. Apr - 11 Patches – 4 Critical - 26 CVEs MS15-032 - Cumulative Security Update for IE MS15-033 - Office, Remote Code MS15-034 - HTTP.sys,

Slides:



Advertisements
Similar presentations
PREVIOUS GNEWS. ? Patches – ? Critical – ? CVEs Affected – ? Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS NEXT WEEK FOOL Patch.
Advertisements

How Secure Are Your On-Line Payments? Brad Rand V.P. Information Technology Infrastructure Manager Information Security Officer.
PREVIOUS GNEWS. ? Patches – ? Critical – ? CVEs Affected – ? Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – RDP, IE, Lync, Windows Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 11 Patches – 5 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS IE, Remote Execution.
. 15 Patches / 32 Vulns – 9 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 13 Patches – 5 Critical Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
3 Patches – x bugs addressed Affecting Kernel, SChannel, DNS/WINS Other updates, MSRT, Defender Definitions, Junk Mail Filter 3 Security Patches - 1 Critical,
GNEWS PREVIOUS. Feb - 14 Patches – 5 Critical - 45 CVEs MS Cumulative Security Update for IE MS VBScript Scripting, Remote Code MS
PREVIOUS GNEWS. Oct - 8 Patches – 3 Critical - 24 CVEs MS Cumulative Security Update for Internet Explorer MS NET Framework, Remote Code.
 . Apr - 8 Patches – 2 Critical - 45 CVEs MS Cumulative Security Update for IE, Remote Code MS Windows Media Player, Remote.
To receive our video stream in LiveMeeting: - Click on “Voice & Video” - Click the drop down next to the camera icon - Select “Show Main Video” Dial-in.
PREVIOUS GNEWS. Apr 4 Patches – 2 Critical – 11 CVEs MS Microsoft Word and Office Web Apps, Remote Code MS Cumulative Security Update.
PREVIOUS GNEWS. Feb - 9 Patches – 3 Critical - 55 CVEs MS Update for Internet Explorer MS Windows Kernel-Mode Driver, Remote Code MS
9 Patches – 2 Critical – 12 CVEs Affected – IE, Kernel, SharePoint, Remote Desktop, AD….. Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. 6 Patches – 1 Critical – 22 CVEs Affected – IE. Kernel, Print, Office MS Cumulative Security Update for Internet Explorer MS
PREVIOUS GNEWS. Patches – 1 Critical Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS DNS Server, DoS –MS Kernal Mode Driver,
PREVIOUS GNEWS. 8 Patches – 10 bugs addressed Affecting Project, Visio, DNS, GDI, Scripting, Activex, IE, Windows Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. 7 Patches – 3 Critical – 23 CVEs Affected – Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Microsoft Word, Remote.
PREVIOUS GNEWS. 7 Patches – 3 Critical – 20 CVEs Affected – IE, Kernel, Visio, Silverlight Sarepoint,….. Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 2 Patches / 3 Vulns – 1 Critical Affecting Windows XP, Vista, 7, 2003, 2008 Other updates, MSRT, Defender Definitions, Junk Mail Filter.
Previous Gnews. 13 Patches – 8 Critical, Affects pretty much everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS SMBv2.
PREVIOUS GNEWS. July - 6 Patches – 2 Critical - 27 CVEs MS Cumulative Security Update for IE, Remote Code MS – Windows Journal, Remote Code.
PREVIOUS GNEWS. 8 Patches – 3 Critical – 19+ CVEs Affected – GDI, Hyper-V, Outlook, Office, IE, Activex, and more MS Cumulative Security Update.
PREVIOUS GNEWS. 7 Patches – 1 Critical Affecting server builds and powerpoint Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Windows.
PREVIOUS GNEWS. 6 Patches – 4 Critical – 19 CVEs Affected – Kernel, SQL, Kerberos, Word, HTML, SharePoint Other updates, MSRT, Defender Definitions, Junk.
P  e  i  Gne . 6 Patches, 12 bugs – 3 Critical, Affects Windows, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS
PREVIOUS GNEWS. 6 Patches – 4 Critical – 11 CVEs Affected – SQL, Visual Basic, Visual Foxpro, more… Other updates, MSRT, Defender Definitions, Junk Mail.
PREVIOUS GNEWS. Oct - ? Patches – ? Critical - ? CVEs Come Back Next Week Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOUS GNEWS. 4 Patches – x bugs addressed Affecting Windows, SQL, Office, Visual Studio,.Net Other updates, MSRT, Defender Definitions, Junk Mail Filter.
. 6 Patches, 15 bug – 3 Critical, Affects 2000, XP, Srv 2003 / 8, Vista, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter.
