March 30, 2023, 3:50 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Keane O’Kelley of Cisco ASIG discovered this vulnerability.

Cisco ASIG recently discovered a remote code execution vulnerability in the SNIProxy open-source tool that occurs when the user utilizes wildcard backend hosts.

SNIProxy proxies incoming HTTP and TLS connections based on the hostname contained in the initial request of the TCP session. This open-source tool allows for users to carry out name-based proxying of HTTPS without decrypting traffic or needing a key or certificate.

Talos discovered a remote code execution vulnerability …

backend certificate cisco code code execution connections cve http https key name proxies proxying remote code remote code execution request session spotlight talos tcp tls tool traffic vulnerability vulnerability spotlight

Director, Cyber Risk

@ Kroll | South Africa

Security Engineer, XRM

@ Meta | New York City

Security Analyst 3

@ Oracle | Romania

Internship - Cyber Security Operations

@ SES | Betzdorf, LU

Principal Product Manager (Network/Security Management) - NetSec

@ Palo Alto Networks | Bengaluru, India

IT Security Engineer

@ Timocom GmbH | Erkrath, Germany