-
If your querying and updating RDF models using the SPARQL standards, please aware of this design weakness. (5th JUl 2021)
Preface: Artificial intelligence (AI) has the potential to overcome the physical limitations of capital and labor and open up new sources of value and growth. Background: Apache Jena is a free and open source Java framework for building semantic web and Linked Data applications. The framework is composed of different APIs interacting together to process…
-
Are there other ways to avoid ransomware infection? (6th Jul, 2021)
Preface: A ransomware attack paralyzed the networks of at least 200 U.S. companies, said headline News. President Biden announces investigation into international ransomware attack on 3rd Jul, 2021. Background analysis: Cyber criminals are turning to fileless attacks to bypass firewalls. These attacks embed malicious code in scripts or load it into memory without writing to…
-
The Thirty-six stratagems – Know yourself and the ransomware, never lost in cyber war. 30-06-2021
Preface: The Thirty-six stratagems is a Chinese essay use to illustrate a series of stratagems used in war. It also applies to cyber warfare. Background: Kernel-based Virtual Machine (KVM) is an open source virtualization technology built into Linux®. Specifically, KVM lets you turn Linux into a hypervisor that allows a host machine to run multiple,…
-
Who makes supercomputers faster and faster (CPU, fibre interconnect, parallel processing or virtual machine)? 29th June, 2021.
Preface: In Japanese mythology, the Namazu (鯰) or Ōnamazu (大鯰) is a giant underground catfish who causes earthquakes. This giant not caused disaster, he is the fastest supercomputer in the world. His name is FUGAKU. Background: Riken and Fujitsu started developing the system in 2014, working closely with ARM to design the A64FX processor. Each…
-
Similar or not relevant – QEMU: net: eepro100: stack overflow via infinite recursion (27-06-2021)
Preface: Similar vulnerability with another CVE record was announced on Feb 2021. Perhaps Citrix waiting for other vendor response and confirmation . Whereby, supculated that this is one of the possible factor of the announcement by the Citrix on Friday (25th June, 2021). Background: How is memory allocated when recursive functions are called? Calling a…
-
Security Focus – About the CVE-2021-21999 VMware vulnerability (23rd June 2021)
Preface: An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl[.]cnf’ in an unrestricted directory which would allow code to be executed with elevated privileges,” VMware said. Background: VMware App Volumes provides a system to deliver applications to desktops through virtual disks. Installing App…
-
Authorization bypass in Cortex XSOAR (palo alto networks) REST API – CVE-2021-3044
Preface: REST API has similar vulnerabilities as a web application. The possibilities will be from various threats, such as Man-in-the-Middle attacks, lack of XML encryptions, insecure endpoints, API URL parameters, ..etc. Technical background: Cortex XSOAR is the Security Orchestration, Automation and Response (SOAR) solution from Palo AltoNetworks. Cortex XSOAR (formerly Demisto) is able to configuration…
-
CVE-2021-32994 – OPC UA C++ SDK is vulnerable to a denial of service 17th June, 2021
-
Digital world situation similar ambush from all sides. Chrome Releases updates (CVE-2021-30554) – 17th June 2021.
Preface: The new Edge and Chrome are very similar, as both are built on the same Chromium platform. Meanwhile, Microsoft Edge is based on the Chromium open-source project. Furthermore, when chrome has vulnerability occurs, perhaps Microsoft browser (edge) will be get involves. Background: WebGL enables web content to use an API based on OpenGL ES…
-
Reduce e-waste and achieve environmental protection: outdated iphone models – Security updates (14-06-2021)
Preface: To protect the safety of customers, Apple will not disclose, discuss or confirm security issues until the investigation is completed and patches or updated versions are provided. My observations on CVE-2021-30737: Background: PKINIT is a preauthentication mechanism for Kerberos 5 which uses X.509 certificates to authenticate the KDC to clients and vice versa.PKINIT requires…