Ryan Naraine

March 12, 2010, 2:06PM Threatpost Original

The Cadence of Microsoft Security Patches

By Andrew Storms

Every month, like clockwork, Microsoft releases security bulletins and every month people ask me if it's small or a big release. While the exact details of the patches are generally treated as news, the expected workload each month really shouldn't be a guessing game because Microsoft's patch releases are predictably cyclical.

Shorten URL: http://threatpost.com/en_us/3JF. Click to copy to clipboard or post to Twitter

March 12, 2010, 10:40AM Threatpost Original

Andy Jaquith on Measuring Meaningful Information Security Metrics

The March issue of Information Security magazine is out this week. The cover story is a look at how security information management systems need to evolve, in particular by integrating identity management with SIM in order to tie policy violations to user activity. Also, expert Andrew Jaquith writes about how to measure meaningful information security metrics. Finally, editor Marcia Savage takes on the HITECH Act's impact on HIPAA and how health care organizations must up their security game. Download the issue here [PDF]

Shorten URL: http://threatpost.com/en_us/3Jy. Click to copy to clipboard or post to Twitter

March 11, 2010, 6:39PM Threatpost Original

Apple Plugs 16 Safari Security Holes

Apple has shipped a new version of its Safari browser to plug multiple serious security vulnerabilities.

The Safari 4.0.5 update, available for Mac OS X and Windows, fixes flaws that could lead to remote code execution if a user is tricked into surfing to a maliciously rigged Web site.

Shorten URL: http://threatpost.com/en_us/3uJ. Click to copy to clipboard or post to Twitter

March 11, 2010, 12:43PM

VA Investigating Security Breach of Veterans' Medical Data

The Veteran Affairs Department's inspector general has launched a criminal investigation into a physician assistant's alleged downloading of veterans' clinical data at its Atlanta medical center.

The assistant allegedly recorded two sets of patient data on to a personal laptop for research purposes. One set included three years' worth of patient data and another held 18 years of medical information.  Read the full story [nextgov]

Shorten URL: http://threatpost.com/en_us/3uE. Click to copy to clipboard or post to Twitter

March 10, 2010, 6:31PM Threatpost Original

Exploit Code Published for Latest IE Zero-Day

Using obvious clues from a McAfee blog post, an Israeli hacker was able to pinpoint the latest Internet Explorer zero-day vulnerability and create working exploit code.

The exploit code, which provides a clear roadmap to launch drive-by download attacks against IE 6 and IE 7 users, is being fitted into the Metasploit point-and-click tool.

Shorten URL: http://threatpost.com/en_us/3zA. Click to copy to clipboard or post to Twitter

March 10, 2010, 4:37PM Threatpost Original

Recently Patched Adobe PDF Flaw Being 'Actively Exploited'

Malicious hackers have pounced on a newly patched Adobe PDF Reader vulnerability to plant Trojan downloaders on tardy Windows users.

According to researchers in Microsoft's malware protection center, the vulnerability (CVE-2010-0188) was patched less than a month ago, proving that malicious hackers are quick to find fresh targets for malware.

Shorten URL: http://threatpost.com/en_us/3zd. Click to copy to clipboard or post to Twitter

March 9, 2010, 2:26PM Threatpost Original

Microsoft Warns of New IE Zero Day Attacks

A zero-day (unpatched) vulnerability in Microsoft’s Internet Explorer is being exploited in the wild, the company warned in an advisory issued today.

On the same day it issued software fixes as part of its Patch Tuesday schedule, Microsoft released a pre-patch advisory to warn of the risk of remote code execution attacks against users of IE 6 and IE 7.

Shorten URL: http://threatpost.com/en_us/3tE. Click to copy to clipboard or post to Twitter

March 8, 2010, 8:27AM Threatpost Original

Energizer Battery Charger Contains Remote Access Backdoor

The United States Computer Emergency Response Team (US-CERT) has warned that the software included in the Energizer DUO USB battery charger contains a backdoor that allows unauthorized remote system access.

Shorten URL: http://threatpost.com/en_us/3Mt. Click to copy to clipboard or post to Twitter

March 4, 2010, 2:51PM Threatpost Original

Microsoft to Patch 8 Vulnerabilities in Windows, Office

Microsoft has announced plans to ship two security bulletins next week to fix a total of eight vulnerabilities affecting Windows and Office products.

Both bulletins are rated "important" because of the risk compromising the confidentiality, integrity or availability of user data.

Shorten URL: http://threatpost.com/en_us/3L9. Click to copy to clipboard or post to Twitter

March 3, 2010, 3:44PM Video

RSA 2010: Cryptographers Discuss Wisdom of 'Foolishness'

At the RSA conference in San Francisco, a panel of leading cryptographers reveal some of the lessons they have learned while making seemingly imprudent decisions. By going against the grain, new objectives can be made and boundaries overcome.

Shorten URL: http://threatpost.com/en_us/3Fo. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy