-
Japan government is going to conduct penetration to citizen smart home devices. Feb 2019.
Japan is going to execute infiltration to citizens smart home devices. Do you think what is the goal? Whether they are aware of 3rd party (enemy) has been completed a surveillance program in their country or they are avoid to become a botnet victim? CNN Headline News: https://edition.cnn.com/2019/02/01/asia/japan-hacking-cybersecurity-iot-intl/index.html
-
The vulnerability of the Internet of Things 4.0 has attracted the interest of the APT Group in the enemy country.
Preface: Maybe this is a trend! If we are going to the next generation world (IoT 4.0). At the same time, the APT Group is also sniffing the cybersecurity loopholes in that place! Technical background: In business world we understand the function of broker. A similar situation in computer world, we so called gateway vs…
-
UTM (all in one) firewall not in good shape! If you are concern cyber security, please forget so called cost effective solution.
Preface: Dynamic memory automatically reclaimed when the garbage collector no longer sees any live reference to it. Description: A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. Official announcement…
-
A specially crafted username through phpmyadmin can be used to trigger an SQL injection attack through the designer weakness – 30th Jan 2019
Preface: phpMyAdmin is a free software tool written in PHP, intended to handle the administration of MySQL over the Web. Description: Phpmyadmin sometimes similar is a gadget. It can help you reset your WordPress password. It seems to be very useful, but this time the vulnerability is equivalent to the Swiss Army Knife, thus breaking…
-
Microsoft Exchange 2013 and newer are vulnerable to NTLM relay attacks – 28th Jan 2019
Preface: EWS Push Subscription, you will get notifications as long as you respond to the server and acknowledge that you received the notification. The CERT Coordination Center (CERT/CC) announcement – 29th Jan 2019: Microsoft Exchange 2013 and newer are vulnerable to NTLM relay attacks Vulnerability detail: Exchange allows any user to specify a desired URL…
-
Python CVE-2019-5010 Remote Denial of Service Vulnerability – 15th Jan 2019
Preface: Programmer just spend 10 minutes write a python script then can listen UDP traffic. Even though we performing Google Search , the function is using Python code. Information background: Python has now become the most taught programming languages in Universities and Academica. Machine learning or artificial intelligence is learning Python because it is the…
-
CVE-2018-20720 Published: 2019-01-15: Terminal Reboot vulnerability in Relion 630 series version 1.3 and earlier release
Preface: IEC 61850 is an international standard defining communication protocols for intelligent electronic devices at electrical substations. Relion products have been designed to implement IEC 61850 standard. Vulnerability has been recorded to National Vulnerability Database – 15th Jan 2019: ABB Relion 630 series allow remote attackers to cause a denial of service (reboot) via a…
-
CISA Releases Blog on Emergency Directive: January 24, 2019
Preface: Cyber security experts predict that global DNS hijacking activities are underway. However, it is not certain who is the attacker (the cyber attack group), FireEye said on January 9, 2019. Background information: This cybersecurity incident caught the attention of the Network Security and Infrastructure Security Agency (CISA). Whereby, CISA released their first emergency order…
-
CVE-2019-1651 – Cisco SD-WAN Solution Buffer Overflow Vulnerability (23rd Jan 2019)
Preface: Cisco SD-WAN key advantage keen to reducing costs with transport independence across MPLS, 3G/4G LTE, etc. Meanwhile it improving business application performance and increasing agility. Technical background: The vSmart controller is the brains of the centralized control plane for the Viptela system network architecture. The vSmart controller runs as a virtual machine (VM) on…
-
TIBCO Security Advisory: January 16, 2019
Preface: Tycoon wants to invest in a football team. He wants to know which is the good team, how many matches they won in years, the revenue they generate,..etc. Believe that analyzing data solution (TIBCO Spotfire ) can help. TIBCO Spotfire technology Synopsis: Data virtualization time-to-solution is 5‒10X faster than traditional data warehousing and ETL.You…