Apple Patches Three New 0-Day Vulnerabilities Affecting iOS/iPadOS/watchOS/macOS, (Thu, Sep 21st)

This update patches three already exploited vulnerabilities:
(1) CVE-2023-41993 Remote code execution in WebKit. This could be used as an initial access vector
(2) CVE-2023-41992 Privilege Escalation. A follow-up after the initial access was achieved via the first vulnerability
(3) CVE-2023-41991 Certificate Validation Issue. A malicious app installed via 1 and 2 may be more difficult to detect due to this vulnerability

Continue reading Apple Patches Three New 0-Day Vulnerabilities Affecting iOS/iPadOS/watchOS/macOS, (Thu, Sep 21st)→

Posted in Uncategorized

What’s Normal? DNS TTL Values, (Wed, Sep 20th)

I am trying to start a series of brief diaries about “what&#;x26;#;39;s normal.” Analysts often only look at the network when they suspect something is wrong. But to find the anomaly, someone must first know what&#;x26;#;39;s normal. So, I am trying to collect data from my home network to show what to consider. The values I am presenting here are normal for my home network and will likely differ for your network. So, instead of just copying/pasting, run the experiment yourself 🙂

Continue reading What’s Normal? DNS TTL Values, (Wed, Sep 20th)→

Posted in Uncategorized

Obfuscated Scans for Older Adobe Experience Manager Vulnerabilities, (Tue, Sep 19th)

Adobe Experience Manager (AEM) is a complex enterprise-level content management system built around open-source products like Apache Sling, Jackrabbit/Oak, and Felix. Just last week, Adobe patched another XSS vulnerability in AEM. But the scans we see now target older vulnerabilities, likely a vulnerability 2-3 years old.

Continue reading Obfuscated Scans for Older Adobe Experience Manager Vulnerabilities, (Tue, Sep 19th)→

Posted in Uncategorized