Security

SecurityTrendMicro

TippingPoint Threat Intelligence and Zero-Day Coverage – Week of January 1, 2018

Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 05 Jan 2018 16:45:25 +0000

Happy New Year! It’s out with the old, in with the new, right? Except we all know that the old tends to stick around, especially when it comes to vulnerabilities and patching them. Trend Micro predicts that that 2018’s biggest attacks will originate from known vulnerabilities. And speaking of known vulnerabilities, the Zero Day Initiative…

Read More
ComputerWorldIndependent

Win7 Monthly Rollup KB 4056894 signals early, abbreviated Patch Tuesday

Credit to Author: Woody Leonhard| Date: Fri, 05 Jan 2018 06:48:00 -0800

Last night Microsoft released KB 4056894, the 2018-01 Security Monthly Quality Rollup for Windows 7. Spurred by early disclosure of the Meltdown and Spectre vulnerabilities, Microsoft has done yeoman work getting the software part of the patches pushed out the Automatic Update chute.

That said, Windows patches are only part of a very formidable picture.

Where we stand with Windows patches

As of this morning, all of the supported versions of Windows have Meltdown-related patches, except for Windows 8.1. In particular:

To read this article in full, please click here

Read More
ComputerWorldIndependent

How Apple users can protect themselves against Spectre and Meltdown

Credit to Author: Jonny Evans| Date: Fri, 05 Jan 2018 06:26:00 -0800

Apple has confirmed that all Macs, iPhones, iPads and other devices (bar Apple Watch) are vulnerable to the newly-revealed Spectre and Meltdown Intel, ARM and AMD processor vulnerabilities.

What’s the problem?

Taking advantage of a vulnerability that has been around for 20-years, Meltdown and Spectre exploit a CPU performance feature called “speculative execution”. Speculative execution exists to improve computer speed by enabling the processor to work on multiple instructions at once, sometimes in non-sequential order.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Windows, Meltdown and Spectre: Keep calm and carry on

Credit to Author: Woody Leonhard| Date: Thu, 04 Jan 2018 08:13:00 -0800

I’m increasingly skeptical of security holes that have their own logos and PR campaigns. Yesterday’s sudden snowballing of disclosures about two groups of vulnerabilities, now known as Meltdown and Spectre, has led to enormous numbers of reports of varying quality, and widespread panic in the streets. In the case of Intel’s stock price, that’s more like blood in the streets.

While it’s true that both vulnerabilities affect nearly every computer made in the past two decades, it’s also true that the threat — especially for plain-vanilla Windows users — isn’t imminent. You should be aware of the situation, but avoid the stampede. The sky isn’t falling.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Apple acts as digital transformation hits panic mode

Credit to Author: Jonny Evans| Date: Thu, 04 Jan 2018 08:03:00 -0800

Apple is updating its systems against newly revealed Spectre and Meltdown vulnerabilities, but it’s not enough to update personal devices – what about older PCs and the millions of servers that may also be vulnerable to the bug?

The bigger picture

The Spectre and Meltdown bugs are causing lots of distress. Meltdown impacts Intel processors, while Spectre appears to threaten chips from AMD and ARM as well. A good explanation of these vulnerabilities is here.

To read this article in full, please click here

Read More