-
machine learning vulnerability – vu#425163 (4th Jun 2020)
Preface: Artificial Intelligence applied machine learning and other techniques to solve problems. Will AI impact human? Background: You can use the Machine Learning model to get predictions on new data for which you do not know the target. For instance, AWS developing AI technology to predict cyber attack especially email spam, email phishing , etc.…
-
US homeland security alert – unpatched MS system vulnerability to cve-2020-0796 (5th Jun 2020)
Preface: Microsoft has released a security advisory to address a remote code execution vulnerability (CVE-2020-0796) in Microsoft Server Message Block 3.1.1 (SMBv3) on 11th Mar 2020. Synopsis: The proof of concept code vulnerability has been made public. Attacker do the exploit is that send a specially crafted packet to a targeted SMBv3 server. (refer to…
-
if not require to use, it is better turn off bluetooth function before your hardware vendor patch – 26th May 2020
Preface: Bluetooth enabled consumer electronics such as mobile phones, cameras simplify data sharing between devices. For instance, smartphone can wirelessly connect to a headset to make hands-free calling easier or can send pictures to another. Background: The Bluetooth market has changed dramatically in the past three to four years. Perhaps is the potential power of…
-
do you know the weaknesses of IP-in-IP design? 2nd jun 2020.
Background: IPIP tunnel is typically used to connect two internal IPv4 subnets through public IPv4 internet. It has the lowest overhead but can only transmit IPv4 unicast traffic. Vulnerability details: The vulnerability is due to the affected device unexpectedly decapsulating and processing IP in IP packets that are destined to a locally configured IP address.…
-
data breach spread to banking enterprise. no exception to bank of America – 28th may 2020.
Background: The PPP provides small businesses with forgivable loans of up to $10 million per company (8 weeks of payroll). This program was launched on April 3, 2020; it is a forgivable loan program offered primarily to help businesses deal with the adverse consequences COVID- 19. Point of view: Cybercrooks have been leveraging malicious macros…
-
weekly security focus – memory leak vulnerability in vmci module (cve-2020-3959)
Preface: TCP / IP design restrictions have introduced security vulnerabilities to transport protocols. Security focus: Memory leak vulnerability in VMCI module (CVE-2020-3959) – VMware ESXi, Workstation and Fusion contain a memory leak vulnerability in the VMCI module. It lets local non-administrative user send a malformed packet to a virtual machine. Such action may be able…
-
NSA preemptive curb threats factor – an exploitation of exim design weakness – 29th May 2020
Preface: The severity depends on your configuration, said vendor. It depends on how close to the standard configuration your Exim runtime configuration is. Jun 2019 Headline news on 28th May 2020 – The National Security Agency (NSA) has released a cybersecurity advisory on Russian advanced persistent threat (APT) group Sandworm exploiting a vulnerability—CVE-2019-10149—in Exim Mail…
-
Critical Android bug 8,8.1 and 9 (CVE-2020-0096) – 27th May 2020
Preface: As of April 2020, 37.4% of Android devices run Pie, making it the most popular Android version. Vulnerability details: A critical vulnerability on Android causes privilege-escalation The impact is that it allows attackers to hijack any app on an infected phone, it is much more difficult to detect, the name so called StrandHogg 2.0.…
-
Ebayer, are you aware someone behind you? 25th may 2020
Preface: Host discovery function embedded detection and vulnerability scan service. Under normal circumstances, since you are on a private network, there is no objection in this setting. Synopsis: When visiting the eBay, a script will run that performs a local port scan of your computer to detect remote support and remote access applications, said bleeping…
-
Security focus – Bind vulnerability (CVE-2020-8616) – 20th May 2020
Preface: BIND is open source software that enables you to publish your Domain Name System (DNS) information on the Internet, and to resolve DNS queries for your users. About traditional DNS attack: An example of a DoS attack is the SYNflood, which uses a the TCP SYN packet to create half open TCP connections on…