Mercoledi 29 Luglio 2026 01:02:06 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#CWE-78


Un bug di una libreria, molte porte chiuse: Siemens Desigo CC affronta un overflow critico in OpenSSL

Pubblicato: 28 Luglio 2026 19:57Categoria: Vulnerabilità e gestione delle patchArea: Europa / GermaniaAutore: NEONPALADIN

Una falla di sicurezza della memoria nel parsing CMS di OpenSSL è stata collegata a Siemens Desigo CC, mostrando come un bug crittografico di basso livello possa diventare un rischio operativo negli ambienti di gestione degli edifici.

Cheatsheet sull'injection di comandi: payload OS e prevenzione (2026)

Pubblicato: 28 Luglio 2026 10:28Categoria: Ricerca, exploit e sicurezza offensivaArea: America del Nord / USAAutore: PATCHVIPER

Un cheatsheet 2026 sull'injection di comandi inquadra CWE-78 come un problema pratico di payload OS, costruzione insicura dei comandi e progettazione difensiva.

Una console web con troppo potere: Arista VeloCloud Orchestrator è oggetto di sfruttamento attivo

Pubblicato: 28 Luglio 2026 08:23Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: SECURESPECTER

CVE-2026-16812 mette sotto pressione un piano di gestione SD-WAN on-premises, dove un singolo bug di command injection potrebbe trasformarsi in un ampio problema operativo.

Una patch, uno zero-day e il piano di controllo SD-WAN sotto attacco

Pubblicato: 28 Luglio 2026 02:16Categoria: Vulnerabilità e gestione delle patchArea: America del Nord / USAAutore: DEEPAUDIT

La correzione di Arista per una falla di command injection attivamente sfruttata nelle distribuzioni on-premises di VeloCloud Orchestrator ricorda che le interfacce di gestione possono essere la parte più pericolosa della rete.

Two FortiSandbox Bugs Turn a Defensive Tool Into an Attack Surface

Published: 17 July 2026 12:33Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

CISA’s KEV listing of two Fortinet flaws shows how a security appliance can become a remote-command foothold when command input is not properly controlled.

PAN-OS User-ID Agent Flaw Turns a Trust Service Into a Risky Entry Point

Published: 09 July 2026 08:22Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Palo Alto Networks has tied a high-urgency buffer-overflow issue in the PAN-OS User-ID Terminal Server Agent to denial-of-service risk and possible arbitrary code execution, but exposure depends heavily on how the component is deployed.

When the Shell Smiles Back: GuardFall and the Fragile Safety Net Around AI Coding Agents

Published: 30 June 2026 18:19Category: AI Security & Agentic SystemsAuthor: KERNELWATCHER

A research bypass aimed at open-source AI coding and computer-use agents shows how quickly a command safeguard can become a paper wall if shell behavior is not modeled correctly.

When the Perimeter Breaks: Splunk’s AI Add-on and Atlassian’s Dependency Cleanup

Published: 18 June 2026 15:44Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Two vendor patch cycles highlight the same hard truth: modern enterprise risk often lives in helper components, not just the headline product.

Splunk’s AI Toolkit Patch Exposes a Hard Truth About Privileged Helpers

Published: 18 June 2026 10:44Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical command-injection flaw in Splunk AI Toolkit shows how a single unsafe helper path can turn legitimate admin access into host-level command execution.

NeMo Patch Alert Exposes a Bigger AI Risk: When Frameworks Start Talking to the Shell

Published: 17 June 2026 10:44Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

Three high-severity flaws in NVIDIA’s NeMo Framework put a familiar weakness back in the spotlight: if AI tooling reaches the operating system unsafely, the blast radius can jump from model logic to host-level command execution.

When the Guard Dog Bites: A Privileged Access Daemon Becomes the Weak Link

Published: 17 June 2026 08:17Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical command injection flaw in Fortra’s BoKS platform shows how a small helper service can put a privileged control plane at risk if it is reachable from the wrong network.

PAN-OS Admin Path Turns into Root-Command Risk

Published: 12 June 2026 14:47Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A newly disclosed command-injection flaw in Palo Alto Networks' firewall software shows how a trusted management interface can become the highest-value target in the room.

Honeypots Started Talking Back: Ivanti Sentry Flaw Draws Fast Command Injection Probing

Published: 12 June 2026 12:10Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A critical OS command injection issue in an edge gateway is already attracting live exploitation attempts, showing how quickly attackers test newly exposed paths to root-level access.

FortiSandbox’s Blind Spot: A Critical Flaw in the Tool Built to Catch Malware

Published: 10 June 2026 08:09Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A Fortinet disclosure puts a security analysis platform under its own spotlight, where a pre-auth command injection issue raises the stakes for defenders running sandboxing at the edge of trust.

Dentro la porta di controllo del robot che può trasformarsi in un percorso di esecuzione di codice

Pubblicato: 14 Maggio 2026 20:23Categoria: Cybersecurity Industriale e Infrastrutture CriticheArea: Europa / DanimarcaAutore: NETAEGIS

Una falla critica in PolyScope 5 di Universal Robots mostra come un’interfaccia di gestione remota su un controllore macchina possa diventare molto più pericolosa di un normale bug software.

Un bug critico nello scheduler espone Siemens RUGGEDCOM ROX a una pericolosa debolezza del management plane

Pubblicato: 14 Maggio 2026 20:13Categoria: Cybersecurity industriale e infrastrutture criticheArea: Europa / GermaniaAutore: NETAEGIS

Una falla di command injection nello scheduler web di un router OT mostra come un piccolo errore nella gestione dell’input possa avere conseguenze sproporzionate quando il bersaglio gira con privilegi elevati.

Crypto industriale, vera corruzione della memoria: il bug del PLC ABB che trasforma un formato di messaggio in un vettore di crash

Pubblicato: 12 Maggio 2026 20:14Categoria: Sicurezza informatica industriale e infrastrutture criticheArea: Europa / SvizzeraAutore: NETAEGIS

Una falla critica nel modo in cui il firmware ABB AC500 V3 analizza i messaggi CMS autenticati mostra come un singolo involucro malformato possa contare più della crittografia racchiusa al suo interno.