techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.8K
active users

#telerik

0 posts0 participants0 posts today

Progress Telerik seems to get the attention of hackers quickly these days when new vulnerabilities are announced. Cyble honeypot sensors also detected attacks on Cisco, QNAP, Linux systems, and more.
#ThreatIntelligence #Cyberattacks #Cybersecurity #Security #Cisco #Linux #QNAP #Telerik #DLink

thecyberexpress.com/telerik-ci

Telerik cyberattacks Cyble honeypot sensors
The Cyber Express · Progress Telerik, Cisco, QNAP and Linux Under Attack: CybleBy Paul Shread

Security researchers have released a proof of concept exploit for Progress Telerik Report Servers

Two flaws, tracked as CVE-2024-4358 and CVE-2024-1800, can be exploited together to achieve remote code execution. The release of PoC exploit means the barrier to mass exploitation is very low. Progress has released software updates to address the vulnerabilities.

Administrators are advised to patch ASAP

#cybersecurity #Progress #Telerik #pocexploit

bleepingcomputer.com/news/secu

Progress security advisory: CVE-2024-1800 (9.9 critical, disclosed 20 March 2024) Insecure Deserialization Vulnerability in Telerik Report Server versions prior to 2024 Q1 (10.0.24.130) allows for remote code execution. 🔗 docs.telerik.com/report-server

Why you should care about CVE-2024-1800: CISA released a cybersecurity advisory on 15 June 2023 warning of threat actors exploiting Progress Telerik vulnerabilities in multiple U.S. Government IIS Servers.

Currently no advisory (published or pending) from Zero Day Initiative, who reported the vulnerability.

H/T: @campuscodi

docs.telerik.comInsecure Deserialization Vulnerability - Telerik Report Server How to mitigate CVE-2024-1800, where a remote code execution attack is possible in an unpatched version of Telerik Report Server.

Hey #Blazor community, for folks out there who have used #TelerikUIForBlazor, I’d love to hear your merit-based criticisms of the component library. I’m not asking you to shit on other developers’ hard work, so please be respectful.

I’m asking because I’ve been trying to help my team see some challenges that are around the corner for us, and they need specifics, so I’m trying to cast a wider net for some anecdotes.

I’ll reply with my own experience (unlisted).