“[un]prompted” is a new AI security conference for practitioners (https://t.co/xKR1ZZKmkG).
The first event was held in San Francisco earlier this month and the recordings are now live:
https://t.co/9UGtUSQl2M
💻 Yippee Ki-Yay Motha Hacka! 🟢 The #CTF is launched. Check your #MailingList email!
Participate, learn, enjoy, have fun. Thank you @hackthebox_eu for setting it up again this year! #BSidesAth 🟢 Our ML: https://t.co/Xx7aG0KZPX 🟢 https://t.co/ZrfByd1M8I 🟩
CVE-2024-21893 (SSRF) can be chained to CVE-2024-21887 for unauthenticated command injection with root privileges (bypassing previous fix).
Take Ivanti hosts offline, rebuild and upgrade to the latest version that addresses all known vulnerabilities.
We have published our AttackerKB @rapid7 analysis for CVE-2024-21893, an SSRF vulnerability in the SAML component of Ivanti Connect Secure, that has recently been exploited in the wild, allowing attackers bypass the mitigation for an earlier exploit chain. https://t.co/tVgUCrp1KH
Another advisory about potential unauthorized access, this time recommending disabling all HTTP and HTTPs traffic to MOVEit Transfer: https://t.co/RjzKgUWsVh
Internet facing MOVEit Transfer hosts are being actively exploited via a critical 0day vulnerability (CVE-2023-34362), look for indicators of compromise.
- https://t.co/57x8mVguGn
- https://t.co/mt1Emj24mr
- https://t.co/ebEKlxbDh5
Log4j 2.17.1 patches an RCE vulnerability (CVE-2021-44832, CVSS 6.6) affecting all versions from 2.0-alpha7 to 2.17.0 (excl.2.3.2 & 2.12.4). The attack requires permission to modify the logging configuration file, if that happens you have more things to worry about.
Log4j 2.17.0 has been released in order to patch a high severity DoS vulnerability (CVE-2021-45105, CVSS 7.5) affecting all versions from 2.0-beta9 to 2.16.0.
https://t.co/F5ackjEbQD