All images scavenged without permission

Slides:



Advertisements
Similar presentations
PREVIOUS GNEWS. ? Patches – ? Critical – ? CVEs Affected – ? Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS NEXT WEEK FOOL Patch.
Advertisements

PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – RDP, IE, Lync, Windows Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 11 Patches – 5 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS IE, Remote Execution.
. 15 Patches / 32 Vulns – 9 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 13 Patches – 5 Critical Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. Oct - 8 Patches – 3 Critical - 24 CVEs MS Cumulative Security Update for Internet Explorer MS NET Framework, Remote Code.
PREVIOUS GNEWS. Apr 4 Patches – 2 Critical – 11 CVEs MS Microsoft Word and Office Web Apps, Remote Code MS Cumulative Security Update.
PREVIOUS GNEWS. 6 Patches – 1 Critical – 22 CVEs Affected – IE. Kernel, Print, Office MS Cumulative Security Update for Internet Explorer MS
PREVIOUS GNEWS. Patches – 1 Critical Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS DNS Server, DoS –MS Kernal Mode Driver,
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Microsoft Word, Remote.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 20 CVEs Affected – IE, Kernel, Visio, Silverlight Sarepoint,….. Other updates, MSRT, Defender Definitions, Junk.
Previous Gnews. 13 Patches – 8 Critical, Affects pretty much everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS SMBv2.
PREVIOUS GNEWS. July - 6 Patches – 2 Critical - 27 CVEs MS Cumulative Security Update for IE, Remote Code MS – Windows Journal, Remote Code.
PREVIOUS GNEWS. 8 Patches – 3 Critical – 19+ CVEs Affected – GDI, Hyper-V, Outlook, Office, IE, Activex, and more MS Cumulative Security Update.
PREVIOUS GNEWS. 7 Patches – 1 Critical Affecting server builds and powerpoint Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 19 CVEs Affected – Kernel, SQL, Kerberos, Word, HTML, SharePoint Other updates, MSRT, Defender Definitions, Junk.
P  e  i  Gne . 6 Patches, 12 bugs – 3 Critical, Affects Windows, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 6 Patches – 4 Critical – 11 CVEs Affected – SQL, Visual Basic, Visual Foxpro, more… Other updates, MSRT, Defender Definitions, Junk Mail.
PREVIOUS GNEWS. Oct - ? Patches – ? Critical - ? CVEs Come Back Next Week Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
 . Jul - 15 Patches – 5 Critical - 60 CVEs MS SQL Server, Remote Code MS Security Update for IE MS VBScript Scripting.
PREVIOUS GNEWS. –MS Microsoft XML Core Services, Remote Execution –MS Cumulative Security Update for Internet Explorer –MS Microsoft.
PREVIOUS GNEWS. Jan 4 Patches – 0 Critical – 6 CVEs 9 Patches – 4 Critical – 31+ CVEs MS Microsoft XML Core Services, Info Disclosure MS
PREVIOUS GNEWS. 7 Patches – 6 Critical – 35 CVEs Affected –.NET, GDI+, IE, Defender, DirectShow MS NET Framework and Silverlight, Remote Code.
PREVIOUS GNEWS. try again next week Patch Tuesday.
PREVIOUS GNEWS. 16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative.
Previous Gnews. 5 Patches – x bugs addressed Other updates, MSRT, Defender Definitions, Junk Mail Filter 5 Security Patches - 5 Critical –MS – JScript.
PREVIOU S GNEWS. May 7 Patches – 2 Critical - 70 CVEs MS Remote Desktop, Allow Tampering MS TCP Protocol, DoS MS Microsoft Lync.
PREVIOUS GNEWS. 4 Patches / 5 Vulns – 3 Critical Affecting Winodow (all of them), Office, IE, SharePoint,.net Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. Aug - 4 Patches – 1 Critical - 42 CVEs MS – IE Cumulative Security Update, Remote Code MS –.NET Framework, DoS MS –
PREVIOUS GNEWS. 2 Patches – 2 Important Affecting Windows Movie Maker, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS –
PREVIOUS GNEWS. 2 Patches – 2 Critical Affecting VB and Mail Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS – Visual Basic for.
PREVIOUS GNEWS. 3 Patches – 4 Critical – 53+ CVEs Affected – Kernel, AD, SharePoint, Office, and more MS Microsoft SharePoint Server, Remote Code.
PREVIOU S GNEWS. May 9 Patches – 3 Critical - 1 out of band – 14 CVEs MS Security Update for Internet Explorer MS SharePoint Server, Remote.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter 10 Security Patches - 6 Critical, 3 Important, 1 Moderate –MS Active.
PREVIOUS GNEWS. Aug - 9 Patches – 1 Critical - 37 CVEs MS Windows Media Center, Remote Code MS – SQL Server, Privilege Escalation MS
PREVIOUSLY GNEWS Patch Tuesday Nov - 12 Patches – 8 Critical – 60ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS Cumulative Security Update for IE (Aug Out of Band) MS Cumulative.
PREVIOUSLY GNEWS Patch Tuesday Jan – 10 (9) Patches – 6 Critical – 24ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
GNEWS, PREVIOUSLY Patch Tuesday Aug - 6 Patches – 3 Critical - 33 CVEs MS Cumulative Security Update for Internet Explorer MS Cumulative.
GNEWS PREVIOUS. Patch Tuesday jul - x Patches – x Critical - x CVEs Releases Next Week.
PREVIOUS GNEWS Mar – 13 Patches – 6 Critical – 30 CVEs MS Cumulative Security Update for IE MS Cumulative Security Update for Microsoft.
PREVIOUS GNEWS. 8 Patches – 6 Critical – 19+ CVEs Affected – Kernel, AD, Exchange, Unicode, ICMP MS Security Update for Internet Explorer, Remote.
PREVIOUS GNEWS Jun – 14 Patches – 7 Critical – 47 CVEs MS Cumulative Security Update for Internet Explorer, Remote Code MS Cumulative.
PREVIOUSLY GNEWS Feb – 13 Patches – 6 Critical – 36ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative Security.
All images scavenged without permission
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
Follow-up issues from the presentation on Anti-virus / Security software TD & SD have encountered problems with AVG, which also is not rated highly in.
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
PREVIOUS GNEWS All images scavenged without permission.
PREVIOUS GNEWS All images scavenged without permission.
PREVIOUS GNEWS All images scavenged without permission.
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Previous Gnews All images scavenged without permission.
Jon Peppler, Menlo Security Channels
Nessus Vulnerability Scanning
Previous Gnews All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Previous Gnews All images scavenged without permission.
All images scavenged without permission
Previous Gnews All images scavenged without permission.
All images scavenged without permission
Presentation transcript:

