JSOF Cyber Security (@jsof18) 's Twitter Profile
JSOF Cyber Security

@jsof18

JSOF is a boutique cyber consultancy and project firm. We are cyber security experts

ID: 1218184289046728706

linkhttp://www.jsof-tech.com calendar_today17-01-2020 14:52:52

250 Tweet

812 Followers

540 Following

Moshe Kol (@0xkol) 's Twitter Profile Photo

Today we release #DNSpooq - 7 vulnerabilities in dnsmasq, a popular open source DNS forwarder. 3 vulnerabilities enable cache poisoning and the other 4 are pre-DNSSEC-validation buffer overflows. Patch! jsof-tech.com/disclosures/dn…

JSOF Cyber Security (@jsof18) 's Twitter Profile Photo

Some recommended workarounds for #dnspooq if you can't upgrade your device. Configuring your devices to directly query a trusted DNS server would also be helpful.

JSOF Cyber Security (@jsof18) 's Twitter Profile Photo

Supply chain issues affect Open Source Software too. Dnsmasq is extremely popular (and for a good reason!) and so the vulnerabilities affect dozens of vendors and many major Linux distributions.

Qualys (@qualys) 's Twitter Profile Photo

The Qualys Research Team has discovered a critical vulnerability in #Sudo, which allows an unprivileged user to gain root privileges in its default configuration. #linux #unix #vulnerability blog.qualys.com/vulnerabilitie…

samvartaka (@s4mvartaka) 's Twitter Profile Photo

As part of Project Memoria we're releasing a report together with JSOF Cyber Security on several DNS vulnerabilities in popular TCP/IP stacks (FreeBSD, NetX, Nucleus NET, ...), including a breakdown of underlying anti-patterns (hint: check your message compression). forescout.com/research-labs/…

Forescout (@forescout) 's Twitter Profile Photo

Forescout & JSOF Cyber Security research disclose NAME:WRECK - 9 new DNS #vulnerabilities affecting popular TCP/IP stacks used in millions of #IoT #OT & IT devices. ow.ly/62ne50EnkpK #NAMEWRECK

Mathy Vanhoef (@vanhoefm) 's Twitter Profile Photo

I found some design and implementation flaws in Wi-Fi again. All Wi-Fi devices are affected. It was a long ~9 months embargo, over this time a lot of info has been collected and that info now available at fragattacks.com