<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vulnerabilities Archives &#8902; CyberHood Sentinel</title>
	<atom:link href="https://hoodguy.net/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>https://hoodguy.net/tag/vulnerabilities/</link>
	<description>Guarding the Digital Frontier</description>
	<lastBuildDate>Fri, 13 Jun 2025 18:26:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://hoodguy.net/wp-content/uploads/2024/05/cropped-DALL·E-2024-05-31-00.53.01-A-single-logo-for-Hoodguy-website-featuring-an-image-of-a-hacker-with-a-hoodie-and-the-tagline-We-Write.-The-logo-should-be-serious-in-style-highl-32x32.webp</url>
	<title>vulnerabilities Archives &#8902; CyberHood Sentinel</title>
	<link>https://hoodguy.net/tag/vulnerabilities/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Apple’s Invisible Threat: Zero-Click Spyware Attack on Journalists via iMessage</title>
		<link>https://hoodguy.net/apples-invisible-threat-zero-click-spyware-attack-on-journalists-via-imessage/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=apples-invisible-threat-zero-click-spyware-attack-on-journalists-via-imessage</link>
					<comments>https://hoodguy.net/apples-invisible-threat-zero-click-spyware-attack-on-journalists-via-imessage/#respond</comments>
		
		<dc:creator><![CDATA[TeamHood]]></dc:creator>
		<pubDate>Fri, 13 Jun 2025 18:26:32 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://hoodguy.net/?p=1315</guid>

					<description><![CDATA[<p>Apple recently disclosed a severe cybersecurity lapse: a “zero-click” zero-day flaw in its Messages app, exploited to deploy spyware—termed Graphite—on iPhones belonging to high-profile journalists and civil society members What’s the Flaw? Tracked as CVE-2025-43200, the vulnerability stemmed from a logic error in how Apple’s Messages app processed maliciously crafted media—specifically photos or videos shared [&#8230;]</p>
<p>The post <a href="https://hoodguy.net/apples-invisible-threat-zero-click-spyware-attack-on-journalists-via-imessage/">Apple’s Invisible Threat: Zero-Click Spyware Attack on Journalists via iMessage</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Apple recently disclosed a severe cybersecurity lapse: a “zero-click” zero-day flaw in its Messages app, exploited to deploy spyware—termed <em>Graphite</em>—on iPhones belonging to high-profile journalists and civil society members </p>



<h4 class="wp-block-heading">What’s the Flaw?</h4>



<p class="wp-block-paragraph">Tracked as <strong>CVE-2025-43200</strong>, the vulnerability stemmed from a logic error in how Apple’s Messages app processed maliciously crafted media—specifically photos or videos shared via iCloud Links. This allowed attackers to execute code silently and without requiring any user interaction</p>



<p class="wp-block-paragraph">Apple addressed the issue on <strong>February 10, 2025</strong>, rolling out patches across iOS 18.3.1, iPadOS 18.3.1 and 17.7.5, macOS Sequoia 15.3.1, Sonoma 14.7.4, Ventura 13.7.4, watchOS 11.3.1, and visionOS 2.3.1  These updates also remedied a second unnamed, actively exploited vulnerability (CVE‑2025‑24200), though Apple has not yet disclosed details about that flaw</p>



<h4 class="wp-block-heading">Who Was Targeted?</h4>



<p class="wp-block-paragraph">Apple acknowledged that CVE‑2025‑43200 was used in a precise, sophisticated campaign targeting Italian journalist <strong>Ciro Pellegrino</strong> and an unnamed high-profile European journalist Forensic analysis by <strong>Citizen Lab</strong> confirmed that both were infected with Paragon’s Graphite spyware—an advanced tool designed for silent surveillance, capturing messages, emails, microphone and camera data, and location, all without user interaction </p>



<p class="wp-block-paragraph">One infection occurred in <strong>January–early February 2025</strong> on a device running iOS 18.2.1. It was stealthy enough that neither journalist likely noticed anything amiss . Apple informed the individuals of the targeting on <strong>April 29, 2025</strong>, through its threat notification system aimed at flagging suspected state-sponsored attacks.</p>



<h4 class="wp-block-heading">What Is Graphite and Who’s Behind It?</h4>



<p class="wp-block-paragraph">Developed by Israel-based offensive cyber contractor <strong>Paragon</strong>, Graphite is marketed to state-level clients as a mercenary spyware platform . It can stealthily infiltrate Apple devices via zero-click vectors—such as corrupted media files—granting near-total access to device capabilities. It&#8217;s typically sold under national-security pretenses.</p>