All images scavenged without permission

Patch Tuesday Aug 2017 – 51 vulnerabilities with 130 unique downloads Internet Explorer / Microsoft Edge / Remote Code Microsoft Windows / Remote Code Microsoft SharePoint / Spoofing Adobe Flash Player / Remote Code Microsoft SQL Server / Info Disclosure Out of Band Outlook Patch EternalSynergy Exploit (SMB again) Sources: https://portal.msrc.microsoft.com/en-us/security-guidance https://technet.microsoft.com/en-us/security/advisories No longer working http://technet.microsoft.com/en-us/security/bulletin/ms17-may out-of-band outlook patch https://urldefense.proofpoint.com/v2/url?u=https-3A__support.office.com_en-2Dus_article_Outlook-2Dknown-2Dissues-2Din-2Dthe-2DJune-2D2017-2Dsecurity-2Dupdates-2D3f6dbffd-2D8505-2D492d-2Db19f-2Db3b89369ed9b-3Fui-3Den-2DUS-26rs-3Den-2DUS-26ad-3DUS-26fromAR-3D1&d=DwMGaQ&c=koUnkbJ1zJj69I6eKjYdZA&r=kslvB9NsW4rDAjC49Xjx6NDyiHRvVKH0kv9NgFtfQUV9Fu1ImLXsK1oYCKKsaMdW&m=V2EFklVZMQc2V65IekCUao7ooWpdra5rIQlWlEJeOzs&s=WEXXy8OAl4Dj4CusjwEPj4CmST1UKvZwdjBrXodaVus&e= Microsoft plans to release security updates for the following versions of Outlook on July 18, 2017. stop with the SMB already https://www.bleepingcomputer.com/news/security/exploit-derived-from-eternalsynergy-upgraded-to-target-newer-windows-versions/

