Matisse & Co

Competitive Intelligence Data Services

 
  • Join Now-Sign Up
  • Log In
Search Results

7 Practical Steps to Get Started with Security Intelligence

…What Practical Steps Can I Take to Get Started with Security Intelligence?…

 

Source: https://securityintelligence.com/7-practical-steps-to-get-started-with-security-intelligence/

Tags: Security Intelligence,
  • Editor Paper Extracts
  • Editor Picks Articles
  • Editor Picks Maps
  • Editor Picks Reports
  • MCO Intelligence Work Group
  • MCO Partners
  • MCO Security Work Group
  • Uncategorized

MCO Security Alerts Advisories

  • Foscam C2/Opticam i5 /mnt/mtd/app Archive File privilege escalation
    A vulnerability was found in Foscam C2 and Opticam i5 (the affected version is unknown). It has been declared as critical. Affected by this vulnerability is an unknown function of ... read more
  • Foscam C2/Opticam i5 Firewall Feature privilege escalation [CVE-2018-19075]
    A vulnerability classified as critical was found in Foscam C2 and Opticam i5 (the affected version is unknown). This vulnerability affects an unknown function of the component Firewall Feature. The ... read more
  • Foscam Opticam i5 1.5.2.11 ONVIF devicemgmt SystemReboot denial of service
    A vulnerability was found in Foscam Opticam i5 1.5.2.11 and classified as problematic. Affected by this issue is an unknown function of the component ONVIF devicemgmt SystemReboot. The manipulation with ... read more
  • Singtel earnings slide across mobile, fixed, security (ZDNet)
    ... read more
  • Cambodia’s ISPs hit by some of the biggest DDoS attacks in the country’s history (ZDNet)
    ... read more
  • U.S. Cyber Command Shares Malware via VirusTotal (SecurityWeek)
    ... read more
  • 64.016
    Newly Added (1)Android/Dialer.P!trModified (15)Adware/Dnotua!AndroidAdware/Ewind!AndroidAdware/Hiddad!AndroidAdware/MobiDash!AndroidAndroid/Agent.AOH!trAndroid/Agent.CEQ!trAndroid/Android_Dowgin.XAndroid/Boogr.GSH!trAndroid/DrdDream.BU!exploitAndroid/Guerrilla.AO!trAndroid/Guerrilla.I!trAndroid/Hiddad.HI!trAndroid/Hiddad.TG!trAndroid/SmsSpy.MK!tr.spyRiskware/SmsReg!Android ]]> ... read more
  • poppler up to 0.71.0 goo/GooString.h filename denial of service
    A vulnerability was found in poppler up to 0.71.0 and classified as problematic. Affected by this issue is an unknown function of the file goo/GooString.h. The manipulation of the argument ... read more
  • nginx up to 1.14.0/1.15.5 HTTP2 CPU Exhaustion denial of service
    A vulnerability, which was classified as problematic, has been found in nginx up to 1.14.0/1.15.5. Affected by this issue is an unknown function of the component HTTP2 Handler. The manipulation ... read more
  • poppler up to 0.71.0 Object.h EmbFile::save2 denial of service
    A vulnerability, which was classified as problematic, was found in poppler up to 0.71.0. Affected is the function EmbFile::save2 of the file Object.h. The manipulation with an unknown input leads ... read more
  • Foscam C2/Application/Opticam i5 CGIProxy.fcgi addAccount usrName privilege escalation
    A vulnerability was found in Foscam C2, Application and Opticam i5 (the affected version is unknown) and classified as critical. This issue affects the function addAccount of the file CGIProxy.fcgi. ... read more
  • poppler up to 0.71.0 FileSpec.cc EmbFile::save2 memory corruption
    A vulnerability has been found in poppler up to 0.71.0 and classified as critical. Affected by this vulnerability is the function EmbFile::save2 of the file FileSpec.cc. The manipulation with an ... read more
  • Foscam C2/Application/Opticam i5 FTP weak authentication [CVE-2018-19064]
    A vulnerability was found in Foscam C2, Application and Opticam i5 (the affected version is unknown). It has been rated as critical. This issue affects an unknown function of the ... read more
  • mPDF up to 7.1.6 Web Application getImage Server-Side Request Forgery
