Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: Diaries by Keyword Diaries by Keyword

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title
2019-11-08Xavier MertensMicrosoft Apps Diverted from Their Main Use
2019-10-03Xavier Mertens"Lost_Files" Ransomware
2019-09-24Xavier MertensHuge Amount of remotewebaccess.com Sites Found in Certificate Transparency Logs
2019-08-19Didier StevensCompressed ISO Files (ISZ)
2019-08-18Didier StevensVideo: Analyzing DAA Files
2019-08-16Didier StevensThe DAA File Format
2019-08-12Didier StevensMalicious .DAA Attachments
2019-07-15Didier Stevensisodump.py and Malicious ISO Files
2019-07-09John BambenekSolving the WHOIS and Privacy Problem: A Draft of Implementing WHOIS in DNS
2019-07-09John BambenekMSFT July 2019 Patch Tuesday
2019-05-29Xavier MertensBehavioural Malware Analysis with Microsoft ASA
2019-05-22Johannes UllrichAn Update on the Microsoft Windows RDP "Bluekeep" Vulnerability (CVE-2019-0708) [now with pcaps]
2019-05-13Xavier MertensFrom Phishing To Ransomware?
2019-04-04Xavier MertensNew Waves of Scans Detected by an Old Rule
2019-02-20Brad DuncanMore Russian language malspam pushing Shade (Troldesh) ransomware
2019-01-31Xavier MertensTracking Unexpected DNS Changes
2019-01-14Rob VandenBrinkMicrosoft LAPS - Blue Team / Red Team
2019-01-10Brad DuncanHeartbreaking Emails: "Love You" Malspam
2018-12-19Xavier MertensMicrosoft OOB Patch for Internet Explorer: Scripting Engine Memory Corruption Vulnerability
2018-12-11Richard PorterMicrosoft December 2018 Patch Tuesday
2018-11-29Brad DuncanRussian language malspam pushing Shade (Troldesh) ransomware
2018-11-13Johannes UllrichNovember 2018 Microsoft Patch Tuesday
2018-10-26Xavier MertensDissecting Malicious Office Documents with Linux
2018-10-18Russ McReeCisco Security Advisories 17 OCT 2018
2018-10-17Russ McReeVMSA-2018-0026 VMware ESXi, Workstation & Fusion updates address out-of-bounds read vulnerability https://www.vmware.com/security/advisories/VMSA-2018-0026.html
2018-10-10Xavier MertensNew Campaign Using Old Equation Editor Vulnerability
2018-10-09Johannes UllrichOctober 2018 Microsoft Patch Tuesday
2018-09-11Johannes UllrichMicrosoft September Patch Tuesday Summary
2018-08-15Brad DuncanMore malspam pushing password-protected Word docs for AZORult and Hermes Ransomware
2018-08-01Johannes UllrichWhen Cameras and Routers attack Phones. Spike in CVE-2014-8361 Exploits Against Port 52869
2018-07-27Brad DuncanMalspam with password-protected Word docs pushes Hermes ransomware
2018-07-15Didier StevensVideo: Retrieving and processing JSON data (BTC example)
2018-07-14Didier StevensRetrieving and processing JSON data (BTC example)
2018-06-25Didier StevensGuilty by association
2018-06-21Xavier MertensAre Your Hunting Rules Still Working?
2018-06-12Johannes UllrichMicrosoft June 2018 Patch Tuesday
2018-05-28Kevin ListonDo you hear Laurel or Yanny or is it On-Off Keying?
2018-05-25Xavier MertensAntivirus Evasion? Easy as 1,2,3
2018-05-24Xavier Mertens"Blocked" Does Not Mean "Forget It"
2018-05-22Xavier MertensMalware Distributed via .slk Files
2018-04-28Rick WannerMicrosoft Security Update for Spectre V2
2018-02-17Xavier MertensMalware Delivered via Windows Installer Files
2018-02-07Brad DuncanGandCrab Ransomware: Now Coming From Malspam
2018-01-26Xavier MertensInvestigating Microsoft BITS Activity
2018-01-25Xavier MertensRansomware as a Service
2018-01-08Johannes UllrichA Story About PeopleSoft: How to Make $250k Without Leaving Home.
2017-12-20Richard PorterVMWare Security Advisory: VMSA-2017-0021: https://www.vmware.com/security/advisories/VMSA-2017-0021.html
2017-12-12Johannes UllrichDecember Microsoft Patch Tuesday Summary
2017-11-25Guy BruneauBenefits associated with the use of Open Source Software
2017-11-13Guy Bruneaujsonrpc Scanning for root account
2017-10-24Xavier MertensBadRabbit: New ransomware wave hitting RU & UA
2017-10-12Xavier MertensVersion control tools aren't only for Developers
2017-09-20Renato MarinhoOngoing Ykcol (Locky) campaign
2017-09-01Brad DuncanMalspam pushing Locky ransomware tries HoeflerText notifications for Chrome and FireFox
2017-08-31Tom WebbRemote SOC Workers Concerns
2017-07-21Didier StevensMalicious .iso Attachments
2017-07-16Renato MarinhoSMS Phishing induces victims to photograph its own token card
2017-07-14Brad DuncanNemucodAES and the malspam that distributes it
2017-07-11Renato MarinhoJuly's Microsoft Patch Tuesday
2017-07-09Russ McReeAdversary hunting with SOF-ELK
2017-06-28Brad DuncanPetya? I hardly know ya! - an ISC update on the 2017-06-27 ransomware outbreak
2017-06-28Brad DuncanCatching up with Blank Slate: a malspam campaign still going strong
2017-05-24Brad DuncanJaff ransomware gets a makeover
2017-05-12Xavier MertensMassive wave of ransomware ongoing
2017-05-06Russell EubanksWhat Can You Learn On Your Own?
