= End-of-Day report =
Timeframe: Dienstag 30-01-2018 18:00 โ Mittwoch 31-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
= News =
โโโ Microsoft Drops the Hammer on Coercive Registry Cleaners & System Optimizers โโโ
Starting March 1st 2018, Windows Defender and other Microsoft products will begin to remove programs that display coercive behavior. This includes registry cleaners and system optimizers that offer free scans, display alarming messages, and then require the user to purchase it.before fixing anything.
โโโ Google hat 2017 mehr als 700.000 bรถsartige Apps aus Google Play verbannt โโโ
In einem Jahresbericht fรผhrt Google aus, wie sicher der eigene Android-App-Store Google Play doch ist. Aufgrund einiger Vorfรคlle wirkt die Argumentation stellenweise jedoch nicht ganz glaubwรผrdig.
โโโ Kritische Sicherheitslรผcke in Mozilla Firefox - Patch verfรผgbar โโโ
Mozilla hat einen Out-of-Band Patch fรผr eine kritische Sicherheitslรผcke im Webbrowser Firefox verรถffentlicht. Auswirkungen Durch Ausnรผtzen dieser Lรผcke kann ein Angreifer beliebigen Code auf betroffenen Systemen, mit den Rechten des angemeldeten Benutzers, ausfรผhren. Dazu reicht es, den Browser zum Anzeigen einer entsprechend prรคparierten Webseite ..
= Vulnerabilities =
โโโ DSA-4102 thunderbird - security update โโโ
โโโ PHOENIX CONTACT mGuard โโโ
โโโ Siemens TeleControl Server Basic โโโ
โโโ WordPress plugin "WP Retina 2x" vulnerable to cross-site scripting โโโ
โโโ Multiple Vulnerabilities in Sprecher Automation SPRECON-E-C, PU-2433 โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Montag 29-01-2018 18:00 โ Dienstag 30-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
= News =
โโโ IBM-Studie: Viele Nutzer halten biometrische Anmeldung fรผr sicher โโโ
Gerade junge Leute wollen sich heutzutage keine Passwรถrter mehr merken: Eine IBM-Studie untersucht Vorlieben von Nutzern aller Altersgruppen. Teilnehmer ab 55 Jahren hingegen merken sich viele verschiedene Passwรถrter auf einmal - auch ohne Passwort-Manager.
โโโ Scammers become the scammed: Ransomware payments diverted with Tor proxy trickery โโโ
Of course this does nothing for victims encrypted files Cybercriminals are using Tor proxies to divert ransomware payments to their own Bitcoin wallets.
โโโ Chrome Extension Malware Has Evolved โโโ
While helpful and creative, Chrome extensions have also become a new playground for hackers intent on stealing your data.
โโโ ENISA organises cyber-exercise to boost CSIRT cooperation โโโ
On 30 January 2018, the EU Cybersecurity Agency ENISA organised โCyber SOPExโ, the first cooperation exercise of the CSIRTs Network.
โโโ E-Mail-Betrug: Vorarlberger Firma zahlt 150.000 Euro โโโ
Mitarbeiterin รผberwies knapp 150.000 Euro ins Ausland โ 83.000 Euro konnten zurรผckgeholt werden
โโโ "spotzi" und "bier1": Cybasar-Leak zeigt die unsicheren Passwรถrter der รsterreicher โโโ
Viele Kennwรถrter offenbaren fahrlรคssigen Umgang mit eigenen Informationen im Netz โ auch von Behรถrdenmitarbeitern
โโโ 2017 in Snort Signatures. โโโ
This post was written by Martin Lee and Vanja Svajcer.2017 was an eventful year for cyber security with high profile vulnerabilities that allowed self-replicating worm attacks such as WannaCry and BadRabbit to impact ..
โโโ Kritische Sicherheitslรผcke in Cisco ASA Software - Patches verfรผgbar โโโ
Cisco hat ein Advisory zu einer kritischen Sicherheitslรผcke in Cisco ASA Software verรถffentlicht. Die Lรผcke befindet sich im Code, der fรผr das "webvpn"-Feature zustรคndig ..
