⚔🛡☣ Comunidad Anonimo501 💻📱🖥


Channel's geo and language: not specified, not specified
Category: not specified


Similar channels

Channel's geo and language
not specified, not specified
Category
not specified
Statistics
Posts filter


National Vulnerability Database
CVE-2020-26210

In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have been exploited the linked advisory provides a SQL query to test. As a workaround, page edit permissions could be limited to only those that are trusted until you can upgrade although this will not address existing exploitation of this vulnerability. The issue is fixed in version 0.30.4.






SENIOR SECURITY ENGINEER REMOTE.
Importante compañía requiere para su equipo de trabajo Profesionales titulados en ingeniería de sistemas con dominio de inglés avanzado en conversación.
Experiencia mínima de 5 años en el rol de seguridad informática, con un dominio demostrado de múltiples clases de defectos de seguridad, comprensión de las plataformas de computación en la nube, diseño y operación de la infraestructura basada en la nube con Amazon Web Service (AWS), manejo de Hipaa y Pci. Conocimiento en ISO 27001.
Labor 100% remota, puede aplicar personal de cualquier ciudad, horarios de lunes a viernes de 9 am a 6 pm.
Salario negociable entre: $7´000.000 a $9´000.000.
Interesados enviar hoja de vida al correo (📧 descrito en la parte inferior de este mensaje ⬇) en el asunto indicar el cargo al cual postula.




Microsoft, in collaboration with MITRE, IBM, NVIDIA, and Bosch, has released — Adversarial ML Threat Matrix Framework — to help security analysts detect, respond to, and remediate adversarial attacks against machine learning (ML) systems.

Details: https://thehackernews.com/2020/10/adversarial-ml-threat-matrix.html






GravityRAT: spyware con módulos para MacOS y Android
https://blog.segu-info.com.ar/2020/10/gravityrat-spyware-con-modulos-para.html


National Vulnerability Database
CVE-2020-5977

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.








Adobe lanza un parche para solventar vulnerabilidades críticas de 10 programas

Dentro de las afectadas tenemos a Photoshop, Illustrator, InDesign, Marketo, After Effects, Animate, Premiere Pro, Media Encoder, Creative Cloud y Dreamweaver tanto en MacOS como en Windows.

Cada herramienta tenía distintas vulnerabilidades, Illustrator por ejemplo recibió un total de 7 fixes entre los que prevenían ejecución de código remoto.

#Adobe

Fuente en inglés:
https://www.zdnet.com/article/adobe-releases-another-out-of-band-patch-to-squash-critical-bugs-across-creative-software/




National Vulnerability Database
CVE-2020-5791

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.






Nuevo método de ataque a certificados TLS, denominado Raccoon attacK
https://t.co/T62CnoTmNR— Fran Andrades (@AndradesFran) September 10, 2020


Major Vulnerabilities Discovered in Qualcomm QCMAP (Qualcomm Mobile Access Point)
(CVE-2020-25858, CVE-2020-3657, CVE-2020-25859)
https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities

20 last posts shown.

542

subscribers
Channel statistics