-
Consider how does JQuery affect millions of people confidential data – Sep 2018
RiskIQ expose one of the possible way how hacker steal customer credit card data of British Airline. Expert speculate the suspects exploit Inject jQuery into a page technique collect the confidential data. BA claim that the data breach only occurs in credit card data. Risk IQ share the proof of concept shown that the technique…
-
Adobe has released security updates to address vulnerabilities in Adobe Flash Player and ColdFusion – Sep 2018
Adobe revealed that the Flash end of life will take place at the end of 2020. So we still can be use the flash. Perhaps computer products includes software and hardware.The key word vulnerability similar human not feeling well (sick) then receive medication. The patient will get well. So vulnerability occurs in cyber world do…
-
Docker for Windows design weakness – without verifying the validity of the object – CVE-2018-15514
Docker brings several new things to the table that the earlier technologies didn’t. It capable to all platform. It equivalent a multiple adapter. It is hard to avoid vulnerability happen on software and hardware. Docker no exception. The specific vulnerability found on Aug 2018. For more details, please see below: Docker for Windows Edge Release…
-
Security Notification – Modicon M221 (Sep 2018)
Because many industries requires monitoring and control capabilities that SCADA offers. In most uses, SCADA is used to manage a physical process of Electric, Gas and water Utilities.We heard cyber security alert in SCADA facilities so far. As a citizen we cannot immagine how worst will be the incident happened. For instance once SCADA PLC…
-
6th Sep 2018 – AirWatch Agent and VMware Content Locker updates resolve data protection vulnerabilities
The development of the cyber security mechanism involves preventive and corrective control. Security experts alert IT world that a unforseen cyber security loophole will be occurs when the poplarity of smartphone growth. Perhaps mobile device management (MDM) establish a way to rescue the enterprise firm business operation in demand of the usage of mobile phone…
-
British Airway announcement – 7th Sep 2018 (380,000 customers’ bank details stolen from website)
The Spokesman of British Airways said around 380,000 payment cards had been compromised and it had notified the police.He stated that they suspected that hacker stolen customers’ bank details through official website and or mobile apps. However the stolen data didn’t include travel or passport details. If there is european citizens become a victims of…
-
Cisco Releases Security Updates on 5th Sep 2018 – Staying alert!
Vendor would like to bring below problems to your attention. Apache Struts Remote Code Execution Vulnerability Affecting Cisco Products: August 2018 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180823-apache-struts Cisco Umbrella API Unauthorized Access Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-umbrella-api Cisco RV110W, RV130W, and RV215W Routers Management Interface Buffer Overflow Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-rv-routers-overflow
-
Automatic DNS registration and autodiscovery boots up cyber attacks – Sep 2018
Have a look back of the LLMNR technical feature, NetBIOS and Link-Local Multicast Name Resolution (LLMNR) are Microsoft’s name resolution protocols for workgroups and domains designed primarily for name resolution in the LAN. When DNS resolution fails, Windows systems use NetBIOS and LLMNR to search for names. These protocols are designed only for local connections.…
-
Amazon Web Services (AWS) CLI weak security – CVE-2018-15869
The amazon-ebs Packer builder is able to create Amazon AMIs backed by EBS volumes for use in EC2. Found design weakness on Amazon Web Services (AWS) that CLI could provide weaker than expected security, caused by the failure to require the –owners flag when describing images. By setting similar image properties, a remote attacker could…
-
Node JS CVE – Aug 2018
Retropective of the programming history, JavaScript was used primarily for client-side scripting, in which scripts written in JavaScript are embedded in a webpage’s HTML and run client-side by a JavaScript engine in the user’s web browser. Node js programming technique lets developers use JavaScript to write command line tools thus transfer script programming function to…