screaminggoat , to random
@screaminggoat@infosec.exchange avatar

just in time to celebrate infosec.exchange returning, Cisco zero day: Cisco NX-OS Software CLI Command Injection Vulnerability
CVE-2024-20399 (6.0 medium) A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.

In April 2024, the Cisco Product Security Incident Response Team (PSIRT) became aware of attempted exploitation of this vulnerability in the wild.

EDIT: Sygnia links attempted zero-day exploitation to Chinese state-sponsored threat actor it tracks as Velvet Ant (no article yet). See related Bleeping Computer reporting; Cisco warns of NX-OS zero-day exploited to deploy custom malware

cc: @campuscodi @briankrebs @cR0w @mttaggart

screaminggoat OP ,
@screaminggoat@infosec.exchange avatar
Nonilex , to random
@Nonilex@masto.ai avatar

’s Guide to Subverting

A 2nd admin could existing government agencies to dismantle democracy itself.

This article is part of “Project 2025: The Plot Against ,” a Nation special issue devoted to unpacking the right’s vast & chilling program for a 2nd Trump term.


https://www.thenation.com/article/society/project-2025-democracy-fcc-fec/

Nonilex OP ,
@Nonilex@masto.ai avatar

In the section on the …there’s a plan to eliminate the ability of the agency that monitors to prevent the spread of about voting & counting.
…Think back to Nov 2020, when was developing his about the he’d lost. Trump’s false assertion the election had been characterized by “massive improprieties & fraud” was tripped up by , who served as dir of the & Infrastructure Agency () in the DHS.

Nonilex OP ,
@Nonilex@masto.ai avatar

In Mandate’s chapter on the #DHS, Ken Cuccinelli writes, “Of the utmost urgency is immediately ending CISA’s counter-mis / #disinformation efforts. … #Project2025 document declares that “the entirety of the #CISA #Cybersecurity Advisory Committee should be dismissed on Day One.”

…This is just one way that Project 2025’s cabal of “experts” is scheming to thwart honest discourse about #elections & #democracy.

#law #justice #UnitedStates #Constitution #politics #USpol #VoteBlue #BidenHarris2024

AAKL , to random
@AAKL@infosec.exchange avatar
simontsui , to random
@simontsui@infosec.exchange avatar

CERT-EU warns of an exploited zero-day for Palo Alto Networks: CVE-2024-3400 (10.0 critical, disclosed 12 April 2024) command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software. Affected versions are PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1. This zero-day is NOT patched yet, and hotfix releases will be made available starting 14 April 2024. 🔗 https://cert.europa.eu/publications/security-advisories/2024-037/ and original Palo Alto Networks security advisory: https://security.paloaltonetworks.com/CVE-2024-3400

simontsui OP ,
@simontsui@infosec.exchange avatar

CISA put out an additional security alert about CVE-2024-3400, noting that Palo Alto Networks released workaround guidance for the command injection vulnerability. 🔗 https://www.cisa.gov/news-events/alerts/2024/04/12/palo-alto-networks-releases-guidance-vulnerability-pan-os-cve-2024-3400

GottaLaff , to random
@GottaLaff@mastodon.social avatar

You wouldn't believe the stuff I'm NOT posting here.

Via Spiro’s Ghost:

WHAT THE FUCK?! He got destroyed there. He is INSANE.

Trump: We have to run the whole East Coast like I did twice. I did twice. I did better the second time, But we have to run the East Coast.

Beachbum ,
@Beachbum@mastodon.sdf.org avatar

@GottaLaff @JaneDoeTheFirst 1) I really don’t like to hear people talk at all about rigging or stealing the elections. That constant mantra that tfg, bannon, stone, started with ‘stop the steal’ in ‘16 & ‘20 played a big part in the insurrection because people listen to pundits and not the 65 cases that were brought by attorneys and denied by judges, indicating that the election was free, fair legitimate. They didn’t listen to Chris Krebs with

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines