Down The Security Rabbithole

DtSR Episode 175 - NewsCast for January 5th 2016

Informações:

Synopsis

In this episode...   Juniper has a backdoor problem 2 separate issues, auth bypass & VPN weakness backdoor discovered in Juniper devices lots of speculation on who put it there, but it was meant to be disguised as ‘debug code’ enterprise implications - same as before (what's the bigger picture?) https://isc.sans.edu/forums/diary/Infocon+Yellow+Juniper+Backdoor+CVE20157755+and+CVE20157756/20521/ Iranians broke into New York dam in 2013 and “had a look around” no direct damage done US has largest number of ICS connected to Internet critical infrastructure is vulnerable, being probed this is not a ‘government problem’ - every company has some ICS on their network http://www.theregister.co.uk/2015/12/21/iranian_hackers_target_new_york_dam/   Facebook announced it’s dumping Adobe Flash is this a bigger deal than it sounds like HTML5 has its own vulnerabilities and issues though… right? *only* for videos, games still in Flash Facebook will work with Adobe (really?) to improve security of Flash http://www.s