#SecurityAdvisories

Bernhard E. Reiterber@social.tchncs.de
2025-09-25

Want to know how to write and distribute #SecurityAdvisories that can be parsed and processed automatically?

Freshly announced are this years workshops for the Common Security Advisory Framework (#CSAF). They will be held in Nuremberg, Germany, November 10th to 12th.

See csaf.io/workshops/2025/
(right after this are the CSAF Community-Days).

2025-07-02

Unauthenticated RCE in Agorum Core Open!

During their regular security analyses, our pentest professionals from #usdHeroLab examined the open source software #AgorumCoreOpen.

They discovered multiple #vulnerabilities that, when chained together, allow an unauthenticated attacker to achieve full remote code execution with root privileges. This critical flaw enables complete system compromise without prior authentication.

๐Ÿ“ฐ๐Ÿ‘‰ Detailed information on the published #SecurityAdvisories can be found here: usd.de/en/security-advisories-

#Pentest #Pentesting #moresecurity #RCE #CyberSecurity #InfoSec

2025-06-17

๐Ÿ” Our professionals at the usd HeroLab have closely examined the software #Vtiger. They discovered two vulnerabiltiies that allow low-privileged authorized users to upload files and thereby execute arbitrary code.

๐Ÿ‘‰ You can find more information in the full security advisories: usd.de/en/security-advisories-

#SecurityAdvisories #Pentest #Pentesting #moresecurity

2024-09-30

Hereโ€™s a collection of the #SecurityAdvisories that Iโ€™ve published over the years:

github.com/0xdea/advisories

If youโ€™re interested in #VulnerabilityResearch and #ExploitDevelopment, on @github and on the @hnsec blog you can also find a trilogy of talks on these topics that I delivered between 2019 and 2021:

github.com/0xdea/raptor_infilt

github.com/0xdea/raptor_infilt

github.com/0xdea/raptor_romhac

I hope youโ€™ll enjoy them!

Ames :verified: :donor:HillClimber@infosec.exchange
2024-02-27

Does anyone know if it's possible to sign up to get CISA's Directives? I'm already signed up for the daily Advisories and weekly Bulletins, but there are lots of them, and I'd like to get a separate feed of just industry-wide critical responses.
#cisa #incidentresponse #SecurityAdvisories

2023-04-28

๐Ÿ“ข#CVE202237955: The #usdHeroLab analysts identified a vulnerability in Microsoft Windows Group Policy Updates that leads to Improper Link Resolution Before File Access (Privilege Escalation CWE-59)
๐Ÿ‘‡โ€‹๐Ÿ’ปโ€‹
herolab.usd.de/security-adviso

#itsecurity #cve #SecurityAdvisories #zeroday #Microsoft #cybersecurity

2023-04-26

Hello Fediverse! We protect companies against Hacker and Criminals. Our work is as dynamic and diverse as the threat itself. #moresecurity is our mission which underlines every step we take. The exchange of knowledge with the Community is important to us. Because #moresecurity can
reach its full potential with many comrades joining the mission.

Follow us for exciting IT security Content.

#EthicalHacking #Pentesting #SecurityAdvisories #ZeroDayExploits #HackingEvents #CTFs #Compliance #PentestingTools #OpenSourceTools #SecurityAudits #PaymentSecurity

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst