110 likes | 120 Views
Stay informed about the latest cybersecurity news and updates, including Microsoft and Apple vulnerabilities, hacking exploits, tech company acquisitions, and important industry events.
E N D
Patch Tuesday • May – 69 CVE / 67 KB Articles with 1276 unique downloads • Reports of 16 Critical / 56 fixes • Internet Explorer • Microsoft Edge • Microsoft Windows • Microsoft Office and Microsoft Office Services and Web Apps • ChakraCore • Adobe Flash Player • .NET Framework • Microsoft Exchange Server • Windows Host Compute Service Shim • DoubleKill IE 0-day?? • Force Win10 April Update • Win10 GPO Trickery
Holes / Patches • VMWare • VMSA-2018-0009 ( 2 CVE ) • vRealize Automation • VMSA-2018-0010 ( 1 CVE ) • Horizon DaaS • Apple • iOS 11.3.1 ( 4 CVE) • Security Update 2018-001 macOS High Sierra ( 3 CVE ) • Safari 11.1 ( 2 CVE) • Security Update 2018-001 Swift 4.1.1 ( 1 CVE) • Trustjacking via iOS WiFi-Sync (RSA) • Cisco • Webex( 7 CVE ) • Remote execution via flash and others • SAML ( 1 CVE ) • AnnyConnect, ASA, Firepower Threat Detect • Oracle • 254 fixes • Meltdown/Spectre (3 CVE ) • Java (14 CVE ) • MySQL (33 CVE ) • Sun (14 CVE ) • Adobe • APSB18-08 Flash Player ( 6 CVE ) • APSB18-10 Experience Mgr ( 3 CVE ) • APSB18-11 InDesign ( 2 CVE ) • APSB18-12 Creative Cloud Desktop Application ( 3 CVE ) • APSB18-13 Digital Editions ( 2 CVE ) • APSB18-14 Clod Fusion ( 5 CVE ) • APSB18-15 PhoneGap Plugin ( 1 CVE ) • APSB18-16 Flash Player ( 1 CVE ) • APSB 18-18 Connect ( 1 CVE )
Hacking • total meltdown exploit • abbott pace makers • outlook ole rtf oh my • BSOD USB (requires autoplay) • coinsecure loses 3 mil • crypto mining now on closed browsers • airgappedcyrpto theft • big fish, little thermometer • Minecraft infection • "upatchable" switch hack • WD nas leaks files • hotel master key • evil maid detection (macbook) • Apple home wifi • VW car hacking • lojack backdoor???
nike buys zodiac inc (analytics) and invertex ltd (imaging) • square buys weebly (365 mil) • Tmobile buys Sprint (26.5 bil) • Global Telco Security Alliance (singapore, japan, span, uae) • Cybersecurity Tech Accord (MS and 33 other corp) • Bad Mongo exposes cryptocurrency users • redbull popped • Github exposes passwords • twitter dumps creds to internal log • SaMD • Cambridge redux • Cambridge shuts down • NSA reports non-use of 0-days • Blu settles • FB history option • developer COCs Corp
internetting is not a crime • accessing public data • PCI cloud guidelines • PCI change looms • webstresser.org takedown • NIST Updates Critical Infrastructure framework (supplychain) • Apple talks to CA autonomous cars • GA now looking at hackback bill • ThaiCERT seizes hidden cobra server • China standard on Personal Info Security • More ICE manuals leaked Govt
cyber bully oem patching? HITB - how andriod hides updates gondala control ToShell WTF
Past Cons InfoSec Southwest BSides OK RSA - MS Security Graph API RSA - hacking med devices RSA Attendee DB exposed
Future Cons HackMiami18-20 May 2018 miami $125+ CircleCity 1-3 Jun 2018 indy $150 ShowMeCon 7-8 Jun St.Charles MO 614Con 14-15 Jun Colombus OH BSidesSATX 16 Jun 2018 san antonio $??? Shakacon 11-12 Jul Honolulu HOPE 20-22 Jul NYC BlackHat 4-9 Aug Vegas BSidesLV 7-8 Aug Vegas DefCon 9-12 Aug Vegas
DHA @Dallas_Hackers ( 1st Wednesday / Family Karaoke, Dallas ) TX2600 @dallas2600 ( 1st Fri / Wild Turkey 35&WalnutHill, Dallas ) The Lab.MS @TheLab_ms ( 2nd Saturday + random events / TheLab.ms, Plano ) ISSA Fort Worth @ISSAFortWorth ( 2nd Tuesday / location varies ) Hack Ft Worth @Hack_FtW ( 3rd-ish Tuesday / Buffalo West, Fort Worth) OWASP Dallas @OWASPDallas ( 3rd Tuesday / location varies ) Crypto Party DFW @CryptoPartyDFW ( 3rd Thursday / TheLab.ms, Plano ) North Texas Cyber Security Group @ntxcsg ( Last Thursday, Jakes, Frisco ) Dallas MakerSpace @dallasmakers ( Random events / Carrollton ) Where
All images scavenged without permission All images scavenged without permission