<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Cisco UCS servers can be hijacked with malicious HTTP request</title><description>2016-04-14 14:57:26 - Help Net Security : A data center server platform running Cisco s Unified Computing System  UCS  Central Software can be compromised by unauthenticated, remote attackers with a single, malicious HTTP request, security researcher Gregory Draperi has discovered The Cisco UCS platform was designed to help organizations efficiently manage distributed Cisco UCS servers at scale Cisco UCS Central Software helps manage multiple Cisco UCS domains The vulnerability  CVE-2016-1352  is present in the product s web framework, and its due to improper input   More   </description><link>http://www.secuobs.com/revue/news/603761.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/603761.shtml</guid></item>
<item><title>Avnet met à disposition de ses revendeurs la solution Cisco HyperFlex Systems </title><description>2016-04-13 11:25:55 - Global Security Mag Online : Avnet, Inc est le premier distributeur à avoir vendu un nouveau système Cisco HyperFlex   à ses partenaires revendeurs dans la région EMEA Construit à partir de la plate-forme informatique UCS de Cisco, leader dans son secteur, Cisco HyperFlex  Systems associe informatique, stockage et réseaux au sein d'une plate-forme simplifiée et facile d'utilisation à destination de clients déployant des applications d'entreprise dans leurs datacenters, ainsi que pour les sites distants et succursales Le    - Business </description><link>http://www.secuobs.com/revue/news/603598.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/603598.shtml</guid></item>
<item><title>DocuSign établit des alliances stratégiques avec Deloitte Digital et Cisco </title><description>2016-04-11 14:33:43 - Global Security Mag Online : Dans le cadre de son action en faveur des entreprises de toutes tailles et de tous secteurs d'activité pour les aider dans leur transformation numérique, DocuSign, Inc annonce une alliance stratégique avec Deloitte Digital et Cisco en vue d'intégrer la signature électronique et la fonctionnalité DTM  Digital Transaction Management  à leurs écosystèmes de clients, partenaires, fournisseurs et collaborateurs Ce rapprochement va permettre d'aider les entreprises à engranger rapidement des valeurs    - Business </description><link>http://www.secuobs.com/revue/news/603417.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/603417.shtml</guid></item>
<item><title>RETIS est certifiée CISCO Gold Partner</title><description>2016-04-06 12:28:55 - Global Security Mag Online : L'intégrateur RETIS obtient la certification Gold pour les technologies CISCO Il est désormais au plus haut niveau du programme partenaire de l'éditeur Américain Après 12 années de certification CISCO Silver et un long travail de l'entreprise pour aligner toute son expertise sur les exigences du programme, RETIS franchit un nouveau cap en devenant Gold selon la nouvelle version 2015 RETIS devient un partenaire spécialisé au niveau Gold sur le Réseau de Données, les Réseaux Sans-fils, la Sécurité,    - Business </description><link>http://www.secuobs.com/revue/news/602987.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/602987.shtml</guid></item>
<item><title>Configuring Cisco ISE 12 and StealthWatch Integration</title><description>2016-03-18 05:54:42 - Priveon Labs Security Blog : </description><link>http://www.secuobs.com/revue/news/601388.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/601388.shtml</guid></item>
<item><title>Bsides San Francisco 2016 - Advanced Techniques For Real-Time Detection Of Polymorphic Malware</title><description>2016-03-16 05:53:08 - SecurityTube.Net : In this Session, we will introduce the audience to various techniques that are used in the identification and classification of polymorphic malware By definition, polymorphic malware easily evades traditional signature based detection methods Approximation Matching algorithms such as ssdeep have had much greater success in detecting polymorphic files The ssdeep hash is one of the more popular attributes that is computed for a file by a number of sites such as VirusTotal, Malwr and Anubis Newer algorithms using bloom filters have also shown great promise in detecting polymorphic malware This session gives an overview of these various algorithms and compares their efficiency and performanceWhile ssdeep is a good tool for comparing two known files, it becomes computationally expensive when a new file  and its ssdeep hash  is to be compared with a large database of existing ssdeep hashes to determine the closest match In this session, we enumerate a class of techniques which reduce the lookup time significantly and allow for fast detection of similar files These techniques are then extended to the classification of polymorphic malware and we show the efficacy of these techniques with real data collected from the field We then analyze the performance of these algorithms both from a speed as well as their success rate For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/601144.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/601144.shtml</guid></item>
<item><title>Bsides San Francisco 2016 - Mobile App Corporate Espionage</title><description>2016-03-16 05:53:08 - SecurityTube.Net : Corporate espionage is at an all-time high, and in terms of data risk threats, is second only to financially motivated data breaches according to the Verizon data breach investigations report Whether your team is designing in-house mobile apps or leveraging 3rd parties for mobile apps, the apps may contain risky behaviors These behaviors can stem from malicious 3rd party SDKs or code injected by the developer that can allow sensitive corporate secrets and documents to be leaked through out-of-band communications This session will explore real-word examples of corporate espionage techniques that leverage hidden behaviors in seemingly innocuous mobile apps For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/601143.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/601143.shtml</guid></item>
<item><title>Cisco patches serious flaws in cable modems and home gateways</title><description>2016-03-11 16:02:12 - LinuxSecurity.com   Latest News : LinuxSecuritycom  Cisco Systems has patched high-impact vulnerabilities in several of its cable modem and residential gateway devices that are distributed by some ISPs to their customers </description><link>http://www.secuobs.com/revue/news/600838.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600838.shtml</guid></item>
<item><title>Mercredi des trous chez Cisco</title><description>2016-03-11 05:51:34 - CNIS mag : Les grands classiques sont indémodables   Avalanche de failles http et de trous de sécurité dans les consoles Web d administration chez Cisco Du côté des passerelles sans fil DPC3941 et DPC3939B tout d abord, avec le colmatage du CVE-2016-1325 Un autre trou référencé CVE-2016-1327 est comblé  exploitable à distance  dans la famille des modems câble DPC2203   </description><link>http://www.secuobs.com/revue/news/600806.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600806.shtml</guid></item>
<item><title>NetApp et Cisco lancent FlexPod  Advantage</title><description>2016-03-10 11:48:43 - Global Security Mag Online : NetApp et Cisco lancent FlexPod  Advantage une solution convergée composée de stockage 100pourcents Flash, de mise en réseau et de serveur dans une architecture unique et flexible L'infrastructure convergée FlexPodAdvantage offre des designs validés pour les clouds privés d'entreprise, les Software-Defined Data Centers  SDDC , le stockage unifié en mode scale-out, les infrastructures de postes de travail virtuels, les bases de données, la colocation sécurisée, la continuité de l'activité et la protection    - Produits </description><link>http://www.secuobs.com/revue/news/600711.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600711.shtml</guid></item>
<item><title>BSides San Francisco 2016 - The Tales of a Bug Bounty Hunter</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Bug bounty hunting is the new black  During this technical talk, several interesting vulnerabilities identified in Instagram will be presented All vulnerabilities were disclosed responsibly via Facebook s Public Bug Bounty program over the course of 2015 and 2016, and will be discussed in depth Required advanced Mobile Security attack techniques for this Research, such as Binary Modification, Dynamic Hooking and Burp Suite Plugin Development will be covered, among other trickery The most interesting vulnerabilities were hybrid  Combinations of complementary vulnerabilities in different environments  eg Web and Mobile  All identified issues  root causes will be mapped onto the Software Development Life Cycle  SDLC , to analyze where they could have been prevented from materializing Last but not least, the monetary rewards offered by Facebook for each vulnerability and general Bug Bounty Hunting advice will be shared with the community For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600342.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600342.shtml</guid></item>
<item><title>BSides San Francisco 2016 - APT Reports and OPSEC Evolution, or  These are not the APT reports you are looking for</title><description>2016-03-07 11:15:23 - SecurityTube.Net : We will discuss how advanced threat actors learn and change with innovation in security defense and constant APT reports, and how we can get better For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600341.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600341.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Sucker-punching Malware  A Case Study in Using Bad Malware Design Against Attackers</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Software developers have provided unlimited job security for the infosecindustry Likewise, malware authors also have a history of making baddesign choices that allow defenders opportunities to use those mistakesagainst them Between failed crypto implementations in ransomware to'license verification' of commercial malware tools, even malware softwaredevelopers suckThis talk will focus on several case studies, one being of AlienSpy JSocket and the design decisions made by the author that can be used to great effect to disable the malware world-wide The earlier version, AlienSpy, was knocked outworldwide forcing the developer to create an entire new version of the malware and have all his customers reinstall  potentially losing theirvictims  Others will be added for interesting current events For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600340.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600340.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Employee Hijacking  Building a hacktober awareness program</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Security awareness can be one of the driest and most boring topics for employee's You hate giving it, and they hate sitting through it Lets change that Learn how to create an annual Hacktober program that teaches employees important lessons, as you hack them all month long, in the name of security awareness Employees win prizes, and your human attack surface gets better prepared For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600339.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600339.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Securing the Distributed Workforce</title><description>2016-03-07 11:15:23 - SecurityTube.Net : A distributed workforce is becoming the trend as new companies start and take off, as well as existing companies expand Traditional and proven security principles do not always apply to this type of environment, thus requiring unique and creative solutions One of the challenges with a distributed workforce is the ability to protect end users as they perform day-to-day work and browse the deep wide internet  personal browsing habits  The ability to monitor end users and production systems becomes increasingly difficult as software and hardware are migrated from physical assets and virtualized into the cloud We have a unique deployment and workforce requiring different approaches to maintain a secure workforce This talk covers the gaps that exist and approaches we are taking and researching to maintain a safe and secure work environment For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600338.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600338.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Scan, Pwn, Next  - exploiting service accounts in Windows networks</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Service accounts are prevalent in Windows networks, but are often mismanaged and ripe for exploitation Too often these accounts are over-privileged, dual-used  both by human users and automated processes , and have credentials omnipresent in the network The services that use these accounts are easily discovered, as they are registered as SPNs on the Active Directory, thus presenting a lucrative target for an attackerIn this talk we will discuss how service accounts can be mismanaged and thus exploited, and present new research examining the exposure of service accounts in real-world networksWe will demonstrate exploitation techniques and introduce an open source tool for detecting potentially vulnerable service accounts in Windows networks We will also discuss how targeted behavioral analytics can be employed to detect potential abuse of service accountsArmed with the knowledge and tools from this presentation, you can now go and test your own networks   and, perhaps, prevent that sneaky attacker from exploiting your service accounts For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600337.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600337.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Guest to root - How to Hack Your Own Career Path and Stand Out</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Three security professionals walk into a bar A Security proTHAT Security proand THE security proI used to only be 'A' security pro - as a result I didn't get any of the recognition or reward I worked towards Not even my mother used to visit my blog In this talk, I distill some of the key skills and traits taken from personal experience as well as industry professionals to present strategies you can employ to increase your value internal to your organisation as well as in the industry For most, simply putting in the hours isn't enough to move up from being A security person to becoming THAT or even THE security person For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600336.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600336.shtml</guid></item>
<item><title>BSides San Francisco 2016 - IoT on Easy Mode  Reversing Embedded Devices </title><description>2016-03-07 11:15:23 - SecurityTube.Net : As technology matures we are seeing a trend of products that are now  smart  The problem is that once we discover how these devices are programmed we can see the flaws but unfortunately the hardware aspect scares some people away This talk is to show people how easy it really is to get into embedded device hacking while also expanding their knowledge outside of the x86 x86_64 space By the end of this talk the audience will be encouraged to go out and start their journey into the embedded device world while having the tools that they need without the need of spending money unless absolutely necessary This talk will also cover the reasoning behind purchasing products such as a logic analyzer and the bricks walls I personally went through to justify the needs For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600335.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600335.shtml</guid></item>
