You are here

Cybersecurity

Microsoft Releases Security Update for Windows Elevation of Privilege Vulnerability

Microsoft has released a security update to address an elevation of privilege vulnerability (CVE-2019-1162) in Windows. An attacker could exploit this vulnerability to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Microsoft Security Advisory and apply the necessary update.

Security Awareness – Use Caution with Malware Scanning Services

Back in the day, data found in malware was much more generic, or at least much less specific. Today, with phishing-based scams, BEC, and CEO-fraud leading the pack of cyber attack techniques, the malware samples being uploaded to free malware scanning services reveal far more specific company data than they used to. The Register posted a reminder about the dangers of uploading malware to public online sandbox services. Malware samples certainly provide valuable data for cyber analysts, but malicious actors also view the data.

Fuji Electric Alpha5 Smart Loader (ICSA-19-227-02)

The NCCIC has published an advisory on a stack-based buffer overflow vulnerability in Fuji Electric Alpha5 Smart Loader. All versions prior to 4.2 are affected. Successful exploitation of this vulnerability could allow an attacker to execute code under the privileges of the application. Fuji Electric has released version 4.2 of the Alpha Loader software. The NCCIC also recommends a series of measures to mitigate the vulnerabilities. Read the advisory at CISA.

Johnson Controls Metasys (ICSA-19-227-01)

The NCCIC has published an advisory on reusing a nonce, key pair in encryption and on the use of hard-coded cryptographic key vulnerabilities in Johnson Controls Metasys. Versions prior to 9.0 are affected. Successful exploitation of these vulnerabilities could be leveraged by an attacker to decrypt captured network traffic. Johnson Controls recommends users upgrade to version 9.0 or later and configure sites with trusted certificates. The NCCIC also recommends a series of measures to mitigate the vulnerabilities.

Microsoft Releases Security Updates to Address Remote Code Execution Vulnerabilities

Microsoft has released security updates to address two remote code execution vulnerabilities, CVE-2019-1181 and CVE-2019-1182, in its operating systems. An attacker could exploit these vulnerabilities to take control of an affected system. Similar to CVE-2019-0708 - dubbed BlueKeep - these vulnerabilities are considered “wormable” because malware exploiting these vulnerabilities on a system could propagate to other vulnerable systems.

Multiple HTTP/2 Implementation Vulnerabilities

The CERT Coordination Center (CERT/CC) has released information on vulnerabilities affecting HTTP/2 implementations. An attacker could exploit these vulnerabilities to cause a denial-of-service (DoS) condition. Attacks can consume excessive system resources and lead to distributed DoS (DDoS) attacks. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review CERT/CC’s Vulnerability Note VU#605641 for more information and refer to vendors for updates.

Cloud Security Primer

Organizations are moving to the cloud in increasing numbers to take advantage of its long list of benefits, including data center distribution, cost savings, efficiencies in managing environments, and flexibility. However, the advantages disappear in the case of a security breach. A primer from Rapid7 covers the basics to provide a foundational understanding of what’s essential for security in the cloud. It discusses SaaS, PaaS, and IaaS cloud security; cloud-focuses security controls; and implementation of policies and procedures.

Pages

Subscribe to Cybersecurity