= Vulnerabilities =
โโโ [20180103] - Core - XSS vulnerability in Uri class โโโ
โโโ [20180102] - Core - XSS vulnerability in com_fields โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Freitag 26-01-2018 18:00 โ Montag 29-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: Nina Bieringer
= News =
โโโ Cyberattacken auf niederlรคndische Banken: Netbanking weg โโโ
Die drei grรถรten Banken der Niederlande hatten am Wochenende mit Cyberangriffen zu kรคmpfen. Teilweise fiel auch das Online-Banking aus.
โโโ Coincheck: Kryptowรคhrung im Wert von 429 Millionen Euro gestohlen โโโ
Fรผr das Unternehmen Coincheck war es ein schwarzer Freitag: Eine groรe Menge der Kryptowรคhrung NEM wurde gestohlen. Der Kurs sank dadurch um elf Prozent. Auch Bitcoin und Etherium waren davon betroffen. Der Angriff ist fรผr einige ein Anlass zur Kritik an Japans Regulierung des Kryptohandels.
โโโ Security: Lenovo gesteht Sicherheitslรผcken im Fingerprint Manager ein โโโ
Die Software Fingerprint Manager Pro speichert biometrische Daten auf dem Gerรคt. Allerdings sagt selbst Lenovo, dass das unsicher sei und rรคt daher zu einem Update. Windows-10-Gerรคte sind davon jedoch nicht betroffen.
โโโ Meltdown & Spectre: Windows-Update deaktiviert Schutz gegen Spectre V2 โโโ
Ein aktuelles Windows-Update schaltet den Schutz gegen Spectre Variant 2 ab, um Instabilitรคten des Systems vorzubeugen.
โโโ First 'Jackpotting' Attacks Hit U.S. ATMs โโโ
ATM "jackpotting" - a sophisticated crime in which thieves install malicious software and/or hardware at ATMs that forces the machines to spit out huge volumes of cash on demand - has long been a threat for banks in Europe and Asia, yet these attacks somehow have eluded U.S. ATM operators. But all that changed this week after the U.S. Secret Service quietly began warning financial institutions that jackpotting attacks have now been spotted targeting cash machines here in the United [...]
โโโ Cybasar.at gehackt: 70.000 รถsterreichische Log-ins im Netz aufgetaucht โโโ
Hunderte E-Mails und Passwรถrter von offiziellen Stellen enthalten โ Daten stammen von Gebrauchtwagenplattform Cybasar
= Vulnerabilities =
โโโ DSA-4099 ffmpeg - security update โโโ
Several vulnerabilities have been discovered in the FFmpeg multimediaframework, which could result in denial of service or potentially theexecution of arbitrary code if malformed files/streams are processed.
โโโ DSA-4101 wireshark - security update โโโ
It was discovered that wireshark, a network protocol analyzer, containedseveral vulnerabilities in the dissectors/file parsers for IxVeriWave,WCP, JSON, XML, NTP, XMPP and GDB, which could result in denial ofservice or the execution of arbitrary code.
โโโ DFN-CERT-2018-0020 โโโ
Auf diesem Wege noch einmal der Hinweis, dass wir unsere Security Advisories zu #Spectre und #Meltdown (DFN-CERT-2018-0020) sowie Spectre 2 (DFN-CERT-2018-0019) beinahe tรคglich aktualisieren. Bleiben Sie via @DFNCERT_ADV auf dem neuesten Stand.
โโโ DFN-CERT-2018-0196: VMware AirWatch Console (AWC): Eine Schwachstelle ermรถglicht einen Cross-Site-Request-Forgery-Angriff โโโ
โโโ Security Advisory - Buffer Overflow Vulnerability in the Bluetooth Module of Some Huawei Mobile Phones โโโ
โโโ IBM Security Bulletin: IBM has released AIX and VIOS iFixes in response to the vulnerabilities known as Spectre and Meltdown โโโ
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Security SiteProtector System โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Mittwoch 24-01-2018 18:00 โ Donnerstag 25-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: Nina Bieringer
= News =
โโโ Maersk Reinstalled 45,000 PCs and 4,000 Servers to Recover From NotPetya Attack โโโ
The worlds largest container shipping company รขโฌโA.P. Mรยธller-Maerskรขโฌโ said it recovered from the NotPetya ransomware incident by reinstalling over 4,000 servers, 45,000 PCs, and 2500 applications over the course of ten days in late June and early July 2017. [...]
