Tarnkappe.info · @tarnkappeinfo
2039 followers · 4373 posts · Server social.tchncs.de
Patrick Donegan · @HardenStance
46 followers · 43 posts · Server infosec.exchange

Which was worse? Day after day waiting to learn the fate of those who were on the Russian submarine Kursk back in 2000? Or waiting to see what becomes of once Singtel finally announces that it is going to do something - anything - with it?

#trustwave

Last updated 2 years ago

6beer · @6beer
7 followers · 41 posts · Server infosec.exchange

```
For the digital processing of value-added tax (VAT) returns, the Chinese government has implemented the Golden Tax the Chinese government has implemented the Golden Tax program. Companies operating in China are required to use the software to file their VAT returns. However, the Golden Tax software is not directly distributed by the distributed by the government, but by two companies, Baiwang and Aisino, which integrate it into their products. It seems that
that the selection of either of these vendors is decided by the companies' Chinese banks.

On June 25, 2020, Singaporean cybersecurity firm published a report [3] revealing that the installation of Chinese VAT management software Aisino Intelligent Tax led to the deployment of what amounts to a backdoor, dubbed "" by the vendor. Two hours after the installation of the VAT management software, codes are downloaded and then silently executed. They have persistence mechanisms, communicate at a random frequency with a remote server and allow the execution of arbitrary codes with system administrator privileges without user interaction.
```
cert.ssi.gouv.fr/uploads/CERTF

#goldentax #trustwave #GoldenSpy #anssi #infosec

Last updated 2 years ago

6beer · @6beer
20 followers · 138 posts · Server infosec.exchange

```
For the digital processing of value-added tax (VAT) returns, the Chinese government has implemented the Golden Tax program. Companies operating in China are required to use the software to file their VAT returns. However, the Golden Tax software is not directly distributed by the distributed by the government, but by two companies, Baiwang and Aisino, which integrate it into their products. It seems that
that the selection of either of these vendors is decided by the companies' Chinese banks.

On June 25, 2020, Singaporean cybersecurity firm published a report [3] revealing that the installation of Chinese VAT management software Aisino Intelligent Tax led to the deployment of what amounts to a backdoor, dubbed "" by the vendor. Two hours after the installation of the VAT management software, codes are downloaded and then silently executed. They have persistence mechanisms, communicate at a random frequency with a remote server and allow the execution of arbitrary codes with system administrator privileges without user interaction.
```
cert.ssi.gouv.fr/uploads/CERTF

#goldentax #trustwave #GoldenSpy #anssi #infosec

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

ASUS Home Router Bugs Open Consumers to Snooping Attacks - The two flaws allow man-in-the-middle attacks that would give an attacker access to all data flowi... more: threatpost.com/asus-home-route -2020-15498 -2020-15499 -ac1900p

#bug #iot #mitm #asus #patch #trustwave #rt #homerouter #websecurity #maninthemiddle #firmwareupdate #cve #totalcompromise #vulnerabilities #securityvulnerability

Last updated 4 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online