Sonicwall Vulnerabilities https://psirt.global.sonicwall.com/vuln-list https://blog.scrt.ch/2020/02/11/sonicwall-sra-and-sma-vulnerabilties/ SQL Server RCE Exploit https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/ Ransomware in Switzerland https://www.melani.admin.ch/melani/en/home/dokumentation/newsletter/sicherheitsrisiko-durch-ransomware.html Peripheral Vulnerabilities in Windows and Linux https://eclypsium.com/2020/2/18/unsigned-peripheral-firmware/
More about Curl on Windows https://isc.sans.edu/forums/diary/curl+and+SSPI/25812/ WHO Warns of Coronavirus Phishing https://www.who.int/about/communications/cyber-security DUO Security / Google Identify Malicous Chrome Extensions https://duo.com/labs/research/crxcavator-malvertising-2020
Keep an Eye on Command-Line Browsers https://isc.sans.edu/forums/diary/Keep+an+Eye+on+CommandLine+Browsers/25804/ Old Tricks in New Bots: KBOT https://securelist.com/kbot-sometimes-they-come-back/96157/ OpenSSH Now With Fido/U2F http://www.openssh.com/txt/release-8.2
Changes to Microsoft LDAP/AD And How to Cope with them https://isc.sans.edu/forums/diary/Authmageddon+deferred+but+not+averted+Microsoft+LDAP+Changes+now+slated+for+Q3Q4+2020/25800/ https://isc.sans.edu/forums/diary/March+Patch+Tuesday+is+Coming+the+LDAP+Changes+will+Change+Your+Life/25796/ SweynTooth BLE Vulnerabilities https://asset-group.github.io/disclosures/sweyntooth/ Symantec Endpoint Protection Multiple Issues https://support.symantec.com/us/en/article.SYMSA1505.html DNSSEC Root Key Signing Ceremony Delayed https://mm.icann.org/pipermail/root-dnssec-announce/2020/000121.html
In Episode 164, Ben and Scott dive in and discuss some new features that are coming to the Office 365 Admin Center and Azure Lighthouse that are going to make your life easier if you manage more than one tenant. Sponsors Skill Me Up – Only Skill Me Up provides the bridge Read More
Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+for+February+2020/25790/ Adobe Patches https://helpx.adobe.com/security.html Ransomware Abuses Out of Date Driver https://news.sophos.com/en-us/2020/02/06/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software/
Paypal Phish is Asking for Everything https://isc.sans.edu/forums/diary/Current+PayPal+phishing+campaign+or+give+me+all+your+personal+information/25786/ Dell SupportAssist Client Uncontrolled Search Patch Vulnerability https://www.dell.com/support/article/ro/ro/robsdt1/sln320101/dsa-2020-005-dell-supportassist-client-uncontrolled-search-path-vulnerability?lang=en Lock My PC Used By Support Scammers https://fspro.net/lock-pc/ https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/ Insecure Docker Registries https://unit42.paloaltonetworks.com/leaked-docker-code/
Sandbox Detection Tricks and Nice Obfuscation in a Single VBScript https://isc.sans.edu/forums/diary/Sandbox+Detection+Tricks+Nice+Obfuscation+in+a+Single+VBScript/25780/ Emotet Spreads via Wifi https://www.binarydefense.com/emotet-evolves-with-new-wi-fi-spreader/ Exploit Available for sudo pwfeedback bug https://dylankatz.com/Analysis-of-CVE-2019-18634/ xiongmail/hisilicon Vulnerability https://censys.io/blog/probing-the-xiongmai-hisilicon-soc-vulnerability
In Episode 163, Ben and Scott dive in Power Platform and the PL-900 Power Platform Fundamentals exam. Along the way, they discuss what makes up Power Platform and how you can approach learning about Power Platform. Sponsors ShareGate - ShareGate's industry-leading products help IT professionals worldwide migrate their business to Read More
Malware Using Text from Impeachment News Coverage https://www.bleepingcomputer.com/news/security/malware-tries-to-trump-security-software-with-potus-impeachment/ Coronavirus Themed Malware Targets Japan with Emotet https://twitter.com/Cryptolaemus1/status/1222388971428294656 https://exchange.xforce.ibmcloud.com/collection/18f373debc38779065a26f1958dc260b abuse.ch Offers new "I got phished" service https://igotphished.abuse.ch/ OpenSMTPD RCE Vulnerability https://www.openwall.com/lists/oss-security/2020/01/28/3
In Episode 162, Ben and Scott discuss one of the latest bad moves out of Redmond - forcefully installing the Microsoft Search in Bing extension in Google Chrome. Sponsors Skill Me Up – Only Skill Me Up provides the bridge from fundamentals to certification paths to advanced skills to accelerate digital transformation Read More