//Week in review - 18 Apr 2019
AusCERT Week in Review for 18th April 2019
Easter is here again, so hopefully some of us will get a few days' break
from work. If travelling, please take care on the roads.
This week Oracle released vulnerability details and patches for its
wide-ranging product list.
For those using their products, there are many fixes to apply (up to 297)!
As for other news, here is a summary (including excerpts) of some of the more
interesting stories we've seen this week:
Oracle Releases 297 Fixes in April 2019 Critical Patch Update
Author: Ionut Arghire
"Oracle this week announced the release of 297 new security fixes as part
of its April 2019 Critical Patch Update (CPU), two-thirds of which are
remotely exploitable without authentication."
The web's infrastructure is under attack from a global hacking spree
Author: Matt Burgess
"Hackers have been conducting a large scale attack on the websites of
governments and intelligence agencies around the world. Security experts
claim the attackers are being backed by an unnamed government and their
actions threaten to undermine the systems that keep the web functioning.
Startling new research from Cisco's Talos security group says that a core
part of the internet's infrastructure has been targeted as the hackers
attempt to steal confidential information. Here's what we know."
Fifth of Web Traffic Comes from Malicious Bots
Author: Phil Muncaster
"Around a fifth of all web traffic last year was linked to malicious
bot activity, with financial services hit more than any other sector,
according to Distil Networks."
Wipro hacked, internal systems used to attack customers: report
Author: Juha Saarinen
"Wipro is currently investigating what appears to be a serious breach
of its networks and systems, which are apparently being used to launch
attacks on customers, forcing the outsourcing giant to build a private
email service to replace compromised corporate system."
Big Companies Thought Insurance Covered a Cyberattack. They May
Author: Adam Satariano and Nicole Perlroth
"Mondelez, owner of dozens of well-known food brands like Cadbury chocolate
and Philadelphia cream cheese, was one of the hundreds of companies struck
by the so-called NotPetya cyberstrike in 2017."
"Mondelez's insurer, Zurich Insurance, said it would not be sending
a reimbursement check. It cited a common, but rarely used, clause in
insurance contracts: the "war exclusion," which protects insurers from
being saddled with costs related to damage from war.
Mondelez was deemed collateral damage in a cyberwar."
Here are some of this week's noteworthy security bulletins (in no particular
1. ESB-2019.1280 - [Linux][OSX] Webkit: Multiple vulnerabilities
"Processing maliciously crafted web content may lead to arbitrary code
2. ESB-2019.1345 - [Win][UNIX/Linux] Drupal: Multiple vulnerabilities
"Service IDs derived from unfiltered user input could result in the
execution of any arbitrary code"
3. ESB-2019.1353 - [SUSE] python: Multiple vulnerabilities
"blacklist bypass in URIs by using the 'local-file:' scheme"
4. ESB-2019.1329 - [Cisco] Aironet access points: Multiple vulnerabilities
Denial of Service and Root Compromise vulnerabilities.
5. ASB-2019.0110 - [Win][UNIX/Linux] Oracle Construction and Engineering
Suite: Multiple vulnerabilities
Remote code execution, Denial of Service, and other vulnerabilities.
Stay safe, stay patched and have a great weekend,