2017-04-12Brad DuncanMalspam on 2017-04-11 pushes yet another ransomware variant
2017-03-31Xavier MertensPro & Con of Outsourcing your SOC
2017-03-14Johannes UllrichFebruary and March Microsoft Patch Tuesday
2017-02-14Johannes UllrichMicrosoft Patch Tuesday Delayed
2017-02-09Brad DuncanCryptoShield Ransomware from Rig EK
2017-02-03Lorna HutchesonCisco - Issue with Clock Signal Component
2017-01-06John BambenekRansomware Operators Cold Calling UK Schools to Get Malware Through
2016-12-27Guy BruneauUsing daemonlogger as a Software Tap
2016-11-25Xavier MertensFree Software Quick Security Checklist
2016-10-11Xavier MertensWiFi Still Remains a Good Attack Vector
2016-10-10Didier StevensRadare2: rahash2
2016-09-30Xavier MertensAnother Day, Another Malicious Behaviour
2016-09-13Rob VandenBrinkMicrosoft Patch Tuesday Analysis
2016-09-05Xavier MertensMalware Delivered via '.pub' Files
2016-08-31Deborah HaleCisco Security Advisories Issued
2016-08-23Xavier MertensVoice Message Notifications Deliver Ransomware
2016-08-20Russell EubanksWhat are YOU doing to give back to the security community?
2016-07-27Xavier MertensCritical Xen PV guests vulnerabilities
2016-07-12Johannes UllrichMicrosoft Patch Tuesday Summary for July 2016
2016-07-08Mark HofmanMalware being distributed pretending to be from AU Fedcourts
2016-06-26Rick WannerBart - a new Ransomware
2016-05-28Russell EubanksApplied Lessons Learned
2016-05-05Xavier MertensMicrosoft BITS Used to Download Payloads
2016-04-11John BambenekTool Released to Decrypt Petya Ransomware Infected Disks
2016-04-01John BambenekTips for Stopping Ransomware
2016-03-15Xavier MertensDockerized DShield SSH Honeypot
2016-03-09Rob VandenBrinkA Wall Against Cryptowall? Some Tips for Preventing Ransomware
2016-03-07Xavier MertensOSX Ransomware Spread via a Rogue BitTorrent Client Installer
2016-03-06Jim ClausingNovel method for slowing down Locky on Samba server using fail2ban
2016-02-22Xavier MertensReducing False Positives with Open Data Sources
2016-02-18Xavier MertensHunting for Executable Code in Windows Environments
2016-02-09Johannes UllrichMicrosoft February 2016 Patch Tuesday
2016-02-03Xavier MertensEMET 5.5 Released
2016-01-10Jim ClausingVMware security update
2016-01-09Xavier MertensVirtual Bitlocker Containers
2015-12-19Russell EubanksVMWare Security Advisory
2015-11-21Didier StevensMaldoc Social Engineering Trick
2015-11-09John BambenekProtecting Users and Enterprises from the Mobile Malware Threat
2015-11-07Didier StevensRansomware & Entropy: Your Turn -> Solution
2015-10-30Didier StevensRansomware & Entropy: Your Turn
2015-10-18Didier StevensRansomware & Entropy
2015-08-31Xavier MertensDetecting file changes on Microsoft systems with FCIV
2015-08-19Bojan ZdrnjaOutsourcing critical infrastructure (such as DNS)
2015-08-18Russ McReeMicrosoft Security Bulletin MS15-093 - Critical OOB - Internet Explorer RCE
2015-07-18Russell EubanksThe Value a "Fresh Set Of Eyes" (FSOE)
2015-07-14Johannes UllrichJuly 2015 Microsoft Patch Tuesday
2015-06-29Rob VandenBrinkThe Powershell Diaries 2 - Software Inventory
2015-05-15Didier StevensAnother Maldoc? I'm Afraid So...
2015-05-09Didier StevensMalicious Word Document: This Time The Maldoc Is A MIME File
2015-04-30Brad DuncanDalexis/CTB-Locker malspam campaign
2015-04-15Johannes UllrichMS15-034: HTTP.sys (IIS) DoS And Possible Remote Code Execution. PATCH NOW
2015-03-18Daniel WesemannPass the hash!
2015-03-17Didier StevensImproperly issued SSL certificate for domain "live.fi" could be used in attempts to spoof content. https://technet.microsoft.com/library/security/3046310
2015-02-22Russell EubanksLeave Things Better Than When You Found Them
2015-02-19Daniel WesemannMacros? Really?!
2015-02-13Johannes UllrichMicrosoft February Patch Failures Continue: KB3023607 vs. Cisco AnyConnect Client
2015-02-11Johannes UllrichMicrosoft Hardens GPO by Fixing Two Serious Vulnerabilities.
2015-02-03Johannes UllrichWhat is using this library?
2014-12-24Rick WannerIncident Response at Sony
2014-10-01Russ McReeVMware security advisory: VMSA-2014-0010 http://www.vmware.com/security/advisories/VMSA-2014-0010.html
2014-09-27Guy BruneauWhat has Bash and Heartbleed Taught Us?
2014-09-12Chris MohanVMware NSX and vCNS product updates address a critical information disclosure vulnerability http://www.vmware.com/security/advisories/VMSA-2014-0009.html
2014-08-20Kevin ShorttSocial Engineering Alive and Well
2014-07-24Bojan ZdrnjaWindows Previous Versions against ransomware
2014-07-01Johannes UllrichMicrosoft No-IP Takedown
2014-06-28Mark HofmanNo more Microsoft advisory email notifications?
2014-06-23Russ McReeMicrosoft Interflow announced today at 26th FIRST conference
2014-06-17Rob VandenBrinkNew Security Advisories / Updates from Microsoft - Heads up for Next Patch Tuesday!
