-
About Microsoft Patch Tuesday: For defense during corrective action. Virtual patching is a must for any company these days. (14th Dec 2022)
Preface: Cybersecurity is always critical. Business operations define cost efficiency. Simply put, reduce costs in cyber defense is not a good idea. Because it might lost your company reputation. Background: The details in today’s vulnerability bulletin are not detailed. Perhaps the reason for vendor not disclosed details is let their customer have schedule enough time…
-
Web server hosting on the cloud using elasticsearch, my brainstorming to cyber security (13th Dec 2022)
Preface: Most people will agree that the best eCommerce platforms are BigCommerce and Shopify.HCL Commerce (formerly known as WebSphere Commerce and WCS (WebSphere Commerce Suite)) is a software platform framework for e-commerce, including marketing, sales, customer and order processing functionality in a tailorable, integrated package. It was formerly product of IBM, the product was sold…
-
Alert awaken by CVE-2022-3259 – NVD Published Date:12/09/2022
Preface: Times have changed, and people’s concerns about data security are compared with the past three decades. it looks important. The basis of the design goals of the http protocol in the 90s was to focus on network connections. Because the computing technology at that time was very simple. It does not have the concepts…
-
CVE-2022-23471 containerd CRI stream server: Host memory exhaustion through Terminal resize goroutine leak (7th Dec 2022)
Preface: As of version 1.23, Kubernetes requires runtimes to be CRI compatible. It means that dockershim is now deprecated, and Docker Engine is no longer supported as a runtime. However, Kubernetes can still communicate with Docker via containerd, which can be CRI compliant with a plugin. History: “To not want a Buddhist monk after the…
-
Xen Security Advisory (XSA-424): CVE-2022-42328 and CVE-2022-42329 – Guests can trigger deadlock in Linux netback driver (7th Dec 2022)
Preface: A Xen guest typically has access to one or more paravirtualised (PV) network interfaces. These PV interfaces enable fast and efficient network communications for domains without the overhead of emulating a real network device. Background: XenServer can directly installs on bare-metal hardware without any restriction, overhead charge and performance obstacles of an Operating System.…
-
CVE-2022-43548 – An operating system command injection vulnerability exists in Node[.]js (possible attack scenario) 5th Dec 2022
Preface: When I read this CVE details. I found a gap between official “node JS” site announcements and security forums, including popular sites that post CVEs on a daily basis. In fact, if an attacker wants to trigger this vulnerability, it should meet the following requirements. That’s why I discuss this topic. Background: Node[.] js…
-
CVE-2022-23465 Fixes two design weaknesses in Swift Term where an attacker could store malicious code (4th Dec 2022)
Preface: Character combinations consisting of a backslash (\) followed by a letter or by a combination of digits are called “escape sequences.” Background: SwiftTerm uses the Swift Package Manager for its build, and you can add the library to your project by using the url for this project. SwiftTerm is a VT100/Xterm terminal emulator library…
-
About CVE-2022-24441: Something happens on “Snyk” when jump to this scenario (1st Dec 2022)
Preface: DevOps philosophy by practices, and tools that improve an organisation’s ability to deliver applications and services. This enables products to be developed and improved at a faster rate than organisations using traditional software development and infrastructure management processes. Efficiency, fast is the slogan of business. Step next phase after digital transformation. DevOps is important…
-
Soap Opera Scene: Vulnerability (CVE-2022-46338) Realized in Life – 1st Dec 2022
Preface: Logitech revenue worldwide 2016-2022, by segmentNews update in Aug 15, 2022.In 2022, the computer peripherals producer Logitech reported sales revenues of 5.48 billion U.S. dollars, of which 1.45 billion U.S. dollars was generated by its gaming segment. A further 967.3 million U.S. dollars in revenue was made from keyboard and keyboard-and-mouse combination (combo) sales.…
-
CVE-2022-46152 Design weakness causes SMC_Calling form cyber attack (29th Nov 2022)
Preface: In the ARM architecture, synchronous control is transferred between the normal Non-secure state to Secure state through System Monitor Call exceptions Background: TEE provides an isolated environment to ensure code/data integrity and confidentiality. A typical embedded system running Linux or Android has vulnerabilities in both the kernel and userspace. Vulnerabilities could allow attackers to…