Hírolvasó

Egykattintásos kémkedéstől  ShinyHunters-letartóztatásig – Heti összefoglaló

Tech.cert-hungary.hu - p, 10/02/2026 - 10:16
Az orosz Star Blizzard egyetlen kattintásra egyszerűsítette a fertőzési láncát, és Ukrajnáról globális célpontokra váltott. Az adathalászat a hét másik meghatározó témája: Google-ellenőrzött hirdetéseken keresztül lopták el a Ledger-tárcák helyreállítási kifejezéseit. Két adatvédelmi incidensről is beszámoltak: egy török e-kereskedelmi szolgáltatóhoz kapcsolódó támadásnál legalább 10,8 millió ember adatai érintettek, Lengyelországban pedig illetéktelen hozzáférést észleltek egy több […]

A Signal iOS és asztali alkalmazásaihoz is bevezette a helyi titkosított mentési funkciót

Tech.cert-hungary.hu - p, 10/02/2026 - 06:39
Kiadásra került a Signal üzenetküldő alkalmazás 8.30-as verziója, így minden támogatott operációs rendszer (Android, iOS, Linux, macOS és Windows) számára elérhetővé vált a helyi biztonsági mentés funkció. Android rendszeren közel egy éve került bevezetésre a funkció, amely lehetővé teszi a felhasználók számára, hogy végpontok közötti titkosítással ellátott biztonsági mentést készítsenek a csevegéseikről, így a készülék […]

VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations

US-CERT.gov - cs, 10/01/2026 - 16:33
Overview

An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations.

Description

HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system.

CVE-2026-12855: An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler.

An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The vulnerable handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation.

Because the affected handler executes in SMM, the resulting arbitrary physical memory write can target memory regions that are normally inaccessible to software executing outside SMM, including SMRAM. Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution in SMM. The ability to affect firmware or ROM contents is platform-dependent and is not assumed as a direct consequence of this vulnerability.

Impact

An attacker with privileged OS kernel access (ring 0) can exploit the vulnerability by raising Software SMI interrupts through I/O port 0xB2 with crafted CPU register values. Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution and persistence via modifying SMRAM.

Solution

Users should check HP's security bulletins to determine whether their system is affected. Insyde advisory is available at https://www.insyde.com/security-pledge/sa-2026009/

Acknowledgements

Thank you to Zhenyu Liu for reporting these vulnerabilities. This document was written by Vijay Sarvepalli.

Kategóriák: Biztonsági hírek

Az ukrán hatóság iPhone-t is érintő kártevőkre hívja fel a figyelmet

Tech.cert-hungary.hu - cs, 10/01/2026 - 13:29
Egyre gyakrabban célozzák meg ukrán katonai személyzetek és kormányhivatalnokok telefonjait az orosz kibertámadók, kémkedés és anyagi érdekek által vezérelt okokból. Az Ukrajnai Különleges Hírközlési és Információvédelmi Állami Szolgálat azt állapította meg hogy mind Android és iOS alapú eszközöket támadnak rosszindulatú alkalmazások és sérülékenységek kihasználásával. Az egyik ilyen eszköz a „DarkSword” nevű sebezhetőséget-kihasználó eszköz melyet kifejezetten […]

Kibertámadás érte a litván belügyminisztérium egyik archivált rendszerét

Tech.cert-hungary.hu - k, 09/29/2026 - 11:45
Kibertámadás érte a litván belügyminisztérium egyik információs rendszerét. A támadók az EPEKIS rendszerhez szereztek jogosulatlan hozzáférést. A rendszert 2018 óta nem használják aktívan, jelenleg archivált rendszerként működik. Az EPEKIS korábban a litván állampolgároknak és külföldieknek nyújtott, a személyes és egyéb okmányok kiadásával, valamint a tanácsadással kapcsolatos közszolgáltatásokat támogatta. Az archivált rendszer a litván állampolgárságot kérő […]

