Hi friends,
I hope you had a good week! I sure did, I passed my exam! :-) There are more to come in the next few months, but that's a concern for future me. For now I'm wrapping a few things up, and then off to a glorious week of vacation.
Have a good one folks!
Cheers,
Websites can have client-side code make requests to 0.0.0.0, and browsers will interpret this is a request to the localhost or local network, yet won't block it.
Fixes are being rolled out, but it's note-worthy that the vulnerability was first reported 18 years ago, and only now is getting attention. Especially since it has been exploited in the wild, with a recent uptick in popularity. It only works on Mac and Linux though, surprisingly.
Don't worry Windows, you get some love too. Researchers discovered a Windows Update downgrade attack that can "unpatch" fully-updated Windows 10, 11, and Server systems to reintroduce old vulnerabilities.
The way the researchers describe it, the attack is "undetectable because it cannot be blocked by endpoint detection and response (EDR) solutions, and it's also invisible since Windows Update reports that a device is fully updated (despite being downgraded)". Great. Kudos to the researchers though, very interesting find.
Microsoft hasn't been able to release patches yet, even though the research was disclosed to them six months ago. They do share some mitigation advice. No exploit attempts have been seen in the wild, let's hope it stays that way.