Thursday, March 1, 2018

IBM Security Bulletin: IBM Tivoli Netcool Impact is affected by an Open Source Apache Poi vulnerability (CVE-2017-5644)

IBM Tivoli Netcool Impact has addressed the following vulnerability Open Source Apache Poi vulnerability (CVE-2017-5644).

CVE(s): CVE-2017-5644

Affected product(s) and affected version(s):

IBM Tivoli Netcool Impact 7.1.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22014107
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/123699

The post IBM Security Bulletin: IBM Tivoli Netcool Impact is affected by an Open Source Apache Poi vulnerability (CVE-2017-5644) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2t9rhaW

CASBs and Education’s Flight to the Cloud

By Jacob Serpa, Product Marketing Manager, Bitglass

Cloud is becoming an integral part of modern organizations seeking productivity and flexibility. For higher education, cloud enables online course creation, dynamic collaboration on research documents, and more. As many cloud services like G Suite are discounted or given to educational institutions for free, adoption is made even simpler. However, across the multiple use cases in education, comprehensive security solutions must be used to protect data wherever it goes. The vertical as a whole needs real-time protection on any app, any device, anywhere.

The Problems
For academic institutions, research is often of critical importance. Faculty members create, share, edit, and reshare various documents in an effort to complete projects and remain at the cutting edges of their fields. Obviously, using cloud apps facilitates this process of collaboration and revision. However, doing so in an unsecured fashion can allow proprietary information to leak to unauthorized parties.

Another point of focus in education is how student and faculty PII (personally identifiable information) is used and stored in the cloud. As information moves to cloud apps, traditional security solutions fail to provide adequate visibility and control over data. Obviously, this creates compliance concerns with regulations, like FISMA and FERPA, that aim to protect personal information. Medical schools have the additional requirement of securing protected health information (PHI) and complying with HIPAA.

The Solutions
Fortunately, cloud access security brokers (CASBs) offer a variety of capabilities that address the above security concerns. Data leakage prevention, for example, can be used to protect data and reach regulatory compliance. DLP policies allow organizations to redact data like PII, quarantine sensitive files, and watermark and track documents. Encryption can be used to obfuscate sensitive data and prevent unauthorized users from viewing things like PHI. Contextual access controls govern data access based on factors like user group, geographical location, and more.

To secure cloud, present-day organizations must also secure mobile data access. Fortunately, agentless mobile security solutions enable BYOD without requiring installations on unmanaged devices. This is critical for ensuring device functionality, user privacy, and employee adoption. Some agentless solutions can enforce device security configurations like PIN codes, selectively wipe corporate data on any device, and more.

The post CASBs and Education’s Flight to the Cloud appeared first on Cloud Security Alliance Blog.



from Cloud Security Alliance Blog http://ift.tt/2CQhPcr

Russians suspected of new German attack may 'have been inside system for a year'

Chafer: Hacking group expands espionage operation with new attacks

French news site L'Express exposed reader data online, weeks before GDPR deadline

Wednesday, February 28, 2018

USN-3579-2: LibreOffice regression

Ubuntu Security Notice USN-3579-2

28th February, 2018

libreoffice regression

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 17.10

Summary

USN-3579-1 caused a regression in LibreOffice.

Software description

  • libreoffice - Office productivity suite

Details

USN-3579-1 fixed a vulnerability in LibreOffice. After upgrading, it was
no longer possible for LibreOffice to open documents from certain
locations outside of the user's home directory. This update fixes the
problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that =WEBSERVICE calls in a document could be used to
read arbitrary files. If a user were tricked in to opening a specially
crafted document, a remote attacker could exploit this to obtain sensitive
information. (CVE-2018-6871)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 17.10:
libreoffice-common 1:5.4.5-0ubuntu0.17.10.4

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart LibreOffice to make
all the necessary changes.

References

LP: 1751005



from Ubuntu Security Notices http://ift.tt/2COr4tw

You can use a ​VPN to battle ISP net neutrality abuse