Security Alerts




Mostly Windows Updates During March Patch Day

Microsoft has pre-announced next week’s Patch Day, and it doesn’t look too bad. (more…)

March 9, 2012 — Category: Security Alerts

WatchGuard Announces Fireware XTM and WSM v11.5.2

Available for All XTM Appliances 7 March, 2012 WatchGuard is excited to announce the general release of Fireware XTM v11.5.2 and WatchGuard System Manager v11.5.2. With this release, WatchGuard is proud to support the new XTM 2 Series models: XTM 25 and XTM 26 (more…)

March 7, 2012 — Category: Security Alerts

Unanticipated Flash Player Update Mends Two Critical Flaws

Summary: This vulnerability affects : Adobe Flash Player 11.1.102.62 and earlier, running on all platforms (including Android) How an attacker exploits it : By enticing users to visit a website containing malicious Flash content Impact : In the worst case, an attacker can execute code on the user’s computer, potentially gaining control of it What to do : Download and install the latest version of Adobe Flash Player (version 11.1.102.63 for computers) Exposure: Adobe Flash Player displays interactive, animated web content called Flash . Although Flash is optional, 99% of PC users download and install it to view multimedia web content. (more…)

March 5, 2012 — Category: Security Alerts

WatchGuard Security Week in Review: Episode 7

RSA Conference, Stratfor Email Leak, NASA Breach, and More Today’s WatchGuard Security Week in Review is coming to you a few hours late, primarily because I’ve just returned from a week at the RSA Security Conference in San Francisco. In this episode, I summarize that conference’s key themes, share the latest Anonymous news, mention some NASA breaches, and recommend a free security tool. (more…)

March 3, 2012 — Category: Security Alerts

Radio Free Security: February 2012 Episode

WatchGuard’s 2012 Security Predictions Do you know what security threats to expect this year? If not, join us for our second Radio Free Security episode where we share WatchGuard’s security predictions for 2012. (more…)

March 2, 2012 — Category: Security Alerts

WatchGuard Security Week in Review: Episode 6

Government Cyber Privacy Policy, Web Breaches, RSA Key Flaw Updates, and More Are you sick of Anonymous-related news? Well, I am. In this week’s WatchGuard Security Week in Review, I purposely ignore Anonymous stories to talk about other security news (more…)

February 24, 2012 — Category: Security Alerts

WatchGuard Security Week in Review: Episode 5

Lots of Patches, Big Nortel Breach, and More Anonymous Shenanigans Are you ready for another week of software updates, Enterprise breaches, and hacktivist cyber-riots? If so, this week’s episode of WatchGuard Security Week in Review is hot off the NLE system . Watch it below, and tell us what you think in the comments section. (more…)

February 17, 2012 — Category: Security Alerts

Adobe Flash Update Plugs Zero Day XSS Hole and Others

Summary: This vulnerability affects : Adobe Flash Player 11.1.102.55 and earlier, running on all platforms. This also affects the Android version of Flash. (more…)

February 16, 2012 — Category: Security Alerts

Grab Adobe’s Shockwave Update to Avoid Web-based Attacks

Summary: This vulnerability affects : Adobe Shockwave Player 11.6.3.633 and earlier, running on Windows and Macintosh computers How an attacker exploits it : By enticing your users into visiting a website containing a malicious Shockwave content Impact : An attacker can execute code on your computer, potentially gaining control of it What to do : If you allow the use of Shockwave in your network, you should download and deploy the latest version (11.6.4.634) of Adobe Shockwave Player as soon as possible. Exposure: Adobe Shockwave Player displays interactive, animated web content and movies called Shockwave . According to Adobe, the Shockwave Player is installed on hundreds of millions of PCs (more…)

February 16, 2012 — Category: Security Alerts

Oracle Shores Up 14 Major Java Vulnerabilities

Severity: High Summary: These vulnerabilities affect: All versions of Sun Java Runtime Environment (JRE) and Java Development Kit (JDK) released before today How an attacker exploits them: Typically by luring your users to a malicious web page containing specially crafted Java Impact: Various results; in the worst case, an attacker can gain complete control of your computer What to do: Install the appropriate JRE (or JDK) update as soon as possible Exposure: Java is a programming language (first implemented by Sun Microsystems) used most often to enhance web pages. Oracle’s Sun Java Runtime Environment (JRE) is one of the most popular Java interpreters used today. (more…)

February 15, 2012 — Category: Security Alerts