Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

usd AG

@usdAG@infosec.exchange
  • Open on infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission.

Imprint: http://usd.de/en/imprint
Privacy protection: http://usd.de/en/privacy-protection

96 Followers
9 Following
10 Posts
Joined April 03, 2023
Website:
https://www.usd.de/en/
Security Advisories:
https://herolab.usd.de/en/security-advisories/
Events (German):
https://www.usd.de/cst-academy/events/

Posts

Open post
usdAG
usd AG @usdAG@infosec.exchange · Apr 13, 2026
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

🔎 You can find detailed information on the #SecurityAdvisories here: https://www.usd.de/en/security-advisories-entra-id-tenable-nessus-manager/

#SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

2
0
2
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Mar 20, 2026
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

Our pentest professionals at #usdHeroLab identified several vulnerabilities in #KofaxCommunicationServer (KCS) and in the #ArcGIS scripting language Arcade ranging from path traversal to XSS.

All #vulnerabilities were responsibly reported to the vendors.

👉 Details on our #SecurityAdvisories can be found here: https://www.usd.de/en/security-advisories-kofax-communication-server-arcgis-arcade/

#Kofax #InfoSec #CyberSecurity #Pentesting #AppSec #Hacking

1
0
1
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Sep 11, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

Our security analyst @kpwn@infosec.exchange identified two #XSS vulnerabilities during web application pentests.

👉 Affected software: Weblication CMS Core and d.3one. These vulnerabilities enable attackers to execute requests on behalf of other users.

📰 Detailed information on our advisories can be found here: https://www.usd.de/en/security-advisories-d-3one-and-weblication-cms-core/

#Pentesting #InfoSec #AppSec #CyberSecurity #Vulnerability #Hacking

infosec.exchange

Konstantin :C_H: (@kpwn@infosec.exchange) - Infosec Exchange

2
0
0
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Jul 02, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

Unauthenticated RCE in Agorum Core Open!

During their regular security analyses, our pentest professionals from #usdHeroLab examined the open source software #AgorumCoreOpen.

They discovered multiple #vulnerabilities that, when chained together, allow an unauthenticated attacker to achieve full remote code execution with root privileges. This critical flaw enables complete system compromise without prior authentication.

📰👉 Detailed information on the published #SecurityAdvisories can be found here: https://www.usd.de/en/security-advisories-on-agorum-core-open/

#Pentest #Pentesting #moresecurity #RCE #CyberSecurity #InfoSec

0
0
0
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Jun 17, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

🔍 Our professionals at the usd HeroLab have closely examined the software #Vtiger. They discovered two vulnerabiltiies that allow low-privileged authorized users to upload files and thereby execute arbitrary code.

👉 You can find more information in the full security advisories: https://www.usd.de/en/security-advisories-vtiger/

#SecurityAdvisories #Pentest #Pentesting #moresecurity

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · May 09, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

We have found an interesting vulnerability in a #Matrix #Android client:

🧩 Software: #Element X Android
📦 Affected Version: <= 25.04.1
🆔 CVE: CVE-2025-27599
📊 CVSSv3.1: MEDIUM
⚠️ Prerequisites: Clicking on a crafted hyperlink or using a malicious app

Since Element X Android usually has the permission to access camera and microphone, this can be used to record audio and video from the victim. Pretty bad! 😨

🔗 Read more: https://herolab.usd.de/security-advisories/usd-2025-0010/

#InfoSec #CyberSecurity #Pentesting #Hacking #CVE_2025_27599 #SpyWare #Phishing

infosec.exchange

Infosec Exchange

4
0
8
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Apr 08, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

If you're using Element Android < 1.6.34, you should update.

In according versions, a brute force attack on the PIN code is possible if the PIN code is set and the Internet connection is deactivated (CVE-2025-27606)

📌 Read the full details here: https://herolab.usd.de/en/security-advisories/usd-2025-0002/

1
0
1
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Mar 07, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

In a recent #forensic engagement our colleagues @fh@infosec.exchange and @nicolas93@infosec.exchange were tasked with analyzing a leak of a #ransomware group for sensitive information 💻🔍

Read more about their experience below 🧵

#CyberSecurity #InfoSec #Hacking #Forensics #Incident

infosec.exchange

Infosec Exchange

0
1
0
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Mar 07, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

If you're using the #Cubro EXA48200 network packet broker, you should update to V5.0R14.5P4-V3.3R1.

Our expert, Tim Wörner, discovered a broken access control vulnerability in the user management API, which leads to privilege escalation (CVE-2024-55570).

📌 Read the full details here: https://herolab.usd.de/en/security-advisories/usd-2024-0014/

#CVE #AppSec #Cubro #InfoSec #CyberSecurity #Hacking #Pentest #CVE_2024_55570

0
0
0
0
Open post
usdAG
usd AG @usdAG@infosec.exchange · Feb 28, 2025
usd AG
@usdAG@infosec.exchange

We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprint Privacy protection: http://usd.de/en/privacy-protection

infosec.exchange

Better Code Scanning? Putting #Opengrep to the Test 🧐

Part of consistently improving our #pentesting procedures includes evaluating the tools we use in our assessments. When conducting code-reviews and pentests of fat-client applications we are often faced with the challenge of identifying vulnerabilities in the targets source code. 🧵

#AppSec #CyberSecurity #InfoSec #Hacking #CodeReview #SourceCode #Semgrep

infosec.exchange

Infosec Exchange

1
1
1
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:28:47 UTC