-
21st May 2018 – Citrix XenMobile 10.x Multiple Security Updates
Applicable Products (XenMobile 10.7 & XenMobile 10.8) Affecting XenMobile Server 10.7 and 10.8: CVE-2018-10653 (High): XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server CVE-2018-10650 (Medium): Insufficient Path Validation Vulnerability in Citrix XenMobile Server CVE-2018-10654 (Medium): Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server CVE-2018-10648 (Low): Unauthenticated File Upload Vulnerabilities in Citrix XenMobile…
-
The book of Revelation – OPC UA will be the target for next phase of SCADA system attack.
Preface A fascinating, unusual story which creates an eerie atmosphere. The security report issued by Kaspersky on 10th May 2018 driven my interest to do this study. So the report equivalent to enlightenment my conception. Background A tremendous potential cyber attack found by Cisco. Thereby it announced to public last week. They reveal this unknown story…
-
Heads-up: Low-end Wi-Fi router vulnerability – 24th May 2018
Botnet from earlier phase relies on workstations engage the attack convert to smartphones in last few years. Most likely the security enhancement in workstations and smartphones improved. The threat actors found the new victims today.It is a low-end wireless router. So below items are the guidance: Never trust input Prefer rejecting data to filtering data…
-
My speculation on how Cisco (Talos) found the malware (VPNFilter malware).
Preface: Using Big Data and data mining methods to predict attacks before they happen,the Cisco Umbrella Security Research team built such detection framework. Point of view: a. Vulnerability routers are vulnerable to Shell Metacharacters Attack Regarding to the observation result of Cisco Talos security team. There are group of router devices are vulnerable. They are…
-
Vulnerabilities – Waiting for vendor response – 23rd May 2018
The cyber attacks are wreak havoc today. In order to protect the power facility, water supply, Gas supply and petroleum industry daily operations. The SCADA control system vendor implemented security control in their system infrastructure. However when vulnerabilities encounter on their products. The remediation step of the vendor response sometimes not in effecient. For instance,…
-
21 May 2018 – CPU hardware utilizing speculative execution may be vulnerable to cache side-channel attacks
Regarding to the subject matter, please refer to below url for reference. Q2 2018 Speculative Execution Side Channel Update https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html Vulnerability of Speculative Processors to Cache Timing Side-Channel Mechanism https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
-
Quick look in virtual machine Zone (CVE-2018-8897) – 05/18/2018
Technology world is a challengeing zone. The key word “rest” looks do not apply to system developer, application programmer and IT expert! I re-call the vulnerability (CVE-2018-8897) to review. It ennounced by security experts for week ago. Perhaps you have full understanding. However no harm in my view point to do the review since it…
-
Software design limitation causes hardware Involved software Attacks – Shanghai 2345 Network
Shanghai 2345 Network major business focusing Mainland China. This companyprovides Internet access platforms. It provides 2345 Website navigation that facilitates users to find their own needs of the site entrance, as well as provides weather forecasts, practical inquiries, commonly used software download, e-mail login, search engine portal, online collection, and other Internet common service; 2345…
-
May 18, 2018 – ISC Releases Security Advisories for BIND
ISC Releases Security Advisories for BIND on May 18, 2018. This alert awaken my defense thinking. I was written few articles about the electronic war and the cyber arsenal. But forgot to contains a scenario which annoucned by ISC today (Security Advisories for BIND). Regarding to to the subject (ISC Releases Security Advisories for BIND) indeed…
-
16th May 2018 – Cisco security update awaken SDLC (software development life cycle) process.
The vulnerabilities occurred so far, it awaken the SDLC (software development life cycle) process. The design bug common appear in development cycle. The bug checker may record in details and put in the report let the decision maker know the actual statis. Project management office member better to use your knowledge learned during PMP or…