We have identified some security vulnerabilities (CVE-2025-1731) in Zyxel USG FLEX H Series firewall appliances, that allow local users with access to a Linux OS shell to escalate privileges to root.

https://security.humanativaspa.it/local-privilege-escalation-on-zyxel-usg-flex-h-series-cve-2025-1731

#Zyxel #VulnerabilityResearch #CoordinatedDisclosure
Local privilege escalation on Zyxel USG FLEX H Series (CVE-2025-1731) - hn security

“So we wait, this is our […]

hn security
oss-security - MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client

We Speak CVE Podcast episode 26 now available!
“CNA Onboarding Process Myths Versus Facts”
https://youtu.be/N22bsppsJSQ

#CVE #Vulnerability #VulnerabilityManagement #Cybersecurity #EOL #CoordinatedDisclosure #InformationSecurity
CNA Onboarding Process Myths Versus Facts

YouTube
As they are not responding to emails, we are looking for security contacts at Atos/Unify for #coordinatedDisclosure #responsibledisclosure purposes. Please help finding someone, the 2 week initial response deadline is ticking fast... #vulnerability
#coordinateddisclosure is such a pain. Vendor with PGP key on website, we send encrypted advisory. They reply they can‘t decrypt and ask if we exchanged keys already… *sigh* disclosure timeline is running though
Kontroverse nach Ende des Organspende-Registers: Wann müssen Lücken öffentlich werden?

Die Tragödie um das Register von Swisstransplant kennt nur Verlierer. Die Schweiz braucht eine politische Diskussion zu Datenbanken mit sensiblen Informationen und zum Meldeverfahren von Sicherheitslücken.

Episode 233: Unpacking Log4Shell’s Un-coordinated Disclosure Chaos |

Mark Stanislav, a Vice President at Gemini, joins Paul to talk about what went wrong with disclosure of Log4Shell, the flaw in Log4j.

The Security Ledger with Paul F. Roberts
Facebook Debuts Third-Party Vulnerability Disclosure Policy - If the social-media behemoth finds a bug in another platform's code, the project has 90 days to re... https://threatpost.com/facebook-third-party-vulnerability-disclosure-policy/158976/ #vulnerabilitydisclosurepolicy #coordinateddisclosure #publicdisclosure #vulnerabilities #thirdpartycode #websecurity #opensource #bugbounty #facebook #90days #vdp
Facebook Debuts Third-Party Vulnerability Disclosure Policy

If the social-media behemoth finds a bug in another platform's code, the project has 90 days to remediate before Facebook goes public.

Threatpost - English - Global - threatpost.com
Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy - Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes availab... more: https://threatpost.com/google-ditches-patch-disclosure-90-day-policy/151626/ #vulnerabilitydisclosure #coordinateddisclosure #vulnerabilities #policychanges #projectzero #bugbounty #90days #google
Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy

Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes available before then.

Threatpost - English - Global - threatpost.com
All versions of Openssh share a critical vulnerability, including embedded code that will never be updated https://boingboing.net/2018/08/22/eternal-defects.html #coordinateddisclosure #revengeofheartbleed #internetofshit #foreverdays #security #infosec #openssh #crypto #Post #iot
All versions of Openssh share a critical vulnerability, including embedded code that will never be updated

Every version of the popular Openssh program — a critical, widely used tool for secure communications — share a critical vulnerability that was present in the program’s initial 19…

Boing Boing