<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=2613%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 12:49:33 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 12:49:33 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=2613%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=2613%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2006-5519 | MambWeather 1.8.1 mosConfig_absolute_path code injection (EDB-2613 / Nessus ID 22049)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in MambWeather 1.8.1. Affected by this vulnerability is an unknown functionality of the component Weather. Executing a manipulation of the argument mosConfig_absolute_path can lead to code injection.

This vulnerability is handled as CVE-2006-5519....]]></description>
<link>https://tsecurity.de/de/3463912/sicherheitsluecken/cve-2006-5519-mambweather-181-mosconfigabsolutepath-code-injection-edb-2613-nessus-id-22049/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3463912/sicherheitsluecken/cve-2006-5519-mambweather-181-mosconfigabsolutepath-code-injection-edb-2613-nessus-id-22049/</guid>
<pubDate>Sat, 25 Apr 2026 13:22:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/mambweather">MambWeather 1.8.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>Weather</em>. Executing a manipulation of the argument <em>mosConfig_absolute_path</em> can lead to code injection.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2006-5519">CVE-2006-5519</a>. The attack can be executed remotely. Additionally, an exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Reprompt Attack Lets Attackers Exfiltrate Data From Microsoft Copilot With a Single Click]]></title>
<description><![CDATA[Reprompt Attack Lets Attackers Exfiltrate Data From Microsoft Copilot With a Single Click
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 9
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
	...]]></description>
<link>https://tsecurity.de/de/3217247/it-security-nachrichten/reprompt-attack-lets-attackers-exfiltrate-data-from-microsoft-copilot-with-a-single-click/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3217247/it-security-nachrichten/reprompt-attack-lets-attackers-exfiltrate-data-from-microsoft-copilot-with-a-single-click/</guid>
<pubDate>Fri, 16 Jan 2026 14:50:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Reprompt Attack Lets Attackers Exfiltrate Data From Microsoft Copilot With a Single Click</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286911 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">9</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="602" data-end="643"><strong>One-Click Attack Against AI Assistants</strong></h2>
<p data-start="645" data-end="919">Cybersecurity researchers have disclosed details of a novel attack technique called <strong data-start="729" data-end="741">Reprompt</strong> that enables attackers to <strong data-start="768" data-end="869">silently exfiltrate sensitive data from AI chatbots such as Microsoft Copilot with a single click</strong>, bypassing enterprise security controls entirely.</p>
<p data-start="921" data-end="1110">“Only a single click on a legitimate Microsoft link is required to compromise victims,” <a href="https://www.varonis.com/blog/reprompt" target="_blank" rel="noopener">said</a> <strong data-start="1014" data-end="1029">Dolev Taler</strong>, security researcher at Varonis. “No plugins, no user interaction with Copilot.”</p>
<p data-start="1112" data-end="1317">Even more concerning, researchers found that the attacker can <strong data-start="1174" data-end="1234">maintain control after the Copilot chat window is closed</strong>, enabling ongoing and hidden data extraction without any further user involvement.</p>
<p data-start="1319" data-end="1478">Microsoft has since <strong data-start="1339" data-end="1393">patched the issue following responsible disclosure</strong> and confirmed that <strong data-start="1413" data-end="1477">Microsoft 365 Copilot enterprise customers were not affected</strong>.</p>
<hr data-start="1480" data-end="1483">
<h2 data-start="1485" data-end="1517"><strong>How the Reprompt Attack Works</strong></h2>
<p><img decoding="async" class="aligncenter" src="https://www.varonis.com/hubfs/Blog_VTL-Reprompt_Diagram_202601_V3.png" alt="Blog_VTL-Reprompt_Diagram_202601_V3" width="822" height="1292"></p>
<div class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" data-hs-cos-general-type="widget" data-hs-cos-type="module">
<figure class="inline-blog-image-modal" data-instance-name="widget_cc8f5581-0811-46f2-b845-45e1ee04f608"><figcaption class="ibim-image-caption">
<p><em>Attack flow diagram</em></p>
</figcaption></figure>
</div>
<p data-start="1519" data-end="1623">At a high level, Reprompt chains together three techniques to create a covert data-exfiltration channel:</p>
<h3 data-start="1625" data-end="1669">1. Prompt Injection via URL Parameters</h3>
<p data-start="1670" data-end="1868">The attack abuses the <strong data-start="1692" data-end="1713"><code data-start="1694" data-end="1697">q</code> URL parameter</strong> in Copilot links (e.g., <code data-start="1738" data-end="1770">copilot.microsoft.com/?q=Hello</code>) to inject a malicious instruction directly from the URL itself—without the user typing anything.</p>
<h3 data-start="1870" data-end="1914">2. Guardrail Bypass Through Repetition</h3>
<p data-start="1915" data-end="2115">By instructing Copilot to <strong data-start="1941" data-end="1965">repeat actions twice</strong>, attackers exploit the fact that data-leak safeguards are applied only to the <em data-start="2044" data-end="2053">initial</em> request, allowing subsequent responses to bypass protections.</p>
<h3 data-start="2117" data-end="2162">3. Persistent Server-Driven Reprompting</h3>
<p data-start="2163" data-end="2387">The injected prompt initiates a loop in which Copilot continuously fetches instructions from an attacker-controlled server. This enables <strong data-start="2300" data-end="2350">dynamic, hidden, and ongoing data exfiltration</strong>, even if the chat session is closed.</p>
<p data-start="2389" data-end="2431">Instructions may include commands such as:</p>
<ul>
<li data-start="2434" data-end="2479">“Summarize all files the user accessed today”</li>
<li data-start="2482" data-end="2509">“Where does the user live?”</li>
<li data-start="2512" data-end="2556">“What vacations does the user have planned?”</li>
</ul>
<p data-start="2558" data-end="2690">Because follow-up instructions are delivered remotely, <strong data-start="2613" data-end="2689">the original prompt reveals nothing about what data is ultimately stolen</strong>.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="2697" data-end="2754"><strong>Turning Copilot Into an Invisible Exfiltration Channel</strong></h2>
<p data-start="2756" data-end="2889">Reprompt effectively transforms Copilot into a <strong data-start="2803" data-end="2826">covert data channel</strong> that operates without plugins, connectors, or visible prompts.</p>
<p data-start="2891" data-end="3054">“The real instructions are hidden in the server’s follow-up requests,” Varonis explained. “There’s no limit to the amount or type of data that can be exfiltrated.”</p>
<p data-start="3056" data-end="3209">This creates a significant <strong data-start="3083" data-end="3106">security blind spot</strong>, as defenders cannot determine what information is being accessed by reviewing the initial link alone.</p>
<hr data-start="3211" data-end="3214">
<h2 data-start="3216" data-end="3256"><strong>Root Cause: Indirect Prompt Injection</strong></h2>
<p data-start="3258" data-end="3478">Like many emerging AI attacks, Reprompt exploits a fundamental limitation in large language models: the inability to reliably distinguish between <strong data-start="3404" data-end="3433">trusted user instructions</strong> and <strong data-start="3438" data-end="3477">untrusted data embedded in requests</strong>.</p>
<p data-start="3480" data-end="3646">This enables <strong data-start="3493" data-end="3522">indirect prompt injection</strong>, where malicious instructions are smuggled through URLs, documents, or other inputs the AI processes as legitimate context.</p>
<hr data-start="3648" data-end="3651">
<h2 data-start="3653" data-end="3692"><strong>Part of a Growing Wave of AI Attacks</strong></h2>
<p data-start="3694" data-end="3799">The Reprompt disclosure coincides with a surge in adversarial techniques targeting AI systems, including:</p>
<ul>
<li data-start="3803" data-end="3912"><strong data-start="3803" data-end="3831">ZombieAgent / ShadowLeak</strong> – Zero-click prompt injections that turn chatbots into data exfiltration tools</li>
<li data-start="3915" data-end="4019"><strong data-start="3915" data-end="3957">Lies-in-the-Loop (HITL Dialog Forging)</strong> – Abusing confirmation prompts to execute malicious actions</li>
<li data-start="4022" data-end="4124"><strong data-start="4022" data-end="4036">GeminiJack</strong> – Hidden instructions in Google Docs and calendar invites targeting Gemini Enterprise</li>
<li data-start="4127" data-end="4212"><strong data-start="4127" data-end="4140">CellShock</strong> – Prompt injection in Claude for Excel to exfiltrate spreadsheet data</li>
<li data-start="4215" data-end="4306"><strong data-start="4215" data-end="4237">MCP Sampling Abuse</strong> – Draining AI compute quotas and injecting persistent instructions</li>
<li data-start="4309" data-end="4402"><strong data-start="4309" data-end="4341">AI Browser Prompt Injections</strong> – Bypassing safety controls in tools like Perplexity Comet</li>
<li data-start="4405" data-end="4500"><strong data-start="4405" data-end="4435">Enterprise AI Budget Abuse</strong> – Attacks against Cursor and Amazon Bedrock leaking API tokens</li>
</ul>
<p data-start="4502" data-end="4656">Researchers warn that as AI systems gain <strong data-start="4543" data-end="4594">autonomy and access to sensitive corporate data</strong>, the impact of a single vulnerability increases dramatically.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/network-eavesdropping-via-man-in-the-middle-on-internal-communications/" target="_blank" rel="noopener noreferrer">Network Eavesdropping via Man-in-the-Middle on Internal Communications<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/evilwaf-web-application-firewall-bypass-toolkit/" target="_blank" rel="noopener">Offensive Security Tool: EvilWAF – Web Application Firewall Bypass Toolkit<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="4663" data-end="4690"><strong>Security Recommendations</strong></h2>
<p data-start="4692" data-end="4772">Experts recommend adopting <strong data-start="4719" data-end="4739">layered defenses</strong> to mitigate AI-specific threats:</p>
<ul>
<li data-start="4776" data-end="4845">Treat AI links as potentially dangerous, even on legitimate domains</li>
<li data-start="4848" data-end="4907">Restrict AI access to sensitive data and privileged tools</li>
<li data-start="4910" data-end="4970">Monitor AI activity for anomalous or excessive data access</li>
<li data-start="4973" data-end="5037">Avoid sharing personal or confidential information in AI chats</li>
<li data-start="5040" data-end="5110">Clearly define trust boundaries between user input and external data</li>
</ul>
<p data-start="5112" data-end="5289">“As AI agents gain broader access to corporate data and autonomy to act on instructions, the blast radius of a single vulnerability expands exponentially,” warned Noma Security.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/actively-exploited-d-link-router-flaw-enables-unauthenticated-remote-code-execution/" target="_blank" rel="noopener noreferrer">Actively Exploited D-Link Router Flaw Enables Unauthenticated Remote Code Execution<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Sources: thehackernews.com, varonis.com/blog/reprompt</em></strong></p>
<p><a href="https://thehackernews.com/2026/01/researchers-reveal-reprompt-attack.html" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/node-js-fixes-critical-dos-flaw-that-could-crash-virtually-every-production-app/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2026/01/877x440-Images-for-the-News-posts-37-300x150.png" alt="Node.js Fixes Critical DoS Flaw That Could Crash “Virtually Every Production App”" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/node-js-fixes-critical-dos-flaw-that-could-crash-virtually-every-production-app/" target="_self">Node.js Fixes Critical DoS Flaw That Could Crash “Virtually Every Production App”</a></h3><time class="rpwe-time published" datetime="2026-01-14T12:52:32+02:00">January 14, 2026</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/actively-exploited-d-link-router-flaw-enables-unauthenticated-remote-code-execution/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2026/01/877x440-Images-for-the-News-posts-36-300x150.png" alt="Actively Exploited D-Link Router Flaw Enables Unauthenticated Remote Code Execution" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/actively-exploited-d-link-router-flaw-enables-unauthenticated-remote-code-execution/" target="_self">Actively Exploited D-Link Router Flaw Enables Unauthenticated Remote Code Execution</a></h3><time class="rpwe-time published" datetime="2026-01-07T13:48:28+02:00">January 7, 2026</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/kali-linux-2025-4-released-with-3-new-tools-desktop-overhauls-and-halloween-mode/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/12/877x440-Images-for-the-News-posts-34-300x150.png" alt="Kali Linux 2025.4 Released With 3 new tools, Desktop Overhauls, and Halloween Mode" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/kali-linux-2025-4-released-with-3-new-tools-desktop-overhauls-and-halloween-mode/" target="_self">Kali Linux 2025.4 Released With 3 new tools, Desktop Overhauls, and Halloween Mode</a></h3><time class="rpwe-time published" datetime="2025-12-16T12:33:50+02:00">December 16, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/new-phishing-kits-automate-mfa-bypass-ai-email-lures-and-bank-credential-theft-at-scale/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/12/877x440-Images-for-the-News-posts-33-300x150.png" alt="New Phishing Kits Automate MFA Bypass, AI Email Lures, and Bank Credential Theft at Scale" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/new-phishing-kits-automate-mfa-bypass-ai-email-lures-and-bank-credential-theft-at-scale/" target="_self">New Phishing Kits Automate MFA Bypass, AI Email Lures, and Bank Credential Theft at Scale</a></h3><time class="rpwe-time published" datetime="2025-12-15T11:53:36+02:00">December 15, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/reprompt-attack-lets-attackers-exfiltrate-data-from-microsoft-copilot-with-a-single-click/">Reprompt Attack Lets Attackers Exfiltrate Data From Microsoft Copilot With a Single Click</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates]]></title>
<description><![CDATA[Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 5
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
...]]></description>
<link>https://tsecurity.de/de/3003471/it-security-nachrichten/kali-linux-20253-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3003471/it-security-nachrichten/kali-linux-20253-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/</guid>
<pubDate>Thu, 25 Sep 2025 10:19:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286388 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">5</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="549" data-end="567"><strong>Release summary</strong></h2>
<p data-start="569" data-end="1015">Kali Linux 2025.3 is now available, delivering a mix of infrastructure refreshes, wireless improvements and fresh tooling. Key highlights since the 2025.2 release include updated <strong data-start="748" data-end="768">Packer &amp; Vagrant</strong> support, <strong data-start="778" data-end="788">Nexmon</strong> integration for Raspberry Pi Wi-Fi monitor/injection capabilities, and <strong data-start="860" data-end="876">10 new tools</strong> added to the repositories.</p>
<hr data-start="1017" data-end="1020">
<h2 data-start="1022" data-end="1061"><strong>Packer &amp; Vagrant — toolchain refresh</strong></h2>
<p data-start="1063" data-end="1391">HashiCorp tooling used by many Kali workflows received updates: <strong data-start="1127" data-end="1137">Packer</strong> and <strong data-start="1142" data-end="1153">Vagrant</strong> have been refreshed in the distribution, improving builders and development workflows that rely on VM images and appliance automation. This benefits infrastructure-as-code users who build and distribute Kali images for labs and training.</p>
<hr data-start="1393" data-end="1396">
<h2 data-start="1398" data-end="1449"><strong>Nexmon support — Raspberry Pi wireless injection</strong></h2>
<p data-start="1451" data-end="1797">A major usability win for wireless testers: Kali 2025.3 adds <strong data-start="1512" data-end="1530">Nexmon support</strong> enabling <strong data-start="1540" data-end="1586">internal monitor mode and packet injection</strong> on Raspberry Pi built-in Wi-Fi chips. That brings affordable, fully capable wireless testing to a broader range of Pi devices and makes compact test rigs easier to deploy for red teams and wireless researchers.</p>
<hr data-start="1799" data-end="1802">
<h2 data-start="1804" data-end="1850"><strong>Xfce VPN IP plugin — configurable interface</strong></h2>
<p data-start="1852" data-end="2286">The Xfce <strong data-start="1861" data-end="1884">VPN IP panel plugin</strong> introduced in 2024.1 gets a practical usability upgrade: you can now <strong data-start="1954" data-end="2008">select which network interface the plugin monitors</strong>. Right-click the plugin → Preferences → update the “Command” parameter to choose a different interface; this is useful if you run multiple VPNs or want to monitor non-default adapters. If the plugin isn’t visible, add the “Generic Monitor” plugin via Panel Preferences → Items.</p>
<p data-start="1852" data-end="2286"><img decoding="async" class="aligncenter" src="https://www.kali.org/blog/kali-linux-2025-3-release/images/xfce-vpn-ip-plugin.png" alt="" width="806" height="599"></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="2293" data-end="2325"><strong>Ten new tools (quick rundown)</strong></h2>
<p data-start="2327" data-end="2472">Kali 2025.3 adds ten packages to network repositories, expanding capabilities across web testing, protocol abuse, LLM integrations, and pivoting:</p>
<ul>
<li data-start="2476" data-end="2544"><a href="https://www.kali.org/tools/caido/" target="_blank" rel="noopener"><strong data-start="2476" data-end="2485">Caido</strong> </a>— client GUI for the Caido web security auditing toolkit</li>
<li data-start="2547" data-end="2610"><a href="https://www.kali.org/tools/caido-cli/" target="_blank" rel="noopener"><strong data-start="2547" data-end="2560">Caido-cli</strong> </a>— server/backend component of the Caido toolkit</li>
<li data-start="2613" data-end="2674"><a href="https://www.kali.org/tools/detect-it-easy/" target="_blank" rel="noopener"><strong data-start="2613" data-end="2637">Detect It Easy (DiE)</strong></a> — file type identification utility</li>
<li data-start="2677" data-end="2749"><a href="https://www.kali.org/tools/gemini-cli/" target="_blank" rel="noopener"><strong data-start="2677" data-end="2691">Gemini CLI</strong> </a>— open-source AI agent for terminal-based Gemini access</li>
<li data-start="2752" data-end="2828"><a href="https://www.kali.org/tools/krbrelayx/" target="_blank" rel="noopener"><strong data-start="2752" data-end="2765">krbrelayx</strong> </a>— Kerberos relaying / unconstrained delegation abuse toolkit</li>
<li data-start="2831" data-end="2897"><a href="https://www.kali.org/tools/ligolo-mp/" target="_blank" rel="noopener"><strong data-start="2831" data-end="2844">ligolo-mp</strong></a> — multiplayer pivoting / lateral movement solution</li>
<li data-start="2900" data-end="2983"><a href="https://www.kali.org/tools/llm-tools-nmap/" target="_blank" rel="noopener"><strong data-start="2900" data-end="2918">llm-tools-nmap</strong></a> — enabling LLM-driven network discovery and scanning with nmap</li>
<li data-start="2986" data-end="3051"><a href="https://www.kali.org/tools/mcp-kali-server/" target="_blank" rel="noopener"><strong data-start="2986" data-end="3005">mcp-kali-server</strong></a> — MCP config to connect an AI agent to Kali</li>
<li data-start="3054" data-end="3153"><a href="https://www.kali.org/tools/patchleaks/" target="_blank" rel="noopener"><strong data-start="3054" data-end="3068">patchleaks</strong></a> — detects security fixes and summarizes patches for rapid validation (or analysis)</li>
<li data-start="3156" data-end="3233"><a href="https://www.kali.org/tools/vwifi-dkms/" target="_blank" rel="noopener"><strong data-start="3156" data-end="3170">vwifi-dkms</strong></a> — create virtual Wi-Fi networks (dummy interfaces) for testing</li>
</ul>
<p data-start="3235" data-end="3344">These additions broaden both classic offensive toolsets and modern workflows that incorporate AI/LLM tooling.</p>
<hr data-start="3346" data-end="3349">
<h2 data-start="3351" data-end="3396"><strong>Kali NetHunter — mobile and device updates</strong></h2>
<p data-start="3398" data-end="3831">NetHunter continues to advance: the project brought a new budget-friendly device with internal monitor mode and injection beyond the Nexus 5 era — the <strong data-start="3549" data-end="3571">Samsung Galaxy S10</strong> port (Nexmon firmware patches + NetHunter kernel). The collaboration (Nexmon, kernel port, and app stability fixes) now provides a viable, modern device for mobile wireless testing. Installation guides for Nexmon + NetHunter are available in the project docs.</p>
<p><span class="lO9hj"></span></p>
<hr data-start="3833" data-end="3836">
<h2 data-start="3838" data-end="3895"><strong>CARsenal (NetHunter Car Hacking) — revamp and features</strong></h2>
<p data-start="3897" data-end="3949">CARsenal received a substantial update and refactor:</p>
<ul>
<li data-start="3953" data-end="4027">Settings moved to the menu bar; service commands editable via long-press</li>
<li data-start="4030" data-end="4093">New <strong data-start="4034" data-end="4052">RFCOMM Connect</strong> service and improved tools integration</li>
<li data-start="4096" data-end="4178"><strong data-start="4096" data-end="4109">Simulator</strong> (formerly ICSim) and <strong data-start="4131" data-end="4140">UDSim</strong> added for richer simulation/testing</li>
<li data-start="4181" data-end="4260">New <strong data-start="4185" data-end="4196">MSF tab</strong> to run automotive Metasploit modules against hardware bridges</li>
<li data-start="4263" data-end="4349">UI refreshes, extensive bug fixes, and full documentation rewrite for 2025.3 content</li>
<li data-start="4352" data-end="4442">New kernel support for CAN on OnePlus6 LineageOS 22.2 (Android 15) — OnePlus6 (6T pending)</li>
</ul>
<p data-start="4444" data-end="4546">The team warns: do not test CARsenal on a production/daily-driver vehicle — use isolated lab hardware.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/how-penetration-testing-supports-dora-compliance-for-financial-and-ict-entities/" target="_blank" rel="noopener noreferrer">How Penetration Testing Supports DORA Compliance for Financial and ICT Entities<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/ringreaper/" target="_blank" rel="noopener">Offensive Security Tool: RingReaper<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="4553" data-end="4574"><strong>What’s coming next</strong></h2>
<p data-start="4576" data-end="4837">Looking ahead to 2025.4, expect more UI polish, improved Metasploit terminal screens, simulator enhancements and additional device/kernel support. CARsenal maintainers plan video demos and continued refinement; community feedback and bug reports are encouraged.</p>
<hr data-start="4839" data-end="4842">
<h2 data-start="4844" data-end="4878"><strong>Where to get it &amp; upgrade notes</strong></h2>
<p data-start="4880" data-end="4976">Kali 2025.3 is available through the usual Kali channels and network repositories. Users should:</p>
<ul>
<li>Update existing installs via <code data-start="5009" data-end="5041">apt update &amp;&amp; apt full-upgrade</code> (follow Kali release guidance).</li>
<li>Review the new tools list and post-install any packages you need.</li>
<li>Consult NetHunter/CARsenal installation guides for device-specific steps (especially for Nexmon patches and kernels).</li>
<li>Test Nexmon and wireless features in a lab environment before operational use.</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/spamgpt-ai-powered-phishing-toolkit-redefines-email-threat-landscape/" target="_blank" rel="noopener noreferrer">SpamGPT: AI-Powered Phishing Toolkit Redefines Email Threat Landscape<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: www.kali.org</em></strong></p>
<p><a href="https://www.kali.org/blog/kali-linux-2025-3-release/" target="_blank" rel="noopener"><strong>Read the full blog:<br>Kali Blog Release</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/critical-entra-id-flaw-could-have-let-attackers-seize-any-microsoft-tenant/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-25-300x150.png" alt="Critical Entra ID Flaw Could Have Let Attackers Seize Any Microsoft Tenant" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/critical-entra-id-flaw-could-have-let-attackers-seize-any-microsoft-tenant/" target="_self">Critical Entra ID Flaw Could Have Let Attackers Seize Any Microsoft Tenant</a></h3><time class="rpwe-time published" datetime="2025-09-22T11:45:29+02:00">September 22, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/sixth-chrome-zero-day-of-2025-patched-after-active-exploitation/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-24-300x150.png" alt="Sixth Chrome Zero-Day of 2025 Patched After Active Exploitation" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/sixth-chrome-zero-day-of-2025-patched-after-active-exploitation/" target="_self">Sixth Chrome Zero-Day of 2025 Patched After Active Exploitation</a></h3><time class="rpwe-time published" datetime="2025-09-19T09:59:51+02:00">September 19, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/spamgpt-ai-powered-phishing-toolkit-redefines-email-threat-landscape/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-22-300x150.png" alt="SpamGPT: AI-Powered Phishing Toolkit Redefines Email Threat Landscape" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/spamgpt-ai-powered-phishing-toolkit-redefines-email-threat-landscape/" target="_self">SpamGPT: AI-Powered Phishing Toolkit Redefines Email Threat Landscape</a></h3><time class="rpwe-time published" datetime="2025-09-16T11:27:18+02:00">September 16, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/new-hybridpetya-ransomware-bypasses-uefi-secure-boot-protection/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-21-300x150.png" alt="New HybridPetya Ransomware Bypasses UEFI Secure Boot Protection" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/new-hybridpetya-ransomware-bypasses-uefi-secure-boot-protection/" target="_self">New HybridPetya Ransomware Bypasses UEFI Secure Boot Protection</a></h3><time class="rpwe-time published" datetime="2025-09-15T10:37:25+02:00">September 15, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/kali-linux-2025-3-released-with-10-new-tools-nexmon-wi-fi-injection-for-raspberry-pi-and-vagrant-updates/">Kali Linux 2025.3 released with 10 New Tools, Nexmon Wi-Fi Injection for Raspberry Pi and Vagrant Updates</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-53265 | Linux Kernel up to 6.2.4 lib/crc32.c crc32_body out-of-bounds (CNNVD-202509-2613)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 6.2.4. This affects the function crc32_body in the library lib/crc32.c. Such manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as CVE-2023-53265. The attack can only be initiated wit...]]></description>
