Presentation is loading. Please wait.

Presentation is loading. Please wait.

All images scavenged without permission

Similar presentations


Presentation on theme: "All images scavenged without permission"— Presentation transcript:

1 All images scavenged without permission

2 All images scavenged without permission
PREVIOUS GNEWS

3 Patch Tuesday Jun – 9 Patches – 5 Critical – 27 CVEs
MS Cumulative Security Update for Internet Explorer, Remote Code MS Cumulative Security Update for Microsoft Edge, Remote Code MS Microsoft Graphics Component, Remote Code MS Windows Kernel-Mode Drivers, Privilege Escalation MS Microsoft Office, Remote Code MS Secure Boot, Security Bypass MS Windows Authentication Methods, Privilege Escalation MS Windows PDF Library, Remote Code MS – ActiveSyncProvider, Info Disclosure Sources:

4 Holes / Patches Oracle Adobe Apple VMWare LastPass 0-Day Ubuntu Forum
276 fixes (new all time high) Adobe APSB16-27 Experience Manager ( 4 CVE) Apple El Capitan and Security update ( 62 CVE) iOS ( 43 CVE) watchOS ( 26 CVE) tvOS ( 37 CVE) Safari ( 12 CVE) iTunes for Win ( 15 CVE) iCloud for Win ( 15 CVE) iOS ( 1 CVE) VMWare VMSA ( 2 CVE) DLL hijack in Windows VM Tools HTTP Header Injection in vCenter and ESXi LastPass 0-Day Thanks Tavis, 1Password on-deck Ubuntu Forum Password dump Bypass UAC with disckcleanup “New” Win10 settings Free MS ebooks Sources: ## Oracle Patches ##Adobe Patches ##Apple patches ##Cisco patches ## VMWare lastpass 0-day ubuntu forum password dump Bypass UAC with disckcleanup new win10 settings MS ebooks

5 Hacking reg key for office based persistence
flaw in asn1 protocol for mobile NEW GSMA SMS auth method (based on phone number?!) detecting hidden services New ransomware decryption protal more wireless input device sniffing hacking OSRAM paypal love google drive love malware and stego spynote leaked Unholy PAC https exploit HEIST https semi side channel (blackhat) Disable chip flag on mag stripe (blackhat) Canbus on 18wheelers (Usnix) Hacking Sources: reg key for office based persistence flaw in asn1 protocol for mobile NEW GSMA SMS auth method (based on phone number?!) detecting hidden services New ransomware decryption protal more wireless input device sniffing hacking OSRAM paypal love google drive love malware and stego spynote leaked unholy pac https exploit https semi side channel Disable chip flag on mag stripe Canbus on 18wheelers

6 Corp bit9 buys confer unilever buys dollar shave club
Verizon buys Yahoo oracle buys NetSuite wallmart courts jetblue cici's pizza breach shapeways hacked well fargo mobile wallet oculus backlog cleared google drops oculus competitor MS overseas data access Sources: bit9 buys confer unilever buys dollar shave club Verizon buys Yahoo oracle buys NetSuite wallmart courts jetblue cici's pizza breach shapeways hacked well fargo mobile wallet oculus backlog cleared google drops oculus competitor MS overseas data access Corp

7 Corp automotive best practices doc google to opensource omnitone
yahoo forced to explain deletion Google HSTS Palo MindMeld threat intel sharing vm kaspersky bug bounty Apple bug bounty Sources: automotive best practices doc google to opensource omnitone yahoo forced to explain deletion Google HSTS Palo MindMeld threat intel sharing vm kaspersky bug bounty Apple bug bounty Corp

8 Govt password sharing NOT cfaa worthy pelosi backs tpp opposition
more tsa master keys (hope) NIST says no to sms 2FA obama response directive Sources: password sharing NOT cfaa worthy pelosi backs tpp opposition more tsa master keys (hope) NIST says no to sms 2FA obama response directive Govt

9 x Papers Sources:

10 WTF Dell Quad Screen 43” Monitor China to lift ban on QR for payments
Sources: dell monitor China to adopt qr code payments

11 Tools Palo Alto CTF http://www.labyrenth.com/
mudge to rate all software BitCluster (hope) Car Hacking Tools (hope) CANtact can-utils ChipWhisper CANiverse (new) can definitions (think googledorks kinda) ICsim - github/zombiecraig github/linklayer github/opengarages Tools Sources: Palo ALto CTF mudge to rate all softwares BitCluster (hope David Décary-Hétu, Mathieu Lavoie) Car Hacking Tools (hope Craig Smith, Eric Evenchick) 2nd can bus allows car start on bit replay CANtact can-utils ChipWhisper CANiverse (new) can definitions (think googledorks kinda) ICsim - github/zombiecraig github/linklayer github/opengarages

12 Future Cons SANS Dallas – 8 – 13 Aug OWASP CFP Open – DC 11-14 Oct
IANS Chicago Information Security Forum –13-14 Sep CornCon – Davenport Iowa 17 Sep SaintCon – Provo Utah Oct Root 66 / InnoTech OKC - 1 Nov BSidesDFW 2016 – 5 Nov Future Cons Sources:

13 North Texas Cyber Security Group
DHA ( 1st Wednesday / Family Karaoke, dallas ) TX2600 ( 1st Fri / Wild Turkey 35&WalnutHill, dallas ) The Lab.MS ( 2nd Monday + random events / TheLab.ms, plano ) OWASP Dallas ( 3rd Tuesday / location varies ) Crypto Party ( 3rd Thursday / Improving Enterprises, addison ) North Texas Cyber Security Group ( 4th Thursday, Jakes, Frisco ) Dallas MakerSpace ( Random events / carrollton ) Hack FtW ( 3rd Thursday / ?? West 7th ?? ) Sources:

14 Sources: All images scavenged without permission


Download ppt "All images scavenged without permission"

Similar presentations


Ads by Google