-
VMware Releases Security Updates (CVE-2021-21985 & CVE-2021-21986) – May 26, 2021
Preface: There are plenty of astronomical events every year.In the evenings of 26 May 2021, it was total lunar eclipse. Do you believe rumours of super moon (astronomical phenomenon)? Background: Virtual SAN Health check plugin checks all aspects of a Virtual SAN configuration. It implements a number of checks on hardware compatibility, networking configuration and…
-
The Chronicle of Ransomware – 26th May 2021
Preface: The first ever ransomware virus was created in 1989 by Harvard-trained evolutionary biologist Joseph L. Popp (now known as the ‘father of ransomware’). It was called the AIDS Trojan, also known as the PC Cyborg. Synopsis: Perhaps mankind cannot imagine that in our modern world. We still impact by viral infection. The situation looks…
-
Aforementioned – Insurance company infected by ransomware – 25th May 2021
News feed: AXA Group announced on Sunday (16-05-2021) that the company has become a victim of a ransomware attack. Axa Hong Kong said there has been no evidence that data processed by Inter Partners Asia in markets other than Thailand have been affected by the targeted ransomware attack. No official announcement till today to update…
-
Exposes ring 0 code execution in the context of the driver, defense software perhaps will encounter this mistake (CVE-2021-31728 MalwareFox AntiMalware)
24th May, 2021 Preface: It let you avoid malware infection in your computer. MalwareFox can detect and remove malware in precise way. MalwareFox Antimalware at low cost comparing to other competitors. Background: In a computer, ioctl is a system call dedicated to the input and output operations of the device. The call receives a request…
-
Update to CISA-FBI Joint Cybersecurity Advisory on DarkSide Ransomware (May 19, 2021).
Preface: Critical infrastructure cybersecurity is not new – it was first addressed by Presidential Decision Directive (PDD) 63 in 1998. The term Internet of Things (IOT) was used but it was for consumer product applications not industrial applications. Perhaps the Executive Order on Cybersecurity does not adequately protect critical infrastructures Background: Best Practices for Preventing…
-
Cyber Security Focus – use a Raspberry Pi for Windows 10 (17th May 2021)
Preface: Windows 10 IoT Core is a version of Windows 10 that is optimized for smaller devices with or without a display, and that runs on the Raspberry Pi 2 and 3. Background: ASP.NET Core is one of the best frameworks available to make cross-platform web applications. The free Windows 10 IoT Core along with…
-
Headline news – Insurer AXA hit by ransomware (17th May 2021)
Preface: Perhaps we think that ransomware only looked at hard drive C. But the truth is that other mapped drives like D:, E:, F will be compromised. Headline News: PARIS (Reuters) – French insurer Axa said on Sunday that one of its businesses in Asia was hit by a ransomware attack, adding that it was…
-
Small storm in Big data world (CVE-2021-22135 & CVE-2021-22136) 13th May 2021
Preface: 3350 companies reportedly use Elasticsearch in their tech stacks, including Uber, Shopify, and Udemy. Background: Organizations can use big data analytics systems and software to make data-driven decisions that can improve business-related outcomes. Elasticsearch is a popular open-source searchand analytics engine for use cases such as log analytics, real-time application monitoring, and click stream…
-
CVE-2021-23134 : Linux – the implementation of nfc sockets contains flaw ! (12th May 2021)
Preface: Near field communication (NFC) technology lets smartphones and other enabled devices communicate with other devices containing a NFC tag. Vulnerability details: Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.2 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local…
-
Citrix Workspace App (CVE-2021-22907) Security Update – 11th May 2021
Preface: The Improper Access Control weakness describes a case where software fails to restrict access to an object properly. Background: Citrix Workspace ensures corporate data is safe and malicious activities are spotted quickly. If the installation is user-based, Citrix Workspace app must be installed for each user who logs on to the local machine. Vulnerability details:…