<item><title>BSides San Francisco 2016 - In the crosshairs  the trend towards targeted attacks</title><description>2016-03-07 11:15:23 - SecurityTube.Net : While we will never see the end of generalized mass attacks, the real damage is being done through highly targeted attacks I will discuss why targeted attacks are so effective and economically advantageous to the attacker and why that trend is likely to continue After considering several examples I will provide some suggestions for countermeasures against this strategy For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600334.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600334.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Developing a Rugged DevOps Approach to Cloud Security</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Your operational tools deliver continuous monitoring and alerting why doesn t your security suite  No single path exists to a rugged DevOps approach that works for every organization, but certain key principles and techniques are used by the DevOps elite that give them distinct advantages You can use these and revamp your organization s processes and behaviors to gain efficiencies in your security operations Security can no longer be thought of as being a separate step in a launch Instead, security must be integrated into the overall processes of development and deployment As organizations move more deeply into continuous patterns of development and deployment, the importance of implementing continuous security behaviors becomes non-negotiable Attendees will learn strategies to better understand their value to an attacker, how to better define the battlefield for their own advantage, how to identify potential Rugged DevOps allies within the organization, why it is time to embrace continuous security cycles and automate security acceptance tests as part of the QA process, and the value of operationalizing security alerts and remediation efforts to achieve a more agile security posture For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600333.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600333.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Digital Intelligence Gathering  Using the Powers of OSINT for Both Blue and Red Teams</title><description>2016-03-07 11:15:23 - SecurityTube.Net : In today's age everyone puts everything on the Internet Not only can this present a personal threat, it can also introduce tangential risk to your organization Seemingly innocent public displays of company pride, human error, and all-to-descriptive LinkedIn profiles are all interconnected pieces of information that can be leveraged by both attackers and defenders in the ongoing battle between red and blueIn this presentation we'll explain and demo how we've leveraged Twitter, Instagram, Google Maps, Whitepagescom, court case records and property records to automate and assist in OSINT discovery We have integrated it all together in a single custom application, coupled all this with the power of Maltego These custom transforms can easily be used to identify potential insider threats within your organization, prepare for a red team engagement, or to simply dox all your friends We will discuss the benefits of this information from both an attacker and defender s point of view For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600332.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600332.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Sharing is Caring  Understanding and measuring Threat Intelligence Sharing Effectiveness</title><description>2016-03-07 11:15:23 - SecurityTube.Net : For the last 18 months, MLSec Project and Niddel collected threat intelligence indicator data from multiple sources in order to make sense of the ecosystem and try to find a measure of efficiency or quality in these feeds This initiative culminated in the creation of Combine and TIQ-test, two of the open source projects from MLSec Project On this talk, we have gathered aggregated usage information from intelligence sharing communities in order to determine if the added interest and 'push' towards sharing is really being followed by the companies and if its adoption is putting us in the right track to close these gaps We propose a new set of metrics on the same vein as TIQ-test to help you understand what does a 'healthy' threat intelligence sharing community looks like, and how to improve the ones you may be a part of today  We will be conducting this analysis with usage data from some high-profile threat intelligence platforms and sharing communities For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600331.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600331.shtml</guid></item>
<item><title>BSides San Francisco 2016 - The Ransomware Threat  Tracking the Digital Footprints</title><description>2016-03-07 11:15:23 - SecurityTube.Net : The continuing evolution of ransomware is a constant threat to businesses of all types Taking a stroll through the timeline of ransomware from it's infancy to current variants, this session will walk through the methodologies for prevention, containment, and detection both inside the system and by following the digital footprints to hunt it in the wild For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600330.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600330.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Access Control in 2016 - deep dive</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Access control is undoubtedly a critical security mechanism, which is often managed as part of Identity   Access Management  IAM  Unfortunately current access control implementations are often quite crude  eg limited to role-based access and account provisioning  This is in contrast to the increasing complexity of the access policies that should actually be implemented - for example, required to meet regulationsAs a poor man s way out, organizations today resort to implementing basic access control mechanisms to meet compliance requirements  eg  least privilege    but these mechanisms are often too coarse and static to be effective  eg  least privilege  is much more than privileged account management In fact access control comprises many different, often not so well-understood approaches, which should be used by InfoSec professionals and developers to make access control more effective, and manageable while at the same time being technically implementable Advanced access control approaches are often criticized for being unmanageable, unimplementable, or too costly In this quite technical session you will learn  why access control policy implementation in 2016 is more complex than you may think, why traditional access control mechanisms are often insufficient, which new approaches are available, and are suitable for what IT business environment For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600329.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600329.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Using Behavior to Protect Cloud Servers</title><description>2016-03-07 11:15:23 - SecurityTube.Net : Cloud server adoption has exploded in the last 5 years Nearly every business is using some kind of IaaS, PaaS platform Securing these cloud servers is challenging The ease of access by developers, contractors, web admins and more needs to be balanced with security Using rule based access security can only go so far Once SSH keys and tokens are compromised, an attacker can wreak havocBehavior based real time analytics can help create a dynamic fingerprint of an automated service like Jenkins or of an employee We will show an example of dynamic privilege management to identify and stop insider threats and privilege escalation attacks in real time See how you can apply next generation privilege management principles to secure your assets For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600328.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600328.shtml</guid></item>
<item><title>BSides San Francisco 2016 - The Art of the Jedi Mind Trick</title><description>2016-03-07 11:15:23 - SecurityTube.Net : The hacker security community continues to struggle with how to get our message across to others We know what's wrong, what's insecure, and what needs to be done to fix the problems BUTwe seem to hear more stories about failure rather than success stories Maybe WE are part of the problem It's easy to give a talk at a conference where you're 'preaching to the choir' and everyone speaks your language, but how do you fare when you are trying to give the message to your boss, or your bosses' boss, or C-Level management  This talk will explore a variety of techniques that I ve learned over my 20  years of consulting advising customers about how to get the right message to the right people so real change happens I'll explore obstacles, attitudes, and challenges that I've faced in hundreds of companies  practical methods for getting your point across  helping others to understand what you are saying  learning to speak their language  and helping them to draw the desired conclusion This is part art, part science, and maybe a little luck - but I believe there are skills you can learn that will make you a successful communicator and get your message heard For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600327.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600327.shtml</guid></item>
<item><title>Reversing Type 7 Cisco Passwords</title><description>2016-03-04 23:58:34 - Security Bloggers Network : While working on a recent pen test, I came across a few Cisco routers sitting on an internal network The fact that they were using default cisco cisco credentials made me   </description><link>http://www.secuobs.com/revue/news/600217.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600217.shtml</guid></item>
<item><title>Cisco patches severe default password security issue in network hardware</title><description>2016-03-04 13:04:42 - Security Bloggers Network : Cisco has patched another hard-coded, default password problem which gives cyberattackers root access to devices </description><link>http://www.secuobs.com/revue/news/600166.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600166.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Keynote  A Declaration of the Independence of Cyberspace</title><description>2016-03-04 09:24:06 - SecurityTube.Net : John Perry Barlow BSides San Francisco 2016 John Perry Barlow will read his 'A Declaration of the Independence of Cyberspace' and answer Q A about it and about EFF's founding For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600146.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600146.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Reverse Engineering the Wetware  Understanding Human Behavior to Improve Information Security</title><description>2016-03-04 09:24:06 - SecurityTube.Net : Alexandre Sieira, Matthew Hathaway BSides San Francisco 2016 The human mind evolved to draw quick conclusions for survival Behavioral economists, like Daniel Kahneman and Dan Ariely, are publishing research on when, why and how decision making can be consistently and predictably irrational You could say these researchers are reverse engineering the wetware, finding bugs and race conditions and disclosing themPeople are key to an organization s information security, even if you believe in the  people, processes and technology  tripod People define and execute processes People decide funding for, implement, operate and or monitor the technology Your adversaries are people At least until we reach the AI singularity, that isUntil then, the aim of this talk is to present some of the counter-intuitive findings of behavioral economics research and their implications for how information security is handled at the organizational and market levels Our hope is that the audience will find they could benefit from changing established, seemingly sensible and logical actions we all do to better match how the wetware actually works For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600145.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600145.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Who's Breaking into Your Garden  iOS and OS X Malware You May or May Not Know</title><description>2016-03-04 09:24:06 - SecurityTube.Net : Apple platforms were thought far away from malware problem in a long term, until at least 21 and 27 new malware or adware families on iOS and OS X were discovered in the past two years Some of these have led to the theft of hundreds of thousand of password  the KeyRaider  or hundreds of million of infections worldwide  the XcodeGhost  This topic will discuss the primary spreading and attack techniques used by these real world malware as well as their common characteristics, and identify trends around these topics The security industry can use this information to build more effective solutions to detect and to defeat similar threats in near future We will discuss with case studies on  attacking non-jailbroken iOS devices, bypassing App Store code review, infecting compilers and libraries, escalating privileges or executing code remotely via zero day vulnerabilities, attacking specific targets via commercial or customized Spyware, attacking multiple platforms or crossing platforms, making profit from advertisers by stealing revenue, and hunting Apple IDs for various evil purposes For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600144.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600144.shtml</guid></item>
<item><title>BSides San Francisco 2016 - A year in the wild  fighting malware at the corporate level</title><description>2016-03-04 09:24:06 - SecurityTube.Net : Yelp as any large company has a problem with viruses, malware and organized phishing campaigns targeting our corporate network and our employees We have assembled a set of tools and processes to stop the pests from infecting our networkFrom the moment of the threat detection, first response throughout the analysis, and the final resolution, we make sure that we can catch as many incidents as possible and properly sanitize the environment so that the potential problems are cut short All this in an automated and orchestrated fashion, eliminating the manual repetition as much as possible thanks to the in-house built tools like AIR  Automated Incident Response , OSXCollector  Mac OS X forensics collection  and ElastAlert  alerting out of Elasticsearch  We also compliment the pipeline with some available open source tools, like osquery and other proprietary threat detection technologies This adds up to a balanced ecosystem that helps us leverage the current assets, learn about the potential problems quickly and respond to them in a timely fashion For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600143.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600143.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Breaking Honeypots for Fun and Profit</title><description>2016-03-04 09:24:06 - SecurityTube.Net : This talk analyzes the concept of the Honeypot, its weaknesses, and how a better honeypot can be constructed For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600142.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600142.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Everything Is Awful  And You're Not Helping </title><description>2016-03-04 09:24:06 - SecurityTube.Net : Shamir's Three Laws of Security have been known for quite some time now - Absolutely secure systems do not exist- To halve your vulnerability, you have to double your expenditure- Cryptography is typically bypassed, not penetratedLikewise for Morris's Three Golden Rules of Computer Security - do not own a computer - do not power it on - and do not use itBut, it appears, we suck at heeding such good advice Stories of failure,ranging from small to epic, let me tell you them Perhaps they even havesomething in common, some sort of moral or lessons we might learn Something uplifting that helps those of us not completely ground topieces by our own cynicism  Naaah, unlikely But a man can dream,though, a man can dream For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600141.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600141.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Why it's all snake oil - and that may be ok</title><description>2016-03-04 09:24:06 - SecurityTube.Net : Every few years, security vendors entice us with  next generation  security products with 0day detection and we must decide if this product will be our salvation or if it s more snake oil full of empty promises Basic theorems of computer science mathematically guarantee that many of the claims made by sales are false without certain allowances, but that doesn t mean that the products are useless Understand how to ask the right questions to determine if a security vendors assumptions are valid for your organization Take a walk through the history of exploitation and computer science theorems to learn how to have an honest conversation about security products and their capabilities For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600140.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600140.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Ask the EFF</title><description>2016-03-04 09:24:06 - SecurityTube.Net : Ask the EFF is a Q A panel with EFF staffers, with short presentations on EFF's ongoing work, then opening the floor for questions from the audience For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600139.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600139.