-
CVE-2021-22941 – May be it is not related, or else was getting the User Enumeration incident waiting to happen (17-09-2021)
Preface: With storage zones controllers, the ShareFile Software-as-a-Service (SaaS) cloud storage also offers private storage for ShareFile data, which is known as storage zones. What is the difference between Dropbox and ShareFile?The goal of ShareFile is to help your team easily share, sync and store large files from any device without compromising important data. And…
-
IS there any related security matter of session (CVE-2021-37535)?
Preface: Did you check your JMS Security Authorization, fix your JMS application immediately. Background: The basic building blocks of a JMS application are: Administered objects: connection factories and destinations Connections Sessions Message producers Message consumers Messages The JMS Connector Service is an enterprise messaging system that provides a way for business applications to exchange datawithout…
-
Forcedentry vulnerability break through iPhone steel door 13th Sep 2021
Preface: These aren’t objects in the “ object-oriented programming” sense of the word; instead, they are the building blocks on which PDF stands. There are nine types of objects: null, Boolean, integer, real, name, string, array, dictionary, and stream. Background: The Pegasus spy program created by NSO uses a zero-day vulnerability in Apple’s operating system…
-
Unkown backdoor run on TCP 7614, virtual patching is one of the protective control methods (12th Sep, 2021)
Preface: Virtual patching acts as a safety measure against threats that exploit known and unknown vulnerabilities. Virtual patching works by implementing layers of security policies and rules that prevent and intercept an exploit from taking network paths to and from a vulnerability. Background: This is so called Evasion Techniques. One of the first techniques that…
-
Security Focus, CVE-2021-28701 on Citrix Hypervisor (9th Sep, 2021)
Preface: You can use Citrix Hypervisor in an unlicensed state. However, you do not have access to some features. To access Citrix hypervisor is easy, go through XenCenter then input user ID and password. Background: Citrix Hypervisor is a high-performance hypervisor optimized for virtual app and desktop workloads and based on the Xen Project hypervisor.…
-
OpenStack Neutron (CVE-2021-40797) – 8th Sep, 2021
Preface: OpenStack Neutron is an SDN networking project focused on delivering networking-as-a-service (NaaS) in virtual compute environments. Neutron has replaced the original networking application program interface (API), called Quantum, in OpenStack. Background: The Web Server Gateway Interface (WSGI) is a simple calling convention for web servers to forward requests to web applications or frameworks written…
-
U.S. Homeland Security Alert (CVE-2021-40444) – 7th Sep, 2021
Preface: Windows RCE vulnerabilities have targeted Office users, and Microsoft urgently provides mitigation instructions. Background: The MS web browser COM control adds browsing, document, viewing, and downloading capabilities to your applications. Parsing and rendering of HTML documents in the WebBrowser control is handled by the MSHTML component which is an Active Document Dynamic HTML (DHTML)…
-
Fortinet’s CVE makes you have questions? How many unknown vulnerabilities remain undiscovered in the REST API framework!(CVE-2021-2400 – 6th Sep 2021)
Preface: Dashboard, a popular design trend concept in the digital world.Dashboard, a popular design trend concept in the digital world.As the cloud and the Internet of Things force the network to evolve. Even operational work and network security can be managed in thesame dashboard. Background: Permission checks will typically use the authentication information in the…
-
Interested topic last week (AWS “AKIA” discussion) – 5th Sep, 2021
Preface: On 2014, Amazon Web Services (AWS) is asking those that write code and use GitHub to go back and check their work to make sure they didn’t forget to remove login credentials. The warning comes as news is circulating about the availability of nearly 10,000 AWS keys in plain sight on GitHub just by…
-
CVE-2020-13929: Apache Zeppelin: Notebook permissions bypass (2nd Sep, 2021)
Preface: Big data analysis can understand data by discovering trends and patterns. Machine learning can accelerate this process with the help of decision-making algorithms. It can classify incoming data, recognize patterns, and transform the data to do the technology development. In addition, it is a way to develop artificial intelligence. Background: What is Apache Zeppelin…