Showing posts with label desktop. Show all posts
Showing posts with label desktop. Show all posts

Friday, November 22, 2019

Kaspersky uncovers 37 vulnerabilities in open-source VNC systems; exploitation could lead to remote code execution

Kaspersky presented on Friday an analysis of open source Virtual Network Computing (VNC) which uncovered memory corruption vulnerabilities that existed in a substantial number of projects for a significant period of time. 

According to shodan.io, the exploitation of some detected vulnerabilities could lead to remote code execution affecting the users of VNC systems, which amounts to over 600,000 servers accessible from the global network. 


VNC systems provide remote access to one device from another through the use of remote frame buffer (RFB) protocol. Due to its availability on multiple platforms and presence of multiple open sources, VNC systems have become some of the more popular desktop sharing tools to date. 

They are actively used in automated industrial facilities enabling remote control of systems, and approximately 32% of industrial network computers having some form of remote administration tools, including VNC.


The prevalence of such systems in general, and particularly ones that are vulnerable, is a significant issue for the industrial sector as potential damages can bring significant losses through disruption of complex production processes. 

As such, Kaspersky researchers studied some VNC systems including LibVNC, UltraVNC, TightVNC1.X and TurboVNC.

Although these VNC projects were previously analyzed by other researchers, not all vulnerabilities were uncovered and patched. As a result of Kaspersky’s analysis, 37 CVE records marking various vulnerabilities were created. 


Vulnerabilities were found not only on the client, but also on the server-side of the system. Some allowed remote code execution, which can then permit a malicious actor to make arbitrary changes on the attacked systems. Alternatively, many server-side vulnerabilities could only be exploited after password authentication, and some servers do not allow password-free access.

Wednesday, November 13, 2019

HiveIO updates Hive Fabric 7.4 to offer optimum security, modern integrations for IT professionals

HiveIO Inc. released version 7.4 of Hive Fabric, an Artificial Intelligence (AI) ready solution that enables organizations to deploy virtualization technology without vendor complexity or the need for specialists. This software release provides Hive Fabric users with increased security and efficiency-enhancing integrations, furthering operational-focused capabilities and removing overhead associated with the day-to-day support of virtualization.

  
Hive Fabric enables users to deploy virtual desktops, virtual servers, and software-defined storage in a single install, eliminating the need for a multi-vendor and multi-contract approach. To further remove common limitations such as inefficient deployments and unreliable applications, the release of 7.4 builds on core performance capabilities to deliver a system that doesn’t just work – it outperforms other solutions. 

Security vulnerabilities are a top concern for IT vendors. Users can now apply an optional layer of security to the desktop broker by enabling two-factor authentication (2FA). This will require end-users to use both a password and a second form of validation to access a desktop. The new authentication includes a wide variety of third party 2FA and multi-factor authentication (MFA) support, including Microsoft Azure MFA and RADIUS enabling solutions like Imprivata.

With the new Gateway Mode, users can place a server or virtual machine (VM) running Hive Fabric in a demilitarized zone. This enhances the security of an environment through the separation of roles and responsibilities for each server. 


By assigning the Gateway role to a Hive Fabric server, it will automatically configure itself and minimize the functionality it provides in the cluster. Additionally, Gateway Mode reduces the number of internet-facing components, such as ports and services, for added security.

Administrative activities should be as simple as possible. Now, administrators can upload an update or new version, and automatically apply this to the entire cluster with a single click.


“Technology should be transformative. We want to enable customers to focus on innovating for their business, not supporting its infrastructure,” said Toby Coleridge, VP of Product. “With the release of Hive Fabric 7.4, we continue to remove the complexities associated with manual configuration to drive end-user experience to new levels of efficiency.”

“Our customers chose Hive Fabric because it can be deployed, operational, and production-ready in a fraction of the time of legacy virtualization solutions,” said Dan Newton, CEO of HiveIO. “Since the launch of 7.0, Hive Fabric continues to remove traditional operational friction to deliver the next generation of responsive, reliable technology that allows doctors to see more patients, students to access education, and employees to develop new business solutions.”

Saturday, November 2, 2019

Fedora 31 generally available; begin push towards innovations around emerging IT use cases like IoT and Linux containers

The Fedora Project, a Red Hat Inc. sponsored and community-driven open source collaboration, announced general availability of Fedora 31, the latest version of the fully open source Fedora operating system. Fedora 31 includes new features that help to address a host of modern computing challenges, from building and running cloud native applications to driving innovation in the connected world.

Each Fedora edition is designed to address specific use cases for modern developers and IT teams with Fedora Workstation and Fedora Server providing open operating systems built to meet the needs of forward-looking developers and server projects. 


Fedora 31 also sees the continued evolution of emerging Fedora editions, including Fedora CoreOS, Fedora IoT and Fedora Silverblue. Fedora 31 brings enhancements to all editions with updates to the common underlying packages, from bug fixes and performance tweaks to new versions. 

This release now includes updated compilers and languages, including NodeJS 12, Perl 5.30 and Golang 1.13. Additionally the "python" command will now refer to Python 3. It also provides support for Cgroupsv2, bringing kernel level support for the latest features and functionality around cgroups in the base packages of Fedora 31. This helps lay the foundation for improved performance and new capabilities in building and running containerized applications.


The new version offers switching RPM compression to ztsd, which decreases the amount of compression time needed and improves the overall performance of processes using binary RPMs; and comes with support for RPM 4.15, the latest version of the RPM Package Manager for enhanced performance and stability across all versions of Fedora.


Fedora 31 also includes key updates to Fedora’s desktop-focused edition, Fedora 31 Workstation. Fedora 31 Workstation provides new tools and features for general users as well as developers with the inclusion of GNOME 3.34. 

GNOME 3.34 brings significant performance enhancements which will be especially noticeable on lower-powered hardware. Fedora 31 Workstation also expands the default uses of Wayland, including allowing Firefox to run natively on Wayland under GNOME instead of the XWayland backend as with prior releases.


Additionally, Fedora CoreOS, Fedora IoT and Fedora Silverblue continue to evolve and be updated to better meet the requirements of modern IT, which is powered by Linux containers, Kubernetes and cloud computing. The emerging Fedora editions remain available in preview.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...