Holes / Patches Oracle Adobe Cisco FreeRadius gSOAP VMWare Apple 308 Fixes Adobe APSB17-23 Flash Player ( 2 CVE) APSB17-24 Acrobat / Reader ( 67 CVE) APSB17-26 Experience Manager ( 3 CVE) APSB17-27 Digital Editions ( 9 CVE) Cisco WebEx Extension FreeRadius 15 Vulns Identified gSOAP cameras VMWare VMSA-2017-0012 ( 1 CVE) VCenter VMSA-2017-0013 ( 4 CVE) VIX API Apple Wifi / Boot Camp 6.1 ( 1 CVE) tvOS 10.2.2 ( 38 CVE) iTunes 12.6.2 Windows ( 23 CVE) iCloud 6.2.2 Windows ( 22 CVE) Safari 10.1.2 ( 25 CVE) Security Update 2017-003 ( 37 CVE) iOS 10.3.3 ( 47 CVE) watchOS 3.2.3 ( 16 CVE) Sources: ## Oracle Patches http://www.oracle.com/technetwork/topics/security/alerts-086861.html Oracle 308 cve https://threatpost.com/oracle-releases-biggest-update-ever-308-vulnerabilities-patched/126910/ ##Adobe Patches https://helpx.adobe.com/security.html https://helpx.adobe.com/security/products/flash-player/apsb17-23.html https://helpx.adobe.com/security/products/acrobat/apsb17-24.html https://helpx.adobe.com/security/products/experience-manager/apsb17-26.html https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html ##Apple patches http://support.apple.com/kb/HT1222 apple broadpwn https://threatpost.com/apple-patches-broadpwn-bug-in-ios-10-3-3/126955/ ##Cisco patches http://tools.cisco.com/security/center/home.x http://tools.cisco.com/security/center/viewAllSearch.x?currentPage=&sortType=d&recordsPerPage=100&searchkey=&filter=43&pageSize=100&pageNo=1 Cisco Webex extension https://threatpost.com/cisco-patches-another-critical-ormandy-bug-in-webex-extension/126879/ Freeradius https://threatpost.com/freeradius-update-patches-bugs-static-analysis-tools-missed/126872/ gSOAP vuln (cameras) https://www.wired.com/story/devils-ivy-iot-vulnerability ## VMWare http://www.vmware.com/security/advisories/ https://www.vmware.com/security/advisories/VMSA-2017-0012.html https://www.vmware.com/security/advisories/VMSA-2017-0013.html ## Android https://source.android.com/security/bulletin/index.html https://source.android.com/security/bulletin/2017-07-01

Hacking Half-baked WP takeovers tor bounty open to all Windows bounty announced safe cracking robot DEFCON - gun magnets BLACKHAT - cache attack DEFCON SMB 0-day docker as malware netflix api ddos Hacking Sources: Half-baked WP takeovers https://threatpost.com/attackers-using-automated-scans-to-takeover-wordpress-installs/126815/ tor bounty open to all https://threatpost.com/tor-project-opens-bounty-program-to-all-researchers/126937/ safe cracking robot https://www.wired.com/story/watch-robot-crack-safe DEFCON - gun magnets https://www.wired.com/story/smart-gun-fire-magnets BLACKHAT - cache attack https://threatpost.com/novel-attack-tricks-servers-to-cache-expose-personal-data/127014/ DEFCON SMB 0-day https://threatpost.com/windows-smb-zero-day-to-be-disclosed-during-def-con/126927/ docker as malware https://threatpost.com/attack-uses-docker-containers-to-hide-persist-plant-malware/126992/ netflix api ddos https://www.wired.com/story/netflix-ddos-attack windows bounty program https://blogs.technet.microsoft.com/msrc/2017/07/26/announcing-the-windows-bounty-program/

Corp ARM buys Simulity Rapid7 buys Komand (orchestration) Micheal Kors buys Jimmy Choo intel shutsdown wearables Adobe draws 2020 EOL line in sand intel discontinues arduino 101 foxxconn in wisconsin bitcoin split Mandiant analyst popped HotSpot Shield data Sources: ARM buys Simulity https://securityledger.com/2017/07/with-an-eye-on-iot-security-arm-buys-simulity-for-15m/ Rapid7 buys Komand (orchestration) https://www.rapid7.com/about/press-releases/rapid7-acquires-security-orchestration-and-automation-company-komand/ Micheal Kors buys Jimmy Choo https://risnews.com/michael-kors-snags-jimmy-choo-12-billion intel shutsdown wearables https://news.hitb.org/content/intel-shuts-down-group-working-wearables-and-fitness-trackers Adobe draws 2020 EOL line in sand https://news.hitb.org/content/adobe-finally-kills-flash-dead intel discontinues arduino 101 https://news.hitb.org/content/intel-discontinues-arduino-101-development-board-and-curie-module foxxconn in wisconsin https://www.wired.com/story/foxconn-wisconsin-us-tech-skills-gap bitcoin split http://www.businessinsider.com/bitcoin-price-fork-happens-2017-8?op=1 Mandiant analyst popped http://www.healthcareinfosecurity.com/hacker-group-31337-dumps-data-stolen-from-mandiant-analyst-a-10160 HotSpot Shield data https://news.hitb.org/content/ftc-must-scrutinize-hotspot-shield-over-alleged-traffic-interception-group-says Corp

Govt Dutch surveillence no cloud searches at the border alphabay takedown (and Hansa) 5yrs for citadel coder civil asset forfieture EFF Guide on Birde crossing and device wipe jersy privacy OCR reporting tool Nevada privacy notice malwaretechblog arrested IOT Cybersecurity Improvement act of 2017 Texas SB4 Sources: Dutch surveillence http://www.theregister.co.uk/2017/07/13/dutch_surveillance_law_revamp/ no cloud searches at the border https://www.eff.org/deeplinks/2017/07/cbp-responds-sen-wyden-border-agents-may-not-search-travelers-cloud-content alphabay takedown (and Hansa) https://www.wired.com/story/alphabay-takedown-dark-web-chaos 5yrs for citadel coder http://www.healthcareinfosecurity.com/russian-citadel-malware-developer-gets-5-year-sentence-a-10127 civil asset forfieture https://theintercept.com/2017/07/20/jeff-sessions-wants-to-make-legalized-theft-great-again/ EFF Guide on Birde crossing and device wipe https://www.eff.org/deeplinks/2017/07/crossing-us-border-heres-how-securely-wipe-your-computer jersy privacy https://www.huntonprivacyblog.com/2017/07/24/new-jersey-shopper-privacy-bill-signed-law/ OCR reporting tool https://www.huntonprivacyblog.com/2017/07/25/ocr-releases-improved-data-breach-reporting-tool/ Nevada privacy notice https://www.huntonprivacyblog.com/2017/07/27/nevada-enacts-website-privacy-notice-law/ malwaretechblog arrested https://motherboard.vice.com/en_us/article/ywp8k5/researcher-who-stopped-wannacry-ransomware-detained-in-us-after-def-con IOT Cybersecurity Improvement act of 2017 http://threatpost.com/legislation-proposed-to-secure-connected-iot-devices/127152/ Texas SB4 https://theintercept.com/2017/08/03/texas-police-say-sb4-is-damaging-public-safety-before-even-taking-effect/ Govt

Papers MS ebooks Car hacking workbench pt2 Car hacking workbench pt3 https://blogs.msdn.microsoft.com/mssmallbiz/2017/07/11/largest-free-microsoft-ebook-giveaway-im-giving-away-millions-of-free-microsoft-ebooks-again-including-windows-10-office-365-office-2016-power-bi-azure-windows-8-1-office-2013-sharepo/ http://ligman.me/2sZVmcG Car hacking workbench pt2 https://community.rapid7.com/community/transpo-security/blog/2017/07/17/building-a-car-hacking-development-workbench-part-2 Car hacking workbench pt3 https://community.rapid7.com/community/transpo-security/blog/2017/07/20/building-a-car-hacking-development-workbench-part-3 Papers Sources: MS ebooks https://blogs.msdn.microsoft.com/mssmallbiz/2017/07/11/largest-free-microsoft-ebook-giveaway-im-giving-away-millions-of-free-microsoft-ebooks-again-including-windows-10-office-365-office-2016-power-bi-azure-windows-8-1-office-2013-sharepo/ http://ligman.me/2sZVmcG Car hacking workbench pt2 https://community.rapid7.com/community/transpo-security/blog/2017/07/17/building-a-car-hacking-development-workbench-part-2 Car hacking workbench pt3 https://community.rapid7.com/community/transpo-security/blog/2017/07/20/building-a-car-hacking-development-workbench-part-3

employees OK with bio implants Metal is Terror employees OK with bio implants WTF Sources: Metal is terror https://www.eff.org/deeplinks/2017/07/payment-processors-are-profiling-heavy-metal-fans-terrorists employees OK with bio implants https://www.nytimes.com/2017/07/25/technology/microchips-wisconsin-company-employees.html?_r=0

