Showing posts with label Security Alert: Vulnerability Management. Show all posts
Showing posts with label Security Alert: Vulnerability Management. Show all posts

Sunday, January 2, 2011

Weekend Vulnerability and Patch Report, December 31, 2010

The following software updates were released last week. Citadel strongly recommends that readers upgrade these programs on their computers.

No upgrades were announced last week for popular home or SOHO (Small Office Home Office) software programs.

Important Vulnerabilities.

Microsoft Internet Explorer Vulnerability: As we reported last week, Microsoft has warned in a security advisory that an exploit now exists for the critical security vulnerability in Internet Explorer that we wrote about recently.The exploit runs remotely over the Internet, compromising a user's system and stealing sensitive information. The vulnerability has been confirmed in all versions of Internet Explorer, including IE 7 and 8. The exploit for this vulnerability gets around two of the key security defenses built into Windows Vista and Windows 7. We suggest running the latest version of Firefox with the NoScript add-on as an alternative to IE. 

If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.
 
If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.  
 
© Copyright 2011. Citadel Information Group. All Rights Reserved.

Sunday, December 26, 2010

Weekend Vulnerability and Patch Report, December 24, 2010

The following software updates were released last week. Citadel strongly recommends that readers upgrade these programs on their computers.

Java Update: Sun has published an update to Java, its ubiquitous browser plug-in. The new version is Java 6, Update 23. Readers can identify their version of Java and get installation help here. Readers will want to pay attention in upgrading Java to make sure that the install does not also install other software, such as the Yahoo Toolbar. 

Important Vulnerabilities.

Microsoft Internet Explorer Vulnerability: Microsoft has warned in a security advisory that an exploit now exists for the critical security vulnerability in Internet Explorer that we wrote about last week. The exploit runs remotely over the Internet, compromising a user's system and stealing sensitive information. The vulnerability has been confirmed in all versions of Internet Explorer, including IE 7 and 8. The exploit for this vulnerability gets around two of the key security defenses built into Windows Vista and Windows 7. We suggest running the latest version of Firefox with the NoScript add-on as an alternative to IE. 

IBM Lotus Notes: Several security vulnerabilities have been identified in IBM Lotus Notes Traveler. Readers should update to version 8.5.1.3 or later. More information is available here.

Adobe Flash: Adobe Flash is a favorite of cyber criminals who seem able to regularly find critical security vulnerabilities in the program. Readers should make sure they are running the latest version of Flash. You can check your version of Adobe Flash here. 

Adobe Reader: Adobe Reader is another favorite of cyber criminals who seem able to regularly find critical security vulnerabilities in the program. Readers should make sure they are running the latest version of Reader. Readers can check for update under "Help" in the file menu. The latest version is 10.0.0.

If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.
 
If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.  
 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Sunday, December 19, 2010

Weekend Vulnerability and Patch Report, December 17, 2010

The following software updates were released last week. Citadel strongly recommends that readers upgrade these programs on their computers.

Microsoft Security Update: This month's Patch Tuesday from Microsoft contains 17 software updates plugging a total of 40 security holes. According to Microsoft the updates include fixes for at least 7 vulnerabilities in Internet Explorer versions 6, 7 & 8, including the 0-day vulnerability we've had on our vulnerability list for the last month. Patches are available through Microsoft Update (using IE) or Automatic Update.


Google Chrome Update: Google has released Chrome 8.0.552.224 to address multiple vulnerabilities. These vulnerabilities allow a cyber criminal to take control of a user's system and steal sensitive information or cause a denial-of-service condition. Users can get the Google Chrome update here.

F-Secure Anti-Virus Products: A vulnerability has been reported in various F-Secure products which can be exploited to compromise a user's system and steal sensitive information. Updates are distributed automatically by the update system.Users should make sure they are running the latest version. 

