-
VMware Cloud Director updates address Code Injection Vulnerability (CVE-2020-3956) – 22nd May 2020
Preface: Don’t underestimate the vulnerabilities discovered in the past, it will cause trouble for your cloud or system. Background: VMware vCloud Director is a management tool for private and hybrid cloud architectures. Top Industries that use VMware vCloud Director are Financial Services, Insurance Program Managers Group, & business technology services provider. Vulnerability details: VMware officially…
-
an issue was discovered in smartbear readyapi soapui pro 3.2.5 (20th May 2020)
Preface: SmartBear ReadyAPI and SoapUI are automated testing tools that you can use to create functional and security tests for web service APIs. The easiest way to run ReadyAPI tests from Azure DevOps is to use the SoapUI Pro for Azure DevOps task. Background: The ReadyAPI platform accelerates functional, security and load testing of RESTful,…
-
Hacker target EU supercomputer – 19th May 2020
Preface: What if your computer is slow? Perhaps it is a sign of malware infection. This scenario also apply to modern supercomputer. Perhaps it is powerful. So no one aware. This is only a assumption. However modern supercomputer will be infected by malware. Why? Because part of the modern supercomputer has deployed a Linux OS…
-
Is it a cyber attack or a design change? (Sunday, May 17, 2020 (EDT))
Preface: High-level state-backed APT groups wreak havoc on cyber world. Does this attack only in short time or it will become a constant activities? Security focus: Information technology professional will relies on DHS (US Homeland security) news update as a standard security alert indicator. For example, I am the follower. Found by tonight that the…
-
Little-Known Linux Exploits is being weaponize – 15th May 2020
Preface: The following information will continue the theme released yesterday. For review the details by yesterday, please follow this link – www.antihackingonline.com/cyber-war/high-level-state-backed-apt-groups-entrenched-in-plenty-of-servers-for-nearly-a-decade-using-little-known-linux-exploits-14th-may-2020/ About the theme: Sound can tell, according to statistic provided by Microsoft. Cyber security attack is rapidly growth especially in education area within past 30 days. Perhaps Healthcare and pharmaceuticals area cyber attack…
-
High-level state-backed APT groups entrenched in plenty of servers for nearly a decade Using Little-Known Linux Exploits – 14th May 2020
Preface: According to statistical data, most organizations store data in cloud platforms operating in Linux based environment. Statistics show that, compared with the Windows operating system, Linux coverage rate exceeds 75%. Background: Linux system commonly using drive by downloads on an infected website. For instance you install program on Linux sometimes require specify library file…
-
For Malicious Cyber Activity, US Homeland Security provides visibility to the world – 13th May 2020
Preface: It is impossible to rely on small group of expert to track malicious activities on the Internet. In fact, it needs strong financial support. This is reality, maybe this is a long-running game. Background: US Homeland Security issue an evaluation article on hostile country malware and phishing attacks motion. Perhaps you may ask? Can…
-
Remedy on CVE-2020 -11651, CVE-2020 -11652 VMware vRealize Operations Manager addresses Authentication Bypass and Directory Traversal vulnerabilities – 12th May 2020
Preface: If application do not defenses against directory traversal attacks, so an attacker can request the following URL: hxxp://xxx[.]com/loadImage?filename=../../../etc/passwd Vulnerability details: The VMware Application Remote Collector (ARC) introduced with vRealize Operations Manager 7.5 can integrate with Salt (SaltStack). However the vulnerabilities (CVE-2020-11651 and CVE-2020-11652) found in saltstack this month will be impact VMware operation simultaneously.…
-
From imagination point of view – The assembly process of Coronvirus kill chian – 10th May 2020
Preface: The pandemic virus has killed about 211,000 people. Is it an artificial product or created by nature? My story can tell: Population growth, it is hard to avoid has a cold. The symptom causes cough & sneeze.However the main problem is the sputum. Perhaps we are the living in modern civilization. However the spit…
-
Discarded Tesla car parts contain information. Maybe you can buy it on eBay. Who can believe in the technological world? Even if no such incident occurs, the supplier can read your local data without your consent (8th May 2020)
Preface: The traditional method of disposing of hard drives is degaussing or incineration. Headline News: The manufacturer has a hardware disposal policy. The incidents encountered by Tesla may be due to improper handling of third parties. For more information about headline news, please refer to this link. https://www.hackread.com/user-data-found-in-tesla-car-parts-ebay/ Supplement: Should you have doubt about your…