Date Author Title

DAY 19 REMOTE USER VPN TUNNELS

2010-10-19Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?

DAY

2024-03-12/a>Johannes UllrichMicrosoft Patch Tuesday - March 2024
2024-03-05/a>Johannes UllrichApple Releases iOS/iPadOS Updates with Zero Day Fixes.
2024-01-22/a>Johannes UllrichApple Updates Everything - New 0 Day in WebKit
2023-12-12/a>Johannes UllrichMicrosoft Patch Tuesday December 2023
2023-10-10/a>Johannes UllrichOctober 2023 Microsoft Patch Tuesday Summary
2023-09-07/a>Johannes UllrichApple Releases iOS/iPadOS 16.6.1, macOS 13.5.2, watchOS 9.6.2 fixing two zeroday vulnerabilities
2023-06-22/a>Johannes UllrichApple Patches Exploited Vulnerabilities in iOS/iPadOS, macOS, watchOS and Safari
2023-05-16/a>Jesse La GrewSignals Defense With Faraday Bags & Flipper Zero
2023-04-07/a>Johannes UllrichApple Patching Two 0-Day Vulnerabilities in iOS and macOS
2023-02-14/a>Johannes UllrichMicrosoft February 2023 Patch Tuesday
2022-11-29/a>Johannes UllrichPacket Tuesday Episode 3: TCP Urgent Flag. https://packettuesday.com
2022-08-17/a>Johannes UllrichApple Patches Two Exploited Vulnerabilities
2022-05-10/a>Renato MarinhoMicrosoft May 2022 Patch Tuesday
2022-05-03/a>Rob VandenBrinkFinding the Real "Last Patched" Day (Interim Version)
2022-02-10/a>Johannes UllrichiOS/iPadOS and MacOS Update: Single WebKit 0-Day Vulnerability Patched
2022-01-11/a>Johannes UllrichMicrosoft Patch Tuesday - January 2022
2021-11-27/a>Didier StevensVideo: SANS Holiday Hack Challenge 2021 Q&A with Ed Skoudis
2021-09-14/a>Renato MarinhoMicrosoft September 2021 Patch Tuesday
2021-04-13/a>Richard PorterMicrosoft April 2021 Patch Tuesday
2021-03-03/a>Johannes UllrichMicrosoft Releases Exchange Emergency Patch to Fix Actively Exploited Vulnerability
2020-12-08/a>Johannes UllrichDecember 2020 Microsoft Patch Tuesday: Exchange, Sharepoint, Dynamics and DNS Spoofing
2020-06-18/a>Jan KoprivaBroken phishing accidentally exploiting Outlook zero-day
2020-05-14/a>Rob VandenBrinkPatch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe
2020-05-01/a>Jim ClausingAttack traffic on TCP port 9673
2020-03-23/a>Didier StevensWindows Zeroday Actively Exploited: Type 1 Font Parsing Remote Code Execution Vulnerability
2020-03-10/a>Johannes UllrichMicrosoft Patch Tuesday March 2020
2019-07-09/a>John BambenekMSFT July 2019 Patch Tuesday
2019-04-25/a>Rob VandenBrinkUnpatched Vulnerability Alert - WebLogic Zero Day
2018-12-11/a>Richard PorterMicrosoft December 2018 Patch Tuesday
2018-10-09/a>Johannes UllrichOctober 2018 Microsoft Patch Tuesday
2018-09-11/a>Johannes UllrichMicrosoft September Patch Tuesday Summary
2018-06-12/a>Johannes UllrichMicrosoft June 2018 Patch Tuesday
2018-02-01/a>Johannes UllrichAdobe Flash 0-Day Used Against South Korean Targets
2017-07-11/a>Renato MarinhoJuly's Microsoft Patch Tuesday
2017-05-02/a>Richard PorterDo you have Intel AMT? Then you have a problem today! Intel Active Management Technology INTEL-SA-00075
