Atlassian has been down for a week or two. The report on why is … definitely on topic.

Twitter avatar for @cynicalsecurity
Arrigo Triulzi @cynicalsecurity
Faulty script. Second, the script we used provided both the "mark for deletion" capability used in normal day-to-day operations (where recoverability is desirable), and the "permanently delete" capability that is required to permanently remove data when required for compliance reasons. The script was executed with the wrong execution mode and the wrong list of IDs. The result was that sites for approximately 400 customers were improperly deleted.


PoC

Twitter avatar for @_r_netsec
/r/netsec @_r_netsec
A real PoC for CVE-2022-21907 RCE DoS IIS


Analysis of a load of crypto code reveals that it isn’t secure because of bad ransomness. Apparently.

Twitter avatar for @trailofbits
Trail of Bits @trailofbits
Your code might be vulnerable! Our cryptography team has discovered a number of Fiat-Shamir vulnerabilities affecting proof systems such as Bulletproofs and PlonK. Check out this blog series for details and contact us if you think your codebase might be…


This is just good news. Though of course the fact that it is necessary in the year of our lord two thousand and twenty two is a fucking tragedy.

Twitter avatar for @jbendery
Jennifer Bendery @jbendery
NEW: In an incredibly unusual move, the Air Force is making a point to let its hundreds of thousands of personnel know that it will provide families with medical + legal help if they are being hurt by new state laws attacking gay and transgender children.


You down with RCE?

Yeah you know me

You down with RCE?

Yeah you know me

Twitter avatar for @l33d0hyun
DoHyun Lee @l33d0hyun
CVE-2022-24543: Windows Upgrade Assistant Remote Code Execution Vulnerability

I was assigned a second Microsoft Product Remote Code Execution CVE.

Image

Don't miss what's next. Subscribe to the grugq's newsletter: