Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

8/5/2008
05:29 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Black Hat 2008, First Day Sessions

I've been in Las Vegas for a couple of days now, meeting with some old friends in the information security community, and making a few new ones. This year, the annual Black Hat confab will be serving interesting talks on the security implications of virtualization, social networks, and Web 2.0. Should make a good conference that will highlight some of the big security concerns going forward.

I've been in Las Vegas for a couple of days now, meeting with some old friends in the information security community, and making a few new ones. This year, the annual Black Hat confab will be serving interesting talks on the security implications of virtualization, social networks, and Web 2.0. Should make a good conference that will highlight some of the big security concerns going forward.On Wednesday, I'll be attending the keynote, from the Application Security track, of Ian O. Angell, professor of information systems, London School of Economics, called Complexity in Computer Security: a Risky Business. While the name of the presentation doesn't pack much punch, this description pulled me in: The mixture of computers and human activity systems spawns bureaucracy and systemic risk, which can throw up singularities that defy any positivist/statistical analysis. Should be interesting, I'm always up for an economist's take on information security.

Next up, we're jumping over to the networking track for a ride with The Four Horsemen of the Virtualization Security Apocalypse, presented by Christopher Hoff, chief security architect at Unisys. This network presentation will focus on both securing virtualization as well as virtualizing security; from virtualization-enabled chipsets to the hypervisor to the VMs, we'll explore the real issues that exist today as well as those that are coming that aren't being discussed or planned for. There's no doubt virtualizing security, as well as securing virtualized environments, are two topics just getting warmed up.

Final session I'll be attending Wednesday will be Xploiting Google Gadgets: Gmalware and Beyond. Couldn't resist this description: This talk will analyze the security history of Google Gadgets and demonstrate ways to exploit Gadgets for nefarious purposes. I guess social-engineering someone to install a gadget so you can scan all of the systems on their subnet will supplement malware-laced USB storage devices used for the same purposes.

I'll be posting my observations from the conference throughout the week. Stay tuned.

Or, you can follow my micro blogs from the event on Twitter.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Exploiting Google Cloud Platform With Ease
Dark Reading Staff 8/6/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: They said you could use Zoom anywhere.......
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13285
PUBLISHED: 2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issue reference number tooltip.
CVE-2020-16087
PUBLISHED: 2020-08-13
An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo client by sending the user of the device a crafted file.
CVE-2020-17463
PUBLISHED: 2020-08-13
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CVE-2019-16374
PUBLISHED: 2020-08-13
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.
CVE-2020-13280
PUBLISHED: 2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.