2014-06-11Daniel WesemannPay attention to Cryptowall!
2014-06-06Johannes UllrichMicrosoft June Patch Tuesday Advance Notification
2014-05-28Rob VandenBrinkAssessing SOAP APIs with Burp
2014-05-07Johannes UllrichDe-Clouding your Life: Things that should not go into the cloud.
2014-05-01Johannes UllrichMicrosoft Announces Special Patch for IE 0-day (Win XP included!)
2014-04-26Guy BruneauNew Project by Linux Foundation - Core Infrastructure Initiative
2014-04-11Rob VandenBrinkVMware Security Advisories / Patches released for 2 issues (NOT Heartbleed) - http://www.vmware.com/security/advisories/VMSA-2014-0003.html and http://www.vmware.com/security/advisories/VMSA-2014-0002.html
2014-04-01Johannes Ullrichcmd.so Synology Scanner Also Found on Routers
2014-03-24Johannes UllrichNew Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks
2014-03-24Johannes UllrichIntegrating Physical Security Sensors
2014-03-11Johannes UllrichMicrosoft Patch Tuesday March 2014
2014-03-10Basil Alawi S.TaherSysinternals Process Explorer v16.02, Process Monitor v3.1, PSExec v2.1 and Sigcheck v2.03 update
2014-03-08Guy BruneauMicrosoft March Patch Pre-Announcement
2014-03-02Stephen HallSymantec goes yellow
2014-02-11Johannes UllrichFebruary 2014 Microsoft Patch Tuesday
2014-02-07Johannes UllrichMicrosoft Advance Notification for February 2014
2014-02-07Rob VandenBrinkNew ISO Standards on Vulnerability Handling and Disclosure
2014-02-05Johannes UllrichTo Merrillville or Sochi: How Dangerous is it to travel?
2014-01-24Chris MohanPhishing via Social Media
2014-01-24Chris MohanSecurity Update for OS X for CVE-2014-1252 http://support.apple.com/kb/HT6117
2014-01-14Johannes UllrichMicrosoft Patch Tuesday January 2014
2014-01-09Johannes UllrichMicrosoft Security Bulletin Advance Notification for January 2014 http://technet.microsoft.com/en-us/security/bulletin/ms14-jan
2013-12-23Scott FendleyVMWare ESX/ESXi Security Advisory
2013-12-07Guy BruneauMicrosoft December Patch Pre-Announcement
2013-12-05Mark HofmanUpdated Standards Part 1 - ISO 27001
2013-12-04Adrien de BeaupreVMware Security Advisory VMSA-2013-0014
2013-11-29Russ McReeMS Exchange update, includes failed backup fix: http://support.microsoft.com/kb/2892464
2013-11-28Rob VandenBrinkMicrosoft Security Advisory (2914486): Vulnerability in Microsoft Windows Kernel 0 day exploit in wild
2013-11-22Rick WannerPort 0 DDOS
2013-11-12Johannes UllrichNovember 2013 Microsoft Patch Tuesday
2013-11-10Rick WannerMicrosoft and Facebook announce bug bounty
2013-11-08Johannes UllrichMicrosoft Patch Tuesday Preview
2013-11-05Daniel WesemannTIFF images in MS-Office documents used in targeted attacks
2013-10-22John BambenekCryptolocker Update, Request for Info
2013-10-21Johannes UllrichNew tricks that may bring DNS spoofing back or: "Why you should enable DNSSEC even if it is a pain to do"
2013-10-17Adrien de BeaupreMicrosoft phish
2013-09-17John BambenekMicrosoft Releases Out-of-Band Advisory for all Versions of Internet Explorer
2013-09-11Johannes UllrichReboot Wednesday: Yesterday's Patch Tuesday Aftermath
2013-09-10Swa FrantzenMicrosoft September 2013 Black Tuesday Overview
2013-08-29Russ McReeSuspect Sendori software
2013-08-19Johannes UllrichMicrosoft re-releases MS13-066: https://technet.microsoft.com/security/bulletin/MS13-066
2013-08-15Johannes UllrichMicrosoft Pulls MS013-061 due to problems with Exchange Server 2013 http://blogs.technet.com/b/exchange/archive/2013/08/14/exchange-2013-security-update-ms13-061-status-update.aspx
2013-08-13Swa FrantzenMicrosoft security advisories: RDP and MD5 deprecation in Microsoft root certificates
2013-08-02Chris MohanVMware Security Advisory VMSA-2013-0009 - http://www.vmware.com/security/advisories/VMSA-2013-0009.html
2013-08-02Chris MohanCisco Security Advisory: OSPF LSA Manipulation Vulnerability in Multiple Cisco Products http://tools.cisco.com/security/center/viewAlert.x?alertId=30210
2013-07-17Johannes UllrichNetwork Solutions Outage
2013-07-15Johannes UllrichProblems with MS13-057
2013-07-13Lenny ZeltserDecoy Personas for Safeguarding Online Identity Using Deception
2013-07-12Johannes UllrichDNS resolution is failing for Microsofts Teredo server (teredo.ipv6.microsoft.com)
2013-07-12Johannes UllrichMicrosoft Teredo Server "Sunset"
2013-07-09Swa FrantzenMicrosoft July 2013 Black Tuesday Overview
2013-07-08Richard PorterWhy do we Click?