<p class="wp-block-paragraph">Evidence suggests both journalists were targeted from the same Apple account, codenamed <strong>“ATTACKER1”</strong>, indicating a single Paragon customer orchestrated the attack </p>



<h4 class="wp-block-heading">Broader Graphite Backstory</h4>



<p class="wp-block-paragraph">Graphite has previously gained infamy. Notably, Meta-owned WhatsApp reported that Graphite was deployed against dozens of users globally, including Pellegrino’s colleague, journalist <strong>Francesco Cancellato</strong>, bringing the public count of known victims to at least <strong>seven</strong> </p>



<p class="wp-block-paragraph">Earlier this week, Paragon announced it had ended contracts with the Italian government. The company cited Italy’s refusal to allow independent verification that the spyware wasn&#8217;t used against investigative journalists </p>



<p class="wp-block-paragraph">Meanwhile, Italy’s <strong>Copasir</strong> (Parliamentary Committee for Republic Security) confirmed that Italian intelligence agencies used Graphite—but not on journalists—claiming it was deployed for law enforcement tasks including fugitive tracking, counter-terrorism, organized crime, smuggling, and counter-espionage .</p>



<p class="wp-block-paragraph">Graphite’s infrastructure requires operator login credentials; every deployment generates logs. These logs reside on customer-controlled servers, not Paragon’s, introducing minimal external oversight </p>



<h4 class="wp-block-heading">Risk and Global Implications</h4>



<p class="wp-block-paragraph">The Citizen Lab emphasized that journalists across Europe remain vulnerable to invasive digital surveillance, spotlighting how unchecked spyware proliferates and threatens privacy. The EU has already criticized such spyware use, calling for stringent export controls and stronger legal safeguards. These incidents are likely to intensify policy focus in Brussels and national capitals.</p>



<p class="wp-block-paragraph">Apple’s threat notification system relies on threat intelligence; receiving an alert does not necessarily confirm infection—but signals suspicious activity.</p>



<h4 class="wp-block-heading">Spyware Landscape: A Wider Context</h4>



<p class="wp-block-paragraph">While Graphite looms large, other spyware like <strong>Predator</strong> has also resurfaced. Recorded Future’s Insikt Group reports renewed Predator operations, including expansion into <strong>Mozambique</strong> and identification of new servers—highlighting persistent global spyware threats .</p>



<h4 class="wp-block-heading">What You Can Do</h4>



<ul class="wp-block-list">
<li><strong>Update your devices</strong>: Ensure your Apple products are updated to the latest iOS, macOS, watchOS, or visionOS versions.</li>



<li><strong>Stay alert</strong>: If you receive a threat notification from Apple, treat it seriously—even if your device seems normal.</li>



<li><strong>Advocate for change</strong>: Encourage stronger legal frameworks to regulate commercial spyware and promote transparency in its deployment.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph">As zero-click spyware becomes more sophisticated, this case highlights the need for vigilance, transparency, and accountability. Users and policymakers must recognize that threats once limited to espionage circles can now penetrate the heart of civil society.</p>
<p>The post <a href="https://hoodguy.net/apples-invisible-threat-zero-click-spyware-attack-on-journalists-via-imessage/">Apple’s Invisible Threat: Zero-Click Spyware Attack on Journalists via iMessage</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://hoodguy.net/apples-invisible-threat-zero-click-spyware-attack-on-journalists-via-imessage/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Google Releases Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability</title>
		<link>https://hoodguy.net/google-releases-urgent-chrome-update-to-patch-actively-exploited-zero-day-vulnerability/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-releases-urgent-chrome-update-to-patch-actively-exploited-zero-day-vulnerability</link>
					<comments>https://hoodguy.net/google-releases-urgent-chrome-update-to-patch-actively-exploited-zero-day-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[TeamHood]]></dc:creator>
		<pubDate>Wed, 26 Mar 2025 18:02:44 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Zero day vulnerability]]></category>
		<guid isPermaLink="false">https://hoodguy.net/?p=1194</guid>