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Sedating the Watchdog  Abusing Security Products to Bypass Windows Protections</title><description>2016-03-04 09:24:06 - SecurityTube.Net : A few months ago, we came across a critical vulnerability in a popular security product that could act as a vehicle for a threat actor to bypass the protections of the underlying Windows system This was only the tip of the icebergA deeper research revealed this issue to be present in a multitude of common Anti-Virus  AV  products This was not something to ignore In fact, we can assume that apart from AV products, other security products such as Data Loss Prevention  DLP  and other intrusive non-security related products such as app-performance solutions, may potentially rely on this malpracticeMaking matters worse, we found a second malpractice in intrusive products which simplifies the process for threat actors to run their exploitsDuring the following few months we notified popular vendors and collaborated with them on a solution In a coordinated effort, various vendors have fixed their products and released the necessary patches In this talk we reveal a detailed description of the vulnerability and its impact Additionally, we release a tool that the audience can use to validate whether their systems are now secure from this vulnerability For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600138.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600138.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Sweet Security  Deploying a Defensive Raspberry Pi</title><description>2016-03-04 09:24:06 - SecurityTube.Net : Securing the Internet of Things  IoT  has become increasingly difficult Devices are often shipped with out-of-date operating systems and unmaintained code, which is littered with vulnerabilities To add to the frustration, traditional security tools cannot be installed on many of these devices This presentation will demonstrate how open-source software, along with various other free tools, can be used to monitor, protect and mitigate against threats to IoT environments The session will explore how all of these technologies and methods can be deployed on inexpensive hardware, such as the Raspberry Pi For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600137.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600137.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Planning Effective Red Team Exercises</title><description>2016-03-04 09:24:06 - SecurityTube.Net : An effective red team exercise is substantially different from a penetration test, and it should be chartered differently as well The scenario, objective, scope, and rules of engagement all need to be positioned correctly at the beginning in order to most closely simulate a real adversary and provide maximum value to the clientIn this presentation, we ll review best practices in each of these areas, distilled from conducting dozens of successful red team exercises - along with some war stories highlighting why each element matters Those in offensive security will gain an understanding of how to manage the client s expectations for this process, and how to guide them towards an engagement that provides a realistic measurement of their ability to prevent, detect, and respond to real attacks Those in enterprise security will gain a deeper understanding of this style of assessment, and how to work with a red team to drive real improvement in their security programs For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600136.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600136.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Fraud Detection and Real-time Trust Decisions</title><description>2016-03-04 09:24:06 - SecurityTube.Net : Fraud detection and computer security have a number of interesting parallels as adversarial   technological ecosystems where systems have exploits and attack surfacesWith the advent of the on-demand economy, the window of time between purchase and service delivery -- the period during which businesses can typically aim to identify fraudulent activity -- is becoming shorter and shorterI'll present a summary of the common ways which in which fraudsters attack online commerce - starting with traditional online storefront attacks, and moving on to the challenges faced in realtime marketplacesI'll explain a number of the techniques and technologies employed in combating online fraud, and draw parallels with traditional network and application security practices For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600135.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600135.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Fuzz Smarter, Not Harder  An afl-fuzz Primer </title><description>2016-03-04 09:24:06 - SecurityTube.Net : Fuzz testing is one of the most powerful tools in the bug hunter s toolset However, many fuzzing platforms require a lot of hard work to first describe a targeted format or protocol These tools also often require a lot of resources, time, or both American Fuzzy Lop  afl-fuzz  from Michal Zalewski  lcamtuf  overcomes these challenges with novel code instrumentation techniques combined with a highly optimized forking process This talk steps through an entire process for using afl-fuzz and other tools like address sanitizer  ASAN  and  exploitable to identify and classify exploitable software bugs Specific example steps for building and fuzzing AFL instrumented Ubuntu packages will allow attendees to quickly start finding 0-days in software deployed on millions of computers world-wide For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600134.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600134.shtml</guid></item>
<item><title>BSides San Francisco 2016 - Elliptic Curve Cryptography for those who are afraid of mathematics</title><description>2016-03-04 09:24:06 - SecurityTube.Net : To fully understand Elliptic Curve Cryptography to a point where you could use it in practice, you would need to spend years inside university lecture rooms to study number theory, geometry and software engineering And then you can probably still be fooled by a backdoored implementationI won't be able to change that in a short talk What I will do, however, is explain the basics of ECC I'll skip over the gory maths  it will help if you can add up, but that's about the extent of it  and explain how this funny thing referred to as 'point addition on curves' can be used to exchange a secret code between two entities over a public connectionI will also explain how the infamous backdoor in Dual_EC_DRGB  a random number generator that uses the same kind of maths  worked and what went on at JuniperAt the end of the presentation, you'll still not be able to find such backdoors yourselves and you probably realise you never will But you will be able to understand articles about ECC a little better And, hopefully, you will be convinced it is important that we educate more people  possibly you  to become ECC-experts For More Information Please Visit - https bsidessfcom http wwwirongeekcom iphp page videos bsidessf2016 mainlist </description><link>http://www.secuobs.com/revue/news/600133.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600133.shtml</guid></item>
<item><title>Cisco Issues Patch For Nexus Switches To Remove Hardcoded Credentials</title><description>2016-03-03 23:51:48 - Slashdot  Your Rights Online : itwbennett writes  Cisco Systems has released critical software updates for its Nexus 3000 and 3500 switches to remove a default administrative account with static credentials that could allow remote attackers access to a bash shell with root privileges, meaning that they can fully control the device The account is created at installation time by the Cisco NX-OS software that runs on these switches and it cannot be changed or deleted without affecting the system's functionality, Cisco said in an advisory The affected devices are  Cisco Nexus 3000 Series switches running NX-OS 60 2 U6 1 , 60 2 U6 2 , 60 2 U6 3 , 60 2 U6 4  and 60 2 U6 5  and Cisco Nexus 3500 Platform switches running NX-OS 60 2 A6 2 , 60 2 A6 3 , 60 2 A6 4 , 60 2 A6 5  and 60 2 A7 1   IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/600109.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600109.shtml</guid></item>
<item><title>Cisco removes weak default static credentials from its switches</title><description>2016-03-03 14:15:45 - Help Net Security : Cisco has released on Wednesday a bucketload of software updates for a wide variety of its products, fixing vulnerabilities of different types and severity But one is deemed critical  default static passwords have been found on the company s Nexus 3000 Series Switches and Nexus 3500 Platform Switches The flaw affects the Cisco NX-OS Software running on those devices, and could be exploited by an unauthenticated, remote attacker to log in to the device with the   More   </description><link>http://www.secuobs.com/revue/news/600031.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600031.shtml</guid></item>
<item><title>DistriWAN reçoit la récompense du meilleur grossiste Cisco France </title><description>2016-03-02 14:49:12 - Global Security Mag Online : La conférence annuelle organisé par Cisco a été l'occasion de récompenser par pays et par région les intégrateurs et les distributeurs Attribués aux partenaires Channel Cisco les plus performants, les prix du Cisco Partner Summit sont conçus pour récompenser les meilleures pratiques commerciales, innovations et succès dans des zones géographiques et dans les secteurs technologiques respectifs A cette occasion, DistriWAN a eu le plaisir de se voir décerner la récompense de   meilleur grossiste France    - Business </description><link>http://www.secuobs.com/revue/news/599903.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/599903.shtml</guid></item>
<item><title>BSides San Francisco 2016 Highlights   Day One</title><description>2016-02-29 11:25:27 - Security Bloggers Network :    This year s conference in the beautiful city of San Francisco started off with a bang Bright and early on a Sunday morning, a huge crowd gathered at the DNA Lounge to hear from industry leaders, innovators and aficionados It s always inspiring to see how tight-knit and supportive the security community is, and BSides   an   Read More The post BSides San Francisco 2016 Highlights   Day One appeared first on The State of Security  IMAGE  </description><link>http://www.secuobs.com/revue/news/599626.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/599626.shtml</guid></item>
<item><title>Cisco renforce la sécurité des réseaux avec son pare-feu de nouvelle génération centré sur la menace</title><description>2016-02-17 11:10:41 - Global Security Mag Online : Alors que les entreprises profitent des avantages de la transformation numérique, la cybersécurité reste l'une de leurs préoccupations majeures et dont Cisco a fait l'une de ses priorités Cisco annonce des améliorations majeures apportées à son pare-feu de nouvelle génération, dont l'objectif est de renforcer encore un peu plus la protection des réseaux des entreprises Le NGFW Cisco Firepower, premier pare-feu du marché entièrement intégré et centré sur la menace, marque une évolution importante par    - Produits </description><link>http://www.secuobs.com/revue/news/598520.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598520.shtml</guid></item>
<item><title>Radware, partenaire de Cisco pour l'intégration de solution de mitigation des attaques DDoS</title><description>2016-02-17 11:10:41 - Global Security Mag Online : Les récentes attaques de la banque HSBC au Royaume-Unis ou de l'ANSSI en France ont démontré l'importance de considérer les attaques DDoS dans l'élaboration d'un système de sécurité informatique Cisco a annoncé aujourd'hui sa nouvelle génération de Firewall   le Cisco Firepower  Next-Generation Firewall Par son ouverture, cette gamme permet d'intégrer les technologies de fournisseurs tiers en partageant notamment des informations et du contexte Il en résulte une meilleure détection et un traitement plus    - Business </description><link>http://www.secuobs.com/revue/news/598518.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598518.shtml</guid></item>
<item><title>Critical bug found in Cisco ASA products, attackers are scanning for affected devices</title><description>2016-02-14 20:19:52 - Help Net Security :    Several Cisco Adaptive Security Appliance  ASA  products   appliances, firewalls, switches, routers, and security modules   have been found sporting a flaw that can ultimately lead to remote code execution by attackers The vulnerability  CVE-2016-1287  is critical, as it can be exploited by an unauthenticated, remote attacker by sending crafted UDP packets to the affected system Cisco ASA Software is affected if the system is configured to terminate Internet Key Exchange  IKE  v1 or IKE   More   The post Critical bug found in Cisco ASA products, attackers are scanning for affected devices appeared first on Help Net Security </description><link>http://www.secuobs.com/revue/news/598264.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598264.shtml</guid></item>
<item><title>Patch Your Cisco ASA s ASAP </title><description>2016-02-12 17:38:42 - MSI   State of Security :    Many networks employ Cisco Adaptive Security Appliances  ASA  as firewalls or to set up Virtual Private Networks, etc Those of you that are among this group should be aware that Cisco published a critical security advisory on February 10 concerning   Continue reading   The post Patch Your Cisco ASA s ASAP  appeared first on MSI   State of Security </description><link>http://www.secuobs.com/revue/news/598171.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598171.shtml</guid></item>
<item><title>How to Choose a Cisco ASA 5500-X Series</title><description>2016-02-12 15:55:55 - Security Bloggers Network :    Photo Credit  Aaron Paxson via Flickr CC The Cisco ASA  Adaptive Security Appliance  is a family of enterprise-level firewalls for a network security infrastructure When it comes to the ASA appliances, there are tons of models to sort through, all with different features This post will compare several models in the ASA 5500-X series and offers   The post How to Choose a Cisco ASA 5500-X Series appeared first on Phoenix TS </description><link>http://www.secuobs.com/revue/news/598160.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598160.shtml</guid></item>
<item><title>How to Basically Configure a Cisco Router RV320</title><description>2016-02-11 17:51:57 - Security Bloggers Network :    Photo Credit  Purple Slog via Flickr CC Want to learn the basics of setting up a Cisco RV32X series router  Today I ll be working with a RV320 Gigabit Dual WAN VPN router, but the steps will be the same for any router that falls in the RV32X family First of all, I m going to assume you already   The post How to Basically Configure a Cisco Router RV320 appeared first on Phoenix TS </description><link>http://www.secuobs.com/revue/news/598060.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598060.shtml</guid></item>
<item><title> Critical bug found in Cisco ASA products, attackers are scanning for affected devices</title><description>2016-02-11 11:49:14 - Help Net Security : Several Cisco Adaptive Security Appliance  ASA  products - appliances, firewalls, switches, routers, and security modules - have been found sporting a flaw that can ultimately lead to remote code exec </description><link>http://www.secuobs.com/revue/news/598012.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598012.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Service Catalog   élévation de privilèges via Configuration Change, analysé le 08 12 2015</title><description>2016-02-10 16:28:25 - Vigilance   vulnérabilités publiques : Un attaquant peut éditer la configuration de Cisco Prime Service Catalog, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/597908.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597908.shtml</guid></item>
<item><title>Vigilance - Cisco Unified Communications Manager   usurpation d'identité via MRA, analysé le 10 12 2015</title><description>2016-02-10 16:28:25 - Vigilance   vulnérabilités publiques : Un attaquant peut contourner l'identification de Cisco Unified Communications Manager avec le service MRA, afin d'usurper l'identité d'un équipement </description><link>http://www.secuobs.com/revue/news/597899.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597899.shtml</guid></item>
<item><title>Vigilance - Cisco Unity Connection   Cross Site Request Forgery, analysé le 10 12 2015</title><description>2016-02-10 16:28:25 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Request Forgery de Cisco Unity Connection, afin de forcer la victime à effectuer des opérations </description><link>http://www.secuobs.com/revue/news/597898.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597898.shtml</guid></item>
