In case you missed it, here's the recording of our #HEXACON2024 talk "Exploiting File Writes in Hardened Environments"!
It's a short and sweet 30-minute talk, so grab a coffee and sit back while @scryh goes from HTTP request to ROP chain in Node.js β
Palo Alto Networks Security Advisory: PAN-SA-2024-0015 Important Informational Bulletin: Ensure Access to Management Interface is Secured
Palo Alto Networks is aware of a claim of a remote code execution vulnerability via the PAN-OS management interface. They do not know the specifics of the claimed vulnerability.
We strongly recommend customers to ensure access to your management interface is configured correctly in accordance with our recommended best practice deployment guidelines. In particular, we recommend that you ensure that access to the management interface is possible only from trusted internal IPs and not from the Internet. The vast majority of firewalls already follow this Palo Alto Networks and industry best practice.
#vulnerability #paloaltonetworks #paloalto #pan #panos #cybersecurity #infosec
Please make this happen. I would love nothing more than to have an image parser run during a bugcheck
If as it appears likely that πͺπΊwill have to start defending itself against Russia π·πΊ alone it may be good to realize our IT systems and society arenβt remotely ready for that. https://berthub.eu/articles/posts/cyber-security-pre-war-reality-check/
Ekoparty 2024 Binary Gecko Challenge π¦π·
Complete the challenge to get a ticket to our VIP dinner/party event in Buenos Aires during the conference.
Winners will also get an interview for a Security Researcher position at Binary Gecko.
CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog
Hot off the press!
#cisa #cisakev #kev #vulnerability #CVE #CVE_2024_5910 #CVE_2024_43093 #CVE_2024_51567 #CVE_2019_16278 #infosec #cybersecurity
Cisco multiple security advisories from 06 November 2024:
The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
The #BHASIA Call for Papers closes on November 13! This year I am on the review committee and I am so thrilled to be checking all the cool tools! Submit your proposal >> bit.ly/3TBThxZ
π CVE-2024-50340: Ability to change environment from query
β‘οΈ https://symfony.com/blog/cve-2024-50340-ability-to-change-environment-from-query
#symfony