Hírolvasó

A Fortinet sérülékenységek javítását sürgeti a CISA

Tech.cert-hungary.hu - h, 07/20/2026 - 11:47
A CISA arra szólította fel a kormányzati ügynökségeket, hogy kezeljék prioritásként a Fortinet FortiSandbox fenyegetésészlelő platform két aktívan kihasznált sebezhetőségét. A szóban forgó CVE-2026-39808 és CVE-2026-25089 azonosítón nyilvántartott sebezhetőségek alacsony komplexitású parancsbefecskendezési (OS command injection) támadással jogosulatlan távoli kódfuttatást tesznek lehetővé, felhasználói beavatkozás nélkül. A Fortinet már április 14-én, illetve június 9-én kiadta a védekezéshez […]

Megduplázódott az új kiberbűnözői útmutatók száma a hackerfórumokon

Tech.cert-hungary.hu - p, 07/17/2026 - 11:05
Jelentősen növekedett a kiberbűnözői fórumokon közzétett támadási és csalási útmutatók száma, miközben egyre nagyobb hangsúlyt kapnak a pénzügyi visszaélésekhez kapcsolódó módszerek. Különösen a bankkártyaadatok megszerzésére és illegális felhasználására irányuló carding technikák, valamint a csalásból származó pénzek tisztára mosására irányuló eljárások (cash-out techniques) kerültek előtérbe. A Radware 2022 decembere és 2026 áprilisa között 24 deepweb- és […]

Júliusban új rekordot állított fel a Microsoft Patch Tuesday

Tech.cert-hungary.hu - p, 07/17/2026 - 10:35
A Microsoft júliusi Patch Tuesday frissítési csomagjában több mint 600 sérülékenység javítását tette közzé. A Microsoft Security Update Guide ezúttal eltért a megszokottól, az egyedi CVE azonosítók részletes listája helyett egy összesítő táblázatot használ, amely termékcsaládonként mutatja a javított sérülékenységek számát, a fontosabb sérülékenységeket pedig a Notable CVEs szakasz tartalmazza. Az egyes sérülékenységekhez tartozó biztonsági […]

VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

US-CERT.gov - cs, 07/16/2026 - 20:00
Overview

A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams.

Description

HTTP/2 is a widely used application-layer protocol that supports multiplexing, header compression, and flow-control mechanisms to regulate the transmission of data between web browsers and servers. Flow control is designed to prevent senders from overwhelming receivers and relies on client-advertised window sizes to determine the maximum volume of unacknowledged data that can be in transit at any given time.

A client can intentionally stall outbound flow control by withholding WINDOW_UPDATE frames or by advertising SETTINGS_INITIAL_WINDOW_SIZE = 0. In some HTTP/2 implementations, the server continues processing requests and generating complete response bodies even though it is unable to transmit them. The resulting response data remains buffered in memory, and each stalled stream retains its allocated buffer until the connection closes or a timeout occurs.

An attacker can exploit this behavior by opening many simultaneous streams and requesting large resources, causing the server to accumulate large amounts of buffered response data. In environments with permissive resource limits, this can lead to excessive memory consumption, swap exhaustion, service instability, and, in severe cases, system crashes. Even under more conservative limits, the attack can exhaust worker or connection resources and degrade service availability.

Impact

A remote, unauthenticated attacker can cause denial-of-service conditions on affected HTTP/2 server implementations. Under high resource limits, an attacker may be able to induce unbounded memory amplification resulting in OOM kills, severe swap thrashing, or full system unresponsiveness. Under default or lower limits, the attack can exhaust available connections or worker resources, temporarily preventing new clients from establishing sessions and degrading overall service availability.

Solution

Several vendors have addressed this vulnerability in recent updates; see the Vendor Information section for individual CVEs and remediation details. Implementations that enforce memory ceilings, restrict concurrent stream counts, and actively terminate stalled connections can substantially reduce the risk of denial-of-service conditions.

Acknowledgements

Thanks to the Okta Red Team for researching and reporting this vulnerability. This document was written by Molly Jaconski.

Kategóriák: Biztonsági hírek

VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem

US-CERT.gov - cs, 07/16/2026 - 16:43
Overview

A Pickle deserialization vulnerability has been discovered within the SGLang project, enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service. No patch is available at this time, and no response was obtained from the project maintainers during coordination.

