SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers

Common Vulnerabilities and Exposures (CVE) stories - Page 19

Thinkstockphotos 846251202

Attackers exploit macro-less Office documents to create havoc

Tue, 3rd Apr 2018
#
malware
#
firewalls
#
network infrastructure
Cybercriminals use Microsoft Office documents to conduct 'macro-less' attacks that dodge organisations' defences and inject malware.
Thinkstockphotos 862290790

China cyberespionage group targets US maritime & engineering sectors

Mon, 19th Mar 2018
#
malware
#
breach prevention
#
cybersecurity
A China-based cyberespionage group may be targeting United States engineering and maritime industries tied up in activities about the South China Sea.
Screen shot 2018 03 12 at 10

New research finds China tampering with public vulnerability data

Mon, 12th Mar 2018
#
cybersecurity
#
fraud
#
cybercrime
Recorded Future believes China has been altering public vulnerability data to allow the Ministry of State Security to play with it first.
Screen shot 2018 03 06 at 12

REPORT: Ransomware decreasing in quantity but increasing in potency

Wed, 7th Mar 2018
#
malware
#
ransomware
#
supply chain
A new report from SonicWall has shed light on the current threat landscape with the company recording an astonishing 9.32b malware attacks in 2017.
Thinkstockphotos 845260736

Chinese websites targeted in drive-by download attack that drops DDoS bot

Tue, 27th Feb 2018
#
ddos
#
botnet
#
malwarebytes
Chinese websites are under siege by a drive-by download campaign planting the decade-old Avzhan DDoS bot, Malwarebytes Labs reveals.
Thinkstockphotos 879913100

State-sponsored North Korean cyberespionage group continues to weaponize tactics

Wed, 21st Feb 2018
#
breach prevention
#
healthtech
#
fireeye
The North Korean threat group known to some as Reaper (APT37) is eyeing bigger targets with more sophisticated tactics.
Thinkstockphotos 880737456

New email spam campaign ditches traditional Office macro infection tactic

Mon, 19th Feb 2018
#
malware
#
email security
#
cybersecurity
A new wave of spam emails use Microsoft Office documents to download password stealers without having to activate Macros.
Thinkstockphotos 584210798 8wnzudo

ASUSTOR responds to Spectre & Meltdown with ADM update

Wed, 14th Feb 2018
#
semiconductors
#
intel
#
asustor
ASUSTOR is releasing updates to its ADM this week as part of its efforts to fix the Meltdown security vulnerabilities.
Security protection anti virus software 60504

Cisco ASA appliances at risk of denial of service exploit

Tue, 13th Feb 2018
#
cisco
#
exploits
#
acsc
The Australian Cyber Security Centre (ACSC) has issued an official alert to those who use Cisco's Adaptive Security Appliance (ASA).
Thinkstockphotos 481086900

Attackers unleash Lokibot malware on unpatched Windows systems

Tue, 13th Feb 2018
#
malware
#
cybersecurity
#
microsoft
Lokibot malware targets unpatched Windows systems exploiting CVE-2017-11882; researchers urge timely updates and restricted installer access to combat threats.
Thinkstockphotos 907549022

Intel releases Spectre & Meltdown patches for some Skylake processors

Mon, 12th Feb 2018
#
semiconductors
#
intel
#
spectre
Intel has rolled out patches for Spectre and Meltdown flaws in some Skylake processors, aiming to enhance data security amid previous update issues.
Pexels photo

42% of Alexa-ranked websites are open invites for attackers

Wed, 7th Feb 2018
#
uc
#
phishing
#
email security
A staggering 42% of top Alexa-ranked websites are vulnerable to cyber-attacks due to outdated software and compromised content, finds Menlo Security.
Thinkstockphotos 653516378

North Korean threat group suspected to be behind Adobe Flash exploit

Mon, 5th Feb 2018
#
martech
#
breach prevention
#
adobe
An exploit that targeted an Adobe Flash vulnerability looks to be the work of a North Korean group called TEMP.Reaper.
Thinkstockphotos 473158924

Oracle MICROS POS vulnerability may compromise 330,000 POS systems

Fri, 2nd Feb 2018
#
martech
#
commerce systems
#
supply chain
A vulnerability in Oracle's POS systems may affect more than 330,000 payment systems across the globe, putting files and sensitive information at risk.
Thinkstockphotos 476580161

Zyklon HTTP malware creates gaping backdoors through MS Office exploits

Mon, 22nd Jan 2018
#
malware
#
ddos
#
breach prevention
Zyklon HTTP malware is described as a publicly-available and fully featured backdoor that is able to conduct DDoS attacks, steal passwords...
Patch

Meltdown and Spectre fallout: patching problems persist

Fri, 12th Jan 2018
#
intel
#
amd
#
spectre
Patching difficulties persist as the tech industry grapples with the fallout from Meltdown and Spectre, highlighting flaws in nearly all modern processors.
Security breach

Intel processor vulnerabilities: What you need to know about Meltdown and Spectre

Mon, 8th Jan 2018
#
semiconductors
#
microsoft
#
google
Desktops, laptops, and smartphones running on vulnerable processors can be exposed to unauthorized access and information theft.
Macos

Apple confirms that macOS and iOS are vulnerable to Meltdown bugs

Mon, 8th Jan 2018
#
ios
#
apple
#
meltdown
Security issues known as Meltdown and Spectre affect all modern processors, including Apple's Mac systems and iOS devices. No known exploits at this time.
Macbook highsierra homescreen saver half

Apple addresses serious root access vulnerability in latest MacOS High Sierra update

Thu, 30th Nov 2017
#
pam
#
apple
#
security vulnerabilities
Apple has been quick to address the major CVE-2017-13872 security flaw in its macOS High Sierra 10.13.1 operating system.
Thinkstockphotos 637770524

Check Point & LG plug security vulnerabilities in smart appliances

Tue, 7th Nov 2017
#
breach prevention
#
cybersecurity
#
security breaches
Check Point researchers recently worked with LG to plug vulnerabilities in a number of home appliances, including robot vacuum cleaners & dishwashers.