moreweb.
164 subscribers
38 photos
19 videos
1 file
245 links
Download Telegram
moreweb.
https://depot.dev/
GItHub actions alternative (Actions compatible, Agents compatible)
This media is not supported in your browser
VIEW IN TELEGRAM
Footage recorded along Tehran’s Azadegan Highway corridor shows an unidentified airborne object displaying a curved array of synchronized, multicolor lights in airspace situated between Mehrabad International Airport and Imam Khomeini International Airport. Analysis of the craft's uniform light spacing and stable flight profile suggests a physical airframe rather than synthetic media, with primary technical explanations pointing to a custom fixed-wing radio-controlled platform, a specialized LED drone array, or an illuminated tethered kite. Aviation and defense monitoring authorities have not released transponder data or an official identification regarding the platform.
According to published reports, India and Iraq have also joined the U.S. air blockade against Iran.
1. Cisco ISE Zero-Day
Cisco ISE and ISE-PIC versions 3.0–3.5 are affected by actively exploited CVE-2026-76460, an authentication-bypass flaw.
No workaround is available. Upgrade immediately.

2. Cisco Secure Email Gateway
CVE-2026-76461 affects Cisco Secure Email Gateway and AsyncOS. The SQL-injection flaw is actively exploited and listed by CISA.
Apply fixed releases, verify versions, and review logs.

3. Acronis Backup Integrations
CVE-2026-87886 affects Acronis plug-ins for cPanel/WHM and Plesk. Local users may escalate privileges to root.
Apply fixes and review accounts and permissions.

4. Pixel Modem Zero-Day
Google fixed exploited Pixel modem flaw CVE-2026-58704.
Install the Android security update dated 2026-09-05 or later. Organizations should check mobile patch compliance.

5. BlueMoon Exploit Chain
The BlueMoon campaign reportedly chained browser, sandbox, and Windows flaws to target government and defense organizations.
Patch browsers and Windows, remove local admin rights, and monitor browser-to-system execution.

Control-plane systems remain major targets, including identity, email, firewalls, backups, and developer automation.
WARNING ⚠️
The Central Bank has presented installing an “internal root certificate” on customers’ devices as one way to continue banking services.

But the issue is not merely eliminating warnings in internet banking. If this trust is established at the level of the entire device, it could affect more than just the bank’s website and, under specific circumstances, create the conditions for monitoring encrypted communications.

A browser considers a website’s certificate valid when its chain of trust leads back to a trusted root authority. If a user adds an internal root certificate to the operating system, the device may also recognize certificates issued by that same authority for other websites as valid.

The danger arises when that authority issues a fake certificate for a website and an attacker is able to position themselves in the traffic path. In such circumstances, the browser may trust the intermediary without displaying the usual warning, while a man-in-the-middle attack could enable the communication to be decrypted.

Installing a root certificate by itself does not mean that eavesdropping will occur; the main issue is the broad discretion granted to that authority.

There is, of course, a lower-risk approach: the banking app could trust an internal authority only for its own services and domains, without changing the trust store for the entire device.

That raises the central question about the Central Bank’s proposal: to resolve disruptions to banking services, why should trust in a new authority potentially be extended to communications outside the banking system as well?
❤1
moreweb.
WARNING ⚠️ The Central Bank has presented installing an “internal root certificate” on customers’ devices as one way to continue banking services. But the issue is not merely eliminating warnings in internet banking. If this trust is established at the level…
We have been saying this at moreweb for months now
This is an immediate security risk for the end-user with surveillance as the real result

I repeat, This is Mitm
THIS IS MITM
THIS IS MITM
DO NOT INSTALL THE ROOT CERTIFICATE
❤2
نصب گواهی ریشه بانک مرکزی در دستگاه شما این امکان را فراهم میکند تا تمام ترافیک شبکه شما بدون استثنا توسط سیستم فیلترینگ بررسی شود

این به این معناست که آیکون قفل سبز در مرورگر به یک دروغ به تمام معنا تبدیل شده و تمام ترافیک قابل مشاهده خواهد بود ⚠️
👍5
moreweb. pinned «نصب گواهی ریشه بانک مرکزی در دستگاه شما این امکان را فراهم میکند تا تمام ترافیک شبکه شما بدون استثنا توسط سیستم فیلترینگ بررسی شود این به این معناست که آیکون قفل سبز در مرورگر به یک دروغ به تمام معنا تبدیل شده و تمام ترافیک قابل مشاهده خواهد بود ⚠️»
moreweb.
نصب گواهی ریشه بانک مرکزی در دستگاه شما این امکان را فراهم میکند تا تمام ترافیک شبکه شما بدون استثنا توسط سیستم فیلترینگ بررسی شود این به این معناست که آیکون قفل سبز در مرورگر به یک دروغ به تمام معنا تبدیل شده و تمام ترافیک قابل مشاهده خواهد بود ⚠️
بانک مرکزی نصب «گواهی ریشه داخلی» روی دستگاه مشتریان را یکی از راه‌های ادامه خدمات بانکی مطرح کرده است!
اما مسئله فقط رفع هشدار اینترنت‌بانک نیست؛ اگر این اعتماد در سطح کل دستگاه ایجاد شود، می‌تواند فراتر از سایت بانک اثر بگذارد و در شرایط مشخص، زمینه رهگیری ارتباطات رمزگذاری‌شده را فراهم کند.

مرورگر زمانی گواهی یک سایت را معتبر می‌داند که زنجیره آن به یک مرجع ریشه مورد اعتماد برسد. اگر کاربر یک ریشه داخلی را به سیستم‌عامل اضافه کند، دستگاه ممکن است گواهی‌های دیگری را هم که همان مرجع صادر کرده معتبر بشناسد.
خطر زمانی ایجاد می‌شود که آن مرجع برای یک سایت گواهی جعلی صادر کند و مهاجم نیز بتواند در مسیر ترافیک قرار بگیرد. در چنین شرایطی، مرورگر می‌تواند بدون هشدار معمول به واسطه اعتماد کند و حمله «مرد میانی» امکان رمزگشایی ارتباط را فراهم کند.

نصب گواهی ریشه به‌تنهایی به معنای شنود نیست؛ مسئله اصلی دامنه اختیاری است که به آن مرجع داده می‌شود.
البته راه کم‌خطرتر وجود دارد؛ اپ بانک می‌تواند فقط برای سرویس‌ها و دامنه‌های خودش به یک مرجع داخلی اعتماد کند، بدون تغییر فهرست اعتماد کل دستگاه.
پرسش اصلی طرح بانک مرکزی همین است: برای حل اختلال خدمات بانکی، چرا باید اعتماد یک مرجع تازه احتمالا به ارتباطات خارج از بانک هم گسترش پیدا کند؟


© raaznet
❤1