News

June 12, 2018

In the last few months our office has received an increasing number of laptop theft reports. These incidents occurred both on and off campus, and in varying circumstances, however in all the recent cases the laptops involved were not configured for Full Disk Encryption (FDE). In a few of these cases, the laptops were used to access sensitive data as part of campus business processes, and the Security team is concerned about possible data exposure due to lost and stolen devices with access to campus protected data. 

April 26, 2018

NOTE: These vulnerabilities are already being exploited in the wild. If you have an affected Drupal site, update IMMEDIATELY!

Summary

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. [1]

March 28, 2018

NOTE: Drupal core developers have stated that exploits for this vulnerability will likely be developed within days. Drupal site owners must take action immediately or risk complete compromise of their sites. 

Summary

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. [1]

Impact

This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised. [1]

March 14, 2018

The IST-Telecommunications networking group will begin piloting the new bSecure Campus VPN service in the coming weeks. Eventually, this service will become the replacement for the existing Cisco AnyConnect based Campus Remote Access VPN service.

March 2, 2018

Summary

Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow an attacker to execute arbitrary code.  PHP is a programming language originally designed for use in web-based applications with HTML content.  PHP supports a wide variety of platforms and is used by numerous web-based software applications.  [1]

February 22, 2018

Summary

Multiple critical vulnerabilities have been discovered in Drupal core. [1]

Impact

Attackers may be able to view restricted content or add content of their own. Additionally, a JavaScript function in Drupal core may allow attackers to perform cross-site scripting attacks. 

January 31, 2018

The bSecure team would like to provide an update on our planned migration to the new firewall services in the Data Center.

Data Center Firewall Administrator Training

As previously announced, we will be holding two on-campus training sessions for Data Center Firewall Administrators.  Both sessions are identical, so you only need to attend one.  The Dates for these one day sessions will be:

January 19, 2018

 Phishing Leads the IRS List of Tax ScamsThe Internal Revenue Service has reported a big spike in phishing and malware incidents during the 2016 and 2017 tax seasons.

January 12, 2018

The bSecure project team would like to provide the Campus IT community, and especially administrators of existing firewall services, with an update on the planned migration to the new service, and information on what to expect next.

January 5, 2018

Summary

A team of security researchers disclosed several software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from many types of computing devices with many different vendors’ processors and operating systems. 

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. [1]

December 4, 2017

The Network Operations and Services team and the Information Security and Policy group are implementing bSecure, a new firewall and information security service for campus. This service will replace the existing Cisco ASA-based Data Center and Campus Departmental Firewall services.

November 29, 2017

Summary

Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow an attacker to execute arbitrary code.  Successfully exploiting the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the affected application.  [1]

October 18, 2017

Summary

The Oracle Critical Patch Update for October, 2017, contains an unusually high number of patches for vulnerabilities that may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.

October 17, 2017

Researchers have discovered serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks.  This includes everything from computers, tablets, phones, home wireless routers and any device that supports WPA2 over Wi-Fi.

While details are still emerging, not all vendors have released patches as of yet.  So, in some cases, there will be little users can do until patches are released.   An attacker needs to be in range of an access-point to leverage this attack.  

September 6, 2017

Summary

A critical vulnerability has been discovered in the Apache Struts web application framework for Java web applications. A remote code execution attack is possible when using the Apache Struts REST plugin with XStream handler to deserialise XML requests. [1]

Impact

Attackers can execute arbitrary code remotely by exploiting this vulnerability.

July 17, 2017

The bSecure team invites you to join us for a series of Town Hall events this month. All are welcome and existing Campus firewall customers are strongly encouraged to attend.

What?

The purpose of these Town Hall events is to introduce Campus to the bSecure project and its team. Topics will include:

June 14, 2017

Summary

A remote code execution vulnerability exists when Windows Search handles objects in memory.  This can be exploited by an attacker sending a specially crafted SMB message to the Windows Search service. [4]

Due to recent nation-state activity and the elevated risk of potential cyber attacks, Microsoft has released security updates for older unsupported versions of Windows for this issue as well as other high-severity fixes in the June patch release. [1]

June 1, 2017

bSecure is the new initiative from the Network Operations & Services and Information Security & Policy teams to replace legacy firewalls and VPN, and provide proactive security technologies to Campus.

You can access all bSecure project information at http://bsecure.berkeley.edu or https://security.berkeley.edu/projects/bsecure.

May 25, 2017

Summary

The samba team has released a patch for a Remote Code Execution bug that affects all versions between 3.5.0 and 4.6.3/4.5.9/4.4.13. This vulnerability will allow a malicious attacker to upload a library to a writable share then cause the server to execute that library. [1] Patches are available from the samba.org. [2]

May 3, 2017

To the campus community,