					<description><![CDATA[<p>Google has issued an emergency security update for its Chrome browser on Windows to address a high-severity zero-day vulnerability, identified as CVE-2025-2783, which has been actively exploited in targeted attacks against organizations in Russia. Details of the Vulnerability CVE-2025-2783 is described as an &#8220;incorrect handle provided in unspecified circumstances in Mojo on Windows.&#8221; Mojo is [&#8230;]</p>
<p>The post <a href="https://hoodguy.net/google-releases-urgent-chrome-update-to-patch-actively-exploited-zero-day-vulnerability/">Google Releases Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Google has issued an emergency security update for its Chrome browser on Windows to address a high-severity zero-day vulnerability, identified as CVE-2025-2783, which has been actively exploited in targeted attacks against organizations in Russia.</p>



<p class="wp-block-paragraph"><strong>Details of the Vulnerability</strong></p>



<p class="wp-block-paragraph">CVE-2025-2783 is described as an &#8220;incorrect handle provided in unspecified circumstances in Mojo on Windows.&#8221; Mojo is a set of runtime libraries facilitating platform-agnostic inter-process communication (IPC). The flaw allows attackers to bypass Chrome&#8217;s sandbox protections, enabling unauthorized access to the system. </p>



<p class="wp-block-paragraph"><strong>Discovery and Exploitation</strong></p>



<p class="wp-block-paragraph">Researchers Boris Larin and Igor Kuznetsov from Kaspersky discovered and reported the vulnerability on March 20, 2025. The attacks, dubbed &#8220;Operation ForumTroll,&#8221; involved sophisticated phishing emails containing malicious links. Upon clicking these links, the victims&#8217; systems were infected without any further action required. The phishing emails masqueraded as invitations from the organizers of the legitimate scientific forum, Primakov Readings, and targeted media outlets, educational institutions, and government organizations in Russia. </p>



<p class="wp-block-paragraph"><strong>Google&#8217;s Response</strong></p>



<p class="wp-block-paragraph">In response to the active exploitation, Google released out-of-band fixes in Chrome version 134.0.6998.177/.178 for Windows. The company acknowledged the reports of the exploit in the wild but has not disclosed additional technical specifics about the attacks or the threat actors involved. </p>



<p class="wp-block-paragraph"><strong>Recommendations for Users</strong></p>



<p class="wp-block-paragraph">Users of Chrome on Windows are strongly advised to update their browsers to the latest version immediately to mitigate potential threats. Additionally, users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi should apply the available fixes promptly. It is also recommended to exercise caution with unsolicited emails and avoid clicking on unknown links to prevent potential infections.</p>



<p class="wp-block-paragraph">This incident underscores the critical importance of timely software updates and vigilance against phishing attempts to maintain cybersecurity.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://hoodguy.net/google-releases-urgent-chrome-update-to-patch-actively-exploited-zero-day-vulnerability/">Google Releases Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://hoodguy.net/google-releases-urgent-chrome-update-to-patch-actively-exploited-zero-day-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GitHub Uncovers Critical Ruby-SAML Vulnerabilities: Urgent Patch Required</title>
		<link>https://hoodguy.net/github-uncovers-critical-ruby-saml-vulnerabilities-urgent-patch-required/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=github-uncovers-critical-ruby-saml-vulnerabilities-urgent-patch-required</link>
					<comments>https://hoodguy.net/github-uncovers-critical-ruby-saml-vulnerabilities-urgent-patch-required/#respond</comments>
		
		<dc:creator><![CDATA[TeamHood]]></dc:creator>
		<pubDate>Thu, 13 Mar 2025 18:41:16 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Github]]></category>
		<category><![CDATA[Ruby-SAML]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://hoodguy.net/?p=1180</guid>

					<description><![CDATA[<p>GitHub&#8217;s Security Lab has identified two severe vulnerabilities in the open-source ruby-saml library, which could enable attackers to bypass Security Assertion Markup Language (SAML) authentication mechanisms. These vulnerabilities pose a significant security risk, potentially leading to account takeovers and unauthorized access. Understanding the Ruby-SAML Vulnerabilities The identified vulnerabilities, tracked as CVE-2025-25291 and CVE-2025-25292, have been [&#8230;]</p>
<p>The post <a href="https://hoodguy.net/github-uncovers-critical-ruby-saml-vulnerabilities-urgent-patch-required/">GitHub Uncovers Critical Ruby-SAML Vulnerabilities: Urgent Patch Required</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">GitHub&#8217;s Security Lab has identified two severe vulnerabilities in the open-source <code>ruby-saml</code> library, which could enable attackers to bypass Security Assertion Markup Language (SAML) authentication mechanisms. These vulnerabilities pose a significant security risk, potentially leading to account takeovers and unauthorized access.</p>



