-
Microsoft October 2018 Security Updates (9th Oct 2018)
When my dreams end, as dream always do. Seems cyber technology world similar. Microsoft Patch Tuesday just released. It lure my interest of Microsoft Exchange Server design limitation. The Microsoft Foundation Class Library design weakness may let Microsfot headache. As a matter of fact, C and C++ programming products encountered overflow attack so far.…
-
Could ring 2 have the same momentum as a IoT backdoor?
Preface: In x86 protected mode, the CPU is always in one of 4 rings. The Linux kernel only uses 0 and 3: 0 for kernel 3 for users Hidden janitor living in your computer SMM is triggered through a System Management Interrupt (SMI), a signal sent from the chipset to the CPU. During platform initialization,…
-
About cyber security threats in aero industry – Oct 2018
DHS has few critical cyber security announcement few days ago. Some technical articles may bring the practitioner attentions. Do you read technical article “Threats to Precision Agriculture” yet? My personal opinion is that the prediction of cyber attack scenario not only happen in agriculture. It may have happen in aero industry. Real-time kinematic (RTK) positioning…
-
VMware has released a security update to address a vulnerability in AirWatch Console – 5thOct2018
From security point of view, it is not recommend deploy single sign-on authentication. A single user ID with single password manage multiple system increase the risk in proportion . Perhaps this factor ignore by modern business world. And therefore SAML single sign on is popular today. VMware has released a security update to address a…
-
Apache Tomcat Fans please staying alert! – 4th Oct 2018
A vulnerability occurs in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33, and 7.0.23 to 7.0.90. Exploit this vulnerability to obtain sensitive information. For more detail, please refer to attached diagram. Official URL shown as below: http://mail-archives.us.apache.org/mod_mbox/www-announce/201810.mbox/%3C4cf697b0-db03-9eab-f2aa-54c2026d0e88@apache.org%3E
-
3rd Oct 2018 – Do you think they are APT 38?
The cyber attack hot topic we focus retail payment system (Fastcash campaign) and adobe product vulnerabilities this week. However an additional cyber security alert announced by DHS. Yes, it is a APT cyber attack activities. APT processes require a high degree of covertness over a long period of time. If you habit to observe the…
-
Your doctor (Cisco) is going to provides a nursing this week – 3rd Oct 2018
Your doctor is going to provides a nursing this week. Since vendor only provided high-level overview of vulnerability. But believe that the weakness given by REST-API. Critical CVE-2018-15386 Cisco Digital Network Architecture Center Unauthenticated Access Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-dna-unauth-access Critical CVE-2018-0448 Cisco Digital Network Architecture Center Authentication Bypass Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-dna-auth-bypass Additional 1: Critical CVE-2018-15379 Cisco Prime Infrastructure…
-
Vulnerabilities causes attacker take control of an affected system – Firefox & Firefox ESR Oct 2018
Firefox 62.0.3 and Firefox ESR 60.2.2 user require attention! System vulnerability never stop and keep running in cyber world. Sometimes you feel frustrated and may give up! As a modern people, no way ! So the only way is follow to do so! People say human can control computer systen. But now vulnerabilities control business,…
-
2nd Oct 2018 – Homeland security alert (Retail payment system security advisory)
US Homeland security urge banking industry especially payment gateway services provider staying alert of new round of malicious cyber attack of their system. Similar of cyber attack was happened in Taiwan. The heist draw the cash equal to $2.6m (£2.1m). Homeland security reveal how the technique let ATM machine like human vomiting. But this is…
-
Honeywell Mobile Computers with Android Operating Systems – CVE-2018-14825
Port of Barcelona and Port of San Diego suffers cyber attack on September 2018. The San Diego port indicated the ransomware attack is mainly an administrative problem and the port is open and operating as usual. Cyber attacker conducting cyber attack to logistic industry not new. Honeywell one of the Industrial Control Systems leading manufacturer.…