If I was Lego, I would release a special set of Jimmy Carter building a house for Habitat for Humanity and raise the age to 100 just for that set. All profits go to Habitat for Humanity. Total missed opportunity.
CfP for Hackerhotel is officially opened:
https://t.co/RPyFjuOwgN
Please submit all your interesting, funny, technical or any other talk, workshop or quiz you would like to present.
📢 Calling all forward-thinking speakers! WICCON is searching for captivating presentations that push boundaries and inspire change. If you have a captivating idea or research to share, submit your CFP today!
https://t.co/rzpJyb5LAe
#WICCON2023#CFP#cybersecurity#infosec
Citrix Gateway VPN compromised via CVE-2023-3519 (a critical unauthenticated RCE) shows evidence of exploitation on 7th July, 11 days before the official patch.
The attackers exfiltrated the system configuration file to then probably use the Metasploit module called "citrix_netscaler_config_decrypt" and gain access as the user "nsroot" (full system access), other important secrets about the network and internal users are leaked.
Webshell/backdoor logout.php has 0 detections in VirusTotal, I shared it here: https://t.co/IyrrM0yNfn
🚨 If you performed the update process to mitigate this vulnerability, assume that you might be compromised and perform a full assessment of the instances and users involved.
Follow these recommendations:
- https://t.co/js49XLDHX4
- https://t.co/js49XLDHX4
Microsoft Incident Response has published a guide for investigating attacks that use CVE-2023-23397, providing steps organizations can take to assess whether users have been targeted or compromised by threat actors exploiting the vulnerability. https://t.co/Izwm5CIU5I
We just launched 5 new AWS CIRT Workshops, and they are FREE!
Learn how to identify unauthorized activity:
- IAM cred usage
- Creation/deletion/access of resources (EC2/S3 buckets)
- Usage of web app vulns
Have fun and let us know what you think!
https://t.co/uMEY7jZut5
Provider organizations are being urged to prioritize patching a critical vulnerability in the Citrix Application Delivery Controller and Gateway platforms, as threat actors have already compromised multiple healthcare entities by exploiting the flaw. https://t.co/0mzlAqPUy3
Our Exercise in a Box tool has multiple exercises for you to pick from... testing your organisations resilience to a ransomware attack to understanding supply chain risks!
And now see all of your reports in one place for up to 60 days! 👇
https://t.co/EAd2frGPcl
.@Google has released a new free tool that allows open-source developers to more easily access vulnerability information relevant to their projects. #cybersecurity#infosec#ITsecurity https://t.co/61vXYKP6eP
Google launches open source availability of OSV-Scanner, a scanner that aims to offer easy access to vulnerability information about various projects.
Read: https://t.co/bRfLO61vMw
#infosec#cybersecurity
Urgent: Fortinet has issued emergency patches for a severe pre-auth RCE vulnerability (CVE-2022-42475) affecting its FortiOS SSL-VPN product that is being actively exploited in the wild.
Read: https://t.co/JgEGIJifoM
#infosec#cybersecurity#hacking
#CISA has added a critical #vulnerability affecting #Oracle Fusion Middleware to the Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation.
Read: https://t.co/JjJOZI9Kww
#infosec#cybersecurity#hacking
Citrix heeft kwetsbaarheden verholpen in Citrix Gateway en Citrix ADC. De kans en schade van de kwetsbaarheid met kenmerk CVE-2022-27510 beoordelen wij als high/high. Lees het beveiligingsadvies hier: https://t.co/RbmizdgfUK
It's official. The sister organization to the Dutch Institute for Vulnerability Disclosure (DIVD) @csirt_global is now officially looking for experienced security researchers to expand the global community. \o/ https://t.co/f9hgBuBkND
Here's my whole story with @VaughnHillyard on how "drop box tailgate parties" went from a meme on Truth Social to armed men standing watch over ballot boxes nationwide.
It happened because the platform allowed it. This platform might allow it soon.
https://t.co/M5UgKcnoQL