<h3 class="wp-block-heading"><strong>Understanding the Ruby-SAML Vulnerabilities</strong></h3>



<p class="wp-block-paragraph">The identified vulnerabilities, tracked as <strong>CVE-2025-25291</strong> and <strong>CVE-2025-25292</strong>, have been assigned a <strong>CVSS score of 8.8</strong>, indicating a high severity level. These flaws impact:</p>



<ul class="wp-block-list">
<li><strong>Ruby-SAML versions below 1.12.4</strong></li>



<li><strong>Ruby-SAML versions 1.13.0 to 1.18.0 (excluding 1.18.0)</strong></li>
</ul>



<p class="wp-block-paragraph">These security issues arise due to inconsistencies in how the <strong>REXML</strong> and <strong>Nokogiri</strong> libraries parse XML data, leading to potential authentication bypass scenarios. By exploiting these discrepancies, attackers can manipulate SAML responses, potentially logging in as any user within an organization.</p>



<h3 class="wp-block-heading"><strong>How Attackers Can Exploit These Flaws</strong></h3>



<p class="wp-block-paragraph">If an attacker obtains a valid signature created with the key used to validate SAML responses, they can craft malicious SAML assertions. This could allow them to:</p>



<ul class="wp-block-list">
<li><strong>Bypass authentication protocols</strong></li>



<li><strong>Gain unauthorized access to user accounts</strong></li>



<li><strong>Compromise sensitive organizational data</strong></li>
</ul>



<h3 class="wp-block-heading"><strong>Additional Security Risks: Denial-of-Service (DoS) Attack</strong></h3>



<p class="wp-block-paragraph">Alongside authentication bypass risks, a related vulnerability <strong>(CVE-2025-25293)</strong> with a <strong>CVSS score of 7.7</strong> was also discovered. This flaw enables attackers to launch <strong>remote denial-of-service (DoS) attacks</strong> by sending specially crafted compressed SAML responses, overwhelming the system and causing service disruptions.</p>



<h3 class="wp-block-heading"><strong>How to Protect Your Organization</strong></h3>



<p class="wp-block-paragraph">To mitigate these risks, <strong>immediate action is required</strong>. The maintainers of <code>ruby-saml</code> have released patched versions:</p>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Upgrade to Ruby-SAML 1.12.4 or 1.18.0</strong> to eliminate security vulnerabilities.</p>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Regularly monitor and update dependencies</strong> to prevent exploitation of outdated libraries.</p>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Implement additional security measures</strong> such as multi-factor authentication (MFA) to enhance protection against unauthorized access.</p>



<h3 class="wp-block-heading"><strong>Conclusion: Stay Secure by Updating Immediately</strong></h3>



<p class="wp-block-paragraph">The discovery of these <code>ruby-saml</code> vulnerabilities highlights the need for continuous security vigilance. Organizations using affected versions should <strong>urgently apply the patches</strong> to mitigate authentication bypass and DoS risks. Keeping software dependencies up to date is a critical step in safeguarding sensitive information from cyber threats.</p>



<p class="wp-block-paragraph">For more information and the latest updates, visit the official GitHub Security Blog.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://hoodguy.net/github-uncovers-critical-ruby-saml-vulnerabilities-urgent-patch-required/">GitHub Uncovers Critical Ruby-SAML Vulnerabilities: Urgent Patch Required</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://hoodguy.net/github-uncovers-critical-ruby-saml-vulnerabilities-urgent-patch-required/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Elastic Releases Urgent Patch for Critical Kibana Vulnerability Allowing Remote Code Execution</title>
		<link>https://hoodguy.net/elastic-releases-urgent-patch-for-critical-kibana-vulnerability-allowing-remote-code-execution/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=elastic-releases-urgent-patch-for-critical-kibana-vulnerability-allowing-remote-code-execution</link>
					<comments>https://hoodguy.net/elastic-releases-urgent-patch-for-critical-kibana-vulnerability-allowing-remote-code-execution/#respond</comments>
		
