TippingPoint Threat Intelligence and Zero-Day Coverage – Week of March 20, 2017
Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 24 Mar 2017 13:33:43 +0000
The 10th anniversary of Pwn2Own is now in the books! It was a crazy week at the CanSecWest Conference, full of drama with the biggest contest ever with teams from Asia, Europe and North America! It was a tight race with only three points separating first and second place.
In the end, we saw a record 51 bugs come through the contest, gave away $833,000 USD and 12 laptops to winners…and the award for Master of Pwn.
| |
You can catch up on the contest by visiting the following blogs:
If you take a look at the zero-day filters we have this week, you’ll see a number of them that include “Pwn2Own” in the filter name. You guessed it! TippingPoint customers are already protected from the very vulnerabilities discovered during the contest while the affected vendors are working on a patch.
It was a grueling contest this year, but definitely one for the record books, with virtual machine escapes and a hacked touch bar. Brian Gorenc, who leads the Zero Day Initiative team, gives his perspective on the past 10 years of Pwn2Own and what the future holds. I can’t wait to see what happens next year!
Virtual Threat Protection System (vTPS) v4.2.0 is Now Available!
Earlier this week, we released version 4.2.0 build 4654 for our TippingPoint Virtual Threat Protection System (vTPS).
vTPS v4.2.0 includes the following:
| |
For a complete list of enhancements and changes, customers can refer to the product Release Notes. For questions or technical assistance on any TippingPoint product, customers can contact the TippingPoint Technical Assistance Center (TAC).
Adobe Security Bulletins Update
This week’s Digital Vaccine (DV) package includes coverage for the Adobe Security Bulletins released on or before March 14, 2017. The following table maps TippingPoint filters to the Adobe Bulletins:
Bulletin # | CVE # | Digital Vaccine Filter # | Status |
APSB17-07 | CVE-2017-2997 | 27499 | |
APSB17-07 | CVE-2017-2998 | 27500 | |
APSB17-07 | CVE-2017-2999 | 27501 | |
APSB17-07 | CVE-2017-3000 | Insufficient Information | |
APSB17-07 | CVE-2017-3001 | 27493, 27511 | |
APSB17-07 | CVE-2017-3002 | 27502 | |
APSB17-07 | CVE-2017-3003 | 27503 |
Zero-Day Filters
There are 27 new zero-day filters covering six vendors in this week’s Digital Vaccine (DV) package. A number of existing filters in this week’s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and/or optimize performance. You can browse the list of published advisories and upcoming advisories on the Zero Day Initiative website.
Adobe (5)
| |
Apple (10)
| |
Google (1)
| |
Mozilla (1)
| |
Microsoft (6)
| |
Trend Micro (4)
| |
Missed Last Week’s News?
Catch up on last week’s news in my weekly recap.