Logo
TGCATALOG
Catalog Collections Blog
Vulnerability Management - безопасность

Vulnerability Management - безопасность

Управление уязвимостями, compliance и автоматизация IT-безопасности.

No ratings
755
10.09.2026
755
10.09.2026
No ratings
755
10.09.2026
Safe redirect via bot
О канале

Управление уязвимостями, compliance и автоматизация IT-безопасности.

Подписчиков 2,871
Язык English
Ссылка t.me/avleonovcom
Description

Vulnerability Management - канал о оценке уязвимостей, управлении соответствием стандартам и автоматизации безопасности. 🔐🛡️

Здесь публикуют руководства по выявлению угроз, инструментам compliance и скриптам для автоматизации. Полезно для IT-специалистов, отвечающих за защиту систем.

Канал охватывает актуальные новости, лучшие практики и кейсы из практики. Отлично подходит для повышения уровня кибербезопасности в компаниях любого масштаба. 📊🔍

Latest posts

Vulnerability Management - безопасность
Vulnerability Management - безопасность
🔒Открыть пост
и посмотреть медиа
About Elevation of Privilege - Microsoft SharePoint (CVE-2026-56164) vulnerability. The vulnerability was disclosed in the July Microsoft Patch Tuesday release on July 14. The vulnerability, related to missing authentication for a critical function (CWE-306), allows an unauthenticated attacker to remotely elevate their privileges. It is quite interesting that the CVSS scores for the vulnerability differ significantly between Microsoft's website and the NVD. 🔹 Microsoft: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N (5.3 MEDIUM) 🔹 NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8 CRITICAL) As can be seen, the difference is that Microsof's experts consider the impact of successful exploitation on integrity to be low, while the NVD rates the impact on confidentiality, integrity, and availability as high. This once again highlights the subjective nature of CVSS as a vulnerability prioritization tool. 😉 👾 Microsoft experts flagged this vulnerability as being exploited in the wild on the day of Patch Tuesday. The vulnerability was also added to the CISA KEV catalog on the same day. Microsoft credited Mandiant Incident Response for reporting this vulnerability, which suggests that Mandiant may have been involved in identifying the exploitation activity. There are currently no publicly available details regarding the attacks. However, according to Bleeping Computer, this vulnerability may have been exploited in an attack against the Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) reported on July 28. During the incident, credentials for around 200 user and technical accounts were compromised on Internet-facing SharePoint servers. The investigation did not reveal any other data breaches. According to BIT, SharePoint vulnerabilities from the July Microsoft Patch Tuesday were exploited on the servers, although the specific CVEs were not disclosed. 🛠 An exploit for the vulnerability has been available on GitHub since August 6. According to the exploit author's description, the vulnerability allows a remote unauthenticated attacker to elevate privileges to the level of Farm Administrator. By abusing request processing and routing mechanisms, an attacker can force a vulnerable server to fall back to an elevated security context instead of rejecting an unauthenticated request. This enables the attacker to access information about site collections, users, and server configuration, add administrators, and execute commands. ⚙️ Updates are available for Microsoft SharePoint Server 2016, 2019, and Subscription Edition. In addition to installing the updates, Microsoft experts recommend enabling the AMSI antimalware scanning interface on the server and setting the Request Body Scan mode to Full to reduce the risk of exploitation. @avleonovcom #Microsoft #SharePoint #CVSS #CISA #CISAKEV #NVD #Mandiant #AMSI #BleepingComputer #BIT
Vulnerability Management - безопасность
Subscriber dynamics
+-0.1% last 30 days
Current
2,871
Month ago
2,873
Average growth
+0 / day
Updated
22 hours ago

Reviews for channel Vulnerability Management - безопасность

Log in to leave a review

Only registered users can share their opinion.

No reviews yet

Be the first to share your impression of this resource!

Similar resources

Stickers Tools - analyst stickers

Stickers Tools - analyst stickers

Telegram-инструменты
28

Tool for analyzing sticker packs.

Bot
Cyber CyberDetective-OSINTtool

Cyber CyberDetective-OSINTtool

Telegram-инструменты
50

Cyber CyberDetectivedailyOSINTinstruments,forensicsandcybersecurityTelegram.

Channel
Gozilla Bot - YouTube video

Gozilla Bot - YouTube video

Telegram-инструменты
89

Bot for downloading videos and audio from YouTube in Telegram.

Bot
Switch to Light Theme
Home Catalog Collections Blog Login