Month: March 2017

ComputerWorldIndependent

Defensive Computing for email attachments

Credit to Author: Michael Horowitz| Date: Wed, 15 Mar 2017 12:12:00 -0700

Email attachments remain an effective way to infect/compromise computers because people trust them too much. Blindly opening them is easy, simple and quick, but, it’s also not secure. What is secure?

Never open email attachments using Microsoft Office or Adobe’s PDF reading software.

Really should go without saying at this point.

Never open attachments on a Windows, Mac or Linux computer you care about or use regularly.

These old desktop systems are simply not as secure as more modern operating systems.

The safest computers for opening suspect files run iOS or Chrome OS.

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

Microsoft fixes record number of flaws, some publicly known

Credit to Author: Lucian Constantin| Date: Wed, 15 Mar 2017 11:54:00 -0700

Microsoft’s batch of security patches for March is one of the largest ever and includes fixes for several vulnerabilities that are publicly known and actively exploited.

The company published 17 security bulletins covering 135 vulnerabilities in its own products and one separate bulletin for Flash Player, which has its security patches distributed through Windows Update. Nine bulletins are rated critical and nine are rated as important.

The affected products include Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Exchange, Skype for Business, Microsoft Lync, and Silverlight.

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

IDG Contributor Network: Largest ever Patch Tuesday from Microsoft

Credit to Author: Greg Lambert| Date: Wed, 15 Mar 2017 11:44:00 -0700

After last month’s rather brief Patch Tuesday from Microsoft, we see the largest ever release of updates for Windows and Microsoft Office — and of course another critical update for Adobe Flash Player.

For this March update, we see an unusually large number of critical updates — nine patches rated as critical and the remaining nine rated by Microsoft as important. In addition to this large cohort of patches, we also get a security advisory with KB3123479.

We have added both browser patches (MS17-006 and MS17-007) and the Adobe Flash Player update (MS17-023) to our “Patch Now” list. In addition, the core XML Services patch (MS17-022), though only rated as important by Microsoft, attempts to resolve a publicly disclosed zero-day flaw. MS17-022 was therefore also added to our “Patch Now” list.

To read this article in full or to leave a comment, please click here

Read More
SecuritySophos

Why you should put your staff to the test with phishing drills

Credit to Author: Bill Brenner| Date: Wed, 15 Mar 2017 18:56:42 +0000

When Sophos Phish Threat was released in January, we pointed out that: Email remains one of the most problematic sources of infection; and It’s the ordinary, well-meaning people who often let poisonous emails into their organizations. Phishing is an old problem, but news stories continue to show that people remain easy prey. New attacks, old tactics A recent […]

Read More
FortinetSecurity

FortiMail named IDC Email Security Leader

Credit to Author: Carl Windsor| Date: Wed, 15 Mar 2017 11:05:56 -0700

As a product manager, the start of the year is a time to take a few breaths and reflect on the successes or failures of the past year and plan for future projects.  When we have invested so much effort into our products, we know their strengths, but spending so much time in such close proximity to a solution can also make one a bit blinkered. Which is why it is always important to get outside opinions on your progress as a sanity check. Of course, customer feedback is essential, and always very welcome, but it was particularly satisfying to…

Read More
SecurityTrendMicro

Welcome to Pwn2Own 2017 – The Schedule

Credit to Author: Dustin Childs (Zero Day Initiative Communications)| Date: Wed, 15 Mar 2017 16:59:01 +0000

Welcome to Pwn2Own 2017 – the tenth anniversary of the competition and our largest Pwn2Own ever. This is also our largest contest ever with over $1,000,000 USD up for the taking – and continuing what we started last year, we’ll crown a “Master of Pwn” as the overall winner on Day Three. As we do every…

Read More
ComputerWorldIndependent

4 charged, including Russian gov't agents, for massive Yahoo hack

Credit to Author: Martyn Williams| Date: Wed, 15 Mar 2017 09:22:00 -0700

The FBI on Wednesday charged four people, including two Russian state intelligence agents, for their involvement in a massive hack of Yahoo that affected half a billion accounts.

In September, Yahoo said hackers had managed to steal personal data on more than 500 million users during an attack in late 2014. The stolen data included names, email addresses, telephone numbers and hashed passwords. Blame for the attack was put on a “state-sponsored” group.

The FBI said that group was the Russian Federal Security Service, the FSB, and it identified agents Dmitry Dokuchaev and Igor Sushchin as leaders of the attack.

To read this article in full or to leave a comment, please click here

Read More