Aggregator
羊城杯Re方向题解
[白利用]VSCode还能这样用?
伪装成京东金融候选人登记表的钓鱼样本详细分析
从Kimsuky组织msc攻击样本到GrimResource
libFuzzer模糊测试引擎调研与自定义魔改
Nacos配置文件攻防思路总结
CVE-2024-21733 tomcat请求走私分析
CTFshow——2024西瓜杯复现及总结
python安全问题
Bypass403(小白食用)
Spring Cloud Data Flow 热点漏洞详细分析
浅析Large_bins_attack在高低版本的利用
泛微E9路径browser.jsp存在权限绕过导致SQL注入漏洞
Patchwork(白象)APT组织PGoshell后门攻击场景复现
CVE-2024-22399 Apache Seata Hessian反序列化漏洞
DASCTF2024八月挑战赛Pwn方向复现
针对spring二次开发的BladeX站点的渗透测试
Ivanti Releases Admin Bypass Security Update for Cloud Services Appliance
Ivanti has released a security update to address an admin bypass vulnerability (CVE-2024-8963) affecting Ivanti Cloud Services Appliance (CSA) version 4.6. A cyber threat actor could exploit this vulnerability in conjunction with CVE-2024-8190–detailed in a Sept. 13 Ivanti security advisory–to take control of an affected system. This vulnerability impacts all versions prior to patch 519.
Ivanti has confirmed limited exploitation and recommends that users upgrade to CSA version 5.0, as version 4.6 is end-of-life and no longer supported. CISA urges users and administrators review the Ivanti security advisory and apply the necessary updates.
Note: CISA has added CVE-2024-8963 to its Known Exploited Vulnerabilities Catalog, which, per Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the specified due date to protect FCEB networks against active threats.
CISA Releases Six Industrial Control Systems Advisories
CISA released six Industrial Control Systems (ICS) advisories on September 19, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-24-263-01 Rockwell Automation RSLogix 5 and RSLogix 500
- ICSA-24-263-02 IDEC PLCs
- ICSA-24-263-03 IDEC CORPORATION WindLDR and WindO/I-NV4
- ICSA-24-263-04 MegaSys Computer Technologies Telenium Online Web Application
- ICSA-24-263-05 Kastle Systems Access Control System
- ICSA-20-168-01 Treck TCP/IP (Update I)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.