PREVIOUS GNEWS Mar – 13 Patches – 6 Critical – 30 CVEs MS16-037 - Cumulative Security Update for IE MS16-038 - Cumulative Security Update for Microsoft.

Slides:



Advertisements
Similar presentations
PREVIOUS GNEWS. ? Patches – ? Critical – ? CVEs Affected – ? Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS NEXT WEEK FOOL Patch.
Advertisements

PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – RDP, IE, Lync, Windows Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 11 Patches – 5 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS IE, Remote Execution.
. 15 Patches / 32 Vulns – 9 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 13 Patches – 5 Critical Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
GNEWS PREVIOUS. Feb - 14 Patches – 5 Critical - 45 CVEs MS Cumulative Security Update for IE MS VBScript Scripting, Remote Code MS
PREVIOUS GNEWS. Oct - 8 Patches – 3 Critical - 24 CVEs MS Cumulative Security Update for Internet Explorer MS NET Framework, Remote Code.
 . Apr - 8 Patches – 2 Critical - 45 CVEs MS Cumulative Security Update for IE, Remote Code MS Windows Media Player, Remote.
PREVIOUS GNEWS. Apr 4 Patches – 2 Critical – 11 CVEs MS Microsoft Word and Office Web Apps, Remote Code MS Cumulative Security Update.
PREVIOUS GNEWS. Feb - 9 Patches – 3 Critical - 55 CVEs MS Update for Internet Explorer MS Windows Kernel-Mode Driver, Remote Code MS
9 Patches – 2 Critical – 12 CVEs Affected – IE, Kernel, SharePoint, Remote Desktop, AD….. Other updates, MSRT, Defender Definitions, Junk Mail Filter.
. Apr - 11 Patches – 4 Critical - 26 CVEs MS Cumulative Security Update for IE MS Office, Remote Code MS HTTP.sys,
PREVIOUS GNEWS. 6 Patches – 1 Critical – 22 CVEs Affected – IE. Kernel, Print, Office MS Cumulative Security Update for Internet Explorer MS
PREVIOUS GNEWS. Patches – 1 Critical Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS DNS Server, DoS –MS Kernal Mode Driver,
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Microsoft Word, Remote.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 20 CVEs Affected – IE, Kernel, Visio, Silverlight Sarepoint,….. Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 2 Patches / 3 Vulns – 1 Critical Affecting Windows XP, Vista, 7, 2003, 2008 Other updates, MSRT, Defender Definitions, Junk Mail Filter.
Previous Gnews. 13 Patches – 8 Critical, Affects pretty much everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS SMBv2.
PREVIOUS GNEWS. July - 6 Patches – 2 Critical - 27 CVEs MS Cumulative Security Update for IE, Remote Code MS – Windows Journal, Remote Code.
PREVIOUS GNEWS. 8 Patches – 3 Critical – 19+ CVEs Affected – GDI, Hyper-V, Outlook, Office, IE, Activex, and more MS Cumulative Security Update.
PREVIOUS GNEWS. 7 Patches – 1 Critical Affecting server builds and powerpoint Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 19 CVEs Affected – Kernel, SQL, Kerberos, Word, HTML, SharePoint Other updates, MSRT, Defender Definitions, Junk.
P  e  i  Gne . 6 Patches, 12 bugs – 3 Critical, Affects Windows, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 6 Patches – 4 Critical – 11 CVEs Affected – SQL, Visual Basic, Visual Foxpro, more… Other updates, MSRT, Defender Definitions, Junk Mail.
PREVIOUS GNEWS. Oct - ? Patches – ? Critical - ? CVEs Come Back Next Week Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
. 6 Patches, 15 bug – 3 Critical, Affects 2000, XP, Srv 2003 / 8, Vista, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. Advanced Notification on Thursday Patch Tuesday.
 . Jul - 15 Patches – 5 Critical - 60 CVEs MS SQL Server, Remote Code MS Security Update for IE MS VBScript Scripting.
PREVIOUS GNEWS. –MS Microsoft XML Core Services, Remote Execution –MS Cumulative Security Update for Internet Explorer –MS Microsoft.
PREVIOUS GNEWS. Jan 4 Patches – 0 Critical – 6 CVEs 9 Patches – 4 Critical – 31+ CVEs MS Microsoft XML Core Services, Info Disclosure MS
PREVIOUS GNEWS. 7 Patches – 6 Critical – 35 CVEs Affected –.NET, GDI+, IE, Defender, DirectShow MS NET Framework and Silverlight, Remote Code.
PREVIOUS GNEWS. try again next week Patch Tuesday.
PREVIOUS GNEWS. 16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative.
Previous Gnews. 5 Patches – x bugs addressed Other updates, MSRT, Defender Definitions, Junk Mail Filter 5 Security Patches - 5 Critical –MS – JScript.
PREVIOU S GNEWS. May 7 Patches – 2 Critical - 70 CVEs MS Remote Desktop, Allow Tampering MS TCP Protocol, DoS MS Microsoft Lync.
PREVIOUS GNEWS A Hacker is You!. 1 Patches – 1 bugs addressed Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 4 Patches / 5 Vulns – 3 Critical Affecting Winodow (all of them), Office, IE, SharePoint,.net Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. Aug - 4 Patches – 1 Critical - 42 CVEs MS – IE Cumulative Security Update, Remote Code MS –.NET Framework, DoS MS –
PREVIOUS GNEWS. 2 Patches – 2 Important Affecting Windows Movie Maker, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS –
PREVIOUS GNEWS. 2 Patches – 2 Critical Affecting VB and Mail Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS – Visual Basic for.
PREVIOUS GNEWS. 3 Patches – 4 Critical – 53+ CVEs Affected – Kernel, AD, SharePoint, Office, and more MS Microsoft SharePoint Server, Remote Code.
Previous Gnews. Patch Tuesday April – 8 Patches (5 high/critical), Windows, Excel, ISA, IE, HTTP Services MS thru MS May – 1 Patch (critical)
PREVIOUS GNEWS. 2 Patches – bugs addressed Affecting Windows (all versions) Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOU S GNEWS. May 9 Patches – 3 Critical - 1 out of band – 14 CVEs MS Security Update for Internet Explorer MS SharePoint Server, Remote.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter 10 Security Patches - 6 Critical, 3 Important, 1 Moderate –MS Active.
PREVIOUS GNEWS. Aug - 9 Patches – 1 Critical - 37 CVEs MS Windows Media Center, Remote Code MS – SQL Server, Privilege Escalation MS
PREVIOUSLY GNEWS Patch Tuesday Nov - 12 Patches – 8 Critical – 60ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS Cumulative Security Update for IE (Aug Out of Band) MS Cumulative.
PREVIOUSLY GNEWS Patch Tuesday Jan – 10 (9) Patches – 6 Critical – 24ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
GNEWS, PREVIOUSLY Patch Tuesday Aug - 6 Patches – 3 Critical - 33 CVEs MS Cumulative Security Update for Internet Explorer MS Cumulative.
GNEWS PREVIOUS. Patch Tuesday jul - x Patches – x Critical - x CVEs Releases Next Week.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter Out of Band Patchs –MS – IE Cumulative Security Update / Activex –MS
PREVIOUS GNEWS. 8 Patches – 6 Critical – 19+ CVEs Affected – Kernel, AD, Exchange, Unicode, ICMP MS Security Update for Internet Explorer, Remote.
PREVIOUS GNEWS Jun – 14 Patches – 7 Critical – 47 CVEs MS Cumulative Security Update for Internet Explorer, Remote Code MS Cumulative.
PREVIOUSLY GNEWS Feb – 13 Patches – 6 Critical – 36ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative Security.
Amol Sarwate Director of Vulnerability Labs, Qualys Inc State of Vulnerability Exploits.
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
PREVIOUS GNEWS All images scavenged without permission.
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Presentation transcript:

