Jun 25, 2024NewsroomVulnerability / Threat Detection Threat actors are exploiting a novel attack technique in the wild that leverages specially crafted management saved console (MSC) files to gain full code execution using Microsoft Management Console (MMC) and evade security defenses. Elastic Security Labs has codenamed the approach GrimResource after identifying an artifact … [Read more...] about New Attack Technique Exploits Microsoft Management Console Files
Console
Big Console improvements in Kibana
5. Autocomplete for new ES entitiesAutocomplete is the heart of Console. In 8.2, we updated autocomplete to suggest the names of the specific composable index templates, component templates, and data streams that exist in your deployment.PerformanceConsole performance has been an issue for larger deployments, especially for folks who use Console a lot. We took some time to … [Read more...] about Big Console improvements in Kibana
Log4Shell-like Critical RCE Flaw Discovered in H2 Database Console
Researchers have disclosed a security flaw affecting H2 database consoles that could result in remote code execution in a manner that echoes the Log4j "Log4Shell" vulnerability that came to light last month. The issue, tracked as CVE-2021-42392, is the " first critical issue published since Log4Shell, on a component other than Log4j, that exploits the same root cause of the … [Read more...] about Log4Shell-like Critical RCE Flaw Discovered in H2 Database Console