Download presentation
Presentation is loading. Please wait.
Published byBarbra Taylor Modified over 9 years ago
1
PREVIOUSLY GNEWS
2
Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS15-093 - Cumulative Security Update for IE (Aug Out of Band) MS15-094 - Cumulative Security Update for IE MS15-095 - Microsoft Graphics Component, Remote Code MS15-096 - Microsoft Office, Remote Code MS15-097 - RDP, Remote Code MS15-098 - Server Message Block, Remote Code MS15-099 - XML Core Services, Information Disclosure MS15-100 - Mount Manager, Privilege Escalation MS15-101 - System Center Operations Manager, Privilege Escalation MS15-102 - UDDI Services, Privilege Escalation MS15-103 - Unsafe Command Line Parameter Passing, Information Disclosure MS15-104 - WebDAV, Information Disclosure MS15-105 - Microsoft Windows, Privilege Escalation
3
Oracle –Due in Oct Adobe –APSB15-20 Live Cycle Data Services (1 CVE) –APSB15-21 ColdFusion ( 1 CVE) –APSB15-22 Shockwave Player ( 2 CVE) Apple –Safari 8.0.8 ( 27 CVE) –OSX 10.10.5 and Security Update 2015-006 ( 136 CVE) –iOS 8.4.1 ( 71 CVE) –OSX Server 4.1.5 ( 1 CVE) –QuickTime 7.7.8 ( 9 CVE) Cisco –TelePresence –ASR 1000 –ACE VMWare –0 Apple –Tpwn privilege escalation –iOS Keyraider (rooted phones) Holes / Patches
4
SS7 is broke (MITM) –PSTN protocols / Cellular Roaming HighSchool kid creates search engine more accurate that the big G Android Store Scanner (+ paper) –ID malware in store Hacking
5
Twitter revokes API access for The Open State Foundation –Project archived deleted politician tweets Kaspersky 0-day by Tavis Ormandy FireEye 0-day by Kristian Erik Hermansen (+poc) Corp
6
Draft ISO Standard for Payments http://www.retailtechnologyreview.com/articles/2015/08/18/first-draft-of-iso-20022-for- real-time-payments-standard-is-‘excellent-news’/ PS DSC https://www.sans.org/reading-room/whitepapers/bestprac/configuration-management- windows-powershell-desired-state-configuration-dsc-36167 What Drives Developers to Use Security https://news.ncsu.edu/2015/08/murphy-hill-security-2015/ http://people.engr.ncsu.edu/ermurph3/papers/fse15-main-jim.pdf Papers
7
-Sleepy Puppy (Netflix) XSS discovery https://github.com/Netflix/sleepy-puppy 5 Analytics tools Open SOC (Cisco) https://opensoc.github.io/ Community Edition Infinit.e (ikanow) http://www.ikanow.com/downloads/ Splunk http://www.splunk.com/en_us/download.html Open Threat Exchange (alienvault) https://otx.alienvault.com/ Symbiosis OSINT Model http://www.internationaljournalofresearch.org/index.php/ijr/arti cle/view/1791/1681 Tools
8
DerbyCon23-27 Sep Root-66 3 Nov B-Sides DFW7 Nov Cons Future
9
DHA ( 1 st Wednesday / Tavern on Main, richardson ) TX2600 ( 1 st Fri / Wild Turkey 35&WalnutHill, dallas ) (1 st Fri / 1418 Coffeehouse, plano) The Lab.MS ( 2 nd Monday / varies, plano ) Crypto Party ( 3 rd Thursday / Improving Enterprises, addison ) NAISG ( 4 th Thursday / CrossPointe Theatre, carrollton ) LockPick DFW ( we want to think it exists ) Dallas MakerSpace Random / carrollton Local
10
All images scavenged without permission
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.