PREVIOUS GNEWS All images scavenged without permission.

Slides:



Advertisements
Similar presentations
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – RDP, IE, Lync, Windows Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
Advertisements

PREVIOUS GNEWS. 11 Patches – 5 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS IE, Remote Execution.
PREVIOUS GNEWS. 13 Patches – 5 Critical Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. Oct - 8 Patches – 3 Critical - 24 CVEs MS Cumulative Security Update for Internet Explorer MS NET Framework, Remote Code.
External Threats to Healthcare Data Joshua Spencer, CPHIMS, C | EH.
PREVIOUS GNEWS. Apr 4 Patches – 2 Critical – 11 CVEs MS Microsoft Word and Office Web Apps, Remote Code MS Cumulative Security Update.
9 Patches – 2 Critical – 12 CVEs Affected – IE, Kernel, SharePoint, Remote Desktop, AD….. Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. 6 Patches – 1 Critical – 22 CVEs Affected – IE. Kernel, Print, Office MS Cumulative Security Update for Internet Explorer MS
PREVIOUS GNEWS. Patches – 1 Critical Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS DNS Server, DoS –MS Kernal Mode Driver,
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Microsoft Word, Remote.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 20 CVEs Affected – IE, Kernel, Visio, Silverlight Sarepoint,….. Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. July - 6 Patches – 2 Critical - 27 CVEs MS Cumulative Security Update for IE, Remote Code MS – Windows Journal, Remote Code.
PREVIOUS GNEWS. 8 Patches – 3 Critical – 19+ CVEs Affected – GDI, Hyper-V, Outlook, Office, IE, Activex, and more MS Cumulative Security Update.
PREVIOUS GNEWS. 7 Patches – 1 Critical Affecting server builds and powerpoint Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 19 CVEs Affected – Kernel, SQL, Kerberos, Word, HTML, SharePoint Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 11 CVEs Affected – SQL, Visual Basic, Visual Foxpro, more… Other updates, MSRT, Defender Definitions, Junk Mail.
PREVIOUS GNEWS. Oct - ? Patches – ? Critical - ? CVEs Come Back Next Week Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOUS GNEWS. 4 Patches – x bugs addressed Affecting Windows, SQL, Office, Visual Studio,.Net Other updates, MSRT, Defender Definitions, Junk Mail Filter.
. Next Week Yo! Patch Tuesday Java Multiple advisories and updates Openssl DoS in ASN1_STRING_print_ex() cisco ios DoS in Cisco Tunneling.
 . Jul - 15 Patches – 5 Critical - 60 CVEs MS SQL Server, Remote Code MS Security Update for IE MS VBScript Scripting.
PREVIOUS GNEWS. –MS Microsoft XML Core Services, Remote Execution –MS Cumulative Security Update for Internet Explorer –MS Microsoft.
PREVIOUS GNEWS. Jan 4 Patches – 0 Critical – 6 CVEs 9 Patches – 4 Critical – 31+ CVEs MS Microsoft XML Core Services, Info Disclosure MS
PREVIOUS GNEWS. 7 Patches – 6 Critical – 35 CVEs Affected –.NET, GDI+, IE, Defender, DirectShow MS NET Framework and Silverlight, Remote Code.
PREVIOUS GNEWS. try again next week Patch Tuesday.
PREVIOUS GNEWS. 16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative.
PREVIOU S GNEWS. May 7 Patches – 2 Critical - 70 CVEs MS Remote Desktop, Allow Tampering MS TCP Protocol, DoS MS Microsoft Lync.
PREVIOUS GNEWS A Hacker is You!. 1 Patches – 1 bugs addressed Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. Aug - 4 Patches – 1 Critical - 42 CVEs MS – IE Cumulative Security Update, Remote Code MS –.NET Framework, DoS MS –
PREVIOUS GNEWS. 2 Patches – 2 Important Affecting Windows Movie Maker, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS –
MobileSecurity Vulnerability Assessment Tools for the Enterprise Mobile Security Vulnerability Assessment Tools for the Enterprise Integrating Mobile/BYOD.
PREVIOUS GNEWS. 2 Patches – 2 Critical Affecting VB and Mail Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS – Visual Basic for.
PREVIOUS GNEWS. 3 Patches – 4 Critical – 53+ CVEs Affected – Kernel, AD, SharePoint, Office, and more MS Microsoft SharePoint Server, Remote Code.
PREVIOU S GNEWS. May 9 Patches – 3 Critical - 1 out of band – 14 CVEs MS Security Update for Internet Explorer MS SharePoint Server, Remote.
PREVIOUS GNEWS. Aug - 9 Patches – 1 Critical - 37 CVEs MS Windows Media Center, Remote Code MS – SQL Server, Privilege Escalation MS
PREVIOUSLY GNEWS Patch Tuesday Nov - 12 Patches – 8 Critical – 60ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS Cumulative Security Update for IE (Aug Out of Band) MS Cumulative.
PREVIOUSLY GNEWS Patch Tuesday Jan – 10 (9) Patches – 6 Critical – 24ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
GNEWS, PREVIOUSLY Patch Tuesday Aug - 6 Patches – 3 Critical - 33 CVEs MS Cumulative Security Update for Internet Explorer MS Cumulative.
GNEWS PREVIOUS. Patch Tuesday jul - x Patches – x Critical - x CVEs Releases Next Week.
PREVIOUS GNEWS Mar – 13 Patches – 6 Critical – 30 CVEs MS Cumulative Security Update for IE MS Cumulative Security Update for Microsoft.
PREVIOUS GNEWS. 8 Patches – 6 Critical – 19+ CVEs Affected – Kernel, AD, Exchange, Unicode, ICMP MS Security Update for Internet Explorer, Remote.
PREVIOUS GNEWS Jun – 14 Patches – 7 Critical – 47 CVEs MS Cumulative Security Update for Internet Explorer, Remote Code MS Cumulative.
PREVIOUSLY GNEWS Feb – 13 Patches – 6 Critical – 36ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative Security.
Amol Sarwate Director of Vulnerability Labs, Qualys Inc State of Vulnerability Exploits.
All images scavenged without permission
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
Do you know who your employees are sharing their credentials with
PREVIOUS GNEWS All images scavenged without permission.
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Previous Gnews All images scavenged without permission.
Previous Gnews All images scavenged without permission.
All images scavenged without permission
Malware March 26, 2018.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Securing the Internet of Things: Key Insights and Best Practices Across the Industry Theresa Bui Revon IoT Cloud Strategy.
Previous Gnews All images scavenged without permission.
All images scavenged without permission
Previous Gnews All images scavenged without permission.
All images scavenged without permission
Current State of Security and Privacy
Presentation transcript:

