Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/8/2019
11:55 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Dark Reading News Desk Live at Black Hat USA 2019

Watch right here for 40 video interviews with speakers and sponsors. Streaming live from Black Hat USA Wednesday and Thursday 2 p.m. to 6 p.m. Eastern.

UPDATE -- The Dark Reading video News Desk has returned to Black Hat, bringing you more than 30 live video interviews with conference speakers and sponsors as we stream live from the expo floor this Wednesday and Thursday.

Check out some of the interviews from yesterday, posted below, and check back soon as we add more. And join us here at 2 p.m. Eastern, 11 a.m. Pacific today -- Thursday, Aug. 8 -- to learn about the newest gobsmacking vulnerability disclosures, headsmacking attack trends, clever penetration tools, inventive security solutions, and, horrifying, um, bug infestations.

Watch here and follow the action on Twitter at #DRNewsDesk.

Here's our line-up for Thursday, Aug. 8: 2 p.m. to 6 p.m. Eastern / 11 a.m. to 3 p.m. Pacific

  • Oded Vanunu, Head of Products Vulnerability Research, Check Point Software Technologies -- Reverse Engineering WhatsApp Encryption for Chat Manipulation and More
  • Jesse Rothstein, CTO and Co-Founder, ExtraHop

  • David Cross, Principal Security Architect, Henry Schein One -- Alexa HackerMode 2.0: Voice auto Pwn using Kali Linux and Alexa skill combo
  • Pablo Breuer, US Special Operations Command, Donovan Group, Innovation Officer, SOFWERX and David M. Perlman, Ph.D., Social Media professional & founder of CoPsyCon -- Hacking Ten Million Useful Idiots
  • Mike Price, Chief Technology Officer, ZeroFOX and Matt Price, Principal Research Engineer, ZeroFox -- Playing Offense and Defense with Deep Fakes
  • Chris Eng, Chief Research Officer, Veracode -- on application security

  • Alex Comerford, data scientist, and Jonathan Saunders, graduate student at University of Oregon -- Detecting DeepFakes with Mice
  • Ruben Santamarta, Principal Security Consultant, IOActive -- Reversing the Boeing 787's Core Network
  • Mike Sapien, Chief Analyst, Enterprise Services, Ovum -- about the MSSP market
  • Eric Parizo, Senior Analyst, Ovum - about what's happening at Symantec
  • John Weinschenk, General Manager of Enterprise Network and Application Security, Spirent -- better vulnerability identification and getting more benefit from compliance efforts

  • Dr. Paul Vixie, CEO, Farsight Security -- about the ethical quandaries of managing Internet infrastructure
  • Brian Knighton, Senior Researcher, National Security Agency Chris Delikat, Technical Lead, CNE Research, National Security AgencyGhidra: Journey from NSA Tool to Open Source
  • Dan Hubbard, CEO, Lacework -- cloud security 

  • Philippe Courtot, Chairman and CEO, Qualys -- cloud security

  • Chris Morales, Vectra -- ransomware's evolving methods

  • Michael Wozniak Technical Lead for Infrastructure Security, Snap Inc and Winston Howes, Technical Lead for Application Security, Snap Inc. -- Securing Apps in the Open-By-Default Cloud
  • Eva Galperin, Director of Cybersecurity, Electronic Frontier Foundation -- Hacking for the Greater Good
  • Pramod Rana -- LMYN: Let's Map Your Network

 

Here was the line-up for yesterday, Wednesday, Aug. 7. Watch archives of some videos below and check back soon as we add more. 

  • Mike Kiser, Office of the CTO, SailPoint -- Spartacus-as-a-Service: privacy via obfuscation

  • Eldon Sprickerhoff, Founder and Chief Innovation Officer, eSentire -- the differences between MSSPs and managed detection response

  • Xavier Garceau-Aranda, Senior Security Consultant, NCC Group -- Scout Suite: a multi-cloud security auditing tool

  • Nathan Hamiel, Head of Cybersecurity Research, Kudelski Security and Nils Amiet, Senior Cybersecurity Engineer, Kudelski Security -- FumbleChain: a purposely vulnerable blockchain

  • Chester Wisniewski, Principal Research Scientist, Sophos -- automated active attacks and why they're here to stay

 

  • Nikhil Mittal, Principal Trainer, PentesterAcademy -- on Active Directory attacks

  • Dean Sysman, CEO & Co-Founder, Axonius -- on asset management and its role in infosec

  • Joshua Maddux, Software Engineer / Security Researcher, PKC Security -- How Apple Scattered Vulns All Over the Internet

  • April Wright, Security Consultant, ArchitectSecurity.org and Jayson Street, VP of Infosec, SphereNY -- on social engineering detection and incident response

  • Spencer McIntyre, Technical Director of R&I,RSM -- King Phisher: A Phishing Campaign Toolkit

  • Tim Vidas, PhD, Senior Distinguished Engineer, Office of the CTO, Secureworks and Nash Borges, PhD, Senior Director of Engineering and Data Science, Secureworks 

  • Patrick Cable, Director of Platform Security, Threat Stack -- Trash Taxi: Taking Out the Garbage in Your Infrastructure

  • Dmitry Snezkhov, Red Team Operator, X-Force Red, IBM Corporation -- Zombie Ant Farming

  • Mark Dufresne, Vice President, Research & Development, Endgame -- achieving security parity between Apple Mac OSX environments and Windows. Also introducing Endgame for MacOS

  • Gregory Conti, Senior Security Strategist, IronNet and David Raymond, Director, U.S. Cyber Range, Virginia Tech -- Information Operations and misinformation

  • Anthony James, VP of Products, Infoblox -- how to use DNS infrastructure to protect your data and users

  • Mohammed Aldoub, independent security consultant & Black Hat Trainer -- barq: The AWS Post-Exploitation Tool

  • Joakim Kennedy, threat intel manager, Anomali -- the impact of the security skills shortage on threat intelligence

  • Kimberly Zenz, on infighting among Russian security agencies
  • Haiyan Song, SVP and GM of Security Markets, Splunk -- the Phantom acquisition, "Dark Data," and the integration of security and analytics

  • Stu Sjouwerman, founder and CEO, KnowBe4 on defending against phishing and social engineering

 

(Image Source: Filmarkivet. Author: Unknown. Creative Commons.)

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
allenred
50%
50%
allenred,
User Rank: Apprentice
8/9/2019 | 3:22:38 AM
cyber security
nice post
GitHub Named in Capital One Breach Lawsuit
Dark Reading Staff 8/14/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
The Flaw in Vulnerability Management: It's Time to Get Real
Jim Souders, Chief Executive Officer at Adaptiva,  8/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4483
PUBLISHED: 2019-08-20
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X...
CVE-2019-4484
PUBLISHED: 2019-08-20
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164068.
CVE-2019-4485
PUBLISHED: 2019-08-20
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164069.
CVE-2019-7593
PUBLISHED: 2019-08-20
Metasys? ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
CVE-2019-7594
PUBLISHED: 2019-08-20
Metasys? ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).