Kibertámadás érte a spanyol Renfe vasúttársaságot

Tech.cert-hungary.hu - k, 09/29/2026 - 11:35
A Renfe spanyol állami vasúttársaság rendszereibe behatolás történt egy korábban kompromittálódott vasúti infrastruktúrakezelő vállalat, az Adif szerverei miatt, amelyekkel hálózati kapcsolatban álltak. A támadók korlátozott számú nevekhez és e-mail címekhez fértek hozzá. Érzékenyebb adatok, mint például banki fizetési adatok vagy személyi azonosítók nem szivárogtak ki. A Renfe azonnal alkalmazta az incidenskezelési protokollokat és elzárta az […]

Esetleges zero-day támadás miatt a Kiteworks a rendszerek leállítását kérte

Tech.cert-hungary.hu - k, 09/29/2026 - 11:16
A Kiteworks arra figyelmeztette ügyfeleit, hogy egy esetleges zero-day támadás miatt ideiglenesen állítsák le rendszereiket. A vállalat a hatóságoktól kapott hiteles információkat egy lehetséges támadásról, ugyanakkor jelenleg nincs tudomása a Kiteworks-rendszerek kompromittálódásáról. A Kiteworks egy amerikai szoftvercég, amely biztonságos és bizalmas kommunikációt lehetővé tevő termékeket kínál, amelyeket többek között hatóságok és pénzügyi intézmények is használnak. […]

Kibertámadás érte a lengyel Medyc egészségügyi szoftverfejlesztőt, betegek adatai szivárogtak ki

Tech.cert-hungary.hu - k, 09/29/2026 - 10:57
Az utóbbi hetekben több súlyos kibertámadás érte a lengyel egészségügyi szektort. A felhőalapú, Qbusoft által fejlesztett Medyc elektronikus orvosi platform egy SQL-injekciós sérülékenység miatt vált kompromittálttá. Az augusztusi támadás során páciensek személyes adatait (nevek, lakcímek, azonosítók) és nagy valószínűséggel érzékeny egészségügyi dokumentumokat, például kezelési zárójelentéseket is megszerezték. A támadók egy titkosított adatbázis-archívumot szivárogtattak ki, melynek […]

Több tucat szervezetet érinthet a ShinyHunters új PeopleSoft-kampánya

Tech.cert-hungary.hu - k, 09/29/2026 - 10:43
Újra aktívan kihasználja a ShinyHunters kiberbűnözői csoport a CVE-2026-35273 azonosítójú, Oracle PeopleSoft rendszereket érintő sérülékenységet. A hibát az Oracle június 10-én javította, miután a Mandiant korábban jelezte, hogy a támadók május 27. és június 9. között, zero-dayként használták ki, elsősorban felsőoktatási intézmények ellen. A mostani kampányban azonban a támadók már olyan szervezeteket is célba vehettek, […]

Célzott támadásban is kihasználhatták az Apple sérülékenységét

Tech.cert-hungary.hu - k, 09/29/2026 - 10:27
Az Apple biztonsági frissítést adott ki az iOS, iPadOS és macOS rendszerek régebbi verzióit érintő sebezhetősége miatt, amelyet a cég elmondása szerint célzott támadások során is kihasználhattak. A CVE-2026-86950 azonosítójú sebezhetőség a CoreGraphics összetevőt érintő out-of-bounds memóriaírási hiba, ami tetszőleges kódfuttatást tesz lehetővé. Az Apple a határellenőrzés (bounds checking) fejlesztésével oldotta meg a problémát. A […]

Biztonsági aggályok miatt nem adják ki az OpenAI új modelljét

Tech.cert-hungary.hu - k, 09/29/2026 - 10:23
Az OpenAI még a hónap elején mutatta be az Astrát, mint eddigi legerősebb modelljét. A cég a következő hónapban tervezte az újabb modell kiadását, azonban biztonsági aggályok miatt úgy döntöttek, egyelőre elmarad a megjelenés. A The Wall Street Journail (WSJ) szerint az Astra 6.1 névre keresztelt modell kiadása a következő hónapra volt tervezve, viszont a […]

