Month: January 2018

ComputerWorldIndependent

Win7 Monthly Rollup KB 4056894 signals early, abbreviated Patch Tuesday

Credit to Author: Woody Leonhard| Date: Fri, 05 Jan 2018 06:48:00 -0800

Last night Microsoft released KB 4056894, the 2018-01 Security Monthly Quality Rollup for Windows 7. Spurred by early disclosure of the Meltdown and Spectre vulnerabilities, Microsoft has done yeoman work getting the software part of the patches pushed out the Automatic Update chute.

That said, Windows patches are only part of a very formidable picture.

Where we stand with Windows patches

As of this morning, all of the supported versions of Windows have Meltdown-related patches, except for Windows 8.1. In particular:

To read this article in full, please click here

Read More
FortinetSecurity

A Security Fabric for Digital-Age Healthcare: A Preview of HIMSS 2018

Credit to Author: Susan Biddle | Date: Fri, 05 Jan 2018 13:45:59 +0000

HIMSS 2018 will be held this year on March 5-9th at the Sands Expo Center in Las Vegas. Fortinet is excited to be attending this event yet again to meet with healthcare IT professionals standing on the front lines of digital transformation initiatives at their organizations, and to attend the various workshops, roundtables, and keynotes presented by thought leaders.

Read More
ComputerWorldIndependent

How Apple users can protect themselves against Spectre and Meltdown

Credit to Author: Jonny Evans| Date: Fri, 05 Jan 2018 06:26:00 -0800

Apple has confirmed that all Macs, iPhones, iPads and other devices (bar Apple Watch) are vulnerable to the newly-revealed Spectre and Meltdown Intel, ARM and AMD processor vulnerabilities.

What’s the problem?

Taking advantage of a vulnerability that has been around for 20-years, Meltdown and Spectre exploit a CPU performance feature called “speculative execution”. Speculative execution exists to improve computer speed by enabling the processor to work on multiple instructions at once, sometimes in non-sequential order.

To read this article in full, please click here

Read More
FortinetSecurity

Fortinet Advisory on New Spectre and Meltdown Vulnerabilities

Credit to Author: Fortinet| Date: Thu, 04 Jan 2018 18:45:59 +0000

Earlier this week, it was announced that researchers uncovered two new side channel attacks that exploit newly discovered vulnerabilities found in most CPU processors, including those from Intel, AMD, and ARM. These vulnerabilities allow malicious userspace processes to read kernel memory, thereby potentially causing sensitive kernel information to leak. These vulnerabilities are known as Meltdown and Spectre.

Read More
IndependentSecuriteam

Know your community – Sergi Alvarez AKA Pancake

Credit to Author: SSD / Maor Schwartz| Date: Thu, 04 Jan 2018 11:13:19 +0000

The creator of Radare2, vulnerability researcher, chef and a family man – meet Sergi Alvarez also known as Pancake! Questions Q: How many years have you been working in the security field? A: I started programming BASIC in Spectrum and PC/M. Then I switched to MSDOS and assembly (TASM) as a main language. From there … Continue reading Know your community – Sergi Alvarez AKA Pancake

Read More