PREVIOUS GNEWS. Advanced Notification on Thursday Patch Tuesday.
 . Jul - 15 Patches – 5 Critical - 60 CVEs MS SQL Server, Remote Code MS Security Update for IE MS VBScript Scripting.
PREVIOUS GNEWS. –MS Microsoft XML Core Services, Remote Execution –MS Cumulative Security Update for Internet Explorer –MS Microsoft.
PREVIOUS GNEWS. Jan 4 Patches – 0 Critical – 6 CVEs 9 Patches – 4 Critical – 31+ CVEs MS Microsoft XML Core Services, Info Disclosure MS
PREVIOUS GNEWS. 7 Patches – 6 Critical – 35 CVEs Affected –.NET, GDI+, IE, Defender, DirectShow MS NET Framework and Silverlight, Remote Code.
PREVIOUS GNEWS. try again next week Patch Tuesday.
PREVIOUS GNEWS. 16 Patches / 49 Vulns – 4 Critical Affecting most everything Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS Cumulative.
Previous Gnews. 5 Patches – x bugs addressed Other updates, MSRT, Defender Definitions, Junk Mail Filter 5 Security Patches - 5 Critical –MS – JScript.
PREVIOU S GNEWS. May 7 Patches – 2 Critical - 70 CVEs MS Remote Desktop, Allow Tampering MS TCP Protocol, DoS MS Microsoft Lync.
PREVIOUS GNEWS A Hacker is You!. 1 Patches – 1 bugs addressed Affecting Windows (pretty much all of them) Other updates, MSRT, Defender Definitions, Junk.
PREVIOUS GNEWS. 4 Patches / 5 Vulns – 3 Critical Affecting Winodow (all of them), Office, IE, SharePoint,.net Other updates, MSRT, Defender Definitions,
PREVIOUS GNEWS. Aug - 4 Patches – 1 Critical - 42 CVEs MS – IE Cumulative Security Update, Remote Code MS –.NET Framework, DoS MS –
PREVIOUS GNEWS. 2 Patches – 2 Important Affecting Windows Movie Maker, Office Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS –
PREVIOUS GNEWS. 2 Patches – 2 Critical Affecting VB and Mail Other updates, MSRT, Defender Definitions, Junk Mail Filter –MS – Visual Basic for.
PREVIOUS GNEWS. 3 Patches – 4 Critical – 53+ CVEs Affected – Kernel, AD, SharePoint, Office, and more MS Microsoft SharePoint Server, Remote Code.
Previous Gnews. Patch Tuesday April – 8 Patches (5 high/critical), Windows, Excel, ISA, IE, HTTP Services MS thru MS May – 1 Patch (critical)
PREVIOUS GNEWS. 2 Patches – bugs addressed Affecting Windows (all versions) Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday.
PREVIOU S GNEWS. May 9 Patches – 3 Critical - 1 out of band – 14 CVEs MS Security Update for Internet Explorer MS SharePoint Server, Remote.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter 10 Security Patches - 6 Critical, 3 Important, 1 Moderate –MS Active.
PREVIOUS GNEWS. Aug - 9 Patches – 1 Critical - 37 CVEs MS Windows Media Center, Remote Code MS – SQL Server, Privilege Escalation MS
PREVIOUSLY GNEWS Patch Tuesday Nov - 12 Patches – 8 Critical – 60ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
PREVIOUSLY GNEWS. Patch Tuesday Aug - 13 Patches – 6 Critical - 57 CVEs MS Cumulative Security Update for IE (Aug Out of Band) MS Cumulative.
PREVIOUSLY GNEWS Patch Tuesday Jan – 10 (9) Patches – 6 Critical – 24ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative.
GNEWS, PREVIOUSLY Patch Tuesday Aug - 6 Patches – 3 Critical - 33 CVEs MS Cumulative Security Update for Internet Explorer MS Cumulative.
GNEWS PREVIOUS. Patch Tuesday jul - x Patches – x Critical - x CVEs Releases Next Week.
Previous Gnews. Other updates, MSRT, Defender Definitions, Junk Mail Filter Out of Band Patchs –MS – IE Cumulative Security Update / Activex –MS
PREVIOUS GNEWS Mar – 13 Patches – 6 Critical – 30 CVEs MS Cumulative Security Update for IE MS Cumulative Security Update for Microsoft.
PREVIOUS GNEWS. 8 Patches – 6 Critical – 19+ CVEs Affected – Kernel, AD, Exchange, Unicode, ICMP MS Security Update for Internet Explorer, Remote.
PREVIOUS GNEWS Jun – 14 Patches – 7 Critical – 47 CVEs MS Cumulative Security Update for Internet Explorer, Remote Code MS Cumulative.
PREVIOUSLY GNEWS Feb – 13 Patches – 6 Critical – 36ish CVEs MS Cumulative Security Update for IE, Remote Code MS Cumulative Security.
Amol Sarwate Director of Vulnerability Labs, Qualys Inc State of Vulnerability Exploits.
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
All images scavenged without permission
Presentation transcript:



Apr - 11 Patches – 4 Critical - 26 CVEs MS Cumulative Security Update for IE MS Office, Remote Code MS HTTP.sys, Remote Code MS Graphics Component, Remote Code MS SharePoint Server, Privilege Esclation MS Windows Task Scheduler, Privilege Escalation MS Windows, Privilege Escaltion MS XML Core Services, Security Bypass MS Active Directory Federation Services, Info Disclosure MS NET Framework, Info Disclosure MS Hyper-V, DoS Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday

May - 13 Patches – 3 Critical - 48 CVEs MS MS MS MS MS MS MS MS MS MS MS MS MS Other updates, MSRT, Defender Definitions, Junk Mail Filter Patch Tuesday Cumulative Security Update for IE Font Drivers, Remote Code Journal, Remote Code Office, Remote Code SharePoint Server, Remote Code.NET Framework, Privilege Escalation Silverlight, Privilege Escalation Service Control Manager, Privilege Escalation Kernel-Mode Drivers, Privilege Escalation Kernel, Security Bypass JScript and VBScript Scripting Engines, Security Bypass Management Console File Format, DoS Schannel, Info Disclosure

Windows “Re-Direct To SMB” issue affects all versions Patched Tuesday redux 30+ optionals out-of-band Windows 10 to kill and bury patch tuesday (for non-pro/business versions) "will also be regularly delivering ongoing Windows innovation in addition to security updates." Limited 2 month bounty on spartan browser, ends 22 June oohh Microsoft ?!

