<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CyberThreat Report: Vulns]]></title><description><![CDATA[A legújabb kritikus sérülékenységek érthetően összefoglalva.]]></description><link>https://www.cyberthreat.report/s/vulns</link><image><url>https://substackcdn.com/image/fetch/$s_!Lmtw!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50383b70-eecb-4f1b-8260-d05e48d1dbc9_256x256.png</url><title>CyberThreat Report: Vulns</title><link>https://www.cyberthreat.report/s/vulns</link></image><generator>Substack</generator><lastBuildDate>Wed, 20 May 2026 23:02:59 GMT</lastBuildDate><atom:link href="https://www.cyberthreat.report/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[CyEx Kft.]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ferencfresz@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ferencfresz@substack.com]]></itunes:email><itunes:name><![CDATA[Ferenc Frész]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ferenc Frész]]></itunes:author><googleplay:owner><![CDATA[ferencfresz@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ferencfresz@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ferenc Frész]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Az elektromos járművek magyarországi töltőinfrastruktúrájának sérülékenysége]]></title><description><![CDATA[A Mobiliti h&#225;l&#243;zatot &#233;rint&#337; CVE-2026-27777 &#233;s kapcsol&#243;d&#243; sebezhet&#337;s&#233;gek]]></description><link>https://www.cyberthreat.report/p/az-elektromos-jarmuvek-magyarorszagi</link><guid isPermaLink="false">https://www.cyberthreat.report/p/az-elektromos-jarmuvek-magyarorszagi</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Fri, 06 Mar 2026 21:15:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TXPY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TXPY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TXPY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TXPY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TXPY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TXPY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TXPY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2875409,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/190143771?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TXPY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TXPY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TXPY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TXPY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c6fa79-ee50-4d8b-9a42-fb20f0f6b407_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Ferenc Fr&#233;sz.</figcaption></figure></div><p>Az eur&#243;pai k&#246;zleked&#233;si szektor dekarboniz&#225;ci&#243;s t&#246;rekv&#233;sei az elm&#250;lt &#233;vtizedben p&#233;ld&#225;tlan &#252;tem&#369; fejl&#337;dettek ki az elektromos j&#225;rm&#369;vek (EV) &#233;s a hozz&#225;juk kapcsol&#243;d&#243; t&#246;lt&#337;infrastrukt&#250;ra ter&#252;let&#233;n. Magyarorsz&#225;g ezen a t&#233;ren k&#246;zponti szerepet t&#246;lt be a k&#246;z&#233;p-eur&#243;pai r&#233;gi&#243;ban, ahol az MVM Csoporthoz tartoz&#243; Mobiliti (e-mobi[.]hu) az egyik legmeghat&#225;roz&#243;bb szolg&#225;ltat&#243;k&#233;nt &#233;p&#237;tette ki h&#225;l&#243;zat&#225;t. Azonban a fizikai infrastrukt&#250;ra gyors expanzi&#243;ja gyakran megel&#337;zi a kiberbiztons&#225;gi protokollok robusztus implement&#225;ci&#243;j&#225;t, ami kritikus sebezhet&#337;s&#233;gek kialakul&#225;s&#225;hoz vezethet. Az amerikai CISA &#225;ltal 2026 m&#225;rcius&#225;ban k&#246;zz&#233;tett ICSA-26-062-06 sz&#225;m&#250; ipari kontrollrendszeri (ICS) s&#233;r&#252;l&#233;kenys&#233;g jelent&#233;s r&#225;vil&#225;g&#237;tott egy olyan sebezhet&#337;s&#233;gi csoportra, amelynek k&#246;zponti eleme a CVE-2026-27777 azonos&#237;t&#243;val ell&#225;tott hiba. </p><h2>A Mobiliti infrastrukt&#250;ra szerepe a nemzeti kritikus rendszerekben</h2><p>A Mobiliti &#225;ltal &#252;zemeltetett h&#225;l&#243;zat nem csup&#225;n egy k&#233;nyelmi szolg&#225;ltat&#225;s az elektromos aut&#243;k tulajdonosai sz&#225;m&#225;ra, hanem a magyarorsz&#225;gi energetikai &#233;s k&#246;zleked&#233;si szektor egyik alappill&#233;r&#233;v&#233; v&#225;lt. A h&#225;l&#243;zat t&#246;bb ezer t&#246;lt&#337;pontot foglal mag&#225;ban, amelyek k&#246;zvetlen&#252;l csatlakoznak az orsz&#225;gos villamosenergia-eloszt&#243; rendszerekhez. A modern t&#246;lt&#337;&#225;llom&#225;sok intelligens eszk&#246;z&#246;k, amelyek folyamatos k&#233;tir&#225;ny&#250; kommunik&#225;ci&#243;t folytatnak egy k&#246;zponti backend szerverrel, jellemz&#337;en az Open Charge Point Protocol (OCPP) haszn&#225;lat&#225;val. Ez a digit&#225;lis &#246;sszek&#246;ttet&#233;s teszi lehet&#337;v&#233; a t&#225;voli monitoroz&#225;st, a sz&#225;ml&#225;z&#225;st &#233;s a terhel&#233;smenedzsmentet, de egyben jelent&#337;s t&#225;mad&#225;si fel&#252;letet is nyithat a kiberb&#369;n&#246;z&#337;k sz&#225;m&#225;ra.</p><p>A CVE-2026-27777 azonos&#237;t&#243;val jel&#246;lt s&#233;r&#252;l&#233;kenys&#233;g a Mobiliti e-mobi[.]hu &#246;sszes verzi&#243;j&#225;t &#233;rinti, ami r&#225;vil&#225;g&#237;t arra, hogy a probl&#233;ma nem egyedi k&#243;dol&#225;si hiba, hanem rendszerszint&#369; tervez&#233;si vagy konfigur&#225;ci&#243;s hi&#225;nyoss&#225;g. A sebezhet&#337;s&#233;g s&#250;lyoss&#225;g&#225;t n&#246;veli, hogy a h&#225;l&#243;zat a kritikus infrastrukt&#250;ra-&#225;gazatok k&#246;z&#233; tartozik, &#237;gy b&#225;rmilyen &#252;zemzavar vagy jogosulatlan hozz&#225;f&#233;r&#233;s k&#246;zvetlen gazdas&#225;gi &#233;s biztons&#225;gi k&#246;vetkezm&#233;nyekkel j&#225;rhat.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sqeD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sqeD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 424w, https://substackcdn.com/image/fetch/$s_!sqeD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 848w, https://substackcdn.com/image/fetch/$s_!sqeD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 1272w, https://substackcdn.com/image/fetch/$s_!sqeD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sqeD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png" width="840" height="336" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:336,&quot;width&quot;:840,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:165796,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/190143771?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91541f1c-a430-4278-80c5-f778da50eaa9_1325x336.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sqeD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 424w, https://substackcdn.com/image/fetch/$s_!sqeD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 848w, https://substackcdn.com/image/fetch/$s_!sqeD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 1272w, https://substackcdn.com/image/fetch/$s_!sqeD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef20c8ca-1446-43f5-81e0-e7f35966d40d_840x336.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Forr&#225;s: https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-06</figcaption></figure></div><p>A technikai elemz&#233;s sor&#225;n figyelembe kell venni, hogy a CVSS 6.5-&#246;s pontsz&#225;ma egy k&#246;zepes s&#250;lyoss&#225;g&#250; besorol&#225;st takar, azonban ez a sz&#225;m nem t&#252;kr&#246;zi teljes m&#233;rt&#233;kben a kumulat&#237;v kock&#225;zatot, amely a h&#225;l&#243;zatban jelen l&#233;v&#337; t&#246;bbi s&#233;r&#252;l&#233;kenys&#233;ggel val&#243; l&#225;ncol&#225;s sor&#225;n keletkezik.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">CyberThreat Report is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>A CVE-2026-27777 technikai mechanizmusa &#233;s a CWE-522 gyenges&#233;g</h2><p>A CVE-2026-27777 l&#233;nyege a t&#246;lt&#337;&#225;llom&#225;sok hiteles&#237;t&#233;si azonos&#237;t&#243;inak nem megfelel&#337; v&#233;delme. A kutat&#225;sok felt&#225;rt&#225;k, hogy ezek a kritikus azonos&#237;t&#243;k nyilv&#225;nosan hozz&#225;f&#233;rhet&#337;v&#233; v&#225;ltak webes t&#233;rk&#233;pplatformokon kereszt&#252;l. Ez a jelens&#233;g a CWE-522 (Insufficiently Protected Credentials) kateg&#243;ri&#225;ba tartozik, ami azt jelenti, hogy az &#233;rz&#233;keny adatokat &#8211; jelen esetben a t&#246;lt&#337;pontok egyedi azonos&#237;t&#243;it &#8211; nem kezelt&#233;k a sz&#252;ks&#233;ges titoktart&#225;si szinten.</p><p>A mechanizmus h&#225;tter&#233;ben val&#243;sz&#237;n&#369;s&#237;thet&#337;, hogy a Mobiliti rendszere &#233;s a k&#252;ls&#337; t&#233;rk&#233;pszolg&#225;ltat&#225;sok (p&#233;ld&#225;ul t&#246;lt&#337;pont-keres&#337;k vagy navig&#225;ci&#243;s alkalmaz&#225;sok) k&#246;z&#246;tti API-kommunik&#225;ci&#243; sor&#225;n olyan technikai param&#233;terek is &#225;tad&#225;sra ker&#252;ltek, amelyeknek kiz&#225;r&#243;lag a t&#246;lt&#337; &#233;s a backend k&#246;z&#246;tti priv&#225;t csatorn&#225;n lett volna hely&#252;k. Amikor egy t&#225;mad&#243; hozz&#225;f&#233;r ezekhez az azonos&#237;t&#243;khoz, k&#233;pess&#233; v&#225;lik arra, hogy legitim t&#246;lt&#337;&#225;llom&#225;snak &#225;lc&#225;zza mag&#225;t a k&#246;zponti rendszer fel&#233;. Ez a sziv&#225;rg&#225;s a bizalmas jelleg megs&#233;rt&#233;s&#233;nek tekintend&#337; alacsony szinten, de a bel&#233;p&#233;si pontot jelenti a magasabb szint&#369; jogosults&#225;gkiterjeszt&#233;shez.</p><h2>Az ICSA-26-062-06 jelent&#233;sben szerepl&#337; &#246;sszef&#252;gg&#337; sebezhet&#337;s&#233;gek</h2><p>A CISA &#225;ltal kiadott jelent&#233;s nem elszigetelten kezeli a CVE-2026-27777-et, hanem egy n&#233;gytag&#250; sebezhet&#337;s&#233;gi csoport r&#233;szek&#233;nt, amely a Mobiliti teljes digit&#225;lis &#246;kosziszt&#233;m&#225;j&#225;t &#233;rinti. A sebezhet&#337;s&#233;gek k&#246;z&#246;tti szinergia lehet&#337;v&#233; teszi a t&#225;mad&#243;k sz&#225;m&#225;ra, hogy a t&#246;lt&#337;&#225;llom&#225;sok felett teljes adminisztrat&#237;v kontrollt gyakoroljanak.</p><h3>A WebSocket kommunik&#225;ci&#243; &#233;s a hiteles&#237;t&#233;s hi&#225;nya (CVE-2026-26051)</h3><p>A csoport legs&#250;lyosabb eleme a CVE-2026-26051, amely a WebSocket v&#233;gpontok hiteles&#237;t&#233;s&#233;nek hi&#225;ny&#225;t &#237;rja le. Az OCPP protokoll modern implement&#225;ci&#243;i WebSocket csatorn&#225;kat haszn&#225;lnak a val&#243;s idej&#369; adat&#225;tvitelre. A Mobiliti rendszer&#233;ben azonban ezek a v&#233;gpontok nem k&#246;veteltek meg megfelel&#337; autentik&#225;ci&#243;t, &#237;gy a t&#225;mad&#243;k a CVE-2026-27777 r&#233;v&#233;n megszerzett azonos&#237;t&#243;kkal legitim t&#246;lt&#337;k&#233;nt regisztr&#225;lhattak a backend szerveren.</p><p>Ez a hiba k&#246;zvetlen utat nyit a t&#246;lt&#233;si folyamatok manipul&#225;l&#225;s&#225;hoz. A t&#225;mad&#243; parancsokat k&#252;ldhet a backendnek, p&#233;ld&#225;ul ind&#237;that vagy le&#225;ll&#237;that t&#246;lt&#233;seket, m&#243;dos&#237;thatja a fogyaszt&#225;si adatokat, vagy ak&#225;r t&#225;volr&#243;l z&#225;rolhatja is a t&#246;lt&#337;oszlopokat. Mivel a backend a t&#225;mad&#243;t legitim eszk&#246;znek l&#225;tja, a k&#252;ld&#246;tt adatok beker&#252;lnek a sz&#225;ml&#225;z&#225;si &#233;s statisztikai rendszerekbe, ami p&#233;nz&#252;gyi csal&#225;sokhoz &#233;s adatkorrupci&#243;hoz vezet.</p><h3>Brute-force &#233;s szolg&#225;ltat&#225;smegtagad&#225;s (CVE-2026-20882)</h3><p>A CVE-2026-20882 a hiteles&#237;t&#233;si k&#237;s&#233;rletek korl&#225;toz&#225;s&#225;nak hi&#225;ny&#225;t jelzi (CWE-307). A rate limiting hi&#225;nya miatt a t&#225;mad&#243;k brute-force m&#243;dszerekkel pr&#243;b&#225;lkozhatnak tov&#225;bbi azonos&#237;t&#243;k kider&#237;t&#233;s&#233;vel, vagy el&#225;raszthatj&#225;k a rendszert k&#233;r&#233;sekkel, ami szolg&#225;ltat&#225;smegtagad&#225;st (DoS) eredm&#233;nyez. Ez k&#252;l&#246;n&#246;sen kritikus egy olyan k&#246;rnyezetben, ahol a felhaszn&#225;l&#243;k a mobilalkalmaz&#225;son kereszt&#252;l v&#225;rj&#225;k a t&#246;lt&#337;k el&#233;rhet&#337;s&#233;g&#233;nek val&#243;s idej&#369; friss&#237;t&#233;s&#233;t; a DoS t&#225;mad&#225;s megb&#233;n&#237;thatja a teljes szolg&#225;ltat&#225;st, lehetetlenn&#233; t&#233;ve a j&#225;rm&#369;vek t&#246;lt&#233;s&#233;t a h&#225;l&#243;zatban.</p><h3>Munkamenet-kezel&#233;si hib&#225;k (CVE-2026-27764)</h3><p>A csoport negyedik tagja, a CVE-2026-27764, a nem megfelel&#337; munkamenet-lej&#225;rati id&#337;ket &#233;s a p&#225;rhuzamos munkamenetek enged&#233;lyez&#233;s&#233;t kritiz&#225;lja (CWE-613). A rendszer lehet&#337;v&#233; tette, hogy t&#246;bb v&#233;gpont csatlakozzon ugyanazzal a munkamenet-azonos&#237;t&#243;val, ahol a legutols&#243; csatlakoz&#243; kiszor&#237;totta a kor&#225;bbit. Ez a session hijacking vagy session shadowing technika lehet&#337;v&#233; teszi, hogy egy t&#225;mad&#243; &#225;tvegye a kommunik&#225;ci&#243;t egy m&#225;r akt&#237;v, legitim t&#246;lt&#337;&#225;llom&#225;st&#243;l, &#233;s fogadja a backendt&#337;l &#233;rkez&#337; parancsokat, mik&#246;zben az eredeti &#225;llom&#225;st lekapcsolja.</p><h2>Felfedez&#233;s &#233;s a nyilv&#225;noss&#225;gra hozatal folyamata</h2><p>A Mobiliti h&#225;l&#243;zat&#225;t &#233;rint&#337; sebezhet&#337;s&#233;gekre nem egy folyamatban l&#233;v&#337; t&#225;mad&#225;s sor&#225;n der&#252;lt f&#233;ny, hanem tudatos biztons&#225;gi kutat&#243;munka eredm&#233;nyek&#233;nt. A hib&#225;kat <strong>Khaled Sarieddine</strong> &#233;s <strong>Mohammad Ali Sayed</strong>, a montreali Concordia Egyetem kutat&#243;i azonos&#237;tott&#225;k. A kutat&#243;k szakter&#252;lete az elektromos j&#225;rm&#369;vek t&#246;lt&#337;infrastrukt&#250;r&#225;j&#225;nak kiberbiztons&#225;gi vizsg&#225;lata, &#233;s munk&#225;juk sor&#225;n a t&#246;lt&#337;&#225;llom&#225;sok backend kommunik&#225;ci&#243;j&#225;t, valamint a kapcsol&#243;d&#243; mobilalkalmaz&#225;sok biztons&#225;g&#225;t elemezt&#233;k.</p><p>A nyilv&#225;noss&#225;gra hozatal folyamata az al&#225;bbi id&#337;vonalat k&#246;vette:</p><ul><li><p><strong>2026. febru&#225;r 24.:</strong> A CVE-2026-27777 azonos&#237;t&#243;t a s&#233;r&#252;l&#233;kenys&#233;g dokument&#225;l&#225;sa c&#233;lj&#225;b&#243;l lefoglalt&#225;k (RESERVED &#225;llapot).</p></li><li><p><strong>Koordin&#225;ci&#243;s k&#237;s&#233;rlet:</strong> A kutat&#243;k jelentett&#233;k az &#233;szrev&#233;teleiket a CISA (Cybersecurity and Infrastructure Security Agency) fel&#233;. <strong>A CISA ezt k&#246;vet&#337;en megpr&#243;b&#225;lta felvenni a kapcsolatot az MVM Mobilitival a sebezhet&#337;s&#233;gek koordin&#225;lt kijav&#237;t&#225;sa &#233;rdek&#233;ben.