Author: admin

  • Vulnerability in SCADA CODESYS Web Server CVE-2018-5440

    To be honest, it make surprise to me this month. An abnormal situation causes SCADA system in high risk. CVE-2018-5440 focusing vulnerability on COdesys web server.This product deployment use mainly in the critical manufacturing and energy sectors. Perhaps this is a Microsoft product and hard to avoid vulnerability occurs. The accusation of NotPetya ransomware attack…

  • IoT World and Smart City must staying wide-awake!

    SmartCity project wide spreading implement in the world. The framework transform existing IT world domain includes Cloud computing, virtual machine, router and network infrastructure. Meanwhile it carry the design flaw so called vulnerability simultaneously. As we know, Microsoft product has famous activities patch Tuesday to do the mitigation of critical risk occurs on their product.…

  • City Union Bank in India victim of cyber hack through SWIFT system – Reuters Headline News (19th Feb 2018)

    Sounds horrible! A heist occurred from SWIFT payment system again? Chief Executive Officer N. Kamakodi called it a “conspiracy” involving multiple countries, and added the lender was still investigating how it had happened. But the statement seems not precise to describe. A fundamental design limitation on original MT 202 message. Perhaps MT 202 COV doing…

  • Heists last year – SWIFT defense solution

    Reuters news told that a heist occurred in Russia Bank last year. Unknown hackers stole 339.5 million roubles ($6 million) from a Russian bank last year in an attack using the SWIFT international payments messaging system. Perhaps we are not going speculating the reason to delaying the public announcemnt. Yes, it may be for forensic…

  • Remediation step – Saturn Ransomware

    Preface: Can we saying this? it is Google Adwords design flaw? It lure the threat actors go through this service to spread malware from Google search engine. Quick note: Saturn ransomware found this month (Feb 2018). It looks strange that attack victim only on physical machine instead of Virtual Machine. Why? Does the threat actor…

  • UK blames Russia for NotPetya cyber-attack on June 2017

    UK blames Russia for NotPetya cyber-attack last year (details shown below url for reference) https://www.theguardian.com/technology/2018/feb/15/uk-blames-russia-notpetya-cyber-attack-ukraine MeDoc is widely used among tax accountants in Ukraine, and the software was the main option for accounting for other Ukrainian businesses. Threat actors using email scam counterfeit MeDoc lure victims goal suspend the services of Nuclear power supply facilities…

  • Adobe Acrobat and Reader CVE-2018-4872 Privilege Escalation

    When I was young, I watch the ali baba movie a unforgettable mystery slogan. Yes, it is open sesame. A magic master come out. Perhaps my life journey told me that this is not true. We now living in electronic world. Open electronic file daily like habit forming sequence. It looks that my dream come…

  • Special Edition – HIDDEN COBRA – Malicious Cyber Activity

    Special Edition: Information security focus US Homeland security (DHS) urge the world to staying alert with HIDDEN COBRA Malicious Cyber Activity. It looks that the cyber attack wreak havoc to the world. And therefore DHS suggest to add below Yara rule into your IDS or malware detector (For instance RSA ECAT). The following YARA rule…

  • Staying alert – vulnerability found on ABRT in 2015 – CVE-2015-1862

    As times go by, Linux especially Fedora replace the position of microsoft windows. This status no popular in personal PC however investment bank environement especially broker and forex exchange trading firm might using intensively. A vulnerabiity found on 2015 but the status of fedora bugzilla display that this is not a bug. My idea is…

  • Mew Trend 2018 – Exfiltrating Data via DNS

    New Trend 2018 – Exfiltrating data via DNS (see below url for reference) https://blogs.forcepoint.com/security-labs/udpos-exfiltrating-credit-card-data-dns Comments: A popular discussion on cyber attack topic this year focusing on DNS attack. Security expert found that threat actor transform DNS topology as a hack tool assists their goal. It show small data set with frequent connections. But the new…