
Cybersecurity Alerts: Vulnerabilities in eSafeNet CDG 3, Hospitality Wi-Fi Exploits, Apple Gatekeeper Bypass, and Supply Chain Protections
On July 27, 2020, the SANS Internet Storm Center reported increased scanning activity targeting eSafeNet CDG 3, a Chinese document management and data leakage prevention system. The scans focused on a hard-coded password vulnerability, one of three known flaws in the product, alongside cross-site scripting (XSS) and SQL injection vulnerabilities. Separately, ReliaQuest documented attacks by Russian threat actors exploiting hospitality Wi-Fi gateways to alter DNS settings, redirecting users to malicious servers to harvest Outlook 365 credentials via fake login pages. Researchers Talal Hasham Bakry and Tommy Mysk disclosed an Apple Gatekeeper bypass where attackers could replace user-installed applications without detection by archiving and restoring them, a flaw Apple declined to fix. GitHub introduced a 3-day delay for Dependabot updates to mitigate supply chain attacks, while PyPI enforced a 14-day window for authors to modify package files before requiring a new release. The video also warned about captive portal hijacking risks in public Wi-Fi networks, where malicious redirects could trick users into credential theft.