</strong></p></li><li><p><strong>A gy&#225;rt&#243;i v&#225;lasz hi&#225;nya:</strong> A rendelkez&#233;sre &#225;ll&#243; adatok alapj&#225;n a Mobiliti nem reag&#225;lt a CISA koordin&#225;ci&#243;s megkeres&#233;seire, <strong>&#237;gy a hiba jav&#237;t&#225;s&#225;ra vonatkoz&#243; gy&#225;rt&#243;i visszajelz&#233;s n&#233;lk&#252;l indult el a publik&#225;ci&#243;s folyamat.</strong></p></li><li><p><strong>2026. m&#225;rcius 3.:</strong> A CISA hivatalosan k&#246;zz&#233;tette az ICSA-26-062-06 sz&#225;m&#250; biztons&#225;gi tan&#225;csad&#225;st.</p></li><li><p><strong>A kutat&#225;s nyilv&#225;noss&#225;ga:</strong> A technikai r&#233;szletek nemzetk&#246;zi szinten is megjelentek (p&#233;ld&#225;ul a JVN adatb&#225;zis&#225;ban 2026. m&#225;rcius 5-&#233;n), felh&#237;vva a figyelmet a nem jav&#237;tott kritikus infrastrukt&#250;ra-elemekre.</p></li></ul><p>A CISA jelent&#233;se szerint a publik&#225;l&#225;s id&#337;pontj&#225;ig nem &#233;rkezett bejelent&#233;s arr&#243;l, hogy ezeket a s&#233;r&#252;l&#233;kenys&#233;geket c&#233;lzottan kihaszn&#225;lt&#225;k volna rosszindulat&#250; t&#225;mad&#225;sok sor&#225;n, ugyanakkor a koordin&#225;lt jav&#237;t&#225;s elmarad&#225;sa miatt a h&#225;l&#243;zat v&#233;dtelen maradt a nyilv&#225;noss&#225;gra hozatalt k&#246;vet&#337;en.</p><h2>Kiber-fizikai kock&#225;zatok &#233;s a villamosenergia-h&#225;l&#243;zat stabilit&#225;sa</h2><p>Az elektromos j&#225;rm&#369;vek t&#246;lt&#337;h&#225;l&#243;zatait &#233;rint&#337; t&#225;mad&#225;sok nem &#225;llnak meg az IT-rendszerek szintj&#233;n, ezeknek s&#250;lyos fizikai k&#246;vetkezm&#233;nyeik vannak. A CVE-2026-27777 &#233;s t&#225;rsai lehet&#337;v&#233; teszik a t&#246;lt&#337;k t&#225;voli, koordin&#225;lt vez&#233;rl&#233;s&#233;t. Khaled Sarieddine &#233;s Mohammad Ali Sayed, a sebezhet&#337;s&#233;geket jelent&#337; kutat&#243;k munk&#225;ss&#225;ga &#233;ppen ezekre a kiber-fizikai fenyeget&#233;sekre f&#243;kusz&#225;l.</p><p>Kor&#225;bbi kutat&#225;saikban le&#237;rt&#225;k, hogyan lehet kompromitt&#225;lt t&#246;lt&#337;&#225;llom&#225;sok t&#246;meg&#233;vel oszcill&#225;ci&#243;s terhel&#233;st l&#233;trehozni a villamosenergia-h&#225;l&#243;zaton. Ha egy t&#225;mad&#243; a CVE-2026-26051 r&#233;v&#233;n t&#246;bb sz&#225;z Mobiliti t&#246;lt&#337;t utas&#237;t arra, hogy egyszerre kezdj&#233;k el vagy fejezz&#233;k be a t&#246;lt&#233;st maxim&#225;lis teljes&#237;tm&#233;nyen, az hirtelen frekvenciaingadoz&#225;st okoz a h&#225;l&#243;zatban.</p><h2>&#214;sszehasonl&#237;t&#225;s m&#225;s ipari s&#233;r&#252;l&#233;kenys&#233;gekkel</h2><p>A 2026-os &#233;v sor&#225;n t&#246;bb hasonl&#243; incidens r&#225;vil&#225;g&#237;tott arra, hogy az EV t&#246;lt&#337;h&#225;l&#243;zatok biztons&#225;ga ipar&#225;gi szint&#369; probl&#233;ma. A Mobiliti esete b&#225;r kritikus, nem egyed&#252;l&#225;ll&#243;, azonban a v&#225;laszreakci&#243; min&#337;s&#233;ge jelent&#337;sen elt&#233;r a versenyt&#225;rsak&#233;t&#243;l.</p><h3>Delta Electronics (CVE-2026-22552)</h3><p>A Delta Electronics szint&#233;n szembes&#252;lt egy WebSocket hiteles&#237;t&#233;si hib&#225;val (CVE-2026-22552), ahol az unauthenticated t&#225;mad&#243;k &#225;llom&#225;sszem&#233;lyes&#237;t&#233;st hajthattak v&#233;gre. A k&#252;l&#246;nbs&#233;g az volt, hogy a Delta Electronics akt&#237;van egy&#252;ttm&#369;k&#246;d&#246;tt a CISA-val, &#233;s azonnal kiadta a v2.1.0.39-es szoftverfriss&#237;t&#233;st a hiba orvosl&#225;s&#225;ra. Ezzel szemben a Mobiliti nem reag&#225;lt a koordin&#225;ci&#243;s megkeres&#233;sekre, &#237;gy a magyarorsz&#225;gi h&#225;l&#243;zat &#233;rintett eszk&#246;zeihez nem &#225;ll rendelkez&#233;sre hivatalos jav&#237;t&#243;csomag a publik&#225;l&#225;s id&#337;pontj&#225;ban.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gdbd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gdbd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 424w, https://substackcdn.com/image/fetch/$s_!gdbd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 848w, https://substackcdn.com/image/fetch/$s_!gdbd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 1272w, https://substackcdn.com/image/fetch/$s_!gdbd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gdbd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png" width="734" height="192" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:192,&quot;width&quot;:734,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35436,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/190143771?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gdbd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 424w, https://substackcdn.com/image/fetch/$s_!gdbd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 848w, https://substackcdn.com/image/fetch/$s_!gdbd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 1272w, https://substackcdn.com/image/fetch/$s_!gdbd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde592f2f-b2b1-4fa7-a557-24146a4906ed_734x192.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>A sebezhet&#337;s&#233;g kihaszn&#225;lhat&#243;s&#225;ga &#233;s t&#225;rsadalmi hat&#225;sai</h2><p>A CVE-2026-27777 nem ig&#233;nyel fizikai hozz&#225;f&#233;r&#233;st a t&#246;lt&#337;h&#246;z; a t&#225;mad&#225;s t&#225;volr&#243;l, az interneten kereszt&#252;l hajthat&#243; v&#233;gre. Ez drasztikusan megn&#246;veli a potenci&#225;lis t&#225;mad&#243;k k&#246;r&#233;t, hiszen nem sz&#252;ks&#233;ges Magyarorsz&#225;gon tart&#243;zkodni a h&#225;l&#243;zat kompromitt&#225;l&#225;s&#225;hoz. A sziv&#225;rg&#225;s forr&#225;sak&#233;nt megjel&#246;lt web-alap&#250; t&#233;rk&#233;pplatformok azt sugallj&#225;k, hogy a Mobiliti olyan API-kat haszn&#225;lhatott, amelyek nem v&#233;gezt&#233;k el a k&#233;r&#233;sek szigor&#250; sz&#369;r&#233;s&#233;t vagy az azonos&#237;t&#243;k maszkol&#225;s&#225;t.</p><p>A t&#225;rsadalmi hat&#225;sok k&#246;z&#252;l kiemelkedik a felhaszn&#225;l&#243;k mozg&#225;si adatainak vesz&#233;lyeztet&#233;se. Ha a t&#246;lt&#337;&#225;llom&#225;s-azonos&#237;t&#243;k nyilv&#225;nosak, &#233;s a t&#225;mad&#243; k&#233;pes monitorozni a WebSocket forgalmat, akkor elm&#233;letileg k&#246;vetni tudja, hogy melyik j&#225;rm&#369; mikor &#233;s hol t&#246;lt. <strong>Ez s&#250;lyos GDPR &#233;s adatv&#233;delmi agg&#225;lyokat vet fel, k&#252;l&#246;n&#246;sen mivel az elektromos aut&#243;k elterjed&#233;se a flottakezel&#337;k &#233;s a korm&#225;nyzati szervek k&#246;r&#233;ben is jelent&#337;s.</strong></p><h2>Kock&#225;zatcs&#246;kkent&#233;si strat&#233;gstrategies &#233;s v&#233;delmi int&#233;zked&#233;sek</h2><p>Mivel a Mobiliti nem adott ki hivatalos jav&#237;t&#225;st, az &#252;zemeltet&#337;knek &#233;s a h&#225;l&#243;zathoz kapcsol&#243;d&#243; partnereknek saj&#225;t hat&#225;sk&#246;rben kell megtenni&#252;k a sz&#252;ks&#233;ges l&#233;p&#233;seket a kock&#225;zatok minimaliz&#225;l&#225;sa &#233;rdek&#233;ben. A CISA &#233;s az ICS szak&#233;rt&#337;k &#225;ltal javasolt Defense-in-Depth strat&#233;gi&#225;t kell alkalmazni.</p><h3>H&#225;l&#243;zati szegment&#225;ci&#243; &#233;s izol&#225;ci&#243;</h3><p>A t&#246;lt&#337;&#225;llom&#225;sokat &#233;s azokat vez&#233;rl&#337; rendszereket el kell szigetelni a publikus internett&#337;l. Javasolt a kontrollrendszerek t&#369;zfalak m&#246;g&#233; helyez&#233;se &#233;s a v&#225;llalati h&#225;l&#243;zatokt&#243;l val&#243; teljes elk&#252;l&#246;n&#237;t&#233;se. Amennyiben a t&#225;voli el&#233;r&#233;s elengedhetetlen, azt kiz&#225;r&#243;lag titkos&#237;tott &#233;s hiteles&#237;tett VPN csatorn&#225;kon kereszt&#252;l szabad megval&#243;s&#237;tani.