nrw.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Wir sind eine freundliche Mastodon Instanz aus Nordrhein-Westfalen. Ob NRW'ler oder NRW-Sympathifanten, jeder ist hier willkommen.

Serverstatistik:

2,8 Tsd.
aktive Profile

#watchtowr

1 Beitrag1 Beteiligte*r0 Beiträge heute
Pyrzout :vm:<p>Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028) <a href="https://www.helpnetsecurity.com/2025/04/24/critical-commvault-rce-vulnerability-fixed-poc-available-cve-2025-34028/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/04/24</span><span class="invisible">/critical-commvault-rce-vulnerability-fixed-poc-available-cve-2025-34028/</span></a> <a href="https://social.skynetcloud.site/tags/dataprotection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dataprotection</span></a> <a href="https://social.skynetcloud.site/tags/vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vulnerability</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/Commvault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Commvault</span></a> <a href="https://social.skynetcloud.site/tags/WatchTowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WatchTowr</span></a> <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/backup" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>backup</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/PoC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PoC</span></a></p>
Pyrzout :vm:<p>NAKIVO Backup &amp; Replication vulnerability exploited by attackers (CVE-2024-48248) <a href="https://www.helpnetsecurity.com/2025/03/21/nakivo-backup-replication-vulnerability-exploited-by-attackers-cve-2024-48248/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/03/21</span><span class="invisible">/nakivo-backup-replication-vulnerability-exploited-by-attackers-cve-2024-48248/</span></a> <a href="https://social.skynetcloud.site/tags/disasterrecovery" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>disasterrecovery</span></a> <a href="https://social.skynetcloud.site/tags/vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vulnerability</span></a> <a href="https://social.skynetcloud.site/tags/enterprise" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>enterprise</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/WatchTowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WatchTowr</span></a> <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/backup" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>backup</span></a> <a href="https://social.skynetcloud.site/tags/NAKIVO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NAKIVO</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/SMBs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SMBs</span></a> <a href="https://social.skynetcloud.site/tags/MSP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MSP</span></a> <a href="https://social.skynetcloud.site/tags/PoC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PoC</span></a></p>
Pyrzout :vm:<p>Critical Veeam Backup &amp; Replication RCE vulnerability fixed, patch ASAP! (CVE-2025-23120) <a href="https://www.helpnetsecurity.com/2025/03/20/critical-veeam-backup-replication-rce-vulnerability-cve-2025-23120/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/03/20</span><span class="invisible">/critical-veeam-backup-replication-rce-vulnerability-cve-2025-23120/</span></a> <a href="https://social.skynetcloud.site/tags/VeeamSoftware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VeeamSoftware</span></a> <a href="https://social.skynetcloud.site/tags/vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vulnerability</span></a> <a href="https://social.skynetcloud.site/tags/enterprise" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>enterprise</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/WatchTowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WatchTowr</span></a> <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/backup" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>backup</span></a> <a href="https://social.skynetcloud.site/tags/Rapid7" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Rapid7</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/SMBs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SMBs</span></a> <a href="https://social.skynetcloud.site/tags/PoC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PoC</span></a></p>
Pyrzout :vm:<p>Abandoned Amazon S3 Buckets Enabled Attacks Against Governments, Big Firms <a href="https://www.securityweek.com/abandoned-amazon-s3-buckets-enabled-attacks-against-governments-big-firms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">securityweek.com/abandoned-ama</span><span class="invisible">zon-s3-buckets-enabled-attacks-against-governments-big-firms/</span></a> <a href="https://social.skynetcloud.site/tags/ApplicationSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ApplicationSecurity</span></a> <a href="https://social.skynetcloud.site/tags/abandoneddomains" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>abandoneddomains</span></a> <a href="https://social.skynetcloud.site/tags/WatchTowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WatchTowr</span></a> <a href="https://social.skynetcloud.site/tags/AWS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AWS</span></a></p>
