1 / 16

Previous Gnews

Previous Gnews. Do Not Poke It If It Is Not Yours Do Not Brag About Questionable Activity Do Not Hack The Venue Not Legal Advice Everything Is Theoretical Use At Your Own Risk Not Responsible For Damages Mileage May Vary Trust No One Verify Everything Do Your Own Research

Download Presentation

Previous Gnews

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Previous Gnews

  2. Do Not Poke It If It Is Not Yours Do Not Brag About Questionable Activity Do Not Hack The Venue Not Legal Advice Everything Is Theoretical Use At Your Own Risk Not Responsible For Damages Mileage May Vary Trust No One Verify Everything Do Your Own Research Create Your Own Opinion Communicate Share Learn Enjoy

  3. Patch Tuesday • Apr –75 CVE / 34 KB Articles • Reports of 4-6 Critical, 1 actively exploited • Adobe Flash Player • Internet Explorer • Microsoft Edge • Microsoft Windows • Microsoft Office and Microsoft Office Services and Web Apps • ChakraCore • ASP.NET • Microsoft Exchange Server • Team Foundation Server • Azure DevOps Server • Open Enclave SDK • Windows Admin Center • Azure Linux Guest Agent

  4. Holes / Patches • VMWare • VMSA-2019-0002 VM Workstation • VMSA-2019-0003 VM Horizon • VMSA-2019-0004 VCloud Director • VMSA-2019-0005 ESXi, Worksation, Fusion • Apple • iOS 12.2 • xCode 10.2 • tvOS 12.2 • MacOS 2019-002 • Safari 12.1 • iTunes (win) 12.9.4 • iCloud (win) 7.11 • watchOS 5.2 • Chrome • x • Oracle • Next week Expect everything • Adobe • APSB19-17 Acrobat and Reader, id • Cisco • x • Juniper • x

  5. isac is a massive tool and left his notes on a remote device Improvise…

  6. Holes • x

  7. Nefarious?! • x

  8. x Corp I (the good…)

  9. Govt • x

  10. Papers x

  11. WTF x

  12. Slack enumeration https://github.com/emtunc/SlackPirate Tools

  13. Past Cons IANS Dallas Informatio Security Forum 27 Mar - Dallas Bsides Austin 28-29 March – Austin Kernelcon 5-6 Apr - Omaha HouSecCon 9 - 9-10 Apr – Houston

  14. Future Cons BSidesOK – 10-12 Apr - Tulsa ThotCon 3-4 May – Chicago HackMiami 17-19 May – Miami NolaCon 17-19 May – New Orleans CircleCityCon 6.0 31 May – 2 Jun - Induabapolis

  15. ISSA Fort Worth @ISSAFortWorth ( 2nd Tuesday / location varies ) Hack Ft Worth @Hack_FtW ( 3rd Tuesday / Barrel & Bones, Fort Worth) DHA @Dallas_Hackers ( 1st Wednesday / Family Karaoke, Dallas ) TX2600 @dallas2600 ( 1st Fri / Wild Turkey 35&WalnutHill, Dallas ) The Lab.MS @TheLab_ms ( 2nd Saturday + random events / TheLab.ms, Plano ) OWASP Dallas @OWASPDallas ( 3rd Tuesday / location varies ) Pwn School Project ( 3rd Wed / Dallas | 4th Mon Denton ) Crypto Party DFW @CryptoPartyDFW ( 3rd Thursday / TheLab.ms, Plano ) North Texas ISSA @ntxissa ( 3rd Thursday / Maggiano’s, Plano ) North Texas Cyber Security Group @ntxcsg ( Last Thursday, Jakes, Frisco ) Dallas MakerSpace @dallasmakers ( Random events / Carrollton ) 0-day All Day @0Dayallday ( Quarterly / GeniusDen, Dallas ) Where

  16. All images scavenged without permission All images scavenged without permission

More Related