2020年6月14日 星期日

Updated Debian 10: 10.4 released

---------- Forwarded message ---------
From: Laura Arjona Reina
Date: May 9, 2020 9:06PM

The Debian project is pleased to announce the fourth update of its
stable distribution Debian 10 (codename "buster"). This point release
mainly adds corrections for security issues, along with a few
adjustments for serious problems. Security advisories have already been
published separately and are referenced where available.

Please note that the point release does not constitute a new version of
Debian 10 but only updates some of the packages included. There is no
need to throw away old "buster" media. After installation, packages can
be upgraded to the current versions using an up-to-date Debian mirror.

Those who frequently install updates from security.debian.org won't have
to update many packages, and most such updates are included in the point
release.

New installation images will be available soon at the regular locations.

Upgrading an existing installation to this revision can be achieved by
pointing the package management system at one of Debian's many HTTP
mirrors. A comprehensive list of mirrors is available at:

https://www.debian.org/mirror/list

About Debian
------------
The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------
For further information, please visit the Debian web pages at
https://www.debian.org/, send mail to , or contact the
stable release team at .

TrendLabs: WebMonitor RAT Bundled with Zoom Installer

Figure 2. Snippets of the strings from the partially unpacked payload
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/webmonitor-rat-bundled-with-zoom-installer/

[USN-4359-1] APT vulnerability

---------- Forwarded message ---------
From: Alex Murray
Date: May 14, 2020 10:36AM

It was discovered that APT incorrectly handled certain filenames during
package installation. If an attacker could provide a specially crafted
package to be installed by the system administrator, this could cause APT
to crash.

References:
  https://usn.ubuntu.com/4359-1
  CVE-2020-3810

TrendLabs: Zoomed In: A Look into a Coinminer Bundled with Zoom Installer

Figure 3. A detailed breakdown of the file’s contents
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/zoomed-in-a-look-into-a-coinminer-bundled-with-zoom-installer/

[USN-4333-1] Python vulnerabilities

---------- Forwarded message ---------
From: Leonidas S. Barbosa
Date: Apr 21, 2020 9:51PM

It was discovered that Python incorrectly stripped certain characters from
requests. A remote attacker could use this issue to perform CRLF injection.
(CVE-2019-18348)

It was discovered that Python incorrectly handled certain HTTP requests.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2020-8492)

References:
  https://usn.ubuntu.com/4333-1
  CVE-2019-18348, CVE-2020-8492

Cloudflare: International Women’s Day 2020: Building a Modern Security Team

REF: https://blog.cloudflare.com/international-womens-day-2020-building-a-modern-security-team/

2020年5月31日 星期日

TrendLabs: More Than 8,000 Unsecured Redis Instances Found in the Cloud

Figure 2. Geographical distribution of deployed unsecured Redis instances
Figure 2. Geographical distribution of deployed unsecured Redis instances
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/more-than-8000-unsecured-redis-instances-found-in-the-cloud/