-
Security Focus – April 2020 (Oracle security alert – cve-2020-2959)
Preface: Perhaps you have similar feeling, everytime when you read the cyber security announcement by Oracle. The first impression is that it has too many. Read into details, some items let you know the remediation process is in long run! Vulnerability detail: An unspecified vulnerability in the Analystics Web General component of Oracle BI Published.…
-
Security Focus – intel modular server (mfs2600kispp) vulnerability – 14th Apr 2020
Preface: The Global Data Center Blade Server market is projected to grow at a CAGR of 8.35% during the forecast period, reaching a total market size of US$23.535 billion in 2025 from US$14.548 billion in 2019, said ResearchAndMarkets.com’s. Vulnerability details: • authenticated attackers to potentially enable escalation of privilege via local access due to improper buffer…
-
To infinity…and beyond! VMware vCenter Server updates address sensitive information disclosure vulnerability in the VMware Directory Service – CVE-2020-3952
Preface: VMware announce that the external Platform Services Controller architecture is deprecated and will not be available in future releases. Background: Authentication and certificate management is handled by the Platform Services Controller. See attached diagram, the platform services controller original design place in a standalone box. It is advice to put together ( a vCenter…
-
Security Focus – Juniper Networks (9th April 2020)
Preface: Technology cannot fight against coronavirus in the moment.Easter, commemorating the resurrection of Jesus from the dead.Wish that human can managed to fight it all. Comparing with coronavirus. The vulnerability in computer system looks easy resolve. Security focus – Juniper Network product: A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual…
-
CVE-2020-10808 Vesta Control Panel Authenticated Remote Code Execution 6th April 2020
Preface: Dockerized Vesta Control Panel aka vestacp. You can download vesta source code and modify it the way you want. You are totally free to do it so to Vesta is licensed under GPL Background: You are able to install and configure VestaCP on an Alibaba Cloud Elastic Compute Service (ECS) instance with CentOS 7…
-
Do you worry your camera on your iphone manipulate by hacker. 6th Apr 2020
Preface: Apple paid $75,000 to the hacker for reporting the camera hijacking bugs. As said, bug is never ending. Perhaps next round will be yours. Background: If you let your friend access your phone for 5–7 minutes, they could have downloaded spyware. Perhaps this action only for joking. As a matter of fact, hacker can…
-
Staying alert! – Mozilla Patches Critical Vulnerabilities in Firefox, Firefox ESR (3rd Apr 2020)
Preface: According on 2020 market statistic, FireFox market share only 9.25%. But Chrome has 68.11% coverage. However I like FireFox. How Firefox’s memory allocator works? Firefox uses a memory allocator called moz jemalloc. There are two properties which focus by cyber security expert so far! [PSJ] – In essence, a chunk is broken into several…
-
Why US Homeland security urge to public stay alert of the vulnerability on DrayTek Devices? 3rd April 2020
Preface: A conspiracy was leaked this week, someone ambitious to spying the world. Details: The espionage activities will be exploit computer technology as 1st approach in today. It is merely relies on design weakness. Yes, it is the vulnerability. When I read the conspiracy details, I was wonder that if the formulation of this design…
-
Marriott says 5.2 million guest records were stolen in another data breach, said Marriott. 31st Mar 2020
Preface: Perhaps this is not the key factor causes data breach on Jan 2020. But the sound can tell. Observation: It is believed that a new round of data breaches by Marriott this week has attracted attention. Maybe the hotel industry will run within 24 hours. Do maintenance or system upgrade is not easy. We…
-
Kwampirs Targeted Attacks Involving Healthcare Sector – (31st Mar 2020)
Preface: Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015. Synopsis: Why does Kwampirs fall into the “Advanced Persistent Threat (APT)” category? For tradition malware “click and action” attacks. APT attack not condct the similar action. Instead, APT merely do the…