uk
Feedback
SysAdmin 24x7

SysAdmin 24x7

Відкрити в Telegram

Noticias y alertas de seguridad informática. Chat y contacto: t.me/sysadmin24x7chat

Показати більше
4 396
Підписники
-224 години
+37 днів
+430 день
Архів дописів
Microsoft Releases Emergency Updates After Breaking Core Features Microsoft has issued a series of emergency out-of-band updates to address serious problems introduced by the January 2026 Patch Tuesday updates. https://www.ghacks.net/2026/01/20/microsoft-releases-emergency-updates-after-broking-core-features/

CVE-2026-23745 Description node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3. https://github.com/isaacs/node-tar/security/advisories/GHSA-8qq5-rm4j-mr97 https://github.com/isaacs/node-tar/commit/340eb285b6d986e91969a1170d7fe9b0face405e

CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal Description A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. https://security.paloaltonetworks.com/CVE-2026-0227

IR Number FG-IR-25-084 Published Date Jan 13, 2026 Component OTHERS Severity High CVSSv3 Score 7.4 Impact Execute unauthorized code or commands CVE ID CVE-2025-25249 https://www.fortiguard.com/psirt/FG-IR-25-084

FG-IR-25-084 Heap-based buffer overflow in cw_acd daemon CVE-2025-25249 Published: Jan 13, 2026 High Severity FG-IR-25-783 SSRF in GUI console CVE-2025-67685 Published: Jan 13, 2026 GUI Low Severity FG-IR-25-783 SSRF in GUI console CVE-2025-67685 Published: Jan 13, 2026 GUI Low Severity https://www.fortiguard.com/psirt

Microsoft - January 2025 Security Updates https://msrc.microsoft.com/update-guide/releaseNote/2026-Jan

Unveiling VoidLink – A Stealthy, Cloud-Native Linux Malware Framework https://research.checkpoint.com/2026/voidlink-the-cloud-native-malware-framework/

n8n Vulnerable to RCE via Arbitrary File Write Impact n8n is affected by an authenticated Remote Code Execution (RCE) vulnerability. Under certain conditions, an authenticated user may be able to cause untrusted code to be executed by the n8n service. This could result in full compromise of the affected instance. Both self-hosted and n8n Cloud instances are impacted. Patches The issue has been resolved in n8n version 1.121.3. Workarounds If upgrading is not immediately possible, administrators can reduce exposure by disabling the Git node and limiting access for untrusted users. https://github.com/advisories/GHSA-v364-rw7m-3263

Security Bulletin: Authentication bypass in IBM API Connect Vulnerability Details CVEID: CVE-2025-13915 DESCRIPTION: IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. CWE: CWE-305: Authentication Bypass by Primary Weakness CVSS Source: IBM CVSS Base score: 9.8 https://www.ibm.com/support/pages/node/7255149

Múltiples vulnerabilidades en routers de D-Link Fecha 30/12/2025 Importancia 4 - Alta Recursos Afectados D-Link DIR-600, hasta 2.15WWb02; D-Link DSL-124 ME_1.00, todas las versiones. Descripción D-Link ha reportado 2 vulnerabilidades de severidad alta que afectan a diversos routers de la marca D-Link y que pueden hacer que un atacante obtenga información de la configuración del router y/o controle las acciones que pueda realizar el dispositivo. https://www.incibe.es/empresas/avisos/multiples-vulnerabilidades-en-routers-de-d-link

CVE-2025-68613 CNA: GitHub, Inc. Base Score: 9.9 CRITICAL Description n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. https://nvd.nist.gov/vuln/detail/CVE-2025-68613

CVE-2025-14847 CNA: MongoDB, Inc. CVSS-B 8.7 HIGH Description Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. https://nvd.nist.gov/vuln/detail/CVE-2025-14847 https://jira.mongodb.org/plugins/servlet/mobile#issue/SERVER-115508 https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-rce-flaw-immediately/

WatchGuard Firebox iked Out of Bounds Write Vulnerability Advisory ID WGSA-2025-00027 CVE CVE-2025-14733 Impact Critical Status Resolved Product Family Firebox Published Date 2025-12-18 Updated Date 2025-12-23 Workaround Available False CVSS Score 9.3 Affected This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3. https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027

Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager Advisory ID: cisco-sa-sma-attack-N9bf4 First Published: 2025 December 17 16:00 GMT Version 1.0: Interim Workarounds: No workarounds available Cisco Bug IDs: CSCws36549 Vulnerable Products This attack campaign affects Cisco Secure Email Gateway, both physical and virtual, and Cisco Secure Email and Web Manager appliances, both physical and virtual, when both of the following conditions are met: The appliance is configured with the Spam Quarantine feature. The Spam Quarantine feature is exposed to and reachable from the internet. The Spam Quarantine feature is not enabled by default. Deployment guides for these products do not require this port to be directly exposed to the Internet. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4

SonicWall SMA1000 appliance local privilege escalation vulnerability Advisory ID SNWLID-2025-0019 First Published 2025-12-17 Last Updated 2025-12-17 Workaround true Status Applicable CVE CVE-2025-40602 CWE CWE-862, CWE-250 CVSS v3 6.6 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019

Boletín de seguridad de Android: diciembre de 2025 Publicado el 1 de diciembre de 2025 | Actualizado el 17 de diciembre de 2025 https://source.android.com/docs/security/bulletin/2025-12-01

Windows Admin Center Elevation of Privilege Vulnerability New Recently updated CVE-2025-64669 Security Vulnerability Released: Dec 9, 2025 Last updated: Dec 11, 2025 Assigning CNA Microsoft CVE.org link CVE-2025-64669  Impact Elevation of Privilege Max Severity Important Weakness CWE-284: Improper Access Control CVSS Source Microsoft Metrics CVSS:3.1 7.8 / 6.8 https://msrc.microsoft.com/update-guide/es-es/vulnerability/CVE-2025-64669

Multiple India-based CCTV Cameras Release DateDecember 09, 2025 Alert CodeICSA-25-343-03 Related topics: Industrial Control System Vulnerabilities, Industrial Control Systems EXECUTIVE SUMMARY CVSS v4 9.3 ATTENTION: Exploitable remotely/Low attack complexity Vendor: D-Link (India Limited), Sparsh Securitech, Securus CCTV Equipment: DCS-F5614-L1 Vulnerability: Missing Authentication for Critical Function RISK EVALUATION Successful exploitation of this vulnerability could result in information disclosure including capture of camera account credentials. https://www.cisa.gov/news-events/ics-advisories/icsa-25-343-03