Author: admin

  • SWIFT Customer Security Controls Framework

      Preface: All SWIFT users must comply with the mandatory security controls by the end of 2018. Objective: Introduction of new controls or guidelines will take account of strong cybersecurity practices that address the currently known new and arising threats in order to pragmatically raise the security bar. Technical details: Mandatory Security Controls 1. Restrict…

  • Security Focus (Microsoft Edge) – Critical vulnerabilities fixed in November 2018 Patch Tuesday

    Preface: Chakra is a JavaScript engine developed by Microsoft for its Microsoft Edge web browser. It is a fork of the JScript engine used in Internet Explorer. Description: The technical details issued by patch Tuesday not describe explicitly (see below). A remote code execution vulnerability exists in the way that the Chakra scripting engine handles…

  • Adobe Releases Security Updates – 13th Nov 2018

    Preface: Integrated Windows Authentication utilizes Negotiate/Kerberos or NTLM to authenticate users based on an encrypted ticket/message passed between a browser and a server. This is the standard authentication algorithm for Microsoft products. Design weakness: Hacker steal the NTLM Credentials via PDF Files. They exploit NTLM hash leaks stealing a Windows user’s NTLM hashes. Official announcement:…

  • Node.js third-party modules vulnerability – Nov 2018

    Preface: Node.js is an open source, cross-platform built on Chrome’s JavaScript runtime for fast and scalable server-side and networking applications. Known technical concerns: Node.js has a set of built-in modules which you can use without any further installation. In order to enhance the function and effectiveness, the 3rd party modules are available to operate with…

  • Security Updates for SIPROTEC and SICAM Products (Oct 2018)

    Preface: SIPROTEC and SICAM – Siemens products and solutions for protection engineering, station automation, power quality, and measurement – can be connected directly and easily to MindSphere and other cloud-based platforms. What is MindSphere? MindSphere is an open cloud platform or “IoT operating system” developed by Siemens for applications in the context of the Internet…

  • What is the situation of Edward Snowden (whistle blower)? Do you still remember him?

    Preface: The samurai (or bushi) were the warriors of premodern Japan.Lone Wolf and Cub is a manga created by Japanese comics writer.Samurai respected justice. Synopsis: Justice is the legal or philosophical theory by which fairness is administered. It is the fundamental of human nature. But the concept of justice differs in every countries and culture.…

  • VMware Releases Security Updates – November 09, 2018

    Subject: VMware ESXi, Workstation, and Fusion updates address uninitialized stack memory usage Technical background: VMXNET3 (VMXNET Generation 3) is a virtual network adapter designed to deliver high performance in virtual machines (VMs) running on the VMware vSphere platform. How to enable it? 1. Power off your Virtual Appliance in the VMWare Console. 2. Right click…

  • Does CUJO IoT firewall will be affected by U-Boot vulnerabilities? Nov 2018

    Preface: CUJO is the most adorable home firewall on the Market. Meanwhile if a threat is detected, CUJO smart firewall will tell the cloud what it has blocked so you can receive a notification on your mobile app to confirm it. Technical background: Cujo product working with U-boot. U-Boot is the bootloader. Meanwhile, it provides…

  • Cisco Releases Security Updates – November 07, 2018

    Cisco Releases Security Updates – November 07, 2018 Cisco Stealthwatch Management Console Authentication Bypass Vulnerability – https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-smc-auth-bypass Cisco Small Business Switches Privileged Access Vulnerability – https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-sbsw-privacc Cisco Unity Express Arbitrary Command Execution Vulnerability –  https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cue Cisco Meraki Local Status Page Privilege Escalation Vulnerability –  https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-meraki?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Meraki%20Local%20Status%20Page%20Privilege%20Escalation%20Vulnerability&vs_k=1

  • Self-Encrypting Solid-State Drive Vulnerabilities – November 06, 2018

    Preface: Retrospective last decade, the key word so called vulnerability look like a stranger to us. But it change today. Design vulnerability, it was no doubt to say. They are the belongings of cost effective solution, market competition (short development life cycle) and satisfy human want. Design technique – Wear leveling (also written as wear…