<item><title>Vigilance - Cisco IP Phone   changement de firmware sur SPA30X SPA5xX, analysé le 10 12 2015</title><description>2016-02-10 16:28:25 - Vigilance   vulnérabilités publiques : Un attaquant local peut modifier le firmware de Cisco IP Phone modèle SPA30X, SPA50X ou SPA51X, afin d'y exécuter du code </description><link>http://www.secuobs.com/revue/news/597897.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597897.shtml</guid></item>
<item><title>Vigilance - Cisco Unity Connection   Cross Site Request Forgery, analysé le 10 12 2015</title><description>2016-02-10 10:54:19 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Request Forgery de Cisco Unity Connection, afin de forcer la victime à effectuer des opérations </description><link>http://www.secuobs.com/revue/news/597835.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597835.shtml</guid></item>
<item><title>Vigilance - Cisco IP Phone   changement de firmware sur SPA30X SPA5xX, analysé le 10 12 2015</title><description>2016-02-10 10:54:19 - Vigilance   vulnérabilités publiques : Un attaquant local peut modifier le firmware de Cisco IP Phone modèle SPA30X, SPA50X ou SPA51X, afin d'y exécuter du code </description><link>http://www.secuobs.com/revue/news/597834.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597834.shtml</guid></item>
<item><title>Vigilance - Cisco Unified Communications Manager   usurpation d'identité via MRA, analysé le 10 12 2015</title><description>2016-02-10 09:06:21 - Vigilance   vulnérabilités publiques : Un attaquant peut contourner l'identification de Cisco Unified Communications Manager avec le service MRA, afin d'usurper l'identité d'un équipement </description><link>http://www.secuobs.com/revue/news/597828.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597828.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Service Catalog   élévation de privilèges via Configuration Change, analysé le 08 12 2015</title><description>2016-02-08 16:01:55 - Vigilance   vulnérabilités publiques : Un attaquant peut éditer la configuration de Cisco Prime Service Catalog, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/597653.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597653.shtml</guid></item>
<item><title>Vigilance - Cisco Unity Connection   Cross Site Scripting de Management Interface, analysé le 03 12 2015</title><description>2016-02-03 13:20:38 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Scripting dans Management Interface de Cisco Unity Connection, afin d'exécuter du code JavaScript dans le contexte du site web </description><link>http://www.secuobs.com/revue/news/597229.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597229.shtml</guid></item>
<item><title>Vigilance - Cisco Web Security Appliance   boucle infinie de FTP Proxy, analysé le 01 12 2015</title><description>2016-02-01 16:35:54 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une boucle infinie dans le proxy FTP de Cisco Web Security Appliance, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/597044.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597044.shtml</guid></item>
<item><title>Vigilance - Cisco IOS-XE 3S   élévation de privilèges, analysé le 01 12 2015</title><description>2016-02-01 16:35:54 - Vigilance   vulnérabilités publiques : Un attaquant authentifié peut injecter une commande sur Cisco IOS-XE 3S, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/597043.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597043.shtml</guid></item>
<item><title>San Francisco Bay Area In Superbowl Surveillance Mode</title><description>2016-02-01 14:37:52 - Slashdot  Your Rights Online : An anonymous reader links to Wired's description of a surveillance society in miniature assembling right now in San Francisco  Super Bowl 50 will be big in every way A hundred million people will watch the game on TV Over the next ten days, 1 million people are expected to descend on the San Francisco Bay Area for the festivities And, according to the FBI, 60 federal, state, and local agencies are working together to coordinate surveillance and security at what is the biggest national security event of the year Previous year's Superbowl security measures have included WMD sensors, database-backed facial recognition, and gamma-ray vehicle scanners Given the fears and cautions in the air about this year's contest, it's easy to guess that the scanning and sensing will be even more prevalent this time  IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/597034.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597034.shtml</guid></item>
<item><title>The Cisco 2016 Annual Security Report  where did 2015 take us </title><description>2016-02-01 13:29:15 - Web Application Security Blog   Acunetix :    Cisco have just published their 2016 Annual Security Report, which covers the last year in cyber security while also looking ahead to growing threats Particularly interesting is the Threat Intelligence section, which examines some of the most common exploits, malware kits and targeted industries in 2015 Naturally Adobe Flash is quite a prominent feature in   Read More   The post The Cisco 2016 Annual Security Report  where did 2015 take us  appeared first on Acunetix </description><link>http://www.secuobs.com/revue/news/597030.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597030.shtml</guid></item>
<item><title>San Francisco Recruits Three California Cities for Regional  Startup in Residence  Program</title><description>2016-01-29 04:41:17 - Security Bloggers Network : Startupinresidenceorg Building on a program from 2014, the San Francisco Mayor's Office of Civic Innovation announced during a Jan 28 press conference the 2016 Startup in Residence program that includes a regional partnership with the neighboring cities of Oakland, San Leandro and West Sacramento Selected startups will work with city departments to solve challenges around housing, transportation, the environment, public safety and public experience through the creation of new technologies developed during a 16-week residency And this isn't a one-off, San Francisco officials said   they're building toward a national and global effort to encourage startup investment in the govtech market  When we look at the transformation happening in nearly every industry and sector, startups are leading the way,  San Francisco Chief Innovation Officer Jay Nath said during the event  Yet the public sector is one of the few remaining areas that have yet to be transformed by startups We believe one of the most critical barriers for entrepreneurs is not understanding the needs of government organizations  In 2014, San Francisco experimented with a four-month Entrepreneurship in Residence program that paired six civic tech startups with city departments to craft new technologies aimed at improving government Smartphone apps, predictive analytics platforms and notification systems were among the technologies developed, and two companies won contracts through a formal procurement with the city At the start of that program, the city was surprised and encouraged by the outpour of participation from around the world as San Francisco received applications from more than 200 startups from 25 cities and countries, Nath said   and the city is now building on this model A  474,453 allocation from a  10 million three-year grant from the US Department of Commerce is allowing San Francisco to scale its program regionally, said Jeremy Goldberg, Startup in Residence program director Through this iteration of the program, startups will develop new technologies that improve cities, Goldberg said, but they're also compiling a repository of resources and methodology that for cities around the world to use  Following the program, all of the education and learning and experience we're developing now will become part of a blueprint and a guide for other cities that seek to participate and develop a version of the Startup in Residence to access that information,  Goldberg said during the press conference The program website lists 27 challenges to which startups can apply before the deadline of Feb 18 They include projects like helping cities improve the process of recruiting foster parents, creating mobile apps for government inspectors to ensure post-disaster assessments are safe, and installing sensors in garbage cans to help cities meet their goal of reduced waste and increased efficiency Organizers will select startups that best match the challenges presented, Nath said, and if no one applies to a given challenge, it may not be pursued He guessed that when the program begins in March, each city would end up with between three and six startups under its tutelage It's about quality, Nath said, not quantity Selected startups will get training on how government works, what its challenges are and which government workers to talk to get things done When the program completes in July, startups will have a chance to sell their technology to government through a streamlined procurement process that Nath said the city hopes will encourage more startups to give the growing govtech sector a chance  This is another way to address a barrier that startups are facing, which is lengthy and complex procurement processes that often require a number of legal resources and know-how that many startups don't have,  Nath said  Government, broadly, is a huge commercial opportunity There's tens of billions of dollars, and internationally hundreds of billions of dollars  and yet the ecosystem is mostly large players, so how do we bring entrepreneurs into that ecosystem  And this is one program that's trying to tackle that challenge  In September, each city will host a demo day to showcase the technologies developed by each startup, and a regional demo day will feature the best products from each city Interested startups can apply by visiting the program website at startupinresidenceorg </description><link>http://www.secuobs.com/revue/news/596818.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596818.shtml</guid></item>
<item><title> Cisco plugs hole in firewall devices that could lead to device hijacking</title><description>2016-01-28 12:54:02 - Help Net Security : Cisco has released a firmware update that plugs a critical, easy-to-exploit vulnerability that could allow a remote attacker to take control of the company's RV220W Wireless Network Security Firewall  </description><link>http://www.secuobs.com/revue/news/596741.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596741.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 5000   déni de service via Telnet, analysé le 26 11 2015</title><description>2016-01-26 13:59:39 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet Telnet malveillant vers Cisco ASR 5000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/596513.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596513.shtml</guid></item>
<item><title>Vigilance - Cisco ASA   déni de service via XML Parser, analysé le 24 11 2015</title><description>2016-01-24 19:11:41 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer des données XML malveillantes vers Cisco ASA Management Interface, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/596368.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596368.shtml</guid></item>
<item><title>Cisco Security Report  Majority of Orgs Do Not Monitor DNS</title><description>2016-01-21 15:24:59 - OpenDNS Blog :    Cisco s annual security report released this week, covering everything from threat intelligence, aging infrastructure, geopolitical Internet governance, outsourcing security, and many other topics The comprehensive report is a view of the security landscape, including results from a large survey that aims to take the pulse of infosec organizations and how they are spending budget and   The post Cisco Security Report  Majority of Orgs Do Not Monitor DNS appeared first on OpenDNS Blog </description><link>http://www.secuobs.com/revue/news/596132.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596132.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Collaboration Assurance   Cross Site Request Forgery, analysé le 17 11 2015</title><description>2016-01-17 09:32:06 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Request Forgery de Cisco Prime Collaboration Assurance, afin de forcer la victime à effectuer des opérations </description><link>http://www.secuobs.com/revue/news/595781.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595781.shtml</guid></item>
<item><title>Vigilance - Cisco Aironet 1800   déni de service via SSHv2, analysé le 16 11 2015</title><description>2016-01-16 11:55:53 - Vigilance   vulnérabilités publiques : Un attaquant non authentifié peut tenter d'ouvrir de nombreuses sessions SSHv2 sur Cisco Aironet 1800, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/595759.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595759.shtml</guid></item>
<item><title>Vigilance - Cisco IOS   contournement des ACL Virtual PPP, analysé le 16 11 2015</title><description>2016-01-16 11:16:06 - Vigilance   vulnérabilités publiques : Un attaquant peut contourner les ACL sur les interfaces virtuelles PPP de Cisco IOS lorsque les ACL sur les interfaces physiques sont ouvertes, afin d'accéder à des services réseaux normalement interdits </description><link>http://www.secuobs.com/revue/news/595756.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595756.shtml</guid></item>
<item><title>Raising awareness  Cisco takes aim at shadow IT</title><description>2016-01-15 23:00:54 - Security Bytes :    Most people have encountered the cloud at work, whether it s downloading files from an external business contact s Dropbox or hearing through the grapevine that your department is now  moving  to a cloud service Security controls in many of these initiatives is handled  you hope  by someone at the company who is setting policy about these rollouts The post Raising awareness  Cisco takes aim at shadow IT appeared first on Security Bytes </description><link>http://www.secuobs.com/revue/news/595741.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595741.shtml</guid></item>
<item><title>Login People  rejoint la French Tech San Francisco</title><description>2016-01-14 18:44:37 - Global Security Mag Online : Login People  rejoint l'écosystème French Tech San Francisco Le 9 janvier 2016, le Ministre de l'Économie, de l'Industrie et du Numérique, Emmanuel Macron a officiellement lancé la French Tech San Francisco par un   Welcome on Board French Tech San Francisco     Après New-York, Israël et Tokyo, le réseau de French Tech Hubs s'étend sur la côte ouest américaine et a pour ambition de permettre aux start-up françaises telles que Login People   d'être visible et identifiée au sein de l'écosystème de San    - Business </description><link>http://www.secuobs.com/revue/news/595662.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595662.shtml</guid></item>
<item><title> Cisco kills hardcoded password bug in Wi-Fi access points </title><description>2016-01-14 13:50:25 - Help Net Security : Along with fixes for a number of older vulnerabilities in Cisco IOS and IOS XE software, the Cisco IOS Software Common Industrial Protocol, and the OpenSSL package incorporated in multiple company pro </description><link>http://www.secuobs.com/revue/news/595633.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595633.shtml</guid></item>
<item><title>EFF  Cisco Shouldn't Get Off the Hook For Aiding Torture In China</title><description>2016-01-13 17:14:14 - Slashdot  Your Rights Online : itwbennett writes  In a lawsuit in Northern California that was dismissed in 2014, Falun Gong practitioners alleged that Cisco Systems built a security system, dubbed  Golden Shield,  for the Chinese government knowing it would be used to track and persecute members of the religious minority That case is being appealed, and on Monday the EFF, Privacy International and free-speech group Article 19 filed a brief that supports the appeal Many US and European companies sell technology to regimes that violate human rights, and if this case goes to trial and Cisco loses, they may think twice, said EFF Staff Attorney Sophia Cope  In a lot of instances, these companies are selling directly to the government, and they know exactly what is going to be happening,  Cope said  IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/595565.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595565.shtml</guid></item>
<item><title>EFF says Cisco shouldn't get off the hook for torture in China</title><description>2016-01-13 15:14:15 - LinuxSecurity.com   Latest News : LinuxSecuritycom  Cisco Systems built a security system for the Chinese government knowing it would be used to track and persecute members of the Falun Gong religious minority, according to the Electronic Frontier Foundation technology rights group </description><link>http://www.secuobs.com/revue/news/595553.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595553.shtml</guid></item>
<item><title>Vigilance - Cisco IOS   contournement des ACL de tunnels, analysé le 13 11 2015</title><description>2016-01-13 09:03:37 - Vigilance   vulnérabilités publiques : Un attaquant peut contourner les ACL sur les interfaces tunnels de Cisco IOS lorsque les ACL sur les interfaces physiques sont ouvertes, afin d'accéder à des services réseaux normalement interdits </description><link>http://www.secuobs.com/revue/news/595517.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595517.shtml</guid></item>
<item><title>Uncooperative Russian ISP Prevents Cisco From Shutting Down Cybercriminal Gang</title><description>2016-01-09 15:44:45 - Slashdot  Your Rights Online : An anonymous reader writes  Cisco's Talos research team has managed to identify and partially shut down a cyber-criminal group that is using the RIG exploit kit to infect users with spambots via a malvertising campaign Their investigation led them back to Russian ISP Eurobyte, who didn't bother answering critical emails and allowed the campaign to go on even today In October 2015, Cisco's researchers also thwarted the activity of another group of cyber-criminals that made around  30 million from distributing ransomware  IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/595236.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595236.shtml</guid></item>
<item><title>Netsparker Heading to RSA Conference 2016 in San Francisco</title><description>2016-01-06 18:03:12 - Netsparker  Web Application Security Scanner :    Visit the Netsparker Booth at RSA 2016 in San Francisco, USA This year Netsparker will be exhibiting at the RSA Conference in San Francisco, USA The event will be held from February 29th to March 4th at the Moscone Centre Several Netsparker team members will be representing Netsparker at stand  N4326, and will be available to answer any questions you might have about automatically detecting SQL injection, XSS and other vulnerabilities with our web application security scanners Netsparker Desktop and Netsparker Cloud Visit the RSA Conference website for a copy of the agenda and for more information about the workshops and tracks that will be held Register for a Free Complementary Hall Pass at RSA Conference 2016 ------------------------------------------------------------------ Click here and use the code XENETSPRK16 during the registration process for a free complementary hall pass Don't forget to drop by our stand  N4326, for more information on how Netsparker can help you find vulnerabilities in your websites before a hacker does If you do not have any questions, you should still pass by to say hello Last year s merchandise was a big hit, so come and check out the goodies we have for this year Looking forward to meeting you there   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/594998.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594998.shtml</guid></item>
<item><title> Cisco Jabber flaw allows MitM attackers to wiretap communications</title><description>2016-01-04 15:57:29 - Help Net Security : A vulnerability in Cisco's Jabber client for Windows can be exploited by attackers to wiretap communications, steal user credentials, and to tamper with messages sent between the client and the Jabber </description><link>http://www.secuobs.com/revue/news/594761.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594761.shtml</guid></item>
<item><title>Vigilance - Cisco IOS XE   déni de service via IPv6 Neighbor Discovery, analysé le 15 12 2015</title><description>2015-12-30 11:07:03 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer de nombreux paquets IPv6 Neighbor Discovery vers Cisco IOS XE, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/594469.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594469.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Service Catalog   injection SQL, analysé le 29 10 2015</title><description>2015-12-29 09:40:40 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une injection SQL de Cisco Prime Service Catalog, afin de lire ou modifier des données </description><link>http://www.secuobs.com/revue/news/594357.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594357.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 5500   déni de service via BGP, analysé le 29 10 2015</title><description>2015-12-29 09:05:00 - Vigilance   vulnérabilités publiques : Un attaquant, distant non identifié, peut générer des paquets BGP pour Cisco ASR 5500, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/594355.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594355.shtml</guid></item>
<item><title>Vigilance - Cisco ASA CX Context-Aware Security   obtention d'information via Web GUI, analysé le 28 10 2015</title><description>2015-12-28 18:28:32 - Vigilance   vulnérabilités publiques : Un attaquant peut utiliser une vulnérabilité dans Cisco ASA CX Context-Aware Security, afin d'obtenir des informations sensibles </description><link>http://www.secuobs.com/revue/news/594296.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594296.shtml</guid></item>
<item><title>Vigilance - Cisco Secure ACS   injection SQL, analysé le 27 10 2015</title><description>2015-12-27 14:29:52 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une injection SQL de Cisco Secure ACS, afin de lire ou modifier des données </description><link>http://www.secuobs.com/revue/news/594251.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594251.shtml</guid></item>
<item><title>Vigilance - Cisco Secure ACS   Cross Site Scripting de DOM, analysé le 26 10 2015</title><description>2015-12-26 18:17:26 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Scripting dans DOM de Cisco Secure ACS, afin d'exécuter du code JavaScript dans le contexte du site web </description><link>http://www.secuobs.com/revue/news/594228.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594228.shtml</guid></item>
<item><title>Vigilance - Cisco Secure ACS   Cross Site Scripting, analysé le 26 10 2015</title><description>2015-12-26 17:01:28 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Scripting de Cisco Secure ACS, afin d'exécuter du code JavaScript dans le contexte du site web </description><link>http://www.secuobs.com/revue/news/594225.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594225.shtml</guid></item>
<item><title>Vigilance - Cisco Secure ACS   élévation de privilèges via Dashboard Portlet, analysé le 26 10 2015</title><description>2015-12-26 17:01:28 - Vigilance   vulnérabilités publiques : Un attaquant peut contourner les restrictions dans Dashboard Portlet de Cisco Secure ACS, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/594224.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594224.shtml</guid></item>
<item><title>Vigilance - Cisco Secure ACS   élévation de privilèges via Report Generation, analysé le 26 10 2015</title><description>2015-12-26 17:01:28 - Vigilance   vulnérabilités publiques : Un attaquant authentifié peut créer un rapport sur Cisco Secure ACS, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/594223.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594223.shtml</guid></item>
<item><title> Cisco Systems will be auditing their code for backdoors</title><description>2015-12-22 16:59:36 - Help Net Security : In the wake of the discovery of two backdoors on Juniper's NetScreen firewall devices, Cisco Systems has announced that they will be reviewing the software running on their devices, just in case A </description><link>http://www.secuobs.com/revue/news/593963.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593963.shtml</guid></item>
<item><title>Vigilance - Cisco ASR   déni de service via PMIPv6, analysé le 20 10 2015</title><description>2015-12-20 08:53:45 - Vigilance   vulnérabilités publiques : Un attaquant distant peut envoyer des paquets PMIPv6 malveillants vers Cisco ASR, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/593735.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593735.shtml</guid></item>
<item><title>Vigilance - Cisco Nexus 5000   déni de service via USB Driver, analysé le 04 12 2015</title><description>2015-12-19 17:41:44 - Vigilance   vulnérabilités publiques : Un attaquant peut connecter un périphérique USB malveillant sur Cisco Nexus 5000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/593716.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593716.shtml</guid></item>
<item><title>Vigilance - Cisco Wireless LAN Controller   déconnexion des clients, analysé le 19 10 2015</title><description>2015-12-19 11:25:06 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer une requête de déconnexion sur l'interface d'administration de Cisco Wireless LAN Controller, afin de mener un déni de service des clients </description><link>http://www.secuobs.com/revue/news/593707.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593707.shtml</guid></item>
<item><title>Vigilance - Cisco SIP Phone 3905   déni de service, analysé le 03 12 2015</title><description>2015-12-18 13:27:34 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer de nombreuses données vers Cisco SIP Phone 3905, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/593626.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593626.shtml</guid></item>
<item><title>Vigilance - Cisco Cloud Services Router 1000V   élévation de privilèges via Environment Variables, analysé le 02 12 2015</title><description>2015-12-17 11:46:08 - Vigilance   vulnérabilités publiques : Un attaquant privilégié peut utiliser des variables d'environnement sur Cisco Cloud Services Router 1000V, afin d'élever ses privilèges vers root </description><link>http://www.secuobs.com/revue/news/593464.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593464.shtml</guid></item>
<item><title>Vigilance - Cisco ASR   déni de service via TACACS, analysé le 13 10 2015</title><description>2015-12-13 11:10:23 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet TACACS malveillant vers Cisco ASR, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/593007.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593007.shtml</guid></item>
<item><title>Exaprobe obtient la Certification Gold Cisco</title><description>2015-12-09 16:24:10 - Global Security Mag Online : Exaprobe, intégrateur du groupe Econocom, annonce avoir obtenu la certification Gold Cisco, le plus haut niveau de certification décerné par Cisco Cisco est le premier partenaire technologique d'Exaprobe sur l'ensemble de ses domaines d'expertise  réseau, communications unifiées, sécurité et digital  La certification Gold Cisco est l'une des plus exigeantes du marché et atteste du haut niveau d'expertise d'Exaprobe sur les solutions Cisco et d'une capacité à les intégrer, les supporter et les    - Business </description><link>http://www.secuobs.com/revue/news/592620.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592620.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Collaboration Assurance   traversée de répertoire, analysé le 09 10 2015</title><description>2015-12-09 10:47:58 - Vigilance   vulnérabilités publiques : Un attaquant peut traverser les répertoires de Cisco Prime Collaboration Assurance, afin de lire un fichier situé hors de la racine du service </description><link>http://www.secuobs.com/revue/news/592576.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592576.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Collaboration Provisioning   injection SQL, analysé le 09 10 2015</title><description>2015-12-09 10:47:58 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une injection SQL de Cisco Prime Collaboration Provisioning, afin de lire ou modifier des données </description><link>http://www.secuobs.com/revue/news/592575.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592575.shtml</guid></item>
<item><title>Vigilance - Cisco AnyConnect Secure Mobility Client   déplacement de fichiers, analysé le 09 10 2015</title><description>2015-12-09 10:47:58 - Vigilance   vulnérabilités publiques : Un attaquant local peut employer IPC de Cisco AnyConnect Secure Mobility Client pour Windows, pour déplacer un fichier, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/592574.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592574.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Collaboration Assurance   injection SQL, analysé le 09 10 2015</title><description>2015-12-09 10:47:58 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une injection SQL de Cisco Prime Collaboration Assurance, afin de lire ou modifier des données </description><link>http://www.secuobs.com/revue/news/592573.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592573.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Infrastructure   déni de service via SSL Renegotiation, analysé le 09 10 2015</title><description>2015-12-09 10:08:40 - Vigilance   vulnérabilités publiques : Un attaquant peut employer une renégociation SSL sur Cisco Prime Infrastructure, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/592569.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592569.shtml</guid></item>
<item><title>Vigilance - Cisco AnyConnect VPN Client   élévation de privilèges via vpnclientini, analysé le 07 10 2015</title><description>2015-12-07 08:57:17 - Vigilance   vulnérabilités publiques : Un attaquant local peut altérer le fichier vpnclientini de Cisco AnyConnect VPN Client, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/592266.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592266.shtml</guid></item>
<item><title>Vigilance - Cisco IOS   déni de service via RADIUS, analysé le 06 10 2015</title><description>2015-12-06 11:34:20 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet RADIUS malveillant vers Cisco IOS, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/592224.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592224.shtml</guid></item>
<item><title>Vigilance - Cisco Aironet   élévation de privilèges via CLI, analysé le 06 10 2015</title><description>2015-12-06 11:34:20 - Vigilance   vulnérabilités publiques : Un attaquant local peut utiliser la CLI de Cisco Aironet, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/592223.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592223.shtml</guid></item>
<item><title>Vigilance - Cisco Wireless LAN Controller   déni de service via 80211i, analysé le 05 10 2015</title><description>2015-12-05 14:44:41 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet 80211i malveillant vers Cisco Wireless LAN Controller, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/592197.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592197.shtml</guid></item>
<item><title>Vigilance - Cisco Unified Communications Manager IM and Presence Service   déni de service via REST, analysé le 05 10 2015</title><description>2015-12-05 14:44:41 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer une requête vers le service REST de Cisco Unified Communications Manager IM and Presence Service, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/592196.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592196.shtml</guid></item>
<item><title>Nimble Storage étend avec Cisco sa gamme SmartStack d'infrastructure intégrée </title><description>2015-12-04 09:02:01 - Global Security Mag Online : Nimble Storage annonce que sa gamme pour le flash SmartStackTM, solutions d'infrastructure intégrée par Nimble Storage et Cisco, a été déployée par plus de 750 entreprises dans le monde, qui ont ainsi accéléré leur déploiement d'applications et réduit les risques Depuis 2012, Cisco et Nimble Storage ont développé plusieurs solutions basées sur l'architecture de référence SmartStack, et l'architecture Cisco Validated Designs  CVD  s'adresse à une variété de cas d'utilisation Cette gamme d'infrastructures    - Produits </description><link>http://www.secuobs.com/revue/news/592084.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592084.shtml</guid></item>
<item><title>Roots in Best Practices  Why Cisco Acquired Lancope</title><description>2015-12-01 14:33:44 - Security Bloggers Network :  Blog Post Roots in Best Practices  Why Cisco Acquired Lancope  IMAGE  Stephen Caimi Dec 01, 2015  IMAGE  Q  What s the best thing about a UDP joke  A  No one really cares whether or not if you  get it  While I can t take credit for that silly networking Read more lancope, Cisco, NIST, Cyber security, Anomaly Detection </description><link>http://www.secuobs.com/revue/news/591682.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/591682.shtml</guid></item>
