Month: January 2019

  • 9th Jan 2019 – Security Focus (Juniper Networks)

    Preface: Historically, telecommunications companies have been the largest customer segment for Juniper. Juniper has provided them with on-premises hardware — routers and switches — for the purpose. Background of XML C parser: Libxml2 is the XML C parser and toolkit developed for the Gnome project. Libxml2 is made of multiple components; some of them are…

  • Cisco Releases Security Updates Published Wednesday, January 9, 2019

    Preface: Crimes that use computer networks or devices to advance other ends includes Phishing scams and Spam. S/MIME technical background: S/MIME is based on asymmetric cryptography to protect your emails from unwanted access. It also allows you to digitally sign your emails to verify you as the legitimate sender of the message, making it an…

  • Apple IntelHD5000 Graphics Process Token Privilege Escalation Vulnerability – CVE-2018-4421

    Preface: A third of people have a virus on their device from porn, said Dailymail.co.uk Description: If you like watch the adult movie online and you are Mac book air user. Please staying alert! Hacker Jeopardize your Mac Book Air by Adult movie. Impact: An application may be able to execute arbitrary code with kernel…

  • Microsoft Patch Tue – Security Focus CVE 2019-0556 | Microsoft Office SharePoint XSS vulnerability

    Preface: SharePoint is unquestionably one of the best and most significant enterprise productivity tools for user. It similar OneDrive for Business and Apps functions. Vulnerability found on SharePoint – 2019 Jan CVE 2019-0556 | Microsoft Office SharePoint XSS vulnerability The attacks could allow the attacker to read content that the attacker is not authorized to…

  • CVE-2018-17195 – Apache NiFi Template Upload API Endpoint Cross-Site Request Forgery Vulnerability

    Preface: What Is Big Data and Why Do We Need It? A complex reason of this question. In short sentence to describe, business and human being looking for operational efficiency to improve the daily life. Technical background of Apache NiFi: Apache NiFi can help you get your S3 data storage into proper shape for analytic…

  • Vulnerability in Java Deserialization Affecting Cisco Products – 2019 Jan

    Cause: A vulnerability in the Java deserialization used by the Apache Commons Collections (ACC) library could allow an unauthenticated, remote attacker to execute arbitrary code. Remark: Researchers have found complex object graphs which, when deserialized, can lead to remote code execution in most Java software. Official announcement:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-java-deserialization

  • Apocalypse – Is that the correct way? But this is the destiny!

    Preface: The 2012 phenomenon was a range of eschatological beliefs that cataclysmic or otherwise transformative events would occur on or around 21 December 2012. In the moment: We are still alive, but climate in the earth running in irregular way. Changes in the amount of sea ice can disrupt normal ocean circulation, thereby leading to…

  • Exploitation of vulnerability transform to APT (Advanced Persistent threat) facility

    Preface: On 4th Jan 2019 CERT/CC Reports Critical Vulnerabilities in Microsoft Windows, Server… Report details: The report recall vulnerabilities found on 13th Dec 2018 (see below): CVE-2018-8626 Windows DNS Server Heap Overflow Vulnerability – https://www.kb.cert.org/vuls/id/531281/ CVE-2018-8611 Windows Kernel Elevation of Privilege Vulnerability – https://www.kb.cert.org/vuls/id/289907/ But vulnerability (CVE-2018-8611) successfully bypasses modern process mitigation policies, such as…

  • 2019 headline news – a data breach may impact nearly 2.4 million Blur users

    Preface: Data breaches continue to be a threat to consumers. Many companies were hacked and likely had information stolen from them since January 2017. Headline news Jan 2019:  Abine announced that they learned on 13th December 2018 that a file containing information from customers who had registered prior to January 2016 was exposed online. Who…

  • Security Bulletin for Adobe Acrobat and Reader | APSB19-02

    An attacker could exploit these vulnerabilities to take control of an affected system. Reminder: It is hard to avoid system administrator read the pdf format of document during installation. If such vulnerability occur, it is very dangerous! Official announcement: https://helpx.adobe.com/security/products/acrobat/apsb19-02.html