Adobe PhotoShop Update: A critical vulnerability has been discovered in Adobe PhotoShop. A cyber criminal can exploit the vulnerability to take control of a user's system and steal sensitive information. The vulnerability has been confirmed in CS4 and CS5 for Windows. Other versions may also be affected. Users should apply Adobe Photoshop 12.0.3 update for Adobe Photoshop CS5.

Apple AirPort Updates: Apple has released AirPort Utility 5.5.2 for Mac and Windows to fix security vulnerabilities. Apple has also fixed security vulnerabilities in its newly released AirPort Base Station and Time Capsule firmware update 7.5.2. Users can download these updates from Apple's Downloads page.
 
iTunes Update: Apple has released iTunes 10.1.1 which fixes several performance and security vulnerabilities.

Important Vulnerabilities.

Symantec Antivirus Alert Management System Vulnerability:  A vulnerability has been reported in Symantec Antivirus, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is reported in Symantec Antivirus Corporate Edition 10.1.4.4010. Other versions may also be affected. No patch is available at this time.   

Opera: Multiple vulnerabilities have been reported in Opera some of which can be exploited by malicious people to disclose potentially sensitive information and manipulate data. The vulnerabilities are reported in versions prior to 11.00. Users should upgrade to version 11.00 which can be found here. 

Microsoft Internet Explorer Vulnerability: On the same day that Microsoft finally fixed the security vulnerabilities that we had listed on our blog for a month, a new critical vulnerability has been discovered in Internet Explorer, which can be exploited by malicious people to compromise a user's system and steal sensitive information. The vulnerability is confirmed in Internet Explorer 7 and 8 on a fully patched Windows XP SP3 system. We suggest running the latest version of Firefox with the NoScript add-on as an alternative to IE. 

RealPlayer Vulnerabilities: Twenty eight critical security vulnerabilities have been found in earlier versions of RealPlayer. Windows users want to make sure they are running RealPlayer 14.0.0 or later. Mac users should make sure they are running version 12.0.0.1548 or later. 

BlackBerry Vulnerabilities: RIM has released a security advisory to address a vulnerability that allow a cyber criminal to take control of a user's BlackBerry and steal sensitive information or cause a denial-of-service condition. Users should alert their IT staff to BlackBerry server security advisory KB24761 so that they may apply  necessary updates to help mitigate these risks. Vulnerabilities in BlackBerry Desktop Software have been discovered. Windows users should make sure they are running BlackBerry Desktop Software version 6.0.1 or later. Macintosh users should make sure they are running BlackBerry Desktop Software version 2.0 or later.

 If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.
If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.  
 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Saturday, December 11, 2010

Weekend Vulnerability and Patch Report, December 10, 2010

The following software updates were released last week. Citadel strongly recommends that readers upgrade these programs on their computers.

Apple QuickTime Update: Apple has released QuickTime version 7.6.9. This update fixes 15 highly critical security vulnerabilities that a cyber criminal can use to take control of a user's system and steal sensitive information. Updates are available for both Mac and Windows versions of the program are available through Apple Downloads. Windows users can also download and install the update through the their iTunes or QuickTime Software Update feature. Mac users can update through the Mac's Software Update feature.
Firefox Update: Firefox has released version 3.6.13 fixing several highly critical security vulnerabilities that a cyber criminal can use to take control of a user's system and steal sensitive information. Users can update by going to "Help/Check for Updates" on the Taskbar.

WordPress Update: A week after releasing 3.0.2, WordPress has released version 3.0.3 to address a highly critical vulnerability that allows a cyber criminal to change or delete a web site built in WordPress. A cyber criminal could also exploit the vulnerability to attack the computers of visitors to the web site. Users will want to notify their web master to upgrade to version 3.0.3. Users whose website has been built using Joomla will also want to notify their webmaster of two newly discovered Joomla vulnerabilities in that popular content management system.
 
Apple MacBook Firmware Update: Apple has released a firmware update to its 11-inch and 13-inch MacBook Air models.According to Apple, the "update resolves a rare issue where MacBook Air boots or wakes to a black screen or becomes unresponsive."  While not a security update, users will want to update. Users can download the update here.
 