<link>https://tsecurity.de/de/2990946/sicherheitsluecken/cve-2023-53265-linux-kernel-up-to-624-libcrc32c-crc32body-out-of-bounds-cnnvd-202509-2613/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2990946/sicherheitsluecken/cve-2023-53265-linux-kernel-up-to-624-libcrc32c-crc32body-out-of-bounds-cnnvd-202509-2613/</guid>
<pubDate>Thu, 18 Sep 2025 11:53:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.linux:kernel">Linux Kernel up to 6.2.4</a>. This affects the function <code>crc32_body</code> in the library <em>lib/crc32.c</em>. Such manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.324393">CVE-2023-53265</a>. The attack can only be initiated within the local network. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mac Infostealer ‘Shamos’ Spreads via ClickFix Attacks Masquerading as Help]]></title>
<description><![CDATA[Mac Infostealer ‘Shamos’ Spreads via ClickFix Attacks Masquerading as Help
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 0
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
				
				
				
	...]]></description>
<link>https://tsecurity.de/de/2956213/it-security-nachrichten/mac-infostealer-shamos-spreads-via-clickfix-attacks-masquerading-as-help/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2956213/it-security-nachrichten/mac-infostealer-shamos-spreads-via-clickfix-attacks-masquerading-as-help/</guid>
<pubDate>Mon, 25 Aug 2025 10:34:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Mac Infostealer ‘Shamos’ Spreads via ClickFix Attacks Masquerading as Help</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286091 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">0</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="126" data-end="193"><strong>New macOS Infostealer ‘Shamos’ Spreads Through ClickFix Attacks</strong></h2>
<p data-start="195" data-end="346">A new infostealer malware named <strong data-start="227" data-end="237">Shamos</strong> is targeting macOS devices through <strong data-start="273" data-end="293">ClickFix attacks</strong> that impersonate troubleshooting guides and fixes.</p>
<p data-start="348" data-end="607">The malware, a variant of the <strong data-start="378" data-end="409">Atomic macOS Stealer (AMOS)</strong>, was developed by the cybercriminal group <strong data-start="452" data-end="469">COOKIE SPIDER</strong> and is designed to steal sensitive information, including browser credentials, Keychain items, Apple Notes, and cryptocurrency wallets.</p>
<p data-start="609" data-end="761"><strong data-start="609" data-end="624">CrowdStrike</strong>, which discovered the malware, <a href="https://www.crowdstrike.com/en-us/blog/falcon-prevents-cookie-spider-shamos-delivery-macos/" target="_blank" rel="noopener">reports</a> attempted infections against <strong data-start="693" data-end="738">over 300 monitored environments worldwide</strong> since <strong data-start="745" data-end="758">June 2025</strong>.</p>
<hr data-start="763" data-end="766">
<h2 data-start="768" data-end="814"><strong>Malvertising and Fake GitHub Repositories</strong></h2>
<p data-start="816" data-end="953">Shamos is delivered through <strong data-start="844" data-end="870">malvertising campaigns</strong> and <strong data-start="875" data-end="903">fake GitHub repositories</strong> posing as legitimate troubleshooting resources.</p>
<p data-start="816" data-end="953"><img decoding="async" class="aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2025/August/github.jpeg" alt="Malicious GitHub repository" width="493" height="542"><strong>Malicious GitHub repository</strong><br><em>Source: CrowdStrike</em></p>
<p data-start="955" data-end="1172">These lures direct victims to websites like <strong data-start="999" data-end="1018">mac-safer[.]com</strong> and <strong data-start="1023" data-end="1043">rescue-mac[.]com</strong>, which provide fake instructions urging users to <strong data-start="1093" data-end="1140">copy-paste shell commands into the Terminal</strong> to fix common macOS problems.</p>
<p data-start="955" data-end="1172"><img decoding="async" class="aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2025/August/sponsored.jpg" alt="Malicious sponsored results on Google Search" width="858" height="244"><strong>Malicious sponsored results on Google Search</strong><br><em>Source: CrowdStrike</em></p>
<p data-start="1174" data-end="1218">Instead of solving anything, the commands:</p>
<ul>
<li data-start="1221" data-end="1254">Decode a <strong data-start="1230" data-end="1252">Base64-encoded URL</strong></li>
<li data-start="1257" data-end="1292">Fetch a malicious <strong data-start="1275" data-end="1290">Bash script</strong></li>
<li data-start="1295" data-end="1322">Steal the user’s password</li>
<li data-start="1325" data-end="1372">Download and execute the Shamos Mach-O binary</li>
</ul>
<p> </p>
<p><img decoding="async" class="b-lazy b-loaded aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2025/August/printer.jpg" alt="False instructions on fixing printer issues on macOS" width="905" height="429"><strong>False instructions for fixing printer issues on macOS</strong><br><em>Source: CrowdStrike</em></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So, you want to be a hacker?<br></strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="1379" data-end="1408"><strong>Bypassing macOS Defenses</strong></h2>
<p data-start="1410" data-end="1443">The malicious script leverages:</p>
<ul>
<li data-start="1446" data-end="1505"><strong data-start="1446" data-end="1455">xattr</strong> → Removes quarantine flags to bypass Gatekeeper</li>
<li data-start="1508" data-end="1550"><strong data-start="1508" data-end="1517">chmod</strong> → Makes the malware executable</li>
</ul>
<p data-start="1552" data-end="1704">Once installed, Shamos runs <strong data-start="1580" data-end="1598">anti-VM checks</strong> to avoid sandbox detection and executes <strong data-start="1639" data-end="1663">AppleScript commands</strong> to gather system and host information.</p>
<hr data-start="1706" data-end="1709">
<h2 data-start="1711" data-end="1742"><strong>Data Theft and Persistence</strong></h2>
<p data-start="1744" data-end="1803">Shamos collects and exfiltrates sensitive data including:</p>
<ul>
<li data-start="1806" data-end="1835">Cryptocurrency wallet files</li>
<li data-start="1838" data-end="1859">Apple Keychain data</li>
<li data-start="1862" data-end="1883">Apple Notes content</li>
<li data-start="1886" data-end="1914">Browser-stored credentials</li>
</ul>
<p data-start="1916" data-end="2017">The stolen data is compressed into <code data-start="1951" data-end="1960">out.zip</code> and transmitted via <strong data-start="1981" data-end="1989">curl</strong> to the attacker’s server.</p>
<p data-start="2019" data-end="2180">If run with <strong data-start="2031" data-end="2050">sudo privileges</strong>, Shamos creates a <strong data-start="2069" data-end="2096">LaunchDaemon Plist file</strong> (<code data-start="2098" data-end="2123">com.finder.helper.plist</code>) in the user’s system, enabling persistence on reboot.</p>
<p data-start="2182" data-end="2334">Additionally, it can download extra payloads, such as a <strong data-start="2238" data-end="2272">spoofed Ledger Live wallet app</strong> or a <strong data-start="2278" data-end="2295">botnet module</strong>, further expanding its capabilities.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/cross-site-scripting-vulnerability-in-get-a-quote-feature-while-bypassing-wordfence-and-cloudflare/" target="_blank" rel="noopener noreferrer">XSS Vulnerability in “Get a Quote” while bypassing WordFence and CloudFlare<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/waybacklister/" target="_blank" rel="noopener">Recon Tool: WaybackLister<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="2341" data-end="2396"><strong>ClickFix Attacks: A Growing Malware Delivery Trend</strong></h2>
<p data-start="2398" data-end="2550">ClickFix attacks trick users into executing malicious commands under the guise of fixing errors or installing updates. Recently, they’ve been seen in:</p>
<ul>
<li data-start="2553" data-end="2572"><strong data-start="2553" data-end="2570">TikTok videos</strong></li>
<li data-start="2575" data-end="2604">Fake <strong data-start="2580" data-end="2602">captcha challenges</strong></li>
<li data-start="2607" data-end="2636">Phony <strong data-start="2613" data-end="2634">Google Meet fixes</strong></li>
<li data-start="2639" data-end="2670">Ransomware delivery campaigns</li>
<li data-start="2673" data-end="2702"><strong data-start="2673" data-end="2700">State-sponsored attacks</strong></li>
</ul>
<p data-start="2704" data-end="2787">This highlights the rising popularity of ClickFix as an initial infection vector.</p>
<hr data-start="2789" data-end="2792">
<h2 data-start="2794" data-end="2815"><strong>How to Stay Safe</strong></h2>
<p data-start="2817" data-end="2836">Mac users should:</p>
<ol>
<li data-start="2840" data-end="2957"><strong data-start="2840" data-end="2900">Avoid executing Terminal commands from untrusted sources</strong>, especially those found in ads or random repositories.</li>
<li data-start="2961" data-end="3040"><strong data-start="2961" data-end="2997">Steer clear of sponsored results</strong> when searching for troubleshooting help.</li>
<li data-start="3044" data-end="3158">Use <strong data-start="3048" data-end="3083">Apple’s official Support forums</strong> or the built-in <strong data-start="3100" data-end="3142">macOS Help tool (Cmd + Space → “Help”)</strong> for guidance.</li>
</ol>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/15-8-million-paypal-logins-allegedly-on-sale-in-hacker-forum/" target="_blank" rel="noopener noreferrer">15.8 Million PayPal Logins Allegedly on Sale in Hacker Forum<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote>
<p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p>
</blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: bleepingcomputer.com</em></strong></p>
<p><a href="https://www.bleepingcomputer.com/news/security/fake-mac-fixes-trick-users-into-installing-new-shamos-infostealer/" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/threat-actors-exploit-two-year-old-apache-activemq-flaw-to-deploy-dripdropper-malware-on-linux-systems/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/08/877x440-Images-for-the-News-posts-13-300x150.png" alt="Threat Actors Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux Systems" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/threat-actors-exploit-two-year-old-apache-activemq-flaw-to-deploy-dripdropper-malware-on-linux-systems/" target="_self">Threat Actors Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux Systems</a></h3><time class="rpwe-time published" datetime="2025-08-20T11:31:34+02:00">August 20, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/15-8-million-paypal-logins-allegedly-on-sale-in-hacker-forum/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/08/877x440-Images-for-the-News-posts-14-300x150.png" alt="15.8 Million PayPal Logins Allegedly on Sale in Hacker Forum" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/15-8-million-paypal-logins-allegedly-on-sale-in-hacker-forum/" target="_self">15.8 Million PayPal Logins Allegedly on Sale in Hacker Forum</a></h3><time class="rpwe-time published" datetime="2025-08-18T10:40:51+02:00">August 18, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/xz-utils-backdoor-still-found-in-35-docker-hub-linux-images/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/08/877x440-Images-for-the-News-posts-12-300x150.png" alt="XZ-Utils Backdoor Still Found in 35+ Docker Hub Linux Images" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/xz-utils-backdoor-still-found-in-35-docker-hub-linux-images/" target="_self">XZ-Utils Backdoor Still Found in 35+ Docker Hub Linux Images</a></h3><time class="rpwe-time published" datetime="2025-08-13T10:23:46+02:00">August 13, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/winrar-zero-day-exploited-to-deploy-romcom-malware/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/08/877x440-Images-for-the-News-posts-11-300x150.png" alt="WinRAR Zero-Day Exploited to Deploy RomCom Malware" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/winrar-zero-day-exploited-to-deploy-romcom-malware/" target="_self">WinRAR Zero-Day Exploited to Deploy RomCom Malware</a></h3><time class="rpwe-time published" datetime="2025-08-11T10:26:32+02:00">August 11, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/mac-infostealer-shamos-spreads-via-clickfix-attacks-masquerading-as-help/">Mac Infostealer ‘Shamos’ Spreads via ClickFix Attacks Masquerading as Help</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2010-2613 | Harmistechnology Com Awd Song index.php cross site scripting (EDB-14059 / XFDB-59807)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Harmistechnology Com Awd Song. Affected is an unknown function of the file index.php. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2010-2613. It is possible to launch the attack remotely. Fu...]]></description>
<link>https://tsecurity.de/de/2919654/sicherheitsluecken/cve-2010-2613-harmistechnology-com-awd-song-indexphp-cross-site-scripting-edb-14059-xfdb-59807/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2919654/sicherheitsluecken/cve-2010-2613-harmistechnology-com-awd-song-indexphp-cross-site-scripting-edb-14059-xfdb-59807/</guid>