2017-03-14/a>Johannes UllrichFebruary and March Microsoft Patch Tuesday
2017-02-14/a>Johannes UllrichMicrosoft Patch Tuesday Delayed
2017-02-04/a>Xavier MertensDetecting Undisclosed Vulnerabilities with Security Tools & Features
2017-01-10/a>Johannes UllrichJanuary 2017 Microsoft Patch Tuesday
2016-09-13/a>Rob VandenBrinkMicrosoft Patch Tuesday Analysis
2016-08-25/a>Xavier MertensOut-of-Band iOS Patch Fixes 0-Day Vulnerabilities
2016-07-12/a>Johannes UllrichMicrosoft Patch Tuesday Summary for July 2016
2016-05-12/a>Xavier MertensAdobe Released Updates to Fix Critical Vulnerability
2016-04-06/a>Bojan ZdrnjaYAFP (Yet Another Flash Patch)
2016-02-09/a>Johannes UllrichMicrosoft February 2016 Patch Tuesday
2016-02-09/a>Johannes UllrichAdobe Patch Tuesday - February 2016
2016-01-12/a>Alex StanfordJanuary 2016 Microsoft Patch Tuesday
2015-12-08/a>Johannes UllrichDecember 2015 Microsoft Patch Tuesday
2015-11-10/a>Johannes UllrichNovember 2015 Microsoft Patch Tuesday
2015-10-13/a>Alex StanfordOctober 2015 Microsoft Patch Tuesday
2015-09-08/a>Johannes UllrichSeptember 2015 Microsoft Patch Tuesday
2015-08-11/a>Manuel Humberto Santander PelaezAugust 2015 Microsoft Patch Tuesday
2015-07-27/a>Daniel WesemannAngler's best friends
2015-07-14/a>Johannes UllrichJuly 2015 Microsoft Patch Tuesday
2015-07-12/a>Rick WannerAnother Adobe Flash Zero Day http://www.kb.cert.org/vuls/id/338736
2015-06-09/a>Johannes UllrichMicrosoft Patch Tuesday Summary for June 2015
2015-05-12/a>Johannes UllrichMay 2015 Microsoft Patch Tuesday Summary
2015-04-14/a>Alex StanfordMicrosoft Patch Tuesday - April 2015
2015-03-10/a>Johannes UllrichMicrosoft March Patch Tuesday
2015-02-10/a>Mark BaggettMicrosoft Update Advisory for February 2015
2015-02-05/a>Johannes UllrichAdobe Flash Player Update Released, Fixing CVE 2015-0313
2015-01-23/a>Adrien de BeaupreInfocon change to yellow for Adobe Flash issues
2015-01-13/a>Johannes UllrichMicrosoft Patch Tuesday - January 2015 (Really? Telnet?)
2014-12-09/a>Alex StanfordMicrosoft Patch Tuesday - December 2014
2014-11-18/a>Jim ClausingMicrosoft November out-of-cycle patch MS14-068
2014-11-11/a>Johannes UllrichMicrosoft November 2014 Patch Tuesday
2014-10-14/a>Johannes UllrichMicrosoft October 2014 Patch Tuesday
2014-09-09/a>Alex StanfordMicrosoft Patch Tuesday - September 2014
2014-08-12/a>Alex StanfordMicrosoft Patch Tuesday - August 2014
2014-07-30/a>Rick WannerSymantec Endpoint Protection Privilege Escalation Zero Day
2014-07-28/a>Johannes UllrichInteresting HTTP User Agent "chroot-apach0day"
2014-07-08/a>Alex StanfordMicrosoft Patch Tuesday - July
2014-06-10/a>Alex StanfordMicrosoft Patch Tuesday June 2014
2014-06-06/a>Johannes UllrichMicrosoft June Patch Tuesday Advance Notification
2014-05-21/a>John BambenekNew, Unpatched IE 0 Day published at ZDI
2014-05-13/a>Johannes UllrichMicrosoft May 2014 Patch Tuesday
2014-05-01/a>Johannes UllrichMicrosoft Announces Special Patch for IE 0-day (Win XP included!)
