{"id":6413,"date":"2017-01-27T12:00:35","date_gmt":"2017-01-27T20:00:35","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/01\/27\/news-250\/"},"modified":"2017-01-27T12:00:35","modified_gmt":"2017-01-27T20:00:35","slug":"news-250","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/01\/27\/news-250\/","title":{"rendered":"Tipping Point Threat Intelligence and Zero-Day Coverage \u2013 Week of January 23, 2017"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"attachment-medium size-medium wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>They say security never sleeps. I wish I could go for days without sleeping, because I could get so much done. Unfortunately, we\u2019re just not built that way, which explains why my post this week is a few hours later than usual. I could say, \u201cbetter late than never,\u201d but that would definitely not apply to the security world, especially if someone\u2019s data was compromised. Whether it\u2019s late or never, the only winner is the attacker that compromised your network.<\/p>\n<p>With the Zero Day Initiative, we are fortunate to have exclusive access to vulnerability information submitted to the program. While ZDI works with the affected vendor to make sure they have the information they need to work on a patch, we protect our customers an average of 57 days before a patch is issued. In 2016, ZDI published a record 677 advisories covering almost 50 vendors. We\u2019re only in the first month of 2017 and ZDI has already published 57 vulnerabilities. We will definitely see more as we prepare for the 10<sup>th<\/sup> anniversary of the <a href=\"http:\/\/blog.trendmicro.com\/pwn2own-returns-for-2017-to-celebrate-10-years-of-exploits\/\">Pwn2Own contest in March<\/a>. Make sure to follow the Zero Day Initiative on <a href=\"https:\/\/twitter.com\/thezdi\">Twitter<\/a> for all the latest information leading up to the contest!<\/p>\n<p><strong>Microsoft Patch Tuesday Update<\/strong><\/p>\n<p>This week\u2019s Digital Vaccine (DV) package includes additional coverage for the Microsoft Security Bulletins released earlier this month. The following table maps one Digital Vaccine filter to the Microsoft Security Bulletins.<\/p>\n<div class=\"lightTable\">\n<table width=\"896\">\n<tbody>\n<tr>\n<td width=\"140\"><strong>Bulletin #<\/strong><\/td>\n<td width=\"183\"><strong>CVE #<\/strong><\/td>\n<td width=\"221\"><strong>Digital Vaccine Filter #<\/strong><\/td>\n<td width=\"337\"><strong>Status<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"140\">MS17-001<\/td>\n<td width=\"183\">CVE-2017-0002<\/td>\n<td width=\"221\">26639<\/td>\n<td width=\"337\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p><strong>Zero-Day Filters<\/strong><\/p>\n<p>There are 10 new zero-day filters covering four vendors in this week\u2019s Digital Vaccine (DV) package. A number of existing filters in this week\u2019s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and\/or optimize performance. You can browse the list of <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/published\/\">published advisories<\/a> and <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/upcoming\/\">upcoming advisories<\/a> on the <a href=\"http:\/\/www.zerodayinitiative.com\/\">Zero Day Initiative<\/a> website.<\/p>\n<p><strong><em>Adobe (2)<\/em><\/strong><\/p>\n<ul>\n<li>26631: ZDI-CAN-4318: Zero Day Initiative Vulnerability (Adobe Reader DC)<\/li>\n<li>26638: HTTP: Adobe Flash loadPCMFromByteArray Integer Overflow Vulnerability (ZDI-13-021)<strong><em>\u00a0<\/em><\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>Hewlett Packard Enterprise (1)<\/em><\/strong><\/p>\n<ul>\n<li>26629: HTTPS: HP Diagnostics Server magentservice.exe Buffer Overflow Vulnerability (ZDI-12-162)<strong>\u00a0<\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>Microsoft (1)<\/em><\/strong><\/p>\n<ul>\n<li>26700: ZDI-CAN-4218: Zero Day Initiative Vulnerability (Microsoft Internet Explorer)<strong><em>\u00a0<\/em><\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>Trend Micro (6)<\/em><\/strong><\/p>\n<ul>\n<li>26508: ZDI-CAN-4320: Zero Day Initiative Vulnerability (Trend Micro Data Loss Prevention Manager)<\/li>\n<li>26633: ZDI-CAN-4311: Zero Day Initiative Vulnerability (Trend Micro InterScan Web Security VA)<\/li>\n<li>26634: ZDI-CAN-4312: Zero Day Initiative Vulnerability (Trend Micro InterScan Web Security VA)<\/li>\n<li>26635: ZDI-CAN-4313: Zero Day Initiative Vulnerability (Trend Micro InterScan Web Security VA)<\/li>\n<li>26636: ZDI-CAN-4315: Zero Day Initiative Vulnerability (Trend Micro InterScan Web Security VA)<\/li>\n<li>26637: ZDI-CAN-4321: Zero Day Initiative Vulnerability (Trend Micro Data Loss Prevention Manager)<strong>\u00a0<\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Missed Last Week\u2019s News?<\/strong><\/p>\n<p>Catch up on last week\u2019s news in my <a href=\"http:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-zero-day-coverage-week-january-16-2017\/\">weekly recap<\/a>.<\/p>\n<p><a href=\"http:\/\/blog.trendmicro.com\/tipping-point-threat-intelligence-zero-day-coverage-week-january-23-2017\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"attachment-medium size-medium wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>They say security never sleeps. I wish I could go for days without sleeping, because I could get so much done. Unfortunately, we\u2019re just not built that way, which explains why my post this week is a few hours later than usual. I could say, \u201cbetter late than never,\u201d but that would definitely not apply&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[10384,714,10415],"class_list":["post-6413","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-network","tag-security","tag-zero-day-initiative"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6413"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6413\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6413"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}