Important Vulnerabilities.

Microsoft Patch Tuesday: Microsoft is scheduled to release its monthly updates this coming Tuesday. Let's hope the IE Vulnerability we've been writing about is on the list. Make sure your PC gets updated.

Google Earth: A vulnerability has been discovered in Google Earth, which can be exploited by malicious people to to take control of a user's system. The vulnerability is confirmed in version 5.1.3533.1731. Users want to make sure they are running version 6.0.

Citrix Web Interface Vulnerability: A vulnerability has been found affecting versions 5.0, 5.1, and 5.3. The vulnerability does not affect version 5.4. You most likely want to update but check with IT staff before doing so.
 If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.
If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.  
 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Sunday, December 5, 2010

Weekend Vulnerability and Patch Report, December 3, 2010

The following software updates were released last week. Citadel strongly recommends that readers upgrade these programs on their computers.

McAfee VirusScan Enterprise: A highly critical vulnerability has been found in McAfee VirusScan Enterprise, which can be exploited by malicious people to compromise a user's system. The vulnerability is confirmed in version 8.5.0i. Other versions may also be affected. The vulnerability has been fixed in McAfee VirusScan version 8.7i and later.

Google Chrome: Google has released version 8.0.552.215 to fix multiple vulnerabilities in Google Chrome 7.x. The latest version of Chrome is available here.

WordPress 3.0.2: WordPress has released WordPress 3.0.2 to address multiple security vulnerabilities. The new version is available here.

D-Link DIR-615: Moderately critical vulnerabilities have been found in this popular wireless router. The vulnerabilities have been found in firmware versions prior to revision D.4-13B01. Users should update their routers to the latest firmware version. Information from D-Link on how to upgrade the firmware on the DIR-615 line of routers can be found here.  

News of Important Vulnerabilities.

CA Internet Security Suite Plus 2010: A vulnerability has has been discovered in CA Internet Security Suite Plus which can be exploited by malicious, local users to gain escalated privileges. No patch is available at this time.

Palm Pre WebOS: Dark Reading reports a moderately critical vulnerability has been found in WebOS 1.4.x versions. According to Secunia, this vulnerability has reportedly been fixed in WebOS 2.0 beta.We have no more information at this time. Palm's web-site is here.  

Kindle for PC: A vulnerability has been discovered in the Kindle for PC program 1.x. According to Secunia, no patch is available at this time. Users are cautioned to only open files from trusted sources. 

Adobe Reader: If you have not yet updated to Adobe Reader X (as we recommended last week), you should do so now. You can download Reader X using the Adobe Download Manager from the Adobe Reader web site. To avoid the Download Manager with its attempt to get you to download other software as well, Windows users can download Windows Reader X here while Mac users can download Mac Reader X here. 

Microsoft Internet Explorer: Microsoft has still not issued an update to fix a zero-day highly critical vulnerability in Internet Explorer that, according to KrebsOnSecurity.com, cyber criminals are exploiting to break into Windows computers.We suggest running the latest version of Firefox with the NoScript add-on as an alternative to IE.

If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.

If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.  
 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Sunday, November 28, 2010

Weekend Vulnerability and Patch Report, November 26, 2010

The following software updates were released last week. Citadel strongly recommends that readers upgrade these programs on their computers.

Adobe Reader: Adobe has released Reader X. This follows repeated security problems with previous versions of Reader. The new Reader should be more secure than earlier versions as it has been built using advanced "sandbox" technology. You can download Reader X using the Adobe Download Manager from the Adobe Reader web site. To avoid the Download Manager with its attempt to get you to download other software as well, Windows users can download Windows Reader X here while Mac users can download Mac Reader X here.

Apple iOS: Apple has released iOS 4.2 for for the iPhone, iPad and iTouch. In addition to improved performance, this update fixes several security vulnerabilities. These updates are available during synchronization.
 
