Martedi 28 Luglio 2026 22:49:07 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#On-Premises


Una falla critica in TeamCity può consentire agli attaccanti di eseguire comandi senza effettuare l'accesso

Pubblicato: 28 Luglio 2026 15:28Categoria: Vulnerabilità e gestione delle patchArea: Europa / Repubblica CecaAutore: NEONPALADIN

Un bug ad alta gravità in TeamCity On-Premises mette sotto pressione i piani di controllo CI/CD, e la correzione rappresenta ora la linea più chiara tra amministrazione ordinaria e serio rischio per la sicurezza.

Il trust core di TeamCity emerge dopo la divulgazione di un RCE critico

Pubblicato: 28 Luglio 2026 14:34Categoria: Vulnerabilità e gestione delle patchArea: Europa / Repubblica CecaAutore: SECURESPECTER

Una vulnerabilità critica di esecuzione di comandi senza autenticazione in TeamCity On-Premises mostra come un controller CI/CD raggiungibile possa diventare l'anello più debole in una catena di distribuzione software.

Il nuovo difetto di TeamCity trasforma un control plane CI/CD in un bersaglio per comandi remoti

Pubblicato: 28 Luglio 2026 14:24Categoria: Vulnerabilità e gestione delle patchArea: Europa / Repubblica CecaAutore: DEEPAUDIT

Una falla critica in TeamCity On-Premises solleva una domanda familiare ma pericolosa: cosa succede quando il server che orchestra le build diventa raggiungibile per l'esecuzione di comandi senza autenticazione?

Il bug del centro nevralgico SD-WAN che trasforma un portale di accesso in una superficie d'attacco

Pubblicato: 28 Luglio 2026 10:31Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: DEEPAUDIT

Una falla critica di command injection in Arista VeloCloud Orchestrator mostra perché il software che dirige le reti può essere sensibile quanto le reti stesse.

Una console web con troppo potere: Arista VeloCloud Orchestrator è oggetto di sfruttamento attivo

Pubblicato: 28 Luglio 2026 08:23Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: SECURESPECTER

CVE-2026-16812 mette sotto pressione un piano di gestione SD-WAN on-premises, dove un singolo bug di command injection potrebbe trasformarsi in un ampio problema operativo.

Una patch, uno zero-day e il piano di controllo SD-WAN sotto attacco

Pubblicato: 28 Luglio 2026 02:16Categoria: Vulnerabilità e gestione delle patchArea: America del Nord / USAAutore: DEEPAUDIT

La correzione di Arista per una falla di command injection attivamente sfruttata nelle distribuzioni on-premises di VeloCloud Orchestrator ricorda che le interfacce di gestione possono essere la parte più pericolosa della rete.

Corsa alla patch di TeamCity dopo che una RCE critica senza autenticazione colpisce il cuore della CI/CD

Pubblicato: 28 Luglio 2026 02:08Categoria: Vulnerabilità e gestione delle patchArea: Europa / Repubblica CecaAutore: NEONPALADIN

JetBrains ha segnalato una grave vulnerabilità di TeamCity On-Premises che può consentire a un attaccante remoto di eseguire codice senza effettuare il login, mettendo sotto pressione immediata i server di build e la fiducia nelle pipeline.

La debolezza silenziosa di SharePoint: quando una web shell diventa una partita lunga

Pubblicato: 20 Luglio 2026 12:08Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: NEONPALADIN

Lo sfruttamento attivo delle vulnerabilità di SharePoint on-premises ricorda che l'applicazione delle patch da sola potrebbe non porre fine a un'intrusione se gli aggressori riescono anche ad accedere alle machine key di IIS e ad altri segreti del livello applicativo.

SharePoint’s New Crack: Why a “Authenticated-Only” Bug Still Sets Off Alarm Bells

Published: 17 July 2026 10:16Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical SharePoint Server flaw moved from disclosure to exploitation in a hurry, showing how quickly permissioned bugs can become server-level emergencies.

FastNetMon’s Netomics Launch Puts Routing Intelligence Inside the Operator’s Perimeter

Published: 10 July 2026 12:23Category: Technology, Innovation & Digital InfrastructureGeo: Europe / United KingdomAuthor: SECPULSE

FastNetMon has introduced Netomics as a self-hosted routing intelligence platform, a reminder that network visibility is often treated as sensitive infrastructure rather than routine analytics.

Why a Local AI Stack Matters When the Stakes Are Industrial

Published: 10 July 2026 12:14Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A new on-premises AI platform aimed at critical infrastructure is less about flashy model demos and more about where data lives, who controls the updates, and how much trust operators can actually place in automation.

SharePoint’s XML Trapdoor Returns as a Public Exploit Surfaces

Published: 07 July 2026 18:26Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A new proof-of-concept for CVE-2026-33112 puts Microsoft SharePoint’s deserialization surface back under the microscope, with the practical risk centered on authenticated code execution in on-premises servers.

CISA Flags a SharePoint RCE as Active Exploitation Pushes Past Patch Day

Published: 02 July 2026 14:34Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A May Microsoft fix has already become a live defensive problem, with public vulnerability records pointing to a high-severity SharePoint server flaw now under attack.

The Real AI Bottleneck Is Not Intelligence - It Is the Meter Running

Published: 30 June 2026 12:44Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Enterprises are learning that generative AI spend is shaped as much by token accounting and workflow design as by model quality.

One Breach, Two Hands: Why Parallel Activity on SharePoint Matters

Published: 23 June 2026 15:07Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

A single intrusion into on-premises SharePoint can blur into more than one operation, leaving defenders to separate a foothold from the actors moving through it.

The Quiet Repatriation: Why Some Workloads Are Leaving the Cloud

Published: 18 June 2026 10:38Category: Technology, Innovation & Digital InfrastructureAuthor: TRUSTBREAKER

Enterprises are not abandoning cloud computing; they are redrawing boundaries around where data and applications live, driven by portability rules, licensing pressure, and the practical limits of hybrid operations.

AI Is Forcing Cloud Strategy to Grow Up

Published: 10 June 2026 10:17Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

The real shift is not a retreat from public cloud, but a move toward workload-by-workload decisions shaped by cost, data movement, latency, and regulatory control.

SharePoint’s Latest Crack: A Deserialization Bug That Could Turn a Server into a Foothold

Published: 27 May 2026 08:15Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

CVE-2026-45659 puts Microsoft SharePoint Server back in the spotlight, with a flaw that can let an authorized attacker push code over the network and force defenders to think beyond patching alone.

SharePoint’s Trusted Filesystem Turns Risky as a Deserialization Bug Lands in Enterprise Farms

Published: 27 May 2026 06:08Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

CVE-2026-45659 highlights how a server-side input flaw in on-premises SharePoint can turn routine collaboration infrastructure into a code-execution concern for defenders.

SharePoint’s Authenticated RCE Warning Reveals the Cost of Slow Patching

Published: 26 May 2026 16:20Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CVE-2026-45659 shows how a network-reachable flaw in a trusted collaboration platform can turn routine access into a serious server-side risk.