2014-04-08/a>Richard PorterApril 2014 Microsoft Patches
2014-03-24/a>Johannes UllrichNew Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks
2014-03-11/a>Johannes UllrichMicrosoft Patch Tuesday March 2014
2014-03-08/a>Guy BruneauMicrosoft March Patch Pre-Announcement
2014-02-20/a>Stephen HallAbobe out of band patch announcement (APSB14-07)
2014-02-14/a>Chris MohanFireEye reports IE 10 zero-day being used in watering hole attack
2014-02-11/a>Johannes UllrichFebruary 2014 Microsoft Patch Tuesday
2014-02-07/a>Johannes UllrichMicrosoft Advance Notification for February 2014
2014-01-14/a>Johannes UllrichMicrosoft Patch Tuesday January 2014
2013-12-10/a>Johannes UllrichMicrosoft December Patch Tuesday
2013-12-07/a>Guy BruneauMicrosoft December Patch Pre-Announcement
2013-11-28/a>Rob VandenBrinkMicrosoft Security Advisory (2914486): Vulnerability in Microsoft Windows Kernel 0 day exploit in wild
2013-11-12/a>Johannes UllrichNovember 2013 Microsoft Patch Tuesday
2013-11-09/a>Guy BruneauIE Zero-Day Vulnerability Exploiting msvcrt.dll
2013-10-08/a>Johannes UllrichMicrosoft October 2013 Patch Tuesday
2013-09-10/a>Swa FrantzenAdobe September 2013 Black Tuesday Overview
2013-09-10/a>Swa FrantzenMicrosoft September 2013 Black Tuesday Overview
2013-08-28/a>Bojan ZdrnjaMS13-056 (false positive)? alerts
2013-08-13/a>Swa FrantzenMicrosoft August 2013 Black Tuesday Overview
2013-08-13/a>Swa FrantzenMicrosoft security advisories: RDP and MD5 deprecation in Microsoft root certificates
2013-07-09/a>Swa FrantzenMicrosoft July 2013 Black Tuesday Overview
2013-07-09/a>Swa FrantzenAdobe July 2013 Black Tuesday Overview
2013-07-06/a>Guy BruneauMicrosoft July Patch Pre-Announcement
2013-06-11/a>Swa FrantzenMicrosoft June 2013 Black Tuesday Overview
2013-06-11/a>Swa FrantzenAdobe June 2013 Black Tuesday Overview
2013-06-11/a>Swa FrantzenOther Microsoft Black Tuesday News
2013-06-11/a>Swa Frantzenvmware security advisory VMSA-2013-0008
2013-05-14/a>Swa FrantzenMicrosoft May 2013 Black Tuesday Overview
2013-05-14/a>Swa FrantzenFirefox & Thunderbird released
2013-05-14/a>Swa FrantzenAdobe May 2013 Black Tuesday Overview
2013-05-14/a>Swa FrantzenMicrosoft Security Advisory 2846338
2013-05-09/a>John BambenekAdobe Releases 0-day Security Advisory for Coldfusion, Exploit Code Available. Advisory here: http://www.adobe.com/support/security/advisories/apsa13-03.html
2013-05-04/a>Kevin ShorttThe Zero-Day Pendulum Swings
2013-04-09/a>Swa FrantzenMicrosoft April 2013 Black Tuesday Overview
2013-04-09/a>Swa FrantzenAdobe April 2013 Black Tuesday Overview
2013-04-04/a>Johannes UllrichMicrosoft April Patch Tuesday Advance Notification
2013-03-12/a>Swa FrantzenMicrosoft March 2013 Black Tuesday Overview
2013-03-12/a>Swa FrantzenAdobe March 2013 Black Tueday
2013-02-14/a>Adam SwangerISC Monthly Threat Update - February 2013 http://isc.sans.edu/podcastdetail.html?id=3121
2013-02-12/a>Adam SwangerMicrosoft February 2013 Black Tuesday Update - Overview
2013-02-12/a>Swa FrantzenAdobe Feb 2013 Black Tuesday patches
2013-02-08/a>Johannes UllrichMicrosoft February Patch Tuesday Advance Notification
2013-02-07/a>John BambenekAdobe Releases Patches for 0-day Vulnerability in Flash Player for Windows and Mac, Upgrade now: http://www.adobe.com/support/security/bulletins/apsb13-04.html
2013-01-22/a>Richard PorterUsing Metasploit for Patch Sanity Checks
2013-01-14/a>Richard PorterMicrosoft Out of Cycle Patch: IE http://technet.microsoft.com/en-us/security/bulletin/ms13-jan
2013-01-14/a>Richard PorterJanuary 2013 Microsoft Out of Cycle Patch
2013-01-13/a>Stephen HallJava 0-Day patched as Java 7 U 11 released
2013-01-12/a>Stephen HallJava 0-day impact to Java 6 (and beyond?)
2013-01-10/a>Adam SwangerISC Monthly Threat Update New Format
2013-01-08/a>Richard PorterMicrosoft January 2013 Black Tuesday Update - Overview
2013-01-04/a>Daniel WesemannPatch pre-notification from Adobe and Microsoft
2013-01-02/a>Russ McReeEMET 3.5: The Value of Looking Through an Attacker's Eyes
2012-12-11/a>John BambenekMicrosoft December 2012 Black Tuesday Update - Overview
2012-11-26/a>John BambenekOnline Shopping for the Holidays? Tips, News and a Fair Warning
2012-11-13/a>Jim ClausingMicrosoft November 2012 Black Tuesday Update - Overview
2012-10-09/a>Johannes UllrichMicrosoft October 2012 Black Tuesday Update - Overview
2012-10-04/a>Johannes UllrichMicrosoft October Patch Pre-Announcement
2012-09-17/a>Rob VandenBrinkIE Zero Day is "For Real"
2012-09-11/a>Adam SwangerMicrosoft September 2012 Black Tuesday Update - Overview
2012-09-01/a>Russ McReeBlackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish
2012-08-14/a>Rick WannerMicrosoft August 2012 Black Tuesday Update - Overview
2012-08-04/a>Kevin ListonVendors: More Patch-Release Options Please
2012-07-10/a>Swa FrantzenMicrosoft July 2012 Black Tuesday Update - Overview
2012-07-10/a>Swa FrantzenMicrosoft revoking trust in Microsoft certificates - SA 2728973
2012-07-10/a>Swa FrantzenMicrosoft fix-it to disable gadgets - SA 2719662
2012-07-05/a>Adrien de BeaupreMicrosoft advanced notification for July 2012 patch Tuesday
2012-06-12/a>Swa FrantzenAdobe June 2012 Black Tuesday patches
2012-06-12/a>Swa FrantzenMicrosoft June 2012 Black Tuesday Update - Overview
2012-06-12/a>Swa FrantzenJava 7u5 and 6u33 released
2012-06-01/a>Johannes UllrichWhat Does "IPv6 Day" mean to you?
2012-05-23/a>Mark BaggettProblems with MS12-035 affecting XP, SBS and Windows 2003?
2012-05-08/a>Adam SwangerMicrosoft May 2012 Black Tuesday Update - Overview
2012-04-15/a>Rick Wanner.Net update affects printing from some applications
2012-04-10/a>Swa FrantzenMicrosoft April 2012 Black Tuesday Update - Overview
2012-04-10/a>Swa FrantzenAdobe April 2012 Black Tuesday Update
2012-04-06/a>Johannes UllrichMicrosoft April Patch Tuesday Pre-Announcement (6 Patches): http://technet.microsoft.com/en-us/security/bulletin/ms12-apr
2012-03-13/a>Lenny ZeltserMarch 2012 Microsoft Black Tuesday
2012-02-14/a>Johannes UllrichFebruary 2012 Microsoft Black Tuesday
2012-01-10/a>Adrien de BeaupreJanuary 2012 Microsoft Black Tuesday Summary
2012-01-10/a>Adrien de BeaupreAdobe January 2012 Black Tuesday overview
2012-01-06/a>Guy BruneauJanuary 2012 Patch Tuesday Pre-release
2011-12-29/a>Richard PorterASP.Net Vulnerability
2011-12-25/a>Deborah HaleMerry Christmas, Happy Holidays
2011-12-21/a>Chris MohanThe off switch
2011-12-13/a>Johannes UllrichDecember 2011 Microsoft Black Tuesday Summary
2011-12-08/a>Adrien de BeaupreNewest Adobe Flash 11.1.102.55 and Previous 0 Day Exploit
2011-12-08/a>Adrien de BeaupreMicrosoft Security Bulletin Advance Notification for December 2011
2011-11-16/a>Jason LamPotential 0-day on Bind 9
2011-11-08/a>Swa FrantzenMicrosoft November 2011 Black Tuesday Overview
2011-11-08/a>Swa FrantzenAbobe November 2011 Black Tuesday Overview
2011-11-08/a>Swa FrantzenApple Black Tuesday
2011-11-03/a>Guy BruneauNovember 2011 Patch Tuesday Pre-release
2011-10-11/a>Swa FrantzenMicrosoft Black Tuesday Overview October 2011
2011-09-13/a>Swa FrantzenMicrosoft September 2011 Black Tuesday
2011-09-13/a>Swa FrantzenAdobe September 2011 Black Tuesday overview
2011-09-09/a>Johannes UllrichEarly Patch Tuesday Today: Microsoft September 2011 Patches
2011-09-08/a>Mark HofmanMicrosoft has released their advanced notification for patch Tuesday. 15 Vulnerabilities to be addressed. more here --> http://blogs.technet.com/b/msrc/archive/2011/09/08/advanced-notification-for-the-september-2011-bulletin-release.aspx
2011-08-09/a>Swa FrantzenMicrosoft August 2011 Black Tuesday Overview
2011-08-09/a>Swa FrantzenAdobe August 2011 Black Tuesday Overview
2011-07-12/a>Swa FrantzenMicrosoft July 2011 Black Tuesday Overview
2011-07-10/a>Raul SilesJailbreakme Takes Advantage of 0-day PDF Vuln in Apple iOS Devices
2011-06-14/a>Swa FrantzenAdobe releases patches
2011-06-14/a>Swa FrantzenMicrosoft June 2011 Black Tuesday Overview
2011-05-10/a>Swa FrantzenMay 2011 Microsoft Black Tuesday Overview
2011-05-06/a>Richard PorterUnpatched Exploit: Skype for MAC
2011-04-11/a>Jim ClausingApril 2011 Microsoft Black Tuesday Summary
2011-04-08/a>Johannes UllrichDark Black Tuesday Coming Up: 17 Microsoft Bulletins
2011-03-08/a>Jim ClausingMarch 2011 Microsoft Black Tuesday Summary
2011-02-08/a>Joel EslerFeburary 2011 Microsoft Black Tuesday Summary
2011-01-11/a>Kevin ShorttJanuary 2011 Microsoft Black Tuesday Summary
2011-01-11/a>Kevin ShorttSpam Cannons on Holiday
2011-01-08/a>Guy BruneauJanuary 2011 Patch Tuesday Pre-release
2010-12-23/a>Mark HofmanIE 0 Day, just in time for Christmas
2010-12-22/a>John BambenekIIS 7.5 0-Day DoS (processing FTP requests)
2010-12-20/a>Guy BruneauPatch Issues with Outlook 2007
2010-12-14/a>Manuel Humberto Santander PelaezDecember 2010 Microsoft Black Tuesday Summary
2010-11-24/a>Bojan ZdrnjaPrivilege escalation 0-day in almost all Windows versions
2010-11-09/a>Johannes UllrichNovember 2010 Microsoft Black Tuesday Summary
2010-11-01/a>Manuel Humberto Santander PelaezCVE-2010-3654 exploit in the wild
2010-10-28/a>Manuel Humberto Santander PelaezCVE-2010-3654 - New dangerous 0-day authplay library adobe products vulnerability
2010-10-26/a>Pedro BuenoFirefox news
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote Access Tools
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN Architectures – SSL or IPSec?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN and Remote Access Tools
2010-10-12/a>Adrien de BeaupreOctober 2010 Microsoft Black Tuesday Summary
2010-10-11/a>Adrien de BeaupreOT: Happy Thanksgiving Day Canada
2010-10-08/a>Rick WannerPatch Tuesday Pre-release -- 16 updates
2010-09-14/a>Adrien de BeaupreSeptember 2010 Microsoft Black Tuesday Summary
2010-08-10/a>Jim ClausingAugust 2010 Micrsoft Black Tuesday Summary
2010-08-07/a>Stephen HallCountdown to Tuesday...
2010-07-13/a>Jim ClausingJuly 2010 Microsoft Black Tuesday Summary
2010-06-08/a>Manuel Humberto Santander PelaezJune 2010 Microsoft Black Tuesday Summary
2010-06-03/a>Guy BruneauMicrosoft Patch Tuesday June 2010 Pre-Release
2010-05-11/a>Scott FendleyMay 2010 Microsoft Patches
2010-05-08/a>Guy BruneauMicrosoft Patch Tuesday May 2010 Pre-Release
2010-04-13/a>Johannes UllrichMicrosoft April 2010 Patch Tuesday
2010-04-08/a>Guy BruneauMicrosoft Patch Tuesday April 2010 Pre-Release
2010-03-09/a>John BambenekMarch 2010 - Microsoft Patch Tuesday Diary
2010-03-01/a>Mark HofmanIE 0-day using .hlp files
2010-02-09/a>Adrien de BeaupreWhen is a 0day not a 0day? Samba symlink bad default config
2010-02-09/a>Johannes UllrichFebruary 2010 Black Tuesday Overview
2010-02-04/a>Johannes UllrichMicrosoft Patch Tuesday Pre-Release
2010-01-21/a>Johannes UllrichMicrosoft January Out of Band Patch
2010-01-14/a>Bojan Zdrnja0-day vulnerability in Internet Explorer 6, 7 and 8
2010-01-12/a>Johannes UllrichMicrosoft Security Bulletin: January 2010
2010-01-12/a>Johannes UllrichPre-Announced Adobe Reader and Acrobat Patch Found!
2010-01-07/a>Daniel WesemannStatic analysis of malicious PDFs
2010-01-07/a>Daniel WesemannStatic analysis of malicous PDFs (Part #2)
2009-12-27/a>Patrick NolanPressure increasing for Microsoft to patch IIS 0 day
2009-12-15/a>Johannes UllrichAdobe 0-day in the wild - again
2009-12-08/a>Deborah HaleDecember 2009 Black Tuesday Overview
2009-11-22/a>Marcus SachsIE6 and IE7 0-Day Reported
2009-11-10/a>Swa FrantzenMicrosoft November Black Tuesday Overview
2009-10-13/a>Johannes UllrichMicrosoft October 2009 Black Tuesday Overview
2009-09-08/a>Adrien de BeaupreMicrosoft Security Advisory 975191 Revised
2009-09-08/a>Guy BruneauMicrosoft September 2009 Black Tuesday Overview
2009-09-04/a>Adrien de BeaupreVulnerabilities (plural) in MS IIS FTP Service 5.0, 5.1. 6.0, 7.0
2009-08-31/a>Pedro BuenoMicrosoft IIS 5/6 FTP 0Day released
2009-08-11/a>Swa FrantzenMicrosoft August 2009 Black Tuesday Overview
2009-07-22/a>Bojan ZdrnjaYA0D (Yet Another 0-Day) in Adobe Flash player
2009-07-17/a>Bojan ZdrnjaA new fascinating Linux kernel vulnerability
2009-07-14/a>Swa FrantzenMicrosoft July Black Tuesday Overview
2009-07-14/a>Swa FrantzenOracle Black Tuesday
2009-07-06/a>Stephen Hall0-day in Microsoft DirectShow (msvidctl.dll) used in drive-by attacks
2009-07-03/a>Adrien de BeaupreHappy 4th of July!