2013-07-06Guy BruneauMicrosoft July Patch Pre-Announcement
2013-06-11Swa FrantzenMicrosoft June 2013 Black Tuesday Overview
2013-06-11Swa FrantzenOther Microsoft Black Tuesday News
2013-06-05Richard PorterWindows Sysinternals Updated http://technet.microsoft.com/en-us/sysinternals/default.aspx
2013-05-31Chris MohanVMware releases new and updated security advisories
2013-05-14Swa FrantzenMicrosoft May 2013 Black Tuesday Overview
2013-05-14Swa FrantzenMicrosoft Security Advisory 2846338
2013-05-10Johannes UllrichMicrosoft and Adobe Patch Tuesday Pre-Release
2013-05-09Johannes UllrichMicrosoft released a Fix-it for the Internet Explorer 8 Vulnerability http://support.microsoft.com/kb/2847140
2013-05-04Kevin ShorttThe Zero-Day Pendulum Swings
2013-04-23Russ McReeMicrosoft's Security Intelligence Report (SIRv14) released
2013-04-04Johannes UllrichMicrosoft April Patch Tuesday Advance Notification
2013-03-27Rob VandenBrinkSourcefire VRT Community ruleset is live
2013-03-19Johannes UllrichWindows 7 SP1 and Windows Server 2008 R2 SP1 Being "pushed" today
2013-03-18Kevin ShorttSpamhaus DDOS
2013-03-12Swa FrantzenMicrosoft March 2013 Black Tuesday Overview
2013-02-25Johannes UllrichMass-Customized Malware Lures: Don't trust your cat!
2013-02-22Chris MohanVMware releases new and updated security advisories
2013-02-12Adam SwangerMicrosoft February 2013 Black Tuesday Update - Overview
2013-02-08Johannes UllrichMicrosoft February Patch Tuesday Advance Notification
2013-02-01Jim ClausingVMware vSphere security updates for the authentication service and third party libraries (see http://www.vmware.com/security/advisories/VMSA-2013-0001.html)
2013-01-15Russ McReeCisco introducing Cisco Security Notices 16 JAN 2013
2013-01-14Richard PorterJanuary 2013 Microsoft Out of Cycle Patch
2013-01-09Rob VandenBrinkHotmail seeing some temporary access issues
2013-01-09Rob VandenBrinkSecurity Update - Cisco Prime LMS (cisco-sa-20130109-lms - remote execution as root vulnerability) - advisory at: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130109-lms
2013-01-09Rob VandenBrinkSecurity Update - Cisco 7900 Phones - cisco-sa-20130109-uipphone privilege escallation issue - advisory at: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130109-uipphone
2013-01-08Richard PorterMicrosoft January 2013 Black Tuesday Update - Overview
2013-01-04Daniel WesemannPatch pre-notification from Adobe and Microsoft
2013-01-01Johannes UllrichFixIt Available for Internet Explorer Vulnerability
2012-12-11John BambenekMicrosoft December 2012 Black Tuesday Update - Overview
2012-11-16Guy BruneauVMware security updates for vSphere API and ESX Service Console - http://www.vmware.com/security/advisories/VMSA-2012-0016.html
2012-11-13Jim ClausingMicrosoft November 2012 Black Tuesday Update - Overview
2012-11-09Mark BaggettRemote Diagnostics with PSR
2012-10-24Russ McReeCyber Security Awareness Month - Day 24 - A Standard for Information Security Incident Management - ISO 27035
2012-10-17Rob VandenBrinkCyber Security Awareness Month - Day 17 - A Standard for Risk Management - ISO 27005
2012-10-08Mark HofmanCyber Security Awareness Month - Day 8 ISO 27001
2012-10-05Richard PorterVMWare Security Advisory: VMSA-2012-0014 - http://www.vmware.com/security/advisories/VMSA-2012-0014.html
2012-10-04Johannes UllrichMicrosoft October Patch Pre-Announcement
2012-09-27Kevin ShorttCisco IOS Security Advisory Bundle - http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep12.html
2012-09-20Russ McReeApple and Cisco Security Advisories 19 SEP 2012
2012-09-14Lenny ZeltserAnalyzing Malicious RTF Files Using OfficeMalScanner's RTFScan
2012-09-11Adam SwangerMicrosoft September 2012 Black Tuesday Update - Overview
2012-08-31Johannes UllrichVMware Updates
2012-08-14Rick WannerMicrosoft August 2012 Black Tuesday Update - Overview
2012-07-25Johannes UllrichMicrosoft Exchange/Sharepoint and others: Oracle Outside In Vulnerability
2012-07-18Rob VandenBrinkVote NO to Weak Keys!
2012-07-13Russ McReeVMWare Security Advisory 12 JUL 2012
2012-07-11Rick WannerExcellent Security Education Resources
2012-07-10Swa FrantzenMicrosoft July 2012 Black Tuesday Update - Overview
2012-07-10Swa FrantzenMicrosoft revoking trust in Microsoft certificates - SA 2728973
2012-07-10Swa FrantzenMicrosoft fix-it to disable gadgets - SA 2719662
2012-07-05Adrien de BeaupreMicrosoft advanced notification for July 2012 patch Tuesday
2012-06-21Russ McReeCisco Security Advisories 20 JUN 2012
2012-06-20Raul SilesCVE-2012-0217 (from MS12-042) applies to other environments too
2012-06-14Johannes UllrichVMWare Security Advisories
2012-06-13Johannes UllrichMicrosoft Certificate Updater
2012-06-12Swa FrantzenMicrosoft June 2012 Black Tuesday Update - Overview
2012-06-12Swa FrantzenMicrosoft Security Advisory 2719615 - MSXML - CVE-2012-1889
2012-06-11Johannes UllrichMicrosoft Update Security
2012-06-07Johannes UllrichMicrosoft June Security Bulletin Advance Notification
2012-06-04Lenny ZeltserDecoding Common XOR Obfuscation in Malicious Code
2012-06-04Johannes UllrichMicrosoft Emergency Bulletin: Unauthorized Certificate used in "Flame"
2012-05-25Guy BruneauVMware vMA Security Advisory VMSA-2012-0010 - http://www.vmware.com/security/advisories/VMSA-2012-0010.html
2012-05-23Mark BaggettProblems with MS12-035 affecting XP, SBS and Windows 2003?
