WatchGuard Security Week in Review: Episode 51 – Flash 0day

Flash Exploit, ICS Hacks, and Federal Reserve Bank Breach

We’ve had another busy week of security news, with more stories than I can cover in a short video. So I’ll stick to the highlights. Today’s episode talks about a couple Adobe Flash zero day vulnerabilities, the latest Anonymous hijinks, some cross-platform mobile malware, and more. If you missed this week’s InfoSec news, and want to learn about the biggest stories (including how to defend against the latest attacks), click the play button below. Also, check out the Reference section for links to some other interesting security stories I skipped.

Enjoy your weekend, and stay frosty out there.

(Episode Runtime: 8:03)

Direct YouTube Link: http://www.youtube.com/watch?v=B6YdI3NGwlg

Episode References:

— Corey Nachreiner, CISSP (@SecAdept)

About Corey Nachreiner

Corey Nachreiner has been with WatchGuard since 1999 and has since written more than a thousand concise security alerts and easily-understood educational articles for WatchGuard users. His security training videos have generated hundreds of letters of praise from thankful customers and accumulated more than 100,000 views on YouTube and Google Video. A Certified Information Systems Security Professional (CISSP), Corey speaks internationally and is often quoted by other online sources, including C|NET, eWeek, and Slashdot. Corey enjoys "modding" any technical gizmo he can get his hands on, and considers himself a hacker in the old sense of the word.

3 Responses to “WatchGuard Security Week in Review: Episode 51 – Flash 0day”

  1. f.bini@ecoelettronica.it Reply February 9, 2013 at 2:12 am

    W
    Fabio Bini
    Eco Elettronica S.I. srl

  2. Two news was most interesting for me: “Lucky 13″ attack to SSL/TLS encryption and malware, which combines spyware for Android and spyware for Windows.
    1. As for “Lucky 13″ should notice, that in spite of high complexity and many “if” conditions should be met for attack to be successful – products from Opera Software and Offspark B.V. (PolarSSL) already have been patched. Besides, OpenSSL is expected to issue patches soon. So, it was taken seriously, in spite of high complexity. Open SSL engine serves as a OEM-technology for a huge number of commercial products.
    To dig more deeper in it – I’ve downloaded “TLStiming.pdf” (PoC for this method). Will study it more closely from theoretical point of view.
    2. About new Android-Windows spyware – it’s W-O-W! Very sad, that malware like this can be placed and distributed through Google Play…Abilities of this particular malware I can classify us innovative, and this is the first known “Mobile Phone–>PC bridge spyware soft”.

    • Hey Alexander,

      I think you are right about Lucky 13. While I still suspect that few attackers will leverage it in the real-world, venders, like OpenSSL and other, MUST take SSL/TLS vulns very seriously, since our entire eCommerce paradigm relies on them. Without SSL, we’d have many issues… Meanwhile, it seems researchers are finding chinks in SSL’s armor every month… and that doesn’t even take into account all the cert issues various CAs have been having (somewhat related to SSL, since we rely on the certs for authentication). So I definitely expect all the SSL providers to patch, and take this seriously.

      Yeah… I like that Google is more open about development, and don’t restrict their SDK and APIs as much as Apple. However, their open marketplace means more trojaned malware. They have implemented “Bouncer,” which is supposed to help discover malicious apps, but researchers have already found ways around it. The good news about the Droidcleaner malware’s PC portion is if you disable “Auto-Play” on your Windows computer, it shouldn’t be able to spread. In anycase, more and more malware is becoming cross-platform (PC + OS X, or Mobile + normal OS), so I suspect we’ll see more of this in the future.

      Thanks for you comments, Alexander, they are always insightful.

      Cheers,
      Corey

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.

Join 7,115 other followers

%d bloggers like this: