ATENTIONβΌ New - CVE-2017-8404 (dcs-1130_firmware)
π Read
via "National Vulnerability Database".
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to the device work properly) result in being passed as commands to a "system" API in the function and thus result in command injection on the device. If the firmware version is dissected using binwalk tool, we obtain a cramfs-root archive which contains the filesystem set up on the device that contains all the binaries. The library "libmailutils.so" is the one that has the vulnerable function "sub_1FC4" that receives the values sent by the POST request. If we open this binary in IDA-pro we will notice that this follows an ARM little endian format. The function sub_1FC4 in IDA pro is identified to be receiving the values sent in the POST request and the value set in POST parameter "receiver1" is extracted in function "sub_15AC" which is then passed to the vulnerable system API call. The vulnerable library function is accessed in "cgibox" binary at address 0x0008F598 which calls the "mailLoginTest" function in "libmailutils.so" binary as shown below which results in the vulnerable POST parameter being passed to the library which results in the command injection issue.π Read
via "National Vulnerability Database".
β GE Aviation Passwords, Source Code Exposed in Open Jenkins Server β
π Read
via "Threatpost".
A DNS misconfiguration resulted in an open Jenkins server being available to all.π Read
via "Threatpost".
Threat Post
GE Aviation Passwords, Source Code Exposed in Open Jenkins Server
A DNS misconfiguration resulted in an open Jenkins server being available to all.
π Airline Facing Record Breaking $229 Million GDPR Fine π
π Read
via "Subscriber Blog RSS Feed ".
The fine would be the largest against a company post-GDPR and roughly 1.5 percent of the company's annual revenue.π Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Airline Facing Record Breaking $229 Million GDPR Fine
The fine would be the largest against a company post-GDPR and roughly 1.5 percent of the company's annual revenue.
π΄ Android App Publishers Won't Take 'No' for an Answer on Personal Data π΄
π Read
via "Dark Reading: ".
Researchers find more than 1,000 apps in the Google Play store that gather personal data even when the user has denied permission.π Read
via "Dark Reading: ".
Dark Reading
Android App Publishers Won't Take 'No' for an Answer on Personal Data
Researchers find more than 1,000 apps in the Google Play store that gather personal data even when the user has denied permission.
π΄ Researchers Poke Holes in Siemens Simatic S7 PLCs π΄
π Read
via "Dark Reading: ".
Black Hat USA session will reveal how they reverse-engineered the proprietary cryptographic protocol to attack the popular programmable logic controller.π Read
via "Dark Reading: ".
Dark Reading
Researchers Poke Holes in Siemens Simatic S7 PLCs
Black Hat USA session will reveal how they reverse-engineered the proprietary cryptographic protocol to attack the popular programmable logic controller.
β Apple aims privacy billboard at Googleβs controversial smart-city β
π Read
via "Naked Security".
It's outside of Sidewalk Labs HQ in Toronto, where Google's sister company is working on stuffing the city with data-collecting sensors.π Read
via "Naked Security".
Naked Security
Apple aims privacy billboard at Googleβs controversial smart-city
Itβs outside of Sidewalk Labs HQ in Toronto, where Googleβs sister company is working on stuffing the city with data-collecting sensors.
π1
β Firefox to include tracker blocking report feature β
π Read
via "Naked Security".
Mozilla has introduced a lot of tracker blocking protections into Firefox lately. Now, it is planning a new feature that will let you see how many online snoopers youβve successfully evaded. A new feature called the Tracking Protections Panel (aka the Protection Report) will tell users how many trackers Firefox blocked in the prior week, [β¦]π Read
via "Naked Security".
Naked Security
Firefox to include tracker blocking report feature
Mozilla has introduced a lot of tracker blocking protections into Firefox lately. Now, it is planning a new feature that will let you see how many online snoopers youβve successfully evaded. β¦
β Google suspends Trends emails after revealing murder suspectβs name β
π Read
via "Naked Security".
People subscribed to Google Trends in New Zealand were emailed the murder suspect's name in violation of a New Zealand court's order.π Read
via "Naked Security".
Naked Security
Google suspends Trends emails after revealing murder suspectβs name
People subscribed to Google Trends in New Zealand were emailed the murder suspectβs name in violation of a New Zealand courtβs order.
β Rapid Incident Response Now Available through Cynetβs Free IR Service Providers Offering β
π Read
via "Threatpost".
Cynet's 360 platform is ready out-of-the-box, for fast, easy deployment across all endpoints.π Read
via "Threatpost".
Threat Post
Rapid Incident Response Now Available through Cynetβs Free IR Service Providers Offering
Cynet's 360 platform is ready out-of-the-box, for fast, easy deployment across all endpoints.
