Hírolvasó

Valódi vállalatok rendszereit törte fel a Gemini egy teszt során

Tech.cert-hungary.hu - h, 09/21/2026 - 07:03
Az izraeli Irregular vállalat által 2026 májusában végzett kiberbiztonsági tesztelése során a Google Gemini mesterséges intelligencia modellje a tesztelők szándéka ellenére internethozzáféréshez jutott, majd behatolt más vállalatok rendszereibe.  Ugyanezen cég hasonló vizsgálatokat végzett az OpenAI, az Anthropic és a Meta rendszereinél is. Az esetről elsőként a Wall Street Journal (WSJ) számolt be. A WSJ értesülései […]

A Microsoft javította a Defender téves jelzéseit okozó hibát

Tech.cert-hungary.hu - h, 09/21/2026 - 06:44
A Microsoft még augusztus végén ismerte el azt a hibát, amely az összes támogatott Windows kliens-és szerververziót, beleértve a legújabb Windows 11 26H1 és a Windows Server 2025 kiadásokat, valamint a Windows Insider program résztvevőit is érintette. A vállalat a szeptember 17-én kiadott Microsoft Defender Antivirus frissítésével (4.18.26080.4-es verzió) orvosolta a problémát. A tech óriás […]

Passkey-témájú megtévesztéstől a választási befolyásolásig – Heti összefoglaló

Tech.cert-hungary.hu - p, 09/18/2026 - 10:47
A hét témáinak többsége az identitás- és hozzáférésvédelemhez kapcsolódik: passkey-beállításra hivatkozó telefonos megtévesztés, kitalált zaklatási ügyre épülő adathalászat, valamint egy böngészőkiegészítő, amely fiókszintű OAuth-tokeneket szivárogtat. Az AI két területen is megjelenik: egy orosz kötődésű kémcsoport AI-ügynökökkel automatizálta kártevői módosítását, a spanyol adatvédelmi hatósághoz pedig első alkalommal érkezett AI-ügynök által végrehajtott incidensről szóló bejelentés. Az amerikai […]

Hamis MRI felvételekkel támadnak az iráni kémek

Tech.cert-hungary.hu - p, 09/18/2026 - 06:23
Brit, amerikai és holland biztonsági szervezetek közösen figyelmeztetnek egy iráni hátterűnek tulajdonított kiberművelettel kapcsolatban. A támadók a CHOSEN BRICK néven azonosított, Windows rendszereket célzó kémprogramot célzott social engineering módszerekkel terjesztették. Egyes esetekben egészen szokatlan csalit alkalmaztak: hamis MRI-vizsgálati eredményt küldtek az áldozatoknak. A kampány elsősorban iráni ellenzékieket, aktivistákat és újságírókat célzott. A támadók WhatsAppon vagy […]

A támadók a Microsoft 365 Direct Send funkcióját használják ki adathalász támadásokhoz

Tech.cert-hungary.hu - p, 09/18/2026 - 04:46
A támadók a Microsoft 365 egyik beépített levelezési funkcióját, a Direct Sendet használják arra, hogy olyan adathalász e-maileket küldjenek, amelyek a szervezet saját domainjéről érkező üzeneteknek tűnnek. A módszerhez nincs szükség felhasználói fiókra vagy jelszóra, a támadók közvetlenül kapcsolódnak a Microsoft 365 nyilvánosan elérhető levelezési végpontjához. A Direct Sendet eredetileg arra tervezték, hogy a nyomtatók, […]

A Google javította a támadásokban kihasznált Pixel mobilmodem sérülékenységét

Tech.cert-hungary.hu - p, 09/18/2026 - 04:42
A Google olyan magas súlyosságú sérülékenységet javított a Pixel készülékek mobilmodemében, amelyet a vállalat szerint korlátozott, célzott támadások során aktívan kihasználhattak. A CVE-2026-58704 azonosítón nyomon követett sérülékenység (CVSS pontszáma: 8,0) jogosultságkiterjesztést tesz lehetővé. A NIST National Vulnerability Database (NVD) leírása szerint a mobilmodem kódjában található logikai hiba miatt megkerülhetők bizonyos jogosultság-ellenőrzések. A sérülékenység távolról, közeli […]

VU#280377: Dokploy is vulnerable to OS command injection

US-CERT.gov - cs, 09/17/2026 - 17:02
Overview

Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privileges and lead to full compromise of the target device.

Description

Dokploy is an open-source Platform as a Service solution for deploying applications and databases on self-hosted servers. Dokploy allows authenticated users to create and schedule database backups and restore previously created backups. These backup operations are executed by the Dokploy process, which runs with root privileges by default.

Dokploy is vulnerable to OS command injection in its database backup creation and restoration functionality due to insufficient sanitization of user-controlled input before it is incorporated into shell commands. The vulnerable backup functionality constructs database-specific shell commands that directly interpolate a user-supplied database name, while the restore functionality incorporates a user-supplied backupFile value into a shell command. Both operations ultimately pass the resulting command to a shell execution helper that invokes /bin/bash as a child of the Dokploy process, without shell escaping or restrictions on shell metacharacters.

The affected parameters are exposed through tRPC procedures that only validate that the supplied values are non-empty strings. Consequently, authenticated users with permission to perform database backups can supply shell metacharacters that are interpreted by /bin/bash, resulting in arbitrary command execution on the Dokploy host with the root privileges of the Dokploy server process.

Impact

An attacker with authenticated Dokploy account with backup permission (granted by default for database services) can execute arbitrary commands as root (default configuration) on the Dokploy host. Successful exploitation provides full control of the host, including persistent read/write access to the target server's filesystem and the ability to steal private credentials stored for other tenants managed by the same Dokploy instance.
The vulnerability affects all five database types supported by Dokploy: PostgreSQL, MySQL, MariaDB, MongoDB, and LibSQL. Exploitation was confirmed against versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch available on GitHub.

Solution

Unfortunately, Dokploy could not be reached to coordinate this vulnerability; however, the issue has been patched in Dokploy versions 0.29.13 and beyond. The CERT/CC recommends users update immediately. Database administrators or general operators unable to update should mitigate potential attacks by turning off default backup permissions, and restricting these permissions only to necessary users and roles.

Acknowledgements

Thanks to Muhammadjon Ahmadjonov for reporting this vulnerability. This document was written by Alex Lewis.

Kategóriák: Biztonsági hírek

Fontos biztonsági frissítések és új Linux kernelhibák

Tech.cert-hungary.hu - cs, 09/17/2026 - 11:39
A héten már külön írtunk az Apple iOS-, iPadOS- és macOS-frissítéseiről, de nem ez volt az egyetlen fontos biztonsági kiadás. Az Oracle, a Google és az IBM is olyan javításokat tett közzé, amelyek vállalati környezetben kiemelt figyelmet igényelnek, miközben a Linux kernel hálózati alrendszerében két új sérülékenységet is feltártak, amelyek javításai még zárt felülvizsgálat alatt […]

Kibertámadás bénította meg a Nemzetközi Meteor Szervezet infrastruktúráját

Tech.cert-hungary.hu - cs, 09/17/2026 - 05:39
A Nemzetközi Meteor Szervezetet (International Meteor Organization, IMO) kibertámadás érte, amely jelentős részben elérhetetlenné tette a Belgiumban működő nonprofit szervezet weboldalát és szolgáltatásait. Az IMO szerint a támadás „kritikus csapást” mért az elöregedett infrastruktúrára, ezért a szervezet jelenleg egy leegyszerűsített tájékoztató oldalon működik. Az IMO arra számít, hogy az átállás új infrastruktúrára és szolgáltatásokra több […]

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

US-CERT.gov - sze, 09/16/2026 - 19:10
Overview

A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control.

Description

MLflow is an open-source platform for managing machine learning lifecycles, including model packaging, versioning, and deployment. "Flavors" refer to the specialized frameworks through which supported models are stored and loaded. In response to previous vulnerability concerns, MLflow implemented the MLFLOW_ALLOW_PICKLE_DESERIALIZATION safety control to block and disable executing any pickle deserialization and subsequent loads per the user’s choice.

When loading models through mlflow.pyfunc.load_model(model), users must specify a model flavor and path in an MLmodel file. With the dspy flavor, MLflow checks the value of MLFLOW_ALLOW_PICKLE_DESERIALIZATION, and whether the specified model path ends in .pkl. A model path that does not end in .pkl (even if the file is actually a pickle file), will route to a separate branch for pickle deserialization, bypassing the safety control. However, when loading through the statsmodels flavor, there is no check for MLFLOW_ALLOW_PICKLE_DESERIALIZATION at all.

Impact

Exploitation of this vulnerability allows for arbitrary remote code execution through a malicious pickle-loaded payload, regardless of a user explicitly disallowing pickle serialization, through vulnerable flavor specifications in the MLmodel configuration file. The attack path requires write access to any location from which a user obtains MLflow models. This vulnerability was confirmed against MLflow 3.12.0.

