Another appliance vuln down...
CVE-2022-40684, affecting multiple #Fortinet solutions, is an auth bypass that allows remote attackers to interact with all management API endpoints.
Blog post and POC coming later this week. Patch now.
RT @binitamshah: memit : Run binaries directly from memory on Linux, using this Go module or the included CLI tool : https://t.co/ql1SXUxeTj credits @liam_galvin
RT @sansforensics: In his #ThreatHuntingSummit talk, @DFIR_TNT covers common ransomware gang "hands on keyboard" techniques for stealing your data, disabling defenses, and making your data and devices resistant to recovery.
https://t.co/epTUlbjiQE
RT @zerocution: Now, our reseachers - @sqrtrev @gPayl0ad @real_as3617 disclose the PHP disable_function bypass RCE via OOB read/write payloads which work from PHP7 to PHP8.2-dev
You can check the codes at https://t.co/SGdqWpakTg
I wanted a way to monitor trending CVEs on Twitter
So I built https://t.co/YiHEgCQ2y9
- data comes from Twitter + NIST NVD APIs
- back-end: Python, Flask, PostgreSQL, and Redis
- front-end: React + Bootstrap
It's a quick MVP, but let me know your thoughts and feedback...