</p><h3>Monitoroz&#225;s &#233;s incidensdetekt&#225;l&#225;s</h3><p>A szervezeteknek folyamatosan monitorozniuk kell a h&#225;l&#243;zati forgalmat a szokatlan OCPP vagy WebSocket tev&#233;kenys&#233;gek ut&#225;n kutatva.  EDR/XDR megold&#225;sok seg&#237;thetnek az olyan anom&#225;li&#225;k felismer&#233;s&#233;ben, mint a v&#225;ratlan helyr&#337;l &#233;rkez&#337; csatlakoz&#225;si k&#237;s&#233;rletek.</p><h2>A sebezhet&#337;s&#233;g hossz&#250; t&#225;v&#250; hat&#225;sai</h2><p>A CVE-2026-27777 k&#246;r&#252;li esem&#233;nyek egy sz&#233;lesebb k&#246;r&#369; kiberbiztons&#225;gi v&#225;ls&#225;g el&#337;jelei lehetnek az energetikai szektorban. A CISA finansz&#237;roz&#225;si gondokkal k&#252;zd. Ism&#233;tl&#337;d&#337; megjegyz&#233;se a sz&#246;vets&#233;gi finansz&#237;roz&#225;s sz&#252;neteltet&#233;s&#233;r&#337;l (lapse in federal funding) a jelent&#233;s publik&#225;l&#225;sakor arra utal, hogy a nemzetk&#246;zi kiberbiztons&#225;gi koordin&#225;ci&#243; s&#233;r&#252;l&#233;keny lehet politikai vagy gazdas&#225;gi v&#225;ls&#225;gok idej&#233;n.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d999af2a-100f-4446-bfdb-eb5ad66154f0&quot;,&quot;caption&quot;:&quot;A v&#233;delemmel &#233;s kutat&#225;ssal foglalkoz&#243; nonprofit MITRE Corporation k&#246;z&#246;lte, hogy az amerikai korm&#225;nyt&#243;l kapott finansz&#237;roz&#225;s szerd&#225;n lej&#225;r, &#237;gy nem tudja tov&#225;bb fenntartani azt a kritikus jelent&#337;s&#233;g&#369; kibersebezhet&#337;s&#233;gi adatb&#225;zist, amelyet vil&#225;gszerte biztons&#225;gi kutat&#243;k &#233;s digit&#225;lis v&#233;delmi szakemberek haszn&#225;lnak.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Finansz&#237;roz&#225;si volatilit&#225;s &#233;s rendszerszint&#369; kock&#225;zatok az USA kiberbiztons&#225;gi infrastrukt&#250;r&#225;j&#225;ban - Gyorselemz&#233;s&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:122890928,&quot;name&quot;:&quot;Ferenc Fr&#233;sz&quot;,&quot;bio&quot;:&quot;Cyber security senior expert conducting cybersecurity and cyber defense capability development on numerous international fronts.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcd5b576-d747-4724-bdf2-51ed3225c5d3_96x96.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-04-16T11:48:50.323Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ehZd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3277d20-fe6e-4e42-b9cd-45e03ba92ac1_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.cyberthreat.report/p/finanszirozasi-volatilitas-es-rendszerszintu&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:161445882,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:3962308,&quot;publication_name&quot;:&quot;CyberThreat Report&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lmtw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50383b70-eecb-4f1b-8260-d05e48d1dbc9_256x256.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p>A kutat&#243;k, Sarieddine &#233;s Sayed &#225;ltal azonos&#237;tott probl&#233;m&#225;k azt mutatj&#225;k, hogy a j&#246;v&#337; h&#225;bor&#250;it vagy szabot&#225;zsakci&#243;it nem felt&#233;tlen&#252;l robban&#243;anyagokkal, hanem rosszul konfigur&#225;lt API-kkal &#233;s hi&#225;nyz&#243; hiteles&#237;t&#233;si protokollokkal fogj&#225;k megv&#237;vni. Az EV infrastrukt&#250;ra biztons&#225;ga m&#225;r nemcsak IT-k&#233;rd&#233;s, hanem az energiabiztons&#225;g &#233;s a k&#246;zrend fenntart&#225;s&#225;nak z&#225;loga.</p><p>A CVE-2026-27777 s&#233;r&#252;l&#233;kenys&#233;g &#233;s a hozz&#225; kapcsol&#243;d&#243; ICSA-26-062-06 jelent&#233;s r&#233;szletes elemz&#233;se alapj&#225;n egy&#233;rtelm&#369;, hogy a Mobiliti h&#225;l&#243;zata jelent&#337;s kiberbiztons&#225;gi kock&#225;zatot hordoz. A t&#246;lt&#337;&#225;llom&#225;sok azonos&#237;t&#243;inak sziv&#225;rg&#225;sa, kombin&#225;lva a WebSocket hiteles&#237;t&#233;s &#233;s a munkamenet-kezel&#233;s s&#250;lyos hib&#225;ival, lehet&#337;v&#233; teszi a h&#225;l&#243;zat feletti jogosulatlan ir&#225;ny&#237;t&#225;st.</p><p></p>]]></content:encoded></item><item><title><![CDATA[Aktívan kihasznált kritikus jogosultságellenőrzési hiba az SAP NetWeaver Visual Composer komponensében (CVE-2025-31324)]]></title><description><![CDATA[A s&#233;r&#252;l&#233;kenys&#233;g a Visual Composer REST API v&#233;gpontj&#225;n kereszt&#252;l hiteles&#237;t&#233;s n&#233;lk&#252;li f&#225;jlfelt&#246;lt&#233;st tesz lehet&#337;v&#233;, amellyel t&#225;mad&#243;k t&#225;voli k&#243;dot hajthatnak v&#233;gre.]]></description><link>https://www.cyberthreat.report/p/aktivan-kihasznalt-kritikus-jogosultsagellenorze</link><guid isPermaLink="false">https://www.cyberthreat.report/p/aktivan-kihasznalt-kritikus-jogosultsagellenorze</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Wed, 14 May 2025 09:30:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vz6b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vz6b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vz6b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!vz6b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!vz6b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!vz6b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vz6b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:775800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/163277129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vz6b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!vz6b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!vz6b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!vz6b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79bff088-0d05-45bc-b24d-169955dc0e2e_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>Az SAP NetWeaver egy nagyv&#225;llalati alkalmaz&#225;splatform, amely a vil&#225;g legnagyobb szervezetein&#233;l j&#225;tszik kulcsszerepet k&#252;l&#246;nf&#233;le &#252;zleti folyamatok &#8211; p&#233;ld&#225;ul p&#233;nz&#252;gyi tranzakci&#243;k, er&#337;forr&#225;s-tervez&#233;s (ERP), hum&#225;ner&#337;forr&#225;s-menedzsment &#233;s &#252;gyf&#233;lkapcsolati rendszerek &#8211; futtat&#225;s&#225;ban. Az SAP NetWeaver Application Server Java komponense gyakran szolg&#225;l port&#225;lfel&#252;letek, middleware-integr&#225;ci&#243;k &#233;s testreszabott &#252;zleti logik&#225;k alapj&#225;ul.</p><p>A s&#233;r&#252;l&#233;kenys&#233;g a rendszer egyik specifikus modulj&#225;t, a <em>Visual Composer</em>-t &#233;rinti &#8211; ez egy webes, k&#243;dmentes fejleszt&#337;i eszk&#246;z, mellyel &#252;zleti felhaszn&#225;l&#243;k vizu&#225;lis m&#243;don, alacsony technikai tud&#225;ssal is l&#233;trehozhatnak SAP UI-alkalmaz&#225;sokat. A komponens sz&#225;mos ipar&#225;gban &#8211; k&#252;l&#246;n&#246;sen az energia-, p&#233;nz&#252;gyi, k&#246;zszolg&#225;lati &#233;s eg&#233;szs&#233;g&#252;gyi szektorban &#8211; haszn&#225;lt SAP alap&#250; port&#225;lrendszerek integr&#225;lt r&#233;sze.