🚨 CVE-2024-27292 exploitation campaign detected! (thread)
What is the CVE-2024-27292 vulnerability?
CVE-2024-27292 is a path traversal vulnerability in Docassemble. It allows unauthenticated attackers to access arbitrary files, such as /etc/passwd via specially crafted URL parameters. The root cause is improper sanitization of user-supplied inputs, making it possible for attackers to probe system-level files.
Over the past few days, CrowdSec telemetry has identified a significant and accelerating wave of exploit attempts targeting the URI pattern: /interview?i=/etc/passwd.
Docassembe is a free, open source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.
This pattern aligns with an exploit attempt for CVE-2024-27292, a vulnerability disclosed in late 2024 affecting Docassemble (v1.4.53 to v1.4.96).
One week ago, I added three CrowdSec Blocklists on a VPS running WordPress and NGINX.
With the CrowdSec NGINX RC's stats feature, I was able to see how effective CrowdSec Blocklists are! In just a week, they blocked 70% of HTTP requests coming from malicious IPs.
#crowdsec
Jumping from New York to Milan for some shopping? Within … 30 minutes? 🧐 That seems a bit sus, wouldn’t you agree?
Follow this tutorial and learn how to use the new conditional feature to detect impossible travel 🌍 and other suspicious IP behaviors.
https://t.co/dX4fgjXAGF
We are thrilled to announce the release of the CrowdSec Majority Report! 🎉
Explore global #cyberthreats, the myth of #VPN ’s popularity in cybercriminal activities, and the most accurate method of evaluating #AutonomousSystems.
https://t.co/9DsLf3c2oY
#cybersecurityreport
@THESMASHY Hello, what issues or errors did you face while upgrading crowdsec ?
We are available on Discord if you need help debugging your crowdsec :)
https://t.co/peTmsICtbV
New scenarios for the CVE-2022-40684 and CVE-2022-26134 are on the Hub.
See them here:
CVE-2022-40684 👉 https://t.co/19zkK475RM
CVE-2022-26134 👉 https://t.co/xjKOe6ouO6
🚨Pesky Forti auth bypass (CVE-2022-40684) is no match for CrowdSec! We just released a scenario to aid in detecting these attacks which you will find here 👉 https://t.co/xUivlps7kB
Proud to announce a €14M Series A round led by @SupernovaInvest and joined by @BreegaVC. This is a big step forward in our goal of combating cybercrime and positioning ourselves as the world’s largest crowdsourced CTI network 🚀
👉 https://t.co/QHPmtVIUXQ
#CyberSecurity
@Crowd_Security The top 5 IP's are already blocked by @Crowd_Security community blocklist another is also stated but coverage of 6/10 based on IP reputation is great start to protecting your websites!
We’re announcing our exciting collaboration with CrowdSec - the only integration of its kind and is set to mark a pivotal moment in WordPress security.
https://t.co/d1XGcUW7gc
#crowdsec#secruity#wordpress#wordpresssecurity
The new version of the CrowdSec @nginx bouncer is out! It comes with stream mode support, reCAPTCHA v2, and more.
Read our latest blog post for the full list of new features and how-to install tutorial 👇👇👇
https://t.co/JfP77bdxog
🎉 Yesterday, our community shared 1+ MILLION signals! 🎉 On one single day!
The detection capabilities of CrowdSec are now growing exponentially. Our users exchange threat signal data with each other daily, generating the greatest CTI network. 🚀🚀🚀
Join Us!
#CyberSecurity
Parse and detect attacks with CrowdSec for free.
Check out our latest article to learn how to write CrowdSec parsers and scenarios (on the example of @asteriskpbx) 👇
https://t.co/fznlRbClqK
#cybersecurity#opensource
💥 PwnKit: find out how to detect and alert on privilege escalation vulnerability (CVE-2021-4034) with CrowdSec. Learn more in our latest article:
https://t.co/zV1Id7zPef
#linux#CybersecurityNews#Pwnkit
🚀Over this year, CrowdSec blocked 1+ MILLION malicious IPs. And is now used in 120+ countries and 2K+ locations.🥳
We thank our community of #opensource enthusiasts and inspired #CyberSecurity professionals for being here with us, outnumbering cybercriminals together!💪