Pyrzout :vm:<p>UK domain registry Nominet breached via Ivanti zero-day <a href="https://www.helpnetsecurity.com/2025/01/13/uk-domain-registry-nominet-breached-via-ivanti-zero-day-cve-2025-0282/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/01/13</span><span class="invisible">/uk-domain-registry-nominet-breached-via-ivanti-zero-day-cve-2025-0282/</span></a> <a href="https://social.skynetcloud.site/tags/Shadowserver" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shadowserver</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/WatchTowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WatchTowr</span></a> <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/Mandiant" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mandiant</span></a> <a href="https://social.skynetcloud.site/tags/Nominet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Nominet</span></a> <a href="https://social.skynetcloud.site/tags/Ivanti" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ivanti</span></a> #0-day <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/CISA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CISA</span></a></p>
Netzpalaver<p>Arctic Wolf beobachtet Bedrohungskampagne gegen Firewalls von Palo Alto</p><p><a href="https://social.tchncs.de/tags/ArcticWolf" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ArcticWolf</span></a> <a href="https://social.tchncs.de/tags/ArcticWolfLabs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ArcticWolfLabs</span></a> <a href="https://social.tchncs.de/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://social.tchncs.de/tags/Firewall" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Firewall</span></a> @AWNetworks <a href="https://social.tchncs.de/tags/PaloAltoNetworks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PaloAltoNetworks</span></a> <a href="https://social.tchncs.de/tags/Schwachstelle" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Schwachstelle</span></a> <a href="https://social.tchncs.de/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.tchncs.de/tags/SecurityBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityBreach</span></a> <a href="https://social.tchncs.de/tags/Sicherheitsl%C3%BCcke" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Sicherheitslücke</span></a> <a href="https://social.tchncs.de/tags/Watchtowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Watchtowr</span></a></p><p><a href="https://netzpalaver.de/2024/11/25/arctic-wolf-beobachtet-bedrohungskampagne-gegen-firewalls-von-palo-alto/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">netzpalaver.de/2024/11/25/arct</span><span class="invisible">ic-wolf-beobachtet-bedrohungskampagne-gegen-firewalls-von-palo-alto/</span></a></p>
Pyrzout :vm:<p>PHP command injection flaw exploited to deliver ransomware (CVE-2024-4577) <a href="https://www.helpnetsecurity.com/2024/06/13/cve-2024-4577-exploited/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2024/06/13</span><span class="invisible">/cve-2024-4577-exploited/</span></a> <a href="https://social.skynetcloud.site/tags/vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vulnerability</span></a> <a href="https://social.skynetcloud.site/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/WatchTowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WatchTowr</span></a> <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/Devcore" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Devcore</span></a> <a href="https://social.skynetcloud.site/tags/exploit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>exploit</span></a> <a href="https://social.skynetcloud.site/tags/Imperva" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Imperva</span></a> <a href="https://social.skynetcloud.site/tags/Windows" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Windows</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/CVE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CVE</span></a> <a href="https://social.skynetcloud.site/tags/PHP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PHP</span></a></p>
Tod Beardsley<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@ha888t" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ha888t</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@catc0n" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>catc0n</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@simontsui" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>simontsui</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@ntkramer" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ntkramer</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@serghei" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>serghei</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@dangoodin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dangoodin</span></a></span> </p><p>Heya Ben! Welcome to Mastodon! We're pretty friendly around here.</p><p>Thanks for the clarification that you're not talking about EITW vulns here. That'll be comforting to many.</p><p>And I happen to agree with your notes on not cavalierly releasing PoCs without doing the usual CVD dance, and I'm glad to hear that you'll push disclosure up in the event of patch availability.</p><p>My gripe with the announcement is not so much that watchTowr failed to provide proof, but that the statement of "we know about vulns" is just about the least actionable form of RUMINT around. It makes management freak out, and there's kind of nothing that IT folks can do about it other than set a calendar reminder. In the worst cases, it feels like bullying the responsible vendor, since it puts them on a back foot. It also puts the vendor in a position to have to decide how much to inform customers versus how much to respect confidentiality expectations.</p><p>I far prefer CVD styles that include limited-time embargoes for <em>everything</em>, including the existence of new research being disclosed, validated, and patched. This is the usual norm. I wouldn't implicate vendors, products, projects, or people until I'm ready to put them on the spot with a PoC.</p><p>I'm a fan of the work <a href="https://infosec.exchange/tags/watchTowr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>watchTowr</span></a> puts out. Keep it up. Just try to be a little more kind about it?</p>