<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyber Attack on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/en-gb/tags/cyber-attack/</link>
    <description>Recent content in Cyber Attack on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-gb</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Thu, 15 May 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/en-gb/tags/cyber-attack/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CVE-2025-32433 Erlang/OTP SSH Pre-Auth RCE: Session Channel Eats Erlang Code</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-05-15-cve-2025-32433-erlang-ssh-rce/</link>
      <pubDate>Thu, 15 May 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-05-15-cve-2025-32433-erlang-ssh-rce/</guid>
      
      <description>&lt;p&gt;Erlang/OTP&amp;rsquo;s SSH server hands client-sent &amp;ldquo;command strings&amp;rdquo; on session channels directly to the Erlang VM to parse and execute — after completing the SSH handshake, attackers send not a normal shell command but an Erlang expression (e.g. &lt;code&gt;os:cmd(&amp;quot;whoami&amp;quot;)&lt;/code&gt;); OTP SSH executes it as code before authentication.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-52287 WSUS Deserialization to RCE: Four-Stage Exploitation via SimpleAuth Cookie Chain</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-04-15-cve-2025-52287-wsus-deserialize/</link>
      <pubDate>Tue, 15 Apr 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-04-15-cve-2025-52287-wsus-deserialize/</guid>
      
      <description>&lt;p&gt;WSUS treats the SimpleAuth plugin&amp;rsquo;s authentication Cookie as &amp;ldquo;verified trust&amp;rdquo;, but the chain that generates the Cookie has no strict deserialization protection — attackers use a 4-stage attack (obtain session ID, get auth Cookie, use Cookie to trigger SimpleAuth, inject malicious .NET deserialization payload) to gain RCE on the patch distribution center.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-5777 Citrix NetScaler Memory Overread: From &lt;InitialValue&gt; Reflection to Pre-Auth Memory Leak</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-03-15-cve-2025-5777-citrix-overread/</link>
      <pubDate>Sat, 15 Mar 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-03-15-cve-2025-5777-citrix-overread/</guid>
      
      <description>&lt;p&gt;Citrix NetScaler reflects the user-supplied login field verbatim into the &lt;code&gt;&amp;lt;InitialValue&amp;gt;&lt;/code&gt; tag of the login response XML — the attacker weaponizes this reflection point by sending an oversized login string, which triggers a memory overread in the NetScaler process and returns adjacent memory as part of the response, leaking session tokens, configuration, credentials, and other sensitive data.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-0133 GlobalProtect Gateway Reflected XSS: credential theft at the VPN portal</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-02-15-cve-2025-0133-globalprotect-xss/</link>
      <pubDate>Sat, 15 Feb 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-02-15-cve-2025-0133-globalprotect-xss/</guid>
      
      <description>&lt;p&gt;The Palo Alto GlobalProtect VPN gateway login page does not filter user input. An attacker injects JavaScript via a malicious URL to steal user credentials.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-0108 PAN-OS Authentication Bypass: Palo Alto firewall compromised again</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-01-15-cve-2025-0108-panos-auth-bypass/</link>
      <pubDate>Wed, 15 Jan 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-01-15-cve-2025-0108-panos-auth-bypass/</guid>
      
      <description>&lt;p&gt;Specific paths of the Palo Alto PAN-OS management interface do not enforce authentication. An attacker bypasses auth to access management functions directly, and combined with command injection, achieves unauthenticated RCE.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-0282 Ivanti Connect Secure Pre-Auth Stack Overflow RCE: Buffer Overflow on the VPN Gateway</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-01-15-cve-2025-0282-ivanti-rce/</link>
      <pubDate>Wed, 15 Jan 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-01-15-cve-2025-0282-ivanti-rce/</guid>
      
      <description>&lt;p&gt;Ivanti Connect Secure exposes the pre-authentication welcome.cgi endpoint directly to the internet without any length check on request parameters — an attacker fills the stack buffer with 500 A&amp;rsquo;s, overwrites the return address with system(), and gets arbitrary command execution on the VPN gateway without any credentials.&lt;/p&gt;</description>
      
    </item>
    
  </channel>
</rss>