</p><p>2025 &#225;prilis v&#233;ge &#243;ta akt&#237;v t&#225;mad&#225;sok c&#233;lozz&#225;k az SAP Visual Composer modulj&#225;t &#233;rint&#337; CVE-2025-31324 jelz&#233;s&#369;&#369; sebezhet&#337;s&#233;get. A hiba lehet&#337;v&#233; teszi, hogy t&#225;mad&#243;k hiteles&#237;t&#233;s n&#233;lk&#252;l felt&#246;ltsenek &#233;s lefuttassanak webshell-eket a c&#233;lrendszeren, ami jogosults&#225;gkiterjeszt&#233;st &#233;s teljes rendszerkompromitt&#225;ci&#243;t eredm&#233;nyezhet. A s&#233;r&#252;l&#233;kenys&#233;get m&#225;r c&#233;lzott kamp&#225;nyban is pr&#243;b&#225;lj&#225;k kihaszn&#225;lni k&#237;nai h&#225;tter&#369; szerepl&#337;k.</p><ul><li><p><strong>CVSS v3.1 pontsz&#225;m</strong>: 9.8 (kritikus)</p></li><li><p><strong>T&#225;mad&#225;si hat&#225;s</strong>: T&#225;voli k&#243;dfuttat&#225;s (RCE), jogosults&#225;gkiterjeszt&#233;s</p></li><li><p><strong>Exploit st&#225;tusz</strong>: Akt&#237;v kihaszn&#225;l&#225;s alatt</p></li></ul><blockquote><p>A s&#233;r&#252;l&#233;kenys&#233;g k&#252;l&#246;n&#246;sen kritikus, mivel az &#233;rintett SAP komponens gyakran k&#246;zvetlen kapcsolatban &#225;ll &#233;rz&#233;keny &#252;zleti adatokkal, bels&#337; folyamatokkal &#233;s m&#225;s, magas &#233;rt&#233;k&#369; rendszerekkel &#8211; &#237;gy egy sikeres t&#225;mad&#225;s sz&#233;les k&#246;r&#369; hozz&#225;f&#233;r&#233;st biztos&#237;that a t&#225;mad&#243;k sz&#225;m&#225;ra az &#225;ldozat szervezet informatikai infrastrukt&#250;r&#225;j&#225;ban.</p></blockquote>
      <p>
          <a href="https://www.cyberthreat.report/p/aktivan-kihasznalt-kritikus-jogosultsagellenorze">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Erlang/OTP SSH kritikus sérülékenység: hitelesítés nélküli távoli kódfuttatás (CVE-2025-32433)]]></title><description><![CDATA[Az internet gerinch&#225;l&#243;zat&#225;t kiszolg&#225;l&#243; eszk&#246;z&#246;k nagy r&#233;sze Erlang-alap&#250; komponensekre &#233;p&#252;l &#8211; &#237;gy a s&#233;r&#252;l&#233;kenys&#233;g besz&#225;ll&#237;t&#243;i l&#225;ncokon &#225;t ICS &#233;s egy&#233;b OT rendszereket is &#233;rinthet.]]></description><link>https://www.cyberthreat.report/p/erlangotp-ssh-kritikus-serulekenyseg</link><guid isPermaLink="false">https://www.cyberthreat.report/p/erlangotp-ssh-kritikus-serulekenyseg</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Wed, 23 Apr 2025 17:22:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6FFW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6FFW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6FFW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!6FFW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!6FFW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!6FFW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6FFW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:775800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/161965017?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6FFW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!6FFW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!6FFW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!6FFW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb802d0f5-d997-46e0-9721-78c51ec15a95_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>Egy kev&#233;ss&#233; ismert, de sz&#225;mos modern digit&#225;lis infrastrukt&#250;ra alapj&#225;t k&#233;pez&#337; szoftverkomponens, az <strong>Erlang/OTP SSH</strong> kritikus s&#233;r&#252;l&#233;kenys&#233;ge ker&#252;lt beazonos&#237;t&#225;sra. A <strong>CVE-2025-32433 </strong>jelz&#233;s&#369; s&#233;r&#252;l&#233;kenys&#233;g <a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> az SSH szolg&#225;ltat&#225;s azon hib&#225;j&#225;nak kihaszn&#225;l&#225;s&#225;t teszi lehet&#337;v&#233;, hogy t&#225;mad&#243;k <em>hiteles&#237;t&#233;s n&#233;lk&#252;l, k&#246;zvetlen&#252;l</em> hajtsanak v&#233;gre tetsz&#337;leges k&#243;dfuttat&#225;st a c&#233;lrendszeren, ami ak&#225;r <em>teljes k&#246;r&#369; rendszerkompromitt&#225;l&#225;shoz</em> is vezethet. A hiba kihaszn&#225;l&#225;sa egyszer&#369;: a t&#225;mad&#243;nak mind&#246;ssze h&#225;l&#243;zati hozz&#225;f&#233;r&#233;sre van sz&#252;ks&#233;ge az &#233;rintett SSH porthoz, nincs sz&#252;ks&#233;g hiteles&#237;t&#233;sre, speci&#225;lis k&#246;rnyezetre vagy felhaszn&#225;l&#243;i interakci&#243;ra. </p><blockquote><p><strong>Az Erlang sz&#233;les k&#246;rben haszn&#225;lt h&#225;l&#243;zati berendez&#233;sekben, amelyek az internet gerinch&#225;l&#243;zat&#225;t alkotj&#225;k. Az SSH protokoll ezekben a rendszerekben gyakran a vez&#233;rl&#233;si s&#237;khoz val&#243; biztons&#225;gos hozz&#225;f&#233;r&#233;sre szolg&#225;l, amely sz&#225;mos eszk&#246;z ir&#225;ny&#237;t&#225;s&#225;t v&#233;gzi. Ez a besz&#225;ll&#237;t&#243;i l&#225;ncban megl&#233;v&#337; kock&#225;zat kiterjedhet ipari ir&#225;ny&#237;t&#243; rendszerekre (ICS) &#233;s egy&#233;b m&#369;k&#246;d&#233;st biztos&#237;t&#243; technol&#243;gi&#225;kra (OT) is &#8211; p&#233;ld&#225;ul &#250;tv&#225;laszt&#243;kra, switchekre &#233;s intelligens szenzorokra. A Cisco becsl&#233;se szerint 2018-ban az internetes forgalom 90%-a Erlanggal vez&#233;relt csom&#243;pontokon haladt kereszt&#252;l.</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a></p></blockquote><p>A Shodan adatai szerint vil&#225;gszerte t&#246;bb mint 600 000 olyan nyilv&#225;nosan el&#233;rhet&#337; rendszer tal&#225;lhat&#243; jelenleg, amely valamilyen m&#243;don Erlang/OTP k&#246;rnyezetet futtat. Ezek k&#246;z&#252;l azonban csak egy kisebb r&#233;sz haszn&#225;lja t&#233;nylegesen az &#233;rintett OTP SSH szervert &#8211; teh&#225;t a val&#243;ban sebezhet&#337; rendszerek sz&#225;ma enn&#233;l j&#243;val kevesebb lehet.</p><p>A sebezhet&#337;s&#233;g jelent&#337;s kock&#225;zatot hordoz azokn&#225;l a rendszerekn&#233;l, amelyek &#252;zletileg kritikus szolg&#225;ltat&#225;sok&#233;rt felel&#337;sek &#8211; p&#233;ld&#225;ul <strong>provisioning rendszerek</strong>, <strong>IoT back-endek</strong>, vagy <strong>&#252;zenetsor-kezel&#337;k (pl. RabbitMQ)</strong>. Az &#233;rintett komponens gyakran rejtve van jelen olyan platformokban, amelyeket nem felt&#233;tlen&#252;l tekintenek els&#337;dleges c&#233;lpontnak &#8211; &#237;gy a fenyeget&#233;s <em>l&#225;thatatlanul, de s&#250;lyosan</em> &#233;rintheti a szervezet m&#369;k&#246;d&#233;s&#233;t.</p><p>A s&#233;r&#252;l&#233;kenys&#233;get m&#225;r akt&#237;van figyelik <strong>k&#237;nai APT csoportok</strong> is, p&#233;ld&#225;ul a <strong>Volt Typhoon</strong> &#233;s a <strong>Salt Typhoon</strong>, amelyek kor&#225;bban kritikus infrastrukt&#250;r&#225;kat &#233;s t&#225;vk&#246;zl&#233;si szektort t&#225;madtak.</p><p><strong>S&#250;lyoss&#225;g:</strong> Kritikus (CVSS 3.1: 10.0 &#8211; forr&#225;s: NVD)</p><p><strong>Aj&#225;nl&#225;s:</strong> Az &#233;rintett rendszerek friss&#237;t&#233;se <em>halad&#233;ktalanul sz&#252;ks&#233;ges</em>. Mivel az Erlang/OTP gyakran m&#225;s szoftvercsomagok (pl. RabbitMQ, MongooseIM) r&#233;szek&#233;nt van jelen, olyan rendszerek is &#233;rintettek lehetnek, ahol az Erlang haszn&#225;lata els&#337;re nem egy&#233;rtelm&#369;. Ez&#233;rt minden olyan infrastrukt&#250;r&#225;t &#233;rdemes ellen&#337;rizni, ahol SSH szolg&#225;ltat&#225;s fut, k&#252;l&#246;n&#246;sen ha az eml&#237;tett komponensek b&#225;rmelyike jelen van.</p>
      <p>
