AmberWolf @amberwolfsec.bsky.social · 04/06/2025AmberWolf has published technical details on CVE-2025-32752, a vulnerability affecting Dell ThinOS. Security researcher Darren McDonald discovered that when the troubleshooting feature “Create Core Dump” is used, ThinOS saves core dumps to an unencrypted partition. 110
AmberWolf @amberwolfsec.bsky.social · 17/01/2025The Kubernetes Security Response Committee has published an advisory for CVE-2024-9042, affecting Windows worker nodes querying the /logs endpoint. Iain Smart, Principal Security Consultant at AmberWolf, reproduced the issue & shared detection insights in our latest blog. 134
AmberWolf @amberwolfsec.bsky.social · 28/12/2024All I want for Christmas is U(RL handlers not vulnerable to RCE)... AmberWolf has published information about CVE-2024-12908, a Remote Code Execution vulnerability in the Delinea Secret Server Protocol Handler. You can read our blog & PoC here: blog.amberwolf.com/blog/2024/de...blog.amberwolf.comDelinea Protocol Handler - Remote Code Execution via Update Process (CVE-2024-12908)AmberWolf Security Research Blog 032
AmberWolf @amberwolfsec.bsky.social · 26/11/2024Today, AmberWolf released two blog posts and our tool "NachoVPN" to target vulnerabilities in major VPNs, including CVE-2024-29014 (SonicWall NetExtender SYSTEM RCE) and CVE-2024-5921 (Palo Alto GlobalProtect RCE and Priv Esc), after our SANS HackFest presentation.🧵 165