Feb. 28, 2024, 5:20 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Our analysis has identified multiple vulnerabilities affecting Zyxel’s USG line of firewalls and VPN appliances running firmware versions 5.36 and below. The vulnerabilities can allow an unauthenticated attacker to force the admin interface of the device to send an HTTP GET to any URL of the attacker’s choosing and store the full response on the device. This creates the potential for an XSS against the administrator account of the device, ultimately leading to full attacker control of the appliance. Likewise, …

admin analysis attacker can device don fire firewall firewalls firmware fix http http get interface play prioritize running send unauthenticated update url vpn vulnerabilities vulnerability zyxel

Senior Security Specialist, Forsah Technical and Vocational Education and Training (Forsah TVET) (NEW)

@ IREX | Ramallah, West Bank, Palestinian National Authority

Consultant(e) Junior Cybersécurité

@ Sia Partners | Paris, France

Senior Network Security Engineer

@ NielsenIQ | Mexico City, Mexico

Senior Consultant, Payment Intelligence

@ Visa | Washington, DC, United States

Corporate Counsel, Compliance

@ Okta | San Francisco, CA; Bellevue, WA; Chicago, IL; New York City; Washington, DC; Austin, TX

Security Operations Engineer

@ Samsara | Remote - US