Author: admin

  • 23rd Jul 2018 – Bluetooth vulnerability

    Elliptic Curve Diffie Hellman (ECDH) make man in the middle attack difficult since hacker would not be able to find out the shared secret and therefore it looks secure. The public keys are either static (and trusted, say via a certificate) or ephemeral (also known as ECDHE, where final ‘E’ stands for “ephemeral”). Ephemeral keys…

  • Security Alerts! July the 22nd the Apache Tomcat team released three security vulnerabilities.

    CVE-2018-8037: User sessions can get mixed up CVE-2018-1336: Denial Of Service (DoS) via UTF-8 decoder CVE-2018-8034: No host name verification in WebSocket client https://tomcat.apache.org/security-9.html

  • Ethereum carrier Solidity shield – Call abuse vulnerability (CVE-2018-14087)

    An Integer Overflow is the condition that occurs when the result of an arithmetic operation, such as multiplication or addition, exceeds the maximum size of the integer type used to store it. Ethereum hits such vulnerability in frequent. The solidity programming language rescue Ethererum in the cryptocurrency world. But no prefect things in the world.…

  • A vulnerability has been identified in IEC 61850 system configurator – CVE-2018-4858

    When a lot of cyber security Guru focusing the nuclear power and critical facilities. It looks they also requires to includes the power substation. From techincal point of view, control central will be hardening both console and network environment. But how about the configuration console for substation? Does it allow install the configuration software (IEC…

  • 20th Jul 2018 – Win32/Emotet return again!

    Strange! A Trojan (Win32/Emotet) found on 2014. It  looks that similar of cyber attack comes again. Published Jul 23, 2014 (Trojan:Win32/Emotet) – https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Emotet This threat can steal your personal information, including your banking user names and passwords. It is usually installed when you open a spam email attachment or click on a malicious link in…

  • Defending the Power Grid From Hackers – Jul 2018

    Cyber defense facilities today are very strong and effecive to fight against different of cyber attacks. Even though stealer deploy DNS steal technique to exfiltrate the data from a firm. Anti cyber technology have their way to quarantine and deny such activities. Perhaps you said the IoT devices attack that wreaked hovac worldwide. It is…

  • If you are the cisco SD WAN /iWan customer, you should stay alert! 18th Jul 2018 (Cisco security advisories)

    Intelligent WAN (iWAN) is a Cisco SD-WAN product that was built from an existing Cisco product (also called iWAN). How do you deploy Cisco SD-WAN? • Cloud-based management and vAnalytics dashboard • Virtual or physical secure routers for on-premise or cloud • In-house IT or managed service with service providers or system integrators • Capital…

  • Cisco Security Advisories and Alerts published on Wed 18th Jul 2018.

    Cisco Policy Suite for Mobile is a carrier-grade policy, charging, and subscriber data management solution. It helps service providers rapidly create and bring services to market, deliver a positive user experience, and optimize network resources. It also generates monetization opportunities across 3G, 4G, and LTE access networks as well as IP Multimedia Subsystem (IMS) service…

  • Jul 2018 – What’s up involving LabCorp Cyber Security incident ?

    Headline News said a global laboratory company suspect encounter cyber attack this month (Jul 2018). LabCorp  a leading global life sciences company,  aim to provides diagnostic, drug development and technology-enabled solutions for more than 115 million patient encounters per year. As of today, we did not heard any official announce the details. However the news on…

  • Have you heard CVE-20170-5645? Oracle critical patch update advisory – July 2018.

    Background Java programming language sometimes look like a accomplice. The Java Sandbox, which attempts to enforce a privilege model that permits safe execution of untrusted code, and is most famously used to permit the automatic execution of Java Applets in a browser. Vulnerability details Apache Log4j is a Java-based logging utility. Log4j is one of…