2012-05-16Johannes UllrichMicrosoft released an update for its Enhanced Mitigation Experience Tool (EMET) http://blogs.technet.com/b/srd/archive/2012/05/15/introducing-emet-v3.aspx
2012-05-03Guy BruneauVMware Critical Security Issues Advisory - http://www.vmware.com/security/advisories/VMSA-2012-0009.html
2012-04-26Richard PorterPacketstorm Security and Metasploit have Exploit code for MS12-027
2012-04-15Rick Wanner.Net update affects printing from some applications
2012-04-06Johannes UllrichMicrosoft April Patch Tuesday Pre-Announcement (6 Patches): http://technet.microsoft.com/en-us/security/bulletin/ms12-apr
2012-04-06Johannes UllrichSocial Share Privacy
2012-03-12Guy BruneauOpenSSL Security Update
2012-03-09Guy BruneauVMware New and Updated Advisories
2012-03-08Johannes UllrichMicrosoft March Patch Tuesday Pre-Anouncement out. 6 patches, 1 critical: http://technet.microsoft.com/en-us/security/bulletin/ms12-mar
2012-02-29Russ McReeCisco Security Advisories - 29FEB2011
2012-02-03Guy BruneauSophos 2012 Security Threat Report
2012-01-31Russ McReeFirefox 10 and VMWare advisories and updates
2012-01-10Adrien de BeaupreJanuary 2012 Microsoft Black Tuesday Summary
2012-01-06Guy BruneauJanuary 2012 Patch Tuesday Pre-release
2011-12-29Richard PorterASP.Net Vulnerability
2011-12-13Johannes UllrichDecember 2011 Microsoft Black Tuesday Summary
2011-12-08Adrien de BeaupreMicrosoft Security Bulletin Advance Notification for December 2011
2011-11-18Kevin ListonRecent VMWare security advisories
2011-11-03Guy BruneauNovember 2011 Patch Tuesday Pre-release
2011-10-05Jim ClausingVMware Advisory - UDF file system handling
2011-09-28Richard PorterAll Along the ARP Tower!
2011-09-09Johannes UllrichEarly Patch Tuesday Today: Microsoft September 2011 Patches
2011-09-08Mark HofmanMicrosoft has released their advanced notification for patch Tuesday. 15 Vulnerabilities to be addressed. more here --> http://blogs.technet.com/b/msrc/archive/2011/09/08/advanced-notification-for-the-september-2011-bulletin-release.aspx
2011-09-06Johannes UllrichMicrosoft Releases Diginotar Related Patch and Advisory
2011-08-30Scott FendleyCisco Security Advisory - Apache HTTPd DoS
2011-08-17Rob VandenBrinkPutting all of Your Eggs in One Basket - or How NOT to do Layoffs
2011-08-13Rick WannerMoonSols Dumpit released...for free!
2011-08-11Johannes UllrichAs part of this weeks patch tuesday, microsoft also re-release MS11-043 to address stability issues.
2011-08-09Swa FrantzenMicrosoft August 2011 Black Tuesday Overview
2011-08-05Johannes UllrichMicrosoft Patch Tuesday Advance Notification: 13 Bulletins coming http://www.microsoft.com/technet/security/Bulletin/MS11-aug.mspx
2011-06-14Swa FrantzenMicrosoft June 2011 Black Tuesday Overview
2011-06-04Rick WannerDo you have a personal disaster recovery plan?
2011-06-01Adrien de BeaupreCisco Security Advisory: Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series - http://www.cisco.com/warp/public/707/cisco-sa-20110601-phone.shtml
2011-06-01Adrien de BeaupreCisco Security Advisory: Default Credentials Vulnerability in Cisco Network Registrar - http://www.cisco.com/warp/public/707/cisco-sa-20110601-cnr.shtml
2011-06-01Adrien de BeaupreCisco Security Advisory: Default Credentials for root Account on the Cisco Media Experience Engine 5600 - http://www.cisco.com/warp/public/707/cisco-sa-20110601-mxe.shtml
2011-06-01Adrien de BeaupreCisco Security Advisory: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client - http://www.cisco.com/warp/public/707/cisco-sa-20110601-ac.shtml
2011-05-25Daniel WesemannFive new Cisco security advisories released. See http://www.cisco.com/go/psirt
2011-05-25Lenny ZeltserMonitoring Social Media for Security References to Your Organization
2011-05-23Mark HofmanMicrosoft Support Scam (again)
2011-05-13Jason LamMicrosoft Security Intelligence Report volume 10
2011-05-10Swa FrantzenMay 2011 Microsoft Black Tuesday Overview
2011-05-10Swa FrantzenChanging MO in scamming our users ?
