-
Tomcat – CVE-2018-1305 – Don’t ignore!
Apache and Tomcat server usage covered more than 60% in cyberworld. A common practice is that Apache server hold the static page or it is a front end (Reversed Proxy function). Tomcat server trend to become a major server component. So all your java application, configure and DB service ID will be located in this…
-
SCADA manufacturer security awareness awaken – ABB
I speculate that APT attack will be proactive doing their engagement in electric Power supply industry and target manufacturer this year. Since they are all deployed SCADA system. Perhaps engage an attack in this zone as much as better than negotiating with world trade commissioner request to reduce other country quota. The SCADA manufacture awaken the…
-
Information warfare and arsenal
Preface: There are different countries located in the world, meanwhile so called regime has different governance concept and strategic task force in different area. A simple introduction of regimes around the planet Our story begin with Bear Bear group views electronic warfare as an essential tool for gaining and maintaining information superiority over its adversaries.…
-
Blockchain technology can do the magic – EU GDPR new data protection regulation
Preface: The movie title – when harry met Sally romantic. It is a comedy film written by Nora Ephron. It gives an idea to the world all we are interconnected with fate. GDPR – High Level Understanding The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation by which the European Parliament, the…
-
Evade sanctions or this is our new world trend – petroleum cryptocurrency
The legitimacy of the crypto currency provides misty seen to everybody. Heard that it is legal in some countries. However it cannot maintain the legitimacy since we must following the traditional financial currencies system guideline and policy. But think it over. In ancient age, people using material change concept. The revolution of the change since the…
-
The US Securities and Exchange Commission (SEC) new guidance
Big country versus Big discussion: The US Securities and Exchange Commission (SEC) released a statement urge high-ranking executives not to trade stocks before the disclosing breaches, major vulnerabilities, and other cybersecurity related incidents. New guidance – https://www.sec.gov/rules/interp/2018/33-10459.pdf Meanwhile Intel release guidance this week (details of availability and schedule for microcode update). For more details, please…
-
For your attention! Multiple vulnerabilities in both Drupal 7 and Drupal 8
It indeed a tragedy. A multiple vulnerabilities in both Drupal 7 and Drupal 8. Drupal is a free and open source content-management framework written in PHP and distributed under the GNU General Public License. In short, in order to avoid unforeseen technology risk issue occurs, please read the official announcement shown as below: https://www.drupal.org/sa-core-2018-001 Synopsis:…
-
Cisco Releases Security Updates for Multiple Products – 21st Feb 2018
Understanding: The VOSS platform is integrated in Cisco HCS where it is called Cisco Unified Communications Domain Manager (UCDM). VOSS has web services application programming interfaces (APIs) available to third-party developers.Features of VOSS include Web-based Administration, Centralised Management, Collaboration Lifecycle Management, Collaboration Service Management, Business Process Layer on top Network Infrastructure and Communications Architectures Management.…
-
About APT37
A cyber security company (FireEye) so bold to accuse a country. As a matter of fact the APT threat actor make a mistake. It inadvertently show their location. Regarding to the details provided by FireEye. The APT 37 develop total 10 different types of malware to satisfy their goal. Regarding to my observation. I would suggest…
-
UK cyber security agency sticks with China’s Huawei despite US spy fears
The espionage scandal jeopardize the trustworthy reputation. However China is not the espionage program initiator. But America worries about espionage by cross counties. It is hard to tell who’s correct or who’s wrong! UK cyber security agency sticks with China’s Huawei despite US spy fears. For more details, please refer below url for reference. http://www.telegraph.co.uk/technology/2018/02/20/uk-cyber-security-agency-sticks-chinas-huawei-despite-us-spy/