Show more

"In jQuery before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0."

cve.circl.lu/cve/CVE-2020-1102 …

Kaspersky researchers analysed PhantomLance, Android malware linked to the OceanLotus APT group that was found on Google Play
securelist.com/apt-phantomlanc …pic.twitter.com/39l28GCijl

The registration for the AIL project virtual session is full. We were surprised by the number of registrations for our first virtual training about AIL. The session will be recorded and we will do more session after. Thank you very much!

twitter.com/circl_lu/status/12 …pic.twitter.com/fvXFx3nnGR

The folks at @circl_lu do great work, so if you work in leak collection/processing you should definitely look at their AIL framework and catch their sessions if you can
twitter.com/circl_lu/status/12 …

"BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence."

cve.circl.lu/cve/CVE-2020-1244 …

"Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter."

cve.circl.lu/cve/CVE-2020-1224 …

Disinfo crowd should check out this 2 hour training on the AIL project. They just released a Twitter feeder (and adding new scrapers is pretty simple). @bodaceacat @Ngree_H0bit @carljackmiller
twitter.com/circl_lu/status/12 …

Adequate awareness of & response to aimed at member states or is key nowadays

This project is enhancing by improving @intelmq & @CERT_at ’s incident handling capabilities & internal security


bit.ly/2Yf8IjG 
twitter.com/CERT_at/status/125 …pic.twitter.com/n0kV3HEyMN

We @circl_lu and @secin_lu just saw a Malspam impersonating @uni_lu . The sample was not detected by any AV software, at the time of delivery. Email subject: 'Ufro fir Zitat (Uni Lëtzebuerg) EUI894/BU4600'

The crisis has undoubtly changed the world we are living in.

However, we want to look at the bright (light) side and focus on the lessons learned by speakers of the public and private sectors.

For more info & registration:
securitymadein.lu/events/may-t …pic.twitter.com/vsQClHu59p

Call for testers! We have pre released our new project called DRAKVUF Sandbox, which is a hypervisor-level malware analysis system which incorporates by @tklengyel.

We invite to test it and any feedback on GitHub would be appreciated!
github.com/CERT-Polska/drakvuf …

"Darkweb monitoring and leak detection with the open source AIL project - Practical examples and new features - Free Virtual session" 05 May 2020 15:00-17:00 Registration:
xing-events.com/FGGBEWA.html  Join us!pic.twitter.com/823wmYFzFv

AIL integration with @MISPProject improved in the past months. If you never look at the open source AIL project, it's time to have a look at their webinar next week.
twitter.com/circl_lu/status/12 …

"ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field"

cve.circl.lu/cve/CVE-2019-1822 …

Kudos to Sophos for publishing its own analysis of the attack that exploited zero-day vulnerabilities in its firewall products. Not only (and mostly importantly) is this the grown-up thing to do, it also helps them control the conversation
news.sophos.com/en-us/2020/04/ …

"The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php."

cve.circl.lu/cve/CVE-2020-1207 …

"A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2."

cve.circl.lu/cve/CVE-2020-7134 …

Show more
OpenCloud Luxembourg Mastodon instance

A Mastodon instance for Luxembourg and beyond.