Skip to main content

Security Blog

Filter by:

Critical Pulse Secure VPN Vulnerability (CVE-2019-11510) Alert

Bad Packets recently stated in a security blog [1] that they detected an internet-wide opportunistic scanning activity targeting Pulse Secure VPN endpoints vulnerable to CVE-2019-11510 [2]. This arbitrary file reading vulnerability allows sensitive information disclosure, enabling unauthenticated attackers to...
Release Date: 6 Sep 2019 7051 Views

New Vulnerabilities in Remote Desktop Service (RDS) Affecting Most Current Windows Versions

Microsoft has just released patches in its August Monthly Security Update for 2 newly discovered vulnerabilities in Remote Desktop Services (RDS). Similar to the “BlueKeep” vulnerability, the new vulnerabilities can be exploited to engineer a worm-like outbreak in the Internet, poising a...
Release Date: 15 Aug 2019 5709 Views

New Trends in Ransom Email Attacks

Recently, HKCERT has received scores of reports of ransom emails. It suspected that cyber criminals were using local email addresses collected from the past information leakage incidents to launch large-scale attacks for profit. To raise public vigilance on such email attacks, HKCERT wishes to...
Release Date: 6 Jun 2019 8471 Views

Stay Vigilant Against IoT Security Risks at Home

The use of smart home appliances has become ever more prevalent in our daily lives where Internet of Things (IoT) are applied to connect various types of devices, bringing greater convenience to our lives like never before. However, sometimes IoT devices are designed to deliver...
Release Date: 2 Jun 2019 4767 Views

HKCERT Urges Microsoft Windows Users to Patch up RDS Vulnerability

(Hong Kong, 23 May 2019) In light of Microsoft’s earlier discovery of a vulnerability in the Remote Desktop Services (RDS) of the Windows system, the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) of the Hong Kong Productivity Council...
Release Date: 23 May 2019 6834 Views

Watch out for New Zombieload Side-channel Attack

HKCERT noted the recent discovery of multiple Microarchitectural Data Sampling (MDS) vulnerabilities in Intel’s Central Processing Unit (CPU). Hackers may exploit these vulnerabilities to access buffer data being processed in the CPU, enabling them to seize sensitive information from the user computers. ...
Release Date: 21 May 2019 3965 Views

Stay Cautious to the Latest WhatsApp Buffer Overflow Vulnerability

HKCERT noted the recent discovery of a buffer overflow vulnerability in messaging app WhatsApp. Hackers may exploit this vulnerability to inject spyware for remote code execution, and to bypass security restriction to eavesdrop on calls; turn on the microphone and camera functions; access the photos, ...
Release Date: 14 May 2019 3956 Views

Updates on Hong Kong Google Play Store's Apps Security Risk Report (7 May 2019)

HKPC’s Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) has obtained preliminary legal advice, and has moved all relevant reports away from the HKCERT website for the moment. Announcements will be made as and when appropriate.
Release Date: 7 May 2019 3485 Views

Beware of Sodinokibi Ransomware

HKCERT observed a new ransomware named "Sodinokibi" being deployed via Zero Day vulnerabilities recently. Web application vulnerabilities is one of the known attack vectors.   What ransomware usually does? Ransomware is used to encrypted victim’s files and causes the data unavailable. And ransom...
Release Date: 30 Apr 2019 4814 Views

Favourite Security Reads of the Fortnight (26 Apr 2019)

  Favourite Security Reads of the Fortnight (26 Apr 2019)   "Favourite Security Reads of the Fortnight". Every two weeks we share news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the favourite security reads of this fortnight. Article written by HKCERT on Hong Kong Economic Times: 防電腦淪「礦場」預防勝治療 (2019-04-12, Chinese) 碌卡消費便利 保護私隱有攻略 (2019-04-19, Chinese) 碌卡消費保...
Release Date: 26 Apr 2019 3520 Views