Presentation is loading. Please wait.

Presentation is loading. Please wait.

PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS15-093 - Cumulative Security Update for IE (Aug Out of Band) MS15-094 - Cumulative.

Similar presentations


Presentation on theme: "PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS15-093 - Cumulative Security Update for IE (Aug Out of Band) MS15-094 - Cumulative."— Presentation transcript:

1 PREVIOUSLY GNEWS

2 Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS15-093 - Cumulative Security Update for IE (Aug Out of Band) MS15-094 - Cumulative Security Update for IE MS15-095 - Microsoft Graphics Component, Remote Code MS15-096 - Microsoft Office, Remote Code MS15-097 - RDP, Remote Code MS15-098 - Server Message Block, Remote Code MS15-099 - XML Core Services, Information Disclosure MS15-100 - Mount Manager, Privilege Escalation MS15-101 - System Center Operations Manager, Privilege Escalation MS15-102 - UDDI Services, Privilege Escalation MS15-103 - Unsafe Command Line Parameter Passing, Information Disclosure MS15-104 - WebDAV, Information Disclosure MS15-105 - Microsoft Windows, Privilege Escalation

3 Oracle –Due in Oct Adobe –APSB15-20 Live Cycle Data Services (1 CVE) –APSB15-21 ColdFusion ( 1 CVE) –APSB15-22 Shockwave Player ( 2 CVE) Apple –Safari 8.0.8 ( 27 CVE) –OSX 10.10.5 and Security Update 2015-006 ( 136 CVE) –iOS 8.4.1 ( 71 CVE) –OSX Server 4.1.5 ( 1 CVE) –QuickTime 7.7.8 ( 9 CVE) Cisco –TelePresence –ASR 1000 –ACE VMWare –0 Apple –Tpwn privilege escalation –iOS Keyraider (rooted phones) Holes / Patches

4 SS7 is broke (MITM) –PSTN protocols / Cellular Roaming HighSchool kid creates search engine more accurate that the big G Android Store Scanner (+ paper) –ID malware in store Hacking

5 Twitter revokes API access for The Open State Foundation –Project archived deleted politician tweets Kaspersky 0-day by Tavis Ormandy FireEye 0-day by Kristian Erik Hermansen (+poc) Corp

6 Draft ISO Standard for Payments http://www.retailtechnologyreview.com/articles/2015/08/18/first-draft-of-iso-20022-for- real-time-payments-standard-is-‘excellent-news’/ PS DSC https://www.sans.org/reading-room/whitepapers/bestprac/configuration-management- windows-powershell-desired-state-configuration-dsc-36167 What Drives Developers to Use Security https://news.ncsu.edu/2015/08/murphy-hill-security-2015/ http://people.engr.ncsu.edu/ermurph3/papers/fse15-main-jim.pdf Papers

7 -Sleepy Puppy (Netflix) XSS discovery https://github.com/Netflix/sleepy-puppy 5 Analytics tools Open SOC (Cisco) https://opensoc.github.io/ Community Edition Infinit.e (ikanow) http://www.ikanow.com/downloads/ Splunk http://www.splunk.com/en_us/download.html Open Threat Exchange (alienvault) https://otx.alienvault.com/ Symbiosis OSINT Model http://www.internationaljournalofresearch.org/index.php/ijr/arti cle/view/1791/1681 Tools

8 DerbyCon23-27 Sep Root-66 3 Nov B-Sides DFW7 Nov Cons Future

9 DHA ( 1 st Wednesday / Tavern on Main, richardson ) TX2600 ( 1 st Fri / Wild Turkey 35&WalnutHill, dallas ) (1 st Fri / 1418 Coffeehouse, plano) The Lab.MS ( 2 nd Monday / varies, plano ) Crypto Party ( 3 rd Thursday / Improving Enterprises, addison ) NAISG ( 4 th Thursday / CrossPointe Theatre, carrollton ) LockPick DFW ( we want to think it exists ) Dallas MakerSpace Random / carrollton Local

10 All images scavenged without permission


Download ppt "PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS15-093 - Cumulative Security Update for IE (Aug Out of Band) MS15-094 - Cumulative."

Similar presentations


Ads by Google