Oracle –14 Apr / 98 fixes Adobe –APSB15-06 Flash Player (13 CVE) –APSB15-09 Flash Player (18 CVE) –APSB15-10 Adobe Reader (7 CVE) Apple, –Safari 8.06 / / (5 CVE) –OSX Server 4.1 (4 CVE) –Xcode 6.3 (1 CVE) –Apple TV 7.2 (gen3+) (39 CVE) –iOS 8.3 (58 CVE) –Security Update (77 CVE) Cisco –Web Security Appliance, Python Parsing issue, Remote Code –FireSIGHT, XSS –NTP, DOS VMWare –none Lenovo –System Update, Remote Code –Patched via System Update :) Holes / Patches

Apple API to root RootPipe not really fixed? Apple Darwin Nuke “No iOS Zone” Reboot Loop browser on apple watch mac keeper? upgrade to now apple beats reportedly seeking exclusive contracts apple bans time apps on watch Apple HealthKit follow-up –"Apple has put too much onus on developers to provide the right level of security.“ –1 st 24hrs, 11K signup for 1 Standford study Mac Tweaks for Speed More Rotten Apples

Hospira LifeCare drug pump flaw 35 sat antena GoT episodes leak Clock speeds are lies Kiosk Break-outs – wifi via LED, Wi-FO HSBC mortgage breach Match.com non-https logon Genome editing is here projector fun (InFocus IN3128HD auth bypass) ebay xss MySQL SSL strip Google pass alert outta my sandbox kid (single core detection) don't audit me brah (rombertik malware) Hacking

Trustwave to be bought by Singtel Raytheon buys Websense Ebay / PayPal split TOR Cloud calls it quits Intercept Secure Drop Hidden Service AlienVault Open Threat Exchange 2.0 product liability protection DropBox Bounty Program Return of WikiLeaks submission site - wlupld3ptjvsgwqw.onion grooveshark.io better bitcoin? (federated Byzantine agreement) Surveillance state repeal act sendgrid breach HardRock payment breach Sally popped again FB video redirect vuln Corp

McConnell and Burr hope to reauthorize sec.215 Medicare to remove SSN from card no-fly reasons now available congressional hearing on crypto you gps'ed my skimmer FBI 3mil "bug" bounty for russian Innovation Act back on the table, Introduction of PATENT Act 11th circuit overturns privacy ruling VA man sues for reader data / LA says we don't have to tell you nee-ner-nee-ner NSA phone data illegal Govt

PCI Card Production Standard update 1.1 PCI 3.1 update Verizon DBIR Symantec ISTR Payment Jury updated200415# &fbinitialized Attaking Smart Homes with Software Defined Radio systems nmap "cheat sheet" Open Smart Grid - Weak Crypto NFTables Papers

hack all the planes Dear Boeing "have you tried turning it off and on again?" RAGE QUIT 3d snowden dirty apple / Bad robot WTF!?

the dude network mgt USBKill rapid shutdown netflix fido IR Toolkit Splunk app for MHN MS LAPS Local Admin Vault ISWatch Intel resumes chip $9 PC Tools Interactive shellcode parser Great Cannon Traffic Injection used against github Project Maelstrom public beta bit torrent p2p browser tor browser update, 4.5 TeslaCrypt cracker Emet Wdigest dumping meterpreter / mimikatzk in win 8.1

RSA InfoSec Southwest10 – 12 Apr B-Sides Nashville11 Apr InnoTech Dallas16 Apr B-Sides OK18 Apr B-Sides San Antonio2 May Cons Past

Google Grants for women at HITB Amsterdam (May) BH/DC teaser, Miller / Valasek to hack car wireless ThotCon 0x614 – 15 May PenTest Austin (SANS)18 – 23 May DefCon 236 – 9 Aug B-Sides DFWTBD Cons Future

DHA ( 1 st Wednesday / Tavern on Main, richardson ) TX2600 ( 1 st Fri / Wild Turkey 35&WalnutHill, dallas ) (1 st Fri / 1418 Coffeehouse, plano) The Lab.MS ( 2 nd Monday / varies, plano ) Crypto Party ( 3 rd Thursday / Improving Enterprises, addison ) NAISG ( 4 th Thursday / CrossPointe Theatre, carrollton ) LockPick DFW ( Last Monday / looking for new spot, dallas ) Dallas MakerSpace Random / carrollton Local

All images scavenged without permission