<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Citadel Information Group</title>
	<atom:link href="http://www.citadel-information.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.citadel-information.com</link>
	<description>Information Peace of Mind - Cyber Security Management</description>
	<lastBuildDate>Sun, 19 Feb 2012 18:49:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Weekend Patch and Vulnerability Report, February 19, 2012</title>
		<link>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-19-2012/</link>
		<comments>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-19-2012/#comments</comments>
		<pubDate>Sun, 19 Feb 2012 18:49:35 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Security Alert: Vulnerability Management]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2999</guid>
		<description><![CDATA[Important Security Updates Adobe Flash Player: Adobe has updated Flash to correct at least seven security vulnerabilities, many of which are highly critical. The current Windows version is 11.1.102.62.  Flash for Androids and other operating systems may have different version numbers. Adobe Shockwave: Adobe has released Shockwave 11.6.4.634 to patch at least nine security vulnerabilities many [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Important Security Updates</strong></h3>
<p><strong>Adobe Flash Player:</strong> Adobe has updated Flash to correct at least seven security vulnerabilities, many of which are highly critical. The current Windows version is 11.1.102.62.  Flash for Androids and other operating systems may have different version numbers.</p>
<p><strong>Adobe Shockwave</strong>: Adobe has released Shockwave 11.6.4.634 to patch at least nine security vulnerabilities many of which are highly critical. The update is available from <a href="http://www.adobe.com/products/shockwaveplayer/" target="_blank">Adobe&#8217;s website</a>.</p>
<p><strong>Google Chrome 17.0.963.56:</strong> Google has updated its Chrome browser to patch at least 12 vulnerabilities, many of which are highly critical. Chrome can be updated from within the browser.<strong><br />
</strong></p>
<p><strong>Microsoft Windows:</strong> Microsoft has issued nine security updates to fix at least 21 security vulnerabilities, many of them highly critical. Included in this month&#8217;s update is a patch to correct the highly critical vulnerability we first alerted readers to in <a href="../2012/02/2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>. Updates are available from the Windows Control Panel.</p>
<p><strong>Mozilla Firefox / Thunderbird / Seamonkey:</strong> Mozilla has updated these programs to correct a highly critical vulnerability. Update to Firefox 10.0.2 or 3.6.27, Thunderbird 10.0.2 or 3.1.19, or SeaMonkey 2.7.2.</p>
<p><strong>Oracle Java:</strong> Oracle has released Java SE 6 Update 31 and Java 7 Update 3. The updates patch at least 14 security vulnerabilities, many of which are highly critical. Updates can be installed from the Windows Control Panel.</p>
<h3>Current Software Versions</h3>
<p>Adobe Flash 11.1.102.62 [Warning; see below]</p>
<p>Adobe Reader 10.1.2</p>
<p>Apple QuickTime 7.7.1</p>
<p>Apple Safari 5.1.2  [Warning; see below]</p>
<p>Google Chrome 17.0.963.56</p>
<p>Internet Explorer 9.0.8112.16421</p>
<p>Java SE 6 Update 31</p>
<p>Mozilla Firefox 10.0.2</p>
<h3><strong>Newly Announced Unpatched Vulnerabilities</strong></h3>
<p><strong>ACDSee 14.x</strong>: <a href="http://secunia.com/advisories/47450/" target="_blank">Secunia </a>reports a highly critical unpatched vulnerability in ACDSee.</p>
<h3>Special Advisory Warning</h3>
<p><strong>Symantec pcAnywhere:</strong> As we reported in our<a href="../2012/02/2012/01/cyber-security-news-of-the-week-january-29-2012/" target="_blank"> Cyber Security News of the Week, January 29, 2012</a>, Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code.</p>
<h3><strong>For Your IT Department</strong></h3>
<p><strong>Cisco Advisory: </strong><a href="http://www.us-cert.gov/current/#cisco_releases_security_advisory_for29" target="_blank">US-CERT </a>has announced that Cisco has released a security advisory for its Nexus products.</p>
<h3><strong>Important Unpatched Vulnerabilities</strong></h3>
<p><strong>ACDSee Photo: </strong>Several highly critical vulnerabilities have been identified in various ACDSee photo products. Vulnerabilities have been identified in <a href="http://secunia.com/advisories/43564/" target="_blank">FotoSlate</a>, <a href="http://secunia.com/advisories/43563/" target="_blank">Photo Editor 2008</a>, and <a href="http://secunia.com/advisories/43562/" target="_blank">Picture Frame Manager</a>. No patches are available at this time. Readers should refrain from using ACDSee to open untrusted files. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/weekend-vulnerability-patch-report-june-12-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 12, 2011</a>. We alerted readers to a second vulnerability in <a href="http://secunia.com/advisories/44722/" target="_blank">FotoSlate </a>in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/weekend-vulnerability-and-patch-report-september-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, September 18, 2011</a>.</p>
<p><strong>ACD Systems Canvas CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45261/" target="_blank">highly critical vulnerability </a>has been found in ACD Systems Canvas which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files. Readers should refrain from opening untrusted files in ACD Systems Canvas. We first alerted readers to this vulnerability in <a href="../2012/02/2011/07/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>Adobe Flash: </strong>The <a href="http://secunia.com/advisories/47161/" target="_blank">highly critical vulnerability </a>we reported in <a href="../2012/02/2012/01/2011/12/vulnerability-and-patch-report-december-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 11,2011</a> remains unpatched. We recommend users disable the Flash player in their browsers or update to the newly-released beta [see above].</p>
<p><strong>Android Browser:</strong> <a href="http://secunia.com/advisories/47315/" target="_blank">Secunia </a>reports a vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to a this vulnerability in <a href="../2012/02/2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Apple Safari:</strong> <a href="http://secunia.com/advisories/47319/" target="_blank">Secunia </a>reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in <a href="../2012/02/2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.<br />
<strong></strong></p>
<p><strong>HTC Mobile Devices: </strong>The <a href="http://secunia.com/advisories/43163/" target="_blank">security vulnerability</a> in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/02/weekend-vulnerability-and-patch-report-february-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, February 11, 2011</a>.</p>
<p><strong>HTC Touch2:</strong> The <a href="http://secunia.com/advisories/47242/" target="_blank">highly critical 0-day vulnerability </a>in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/weekend-vulnerability-and-patch-report-december-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 18, 2011</a>.</p>
<p><strong>McAfee SaaS:</strong> The <a href="http://secunia.com/advisories/47520/" target="_blank">highly critical vulnerability</a> in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/weekend-patch-and-vulnerability-report-january-22-2012/" target="_blank">Weekend Vulnerability and Patch Report, January 22, 2012.</a></p>
<p><strong>Microsoft Windows XP: </strong>A <a href="http://secunia.com/advisories/45475/" target="_blank">less-critical security vulnerability </a>has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/weekend-vulnerability-and-patch-report-august-7-2011/" target="_blank">Weekend Vulnerability and Patch Report, August 7, 2011</a>.</p>
<p><strong>Microsoft Word: </strong>A <a href="http://secunia.com/advisories/44923/" target="_blank">highly critical vulnerability </a>has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/weekend-vulnerability-patch-report-june-19-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 19, 2011</a>.</p>
<p><strong>Microsoft Reader: </strong>The <a href="http://secunia.com/advisories/44121/" target="_blank">highly critical vulnerability </a>in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/weekend-vulnerability-and-patch-report-april-15-2011/" target="_blank">Weekend Vulnerability and Patch Report, April 15, 2011</a>.</p>
<p><strong>PDF-Pro:</strong> Several <a href="http://secunia.com/advisories/42805/" target="_blank">highly critical vulnerabilities</a> in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, March 4, 2011</a>.</p>
<p><strong><strong>Photoshop Elements:</strong> </strong>Adobe versions 1 – 8 contain a <a href="http://secunia.com/advisories/46277/" target="_blank">highly critical unpatched vulnerability</a>. The vulnerability is confirmed in version 8.0 20090905.r.605812 and Adobe reports that the vulnerability affects versions 8.0 and earlier. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/weekend-vulnerability-and-patch-report-october-9-2011/" target="_blank">Weekend Vulnerability and Patch Report, October 9, 2011</a>.</p>
<p><strong>Quick View Plus CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45281/" target="_blank">highly critical vulnerability </a>has been found in Quick View Plus which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/weekend-vulnerability-and-patch-report-july-31-2011/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>VLC Media Player:</strong> VLC has released an <a href="http://www.videolan.org/security/sa1108.html" target="_blank">advisory </a>regarding a highly critical unpatched vulnerability in versions 0.9.0 through 1.1.12. VLC has announced that media player 1.1.13 will address the issue. We first alerted readers to a this vulnerability in <a href="../2012/02/2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><em>If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.</em></p>
<p><em>If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.</em></p>
<p>Vulnerability management is a key element of <a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/04/2011/04/2011/04/services/" target="_self"><em>cyber security management</em></a>. Cyber criminals take over user computers by writing computer programs that “exploit” vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer’s computers.</p>
<p><a href="../2012/02/2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/" target="_blank">Citadel</a> publishes our <em>Weekend Vulnerability and Patch Report</em> to alert readers to some of the week’s important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-19-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News of the Week, February 19, 2012</title>
		<link>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-19-2012/</link>
		<comments>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-19-2012/#comments</comments>
		<pubDate>Sun, 19 Feb 2012 14:47:10 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Cyber Security Management]]></category>
		<category><![CDATA[ISSA-LA]]></category>
		<category><![CDATA[Privacy Matters]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2995</guid>
		<description><![CDATA[Dr. Stahl to discuss cyber security with KFWB&#8217;s Bob McCormick Dr. Stahl will be a guest on KFWB&#8217;s Money 101 with Bob McCormick on Tuesday, February 21 at 10:00 AM. KFWB is at AM980 and on the Internet. News of the Week Commentary — ISSA-LA Announces Annual Information Security Summit ISSA of Los Angeles Holds [...]]]></description>
			<content:encoded><![CDATA[<h3>Dr. Stahl to discuss cyber security with KFWB&#8217;s Bob McCormick</h3>
<p>Dr. Stahl will be a guest on KFWB&#8217;s Money 101 with Bob McCormick on Tuesday, February 21 at 10:00 AM. KFWB is at AM980 and on the <a href="http://kfwbam.com/" target="_blank">Internet</a>.</p>
<h3>News of the Week Commentary — ISSA-LA Announces Annual Information Security Summit</h3>
<p><a href="http://www.myprgenie.com/view-publication/issa-of-los-angeles-holds-fourth-annual-information-security-summit-on-protecting-businesses-from-cybercrime">ISSA of Los Angeles Holds Fourth Annual Information Security Summit on Protecting Businesses from Cybercrime:</a> The Los Angeles Chapter of the Information Systems Security Association (ISSA-LA) will hold its fourth annual Information Security Summit on Wednesday, May 16, 2012 at Hilton Universal City Hotel in Los Angeles. The theme of the one-day Summit is The Growing Cyber Threat: Protect Your Business.</p>
<h3>Cyber Crime</h3>
<p><a href="http://www.washingtonpost.com/business/technology/report-chinese-hackers-breach-nortel-networks/2012/02/14/gIQApXsRDR_story.html">Report: Chinese hackers breach Nortel networks:</a> Hackers working from China have reportedly had access to Nortel’s networks since breaching the telecommunication company’s networks as far back as 2000. According to a report from the Wall Street Journal, hackers stole seven passwords from Nortel’s top executives, granting them access to reports, business plans, employee e-mails and other documents. <em>Washington Post, February 14, 2012</em></p>
<p><a href="http://bits.blogs.nytimes.com/2012/02/14/how-much-have-foreign-hackers-stolen/?src=rechp">How Much Have Foreign Hackers Stolen?:</a> Hackers in China and Russia, security experts say, are habitually breaking into foreign travelers’ mobile devices, leapfrogging into their corporate networks and stealing sensitive government information and corporate trade secrets, often undetected. I explored this issue in an article in Saturday’s New York Times. <em>The New York Times, February 14, 2012</em></p>
<h3>Cyber Crime &#8211; Social Engineering</h3>
