Apple Updates Everything – New 0 Day in WebKit, (Mon, Jan 22nd)

Today, Apple released significant “point releases” for all its operating systems. With new features, we also got patches for 29 different vulnerabilities. The table below shows how some vulnerabilities affect multiple operating systems across the Apple ecosystem.

Continue reading Apple Updates Everything – New 0 Day in WebKit, (Mon, Jan 22nd)

Posted in Uncategorized

Scans/Exploit Attempts for Atlassian Confluence RCE Vulnerability CVE-2023-22527, (Mon, Jan 22nd)

Last week (January 16th), Atlassian released it&#;x26;#;39;s January 2024 Security Bulletin. Included with the bulletin was a patch for CVE-2023-22527, a remote code execution vulnerability in Confluence Data Center and Confluence Server. Atlassian assigned a CVSS score of 10.0 to the vulnerability. Exploitation does not require authentication [1].

Continue reading Scans/Exploit Attempts for Atlassian Confluence RCE Vulnerability CVE-2023-22527, (Mon, Jan 22nd)

Posted in Uncategorized

macOS Python Script Replacing Wallet Applications with Rogue Apps, (Fri, Jan 19th)

Still today, many people think that Apple and its macOS are less targeted by malware. But the landscape is changing and threats are emerging in this ecosystem too[1]. Here is a good example: I found a malicious Python script targeting wallet application on macOS.

Continue reading macOS Python Script Replacing Wallet Applications with Rogue Apps, (Fri, Jan 19th)

Posted in Uncategorized

More Scans for Ivanti Connect “Secure” VPN. Exploits Public, (Thu, Jan 18th)

Exploits around the Ivanti Connect “Secure” VPN appliance, taking advantage of CVE-2023-46805, continue evolving. Late on Tuesday, more details became public, particularly the blog post by Rapid7 explaining the underlying vulnerability in depth [1]. Rapid7 also does a good job walking you through how Ivanti obfuscates the LUKS key in its appliance. This will make it easier for security researchers to inspect the code, hopefully pointing out additional vulnerabilities to Ivanti in the future. In other words, get ready for more Ivanti exploits, and hopefully patches, this year.

Continue reading More Scans for Ivanti Connect “Secure” VPN. Exploits Public, (Thu, Jan 18th)

Posted in Uncategorized