Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/8/2019
11:55 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Dark Reading News Desk Live at Black Hat USA 2019

Watch right here for 40 video interviews with speakers and sponsors. Streaming live from Black Hat USA Wednesday and Thursday 2 p.m. to 6 p.m. Eastern.

UPDATE -- The Dark Reading video News Desk has returned to Black Hat, bringing you more than 30 live video interviews with conference speakers and sponsors as we stream live from the expo floor this Wednesday and Thursday.

Check out some of the interviews from yesterday, posted below, and check back soon as we add more. And join us here at 2 p.m. Eastern, 11 a.m. Pacific today -- Thursday, Aug. 8 -- to learn about the newest gobsmacking vulnerability disclosures, headsmacking attack trends, clever penetration tools, inventive security solutions, and, horrifying, um, bug infestations.

Watch here and follow the action on Twitter at #DRNewsDesk.

Here's our line-up for Thursday, Aug. 8: 2 p.m. to 6 p.m. Eastern / 11 a.m. to 3 p.m. Pacific

  • Oded Vanunu, Head of Products Vulnerability Research, Check Point Software Technologies -- Reverse Engineering WhatsApp Encryption for Chat Manipulation and More
  • Jesse Rothstein, CTO and Co-Founder, ExtraHop

  • David Cross, Principal Security Architect, Henry Schein One -- Alexa HackerMode 2.0: Voice auto Pwn using Kali Linux and Alexa skill combo
  • Pablo Breuer, US Special Operations Command, Donovan Group, Innovation Officer, SOFWERX and David M. Perlman, Ph.D., Social Media professional & founder of CoPsyCon -- Hacking Ten Million Useful Idiots
  • Mike Price, Chief Technology Officer, ZeroFOX and Matt Price, Principal Research Engineer, ZeroFox -- Playing Offense and Defense with Deep Fakes
  • Chris Eng, Chief Research Officer, Veracode -- on application security

  • Alex Comerford, data scientist, and Jonathan Saunders, graduate student at University of Oregon -- Detecting DeepFakes with Mice
  • Ruben Santamarta, Principal Security Consultant, IOActive -- Reversing the Boeing 787's Core Network
  • Mike Sapien, Chief Analyst, Enterprise Services, Ovum -- about the MSSP market
  • from Informa, Eric Parizo, Senior Analyst, Ovum and Tanner Johnson, Senior Research Analyst, IHS Markit, about shake-ups at Symantec and trends in IoT security

  • John Weinschenk, General Manager of Enterprise Network and Application Security, Spirent -- better vulnerability identification and getting more benefit from compliance efforts

  • Dr. Paul Vixie, CEO, Farsight Security -- about the ethical quandaries of managing Internet infrastructure
  • Brian Knighton, Senior Researcher, National Security Agency Chris Delikat, Technical Lead, CNE Research, National Security AgencyGhidra: Journey from NSA Tool to Open Source
  • Dan Hubbard, CEO, Lacework -- cloud security 

  • Philippe Courtot, Chairman and CEO, Qualys -- cloud security

  • Chris Morales, Vectra -- ransomware's evolving methods

  • Michael Wozniak Technical Lead for Infrastructure Security, Snap Inc and Winston Howes, Technical Lead for Application Security, Snap Inc. -- Securing Apps in the Open-By-Default Cloud
  • Eva Galperin, Director of Cybersecurity, Electronic Frontier Foundation -- Hacking for the Greater Good
  • Pramod Rana -- LMYN: Let's Map Your Network

 

Here was the line-up for yesterday, Wednesday, Aug. 7. Watch archives of some videos below and check back soon as we add more. 

  • Mike Kiser, Office of the CTO, SailPoint -- Spartacus-as-a-Service: privacy via obfuscation

  • Eldon Sprickerhoff, Founder and Chief Innovation Officer, eSentire -- the differences between MSSPs and managed detection response

  • Xavier Garceau-Aranda, Senior Security Consultant, NCC Group -- Scout Suite: a multi-cloud security auditing tool

  • Nathan Hamiel, Head of Cybersecurity Research, Kudelski Security and Nils Amiet, Senior Cybersecurity Engineer, Kudelski Security -- FumbleChain: a purposely vulnerable blockchain

  • Chester Wisniewski, Principal Research Scientist, Sophos -- automated active attacks and why they're here to stay

 

  • Nikhil Mittal, Principal Trainer, PentesterAcademy -- on Active Directory attacks

  • Dean Sysman, CEO & Co-Founder, Axonius -- on asset management and its role in infosec

  • Joshua Maddux, Software Engineer / Security Researcher, PKC Security -- How Apple Scattered Vulns All Over the Internet

  • April Wright, Security Consultant, ArchitectSecurity.org and Jayson Street, VP of Infosec, SphereNY -- on social engineering detection and incident response

  • Spencer McIntyre, Technical Director of R&I,RSM -- King Phisher: A Phishing Campaign Toolkit

  • Tim Vidas, PhD, Senior Distinguished Engineer, Office of the CTO, Secureworks and Nash Borges, PhD, Senior Director of Engineering and Data Science, Secureworks 

  • Patrick Cable, Director of Platform Security, Threat Stack -- Trash Taxi: Taking Out the Garbage in Your Infrastructure

  • Dmitry Snezkhov, Red Team Operator, X-Force Red, IBM Corporation -- Zombie Ant Farming

  • Mark Dufresne, Vice President, Research & Development, Endgame -- achieving security parity between Apple Mac OSX environments and Windows. Also introducing Endgame for MacOS

  • Gregory Conti, Senior Security Strategist, IronNet and David Raymond, Director, U.S. Cyber Range, Virginia Tech -- Information Operations and misinformation

  • Anthony James, VP of Products, Infoblox -- how to use DNS infrastructure to protect your data and users

  • Mohammed Aldoub, independent security consultant & Black Hat Trainer -- barq: The AWS Post-Exploitation Tool

  • Joakim Kennedy, threat intel manager, Anomali -- the impact of the security skills shortage on threat intelligence

  • Kimberly Zenz, on infighting among Russian security agencies
  • Haiyan Song, SVP and GM of Security Markets, Splunk -- the Phantom acquisition, "Dark Data," and the integration of security and analytics

  • Stu Sjouwerman, founder and CEO, KnowBe4 on defending against phishing and social engineering

 

(Image Source: Filmarkivet. Author: Unknown. Creative Commons.)

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ...
View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
allenred
50%
50%
allenred,
User Rank: Apprentice
8/9/2019 | 3:22:38 AM
cyber security
nice post
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/28/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
10 iOS Security Tips to Lock Down Your iPhone
Kelly Sheridan, Staff Editor, Dark Reading,  5/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11949
PUBLISHED: 2020-05-28
testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.
CVE-2020-11950
PUBLISHED: 2020-05-28
VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.
CVE-2020-13645
PUBLISHED: 2020-05-28
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verificat...
CVE-2020-13643
PUBLISHED: 2020-05-28
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be e...
CVE-2020-13644
PUBLISHED: 2020-05-28
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accord...