Blumira Briefings
Staying on top of security news shouldn't be another full-time job.
Enter Blumira Briefings, our weekly panel series where security experts break down the headlines you might have missed, and explain what they actually mean for your security practice! 🔒
Each week, join a lineup of different Blumira experts (and sometimes special guests!) who will:
- Share the top threats, suspects, and risks we're seeing across our detection and response platform
- Discuss significant security stories and what they mean for YOU
- Provide practical advice you can actually implement right away
••Keep it conversational, informative, and under 30 minutes
Blumira Briefings
Gitea Code Injection, miniOrange Auth Bypass, and Shrinking Patch Windows - Blumira Briefings
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to Blumira Briefings, your weekly download of the top headlines for your security practice!
In this week's edition:
- Critical Remote Code Execution Vulnerability in Gitea Actively Exploited, CISA Warns
- Critical WordPress SAML Plugin Authentication Bypasses Actively Exploited While Unpatched
- Microsoft Advises Network Controls as Vulnerability Patching Window Rapidly Shrinks
Sources:
Hackers now exploit critical Gitea flaw in code injection attacks
https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
--
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
https://securityaffairs.com/197815/security/two-cvss-9-8-auth-bypasses-in-miniorange-saml-wordpress-plugin-were-exploited-before-any-database-even-listed-the-paid-editions-as-vulnerable.html
--
Microsoft warns patch window is collapsing, urges shift to network-level containment
https://www.csoonline.com/article/4214135/microsoft-warns-patch-window-is-collapsing-urges-shift-to-network-level-containment.html
--