{"id":8412,"date":"2017-07-21T09:00:44","date_gmt":"2017-07-21T17:00:44","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/07\/21\/news-2186\/"},"modified":"2017-07-21T09:00:44","modified_gmt":"2017-07-21T17:00:44","slug":"news-2186","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/07\/21\/news-2186\/","title":{"rendered":"TippingPoint Threat Intelligence and Zero-Day Coverage \u2013 Week of July 17, 2017"},"content":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 21 Jul 2017 18:07:14 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>If you conduct a search on the Web for the number of languages spoken around the world, you\u2019ll see numbers ranging anywhere from 6,000-7,000. I figure I\u2019m doing okay since I can speak English and Spanish, sign the English alphabet, recite the Greek alphabet, and read music. There are roughly over 1.2 billion web sites on the Internet, yet, a large majority of those sites share the same programming language.<\/p>\n<p>&nbsp;<\/p>\n<p>Earlier this week, Zero Day Initiative (ZDI) vulnerability researcher Simon Zuckerbraun published a <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2017\/7\/18\/understanding-risk-in-the-unintended-giant-javascript\">blog<\/a> discussing how JavaScript grew from a simple scripting language to become the assembly language of the web. According to the results of the <a href=\"https:\/\/insights.stackoverflow.com\/survey\/2016\">2016 StackOverflow Developer Survey<\/a>, \u201cJavaScript is the most commonly used programming language on Earth.\u201d In addition to its role as a programming language, JavaScript often serves as the intermediate representation for dozens of other compiled languages. So you can imagine what can happen. A new class of security risk is emerging in connection with JavaScript \u2013 the danger of vulnerabilities in the execution engine itself. Simon\u2019s blog is the first in a series on JavaScript vulnerabilities and how the broad implementation of the language affects the enterprise attack surface. You can read his blog here: <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2017\/7\/18\/understanding-risk-in-the-unintended-giant-javascript\">Understanding Risk in the Unintended Giant: JavaScript<\/a>.<\/p>\n<p><strong>Adobe Security Update<\/strong><\/p>\n<p>This week\u2019s Digital Vaccine (DV) package includes coverage for Adobe updates released on or before July 11, 2017. The following table maps Digital Vaccine filters to the Adobe updates. Filters marked with an (*) shipped prior to this DV package, providing zero-day protection for our customers. You can get more detailed information on this month\u2019s security updates from Dustin Childs\u2019 <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2017\/7\/11\/the-july-2017-security-update-review\">July 2017 Security Update Review<\/a> from the Zero Day Initiative:<\/p>\n<div class=\"lightTable\">\n<table width=\"0\">\n<tbody>\n<tr>\n<td width=\"111\"><strong>Bulletin #<\/strong><\/td>\n<td width=\"128\"><strong>CVE #<\/strong><\/td>\n<td width=\"196\"><strong>Digital Vaccine Filter #<\/strong><\/td>\n<td width=\"190\"><strong>Status<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"111\">APSB17-21<\/td>\n<td width=\"128\">CVE-2017-3080<\/td>\n<td width=\"196\">29078<\/td>\n<td width=\"190\"><\/td>\n<\/tr>\n<tr>\n<td width=\"111\">APSB17-21<\/td>\n<td width=\"128\">CVE-2017-3099<\/td>\n<td width=\"196\">29130<\/td>\n<td width=\"190\"><\/td>\n<\/tr>\n<tr>\n<td width=\"111\">APSB17-21<\/td>\n<td width=\"128\">CVE-2017-3100<\/td>\n<td width=\"196\">*28917<\/td>\n<td width=\"190\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>&nbsp;<\/p>\n<p><strong>Zero-Day Filters<\/strong><\/p>\n<p>There is one new zero-day filter covering one vendor in this week\u2019s Digital Vaccine (DV) package. A number of existing filters in this week\u2019s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and\/or optimize performance. You can browse the list of <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/published\/\">published advisories<\/a> and <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/upcoming\/\">upcoming advisories<\/a> on the <a href=\"http:\/\/www.zerodayinitiative.com\/\">Zero Day Initiative<\/a> website.<\/p>\n<p><strong><em>Adobe (1)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>29078: HTTP: Adobe Flash Broker API Information Disclosure Vulnerability (ZDI-17-486)<strong><em>\u00a0<\/em><\/strong><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Missed Last Week\u2019s News?<\/strong><\/p>\n<p>Catch up on last week\u2019s news in my <a href=\"http:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-zero-day-coverage-week-july-10-2017\/\">weekly recap<\/a>.<\/p>\n<p><a href=\"http:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-zero-day-coverage-week-july-17-2017\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 21 Jul 2017 18:07:14 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>If you conduct a search on the Web for the number of languages spoken around the world, you\u2019ll see numbers ranging anywhere from 6,000-7,000. I figure I\u2019m doing okay since I can speak English and Spanish, sign the English alphabet, recite the Greek alphabet, and read music. There are roughly over 1.2 billion web sites&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[10384,714,10415],"class_list":["post-8412","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-network","tag-security","tag-zero-day-initiative"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=8412"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8412\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=8412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=8412"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=8412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}