 . Jul - 15 Patches – 5 Critical - 60 CVEs MS15-058 - SQL Server, Remote Code MS15-065 - Security Update for IE MS15-066 - VBScript Scripting.

Slides:



Advertisements
Similar presentations
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – RDP, IE, Lync, Windows Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
Advertisements

PREVIOUS GNEWS. 11 Patches – 5 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS IE, Remote Execution.
. 15 Patches / 32 Vulns – 9 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 13 Patches – 5 Critical Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
GNEWS PREVIOUS. Feb - 14 Patches – 5 Critical - 45 CVEs MS Cumulative Security Update for IE MS VBScript Scripting, Remote Code MS
PREVIOUS GNEWS. Oct - 8 Patches – 3 Critical - 24 CVEs MS Cumulative Security Update for Internet Explorer MS NET Framework, Remote Code.
 . Apr - 8 Patches – 2 Critical - 45 CVEs MS Cumulative Security Update for IE, Remote Code MS Windows Media Player, Remote.
PREVIOUS GNEWS. Apr 4 Patches – 2 Critical – 11 CVEs MS Microsoft Word and Office Web Apps, Remote Code MS Cumulative Security Update.
To receive our video stream in LiveMeeting: - Click on “Voice & Video” - Click the drop down next to the camera icon - Select “Show Main Video” Dial-in.
PREVIOUS GNEWS. Feb - 9 Patches – 3 Critical - 55 CVEs MS Update for Internet Explorer MS Windows Kernel-Mode Driver, Remote Code MS
9 Patches – 2 Critical – 12 CVEs Affected – IE, Kernel, SharePoint, Remote Desktop, AD….. Other updates, MSRT, Defender Definitions, Junk Mail Filter.
. Apr - 11 Patches – 4 Critical - 26 CVEs MS Cumulative Security Update for IE MS Office, Remote Code MS HTTP.sys,
PREVIOUS GNEWS. 6 Patches – 1 Critical – 22 CVEs Affected – IE. Kernel, Print, Office MS Cumulative Security Update for Internet Explorer MS
PREVIOUS GNEWS. Patches – 1 Critical Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS DNS Server, DoS –MS Kernal Mode Driver,
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Microsoft Word, Remote.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 20 CVEs Affected – IE, Kernel, Visio, Silverlight Sarepoint,….. Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 2 Patches / 3 Vulns – 1 Critical Affecting Windows XP, Vista, 7, 2003, 2008 Other updates, MSRT, Defender Definitions, Junk Mail Filter.
Previous Gnews. 13 Patches – 8 Critical, Affects pretty much everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS SMBv2.
PREVIOUS GNEWS. July - 6 Patches – 2 Critical - 27 CVEs MS Cumulative Security Update for IE, Remote Code MS – Windows Journal, Remote Code.
PREVIOUS GNEWS. 8 Patches – 3 Critical – 19+ CVEs Affected – GDI, Hyper-V, Outlook, Office, IE, Activex, and more MS Cumulative Security Update.
PREVIOUS GNEWS. 7 Patches – 1 Critical Affecting server builds and powerpoint Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 19 CVEs Affected – Kernel, SQL, Kerberos, Word, HTML, SharePoint Other updates, MSRT, Defender Definitions, Junk.
P  e  i  Gne . 6 Patches, 12 bugs – 3 Critical, Affects Windows, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 6 Patches – 4 Critical – 11 CVEs Affected – SQL, Visual Basic, Visual Foxpro, more… Other updates, MSRT, Defender Definitions, Junk Mail.
PREVIOUS GNEWS. Oct - ? Patches – ? Critical - ? CVEs Come Back Next Week Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOUS GNEWS. 4 Patches – x bugs addressed Affecting Windows, SQL, Office, Visual Studio,.Net Other updates, MSRT, Defender Definitions, Junk Mail Filter.
. 6 Patches, 15 bug – 3 Critical, Affects 2000, XP, Srv 2003 / 8, Vista, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. Advanced Notification on Thursday Patch Tuesday.
PREVIOUS GNEWS. –MS Microsoft XML Core Services, Remote Execution –MS Cumulative Security Update for Internet Explorer –MS Microsoft.
PREVIOUS GNEWS. Jan 4 Patches – 0 Critical – 6 CVEs 9 Patches – 4 Critical – 31+ CVEs MS Microsoft XML Core Services, Info Disclosure MS
PREVIOUS GNEWS. 7 Patches – 6 Critical – 35 CVEs Affected –.NET, GDI+, IE, Defender, DirectShow MS NET Framework and Silverlight, Remote Code.
PREVIOUS GNEWS. try again next week Patch Tuesday.
PREVIOUS GNEWS. 16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative.
Previous Gnews. 5 Patches – x bugs addressed Other updates, MSRT, Defender Definitions, Junk Mail Filter 5 Security Patches - 5 Critical –MS – JScript.
PREVIOU S GNEWS. May 7 Patches – 2 Critical - 70 CVEs MS Remote Desktop, Allow Tampering MS TCP Protocol, DoS MS Microsoft Lync.
PREVIOUS GNEWS A Hacker is You!. 1 Patches – 1 bugs addressed Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 4 Patches / 5 Vulns – 3 Critical Affecting Winodow (all of them), Office, IE, SharePoint,.net Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. Aug - 4 Patches – 1 Critical - 42 CVEs MS – IE Cumulative Security Update, Remote Code MS –.NET Framework, DoS MS –
PREVIOUS GNEWS. 2 Patches – 2 Important Affecting Windows Movie Maker, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS –
PREVIOUS GNEWS. 2 Patches – 2 Critical Affecting VB and Mail Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS – Visual Basic for.
PREVIOUS GNEWS. 3 Patches – 4 Critical – 53+ CVEs Affected – Kernel, AD, SharePoint, Office, and more MS Microsoft SharePoint Server, Remote Code.
Previous Gnews. Patch Tuesday April – 8 Patches (5 high/critical), Windows, Excel, ISA, IE, HTTP Services MS thru MS May – 1 Patch (critical)
PREVIOUS GNEWS. 2 Patches – bugs addressed Affecting Windows (all versions) Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOU S GNEWS. May 9 Patches – 3 Critical - 1 out of band – 14 CVEs MS Security Update for Internet Explorer MS SharePoint Server, Remote.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter 10 Security Patches - 6 Critical, 3 Important, 1 Moderate –MS Active.
PREVIOUS GNEWS. Aug - 9 Patches – 1 Critical - 37 CVEs MS Windows Media Center, Remote Code MS – SQL Server, Privilege Escalation MS
PREVIOUSLY GNEWS Patch Tuesday Nov - 12 Patches – 8 Critical – 60ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS Cumulative Security Update for IE (Aug Out of Band) MS Cumulative.
PREVIOUSLY GNEWS Patch Tuesday Jan – 10 (9) Patches – 6 Critical – 24ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
GNEWS, PREVIOUSLY Patch Tuesday Aug - 6 Patches – 3 Critical - 33 CVEs MS Cumulative Security Update for Internet Explorer MS Cumulative.
GNEWS PREVIOUS. Patch Tuesday jul - x Patches – x Critical - x CVEs Releases Next Week.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter Out of Band Patchs –MS – IE Cumulative Security Update / Activex –MS
PREVIOUS GNEWS Mar – 13 Patches – 6 Critical – 30 CVEs MS Cumulative Security Update for IE MS Cumulative Security Update for Microsoft.
PREVIOUS GNEWS. 8 Patches – 6 Critical – 19+ CVEs Affected – Kernel, AD, Exchange, Unicode, ICMP MS Security Update for Internet Explorer, Remote.
PREVIOUS GNEWS Jun – 14 Patches – 7 Critical – 47 CVEs MS Cumulative Security Update for Internet Explorer, Remote Code MS Cumulative.
PREVIOUSLY GNEWS Feb – 13 Patches – 6 Critical – 36ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative Security.
Amol Sarwate Director of Vulnerability Labs, Qualys Inc State of Vulnerability Exploits.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
PREVIOUS GNEWS All images scavenged without permission.
PREVIOUS GNEWS All images scavenged without permission.
PREVIOUS GNEWS All images scavenged without permission.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Presentation transcript:

 

Jul - 15 Patches – 5 Critical - 60 CVEs MS SQL Server, Remote Code MS Security Update for IE MS VBScript Scripting Engine, Remote Code MS RDP, Remote Code MS Windows Hyper-V, Remote Code MS Windows, Remote Code MS Microsoft Office, Remote Code MS Netlogon, Privilege Escalation MS Windows Graphics Component, Privilege Escalation MS Windows Kernel-Mode Driver, Privilege Escalation MS Windows Installer Service, Privilege Escalation MS OLE, Privilege Escalation MS Windows Remote Procedure Call, Privilege Escalation MS ATM Font Driver, Privilege Escalation MS Microsoft Font Driver, Remote Code Patch Tuesday

Aug - 14 Patches – 4 Critical - 58 CVEs MS Cumulative Security Update for IE MS Microsoft Graphics Component, Remote Code MS Microsoft Office, Remote Code MS RDP, Remote Code MS Server Message Block, Remote Code MS XML Core Services, Information Disclosure MS Mount Manager, Privilege Escalation MS System Center Operations Manager, Privilege Escalation MS UDDI Services, Privilege Escalation MS Unsafe Command Line Parameter Passing, Information Disclosure MS WebDAV, Information Disclosure MS Microsoft Windows, Privilege Escalation MS Cumulative Security Update for Microsoft Edge MS NET Framework, Privilege Escalation

Oracle –193 fixes Adobe –APSB15-16 Flash Player (37 CVE) –APSB15-18 Flash Player (2 CVE) –APSB15-19 Flash Player (35 CVE) Apple –0 Cisco –TelePresence –Videoscape –Virtual WSA, ESA, SMA (default ssh keys) –FireSIGHT (XSS) –WebEx VMWare –VMSA (1 CVE) –Workstation/Player/Horizon View Holes / Patches

IE 0-day MS out-of-band patch, MS Win 10 to virtualize LSA win10 release qualys Xen exscape flaw tweetable mac exploit apple invoice vuln mac firmware worm mac dyld vuln Mucho Grande

LandRover door unlock bug jeep killer –Recall on 1.4 mil models with Uconnect GM on-star new list of pervs malware + barphone = tempest square skimmer stealing never pays Hacking

ProxyHam box dies in dev CVS Photo Kiosk Walmart CA BestBuy giftcards United now rewarding hackers fireeye intern busted cloudflare transparency report Adobe teams up with google for flash security netragard shuts down exploit acquisutions vupen creates new co Zerodium opendns to launch bgp twitter feed FTC Charges Lifelock with deception Corp

MS to acquire Adallom UCLA Health sued for 4.5mil person breach MIE healthcare breach 3.9mil Can Epson get printers right?! bitdefender popped google / samsung to begin monthly patching Corp

Govt enters vuln disclosure debate new car legislation expected German declares treason on netzpolitik.org nist sha-3 FDA says stop using pump Govt

Palo Alto Security Canon New DNT initiative WebApp stuff application-penetration-testing Dissecting the Hack: The V3rboten Network Papers

WTF Smart Safe with external usb port hack my rifle (or just learn to shoot)

Mozilla InvestiGator (mig) PSRecon Lockheed Laika BOSS (+paper) (malware analysis) powershell empire privacy badger 1.0 MS ATA (Advanced Threat Analytics) ctf survey (85% of us use the same 5 tools) “Milano” hacking team malware detection utility Hackerslist.com your're doing it wrong! change grades in highschool $ to $2, vs Change Grades from University $ to $ regripper shellbags explorer Kansa (powershell ir framework)

BlackHat Chrysler vulns to be discussed Hardware hacking Cylance "no sandbox" machine learning malware detection BGP?? Wearable IoT (who wears a fitbit but refuses to use FB?) door badge skimming BSidesLV DefCon 23 Cons Past

SCADA Nexus2-3 Sep Hacker Halted13 Sep DerbyCon23-27 Sep IT Security one2one Summit4-6 Oct Root-66 3 Nov B-Sides DFW7 Nov Cons Future

DHA ( 1 st Wednesday / Tavern on Main, richardson ) TX2600 ( 1 st Fri / Wild Turkey 35&WalnutHill, dallas ) (1 st Fri / 1418 Coffeehouse, plano) The Lab.MS ( 2 nd Monday / varies, plano ) Crypto Party ( 3 rd Thursday / Improving Enterprises, addison ) NAISG ( 4 th Thursday / CrossPointe Theatre, carrollton ) LockPick DFW ( we want to think it exists ) Dallas MakerSpace Random / carrollton Local

All images scavenged without permission