โโโ BSI-Richtlinie: Der streng geheime Streit รผber die Routersicherheit โโโ
Das BSI will in den kommenden Monaten eine Technische Richtlinie fรผr Heimrouter herausgeben. Vor allem die Kabelnetzbetreiber halten nichts davon, fรผr mรถglichst viel Sicherheit bei den Gerรคten zu sorgen. Der CCC spricht von "Lobbying-Sabotage".
โโโ Windows 10: Microsoft will aufzeigen, was an Gerรคtedaten gesammelt wird โโโ
Sprachdaten, Positionsdaten und Browserverlauf: Nutzer sollen kรผnftig einen besseren รberblick รผber gesammelte Daten in Windows 10 bekommen. Dazu stellt Microsoft ein Dashboard fรผr Microsoft-Accounts und einen Diagnostic Viewer fรผr Gerรคteinformation zur Verfรผgung. (Microsoft, Datenschutz)
โโโ Cloudflare[.]solutions Keylogger Returns on New Domains โโโ
A few months ago, we covered two injections related to the โcloudflare.solutionsโ malware: a CoinHive cryptominer hidden within fake Google Analytics and jQuery, and the WordPress keylogger from Cloudflare[.]solutions. This malware was originally identified by one of our analysts in April 2017 and has since evolved and spread to new domains. Keylogger Spreads to New Domains A few days after our keylogger post was released on Dec 8th, 2017, the Cloudflare[.]solutions domain was taken [...]
โโโ libcurl has had auth leak bug since the first commit we recorded โโโ
Fixed in 7.58.0 If you use libcurl, the command line tool and library for transferring data with URLs, get ready to patch. The tool has a pair of problems, one of which is an authentication leak.โฆ
โโโ Healthcare CERTs highlight the need for security guidance for specific sectors โโโ
A new computer emergency response team has been launched in the Netherlands to provide guidance specifically tailored to the healthcare sector. Martijn Grooten welcomes the development. Read more
โโโ Announcing turndown of the deprecated Google Safe Browsing APIs โโโ
Posted by Alex Wozniak, Software Engineer, Safe Browsing TeamIn May 2016, we introduced the latest version of the Google Safe Browsing API (v4). Since this launch, thousands of developers around the world have adopted the API to protect over 3 billion devices from unsafe web resources.Coupled with that announcement was the deprecation of legacy Safe Browsing APIs, v2 and v3. Today we are announcing an official turn-down date of October 1st, 2018, for these APIs. All v2 and v3 clients must [...]
= Vulnerabilities =
โโโ DSA-4096 firefox-esr - security update โโโ
Several security issues have been found in the Mozilla Firefox webbrowser: Multiple memory safety errors, use-after-frees, integeroverflows and other implementation errors may lead to the execution ofarbitrary code, denial of service or URL spoofing.
โโโ Vulnerability Spotlight: Multiple Unpatched Vulnerabilities in Blender Identified โโโ
Update 1/25/18: Blender has released version 2.79a to address these issues
Technology has evolved in incredible ways that has helped people to create and visualize media like never before. Today, people can use tools such as Blender to visualize, model, and animate 3D content, especially since its free and open-source software. However, this also make it an attractive target for adversaries to audit and find vulnerabilities. Given the user base of Blender, exploiting these vulnerabilities to [...]
โโโ DFN-CERT-2018-0177: Google Chrome, Chromium: Mehrere Schwachstellen ermรถglichen u.a. die Ausfรผhrung beliebigen Programmcodes โโโ
โโโ IBM Security Bulletin: PowerKVM has released fixes in response to the vulnerabilities known as Spectre and Meltdown. โโโ
โโโ IBM Security Bulletin: Vulnerabilities in postgresql affect PowerKVM โโโ
โโโ IBM Security Bulletin: Vulnerabilities in PHP affect PowerKVM โโโ
โโโ IBM Security Bulletin: A vulnerability in Apache Portable Runtime affects PowerKVM โโโ
โโโ IBM Security Bulletin: A vulnerability in procmail affects PowerKVM โโโ
โโโ IBM Security Bulletin: A vulnerability in curl affects PowerKVM โโโ
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Tivoli Netcool Impact โโโ
โโโ IBM Security Bulletin: Vulnerabilities in the Linux kernel affect PowerKVM โโโ
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect IBM Tivoli Netcool Configuration Manager (ITNCM) โโโ
โโโ IBM Security Bulletin: Rational DOORS is affected by multiple vulnerabilities โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Dienstag 23-01-2018 18:00 โ Mittwoch 24-01-2018 18:00
Handler: Robert Waldner
Co-Handler: Stephan Richter
= News =
โโโ Skype, Signal, Slack, other apps inherit Electron vuln โโโ
If youve built a Windows application on Electron, check to see if its subject to a just-announced remote code execution vulnerability. ... Slack users should update to version 3.0.3 or better, and the latest version of Skype for Windows is protected
โโโ [papers] Hardcore SAP Penetration Testing โโโ
โโโ 14 flaws found that could take over industrial control systems โโโ
Licence management systems used in industrial control systems are plagued with vulnerabilities - contain 14 flaws could enable hackers to take control of systems and carry out DoS attacks
= Vulnerabilities =
โโโ Advantech WebAccess/SCADA โโโ
This advisory contains mitigation details for path traversal and SQL injection vulnerabilities in Advantechโs WebAccess/SCADA software platform.