2009-06-09/a>Swa FrantzenMicrosoft June Black Tuesday Overview
2009-06-09/a>Swa FrantzenAdobe June Black Tuesday upgrades
2009-05-12/a>Swa FrantzenMSFT's version of responsible disclosure
2009-05-12/a>Swa FrantzenMay Black Tuesday Overview
2009-04-29/a>Jason LamTwo Adobe 0-day vulnerabilities
2009-04-14/a>Swa FrantzenApril Black Tuesday Overview
2009-03-18/a>Adrien de BeaupreAdobe Security Bulletin Adobe Reader and Acrobat
2009-03-10/a>Swa FrantzenMarch black Tuesday overview
2009-02-25/a>Andre LudwigAdobe Acrobat pdf 0-day exploit, No JavaScript needed!
2009-02-10/a>Swa FrantzenFebruary Black Tuesday Overview
2009-01-13/a>Johannes UllrichJanuary Black Tuesday Overview
2008-12-12/a>Johannes UllrichMSIE 0-day Spreading Via SQL Injection
2008-12-12/a>Kevin ListonIE7 0day expanded to include IE6 and IE8(beta)
2008-12-10/a>Bojan Zdrnja0-day exploit for Internet Explorer in the wild
2008-12-09/a>Swa FrantzenDecember Black Tuesday Overview
2008-11-11/a>Swa FrantzenNovember Black Tuesday Overview
2008-11-02/a>Adrien de BeaupreDaylight saving time
2008-10-14/a>Swa FrantzenOctober Black Tuesday Overview
2008-09-09/a>Swa FrantzenSeptember 2008 Black Tuesday Overview
2008-08-12/a>Stephen HallAugust 2008 Black Tuesday Overview
2008-07-08/a>Swa FrantzenJuly 2008 black tuesday overview
2008-06-10/a>Swa FrantzenJune 2008 Black Tuesday Overview
2008-05-13/a>Swa FrantzenMay 2008 black tuesday overview
2008-04-08/a>Swa FrantzenApril 2008 - Black Tuesday Overview
2008-03-11/a>Swa FrantzenMarch Black Tuesday Overview
2008-02-12/a>Swa FrantzenFebruary Black Tuesday Overview
2008-01-08/a>Swa FrantzenJanuary Black Tuesday overview
2007-12-11/a>Swa FrantzenDecember black tuesday overview
2007-11-13/a>Swa Frantzennovember black tuesday overview
2007-10-09/a>Swa FrantzenOctober Black Tuesday overview
2007-09-11/a>Swa FrantzenSeptember microsoft patch overview
2007-08-14/a>Swa FrantzenAugust 'Black Tuesday' overview
2007-07-10/a>Swa FrantzenJuly 'Black Tuesday' overview
2007-06-12/a>Johannes UllrichJune 2007, Microsoft Patch Tuesday Overview.
2007-05-08/a>Swa FrantzenMay 2007, Black Tuesday patch overview
2007-04-10/a>Swa FrantzenMicrosoft black Tuesday patches - April 2007
2007-04-03/a>Swa Frantzen* Microsoft out of cycle patch
2007-02-13/a>Swa FrantzenMicrosoft Black Tuesday patches - February 2007
2007-01-09/a>Swa FrantzenMicrosoft Patches - January 2007 - overview
2006-12-12/a>Swa FrantzenMicrosoft Black Tuesday - December 2006 overview
2006-12-12/a>Robert DanfordMS06-078: 2 Windows Media Format Vulnerabilities (CVE-2006-4702, CVE-2006-6134)
2006-11-29/a>Toby KohlenbergWeek of Oracle bugs cancelled
2006-11-14/a>Swa FrantzenMicrosoft Black Tuesday Overview
2006-10-09/a>Swa FrantzenMicrosoft black tuesday - October 2006 STATUS
2006-09-28/a>Swa FrantzenPowerpoint, yet another new vulnerability
2006-09-28/a>Swa FrantzenMSIE: One patched, one pops up again (setslice)
2006-09-22/a>Swa FrantzenYellow: MSIE VML exploit spreading
2006-09-19/a>Swa FrantzenYet another MSIE 0-day: VML
2006-09-15/a>Swa FrantzenMSIE DirectAnimation ActiveX 0-day update
2006-09-12/a>Swa FrantzenMicrosoft security patches for September 2006

19

2023-07-12/a>Brad DuncanLoader activity for Formbook "QM18"
2022-06-09/a>Brad DuncanTA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt)
2022-01-12/a>Johannes UllrichA Quick CVE-2022-21907 FAQ
2022-01-02/a>Guy BruneauExchange Server - Email Trapped in Transport Queues
2021-09-16/a>Jan KoprivaPhishing 101: why depend on one suspicious message subject when you can use many?