<p><a href="http://www.latimes.com/news/local/environment/la-me-gs-climate-deniers-heartland-institute-documents-leaked-20120216,0,3932985.story">Climate change doubter Heartland Institute documents leaked:</a> Earlier this week, the Heartland Institute, a self-described “free-market think tank” that pilloried climate scientists whose stolen emails were released in 2009 as part of the so-called Climategate flap, found itself duped out of several confidential fundraising documents that were then distributed widely over the Internet, offering a glimpse of its priorities. <em>LA Times, February 16, 2012</em></p>
<h3>Hacktivists</h3>
<p><a href="http://www.usatoday.com/tech/news/story/2012-02-14/anonymous-hacks-tear-gas/53087858/1">Anonymous movement claims attack on U.S. tear gas company:</a> The website of a U.S. company whose tear gas has been used against demonstrators in Egypt is the latest to be broken into by the Anonymous movement, hackers claimed Tuesday. <em>USA Today, February 14, 2012</em></p>
<h3>Cyber Security Management</h3>
<p><a href="http://www.forbes.com/sites/ciocentral/2012/02/12/conversations-on-cybersecurity-part-3-why-you-arent-protected/">Conversations On Cybersecurity Part 3: Why You Aren&#8217;t Protected:</a> When we last left the attorneys, they had learned who attacked them and why, they had learned how the attackers got into their systems, and they were waiting to learn why the tools that security vendors had sold them didn’t protect their computers against the targeted attacks. <em>Forbes, February 12, 2012</em></p>
<p><a href="http://yourlife.usatoday.com/health/story/2012-02-12/Data-breaches-put-patients-at-risk-for-identity-theft/53065576/1">Data breaches put patients at risk for identity theft:</a> Walk into a doctor&#8217;s office and chances are that some of your most private information &#8212; from your Social Security number to the details of your last cervical exam and your family&#8217;s cancer history &#8212; is stored electronically. <em>USA Today, February 13, 2012</em></p>
<h3>Smartphone Privacy</h3>
<p><a href="http://www.informationweek.com/news/security/mobile/232601089">10 Steps To Smartphone Privacy:</a> Your smartphone is simultaneously your best friend and your worst enemy. It can help you find the nearest Starbucks for a caffeine fix, reach out to loved ones in times of need, or get the score of that vital play-off game. If it falls into the wrong hands, heck, even if it doesn&#8217;t fall into the wrong hands, a smartphone can expose your contacts, location history, banking data, and more. Smartphone privacy was in the news again this week, due to a fresh Google and Apple iPhone privacy flap. <em>Information Week, February 18, 2012</em></p>
<h3>Cyber Privacy</h3>
<p><a href="http://arstechnica.com/tech-policy/news/2012/02/google-hit-with-ftc-complaint-says-circumventing-safari-privacy-features-accidental.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss">Google hit with FTC complaint, says circumventing Safari privacy features accidental:</a> The Consumer Watchdog advocacy group today asked the Federal Trade Commission to investigate whether Google violated a previous privacy agreement with the FTC by tracking cookies in a way that circumvents default privacy settings in Apple&#8217;s Safari browser. <em>ars technica, February 18, 2012</em></p>
<p><a href="http://www.washingtonpost.com/business/google-sued-by-safari-user-over-privacy-flap/2012/02/17/gIQAVtazLR_story.html">Google sued by Safari user over privacy flap:</a> Google Inc. officials were sued for violating users’ privacy rights on Apple Inc.’s Safari Web browser by bypassing computer settings designed to block monitoring of consumers’ online activity. <em>Washington Post, February 17, 2012</em></p>
<h3>Cyber Security Legislation</h3>
<p><a href="http://www.businessweek.com/news/2012-02-15/cybersecurity-measure-to-boost-companies-costs-lobbyists-say.html">Cybersecurity Measure to Boost Companies’ Costs, Lobbyists Say:</a> wo of the largest U.S. business- lobbying groups criticized a Senate cybersecurity bill aimed at shielding vital computer networks, saying the measure would burden companies with unneeded and costly regulation. <em>Bloomberg, February 15, 2012</em></p>
<p><a href="http://www.politico.com/news/stories/0212/72943.html">Cybersecurity bill blocked by top GOP senators:</a> There’s no disagreement on Capitol Hill that more needs to be done to protect the country’s critical infrastructure from potentially devastating cyberattacks. It’s just that lawmakers, particularly in the Senate, can’t agree on how to go about doing it. <em>Politico, February 16, 2012</em></p>
<p><a href="http://www.nextgov.com/nextgov/ng_20120216_1164.php?oref=topstory">Napolitano backs Senate cybersecurity bill, industry reporting requirement:</a> Homeland Security Department Secretary Janet Napolitano told lawmakers the White House approves of new Senate computer security legislation that would require critical sectors to report network intrusions to the government. <em>Nextgov, February 16, 2012</em></p>
<h3>Cyber Security Infrastructure</h3>
<p><a href="http://www.nytimes.com/2012/02/15/technology/researchers-find-flaw-in-an-online-encryption-method.html?_r=2&amp;hp">Flaw Found in an Online Encryption Method:</a> A team of European and American mathematicians and cryptographers have discovered an unexpected weakness in the encryption system widely used worldwide for online shopping, banking, e-mail and other Internet services intended to remain private and secure. <em>The New York Times, February 14, 2012</em></p>
<h3>Cyber Security R&amp;D</h3>
<p><a href="http://www.wired.co.uk/news/archive/2012-02/16/genetically-inspired-security-algorithm">Genetically-inspired algorithm could improve network security:</a> Computer scientists at Wake Forest University are using a genetically-inspired algorithm that proactively discovers more secure computer network configurations. <em>Wired, February 16, 2012</em></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-19-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekend Patch and Vulnerability Report, February 12, 2012</title>
		<link>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-12-2012/</link>
		<comments>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-12-2012/#comments</comments>
		<pubDate>Sun, 12 Feb 2012 23:45:17 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Security Alert: Vulnerability Management]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2976</guid>
		<description><![CDATA[Important Security Updates Adobe Flash 11.2 beta 5: Adobe has released a public beta version of its Flash player software for Firefox that forces the program to run in a heightened security mode or “sandbox” designed to block attacks that target vulnerabilities in the software. The sandboxed Flash beta for Firefox  works with Firefox 4 [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Important Security Updates</strong></h3>
<p><strong>Adobe Flash 11.2 beta 5:</strong> Adobe has released a public beta version of its Flash player software for Firefox that forces the program to run in a heightened security mode or “sandbox” designed to block attacks that target vulnerabilities in the software. The sandboxed Flash beta for Firefox  works with Firefox 4 or later running on Window Vista or Windows 7. The beta is available from <a href="http://labs.adobe.com/downloads/flashplatformruntimes_incubator.html">Adobe</a>. Brian Krebs at <a href="http://krebsonsecurity.com/2012/02/forcing-flash-to-play-in-the-sandbox/" target="_blank">KrebsOnSecurity.com</a> writes &#8220;I’ve been using the beta version for nearly two days now without incident on a Windows 7 <strong>Firefox 10</strong> install (with Firefox running under Microsoft’s <a title="Exploit Published for New IE Flaw" href="http://krebsonsecurity.com/2010/12/exploit-published-for-new-internet-explorer-flaw/#more-7194" target="_blank">Enhanced Mitigation Experience Toolkit</a>, or EMET). But if you do experience glitches or compatibility issues, you can always revert back to the non-sandboxed version. If you decide to try the beta, make sure to uninstall the current version using Adobe’s <a title="Uninstall Flash Player tool" href="http://kb2.adobe.com/cps/141/tn_14157.html" target="_blank">Flash uninstaller tool</a>; then grab and install the beta.&#8221;</p>
<p><strong>Firefox 10.0.1:</strong> Mozilla has released an update to Firefox to patch vulnerabilities. Firefox can be updated from within the program.</p>
<p><strong>Google Chrome 17.0.963.46;</strong> Google has updated its Chrome browser to patch at least 20 vulnerabilities, many of which are highly critical. Chrome can be updated from within the browser.<strong><br />
</strong></p>
<p><strong>RealPlayer 15.0.2.71:</strong> RealPlayer has been updated to patch multiple highly critical security vulnerabilities. RealPlayer can be updated from within the program.</p>
<h3>Current Software Versions</h3>
<p>Adobe Flash 11.1.102.55 [Warning; see below]</p>
<p>Adobe Reader 10.1.2</p>
<p>Apple QuickTime 7.7.1</p>
<p>Apple Safari 5.1.2  [Warning; see below]</p>
<p>Google Chrome 17.0.963.46</p>
<p>Internet Explorer 9.0.8112.16421</p>
<p>Java SE 6 Update 30</p>
<p>Mozilla Firefox 10.0.1</p>
<h3><strong>Newly Announced Unpatched Vulnerabilities</strong></h3>
<p>None</p>
<h3>Special Advisory Warning</h3>
<p><strong>Symantec pcAnywhere:</strong> As we reported in our<a href="../2012/01/cyber-security-news-of-the-week-january-29-2012/" target="_blank"> Cyber Security News of the Week, January 29, 2012</a>, Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code.</p>
<h3><strong>For Your IT Department</strong></h3>
<p><strong>CA Total defense Suite R12 SE3 (Build 831)</strong>: Computer Associates has released an update to CA Total defense to patch two vulnerabilities.</p>
<h3><strong>Important Unpatched Vulnerabilities</strong></h3>
<p><strong>ACDSee Photo: </strong>Several highly critical vulnerabilities have been identified in various ACDSee photo products. Vulnerabilities have been identified in <a href="http://secunia.com/advisories/43564/" target="_blank">FotoSlate</a>, <a href="http://secunia.com/advisories/43563/" target="_blank">Photo Editor 2008</a>, and <a href="http://secunia.com/advisories/43562/" target="_blank">Picture Frame Manager</a>. No patches are available at this time. Readers should refrain from using ACDSee to open untrusted files. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/weekend-vulnerability-patch-report-june-12-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 12, 2011</a>. We alerted readers to a second vulnerability in <a href="http://secunia.com/advisories/44722/" target="_blank">FotoSlate </a>in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/weekend-vulnerability-and-patch-report-september-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, September 18, 2011</a>.</p>
<p><strong>ACD Systems Canvas CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45261/" target="_blank">highly critical vulnerability </a>has been found in ACD Systems Canvas which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files. Readers should refrain from opening untrusted files in ACD Systems Canvas. We first alerted readers to this vulnerability in <a href="../2011/07/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>Adobe Flash: </strong>The <a href="http://secunia.com/advisories/47161/" target="_blank">highly critical vulnerability </a>we reported in <a href="../2012/01/2011/12/vulnerability-and-patch-report-december-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 11,2011</a> remains unpatched. We recommend users disable the Flash player in their browsers or update to the newly-released beta [see above].</p>
<p><strong>Android Browser:</strong> <a href="http://secunia.com/advisories/47315/" target="_blank">Secunia </a>reports a vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Apple Safari:</strong> <a href="http://secunia.com/advisories/47319/" target="_blank">Secunia </a>reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.<br />
<strong></strong></p>
<p><strong>HTC Mobile Devices: </strong>The <a href="http://secunia.com/advisories/43163/" target="_blank">security vulnerability</a> in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/02/weekend-vulnerability-and-patch-report-february-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, February 11, 2011</a>.</p>
<p><strong>HTC Touch2:</strong> The <a href="http://secunia.com/advisories/47242/" target="_blank">highly critical 0-day vulnerability </a>in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/weekend-vulnerability-and-patch-report-december-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 18, 2011</a>.</p>
<p><strong>McAfee SaaS:</strong> The <a href="http://secunia.com/advisories/47237/" target="_blank">highly critical vulnerability</a> in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in <a href="../2012/01/weekend-patch-and-vulnerability-report-january-22-2012/" target="_blank">Weekend Vulnerability and Patch Report, January 22, 2012.</a></p>
<p><strong>Microsoft Windows:</strong> <a href="http://secunia.com/advisories/47237/" target="_blank">Secunia </a>reports a highly critical unpatched vulnerability in Windows 7 Professional 64-bit. Other versions may also be affected. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Microsoft Windows XP: </strong>A <a href="http://secunia.com/advisories/45475/" target="_blank">less-critical security vulnerability </a>has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/weekend-vulnerability-and-patch-report-august-7-2011/" target="_blank">Weekend Vulnerability and Patch Report, August 7, 2011</a>.</p>
