-
Security advisories – Drupal Releases Security Update (August 02, 2018)
In a nutshell, a CMS function enables anyone to build a website without a prerequisite requirement. The CMS feature similar like anytime ready to run. In a nutshell, a CMS function enables anyone to build a website without a prerequisite requirement. The CMS feature similar like anytime ready to run. The most popular CMS systems nowadays…
-
1st Aug 2018 – Cisco Secuirty Advisory CVE-2018-0391
Cisco Prime Collaboration Provisioning provides a scalable web-based solution to manage your company’s next-generation communication services. CiscoPrimeCollaboration Provisioning manages IPcommunication endpoints and services in an integrated IP telephony, video, voicemail and unified messaging environment that includes Cisco Unified Communications Manager, Cisco Unified Communications Manager Express, Cisco Unity Express, Cisco Unity Connection systems and analog gateways.…
-
Apache OpenWhisk security alert ! Jul 2018
The world is on the way go to robotics automation skeleton. No only the factory, even though software deployment is included. Although you don’t believe this is the prelude. Not a coincidence.But we can’t evade this industries revolution. The artificial intelligence work status depends on what type of issue encounters. The zero day (vulnerability) similar…
-
2018-07-18 – Jenkins Security Advisory
Jenkins is the leading open-source automation server. Built with Java, it provides over 1000 plugins to support automation. Is it a robot? Basically, Jenkins is commonly used for building projects, running tests to detect bugs and other issues as soon as they are introduced, static code analysis and deployment. For instance combining Jenkins and Docker…
-
Silent security alert – RSA archer (CVE-2018-11059 & CVE-2018-11060)
Archer Technologies provided enterprise governance, risk, and compliance management software. The product aim to reduce enterprise risks, manage and demonstrate compliance, automate business processes, and gain visibility into corporate risk and security controls. Whereby, it integrate with your internal systems equivalent as workflow management especially approval process. REST API relies on a stateless, client-server, cacheable…
-
CYBER SECURITY ADVISORY – Panel Builder 800,Improper input validation vulnerability (CVE-2018-10616)
Retrospectively cyber attack encountered on Nuclear power facility in past. The SCADA system facilities vendor are working hard to hardening their device and provided cyber security advisory. An cyber security alert announced by ABB that a software engineering tool for configure Panel 800 has vulnerability occurs. ABB Panel Builder 800 all versions has an improper…
-
26th Jul 2018 – CVE-2018-1046 (POWERDNS)
Cyber attack wreak havoc, perhaps this is a digital world. We focus cyber attacks happens in company and personal workstation in past decade. The smartphones and IoT devices market coverage bigger than hardward devices in business world. From business point of view, it is a good oppuntunities. The telcom services providers will be more business…
-
Security Advisory for Vulnerabilities in QNAP (Q’center) Virtual Appliance – Jul 2018
QNAP’s Network Attached Storage(NAS) is the friend from SME users. Even thought IT Dept, they are also satisfy with NAS. Since the price is affordable and provides plug and play function. It is common that NAT on firewall will be deploy with Hide NAT. As a result your QNAP’s will be receive the new patch…
-
25th JUl 2018 – Malicious Cyber Activity Targeting ERP Applications (Stay alert!)
A consulting firm observe that the abuse of the SAP Invoker Servlet rapidly increase (built-in functionality in SAP NetWeaver Application Server Java systems (SAP Java platforms)). The fact is that customer may not aware or encounter technical difficulties to remediate a former vulnerability. May be a new attack (former vulnerability + Zero day) let…
-
Lost of civilization – Enterprise MDM solution may not detect these apps
The installation packages of Android apps (.APK files) are deploy with.ZIP files. Because of the fundemental design concept. It let malware has way for infection. Yes, threat actor can place a malicious DEX file at the start of the APK file. But V2 signing mechanism can avoid above types of infection. However of the compatiblity…