PREVIOUS GNEWS All images scavenged without permission

Patch Tuesday May 2017 - 243 CVEs Advisories Malware Protection Engine Deprecating Sha-1 IE / Edge .NET Privilege Escalation Update Client Failure Windows 10 and Windows Server 2016 (including Microsoft Edge) / Remote Code Windows 8.1 and Windows Server 2012 R2 / Remote Code Windows Server 2012 / Remote Code Windows RT 8.1 / Remote Code Windows 7 and Windows Server 2008 R2 / Remote Code Windows Server 2008 / Remote Code Internet Explorer / Remote Code Adobe Flash Player / Remote Code Microsoft Office, Office Services, Office Web Apps, and other Office-related software / Remote Code .NET Framework / Security Bypass Sources: https://portal.msrc.microsoft.com/en-us/security-guidance https://technet.microsoft.com/en-us/security/advisories MS malware protection engine https://technet.microsoft.com/library/security/4022344 https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5 MS kills SHA-1 in ie edge https://threatpost.com/microsoft-makes-it-official-cuts-off-sha-1-support-in-ie-edge/125579/ Last Update Mar 2017 https://technet.microsoft.com/en-us/security/bulletins No longer working http://technet.microsoft.com/en-us/security/bulletin/ms17-may

Holes / Patches Oracle Adobe Android VMWare Intel AMT MS WifiSense 300 security fixes 8 Java / 40 MySQL Patches vuln with struts Adobe APSB17-14 ColdFusion ( 2 CVE) APSB17-15 Flash Player ( 7 CVE) APSB17-16 Experienace Manager Forms ( 1 CVE) Android Coming soon VMWare VMSA-2017-0007 ( 1 CVE) vCenter Server VMSA-2017-0008.2 ( 7 CVE) Unified Access Gateway, Horizon View, Workstation Intel AMT ver 6.x – 11.6 MS WifiSense now disabled by default Sources: ## Oracle Patches http://www.oracle.com/technetwork/topics/security/alerts-086861.html ##Adobe Patches https://helpx.adobe.com/security.html https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html https://helpx.adobe.com/security/products/flash-player/apsb17-15.html ##Apple patches http://support.apple.com/kb/HT1222 ##Cisco patches http://tools.cisco.com/security/center/home.x http://tools.cisco.com/security/center/viewAllSearch.x?currentPage=&sortType=d&recordsPerPage=100&searchkey=&filter=43&pageSize=100&pageNo=1 ## VMWare http://www.vmware.com/security/advisories/ https://www.vmware.com/security/advisories/VMSA-2017-0007.html https://www.vmware.com/security/advisories/VMSA-2017-0008.html ## Android https://source.android.com/security/bulletin/index.html https://source.android.com/security/bulletin/2017-05-01 AMT Vuln https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it oracle https://threatpost.com/record-oracle-patch-update-addresses-shadowbrokers-struts-2-vulnerabilities/125046/ MS finally disables wifisense by default http://www.healthcareinfosecurity.com/blogs/microsoft-turns-off-wi-fi-sense-after-risk-revealed-p-2462

Hacking bad fingerprint reader iot white-worm hajime domain fronting data pollution tools are they worth it SS7 EG PassFreely Oarcle Auth Bypass USAF Bug Bounty CIA tool ''scribbles' Apple revokes cert OSX/Dok keyless entry bypass Google Doc Phish True Health Patient Portal Hacking Sources: bad fingerprint reader https://www.nytimes.com/2017/04/10/technology/fingerprint-security-smartphones-apple-google-samsung.html iot whiteworm hajime https://news.hitb.org/content/vigilante-botnet-infects-iot-devices-blackhats-can-hijack-them domain fronting http://resources.infosecinstitute.com/domain-fronting/ data polution tools are they worth it https://www.eff.org/deeplinks/2017/05/limitations-isp-data-pollution-tools SS7 https://arstechnica.com/security/2017/05/thieves-drain-2fa-protected-bank-accounts-by-abusing-ss7-routing-protocol/ EG PassFreely Oarcle Auth Bypass http://www.healthcareinfosecurity.com/passfreely-attack-bypasses-oracle-database-authentication-a-9868 USAF Bug Bounty https://threatpost.com/air-force-hopes-to-attract-hackers-with-bug-bounty-program/125235/ CIA tool ''scribbles' https://threatpost.com/wikileaks-reveals-cia-tool-scribbles-for-document-tracking/125299/ Apple revokes cert OSX/Dok https://threatpost.com/apple-revokes-certificate-used-by-osxdok-malware/125322/ keyless entry bypass https://news.hitb.org/content/security-researchers-demonstrate-fast-and-cheap-relay-hack-keyless-entry-system-cars Google Doc Phish https://threatpost.com/google-shuts-down-docs-phishing-spree/125414/ True Health Patient Portal http://www.healthcareinfosecurity.com/patient-portal-flaw-exposes-lab-records-a-9904