Solution

MLFlow could not be reached to coordinate this vulnerability; however, the statsmodels flavor was patched in versions >= 3.15.0. Users should upgrade immediately. Until a further fix remedying the dspy flavor vulnerability is available, MLflow users who wish to block pickle deserialization and loads should avoid loading any models via the dspy flavor.

Acknowledgements

Thanks to Prasanna Dabi for reporting this vulnerability. This document was written by Alex Lewis.

Kategóriák: Biztonsági hírek

VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

US-CERT.gov - sze, 09/16/2026 - 17:18
Overview

A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999.

Description

Sentry is a software error‑monitoring and performance‑tracking platform used by developers to detect, diagnose, and understand issues in their applications. It collects telemetry such as exceptions, stack traces, logs, and performance data from applications. Built into Sentry, Seer acts as an automated debugging assistant that converts telemetry into actionable remediation steps and can hand off issues to an integrated coding agent to propose code fixes.

Because Sentry front-end projects commonly expose a public DSN (Data Source Name) to allow browsers to submit this telemetry, an attacker can craft and submit malicious events through this public endpoint. When Seer is enabled to automatically pass issues to a coding agent, these attacker-supplied events can traverse multiple trust boundaries. Ultimately, malicious event fields propagate through Seer’s analysis pipeline, transforming into untrusted instructions that the privileged coding agent may execute.

The vulnerable workflow is as follows:
* Sentry ingests attacker‑generated exception events submitted through the public DSN.
* Seer evaluates whether the event represents an issue eligible for automated remediation.
* Seer generates a root‑cause analysis that uses attacker-controlled event fields, including exception messages, stack traces, source context, and breadcrumbs.
* The generated analysis is embedded directly into the initial prompt provided to the coding agent.
* The coding agent interprets the fabricated analysis as a legitimate description of the victim’s codebase.
* During its investigation, the coding agent downloads and executes a package controlled by the attacker.
* The package executes within the coding‑agent environment prior to any human review of a pull request.

Impact

Successful exploitation may allow arbitrary code execution in the coding‑agent environment that processes the affected repository.

Solution

At the time of this writing, no vendor‑supplied patch information has been provided. Mitigations may include disabling automated remediation flows, restricting coding‑agent package installation, or disabling Seer handoff until a fix is available. Additional defensive filtering of telemetry content before Seer analysis may also reduce risk.

Acknowledgements

Thank you to Nikita Benkovich and Vitalii Valkov, agyn for reporting this vulnerability. This document was written by Bob Kemerer.

Kategóriák: Biztonsági hírek

Több százezer Trezor-ügyfelet céloznak adathalász támadásokkal

Tech.cert-hungary.hu - sze, 09/16/2026 - 12:01
A hardveres kriptotárcákat gyártó Trezor újabb adatbiztonsági incidensre figyelmeztette ügyfeleit. A vállalat hírleveleinek kiküldésére használt Brevo marketingtechnológiai szolgáltatót kibertámadás érte, amelynek során a támadók 138 Brevo-fiókhoz fértek hozzá. Ezeket a hozzáféréseket mintegy 347 ezer, Trezor-ügyfeleknek címzett adathalász e-mail kiküldésére használták fel. Az üzenetek a Trezor nevében érkeztek, és egy rosszindulatú linket tartalmaztak. A hivatkozás egy […]

A TA488 minimális felhasználói interakciót igénylő támadással célozza az Outlookot

Tech.cert-hungary.hu - sze, 09/16/2026 - 11:55
A Proofpoint 2026. július 29-én egy új, a Laundry Bear (Void Blizzard, TA488) nevű, Oroszországhoz köthető hacker csoport támadási kampányáról számolt be, amely egy Microsoft Outlook Web Access (OWA) sérülékenységet, a CVE-2026-42897 azonosítón nyomon követett XSS hibát használja ki. A kampány az amerikai és európai kormányzati szerveket, a telekommunikációs, a pénzügyi, a vendéglátóipari valamint a […]

Hamis hirdetések az HBO Max hivatalos Reddit fiókján

Tech.cert-hungary.hu - k, 09/15/2026 - 12:45
2026 szeptemberében az HBO Max hivatalos, ellenőrzött Reddit fiókját (u/hbomax) támadók kompromittálták, és több mint száz rosszindulatú hirdetést futtattak, amelyek Windows és macOS felhasználókat céloztak különböző adatlopó kártevőkkel. A vizsgálat alapján rekonstruálható, mi történt, és hogyan épül fel a „PasteSwitch” névre keresztelt kampány. A kutatók szerint a támadók nagyjából 48 órára vették át az irányítást […]

Aktívan kihasznált kritikus sérülékenységet javított a Cisco

Tech.cert-hungary.hu - k, 09/15/2026 - 08:56
A Cisco sürgős figyelmeztetést adott ki a Secure Email Gateway eszközeit érintő, aktívan kihasznált nulladik napi sérülékenységről.

