Update on #NetScaler vulnerability CVE-2023-24488 & CVE-2023-3519: There are still >20,2k systems vulnerable to #XSS & #RCE. Patch now! Check out our slides for more info about the scan data: https://t.co/BtLmCQfBWB
We scanned for CVE-2023-24488 on Monday, 10th of July 2023 and identified 30,659 vulnerable systems.
Check out our results here: https://t.co/11TBWC9AvO
More than 60% of all identified systems are still vulnerable. Patch now! now! #internetscanning
🔥 @OWASP Kubernetes Top 10
A prioritized list of risks backed by data aimed at helping security practitioners, system administrators, and software developers prioritize risks around the #Kubernetes ecosystem
https://t.co/1ysbb2QO3c
FIRST has updated the globally renowned Traffic Light Protocol - a vital system used by the cybersecurity industry worldwide to share sensitive information. TLP Version 2.0 can be found on the website. https://t.co/XMloBEQYme
#cybersecurity#incidentresponse#securityteams
Im Projekt #SiSyPHuS Win10 haben wir ein Tool veröffentlicht, mit dem das Verhalten der Windows Telemetrie detailliert beobachtet werden kann - der "System Activity Monitor" (SAM). Mehr hier: ➡https://t.co/W7fnvpstMp
#DeutschlandDigitalSicherBSI
Start of round 2 for the openECSC Challenge - spread the word and join - great prices to win and great people to meet - take the chance and show your skills https://t.co/Ieh9rYXSE3
NIST has released the initial public draft of NIST Special Publication (SP) 800-82r3, Guide to Operational Technology (OT) Security
https://t.co/SxyGwMaylz
https://t.co/iGssO6pv3f
Vielen Dank allen Teilnehmern und unseren Langjährigen Partnern ohne deren tolle Unterstützung diese Erfolgsgeschichte nie mögliche wäre !!
❗️ #CERTWarnung ❗️
Derzeit erwarten wir nicht, dass von der #Spring4Shell#Schwachstelle ein mit #Log4Shell vergleichbares Bedrohungsszenario ausgeht. Dennoch empfehlen wir dringend, die veröffentlichten Sicherheitshinweise zu beachten:
https://t.co/PVZRWDwlX3
⚠️ #ENISA and @CERTEU strongly encourage all public and private sector organisations in the EU to adopt a minimum set of cybersecurity best practices,
See below 👇
It's amazing to me that after all this time, almost all media coverage of Telegram still refers to it as an "encrypted messenger."
Telegram has a lot of compelling features, but in terms of privacy and data collection, there is no worse choice. Here's how it actually works:
1/
We published an open-sourced log4j-scanner derived from scanners created by other members of the open-source community. This tool is intended to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities: https://t.co/af8uszW8K4
Here are the latest results of our scans for the #log4shell vulnerability (#cve202144228). More than 15,700 vulnerable services have been identified. Scan results are already on the way to national CERTs.
More info on how we scan: https://t.co/uXDwGZfrfG
We started our second research scan for rhe log4j vulnerability (CVE-2021-44228). Following up on the results of the first scans we are trying to keep track of successfully patched systems and improve our scan queries to get better results. More info on https://t.co/uXDwGZfrfG
4. We try to answer all inquiries and calls that we receive in a very timely manner and we allso try to be transparent about what we intend to do with our research and how we go about it.
3. The abuse domain refers to our main website, indicating we are a legitimate IT security service provider and researcher entity. A traceable track record of public presentations and publications can be quickly found.