unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
ABRTraryRoot: Local privilege escalation in Red Hat distributions
A chain of five bugs in ABRT allows any unprivileged local user to write attacker-controlled co...
2026-8-10 00:0:0 | 阅读: 4 |
收藏
|
Telekom Security - github.security.telekom.com
abrt
2026
crash
fedora
journal
From Infected Zyxel to Exposed C2: A Case Study in IoT Botnet Operations
This report documents the identification of previously concealed operational infrastructure, in...
2026-7-29 00:0:0 | 阅读: 2 |
收藏
|
Telekom Security - github.security.telekom.com
zyxel
staging
proxy
c2
xserver
SetRootLanguage: Local privilege escalation in Ubuntu via AccountsService
A two-bug chain in Ubuntu’s AccountsService language...
2026-7-21 00:0:0 | 阅读: 4 |
收藏
|
Telekom Security - github.security.telekom.com
2026
security
canonical
From Dropbox to Violet RAT v5: A Multi-Stage WebDAV Delivery Chain
Threat activity clusters rarely remain static over time. Deliver...
2026-7-7 00:0:0 | 阅读: 18 |
收藏
|
Telekom Security - github.security.telekom.com
python
windows
webdav
violet
loader
ZipLine-linked spearphishing campaign uses PowerShell backdoor and Cloudflare Tunnel
Telekom Security investigated a spearphishing campaign targeting organizations in several Europe...
2026-6-11 00:0:0 | 阅读: 4 |
收藏
|
Telekom Security - github.security.telekom.com
tunnel
powershell
c2
herokuapp
victim
Pack2TheRoot (CVE-2026-41651): Cross-Distro Local Privilege Escalation Vulnerability
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。用户的要求是直接写描述,不需要特定的开头。首先,我得仔细阅读文章,抓住关键点。 文章主要讲的是一个叫Pack2TheRoot的高危漏洞,CVSS评分3.8.8,影响多个Linux发行版。漏洞存在于PackageKit守护进程中,允许无特权用户获取root权限。发现者是德国电信的红队,在2026年4月22日公开披露,并提供了修复版本和检测方法。 接下来,我需要把这些信息浓缩到100字以内。要确保包括漏洞名称、影响范围、攻击方式、发现者、修复版本和检测方法。同时,语言要简洁明了。 可能会遇到的问题是如何在有限的字数内涵盖所有重要信息而不遗漏关键点。比如,是否需要提到受影响的具体发行版?可能不需要,因为用户只要求总结,不需要详细列表。 最后,组织语言时要确保流畅自然,避免重复或冗余的信息。 </think> 这篇文章披露了一个高危漏洞Pack2TheRoot(CVE-2026-41651),影响多个Linux发行版,默认安装下易受攻击。该漏洞允许无特权用户通过PackageKit守护进程获取root权限或安装/删除系统包。已发布修复版本1.3.5,并提供检测方法以检查系统是否受漏洞影响。...
2026-4-22 00:0:0 | 阅读: 17 |
收藏
|
Telekom Security - github.security.telekom.com
packagekit
2026
fedora
maintainers
Mass exploitation of CVE-2026-1281 and CVE-2026-1340 in Ivanti EPMM
嗯,用户让我总结一篇文章的内容,控制在100字以内,而且不需要特定的开头。首先,我需要通读整篇文章,抓住主要信息。 文章讲的是2026年初Ivanti的移动设备管理平台出现了两个零日漏洞,CVE-2026-1281和CVE-2026-1340,评分很高,都是9.8分。这些漏洞允许攻击者远程执行代码,影响了多个行业。Ivanti在1月29日披露了这些漏洞,并提供了紧急修复建议。 接下来,德国BSI也发出了警告,指出这些漏洞被广泛利用,并建议用户进行评估和响应。作者的团队最近处理了多个涉及这些漏洞的事件,发现攻击者已经建立了持久性并展开了后续行动。 文章还详细描述了漏洞的工作原理、观察到的攻击行为、其他研究机构的报告以及推荐的安全措施。最后列出了相关的IOCs。 现在我需要把这些信息浓缩到100字以内。重点包括漏洞名称、评分、影响范围、披露时间、攻击者行为以及修复建议。 可能的结构:两个零日漏洞在Ivanti平台被发现,评分高,允许远程代码执行。披露后被广泛利用,攻击者建立持久性和后续活动。修复建议和IOCs提供。 这样应该能涵盖主要内容。 </think> 2026年初,Ivanti移动设备管理平台曝出两个零日漏洞(CVE-2026-1281和CVE-2026-1340),评分均为9.8分。这些漏洞允许未认证远程代码执行,已遭广泛利用。攻击者通过这些漏洞建立持久性并展开后续行动。Ivanti于1月29日发布紧急修复建议,德国BSI亦发出警告。...
2026-3-3 00:0:0 | 阅读: 3 |
收藏
|
Telekom Security - github.security.telekom.com
mi
mifs
2026
403
ivanti
Security Content for REDAXO
A reflected Cross-Site Scripting vulnerability (CVE-2025-66026) has been identified in the REDAX...
