{"id":6850,"date":"2017-03-03T09:00:06","date_gmt":"2017-03-03T17:00:06","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/03\/news-641\/"},"modified":"2017-03-03T09:00:06","modified_gmt":"2017-03-03T17:00:06","slug":"news-641","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/03\/news-641\/","title":{"rendered":"TippingPoint Threat Intelligence and Zero-Day Coverage \u2013 Week of February 27, 2017"},"content":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 03 Mar 2017 16:42:53 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><em>\u201cEvery new beginning comes from some other beginning&#8217;s end.\u201d<\/em><\/p>\n<p>That\u2019s the last line of the song \u201cClosing Time\u201d by the band Semisonic. The TippingPoint team is no stranger to new beginnings. Our latest \u201cnew beginning\u201d began almost a year ago when Trend Micro acquired us from Hewlett Packard Enterprise. The second part of our new beginning starts next Monday, when we\u2019ll be starting our day in a new building. It\u2019s so easy to be nostalgic when you\u2019re packing up an office \u2013 getting that wistful affection for the past when you find relics you thought were long gone and reminiscing about special moments. We have a lot to reminisce about from the past year alone \u2013\u00a0 and hopefully there will be many more memories in the years to come.<\/p>\n<p><strong>New ThreatDV DGA Filters<\/strong><\/p>\n<p>The ThreatDV Domain Generation Algorithm (DGA) Defense family of filters is designed to detect DNS requests from malware infected hosts that are attempting to contact their command and control (C&amp;C) hosts using DGAs. There are two new DGA filters in this week\u2019s ThreatDV package:<\/p>\n<ul>\n<li>27237: DNS: Suspicious DNS Lookup NXDOMAIN Response (DGA &#8211; Digit Dash)<\/li>\n<li>27242: DNS: Suspicious DNS Lookup NOERROR Response (DGA &#8211; Digit Dash)<\/li>\n<\/ul>\n<p>Customers can access the ThreatDV Deployment and Best Practices guide through the <a href=\"https:\/\/tmc.tippingpoint.com\/TMC\/\">TippingPoint Threat Management Center website<\/a>.<\/p>\n<p><strong>New Support Phone Numbers for Trend Micro TippingPoint Customers<\/strong><\/p>\n<p>Trend Micro TippingPoint will soon update and expand international technical support phone numbers. The existing phone numbers for the United States and Canada will remain unchanged. For all other countries, the TippingPoint menu will be added to the existing in country Trend Micro numbers. The updated list of phone numbers will be posted to the Threat Management Center (TMC) website. This change will be effective <strong>March 6, 2017<\/strong>. If customers have any questions or concerns, they can contact the TippingPoint Technical Assistance Center (TAC).<\/p>\n<p><strong>Zero-Day Filters<\/strong><\/p>\n<p>There are 12 new zero-day filters covering four vendors in this week\u2019s Digital Vaccine (DV) package. A number of existing filters in this week\u2019s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and\/or optimize performance. You can browse the list of <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/published\/\">published advisories<\/a> and <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/upcoming\/\">upcoming advisories<\/a> on the <a href=\"http:\/\/www.zerodayinitiative.com\/\">Zero Day Initiative<\/a> website.<\/p>\n<p><strong><em>Adobe (3)<\/em><\/strong><\/p>\n<ul>\n<li>27225: ZDI-CAN-4355: Zero Day Initiative Vulnerability (Adobe Reader DC)<\/li>\n<li>27233: ZDI-CAN-4369: Zero Day Initiative Vulnerability (Adobe Reader DC)<\/li>\n<li>27236: ZDI-CAN-4374: Zero Day Initiative Vulnerability (Adobe Reader DC)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>Cisco (1)<\/em><\/strong><\/p>\n<ul>\n<li>27223: ZDI-CAN-4343: Zero Day Initiative Vulnerability (Cisco Prime Collaboration Provisioning)<strong><em>\u00a0<\/em><\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>Foxit (2)<\/em><\/strong><\/p>\n<ul>\n<li>27224: ZDI-CAN-4354: Zero Day Initiative Vulnerability (Foxit Reader)<\/li>\n<li>27227: ZDI-CAN-4365: Zero Day Initiative Vulnerability (Foxit Reader)<strong><em>\u00a0<\/em><\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>Hewlett Packard Enterprise (6)<\/em><\/strong><\/p>\n<ul>\n<li>27222: ZDI-CAN-4342: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Universal CMDB)<\/li>\n<li>27228: ZDI-CAN-4367: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management)<\/li>\n<li>27232: ZDI-CAN-4368: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management)<\/li>\n<li>27234: ZDI-CAN-4372: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management) 27234: ZDI-CAN-4372: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management)<\/li>\n<li>27235: ZDI-CAN-4373: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management) 27235: ZDI-CAN-4373: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management)<\/li>\n<li>27238: ZDI-CAN-4378: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management)<strong><em>\u00a0<\/em><\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Missed Last Week\u2019s News?<\/strong><\/p>\n<p>Catch up on last week\u2019s news in my <a href=\"http:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-zero-day-coverage-week-february-20-2017\/\">weekly recap<\/a>.<\/p>\n<p><a href=\"http:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-zero-day-coverage-week-february-27-2017\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 03 Mar 2017 16:42:53 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>\u201cEvery new beginning comes from some other beginning&#8217;s end.\u201d That\u2019s the last line of the song \u201cClosing Time\u201d by the band Semisonic. The TippingPoint team is no stranger to new beginnings. Our latest \u201cnew beginning\u201d began almost a year ago when Trend Micro acquired us from Hewlett Packard Enterprise. The second part of our new&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[10384,714,10415],"class_list":["post-6850","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-network","tag-security","tag-zero-day-initiative"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6850"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6850\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6850"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}