PREVIOUS GNEWS

Mar – 13 Patches – 6 Critical – 30 CVEs MS Cumulative Security Update for IE MS Cumulative Security Update for Microsoft Edge MS Microsoft Graphics Component MS Microsoft XML Core Services MS NET Framework MS Microsoft Office MS Windows OLE MS Windows Hyper-V MS Secondary Logon MS SAM and LSAD Remote Protocols MS CSRSS MS HTTP.sys MS Adobe Flash Player Patch Tuesday

Oracle –Due April 19th Adobe –APSA16-01 Flash Player ( 1 CVE) –APSB16-10 Flash Player ( 24 CVE) –APSB16-11 Creative Cloud ( 1 CVE) –APSB16-12 RoboHelp ( 1 CVE) Apple –iOS 9.3 / ( 38 CVE) –watchOS 2.2 ( 34 CVE) –tvOS 9.3 ( 23 CVE) –Xcode 7.3 ( 3 CVE) –OSX Security Update ( 59 CVE) –Safari 9.1 ( 11 CVE) –OSX Server 5.1 ( 4 CVE) –iBooks Author ( 1 CVE) VMWare –VMSA ( 2 CVE) –XSS in vRealize Automation x Holes / Patches

Adobe 0-day –CVE –CVE Bad Java Patch –Sandbox bypass OpenSSH –Info Disclosure Symantec Endpoint Protection (SEP) –SEPM, XSS and SQL Injection –SysPlant.sys driver, code execution Apple iMessage –Crypto weakness (patched in 9.3) Apple System Integrity Protection (SIP) bypass Badlock warning is bad –Preannounce vs responsible disclosure vs full disclosure –Ms Holes / Patches

ios worm FB account take over Finger printing based on mouse usage prime patterns DDR4 suseptible to rowhammer surveilence as art usb thief - portable app sidecar ransomware going fileless Security Cams Pre-Infected with malware Windows 10 “Blue Screen” now with QR Codes Hacking

EFA Launched eero - wifi mesh router landesk to buy appsense google doubles chromebook bounty uber bug bounties amex 3rd party breach 1800 flowers hacked verizon breached CBS Sports App leaks personal data Wordpress.com HTTPS for all! Corp

3rd party access method Whatsapp is next? CVE backlog Darpa improv lavabit = snowden fbi delay / drop case with apple “One Time” request moves to NY breakdown of intell sharing restrictions HR.2666 Threat to Net Neutrality? Burr Feinstein anti-crypto bill FBI modifies data redaction rules Govt

mimikatz intro imperva cryptowall report imperva web app report Cisco Talos RansomWare Report Papers

hackers misspell foundation

Tools pafish v malware analysis lynis v unix security audit tool nmap 7.11 IIS Crypto - manage ciphers on windows iis AutoNessus - (python nessus api) automate scanner tasks

CanSecWest – Vancouver Mar B-Sides Austin Mar-Apr InfoSec Southwest – Austin 8-10 Apr B-Sides OK – 09 Apr Past Cons

B-Sides Nashville – 16 Apr ThotCon 0x7 – Chicago 5-6 May B-Sides - San Antonio21 May Circle City Con – Indianapolis Jun SANS DFIR Summit – Austin Jun SANS San Antonio – Jul Hope 11 – NYC Jul BlackHat – Vegas 30 Jul – 4 Aug BSidesLV – Vegas 2-3 Aug DefCon 24 – Vegas 4 – 7 Aug SANS Dallas – 8 – 13 Aug OWASP CFP Open – DC Oct Future Cons

DHA ( 1 st Wednesday / Family Karaoke, dallas ) TX2600 ( 1 st Fri / Wild Turkey 35&WalnutHill, dallas ) The Lab.MS ( 2 nd Monday + random events / TheLab.ms, plano ) OWASP Dallas ( 3 rd Tuesday / location varies ) Crypto Party ( 3 rd Thursday / Improving Enterprises, addison ) National Information Security and Assurance Group ( 4 th Thursday, Jakes, Frisco ) Dallas MakerSpace ( Random events / carrollton )

All images scavenged without permission