-
The world cup 2018 – malicious game website and phishing email also involved in this competition. This like malware transformation of football shooting.
THE 2018 WORLD CUP lure hacker interest, a breeding ground for hackers. The phishing campaign linked to the start of the FIFA World Cup where cyber-criminals attempt to lure would-be victims into downloading. For instance, Games, email and related information. Such download contain malware and let the downloader become cyber attack victim. How do you…
-
Sometimes RESTful API jeopardize your personal data privacy
Ticketmaster Hacked! The company sold 500 million tickets to 86 million people last year. It is important for you to select the best API to create chatbot. Common way call a RESTful API from your Chatbot. What makes RESTful APIs even more attractive is that the same REST API could potentially be used both by…
-
See whether does it a defect on GNU Binutils (status update on 25th June 2018)
Bug (CVE-2018-7642) found GNU Binutils 2.30 on 24th Feb 2018. GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code. The GNU compiler Collection (gcc) play a important role of software development. If a bug will be happened…
-
Found buffer overflow, integrate overflow & memory corruption in redis – Jun 2018
If you have a database of geo-located data, what is the appropriate database setup? The geospatial require fastest database so Redis is one of the option.Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache and message broker. It supports data structures such as strings, hashes, lists, sets, sorted…
-
Will satellites be affected by a buffer overflow vulnerability?
Will satellites be affected by a buffer overflow vulnerability? Heard that hacker interested of the satellite device. This news let you imagine that it is a APT attack, right? It looks that political issues run around the world. Who’s right? Who’s wrong? Perhaps god also doesn’t know. On 16th Jan 2018, the confirmation of Solaris…
-
“With great power comes great responsibility” (CVE-2018-6961)
Sometimes we review the vulnerability check list. We are aim to address high severity of vulnerabilities items in first piority. From technical point of view it looks correct. Since some medium vulnerabilities especially cookie or cross site scripting issue may spend more time to do the remediation. A security advisories announced by VMware on 15th May…
-
Not seen attack related to CVE-2018-7559, but require considerations and stay alert.
US Homeland security has announcement three times within this year ( April 16, 2018,May 29, 2018 and June 14, 2018) thus to urge the world staying alert malicious attack.Perhaps the industrial sector especailly oil and gas, power supplier facilities has detective and preventive control in placed. Hacker will be facing difficulties for attack. As far as…
-
June 2018 Node.js Security Releases
Node.js runs on top of a Javascript engine therefore it is portable to any platform in computer world. Deploy a Node.js web application environment using AWS Elastic Beanstalk and Amazon DynamoDB. Elastic Beanstalk provisions and manages the underlying infrastructure. Solutions Infini is the Leading Bulk SMS & Cloud Telephony service provider. But the front end…
-
June 20, 2018 – Cisco Releases Security Updates for Multiple Products
A remote attacker could exploit some of these vulnerabilities to take control of an affected system on both NX and FX OS. In the sense that both router, switch and Firewall requires users considerations. NX-OS Software NX-API Arbitrary Code Execution Vulnerability – https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo FXOS and NX-OS Software Cisco Fabric Services Arbitrary Code Execution Vulnerability – https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace FXOS…
-
Windows SharePoint Services – “To be, or not to be”
Microsoft formalized Patch Tuesday in October 2003 till today. It was focus on workstation, server and software product till today. Any differences in the Microsoft architecture model in last decade? Perhaps your answer is the cloud platform and collaboration cloud. Yes, the cloud computing technology similar 14th and 17th centuries renaissance. Thus, a major component…