Safely Resetting Routers https://isc.sans.edu/forums/diary/Resetting+Your+Router+the+Paranoid+Right+Way/23719/ CSS mix-blend-mode Side Channel Attack https://www.evonide.com/side-channel-attacking-browsers-through-css3-features/ New ActiveX Exploit Seen in the Wild https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=27263 Apple iMessage Security https://support.apple.com/en-us/HT202303 10 Year Old Vulnerability in Steam Discovered https://www.contextis.com/blog/frag-grenade-a-remote-code-execution-vulnerability-in-the-steam-client
In Episode 67, Ben and Scott are joined by Adam Harmetz where they discuss the latest updates and announcements from SharePoint Conference 2018, including SharePoint spaces, improvements to the Modern UI, SharePoint Lists, and AI. Sponsors Office365AdminPortal.com - Providing admins the knowledge and tools to run Office 365 successfully Intelligink Read More
Windows JScript Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-18-534/ Two Git Vulnerabilities Patched https://marc.info/?l=git&m=152761328506724&w=2 https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/ SpamCannibal Blacklist Temporarily Marks All IPs as "Spam" https://twitter.com/GossiTheDog/status/1001778042400854016 QRadar Remote Code Execution https://blogs.securiteam.com/index.php/archives/3689
New DNS Features https://isc.sans.edu/forums/diary/DNS+is+Changing+Are+you+Ready/23711/ Apple Updates https://support.apple.com/en-us/HT201222 Scans For Misconfigured EOS Blockchain Nodes https://www.bleepingcomputer.com/news/security/misconfigured-eos-blockchain-nodes-under-attack/ NPM Bug Causes Update Failures / Application Crashes https://github.com/npm/npm/issues/20791#issuecomment-392648459 MnuBot Exfiltrates Data Via MSSQL https://securityintelligence.com/new-banking-trojan-mnubot-discovered-by-ibm-x-force-research/
In Episode 66, Ben and Scott are joined by Stephen Rose where they discuss the latest updates and announcements from SharePoint Conference 2018, including OneDrive for Business multi-geo support, improvements to the sharing experience, and reporting. Sponsors Office365AdminPortal.com - Providing admins the knowledge and tools to run Office 365 successfully Read More
In Episode 65, Ben and Scott are joined by Mark Kashman where they discuss the latest updates and announcements from SharePoint Conference 2018. Sponsors Office365AdminPortal.com - Providing admins the knowledge and tools to run Office 365 successfully Intelligink - We focus on the Microsoft Cloud so you can focus on Read More
In Episode 64, Ben and Scott lost the rails, found the rails, and then fell off of them again. Sponsors Office365AdminPortal.com - Providing admins the knowledge and tools to run Office 365 successfully Intelligink - We focus on the Microsoft Cloud so you can focus on your business Show Notes Read More
Malicious SYLK Files Used to Execute Code in Excel https://isc.sans.edu/forums/diary/Malware+Distributed+via+slk+Files/23687/ BMW Releases Patches for Several Cars https://keenlab.tencent.com/en/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf Mac Crypto Miners https://blog.malwarebytes.com/threat-analysis/mac-threat-analysis/2018/05/new-mac-cryptominer-uses-xmrig/ VMWare Spectre Updates https://www.vmware.com/security/advisories/VMSA-2018-0012.html
Spectre NG Patches https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012 https://newsroom.intel.com/editorials/addressing-new-research-for-side-channel-analysis/ https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012 https://bugs.chromium.org/p/project-zero/issues/detail?id=1528 New "Moon" Variant http://blog.netlab.360.com/gpon-exploit-in-the-wild-iv-themoon-botnet-join-in-with-a-0day/ https://isc.sans.edu/forums/diary/Something+Wicked+this+way+comes/23681/ Extracting Keys From Windows ssh-agent https://blog.ropnop.com/extracting-ssh-private-keys-from-windows-10-ssh-agent/
In Episode 63, Ben and Scott lament the end of life announcement for the integration of third-party audio conferencing providers (ACP) with Skype for Business. Sponsors Join Ben and Scott at SharePoint Conference North America. Register today at sharepointna.com with the code SHOAG and save $50 on your registration. Office365AdminPortal.com Read More
PDF Exploit (and Windows Priv. Escalation) Leaked https://www.welivesecurity.com/2018/05/15/tale-two-zero-days/ Possible Vulnerability in Keeper Password Manager http://seclists.org/fulldisclosure/2018/May/41 MyEtherWallet Phishing https://isc.sans.edu/forums/diary/Phishing+emails+for+fake+MyEtherWallet+login+page/23655/
Odd njRat Like Scans Reversed C2 traffic from China Signal Vulnerability (Possibly in Electron, which affects Skype/Slack/others) https://twitter.com/ortegaalfredo/status/995017143002509313 Electron Vulnerability https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass/ Cryptocoin Miner Found in Ubuntu Snap Store https://github.com/canonical-websites/snapcraft.io/issues/651
DNS Exfiltration in Windows https://isc.sans.edu/forums/diary/Exfiltrating+data+from+very+isolated+environments/23645/ Fake Electrun Wallet https://github.com/spesmilo/electrum-docs/blob/master/decompiling_guide.md Treasure Hunter PoS Malware Source Code Leaked https://www.flashpoint-intel.com/blog/treasurehunter-source-code-leaked/ More Malicious Chrome Extensions Spreading via Facebook https://blog.radware.com/security/2018/05/nigelthorn-malware-abuses-chrome-extensions/