Obfuscated JavaScript Targeting Mobile Devices https://isc.sans.edu/forums/diary/Malicious+JavaScript+Targeting+Mobile+Browsers/23778/ Axis Camera Vulnerabilities https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/ Apple Caches Confidential Data on Unencrypted Drives https://wojciechregula.blog/your-encrypted-photos-in-macos-cache/ Andy Emulator Infected With CryptoMiner https://www.reddit.com/r/emulators/comments/8rj8g5/warning_andy_android_emulator_andyos_andyroid/
Analyzing a Compromised Wordpress Site https://isc.sans.edu/forums/diary/A+Bunch+of+Compromized+Wordpress+Sites/23764/ Breacking Bluetooth Low Energy Smart Padlock https://www.pentestpartners.com/security-blog/totally-pwning-the-tapplock-smart-lock/ WIM Disk Image Vulnerability https://blog.talosintelligence.com/2018/06/vulnerability-spotlight-talos-2018-0545.html Extracting Timely Sign-In Data from Office 365 Logs https://www.sans.org/reading-room/whitepapers/logging/extracting-timely-sign-in-data-office-365-logs-38435
In Episode 69, Ben sits down with Laura Rogers from IW Mentor at SharePoint Conference 2018. Laura shares her experience with SharePoint Swoop and provides insights on the PowerApps landscape. Sponsors Office365AdminPortal.com - Providing admins the knowledge and tools to run Office 365 successfully Intelligink - We focus on the Read More
From MicroTik With Love: Yet Another Router Botnet? https://isc.sans.edu/forums/diary/From+Microtik+with+Love/23762/ Using Cortana To Compromise Windows 10 https://securingtomorrow.mcafee.com/mcafee-labs/want-to-break-into-a-locked-windows-10-device-ask-cortana-cve-2018-8140/ Compromised Docker Images https://kromtech.com/blog/security-center/cryptojacking-invades-cloud-how-modern-containerization-trend-is-exploited-by-attackers Lazy FPU Save/Restore Allows Malware Access to FPU https://access.redhat.com/solutions/3485131
The Seven Properties of Highly Secure Devices https://www.microsoft.com/en-us/research/wp-content/uploads/2017/03/SevenPropertiesofHighlySecureDevices.pdf Finding Deserialisation Issues With Burp https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/june/finding-deserialisation-issues-has-never-been-easier-freddy-the-serialisation-killer/ FTC Starts Looking Into Cryptojacking https://www.consumer.ftc.gov/blog/2018/06/protecting-your-devices-cryptojacking Drupal Disputes Number of Vulnerable Sites https://groups.drupal.org/node/520149
In Episode 68, Ben sits down with Bill Baer to talk about the latest announcements from SharePoint Conference 2018 and the SharePoint Virtual Summit! They touch on everything from the latest announcements with SharePoint spaces to the functionality and release timelines for SharePoint 2019. Sponsors Office365AdminPortal.com - Providing admins the Read More
Running Only Signed Code. Does it work in Windows 10? https://isc.sans.edu/forums/diary/Digging+into+Authenticode+Certificates/23731/ Misconfigured G-Suite Mailing Lists https://www.kennasecurity.com/widespread-google-groups-misconfiguration-exposes-sensitive-information/ Microsoft Releases Open Source Post Quantum VPN https://github.com/Microsoft/PQCrypto-VPN
Apple Patches Everything https://isc.sans.edu/forums/diary/Apple+Security+Updates/23727/ VPNFilter Makes a Comeback https://jask.com/from-russia-with-love/ Reverse Analysis with Radare2 https://isc.sans.edu/forums/diary/Binary+analysis+with+Radare2/23723/ Pet Location Tracker Vulnerabilities https://threatpost.com/pet-trackers-open-to-mitm-attacks-interception/132291/
Safely Resetting Routers https://isc.sans.edu/forums/diary/Resetting+Your+Router+the+Paranoid+Right+Way/23719/ CSS mix-blend-mode Side Channel Attack https://www.evonide.com/side-channel-attacking-browsers-through-css3-features/ New ActiveX Exploit Seen in the Wild https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=27263 Apple iMessage Security https://support.apple.com/en-us/HT202303 10 Year Old Vulnerability in Steam Discovered https://www.contextis.com/blog/frag-grenade-a-remote-code-execution-vulnerability-in-the-steam-client
In Episode 67, Ben and Scott are joined by Adam Harmetz where they discuss the latest updates and announcements from SharePoint Conference 2018, including SharePoint spaces, improvements to the Modern UI, SharePoint Lists, and AI. Sponsors Office365AdminPortal.com - Providing admins the knowledge and tools to run Office 365 successfully Intelligink Read More
Windows JScript Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-18-534/ Two Git Vulnerabilities Patched https://marc.info/?l=git&m=152761328506724&w=2 https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/ SpamCannibal Blacklist Temporarily Marks All IPs as "Spam" https://twitter.com/GossiTheDog/status/1001778042400854016 QRadar Remote Code Execution https://blogs.securiteam.com/index.php/archives/3689
New DNS Features https://isc.sans.edu/forums/diary/DNS+is+Changing+Are+you+Ready/23711/ Apple Updates https://support.apple.com/en-us/HT201222 Scans For Misconfigured EOS Blockchain Nodes https://www.bleepingcomputer.com/news/security/misconfigured-eos-blockchain-nodes-under-attack/ NPM Bug Causes Update Failures / Application Crashes https://github.com/npm/npm/issues/20791#issuecomment-392648459 MnuBot Exfiltrates Data Via MSSQL https://securityintelligence.com/new-banking-trojan-mnubot-discovered-by-ibm-x-force-research/
In Episode 66, Ben and Scott are joined by Stephen Rose where they discuss the latest updates and announcements from SharePoint Conference 2018, including OneDrive for Business multi-geo support, improvements to the sharing experience, and reporting. Sponsors Office365AdminPortal.com - Providing admins the knowledge and tools to run Office 365 successfully Read More