PREVIOUSLY GNEWS
Patch Tuesday Jan – 10 (9) Patches – 6 Critical – 24ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative Security Update for Edge, Remote Code MS Cumulative Security Update for JScript and VBScript, Remote Code MS Microsoft Office, Remote Code MS Windows Kernel-Mode Drivers, Remote Code MS Silverlight, Remote Code, Remote Code MS Microsoft Windows, Remote Code MS Windows Kernel, Privilege Escalation MS ??, ?? MS Microsoft Exchange Server, Spoofing
Adobe –Due on 19 Jan Adobe –APSB16-01 Flash Player ( 19 CVE) –APSB16-02 Acrobat/Reader ( 17 CVE) Apple –QuickTime ( 9 CVE) –Security Update ( 56 CVE) –iTunes ( 12 CVE) MS –MS Radius issue Can bypass Bitlocker when pre-boot is diabled. –PUP detection coming to SCEP/FEP VMWare –VMSA ( 1 CVE) deserialization –VMSA ( 1 CVE) guest privilege escalation Jabber MITM FireEye Bug Juniper Bug Win8, IE 8/9/10 – lose support Holes / Patches
port fail (vpn data leakage) latentbot, super stealthy of the week 13 mil mackeeper datas Corolla controlled by cellphone Unsecure Mongos Dell pre-boot driver Side Loading iOS apps Comcast home security fail open 3d print ceramics Hacking
The tweets warn on state-sponsorship MS to join the nation state advisory band wagon FB open-sources hardware design SEC allows blookchain for stocks Linux foundation corrals IBM, Intel, Chase and more with Openledger (blockchain) Java slap Target mobile app data leak Landry’s breach Hello Kitty breach 3.3 million Hyatt breach Corp
TWC Hacked Voter DB exposed SpaceX makes a successful landing MS acquires Metanautix Toshiba to 86 TV, Laptops, and 7k people Windows 10 + MS Account = encryption key upload Tmobile throttling / CEO asks "who is EFF" GM and Lyft partnership GM "bounty" program TOR Project bug bounty Corp
CISA, because… budget Spy catalouge leaked Kim Dotcom to be extradited DHS Drone Guidance Dutch say yes to encryption body scans one step closer to mandatory Govt
Win10 STIG Kerberos National Security Implications of Virtual Currency powershell remoting remoting-enterprise Data Analytics on Vulnerability Data (using python pandas) Papers
threat intel sharing/automation intelligence-knowledge-management TLS bicycle attack - Guido Vranken SLOTH attacks on SHA Freestart attacks on SHA Papers
Frijoles LV commercial "first" power station hack WTF !!!
Cheap course bundle stacksocial.com Firemon Immediate Insight Community edition Log Analytics ToolWath.org 2014 Top Tools SCADA Default Passwds er/scadapass.csv PrivaTegrity new crypto tool to be released
ShmooCon – DC Jan B-Sides Houston - ? Jan CanSecWest – Vancouver Mar B-Sides Austin Mar-Apr InfoSec Southwest – Austin 8-10 Apr B-Sides OK – 09 Apr B-Sides Nashville – 16 Apr ThotCon 0x7 – Chicago 5-6 May B-Sides San Antonio21 May Cons
DHA ( 1 st Wednesday / Family Karaoke, dallas ) TX2600 ( 1 st Fri / Wild Turkey 35&WalnutHill, dallas ) The Lab.MS ( 2 nd Monday + random events / TheLab.ms, plano ) OWASP Dallas ( 3 rd Tuesday / location varies ) Crypto Party ( 3 rd Thursday / Improving Enterprises, addison ) NAISG replacement is coming ( 4 th Thursday, Jakes, Frisco ) Dallas MakerSpace ( Random events / carrollton )
All images scavenged without permission