Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: SANS Daily Network Security Podcast (Stormcast) for Tuesday, June 17th 2014 SANS Daily Network Security Podcast (Stormcast) for Tuesday, June 17th 2014


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!


SANS Daily Network Security Podcast (Stormcast) for Tuesday, June 17th 2014
00:00

My Next Class

Intrusion Detection In-DepthBaltimoreApr 27th - May 2nd 2020
Defending Web Applications Security EssentialsAmsterdamMay 11th - May 16th 2020

… more classes

Cumulative IE Patch Not always cumulative. Everything that went wrong at #Stratfor (and not much that went right). #Dominos EU hack!

Cumulative IE Update (MS14-035) only applies if MS14-018 is applied first
http://www.theregister.co.uk/2014/06/16/ie_11_apply_april_fix_or_be_hacker_fodder/

Domino's Attacker asking for Ransom in order to not leak stolen data.
http://www.tomsguide.com/us/dominos-pizza-data-breach,news-18996.html

Verizon Stratfor Report
https://pdf.yt/d/yGrhyxVVK5yKmbcq Get a free ISC sticker (login required):
https://isc.sans.edu/sticker.html
Spotify spotify logo

Discussion

The story about the IE patch is overwrought. It's nothing new. MS14-018 itself effectively requires MS14-012. See the FAQ:
For Internet Explorer 11, do I need to install the last cumulative security update for Internet Explorer, MS14-012?
Yes. In all cases, the 2936068 (MS14-018) update protects customers from the vulnerabilities discussed in this bulletin. However, Internet Explorer 11 customers who have not installed the latest cumulative security update for Internet Explorer may experience compatibility issues after installing the 2936068 (MS14-018) update.

And there have been others.
Posted by Larry Seltzer on Tue Jun 17 2014, 04:07

New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form

Intrusion Detection In-DepthBaltimoreApr 27th - May 2nd 2020
Defending Web Applications Security EssentialsAmsterdamMay 11th - May 16th 2020
IPv6 EssentialsAmsterdamMay 17th - May 18th 2020
Intrusion Detection In-DepthLas VegasJun 8th - Jun 13th 2020
Defending Web Applications Security EssentialsCupertinoJun 22nd - Jun 27th 2020
Intrusion Detection In-DepthMunichJul 6th - Jul 11th 2020
Defending Web Applications Security EssentialsArlingtonAug 10th - Aug 15th 2020
Intrusion Detection In-DepthLondonSep 7th - Sep 12th 2020
Intrusion Detection In-DepthMunichSep 14th - Sep 19th 2020
Intrusion Detection In-DepthRestonSep 28th - Oct 3rd 2020