          <a href="https://www.cyberthreat.report/p/erlangotp-ssh-kritikus-serulekenyseg">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[IngressNightmare: Több ezer Kubernetes klaszter kompromittálható egyetlen sebezhető komponensen keresztül]]></title><description><![CDATA[T&#225;volr&#243;l, egyetlen konfigur&#225;ci&#243;s mez&#337; manipul&#225;l&#225;s&#225;val hajthat&#243; v&#233;gre k&#243;dfuttat&#225;s az Ingress NGINX Controller proxyj&#225;ban &#8211; jogosults&#225;gkiterjeszt&#233;st &#233;s &#233;rz&#233;keny adatok kisziv&#225;rg&#225;s&#225;t eredm&#233;nyezheti.]]></description><link>https://www.cyberthreat.report/p/ingressnightmare-tobb-ezer-kubernetes</link><guid isPermaLink="false">https://www.cyberthreat.report/p/ingressnightmare-tobb-ezer-kubernetes</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Thu, 27 Mar 2025 16:58:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PHLV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PHLV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PHLV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!PHLV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!PHLV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!PHLV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PHLV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:775800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/159987201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PHLV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!PHLV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!PHLV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!PHLV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa27e6bcb-78f8-46ba-a351-9b4c6356797c_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>A Kubernetes &#246;kosziszt&#233;ma egyik legelterjedtebb komponens&#233;ben, az <strong>Ingress NGINX Controller</strong>ben fedeztek fel t&#246;bb, l&#225;ncba f&#369;zhet&#337; kritikus s&#233;r&#252;l&#233;kenys&#233;get, amelyeknek a kiberbiztons&#225;gi szak&#233;rt&#337;kaz<strong> IngressNightmare</strong><em> </em>&#246;sszefoglal&#243; nevet adt&#225;k<em>. </em>Az &#233;rintett s&#233;r&#252;l&#233;kenys&#233;gek CVE azonos&#237;t&#243;i:<em> </em><strong>CVE-2025-1974, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098 &#233;s CVE-2025-24513.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></strong></p><p>Az Ingress NGINX Controller a Kubernetes klaszterek perem&#233;n elhelyezked&#337; reverse proxy, amely az &#233;rkez&#337; forgalmat tov&#225;bb&#237;tja a megfelel&#337; szolg&#225;ltat&#225;sokhoz &#233;s podokhoz &#8211; kulcsfontoss&#225;g&#250; szerepet j&#225;tszva a kont&#233;neriz&#225;lt alkalmaz&#225;sok k&#252;ls&#337; el&#233;rhet&#337;s&#233;g&#233;ben. A projekt a Kubernetes k&#246;z&#246;ss&#233;g hivatalos r&#233;sze.</p><p><strong>A felh&#337;alap&#250; k&#246;rnyezetek 43%-a &#233;rintett</strong> &#233;s t&#246;bb mint <strong>6500 klaszter</strong> &#8211; k&#246;zt&#252;k Fortune 500 c&#233;gek k&#246;rnyezet&#233;ben &#8211; publikusan el&#233;rhet&#337;v&#233; tette az Ingress admission controller-t, ami <strong>azonnali, kritikus kock&#225;zatot</strong> jelent. A t&#225;mad&#243;k speci&#225;lisan kialak&#237;tott Ingress objektumokon kereszt&#252;l t&#225;voli k&#243;dfuttat&#225;st hajthatnak v&#233;gre &#233;s <strong>teljes ir&#225;ny&#237;t&#225;st szerezhetnek a klaszter felett</strong>.</p><p>A legs&#250;lyosabb CVE (CVE-2025-1974) <strong>CVSS v3.1 pontsz&#225;ma 9.8, ami kritikus, m&#233;g a t&#246;bbi s&#233;r&#252;l&#233;kenys&#233;g magas</strong> (CVSS 7.0&#8211;9.0 k&#246;z&#246;tti) kock&#225;zati besorol&#225;st kapott.</p><p><strong>&#201;rintett term&#233;kek &#233;s verzi&#243;k:</strong></p><ul><li><p><strong>Kubernetes Ingress-NGINX Controller</strong></p></li><li><p>&#201;rintett verzi&#243;k: &lt; 1.11.0, 1.11.0 - 1.11.4, 1.12.0 </p></li><li><p>&#201;rintett telep&#237;t&#233;si m&#243;dok:</p><ul><li><p>Az admission webhook nyilv&#225;nosan el&#233;rhet&#337;</p></li><li><p>Nem megb&#237;zhat&#243; felhaszn&#225;l&#243;k hozhatnak l&#233;tre Ingress objektumokat</p></li></ul></li></ul><p><strong>T&#225;mad&#225;s hat&#225;sa:</strong></p><ul><li><p>Jogosulatlan t&#225;voli k&#243;dfuttat&#225;s (RCE)</p></li><li><p>Teljes klaszter kompromitt&#225;l&#225;sa</p></li><li><p>Titkos adatok kisziv&#225;rg&#225;sa</p></li><li><p>Szolg&#225;ltat&#225;smegtagad&#225;s (DoS)</p></li></ul><p><strong>Exploit el&#233;rhet&#337;s&#233;ge:</strong></p><ul><li><p>R&#233;szleges PoC-ok nyilv&#225;nosan el&#233;rhet&#337;k, teljes funkcionalit&#225;s&#250; exploit egyel&#337;re nem ismert</p></li><li><p>A s&#233;r&#252;l&#233;kenys&#233;gek kihaszn&#225;l&#225;sa viszonylag egyszer&#369;, automatiz&#225;lhat&#243;</p></li></ul>
      <p>
          <a href="https://www.cyberthreat.report/p/ingressnightmare-tobb-ezer-kubernetes">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Apple WebKit Zero-Day sérülékenység – CVE-2025-24201]]></title><description><![CDATA[Akt&#237;van kihaszn&#225;lt sebezhet&#337;s&#233;g, amely lehet&#337;v&#233; teheti a WebKit sandbox megker&#252;l&#233;s&#233;t. Miel&#337;bbi friss&#237;t&#233;s sz&#252;ks&#233;ges.]]></description><link>https://www.cyberthreat.report/p/apple-webkit-zero-day-serulekenyseg</link><guid isPermaLink="false">https://www.cyberthreat.report/p/apple-webkit-zero-day-serulekenyseg</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Fri, 14 Mar 2025 14:13:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Lz43!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lz43!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lz43!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!Lz43!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!Lz43!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!Lz43!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lz43!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:775800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/159021078?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Lz43!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!Lz43!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!Lz43!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!Lz43!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34f9a72b-8012-45e9-bfab-0beb30ce05bc_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>Az <strong>Apple</strong> s&#252;rg&#337;ss&#233;gi <strong>biztons&#225;gi friss&#237;t&#233;s</strong>t adott ki a <strong>CVE-2025-24201</strong> azonos&#237;t&#243;j&#250;, <strong>nulladik napi sebezhet&#337;s&#233;g</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> jav&#237;t&#225;s&#225;ra, amelyet kifinomult t&#225;mad&#225;sok sor&#225;n m&#225;r akt&#237;van kihaszn&#225;ltak. A sebezhet&#337;s&#233;g a WebKit motort &#233;rinti &#8211; ez az a szoftverkomponens, amely felel&#337;s a webes tartalmak megjelen&#237;t&#233;s&#233;&#233;rt a Safari b&#246;ng&#233;sz&#337;ben, va&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/apple-webkit-zero-day-serulekenyseg">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[PingAM Java Agent Sérülékenység (CVE-2025-20059) – Kritikus kockázat az identitás- és hozzáférés-kezelésben]]></title><description><![CDATA[A s&#233;r&#252;l&#233;kenys&#233;g kiemelten &#233;rintheti a p&#233;nz&#252;gyi int&#233;zm&#233;nyeket, korm&#225;nyzati szerveket, nagyv&#225;llalatokat &#233;s hibrid felh&#337;alap&#250; hiteles&#237;t&#233;st haszn&#225;l&#243; rendszereket. Azonnali friss&#237;t&#233;s sz&#252;ks&#233;ges!]]