Felhasználói képeket töltöttek fel külső szolgáltatásokhoz az OpenAI MI-ágensei

Tech.cert-hungary.hu - k, 09/29/2026 - 04:45
Az OpenAI megerősítette azt az új biztonsági incidenst, amely során a mesterséges intelligencia (MI) ágensei felhasználók által megadott képeket töltöttek fel külső képtároló szolgáltatókhoz. A vállalat tájékoztatása szerint eddig 53 ilyen esetet azonosítottak annak az átfogó vizsgálatnak a részeként, amelyet az ágensek nem kívánatos viselkedésével kapcsolatban indítottak még a Hugging Face-t érintő biztonság incidens következtében. […]

VU#762428: Authlib library contains a signature‑verification bypass vulnerability

US-CERT.gov - h, 09/28/2026 - 21:36
Overview

Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material.

Description

Authlib is a Python library that provides tools for implementing OAuth, OpenID Connect, JWT/JWS/JWE (JSON Web Token / JSON Web Signature / JSON Web Encryption), and other modern authentication and authorization standards. It’s widely used in web applications and microservices to handle token creation, cryptographic validation, and secure communication.

As discussed in CVE-2026-96760, a security flaw in Authlib’s handling of JSON Web Signatures (JWS) makes it possible for an attacker to skip signature verification completely. Normally, a JWS should include at least one valid signature to prove the data hasn’t been tampered with. However, Authlib’s deserialize_json() function mistakenly accepts JWS objects even when the "signatures" section is an empty list. Because the function starts by assuming the signatures are valid and never performs any checks when the list is empty, it ends up treating unsigned data as if it were properly signed. This means an attacker could provide a JWS with no signatures, and Authlib would still treat it as trusted. Both ways of loading a JWS in Authlib are affected:

jws.deserialize_json({"payload":"...", "signatures":[]}, key=None)
jws.deserialize('{"payload":"...","signatures":[]}', key=None)

Impact

An attacker can forge arbitrary authenticated payloads without any signing key or credentials. Systems that rely on Authlib’s JWS verification for authentication, authorization, inter-service message integrity, or signed configuration data may accept attacker‑supplied content as legitimate. Potential attack scenarios inlcude the following:
* Authentication bypass: forged identity or privilege‑escalation claims (e.g., sub=admin).
* Signed message injection between microservices using JWS.
* Forged authorization claims such as scopes, roles, or permissions.
* Integrity bypass in systems relying on signed JWS data.

Solution

The vendor could not be reached to coordinate this vulnerability and an official patch has not been made available at the time of this writing. Users are advised to monitor the project's GitHub repository for updates and install the latest version of this library once a fix has been released.

Acknowledgements

Thank you to Tong Hoang Gia (uziii2208) and Nguyen Minh Tuan (nguyenminhtuan28) for reporting this vulnerability. This document was written by Bob Kemerer.

Kategóriák: Biztonsági hírek

Fizetett Meta hirdetésekkel terjesztett Android kártevőt azonosított a lengyel CERT

Tech.cert-hungary.hu - h, 09/28/2026 - 12:42
A lengyel CERT Polska egy kiterjedt, Android-eszközöket érintő toll fraud (prémiumszolgáltatásokkal visszaélő) támadássorozatot azonosított és zavart meg, amely fizetett Meta-hirdetésekkel irányította a lengyel felhasználókat kártékony alkalmazások letöltésére a Google Play Áruházból. A vizsgálat során 1235 Meta-hirdetést dokumentáltak, amelyek közül 852 összesen 17, a támadássorozathoz köthető alkalmazást népszerűsített. Hat alkalmazásban bizonyítottan jelen voltak a prémiumszolgáltatásokkal való […]

VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

US-CERT.gov - p, 09/25/2026 - 18:25
Overview

Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens.

Description

Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. It is available on multiple platforms including Android and can synchronize content across devices.

CVE-2026-18311: A stored cross-site scripting (XSS) vulnerability in the header rendering component in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via crafted document metadata fields. The header rendering component is impacted due to insufficient HTML escaping of metadata fields such as 'doc.author' and 'doc.title', which allows malicious scripts to be stored in the user's library and synchronized to Android devices where they are executed in the WebView context.

CVE-2026-18312: A stored cross-site scripting (XSS) vulnerability in the WebView URL construction logic in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via malicious URL metadata. The WebView URL construction for X (formerly Twitter) video fallback and iOS paywall messages is impacted due to improper escaping of URL metadata before interpolation into href attributes, which allows user-controlled values to break out of the URL structure and inject script elements that are inserted into the DOM via innerHTML.

CVE-2026-18320: A stored cross-site scripting (XSS) vulnerability in the article body sanitization component in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via malicious SVG markup. The sanitize-html configuration is impacted due to a wildcard attribute rule that permits all attributes on SVG and PATH elements, which allows script-capable attributes such as onload and onerror to bypass sanitization.

Impact

An attacker with the ability to create or modify documents accessible to Readwise Reader can supply documents containing malicious metadata or markup that bypasses sanitization and is subsequently stored in users libraries. Because these documents are synchronized to Android devices and rendered within the Reader WebView, each vulnerability enables stored XSS: CVE-2026-18311 and CVE-2026-18312 through poisoned metadata, and CVE-2026-18320 through malicious SVG markup.

Solution

Unfortunately, the vendor could not be reached to coordinate this issue. Users should apply vendor updates as they become available (check Vendor Information section for updates) and keep Readwise Reader updated through the Google Play Store. As of publication, version 8.10.1 includes a patch that addresses the sanitizer-wildcard issue. Additionally, users should exercise caution when adding content from untrusted sources to their reading library and consider manually reviewing document metadata before saving articles to minimize exposure to malicious content.

Acknowledgements

Thanks to Zampier Zago (FUNFACTOR1) for reporting these vulnerabilities. This document was written by Alex Lewis.

Kategóriák: Biztonsági hírek

Ausztrál kormányzati rendszerekhez fért hozzá egy OpenAI ügynök

Tech.cert-hungary.hu - p, 09/25/2026 - 10:01
Az OpenAI egyik mesterséges intelligencia ügynöke júniusban jogosulatlanul hozzáfért egy ausztrál kormányzati egészségügyi weboldal nem nyilvános fájljaihoz.

Kihasznált webes sérülékenységektől az AI-vezérelt bűnözői műveletekig – Heti összefoglaló

Tech.cert-hungary.hu - p, 09/25/2026 - 09:37
A hét egyik fő kockázatát az internet felől elérhető rendszerek sérülékenységei jelentik: a WordPress egyik frissen javított hibáját órákon belül támadni kezdték, miközben egy májusban javított Roundcube-hiba aktív kihasználását is megerősítették. Emellett az AI egyre nagyobb szerepet kap a támadások automatizálásában, az ukrajnai események pedig ismét megmutatták a fizikai és a digitális infrastruktúra szoros összefonódását.

Frissített OT-biztonsági útmutatót ad ki a NIST

Tech.cert-hungary.hu - p, 09/25/2026 - 09:33
A NIST közzétette az operatív technológia (OT) biztonságáról szóló Special Publication 800-82 Revision 4 c. útmutatójának frissített tervezetét. A dokumentum nyilvános véleményezése 2026. november 30-ig tart. Az útmutató bemutatja, hogyan biztosítható az OT-rendszerek védelme a teljesítményre, megbízhatóságra és üzembiztonságra vonatkozó sajátos követelmények figyelembevételével. A felülvizsgált változat kibővíti az érintett ágazatok körét, többek között az épületautomatizálással, […]

VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise

US-CERT.gov - cs, 09/24/2026 - 21:27
Overview

ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise.

