Tag: http

security

SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo

HTTP QUERY Method: The Grey Zone Between GET and POST https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352 Simple MacOS Docker Escape https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179 Brevo ClickFix Compromise https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Mehr lesen →
security

Kritische NGINX-Lücken in HTTP/3- und HTTP/2-Modulen

F5 schließt zwei kritische Speicherfehler im NGINX-Webserver, die Angreifern ohne Anmeldung Denial of Service und Codeausführung ermöglichen. Betroffen sind HTTP/3-Verarbeitung und HTTP/2-Proxying, bewertet mit CVSS von 9.2. Die außerplanmäßigen Patches kommen kurz nach NGINX Rift, dessen Rewrite-Lücke binnen Tagen nach Offenlegung ausgenutzt wurde.

Mehr lesen →