Security News

Amnimo to develop an industrial-use LTE gateway, Edge Gateway
2020-03-24 02:00

To resolve such issues, Amnimo is developing the Edge Gateway, which is optimized for IIoT. The objective is to equip the Edge Gateway with LTE communication features that can be used in a wide variety of industries; in particular, to develop an optimal design for use in surveillance-camera systems. Amnimo Edge Gateway characteristics Wide operating temperature range and power voltage range.

First patches for the Citrix ADC, Gateway RCE flaw released
2020-01-21 14:58

As attackers continue to hit vulnerable Citrix ADC and Gateway installations, Citrix has released permanent fixes for some versions and has promised to provide them for other versions and for two older versions of SD-WAN WANOP by January 24. CVE-2019-19781, a critical vulnerability affecting Citrix ADC and Gateway that may allow unauthenticated attackers to achieve remote code execution and obtain direct access to an organization's local network from the internet, was responsibly disclosed last December.

Citrix emits patches to stop RCE-holes fiddling with Gateway and ADC
2020-01-20 17:40

Citrix has rushed out official fixes for the well-publicised vuln in some of its server products after miscreants were seen deploying their own custom patches that left a backdoor open for later exploitation. As previously reported, vulnerabilities in Citrix Application Delivery Encoder and Citrix Gateway could allow remote attackers to carry out unauthenticated code execution.

Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don't work for older kit
2020-01-16 23:13

Easy-to-use exploits have emerged online for two high-profile security vulnerabilities, namely the Windows certificate spoofing bug and the Citrix VPN gateway hole. Within hours of the NSA going public with details about its prized bug find, exploit writers posted working code demonstrating how the flaw can be abused to trick unpatched Windows computers into accepting fake digital certificates - which are used to verify the legitimacy of software, and encrypt web connections.

Microsoft fixes critical bugs in CryptoAPI, RD Gateway and .NET
2020-01-15 12:10

The CryptoAPI cryptographic bug that Microsoft reported in its Patch Tuesday release yesterday was so big that it warranted its own story. Among the most serious bugs were remote code execution flaws affecting the Windows Remote Desktop Gateway, which is a Microsoft service that lets authorised remote users connect to resources on a network via the Remote Desktop Connection client.

Exploits for Citrix ADC and Gateway flaw abound, attacks are ongoing
2020-01-13 11:53

With several exploits targeting CVE-2019-19781 having been released over the weekend and the number of vulnerable endpoints still being over 25,000, attackers are having a field day. Some other researchers then published exploits and scanners for it.

PoC Exploits Released for Citrix ADC and Gateway RCE Vulnerability
2020-01-11 02:22

Why the urgency? Earlier today, multiple groups publicly released weaponized proof-of-concept exploit code [1, 2] for a recently disclosed remote code execution vulnerability in Citrix's NetScaler ADC and Gateway products that could allow anyone to leverage them to take full control over potential enterprise targets. Just before the last Christmas and year-end holidays, Citrix announced that its Citrix Application Delivery Controller and Citrix Gateway are vulnerable to a critical path traversal flaw that could allow an unauthenticated attacker to perform arbitrary code execution on vulnerable servers.

Attackers exploiting critical Citrix ADC, Gateway flaw, company yet to release fixes
2020-01-09 13:56

Nearly a month has passed since Citrix released mitigation measures for CVE-2019-19781, a critical vulnerability affecting Citrix Application Delivery Controller and Citrix Gateway, which could lead to remote code execution. Citrix Gateway is a secure remote access network gateway solution that is offered as a cloud service or an on-premises solution.

Comcast launches xFi Advanced Gateway, a WiFi 6 certified device
2020-01-09 03:30

The nation's largest gigabit speed provider, now becomes one of the first U.S. Internet Service Providers to offer a WiFi 6 Certified gateway delivering faster speeds, ultimate capacity, lower latency and best-in-class WiFi coverage throughout the home. The xFi Advanced Gateway is designed for high-performance users to handle more capacity for even more smart home devices coming online today and in the future.

Comcast announces new Wi-Fi 6-certified gateway, security features for internet customers at CES 2020
2020-01-06 22:00

Comcast is making its internet service faster and more secure with new hardware and free security features that alerts customers to threats. Comcast Xfinity made two big announcements at CES 2020: It's going to have a fast new gateway available, and it's making important security features available for free to its internet customers.