Description

ViewSonic ViewBoards are widely used smart display devices (smartboard), typically deoloyed in enterprise and educational environments. vCast is ViewSonic’s proprietary software suite for wireless connection between smartboards, which are Android-based systems, and devices running a client application. Three distinct vulnerabilities, all invoking unauthenticated endpoints, have been identified within the vCast suite.

CVE-2026-82989
vCast’s media streaming service allows a remote attacker to exfiltrate JPEG images of screen content via GET requests to an unauthenticated /snapshot or /screen API endpoint.

CVE-2026-82988
vCast’s Android Package Kit (APK) delivery mechanism allows a remote attacker to trigger unprivileged file installation by providing a malicious APK URL through an unauthenticated download endpoint.

CVE-2026-82987
vCast’s network services allow a remote attacker to inject arbitrary input into service endpoints via HTTP requests to exposed unauthenticated endpoints

Impact

An unauthenticated attacker can chain these vulnerabilities via a shared network to deliver and execute arbitrary code on a vCast-based device without user interaction. Potential device-level impact includes unauthorized access to displayed content, persistent installation and execution of arbitrary applications, and full compromise of the device. Additionally, an exploited device’s connected network may be prone to lateral movement.

Solution

Unfortunately, ViewSonic could not be reached to coordinate the vulnerability. In the meantime, firmware updates should be applied when available. If possible, segment vCast devices onto an isolated, secure network with strict controls, separate from systems containing sensitive data. Network activity should be monitored for suspicious vCast connections.

Acknowledgements

Thank you to Adam Mohammed Zenker for this report. This document was written by Alexander Lewis.

Kategóriák: Biztonsági hírek

VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability

US-CERT.gov - cs, 09/24/2026 - 17:44
Overview

Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers.

Description

Norwegian Cruise Line is a global cruise company that operates a modern fleet sailing to destinations worldwide. As described in CVE-2026-75907, the affected card reader authenticates NFC credentials only by checking their static 7-byte UID. A UID is not a secret and does not support cryptographic challenge‑response operations, so it cannot serve as a reliable authentication factor. Although the keycard's NTAG212 tag contains a memory block with a printed serial number and a value resembling a signature, the reader does not inspect this data during the access-control process. Validation based solely on UID constitutes identification rather than authentication. Because the credential performs no cryptographic exchange and offers no defense against cloning, any device capable of replaying or emulating UIDs can reproduce a functioning keycard.

Impact

An attacker with brief physical proximity to a valid keycard can use an RFID reader to capture the UID without interacting with or altering the card. Once obtained, this UID can be copied to an inexpensive UID‑writable card to create a permanent duplicate credential. The access control readers will accept these forgeries as genuine, granting entry. Depending on logging configuration, the unauthorized entry may be indistinguishable from legitimate use. Because unauthorized access to restricted areas on a cruise vessel can have direct safety implications, this vulnerability presents a significant security risk to both internal operations and guest safety.

Solution

Unfortunately, we were unable to reach the vendor to coordinate this vulnerability. Users are encouraged to employ the following methods to help reduce the risk of RFID cloning:
* RFID‑blocking wallets and shielded card-holder sleeves prevent unauthorized scans.
* Placing aluminum foil on both sides of your RFID card can help limit signal transmission by creating a basic Faraday shield.
* When using or storing your card, try to keep a distance of at least 12 inches from other people or devices. Cards operating at 13.56 MHz are usually read at an approximate distance of 2–5 cm (1–2 inches).

Acknowledgements

Thank you to Mark Linton for reporting this vulnerability. This document was written by Bob Kemerer.

Kategóriák: Biztonsági hírek

Oldalak

Feliratkozás Anaheim.hu hírolvasó csatornájára