PREVIOUS GNEWS
16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative Security Update for Internet Explorer –MS SafeHTML, Could Allow Information Disclosure –MS Windows Kernel-Mode Drivers, Elevation of Privilege –MS Microsoft Foundation Classes, Remote Code Execution –MS Media Player Network Sharing Service, Remote Code Execution –MS Embedded OpenType Font Engine, Remote Code Execution –MS NET Framework, Remote Code Execution –MS OpenType Font (OTF) Format Driver, Elevation of Privilege –MS Microsoft Word, Remote Code Execution –MS Microsoft Excel, Remote Code Execution –MS Windows Common Control Library, Remote Code Execution –MS Windows Media Player, Remote Code Execution –MS COM Validation in Windows Shell and WordPad, Remote Code Execution –MS Windows Local Procedure Call, Elevation of Privilege –MS SChannel, Denial of Service ( ) –MS Windows Shared Cluster Disks, Tampering Patch Tuesday
Oracle, 85 patches Adobe, 3 patches (23 holes in Reader) –APSB10-21 Adobe Reader and Acrobat –APSB10-22 Adobe Flash Player –APSA10-03 Flash Player Apple, –Security Update –QuickTime Cisco –14 patches, multiple products –NTP and SSLVPN, DoS –Multiple issues with H.323 Browsers –YES Holes / Patches
Corp. Hell Apple patents parental controls Apple trademarks “there’s an app for that”
Papers Hakin9 is out ( , ipv6, voip) (IN)Secure Magazine #27 is out
OWSP ZAP (Zed Attack Proxy) A fork of Paros Proxy Updates
Gfirst 6 presentations posted (Aug 2010) Lite coverage of HITB Past Cons
ToorCon San Diego CA 20 – 22 Oct 2010 DayCon Dayton, OH 22 – 23 Oct 2010 SecTor Toronto CA 25 – 27 Oct 2010 B-Sides Dallas, TX 6 Nov 2010 Con
All images scavenged without permission