2011-05-06Richard PorterUpdated Exploit Index for Microsoft
2011-05-04Richard PorterMicrosoft Sysinterals Update
2011-04-28Chris MohanCisco Security Advisories
2011-04-25Rob VandenBrinkSony PlayStation Network Outage - Day 5
2011-04-11Jim ClausingApril 2011 Microsoft Black Tuesday Summary
2011-04-08Johannes UllrichDark Black Tuesday Coming Up: 17 Microsoft Bulletins
2011-04-05Mark HofmanSony DDOS
2011-03-30Adrien de BeaupreTwo Cisco advisories: cisco-sa-20110330-nac and cisco-sa-20110330-acs
2011-03-11Guy BruneauSnort IDS Sensor with Sguil Framework ISO
2011-03-09Chris MohanPossible Issue with Forefront Update KB2508823
2011-03-08Jim ClausingMarch 2011 Microsoft Black Tuesday Summary
2011-03-02Chris MohanMicrosoft’s Autorun update v2.1 now automatically deployed from Windows Update
2011-02-24Johannes UllrichWindows 7 / 2008 R2 Service Pack 1 Problems
2011-02-23Johannes UllrichWindows 7 Service Pack 1 out
2011-02-10Chris MohanLinksys WAP610N has Unauthenticated Root Console issue
2011-02-10Chris MohanBefriending Windows Security Log Events
2011-02-08Chris MohanVMWare Security Advisory
2011-02-02Chris MohanDefault Credentials for Root Account on Cisco Personal Video units
2011-01-29Mark HofmanSourceforge attack
2011-01-19Johannes UllrichMicrosoft's Secure Developer Tools
2011-01-12Richard PorterHow Many Loyalty Cards do you Carry?
2011-01-08Guy BruneauJanuary 2011 Patch Tuesday Pre-release
2011-01-05Johannes UllrichSurvey: Software Security Awareness Training
2011-01-05Johannes UllrichCurrently Unpatched Windows / Internet Explorer Vulnerabilities
2011-01-04Johannes UllrichMicrosoft Advisory: Vulnerability in Graphics Rendering Engine
2010-12-29Daniel WesemannBeware of strange web sites bearing gifts ...
2010-12-22John BambenekIIS 7.5 0-Day DoS (processing FTP requests)
2010-12-20Guy BruneauPatch Issues with Outlook 2007
2010-12-14Manuel Humberto Santander PelaezDecember 2010 Microsoft Black Tuesday Summary
2010-12-10Mark HofmanMicrosoft patches
2010-11-29Stephen HallSun security updates
2010-11-22Lenny ZeltserBrand Impersonations On-Line: Brandjacking and Social Networks
2010-11-04Johannes UllrichMicrosoft Patches Pre-Announcement
2010-11-04Johannes UllrichMicrosoft Smart Screen False Positivies
2010-10-12Adrien de BeaupreOctober 2010 Microsoft Black Tuesday Summary
2010-10-08Rick WannerPatch Tuesday Pre-release -- 16 updates
2010-10-07Rob VandenBrinkSORBS.NET - email RBL issues
2010-09-28Daniel WesemannMS10-070 OOB Patch for ASP.NET vulnerability
2010-09-27Adrien de BeaupreMS OOB patch tomorrow for Security Advisory 2416728
2010-09-18Rick WannerMicrosoft Security Advisory for ASP.NET
2010-09-16Johannes UllrichFacebook "Like Pages"
2010-09-14Adrien de BeaupreSeptember 2010 Microsoft Black Tuesday Summary
2010-09-02Daniel WesemannMicrosoft EMETv2 released
2010-08-22Manuel Humberto Santander PelaezSCADA: A big challenge for information security professionals
2010-08-15Manuel Humberto Santander PelaezOpensolaris project cancelled, replaced by Solaris 11 express
2010-08-10Jim ClausingAugust 2010 Micrsoft Black Tuesday Summary
2010-08-04Adrien de BeaupreMultiple Cisco Advisories
2010-08-03Johannes UllrichSolar activity may cause problems this week
2010-08-02Johannes UllrichMicrosoft Out-of-Band bulletin addresses LNK/Shortcut vulnerability
2010-07-30Johannes UllrichMicrosoft LNK vulnerability fix coming on Monday
2010-07-21Adrien de BeaupreUpdate on .LNK vulnerability
2010-07-20Manuel Humberto Santander PelaezLNK vulnerability now with Metasploit module implementing the WebDAV method
2010-07-13Jim ClausingJuly 2010 Microsoft Black Tuesday Summary
2010-07-07Kevin ShorttFacebook, Facebook, What Do YOU See?
2010-06-26Guy Bruneausocat to Simulate a Website
2010-06-17Deborah HaleFYI - Another bogus site
2010-06-15Manuel Humberto Santander PelaezMicrosoft Windows Help and Support Center vulnerability (CVE 2010-1885) exploit in the wild
2010-06-15Manuel Humberto Santander PelaezApple releases advisory for Mac OS X - Multiple vulnerabilities discovered
2010-06-14Manuel Humberto Santander PelaezNew way of social engineering on IRC
2010-06-10Deborah HaleTop 5 Social Networking Media Risks
2010-06-10Deborah HaleMicrosoft Help Centre Handling of Escape Sequences May Lead to Exploit
2010-06-10Deborah HaleMicrosoft Security Advisory 2219475
2010-06-08Manuel Humberto Santander PelaezJune 2010 Microsoft Black Tuesday Summary
2010-06-07Manuel Humberto Santander PelaezSoftware Restriction Policy to keep malware away
2010-06-05Guy BruneauSecurity Advisory for Flash Player, Adobe Reader and Acrobat
2010-06-03Guy BruneauMicrosoft Patch Tuesday June 2010 Pre-Release
2010-05-30Kevin ListonVMware ESX/ESXi Updates
2010-05-18Johannes UllrichCanonical Display Driver Vulnerability
2010-05-11Scott FendleyMay 2010 Microsoft Patches
2010-05-08Guy BruneauMicrosoft Patch Tuesday May 2010 Pre-Release
2010-05-02Mari NicholsZbot Social Engineering
2010-04-30Johannes UllrichSharepoint XSS Vulnerability
2010-04-29Bojan ZdrnjaWho needs exploits when you have social engineering?