โโโ Security updates for Tuesday โโโ
Security updates have been issued by Debian (smarty3), Fedora (bind, bind-dyndb-ldap, dnsperf, glibc, kernel, libtasn1, libvpx, mariadb, python-bottle, ruby, and sox), Red Hat (rh-eclipse46-jackson-databind), SUSE (kernel), and Ubuntu (kernel, linux, linux-aws, linux-euclid, linux-hwe, linux-azure, linux-gcp, linux-oem, linux-lts-trusty, linux-lts-xenial, linux-aws, and rsync).
โโโ Apple Updates Everything, Again, (Tue, Jan 23rd) โโโ
โโโ Vuln: GIMP CVE-2017-17786 Heap Buffer Overflow Vulnerability โโโ
โโโ Security Advisory - Memory Leak Vulnerability in Some Huawei Products โโโ
โโโ Security Advisory - Two Vulnerabilities in MGCP Protocol of Some Huawei Products โโโ
โโโ Security Advisory - Integer Overflow Vulnerability on Smartphones โโโ
โโโ Security Advisory - DoS Vulnerability in Some Huawei Products โโโ
โโโ Security Advisory - CPU Vulnerabilities Meltdown and Spectre โโโ
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect Content Collector for Email, Content Collector for File Systems, Content Collector for Microsoft SharePoint and Content Collector for IBM Connections โโโ
โโโ IBM Security Bulletin: Cross-site scripting vulnerability in IBM Jazz Team Server affect IBM Rational products based on IBM Jazz technology โโโ
โโโ IBM Security Bulletin: Content Collector for Email is affected by vulnerability due to information disclosure in MyFaces for WebSphere Application Server โโโ
โโโ IBM Security Bulletin: Content Collector for Email is affected by vulnerability due to information disclosure in Apache MyFaces โโโ
โโโ IBM Security Bulletin: Multiple Security Vulnerabilities exist in IBM Cognos TM1 โโโ
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Cognos Insight. โโโ
โโโ SSA-824231 (Last Update 2018-01-24): Unauthenticated Firmware Upload Vulnerability in Desigo PXC โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Montag 22-01-2018 18:00 โ Dienstag 23-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
= News =
โโโ Newsletter-Dienst: Mailchimp verrรคt E-Mail-Adressen von Newsletter-Abonnenten โโโ
Spezifische Referrer fรผr jeden Newsletter-Nutzer haben dazu gefรผhrt, dass Webseitenbetreiber die E-Mail-Adressen von Mailchimp-Nutzern herausfinden konnten. Das Problem wurde nach Meldung an den Anbieter mittlerweile behoben.
โโโ Just Keep Swimming: How to Avoid Phishing on Social Media โโโ
>From Facebook to LinkedIn, social media is flat-out rife with phishing attacks. Youโve probably encountered one beforeโฆ Do fake Oakley sunglasses sales ring a bell? Phishing attacks attempt to steal ..
