MICROARCHITECTURE DATA SAMPLING

Priority: High Executive Summary: Intel have publicly disclosed a set of vulnerabilities involving side-channel attacks which allow microarchitecture data sampling (MDS), affecting Intel microprocessors. The four vulnerabilities are similar to Spectre/Meltdown in nature. The issue exists in Intel’s implementation of simultaneous multithreading, named Hyper-Threading. Microprocessor performance is improved by splitting a single physical processor core […]

REMOTE DESKTOP SERVICES ‘WORMABLE’ VULNERABILITY

Priority: High Executive Summary: Microsoft have addressed a remote code execution vulnerability found in their Remote Desktop Services (formally known as Terminal Services in Windows Server 2008 and earlier) affecting older versions of Windows prior to Windows 8. The security flaw, CVE-2019-0708, allows an attacker to send maliciously crafted packets towards a device running Remote […]

CISCO SECURITY ADVISORIES

[vc_row][vc_column][vc_column_text css=”.vc_custom_1556872488982{margin-bottom: 0px !important;}”]Priority: High Executive Summary: Cisco have disclosed 41 new Security Advisories, covering 1 Critical security impacting vulnerability, 23 High impact CVEs and 18 Medium impact CVEs. The Security Advisories cover a range of affect Cisco products, which have been provided below. The critical vulnerability (CVE-2019-1804), has a CVSS score of 9.8 and […]

CISCO SEMIANNUAL SECURITY ADVISORY

[vc_row][vc_column][vc_column_text css=”.vc_custom_1553794080691{margin-bottom: 0px !important;}”]Priority: High Executive Summary: Cisco released its Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication on March 27, 2019. This describes 17 Cisco Security Advisories, covering 19 vulnerabilities in Cisco’s IOS Software and Cisco’s IOS XE Software. These vulnerabilities each have a High Security Impact Rating. If successfully exploited, […]

LOCKERGOGA

Priority: High Executive Summary: Norsk Hydro, a Norwegian metals and renewable energies company, has been hit with a severe ransomware infection across their network. Information from NorCERT strongly indicates that the ransomware is LockerGoga, however this is yet to be confirmed by Norsk Hydro. This information also specifies that the attack is spread by targeting Active […]

REVERSE RDP ATTACKS

Priority: High Executive Summary: Researchers at Check Point have uncovered a number of vulnerabilities in three Remote Desktop Protocol (RDP) Clients: Microsoft’s RDP client, rdesktop, and FreeRDP, which can be exploited by a malicious server when the client connects to it over RDP. This would allow an attacker who had compromised a user’s device to […]