Week in review: WHOIS after GDPR, April Patch Tuesday forecast, how to Marie Kondo your data
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0211 | Use-After-Free Root Local Privilege Escalation in Apache HTTP Server 2.4 In Apache HTTP Server 2.4 releases 2.4.17 through 2.4.38, a use-after-free flaw (CWE-416) in scoreboard handling allows code running in less-privileged child processes or threads — including in-process scripting interpreters such as mod_php — to execute arbitrary code with the privileges of the parent process, which is usually root. All three standard multi-processing modules (event, worker, and prefork) are affected on Unix-like systems; non-Unix systems such as Windows are not affected. An attacker who can already run code inside the web server process, for example a shared-hosting customer running PHP, gains root privileges on the host, putting every site and service on that server at risk. The flaw is rated 7.8 (high), a public proof-of-concept exploit known as 'Carpe Diem' has been released, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 65% (99th percentile). Public scans reported in news coverage counted more than 2 million Apache HTTP servers running affected versions, with shared web hosting environments highlighted as most at risk. Do: Upgrade Apache HTTP Server to a fixed release (2.4.39 or later) or apply patched packages from your OS/vendor — Apache, Fedora, Canonical/Ubuntu, Debian, openSUSE, NetApp, Red Hat, and Oracle have shipped fixes — as required by the CISA KEV catalog. Prioritize internet-facing and shared-hosting servers that run in-process scripting such as mod_php, and verify the running version (e.g. 'apachectl -v' or 'httpd -v') is outside the 2.4.17–2.4.38 range. Note that Windows and other non-Unix installations are not affected. | 7.8 | 65% | KEV PoC ×2 |
| mass≈2,000,000+ Apache HTTP servers running affected 2.4.17–2.4.38 releases (subset requiring local code-execution access, e.g. shared hosts) |
Full article816 words · extracted from helpnetsecurity.com · click to collapse
Here’s an overview of some of last week’s most interesting news and articles:
Georgia Tech data breach: 1.3M students and staff potentially affected
The Georgia Institute of Technology, commonly referred to as Georgia Tech, has suffered yet another data breach. This time, the number of affected individuals may have reached 1.3 million.
The CIO’s greatest roadblock to Agile development: Security governance
The greatest roadblock CIOs face when adopting Agile development is not ‘security in general,’ but ‘security governance.’ We can define ‘security governance’ as the establishment of security policies and the continuous monitoring of their proper implementation by stakeholders within an organization.
April Patch Tuesday Forecast: Be aware of end-of-service issues and browser exploits
April Patch Tuesday is nearly here with two significant topics of concern. The first relates to end-of-service milestones and the second issue is browser exploits.
Vulnerability found in Guard Provider, Xiaomi’s pre-installed security app
Check Point Research discovered a vulnerability in one of the preinstalled apps on devices manufactured by one of the world’s biggest mobile vendors, Xiaomi.
Patched Apache flaw is a serious threat for web hosting providers
Organizations running Apache web servers are urged to implement the latest security update to fix a serious privilege escalation flaw (CVE-2019-0211) that can be triggered via scripts and could allow unprivileged web host users to execute code with root privileges, i.e. allow them to gain complete control of the machine.
WHOIS after GDPR: A quick recap for CISOs
2018 was a big year for data protection with the implementation of the General Data Protection Regulation (GDPR) last May — forcing CISOs and other professionals to rethink how the personal data of European consumers should be collected and processed.
Consumer routers targeted by DNS hijacking attackers
Owners of a slew of D-Link, ARGtek, DSLink, Secutech, TOTOLINK and Cisco consumer routers are urged to update their device’s firmware, lest they fall prey to ongoing DNS hijacking campaigns and device hijacking attacks.
3.1 million customer records possibly stolen in Toyota hack
Personal information of some 3.1 million Toyota customers may have been leaked outside the company, the Toyota Motor Corporation (TMC) announced.
Main threat source to industrial computers? Mass-distributed malware
Malicious cyber activities on Industrial Control System (ICS) computers are considered an extremely dangerous threat as they could potentially cause material losses and production downtime in the operation of industrial facilities.
Automatically and invisibly encrypt email as soon as it is received on any trusted device
While an empty email inbox is something many people strive for, most of us are not successful. And that means that we probably have stored away hundreds, even thousands, of emails that contain all kinds of personal information we would prefer to keep private.
Anomali: Threat detection, investigation and response
In this Help Net Security podcast recorded at RSA Conference 2019, Nicholas Hayden, Senior Director of Threat Intelligence at Anomali, talks about how Anomali arms security teams with highly optimized threat intelligence, powered by machine learning.
Microsoft rolls out new security capabilities for Azure customers
Microsoft has announced new security features for customers of its Azure cloud computing service.
How to Marie Kondo your data
While the #KonMariMethod has put households across America in an organizing frenzy, we found that her tidying principles can also be applied to solve a core challenge for the business world: too much data.
The security challenges that come with serverless computing
Serverless computing (aka Function-as-a-Service) has been a boon to many enterprises: it simplifies the code development and deployment processes while improving utilization of server resources, minimizing costs and reducing security overhead.
Digital transformation goes hand-in-hand with Zero Trust security
Forward-looking organizations are investing in Zero Trust security and strong MFA, modern app development, IaaS, and digital transformation, a recently released Okta report has shown.
A LockerGoga primer and decrypters for Mira and Aurora ransomwares
There’s some good news for victims of the Mira and Aurora ransomwares: free decrypters have been made available.
Organizations investing in security analytics and machine learning to tackle cyberthreats
IT security’s greatest inhibitor to success is contending with too much security data. To address this challenge, 47 percent of IT security professionals acknowledged their organization’s intent to acquire advanced security analytics solutions that incorporate machine learning (ML) technology within the next 12 months.
Current and emerging third-party cyber risk management approaches and challenges
Managing third-party cyber risk is critical for businesses, but a lack of continuous monitoring, consistent reporting, and other blind spots are creating challenges that could leave organizations vulnerable to data breaches and other consequences.
To DevSecOps or not to DevSecOps?
Would your organization benefit from introducing DevSecOps? Dan Cornell, CTO of application security company Denim Group, believes that most organizations would. With one caveat, though: they must realize that the transition is, first and foremost, cultural rather than technological.
New infosec products of the week: April 5, 2019
A rundown of infosec products released last week.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/04/07/week-in-review-whois-after-gdpr-april-patch-tuesday-forecast-how-to-marie-kondo-your-data/