Description

SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. A vulnerability has been discovered within the tool and is tracked as follows:

CVE-2026-14890
SGLang uses an expert-parallel backup subsystem designed to handle the large amount of compute and memory constraints associated with different model types. This system, when running, exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.

The vulnerability is caused by the ZeroMQ PULL socket in expert_backup_manager.py binding to an external IP address with no authentication, meaning that any process that can reach the endpoint can send a payload that eventually gets deserialized with Pickle. This vulnerability is structurally similar to CVE-2026-7301 and CVE-2026-7304 in that it enables unauthenticated remote code execution via unsafe deserialization of data through pickle.loads(), but differs by occurring in the expert-parallel backup subsystem, rather than the multimodal scheduler or custom logit processor interfaces.

Impact

If exploited, this vulnerability could allow an unauthenticated attacker to achieve remote code execution on the host running SGLang. Deployments that expose the affected interface to untrusted networks are at the highest risk of exploitation.

Solution

Until a patch is available, affected users should consider the following mitigations:

Mitigations
  • Restrict access to the service interfaces and ensure they are not exposed to untrusted networks.
  • Implement network segmentation and access controls to prevent unauthorized interaction with the vulnerable endpoints.
  • Change SGLANG_USE_PICKLE_IPC to "false" within environ.py.

The SGLang maintainers have made strides in addressing pickle deserialization vulnerabilities, and have begun to work to refactor the code base with msgpack to prevent deserialization issues such as CVE-2026-14890, but the SGLANG_USE_PICKLE_IPC defaults to true within the codebase at the time of writing.

Acknowledgements

Thanks to the reporter, edwardav970@gmail.com.

This document was written by Christopher Cullen.

Kategóriák: Biztonsági hírek

Nyilvánosan elérhető szerver buktatott le három Microsoft 365 elleni adathalász kampányt

Tech.cert-hungary.hu - cs, 07/16/2026 - 13:03
Egy nyilvánosan elérhető, hibásan konfigurált szerveren hagyott Python HTTP-kiszolgáló segítségével a Lexfo kutatói három, Microsoft 365-felhasználókat célzó adathalász kampány működését térképezték fel. A szerveren elérhető könyvtárlistaés a .bash_history fájl olyan érzékeny adatokat fedett fel, mint az Evilginx-alapú adathalász készletek, hitelesítő adatok naplói, távoli menedzsment eszközök, Telegram-botok és egyéb operátori fájlok. A vizsgálat szerint az egyik […]

VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

US-CERT.gov - sze, 07/15/2026 - 19:08
Overview

A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system.

Description

The tdeio64.sys driver distributed by Pegatron Corporation, a Taiwanese electronics manufacturer that produces motherboards and OEM components, is a Windows Driver Model (WDM) driver that provides low-level access to system I/O ports and hardware components. The driver exposes the \\.\TdeIo device interface and processes privileged IOTL requests without enforcing adequate access control or validating user-supplied memory addresses.

CVE-2026-14961 By sending a crafted DeviceIoControl request, an unprivileged attacker can abuse the driver's IOCTL dispatcher to perform arbitrary kernel memory reads and writes. This capability can be used to overwrite the current process token with the SYSTEM process token, resulting in privilege escalation to NT AUTHORITY\SYSTEM.

CVE-2026-14960 In addition to arbitrary kernel memory access, the driver exposes IOCTLs capable of interacting directly with hardware I/O ports. An attacker who successfully exploits these interfaces may be able to manipulate hardware resources in ways that extend beyond normal operating system protections.

Impact

Successful exploitation provides an attacker with arbitrary kernel read and write capabilities, enabling a complete compromise of the operating system. An attacker can elevate privileges to NT AUTHORITY\SYSTEM, bypass or disable endpoint security controls, extract credentials from protected processes such as lsass.exe, install persistent rootkits, manipulate kernel data structures, and issue low-level hardware I/O operations.

Solution

At the time of publication, no vendor-supported fix is available for the Pegatron tdeio64.sys kernel driver vulnerability.

Mitigations

Organizations should disable or remove the vulnerable driver where it is not required, prevent untrusted users from loading or interacting with the driver, and implement solutions such as Windows Defender Application Control (WDAC) or Hypervisor-Protected Code Integrity (HVCI) to block known vulnerable drivers from loading where supported.

Acknowledgements

Thanks to Lucian Alexandru Necula for researching and reporting this vulnerability. This document was written by Michael Bragg.

Kategóriák: Biztonsági hírek

VU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations

US-CERT.gov - sze, 07/15/2026 - 18:07
Overview

Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions.

Description

Both vulnerabilities stem from insufficient enforcement of canonical cryptographic structures during verification: in the RSA case, non-standard ASN.1 encodings and undersized padding are accepted; in the Ed25519 case, non-canonical signature scalars are not rejected. As a result, node-forge accepts signatures that appear valid internally but are rejected by industry-standard libraries such as OpenSSL and Node.js’s native crypto module.

The vulnerabilities affect node-forge versions 0.1.2 through 1.3.3 for RSA-PKCS#1 v1.5, and 0.7.4 through 1.3.3 for Ed25519. Both issues were resolved in v1.4.0, released on 2026-04-05.

CVE-2026-33894 arises in lib/rsa.js, where RSASSA-PKCS1-v1_5 verification accepts forged signatures due to two related flaws. First, the ASN.1 parser for DigestInfo permits non-canonical encodings—specifically, structures with more than the two required fields (algorithm OID and octet string), including attacker-controlled additional data. Second, the PKCS#1 v1.5 decoding logic fails to enforce the RFC 2313 requirement that the padding string (PS) must be at least 8 bytes. These combined weaknesses enable attackers to construct specially crafted signatures, particularly with low public exponents (e.g., e = 3), that node-forge validates successfully while standard implementations correctly reject them.

CVE-2026-33895 resides in lib/ed25519.js, where signature verification does not enforce scalar canonicality as mandated by RFC 8032. The scalar S (last 32 bytes of the signature) is used without ensuring it lies within the valid range [0, L−1], where L is the Ed25519 group order. Consequently, signatures with S′ = S + k·L (e.g., S + L) verify as valid in node-forge, even though canonical implementations such as Node.js crypto and OpenSSL reject them. This undermines assumptions about signature uniqueness and enables substitution attacks in systems relying on strict byte-for-byte signature validity—for instance, audit logs, token binding, or attestation protocols.

Impact

The most immediate concern is integrity: attackers may forge signatures for arbitrary messages in the RSA case or mutate valid Ed25519 signatures in ways that remain accepted by node-forge. Such forgery enables bypassing authentication, code-signing, or session-bound token validations, especially in workflows where node-forge is used as the sole verification engine.

The scope is broad. Any application using node-forge’s default verification APIs—including JOSE libraries like node-jose, certificate tooling from Adobe and Expo, and custom PKI integrations—is potentially affected. Because the vulnerabilities manifest in the default configuration (i.e., no unusual flags or options required), unpatched deployments face exposure without any operator action.

Exploitation is straightforward. Public proofs of concept demonstrate RSA forgery with low-exponent keys and Ed25519 scalar manipulation with minimal effort, and both attacks work over the network against remote endpoints performing verification.

Solution

The vulnerabilities have been fully addressed in node-forge v1.4.0, released on 2026-04-05. This release enforces strict canonical validation: RSA verification now rejects non-canonical DigestInfo structures and enforces PS greater than or equal to 8 bytes of padding, while Ed25519 verification explicitly checks that S < L.

After upgrading, users can verify the fix by running the included test suite, which includes dedicated test cases for both CVEs.

If you maintain downstream packages that depend on node-forge, update your dependency lockfiles and test thoroughly with v1.4.0 before releasing. Even indirect usage through frameworks, build tools, or security plugins may expose your users to risk until the transitive dependency is upgraded.

Mitigations

If immediate upgrade is not possible due to legacy dependencies or indirect usage in transitive dependencies, the following interim measures are recommended:
1. Audit all call sites invoking forge.pki.publicKey.verify(), ed25519.verify(), or JOSE-based verification routes.
2. Where feasible, fall back to Node.js native crypto.verify() for RSA and Ed25519 validation, particularly in high-assurance flows such as code signing or identity assertion.
3. In critical workflows, consider implementing cross-library verification: for instance, compute the signature with node-forge but validate it using the Node.js crypto module as a secondary check.

It is important to note that options such as_parseAllDigestBytes: true do not mitigate these vulnerabilities, as they neither enforce ASN.1 strictness nor padding length. Relying on them may create a false sense of security.

Acknowledgements

This vulnerability was discovered by Austin Chu, Sohee Kim, and Corban Villa, of the University of California, Berkeley, as part of a security research project. This AI-assisted vulnerability note was prepared by Timur Snoke.

Kategóriák: Biztonsági hírek

Újabb adathalász kampány célozza a LastPass és Bitwarden felhasználóit

Tech.cert-hungary.hu - sze, 07/15/2026 - 13:29
A LastPass egy olyan adathalász kampányra figyelmeztette a felhasználóit, amely hamis biztonsági értesítésekkel próbálja rosszindulatú weboldalakra irányítani az áldozatokat. Az adathalász e-maileket úgy alakították ki, hogy megtévesztésig hasonlítsanak a vállalat hivatalos kommunikációjára. A levelek frissített biztonsági szabályzatokról tájékoztatják a címzetteket, majd egy, a DocuSign felületét utánzó weboldalra irányítják őket, ahol azt állítják, hogy egy dokumentum […]

Üzleti titkok ellopása miatt pert indított az Apple

Tech.cert-hungary.hu - sze, 07/15/2026 - 09:00
Az Apple július 10-én jelentette be, hogy pert indít egy volt alkalmazottja ellen, mert – miközben már az OpenAI alkalmazásában állt – egy korábban ismeretlen hitelesítési hiba kihasználásával továbbra is hozzáfért az Apple belső hálózatához és bizalmas adataihoz. A benyújtott kereset szerint az Apple egy volt mérnöke, Chang Liu, a cégtől való távozása után nem […]

EU: jöhet a 13 éves korhatár a közösségi médiában?

Tech.cert-hungary.hu - sze, 07/15/2026 - 07:47
Az Európai Bizottság fontolóra veszi, hogy a közösségi média használatát 13 éves korhatárhoz kösse – közölte Ursula von der Leyen. Hozzátette: az intézkedés az uniós tagállamokban egységes szabályozást vezetne be, amely korlátozná a szülői vagy gondviselői felügyelet nélkül internetező, 13 év alatti gyermekek hozzáférését a közösségi platformokhoz. Az intézmény elnöke hozzátette, hogy a megfelelő kort […]

Vásárlói adatokat loptak a Lidl-től

Tech.cert-hungary.hu - k, 07/14/2026 - 11:17
A Lidl német áruházlánc nemrég arról értesítette németországi, belga és holland vásárlóit, hogy az informatikai szolgáltatójukat ért kibertámadás következményeként az elkövetők hozzáférést szerezhettek a személyes adataikhoz. A Schwarz Group tulajdonában lévő áruházlánc Európa legnagyobb élelmiszer-kereskedője, több mint 376.000 alkalmazottat foglalkoztat és 12.000 üzletet üzemeltet Európában és az Egyesült Államokban. tett közzé a belga és holland […]

A Joomla-bővítmények aktívan kihasznált RCE-hibáira figyelmeztet a CISA

Tech.cert-hungary.hu - k, 07/14/2026 - 11:13
A CISA további két, ezúttal az iCagenda és Balbooa Forms Joomla-bővítmények sebezhetőségeinek aktív kihasználására hívja fel a figyelmet. A hibák a legmagasabb prioritásúként kerültek megjelölésre, így a szövetségi ügynökségeknek három napon belül telepíteniük kell a rendelkezésre álló biztonsági frissítéseket, illetve végrehajtani az enyhítő műveleteket. Az ismerten kihasznált sebezhetőségeket tartalmazó KEV (Known Exploited Vulnerabilities) katalógusba felvételre […]

Több mint 5800 letartóztatás a csalók elleni globális akcióban

Tech.cert-hungary.hu - h, 07/13/2026 - 13:53
Az Interpol koordinálásával lezajlott nemzetközi művelet során összesen 5811 embert vettek őrizetbe, és mintegy 293 millió dolláros illegális vagyont sikerült befagyasztaniuk vagy elkobozniuk. Az akciót „Operation First Light 2026” néven futtatták, és 2026. január 15. és április 30. között zajlott. A művelet célja a social engineering típusú csalások, valamint az ezekhez kapcsolódó pénzmosási tevékenységek felderítése […]