Tools siemonster pyREBox yython sandbox Blackhat arsenal Luckystrike 2.0 evil macro generator fireEye FlareVM malware analysis anti-drone DefPloreX machine learning Tools Sources: https://siemonster.com/ pyREBox https://blogs.cisco.com/security/talos/pyrebox Blackhat arsenal http://feedproxy.google.com/~r/Toolswatch/~3/36pHpS866W8/ Luckystrike 2.0 https://curi0usjack.blogspot.com/2017/07/luckystrike-20-is-here.html fireEye FlareVM (malware analysis) https://www.fireeye.com/blog/threat-research/2017/07/flare-vm-the-windows-malware.html anti-drone https://www.wired.com/story/watch-anti-drone-weapons-test DefPloreX http://blog.trendmicro.com/trendlabs-security-intelligence/defplorex-machine-learning-toolkit-large-scale-ecrime-forensics/

BH - Palo Alto IOT honeypot BH - priveiw BH - top 20 BH - best of BH - Palo Alto IOT honeypot BH - Carwash smash DC - Queercon Badge DC - mr Robot Badge DC - badges DC - Tor Past Cons Sources: BH- priveiw https://threatpost.com/black-hat-usa-2017-preview/126984/ BH - top 20 http://www.healthcareinfosecurity.com/blogs/20-hot-sessions-black-hat-2017-p-2521 BH - best of https://www.wired.com/story/best-black-hat-defcon-talks DC - Queercon Badge https://blinkylights.ninja/blinky-lights/queercon-14-defcon-25-2017/ DC mr Robot Badge https://hackaday.io/project/18508-mr-robot-badge/log/64526-how-i-created-the-mr-robot-badge DC badges http://hackaday.com/2017/08/04/all-the-hardware-badges-of-def-con-25/ DC Tor https://threatpost.com/tor-developer-busts-myths-announces-new-features/127207/ palo iot honeypot https://researchcenter.paloaltonetworks.com/2017/07/palo-alto-networks-showcase-iot-honeypot-research-black-hat-2017/ https://infosec-conferences.com/ https://opensource.com/resources/conferences-and-events-monthly https://cfptime.org/ http://wikicfp.com/cfp/ BH - Carwash smash https://motherboard.vice.com/en_us/article/bjxe33/car-wash-hack-can-smash-vehicle-trap-passengers-douse-them-with-water

Future Cons SANS San Antonio 6-11 Aug ToorCon San Diego 28Aug – 3 Sep DerbyCon 20-24 Sep Rock Stars of Cybersecurity Technologies 26 Sep CactusCon 29-30 Sep Future Cons Sources: https://www.concise-courses.com/security/conferences-of-2017/ http://www.securitybsides.com/w/page/12194156/FrontPage

Where DHA @Dallas_Hackers TX2600 @dallas2600 The Lab.MS @TheLab_ms ( 1st Wednesday / Family Karaoke, Dallas ) TX2600 @dallas2600 ( 1st Fri / Wild Turkey 35&WalnutHill, Dallas ) The Lab.MS @TheLab_ms ( 2nd Saturday + random events / TheLab.ms, Plano ) ISSA Fort Worth @ISSAFortWorth ( 2nd Tuesday / location varies ) ?? Fort Worth Crypto Party ?? ( 2nd Tuesday ? / The Maker Spot, N. Richland Hills ) Hack Ft Worth @Hack_FtW ( 3rd-ish Tuesday / Buffalo West, Fort Worth) OWASP Dallas @OWASPDallas ( 3rd Tuesday / location varies ) Crypto Party DFW @CryptoPartyDFW ( 3rd Thursday / TheLab.ms, Plano ) North Texas Cyber Security Group @ntxcsg ( Last Thursday, Jakes, Frisco ) Dallas MakerSpace @dallasmakers ( Random events / Carrollton ) Sources: https://www.google.com/calendar/embed?src=c4ervam9s3ep79dtdjd1k9kgbk%40group.calendar.google.com&ctz=America/Chicago Where

Sources: All images scavenged without permission