Новости - Выпуск 4
Четвертый подкаст освещает новости 2-8 декабря 2019 года:
1. OpenBSD Multiple Authentication Vulnerabilitie [1] [2]
2. New vulnerability lets attackers sniff or hijack VPN connections [3][4]
3. The StrandHogg vulnerability [5][6]
4. Vulnerability Spotlight: Two vulnerabilities in EmbedThis GoAhead [7][8]
5. PCI Contactless Payments on COTS [9][10]
6. New Destructive Wiper “ZeroCleare” Targets Energy Sector in the Middle East [11][12][13]
7. Группировка Lazarus обзавелась собственным бесфайловым вредоносом [14] [15]
[1] - https://blog.qualys.com/laws-of-vulnerabilities/2019/12/04/openbsd-multiple-authentication-vulnerabilities
[2] - https://www.securitylab.ru/news/503146.php
[3] - https://seclists.org/oss-sec/2019/q4/122
[4] - https://www.zdnet.com/article/new-vulnerability-lets-attackers-sniff-or-hijack-vpn-connections/
[5] - https://promon.co/security-news/strandhogg/
[6] - https://xakep.ru/2019/12/03/strandhogg/
[7] - https://blog.talosintelligence.com/2019/12/vulnerability-spotlight-EmbedThis-GoAhead.html
[8] - https://xakep.ru/2019/12/05/goahead-rce-2/
[9] - https://blog.pcisecuritystandards.org/just-published-pci-contactless-payments-on-cots
[10] - https://www.securitylab.ru/news/503159.php
[11] - https://www.ibm.com/downloads/cas/OAJ4VZNJ
[12] - https://xakep.ru/2019/12/05/zerocleare/
[13] - https://threatpost.ru/new-zerocleare-wiper-targets-energy-industrial-organizations-in-the-middle-east/34973/
[14] - https://twitter.com/dineshdina04/status/1201834142704394242
[15] - https://www.securitylab.ru/news/503133.php
Канал в телеграме: tgclick.ru/voiceofsecurity/609