π How financial services companies can protect against mobile threats π
π Read
via "Security on TechRepublic".
Financial services organizations face a variety of cyber threats. But mobile risks represent a major Achilles' heel for the industry, says a new report from Wandera.π Read
via "Security on TechRepublic".
TechRepublic
How financial services companies can protect against mobile threats
Financial services organizations face a variety of cyber threats. But mobile risks represent a major Achilles' heel for the industry, says a new report from Wandera.
π Cybersecurity incidents cost businesses $45B last year π
π Read
via "Security on TechRepublic".
Ransomware, cryptojacking, and business email compromise attacks all ramped up the financial losses due to cyber breaches, according to the Online Trust Alliance.π Read
via "Security on TechRepublic".
TechRepublic
Cybersecurity incidents cost businesses $45B last year
Ransomware, cryptojacking, and business email compromise attacks all ramped up the financial losses due to cyber breaches, according to the Online Trust Alliance.
π΄ DevOps' Inevitable Disruption of Security Strategy π΄
π Read
via "Dark Reading: ".
Black Hat USA programming will dive into the ways DevOps-driven shifts in practices and tools are introducing both new vulnerabilities and new ways of securing enterprises.π Read
via "Dark Reading: ".
Dark Reading
DevOps' Inevitable Disruption of Security Strategy
Black Hat USA programming will dive into the ways DevOps-driven shifts in practices and tools are introducing both new vulnerabilities and new ways of securing enterprises.
π΄ Insider Threats: An M&A Dealmaker's Nightmare π΄
π Read
via "Dark Reading: ".
Because data has never been more portable, taking it has never been easier. And that's a huge problem during mergers and acquisitions.π Read
via "Dark Reading: ".
Dark Reading
Insider Threats: An M&A Dealmaker's Nightmare
Because data has never been more portable, taking it has never been easier. And that's a huge problem during mergers and acquisitions.
β Backdoor discovered in Ruby strong_password library β
π Read
via "Naked Security".
An eagle-eyed developer has discovered a backdoor recently sneaked into a library (or βgemβ) used by Ruby on Rails (RoR) web apps to check password strength.π Read
via "Naked Security".
Naked Security
Backdoor discovered in Ruby strong_password library
An eagle-eyed developer has discovered a backdoor recently sneaked into a library (or βgemβ) used by Ruby on Rails (RoR) web apps to check password strength.
π How to secure your Zoom conference line from hackers π
π Read
via "Security on TechRepublic".
A Zero Day vulnerability allows any website to open up a video-enabled call on a Mac with the Zoom app installed. Here's how to patch it.π Read
via "Security on TechRepublic".
β Zoom Zero-Day Bug Opens Mac Users to Webcam Hijacking β
π Read
via "Threatpost".
The vulnerability can be exploited on a drive-by basis by a malicious website.π Read
via "Threatpost".
Threat Post
Zoom Zero-Day Bug Opens Mac Users to Webcam Hijacking
The vulnerability can be exploited on a drive-by basis by a malicious website.
β Marriott Hit With $123M Fine For Massive 2018 Data Breach β
π Read
via "Threatpost".
The data breach fine against Marriott by the Information Commissioner's Office comes a day after British Airways was also penalized.π Read
via "Threatpost".
Threat Post
Marriott Hit With $123M Fine For Massive 2018 Data Breach
The data breach fine against Marriott by the Information Commissioner's Office comes a day after British Airways was also penalized.
π΄ Marriott Faces $124 Million GDPR Fine in UK π΄
π Read
via "Dark Reading: ".
The proposed penalty is for a data breach beginning in 2014 that affected more than 500 million customers worldwide.π Read
via "Dark Reading: ".
Dark Reading
Marriott Faces $124 Million GDPR Fine in UK
The proposed penalty is for a data breach beginning in 2014 that affected more than 500 million customers worldwide.
π΄ Cybercriminals Target Budding Cannabis Retailers π΄
π Read
via "Dark Reading: ".
Companies in the young, rapidly growing industry are targeted for sensitive information they store and immature security practices.π Read
via "Dark Reading: ".
Darkreading
Cybercriminals Target Budding Cannabis Retailers
Companies in the young, rapidly growing industry are targeted for sensitive information they store and immature security practices.
ATENTIONβΌ New - CVE-2018-14866 (odoo)
π Read
via "National Vulnerability Database".
Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-14833
π Read
via "National Vulnerability Database".
Intuit Lacerte 2017 has Incorrect Access Control.π Read
via "National Vulnerability Database".