2010-04-18Guy BruneauSome NetSol hosted sites breached
2010-04-13Johannes UllrichMicrosoft April 2010 Patch Tuesday
2010-04-13Johannes UllrichMore Legal Threat Malware E-Mail
2010-04-08Guy BruneauMicrosoft Patch Tuesday April 2010 Pre-Release
2010-03-27Guy BruneauCreate a Summary of IP Addresses from PCAP Files using Unix Tools
2010-03-10Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-03-10Rob VandenBrinkMicrosoft re-release of KB973811 - attacks on Extended Protection for Authentication
2010-03-09John BambenekMarch 2010 - Microsoft Patch Tuesday Diary
2010-03-08Raul SilesMicrosoft announced two important bulletins (fixing multiple vulns. affecting Windows and Office) for tomorrow: http://www.microsoft.com/technet/security/Bulletin/MS10-mar.mspx
2010-03-03Mark HofmanMS10-015 re-released
2010-03-01Mark HofmanMicrosoft will drop support for Vista (without any Service Packs) on April 13 and support for XP SP2 ends July 13. (i.e. no more security updates). If you are still running these, it it time to update.
2010-02-25Andre LudwigMicrosoft, restraining orders, and how a big botnet (waledec) ate curb.
2010-02-19Mark HofmanMS10-015 may cause Windows XP to blue screen (but only if you have malware on it)
2010-02-17Rob VandenBrinkCisco ASA5500 Security Updates - cisco-sa-20100217-asa
2010-02-17Rob VandenBrinkCisco Security Agent Security Updates: cisco-sa-20100217-csa
2010-02-15Johannes UllrichVarious Olympics Related Dangerous Google Searches
2010-02-11Johannes UllrichMS10-015 may cause Windows XP to blue screen
2010-02-11Deborah HaleCritical Update for AD RMS
2010-02-10Marcus SachsVulnerability in TLS/SSL Could Allow Spoofing
2010-02-09Johannes UllrichFebruary 2010 Black Tuesday Overview
2010-02-04Johannes UllrichMicrosoft Patch Tuesday Pre-Release
2010-02-03Johannes UllrichInformation Disclosure Vulnerability in Internet Explorer
2010-01-21Johannes UllrichNew Microsoft Advisory: Vulnerability in Windows Kernel Privilege Escalation (CVE-2010-0232)
2010-01-21Chris Carboni* Microsoft Out Of Band Patch Release
2010-01-21Johannes UllrichMicrosoft January Out of Band Patch
2010-01-19Johannes UllrichUnpatched Microsoft Windows (all versions) Privilege Escalation Vulnerability Released
2010-01-12Johannes UllrichMicrosoft Patch Tuesday - Preannouncement
2010-01-12Johannes UllrichMicrosoft Security Bulletin: January 2010
2010-01-12Johannes UllrichMicrosoft Advices XP Users to Uninstall Flash Player 6
2009-12-29Rick WannerMicrosoft responds to possible IIS 6 0-day
2009-12-08Deborah HaleDecember 2009 Black Tuesday Overview
2009-12-02Rob VandenBrinkMicrosoft Black Screen of Death - Fact of Fiction?
2009-11-25Jim ClausingMicrosoft Updates requiring reboot
2009-11-24John BambenekBIND Security Advisory (DNSSEC only)
2009-11-24Rick WannerMicrosoft Security Advisory 977981 - IE 6 and IE 7
2009-11-14Adrien de BeaupreMicrosoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-10Swa FrantzenMicrosoft November Black Tuesday Overview
2009-11-07Marcus SachsMore Thoughts on Legacy Systems
2009-11-02Rob VandenBrinkMicrosoft releases v1.02 of Enhanced Mitigation Evaluation Toolkit (EMET)
2009-10-17Rick WannerMozilla disables Microsoft plug-ins?
2009-10-16Adrien de BeaupreDisable MS09-054 patch, or Firefox Plugin?
2009-10-13Johannes UllrichMicrosoft October 2009 Black Tuesday Overview
2009-09-16Bojan ZdrnjaSMB2 remote exploit released
2009-09-10Guy BruneauFirefox 3.5.3 and 3.0.14 has been released
2009-08-31Pedro BuenoMicrosoft IIS 5/6 FTP 0Day released
2009-08-26Johannes UllrichWSUS 3.0 SP2 released
2009-08-11Swa FrantzenMicrosoft August 2009 Black Tuesday Overview
2009-07-28Adrien de BeaupreYYAMCCBA
2009-07-28Adrien de BeaupreMS released two OOB bulletins and an advisory
2009-07-24Rick WannerMicrosoft Out of Band Patch
2009-07-14Swa FrantzenMicrosoft July Black Tuesday Overview
2009-07-13Adrien de BeaupreVulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution
2009-07-09John BambenekLatest Updates on Ongoing DDoS on Governmental/Commercial Websites in USA and S. Korea
2009-06-12Adrien de BeaupreGoogle updates for Chrome
2009-06-10Rick WannerSysInternals Survey
2009-06-09Swa FrantzenMicrosoft June Black Tuesday Overview
2009-06-01G. N. WhiteYet another "Digital Certificate" malware campaign
2009-05-28Stephen HallMicrosoft DirectShow vulnerability
2009-05-27donald smithWebDAV write-up
2009-05-15Daniel WesemannIIS6.0 WebDav Remote Auth Bypass
2009-05-12Swa FrantzenMSFT's version of responsible disclosure
2009-05-12Swa FrantzenMay Black Tuesday Overview
2009-05-05Bojan ZdrnjaEvery dot matters
2009-05-05Bojan ZdrnjaHealth database breached
2009-04-30Marcus SachsMicrosoft Revises 08-069, 08-076, and 09-012
2009-04-24Pedro BuenoDid you check your conference goodies?
