Quantcast
Channel: botnets
Viewing all articles
Browse latest Browse all 527

TippingPoint Threat Intelligence and Zero-Day Coverage – Week of July 25, 2016

$
0
0
TP-WeeklyBlog-300x205

History was made this week in the United States. A woman was officially named the presidential nominee for a major political party. Given the fact that the 19th Amendment of the United States Constitution isn’t even 100 years old, this is a tremendous accomplishment. But in my opinion, this accomplishment is long overdue.

While the practice of politics has existed as far back as 2100 BC, information security, in comparison, is in its infancy. Unfortunately, according to a study by the Women’s Society of Cyberjutsu, the percentage of women in network security is not only where it should be, it’s stagnant at 11 percent. I know many women in this field, from hardware and software engineers to product marketing, and from hackers (the good kind) and C-level executives, including our very own CEO Eva Chen. Cyber security professionals aren’t represented by a guy in a hoodie in his basement on his computer hacking things. There are so many security jobs out there and not enough people to fill them. With the number of cybersecurity programs targeting young women, it’s only a matter of time before we hack through that “glass ceiling” firewall. And that’s a platform I can definitely support.

TippingPoint Security Management System (SMS) v4.3.0 Patch 2

Earlier this week, we released patch 2 for SMS v4.3.0.50865. In addition to a number of bug fixes, this patch corrects the following issues:

  • No failed Active Directory login attempts in the SMS audit log.
  • Made it easier to bulk delete a large number of named objects by allowing you to ignore any “named object in use” notifications that occurred during the delete.
  • Out of Memory when performing a large number of filter overrides.
  • Vulnerabilities:
    • CVE-2016-0777: The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
    • CVE-2016-0778: The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
  • Profile and Reputation Enhancements

Prior to performing any upgrade, customers should refer to the version Release Notes for migration planning. For questions or technical assistance, customers can contact the TippingPoint Technical Assistance Center (TAC).

Black Hat 2016 – Las Vegas, Nevada

We will be at Black Hat 2016 next week at the Mandalay Bay in Las Vegas. We’ll be showing a number of demos and participating in the following speaking sessions:

  • Trend Micro sponsored ePlus EC-Council Panel Discussion and Reception at Black Hat
    • Monday, August 1st at the 1923 Bourbon Bar at Mandalay Bay Resort & Casino
  • BADWPAD
    • Maxim Goncharov, Senior Threat Researcher
  • $hell on Earth: From Browser to System Compromise
    • Abdul-Aziz Hariri, Security Researcher
    • Matt Molinyawe, Security Researcher
    • Joshua Smith, Senior Security Researcher
    • Jasiel Spelman, Security Researcher

We’re also having a reception next Tuesday night (August 2) at the Foundation Room at the Mandalay Bay from 6-9pm. We’ll have free drinks and appetizers as well as a chance for you to win a drone! To register for the party, go to https://resources.trendmicro.com/2016-Black-Hat-Reception.html.

Zero-Day Filters

For the second time this month, we did not have any new zero-day filters in this week’s Digital Vaccine (DV) package. A number of existing filters in this week’s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and/or optimize performance. You can browse the list of published advisories and upcoming advisories on the Zero Day Initiative website.

Missed Last Week’s News?

Catch up on last week’s news in my weekly recap posted on the Trend Micro Simply Security blog!


Viewing all articles
Browse latest Browse all 527

Trending Articles