Telekom Security Updates
-
Apple's iOS & macOS Contacts Vulnerability - Privacy Preferences Bypass
A vulnerability has been identified in iOS/iPadOS < 15.7 / < 16.0 and macOS Big Sur < 11.7 that allows an app to bypass Privacy preferences, posing a significant risk. The vulnerability, classified as Improper Input Validation a...
Continue Reading -
T-Pot Version 22.04 released
We are proud to announce the release of T-Pot 22.04 with lots of new features i.e. new honeypots, a distributed installation option, arm64 support, live attack maps, Debian 11 base, ELK 8.x, and more. If you ever wanted to get started wi...
Continue Reading -
Twitter Account of Deutsche Telekom's CERT Resumed
We are very pleased to announce that Deutsche Telekom’s CERT recently has resumed their twitter activity. Make sure to follow @DTCERT for technical tweets from CERT, CTI, and DFIR.
Continue Reading -
Enumerating and indexing SMB shares at scale
In order to improve and harden our group’s critical telco-infrastructure,Deutsche Telekom Security GmbH provides a red team to simulate real worldattack scenarios. While our red team also offers its capabilities for externalcustomers, ou...
Continue Reading -
Critical DoS vulnerability in SQLCipher SQL command processing
A new critical denial-of-service vulnerability (CVE-2021-3119) in the SQLCipher SQL command processing of the master branch was discovered with a self-developed SQLCipher-FAST (Fast Automated Software Testing) framework.View the full adv...
Continue Reading -
Denial of service vulnerability in SQLCipher SQL command processing
A new critical denial of service vulnerability (Use CVE-2020-27207) in the SQLCipher SQL command processing of the master branch (https://github.com/sqlcipher) was discovered with a self-developed SQLCipher-FAST (Fast Automated Software ...
Continue Reading -
Wire Secure Messenger Remote Format String Vulnerability
A Remote Format String Vulnerability in the Wire Secure Messenger (CVE-2020-27853) allows an attacker to cause a denial of service (application crash) or possibly execute arbitrary code via voice or video call. This affects Wire AVS (Aud...
Continue Reading -
ILIAS RCE Via PHP File Inclusion
Two vulnerabilities in the ILIAS learning management < 5.4.10 system were found which can be chained together to achieve remote code execution via an authenticated user.
Continue Reading