></description><link>https://www.cyberthreat.report/p/pingam-java-agent-serulekenyseg-cve</link><guid isPermaLink="false">https://www.cyberthreat.report/p/pingam-java-agent-serulekenyseg-cve</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Thu, 06 Mar 2025 13:26:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GvpK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GvpK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GvpK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!GvpK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!GvpK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!GvpK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GvpK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:775800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/158257821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GvpK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!GvpK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!GvpK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!GvpK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4664110c-4005-446f-803f-96ae2b1ac64a_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>A <strong>PingAM Java Agent</strong> a Ping Identity<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> hiteles&#237;t&#233;si &#233;s hozz&#225;f&#233;r&#233;s-kezel&#233;si megold&#225;sainak r&#233;szek&#233;nt m&#369;k&#246;d&#337; <strong>Java-alap&#250; &#252;gyn&#246;k</strong>, amelyet sz&#233;les k&#246;rben alkalmaznak <strong>v&#225;llalati, p&#233;nz&#252;gyi &#233;s korm&#225;nyzati rendszerek</strong> hozz&#225;f&#233;r&#233;s-kezel&#233;s&#233;re. A PingAM Java Agent k&#233;pes integr&#225;l&#243;dni <strong>Apache Tomcat, IBM WebSphere, JBoss/WildFly</strong> &#233;s egy&#233;b alkalmaz&#225;sszerverekkel, biztos&#237;tva a <strong>k&#246;zponti azonos&#237;t&#225;si &#233;s jogosults&#225;gkezel&#233;si</strong> folyamatokat. Tov&#225;bb&#225; a <strong>Microsoft Azure </strong>&#233;s az<strong> OPSWAT</strong> integr&#225;ci&#243;k r&#233;v&#233;n a PingAM t&#246;bb szervezet <strong>identit&#225;skezel&#233;si infrastrukt&#250;r&#225;j&#225;nak elem&#233;t k&#233;pezi</strong>.</p><p>A PingAM Java Agent &#250;jonnan felfedezett <strong>kritikus besorol&#225;s&#250; Relative Path Traversal (relat&#237;v k&#246;nyvt&#225;rstrukt&#250;ra bej&#225;r&#225;s)</strong> <strong>s&#233;r&#252;l&#233;kenys&#233;ge (CVE-2025-20059)</strong> komoly vesz&#233;lyt jelenthet az &#233;rintett rendszerekre, mivel lehet&#337;v&#233; teszi <strong>nem hiteles&#237;tett, t&#225;voli t&#225;mad&#243;k sz&#225;m&#225;ra</strong>, hogy speci&#225;lisan kialak&#237;tott URL-ek seg&#237;ts&#233;g&#233;vel hozz&#225;f&#233;rjenek a c&#233;lrendszer f&#225;jlrendszer&#233;hez. A t&#225;mad&#243;k &#237;gy <strong>&#233;rz&#233;keny adatokat - konfigur&#225;ci&#243;s f&#225;jlokat, hiteles&#237;t&#337; adatokat &#233;s API-kulcsokat is megszerezhetnek</strong>, amelyeket azt&#225;n tov&#225;bbi t&#225;mad&#225;si vektorok kialak&#237;t&#225;s&#225;ra haszn&#225;lhatnak. </p><blockquote><p>A probl&#233;ma s&#250;ly&#225;t n&#246;veli, hogy a <strong>PingAM Java Agent kulcsszerepet j&#225;tszik sz&#225;mos v&#225;llalat &#233;s int&#233;zm&#233;ny identit&#225;skezel&#233;si infrastrukt&#250;r&#225;j&#225;ban, &#237;gy a s&#233;r&#252;l&#233;kenys&#233;g k&#246;zvetlen hat&#225;ssal lehet kritikus szektorokra, mint a p&#233;nz&#252;gyi szolg&#225;ltat&#225;sok, eg&#233;szs&#233;g&#252;gy, korm&#225;nyzat &#233;s telekommunik&#225;ci&#243;. Az ell&#225;t&#225;si l&#225;nc biztons&#225;ga szempontj&#225;b&#243;l is jelent&#337;s kock&#225;zatot jelenthet, mivel egyetlen kompromitt&#225;lt PingAM &#252;gyn&#246;k&#246;n kereszt&#252;l t&#246;bb kapcsol&#243;d&#243; alkalmaz&#225;s &#233;s szolg&#225;ltat&#225;s is vesz&#233;lybe ker&#252;lhet.</strong></p></blockquote><p>A s&#233;r&#252;l&#233;kenys&#233;g <strong>CVSS v3.1 alapj&#225;n 10-es, azaz kritikus besorol&#225;st kapott</strong>, ami szint&#233;n jelzi a probl&#233;ma rendk&#237;v&#252;li s&#250;lyoss&#225;g&#225;t &#233;s <strong>azonnali beavatkoz&#225;st ig&#233;nyel</strong>.</p>
      <p>
          <a href="https://www.cyberthreat.report/p/pingam-java-agent-serulekenyseg-cve">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Kritikus sérülékenységek a Palo Alto Networks tűzfalakban]]></title><description><![CDATA[Hiteles&#237;t&#233;s megker&#252;l&#233;s&#233;t &#233;s rendszerszint&#369; jogosults&#225;gok megszerz&#233;s&#233;t lehet&#337;v&#233; tev&#337; sebezhet&#337;s&#233;gek a Palo Alto Network term&#233;kekben. Azonnali friss&#237;t&#233;s sz&#252;ks&#233;ges.]]></description><link>https://www.cyberthreat.report/p/kritikus-serulekenysegek-a-palo-alto</link><guid isPermaLink="false">https://www.cyberthreat.report/p/kritikus-serulekenysegek-a-palo-alto</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Fri, 21 Feb 2025 05:20:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PFEE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PFEE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PFEE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!PFEE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!PFEE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!PFEE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PFEE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:775800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/157550499?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PFEE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!PFEE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!PFEE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!PFEE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eef66bf-2c29-4cab-888e-53d6bfa54e63_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>A Palo Alto Networks PAN-OS t&#369;zfalakban t&#246;bb s&#233;r&#252;l&#233;kenys&#233;get azonos&#237;tottak, amelyek kihaszn&#225;l&#225;s&#225;val a t&#225;mad&#243;k hiteles&#237;t&#233;s n&#233;lk&#252;l hozz&#225;f&#233;rhetnek a rendszerekhez, &#233;s rendszergazdai jogosults&#225;gokat szerezhetnek. Ezeket a s&#233;r&#252;l&#233;kenys&#233;geket m&#225;r akt&#237;van kihaszn&#225;lj&#225;k a t&#225;mad&#243;k, ez&#233;rt elengedhetetlen a rendszerek azonnali friss&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/kritikus-serulekenysegek-a-palo-alto">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[OpenSSH Man-in-the-Middle és Denial-of-Service sérülékenységek]]></title><description><![CDATA[A k&#233;t &#250;jonnan felfedezett s&#233;r&#252;l&#233;kenys&#233;g az OpenSSH rendszerekben lehet&#337;v&#233; teszi a kommunik&#225;ci&#243; lehallgat&#225;s&#225;t &#233;s a szolg&#225;ltat&#225;sok megb&#233;n&#237;t&#225;s&#225;t. A jav&#237;t&#225;s m&#225;r el&#233;rhet&#337;.]]></description><link>https://www.cyberthreat.report/p/openssh-man-in-the-middle-es-denial</link><guid isPermaLink="false">https://www.cyberthreat.report/p/openssh-man-in-the-middle-es-denial</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Fri, 21 Feb 2025 02:15:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vaNq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vaNq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vaNq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!vaNq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!vaNq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!vaNq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vaNq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:775800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/157560621?