2025-11-25 00:0:0 | 阅读: 9 |
收藏
|
Telekom Security - github.security.telekom.com
redaxo
github
66026
mediapool
holger
Multiple vulnerabilities in Janitza UMG 96RM-E
好的,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,找出关键信息。 文章主要讲的是Janitza UMG 96RM-E设备发现了四个漏洞,影响版本是低于3.14的固件。漏洞类型包括命令注入、硬编码凭据、加密算法问题和权限分配错误。风险等级是关键,已经修复了,建议升级到3.14版本,并且在网络防护方面给出了一些建议。 接下来,我需要将这些信息浓缩到100字以内。要确保涵盖设备型号、漏洞数量、风险等级、修复情况以及防护建议。同时,语言要简洁明了,避免使用复杂的术语。 可能的结构是:设备型号+发现漏洞数量+漏洞类型+风险等级+修复建议+防护措施。这样既全面又简洁。 最后,检查字数是否在限制内,并确保没有遗漏重要信息。 </think> Janitza UMG 96RM-E设备被发现存在四个安全漏洞(CVE-2025-41709至CVE-2025-41712),包括命令注入、硬编码凭据、加密算法问题及权限分配错误。这些漏洞允许远程攻击者完全控制设备或获取敏感信息。建议更新至固件3.14版本,并采取网络防护措施以减少风险。...
2025-11-4 00:0:0 | 阅读: 7 |
收藏
|
Telekom Security - github.security.telekom.com
remote
attacker
firmware
96rm
Multiple vulnerabilities in Kanboard (Exploiting web applications Part II)
本文介绍了Kanboard软件中的三个安全漏洞:任意文件读取(CVE-2024-51747)、远程代码执行(CVE-2024-51748)和会话固定问题(CVE-2024-55603)。通过分析源代码和渗透测试发现这些漏洞,并已修复。...
2025-6-3 00:0:0 | 阅读: 11 |
收藏
|
Telekom Security - github.security.telekom.com
php
download
kanboard
database
Rasa (un)authenticated Remote Code Execution via remote model loading (CVE-2024-49375)
Rasa 和 Rasa-pro 的旧版本存在未经认证的远程代码执行漏洞,默认配置不受影响,启用 HTTP API 时受影响;修复版本已发布;CVSS 评分 9.1 分;exploits 可用。...
2025-4-1 00:0:0 | 阅读: 10 |
收藏
|
Telekom Security - github.security.telekom.com
rasa
github
security
scheid
Multiple critical vulnerabilities in SICK DL100-2xxxxxxx Products
SICK DL100设备发现三个关键漏洞:代码下载无完整性检查、敏感信息明文传输及弱哈希算法使用。这些漏洞可能导致恶意代码执行、密码窃取及设备安全风险。厂商已确认并提供修复建议。...
2025-3-14 00:0:0 | 阅读: 54 |
收藏
|
Telekom Security - github.security.telekom.com
sick
security
dl100
27595
27593
During red teaming engagements, the first step is to gain a foothold in the client’s network. Th...
2025-1-14 10:46:22 | 阅读: 21 |
收藏
|
Telekom Security - github.security.telekom.com
php
lam
remote
Remote code execution in LDAP Account manager through CVE-2024-23333 (Exploiting web applications Part I)
During red teaming engagements, the first step is to gain a foothold in the client’s network. Th...
2025-1-14 00:0:0 | 阅读: 25 |
收藏
|
Telekom Security - github.security.telekom.com
php
lam
Remote buffer overflow vulnerability in SharkSSL TLS handshake processing
A new remote buffer overflow vulnerability was discovered in the latest version of the SharkSSL...
2024-12-19 00:0:0 | 阅读: 9 |
收藏
|
Telekom Security - github.security.telekom.com
sharkssl
remote
telekom
security
attacker
Tuta Mail Vulnerability - Client Information Leak
An client information leak vulnerability (CVE-2024-23330) has been identified in Tuta Mail. This...
2024-11-29 08:0:0 | 阅读: 10 |
收藏
|
Telekom Security - github.security.telekom.com
tuta
23330
client
tutanota
embeded
Tuta Mail Vulnerability - DoS
A denial of service vulnerability (CVE-2024-23655) has been identified in Tuta Mail. This vulner...
2024-11-29 08:0:0 | 阅读: 8 |
收藏
|
Telekom Security - github.security.telekom.com
tuta
23655
attacker
mails
manipulated
Security Content for iOS, iPadOS, and macOS
A heap corruption vulnerability (CVE-2024-44126) has been identified in several Apple products t...
2024-11-27 08:0:0 | 阅读: 15 |
收藏
|
Telekom Security - github.security.telekom.com
44126
software
787
holger
corruption
Remote buffer overflow vulnerability in SharkSSL TLS Client Key Exchange handshake processing
A new remote buffer overflow vulnerability (CVE-2024-48075) was discovered in the latest version...
2024-11-4 08:0:0 | 阅读: 15 |
收藏
|
Telekom Security - github.security.telekom.com
deutsche
telekom
sharkssl
security
remote
Collabora Office for Android - JavaScript Injection via Links
A JavaScript Injection vulnerability (CVE-2024-45045) has been identified in Collabora Office fo...
2024-9-6 08:0:0 | 阅读: 14 |
收藏
|
Telekom Security - github.security.telekom.com
collabora
activated
victim
45045
Previous
-3
-2
-1
0
1
2
3
4
Next