<p><strong>Microsoft Word: </strong>A <a href="http://secunia.com/advisories/44923/" target="_blank">highly critical vulnerability </a>has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/weekend-vulnerability-patch-report-june-19-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 19, 2011</a>.</p>
<p><strong>Microsoft Reader: </strong>The <a href="http://secunia.com/advisories/44121/" target="_blank">highly critical vulnerability </a>in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/weekend-vulnerability-and-patch-report-april-15-2011/" target="_blank">Weekend Vulnerability and Patch Report, April 15, 2011</a>.</p>
<p><strong>PDF-Pro:</strong> Several <a href="http://secunia.com/advisories/42805/" target="_blank">highly critical vulnerabilities</a> in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, March 4, 2011</a>.</p>
<p><strong><strong>Photoshop Elements:</strong> </strong>Adobe versions 1 – 8 contain a <a href="http://secunia.com/advisories/46277/" target="_blank">highly critical unpatched vulnerability</a>. The vulnerability is confirmed in version 8.0 20090905.r.605812 and Adobe reports that the vulnerability affects versions 8.0 and earlier. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/weekend-vulnerability-and-patch-report-october-9-2011/" target="_blank">Weekend Vulnerability and Patch Report, October 9, 2011</a>.</p>
<p><strong>Quick View Plus CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45281/" target="_blank">highly critical vulnerability </a>has been found in Quick View Plus which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/weekend-vulnerability-and-patch-report-july-31-2011/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>VLC Media Player:</strong> VLC has released an <a href="http://www.videolan.org/security/sa1108.html" target="_blank">advisory </a>regarding a highly critical unpatched vulnerability in versions 0.9.0 through 1.1.12. VLC has announced that media player 1.1.13 will address the issue. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><em>If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.</em></p>
<p><em>If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.</em></p>
<p>Vulnerability management is a key element of <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/04/2011/04/2011/04/services/" target="_self"><em>cyber security management</em></a>. Cyber criminals take over user computers by writing computer programs that “exploit” vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer’s computers.</p>
<p><a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/" target="_blank">Citadel</a> publishes our <em>Weekend Vulnerability and Patch Report</em> to alert readers to some of the week’s important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-12-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News of the Week, February 12, 2012</title>
		<link>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-12-2012/</link>
		<comments>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-12-2012/#comments</comments>
		<pubDate>Sun, 12 Feb 2012 15:07:31 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Cyber Security Management]]></category>
		<category><![CDATA[Information at Risk]]></category>
		<category><![CDATA[Internet badlands]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2971</guid>
		<description><![CDATA[News of the Week Commentary &#8211; Vulnerability Management This week&#8217;s story by Brian Krebs of KrebsOnSecurity.com that half of Fortune 500s and Government agencies are still infected with the DNSChanger Trojan should serve as a reminder of the critical importance of vulnerability management to all organizations. The DNSChanger Trojan malware alters an infected computer’s Internet [...]]]></description>
			<content:encoded><![CDATA[<h3>News of the Week Commentary &#8211; Vulnerability Management</h3>
<p>This week&#8217;s <a href="http://krebsonsecurity.com/2012/02/half-of-fortune-500s-us-govt-still-infected-with-dnschanger-trojan/" target="_blank">story </a>by Brian Krebs of <a href="http://krebsonsecurity.com/" target="_blank">KrebsOnSecurity.com</a> that half of Fortune 500s and Government agencies are still infected with the DNSChanger Trojan should serve as a reminder of the critical importance of vulnerability management to all organizations.</p>
<p>The DNSChanger Trojan malware alters an infected computer’s Internet settings to hijack search results and to block victims from visiting security sites that might help scrub the infections. According to Krebs, DNSChanger was frequently bundled with other types of malware, meaning that systems infected with the Trojan often also host other, even more nefarious digital parasites.</p>
<p>Krebs continues:<em> &#8220;Computers still infected with DNSChanger are up against a countdown clock. As part of the DNSChanger botnet takedown, the feds secured a court order to replace the Trojan’s DNS infrastructure with surrogate, legitimate DNS servers. But those servers are only allowed to operate until March 8, 2012. Unless the court extends that order, any computers still infected with DNSChanger may no longer be able to browse the Web.&#8221;</em></p>
<p>Management needs to ensure that IT Departments are diligent in removing DNSChanger from infected PCs. Home users can check to see if they are running DNSChanger by following the instructions <a href="http://dcwg.org/checkup.html" target="_blank">here</a>.</p>
<h3>Warnings</h3>
<p><a href="http://news.cnet.com/8301-1009_3-57373302-83/hackers-release-source-code-for-symantecs-pcanywhere/">Hackers release source code for Symantec&#8217;s PCAnywhere:</a> A group of hackers has released the source code for Symantec&#8217;s PCAnywhere product. The public release of the code yesterday came as no surprise as the hackers had been threatening such an action in a series of e-mail negotiations with what they thought were representatives of Symantec. The group, known as Yamatough but operating under the umbrella of Anonymous, had been demanding a $50,000 payoff from Symantec to keep the source code private. <em>Cnet, February 8, 2012</em></p>
<p><a href="http://www.msnbc.msn.com/id/46332574/ns/technology_and_science-security/#.TzSEPfF5mSM">Google Wallet flaws let attackers view card info:</a> A security researcher has found a serious flaw in Google Wallet&#8217;s PIN protection that, in seconds, could enable an attacker to view everything in the owner&#8217;s digital wallet, including credit card numbers and transaction history. <em>MSNBC, February 10, 2012</em></p>
<h3>Spam Warnings</h3>
<p><a href="http://www.pcworld.com/businesscenter/article/249664/hackers_ask_will_you_be_my_valentine.html">Hackers Ask &#8216;Will You Be My Valentine?&#8217;:</a> There are only five days to Valentine’s Day. Those of you who are shocked by that revelation are prime targets for Valentine’s Day related spam and phishing attacks as hackers hope to catch you with your guard down for this day of romance. <em>PC World, February 9, 2012</em></p>
<p><a href="http://www.us-cert.gov/current/#us_tax_season_phishing_scams1" target="_blank">U.S. Tax Season Phishing Scams and Malware Campaigns</a>: US-CERT has received reports of an increased number of phishing scams and malware campaigns that take advantage of the United States tax season. Due to the upcoming tax deadline, US-CERT reminds users to remain cautious when receiving unsolicited email that could be part of a potential phishing scam or malware campaign.These phishing scams and malware campaigns may include, but are not limited to, the following:</p>
<ul>
<li>information that refers to a tax refund,</li>
<li>warnings about unreported or under-reported income,</li>
<li>offers to assist in filing for a refund, and</li>
<li>details about fake e-file websites.</li>
</ul>
<h3>Cyber Security Management</h3>
<p><a href="http://krebsonsecurity.com/2012/02/half-of-fortune-500s-us-govt-still-infected-with-dnschanger-trojan/">Half of Fortune 500s, US Govt. Still Infected with DNSChanger Trojan:</a> More than two months after authorities shut down a massive Internet traffic hijacking scheme, the malicious software that powered the criminal network is still running on computers at half of the Fortune 500 companies, and on PCs at nearly 50 percent of all federal government agencies, new research shows. <em>KrebsOnSecurity, February 9, 2012</em></p>
<p><a href="http://www.forbes.com/sites/ciocentral/2012/01/31/conversations-on-cybersecurity-the-trouble-with-china-part-1/">Conversations On Cybersecurity: The Trouble With China, Part 1:</a><br />
A few Sundays ago, two visitors from a large law firm in New York came to my home for conversation. The managing partner and IT partner flew to Washington to talk about what they might do in the aftermath of a troubling visit they had had from the FBI. <em>Forbes, January 31, 2012</em></p>
<p><a href="http://www.forbes.com/sites/ciocentral/2012/02/05/conversations-on-cybersecurity-the-trouble-with-china-part-2/">Conversations On Cybersecurity: The Trouble With China, Part 2:</a> When we left the attorneys, in the last installment, they were wondering just how the cyber industrial spies had gotten into their computers. <em>Forbes, February 5, 2012</em></p>
<p><a href="http://www.marketwatch.com/story/new-informationweek-reports-research-finds-21-of-it-pros-think-their-encryption-initiatives-are-falling-behind-peers-2012-02-07">New InformationWeek Reports Research Finds 21% of IT Pros Think Their Encryption Initiatives Are Falling Behind Peers&#8217;:</a> SAN FRANCISCO, Feb. 7, 2012 /PRNewswire via COMTEX/ &#8212; InformationWeek Reports ( www.reports.informationweek.com ), a service provider for peer-based IT research and analysis, announced the release of its latest research report. Data Encryption: Ushering In a New Era encompasses analysis of results from InformationWeek&#8217;s recent 2012 data encryption survey and guides readers in choosing and deploying encryption to support a data-centric security policy. More than 500 business technology professionals responded to this poll. <em>The Wall Street Journal, February 7, 2012</em></p>
<p><a href="http://www.informationweek.com/news/security/mobile/232600415">Google Bouncer Won&#8217;t Block All Android Malware:</a> Will the newly announced Google Bouncer help the company prevent all fraudulent and malicious apps from sneaking into its Android Market? <em>InformationWeek, February 7, 2012</em></p>
<p><a href="http://www.nytimes.com/2012/02/11/technology/electronic-security-a-worry-in-an-age-of-digital-espionage.html?hp">Traveling Light in a Time of Digital Thievery:</a> SAN FRANCISCO — When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film. <em>The New York Times, February 11, 2012</em></p>
<h3>Internet Badlands</h3>
<p><a href="http://www.businessinsider.com/itunes-hack-apple-2010-2012-2">Hackers Have Been Robbing iTunes Customers Since 2010:</a> Lots of iTunes users are receiving refunds after hackers stole their ITunes Store balance with no explanation from Apple on how it happened, reports CNET. <em>Business Insider, February 10, 2012</em></p>
<h3>Critical Infrastructure</h3>
<p><a href="http://www.foxnews.com/politics/2012/02/04/watchdog-finds-cybersecurity-shortcomings-with-stimulus-backed-power-grid/">Watchdog finds cybersecurity &#8216;shortcomings&#8217; with stimulus-backed power grid program:</a> A multibillion-dollar stimulus push to modernize the nation&#8217;s power grid is raising cybersecurity concerns, as the Department of Energy&#8217;s official watchdog reports that dozens of grant recipients came to the table with inadequate security plans. <em>Fox News, February 4, 2012</em></p>
<h3>Home Security</h3>
<p><a href="http://www.wired.com/threatlevel/2012/02/home-cameras-exposed/">Flaw in Home Security Cameras Exposes Live Feeds to Hackers:</a> A flaw in home security cameras made by Trendnet potentially exposed thousands of customers to hackers who could access the live video feeds without a password. <em>Wired, February 7, 2012</em></p>
<h3>Hacktivists</h3>
<p><a href="http://news.bostonherald.com/news/regional/view/20220211national_hacking_spree_hits_cop_sites/">National hacking spree hits cop sites:</a> The same hackers who brought down the Boston Police Department community website last week kept their promise to launch cyber attacks against a string of government sites yesterday. <em>February 11, 2012</em></p>
<p><a href="http://www.dailytech.com/Hackers+Have+Their+Way+With+Apple+Supplier+Foxconn/article23972.htm"> Hackers Have Their Way With Apple Supplier Foxconn:</a> Those mischievous rapscallion hackers have been up to their usual fare, targeting a Chinese supplier infamous both for its deep relationship with Apple and its long history of alleged worker abuses. <em>Daily Tech, February 9, 2012</em></p>
<h3>Cyber Piracy</h3>
<p><a href="http://www.nytimes.com/2012/02/09/technology/in-piracy-debate-deciding-if-the-sky-is-falling.html">The Piracy Problem: How Broad?:</a> When Fred Wilson, a prominent New York venture capitalist who has backed Twitter and Zynga, wanted to watch the Knicks game last month, he got an unpleasant surprise. Time Warner Cable was not showing the game because of a contract dispute. <em>The New York Times, February 8, 2012</em></p>
<h3>Cyber Security Legislation</h3>
<p><a href="http://www.businessweek.com/news/2012-02-09/tax-breaks-considered-to-improve-cybersecurity-on-vital-networks.html">Tax Breaks Considered to Improve Cybersecurity on Vital Networks:</a> Feb. 8 (Bloomberg) &#8212; Tax breaks and liability protection may spur banking, energy and telecommunication companies to improve cybersecurity on their computer networks, the chairman of a House technology panel said. <em>BusinessWeek, February 09, 2012</em></p>
<p><a href="http://www.foxnews.com/scitech/2012/02/06/bigger-us-role-against-companies-cyberthreats/">Bigger US role against companies&#8217; cyberthreats?:</a> WASHINGTON – A developing Senate plan that would bolster the government&#8217;s ability to regulate the computer security of companies that run critical industries is drawing strong opposition from businesses that say it goes too far and security experts who believe it should have even more teeth. <em>Fox News, February 6, 2012</em></p>
<p><a href="http://www.federaltimes.com/article/20120209/IT01/202090309/1015/CONGRESS02">Senators to introduce long-awaited cybersecurity bill next week:</a> Three senators are expected to introduce a long-awaited cybersecurity bill next week that will overhaul the way the government protects critical networks. <em>Federal Times, February 9, 2012</em></p>
<p><a href="http://www.nytimes.com/2012/02/09/technology/digital-security-bills-bruised-by-a-lingering-antipiracy-fight.html">Security Bills Bruised by Lingering Fight:</a> The ghosts of two doomed antipiracy bills hang over a new and unrelated issue on Capitol Hill: proposed legislation to help secure the nation’s nuclear plants, water systems and other essential infrastructure from hackers and terrorists. <em>The New York Times, February 8, 2012</em></p>
<p><a href="http://www.businessweek.com/news/2012-02-10/cybersecurity-bill-responds-to-industry-cost-concerns-reid-says.html">Cybersecurity Bill Responds to Industry Cost Concerns, Reid Says:</a> Feb. 10 (Bloomberg) &#8212; Cybersecurity legislation in the U.S. Senate was designed to avoid unmanageable costs to industry and can be altered in coming weeks, Senate Majority Leader Harry Reid told the nation’s largest business lobbying group. <em>Bloomberg, February 10, 2012</em></p>
<h3>International Cyber Security</h3>
<p><a href="http://www.pcworld.com/businesscenter/article/249521/eu_to_stengthen_its_cybersecurity_watchdog.html">EU to Stengthen Its Cybersecurity Watchdog:</a> A push by European authorities to strengthen the European Union&#8217;s cybersecurity watchdog has been given a green light by parliamentarians. <em>PC World, February 8, 2012</em></p>
<p><a href="http://www.fastcompany.com/1814963/inside-interpols-new-cybercrime-innovation-center">Inside INTERPOL&#8217;s New Cybercrime Innovation Center:</a> INTERPOL, the international policing agency, is opening a massive innovation center in Singapore in 2014. At the center, law enforcement will learn all about the latest cybercrimes&#8230; and have access to cutting-edge forensics laboratories and research stations. <em>Fast Company, February 9, 2012</em></p>
<h3>Cyber Comedy</h3>
<p><a href="http://westroxbury.patch.com/articles/boston-police-respond-to-hackers-with-satirical-youtube-video-6e8539ff">Boston Police Respond to Hackers with Satirical YouTube Video:</a> With rapper KRS-One’s now all-too-familiar “Sound of Da Police” music video intermittently popping up, Boston Police officers satirically discuss the “emotional trauma” they felt after the police department’s website, BPDNews.com,was hacked last Friday, in a light-hearted, video comeback of sorts at the hacking group “Anonymous.” <em>WestRoxburyPatch, February 9, 2012</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-12-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekend Patch and Vulnerability Report, February 5, 2012</title>
		<link>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-5-2012/</link>
		<comments>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-5-2012/#comments</comments>
		<pubDate>Sun, 05 Feb 2012 19:13:41 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Cyber Security Management]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2886</guid>
		<description><![CDATA[Important Security Updates Apple Mac OS X 10.7.3: Apple has released a security update to Mac OS X to patch several highly critical vulnerabilities. Updates are available through Apple&#8217;s website. HTC Products: HTC has released updates to several of its products to patch a common vulnerability. Updates are available through HTC&#8217;s update channel. Mozilla Firefox [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Important Security Updates</strong></h3>
<p><strong>Apple Mac OS X 10.7.3: </strong>Apple has released a security update to Mac OS X to patch several highly critical vulnerabilities. Updates are available through Apple&#8217;s website. <strong></strong></p>
<p><strong>HTC Products: </strong>HTC has released updates to several of its products to patch a common vulnerability. Updates are available through HTC&#8217;s update channel.</p>
<p><strong>Mozilla Firefox 3.6.26 / Thunderbird 3.1.18: </strong>Mozilla has released a security update to patch several highly critical vulnerabilities. We first alerted readers to these vulnerabilities in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, January 15, 2012</a>. Updates are available through the programs. <strong></strong></p>
<p><strong>Mozilla Firefox 10.0 /  Thunderbird 10.0: </strong>Mozilla has released a security update to patch several highly critical vulnerabilities. We first alerted readers to these vulnerabilities in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, January 15, 2012</a>. Updates are available through the programs.<strong><br />
</strong></p>
<p><strong>Mozilla SeaMonkey 2.7: </strong>Mozilla has released a security update to patch several highly critical vulnerabilities. Updates are available through the program. <strong><br />
</strong></p>
<p><strong>RoboForm 7.7.0: </strong>Roboform has updated its popular password management program. The update is available through the program. <strong><br />
</strong></p>
<p><strong>Skype 5.8.0.154: </strong>Skype has released an update to patch a moderately critical vulnerability. The update is available through the program. [<em>Note: When I tried to update Skype from within the program, Skype reported it was up-to-date. To update Skype, I had to download Skype from <a href="http://www.skype.com/intl/en-us/home" target="_blank">Skype's website</a> and re-install the program.</em>]<strong></strong></p>
<h3>Current Software Versions</h3>
<p>Adobe Flash 11.1.102.55 [Warning; see below]</p>
<p>Adobe Reader 10.1.2</p>
<p>Apple QuickTime 7.7.1</p>
<p>Apple Safari 5.1.2  [Warning; see below]</p>
<p>Google Chrome 16.0.912.77</p>
<p>Internet Explorer 9.0.8112.16421</p>
<p>Java SE 6 Update 30</p>
<p>Mozilla Firefox 10.0</p>
<h3><strong>Newly Announced Unpatched Vulnerabilities</strong></h3>
<p>None</p>
<h3>Special Advisory Warning</h3>
<p><strong>Symantec pcAnywhere:</strong> As we reported last week in our<a href="../2012/01/cyber-security-news-of-the-week-january-29-2012/" target="_blank"> Cyber Security News of the Week</a>, Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code.</p>
<h3><strong>For Your IT Department</strong></h3>
<p>None</p>
<h3><strong>Important Unpatched Vulnerabilities</strong></h3>