Több száz sérülékenységet javít az Apple új operációs rendszereiben

Tech.cert-hungary.hu - k, 09/15/2026 - 07:29
Az Apple új operációs rendszereinek végleges kiadásával lezárult a béta tesztelési időszak, az iOS 27 és a macOS 27 pedig számos biztonsági javítással és új védelmi funkcióval érkezett. Az iOS 27 biztonsági frissítése összesen 122 sérülékenységet kezel, míg a macOS 27 több mint 200 biztonsági hibára kínál javítást, amelyek egy részét az Apple a korábbi, […]

A Revolut hamis hatósági megkeresésre adott ki érzékeny ügyféladatokat

Tech.cert-hungary.hu - h, 09/14/2026 - 09:29
A Revolut útlevéladatokat, azonosításhoz használt szelfiket, lakcímeket és teljes tranzakciós előzményeket adott át kiberbűnözőknek, miután egy hamis megkeresést valódi hatósági adatkérésnek hitt. Az incidens bitcoin-tranzakciókat is érintett, az ügyfelek pénze azonban nem került veszélybe. A hamis megkeresés egy valódi kormányzati szervtől érkező kérés benyomását keltette, és olyan hitelesítő adatokat tartalmazott, amelyek átmentek a Revolut belső […]

180 sebezhetőséget javít az Android szeptemberi frissítése

Tech.cert-hungary.hu - h, 09/14/2026 - 06:29
A júliusi és augusztusi, sérülékenységet nem tartalmazó Android biztonsági közlemények után a Google 180, köztük az Android keretrendszert (Framework), a rendszert (System) és a rendszermagot (Kernel) érintő sérülékenységet javított a szeptemberi biztonsági frissítéssel. A biztonsági közlemény ezúttal is két javítási szintet határoz meg, az első, 2026-09-01-es 95 hibát orvosol az Android Runtime, a Framework, a […]

VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index

US-CERT.gov - p, 09/11/2026 - 22:11
Overview

An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful exploitation can lead to an immediate denial of service or application instability. This vulnerability is tracked as CVE-2026-84286.

Description

An OOB memory access vulnerability exists in the exllamav3_ext module due to insufficient input validation.

When the kernel parameter K is set to 0 in a crafted input, the extension generates a negative array index, resulting in a CUDA illegal memory access.s. The root cause is a missing bounds check in the kernel-table dispatch process. The checkpoint-derived block index (cbi) is used to access a fixed 24-entry array without confirming that either K or cbi fall within safe limits.

Impact

Primary impacts include Denial of Service (DoS) through process crashes and potential unstable execution states within applications utilizing the library.

Solution

The vendor has addressed this vulnerability in the main repository. Users are advised to update their installations or apply the fix from the merged pull request: https://github.com/turboderp-org/exllamav3/pull/310.

Supply chain

Downstream projects utilizing this library are indirectly exposed to this vulnerability. According to the ExLlamaV3 Dependency Graph, there are 49 total dependencies currently tracking this repository. Notable downstream projects directly affected by this supply chain link include: UnstableLlama / ezexl3 and Ednaordinary / MawDiscord
Developers and maintainers of these dependent repositories are strongly encouraged to rebuild their packages against the patched version of exllamav3_ext.

Acknowledgements

The CERT Coordination Center (CERT/CC) thanks Nathan Keys (professor-moody) for discovering and responsibly reporting this vulnerability.
This AI-assisted vulnerability note was prepared by Laurie Tyzenhaus.

Kategóriák: Biztonsági hírek

Piacra dobta MI-ügynökét a Meta, érkezik a Muse

Tech.cert-hungary.hu - p, 09/11/2026 - 16:11
A Meta kedden indította útjára – egyelőre csak az Egyesült Államokban – Muse nevű személyes mesterségesintelligencia-alapú ügynökét a 18 év feletti felhasználói számára. A techóriás különös hangsúlyt fektet az ügynök biztonsági és adatvédelmi funkcióira, tájékoztatásuk szerint a Muse egy dedikált, biztonságos virtuális gépen fut, amely magát az ügynököt és a felhasználó adatait tárolja. A felhasználók […]

Oldalak

Feliratkozás Anaheim.hu hírolvasó csatornájára