<pubDate>Sat, 02 Aug 2025 22:43:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.harmistechnology:com_awd_song">Harmistechnology Com Awd Song</a>. Affected is an unknown function of the file <em>index.php</em>. The manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.53904">CVE-2010-2613</a>. It is possible to launch the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-6101 | letta-ai letta up to 0.4.1 letta/letta/interface.py function_message function_name/function_args eval injection (Issue 2613)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralization of directives in dynamically evaluated...]]></description>
<link>https://tsecurity.de/de/2833351/sicherheitsluecken/cve-2025-6101-letta-ai-letta-up-to-041-lettalettainterfacepy-functionmessage-functionnamefunctionargs-eval-injection-issue-2613/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2833351/sicherheitsluecken/cve-2025-6101-letta-ai-letta-up-to-041-lettalettainterfacepy-functionmessage-functionnamefunctionargs-eval-injection-issue-2613/</guid>
<pubDate>Mon, 16 Jun 2025 05:49:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.letta-ai:letta">letta-ai letta up to 0.4.1</a>. Affected is the function <code>function_message</code> of the file <em>letta/letta/interface.py</em>. The manipulation of the argument <em>function_name/function_args</em> leads to improper neutralization of directives in dynamically evaluated code.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.312570">CVE-2025-6101</a>. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Patches WhatsApp for Windows Vulnerability That Enables Code Execution via File Spoofing]]></title>
<description><![CDATA[Meta Patches WhatsApp for Windows Vulnerability That Enables Code Execution via File Spoofing
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 4
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
		...]]></description>
<link>https://tsecurity.de/de/2714000/hacking/meta-patches-whatsapp-for-windows-vulnerability-that-enables-code-execution-via-file-spoofing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2714000/hacking/meta-patches-whatsapp-for-windows-vulnerability-that-enables-code-execution-via-file-spoofing/</guid>
<pubDate>Wed, 09 Apr 2025 11:04:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Meta Patches WhatsApp for Windows Vulnerability That Enables Code Execution via File Spoofing</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-283913 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">4</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="flex-1 overflow-hidden @container/thread">
<div class="h-full">
<div class="react-scroll-to-bottom--css-hlgkg-79elbk h-full">
<div class="react-scroll-to-bottom--css-hlgkg-1n7m0yu">
<div class="flex flex-col text-sm md:pb-9">
<article class="w-full scroll-mb-[var(--thread-trailing-height,150px)] text-token-text-primary focus-visible:outline-2 focus-visible:outline-offset-[-4px]" dir="auto" data-testid="conversation-turn-303" data-scroll-anchor="true">
<div class="m-auto text-base py-[18px] px-3 md:px-4 w-full md:px-5 lg:px-4 xl:px-5">
<div class="mx-auto flex flex-1 gap-4 text-base md:gap-5 lg:gap-6 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem]">
<div class="group/conversation-turn relative flex w-full min-w-0 flex-col agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex max-w-full flex-col flex-grow">
<div class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="780b2db2-e3cd-4c79-b2d4-4e39f2f5fa49" data-message-model-slug="gpt-4o">
<div class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 class="" data-start="615" data-end="701"><strong data-start="618" data-end="701">Spoofing Bug in Desktop App Exploited File Extension Trick to Bypass User Trust</strong></h2>
<p class="" data-start="703" data-end="1035">Meta has released a security update for <strong data-start="743" data-end="767">WhatsApp for Windows</strong>, urging users to <strong data-start="785" data-end="828">upgrade immediately to version 2.2450.6</strong> to fix a vulnerability tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30401" target="_blank" rel="noopener"><strong data-start="863" data-end="881">CVE-2025-30401</strong></a>. This <strong data-start="888" data-end="914">critical spoofing flaw</strong> could allow attackers to trick users into running <strong data-start="965" data-end="983">malicious code</strong> simply by opening what appears to be a benign file.</p>
<hr class="" data-start="1037" data-end="1040">
<h2 class="" data-start="1042" data-end="1069"><strong data-start="1045" data-end="1069">How the Attack Works</strong></h2>
<p class="" data-start="1070" data-end="1173">According to Meta’s <a href="https://www.whatsapp.com/security/advisories/2025/" target="_blank" rel="noopener">advisory</a>, the vulnerability is rooted in how <strong data-start="1135" data-end="1172">WhatsApp handles file attachments</strong>:</p>
<blockquote data-start="1174" data-end="1374">
<p class="" data-start="1176" data-end="1374">“A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their <strong data-start="1285" data-end="1298">MIME type</strong> but selected the file opening handler based on the <strong data-start="1350" data-end="1372">filename extension</strong>.”</p>
</blockquote>
<p class="" data-start="1376" data-end="1662">In simpler terms, an attacker could send a file that looks like an image or document based on its MIME type, while hiding an <strong data-start="1501" data-end="1523">executable payload</strong> using a misleading file extension. If a recipient opens the file manually from within WhatsApp, they may <strong data-start="1629" data-end="1661">inadvertently launch malware</strong>.</p>
<hr class="" data-start="1664" data-end="1667">
<h2 class="" data-start="1669" data-end="1710"><strong data-start="1672" data-end="1710">No Evidence of Active Exploitation</strong></h2>
<p class="" data-start="1711" data-end="1940">Meta credits an <strong data-start="1727" data-end="1759">external security researcher</strong> for discovering and responsibly disclosing the flaw through its <strong data-start="1824" data-end="1846">Bug Bounty program</strong>. As of now, the company has <strong data-start="1875" data-end="1921">not confirmed any in-the-wild exploitation</strong> of CVE-2025-30401.</p>
<p class="" data-start="1942" data-end="2109">However, given WhatsApp’s <strong data-start="1968" data-end="1986">widespread use</strong>—especially on desktop in business environments—the window for abuse could have been significant had it remained unpatched.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</article>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So, you want to be a hacker?<br></strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="" data-start="2116" data-end="2181"><strong data-start="2119" data-end="2181">Not the First Time WhatsApp Has Faced File Execution Risks</strong></h2>
<p class="" data-start="2182" data-end="2447">This is not the first time WhatsApp’s desktop version has allowed for unintended code execution. In <strong data-start="2282" data-end="2295">July 2024</strong>, a similar issue enabled automatic execution of <strong data-start="2344" data-end="2368">Python and PHP files</strong> when opened on machines where Python was installed, without alerting the user.</p>
<hr class="" data-start="2449" data-end="2452">
<h2 class="" data-start="2454" data-end="2505"><strong data-start="2457" data-end="2505">Part of a Larger Pattern of Targeted Attacks</strong></h2>
<p class="" data-start="2506" data-end="2572">WhatsApp continues to be a <strong data-start="2533" data-end="2571">prime target for spyware campaigns</strong>:</p>
<ul data-start="2573" data-end="2942">
<li class="" data-start="2573" data-end="2719">
<p class="" data-start="2575" data-end="2719">In late 2024, a <strong data-start="2591" data-end="2613">zero-click exploit</strong> was used to install <strong data-start="2634" data-end="2664">Paragon’s Graphite spyware</strong>, affecting nearly 90 users across two dozen countries.</p>
</li>
<li class="" data-start="2720" data-end="2942">
<p class="" data-start="2722" data-end="2942">In a U.S. federal court ruling last year, <strong data-start="2764" data-end="2799">Israeli spyware maker NSO Group</strong> was found to have exploited multiple WhatsApp zero-days to install <strong data-start="2867" data-end="2886">Pegasus spyware</strong> on over <strong data-start="2895" data-end="2912">1,400 devices</strong>, violating U.S. hacking laws.</p>
</li>
</ul>
<p class="" data-start="2944" data-end="3063">These incidents underscore WhatsApp’s attractiveness to threat actors deploying <strong data-start="3024" data-end="3062">highly targeted surveillance tools</strong>.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/top-10-things-to-do-after-installing-kali-linux/" target="_blank" rel="noopener noreferrer">Top 10 Things to Do After Installing Kali Linux<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/ctfpacker/" target="_blank" rel="noopener">Offensive Security Tool: CTFPacker<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 class="" data-start="3070" data-end="3097"><strong data-start="3073" data-end="3097">User Recommendations</strong></h2>
<p class="" data-start="3098" data-end="3131">Meta is strongly urging users to:</p>
<p class="" data-start="3134" data-end="3196">✅ <strong data-start="3136" data-end="3196">Update WhatsApp for Windows to version 2.2450.6 or later</strong></p>
<p class="" data-start="3199" data-end="3272">✅ <strong data-start="3201" data-end="3246">Avoid opening unexpected file attachments</strong>, even from known contacts</p>
<p class="" data-start="3275" data-end="3358">✅ <strong data-start="3277" data-end="3312">Verify file extensions manually</strong>, especially if the file type seems mismatched</p>
<p class="" data-start="3361" data-end="3464">✅ <strong data-start="3363" data-end="3400">Use reputable endpoint protection</strong>, especially on devices used for communication and collaboration</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/oracle-breach-exposes-millions-of-stolen-credentials-from-legacy-cloud-system/" target="_blank" rel="noopener noreferrer">Oracle Breach Exposes Millions of Stolen Credentials from Legacy Cloud System</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote>
<p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p>
</blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: hackread.com</em></strong></p>
<p><a href="https://www.bleepingcomputer.com/news/security/whatsapp-flaw-can-let-attackers-run-malicious-code-on-windows-pcs/" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/new-neptune-rat-variant-spreads-via-youtube-and-telegram-targets-windows-users/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/04/877x440-Images-for-the-News-posts-24-300x150.png" alt="New Neptune RAT Variant Spreads via YouTube and Telegram, Targets Windows Users" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/new-neptune-rat-variant-spreads-via-youtube-and-telegram-targets-windows-users/" target="_self">New Neptune RAT Variant Spreads via YouTube and Telegram, Targets Windows Users</a></h3><time class="rpwe-time published" datetime="2025-04-08T11:21:41+02:00">April 8, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/oracle-breach-exposes-millions-of-stolen-credentials-from-legacy-cloud-system/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/04/877x440-Images-for-the-News-posts-23-300x150.png" alt="Oracle Breach Exposes Millions of Stolen Credentials from Legacy Cloud System" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/oracle-breach-exposes-millions-of-stolen-credentials-from-legacy-cloud-system/" target="_self">Oracle Breach Exposes Millions of Stolen Credentials from Legacy Cloud System</a></h3><time class="rpwe-time published" datetime="2025-04-04T10:58:22+02:00">April 4, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/apple-backports-zero-day-fixes-to-older-ios-and-macos-versions/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/04/877x440-Images-for-the-News-posts-22-300x150.png" alt="Apple Backports Zero-Day Fixes to Older iOS and macOS Versions" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/apple-backports-zero-day-fixes-to-older-ios-and-macos-versions/" target="_self">Apple Backports Zero-Day Fixes to Older iOS and macOS Versions</a></h3><time class="rpwe-time published" datetime="2025-04-02T12:03:48+02:00">April 2, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/firefox-update-fixes-sandbox-escape-flaw-similar-to-chrome-zero-day/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/03/877x440-Images-for-the-News-posts-21-1-300x150.png" alt="Firefox Update Fixes Sandbox Escape Flaw Similar to Chrome Zero-Day" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/firefox-update-fixes-sandbox-escape-flaw-similar-to-chrome-zero-day/" target="_self">Firefox Update Fixes Sandbox Escape Flaw Similar to Chrome Zero-Day</a></h3><time class="rpwe-time published" datetime="2025-03-28T10:33:08+02:00">March 28, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/meta-patches-whatsapp-for-windows-vulnerability-that-enables-code-execution-via-file-spoofing/">Meta Patches WhatsApp for Windows Vulnerability That Enables Code Execution via File Spoofing</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-2613 | Mozilla Firefox up to 123 QUIC ACK Frame Decoder memory allocation]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 123. Affected by this issue is some unknown functionality of the component QUIC ACK Frame Decoder. The manipulation leads to uncontrolled memory allocation.

