Threat Intelligence

3/5/2018
05:00 PM
50%
50%

CERT.org Goes Away, Panic Ensues

Turns out the Carnegie Mellon CERT just moved to a newly revamped CMU Software Engineering Institute website.

When a major security-based website goes away, people notice and often assume the worst. So while the Carnegie Mellon Computer Emergency Response Team (CERT)'s stand-alone website recently was removed, it caused some confusion. It turns out the CERT remains in operation.

A blog post by Risk Based Security reflected the uncertainty that ensued in the wake of the recent disappearance of the cert.org site. The confusion began after a tweet by a CERT employee that the website had been removed. Risk Based Security then found that the content of cert.org had folded into the Software Engineering Institute website at Carnegie Mellon. It seemed ominous that typing in the former CERT URL took visitors not to the CERT site, but to the site of the SEI.

"The important thing is that this [website change] doesn't portend anything about CERT itself," a CERT spoksperson said, adding that the work of CERT is more important than ever.

All of the information formerly found at cert.org - from blog posts to podcasts to research reports - is available at www.sei.cmu.edu, and CERT's knowledge base of security issues remains accessible under its traditional URL, https://kb.cert.org.

CERT announced the changes in late January, he said. "We put banners on most of the main websites, and on the blog and resource library and other sites, we put splashes up about a month in advice. We gave a link to preview the new site well ahead of the launch," the spokesperson said. "We were managing a large number of external Web properties. These were two of the largest and for a variety of organizational reasons we decided to combine them," he said.

Read more here and here.

Interop ITX 2018

Join Dark Reading LIVE for two cybersecurity summits at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the Interop ITX 2018 agenda here.

Related Content:

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7715
PUBLISHED: 2019-03-26
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell handler function uses the value of the environment variable ipcom.shell.greeting as the first argument to printf(). Setting this variable using the sysvar command results in a user-c...
CVE-2019-8981
PUBLISHED: 2019-03-26
tls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because the need_bytes value is mismanaged.
CVE-2019-10061
PUBLISHED: 2019-03-26
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
CVE-2019-7711
PUBLISHED: 2019-03-26
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The undocumented shell command "prompt" sets the (user controlled) shell's prompt value, which is used as a format string input to printf, resulting in an information leak of memory addre...
CVE-2019-7712
PUBLISHED: 2019-03-26
An issue was discovered in handler_ipcom_shell_pwd in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. When using the pwd command, the current working directory path is used as the first argument to printf() without a proper check. An attacker may thus forge a path contain...