-
Huge volumes of vulnerability items on a single vendor announce this week because of US-CERT resources issue.
It indeed running out of resources for US CERT resources. A unpredictable volume of Huawei vulnerability this week. Just think it , a lot of bug fix (software patch) is accumulate. Do you have anxious find out your device name to do the patching. Perhaps on the list you find a long listing of vulnerability checklist…
-
Flaw and practices – AMD CPU design flaw more worse than the other product!
The threat actor spending their effort to re-engineering the vulnerabilities of Meltdown and Spectre. Their objective is relies on design flaw convert as a cyber attack solution including data extraction and collect the user credential. However it is still in development phase. Today, AMD vulnerabilities looks harm the IT world. Since the proof of…
-
Mozilla Releases Security Updates for Firefox Published March 13, 2018
Use After Free and Out-of-bounds Write vulnerabilities totally appears in Firefox web browser. It looks that there are more vulnerabilities found! The code for all projects in the Mozilla family (such as Firefox, Thunderbird, etc.) … Contains images and CSS files to skin the browser for each OS (Linux, Mac and Windows) … Support code…
-
CISCO vulnerabilities checklist – Mar 2018
As of this month, Cisco found more vulnerabilities just this month. It looks that network equipment provider will be felt Microsoft pain since they have web server and java applet. For more details, please refer below: CVE-2018-0087 – A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote…
-
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization
Retrospectively Shibboleth(SAML IDP) found vulnerability on 13th Jan 2018 (CVE-2018-0486). The flaw was that it allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD. However there is an additional vulnerability found on Security Assertion Markup Language (SAML). It is the CVE-2018-0489. A multiple SAML libraries may allow authentication bypass…
-
New detection of technology. Will it be let Antivirus firm embarrassing?
Retrospectively, the IT technology defense mechanism especially behavior analysis and cloud machine learning model are powerful. The threat actors looks difficult to masquerade themselves to start the infiltration. In order to fight against crime. The law enforcement might have to doing the surveillance or scrutiny the suspects. Since it is not a secret, a professional…
-
CVE-2018-7642 – GNU Binutils 2.30
-
9th Mar 2018 – Crypto currency world Trivia
Crypto currency world Trivia: Most crypto exchange are currently licensed at United States level as money transmitter businesses. Status update on Mar 2018: US regulators have stated their desire to implement more oversight at the federal level. Reference URL: https://sg.finance.yahoo.com/news/crypto-exchange-bittrex-compliant-sec-225148555.html
-
How much is your personal data worth?
Microsoft windows defender make the world safe. The threat actor masquerading a legitimate file goal to doing bitcoin mining. Windows defender just kill it within seconds. It is very powerful. It hints to the world that there will be formed different countries will have their own operation system. Why? Nobody want that all the time under monitoring.…
-
Heard that Crypto exchange BINANCE faced ‘large scale’ theft attempt
Heard that a rumors on discussion website. A victim stated that an unknown counterfeit cryptocurrency transaction submitted in his account. I retrospectively his discussion detail and feeling that the problem may not happen in his endpoint. The victim stated that he noticed that a 3rd API key has been created, without IP white listing. But…