		<dc:creator><![CDATA[TeamHood]]></dc:creator>
		<pubDate>Thu, 06 Mar 2025 18:35:46 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hacking news]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://hoodguy.net/?p=1148</guid>

					<description><![CDATA[<p>Elastic has issued a critical security update to address a severe vulnerability in its Kibana data visualization dashboard, which could enable attackers to execute arbitrary code on affected systems. The flaw, identified as CVE-2025-25012, has been assigned a CVSS score of 9.9 out of 10, underscoring its severity. ​ Nature of the Vulnerability The vulnerability [&#8230;]</p>
<p>The post <a href="https://hoodguy.net/elastic-releases-urgent-patch-for-critical-kibana-vulnerability-allowing-remote-code-execution/">Elastic Releases Urgent Patch for Critical Kibana Vulnerability Allowing Remote Code Execution</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Elastic has issued a critical security update to address a severe vulnerability in its Kibana data visualization dashboard, which could enable attackers to execute arbitrary code on affected systems. The flaw, identified as CVE-2025-25012, has been assigned a CVSS score of 9.9 out of 10, underscoring its severity. ​</p>



<p class="wp-block-paragraph"><strong>Nature of the Vulnerability</strong></p>



<p class="wp-block-paragraph">The vulnerability arises from a prototype pollution issue within Kibana. Prototype pollution is a type of security flaw that allows attackers to manipulate an application&#8217;s JavaScript objects and properties. This manipulation can lead to unauthorized data access, privilege escalation, denial-of-service, or, as in this case, remote code execution. Specifically, the flaw can be exploited through a crafted file upload combined with specially crafted HTTP requests. ​</p>



<p class="wp-block-paragraph"><strong>Affected Versions</strong></p>



<p class="wp-block-paragraph">All Kibana versions from 8.15.0 up to, but not including, 8.17.3 are affected by this vulnerability. The exploitability varies depending on the version:​</p>



<ul class="wp-block-list">
<li><strong>Versions 8.15.0 to 8.17.0</strong>: Exploitable by users with the &#8216;Viewer&#8217; role.​</li>



<li><strong>Versions 8.17.1 and 8.17.2</strong>: Exploitable by users possessing all of the following privileges:​
<ul class="wp-block-list">
<li><code>fleet-all</code>​</li>



<li><code>integrations-all</code>​</li>



<li><code>actions:execute-advanced-connectors</code>​</li>
</ul>
</li>
</ul>



<p class="wp-block-paragraph"><strong>Recommended Actions</strong></p>



<p class="wp-block-paragraph">Users are strongly advised to upgrade to Kibana version 8.17.3 immediately to mitigate this vulnerability. For those who cannot apply the update promptly, a temporary workaround involves disabling the Integration Assistant feature by setting <code>xpack.integration_assistant.enabled: false</code> in the Kibana configuration file (<code>kibana.yml</code>).</p>



<p class="wp-block-paragraph"><strong>Previous Similar Vulnerabilities</strong></p>



<p class="wp-block-paragraph">This is not the first time Kibana has faced critical security issues. In August 2024, Elastic addressed another critical prototype pollution flaw (CVE-2024-37287) that could lead to code execution. Subsequently, in September 2024, two severe deserialization vulnerabilities (CVE-2024-37288 and CVE-2024-37285) were also patched, both of which could permit arbitrary code execution. ​</p>



<p class="wp-block-paragraph"><strong>Conclusion</strong></p>



<p class="wp-block-paragraph">Given the critical nature of CVE-2025-25012, it is imperative for organizations using affected versions of Kibana to apply the necessary updates or mitigations without delay to protect their systems from potential exploitation.​</p>
<p>The post <a href="https://hoodguy.net/elastic-releases-urgent-patch-for-critical-kibana-vulnerability-allowing-remote-code-execution/">Elastic Releases Urgent Patch for Critical Kibana Vulnerability Allowing Remote Code Execution</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://hoodguy.net/elastic-releases-urgent-patch-for-critical-kibana-vulnerability-allowing-remote-code-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Citrix release patch for critical Authentication Bypass vulnerability</title>
		<link>https://hoodguy.net/citrix-release-patch-for-critical-authentication-bypass-vulnerability/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=citrix-release-patch-for-critical-authentication-bypass-vulnerability</link>
					<comments>https://hoodguy.net/citrix-release-patch-for-critical-authentication-bypass-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[TeamHood]]></dc:creator>
		<pubDate>Wed, 09 Nov 2022 22:22:59 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[citrix]]></category>
		<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://hoodguy.net/?p=874</guid>