Trend Micro:  TrendMicro has released an update to OfficeScan 10.x. The update fixes a vulnerability that put users at risk of a cyber criminal taking full control of their computer. 
 
News of Important Vulnerabilities.

Microsoft Internet Explorer: Microsoft has still not issued an update to fix a zero-day highly critical vulnerability in Internet Explorer that, according to KrebsOnSecurity.com, cyber criminals are exploiting to break into Windows computers.We suggest running the latest version of Firefox with the NoScript add-on as an alternative to IE. 

If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.

If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.  
 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Saturday, November 20, 2010

Weekend Vulnerability and Patch Report, November 19, 2010

The following software updates were released last week. Citadel strongly recommends that readers upgrade these programs on their computers.

Apple Safari:  Apple has released Safari 5.0.3 and 4.1.3 to address multiple vulnerabilities in the Safari and WebKit packages. Because of these vulnerabilities, users are at risk of a cyber criminal taking full control of their computer. See Apple article HT4455 for more information.

Adobe Reader and Acrobat: Adobe has released security updates for Reader and Acrobat for Windows and Macintosh. These updates address multiple vulnerabilities that put users at risk of a cyber criminal taking full control of their computer. See Adobe Bulletin APSB10-28 for additional information.

Mac OS X: Apple has released Mac OS X v10.6.5 and Security Update 2010-007 to address multiple highly critical vulnerabilities in OS X. Mac users should install these. These updates are available on Apple's Downloads page and we urge all users to apply them. 

News of Important Vulnerabilities.

Microsoft Internet Explorer: Microsoft has still not issued an update to fix a zero-day highly critical vulnerability in Internet Explorer that, according to KrebsOnSecurity.com, cyber criminals are exploiting to break into Windows computers.We suggest running the latest version of Firefox with the NoScript add-on as an alternative to IE. 

RealPlayer: RealPlayer users should make sure they are running version 14.0.1.609 or later as serious vulnerabilities have been found in some earlier versions. 

WordPress: For those of you with web sites coded in the popular WordPress, Secunia has announced that an extremely serious security vulnerability has been found in the WordPress' Event Registration Plugin. (This follows the announcement last week of 6 serious WordPress vulnerabilities.) The vulnerability has the potential to allow a cyber criminal full access to any databases connected to a web site using the plug-in. Insist your web-master takes steps to protect any of your sensitive information that this vulnerability puts at risk. Direct your web-master to Secunia Advisory SA42265 for more information.

If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.

If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.  
 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Sunday, November 14, 2010

Weekend Vulnerability and Patch Report, November 12, 2010

Microsoft Windows & Office: This month's Patch Tuesday fixed more than 11 security flaws in Microsoft products. One patch fixes a highly critical vulnerability that could allow a cyber criminal to gain control of a user's computer simply by having the user view an email in Outlook's Preview Pane. We strongly recommend all home users make sure that automatic updates is turned on so these and other Microsoft patches will be downloaded and installed automatically. All other things being equal business computers should also have automatic updates turned on, except sometimes the IT department has to manage these updates differently.

Microsoft did not issue an update to fix a zero-day highly critical vulnerability in Internet Explorer that, according to KrebsOnSecurity.com, cyber criminals are exploiting to break into Windows computers.We suggest running the latest version of Firefox with the NoScript add-on as an alternative to IE.

Mac OS X: Apple has issued several updates to patch highly critical vulnerabilities in OS X. Mac users should install these. These are available on Apple's Downloads page and we urge all users to apply them. 

iTunes / QuickTime: Users should download and install iTunes 10.1 which includes Apple's QuickTime 7.6.8. Don't be lulled into a false sense of security though. Secunia has announced that a highly critical 0-day vulnerability has already been discovered in the new QuickTime version 7.6.8.

PayPal for iPhone: PayPal has issued an update fixing a relatively minor security vulnerability in it's iPhone app. We suggest users update to the latest version.