finger your card MS phone sign-on, cause compromise never happens due to a stolen phone cylance samples?? FB password SDK intercontinental popped again how not to startup chipotle popped holiday inn (IHG) popped tinder popped Albertsons too buy wholefoods? petsmart buys chewy sabre popped hipchat popped ALliance direct lending popped IBM pops Storwize cusomters Reconyc on usbdrives Sources: finger your card http://www.bbc.co.uk/news/technology-39643453 MS phone sign-on, cause compromise never happens due to a stolen phone https://www.engadget.com/2017/04/18/microsoft-replaces-the-password-with-a-phone-based-log-in/ cylance samples?? https://arstechnica.com/information-technology/2017/04/the-mystery-of-the-malware-that-wasnt/ FB password SDK http://threatpost.com/facebook-delegated-account-recovery-sdks-published-for-java-ruby-apps/125028/ intercontinental popped again https://threatpost.com/ihg-confirms-second-credit-card-breach-impacting-1000-plus-hotels/125033/ how not to startup http://www.healthcareinfosecurity.com/cybersecurity-startup-exposed-hospital-network-data-in-demos-a-9853 chipotle popped https://www.theregister.co.uk/AMP/2017/04/26/chipotle_malware_infection/ holiday inn (IHG) popped https://www.theregister.co.uk/2017/04/19/intercontinental_hotels_group_malware/ tinder popped http://www.bbc.com/news/technology-39778568 Albertsons too buy wholefoods? https://risnews.com/albertsons-may-bid-whole-foods-appoints-evp-retail-operations petsmart buys chewy https://risnews.com/petsmart-acquires-e-commerce-upstart-chewy sabre popped https://krebsonsecurity.com/2017/05/breach-at-sabre-corp-s-hospitality-unit/ hipchat popped https://threatpost.com/atlassian-resets-hipchat-passwords-following-breach/125210/ ALliance direct lending popped https://threatpost.com/auto-lender-exposes-loan-data-for-up-to-1-million-applicants/125216/ http://www.esecurityplanet.com/hackers/chipotle-hit-by-credit-card-breach.html IBM pops Storwize cusomters Reconyc on usbdrives Corp

Govt guns end of net neutrality? new copyright censors qwith china Social Security luanches 2FA Sources: guns https://theintercept.com/2017/04/24/greg-gianforte-oracle/ end of net neutrality? https://www.eff.org/deeplinks/2017/04/fcc-wants-eliminate-net-neutrality-protections-we-cant-let-happen https://www.eff.org/deeplinks/2017/04/fcc-announces-plan-abandon-net-neutrality-and-isp-privacy new copyright censors qwith china https://www.eff.org/deeplinks/2017/04/chinese-snooping-foreshadows-future-copyright-enforcement Social Security luanches 2FA Govt

Papers Car hacking archive Verizon DBIR ultrasonic beacons https://www.theregister.co.uk/2017/04/25/car_hacking_research/?mt=1493124610430 http://illmatics.com/carhacking.html Verizon DBIR http://www.verizonenterprise.com/verizon-insights-lab/dbir/ https://community.rapid7.com/community/infosec/blog/2017/05/05/2017-verizon-data-breach-report-dbir-key-takeaways ultrasonic beacons https://www.sec.cs.tu-bs.de/pubs/2017a-eurosp.pdf Papers Sources: Car hacking archive https://www.theregister.co.uk/2017/04/25/car_hacking_research/?mt=1493124610430 http://illmatics.com/carhacking.html Verizon DBIR http://www.verizonenterprise.com/verizon-insights-lab/dbir/ https://community.rapid7.com/community/infosec/blog/2017/05/05/2017-verizon-data-breach-report-dbir-key-takeaways ultrasonic beacons https://www.sec.cs.tu-bs.de/pubs/2017a-eurosp.pdf Privacy Threats through Ultrasonic Side Channels on Mobile Devices

