Learn more about how we can help your business prevent attacks like this
Contact Us: https://hubs.ly/Q02JyH5Q0
Pentest ROI Calculator Download: https://hubs.ly/Q02wBB5d0
Linux CUPS Vulnerabilities
A new set of security vulnerabilities has been uncovered in the OpenPrinting Common Unix Printing System (CUPS) on Linux systems, potentially enabling remote command execution. The vulnerabilities, disclosed by security researcher Simone Margaritelli, allow an unauthenticated attacker to replace or install malicious printer IPP URLs, triggering arbitrary code execution when a print job is initiated. The flaws, which impact several Linux distributions including ArchLinux, Debian, and Red Hat Enterprise Linux, pose risks if UDP port 631 is exposed. While the vulnerabilities are serious in technical terms, experts, including Benjamin Harris of WatchTowr and Satnam Narang of Tenable, caution that they are unlikely to reach the severity of past threats like Log4Shell or Heartbleed. Patches are forthcoming, and administrators are advised to disable the affected service and restrict network traffic to mitigate the risk.
More reading:
https://www.evilsocket.net/2024/09/26...
https://www.redhat.com/en/blog/red-ha...
https://ubuntu.com/blog/cups-remote-c...
Misconfigurations Lead to Remote Access of Millions of Kia Cars
Security researcher Sam Curry has disclosed a set of vulnerabilities in Kia's website for vehicle owners that could have allowed attackers to remotely control millions of cars in under 30 seconds, using only the car’s license plate. These flaws not only enabled remote command execution, such as unlocking doors or starting the vehicle, but also allowed attackers to access sensitive personal information, including names, addresses, and phone numbers. By exploiting the Kia dealer website and its backend API, Curry and his team could create new users on vehicles without the owners’ knowledge, granting full control over key functions. Reported in June 2024, Kia acknowledged the vulnerabilities and implemented a fix by mid-August. The exploit affected nearly all Kia vehicles manufactured since 2013, with no alerts provided to owners that their vehicle had been compromised during an attack.
More reading:
https://www.securityweek.com/millions...
https://samcurry.net/hacking-kia#taki...