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vaNq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!vaNq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!vaNq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!vaNq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4857aef8-b8c8-4c73-8793-4633539a7488_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>Az OpenSSH h&#225;l&#243;zati kommunik&#225;ci&#243;s eszk&#246;zk&#233;szlet&#233;ben k&#233;t &#250;j k&#246;zepes s&#250;lyoss&#225;g&#250; s&#233;r&#252;l&#233;kenys&#233;get azonos&#237;tottak. B&#225;r <strong>a CVSS pontsz&#225;muk nem min&#337;s&#252;l kritikusnak</strong>, egyes k&#246;rnyezetekben a <strong>val&#243;s kock&#225;zati hat&#225;suk magas lehet</strong>, k&#252;l&#246;n&#246;sen akkor, ha a t&#225;mad&#243;k m&#225;s t&#225;mad&#225;si technik&#225;kkal kombin&#225;lj&#225;k &#337;ket.</p><p><strong>CVE-2025-26465 (CVSS: 6.8 &#8211; Man-in-the-Middle t&#225;mad&#225;s lehet&#337;s&#233;ge)</strong></p><ul><li><p>A <code>VerifyHostKeyDNS</code> opci&#243; hib&#225;s m&#369;k&#246;d&#233;se miatt egy t&#225;mad&#243; <strong>legitim SSH szervernek &#225;lc&#225;zhatja mag&#225;t</strong>, &#237;gy lehet&#337;s&#233;ge ny&#237;lik a h&#225;l&#243;zati forgalom elfog&#225;s&#225;ra &#233;s m&#243;dos&#237;t&#225;s&#225;ra.</p></li></ul><p><strong>CVE-2025-26466 (CVSS: 5.9 &#8211; Denial-of-Service t&#225;mad&#225;s)</strong></p><ul><li><p>Egy speci&#225;lisan kialak&#237;tott SSH k&#233;r&#233;s kihaszn&#225;l&#225;s&#225;val <strong>a t&#225;mad&#243; t&#250;lterhelheti az SSH szervert vagy klienst</strong>, megb&#233;n&#237;tva annak m&#369;k&#246;d&#233;s&#233;t &#233;s megakad&#225;lyozva a legitim hozz&#225;f&#233;r&#233;seket.</p></li></ul><p><strong>Kritikus rendszerek eset&#233;ben (pl. v&#225;llalati infrastrukt&#250;ra, t&#225;voli hozz&#225;f&#233;r&#233;si szolg&#225;ltat&#225;sok, DevOps k&#246;rnyezetek)</strong> a s&#233;r&#252;l&#233;kenys&#233;gek hat&#225;sa <strong>magas kock&#225;zat&#250;v&#225; v&#225;lhat</strong>, k&#252;l&#246;n&#246;sen <strong>t&#225;mad&#225;si l&#225;nc r&#233;szek&#233;nt</strong>.</p>
      <p>
          <a href="https://www.cyberthreat.report/p/openssh-man-in-the-middle-es-denial">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Juniper Session Smart Router hitelesítés megkerülési sérülékenység (CVE-2025-21589)]]></title><description><![CDATA[Kritikus sebezhet&#337;s&#233;g a Juniper Session Smart Router rendszereiben, amely lehet&#337;v&#233; teszi a hiteles&#237;t&#233;s megker&#252;l&#233;s&#233;t &#233;s az eszk&#246;z&#246;k teljes ir&#225;ny&#237;t&#225;s&#225;t. Azonnali friss&#237;t&#233;s sz&#252;ks&#233;ges!]]></description><link>https://www.cyberthreat.report/p/juniper-session-smart-router-hitelesites</link><guid isPermaLink="false">https://www.cyberthreat.report/p/juniper-session-smart-router-hitelesites</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Thu, 20 Feb 2025 12:59:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kUN0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kUN0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kUN0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!kUN0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!kUN0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!kUN0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kUN0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:761960,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/157514161?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kUN0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!kUN0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!kUN0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!kUN0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd866ffa-928a-40d9-9930-29306a9b4389_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>A Juniper Networks <strong>Session Smart Router</strong>, <strong>Session Smart Conductor</strong> &#233;s <strong>WAN Assurance Router</strong> term&#233;keiben egy kritikus, <strong>hiteles&#237;t&#233;s megker&#252;l&#233;si</strong> sebezhet&#337;s&#233;get (CVE-2025-21589) azonos&#237;tottak. A sebezhet&#337;s&#233;g kihaszn&#225;l&#225;s&#225;val a t&#225;mad&#243;k h&#225;l&#243;zati hozz&#225;f&#233;r&#233;ssel megker&#252;lhetik az autentik&#225;ci&#243;t, &#233;s teljes adminisztrat&#237;v ir&#225;ny&#237;t&#225;st sze&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/juniper-session-smart-router-hitelesites">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[SonicWall SSL VPN Hitelesítés Megkerülési Sérülékenység (CVE-2024-53704)]]></title><description><![CDATA[Kritikus SonicWall SSL VPN sebezhet&#337;s&#233;g teszi lehet&#337;v&#233; a hiteles&#237;t&#233;s megker&#252;l&#233;s&#233;t. Az exploit k&#243;d el&#233;rhet&#337;, a t&#225;mad&#225;sok akt&#237;vak. Azonnali friss&#237;t&#233;s &#233;s v&#233;dekez&#233;s sz&#252;ks&#233;ges!]]></description><link>https://www.cyberthreat.report/p/sonicwall-ssl-vpn-hitelesites-megkerulesi</link><guid isPermaLink="false">https://www.cyberthreat.report/p/sonicwall-ssl-vpn-hitelesites-megkerulesi</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Thu, 20 Feb 2025 12:56:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!T905!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T905!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T905!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!T905!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!T905!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!T905!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T905!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:749944,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/157507686?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T905!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!T905!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!T905!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!T905!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67027584-daaf-4c85-8ace-ef41f52b65da_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated wit AI by Katalin B&#233;res</figcaption></figure></div><p></p><p>Egy <strong>kritikus hiteles&#237;t&#233;s megker&#252;l&#233;si (authentication bypass) sebezhet&#337;s&#233;g</strong> ker&#252;lt azonos&#237;t&#225;sra a <strong>SonicWall SSL VPN</strong> megold&#225;sokban. A sebezhet&#337;s&#233;g kihaszn&#225;l&#225;s&#225;val t&#225;mad&#243;k jogosulatlan hozz&#225;f&#233;r&#233;st szerezhetnek a bels&#337; h&#225;l&#243;zatokhoz, <strong>megker&#252;lve az autentik&#225;ci&#243;s mechanizmusokat</strong>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">A CyberThreat Report egy az olvas&#243;k &#225;ltal t&#225;mogato&#8230;</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>
      <p>
          <a href="https://www.cyberthreat.report/p/sonicwall-ssl-vpn-hitelesites-megkerulesi">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>