โโโ "MaMi": MacOS-Malware hรถrt User ab und manipuliert Datenverkehr โโโ
Schรคdling leitet Traffic รผber von Unbekannten kontrollierte DNS-Server um
โโโ Millionen PCs verwundbar: Forscher deckt Lรผcke in allen Blizzard-Games auf โโโ
Konzern arbeitet bereits an Lรถsung โ Problem bei Client
โโโ Achtung: Whatsapp Abo-Betrug kursiert derzeit per Mail โโโ
"Konto ist abgelaufen" โ ehemaliges Abomodell von Whatsapp wird instrumentalisiert um Kreditkartendaten zu ergattern
โโโ SamSam - The Evolution Continues Netting Over $325,000 in 4 Weeks โโโ
This post was written by Vitor VenturaIntroductionTalos has been working in conjunction with Cisco IR Services on what we believe to be a new variant of the SamSam ransomware. This ransomware has been observed across multiple industries including Government, Healthcare and ICS. These attacks do not appear to be highly targeted, and appear to be more opportunistic in nature.Given SamSams victimology, its impacts are not just felt within the business world, they are also impacting people,
= Vulnerabilities =
โโโ HTTP Host header attacks against web proxy disclaimer response webpage โโโ
The FortiOS web proxy disclaimer page is potentially vulnerable to an XSS attack, via maliciously crafted "Host" headers in user HTTP requests. The latter is possible if an attacker is in a Man-in-the-middle position (i.e. able to modify the HTTP requests of the potential victim before they reach the web proxy), or poisons a web cache used by the potential victim.In the latter attack scenario, the tainted disclaimer web page being cached, the XSS attack can be considered as persistent.
โโโ VMSA-2018-0002.3 โโโ
VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
โโโ JSA10836 - 2018-01 Security Bulletin: SRX Series: Firewall bypass vulnerability when UUID with leading zeros is configured. (CVE-2018-0009) โโโ
โโโ XXE & Reflected XSS in Oracle Financial Services Analytical Applications โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Freitag 19-01-2018 18:00 โ Montag 22-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
= News =
โโโ Hacker One: Nur 20 Prozent der Bounty-Jรคger hacken in Vollzeit โโโ
Das US-Unternehmen Hacker One hat aktuelle Zahlen vorgestellt: Die meisten Bounties werden nach wie vor von US-Unternehmen gezahlt. Die Daten zeigen auรerdem, dass das Finden von Schwachstellen fรผr die meisten ein Nebenberuf oder Hobby ist.
โโโ Powerful Skygofree Spyware Was Already Reported and Analyzed In 2017 โโโ
The Skygofree spyware analyzed by Kaspersky today was first spotted by the researcher Lukas Stefanko and the first analysis was published last year by the experts of CSE Cybsec ZLab. The Skygofree ..
โโโ Apple Preps ChaiOS iMessage Bug Fix, Report โโโ
A so-called โtext bombโ flaw in Appleโs iPhone and Mac computers that causes devices to crash or restart will be patched next week, according to multiple sources.
โโโ Followup to IPv6 brute force and IPv6 blocking โโโ
My diary earlier this week led to some good discussion in the comments and on twitter. I want to, first off, apologize for not responding as much or as quickly as I would have liked, I&#;x26;#;39;ve actually been ill most of this week since posting the previous diary (and signing up for this slot as handler on duty). Having said that, ..
โโโ Struts and DotNetNuke Server Exploits Used For Cryptocurrency Mining โโโ
Threat actors have turned to cryptocurrency mining as a reliable way to make a profit in recent months. Cryptocurrency miners use the computing power of end users to mine coins of various kinds, most commonly via malware or compromised websites. By compromising servers in order to run cryptocurrency miners, the threat actors would gain ..
โโโ Dark Caracal: Good News and Bad News โโโ
Yesterday, EFF and Lookout announced a new report, Dark Caracal, that uncovers a new, global malware espionage campaign. One aspect of that campaign was the use of malicious, fake apps to impersonate legitimate popular apps like Signal and WhatsApp. Some readers had questions about what this means for them. This blog post is here to answer ..
โโโ DarkComet upload vulnerability โโโ
This post will introduce a file upload vulnerability in DarkCometโs C&C server. While a flaw that allows an attacker to download files has already been known for many years there is no mention of this very similar vulnerability. A quick disclaimer before we go into the actual matter: Hacking a C&C server might seem morally justified but it is still illegal. Donโt do it.
โโโ Zweiter Faktor: Nur wenige User sichern ihren Google-Account zusรคtzlich ab โโโ
Laut Google wird Zwei-Faktor-Authentifizierung gerade einmal von zehn Prozent alle Nutzer eingesetzt
โโโ 2018 ICS Security Predictions โโโ
We just closed another year in the ICS security industry, one filled with advanced (and exciting) product developments. We also saw an increased market awareness, with growing a emphasis on protecting industrial infrastructure.