    A vulnerability was found in mPDF up to 7.1.6 and classified as critical. This issue affects the function getImage of the component Web Application. The manipulation with an unknown input ... read more
  • axTLS up to 2.1.3 PKCS #1 x509.c sig_verify() Certificate spoofing
    A vulnerability classified as critical has been found in axTLS up to 2.1.3. Affected is the function sig_verify() of the file x509.c of the component PKCS #1 Handler. The manipulation ... read more
  • Foscam C2/Application/Opticam i5 Password Default Credentials weak authentication
    A vulnerability, which was classified as critical, has been found in Foscam C2, Application and Opticam i5 (the affected version is unknown). Affected by this issue is an unknown function. ... read more
  • lighttpd up to 1.4.49 mod_alias_physical_handler mod_alias.c directory traversal
    A vulnerability was found in lighttpd up to 1.4.49. It has been rated as critical. Affected by this issue is an unknown function of the file mod_alias.c of the component ... read more
  • DeDeCMS 5.7 dedeco_do.php ids sql injection
    A vulnerability was found in DeDeCMS 5.7. It has been classified as critical. This affects an unknown function of the file dedeco_do.php. The manipulation of the argument ids as part ... read more
  • Foscam C2/Application/Opticam i5 Password Default Credentials weak authentication
    A vulnerability classified as critical was found in Foscam C2, Application and Opticam i5 (the affected version is unknown). Affected by this vulnerability is an unknown function. The manipulation of ... read more
  • Micro Focus Operations Bridge Containerized Suite 2017.11/2018.02/2018.05/2018.08 Code Execution
    A vulnerability has been found in Micro Focus Operations Bridge Containerized Suite 2017.11/2018.02/2018.05/2018.08 and classified as critical. This vulnerability affects an unknown function. The manipulation with an unknown input leads ... read more
  • Foscam C2/Application/Opticam i5 1.11.1.8 Password Default Credentials weak authentication
    A vulnerability classified as critical has been found in Foscam C2, Application and Opticam i5 1.11.1.8. Affected is an unknown function. The manipulation of the argument Password with the input ... read more
  • Foscam C2/Application/Opticam i5 CGIProxy.fcgi unknown vulnerability
    A vulnerability, which was classified as critical, was found in Foscam C2, Application and Opticam i5 (the affected version is unknown). This affects an unknown function of the file CGIProxy.fcgi?cmd=setTelnetSwitch. ... read more
  • nginx up to 1.14.0/1.15.5 ngx_http_mp4_module Loop denial of service
    A vulnerability, which was classified as problematic, was found in nginx up to 1.14.0/1.15.5. This affects an unknown function of the component ngx_http_mp4_module. The manipulation with an unknown input leads ... read more
  • axTLS up to 2.1.3 ASN.1 x509.c sig_verify() Certificate denial of service
    A vulnerability was found in axTLS up to 2.1.3. It has been declared as problematic. This vulnerability affects the function sig_verify() of the file x509.c of the component ASN.1 Handler. ... read more
  • Foscam C2/Application/Opticam i5 weak authentication [CVE-2018-19063]
    A vulnerability was found in Foscam C2, Application and Opticam i5 (the affected version is unknown). It has been declared as critical. This vulnerability affects an unknown function. The manipulation ... read more
  • MetInfo 6.1.3 index.php abt_type cross site scripting
    A vulnerability was found in MetInfo 6.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown function of the file admin/index.php?a=dogetpassword. The manipulation of the argument ... read more
  • MetInfo 6.1.3 index.php langset cross site scripting
    A vulnerability was found in MetInfo 6.1.3. It has been classified as problematic. Affected is an unknown function of the file admin/index.php?a=dogetpassword. The manipulation of the argument langset as part ... read more
