=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 30-01-2018 18:00 โ Mittwoch 31-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
โโโ Microsoft Drops the Hammer on Coercive Registry Cleaners & System Optimizers โโโ
---------------------------------------------
Starting March 1st 2018, Windows Defender and other Microsoft products will begin to remove programs that display coercive behavior. This includes registry cleaners and system optimizers that offer free scans, display alarming messages, and then require the user to purchase it.before fixing anything.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-drops-the-hammer-โฆ
โโโ Google hat 2017 mehr als 700.000 bรถsartige Apps aus Google Play verbannt โโโ
---------------------------------------------
In einem Jahresbericht fรผhrt Google aus, wie sicher der eigene Android-App-Store Google Play doch ist. Aufgrund einiger Vorfรคlle wirkt die Argumentation stellenweise jedoch nicht ganz glaubwรผrdig.
---------------------------------------------
https://www.heise.de/meldung/Google-hat-2017-mehr-als-700-000-boesartige-Apโฆ
โโโ Kritische Sicherheitslรผcke in Mozilla Firefox - Patch verfรผgbar โโโ
---------------------------------------------
Mozilla hat einen Out-of-Band Patch fรผr eine kritische Sicherheitslรผcke im Webbrowser Firefox verรถffentlicht. Auswirkungen Durch Ausnรผtzen dieser Lรผcke kann ein Angreifer beliebigen Code auf betroffenen Systemen, mit den Rechten des angemeldeten Benutzers, ausfรผhren. Dazu reicht es, den Browser zum Anzeigen einer entsprechend prรคparierten Webseite ..
---------------------------------------------
http://www.cert.at/warnings/all/20180131.html
=====================
= Vulnerabilities =
=====================
โโโ DSA-4102 thunderbird - security update โโโ
---------------------------------------------
https://www.debian.org/security/2018/dsa-4102
โโโ PHOENIX CONTACT mGuard โโโ
---------------------------------------------
https://ics-cert.us-cert.gov/advisories/ICSA-18-030-01
โโโ Siemens TeleControl Server Basic โโโ
---------------------------------------------
https://ics-cert.us-cert.gov/advisories/ICSA-18-030-02
โโโ WordPress plugin "WP Retina 2x" vulnerable to cross-site scripting โโโ
---------------------------------------------
http://jvn.jp/en/jp/JVN30636823/
โโโ Multiple Vulnerabilities in Sprecher Automation SPRECON-E-C, PU-2433 โโโ
---------------------------------------------
https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-โฆ
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Montag 29-01-2018 18:00 โ Dienstag 30-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
โโโ IBM-Studie: Viele Nutzer halten biometrische Anmeldung fรผr sicher โโโ
---------------------------------------------
Gerade junge Leute wollen sich heutzutage keine Passwรถrter mehr merken: Eine IBM-Studie untersucht Vorlieben von Nutzern aller Altersgruppen. Teilnehmer ab 55 Jahren hingegen merken sich viele verschiedene Passwรถrter auf einmal - auch ohne Passwort-Manager.
---------------------------------------------
https://www.golem.de/news/ibm-studie-viele-nutzer-halten-biometrische-anmelโฆ
โโโ Scammers become the scammed: Ransomware payments diverted with Tor proxy trickery โโโ
---------------------------------------------
Of course this does nothing for victims encrypted files Cybercriminals are using Tor proxies to divert ransomware payments to their own Bitcoin wallets.
---------------------------------------------
theregister.com/feed/www.theregister.co.uk/2018/01/30/ransomware_diversions/
โโโ Chrome Extension Malware Has Evolved โโโ
---------------------------------------------
While helpful and creative, Chrome extensions have also become a new playground for hackers intent on stealing your data.
---------------------------------------------
https://www.wired.com/story/chrome-extension-malware
โโโ ENISA organises cyber-exercise to boost CSIRT cooperation โโโ
---------------------------------------------
On 30 January 2018, the EU Cybersecurity Agency ENISA organised โCyber SOPExโ, the first cooperation exercise of the CSIRTs Network.
---------------------------------------------
https://www.enisa.europa.eu/news/enisa-news/enisa-organises-cyber-exercise-โฆ
โโโ E-Mail-Betrug: Vorarlberger Firma zahlt 150.000 Euro โโโ
---------------------------------------------
Mitarbeiterin รผberwies knapp 150.000 Euro ins Ausland โ 83.000 Euro konnten zurรผckgeholt werden
---------------------------------------------
http://derstandard.at/2000073288109
โโโ "spotzi" und "bier1": Cybasar-Leak zeigt die unsicheren Passwรถrter der รsterreicher โโโ
---------------------------------------------
Viele Kennwรถrter offenbaren fahrlรคssigen Umgang mit eigenen Informationen im Netz โ auch von Behรถrdenmitarbeitern
---------------------------------------------
http://derstandard.at/2000073316365
โโโ 2017 in Snort Signatures. โโโ
---------------------------------------------
This post was written by Martin Lee and Vanja Svajcer.2017 was an eventful year for cyber security with high profile vulnerabilities that allowed self-replicating worm attacks such as WannaCry and BadRabbit to impact ..
---------------------------------------------
http://blog.talosintelligence.com/2018/01/2017-in-snort-signatures.html
โโโ Kritische Sicherheitslรผcke in Cisco ASA Software - Patches verfรผgbar โโโ
---------------------------------------------
Cisco hat ein Advisory zu einer kritischen Sicherheitslรผcke in Cisco ASA Software verรถffentlicht. Die Lรผcke befindet sich im Code, der fรผr das "webvpn"-Feature zustรคndig ..
---------------------------------------------
http://www.cert.at/warnings/all/20180130.html
=====================
= Vulnerabilities =
=====================
โโโ [20180103] - Core - XSS vulnerability in Uri class โโโ
---------------------------------------------
https://developer.joomla.org/security-centre/721-20180103-core-xss-vulnerabโฆ
โโโ [20180102] - Core - XSS vulnerability in com_fields โโโ
---------------------------------------------
https://developer.joomla.org/security-centre/720-20180102-core-xss-vulnerabโฆ
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 26-01-2018 18:00 โ Montag 29-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: Nina Bieringer
=====================
= News =
=====================
โโโ Cyberattacken auf niederlรคndische Banken: Netbanking weg โโโ
---------------------------------------------
Die drei grรถรten Banken der Niederlande hatten am Wochenende mit Cyberangriffen zu kรคmpfen. Teilweise fiel auch das Online-Banking aus.
---------------------------------------------
https://futurezone.at/digital-life/cyberattacken-auf-niederlaendische-bankeโฆ
โโโ Coincheck: Kryptowรคhrung im Wert von 429 Millionen Euro gestohlen โโโ
---------------------------------------------
Fรผr das Unternehmen Coincheck war es ein schwarzer Freitag: Eine groรe Menge der Kryptowรคhrung NEM wurde gestohlen. Der Kurs sank dadurch um elf Prozent. Auch Bitcoin und Etherium waren davon betroffen. Der Angriff ist fรผr einige ein Anlass zur Kritik an Japans Regulierung des Kryptohandels.
---------------------------------------------
https://www.golem.de/news/coincheck-kryptowaehrung-im-wert-von-429-milliardโฆ
โโโ Security: Lenovo gesteht Sicherheitslรผcken im Fingerprint Manager ein โโโ
---------------------------------------------
Die Software Fingerprint Manager Pro speichert biometrische Daten auf dem Gerรคt. Allerdings sagt selbst Lenovo, dass das unsicher sei und rรคt daher zu einem Update. Windows-10-Gerรคte sind davon jedoch nicht betroffen.
---------------------------------------------
https://www.golem.de/news/security-lenovo-gesteht-sicherheitsluecken-im-finโฆ
โโโ Meltdown & Spectre: Windows-Update deaktiviert Schutz gegen Spectre V2 โโโ
---------------------------------------------
Ein aktuelles Windows-Update schaltet den Schutz gegen Spectre Variant 2 ab, um Instabilitรคten des Systems vorzubeugen.
---------------------------------------------
https://www.heise.de/newsticker/meldung/Meltdown-Spectre-Windows-Update-deaโฆ
โโโ First 'Jackpotting' Attacks Hit U.S. ATMs โโโ
---------------------------------------------
ATM "jackpotting" - a sophisticated crime in which thieves install malicious software and/or hardware at ATMs that forces the machines to spit out huge volumes of cash on demand - has long been a threat for banks in Europe and Asia, yet these attacks somehow have eluded U.S. ATM operators. But all that changed this week after the U.S. Secret Service quietly began warning financial institutions that jackpotting attacks have now been spotted targeting cash machines here in the United [...]
---------------------------------------------
https://krebsonsecurity.com/2018/01/first-jackpotting-attacks-hit-u-s-atms/
โโโ Cybasar.at gehackt: 70.000 รถsterreichische Log-ins im Netz aufgetaucht โโโ
---------------------------------------------
Hunderte E-Mails und Passwรถrter von offiziellen Stellen enthalten โ Daten stammen von Gebrauchtwagenplattform Cybasar
---------------------------------------------
http://derstandard.at/2000073253135
=====================
= Vulnerabilities =
=====================
โโโ DSA-4099 ffmpeg - security update โโโ
---------------------------------------------
Several vulnerabilities have been discovered in the FFmpeg multimediaframework, which could result in denial of service or potentially theexecution of arbitrary code if malformed files/streams are processed.
---------------------------------------------
https://www.debian.org/security/2018/dsa-4099
โโโ DSA-4101 wireshark - security update โโโ
---------------------------------------------
It was discovered that wireshark, a network protocol analyzer, containedseveral vulnerabilities in the dissectors/file parsers for IxVeriWave,WCP, JSON, XML, NTP, XMPP and GDB, which could result in denial ofservice or the execution of arbitrary code.
---------------------------------------------
https://www.debian.org/security/2018/dsa-4101
โโโ DFN-CERT-2018-0020 โโโ
---------------------------------------------
Auf diesem Wege noch einmal der Hinweis, dass wir unsere Security Advisories zu #Spectre und #Meltdown (DFN-CERT-2018-0020) sowie Spectre 2 (DFN-CERT-2018-0019) beinahe tรคglich aktualisieren. Bleiben Sie via @DFNCERT_ADV auf dem neuesten Stand.
---------------------------------------------
https://twitter.com/DFNCERT/status/956906148388536321
โโโ DFN-CERT-2018-0196: VMware AirWatch Console (AWC): Eine Schwachstelle ermรถglicht einen Cross-Site-Request-Forgery-Angriff โโโ
---------------------------------------------
https://portal.cert.dfn.de/adv/DFN-CERT-2018-0196/
โโโ Security Advisory - Buffer Overflow Vulnerability in the Bluetooth Module of Some Huawei Mobile Phones โโโ
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180129-โฆ
โโโ IBM Security Bulletin: IBM has released AIX and VIOS iFixes in response to the vulnerabilities known as Spectre and Meltdown โโโ
---------------------------------------------
http://aix.software.ibm.com/aix/efixes/security/spectre_meltdown_advisory.aโฆ
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Security SiteProtector System โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012707
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 24-01-2018 18:00 โ Donnerstag 25-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: Nina Bieringer
=====================
= News =
=====================
โโโ Maersk Reinstalled 45,000 PCs and 4,000 Servers to Recover From NotPetya Attack โโโ
---------------------------------------------
The worlds largest container shipping company รขโฌโA.P. Mรยธller-Maerskรขโฌโ said it recovered from the NotPetya ransomware incident by reinstalling over 4,000 servers, 45,000 PCs, and 2500 applications over the course of ten days in late June and early July 2017. [...]
---------------------------------------------
https://www.bleepingcomputer.com/news/security/maersk-reinstalled-45-000-pcโฆ
โโโ BSI-Richtlinie: Der streng geheime Streit รผber die Routersicherheit โโโ
---------------------------------------------
Das BSI will in den kommenden Monaten eine Technische Richtlinie fรผr Heimrouter herausgeben. Vor allem die Kabelnetzbetreiber halten nichts davon, fรผr mรถglichst viel Sicherheit bei den Gerรคten zu sorgen. Der CCC spricht von "Lobbying-Sabotage".
---------------------------------------------
https://www.golem.de/news/bsi-richtlinie-der-streng-geheime-streit-ueber-diโฆ
โโโ Windows 10: Microsoft will aufzeigen, was an Gerรคtedaten gesammelt wird โโโ
---------------------------------------------
Sprachdaten, Positionsdaten und Browserverlauf: Nutzer sollen kรผnftig einen besseren รberblick รผber gesammelte Daten in Windows 10 bekommen. Dazu stellt Microsoft ein Dashboard fรผr Microsoft-Accounts und einen Diagnostic Viewer fรผr Gerรคteinformation zur Verfรผgung. (Microsoft, Datenschutz)
---------------------------------------------
https://www.golem.de/news/windows-10-microsoft-will-aufzeigen-was-an-geraetโฆ
โโโ Cloudflare[.]solutions Keylogger Returns on New Domains โโโ
---------------------------------------------
A few months ago, we covered two injections related to the โcloudflare.solutionsโ malware: a CoinHive cryptominer hidden within fake Google Analytics and jQuery, and the WordPress keylogger from Cloudflare[.]solutions. This malware was originally identified by one of our analysts in April 2017 and has since evolved and spread to new domains. Keylogger Spreads to New Domains A few days after our keylogger post was released on Dec 8th, 2017, the Cloudflare[.]solutions domain was taken [...]
---------------------------------------------
https://blog.sucuri.net/2018/01/cloudflare-solutions-keylogger-returns-on-nโฆ
โโโ libcurl has had auth leak bug since the first commit we recorded โโโ
---------------------------------------------
Fixed in 7.58.0 If you use libcurl, the command line tool and library for transferring data with URLs, get ready to patch. The tool has a pair of problems, one of which is an authentication leak.โฆ
---------------------------------------------
http://go.theregister.com/feed/www.theregister.co.uk/2018/01/25/curl_carrieโฆ
โโโ Healthcare CERTs highlight the need for security guidance for specific sectors โโโ
---------------------------------------------
A new computer emergency response team has been launched in the Netherlands to provide guidance specifically tailored to the healthcare sector. Martijn Grooten welcomes the development. Read more
---------------------------------------------
https://www.virusbulletin.com:443/blog/2018/01/healthcare-certs-show-need-sโฆ
โโโ Announcing turndown of the deprecated Google Safe Browsing APIs โโโ
---------------------------------------------
Posted by Alex Wozniak, Software Engineer, Safe Browsing TeamIn May 2016, we introduced the latest version of the Google Safe Browsing API (v4). Since this launch, thousands of developers around the world have adopted the API to protect over 3 billion devices from unsafe web resources.Coupled with that announcement was the deprecation of legacy Safe Browsing APIs, v2 and v3. Today we are announcing an official turn-down date of October 1st, 2018, for these APIs. All v2 and v3 clients must [...]
---------------------------------------------
https://security.googleblog.com/2018/01/announcing-turndown-of-deprecated.hโฆ
=====================
= Vulnerabilities =
=====================
โโโ DSA-4096 firefox-esr - security update โโโ
---------------------------------------------
Several security issues have been found in the Mozilla Firefox webbrowser: Multiple memory safety errors, use-after-frees, integeroverflows and other implementation errors may lead to the execution ofarbitrary code, denial of service or URL spoofing.
---------------------------------------------
https://www.debian.org/security/2018/dsa-4096
โโโ Vulnerability Spotlight: Multiple Unpatched Vulnerabilities in Blender Identified โโโ
---------------------------------------------
Update 1/25/18: Blender has released version 2.79a to address these issues
Technology has evolved in incredible ways that has helped people to create and visualize media like never before. Today, people can use tools such as Blender to visualize, model, and animate 3D content, especially since its free and open-source software. However, this also make it an attractive target for adversaries to audit and find vulnerabilities. Given the user base of Blender, exploiting these vulnerabilities to [...]
---------------------------------------------
http://blog.talosintelligence.com/2018/01/unpatched-blender-vulns.html
โโโ DFN-CERT-2018-0177: Google Chrome, Chromium: Mehrere Schwachstellen ermรถglichen u.a. die Ausfรผhrung beliebigen Programmcodes โโโ
---------------------------------------------
https://portal.cert.dfn.de/adv/DFN-CERT-2018-0177/
โโโ IBM Security Bulletin: PowerKVM has released fixes in response to the vulnerabilities known as Spectre and Meltdown. โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1026853
โโโ IBM Security Bulletin: Vulnerabilities in postgresql affect PowerKVM โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1026733
โโโ IBM Security Bulletin: Vulnerabilities in PHP affect PowerKVM โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1026732
โโโ IBM Security Bulletin: A vulnerability in Apache Portable Runtime affects PowerKVM โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1026735
โโโ IBM Security Bulletin: A vulnerability in procmail affects PowerKVM โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1026736
โโโ IBM Security Bulletin: A vulnerability in curl affects PowerKVM โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1026734
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Tivoli Netcool Impact โโโ
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=swg22012767
โโโ IBM Security Bulletin: Vulnerabilities in the Linux kernel affect PowerKVM โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1026731
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect IBM Tivoli Netcool Configuration Manager (ITNCM) โโโ
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=swg22007398
โโโ IBM Security Bulletin: Rational DOORS is affected by multiple vulnerabilities โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012789
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 23-01-2018 18:00 โ Mittwoch 24-01-2018 18:00
Handler: Robert Waldner
Co-Handler: Stephan Richter
=====================
= News =
=====================
โโโ Skype, Signal, Slack, other apps inherit Electron vuln โโโ
---------------------------------------------
If youve built a Windows application on Electron, check to see if its subject to a just-announced remote code execution vulnerability. ... Slack users should update to version 3.0.3 or better, and the latest version of Skype for Windows is protected
---------------------------------------------
https://www.theregister.co.uk/2018/01/24/skype_signal_slack_nherit_electronโฆ
โโโ [papers] Hardcore SAP Penetration Testing โโโ
---------------------------------------------
http://www.exploit-db.com/docs/english/43859-hardcore-sap-penetration-testiโฆ
โโโ 14 flaws found that could take over industrial control systems โโโ
---------------------------------------------
Licence management systems used in industrial control systems are plagued with vulnerabilities - contain 14 flaws could enable hackers to take control of systems and carry out DoS attacks
---------------------------------------------
https://www.scmagazineuk.com/news/14-flaws-found-that-could-take-over-indusโฆ
=====================
= Vulnerabilities =
=====================
โโโ Advantech WebAccess/SCADA โโโ
---------------------------------------------
This advisory contains mitigation details for path traversal and SQL injection vulnerabilities in Advantechโs WebAccess/SCADA software platform.
---------------------------------------------
https://ics-cert.us-cert.gov/advisories/ICSA-18-023-01
โโโ Security updates for Tuesday โโโ
---------------------------------------------
Security updates have been issued by Debian (smarty3), Fedora (bind, bind-dyndb-ldap, dnsperf, glibc, kernel, libtasn1, libvpx, mariadb, python-bottle, ruby, and sox), Red Hat (rh-eclipse46-jackson-databind), SUSE (kernel), and Ubuntu (kernel, linux, linux-aws, linux-euclid, linux-hwe, linux-azure, linux-gcp, linux-oem, linux-lts-trusty, linux-lts-xenial, linux-aws, and rsync).