โโโ Cryptocurrency Hacks and Heists in 2017 โโโ
The cryptocurrency rush took the world by storm last year. This dynamic environment lured new players, including hungry investors, miners, enthusiasts, looking to their hand at innovative startups not to mention threat actors. We witnessed blockchain splits, a boom of Initial Coin Offerings (ICOs), regulatory attempts by governments, the ..
= Vulnerabilities =
โโโ Google Forms <= 0.91 - Unauthenticated Server-Side Request Forgery (SSRF) โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Donnerstag 18-01-2018 18:00 โ Freitag 19-01-2018 18:00
Handler: Nina Bieringer
Co-Handler: Stephan Richter
= News =
โโโ Magento: Kreditkartendaten von bis zu 40.000 Oneplus-Kรคufern kopiert โโโ
Oneplus hat seine Untersuchung zu kopierten Kreditkarten abgeschlossen. Angreifer konnten wohl eine Schwachstelle fรผr Cross-Site-Scripting ausnutzen.
โโโ NCSC Releases Security Advisory โโโ
Original release date: January 18, 2018 The United Kingdoms National Cyber Security Centre (NCSC) has released a report updating its guidance on Turla Neuron malware, which provides a platform to steal sensitive data. NCSC provides enhanced cybersecurity services to protect against cybersecurity threats. NCCIC/US-CERT encourages users and administrators to review the NCSC advisory to access the report and for more information.
โโโ 2018: Vierfach-Jubilรคum fรผr รsterreichs Internet โโโ
Nicht nur die Republik begeht im heurigen Jahr mehrere Jahrestage, auch รsterreichs Internet hat 2018 mehrfachen Grund zu feiern: Vor genau dreiรig Jahren wurde die Internet-Endung .at ins weltweite Domain Name System eingetragen, 1998 wurden die Vergabestelle nic.at und die Online-Meldestelle Stopline ins Leben gerufen. Das CERT.at, รsterreichs nationales Computer Emergency Response Team, feiert 2018 seinen zehnten Geburtstag.
โโโ Militรคrs, Journalisten, Aktivisten: Libanesische Hacker vergaรen Daten auf offenem Server โโโ
Libanesischer Geheimdienst GDGS als Urheber des Leaks vermutet โ Betroffene aus รผber 20 Lรคndern
= Vulnerabilities =
โโโ Cisco Releases Security Updates โโโ
Original release date: January 17, 2018 | Last revised: January 18, 2018 Cisco has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit one of these vulnerabilities to take control of an affected system. NCCIC/US-CERT encourages users and administrators to review the following Cisco Security Advisories and apply the necessary updates: [...]
โโโ Filr 3.0 - Security Update 3 โโโ
Abstract: Security Update for Spectre and Meltdown vulnerabilities in Filr (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754).Document ID: 5360950Security Alert: YesDistribution Type: PublicEntitlement Required: YesFiles:readme_filr_3su3.txt (2.68 kB)Products:Filr 3 Standard EditionFilr 3 Advanced EditionSuperceded Patches: None
โโโ Filr 2.0 - Security Update 4 โโโ
Abstract: Security Update for Spectre and Meltdown vulnerabilities in Filr (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754).Document ID: 5360930Security Alert: YesDistribution Type: PublicEntitlement Required: YesFiles:Search- (157.55 MB)MySQL- (157.55 MB)Filr- (157.55 MB)Products:Filr 2Superceded Patches: None
โโโ Citrix XenServer Multiple Security Updates โโโ
Due to concerns about the robustness of some of the Intel microcode updates included in the earlier hotfixes for these issues (XS71ECU1009, XS72E013 and XS73E001), Citrix has superseded these hotfixes with new hotfixes listed below. Customers are strongly recommended to apply these new hotfixes.
โโโ Security updates for Friday โโโ
Security updates have been issued by Arch Linux (bind, irssi, nrpe, perl-xml-libxml, and transmission-cli), CentOS (java-1.8.0-openjdk), Debian (awstats, libgd2, mysql-5.5, rsync, smarty3, and transmission), Fedora (keycloak-httpd-client-install and rootsh), and Red Hat (java-1.7.0-oracle and java-1.8.0-oracle).
