Crypto News | ETH Fork | Mining Algorithm Change? | Bitmain Overvalued | Bittrex Securities
ABBYY 'temporary data breach' exposed 200,000 scanned docs

TfNSW taps Cubic to alleviate Sydney's transport woes
Active scanning and exploitation of unpatched boxes afoot.
Researchers have recorded the first mass automated attacks against servers running unpatched versions of the open source Apache Struts enterprise web application framework.
four days ago and allows for remote code execution.

Apache has issued patched versions of Struts, version 2.3.35 and 2.5.17, but many administrators have failed to apply the fixed software.

Latest Crypto Mining News
If the exploit code executes successfully on a vulnerable Apache Struts installation, wget requests run to fetch a copy of CNRig Miner - a cryptocurrency miner that runs on Linux distributions - again from Github.
The attacks would also plant a script on vulnerable systems that downloads further Linux ELF binaries for Intel, ARM and MIPS processors.
Volexity said this shows the cryptocurrency miner is capable of running on a wide range of hardware, such as servers, desktops, laptops, IoT devices, wireless routers and other internet connected devices with vulnerable instances of Apache Struts.
Initial scans have come from Russian and French internet protocol addresses, Volexity said.

Volexity warned that while the current round of attacks compromised equipment with cryptocurrency mining payloads, unpatched Apache Struts installations left organisations open to significant risks, including advanced persistent threat (APT) state-sponsored hacking groups gaining access to networks.
Security engineer Dino A Dai Zovi at payments company Square suggested on Twitter a number of common-sense security measures that could mitigate against successful exploitation of the current Apache Struts vulnerability and others that might follow it, on top of patching:
After patching this vuln, a few good questions to ask are:
- why are our web services allowed to connect directly to external Internet hosts from production?
- why are our web services allowed to execute dynamically downloaded binaries?
New critical Apache Struts hole allows remote code execution
ABBYY 'temporary data breach' exposed 200,000 scanned docs
NBN Co will add FTTC upgrade options to Technology Choice
Online payments fraud in Australia explodes to $476m
Report: ANZ IT Decision Makers - Top Priorities for Endpoint Security 2018
What Every CIO Should Know about DevOps & Container Guides by Puppet
ISACA Oceania Computer Audit, Control and Security (Oceania CACS) 2018
Telarus changes Aussie trading name to Tradewinds during launch event in Sydney
CSG's losses triple to $150 million after exiting enterprise business
Communications Workers Union slam Telstra boss Andrew Penn's letter to employees
Melbourne MSP Blue Apache toasts 20 years in business
6 cloud accounting systems for Australian small businesses compared: MYOB, QuickBooks, Reckon, Saasu, Sage and Xero
How long will a UPS keep your computers on if the lights go out?
7 accounting packages for Australian small businesses compared: including MYOB, QuickBooks Online, Reckon, Xero
Xero and GoCardless integrate for easy direct debits
Two new iPhone X devices and iPhone 9 leak in video
How to: Remove a device from Netflix when someone's accessing your account
25 secret WhatsApp tricks you (probably) didn't know about
Every main Assassin’s Creed game ranked from worst to best
Every Rainbow Six Siege defender ranked from optional to essential
Every Call of Duty game ranked from worst to best
RTX 2080 first impressions: Nvidia's new DLSS technology
18 pro tips from the Rainbow Six Siege world cup
Maroochydore to host intelligent lighting pilot
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website
constitutes acceptance of nextmedia's

0 Reviews:
Post Your Review