July 24, 2018
Vulnerability Notification: Asterisk PJSIP Endpoint Presence Disclosure
[Overview] Asterisk is an open source software that implements the Private Branch eXchange (PBX) of telephone, allowing multiple affiliated telephones or user agents to call each other and connect to other telephone services, including the Public Switched Telephone Network (PSTN), via trunks. Recently, Asterisk fixed an information disclosure vulnerability. [Vulnerability Details] CVE-2018-12227: This vulnerability is…July 17, 2018
Announcing the Hillstone Security Audit platform (HSA) 2.0R4
We are proud to announce the release of the Hillstone Security Audit platform, HSA 2.0R4 This new version is based on a new architecture, has a new web user interface, and is optimized for operational stability, along with geo-location friendly features. New features highlights: New web-based user interface optimized for user experience and stability Support…July 10, 2018
Vulnerability Notification: Adobe ColdFusion DataServicesCFProxy ROME Framework Insecure Deserialization
[Overview] Adobe ColdFusion is an application development platform. The Flex integration service includes ColdFusion, which allows Flash applications to communicate with the ColdFusion server via Java RMI. Recently, Adobe fixed a deserialization vulnerability in AdobeCloudFusion Flex integration service. [Vulnerability Details] CVE-2018-4939: This vulnerability is caused by a lack of input validation for RMI method parameters…July 6, 2018