SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues
DEC 22, 20256 MIN
SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues
DEC 22, 20256 MIN
Description
<br/>
DLLs & TLS Callbacks<br/>
As a follow-up to last week's diary about DLL Entrypoints, Didier is looking at TLS ( Thread Local Storage ) and how it can be abused.<br/>
<a href="https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580">https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580</a><br/>
FreeBSD Remote code execution via ND6 Router Advertisements<br/>
A critical vulnerability in FreeBSD allows for remote code execution. But an attacker must be on the same network.<br/>
<a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc">https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc</a><br/>
NIST Time Server Problems<br/>
The atomic ensemble time scale at the NIST Boulder campus has failed due to a prolonged utility power outage. One impact is that the Boulder Internet Time Services no longer have an accurate time reference. <br/>
<a href="https://tf.nist.gov/tf-cgi/servers.cgi">https://tf.nist.gov/tf-cgi/servers.cgi</a> <a href="https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I">https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I</a><br/>