<item><title>Vigilance - Cisco Nexus 3000   déni de service via SNMP Non-Existent OID, analysé le 01 10 2015</title><description>2015-12-01 14:04:46 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet SNMP avec un OID inexistant vers Cisco Nexus 3000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/591676.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/591676.shtml</guid></item>
<item><title>Vigilance - Cisco Email Security Appliance   déni de service via Max Files, analysé le 01 10 2015</title><description>2015-12-01 12:05:03 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer quelques milliers de requêtes malveillantes vers Cisco Email Security Appliance, afin d'utiliser tous les descripteurs, et de mener un déni de service </description><link>http://www.secuobs.com/revue/news/591658.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/591658.shtml</guid></item>
<item><title> Credential manager system used by Cisco, IBM, F5 has been breached</title><description>2015-11-24 15:55:27 - Help Net Security : Pearson VUE, a provider of computer-based assessment testing for regulatory and certification boards, has announced that its Credential Manager system  PMC  has been compromised by an unauthorized thi </description><link>http://www.secuobs.com/revue/news/591063.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/591063.shtml</guid></item>
<item><title>Vigilance - Cisco AnyConnect Secure Mobility Client   élévation de privilèges, analysé le 24 09 2015</title><description>2015-11-24 09:25:45 - Vigilance   vulnérabilités publiques : Un attaquant local peut utiliser Cisco AnyConnect Secure Mobility Client, afin d'élever ses privilèges sur Linux ou Mac OS X </description><link>http://www.secuobs.com/revue/news/591006.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/591006.shtml</guid></item>
<item><title>Vigilance - Cisco IOS, IOS XE   déni de service via IPv6 First Hop, analysé le 23 09 2015</title><description>2015-11-23 19:35:48 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une erreur fatale dans la gestion IPv6 First Hop par Cisco IOS IOS XE, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/590960.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590960.shtml</guid></item>
<item><title>Cisco Light, garanti 100pourcents sans NSA</title><description>2015-11-23 16:48:25 - CNIS mag : Nous sommes NSA Free, clame Cisco, pour se dédouaner d une photo compromettante parue dans un document Snowden Et pour le prouver, nous convions tous nos utilisateurs à effectuer une revue de code grâce à notre   technology verification service  , lequel prouvera notre bonne volonté et notre totale transparence, affirme en substance l équipementier Quelques esprits   </description><link>http://www.secuobs.com/revue/news/590925.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590925.shtml</guid></item>
<item><title>Data breach at firm that manages Cisco, Microsoft certifications</title><description>2015-11-23 14:25:37 - Office of Inadequate Security : Alexander J Martin reports  Cisco, IBM, Oracle and Microsoft s certification management provider, Pearson VUE, has </description><link>http://www.secuobs.com/revue/news/590891.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590891.shtml</guid></item>
<item><title>SAINTCON 2015 -  Cisco Threat-Centric Security</title><description>2015-11-23 08:00:14 - SecurityTube.Net : Changing business models, a dynamic threat landscape, and complex, fragmented security solutions call for a new security model To deal with today's biggest security challenges, organizations need a simpler, scalable, threat-centric approach that addresses security across the entire attack continuum   before, during, and after an attack Before an attack, you need comprehensive awareness of and visibility showing what's on the extended network so you can implement policies and controls to defend it During an attack, the ability to continuously detect malware and block it is critical After an attack, you need to marginalize the impact of an attack by identifying point of entry, determining the scope, containing the threat, eliminating the risk of re-infection, and remediating The Cisco threat-centric security model is built to address your biggest security challenges, cover the entire attack continuum, and reduce security gaps and complexity caused by disparate products and disjointed solutions The comprehensive Cisco portfolio of platform-based cybersecurity solutions offer these benefits For More Information Please Visit - https wwwsaintconorg  </description><link>http://www.secuobs.com/revue/news/590824.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590824.shtml</guid></item>
<item><title>Vigilance - Cisco Wireless LAN Controller   déni de service via RADIUS, analysé le 22 09 2015</title><description>2015-11-22 09:07:52 - Vigilance   vulnérabilités publiques : Un attaquant peut forger des paquets de déconnexion RADIUS pour Cisco Wireless LAN Controller, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/590787.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590787.shtml</guid></item>
<item><title>Vigilance - Cisco Unity Connection   injection SQL, analysé le 21 09 2015</title><description>2015-11-21 09:02:52 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une injection SQL de Cisco Unity Connection, afin de lire ou modifier des données </description><link>http://www.secuobs.com/revue/news/590754.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590754.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 9000   déni de service via DHCPv6, analysé le 21 09 2015</title><description>2015-11-21 09:02:52 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet DHCPv6 malveillant vers Cisco ASR 9000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/590753.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590753.shtml</guid></item>
<item><title>How Cisco Is Trying To Prove It Can Keep NSA Spies Out of Its Gear</title><description>2015-11-18 21:13:40 - Slashdot  Your Rights Online : itwbennett writes  A now infamous photo  leaked by Edward Snowden  showed NSA employees around a box labeled Cisco during a so-called 'interdiction' operation, one of the spy agency's most productive programs,' writes Jeremy Kirk 'Once that genie is out of the bottle, it's a hell of job to put it back in,' said Steve Durbin, managing director of the Information Security Forum in London Yet that's just what Cisco is trying to do, and early next year, the company plans to open a facility in the Research Triangle Park in North Carolina where customers can test and inspect source code in a secure environment But, considering that a Cisco router might have 30 million lines of code, proving a product hasn't been tampered with by spy agencies is like trying 'to prove the non-existence of god,' says Joe Skorupa, a networking and communications analyst with Gartner  IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/590493.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590493.shtml</guid></item>
<item><title>Vigilance - Cisco Secure ACS   déni de service via SSH Screen Process, analysé le 18 09 2015</title><description>2015-11-18 17:40:20 - Vigilance   vulnérabilités publiques : Un attaquant authentifié peut stopper le SSH Screen Process de Cisco Secure ACS, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/590466.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590466.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Network Registrar   élévation de privilèges, analysé le 18 09 2015</title><description>2015-11-18 09:34:06 - Vigilance   vulnérabilités publiques : Un attaquant local peut utiliser un compte actif par défaut de Cisco Prime Network Registrar, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/590374.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590374.shtml</guid></item>
<item><title>Vigilance - Cisco IOS XE   déni de service via Cisco Discovery Protocol, analysé le 17 09 2015</title><description>2015-11-17 11:23:35 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet Cisco Discovery Protocol malveillant vers Cisco IOS XE, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/590270.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590270.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Collaboration Provisioning   élévation de privilèges, analysé le 17 09 2015</title><description>2015-11-17 08:56:37 - Vigilance   vulnérabilités publiques : Un attaquant authentifié peut utiliser Cisco Prime Collaboration Provisioning, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/590256.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590256.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Collaboration Assurance   trois vulnérabilités, analysé le 17 09 2015</title><description>2015-11-17 08:19:56 - Vigilance   vulnérabilités publiques : Un attaquant peut employer plusieurs vulnérabilités de Cisco Prime Collaboration Assurance </description><link>http://www.secuobs.com/revue/news/590254.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590254.shtml</guid></item>
<item><title>Cisco renforce sa stratégie Security Everywhere</title><description>2015-11-10 13:30:47 - Global Security Mag Online : Cisco annonce le lancement de nouveaux produits et fonctionnalités de sécurité destinés à renforcer sa stratégie Security Everywhere dans le cloud, les réseaux et les terminaux, ainsi que la mise en place d'un service de sensibilisation aux menaces Ces innovations sont spécialement conçues pour les entreprises opérant leur transformation numérique Les sociétés comptent sur les innovations numériques pour développer de nouvelles opportunités de croissance et réduire leur complexité opérationnelle    - Produits </description><link>http://www.secuobs.com/revue/news/589635.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589635.shtml</guid></item>
<item><title>Vigilance - Cisco WSA   fuite mémoire via HTTP, analysé le 10 09 2015</title><description>2015-11-10 11:32:36 - Vigilance   vulnérabilités publiques : Un attaquant, disposant d'un serveur web, peut provoquer une fuite mémoire dans Cisco WSA, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/589621.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589621.shtml</guid></item>
<item><title>Vigilance - Cisco ESA   corruption de mémoire, analysé le 10 09 2015</title><description>2015-11-10 09:08:32 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une corruption de mémoire sur Cisco ESA, afin de mener un déni de service, et éventuellement d'exécuter du code </description><link>http://www.secuobs.com/revue/news/589607.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589607.shtml</guid></item>
<item><title>Vigilance - Cisco WSA   déni de service via DNS, analysé le 09 09 2015</title><description>2015-11-09 17:15:59 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer de nombreuses requêtes nécessitant une résolution DNS vers Cisco WSA, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/589549.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589549.shtml</guid></item>
<item><title>Vigilance - Cisco SMA   déni de service via Log Rollover, analysé le 09 09 2015</title><description>2015-11-09 16:35:28 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer une erreur dans le Log Rollover de Cisco SMA, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/589542.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589542.shtml</guid></item>
<item><title>Vigilance - Cisco ASA   déni de service via DHCPv6, analysé le 22 10 2015</title><description>2015-11-06 09:48:51 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet DHCPv6 illicite vers Cisco ASA, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/589254.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589254.shtml</guid></item>
<item><title> Selon l'étude Global Cloud Index de Cisco, le trafic cloud devrait quadrupler d'ici 2019</title><description>2015-11-05 16:29:46 - Global Security Mag Online : Selon le cinquième rapport annuel Cisco  Global Cloud Index  2014-2019  publié, le trafic cloud mondial devrait quadrupler d'ici fin 2019 et passer de 2,1 à 8,6 zettaoctets  Zo  Le taux de croissance du trafic cloud est supérieur à celui du trafic total des datacenters dans le monde, qui devrait quant à lui tripler sur la même période  passant de 3,4 à 10,4 Zo  Plusieurs facteurs contribuent à accélérer la croissance du trafic cloud et favorisent la transition vers des services en cloud Parmi ceux-ci,    - Investigations </description><link>http://www.secuobs.com/revue/news/589178.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589178.shtml</guid></item>
<item><title>Invincea Expands Our Partnership with Cisco to Deliver Automated Threat Intelligence Across the Enterprise</title><description>2015-11-04 16:36:58 - Security Bloggers Network :    In the world of IT security, customers have long sought a panacea for preventing data breaches However, just as with the five theatres of war  air, land, sea, space, cyber , finding a solution that protects against all attack vectors for an organization is impossible It s commonly said that there is no  silver bullet , and we agree The post Invincea Expands Our Partnership with Cisco to Deliver Automated Threat Intelligence Across the Enterprise appeared first on Invincea </description><link>http://www.secuobs.com/revue/news/589052.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589052.shtml</guid></item>
<item><title>Cisco and Lancope  Advancing Security Everywhere</title><description>2015-11-04 15:50:02 - Security Bloggers Network :  Blog Post Cisco and Lancope  Advancing Security Everywhere  IMAGE  Scott Harrell Nov 04, 2015  IMAGE  It s been an exciting few weeks for both Cisco and Lancope Last week, Cisco announced its intent to acquire Lancope  Through a successful program Read more Cisco, security everywhere, VISION IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/589040.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589040.shtml</guid></item>
<item><title>SPIE Communications reçoit la distinction d'excellence de son partenaire Cisco </title><description>2015-11-03 15:10:24 - Global Security Mag Online : SPIE Communications a reçu la meilleure distinction de son partenaire stratégique Cisco nommée   Cisco Channel Customer Satisfaction Excellence   - dit   CSAT   lors des derniers résultats d'enquêtes menées auprès de ses clients Le niveau excellence de   Customer Satisfaction   est la plus haute distinction que le constructeur puisse donner à une entreprise de services numériques dans le cadre de ses programmes de partenariat GOLD Ce processus d'évaluation est mondial et l'ensemble des partenaires    - Business </description><link>http://www.secuobs.com/revue/news/588896.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588896.shtml</guid></item>
<item><title>Cisco Security Everywhere expands to protect shadow IT, cloud services</title><description>2015-11-03 11:48:32 - Security Bloggers Network : The firm's  security everywhere  strategy is being implemented with new solutions to improve network threat visibility </description><link>http://www.secuobs.com/revue/news/588850.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588850.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 1000   déni de service via IPv4 Fragments, analysé le 01 09 2015</title><description>2015-11-01 09:16:53 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer de nombreux paquets IPv4 fragmentés vers Cisco ASR 1000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/588638.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588638.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 1000   déni de service via SIP, analysé le 28 08 2015</title><description>2015-10-28 10:12:40 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet SIP malveillant vers Cisco ASR 1000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/588214.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588214.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 1000   déni de service via L2TP, analysé le 28 08 2015</title><description>2015-10-28 09:35:42 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet L2TP malveillant vers Cisco ASR 1000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/588209.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588209.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 1000   déni de service via H323, analysé le 28 08 2015</title><description>2015-10-28 09:35:42 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet H323 malveillant vers Cisco ASR 1000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/588208.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588208.shtml</guid></item>
