Cisco CVE-2023-20198 exploitation activity: We see over 32.8K Cisco IOS XE IPs compromised with implants based on the check published by Cisco in blog.talosintelligence.com/act

IP data on implants shared out daily in: shadowserver.org/what-we-do/ne tagged 'device-implant'.

All existing #curl CVEs are now available as #JSON: curl.se/docs/vuln.json

All individual issues are also available as JSON, like for example CVE-2023-27538 like this: curl.se/docs/CVE-2023-27538.js

Enjoy!

#infosec

WiFi protocol flaw allows attackers to hijack network traffic 👇🏾

"Cisco, admitting that the attacks outlined in the paper may be successful against Cisco Wireless Access Point products and Cisco Meraki products with wireless capabilities.

However, Cisco believes says that the retrieved frames are unlikely to jeopardize the overall security of a properly secured network."

bleepingcomputer.com/news/secu

This is great - Google providing 100,000 free security keys through 2023 to high-risk users. (Though I am still disappointed that - after all of the joint early work Google did with Yubico - they went with Feitian instead of Yubico to provide the raw hardware for the current Titan Security Key series.)

blog.google/technology/safety-

#securitykeys #google #yubico #yubikey

Friends in #security that use #macOS, are you using Lockdown Mode? Why or why not?

Mastodon BASIC experimental (Futex BBS)

Futex BBS