WordPress: For those of you with web sites coded in WordPress, Secunia has announced a number of security vulnerabilities in various WordPress plug-ins. Direct your web-masters to Secunia's web-site for more information.

If you are responsible for keeping your computer secure, this is for you. If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.
 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Sunday, November 7, 2010

Weekend Vulnerability and Patch Report, November 5, 2010

Adobe Update for Flash Player: Adobe has now fixed the 0-day Flash vulnerability we reported last week. This update fixes 18 different security holes. Readers are urged to update their Flash version to v 10.1.102.64. Updates are available for Windows, Macintosh, Linux, and Solaris versions of Flash. If you use Internet Explorer in addition to other browsers, you will need to apply this update twice: Once to install the Flash Active X plugin for IE, and again to update other browsers, such as Firefox or Google Chrome. The new version is available from this link, but be aware that if you accept all of the default settings, the update may include additional software, such as a toolbar or anti-virus scanner.

Microsoft Warns of New IE 0-Day Vulnerability: Microsoft warned Internet Explorer users that attackers are exploiting a previously unknown security hole in their browser to install malicious software on user workstations. User workstations can be compromised simply by visiting a compromised web site. (Compromised web sites are all-too-common. See our blog post of April 19: Visitors to Web Sites Hosted by Network Solutions Again at Risk and August 16: Network Solutions Once Again Serves Up Malware.) Hopefully Microsoft will update IE on this week's Patch Tuesday. We recommend using Firefox with the No-Script add-on for Internet browsing, particularly until this 0-day is patched.

Mobile Banking Security Holes Discovered; Great Caution Urged: Be very careful  if you access your bank account from your iPhone or Android. Security research firm viaForensics reports that mobile apps from USAA, Chase, Wells Fargo, Bank of America, and TD Ameritrade have major security holes. The bugs could potentially allow a hacker to learn your username, password, and financial information. Information could be stolen just by visiting a malicious website. According to The Wall Street Journal and Yahoo News, Wells Fargo and USAA have already released updates, Bank of America should have an update out in the next few days, and TD Ameritrade will fix the issue in the next 30 days. We continue to urge great caution in mobile online banking. If you don't absolutely need it, don't use it. Readers who must use mobile online banking are urged to upgrade their online bank apps as quickly as upgrades become available.

Beware of ThinkPoint and Other Fake Anti-Virus Products: A small business we know was recently infected with ThinkPoint. It was delivered via a fake Microsoft Security Essentials Alert that was clicked on by an unsuspecting employee. Once installed, ThinkPoint tried to prevent the company from using the workstation until it paid money to buy a licensed version of useless software. ThinkPoint is just one more reminder of how users must be extremely careful what they allow to run on their computers. Don't trust a reminder to upgrade or install software unless you're sure it's legit. Set Microsoft to update automatically. Check Adobe products regularly. Follow our alerts. Better safe than sorry.

If you are responsible for keeping your computer secure, this is for you. If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.

 
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Friday, October 29, 2010

Weekend Vulnerability and Patch Report, October 29, 2010

Adobe Shockwave Update: Adobe has released a critical update for its shockwave player. The shockwave patch plugs 11 different security holes affecting both Windows and Mac computers. Readers should update to the newest Adobe Shockwave Player.

Adobe Advisory for Flash Player, Acrobat Reader and Acrobat: Adobe has issued a security advisory that a new 0-day vulnerability has been found affecting all these products. The vulnerability affects these Adobe products on Windows, Mac and other operating systems. Readers are urged to be cautious until Adobe issues a patch for this vulnerability. We will alert readers to the patch when it is released.

Facebook Users Under Attack: According to KrebsOnSecurity.com, Facebook users running Mac OS X are being attacked by a new version of the Koobface worm. The attack uses a malicious Java applet. In order for the attack to succeed the user must OK a prompt to download and install the malicious software. Readers are urged to be cautious in allowing Facebook applets to run. Readers should also make sure the have the latest version of Java running on their Mac.

Firefox Update: Firefox has been updated to version 3.6.12. The program and its predecessor 3.6.11 (also released this week) fix 10 security vulnerabilities, many critical. Readers should update to the newest version. 

If you are responsible for keeping your computer secure, this is for you. If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

The Weekend Vulnerability and Patch Report is intended to raise user awareness to cyber security challenges by alerting them to some of the week's important vulnerability news and updates.
© Copyright 2010. Citadel Information Group. All Rights Reserved.

Friday, October 22, 2010

Weekend Patch Report, Oct 22, 2010

RealPlayer: RealPlayer has released a product upgrade that fixes several critical vulnerabilities. The latest versions are available here. (October 20). 

Microsoft Windows & Office: This month's Patch Tuesday fixed a record 49 security holes. Always install Microsoft patches. Home computers should have automatic updates turned on. All other things being equal so should business computers, except sometimes the IT department has to manage these updates differently. (October 12)

Java:  This is a critical update. Microsoft has issued a warning that it is seeing a huge increase in attacks against security vulnerabilities in Java. When you are on the Internet, Java is running. Make sure to install this update. (October 12)

Adobe Reader & Acrobat: This critical update plugs at least 23 holes in the Adobe PDF Reader and Acrobat software, including two vulnerabilities that are being actively exploited by cyber criminals. Update your program while running it. "Check for Updates" is on the drop-down list under "Help." (Oct 5)

If you are responsible for keeping your computer secure, this is for you. If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Patch Report to them and following up to make sure your computer has been patched.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). Just like DNA, every program has hidden flaws, or vulnerabilities, in its code. When software companies find a vulnerability, they will issue an update patch to fix the code running in their customer's computers.

It is the user's responsibility to make sure update patches are installed. Home users usually have to do this themselves. Users working in offices may have IT staff to do this for them, but even here, Citadel recommends strongly that users take the initiative to check that updates are being installed on their computers.

The Weekend Patch report is intended to raise user awareness to the challenges of vulnerability management by alerting them to some of the week's important update patches. We do this to help users get the knowledge they need to take the necessary initiative in making sure the security of their computers is being effectively managed.


© Copyright 2010. Citadel Information Group. All Rights Reserved.


Tuesday, October 5, 2010

Critical Security Updates Available for Adobe Acrobat/Reader

Adobe has announced that critical updates are now available for the Adobe Acrobat/Reader vulnerabilities we described in our blog post of September 8: Cybercriminals Exploit New 0-Day Adobe Acrobat/Reader Vulnerability.

We strongly recommend that users immediately update their Adobe Acrobat and Reader programs. To do so, open the Adobe Acrobat or Adobe Reader program, click on 'Help' and then 'Check for Updates."

Monday, September 20, 2010

Security update available for Critical 0-Day Vulnerability in Adobe Flash Player

Adobe has released a security update to the Flash vulnerability we reported last week (Adobe Issues Security Advisory for Critical 0-Day Flash Player Vulnerability).

Adobe recommends all users of Adobe Flash Player 10.1.82.76 and earlier versions upgrade to the newest version 10.1.85.3 by downloading it from the Adobe Flash Player Download Center or by installing it via the auto-update mechanism within the product when prompted.

To verify the version of Adobe Flash Player installed on your system, access the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe (or Macromedia) Flash Player" from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system.

Monday, September 13, 2010

Adobe Issues Security Advisory for Critical 0-Day Flash Player Vulnerability

Adobe has announced a critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android. This vulnerability (CVE-2010-2884) could allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows.

As attacks exploiting this vulnerability are likely to get by anti-virus and anti-malware defenses, users should consider installing advanced intrusion-prevention technology capable of blocking 0-day attacks.

Wednesday, September 8, 2010

Cybercriminals Exploit New 0-Day Adobe Acrobat/Reader Vulnerability

Adobe has announced that a critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX. The vulnerability is also present in Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh.

The vulnerability (CVE-2010-2883) could allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.

Users are advised to take extra precautions in opening Adobe PDF files. As attacks exploiting this vulnerability are likely to get by anti-virus and anti-malware defenses, users should consider installing advanced intrusion-prevention technology capable of blocking 0-day attacks.

Wednesday, August 25, 2010

Adobe, Apple Issue Security Updates

KrebsOnSecurity reports that both Adobe and Apple have released security updates or alerts in the past 24 hours. Adobe pushed out a critical patch that fixes at least 20 vulnerabilities in its Shockwave Player, while Apple issued updates to correct 13 flaws in Mac OS X systems.

Apple’s update affects Mac OS X Server 10.5, Mac OS X 10.5.8 , Mac OS X Server 10.6 , Mac OS X 10.6.4 and is available via Software Update or from Apple Downloads.

Krebs writes "The Adobe patch applies to Shockwave Player 11.5.7.609 and earlier on Windows and Mac operating systems. Adobe recommends that users upgrade to Shockwave Player 11.5.8.612, available at this link. But before you do that, you might want to visit this link, which will tell you whether or not you need to update, and indeed whether you currently have Shockwave installed at all. If you visit it and don’t see an animation, then you don’t have Shockwave (and probably aren’t missing it either)."

Thursday, August 19, 2010

Adobe Issues Acrobat, Reader Security Patches

KrebsOnSecurity.com reports Adobe Systems Inc. today issued software updates to fix at least two security vulnerabilities in its widely-used Acrobat and PDF Reader products. Acrobat and Reader users can update to the latest version, v. 9.3.4, using the built-in updater, by clicking “Help” and then “Check for Updates.”

Krebs writes that "today’s update is an out-of-cycle release for Adobe, which recently moved to a quarterly patch release schedule. ...  More information on these patches, such as updating older versions of Acrobat and Reader, is available in the Adobe security advisory."

Wednesday, August 18, 2010

Apple Patches Fix Security Vulnerabilities

KrebsOnSecurity reports Apple has released a series of patches to correct security vulnerabilities in several of its products:

Tuesday, August 10, 2010

Critical Updates for Windows, Flash Player

KrebsOnSecurity.com reports Microsoft issued a record number of software updates today, releasing 14 update bundles to plug at least 34 security holes in its Windows operating system, Microsoft Office and other software. More than a third of flaws earned a “critical” severity rating, Microsoft’s most serious.

Krebs also reports Adobe released a patch for its ubiquitous Flash Player that fixes at least six flaws in Flash. The newest version brings Flash to v. 10.1.82.76. If you’d like to know what version of Flash you are currently using, browse to this link.

Sunday, August 8, 2010

Security Flaw Allows Users to Jailbreak their iPhones

When is a security flaw not a security flaw? There are a lot of happy iPhone people this week who have been able to "jailbreak" their iPhones thanks to a security flaw in Apple's iOS4 [through version 4.0.1]. While many iPhone users — myself included — are content to run our iPhones the way Steve Jobs intended, many users are known to chafe at the limits that Jobs [and AT&T] have built into the iPhone. Hence the demand for products that allow these disgruntled users to break their iPhone out of the jail to which they have been sentenced by Jobs and [AT&T].

The Apple flaw manifests in PDF readers, like those of Adobe and Foxit. And while no one knows of any security exploits targeting this vulnerability, as security experts, these kinds of holes are the scary stuff that keeps us up at night.

As Brian Krebs writes in KrebsOnSecurity.com: "I’m left wondering what to call these sorts of vulnerabilities that quite obviously give users the freedom that jailbreaking their device(s) allows (the ability to run applications that are not approved and vetted by Apple) but that necessarily direct the attention of attackers to very potent vulnerabilities that can be used to target jailbreakers and regular users alike."

Perhaps we ought to view these jailbreakers the same way we view the proverbial canaries in the mine: as early-warning systems designed to alert the rest of us to vulnerabilities needing to be corrected. If the jailbreakers can find vulnerabilities before the cybercriminals have found and exploited them, then the community benefits from their efforts.