<item><title>How Cisco CSIRT uses StealthWatch to Combat DoS Reflection Attacks</title><description>2015-10-27 14:46:59 - Security Bloggers Network :  Blog Post How Cisco CSIRT uses StealthWatch to Combat DoS Reflection Attacks  IMAGE  Gavin Reid Oct 27, 2015  IMAGE  Most organizations are occupied with protecting themselves from being victims of denial-of-service  DoS  attacks, but few give much thought to Read more Cisco, csirt, DoS, ddos, Threat Detection, Incident Response IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/588112.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588112.shtml</guid></item>
<item><title>Cisco Announces Intent to Acquire Lancope</title><description>2015-10-27 14:46:59 - Security Bloggers Network :  Blog Post Cisco Announces Intent to Acquire Lancope  IMAGE  Mike Potts Oct 27, 2015 It is with great pleasure that I share some exciting news  Earlier today Cisco announced its intent to acquire Lancope in a move that formalizes this Read more  IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/588110.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588110.shtml</guid></item>
<item><title>Vigilance - Cisco ACE 4700, ACE30   accès en lecture et écriture via CLI, analysé le 27 08 2015</title><description>2015-10-27 09:23:30 - Vigilance   vulnérabilités publiques : Un attaquant authentifié peut utiliser un fichier et la CLI, pour contourner les restrictions d'accès de Cisco ACE 4700 ou ACE30, afin de lire ou modifier des données </description><link>http://www.secuobs.com/revue/news/588058.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588058.shtml</guid></item>
<item><title>Vigilance - Cisco ACE   Cross Site Request Forgery, analysé le 25 08 2015</title><description>2015-10-25 11:32:49 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Request Forgery de Cisco ACE, afin de forcer la victime à effectuer des opérations </description><link>http://www.secuobs.com/revue/news/587887.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587887.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Infrastructure   Cross Site Request Forgery, analysé le 25 08 2015</title><description>2015-10-25 08:59:39 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Request Forgery de Cisco Prime Infrastructure, afin de forcer la victime à effectuer des opérations </description><link>http://www.secuobs.com/revue/news/587883.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587883.shtml</guid></item>
<item><title>Vigilance - Cisco Wireless LAN Controller   transfert IPv6 via IAPP et WIPS, analysé le 24 08 2015</title><description>2015-10-24 10:17:43 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer des paquets IPv6 vers Cisco Wireless LAN Controller avec IAPP et wIPS, afin qu'ils atteignent le réseau interne </description><link>http://www.secuobs.com/revue/news/587841.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587841.shtml</guid></item>
<item><title>Cisco Identifies Multiple Vulnerabilities in Network Time Protocol daemon  ntpd </title><description>2015-10-21 22:11:35 - Security Bloggers Network : Cisco is committed to improving the overall security of the products and services our customers rely on As part of this commitment, Cisco assesses the security of software components used in our products Open source software plays a key role in many Cisco products and as a result, ensuring the security of open source software components is vital, especially in the wake of major vulnerabilities such as Heartbleed and Shellshock In April 2014, the Linux Foundation spearheaded the creation of the Core Infrastructure Initiative in response to the disclosure of Heartbleed with the goal of securing open source projects that are widely used on the internet As a member of the Linux Foundation Core Infrastructure Initiative  CII  Steering Group, Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon  ntpd  for security defects ntpd is a widely deployed software package used to synchronize time between hosts ntpd ships with a wide variety of network and embedded devices as well as desktop and server operating systems, including Mac OS X, major Linux distributions, and BSDs Today, in coordination with the NTP Project, Cisco is releasing 8 advisories for vulnerabilities that have been identified by the Talos Group and the Advanced Security Initiatives Group  ASIG  within Cisco These vulnerabilities have been reported to the NTP Project in accordance with Cisco vulnerability reporting and disclosure guidelines The following serves as a summary for all the advisories being released For the full advisories, readers should visit the Vulnerability Reports page on the Talos website Advisory Summaries ------------------ The advisories that are being released today are broken down by vulnerability type Error Handling Logic Error An error handling logic error exists within ntpd that manifests due to improper error condition handling associated with certain crypto-NAK packets An unauthenticated, off-path attacker can force ntpd processes on targeted servers to peer with time sources of the attacker's choosing by transmitting symmetric active crypto-NAK packets to ntpd This attack bypasses the authentication typically required to establish a peer association and allows an attacker to make arbitrary changes to system time Matthew Van Gundy of Cisco ASIG is credited with discovering this vulnerability   CVE-2015-7871 - NAK to the Future  NTP crypto-NAK Symmetric Association Authentication Bypass Vulnerability Memory Corruption Multiple memory corruption vulnerabilities exist within ntpd that can manifest themselves due to improper handling of objects in memory An adversary who exploits these vulnerabilities could modify memory via a buffer overflow or use-after-free condition Aleksandar Nikolic and Yves Younan of Cisco Talos are credited with the discovery of these vulnerabilities   CVE-2015-7849 - Network Time Protocol Trusted Keys Memory Corruption Vulnerability   CVE-2015-7852 - Network Time Protocol ntpq atoascii Memory Corruption Vulnerability   CVE-2015-7853 - Network Time Protocol Reference Clock Memory Corruption Vulnerability   CVE-2015-7854 - Network Time Protocol Password Length Memory Corruption Vulnerability Denial of Service Multiple denial of service vulnerabilities exist within ntpd that manifest themselves due to ntpd failing to properly validate input received via private mode packets or a remote configuration file An adversary who crafts a specially formatted packet and transmits it to an ntpd server, or who crafts a specially formatted configuration file and transmits it to the ntpd server could cause the server daemon to crash or enter an infinite loop Aleksandar Nikolic and Yves Younan of Cisco Talos are credited with the discovery of these vulnerabilities   CVE-2015-7848 - Network Time Protocol Multiple Integer Overflow Read Access Violations   CVE-2015-7850 - Network Time Protocol Remote Configuration Denial of Service Vulnerability Directory Traversal   File Overwrite A file path traversal vulnerability exists within ntpd that manifests when saving a config file on VMS operating systems, potentially resulting in files being overwritten An adversary would need to provide a malicious path in the configuration file to exploit this vulnerability Yves Younan of Cisco Talos is credited with the discovery of this vulnerability   CVE-2015-7851 - Network Time Protocol saveconfig Directory Traversal Vulnerability Known Vulnerable Versions   ntp 425p186 though ntp 428p3   ntp-dev4370 Cisco remains committed to improving the overall security of the products and services our customers rely on by assessing the security of all software components that are used in our products Through the research efforts by Talos and ASIG to identify vulnerabilities in ntpd, Cisco is able to assist the CII in improving the overall security of open source software components the overall community relies on In response to these vulnerability disclosures, Cisco is taking the following actions to help address our customer's concerns Cisco PSIRT has posted a Security Advisory enumerating which Cisco products are affected by these ntpd vulnerabilities You can find the Cisco Security Advisory here  http toolsciscocom security center publicationListingx In addition, Talos has released rules that detect attempts to exploit these vulnerabilities to protect our customers Please note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information For the most current rule information, please refer to your Defense Center, FireSIGHT Management Center or Snortorg Snort Rules  35831, 36250-36253, 36536 For additional information and vulnerability reports visit  http talosintelcom vulnerability-reports IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/587554.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587554.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 5K   déni de service via OSPF, analysé le 20 08 2015</title><description>2015-10-20 18:49:00 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet OSPF malveillant vers Cisco ASR, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/587409.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587409.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Infrastructure   élévation de privilèges via Case-sensitive, analysé le 20 08 2015</title><description>2015-10-20 18:49:00 - Vigilance   vulnérabilités publiques : Un attaquant peut changer la casse de son login sur Cisco Prime Infrastructure, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/587408.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587408.shtml</guid></item>
<item><title>Vigilance - Cisco NX-OS   déni de service via IGMPv3, analysé le 18 08 2015</title><description>2015-10-18 15:28:33 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet IGMPv3 malveillant vers Cisco NX-OS, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/587117.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587117.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Infrastructure   élévation de privilèges via SUID Root Binaries, analysé le 18 08 2015</title><description>2015-10-18 15:28:33 - Vigilance   vulnérabilités publiques : Un attaquant, ayant un accès shell, peut appeler deux programmes suid root sur Cisco Prime Infrastructure, afin d'élever ses privilèges </description><link>http://www.secuobs.com/revue/news/587116.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587116.shtml</guid></item>
<item><title>Vigilance - Cisco Content Security Management Appliance   élévation de privilèges via Spam Quarantine, analysé le 17 08 2015</title><description>2015-10-17 11:32:44 - Vigilance   vulnérabilités publiques : Un attaquant peut accéder à la Spam Quarantine de Cisco Content Security Management Appliance, afin de lire les mails ou modifier la configuration </description><link>http://www.secuobs.com/revue/news/587074.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587074.shtml</guid></item>
<item><title>Vigilance - Cisco NX-OS   déni de service via ARP, analysé le 17 08 2015</title><description>2015-10-17 10:26:41 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet ARP malveillant vers Cisco NX-OS, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/587073.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587073.shtml</guid></item>
<item><title>La sécurité SDN haute-performance de Fortinet vient au renfort de l'infrastructure ACI de Cisco</title><description>2015-10-16 15:34:36 - Global Security Mag Online : Fortinet  annonce l'intégration du pare-feu FortiGate avec APIC  Cisco  Application Policy Infrastructure Controller , le contrôleur de l'infrastructure ACI  Application Centric Infrastructure  de Cisco Cette architecture SDN, qui compte parmi les plus sophistiquées du marché, est gage de maîtrise des coûts, automatise les tâches informatiques et accélère le déploiement des applications des centres de données Le nouveau FortiGate Connector for Cisco ACI prend en compte les besoins de sécurité des    - Produits </description><link>http://www.secuobs.com/revue/news/586997.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586997.shtml</guid></item>
<item><title>Radware Integration Enables Cisco Customers to Fight Security Fire with Firepower</title><description>2015-10-15 18:10:38 - Security Bloggers Network : Zeus Kerravala is founder and principal analyst of ZK Research, and is a featured guest blogger The topic of cyber security is always near the top of any business or IT leaders  priority list In my years as an analyst and prior to that, an IT leader, I ve never seen more focus on security than   </description><link>http://www.secuobs.com/revue/news/586888.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586888.shtml</guid></item>
<item><title>Top 5 Cybersecurity Conferences in San Francisco</title><description>2015-10-14 12:09:23 - Security Bloggers Network :    San Francisco,  San-Fran  or just plain old  Frisco  if that s how you roll, is the world s capital of pioneering tech Sure, we all appreciate that California state is the  de-facto  world s engine house for tech, but what about the Cyber Scene  In this post we take a look at some Cyber Security Conferences that take   The post Top 5 Cybersecurity Conferences in San Francisco appeared first on concise </description><link>http://www.secuobs.com/revue/news/586700.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586700.shtml</guid></item>
<item><title>Vigilance - Cisco Nexus 3000   déni de service via Nexus Data Broker, analysé le 13 08 2015</title><description>2015-10-13 16:13:47 - Vigilance   vulnérabilités publiques : Un attaquant peut utiliser Nexus Data Broker de Cisco Nexus 3000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/586574.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586574.shtml</guid></item>
<item><title>Vigilance - Cisco ASA   contournement de uRPF, analysé le 13 08 2015</title><description>2015-10-13 12:02:15 - Vigilance   vulnérabilités publiques : Un attaquant peut usurper un paquet vers Cisco ASA, afin de le faire transiter vers le réseau interne </description><link>http://www.secuobs.com/revue/news/586530.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586530.shtml</guid></item>
<item><title>Vigilance - Cisco Nexus 9000   déni de service via Large Files, analysé le 13 08 2015</title><description>2015-10-13 10:50:04 - Vigilance   vulnérabilités publiques : Un attaquant authentifié peut copier des gros fichiers sur Cisco Nexus 9000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/586523.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586523.shtml</guid></item>
<item><title>Vigilance - Cisco Unified Communications Manager   exécution de ping, analysé le 13 08 2015</title><description>2015-10-13 09:40:42 - Vigilance   vulnérabilités publiques : Un attaquant non authentifié peut utiliser pingExecute de Cisco Unified Communications Manager, afin d'obtenir des informations sur le réseau </description><link>http://www.secuobs.com/revue/news/586509.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586509.shtml</guid></item>
<item><title>Vigilance - Cisco Unified Communications Manager   obtention d'information via SOAP, analysé le 13 08 2015</title><description>2015-10-13 09:40:42 - Vigilance   vulnérabilités publiques : Un attaquant peut utiliser une vulnérabilité dans SOAP de Cisco Unified Communications Manager, afin d'obtenir des informations sensibles </description><link>http://www.secuobs.com/revue/news/586508.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586508.shtml</guid></item>
<item><title> Attackers compromise Cisco Web VPNs to steal login credentials, backdoor target networks</title><description>2015-10-09 11:54:12 - Help Net Security : Another Cisco product is being targeted by attackers looking for a permanent way into the computer networks and systems of various organizations, Volexity researchers warn  The Cisco Clientless SS </description><link>http://www.secuobs.com/revue/news/586188.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586188.shtml</guid></item>
<item><title>Backdoor infecting Cisco VPNs steals customers  network passwords</title><description>2015-10-08 21:30:02 - Ars Technica   Risk Assessment : Dozens of successful attacks detected that install malicious code on company portals </description><link>http://www.secuobs.com/revue/news/586144.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586144.shtml</guid></item>
<item><title> CiscoChat  Celebrating National Cyber Security Awareness Month</title><description>2015-10-08 21:28:57 - OpenDNS Blog :     View the story  CiscoChat  Celebrating National Cyber Security Awareness Month  on Storify  The post  CiscoChat  Celebrating National Cyber Security Awareness Month appeared first on OpenDNS Blog </description><link>http://www.secuobs.com/revue/news/586143.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586143.shtml</guid></item>
<item><title>Cisco disrupts  30 million browser plug-in hacking operation</title><description>2015-10-07 16:21:22 - Security Bloggers Network : Hackers used the Angler toolkit in order to take advantage of vulnerabilities in Flash, Java, and other browser plug-ins </description><link>http://www.secuobs.com/revue/news/585968.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585968.shtml</guid></item>
<item><title>Cisco shuts down  30 million ransomware operation</title><description>2015-10-06 19:24:31 - Ars Technica   Risk Assessment : Group used Angler Exploit kit to push ransomware on unsuspecting Internet users </description><link>http://www.secuobs.com/revue/news/585852.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585852.shtml</guid></item>
<item><title> Cisco disrupts major ransomware campaign that brought in  30M annually</title><description>2015-10-06 18:09:12 - Help Net Security : Cisco researchers, with the help of Level 3 Threat Research Labs and OpenDNS, have managed to strike a considerable blow against ransomware peddlers that used the Angler exploit kit to deliver the mal </description><link>http://www.secuobs.com/revue/news/585840.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585840.shtml</guid></item>
<item><title>International Exploit Kit Angler Thwarted By Cisco Security Team</title><description>2015-10-06 16:59:22 - Slashdot  Your Rights Online : An anonymous reader writes  Researchers at a Cisco security unit have successfully interrupted the spread of a massive international exploit kit which is commonly used in ransomware attacks The scientists discovered that around 50pourcents of computers infected with Angler were connecting with servers based at a Dallas facility, owned by provider Limestone Networks Once informed, Limestone cut the servers from its network and handed over the data to the researchers who were able to recover Angler authentication protocols, information needed to disrupt future diffusion  IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/585823.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585823.shtml</guid></item>
<item><title>Cisco Disrupts Major Ransomware Campaign</title><description>2015-10-06 15:30:26 - OpenDNS Blog :    Security professionals generally spend their lives playing defense against adversaries that are not only anonymous, but often invisible It s a rare event when hackers and malware authors have their operations curtailed, shutdown or even impacted by members of the infosec community  and even more rare when the community can get an inside look at the   The post Cisco Disrupts Major Ransomware Campaign appeared first on OpenDNS Blog </description><link>http://www.secuobs.com/revue/news/585802.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585802.shtml</guid></item>
<item><title>Vigilance - Cisco ASR 9000   déni de service via DHCPv6, analysé le 18 09 2015</title><description>2015-10-03 15:18:22 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet DHCPv6 malveillant vers Cisco ASR 9000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/585576.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585576.shtml</guid></item>
<item><title>Vigilance - Cisco Unified Communications Manager   Cross Site Scripting de IM and Presence Service, analysé le 03 08 2015</title><description>2015-10-03 11:31:21 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Scripting dans IM and Presence Service de Cisco Unified Communications Manager, afin d'exécuter du code JavaScript dans le contexte du site web </description><link>http://www.secuobs.com/revue/news/585562.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585562.shtml</guid></item>
<item><title>Security Everywhere  OpenDNS and Cisco Are Better Together</title><description>2015-10-02 19:38:07 - OpenDNS Blog :    As you know, OpenDNS is undergoing a period of substantive change Last month, the company was officially acquired by Cisco Systems, Inc Although the initial announcement in June caused a surge of interest and a barrage of questions, now that the ink has dried and the dust has settled  somewhat , I can speak more definitively   The post Security Everywhere  OpenDNS and Cisco Are Better Together appeared first on OpenDNS Blog </description><link>http://www.secuobs.com/revue/news/585521.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585521.shtml</guid></item>
<item><title>Vigilance - Cisco Nexus 9000   déni de service via Layer 2, analysé le 17 09 2015</title><description>2015-10-02 11:31:18 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet Layer 2 malveillant vers Cisco Nexus 9000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/585463.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585463.shtml</guid></item>
<item><title>Cisco acquires Portcullis to boost security consultancy business</title><description>2015-10-01 10:15:26 - Security Bloggers Network : The buyout increases Cisco's strength in the security consultancy realm </description><link>http://www.secuobs.com/revue/news/585322.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585322.shtml</guid></item>
<item><title>Former Cisco CEO  China, India, UK Will Lead US In Tech Race Without Action</title><description>2015-10-01 04:30:27 - Slashdot  Your Rights Online : Mickeycaskill writes  Former Cisco CEO John Chambers says the US is the only major country without a proper digital agenda and laments the fact none of the prospective candidates for the US Presidential Election have made it an issue Chambers said China, India, the UK and France were among those to recognize the benefits of the trend but the US had been slow   risking any economic gains and support for startups  This is the first time that our government has not led a technology transition,  he said  Our government has been remarkably slow We are the last major developed country in the world without a digital agenda I think every major country has this as one of their top two priorities and we don't We won't get GDP increase and we won't be as competitive with our startups The real surprise to me was how governments around the world, except ours, moved   IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/585284.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585284.shtml</guid></item>
<item><title>Vigilance - Cisco Unified Communications Manager   obtention d'information via Prime Collaboration Deployment, analysé le 31 07 2015</title><description>2015-09-30 15:20:59 - Vigilance   vulnérabilités publiques : Un attaquant peut utiliser une vulnérabilité dans Prime Collaboration Deployment de Cisco Unified Communications Manager, afin d'obtenir des informations sensibles </description><link>http://www.secuobs.com/revue/news/585197.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585197.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Central Hosted Collaboration Solution   Cross Site Scripting, analysé le 31 07 2015</title><description>2015-09-30 14:43:02 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Scripting de Cisco Prime Central Hosted Collaboration Solution, afin d'exécuter du code JavaScript dans le contexte du site web </description><link>http://www.secuobs.com/revue/news/585181.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585181.shtml</guid></item>
<item><title>Vigilance - Cisco AnyConnect Secure Mobility Client   traversée de répertoire, analysé le 31 07 2015</title><description>2015-09-30 14:43:02 - Vigilance   vulnérabilités publiques : Un attaquant peut traverser les répertoires de Cisco AnyConnect Secure Mobility Client, afin de modifier un fichier situé hors de la racine du service </description><link>http://www.secuobs.com/revue/news/585180.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585180.shtml</guid></item>
<item><title>Vigilance - Cisco IOS-XE   déni de service via ATTN-3-SYNC_TIMEOUT, analysé le 30 07 2015</title><description>2015-09-30 11:38:20 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer de nombreux paquets TCP fragmentés vers Cisco IOS-XE, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/585156.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585156.shtml</guid></item>
<item><title>Vigilance - Cisco ESA, SMA, WSA   Cross Site Scripting, analysé le 28 07 2015</title><description>2015-09-28 11:22:57 - Vigilance   vulnérabilités publiques : Un attaquant peut provoquer un Cross Site Scripting de Cisco ESA, SMA ou WSA, afin d'exécuter du code JavaScript dans le contexte du site web </description><link>http://www.secuobs.com/revue/news/584842.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584842.shtml</guid></item>
<item><title>Vigilance - Cisco ESA, SMA, WSA   Man-in-the-Middle de LDAP, analysé le 27 07 2015</title><description>2015-09-27 15:22:47 - Vigilance   vulnérabilités publiques : Un attaquant peut se positionner en Man-in-the-Middle entre Cisco ESA SMA WSA et un serveur LDAP, afin de lire ou d'altérer des données de l'annuaire </description><link>http://www.secuobs.com/revue/news/584801.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584801.shtml</guid></item>
<item><title> Cisco releases tool for detecting malicious router implants</title><description>2015-09-25 13:38:47 - Help Net Security : Cisco Systems has provided a tool that allows enterprise users to scan their networks and discover if their routers have been compromised with malicious SYNful Knock implants The SYNful Knock Scan </description><link>http://www.secuobs.com/revue/news/584666.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584666.shtml</guid></item>
<item><title>SYNful Knock  What the Cisco Router Vulnerability Means for Your Business</title><description>2015-09-24 23:10:20 - Security Bloggers Network :    By Michael Perry and Val Vask In the aftermath of Cisco s announcement that several discontinued Integrated Service Routers  ISRs  have been compromised, Cyveillance recommends a thorough screening of networking infrastructure and policy The impacted models   1841, 2811, and 3825   are what Cisco calls  branch routers  These routers are specifically responsible for addressing the   The post SYNful Knock  What the Cisco Router Vulnerability Means for Your Business appeared first on Cyveillance Blog - The Cyber Intelligence Blog </description><link>http://www.secuobs.com/revue/news/584623.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584623.shtml</guid></item>
<item><title>Vigilance - Cisco IOS XR, ASR 9000   déni de service via LPTS, analysé le 23 07 2015</title><description>2015-09-23 10:02:07 - Vigilance   vulnérabilités publiques : Un attaquant peut employer le service LPTS de Cisco IOS XR sur ASR 9000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/584400.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584400.shtml</guid></item>
<item><title>Vigilance - Cisco Nexus 9000 Series ACI Mode Switches   élévation de privilèges via APIC ACS, analysé le 23 07 2015</title><description>2015-09-23 09:25:33 - Vigilance   vulnérabilités publiques : Un attaquant authentifié peut accéder au système de fichiers APIC de Cisco Nexus 9000 Series ACI Mode Switches, afin d'obtenir les privilèges root </description><link>http://www.secuobs.com/revue/news/584398.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584398.shtml</guid></item>
<item><title>Vigilance - Cisco IOS, XE   déni de service via TFTP, analysé le 23 07 2015</title><description>2015-09-23 09:25:33 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer des paquets TFTP malveillants vers Cisco IOS ou Cisco IOS XE, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/584397.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584397.shtml</guid></item>
<item><title> CiscoChat  Managing the Shadow IT Explosion in Cloud</title><description>2015-09-22 22:53:43 - OpenDNS Blog :     View the story  CiscoChat  Managing the Shadow IT Explosion in Cloud  on Storify  The post  CiscoChat  Managing the Shadow IT Explosion in Cloud appeared first on OpenDNS Blog </description><link>http://www.secuobs.com/revue/news/584355.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584355.shtml</guid></item>
<item><title>Vigilance - Cisco IOS XR, ASR   déni de service via BGPv4, analysé le 22 07 2015</title><description>2015-09-22 14:57:35 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet BGPv4 malveillant vers Cisco IOS XR sur ASR 9000, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/584287.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584287.shtml</guid></item>
<item><title>Outscale reçoit la certification CMSP de Cisco</title><description>2015-09-22 10:33:15 - Global Security Mag Online : Outscale annonce avoir obtenu la spécialisation   Advanced   du Programme CMSP  Cloud and Managed Services Program  de Cisco Grâce à cette certification   Advanced  , accessible seulement à une élite de fournisseurs Cloud, l'expertise commerciale et technique d'Outscale dans ce domaine est reconnue et labellisée par Cisco Ce partenariat inclut un volet commercial international, au service de la croissance mutuelle des deux entreprises et de l'innovation Une garantie d'excellence en matière de    - Business </description><link>http://www.secuobs.com/revue/news/584242.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584242.shtml</guid></item>
<item><title>Christophe Jolly, Cisco France   Les RSSI doivent maintenir opérationnels les systèmes IT critiques de l'entreprise </title><description>2015-09-21 21:11:43 - Global Security Mag Online : La sécurité est devenue un pilier stratégique de Cisco, c'est ce qui explique sa présence aux Assises de la Sécurité Cette année, Cisco présentera son approche de la sécurité centrée sur la menace ainsi que ses dernières innovations issues entre autre du rachat de SourceFire Christophe Jolly, Directeur Sécurité de Cisco France considère que face aux nouvelles menaces les RSSI doivent maintenir opérationnels les systèmes IT critiques de l'entreprise Global Security Mag   Qu'allez-vous présenter à    - Interviews   affiche </description><link>http://www.secuobs.com/revue/news/584203.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584203.shtml</guid></item>
<item><title>SYNful Knock Attack Against Cisco Routers</title><description>2015-09-21 19:38:58 - Security Bloggers Network : FireEye is reporting the discovery of persistent malware that compromises Cisco routers  While this attack could be possible on any router technology, in this case, the targeted victims were Cisco routers The Mandiant team found 14 instances of this  </description><link>http://www.secuobs.com/revue/news/584197.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584197.shtml</guid></item>
<item><title> Week in review  Malicious Cisco router implants, onion becomes a special-use domain name, and the new issue of  IN SECURE Magazine</title><description>2015-09-21 08:49:28 - Help Net Security : Here's an overview of some of last week's most interesting news, reviews and articles   IN SECURE Magazine issue 47 released  IN SECURE Magazine is a free digital security publication discussing </description><link>http://www.secuobs.com/revue/news/584104.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584104.shtml</guid></item>
<item><title> Malicious SYNful Cisco router implant found on more devices around the globe</title><description>2015-09-18 09:35:39 - Help Net Security : After FireEye researchers published on Tuesday their discovery of 14 Cisco routers in India, Mexico, Philippines and Ukraine that have been implanted with a modified, malicious Cisco IOS image, anothe </description><link>http://www.secuobs.com/revue/news/583912.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/583912.shtml</guid></item>
<item><title>Vigilance - Cisco Prime Collaboration Assurance   déni de service via HTTP, analysé le 17 07 2015</title><description>2015-09-17 11:14:19 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer une requête HTTP vers Cisco Prime Collaboration Assurance, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/583792.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/583792.shtml</guid></item>
<item><title>Vigilance - Cisco NX-OS   déni de service via ARP, analysé le 02 09 2015</title><description>2015-09-17 11:14:19 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet ARP malveillant vers Cisco NX-OS, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/583790.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/583790.shtml</guid></item>
<item><title>Malicious Cisco router backdoor found on 79 more devices, 25 in the US</title><description>2015-09-16 17:28:26 - Ars Technica   Risk Assessment : SYNful Knock implant appears to be much bigger than first reported, researchers say </description><link>http://www.secuobs.com/revue/news/583724.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/583724.shtml</guid></item>

 </channel>
</rss>
