Software Engineering Institute(@SEI_CMU) 's Twitter Profile Photo

A New CERT Vulnerability Note: R Programming Language implementations are vulnerable to arbitrary code execution during deserialization of .rds and .rdx files - kb.cert.org/vuls/id/238194

A New CERT Vulnerability Note: R Programming Language implementations are vulnerable to arbitrary code execution during deserialization of .rds and .rdx files - kb.cert.org/vuls/id/238194
account_circle
Ricardo Ferreira(@riferrei) 's Twitter Profile Photo

Using Amazon Q Developer to solve a problem in my code related to data deserialization in and .

📝 Blog post:

community.aws/content/2fbWID…

account_circle
Sergio Medeiros(@grumpzsux) 's Twitter Profile Photo

CVE-2024-27322 vulnerability in R's deserialization process gives attackers a way to execute arbitrary code in target environments via specially crafted files 🔥

buff.ly/3WoDTaj

RT Stefan Tanase

CVE-2024-27322 vulnerability in R's deserialization process gives attackers a way to execute arbitrary code in target environments via specially crafted files 🔥 

buff.ly/3WoDTaj 

RT @stefant

#hackernews #hackers #cybersecurity
account_circle
Anna Leushchenko 👩‍💻💙📱🇺🇦(@AnnaLeushchenko) 's Twitter Profile Photo

Creating and applications often includes a range of typical tasks, such as implementing JSON deserialization, consuming backend APIs, creating a dependency inversion mechanism, implementing navigation and localization, managing assets, writing tests, and more.

👇🏻

account_circle
Gray Hats(@the_yellow_fall) 's Twitter Profile Photo

CVE-2024-27322 (CVSS 8.8) arises from the deserialization process in R, where objects encoded in formats like JSON, XML, and binary are converted back to their original form for use within an application or program
meterpreter.org/high-severity-…

account_circle
Ricardo Ferreira(@riferrei) 's Twitter Profile Photo

What if I told you that helped me solve a nasty data deserialization problem involving , , and ?

➡️ Would you believe it? 🤨

You don't have to believe it. See for yourself. I wrote a blog post detailing this experience.

community.aws/content/2fbWID…

What if I told you that #AmazonQ helped me solve a nasty data deserialization problem involving #ApacheKafka, #Go, and #ProtoBuf?

➡️ Would you believe it? 🤨

You don't have to believe it. See for yourself. I wrote a blog post detailing this experience.

community.aws/content/2fbWID…
account_circle
HiddenLayer(@hiddenlayersec) 's Twitter Profile Photo

Our SAI team uncovered a deserialization vulnerability in the popular statistical programming language R, widely used within and . This could be used as part of a .

Learn more 👇hubs.ly/Q02vkG4w0

account_circle
Artillain(@artillain) 's Twitter Profile Photo

Deserialization is a major security hole in OOP PHP applications.

Here's a tool to design a remote code execution on popular OOP PHP libraries. Hair raising.

Luckily, Zerolith does not use serialization/deserialization because it's not OOP. :)

github.com/ambionics/phpg…

account_circle
CCB Alert(@CCBalert) 's Twitter Profile Photo

Warning: -2024-27322 is a in resulting in . Avoid importing untrusted files in your projects and beware of possible supply chain attacks via R packages using the function. kb.cert.org/vuls/id/238194

account_circle
bruHFT(@BruHFT_quant) 's Twitter Profile Photo

Working on cutting down deserialization times, had a vague idea, turns out it worked pretty well :) If this is a bottleneck for you take some time to really think about it, you'll probably cut down your time atmost in a days time by 30%

Working on cutting down deserialization times, had a vague idea, turns out it worked pretty well :) If this is a bottleneck for you take some time to really think about it, you'll probably cut down your time atmost in a days time by 30%
account_circle
βeta(@levbeta) 's Twitter Profile Photo

Deserialization is slow, but, what about the time u are taking to serialize ur orders before sending to the exchange?

Yeah, that can be made faster, with 9 lines of code, almost 50% faster.

Deserialization is slow, but, what about the time u are taking to serialize ur orders before sending to the exchange?

Yeah, that can be made faster, with 9 lines of code, almost 50% faster.
account_circle
Fede’s intern(@fede_intern) 's Twitter Profile Photo

We were able to further reduce the gas consumption of Mina Protocol (httpz) 🪶 bridge to Ethereum Foundation. It’s still huge but we lowered from hundreds of millions in only a few days. I think we can get it to 5/10M.

Latest values:
- Deserialization: from ~26M --> 17M
- Verifier: from ~27M --> 21M…

account_circle
Loukas Theodosiou(@loukesio) 's Twitter Profile Photo

Dear network,
A severe security vulnerability has been discovered in R, and reported from the US National Vulnerability Database lnkd.in/dmYP2Vcs.

📌 The vulnerability involves the 'deserialization of untrusted data'...

Upgrade to R Version 4.4.0 Now! 🚨

account_circle
Neil Gunther(@DrQz) 's Twitter Profile Photo

PSA: R security note VU#238194

R is vulnerable to arbitrary code execution during deserialization of .rds and .rdx files. V4.4.0 now restricts promises in the serialization stream so they're used for implementing lazy evaluation
kb.cert.org/vuls/id/238194

PSA: R security note  VU#238194 

R is vulnerable to arbitrary code execution during deserialization of .rds and .rdx files. V4.4.0 now restricts promises in the serialization stream so they're used for implementing lazy evaluation 
kb.cert.org/vuls/id/238194  #rstats #infosec
account_circle