Skip to content

bentoboxinfosec

many parts make the whole

  • Home
  • Blog
  • CTF Cheat Sheet
  • About
  • Home
  • Blog
  • vulnerability

Tag: vulnerability

VULNERABILITIES FOUND IN ALL Nvidia GeForce GPUS

Posted on October 30, 2024January 20, 2025 By topbento
News, Vulnerability

Vulnerabilities have been discovered/disclosed in ALL Nvidia GeForce GPUs requiring a driver update that is currently available. The vulnerabilities potentially allow a threat actor to gain full control of a compromised system so be sure to update ASAP if you have an Nvidia GPU! Updated drivers can be found here More reading here and here! … Read More “VULNERABILITIES FOUND IN ALL Nvidia GeForce GPUS” »

NOVEL VPN ATTACK FORCES TRAFFIC OUTSIDE OF ENCRYPTED TUNNEL

Posted on May 8, 2024September 19, 2024 By topbento
News, Vulnerability

A novel VPN attack being called TunnelVision is able to force encrypted VPN traffic to route outside of the secure tunnel, potentially allowing a bad actor to intercept communication thought to be encrypted and secure. According to researchers the vulnerability may have existed since as early as 2002. The attack does not appear to effect … Read More “NOVEL VPN ATTACK FORCES TRAFFIC OUTSIDE OF ENCRYPTED TUNNEL” »

CRITICAL VULNERABILITY IN Delinea Secret Server ALLOWS AUTH BYPASS

Posted on April 17, 2024September 19, 2024 By topbento
News, Vulnerability

A vulnerability exists that could allow a bad actor to bypass authentication and gain admin access to Delinea Secret Server which is a Privileged Access Management solution. Attackers could potentially extract secrets. The vulnerability exists in the Secret Server SOAP API. Information on the vulnerability and a PoC are already available from a blog post … Read More “CRITICAL VULNERABILITY IN Delinea Secret Server ALLOWS AUTH BYPASS” »

ADDITIONAL ANALYSIS ON THE xz Utils BACKDOOR

Posted on April 9, 2024January 20, 2025 By topbento
Uncategorized, Vulnerability

Evan Boehs has provided a detailed analysis and timeline of the xz Utils backdoor. Evan has gone in detail into the why of the compromise, how the threat actor leveraged the culture of the open source software community to gain the trust and experience needed to attempt rolling a malicious backdoor out to a very … Read More “ADDITIONAL ANALYSIS ON THE xz Utils BACKDOOR” »

BACKDOOR IN WIDELY USED Linux UTILITY TARGETS SSH CONNECTIONS

Posted on March 30, 2024January 20, 2025 By topbento
Uncategorized, Vulnerability

Malicious code has been detected in xz Utils that appears to be intended to create a backdoor in sshd. xz Utils is a common compression utility used in many Linux distros including Debian and Red Hat. according to a researcher from Analygence the malicious versions of xz Utils were not added to production versions of … Read More “BACKDOOR IN WIDELY USED Linux UTILITY TARGETS SSH CONNECTIONS” »

PrintNightmare – REMOTE CODE EXECUTION in Windows Spooler Service CVE-2021-1675

Posted on July 1, 2021May 24, 2023 By topbento No Comments on PrintNightmare – REMOTE CODE EXECUTION in Windows Spooler Service CVE-2021-1675
News, Vulnerability

Exploit code is now available for CVE-2021-1675 allowing for Remote Code Execution. This vulnerability allows an unauthenticated bad actor to execute code as SYSTEM on vulnerable systems. Microsoft has released an advisory and patches are available here. There are reports that the patches alone are not sufficient at this time so you may want to … Read More “PrintNightmare – REMOTE CODE EXECUTION in Windows Spooler Service CVE-2021-1675” »

Microsoft Exchange CVE-2020-0688 – MULTIPLE EXPLOITS AVAILABLE

Posted on February 29, 2020May 23, 2023 By topbento No Comments on Microsoft Exchange CVE-2020-0688 – MULTIPLE EXPLOITS AVAILABLE
News, Vulnerability

At this time there are now multiple exploits available for CVE-2020-0688 which allows for Remote Code Execution on servers running a vulnerable version of Microsoft Exchange. This code is executed as SYSTEM and the CVSS score for this vulnerability is 9.0 HIGH. Authentication is required, however, due to Outlook Web Access this could be easy … Read More “Microsoft Exchange CVE-2020-0688 – MULTIPLE EXPLOITS AVAILABLE” »

NVIDIA GEFORCE EXPERIENCE OS COMMAND INJECTION

Posted on June 7, 2019May 23, 2023 By topbento No Comments on NVIDIA GEFORCE EXPERIENCE OS COMMAND INJECTION
News, Vulnerability

A security vulnerability was revealed earlier this week in the Nvidia GeForce Experience. If you are not familiar this is Nvidia’s preferred, (meaning default), method of delivering drivers to their video cards. Most gamers using Nvidia cards likely have this application installed to keep their drivers updated. It also includes the ability to take screenshots … Read More “NVIDIA GEFORCE EXPERIENCE OS COMMAND INJECTION” »

Recent Posts

  • Salt Typhoon THREAT ACTORS SPOTTED ON US GOVT NETWORKS BEFORE TELCOS
  • Charter and Windstream ADDED TO LIST OF TELCO PROVIDERS COMPROMISED BY Salt Typhoon
  • Cisco CONFIRMS AUTHENTICITY OF 4.45 GB DATA BREACH
  • NINTH TELECOM COMPANY ADDED TO LIST OF Salt Typhoon TARGETS
  • McDonald’s API EXPLOITED FOR ONE CENT DELIVERIES

Recent Comments

No comments to show.

Archives

  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • May 2024
  • April 2024
  • March 2024
  • September 2023
  • August 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • August 2022
  • July 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • September 2021
  • August 2021
  • July 2021
  • January 2021
  • December 2020
  • August 2020
  • May 2020
  • March 2020
  • February 2020
  • October 2019
  • June 2019
  • April 2019

Categories

  • Breach
  • Cloud
  • Conferences
  • Hardware Hacking
  • Malware
  • News
  • Ransomware
  • Tools
  • Tutorial
  • Uncategorized
  • Vulnerability
  • Walkthough
  • Home
  • Blog
  • CTF Cheat Sheet
  • About
  • Twitter
  • Github
  • YouTube

Copyright © 2025 bentoboxinfosec.

Theme: Oceanly News Dark by ScriptsTown