					<description><![CDATA[<p>Citrix is asking its customers to deploy the security updates for a critical authentication bypass vulnerability in Citrix ADC and Citrix Gateway. The vulnerabilities can enable attackers to gain unauthorized access to the device, perform remote desktop takeover, or bypass the login brute force protection. As per Citrix security Bulletin &#8220;The only appliances that are [&#8230;]</p>
<p>The post <a href="https://hoodguy.net/citrix-release-patch-for-critical-authentication-bypass-vulnerability/">Citrix release patch for critical Authentication Bypass vulnerability</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Citrix is asking its customers to deploy the security updates for a critical authentication bypass vulnerability in Citrix ADC and Citrix Gateway.</p>



<p class="wp-block-paragraph">The vulnerabilities can enable attackers to gain unauthorized access to the device, perform remote desktop takeover, or bypass the login brute force protection.</p>



<p class="wp-block-paragraph">As per Citrix security Bulletin  &#8220;The only appliances that are operating as a Gateway (appliances using the SSL VPN functionality or deployed as an ICA proxy with authentication enabled) are affected by the first issue, which is rated as a Critical severity vulnerability,&#8221; </p>



<p class="wp-block-paragraph">Citrix Gateway is an SSL VPN service providing secure remote access with identity and access management capabilities, widely deployed in the cloud or on on-premise company servers.</p>



<p class="wp-block-paragraph">Citrix ADC is a load-balancing solution for cloud applications deployed in the enterprise, ensuring uninterrupted availability and optimal performance.</p>



<p class="wp-block-paragraph">The following vulnerabilities are released as part of Citrix Advisory </p>



<p class="wp-block-paragraph"><strong>CVE-2022-27516</strong>:Login brute force protection mechanism failure allowing its bypassing. This vulnerability can only be exploited if the appliance is configured as VPN (Gateway) or AAA virtual server with “Max Login Attempts” configuration.</p>



<p class="wp-block-paragraph"><strong>CVE-2022-27513</strong>: Insufficient verification of data authenticity, allowing remote desktop takeover via phishing. The flaw is exploitable only if the appliance is configured as VPN (Gateway), and the RDP proxy functionality is configured.</p>



<p class="wp-block-paragraph"><strong>CVE-2022-27510</strong>: Critical-severity authentication bypassing using an alternate path or channel, exploitable only if the appliance is configured as VPN (Gateway).</p>



<p class="wp-block-paragraph">Citrix warns that &#8220;Affected customers of Citrix ADC and Citrix Gateway are recommended to install the relevant updated versions of Citrix ADC or Citrix Gateway as soon as possible,&#8221;</p>



<p class="wp-block-paragraph">Following citrix versions are affected by the above vulnerabilities </p>



<ul class="wp-block-list">
<li>Citrix ADC and Citrix Gateway 13.1 before 13.1-33.47</li>



<li>Citrix ADC and Citrix Gateway 13.0 before 13.0-88.12</li>



<li>Citrix ADC and Citrix Gateway 12.1 before 12.1.65.21</li>



<li>Citrix ADC 12.1-FIPS before 12.1-55.289</li>



<li>Citrix ADC 12.1-NDcPP before 12.1-55.289</li>
</ul>



<p class="wp-block-paragraph">Customers who rely on Citrix for cloud-based management services don’t need to take any action, as the vendor has already applied the security updates.</p>



<p class="wp-block-paragraph">The citrix versions before 12.1 do not need to take any actions on the vulnerabilities.</p>
<p>The post <a href="https://hoodguy.net/citrix-release-patch-for-critical-authentication-bypass-vulnerability/">Citrix release patch for critical Authentication Bypass vulnerability</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://hoodguy.net/citrix-release-patch-for-critical-authentication-bypass-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>All Log4j vulnerabilities in a Nutshell</title>
		<link>https://hoodguy.net/all-log4j-vulnerabilities-in-a-nutshell/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=all-log4j-vulnerabilities-in-a-nutshell</link>
					<comments>https://hoodguy.net/all-log4j-vulnerabilities-in-a-nutshell/#respond</comments>
		
		<dc:creator><![CDATA[TeamHood]]></dc:creator>
		<pubDate>Sat, 18 Dec 2021 18:19:03 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[log4j]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://hoodguy.net/?p=855</guid>