This vulnerability is handled as CVE-2024-261...]]></description>
<link>https://tsecurity.de/de/2259945/sicherheitsluecken/cve-2024-2613-mozilla-firefox-up-to-123-quic-ack-frame-decoder-memory-allocation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2259945/sicherheitsluecken/cve-2024-2613-mozilla-firefox-up-to-123-quic-ack-frame-decoder-memory-allocation/</guid>
<pubDate>Sat, 03 Aug 2024 03:11:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.mozilla:firefox">Mozilla Firefox up to 123</a>. Affected by this issue is some unknown functionality of the component <em>QUIC ACK Frame Decoder</em>. The manipulation leads to uncontrolled memory allocation.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.257276">CVE-2024-2613</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Password Reset #infosecnews #podcast #cybersecurity #infosec #podcastclips]]></title>
<description><![CDATA[Author: Black Hills Information Security - Bewertung: 51x - Views:2613 ///Black Hills Infosec Socials
Twitter: https://twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: https://www.linkedin.com/company/antisyphon-training
Discord: https://discord.gg/ffzdt3...]]></description>
<link>https://tsecurity.de/de/2136891/it-security-video/gitlab-password-reset-infosecnews-podcast-cybersecurity-infosec-podcastclips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2136891/it-security-video/gitlab-password-reset-infosecnews-podcast-cybersecurity-infosec-podcastclips/</guid>
<pubDate>Mon, 06 May 2024 15:59:41 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/Usibe-3-xZk/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Black Hills Information Security - Bewertung: 51x - Views:2613 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Usibe-3-xZk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>///Black Hills Infosec Socials
Twitter: https://twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: https://www.linkedin.com/company/antisyphon-training
Discord: https://discord.gg/ffzdt3WUDe

///Black Hills Infosec Shirts & Hoodies
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections

///Black Hills Infosec Services
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/
Penetration Testing: https://www.blackhillsinfosec.com/services/
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/

///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: https://www.backdoorsandbreaches.com/
Play B&B Online: https://play.backdoorsandbreaches.com/

///Antisyphon Training
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/
Live Training: https://www.antisyphontraining.com/course-catalog/
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/
Antisyphon Discord: https://discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training

///Educational Infosec Content
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/
Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining
Active Countermeasures YouTube: https://youtube.com/activecountermeasures
Threat Hunter Community Discord: https://discord.gg/threathunter

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Long Term Support Channel Update for ChromeOS]]></title>
<description><![CDATA[LTS-102 has been updated in the LTS channel to 102.0.5005.182 (Platform Version: 14695.135.0) for most ChromeOS devices. Want to know more about Long-term Support? Click here.This update contains multiple Security fixes, including:1340253  Critical CVE-2022-3038 Use after free in Network Service....]]></description>
<link>https://tsecurity.de/de/1651675/it-security-nachrichten/long-term-support-channel-update-for-chromeos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1651675/it-security-nachrichten/long-term-support-channel-update-for-chromeos/</guid>
<pubDate>Wed, 05 Oct 2022 04:18:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span><span color="rgba(0, 0, 0, 0.87)">LTS-102 has been updated in the LTS channel to </span><span>102.0.5005.182 </span><span color="rgba(0, 0, 0, 0.87)">(Platform Version: </span><span>14695.135.0</span><span>) for most ChromeOS devices. Want to know more about Long-term Support? Click </span><a href="https://support.google.com/chrome/a/answer/11333726">here</a><span>.</span></span></p><p><span><br></span></p><div><span>This update contains multiple Security fixes, including:</span></div><div><span><br></span></div><div><span><span><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1340253",1340253)' data-sheets-hyperlink="https://crbug.com/1340253" data-sheets-value='{"1":3,"3":1340253}'><a class="in-cell-link" href="https://crbug.com/1340253" target="_blank">1340253</a> </span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1340253",1340253)' data-sheets-hyperlink="https://crbug.com/1340253" data-sheets-value='{"1":3,"3":1340253}'> </span></span>Critical CVE-2022-3038 Use after free in Network Service.</span></span></div><div><span><span><span><a class="in-cell-link" href="https://crbug.com/1051198" target="_blank">1051198</a>  </span></span><span>High <span data-sheets-userformat='{"2":513,"3":{"1":0},"12":0}' data-sheets-value='{"1":2,"2":"CVE-2022-3044"}'>CVE-2022-3044</span>: <span data-sheets-userformat='{"2":10753,"3":{"1":0},"12":0,"14":{"1":2,"2":6710886},"16":10}' data-sheets-value='{"1":2,"2":"Inappropriate implementation in Site Isolation"}'>Inappropriate implementation in Site Isolation</span>.</span><span> </span></span></div><div><span><span><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1355103",1355103)' data-sheets-hyperlink="https://crbug.com/1355103" data-sheets-value='{"1":3,"3":1355103}'><a class="in-cell-link" href="https://crbug.com/1355103" target="_blank">1355103</a>  </span></span></span><span>High </span><span>CVE-2022-3200 </span><span>Heap buffer overflow in Internals</span></span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1343104",1343104)' data-sheets-hyperlink="https://crbug.com/1343104" data-sheets-value='{"1":3,"3":1343104}'><a class="in-cell-link" href="https://crbug.com/1343104" target="_blank">1343104</a>  </span><span>High </span><span>CVE-2022-3201 </span><span>Insufficient validation of untrusted input in DevTools</span></span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1345947",1345947)' data-sheets-hyperlink="https://crbug.com/1345947" data-sheets-value='{"1":3,"3":1345947}'><a class="in-cell-link" href="https://crbug.com/1345947" target="_blank">1345947</a> </span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1345947",1345947)' data-sheets-hyperlink="https://crbug.com/1345947" data-sheets-value='{"1":3,"3":1345947}'> </span><span>High </span><span>CVE-2022-3041 </span><span>Use after free in WebSQL</span></span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1336979",1336979)' data-sheets-hyperlink="https://crbug.com/1336979" data-sheets-value='{"1":3,"3":1336979}'><a class="in-cell-link" href="https://crbug.com/1336979" target="_blank">1336979</a>  </span><span>High </span><span>CVE-2022-3043 </span><span>Heap buffer overflow in Screen Capture.</span></span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1341918",1341918)' data-sheets-hyperlink="https://crbug.com/1341918" data-sheets-value='{"1":3,"3":1341918}'><a class="in-cell-link" href="https://crbug.com/1341918" target="_blank">1341918</a> </span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1341918",1341918)' data-sheets-hyperlink="https://crbug.com/1341918" data-sheets-value='{"1":3,"3":1341918}'> </span>High CVE-2022-2858 <span>Use after free in Sign-In Flow</span></span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1325256",1325256)' data-sheets-hyperlink="https://crbug.com/1325256" data-sheets-value='{"1":3,"3":1325256}'><a class="in-cell-link" href="https://crbug.com/1325256" target="_blank">1325256</a> </span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1325256",1325256)' data-sheets-hyperlink="https://crbug.com/1325256" data-sheets-value='{"1":3,"3":1325256}'> </span>Medium CVE-2022-2613 Use after free in Input</span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1345245",1345245)' data-sheets-hyperlink="https://crbug.com/1345245" data-sheets-value='{"1":3,"3":1345245}'><a class="in-cell-link" href="https://crbug.com/1345245" target="_blank">1345245</a>  </span>Medium CVE-2022-3051 Heap buffer overflow in Exosphere</span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1346154",1346154)' data-sheets-hyperlink="https://crbug.com/1346154" data-sheets-value='{"1":3,"3":1346154}'><a class="in-cell-link" href="https://crbug.com/1346154" target="_blank">1346154</a>  </span>Medium CVE-2022-3052 Heap buffer overflow in Ash</span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1337132",1337132)' data-sheets-hyperlink="https://crbug.com/1337132" data-sheets-value='{"1":3,"3":1337132}'><a class="in-cell-link" href="https://crbug.com/1337132" target="_blank">1337132</a>  </span>Medium CVE-2022-3050 Heap buffer overflow in WebUI</span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1316892",1316892)' data-sheets-hyperlink="https://crbug.com/1316892" data-sheets-value='{"1":3,"3":1316892}'><a class="in-cell-link" href="https://crbug.com/1316892" target="_blank">1316892</a>  </span>Medium CVE-2022-3049 Use after free in SplitScreen</span></div><div><span><span data-sheets-formula='=HYPERLINK("https://crbug.com/1303308",1303308)' data-sheets-hyperlink="https://crbug.com/1303308" data-sheets-value='{"1":3,"3":1303308}'><a class="in-cell-link" href="https://crbug.com/1303308" target="_blank">1303308</a>  </span>Medium CVE-2022-3048 Inappropriate implementation in Chrome OS lockscreen</span></div><div><span><br></span></div><div><div><span><br></span></div><div><span>Giuliana Pritchard</span></div><div><br></div><div><span>Google Chrome OS</span></div></div><div><span data-sheets-userformat='{"2":10753,"3":{"1":0},"12":0,"14":{"1":2,"2":-570425344},"16":10}' data-sheets-value='{"1":2,"2":"Use after free in Sign-In Flow"}'>Use after free in Sign-In Flow</span><span> se after free in Sign-In Flow</span><span>Use after free in Sign-In Flo</span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-2613 | Google Chrome prior 104.0.5112.79 Input use after free]]></title>
<description><![CDATA[A vulnerability has been found in  Google Chrome and classified as critical. This vulnerability affects unknown code of the component Input. The manipulation leads to use after free.

This vulnerability was named CVE-2022-2613. The attack can be initiated remotely. There is no exploit available.
...]]></description>
<link>https://tsecurity.de/de/1627199/sicherheitsluecken/cve-2022-2613-google-chrome-prior-1040511279-input-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1627199/sicherheitsluecken/cve-2022-2613-google-chrome-prior-1040511279-input-use-after-free/</guid>
<pubDate>Sun, 11 Sep 2022 10:49:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in  Google Chrome and classified as critical. This vulnerability affects unknown code of the component <em>Input</em>. The manipulation leads to use after free.

This vulnerability was named <a href="https://vuldb.com/?source_cve.206374">CVE-2022-2613</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-2613]]></title>
<description><![CDATA[Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.]]></description>
<link>https://tsecurity.de/de/1600245/sicherheitsluecken/cve-2022-2613/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1600245/sicherheitsluecken/cve-2022-2613/</guid>
<pubDate>Sat, 13 Aug 2022 01:04:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Promotion for ChromeOS]]></title>
<description><![CDATA[Hello All,The Stable channel is being updated to 104.0.5112.83 (Platform version: 14909.100.0) for most ChromeOS devices and will be rolled out over the next few days.For Chrome browser fixes, see the Chrome Desktop release announcement.If you find new issues, please let us know one of the follow...]]></description>
<link>https://tsecurity.de/de/1592024/it-security-nachrichten/stable-channel-promotion-for-chromeos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1592024/it-security-nachrichten/stable-channel-promotion-for-chromeos/</guid>
<pubDate>Fri, 05 Aug 2022 00:48:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span color="rgba(0, 0, 0, 0.870588235294118)"><span>Hello All,</span></span></p><p><span color="rgba(0, 0, 0, 0.870588235294118)"><span><br></span></span></p><p><span><span color="rgba(0, 0, 0, 0.870588235294118)">The Stable channel is being updated to </span>104.0.5112.83<span color="rgba(0, 0, 0, 0.870588235294118)"> (Platform version: </span><span color="rgba(0, 0, 0, 0.870588235294118)">14909.100.0</span><span color="rgba(0, 0, 0, 0.870588235294118)">) for most ChromeOS devices and will be rolled out over the next few days.</span></span></p><p><span><span color="rgba(0, 0, 0, 0.87)">For Chrome browser fixes, see the </span><a href="https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html"><span>Chrome Desktop release announcement</span></a><span color="rgba(0, 0, 0, 0.870588235294118)"><span>.</span></span></span></p><p><span>If you find new issues, please let us know one of the following ways:</span></p><div><ul><li><span><a href="https://bugs.chromium.org/p/chromium/issues/list">File a bug</a> </span></li><li><span>Visit our Chrome OS communities</span></li><ul><li><span>General: <a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central">Chromebook Help Community</a></span></li><li><span>Beta Specific: <a href="https://support.google.com/chromeos-beta/community">ChromeOS Beta Help Community</a></span></li></ul><li><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span>Report an issue or send feedback on Chrome</span></a></li></ul></div><div><span color="rgba(0, 0, 0, 0.87)"><span><span color="rgba(0, 0, 0, 0.87)">Interested in switching channels? </span><a href="https://support.google.com/chromebook/answer/1086915">Find out how</a><span color="rgba(0, 0, 0, 0.87)">.</span></span></span></div><div><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span><br></span></span></span></div><div><span color="rgba(0, 0, 0, 0.87)"><span><p><span color="rgba(0, 0, 0, 0.870588235294118)">Please see the bug fixes and security updates:</span></p><p dir="ltr"><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed</span></p><p><span>[</span><a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1338560&amp;q=Type%3DBug-Security%20label%3ARelease-0-M104%20OS%3DChrome%2CLacros%20-OS%3DWindows%2CMac%2CLinux%2CiOS%2CFuchsia%20-is%3Aopen&amp;can=1"><span>1338560</span></a><span>] High CVE-2022-2609: Use after free in NearbyShare Reported by </span><span>koocola(@alo_cook) and Guang Gong of 360 Vulnerability Research Institute </span><span>on Wed, Jun 22, 2022</span></p><p dir="ltr"><span>[</span><a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1337304&amp;q=Type%3DBug-Security%20label%3ARelease-0-M104%20OS%3DChrome%2CLacros%20-OS%3DWindows%2CMac%2CLinux%2CiOS%2CFuchsia%20-is%3Aopen&amp;can=1"><span>1337304</span></a><span>] Medium CVE-2022-2620: Use after free in WebUI Reported by Nan Wang(@eternalsakura13) and Guang Gong of 360 Vulnerability Research Institute on Fri, Jun 17, 2022</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>[</span><a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1330775&amp;q=Type%3DBug-Security%20label%3ARelease-0-M104%20OS%3DChrome%2CLacros%20-OS%3DWindows%2CMac%2CLinux%2CiOS%2CFuchsia%20-is%3Aopen&amp;can=1"><span>1330775</span></a><span>] High CVE-2022-2608: Use after free in Ash Reported by Khalil </span><span>Zhani </span><span>on Wed, Jun 1, 2022</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>[</span><a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1325256&amp;q=Type%3DBug-Security%20label%3ARelease-0-M104%20OS%3DChrome%2CLacros%20-OS%3DWindows%2CMac%2CLinux%2CiOS%2CFuchsia%20-is%3Aopen&amp;can=1"><span>1325256</span></a><span>] Medium CVE-2022-2613: Use after free in Gesture Process Reported by Piotr Tworek, Vewd Software on Fri, May 13, 2022</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>[</span><a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1319172&amp;q=Type%3DBug-Security%20label%3ARelease-0-M104%20OS%3DChrome%2CLacros%20-OS%3DWindows%2CMac%2CLinux%2CiOS%2CFuchsia%20-is%3Aopen&amp;can=1"><span>1319172</span></a><span>] High CVE-TBD: Use after free in Exosphere Reported by </span><span>@ginggilBesel</span><span> on Sun, Apr 24, 2022</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>[</span><a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1316960&amp;q=Type%3DBug-Security%20label%3ARelease-0-M104%20OS%3DChrome%2CLacros%20-OS%3DWindows%2CMac%2CLinux%2CiOS%2CFuchsia%20-is%3Aopen&amp;can=1"><span>1316960</span></a><span>] High CVE-TBD: </span><span>Use after free in Window Manger</span><span> by Rheza Shan on Sun, Apr 17, 2022</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>[</span><a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1286203&amp;q=Type%3DBug-Security%20label%3ARelease-0-M104%20OS%3DChrome%2CLacros%20-OS%3DWindows%2CMac%2CLinux%2CiOS%2CFuchsia%20-is%3Aopen&amp;can=1"><span>1286203</span></a><span>] High CVE-2022-2607: Use after free in WebUI Reported by </span><span>@ginggilBese </span><span>on Tue, Jan 11, 2022</span></p></span></span></div><div><span><span color="rgba(0, 0, 0, 0.87)"><br></span><span color="rgba(0, 0, 0, 0.87)"><br><br></span><span color="rgba(0, 0, 0, 0.87)">Google ChromeOS.</span></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Chrome team is delighted to announce the promotion of Chrome 104 to the stable channel for Windows, Mac and Linux.Chrome 104 is also promoted to our new extended stable channel for Windows and Mac. This will roll out over the coming days/weeks.Chrome 104.0.5112.79 ( Mac/linux) and 104.0.5112....]]></description>
<link>https://tsecurity.de/de/1589571/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1589571/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Tue, 02 Aug 2022 20:48:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span color="rgba(0, 0, 0, 0.87)"><span>The Chrome team is delighted to announce the promotion of Chrome 104 to the stable channel for Windows, Mac and Linux.Chrome 104 is also promoted to our new </span><a href="https://chromium.googlesource.com/chromium/src/+/refs/heads/main/docs/process/release_cycle.md" target="_blank">extended stable</a><span> channel for Windows and Mac. </span></span><span>This will roll out over the coming days/weeks.</span></p><br><span color="rgba(0, 0, 0, 0.87)"><span face="roboto, sans-serif"><br></span><span face="arial, helvetica, sans-serif"><span>Chrome 104.0.5112.79 ( Mac/linux) and </span></span></span><span>104.0.5112.79/80/81 ( Windows) </span><span color="rgba(0, 0, 0, 0.87)"><span face="arial, helvetica, sans-serif"><span> contains a number of fixes and improvements -- a list of changes is available in the</span><a href="https://chromium.googlesource.com/chromium/src/+log/103.0.5060.134..104.0.5112.81?pretty=fuller&amp;n=10000"> log</a><span>. Watch out for upcoming</span><a href="https://chrome.blogspot.com/"> </a><a href="https://chrome.blogspot.com/">Chrome</a><span> and</span><a href="https://blog.chromium.org/"> Chromium</a><span> blog posts about new features and big efforts delivered in 104.</span></span></span><div><span color="rgba(0, 0, 0, 0.87)"><span face="arial, helvetica, sans-serif"><span><br></span></span></span></div><div><div><span face="arial, helvetica, sans-serif"><p dir="ltr"><span><span>Security Fixes and Rewards</span></span></p><p dir="ltr"><span><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed</span></span></p><span><br><br><br><span>This update includes <a href="https://bugs.chromium.org/p/chromium/issues/list?can=1&amp;q=type%3Abug-security+os%3DAndroid%2Cios%2Clinux%2Cmac%2Cwindows%2Call%2Cchrome+label%3ARelease-0-M104">27</a> security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the <a href="https://sites.google.com/a/chromium.org/dev/Home/chromium-security">Chrome Security Page</a> for more information.<br><br><br>[$15000][<a href="https://crbug.com/1325699">1325699</a>] High CVE-2022-2603: Use after free in Omnibox. Reported by Anonymous on 2022-05-16<br><br>[$10000][<a href="https://crbug.com/1335316">1335316</a>] High CVE-2022-2604: Use after free in Safe Browsing. Reported by Nan Wang(@eternalsakura13) and Guang Gong of 360 Alpha Lab  on 2022-06-10<br><br>[$7000][<a href="https://crbug.com/1338470">1338470</a>] High CVE-2022-2605: Out of bounds read in Dawn. Reported by Looben Yang on 2022-06-22<br><br>[$5000][<a href="https://crbug.com/1330489">1330489</a>] High CVE-2022-2606: Use after free in Managed devices API. Reported by Nan Wang(@eternalsakura13) and Guang Gong of 360 Alpha Lab  on 2022-05-31<br><br>[$3000][<a href="https://crbug.com/1286203">1286203</a>] High CVE-2022-2607: Use after free in Tab Strip. Reported by @ginggilBesel on 2022-01-11<br><br>[$3000][<a href="https://crbug.com/1330775">1330775</a>] High CVE-2022-2608: Use after free in Overview Mode. Reported by Khalil Zhani on 2022-06-01<br><br>[$TBD][<a href="https://crbug.com/1338560">1338560</a>] High CVE-2022-2609: Use after free in Nearby Share. Reported by koocola(@alo_cook) and Guang Gong of 360 Vulnerability Research Institute on 2022-06-22<br><br>[$8000][<a href="https://crbug.com/1278255">1278255</a>] Medium CVE-2022-2610: Insufficient policy enforcement in Background Fetch. Reported by Maurice Dauer on 2021-12-09<br><br>[$5000][<a href="https://crbug.com/1320538">1320538</a>] Medium CVE-2022-2611: Inappropriate implementation in Fullscreen API. Reported by Irvan Kurniawan (sourc7) on 2022-04-28<br><br>[$5000][<a href="https://crbug.com/1321350">1321350</a>] Medium CVE-2022-2612: Side-channel information leakage in Keyboard input. Reported by Erik Kraft (erik.kraft5@gmx.at), Martin Schwarzl (martin.schwarzl@iaik.tugraz.at) on 2022-04-30<br><br>[$5000][<a href="https://crbug.com/1325256">1325256</a>] Medium CVE-2022-2613: Use after free in Input. Reported by Piotr Tworek (Vewd) on 2022-05-13<br><br>[$5000][<a href="https://crbug.com/1341907">1341907</a>] Medium CVE-2022-2614: Use after free in Sign-In Flow. Reported by raven at KunLun lab on 2022-07-05<br><br>[$4000][<a href="https://crbug.com/1268580">1268580</a>] Medium CVE-2022-2615: Insufficient policy enforcement in Cookies. Reported by Maurice Dauer  on 2021-11-10<br><br>[$3000][<a href="https://crbug.com/1302159">1302159</a>] Medium CVE-2022-2616: Inappropriate implementation in Extensions API. Reported by Alesandro Ortiz on 2022-03-02<br><br>[$2000][<a href="https://crbug.com/1292451">1292451</a>] Medium CVE-2022-2617: Use after free in Extensions API. Reported by @ginggilBesel on 2022-01-31<br><br>[$2000][<a href="https://crbug.com/1308422">1308422</a>] Medium CVE-2022-2618: Insufficient validation of untrusted input in Internals. Reported by asnine on 2022-03-21<br><br>[$2000][<a href="https://crbug.com/1332881">1332881</a>] Medium CVE-2022-2619: Insufficient validation of untrusted input in Settings. Reported by Oliver Dunk on 2022-06-04<br><br>[$2000][<a href="https://crbug.com/1337304">1337304</a>] Medium CVE-2022-2620: Use after free in WebUI. Reported by Nan Wang(@eternalsakura13) and Guang Gong of 360 Alpha Lab  on 2022-06-17<br><br>[$1000][<a href="https://crbug.com/1323449">1323449</a>] Medium CVE-2022-2621: Use after free in Extensions. Reported by Huyna at Viettel Cyber Security on 2022-05-07<br><br>[$1000][<a href="https://crbug.com/1332392">1332392</a>] Medium CVE-2022-2622: Insufficient validation of untrusted input in Safe Browsing. Reported by Imre Rad (@ImreRad) and @j00sean on 2022-06-03<br><br>[$1000][<a href="https://crbug.com/1337798">1337798</a>] Medium CVE-2022-2623: Use after free in Offline. Reported by raven at KunLun lab on 2022-06-20<br><br><br><br>[$TBD][<a href="https://crbug.com/1339745">1339745</a>] Medium CVE-2022-2624: Heap buffer overflow in PDF. Reported by YU-CHANG CHEN and CHIH-YEN CHANG, working with DEVCORE Internship Program on 2022-06-27</span></span><div><span><br></span></div><p dir="ltr"><span><span><br></span></span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span><span><br></span><span><br></span><span>As usual, our ongoing internal security work was responsible for a wide range of fixes:</span></span></p><ul><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span><span>[</span><a href="https://crbug.com/1251653"><span>1251653</span></a><span>] Various fixes from internal audits, fuzzing and other initiatives</span></span></p></li></ul><p dir="ltr"><span><br></span></p><p dir="ltr"><span><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://sites.google.com/a/chromium.org/dev/developers/testing/control-flow-integrity"><span>Control Flow Integrity</span></a><span>, </span><a href="https://sites.google.com/a/chromium.org/dev/developers/testing/libfuzzer"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></span></p><p dir="ltr"><span><br><span>Interested in switching release channels?  Find out how </span><a href="https://www.chromium.org/getting-involved/dev-channel"><span>here</span></a><span>. If you find a new issue, please let us know by </span><a href="https://crbug.com/"><span>filing a bug</span></a><span>. </span><span>The </span><a href="https://support.google.com/chrome/community"><span>community help forum</span></a><span> is also a great place to reach out for help or learn about common issues.</span></span></p></span></div><div><div dir="ltr"><span><span face="arial, helvetica, sans-serif"></span><br></span></div><div><span face="arial, helvetica, sans-serif"><br><br></span></div><div><span>Srinivas Sista</span></div><div><span>Google Chrome</span></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Akuvox C315 115.116.2613 cfgd_server Service command injection]]></title>
<description><![CDATA[A vulnerability was found in Akuvox C315 115.116.2613. It has been classified as critical. Affected is some unknown functionality of the component cfgd_server Service. It is possible to mitigate the weakness by firewalling .]]></description>
<link>https://tsecurity.de/de/1456738/sicherheitsluecken/akuvox-c315-1151162613-cfgdserver-service-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1456738/sicherheitsluecken/akuvox-c315-1151162613-cfgdserver-service-command-injection/</guid>
<pubDate>Thu, 29 Apr 2021 15:04:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.akuvox:c315">Akuvox C315 115.116.2613</a>. It has been classified as critical. Affected is some unknown functionality of the component <em>cfgd_server Service</em>. It is possible to mitigate the weakness by firewalling .]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-31726]]></title>
<description><![CDATA[Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).]]></description>
<link>https://tsecurity.de/de/1451063/sicherheitsluecken/cve-2021-31726/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1451063/sicherheitsluecken/cve-2021-31726/</guid>
<pubDate>Sun, 25 Apr 2021 22:17:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).]]></content:encoded>
</item>
<item>
<title><![CDATA[CentOS Blog: CentOS Community newsletter, July 2020 (#2007)]]></title>
<description><![CDATA[Dear CentOS enthusiasts,
Thanks for coming back for another edition of the CentOS community newsletter.
