Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

RSS FEEDS

Siemens PLCs Memory Protection Bypass Vulnerability

Sunday, 30 May, 2021

A new memory protection bypass vulnerability tracked as CVE-2020-15782 has been discovered in Siemens SIMATIC S7-1200 and S7-1500 CPU products. If exploited successfully, this vulnerability could allow attackers to write arbitrary data to protected memory areas or read sensitive data from the device's memory, which could lead to completely taking over the affected device.

Bluetooth Impersonation and AuthValue Disclosure Vulnerabilities

Thursday, 27 May, 2021

Multiple vulnerabilities have been discovered in Bluetooth devices that support Bluetooth Core and Mesh Specifications. These vulnerabilities allow for impersonation attacks and AuthValue disclosure which, in practice, could allow for man in the middle attacks within the range of two vulnerable bluetooth devices. Please find below the list of vulnerabilities:

 

Apple macOS Gatekeeper Bypass Vulnerability Exploited in the Wild

Thursday, 27 May, 2021

A new vulnerability has been discovered in Apple macOS Gatekeeper and is being exploited in the wild to target macOS users. The vulnerability has been tracked as CVE-2021-30657, and could allow attackers to bypass security checks performed by macOS to execute code on remote victims by crafting a malicious image and app file for macOS.

 

Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

Wednesday, 19 May, 2021

A new proof of concept exploit has been released for CVE-2021-31166, a remote code execution vulnerability in Microsoft's HTTP Protocol Stack that is exploitable without authentication and according to Microsoft, wormable between HTTP services. This use after free vulnerability affects the HTTP.SYS component which handles the HTTP protocol stack, specifically the http!UlpParseContentCoding method.

 

“BadAlloc” Multiple Vulnerabilities in IoT/OT Devices

Tuesday, 4 May, 2021

A critical set of vulnerabilities known as "BadAlloc" have been identified affecting multiple Real Time Operating System (RTOS), Embedded Software Development Kit and libraries. The vulnerabilities have been categorized as Integer Overflow or Wraparound, and the impact can be Remote Code Execution (RCE) or Denial of Service (DoS) if such vulnerability exploited.

Pulse Connect Secure Exploited in the Wild by Malicious Actors

Wednesday, 21 April, 2021

Pulse Connect Secure appliances are being actively exploited in the wild by different malicious actors with different malware families. In order to compromise the Pulse Connect Secure appliances, threat actors are using different vulnerabilities in Pulse Connect Secure, including CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, and a new zero-day vulnerability tracked as CVE-2021-22893.

 

NAME:WRECK - Multiple Vulnerabilities in DNS Implementations

Monday, 19 April, 2021
A new set of nine vulnerabilities dubbed NAME:WRECK has been discovered by researchers at Forescout and JSOF Research Labs. These vulnerabilities affect the Domain Name System (DNS) component on at least four TCP/IP stack implementations: FreeBSD, IPNet, NetX, and Nucleus NET. These TCP/IP stack implementations are widely utilized in Internet of Things (IoT), operational technology (OT), and information technology (IT) devices.

Microsoft Security Updates April 2021

Wednesday, 14 April, 2021
Microsoft has released its April 2021 security updates addressing 108 vulnerabilities in multiple products. It is strongly suggested to apply the recommendations below in order to prevent security incidents from happening.
 
Microsoft’s April 2021 security update collection contains fixes for 19 critical vulnerabilities and 88 rated important, including patches for another set of vulnerabilities in Microsoft Exchange that are listed as critical. Additionally, Microsoft has included updates for a privilege escalation vulnerability exploited in the wild in Win32.

Google Chrome Zero-Day Vulnerabilities Exploited in the Wild

Wednesday, 14 April, 2021
Two new high severity vulnerabilities in Google Chrome have been discovered and are being actively exploited in the wild. It is suggested to apply the recommendations below in order to prevent security incidents from happening.
 
The vulnerabilities have been tracked as CVE-2021-21206 and CVE-2021-21220 and affect Google Chrome for Windows, Mac and Linux. Please note that we are aware of these vulnerabilities being exploited in the wild at the time of this writing to target Chrome users.
Subscribe to RSS FEEDS