					<description><![CDATA[<p>Every security administrator nightmare critical log4j zero-day is a household name by now. Dubbed &#8216;Log4Shell,&#8217; the vulnerability has already set the internet on fire. Thus far, the log4j vulnerability, tracked as CVE-2021-44228, has been abused by all kinds of threat actors from state-backed hackers to ransomware gangs and others to inject Monero miners on vulnerable systems. Log4j usage is rampant among many software products and [&#8230;]</p>
<p>The post <a href="https://hoodguy.net/all-log4j-vulnerabilities-in-a-nutshell/">All Log4j vulnerabilities in a Nutshell</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Every security administrator nightmare critical log4j zero-day is a household name by now. Dubbed &#8216;Log4Shell,&#8217; the vulnerability has already set the internet on fire.</p>



<p class="wp-block-paragraph">Thus far, the log4j vulnerability, tracked as CVE-2021-44228, has been abused by all kinds of threat actors from state-backed hackers to ransomware gangs and others to inject Monero miners on vulnerable systems.</p>



<p class="wp-block-paragraph">Log4j usage is rampant among many software products and multiple vendor advisories have since surfaced. And, it now seems, &#8216;logback&#8217; isn&#8217;t all that immune either.</p>



<p class="wp-block-paragraph">Given Log4j&#8217;s vast usage&nbsp;in the majority of Java applications, Log4Shell soon&nbsp;turned into a&nbsp;<a href="https://www.bleepingcomputer.com/news/security/new-zero-day-exploit-for-log4j-java-library-is-an-enterprise-nightmare/" target="_blank" rel="noreferrer noopener">nightmare for enterprises and governments</a>&nbsp;worldwide.</p>



<p class="wp-block-paragraph">Below are the CVEs&nbsp;in the order that they emerged that you should know about:</p>



<ul class="wp-block-list"><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228" target="_blank" rel="noreferrer noopener">CVE-2021-44228</a><strong> [Critical]</strong>: The original &#8216;Log4Shell&#8217; vulnerability is an <a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noreferrer noopener">untrusted deserialization</a> flaw. Rated critical in severity, this one scores a 10 on the <a href="https://www.first.org/cvss/" target="_blank" rel="noreferrer noopener">CVSS</a> scale and grants remote code execution (RCE) abilities to unauthenticated attackers, allowing complete system takeover.<br><br>Reported by Chen Zhaojun of Alibaba Cloud Security Team to Apache on November 24th, CVE-2021-44228 impacts the default configurations of multiple Apache frameworks, including Apache Struts2, Apache Solr, Apache Druid, Apache Flink, and others.<br><br>Being the most dangerous of them all, this vulnerability lurks in the <a href="https://search.maven.org/artifact/org.apache.logging.log4j/log4j-core" target="_blank" rel="noreferrer noopener">log4j-core</a> component, limited to 2.x versions: from 2.0-beta9 up to and including 2.14.1. A fix for Log4Shell was rolled out in version 2.15.0 but deemed incomplete (keep reading).<br></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45046" target="_blank" rel="noreferrer noopener">CVE-2021-45046</a> [<strong>Critical</strong>, previously Low]: This one is a Denial of Service (DoS) flaw scoring a <s>3.7</s> 9.0. The flaw arose as a result of an incomplete fix that went into 2.15.0 for CVE-2021-44228. While the fix applied to 2.15.0 did largely resolve the flaw, that wasn&#8217;t quite the case for certain non-default configurations.   <br><br>Log4j 2.15.0 makes &#8220;a best-effort attempt&#8221; to restrict JNDI LDAP lookups to <em>localhost</em> by default. But, attackers who have control over the Thread Context Map (MDC) input data can craft malicious payloads via the JNDI Lookup patterns to cause DoS attacsk. This applies to non-default configurations in which a non-default Pattern Layout using either a Context Lookup, e.g. $${ctx:loginId}, or a Thread Context Map pattern (%X, %mdc, or %MDC).  <br><br>Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default,&#8221; states the NVD advisory. For those on 2.12.1 branch, a fix was backported into 2.12.2.<br></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4104" target="_blank" rel="noreferrer noopener">CVE-2021-4104</a><strong>[High]</strong>: Did we say Log4j 2.x versions were vulnerable? What about Log4j 1.x? <br>While previously thought to be safe, Log4Shell found a way to lurk in the older Log4j too. Essentially, non-default configuration of Log4j 1.x instances using the <em>JMSAppender </em>class also become susceptible to the untrusted deserialization flaw.<br><br>Although a less severe variant of CVE-2021-44228, nonetheless, this CVE impacts all versions of the <a href="https://search.maven.org/artifact/log4j/log4j" target="_blank" rel="noreferrer noopener">log4j:log4j</a> and <a href="https://mvnrepository.com/artifact/org.apache.log4j/log4j" target="_blank" rel="noreferrer noopener">org.apache.log4j:log4j</a> components for which only 1.x releases exist. Because these are <a href="https://logging.apache.org/log4j/1.2/" target="_blank" rel="noreferrer noopener">end-of-life</a> versions, a fix for 1.x branch does not exist anywhere, and one should upgrade to <em>log4j-core</em> 2.16.0.<br></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42550" target="_blank" rel="noreferrer noopener">CVE-2021-42550</a><strong> [Moderate]:</strong> This is a vulnerability in the Logback logging framework. A successor to the Log4j 1.x library, Logback claims to pick up &#8220;where log4j 1.x leaves off.&#8221;<br><br>Up until last week, Logback also <a href="https://archive.md/QkzIy" target="_blank" rel="noreferrer noopener">bragged</a> that being &#8220;unrelated to log4j 2.x, [logback] does not share its vulnerabilities.&#8221;<br><br>That assumption quickly faded when CVE-2021-4104 was discovered to impact Log4j 1.x as well, and the possibility of potential impact to Logback was <a href="https://jira.qos.ch/browse/LOGBACK-1591" target="_blank" rel="noreferrer noopener">assessed</a>. Newer Logback versions, 1.3.0-alpha11 and 1.2.9 addressing this less severe vulnerability have now been <a href="https://search.maven.org/artifact/ch.qos.logback/logback-classic" target="_blank" rel="noreferrer noopener">released</a>.<br> </li><li>CVE-2021-45105 <strong>[High]</strong>: Log4j 2.16.0 was found out to be vulnerable to a DoS flaw rated &#8216;High&#8217; in severity. Apache has since released a log4j 2.17.0 version fixing the CVE. </li></ul>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Patch Log4j 2.15: DNS exfiltration &amp; RCE possible</h2>