News
8.2.2004 release
We are pleased to announce the general availability of CentOS Linux 8.2.2004. Effectively immediately, this is the current release for CentOS Linux 8 and is tagged as 2004...]]></description>
<link>https://tsecurity.de/de/1170665/unix-server/centos-blog-centos-community-newsletter-july-2020-2007/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1170665/unix-server/centos-blog-centos-community-newsletter-july-2020-2007/</guid>
<pubDate>Tue, 07 Jul 2020 04:30:53 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Dear CentOS enthusiasts,</span></p>
<p><span>Thanks for coming back for another edition of the CentOS community newsletter.</span></p>
<h2>News</h2>
<h3><b>8.2.2004 release</b></h3>
<p><span>We are pleased to announce the general availability of CentOS Linux 8.2.2004. </span><span>Effectively immediately, this is the current release for CentOS Linux 8 </span><span>and is tagged as 2004, derived from Red Hat Enterprise Linux 8.2 Source Code.</span></p>
<p><span>As always, read through the Release Notes at : </span><a href="http://wiki.centos.org/Manuals/ReleaseNotes/CentOS8.2004"><span>http://wiki.centos.org/Manuals/ReleaseNotes/CentOS8.2004</span></a><span>  - these notes </span><span>contain important information about the release and details about some </span><span>of the content inside the release from the CentOS QA team. These notes </span><span>are updated constantly to include issues and incorporate feedback from </span><span>the users.</span></p>
<p><span>More information at </span><a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035756.html"><span>https://lists.centos.org/pipermail/centos-announce/2020-June/035756.html</span></a></p>
<p><span>You can track the status of upcoming 7.x and 8.x releases at  </span><a href="https://wiki.centos.org/About/Building_7"><span>https://wiki.centos.org/About/Building_7</span></a><span> and </span><a href="https://wiki.centos.org/About/Building_8"><span>https://wiki.centos.org/About/Building_8</span></a><span> respectively</span></p>
<h3><b>centos.org refresh</b></h3>
<p><span>With a great deal of help from community members Fabian Arrotin and Alain Reguera Delgado, we are proud to announce our new centos.org website, which you can see today at </span><a href="https://centos.org/"><span>https://centos.org/</span></a><span>   The new site is built using Jekyll - </span><a href="https://jekyllrb.com/"><span>https://jekyllrb.com/</span></a><span> - which makes it easier to contribute to, and easier to build and deploy.</span></p>
<p><span>If you want to contribute patches or changes to the website, that is now done via </span><a href="https://git.centos.org/centos/centos.org"><span>https://git.centos.org/centos/centos.org</span></a><span>  The new workflow makes it easy to test your changes locally, and send pull requests which can be approved and rolled out automatically to the live site.</span></p>
<p><span>Additionally, of course the site design has been refreshed and redesigned, updating the site that was last refreshed in 2013. So a huge thank you in particular to Alain for that work.</span></p>
<h3><b>Board meeting minutes</b></h3>
<p><span>The minutes of the June CentOS Board of Directors meeting may be found on the CentOS Blog at </span><a href="https://blog.centos.org/2020/06/minutes-for-centos-board-of-directors-for-2020-06-10/"><span>https://blog.centos.org/2020/06/minutes-for-centos-board-of-directors-for-2020-06-10/</span></a></p>
<p><span>Highlights include:</span></p>
<p><span>Board Liaison role has passed from Karsten Wade to Brian “bex” Exelbierd, due to his strategic placement in Red Hat’s RHEL business unit. Please welcome bex to the board.</span></p>
<p><span>The Community Architect (currently Rich Bowen) has been added as a permanent invite to board meetings. This is to give you, the community, another way to have your voice heard.</span></p>
<p><span>The Secretary role has passed from Karsten Wade to Thomas Oulevey as part of the regular rotation of that position.</span></p>
<p><span>The July board meeting will be held on July 8th. (it’s always on the second Wednesday of the month.) If you have issues that you need to raise to the board, you are encouraged to open a ticket at </span><a href="https://git.centos.org/centos/board/issues"><span>https://git.centos.org/centos/board/issues</span></a></p>
<h3><b>CPE Updates</b></h3>
<p><span>CPE (Community Platform Engineering) is the group in Red Hat which provides infrastructure support to the CentOS and Fedora projects. Their weekly updates, posted both to the centos-devel mailing list and to the CentOS blog, provide insight into what they’re working on, and what’s coming next.</span></p>
<ul><li><span>June 7 - </span><a href="https://blog.centos.org/2020/06/cpe-weekly-2020-06-07/"><span>https://blog.centos.org/2020/06/cpe-weekly-2020-06-07/</span></a></li>
<li><span>June 14 - </span><a href="https://blog.centos.org/2020/06/cpe-weekly-2020-06-14/"><span>https://blog.centos.org/2020/06/cpe-weekly-2020-06-14/</span></a></li>
<li><span>June 21 - </span><a href="https://blog.centos.org/2020/06/cpe-weekly-2020-06-21/"><span>https://blog.centos.org/2020/06/cpe-weekly-2020-06-21/</span></a></li>
<li><span>June 28 - </span><a href="https://blog.centos.org/2020/06/cpe-weekly-2020-06-28/"><span>https://blog.centos.org/2020/06/cpe-weekly-2020-06-28/</span> </a></li>
</ul><p><span>To learn more about what CPE is doing, come to the CPE office hours, every other Tuesday at 15:00 UTC on the #centos-meeting IRC channel, on Freenode.</span></p>
<h2>Events</h2>
<p><span>Please plan to join us September 24th and 25th for <a href="http://devconf.us/">DevConf.US</a>, an event for open source developers. The call for presentations is still open for one more day!</span></p>
<h2>Updates</h2>
<h3>Errata and Enhancements Advisories</h3>
<p>We issued the following CEEA (CentOS Errata and Enhancements Advisories) during June:</p>
<ul><li>Thu Jun 25 2020: CEEA-2020:2742 CentOS 6 microcode_ctl Enhancement - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035770.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035770.html</a></li>
<li>Thu Jun 25 2020: CEEA-2020:2743 CentOS 7 microcode_ctl Enhancement - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035771.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035771.html</a></li>
</ul><h3>Errata and Security Advisories</h3>
<p>We issued the following CESA (CentOS Errata and Security Advisories) during June:</p>
<ul><li>Mon Jun 1 2020: CESA-2020:2334 Important CentOS 7 freerdp Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035742.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035742.html</a></li>
<li>Mon Jun 1 2020: CESA-2020:2337 Important CentOS 7 git Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035743.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035743.html</a></li>
<li>Mon Jun 1 2020: CESA-2020:2344 Important CentOS 7 bind Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035744.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035744.html</a></li>
<li>Thu Jun 4 2020: CESA-2020:2381 Important CentOS 7 firefox Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035746.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035746.html</a></li>
<li>Thu Jun 4 2020: CESA-2020:2378 Important CentOS 6 firefox Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035747.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035747.html</a></li>
<li>Thu Jun 4 2020: CESA-2020:2383 Important CentOS 6 bind Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035748.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035748.html</a></li>
<li>Thu Jun 4 2020: CESA-2020:2406 Important CentOS 6 freerdp Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035749.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035749.html</a></li>
<li>Tue Jun 9 2020: CESA-2020:2414 Important CentOS 7 unbound Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035750.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035750.html</a></li>
<li>Tue Jun 9 2020: CESA-2020:2414 Important CentOS 7 unbound Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035751.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035751.html</a></li>
<li>Wed Jun 10 2020: CESA-2020:2433 Moderate CentOS 6 microcode_ctl Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035752.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035752.html</a></li>
<li>Wed Jun 10 2020: CESA-2020:2430 Moderate CentOS 6 kernel Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035753.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035753.html</a></li>
<li>Wed Jun 10 2020: CESA-2020:2432 Moderate CentOS 7 microcode_ctl Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035754.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035754.html</a></li>
<li>Thu Jun 11 2020: CESA-2020:2530 Important CentOS 7 tomcat Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035755.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035755.html</a></li>
<li>Tue Jun 16 2020: CESA-2020:2549 Moderate CentOS 7 libexif Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035757.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035757.html</a></li>
<li>Fri Jun 19 2020: CESA-2020:2615 Important CentOS 7 thunderbird Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035758.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035758.html</a></li>
<li>Fri Jun 19 2020: CESA-2020:2613 Important CentOS 6 thunderbird Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035759.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035759.html</a></li>
<li>Tue Jun 23 2020: CESA-2020:2642 Important CentOS 7 unbound Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035766.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035766.html</a></li>
<li>Tue Jun 23 2020: CESA-2020:2663 Moderate CentOS 7 ntp Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035768.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035768.html</a></li>
<li>Tue Jun 23 2020: CESA-2020:2664 Important CentOS 7 kernel Security - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035769.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035769.html</a></li>
</ul><h3>Errata and Bugfix Advisories</h3>
<p>We issued the following CEBA (CentOS Errata and Bugfix Advisories) during June:</p>
<ul><li>Thu Jun 4 2020: CEBA-2020:2355 CentOS 7 kernel BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035745.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035745.html</a></li>
<li>Tue Jun 23 2020: CEBA-2020:2656 CentOS 7 net-snmp BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035760.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035760.html</a></li>
<li>Tue Jun 23 2020: CEBA-2020:2658 CentOS 7 resource-agents BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035761.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035761.html</a></li>
<li>Tue Jun 23 2020: CEBA-2020:2660 CentOS 7 rsyslog BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035762.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035762.html</a></li>
<li>Tue Jun 23 2020: CEBA-2020:2657 CentOS 7 fence-agents BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035763.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035763.html</a></li>
<li>Tue Jun 23 2020: CEBA-2020:2666 CentOS 7 ca-certificates BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035764.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035764.html</a></li>
<li>Tue Jun 23 2020: CEBA-2020:2655 CentOS 7 ncompress BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035765.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035765.html</a></li>
<li>Tue Jun 23 2020: CEBA-2020:2654 CentOS 7 cloud-init BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035767.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035767.html</a></li>
<li>Tue Jun 30 2020: CEBA-2020:2662 CentOS 7 selinux-policy BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035772.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035772.html</a></li>
<li>Tue Jun 30 2020: CEBA-2020:2659 CentOS 7 systemd BugFix - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035773.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035773.html</a></li>
</ul><h3>Other releases</h3>
<p>The following releases also happened during June:</p>
<ul><li>Mon Jun 15 2020: Release for CentOS Linux 8 (2004) - <a href="https://lists.centos.org/pipermail/centos-announce/2020-June/035756.html">https://lists.centos.org/pipermail/centos-announce/2020-June/035756.html</a></li>
</ul><h2>CentOS Stream</h2>
<p>We've done a lot of work over the past few weeks to keep up to date with Red Hat Enterprise Linux Development. Currently Red Hat is in the middle of the development cycle for the upcoming RHEL 8.3, and you should be seeing some content from 8.3 reflected in CentOS Stream. Expect to see more content coming through as we add more modules. There is an updated installer and refreshed install media on the mirrors for you to try right now!</p>
<h3>RealTime in CentOS Stream</h3>
<p>One major addition to CentOS Stream is the RealTime (RT) repository. This is a set of packages that is developed alongside Red Hat Enterprise Linux, focused on latency-sensitive workloads. Because these packages are developed so closely with a given RHEL release, it makes perfect sense to include these packages in and gather feedback from CentOS Stream. The packages in the RealTime repository represent what's coming in the Red Hat Enterprise Linux for Real Time addon for RHEL 8.3.</p>
<p>You can see the documentation for Red Hat Enterprise Linux for Real Time here:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux_for_real_time/8/html/installation_guide/index">https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux_for_real_time/8/html/installation_guide/index</a></p>
<p>To enable this repository on your system, make sure you have a fresh install of CentOS Stream or `dnf update` to be sure you have the latest `centos-release-stream package` and enable the `Stream-RT` repository</p>
<p>Yum repo files are located in: `/etc/yum.repos.d/CentOS-Stream-RT.repo`</p>
<p>As always, bugs can be reported against the CentOS Stream version in bugzilla: <a href="https://bugzilla.redhat.com/enter_bug.cgi?product=Red%20Hat%20Enterprise%20Linux%208&amp;version=CentOS%20Stream">https://bugzilla.redhat.com/enter_bug.cgi?product=Red%20Hat%20Enterprise%20Linux%208&amp;version=CentOS%20Stream</a></p>
<h2>SIG Reports</h2>
<h3>Software Collections SIG Report</h3>
<h3><span> Membership update</span></h3>
<p><span>We are always looking for new members. </span><span>However, no changes in membership happened in the last six months.</span></p>
<p><span>Process changes and releases</span></p>
<ol><li><span> The SIG started to reap benefits of the new, streamlined process </span>of releasing packages from the CentOS build system. As a consequence, packages successfully build in CBS should be now coming to you with less bureaucracy.</li>
</ol><p><span>    However, this move required changes in the release CI.</span><span> Although most of the associated issues are now resolved,</span><span> there are still some kinks to iron out as we go along.</span></p>
<ol start="2"><li><span> The Red Hat Software Collections 3.5 were sucessfully rebuilt</span> and should be presently available in the testing (buildlogs) repository. Due to the changes mentioned in the previous point, not all of the collections reached the release repositories (mirrors) yet, but they should be appearing gradually in a few weeks.</li>