2021-06-26/a>Guy BruneauCVE-2019-9670: Zimbra Collaboration Suite XXE vulnerability
2020-12-18/a>Jan KoprivaA slightly optimistic tale of how patching went for CVE-2019-19781
2020-07-21/a>Jan KoprivaCouple of interesting Covid-19 related stats
2020-04-29/a>Johannes UllrichPrivacy Preserving Protocols to Trace Covid19 Exposure
2020-04-17/a>Xavier MertensWeaponized RTF Document Generator & Mailer in PowerShell
2020-04-03/a>Xavier MertensObfuscated with a Simple 0x0A
2020-03-28/a>Didier StevensCovid19 Domain Classifier
2020-03-27/a>Johannes UllrichHelp us classify Covid19 related domains https://isc.sans.edu/covidclassifier.html (login required)
2020-03-24/a>Russ McReeAnother Critical COVID-19 Shortage: Digital Security
2020-03-19/a>Xavier MertensCOVID-19 Themed Multistage Malware
2020-01-13/a>Didier StevensCitrix ADC Exploits: Overview of Observed Payloads
2020-01-11/a>Johannes UllrichCitrix ADC Exploits are Public and Heavily Used. Attempts to Install Backdoor
2020-01-07/a>Johannes UllrichA Quick Update on Scanning for CVE-2019-19781 (Citrix ADC / Gateway Vulnerability)
2019-06-19/a>Johannes UllrichCritical Actively Exploited WebLogic Flaw Patched CVE-2019-2729
2019-05-22/a>Johannes UllrichAn Update on the Microsoft Windows RDP "Bluekeep" Vulnerability (CVE-2019-0708) [now with pcaps]
2019-04-28/a>Johannes UllrichUpdate about Weblogic CVE-2019-2725 (Exploits Used in the Wild, Patch Status)
2017-08-24/a>Bojan ZdrnjaFree Bitcoins? Why not?
2016-05-16/a>Rick WannerAn oldie but a goodie - 419 Death Scam
2014-06-12/a>Johannes UllrichMetasploit now includes module to exploit CVE-2014-0195 (OpenSSL DTLS Fragment Vuln.)
2012-05-16/a>Johannes UllrichReserved IP Address Space Reminder
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote Access Tools
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN Architectures – SSL or IPSec?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN and Remote Access Tools
2010-07-26/a>Guy BruneauSophosLabs Released Free Tool to Validate Microsoft Shortcut
2010-07-20/a>Manuel Humberto Santander PelaezLNK vulnerability now with Metasploit module implementing the WebDAV method

REMOTE

2022-10-07/a>Xavier MertensCritical Fortinet Vulnerability Ahead
2021-05-14/a>Xavier Mertens"Open" Access to Industrial Systems Interface is Also Far From Zero
2021-02-13/a>Guy BruneauvSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2020-09-29/a>Xavier MertensManaging Remote Access for Partners & Contractors
2020-08-22/a>Guy BruneauRemote Desktop (TCP/3389) and Telnet (TCP/23), What might they have in Common?
2019-09-24/a>Xavier MertensHuge Amount of remotewebaccess.com Sites Found in Certificate Transparency Logs
2017-11-25/a>Guy BruneauExim Remote Code Exploit
2015-10-12/a>Guy BruneauCritical Vulnerability in Multiple Cisco Products - Apache Struts 2 Command Execution http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2
2013-09-18/a>Rob VandenBrinkCisco DCNM Update Released
2013-02-16/a>Lorna HutchesonFedora RedHat Vulnerabilty Released
2012-08-22/a>Adrien de BeaupreApple Remote Desktop update fixes no encryption issue
2012-03-16/a>Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2011-11-28/a>Tom ListonA Puzzlement...