โโโ CPU Side-Channel Information Disclosure Vulnerabilities โโโ
โโโ DFN-CERT-2018-0136: Symantec Advanced Secure Gateway, ProxySG: Mehrere Schwachstellen ermรถglichen u.a. Cross-Site-Scripting-Angriffe โโโ
โโโ CPU hardware vulnerable to Meltdown and Spectre attacks โโโ
โโโ IBM Security Bulletin: IBM StoredIQ is affected by the vulnerabilities known as Spectre and Meltdown. โโโ
โโโ IBM Security Bulletin: Multiple Vulnerabilities in IBMยฎ Java SDK affects IBM WebSphere Application Server for IBM Cloud October 2017 CPU โโโ
โโโ IBM Security Bulletin: September 2016 OpenSSL Vulnerabilities affect Multiple N series Products โโโ
โโโ BIG-IP AFM vulnerability CVE-2017-6142 โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
= End-of-Day report =
Timeframe: Mittwoch 17-01-2018 18:00 โ Donnerstag 18-01-2018 18:00
Handler: Nina Bieringer
Co-Handler: Stephan Richter
= News =
โโโ How I exploited ACME TLS-SNI-01 issuing Lets Encrypt SSL-certs for any domain using shared hosting โโโ
TL;DR: I was able to issue SSL certificates I was not supposed to be able to. AWS CloudFront and Heroku were among the affected. The issue was in the specification of ACME TLS-SNI-01 in combination with shared hosting providers. To be clear, Letโs Encrypt only followed the specification, they did nothing wrong here. Quite the opposite I would say.
โโโ Some Basic Rules for Securing Your IoT Stuff โโโ
Most readers here have likely heard or read various prognostications about the impending doom from the proliferation of poorly-secured "Internet of Things" or IoT devices. Loosely defined as any gadget or gizmo that connects to the Internet but which most consumers probably wouldnt begin to know how to secure, IoT encompasses everything from security cameras, routers and digital video recorders to printers, wearable devices and "smart" lightbulbs. Throughout 2016 and 2017, [...]
= Vulnerabilities =
โโโ Meltdown and Spectre Vulnerabilities (Update B) โโโ
This updated alert is a follow-up to the updated alert titled ICS-ALERT-18-011-01A Meltdown and Spectre Vulnerabilities that was published January 16, 2018, on the NCCIC/ICS-CERT web site.
โโโ Citrix XenServer Multiple Security Updates โโโ
Due to concerns about the robustness of some of the Intel microcode updates included in the hotfixes below, Citrix recommends that customers ...
โโโ Security updates for Thursday โโโ
Security updates have been issued by CentOS (linux-firmware and microcode_ctl), Fedora (icecat and transmission), Oracle (java-1.8.0-openjdk and microcode_ctl), Red Hat (java-1.8.0-openjdk), Scientific Linux (java-1.8.0-openjdk), Slackware (bind), SUSE (kernel), and Ubuntu (eglibc).
โโโ Bugtraq: [security bulletin] HPESBMU03806 rev.1 - HPE IceWall Products, Multiple Remote Unauthorized Disclosure of Information, Unauthorized Modificiation โโโ
โโโ DFN-CERT-2018-0111: GitLab: Mehrere Schwachstellen ermรถglichen u.a. die Ausfรผhrung beliebigen Programmcodes โโโ
โโโ IBM Security Bulletin: Vulnerabilities in OpenSSL Affect IBM Sterling Connect:Direct for HP NonStop (CVE-2017-3736) โโโ
โโโ IBM Security Bulletin: Security Vulnerabilities in IBMยฎ Java SDK affects multiple IBM Rational products based on IBM Jazz technology โโโ
โโโ SSA-284673 (Last Update 2018-01-18): Vulnerability in Industrial Products โโโ
โโโ SSA-275839 (Last Update 2018-01-18): Denial-of-Service Vulnerability in Industrial Products โโโ
โโโ SSA-346262 (Last Update 2018-01-18): Denial-of-Service in Industrial Products โโโ
โโโ SSA-701708 (Last Update 2018-01-18): Local Privilege Escalation in Industrial Products โโโ
โโโ SSA-127490 (Last Update 2018-01-18): Vulnerabilities in SIMATIC WinCC Add-Ons โโโ
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily