2020年6月14日 星期日

Cloudflare: The History of the URL

ARPANET circa 1969
REF: https://blog.cloudflare.com/the-history-of-the-url/

LibreSSL 3.2.0 Released

---------- Forwarded message ---------
From: Brent Cook <busterb@gmail.com>
Date: Mon, Jun 1, 2020 at 9:16 AM

This is the first development release from the 3.2.x series, which will
eventually be part of OpenBSD 6.8.  

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.

TrendLabs: QNodeService: Node.js Trojan Spread via Covid-19 Lure

Figure 11. WebSocket handshake
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/qnodeservice-node-js-trojan-spread-via-covid-19-lure/

[USN-4375-1] PHP vulnerability

---------- Forwarded message ---------
From: Leonidas S. Barbosa <leo.barbosa@canonical.com>
Date: May 28, 2020 3:55AM

It was discovered that PHP incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.

References:
  https://usn.ubuntu.com/4375-1
  CVE-2019-11048

TrendLabs: Targeted Ransomware Attack Hits Taiwanese Organizations

Figure 1. Reflective loading of the .DLL file
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/targeted-ransomware-attack-hits-taiwanese-organizations/

[USN-4371-1] libvirt vulnerabilities

---------- Forwarded message ---------
From: Marc Deslauriers
Date: May 22, 2020 2:46AM

It was discovered that libvirt incorrectly handled an active pool without a
target path. A remote attacker could possibly use this issue to cause
libvirt to crash, resulting in a denial of service. (CVE-2020-10703)

It was discovered that libvirt incorrectly handled memory when retrieving
certain domain statistics. A remote attacker could possibly use this issue
to cause libvirt to consume resources, resulting in a denial of service.
This issue only affected Ubuntu 19.10. (CVE-2020-12430)

References:
  https://usn.ubuntu.com/4371-1
  CVE-2020-10703, CVE-2020-12430

TrendLabs: Gamaredon APT Group Use Covid-19 Lure in Campaigns

Figure 1. The infection chain of the Gamaredon campaign
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/gamaredon-apt-group-use-covid-19-lure-in-campaigns/