<p class="wp-block-paragraph">Log4j 2.15.0 might contain even more severe vulnerabilities than the ones discovered so far, which is why 2.16.0 is by far a safer bet.</p>



<p class="wp-block-paragraph">Because of CVE-2021-45046 described above, the maximum impact from the flaw initially appeared to be DoS, but that assumption is evolving.</p>



<p class="wp-block-paragraph">Cloud security firm Praetorian demonstrated how Log4j 2.15.0 versions could still be abused for DNS-based data exfiltration from external hosts, and is working with Apache towards a coordinated disclosure.</p>



<p class="wp-block-paragraph">As Bleeping computer reports &#8221; The Praetorian <a href="https://www.praetorian.com/blog/log4j-2-15-0-stills-allows-for-exfiltration-of-sensitive-data/" target="_blank" rel="noreferrer noopener">blog post</a> is in response to CVE-2021-45046, which applies to Log4j version 2.15. The CVE description states that—when using a specific type of Pattern Layout—this vulnerability can lead to a denial of service. The reason they state it is DoS only is due to the <em>localhost</em> allowlist,&#8221; Weems tells BleepingComputer.</p>



<p class="wp-block-paragraph">&#8220;We&#8217;ve developed a bypass for this &#8216;localhost&#8217; allowlist and sent the details to Apache. At minimum, this means systems that are vulnerable to CVE-2021-45046 are not just vulnerable to DoS, but also DNS exfil of potentially sensitive environment variables. &#8220;</p>



<p class="wp-block-paragraph">The worst possible scenario resulting from Log4j 2.15.0 is yet to be fully determined, but suffice to say, it doesn&#8217;t seem like it&#8217;s just limited to DoS.</p>
<p>The post <a href="https://hoodguy.net/all-log4j-vulnerabilities-in-a-nutshell/">All Log4j vulnerabilities in a Nutshell</a> appeared first on <a href="https://hoodguy.net">CyberHood Sentinel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://hoodguy.net/all-log4j-vulnerabilities-in-a-nutshell/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
