Logo
TGCATALOG
Catálogo Selecciones Blog
Vulnerability Management - безопасность

Vulnerability Management - безопасность

Управление уязвимостями, compliance и автоматизация IT-безопасности.

Sin valoraciones
752
10.09.2026
752
10.09.2026
Sin valoraciones
752
10.09.2026
Redirección segura vía bot
О канале

Управление уязвимостями, compliance и автоматизация IT-безопасности.

Подписчиков 2,871
Язык Español
Ссылка t.me/avleonovcom
Descripción

Vulnerability Management - канал о оценке уязвимостей, управлении соответствием стандартам и автоматизации безопасности. 🔐🛡️

Здесь публикуют руководства по выявлению угроз, инструментам compliance и скриптам для автоматизации. Полезно для IT-специалистов, отвечающих за защиту систем.

Канал охватывает актуальные новости, лучшие практики и кейсы из практики. Отлично подходит для повышения уровня кибербезопасности в компаниях любого масштаба. 📊🔍

Últimas publicaciones

Vulnerability Management - безопасность
Vulnerability Management - безопасность
🔒Открыть пост
и посмотреть медиа
About Elevation of Privilege - Microsoft SharePoint (CVE-2026-56164) vulnerability. The vulnerability was disclosed in the July Microsoft Patch Tuesday release on July 14. The vulnerability, related to missing authentication for a critical function (CWE-306), allows an unauthenticated attacker to remotely elevate their privileges. It is quite interesting that the CVSS scores for the vulnerability differ significantly between Microsoft's website and the NVD. 🔹 Microsoft: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N (5.3 MEDIUM) 🔹 NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8 CRITICAL) As can be seen, the difference is that Microsof's experts consider the impact of successful exploitation on integrity to be low, while the NVD rates the impact on confidentiality, integrity, and availability as high. This once again highlights the subjective nature of CVSS as a vulnerability prioritization tool. 😉 👾 Microsoft experts flagged this vulnerability as being exploited in the wild on the day of Patch Tuesday. The vulnerability was also added to the CISA KEV catalog on the same day. Microsoft credited Mandiant Incident Response for reporting this vulnerability, which suggests that Mandiant may have been involved in identifying the exploitation activity. There are currently no publicly available details regarding the attacks. However, according to Bleeping Computer, this vulnerability may have been exploited in an attack against the Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) reported on July 28. During the incident, credentials for around 200 user and technical accounts were compromised on Internet-facing SharePoint servers. The investigation did not reveal any other data breaches. According to BIT, SharePoint vulnerabilities from the July Microsoft Patch Tuesday were exploited on the servers, although the specific CVEs were not disclosed. 🛠 An exploit for the vulnerability has been available on GitHub since August 6. According to the exploit author's description, the vulnerability allows a remote unauthenticated attacker to elevate privileges to the level of Farm Administrator. By abusing request processing and routing mechanisms, an attacker can force a vulnerable server to fall back to an elevated security context instead of rejecting an unauthenticated request. This enables the attacker to access information about site collections, users, and server configuration, add administrators, and execute commands. ⚙️ Updates are available for Microsoft SharePoint Server 2016, 2019, and Subscription Edition. In addition to installing the updates, Microsoft experts recommend enabling the AMSI antimalware scanning interface on the server and setting the Request Body Scan mode to Full to reduce the risk of exploitation. @avleonovcom #Microsoft #SharePoint #CVSS #CISA #CISAKEV #NVD #Mandiant #AMSI #BleepingComputer #BIT
Vulnerability Management - безопасность
Evolución de suscriptores
+-0.1% últimos 30 días
Actuales
2,871
Hace un mes
2,873
Crecimiento medio
+0 / día
Actualizado
hace 21 horas

Reseñas de canal Vulnerability Management - безопасность

Inicia sesión para dejar una reseña

Solo los usuarios registrados pueden compartir su opinión.

Aún no hay reseñas

¡Sé el primero en compartir tu experiencia con este recurso!

Recursos similares

Ayuda de canal - Ayuda en italiano

Ayuda de canal - Ayuda en italiano

Telegram-инструменты
29

Un canal italiano con instrucciones y ayuda para usar un bot de Telegram.

Canal
Ciklopo - Búsqueda de canales OSINT

Ciklopo - Búsqueda de canales OSINT

Telegram-инструменты
33

Servicio OSINT para buscar y monitorear canales Telegram. Busque información de miles de fuentes regionales de manera rápida y eficiente.

Bot
Los CyberDeals- Cyber descuentos.

Los CyberDeals- Cyber descuentos.

Telegram-инструменты
43

Canal con descuentos cibernéticos: promociones para electrónica, ropa, gadgets. Ofertas calientes y cupones en Telegram.

Canal
Cambiar a tema claro
Inicio Catálogo Selecciones Blog Entrar