2011-11-19/a>Pedro BuenoDragon Research Group (DRG) announced the white paper entitled "VNC: Threats and Countermeasures" : https://dragonresearchgroup.org/insight/vnc-tac.html
2011-08-11/a>Guy BruneauBlackBerry Enterprise Server Critical Update
2010-12-19/a>Raul SilesIntel's new processors have a remote kill switch (Anti-Theft 3.0)
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote Access Tools
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN and Remote Access Tools
2010-05-12/a>Rob VandenBrinkAdobe Shockwave Update
2010-03-15/a>Adrien de BeaupreSpamassassin Milter Plugin Remote Root Attack
2010-03-10/a>Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-02-02/a>Guy BruneauCisco Secure Desktop Remote XSS Vulnerability
2009-11-14/a>Adrien de BeaupreMicrosoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-12/a>Rob VandenBrinkWindows 7 / Windows Server 2008 Remote SMB Exploit
2008-05-06/a>Marcus SachsIndustrial Control Systems Vulnerability
2008-03-13/a>Jason LamRemote File Include spoof!?
2006-11-20/a>Joel EslerMS06-070 Remote Exploit

USER

2024-02-28/a>Johannes UllrichExploit Attempts for Unknown Password Reset Vulnerability
2024-01-24/a>Johannes UllrichHow Bad User Interfaces Make Security Tools Harmful
2024-01-08/a>Jesse La GrewWhat is that User Agent?
2023-09-05/a>Jesse La GrewCommon usernames submitted to honeypots
2021-09-24/a>Xavier MertensKeep an Eye on Your Users Mobile Devices (Simple Inventory)
2021-04-24/a>Guy BruneauBase64 Hashes Used in Web Scanning
2021-03-02/a>Russ McReeAdversary Simulation with Sim
2019-07-25/a>Rob VandenBrinkWhen Users Attack! Users (and Admins) Thwarting Security Controls
2019-07-05/a>Didier StevensA "Stream O" Maldoc
2019-07-01/a>Didier StevensMaldoc: Payloads in User Forms
2018-05-27/a>Guy BruneauCapture and Analysis of User Agents
2018-01-01/a>Didier StevensWhat is new?
2014-04-05/a>Jim ClausingThose strange e-mails with URLs in them can lead to Android malware
2013-01-15/a>Rob VandenBrinkWhen Disabling IE6 (or Java, or whatever) is not an Option...
2012-07-14/a>Tony CarothersUser Awareness and Education
2012-04-05/a>Johannes UllrichEvil hides everywhere: Web Application Exploits in Headers
2011-08-26/a>Daniel WesemannUser Agent 007
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2009-05-28/a>Jim ClausingMore new volatility plugins
2008-09-18/a>Bojan ZdrnjaMonitoring HTTP User-Agent fields

VPN

2024-01-16/a>Johannes UllrichScans for Ivanti Connect "Secure" VPN Vulnerability (CVE-2023-46805, CVE-2024-21887)
2023-09-18/a>Johannes UllrichInternet Wide Multi VPN Search From Single /24 Network
2023-09-07/a>Johannes UllrichFleezeware/Scareware Advertised via Facebook Tags; Available in Apple App Store
2023-06-21/a>Yee Ching TokAnalyzing a YouTube Sponsorship Phishing Mail and Malware Targeting Content Creators
2021-09-21/a>Johannes UllrichA First Look at Apple's iOS 15 "Private Relay" feature.
2021-07-10/a>Guy BruneauScanning for Microsoft Secure Socket Tunneling Protocol
2020-07-29/a>Johannes UllrichConsumer VPNs: You May Be Fine Without
2020-03-15/a>Guy BruneauVPN Access and Activity Monitoring
2018-09-19/a>Rob VandenBrinkCertificates Revisited - SSL VPN Certificates 2 Ways
2017-04-02/a>Guy BruneauIPFire - A Household Multipurpose Security Gateway
2015-12-22/a>Rick WannerThe other Juniper vulnerability - CVE-2015-7756
2015-02-13/a>Johannes UllrichMicrosoft February Patch Failures Continue: KB3023607 vs. Cisco AnyConnect Client
2012-12-06/a>Johannes UllrichHow to identify if you are behind a "Transparent Proxy"
2011-06-28/a>Johannes UllrichDeja-Vu: Cisco VPN Windows Client Privilege Escalation
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN Architectures – SSL or IPSec?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN and Remote Access Tools
2009-12-01/a>Chris CarboniClientless SSL VPN products break web browser domain-based security models
2009-11-17/a>Guy BruneauOpenVPN Fixed OpenSSL Session Renegotiation Issue

TUNNELS

2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?