Logo
TGCATALOG
Каталог Подборки Блог
Vulnerability Management - безопасность

Vulnerability Management - безопасность

Управление уязвимостями, compliance и автоматизация IT-безопасности.

Нет оценок
753
10.09.2026
753
10.09.2026
Нет оценок
753
10.09.2026
Безопасный переход через бот
О канале

Управление уязвимостями, compliance и автоматизация IT-безопасности.

Подписчиков 2,871
Язык Русский
Ссылка t.me/avleonovcom
Описание

Vulnerability Management - канал о оценке уязвимостей, управлении соответствием стандартам и автоматизации безопасности. 🔐🛡️

Здесь публикуют руководства по выявлению угроз, инструментам compliance и скриптам для автоматизации. Полезно для IT-специалистов, отвечающих за защиту систем.

Канал охватывает актуальные новости, лучшие практики и кейсы из практики. Отлично подходит для повышения уровня кибербезопасности в компаниях любого масштаба. 📊🔍

Последние посты

Vulnerability Management - безопасность
Vulnerability Management - безопасность
🔒Открыть пост
и посмотреть медиа
About Elevation of Privilege - Microsoft SharePoint (CVE-2026-56164) vulnerability. The vulnerability was disclosed in the July Microsoft Patch Tuesday release on July 14. The vulnerability, related to missing authentication for a critical function (CWE-306), allows an unauthenticated attacker to remotely elevate their privileges. It is quite interesting that the CVSS scores for the vulnerability differ significantly between Microsoft's website and the NVD. 🔹 Microsoft: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N (5.3 MEDIUM) 🔹 NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8 CRITICAL) As can be seen, the difference is that Microsof's experts consider the impact of successful exploitation on integrity to be low, while the NVD rates the impact on confidentiality, integrity, and availability as high. This once again highlights the subjective nature of CVSS as a vulnerability prioritization tool. 😉 👾 Microsoft experts flagged this vulnerability as being exploited in the wild on the day of Patch Tuesday. The vulnerability was also added to the CISA KEV catalog on the same day. Microsoft credited Mandiant Incident Response for reporting this vulnerability, which suggests that Mandiant may have been involved in identifying the exploitation activity. There are currently no publicly available details regarding the attacks. However, according to Bleeping Computer, this vulnerability may have been exploited in an attack against the Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) reported on July 28. During the incident, credentials for around 200 user and technical accounts were compromised on Internet-facing SharePoint servers. The investigation did not reveal any other data breaches. According to BIT, SharePoint vulnerabilities from the July Microsoft Patch Tuesday were exploited on the servers, although the specific CVEs were not disclosed. 🛠 An exploit for the vulnerability has been available on GitHub since August 6. According to the exploit author's description, the vulnerability allows a remote unauthenticated attacker to elevate privileges to the level of Farm Administrator. By abusing request processing and routing mechanisms, an attacker can force a vulnerable server to fall back to an elevated security context instead of rejecting an unauthenticated request. This enables the attacker to access information about site collections, users, and server configuration, add administrators, and execute commands. ⚙️ Updates are available for Microsoft SharePoint Server 2016, 2019, and Subscription Edition. In addition to installing the updates, Microsoft experts recommend enabling the AMSI antimalware scanning interface on the server and setting the Request Body Scan mode to Full to reduce the risk of exploitation. @avleonovcom #Microsoft #SharePoint #CVSS #CISA #CISAKEV #NVD #Mandiant #AMSI #BleepingComputer #BIT
Vulnerability Management - безопасность
Динамика подписчиков
+-0.1% за 30 дней
Текущие
2,871
Месяц назад
2,873
Средний рост
+0 / день
Обновлено
21 час назад

Отзывы о канале Vulnerability Management - безопасность

Авторизуйтесь, чтобы оставить отзыв

Только зарегистрированные пользователи могут делиться своим мнением.

Пока нет отзывов

Станьте первым, кто поделится своим впечатлением об этом ресурсе!

Похожие ресурсы

CallAnalyserBot - анализ KOL

CallAnalyserBot - анализ KOL

Telegram-инструменты
30

Бот для анализа инфлюенсеров и каналов в Telegram.

Бот

Сообщество Python-разработчиков: вопросы с собеседований, обзоры библиотек, идеи программ и фишки языка.

Канал
Gozilla Bot - YouTube видео

Gozilla Bot - YouTube видео

Telegram-инструменты
89

Бот для загрузки видео и аудио с YouTube в Telegram.

Бот
Переход на светлую тему
Главная Каталог Подборки Блог Вход