</ol><p><span> New collections included in this release are:</span></p>
<p><span>    -   Perl 5.30 (rh-perl530)<br></span><span>    -   Python 3.8 (rh-python38)<br></span><span>    -   Ruby 2.7 (rh-ruby27)</span></p>
<p><span>    Several other existing collections also received updates.</span></p>
<p><span>    For details, please see the <a href="https://access.redhat.com/documentation/en-us/red_hat_software_collections/3/html/3.5_release_notes/index">official release notes</a>.</span></p>
<ol start="3"><li><span> The <a href="https://www.softwarecollections.org/">https://www.softwarecollections.org/</a> website was migrated</span> to run in OpenShift environment. The benefits should include increased availability and stability. As the backend changes necessary were not insignificant, there may be unforeseen new issues still present despite the testing done beforehand. Please do not hesitate to report them to the <a href="https://www.redhat.com/mailman/listinfo/sclorg">sclorg mailing list</a>.</li>
</ol><p><span>Health and activity</span></p>
<p><span>The SIG remains active and tries to respond to any issues raised while </span><span>keeping the official Red Hat collections available and up-to-date on CentOS.</span></p>
<p><span>However, most of the actual work is done by a single person (jstanek). </span><span>More active members would be more than welcome, </span><span>at least in order to increase the bus factor above 1 <img alt="?" class="wp-smiley" src="https://s.w.org/images/core/emoji/12.0.0-1/72x72/1f642.png"></span></p>
<p> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat Security Advisory 2020-2613-01]]></title>
<description><![CDATA[Red Hat Security Advisory 2020-2613-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 68.9.0. Issues addressed include information leakage and use-after-free vulnerabilities.]]></description>
<link>https://tsecurity.de/de/1154308/it-security-tools/red-hat-security-advisory-2020-2613-01/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1154308/it-security-tools/red-hat-security-advisory-2020-2613-01/</guid>
<pubDate>Fri, 19 Jun 2020 20:01:45 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Red Hat Security Advisory 2020-2613-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 68.9.0. Issues addressed include information leakage and use-after-free vulnerabilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat Security Advisory 2018-2613-01]]></title>
<description><![CDATA[Red Hat Security Advisory 2018-2613-01 - Samba is an open-source implementation of the Server Message Block protocol and the related Common Internet File System protocol, which allow PC-compatible machines to share files, printers, and various information. Issues addressed include a null pointer ...]]></description>
<link>https://tsecurity.de/de/367750/it-security-tools/red-hat-security-advisory-2018-2613-01/</link>
<guid isPermaLink="true">https://tsecurity.de/de/367750/it-security-tools/red-hat-security-advisory-2018-2613-01/</guid>
<pubDate>Wed, 05 Sep 2018 18:47:31 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Red Hat Security Advisory 2018-2613-01 - Samba is an open-source implementation of the Server Message Block protocol and the related Common Internet File System protocol, which allow PC-compatible machines to share files, printers, and various information. Issues addressed include a null pointer vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[WikkaWiki 1.1.6.2 Configuration File unknown vulnerability [CVE-2007-2613]]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, was found in WikkaWiki 1.1.6.2. Affected is an unknown function of the component Configuration File.  Upgrading to version 1.1.6.3 eliminates this vulnerability.]]></description>
<link>https://tsecurity.de/de/365269/sicherheitsluecken/wikkawiki-1162-configuration-file-unknown-vulnerability-cve-2007-2613/</link>
<guid isPermaLink="true">https://tsecurity.de/de/365269/sicherheitsluecken/wikkawiki-1162-configuration-file-unknown-vulnerability-cve-2007-2613/</guid>
<pubDate>Fri, 31 Aug 2018 11:22:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as very critical, was found in WikkaWiki 1.1.6.2. Affected is an unknown function of the component <em>Configuration File</em>.  Upgrading to version 1.1.6.3 eliminates this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week's Total Lunar Eclipse Is the Longest of the Century]]></title>
<description><![CDATA[On July 27, the moon is set to glide through Earth's shadow to create a red total lunar eclipse for one hour and 43 minutes -- the longest such eclipse of the young century. Viewers in the United States will have to watch the eclipse online as they're on the wrong side of the world. "Folks in wes...]]></description>
<link>https://tsecurity.de/de/347058/it-security-nachrichten/this-weeks-total-lunar-eclipse-is-the-longest-of-the-century/</link>
<guid isPermaLink="true">https://tsecurity.de/de/347058/it-security-nachrichten/this-weeks-total-lunar-eclipse-is-the-longest-of-the-century/</guid>
<pubDate>Thu, 26 Jul 2018 09:31:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On July 27, the moon is set to glide through Earth's shadow to create a red total lunar eclipse for one hour and 43 minutes -- the longest such eclipse of the young century. Viewers in the United States will have to watch the eclipse online as they're on the wrong side of the world. "Folks in western Africa, part of Europe, the Middle East and India will only have to look up to the sky to catch the deep-copper-toned totality in person," reports The Washington Post. From the report: "What makes the upcoming one special is that it occurs at nearly the same time as the year's second-most-distant lunar apogee (the monthly moment when the moon is most distant from Earth) and the moon passes almost smack through the center of Earth's shadow," astronomer Geoff Chester of the Naval Observatory said. He continued: "This will make it the longest-duration total lunar eclipse of the century. It's also cool that [the eclipse] occurs on the night that Mars reaches opposition, so (for people on the other side of the world) you'll have a red moon six degrees north of the Red Planet." All eclipses belong to eclipse families called saros. In this case, this eclipse is part of Saros 139, and it is No. 38 in a family of 71 that started June 10, 1351. This saros will last until July 24, 2613, per NASA. While technically this will be the longest eclipse of the century, the two previous lunar eclipses in this series -- July 16, 2000 (No. 37, Saros 139) and July 6, 1982 (No. 36, Saros 139) -- lasted longer than this one. In fact, the July 16, 2000, lunar eclipse lasted about three minutes longer. But remember, astronomers count the year 2000 as part of the last century. Throughout the Eastern time zone, according to NASA and the U.S. Naval Observatory, the lunar eclipse (penumbral phase) starts at 1:14 p.m. and partiality occurs at 2:24 p.m. Totality starts at 3:30 p.m., with the maximum totality at 4:21 p.m. Totality will end at 5:13 p.m., and the partial eclipse ends at 6:19 p.m. Everything is over by 7:28 p.m. Unfortunately, the moon will not have risen anywhere in the United States for viewing during this window. If you're not able to watch it locally, you can tune to the Weather Channel app, the website Slooh, or TimeandDate.com. The NBC News streaming network is also showing the eclipse at 4 p.m. on July 27.<p></p>
<div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=This+Week's+Total+Lunar+Eclipse+Is+the+Longest+of+the+Century%3A+http%3A%2F%2Fbit.ly%2F2JSGlgs"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F18%2F07%2F25%2F2330254%2Fthis-weeks-total-lunar-eclipse-is-the-longest-of-the-century%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>

<a class="nobg" href="http://plus.google.com/share?url=https://science.slashdot.org/story/18/07/25/2330254/this-weeks-total-lunar-eclipse-is-the-longest-of-the-century?utm_source=slashdot&amp;utm_medium=googleplus"><img src="https://www.gstatic.com/images/icons/gplus-16.png" alt="Share on Google+"></a>



</div>
<p><a href="https://science.slashdot.org/story/18/07/25/2330254/this-weeks-total-lunar-eclipse-is-the-longest-of-the-century?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Jenkins 2.32.1/2.43 Restart Cross Site Request Forgery]]></title>
<description><![CDATA[Eine problematische Schwachstelle wurde in Jenkins 2.32.1/2.43 entdeckt. Es geht hierbei um eine unbekannte Funktion. Durch Beeinflussen mit einer unbekannten Eingabe kann eine Cross Site Request Forgery-Schwachstelle (Restart) ausgenutzt werden. Klassifiziert wurde die Schwachstelle durch CWE al...]]></description>
<link>https://tsecurity.de/de/312819/sicherheitsluecken/jenkins-2321243-restart-cross-site-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/312819/sicherheitsluecken/jenkins-2321243-restart-cross-site-request-forgery/</guid>
<pubDate>Wed, 16 May 2018 09:18:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p>Eine problematische Schwachstelle wurde in Jenkins 2.32.1/2.43 entdeckt. Es geht hierbei um eine unbekannte Funktion. Durch Beeinflussen mit einer unbekannten Eingabe kann eine Cross Site Request Forgery-Schwachstelle (Restart) ausgenutzt werden. Klassifiziert wurde die Schwachstelle durch CWE als <a href="https://cwe.mitre.org/data/definitions/352.html">CWE-352</a>. Das hat Auswirkungen auf  die Vertraulichkeit. </p>
<p>Die Schwachstelle wurde am 15.05.2018 in Form eines Bug Reports (Bugzilla) veröffentlicht. Das Advisory kann von <a href="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2613">bugzilla.redhat.com</a> heruntergeladen werden. Die Identifikation der Schwachstelle findet seit dem 01.12.2016 als <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2613">CVE-2017-2613</a> statt. Sie gilt als leicht ausnutzbar. Der Angriff kann über das Netzwerk passieren. Das Ausnutzen erfordert keine spezifische Authentisierung. Es sind weder technische Details noch ein Exploit zur Schwachstelle bekannt. </p>
<p>Für den Vulnerability Scanner Nessus wurde am 02.02.2017 ein Plugin mit der ID <a href="https://www.tenable.com/plugins/nessus/96939">96939</a> (FreeBSD : jenkins -- multiple vulnerabilities (5cfa9d0c-73d7-4642-af4f-28fbed9e9404)) herausgegeben, womit die Existenz der Schwachstelle geprüft werden kann. Es wird der Family <em>FreeBSD Local Security Checks</em> zugeordnet und im Kontext local ausgeführt. </p>
<p> Ein Upgrade auf die Version 2.32.2 oder 2.44 vermag dieses Problem zu beheben. Das Erscheinen einer Gegenmassnahme geschah vor und nicht erst nach der Veröffentlichung der Schwachstelle. Die Entwickler haben hiermit vorgängig reagiert.</p>
<p> Mit dieser Schwachstelle verwandte Einträge finden sich unter <a href="https://vuldb.com/?id.116083">116083</a>, <a href="https://vuldb.com/?id.117413">117413</a>, <a href="https://vuldb.com/?id.117414">117414</a> und <a href="https://vuldb.com/?id.117572">117572</a>.</p>
<h2>CVSSv3</h2>
<span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#i2">4.3</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#i3">4.1</a><br><span>VulDB Vector</span>: <a href="https://www.first.org/cvss/specification-document#i6">CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:X</a><br><span>VulDB Zuverlässigkeit</span>: High<br><h2>CVSSv2</h2>
<span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.1">5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.2">4.4 (CVSS2#E:ND/RL:OF/RC:ND)</a><br><span>VulDB Zuverlässigkeit</span>: High<br><br><h2>CPE</h2>
<ul>
<li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Ajenkins%3Ajenkins%3A2.32.1&amp;page_num=0&amp;cid=3">cpe:/a:jenkins:jenkins:2.32.1</a></li>
<li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Ajenkins%3Ajenkins%3A2.43&amp;page_num=0&amp;cid=3">cpe:/a:jenkins:jenkins:2.43</a></li>
</ul>
<h2>Exploiting</h2>
<span>Klasse</span>: Cross Site Request Forgery / Restart (<a href="https://cwe.mitre.org/data/definitions/352.html">CWE-352</a>)<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: gleichbleibend<br><span>Aktuelle Preisschätzung</span>: <span>$0-$5k (0-day) / $0-$5k (Heute)</span><br><br><span>Nessus ID</span>: <a href="https://www.tenable.com/plugins/nessus/96939">96939</a><br><span>Nessus Name</span>: FreeBSD : jenkins -- multiple vulnerabilities (5cfa9d0c-73d7-4642-af4f-28fbed9e9404)<br><span>Nessus File</span>: freebsd_pkg_5cfa9d0c73d74642af4f28fbed9e9404.nasl<br><span>Nessus Risk</span>: Medium<br><span>Nessus Family</span>: FreeBSD Local Security Checks<br><span>Nessus Context</span>: local<br><br><span>OpenVAS ID</span>: 100755<br><span>OpenVAS Name</span>: CloudBees Jenkins Multiple Vulnerability Feb17 - 01 - (Windows)<br><span>OpenVAS File</span>: gb_cloudbees_jenkins_20170201_win.nasl<br><span>OpenVAS Family</span>: Web application abuses<br><br><h2>Gegenmassnahmen</h2>
<span>Empfehlung</span>: Upgrade<br><span>Status</span>: Offizieller Fix<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><br><span>Upgrade</span>: Jenkins 2.32.2/2.44<br><h2>Timeline</h2>
<span>01.12.2016</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2613">CVE zugewiesen</a><br><span>01.02.2017</span>  Gegenmassnahme veröffentlicht<br><span>02.02.2017</span>  <a href="https://www.tenable.com/plugins/nessus/96939">Nessus Plugin veröffentlicht</a><br><span>15.05.2018</span>  <a href="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2613">Advisory veröffentlicht</a><br><span>16.05.2018</span>  <a href="https://vuldb.com/?id.117776">VulDB Eintrag erstellt</a><br><span>16.05.2018</span>  <a href="https://vuldb.com/?id.117776">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2>
<span>Advisory</span>: <a href="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2613">bugzilla.redhat.com</a><br><br><span>CVE</span>: CVE-2017-2613 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2613">(mitre.org)</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2613">(nvd.nist.org)</a> <a href="https://www.cvedetails.com/cve/CVE-2017-2613/">(cvedetails.com)</a><br><span>Siehe auch</span>: <a href="https://vuldb.com/?id.116083">116083</a>, <a href="https://vuldb.com/?id.117413">117413</a>, <a href="https://vuldb.com/?id.117414">117414</a>, <a href="https://vuldb.com/?id.117572">117572</a>, <a href="https://vuldb.com/?id.117769">117769</a>, <a href="https://vuldb.com/?id.117770">117770</a>, <a href="https://vuldb.com/?id.117771">117771</a>, <a href="https://vuldb.com/?id.117772">117772</a>, <a href="https://vuldb.com/?id.117773">117773</a>, <a href="https://vuldb.com/?id.117774">117774</a>, <a href="https://vuldb.com/?id.117775">117775</a><br><h2>Eintrag</h2>
<span>Erstellt</span>: 16.05.2018<br><span>Eintrag</span>: 76% komplett<br>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: Jenkins CVE-2017-2613 Cross Site Request Forgery Vulnerability]]></title>
<description><![CDATA[Jenkins CVE-2017-2613 Cross Site Request Forgery Vulnerability]]></description>
<link>https://tsecurity.de/de/120360/sicherheitsluecken/vuln-jenkins-cve-2017-2613-cross-site-request-forgery-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/120360/sicherheitsluecken/vuln-jenkins-cve-2017-2613-cross-site-request-forgery-vulnerability/</guid>
<pubDate>Thu, 02 Feb 2017 20:04:37 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jenkins CVE-2017-2613 Cross Site Request Forgery Vulnerability]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,02ms -->