  • Vuln: Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability
    Apache Tomcat CVE-2018-1304 Security Bypass Vulnerability ... read more
  • Vuln: Apache Tomcat Native Connector CVE-2018-8019 Remote Security Vulnerability
    Apache Tomcat Native Connector CVE-2018-8019 Remote Security Vulnerability ... read more
  • 64.015
    Newly Added (1)Android/Ctchm.C!trModified (10)Adware/Apofer!AndroidAdware/Hiddad!AndroidAdware/Wiyun!AndroidAndroid/Agent.ACY!trAndroid/Agent.CMH!trAndroid/Android_Wapsx.GAndroid/Obfus.KA!trRiskware/FakeApp!AndroidRiskware/SmsPay!AndroidRiskware/SmsReg!Android ]]> ... read more
  • StatCounter fingers cache-poisoning caper for Bitcoin-slurping JavaScript hijack (The Register)
    ... read more
  • Troj/PDFUri-GLC
    ... read more
  • 64.014
    Newly Added (1)Android/Generic.AP.22707C!trModified (8)Adware/Mytrackp!AndroidAndroid/Agent.CEQ!trAndroid/Ctchm.C!trAndroid/Generic.AP.154E9D4!trAndroid/Hiddad.SP!trAndroid/SmsSpy.IT!tr.spyRiskware/Dnotua!AndroidRiskware/FakeApp!Android ]]> ... read more
  • South Australia Police to be able to compel passwords and biometrics from suspects (ZDNet)
    ... read more
  • 64.013
    Modified (6)Adware/Kuguo!AndroidAdware/MobiDash!AndroidAndroid/Agent.CEQ!trAndroid/Agent.CMW!trAndroid/Hiddad.AL!trRiskware/SmsReg!Android ]]> ... read more
  • CVE-2018-19090
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** tianti 2.3 has stored XSS in the article management module via an article title. ... read more
  • CVE-2018-19089
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-adminsrcmainwebappWEB-INFviewsuseruser_list.jsp. ... read more
  • CVE-2018-16150
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data ... read more
  • CVE-2018-16253
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ... read more
  • CVE-2018-16149
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths ... read more
  • CVE-2018-19091
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter. ... read more
  • CVE-2018-19093
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** ** DISPUTED ** An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/client_control.c. NOTE: ... read more
  • CVE-2018-19092
    Gravedad: NonePublicado: 07/11/2018Last revised: 07/11/2018Descripción: *** Pendiente de traducción *** An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html ... read more
  • 30 Years Ago, the World’s First Cyberattack Set the Stage for Modern Cybersecurity Challenges (SecurityWeek)
    ... read more
  • 64.012
    Newly Added (1)Android/Obfus.KA!trModified (5)Adware/Dowgin!AndroidAndroid/Agent.ACY!trAndroid/Agent.BQH!trAndroid/Banker.AJH!tr.spyAndroid/Hiddad.HI!tr ]]> ... read more
  • ISC Stormcast For Thursday, November 8th 2018 https://isc.sans.edu/podcastdetail.html?id=6246, (Thu, Nov 8th)
    ... read more
  • ISC StormCast for Thursday, November 8th 2018
    VirtualBox 0 Day Guest Escape Exploit Released https://github.com/MorteNoir1/virtualbox_e1000_0dayWooCommerce / Wordpress Bug Leads to RCE https://blog.ripstech.com/2018/wordpress-design-flaw-leads-to-woocommerce-rce/Bing Advertises Fake Version of Notepad2 https://www.bleepingcomputer.com/news/security/beware-of-unofficial-sites-pushing-notepad2-adware-bundles/Jacksonville BSides https://bsidesjax.org ... read more
  • RKL KeyLogger
    ... read more
  • Android Skymobi Pay
    ... read more
  • Remote Admin Tool TektonIT
    ... read more

Matisse & Co @2019

KAVI MCO iSTRACIN Platform v 02.25 Tuesday, August 26, 2025

  • Disclaimer |
  • Terms |
  • Privacy
  • About-Services
  • Blog-Reports
  • YouTube
  • Pinterest
  • LinkedIn
  • Twitter
  • LinkedIn
  • Twitter
  • Connect-Contact

Login

Login to Matisse & Co Competitive Intelligence

Forgot password?
Register Now

Hello

  • Your Account Type is
  • Your Mail Id is
  • Your Username is

Security Briefing Search

PDF Library Search

Search

Reset Password

Reset Password

You have no permission to access this content