XSS sebezhetőség a Zimbra Classic Web Clientben

Tech.cert-hungary.hu - h, 07/13/2026 - 13:44
A Zimbra biztonsági csapata sürgős frissítést kér ügyfeleitől egy kritikus, e-mailen keresztül kihasználható XSS sebezhetőség miatt, amely a klasszikus webes levelezőkliens felhasználóit veszélyezteti. A hiba a „Classic Web Client” (más néven Classic UI) nevű webmail felületet érinti. A sebezhetőség egy stored cross-site scripting hiba, amelyhez a nyilvánosságra hozatal idején még nem rendeltek CVE-azonosítót. A támadók […]

Az Európai Parlament meghosszabbította a CSAM-tartalmak önkéntes szkennelését lehetővé tevő szabályozást

Tech.cert-hungary.hu - h, 07/13/2026 - 12:43
Az Európai Parlament megszavazta annak a jogszabálynak a meghosszabbítását, amely lehetővé teszi a nagy technológiai vállalatok számára, hogy önkéntes alapon átvizsgálják a felhasználók kommunikációját a gyermekekkel szembeni szexuális visszaéléseket ábrázoló tartalmak (CSAM – Child Sexual Abuse Material) felderítése érdekében. A kritikusok ezt a gyakorlatot „Chat Control” néven emlegetik. A szavazásra a parlament nyári szünete előtti […]

Új képességeket kapott a RedHook Androidos kártevő

Tech.cert-hungary.hu - h, 07/13/2026 - 10:12
A Group-IB kiberbiztonsági cég elemezte a RedHook mobilkártevő újabb kiadását, amely a 2025-ös verziójához képest számos új képességgel bővült. A kártevő például már képes shell szintű jogosultságokat szerezni az Android Wireless Debugging (Wireless ADB) mechanizmusának visszaélésével, miközben továbbra is megtartotta a távoli hozzáférésű trójai (RAT) funkcióit, lehetővé téve a képernyő streamelését, billentyűleütések elfogását, a felhasználói […]

VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs

US-CERT.gov - p, 07/10/2026 - 20:19
Overview

GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. This vulnerability has been remediated in a recent update by GNU; see the Solutions section below for resolution guidance.

Description

GNU Wget is a widely used command-line utility for retrieving content over HTTP, HTTPS, and FTP. When operating over FTP in passive mode, Wget relies on the server’s PASV response to determine which IP address and port to use for the data connection.

CVE-2026-15146 GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

This issue belongs to a known class of FTP PASV vulnerabilities such as CVE-2021-40491, which was previously remediated in GNU Inetutils.

Impact

A remote attacker controlling or influencing an FTP endpoint can induce Wget to establish connections to otherwise inaccessible internal network addresses. This may allow the attacker to retrieve service banners, access internal HTTP endpoints, or exfiltrate data from internal systems reachable by the victim host. Applications that embed Wget for automated retrieval are particularly susceptible, because the vulnerability may be triggered automatically through redirected requests and untrusted user-supplied URLs.

Solution

GNU Wget has remediated this issue in the 07/05/2026 commit 4f85853f641863d5915786a8413e1a213726a62b. Users are advised to update their version according to vendor guidance.

Acknowledgements

Thanks to Jeremy Brown for researching and reporting this vulnerability. This document was written by Molly Jaconski.

Kategóriák: Biztonsági hírek

A DuckDuckGo mostantól blokkolja a YouTube videóhirdetéseket

Tech.cert-hungary.hu - p, 07/10/2026 - 15:05
A DuckDuckGo böngésző bejelentette, hogy mostantól képes blokkolni a legtöbb YouTube videóhirdetést, beleérve a videók előtt lejátszódó reklámokat is. A funkció alapértelmezés szerint engedélyezve van a böngésző legújabb verzióiban iOS, Mac és Windows rendszereken, viszont az Androidos felhasználóknak manuálisan kell beállítaniuk a funkciót a Beállítások -> Hirdetésblokkolás (Settings -> Ad Blocking) menüpontban. Az elmúlt években […]

Oldalak

Feliratkozás Anaheim.hu hírolvasó csatornájára