ISC StormCast for Wednesday, January 15th, 2025

ISC StormCast for Wednesday, January 15th, 2025

Update: 2025-01-15
Share

Description

Today, Microsoft Patch Tuesday headlines our news with Microsoft patching 209 vulnerabilities, some

of which have already been exploited. Fortinet suspects a so far unpatched Node.js authentication

bypass to be behind some recent exploits of FortiOS and FortiProxy devices.

Microsoft January 2025 Patch Tuesday

This month's Microsoft patch update addresses a total of 209 vulnerabilities, including 12 classified as critical. Among these, 3 vulnerabilities have been actively exploited in the wild, and 5 have been disclosed prior to the patch release, marking them as zero-days.

https://isc.sans.edu/diary/rss/31590

Fortinet Security Advisory FG-IR-24-535 CVE-2024-55591

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

https://fortiguard.fortinet.com/psirt/FG-IR-24-535

PRTG Network Monitor Update:

Update for an already exploited XSS vulnerability in Paesler PRTG Network Monitor CVE-2024-12833

https://www.paessler.com/prtg/history/stable
Comments 
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

ISC StormCast for Wednesday, January 15th, 2025

ISC StormCast for Wednesday, January 15th, 2025

Dr. Johannes B. Ullrich