🐧 Linux TippsDistribution Release: Grml 2026.09(04.09.2026 um 01:39 Uhr)
🔧 ProgrammierungDistribution Release: Talos Linux 1.14.0(04.09.2026 um 11:06 Uhr)
🐧 Linux TippsDistribution Release: Zenwalk GNU Linux Current-260905(05.09.2026 um 22:05 Uhr)
🔧 AI Nachrichten DistroWatch Weekly, Issue 1189(07.09.2026 um 02:18 Uhr)
🐧 Linux TippsDistroWatch Weekly, Issue 1190(14.09.2026 um 02:11 Uhr)
🐧 Linux TippsSecurity: Denial of Service in perl-Protocol-HTTP2 (Fedora)(15.09.2026 um 07:55 Uhr)
🐧 Linux TippsSecurity: Mangelnde Rechteprüfung in perl-Dancer2 (Fedora)(15.09.2026 um 07:58 Uhr)
🐧 Linux TippsSecurity: Denial of Service in perl-Protocol-HTTP2 (Fedora)(15.09.2026 um 07:58 Uhr)
🐧 Linux TippsDistribution Release: Grml 2026.09(04.09.2026 um 01:39 Uhr)
🔧 ProgrammierungDistribution Release: Talos Linux 1.14.0(04.09.2026 um 11:06 Uhr)
🐧 Linux TippsDistribution Release: Zenwalk GNU Linux Current-260905(05.09.2026 um 22:05 Uhr)
🔧 AI Nachrichten DistroWatch Weekly, Issue 1189(07.09.2026 um 02:18 Uhr)
🐧 Linux TippsDistroWatch Weekly, Issue 1190(14.09.2026 um 02:11 Uhr)
🐧 Linux TippsSecurity: Denial of Service in perl-Protocol-HTTP2 (Fedora)(15.09.2026 um 07:55 Uhr)
🐧 Linux TippsSecurity: Mangelnde Rechteprüfung in perl-Dancer2 (Fedora)(15.09.2026 um 07:58 Uhr)
🐧 Linux TippsSecurity: Denial of Service in perl-Protocol-HTTP2 (Fedora)(15.09.2026 um 07:58 Uhr)

🎥 IT Security Video 🕛 vor 2 Jahren 2 Min Lesezeit CVE-2024-3094
0

Hak5: OWASP Oopsies and Calling XZ What It Is - ThreatWire

Cyber Threat & Vulnerability Dossier CVSS 9.5 CRITICAL (Heuristik) EPSS 89.4%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
Im CVE-Radar öffnen
↗ Quelle (YouTube)
🔬 IoC Intelligence (1 Indikatoren erkannt)
223949d5a074ebc3dce9ee78baad9e27
🗣️ Stimme:
📺
YouTube
17k YouTube-Aufrufe

Author: Hak5 - Bewertung: 56x - Views:479

⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️

Support ThreatWire → https://patreon.com/threatwire

@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

@0xTib3rius
Twitter: https://twitter.com/0xTib3rius
Twitch: https://www.twitch.tv/0xTib3rius
YouTube: https://www.youtube.com/Tib3rius
Everywhere else: https://tib3rius.com/

@TracketPacer
Twitter: https://twitter.com/TracketPacer
YouTube: https://www.youtube.com/c/tracketpacer
TikTok: https://www.tiktok.com/@tracketpacer
Everywhere else: https://www.tracketpacer.com/

[❗] Join the book club on Patreon→ https://patreon.com/threatwire

0:00 Intro
0:11 - Backdoor in XZ-Utils
4:46 - OWASP Oopsies
5:30 - UPDATE: NVD has broken its silence
8:14 - UPDATE: AT&T Finally Admits The L
8:57 - OUTRO

LINKS
🔗 Story 1: Backdoor in XZ-Utils
https://mastodon.social/@AndresFreundTec/112180406142695845
https://www.wiz.io/blog/cve-2024-3094-critical-rce-vulnerability-found-in-xz-utils
https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b
https://www.mail-archive.com/[email protected]/msg00566.html
https://www.openwall.com/lists/oss-security/2024/03/29/4
https://boehs.org/node/everything-i-know-about-the-xz-backdoor#fnref2
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27

🔗 Story 2: OWASP Oopsies
https://twitter.com/owasp/status/1774851614752313460
https://www.bleepingcomputer.com/news/security/owasp-discloses-data-breach-caused-by-wiki-misconfiguration/
https://owasp.org/blog/2024/03/29/OWASP-data-breach-notification.html

🔗 Story 3: UPDATE: NVD has broken its silence
https://www.first.org/conference/vulncon2024/
https://www.infosecurity-magazine.com/news/nist-unveils-new-nvd-consortium/?&web_view=true
https://sos-vo.org/news/nist-unveils-new-consortium-operate-its-national-vulnerability-database
https://nvd.nist.gov/general/news/nvd-program-transition-announcement

🔗 Story 4: UPDATE: AT&T Finally Admits The L
https://www.securityweek.com/att-says-data-on-73-million-customers-leaked-on-dark-web/

____________________________________________

Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Coffee with the Council Podcast: Celebrating 20 Years of Securing Payment Data
1 Quelle
Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
1 Quelle
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten OWASP Oopsies and Calling XZ What It Is - ThreatWire

Thematisch verwandte Begriffe: OWASP, Oopsies, Calling, What · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...