2009-04-16Adrien de BeaupreSome conficker lessons learned
2009-04-14Swa FrantzenApril Black Tuesday Overview
2009-03-26Mark HofmanWebhoneypot fun
2009-03-10Swa FrantzenMarch black Tuesday overview
2009-02-25Swa FrantzenTargeted link diversion attempts
2009-02-14Deborah HaleMicrosoft Time Sync Appears to Down
2009-02-10Swa FrantzenFebruary Black Tuesday Overview
2009-02-08Mari NicholsAre we becoming desensitized to data breaches?
2009-01-31Swa FrantzenWindows 7 - not so secure ?
2009-01-18Maarten Van HorenbeeckTargeted social engineering
2009-01-13Johannes UllrichJanuary Black Tuesday Overview
2009-01-07William SaluskyBIND 9.x security patch - resolves potentially new DNS poisoning vector
2008-12-16donald smithMicrosoft announces an out of band patch for IE zero day
2008-12-12Johannes UllrichMSIE 0-day Spreading Via SQL Injection
2008-12-10Mark HofmanMicrosoft wordpad text converter issue
2008-12-09Swa FrantzenDecember Black Tuesday Overview
2008-12-02Deborah HaleSonicwall License Manager Failure
2008-11-11Swa FrantzenNovember Black Tuesday Overview
2008-11-02Mari NicholsDay 33 - Working with Management to Improve Processes
2008-10-29Deborah HaleDay 29 - Should I Switch Software Vendors?
2008-10-23Mark HofmanMicrosoft out-of-band patch - Severity Critical
2008-10-14Swa FrantzenOctober Black Tuesday Overview
2008-10-10Marcus SachsFake Microsoft Update Email
2008-09-24Deborah HaleFlurry of Security Advisories from CISCO
2008-09-09Swa FrantzenSeptember 2008 Black Tuesday Overview
2008-08-12Stephen HallAugust 2008 Black Tuesday Overview
2008-08-01Robert DanfordMicrosoft Malicious Software Removal Tool users double check it's running
2008-07-09Johannes UllrichUnpatched Word Vulnerability
2008-07-08Swa FrantzenJuly 2008 black tuesday overview
2008-07-08Johannes UllrichMulitple Vendors DNS Spoofing Vulnerability
2008-07-07Scott FendleyMicrosoft Snapshot Viewer Security Advisory
2008-06-24Jason LamMicrosoft SQL Injection Prevention Strategy
2008-06-10Swa FrantzenRansomware keybreaking
2008-06-10Swa FrantzenJune 2008 Black Tuesday Overview
2008-06-06Kevin ListonMicrosoft Security Bulletin Advance Notification for June 2008
2008-06-01Mari NicholsUpdates to VMware resolve critical security issues
2008-05-28Jim ClausingSo, how do you monitor your website?
2008-05-17Lorna HutchesonXP SP3 Issues
2008-05-13Swa FrantzenMay 2008 black tuesday overview
2008-05-13Swa FrantzenMicrosoft office file block & MOICE
2008-05-06John BambenekWindows XP Service Pack 3 Released
2008-05-01Adrien de BeaupreWindows XP SteadyState
2008-05-01Adrien de BeaupreWindows Detours
2008-04-18John BambenekIIS Vulnerability Documented by Microsoft - Includes Workarounds
2008-04-18John BambenekThe Patch Window is Gone: Automated Patch-Based Exploit Generation
2008-04-16William StearnsWindows XP Service Pack 3 - unofficial schedule: Apr 21-28
2008-04-09Joel EslerISC Podcast Episode Number 2
2008-04-08Swa FrantzenApril 2008 - Black Tuesday Overview
2008-04-07John BambenekNetwork Solutions Technical Difficulties? Enom too
2008-04-03Bojan ZdrnjaOpera fixes vulnerabilities and Microsoft announces April's fixes
2008-04-02Adrien de BeaupreWhen is a DMG file not a DMG file
2008-03-25Raul SilesMicrosoft Jet Database Engine Advisory Update (950627)
2008-03-22Koon Yaw TanMicrosoft Security Advisory Released (950627)
2006-12-26Swa FrantzenVista: better security [Y/N] ?
2006-12-12Swa FrantzenMicrosoft Black Tuesday - December 2006 overview
2006-12-12Jim ClausingMS06-075: csrss local privilege escalation (CVE-2006-5585)
2006-12-12Lorna HutchesonMS06-072: Cumulative Security Update for Internet Explorer (925454)
2006-12-12Robert DanfordMS06-078: 2 Windows Media Format Vulnerabilities (CVE-2006-4702, CVE-2006-6134)
2006-12-12Swa FrantzenMicrosoft Office 2004 - Mac OS X updated
2006-12-12Swa FrantzenOffline Microsoft Patching
2006-12-12Swa FrantzenThe missing Microsoft patches
2006-11-20Joel EslerMS06-070 Remote Exploit
2006-11-14Jim ClausingMS06-069: Adobe Flash Player
2006-11-14Jim ClausingMS06-071: MSXML Core Services
2006-11-10Tony CarothersA busy Black Tuesday coming up.....
2006-10-09Swa FrantzenMicrosoft black tuesday - October 2006 STATUS
2006-10-05Swa FrantzenMS06-053 revisited ?
2006-09-30Swa FrantzenYellow: WebViewFolderIcon setslice exploit spreading
2006-09-28Swa FrantzenPowerpoint, yet another new vulnerability
2006-09-28Swa FrantzenMSIE: One patched, one pops up again (setslice)
2006-09-26Jim ClausingMS06-049 re-release
2006-09-12Michael HaisleyMicrosoft Security Bulletin MS06-054
2006-09-12Swa FrantzenMicrosoft security patches for September 2006
2006-09-12Michael HaisleyMicrosoft Security Bulletin MS06-052
2006-08-17Swa FrantzenMicrosoft August 2006 Patches: STATUS