Why CISOs should be concerned about space-based attacks

Read Time:37 Second

Russia didn’t just attack Ukraine on the ground when it invaded that country on February 24, 2022, it also raided Ukraine’s data connections in space. On that date, “a multifaceted and deliberate cyber-attack against Viasat’s KA-SAT network resulted in a partial interruption of KA-SAT’s consumer-oriented satellite broadband service,” Viasat reported on March 30, 2022.

According to the satellite services provider, “the cyber-attack did impact several thousand customers located in Ukraine and tens of thousands of other fixed broadband customers across Europe.” They included the remote monitoring and control of 5,800 wind turbines owned by Germany’s Enercon, with a total capacity of 11 gigawatts.

To read this article in full, please click here

Read More

USN-6181-1: Ruby vulnerabilities

Read Time:24 Second

Hiroshi Tokumaru discovered that Ruby did not properly handle certain
user input for applications the generate HTTP responses using cgi gem.
An attacker could possibly use this issue to maliciously modify the
response a user would receive from a vulnerable application. This issue
only affected Ubuntu 22.10. (CVE-2021-33621)

It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755, CVE-2023-28756)

Read More

CVE-2022-25883

Read Time:10 Second

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

Read More

USN-6143-3: Firefox regressions

Read Time:39 Second

USN-6143-1 fixed vulnerabilities and USN-6143-2 fixed minor regressions in
Firefox. The update introduced several minor regressions. This update fixes
the problem.

We apologize for the inconvenience.

Original advisory details:

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-34414,
CVE-2023-34416, CVE-2023-34417)

Jun Kokatsu discovered that Firefox did not properly validate site-isolated
process for a document loaded from a data: URL that was the result of a
redirect, leading to an open redirect attack. An attacker could possibly
use this issue to perform phishing attacks. (CVE-2023-34415)

Read More

DSA-5436 hsqldb1.8.0 – security update

Read Time:27 Second

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL
database engine, allowed the execution of spurious scripting commands in
.script and .log files. Hsqldb supports a SCRIPT keyword which is normally
used to record the commands input by the database admin to output such a
script. In combination with LibreOffice, an attacker could craft an odb
containing a “database/script” file which itself contained a SCRIPT command
where the contents of the file could be written to a new file whose location
was determined by the attacker.

Read More

DSA-5437 hsqldb – security update

Read Time:27 Second

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL
database engine, allowed the execution of spurious scripting commands in
.script and .log files. Hsqldb supports a SCRIPT keyword which is normally
used to record the commands input by the database admin to output such a
script. In combination with LibreOffice, an attacker could craft an odb
containing a “database/script” file which itself contained a SCRIPT command
where the contents of the file could be written to a new file whose location
was determined by the attacker.

Read More