screaminggoat , to random
@screaminggoat@infosec.exchange avatar

just in time to celebrate infosec.exchange returning, Cisco zero day: Cisco NX-OS Software CLI Command Injection Vulnerability
CVE-2024-20399 (6.0 medium) A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.

In April 2024, the Cisco Product Security Incident Response Team (PSIRT) became aware of attempted exploitation of this vulnerability in the wild.

EDIT: Sygnia links attempted zero-day exploitation to Chinese state-sponsored threat actor it tracks as Velvet Ant (no article yet). See related Bleeping Computer reporting; Cisco warns of NX-OS zero-day exploited to deploy custom malware

cc: @campuscodi @briankrebs @cR0w @mttaggart

Nonilex , to random
@Nonilex@masto.ai avatar

The top U.S. #intelligence ofcl on Mon warned that the #war in #Gaza could embolden #terrorist groups, which are aligned in their opposition to the #UnitedStates for its support of #Israel.
“The crisis has galvanized #violence by a range of actors around the world. And while it is too early to tell, it is likely that the Gaza conflict will have a generational impact on #terrorism,” #ODNI #AvrilHaines, told an annual hearing on #GlobalSecurity #threats.

https://www.washingtonpost.com/national-security/2024/03/11/cia-israel-gaza-ukraine-ai/

Nonilex OP ,
@Nonilex@masto.ai avatar

The witnesses, who included the dirs of the #FBI, the #NSA, the #DIA, & the State Dept’s #INR, spoke about a panoply of challenges, from an ambitious #China to the proliferation of #ArtificialIntelligence & the continuing #threat of #cyberespionage & #CyberWarfare. Brett Holmgren, the State Dept’s top #intelligence ofcl, said that the power of #AI could “lower the barrier” for #UnitedStates adversaries to engage in #ElectionInterference.
#NationalSecurity #ForeignPolicy #terrorism #geopolitics

jos1264 , to random
@jos1264@social.skynetcloud.site avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines