Posts
2524
Following
646
Followers
1461
"I'm interested in all kinds of astronomy."
repeated

D-Link is warning that four remote code execution (RCE) flaws impacting all hardware and firmware versions of its DIR-846W router will not be fixed as the products are no longer supported.

https://www.bleepingcomputer.com/news/security/d-link-says-it-is-not-fixing-four-rce-flaws-in-dir-846w-routers/

2
5
0
CVE-2024-45310: runc can be tricked into creating empty files/directories on host

https://seclists.org/oss-sec/2024/q3/237
0
0
1
repeated

SecureLayer7: CVE-2024-37084: Spring Cloud Remote Code Execution
SecureLayer7 has been churning out zero-day vulnerabilities (publicly releasing information about vulnerabilities without a coordinated vulnerability disclosure with the impacted vendor or assigning CVEs) and proofs of concepts for vulnerabilities. According to Spring.io, Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing platform deployed in Cloud Foundry and Kubernetes. CVE-2024-37084 (9.8 CRITICAL) is an arbitrary file write. SecureLayer7 used patch diffing to determine that it’s an insecure deserialization vulnerability that leads to remote code execution, and provides a proof of concept for it.

0
1
0
repeated
Edited 10 months ago

Mozilla Foundation security advisories:

  • 2024-39 Security Vulnerabilities fixed in Firefox 130
  • 2024-40 Security Vulnerabilities fixed in Firefox ESR 128.2
  • 2024-41 Security Vulnerabilities fixed in Firefox ESR 115.15
  • 2024-42Security Vulnerabilities fixed in Focus for iOS 130

No mention of Firefox for iOS or Thunderbird (which would arrive in 2 separate advisories). Expect future advisories likely later today. No mention of exploitation.

Edited to include late advisory for Focus for iOS 130.

1
1
0
@jerry Hi! infosec.place throwing 504's again for the main timeline :( Could you please take a look?
1
0
0
repeated

The recording of our @WEareTROOPERS presentation is now online, enjoy!

- IBM i for Wintel Hackers

https://www.youtube.com/watch?v=t4fUvfzgUbY

0
1
0
repeated

Analysis of CVE-2024-37084: Spring Cloud Remote Code Execution https://blog.securelayer7.net/spring-cloud-skipper-vulnerability/

0
1
0
Off-by-One 2024 Day 1 - Keynote : Breaking Into Vulnerability Research: Dr Silvio Cesare

https://www.youtube.com/watch?v=tAmjkfO3-Ow
0
3
3
:O

"The TMS9900 is bonkers. Big endian, has no stack pointer, and there's an instruction to execute the contents of a register as if it were an instruction in memory." - @travisgoodspeed

"Mike Brent (tursilion) made an awesome TMS9900 code generator for CVBasic, so now it can target TI-99/4A computers. The picture shows Viboritas running in the Classic99 emulator." - @nanochess

https://github.com/nanochess/cvbasic
2
3
10
CVE-2023-41111: Samsung Baseband RLC Data Re-Assembly Buffer Overflow

https://labs.taszk.io/blog/post/93_rlc_bof/
0
0
3
repeated

Traceeshark: Deep Linux runtime visibility meets Wireshark https://github.com/aquasecurity/traceeshark

0
1
0
repeated

'The Dutch Data Protection Authority imposes a fine of 30.5 million euro and orders subject to a penalty for non-compliance up to more than 5 million euro on Clearview AI... Clearview has built an illegal database with billions of photos of faces, including of Dutch people. The Dutch DPA warns that using the services of Clearview is also prohibited.' https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition

0
7
0
repeated
[RSS] The Co­Initialize­Security function demands an absolute security descriptor

https://devblogs.microsoft.com/oldnewthing/20240902-00/?p=110201
0
0
0
repeated

Zero Trust Environments

8
17
2
Show older