---------------------------------------------
https://lwn.net/Articles/745165/rss
โโโ Apple Updates Everything, Again, (Tue, Jan 23rd) โโโ
---------------------------------------------
https://isc.sans.edu/diary/rss/23269
โโโ Vuln: GIMP CVE-2017-17786 Heap Buffer Overflow Vulnerability โโโ
---------------------------------------------
http://www.securityfocus.com/bid/102765
โโโ Security Advisory - Memory Leak Vulnerability in Some Huawei Products โโโ
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20180124-โฆ
โโโ Security Advisory - Two Vulnerabilities in MGCP Protocol of Some Huawei Products โโโ
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180124-โฆ
โโโ Security Advisory - Integer Overflow Vulnerability on Smartphones โโโ
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180124-โฆ
โโโ Security Advisory - DoS Vulnerability in Some Huawei Products โโโ
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180124-โฆ
โโโ Security Advisory - CPU Vulnerabilities Meltdown and Spectre โโโ
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20180106-โฆ
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect Content Collector for Email, Content Collector for File Systems, Content Collector for Microsoft SharePoint and Content Collector for IBM Connections โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012739
โโโ IBM Security Bulletin: Cross-site scripting vulnerability in IBM Jazz Team Server affect IBM Rational products based on IBM Jazz technology โโโ
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=swg22012712
โโโ IBM Security Bulletin: Content Collector for Email is affected by vulnerability due to information disclosure in MyFaces for WebSphere Application Server โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012737
โโโ IBM Security Bulletin: Content Collector for Email is affected by vulnerability due to information disclosure in Apache MyFaces โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012735
โโโ IBM Security Bulletin: Multiple Security Vulnerabilities exist in IBM Cognos TM1 โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012623
โโโ IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Cognos Insight. โโโ
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=swg22012627
โโโ SSA-824231 (Last Update 2018-01-24): Unauthenticated Firmware Upload Vulnerability in Desigo PXC โโโ
---------------------------------------------
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-824231โฆ
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Montag 22-01-2018 18:00 โ Dienstag 23-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
โโโ Newsletter-Dienst: Mailchimp verrรคt E-Mail-Adressen von Newsletter-Abonnenten โโโ
---------------------------------------------
Spezifische Referrer fรผr jeden Newsletter-Nutzer haben dazu gefรผhrt, dass Webseitenbetreiber die E-Mail-Adressen von Mailchimp-Nutzern herausfinden konnten. Das Problem wurde nach Meldung an den Anbieter mittlerweile behoben.
---------------------------------------------
https://www.golem.de/news/newsletter-dienst-mailchimp-verraet-e-mail-adressโฆ
โโโ Just Keep Swimming: How to Avoid Phishing on Social Media โโโ
---------------------------------------------
>From Facebook to LinkedIn, social media is flat-out rife with phishing attacks. Youโve probably encountered one beforeโฆ Do fake Oakley sunglasses sales ring a bell? Phishing attacks attempt to steal ..
---------------------------------------------
https://www.webroot.com/blog/2018/01/22/how-to-avoid-phishing-social-media/
โโโ "MaMi": MacOS-Malware hรถrt User ab und manipuliert Datenverkehr โโโ
---------------------------------------------
Schรคdling leitet Traffic รผber von Unbekannten kontrollierte DNS-Server um
---------------------------------------------
http://derstandard.at/2000072382780
โโโ Millionen PCs verwundbar: Forscher deckt Lรผcke in allen Blizzard-Games auf โโโ
---------------------------------------------
Konzern arbeitet bereits an Lรถsung โ Problem bei Client
---------------------------------------------
http://derstandard.at/2000072835431
โโโ Achtung: Whatsapp Abo-Betrug kursiert derzeit per Mail โโโ
---------------------------------------------
"Konto ist abgelaufen" โ ehemaliges Abomodell von Whatsapp wird instrumentalisiert um Kreditkartendaten zu ergattern
---------------------------------------------
http://derstandard.at/2000072831670
โโโ SamSam - The Evolution Continues Netting Over $325,000 in 4 Weeks โโโ
---------------------------------------------
This post was written by Vitor VenturaIntroductionTalos has been working in conjunction with Cisco IR Services on what we believe to be a new variant of the SamSam ransomware. This ransomware has been observed across multiple industries including Government, Healthcare and ICS. These attacks do not appear to be highly targeted, and appear to be more opportunistic in nature.Given SamSams victimology, its impacts are not just felt within the business world, they are also impacting people,
---------------------------------------------
http://blog.talosintelligence.com/2018/01/samsam-evolution-continues-nettinโฆ
=====================
= Vulnerabilities =
=====================
โโโ HTTP Host header attacks against web proxy disclaimer response webpage โโโ
---------------------------------------------
The FortiOS web proxy disclaimer page is potentially vulnerable to an XSS attack, via maliciously crafted "Host" headers in user HTTP requests. The latter is possible if an attacker is in a Man-in-the-middle position (i.e. able to modify the HTTP requests of the potential victim before they reach the web proxy), or poisons a web cache used by the potential victim.In the latter attack scenario, the tainted disclaimer web page being cached, the XSS attack can be considered as persistent.
---------------------------------------------
http://fortiguard.com/psirt/FG-IR-17-262
โโโ VMSA-2018-0002.3 โโโ
---------------------------------------------
VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
---------------------------------------------
https://www.vmware.com/security/advisories/VMSA-2018-0002.html
โโโ JSA10836 - 2018-01 Security Bulletin: SRX Series: Firewall bypass vulnerability when UUID with leading zeros is configured. (CVE-2018-0009) โโโ
---------------------------------------------
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10836
โโโ XXE & Reflected XSS in Oracle Financial Services Analytical Applications โโโ
---------------------------------------------
https://www.sec-consult.com/en/blog/advisories/xxe-reflected-xss-in-oracle-โฆ
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 19-01-2018 18:00 โ Montag 22-01-2018 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
โโโ Hacker One: Nur 20 Prozent der Bounty-Jรคger hacken in Vollzeit โโโ
---------------------------------------------
Das US-Unternehmen Hacker One hat aktuelle Zahlen vorgestellt: Die meisten Bounties werden nach wie vor von US-Unternehmen gezahlt. Die Daten zeigen auรerdem, dass das Finden von Schwachstellen fรผr die meisten ein Nebenberuf oder Hobby ist.
