-
CVE-2021-41135 Cosmos-SDK up to 0.44.1 xauthz Module ValidateBasic unusual condition (21st Oct, 2021)
Preface:To date, more than 240 applications have been built on the Cosmos mainnet. The main categories of applications include finance, infrastructure, privacy, and social interactions. Background: The Cosmos SDK is a framework for building blockchain applications. Tendermint Core (BFT Consensus) and the Cosmos SDK are written in the Golang programming language. Cosmos SDK is used…
-
Security focus: Oracle Critical Patch Update Advisory (October 2021)
Preface: The design weakness was disclosed by the apache organization on January 14, 2021. Design limitations on Xmlbeans have been fixed. Developer suggest to use 3.0.1, instead of Xmlbeans 2.6.0. Background: PS/nVision – a PeopleTools software that you use to design and create Microsoft Excel spreadsheet reports for PeopleSoft data. nVision selects data from your…
-
BlackMatter Ransomware – Stay Alert (18th Oct, 2021)
Preface: Ransomware common deploying malicious actions is the automatically propagation. Their target will be included ADMIN$, C$, SYSVOL, and NETLOGON default setup. Common infection technique: Believe it or not, quite a lot of ransomware developers will use simple technique.Deploy encryptors across the environment using Windows batch files (mount C$ shares, copy the encryptor, and executed…
-
ClearPass Policy Manager Multiple Vulnerabilities. Does your infrastructure fall into this design weakness? (18-10-2021)
Preface: Sometimes, a low to medium risk rating vulnerability will be transformed into potential risk. Background: Aruba’s ClearPass Policy Manager, part of the Aruba 360 Secure Fabric, provides role- and device-based secure network access control for IoT, BYOD & corporate devices. The ClearPass Policy Manager is the only policy solution that centrally enforces all aspects…
-
Old defects, new records – CVE-2021-42340 (14th Oct, 2021)
Preface: A Java EE server is a server application that the implements the Java EE platform APIs and provides the standard Java EE services. Java EE servers are sometimes called application servers, because they allow you to serve application data to clients, much like web servers serve web pages to web browsers. Background: The difference…
-
Apple released security update (11th Oct, 2021)
Preface: For our customers’ protection, Apple doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Background: The assert macro performs a runtime check of the given condition. For example: When a buffer maximum is 8, where the value of i is less that 8 the assert…
-
Above CVE-2021-42252 (11th October, 2021)
Preface: Linux mainly uses a paging mechanism to achieve virtual memory management. The size of the memory page is PAGE_SIZE bytes instead of 4 KB. On different platforms, the page size can range from 4 KB to 64 KB. Background: The Aspeed BMC family which is what is used on OpenPOWER machines and a number…
-
Stay alert: Recently, an unknown trojan attack in the Linux environment, a malicious ELF file with UPX compression (11th Oct, 2021)
Preface: Antivirus software isn’t entirely useless on Linux. If you are running a Linux-based file server or mail server, you will probably need antivirus help. Background: ELF file extension, an acronym for Executable and Linkable Format, is a common standard file extension used for executable, object code, core dumps and shared libraries. It was being…
-
About Apache HTTP Server 2.4.49 and 2.4.50 – CISA urges organizations to patch immediately if they haven’t already (7th Oct 2021)
Preface: the most famous UTF-8 attack was against unpatched web server. Background: The most common users of Apache HTTP Server are from Small Businesses and the Information Technology & Services industry. Perhaps How to Check the Apache Version? Open terminal application on your Linux, Windows/WSL or macOS desktop. Login to remote server using the ssh…
-
If your IoT development is based on Zigbee,perhaps Zephyr CVE will bring to your consideration. (6th Oct 2021)
Preface: Ensure that the JSON parser does not try to write a potentially unlimited number of elements into a C array of a fixed size. Background: Zephyr is a small real-time operating system (RTOS) for connected, resource-constrained and embedded devices (with an emphasis on microcontrollers) supporting multiple architectures and released under the Apache License 2.0.…