Security News

How attackers target and exploit Microsoft Exchange servers
2020-06-25 10:38

Microsoft Exchange servers are an ideal target for attackers looking to burrow into enterprise networks, says Microsoft, as "They provide a unique environment that could allow attackers to perform various tasks using the same built-in tools or scripts that admins use for maintenance." According to Microsoft, April was the month when multiple campaigns began to target Exchange servers.

The state of OpenPGP key servers: Kristian, can you renew my certificate? A month later: Kristian? Ten days later: Too late, it’s expired
2020-06-24 00:05

"Hi all, Has anyone seen or heard from Kristian in the last month or so?" asked Todd Fleisher earlier this month - in fact, 11 June - on the main mailing list for an important cluster of OpenPGP key servers. Fiskerstrand, who had seemingly gone AWOL, issues cryptographic certificates to servers that join the SKS keyserver pools, allowing these volunteer machines to share the load in securely handling key lookup requests.

Inspur eleases NF5468M6 and NF5468A5 AI servers supporting NVIDIA A100 PCIe Gen 4 GPU at ISC20
2020-06-24 00:00

Thanks to its agile and strong product design and development capabilities, Inspur is one of the first in the industry to support the NVIDIA A100 Tensor Core GPU and build up a comprehensive and competitive next-generation AI computing platform. The NVIDIA A100 offers multi-instance GPU technology, which enables a single GPU to be partitioned into seven hardware-isolated instances to work on multiple networks simultaneously.

XORDDoS, Kaiji DDoS Botnets Target Docker Servers
2020-06-23 12:06

The distributed denial-of-service botnets named XORDDoS and Kaiji recently started targeting exposed Docker servers, Trend Micro warned on Monday. Trend Micro has recently spotted variants that also target Docker servers.

IBM Maximo Asset Management servers patched against attacks
2020-06-19 13:44

To explain: SSRF is a way that someone with possibly very limited access to your network can send a legitimate looking query to one of your servers. If you can trick the vulnerable server into calling outside its own network by sending it an otherwise legimitate request, you may be able to capture server data such as secret authentication tokens or special HTTP headers that are usually only visible if you are already inside the network.

Drupal Patches Code Execution Flaw Most Likely to Impact Windows Servers
2020-06-18 12:37

Updates released this week by Drupal patch several vulnerabilities, including a flaw that could allow an attacker to execute arbitrary PHP code. The code execution vulnerability, tracked as CVE-2020-13664, can be exploited against Drupal 8 and 9 installations, but only in certain circumstances.

Global server market revenue declined 6.0% year over year in 1Q20
2020-06-12 03:30

Vendor revenue in the worldwide server market declined 6.0% year over year to $18.6 billion during the first quarter of 2020. Worldwide server shipments declined 0.2% year over year to just under 2.6 million units in 1Q20, IDC reveals.

Details of Serious SAP Adaptive Server Enterprise Vulnerabilities Disclosed
2020-06-03 15:03

Cybersecurity firm Trustwave on Wednesday disclosed the details of several vulnerabilities found by its researchers in SAP Adaptive Server Enterprise. SAP ASE is a relational database management system that is used by many major organizations, particularly in the financial sector.

Newly Patched SAP ASE Flaws Could Let Attackers Hack Database Servers
2020-06-03 06:10

A new set of critical vulnerabilities uncovered in SAP's Sybase database software can grant unprivileged attackers complete control over a targeted database and even the underlying operating system in certain scenarios. A second vulnerability concerns ASE Cockpit, a web-based administrative console that's used for monitoring the status and availability of ASE servers.

Newly Patched SAP ASE Flaws Could Let Attackers Hack Database Servers
2020-06-03 06:10

A new set of critical vulnerabilities uncovered in SAP's Sybase database software can grant unprivileged attackers complete control over a targeted database and even the underlying operating system in certain scenarios. A second vulnerability concerns ASE Cockpit, a web-based administrative console that's used for monitoring the status and availability of ASE servers.