Black Hat USA
August 4-9, 2018
Las Vegas, NV, USA
Black Hat Trainings
October 22-23, 2018
Chicago, IL USA
Black Hat Europe
December 3-6, 2018
London UK
7/10/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: A Massive Enterprise

In today's Intel Update we're going big... enterprise big, with a selection of Black Hat Briefing highlights that focus on big ideas that affect large organizations.

The St. Regis ShenZhen, a gorgeous luxury hotel occupying the top 28 floors of a 100-story skyscraper, lets visitors control lighting, temperature, music, TV, the blinds, and other room features with an iPad 2. Unfortunately, the system relies on outdated home automation protocols, which allowed presenter Jesus Molina full control over every wired room in the hotel... even from home. In "The Dangers of Insecure Home Automation Deployment," Molina will explore the implications for large-scale home automation applications, particularly in public settings which leave the venue open to potentially serious liability.

Big data is changing the way things are done, but many organizations' security sensibilities haven't caught up to their wanton usage of Hadoop. Are they taking on too much risk, too quickly? Big data's supposed to generate better, more intelligent predictions, but why should we trust our least-secure systems? Based on Davi Ottenheimer's new book, Realities of Big Data Security, "Babar-ians at the Gate: Data Protection at Massive Scale" will present the author's findings, probing tomorrow's hardest big data problem areas and offering recommendations for today.

Next up, companies and their systems still leak information like a sieve, despite an endless array of security and protection standards and certs. Data Loss Prevention (DLP) solutions are touted as the silver bullet that will save corporations from starring in tomorrow's headlines, but how effective are they, really? "Stay Out of the Kitchen: A DLP Security Bake-Off" will examine the most popular DLP solutions and show you how they really stack up, complete with flaws and exploits.

Finally, today's final Briefing reminds us that on today's Internet both enterprises and individuals are increasingly faced with nation-state class adversaries. Yesterday's tired security dogma (for example, "perimeter defense") is completely inadequate against such an adversary. The presenters of "The Library of Sparta" posit that the collective military wisdom of the last two millennia offers a welcome source of insight, with timeless strategies that can be adapted into effective cyber-security today. Topics will include deception, electronic warfare, operations security, human intelligence collection, psychological operations, and military cryptanalysis, among many others.

Regular registration ends on July 26. Please visit Black Hat USA 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: In Russia, application hangs YOU!
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-3912
PUBLISHED: 2018-09-18
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
CVE-2018-6690
PUBLISHED: 2018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
CVE-2018-6693
PUBLISHED: 2018-09-18
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escal...
CVE-2018-16515
PUBLISHED: 2018-09-18
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-16794
PUBLISHED: 2018-09-18
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.