WTF Bill would require hardware mods and porrn tax internet archives, apps in browser USA today FBI Facebook Canadian parking app WTF Sources: Bill would require hardware mods and porrn tax https://www.eff.org/deeplinks/2017/04/states-introduce-dubious-legislation-ransom-internet internet archives, apps in browser https://news.hitb.org/content/classic-mac-os-and-dozens-apps-can-now-be-run-browser-window USA today FBI Facebook https://www.usatoday.com/story/tech/news/2017/05/05/usa-today-asks-fbi-probe-rise-fake-facebook-followers/101303300/ Canadian parking app https://www.nfcworld.com/2017/05/09/352201/canadian-city-rolls-mobile-app-links-payments-parking-drivers-licence-plate/

https://github.com/olacabs/jackhammer Shodan malware hunter https://malware-hunter.shodan.io PA LabyREnth CTF 2017 http://researchcenter.paloaltonetworks.com/2017/04/unit42-labyrenth-ctf-2017/ donkeydocker ctf http://resources.infosecinstitute.com/donkeydocker1-ctf-walkthrough/ billu box vulnwebapp http://resources.infosecinstitute.com/billu-b0x-walkthrough/ jackhammer https://github.com/olacabs/jackhammer Tools Sources: Shodan malware hunter https://malware-hunter.shodan.io PA LabyREnth CTF 2017 http://researchcenter.paloaltonetworks.com/2017/04/unit42-labyrenth-ctf-2017/ donkeydocker ctf http://resources.infosecinstitute.com/donkeydocker1-ctf-walkthrough/ billu box vulnwebapp http://resources.infosecinstitute.com/billu-b0x-walkthrough/ jackhammer https://github.com/olacabs/jackhammer http://www.darknet.org.uk/ http://www.toolswatch.org/ Raytheon competition http://www.nationalccdc.org/index.php/competition/about-ccdc/mission

Past Cons BSides Nashville 22 Apr BSides Austin 4-5 May Thotcon Chicago 4-5 May Past Cons Sources: https://www.concise-courses.com/security/conferences-of-2017/ http://www.securitybsides.com/w/page/12194156/FrontPage cansecwest pwn2own https://news.hitb.org/content/adobe-reader-edge-safari-and-ubuntu-fall-during-first-day-https://threatpost.com/vmware-patches-pwn2own-vm-escape-vulnerabilities/124629/ https://threatpost.com/vm-escape-earns-hackers-105k-at-pwn2own/124397/

Circle City Con Indy 9-11 Jun HackMiami 19-21 May NolaCon 19-21 May Circle City Con Indy 9-11 Jun ANYCon Albany 16-18 Jun BlackHat 22-27 Jul BSidesLV 25-26 Jul DefCon 27-30 Jul Future Cons Sources: https://www.concise-courses.com/security/conferences-of-2017/ http://www.securitybsides.com/w/page/12194156/FrontPage

Where DHA @Dallas_Hackers TX2600 @dallas2600 The Lab.MS @TheLab_ms ( 1st Wednesday / Family Karaoke, Dallas ) TX2600 @dallas2600 ( 1st Fri / Wild Turkey 35&WalnutHill, Dallas ) The Lab.MS @TheLab_ms ( 2nd Saturday + random events / TheLab.ms, Plano ) ISSA Fort Worth @ISSAFortWorth ( 2nd Tuesday / location varies ) Fort Worth Crypto Party ( 2nd Tuesday ? / The Maker Spot, N. Richland Hills ) Hack Ft Worth @Hack_FtW ( 3rd-ish Tuesday / Buffalo West, Fort Worth) OWASP Dallas @OWASPDallas ( 3rd Tuesday / location varies ) Crypto Party DFW @CryptoPartyDFW ( 3rd Thursday / TheLab.ms, Plano ) North Texas Cyber Security Group @ntxcsg ( Last Thursday, Jakes, Frisco ) Dallas MakerSpace @dallasmakers ( Random events / Carrollton ) Lock Pick DFW @LockPickDFW ( Last Monday/ Sherlocks Arlington ) Sources: https://www.google.com/calendar/embed?src=c4ervam9s3ep79dtdjd1k9kgbk%40group.calendar.google.com&ctz=America/Chicago Where

Sources: All images scavenged without permission