---------------------------------------------
https://www.golem.de/news/hacker-one-nur-20-prozent-der-bounty-jaeger-hackeโฆ
โโโ Powerful Skygofree Spyware Was Already Reported and Analyzed In 2017 โโโ
---------------------------------------------
The Skygofree spyware analyzed by Kaspersky today was first spotted by the researcher Lukas Stefanko and the first analysis was published last year by the experts of CSE Cybsec ZLab. The Skygofree ..
---------------------------------------------
http://resources.infosecinstitute.com/powerful-skygofree-spyware-already-reโฆ
โโโ Apple Preps ChaiOS iMessage Bug Fix, Report โโโ
---------------------------------------------
A so-called โtext bombโ flaw in Appleโs iPhone and Mac computers that causes devices to crash or restart will be patched next week, according to multiple sources.
---------------------------------------------
http://threatpost.com/apple-preps-chaios-imessage-bug-fix-report/129544/
โโโ Followup to IPv6 brute force and IPv6 blocking โโโ
---------------------------------------------
My diary earlier this week led to some good discussion in the comments and on twitter. I want to, first off, apologize for not responding as much or as quickly as I would have liked, I&#;x26;#;39;ve actually been ill most of this week since posting the previous diary (and signing up for this slot as handler on duty). Having said that, ..
---------------------------------------------
https://isc.sans.edu/diary/23253
โโโ Struts and DotNetNuke Server Exploits Used For Cryptocurrency Mining โโโ
---------------------------------------------
Threat actors have turned to cryptocurrency mining as a reliable way to make a profit in recent months. Cryptocurrency miners use the computing power of end users to mine coins of various kinds, most commonly via malware or compromised websites. By compromising servers in order to run cryptocurrency miners, the threat actors would gain ..
---------------------------------------------
https://blog.trendmicro.com/trendlabs-security-intelligence/struts-dotnetnuโฆ
โโโ Dark Caracal: Good News and Bad News โโโ
---------------------------------------------
Yesterday, EFF and Lookout announced a new report, Dark Caracal, that uncovers a new, global malware espionage campaign. One aspect of that campaign was the use of malicious, fake apps to impersonate legitimate popular apps like Signal and WhatsApp. Some readers had questions about what this means for them. This blog post is here to answer ..
---------------------------------------------
https://www.eff.org/deeplinks/2018/01/dark-caracal-good-news-and-bad-news
โโโ DarkComet upload vulnerability โโโ
---------------------------------------------
This post will introduce a file upload vulnerability in DarkCometโs C&C server. While a flaw that allows an attacker to download files has already been known for many years there is no mention of this very similar vulnerability. A quick disclaimer before we go into the actual matter: Hacking a C&C server might seem morally justified but it is still illegal. Donโt do it.
---------------------------------------------
https://pseudolaboratories.github.io/DarkComet-upload-vulnerability/
โโโ Zweiter Faktor: Nur wenige User sichern ihren Google-Account zusรคtzlich ab โโโ
---------------------------------------------
Laut Google wird Zwei-Faktor-Authentifizierung gerade einmal von zehn Prozent alle Nutzer eingesetzt
---------------------------------------------
http://derstandard.at/2000072757014
โโโ 2018 ICS Security Predictions โโโ
---------------------------------------------
We just closed another year in the ICS security industry, one filled with advanced (and exciting) product developments. We also saw an increased market awareness, with growing a emphasis on protecting industrial infrastructure.
---------------------------------------------
https://www.bayshorenetworks.com/blog/ics-security-2018-predictions
โโโ Cryptocurrency Hacks and Heists in 2017 โโโ
---------------------------------------------
The cryptocurrency rush took the world by storm last year. This dynamic environment lured new players, including hungry investors, miners, enthusiasts, looking to their hand at innovative startups not to mention threat actors. We witnessed blockchain splits, a boom of Initial Coin Offerings (ICOs), regulatory attempts by governments, the ..
---------------------------------------------
https://www.tripwire.com/state-of-security/security-data-protection/cyber-sโฆ
=====================
= Vulnerabilities =
=====================
โโโ Google Forms <= 0.91 - Unauthenticated Server-Side Request Forgery (SSRF) โโโ
---------------------------------------------
https://wpvulndb.com/vulnerabilities/9013
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 18-01-2018 18:00 โ Freitag 19-01-2018 18:00
Handler: Nina Bieringer
Co-Handler: Stephan Richter
=====================
= News =
=====================
โโโ Magento: Kreditkartendaten von bis zu 40.000 Oneplus-Kรคufern kopiert โโโ
---------------------------------------------
Oneplus hat seine Untersuchung zu kopierten Kreditkarten abgeschlossen. Angreifer konnten wohl eine Schwachstelle fรผr Cross-Site-Scripting ausnutzen.
---------------------------------------------
https://www.golem.de/news/magento-kreditkartendaten-von-bis-zu-40-000-oneplโฆ
โโโ NCSC Releases Security Advisory โโโ
---------------------------------------------
Original release date: January 18, 2018 The United Kingdoms National Cyber Security Centre (NCSC) has released a report updating its guidance on Turla Neuron malware, which provides a platform to steal sensitive data. NCSC provides enhanced cybersecurity services to protect against cybersecurity threats. NCCIC/US-CERT encourages users and administrators to review the NCSC advisory to access the report and for more information.
---------------------------------------------
https://www.us-cert.gov/ncas/current-activity/2018/01/18/NCSC-Releases-Secuโฆ
โโโ 2018: Vierfach-Jubilรคum fรผr รsterreichs Internet โโโ
---------------------------------------------
Nicht nur die Republik begeht im heurigen Jahr mehrere Jahrestage, auch รsterreichs Internet hat 2018 mehrfachen Grund zu feiern: Vor genau dreiรig Jahren wurde die Internet-Endung .at ins weltweite Domain Name System eingetragen, 1998 wurden die Vergabestelle nic.at und die Online-Meldestelle Stopline ins Leben gerufen. Das CERT.at, รsterreichs nationales Computer Emergency Response Team, feiert 2018 seinen zehnten Geburtstag.
---------------------------------------------
https://www.nic.at/de/news/pressemeldungen/2018-vierfach-jubilaum-fur-osterโฆ
โโโ Militรคrs, Journalisten, Aktivisten: Libanesische Hacker vergaรen Daten auf offenem Server โโโ
---------------------------------------------
Libanesischer Geheimdienst GDGS als Urheber des Leaks vermutet โ Betroffene aus รผber 20 Lรคndern
---------------------------------------------
http://derstandard.at/2000072593892
=====================
= Vulnerabilities =
=====================
โโโ Cisco Releases Security Updates โโโ
---------------------------------------------
Original release date: January 17, 2018 | Last revised: January 18, 2018 Cisco has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit one of these vulnerabilities to take control of an affected system. NCCIC/US-CERT encourages users and administrators to review the following Cisco Security Advisories and apply the necessary updates: [...]
---------------------------------------------
https://www.us-cert.gov/ncas/current-activity/2018/01/17/Cisco-Releases-Secโฆ
โโโ Filr 3.0 - Security Update 3 โโโ
---------------------------------------------
Abstract: Security Update for Spectre and Meltdown vulnerabilities in Filr (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754).Document ID: 5360950Security Alert: YesDistribution Type: PublicEntitlement Required: YesFiles:readme_filr_3su3.txt (2.68 kB)Products:Filr 3 Standard EditionFilr 3 Advanced EditionSuperceded Patches: None
---------------------------------------------
https://download.novell.com/Download?buildid=4_X7yeGlMKg~
โโโ Filr 2.0 - Security Update 4 โโโ
---------------------------------------------
Abstract: Security Update for Spectre and Meltdown vulnerabilities in Filr (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754).Document ID: 5360930Security Alert: YesDistribution Type: PublicEntitlement Required: YesFiles:Search-2.0.0.423.HP.zip (157.55 MB)MySQL-2.0.0.205.HP.zip (157.55 MB)Filr-2.0.0.494.HP.zip (157.55 MB)Products:Filr 2Superceded Patches: None
---------------------------------------------
https://download.novell.com/Download?buildid=h0wMCm1OqIU~
โโโ Citrix XenServer Multiple Security Updates โโโ
---------------------------------------------
Due to concerns about the robustness of some of the Intel microcode updates included in the earlier hotfixes for these issues (XS71ECU1009, XS72E013 and XS73E001), Citrix has superseded these hotfixes with new hotfixes listed below. Customers are strongly recommended to apply these new hotfixes.
---------------------------------------------
https://support.citrix.com/article/CTX231390
โโโ Security updates for Friday โโโ
---------------------------------------------
Security updates have been issued by Arch Linux (bind, irssi, nrpe, perl-xml-libxml, and transmission-cli), CentOS (java-1.8.0-openjdk), Debian (awstats, libgd2, mysql-5.5, rsync, smarty3, and transmission), Fedora (keycloak-httpd-client-install and rootsh), and Red Hat (java-1.7.0-oracle and java-1.8.0-oracle).
---------------------------------------------
https://lwn.net/Articles/744791/rss
โโโ CPU Side-Channel Information Disclosure Vulnerabilities โโโ
---------------------------------------------
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/ciscoโฆ
โโโ DFN-CERT-2018-0136: Symantec Advanced Secure Gateway, ProxySG: Mehrere Schwachstellen ermรถglichen u.a. Cross-Site-Scripting-Angriffe โโโ
---------------------------------------------
https://portal.cert.dfn.de/adv/DFN-CERT-2018-0136/
โโโ CPU hardware vulnerable to Meltdown and Spectre attacks โโโ
---------------------------------------------
http://fortiguard.com/psirt/FG-IR-18-002
โโโ IBM Security Bulletin: IBM StoredIQ is affected by the vulnerabilities known as Spectre and Meltdown. โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012718
โโโ IBM Security Bulletin: Multiple Vulnerabilities in IBMยฎ Java SDK affects IBM WebSphere Application Server for IBM Cloud October 2017 CPU โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22011913
โโโ IBM Security Bulletin: September 2016 OpenSSL Vulnerabilities affect Multiple N series Products โโโ
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1010852
โโโ BIG-IP AFM vulnerability CVE-2017-6142 โโโ
---------------------------------------------
https://support.f5.com/csp/article/K20682450
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 17-01-2018 18:00 โ Donnerstag 18-01-2018 18:00
Handler: Nina Bieringer
Co-Handler: Stephan Richter
=====================
= News =
=====================
โโโ How I exploited ACME TLS-SNI-01 issuing Lets Encrypt SSL-certs for any domain using shared hosting โโโ
---------------------------------------------
TL;DR: I was able to issue SSL certificates I was not supposed to be able to. AWS CloudFront and Heroku were among the affected. The issue was in the specification of ACME TLS-SNI-01 in combination with shared hosting providers. To be clear, Letโs Encrypt only followed the specification, they did nothing wrong here. Quite the opposite I would say.
---------------------------------------------
https://labs.detectify.com/2018/01/12/how-i-exploited-acme-tls-sni-01-issuiโฆ
โโโ Some Basic Rules for Securing Your IoT Stuff โโโ
---------------------------------------------
Most readers here have likely heard or read various prognostications about the impending doom from the proliferation of poorly-secured "Internet of Things" or IoT devices. Loosely defined as any gadget or gizmo that connects to the Internet but which most consumers probably wouldnt begin to know how to secure, IoT encompasses everything from security cameras, routers and digital video recorders to printers, wearable devices and "smart" lightbulbs. Throughout 2016 and 2017, [...]
---------------------------------------------
https://krebsonsecurity.com/2018/01/some-basic-rules-for-securing-your-iot-โฆ
=====================
= Vulnerabilities =
=====================
โโโ Meltdown and Spectre Vulnerabilities (Update B) โโโ
---------------------------------------------
This updated alert is a follow-up to the updated alert titled ICS-ALERT-18-011-01A Meltdown and Spectre Vulnerabilities that was published January 16, 2018, on the NCCIC/ICS-CERT web site.
---------------------------------------------
https://ics-cert.us-cert.gov/alerts/ICS-ALERT-18-011-01B
โโโ Citrix XenServer Multiple Security Updates โโโ
---------------------------------------------
Due to concerns about the robustness of some of the Intel microcode updates included in the hotfixes below, Citrix recommends that customers ...
---------------------------------------------
https://support.citrix.com/article/CTX231390
โโโ Security updates for Thursday โโโ
---------------------------------------------
Security updates have been issued by CentOS (linux-firmware and microcode_ctl), Fedora (icecat and transmission), Oracle (java-1.8.0-openjdk and microcode_ctl), Red Hat (java-1.8.0-openjdk), Scientific Linux (java-1.8.0-openjdk), Slackware (bind), SUSE (kernel), and Ubuntu (eglibc).
---------------------------------------------
https://lwn.net/Articles/744713/rss
โโโ Bugtraq: [security bulletin] HPESBMU03806 rev.1 - HPE IceWall Products, Multiple Remote Unauthorized Disclosure of Information, Unauthorized Modificiation โโโ
---------------------------------------------
http://www.securityfocus.com/archive/1/541694
โโโ DFN-CERT-2018-0111: GitLab: Mehrere Schwachstellen ermรถglichen u.a. die Ausfรผhrung beliebigen Programmcodes โโโ
---------------------------------------------
https://portal.cert.dfn.de/adv/DFN-CERT-2018-0111/
โโโ IBM Security Bulletin: Vulnerabilities in OpenSSL Affect IBM Sterling Connect:Direct for HP NonStop (CVE-2017-3736) โโโ
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=swg22012552
โโโ IBM Security Bulletin: Security Vulnerabilities in IBMยฎ Java SDK affects multiple IBM Rational products based on IBM Jazz technology โโโ
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg22012696
โโโ SSA-284673 (Last Update 2018-01-18): Vulnerability in Industrial Products โโโ
---------------------------------------------
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284673โฆ
โโโ SSA-275839 (Last Update 2018-01-18): Denial-of-Service Vulnerability in Industrial Products โโโ
---------------------------------------------
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-275839โฆ
โโโ SSA-346262 (Last Update 2018-01-18): Denial-of-Service in Industrial Products โโโ
---------------------------------------------
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-346262โฆ
โโโ SSA-701708 (Last Update 2018-01-18): Local Privilege Escalation in Industrial Products โโโ
---------------------------------------------
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-701708โฆ
โโโ SSA-127490 (Last Update 2018-01-18): Vulnerabilities in SIMATIC WinCC Add-Ons โโโ
---------------------------------------------
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-127490โฆ
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily