Emergency Response

Android Bluetooth Component Critical Vulnerability (CVE-2020-0022) Threat Alert

February 18, 2020 | Adeline Zhang

Overview Recently, Google released February 2020 security updates for Android which fixed a critical vulnerability (CVE-2020-0022) in Android’s Bluetooth component. This vulnerability could be exploited without user interaction when Bluetooth is enabled on devices. An attacker that successfully exploits this vulnerability could execute arbitrary code on the target system. Also, researchers pointed out that this […]

FusionAuth Remote Code Execution Vulnerability (CVE-2020-7799) Threat Alert

February 14, 2020 | Adeline Zhang

Vulnerability Description On January 28, 2019, Beijing time, NVD released a remote command execution vulnerability (CVE-2020-7799) in the Apache Freemarker template in FusionAuth. It is found that an authenticated user can edit email templates (Home > Settings > Email Templates) or themes (Home > Settings > Themes) in FusionAuth to execute arbitrary commands in the […]

oracle

WebLogic WLS Component IIOP Protocol Remote Code Execution Vulnerability (CVE-2020-2551) Threat Alert

February 12, 2020 | Adeline Zhang

Overview Oracle released Critical Patch Update (CPU) for January 2020, announcing a remote code execution vulnerability (CVE-2020-2551) in the Internet Inter-ORB Protocol (IIOP) used by the WLA component in WebLogic.

Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities

January 31, 2020 | Adeline Zhang

Overview Microsoft released the January security update on Tuesday, fixing 49 security issues ranging from simple spoofing attacks to remote code execution, discovered in products like .NET Framework, Apps, ASP.NET, Common Log File System Driver, Microsoft Dynamics, Microsoft Graphics Component, Microsoft Office, Microsoft Scripting Engine, Microsoft Windows, Microsoft Windows Search Component, Windows Hyper-V, Windows Media, […]

Adobe Security Bulletins for January 2020 Security Updates Security Alert

January 30, 2020 | Adeline Zhang

Overview On January 14, local time, Adobe officially released the January security update, which fixed multiple vulnerabilities in various Adobe products, including Adobe Experience Manager and Adobe Illustrator CC. Official notification address: https://helpx.adobe.com/security.html  

Weblogic WLS Component IIOP Protocol Remote Code Execution Vulnerability (CVE-2020-2551) Security Alert

January 29, 2020 | Adeline Zhang

Overview In January 2020, the critical patch update announcement CPU (Critical Patch Update) officially released by Oracle, a remote code execution vulnerability (CVE-2020-2551) in the IIOP protocol of Weblogic WLS component was announced.

Oracle family key patch update January 2020 Security Alert

January 28, 2020 | Adeline Zhang

Overview On January 14, 2020, Oracle officially announced critical patch update (CPU) security announcement and third-party security announcement, and fixed 334 vulnerabilities. See the appendix table for the affected conditions and available patches of each product.

Windows CryptoAPI High Risk Vulnerability (CVE-2020-0601) Security Alert

January 27, 2020 | Adeline Zhang

Overview   On January 14, local time, one of the latest monthly patch updates from Microsoft fixed the Windows CryptoAPI spoofing vulnerability (CVE-2020-0601) discovered and reported to Microsoft by the National Security Agency (NSA), which affects Windows 10. , Windows Server 2016 and Windows Server 2019.

WordPress plug-in authentication bypass vulnerability Security Alert

January 26, 2020 | Adeline Zhang

Overview Recently, webarx researchers announced two high-risk authentication bypass vulnerabilities in WordPress plug-ins, which allow attackers to log in to an administrator account without a password.

GitLab EE / CE Information Disclosure Vulnerability (CVE-2020-6832) Security Alert

January 24, 2020 | Adeline Zhang

Vulnerability Description On January 14th, GitLab officially released an important version update security notice, fixing a vulnerability (CVE-2020-6832) that could lead to private project inform-ation disclosure. GitLab is an open source project for a warehouse management system. It uses Git as a code management tool and a web service built on it.