-
The famous MSS became a victim. Is it attacked by Maze Ransomware (3rd Mar, 2021)
Background: On July last year (2020), Secret Service warned that since MSPs service a large number of organizations at the same timethrough remote administration tools, cyber criminals are specifically targeting MSPs to conduct their attacks at scale to infect multiple companies through the same vector. Incident details: CompuCom began contacting customers to alert them that…
-
Microsoft fixes actively exploited Exchange zero-day bugs attacks (2nd Mar 2021). When service you are not in used, you should disable immediately.
Preface: The Microsoft Exchange Unified Messaging service on the Mailbox server will accept connections from a Client Access server on SIP ports 5062 and 5063. Technical background: Unified Messaging (UM) enables users to use voice mail and other features, including Outlook Voice Access and Call Answering Rules. UM combines voice messaging and email messaging into…
-
CVE-2021-25296 – Nagios XI version xi-5.7.5 is affected by OS command injection. (1st Mar, 2021)
Preface: Vulnerabilities are inevitable! For instance , the injection vulnerability will be managed by detective control. As usually, conducting remediation is the preventive and corrective control. To cope with reality, found and fix concept will be reduce the effectiveness of Defense concept. Zero Trust solution will be applied soon or later especially endpoint environment. Background:…
-
Security Focus: VMware vCenter Server remote code execution vulnerability in vSphere client (CVE-2021-21972) – 24th Feb, 2021
Background: The earlier release of vRealize Operations Manager with vCenter Server was shipped with the NGC plugin. The new vRealize Operations Manager plugin in vCenter Server, provides a mechanism to provide specific metrics and high-level information about data centers, datastores, VMs, and hosts, for the vCenter Server and vSAN. The plugin is supported only in…
-
Design weakness on RPC service awaken your alert! (24th Feb 2021)
Background: Remote Procedure Call (RPC) TCP port 135 is used for client-server communications by Microsoft Message Queuing (MSMQ) as well as other Microsoft Windows/Windows Server software.Allowing unrestricted RPC access on TCP port 135 can increase opportunities for malicious activities such as hacking (backdoor command shell). Recent RCP-related vulnerabilities in software product:CVE-2020-11635: The Zscaler Client Connector…
-
Would it be possible? Malware attack Apple M1 chip? – 21st Feb 2021
Preface: Can M1 chip run Windows? It is unsupported. the M1 decided not to use Boot Camp. Therefore it is not possible running Windows on Macs! Background: So called “System on a Chip”, M1 integrates several different components, including the CPU, GPU, unified memory architecture (RAM), Neural Engine, Secure Enclave, SSD controller, image signal processor,…
-
Have you worry your source code will be stolen by someone else? – – Vulnerability Note VU#240785 (18th Feb 2021)
Preface: Bitbucket’s advantage over GitHub used to be that both Git and Mercurial repository hosting were available with Bitbucket. Background: If you are a Jira user, you can import your existing Git repositories into Bitbucket. Jira Software and Bitbucket does integrate and will work with third party builders like Jenkins. However, the deepest integrations are…
-
CVE-2021-21305 – CarrierWave (18th Feb 2021)
Preface: CarrierWave provides a simple and extremely flexible way to upload files from Ruby applications. Ruby On Rails Companies Websites are popular. It covered all your familiar areas – Airbnb, Groupon, GitHub, Twitter, Zendesk, Bloomberg… Background: CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In…
-
Embedded TCPip stacks memory corruption vulnerabilities, there are plenty of companies current status not confirmed – 16-02-2021
Preface: Embedded TCP/IP stacks have memory corruption vulnerabilities (Vulnerability Note VU#815128) – Siemens, SUSE Linux, iSCSI, FNet, Micrichip Technology, Weinert Automation, Abbott Labs, ….There are plenty of companies current status not confirmed. Background: CERT Coordination Center alert to public on December 2020 that the TCP/IP stacks has memory corruption vulnerabilities. Therefore, this design weakness is…
-
Node-ps package encountered design weakness – CVE-2020-7785 (11th Feb 2021)
Preface: Node.js is an application runtime environment that enables using JavaScript for building server-side applications that have access to the operating system, file system, and everything else to be fully-functional. There are total 8 Top companies that rely on Node.js. Background: Using Node.js allows organizing full stack JavaScript development ensuring the speed and performance of…