52. That's quite a number. It's not the number of updates we have to talk about in this episode, but it is the number of episodes we've released. With that being said, Episode 52 is all about news for the month of February 2018. We have updates in Azure, the Read More
How Did This Memcache Thing Happen? https://isc.sans.edu/forums/diary/How+did+this+Memcache+thing+happen/23391/ Trustico TLS Certificate Revocation https://groups.google.com/forum/#!msg/mozilla.dev.security.policy/wxX4Yv0E3Mk/QZt8UPhKAwAJ Flash on Its Way Out https://www.bleepingcomputer.com/news/security/google-chrome-flash-usage-declines-from-80-percent-in-2014-to-under-8-percent-today/ DNSSEC Is Getting Better But Still Struggeling http://www.theregister.co.uk/2018/02/28/dutch_name_authority_dnssec_validation_errors_can_be_eliminated/ Smart TV Firmware Flaws https://www.av-comparatives.org/wp-content/uploads/2018/02/avc_sigma_medion_201802.pdf
Memcached Servers Used in Reflective DDoS Attacks https://isc.sans.edu/forums/diary/Why+we+Dont+Deserve+the+Internet+Memcached+Reflected+DDoS+Attacks/23389/ Malspam Pushing Formbook Info Stealer https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/23387/ Various SAML Parsers Affected by Comment Parsing Vulnerability https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations
Enumerating S3 Buckets https://github.com/jordanpotti/AWSBucketDump Creating AWS Network Diagrams https://github.com/duo-labs/cloudmapper Selling Macs and "Find my Mac" Feature https://medium.com/@mulligan/how-i-sold-an-old-mac-and-unknowingly-tracked-its-location-for-over-3-years-9a35cd3ca4cf Apple Stopping Support for 1st Gen Apple TV and iTunes on Windows XP / Vista https://support.apple.com/en-us/HT208104
Retrieving Malware Over Tor On Windows (Update) https://isc.sans.edu/forums/diary/Retrieving+malware+over+Tor+on+Windows/23379/ Blackholing Advertising Sites with Pi-Hole https://isc.sans.edu/forums/diary/Blackhole+Advertising+Sites+with+Pihole/23377/ Taxslayer Consent Degree with FTC https://biglawbusiness.com/cybersecurity-enforcers-wake-up-to-unauthorized-computer-access-via-credential-stuffing/ Fortinet (OMG) Mirai https://www.fortinet.com/blog/threat-research/omg--mirai-based-bot-turns-iot-devices-into-proxy-servers.html
In Episode 51, Ben schools Scott on Microsoft 365. Introducing Microsoft 365 “A complete, intelligent solution, including Office 365, Windows 10, and Enterprise Mobility + Security, that empowers everyone to be creative and work together, securely.” Windows 10 Pro, Enterprise & Education Compare Windows 10 editions Windows 10 Enterprise E3 Read More
In Episode 50, Ben and Scott sit down with Waldek Mastykarz to talk about the Office 365 CLI - why it exists, how to get started, what's available today, and how to keep up-to-date as the project grows. https://aka.ms/o365cli Waldek's Blog About Waldek Waldek Mastykarz is a Product Owner at Read More
Ben and Scott are back again in Episode 49 with a recap of your Office 365 news for January 2018. This month it is all about Yammer, SharePoint Online, OneDrive for Business, and Azure Active Directory. Seen Counts in Yammer Manage Yammer users across their life cycle from Office 365 Read More
Episode 48 Scott and Ben jump back into Azure to discuss Azure Log Analytics: Change Tracking and Update Management. As you start to move workloads into Azure IaaS, this is something you'll definitely want to take a look at for better management of your Azure servers. Preview: Update management, inventory, Read More
Analyzing a Word Document Used in a Pentest https://isc.sans.edu/forums/diary/Is+this+a+pentest/23283/ Analyzing BITS Activity https://isc.sans.edu/forums/diary/Investigating+Microsoft+BITS+Activity/23281/ CryptoJacking on YouTube due to Malicious Ads https://blog.trendmicro.com/trendlabs-security-intelligence/malvertising-campaign-abuses-googles-doubleclick-to-deliver-cryptocurrency-miners/ Coincheck Hack Nets 400M USD https://coincheck.com/en/blog/4673 PHPBB Mirror Compromissed https://www.phpbb.com/community/viewtopic.php?f=14&t=2456896 Microsoft Disables Sepctre Variant 2 Patches https://support.microsoft.com/en-us/help/4078130/update-to-disable-mitigation-against-spectre-variant-2
Ransomware As a Service https://isc.sans.edu/forums/diary/Ransomware+as+a+Service/23277/ libcurl Vulnerability http://seclists.org/oss-sec/2018/q1/94 Hide 'N Seek IoT Botnet https://labs.bitdefender.com/2018/01/new-hide-n-seek-iot-botnet-using-custom-built-peer-to-peer-communication-spotted-in-the-wild/ Container Intrusions: Assessing the Efficacy of Intrusion Detection and Analysis Methods for Linux Container Environments https://www.sans.org/reading-room/whitepapers/detection/container-intrusions-assessing-efficacy-intrusion-detection-analysis-methods-linux-container-environments-38245
In Episode 47, Ben and Scott walk through Office 365 Advanced Threat Protection (ATP) and all of the ways it can help you improve your security posture in Office 365 for both Exchange Online and SharePoint Online (including OneDrive for Business and Microsoft Teams!). Office 365 Advanced Threat Protection - Marketing Read More
Apple Patches Everything, Again https://isc.sans.edu/forums/diary/Apple+Updates+Everything+Again/23269/ OpenSSL Introduces its Version of a "Patch Tuesday" https://www.openssl.org/blog/blog/2018/01/18/f2f-london/ "Rapid" Ransomware https://id-ransomware.blogspot.ru/2018/01/rapid-ransomware.html (Russian) https://www.bleepingcomputer.com/forums/t/667032/rapid-ransomware-rapid-paymeme-how-recovery-filestxt-support-topic/page-2