 zero-days (6 exploited)

  • CVE-2024-38189 (8.8 high) Microsoft Project Remote Code Execution Vulnerability (exploited)
  • CVE-2024-38107 (7.8 high) Windows Power Dependency Coordinator Elevation of Privilege Vulnerability (exploited)
  • CVE-2024-38106 (7.0 high) Windows Kernel Elevation of Privilege Vulnerability (exploited)
  • CVE-2024-38213 (6.5 medium) Windows Mark of the Web Security Feature Bypass Vulnerability (exploited)
  • CVE-2024-38193 (7.8 high) Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (exploited)
  • CVE-2024-38178 (7.5 high) Scripting Engine Memory Corruption Vulnerability (exploited)
  • CVE-2024-38199 (9.8 critical) Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability (publicly disclosed)

cc: @campuscodi @briankrebs @mttaggart @deepthoughts10 @cR0w @regnil @bschwifty @arinc629 @Cali @wvu @hrbrmstr @avoidthehack @bieberium @TheDustinChilds @dreadpir8robots (make sure to remove all the mentions to avoid ReplyAll madness)

4
6
0
repeated

Fortinet security advisories for :

  • FG-IR-22-445 CVE-2022-45862 (3.7 low) GUI Console WebSockets do not terminate on logout
  • FG-IR-24-012 CVE-2024-36505 (5.1 medium) Real-time file system integrity checking write protection bypass
  • FG-IR-22-047 CVE-2022-27486(6.7 medium) OS command injections in execute CLI commands
  • FG-IR-24-255 RADIUS Protocol CVE-2024-3596 (Fortinet gives it a 6.5 medium) aka
  • FG-IR-23-467 CVE-2024-21757 (6.1 medium) Priviledged admin able to modify super-admins password
  • FG-IR-23-088 CVE-2023-26211 (6.8 medium) XSS vulnerability in communications triggered in playbooks

No mention of exploitation. CVE-2024-3596 was publicly disclosed 09 July 2024.

0
1
0
[FD] Microsoft PlayReady WMRMECC256 Key / root key issue (attack #5)

https://seclists.org/fulldisclosure/2024/Aug/15
0
0
0
repeated

Politico, the NYT, the WaPo, and others say they received hacked Trump campaign materials, but gave few details, a marked contrast to Clinton's emails in 2016 (David Bauder/Associated Press)

https://apnews.com/article/trump-vance-leak-media-wikileaks-e30bdccbdd4abc9506735408cdc9bf7b
http://www.techmeme.com/240813/p14#a240813p14

0
1
0
repeated
repeated

Zoho ManageEngine security advisories:

No mention of exploitation. Mitre and NVD only have publish dates from yesterday 12 August 2024, even though the Zoho advisories marked them fixed 14 June 2024. Zoho also doesn't indicate when the advisories were published. Happy

0
1
0
repeated

‼️Big day! NIST publishes standards for next-generation cryptography (cipher, digital signature) understood as resistant to attacks with future quantum computers. Migration will not be a piece of cake, but there’s time. https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.203.pdf https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.204.pdf https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.204.pdf

1
1
0
repeated

Seeking help from an IT security person - please share!

I run an open source, federated event sharing site, (https://gath.io). A few days ago, it was victim to a ransomware attack that deleted the database. I need a few hours of someone's time (paid of course!) to sit with me and go through my security configuration ASAP.

Sometimes, running open source, free, community services _sucks_. blobhaj_sadreach

7
11
0
[RSS] It rather involved being on the other side of the airtight hatchway: Disabling a security feature as an administrator

https://devblogs.microsoft.com/oldnewthing/20240806-00/?p=110103
1
0
1
[RSS] Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)

https://sector7.computest.nl/post/2024-08-pwn2own-automotive-chargepoint-home-flex/
0
3
1
[RSS] BSidesLV 2024 Slides - Modern ColdFusion Exploitation and Attack Surface Reduction

https://www.hoyahaxa.com/2024/08/bsideslv-2024-slides-modern-coldfusion.html
0
1
2
[RSS] You Can’t Spell WebRTC without RCE - Part 3

https://margin.re/2024/08/you-cant-spell-webrtc-without-rce-part-3/
0
4
3
Show older