<p><strong>ACDSee Photo: </strong>Several highly critical vulnerabilities have been identified in various ACDSee photo products. Vulnerabilities have been identified in <a href="http://secunia.com/advisories/43564/" target="_blank">FotoSlate</a>, <a href="http://secunia.com/advisories/43563/" target="_blank">Photo Editor 2008</a>, and <a href="http://secunia.com/advisories/43562/" target="_blank">Picture Frame Manager</a>. No patches are available at this time. Readers should refrain from using ACDSee to open untrusted files. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/weekend-vulnerability-patch-report-june-12-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 12, 2011</a>. We alerted readers to a second vulnerability in <a href="http://secunia.com/advisories/44722/" target="_blank">FotoSlate </a>in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/weekend-vulnerability-and-patch-report-september-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, September 18, 2011</a>.</p>
<p><strong>ACD Systems Canvas CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45261/" target="_blank">highly critical vulnerability </a>has been found in ACD Systems Canvas which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files. Readers should refrain from opening untrusted files in ACD Systems Canvas. We first alerted readers to this vulnerability in <a href="../2011/07/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>Adobe Flash: </strong>The <a href="http://secunia.com/advisories/47161/" target="_blank">highly critical vulnerability </a>we reported in <a href="../2012/01/2011/12/vulnerability-and-patch-report-december-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 11,2011</a> remains unpatched. We recommend users disable the Flash player in their browsers.</p>
<p><strong>Android Browser:</strong> <a href="http://secunia.com/advisories/47315/" target="_blank">Secunia </a>reports a vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Apple Safari:</strong> <a href="http://secunia.com/advisories/47319/" target="_blank">Secunia </a>reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.<br />
<strong></strong></p>
<p><strong>HTC Mobile Devices: </strong>The <a href="http://secunia.com/advisories/43163/" target="_blank">security vulnerability</a> in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/02/weekend-vulnerability-and-patch-report-february-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, February 11, 2011</a>.</p>
<p><strong>HTC Touch2:</strong> The <a href="http://secunia.com/advisories/47242/" target="_blank">highly critical 0-day vulnerability </a>in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/weekend-vulnerability-and-patch-report-december-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 18, 2011</a>.</p>
<p><strong>McAfee SaaS:</strong> The <a href="http://secunia.com/advisories/47237/" target="_blank">highly critical vulnerability</a> in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in <a href="../2012/01/weekend-patch-and-vulnerability-report-january-22-2012/" target="_blank">Weekend Vulnerability and Patch Report, January 22, 2012.</a></p>
<p><strong>Microsoft Windows:</strong> <a href="http://secunia.com/advisories/47237/" target="_blank">Secunia </a>reports a highly critical unpatched vulnerability in Windows 7 Professional 64-bit. Other versions may also be affected. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Microsoft Windows XP: </strong>A <a href="http://secunia.com/advisories/45475/" target="_blank">less-critical security vulnerability </a>has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/weekend-vulnerability-and-patch-report-august-7-2011/" target="_blank">Weekend Vulnerability and Patch Report, August 7, 2011</a>.</p>
<p><strong>Microsoft Word: </strong>A <a href="http://secunia.com/advisories/44923/" target="_blank">highly critical vulnerability </a>has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/weekend-vulnerability-patch-report-june-19-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 19, 2011</a>.</p>
<p><strong>Microsoft Reader: </strong>The <a href="http://secunia.com/advisories/44121/" target="_blank">highly critical vulnerability </a>in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/weekend-vulnerability-and-patch-report-april-15-2011/" target="_blank">Weekend Vulnerability and Patch Report, April 15, 2011</a>.</p>
<p><strong>PDF-Pro:</strong> Several <a href="http://secunia.com/advisories/42805/" target="_blank">highly critical vulnerabilities</a> in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, March 4, 2011</a>.</p>
<p><strong><strong>Photoshop Elements:</strong> </strong>Adobe versions 1 – 8 contain a <a href="http://secunia.com/advisories/46277/" target="_blank">highly critical unpatched vulnerability</a>. The vulnerability is confirmed in version 8.0 20090905.r.605812 and Adobe reports that the vulnerability affects versions 8.0 and earlier. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/weekend-vulnerability-and-patch-report-october-9-2011/" target="_blank">Weekend Vulnerability and Patch Report, October 9, 2011</a>.</p>
<p><strong>Quick View Plus CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45281/" target="_blank">highly critical vulnerability </a>has been found in Quick View Plus which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/weekend-vulnerability-and-patch-report-july-31-2011/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>VLC Media Player:</strong> VLC has released an <a href="http://www.videolan.org/security/sa1108.html" target="_blank">advisory </a>regarding a highly critical unpatched vulnerability in versions 0.9.0 through 1.1.12. VLC has announced that media player 1.1.13 will address the issue. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><em>If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.</em></p>
<p><em>If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.</em></p>
<p>Vulnerability management is a key element of <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/04/2011/04/2011/04/services/" target="_self"><em>cyber security management</em></a>. Cyber criminals take over user computers by writing computer programs that “exploit” vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer’s computers.</p>
<p><a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/" target="_blank">Citadel</a> publishes our <em>Weekend Vulnerability and Patch Report</em> to alert readers to some of the week’s important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/02/weekend-patch-and-vulnerability-report-february-5-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News of the Week, February 5, 2012</title>
		<link>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-5-2012-2/</link>
		<comments>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-5-2012-2/#comments</comments>
		<pubDate>Sun, 05 Feb 2012 17:21:07 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Cyber Security Management]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Information at Risk]]></category>
		<category><![CDATA[Internet badlands]]></category>
		<category><![CDATA[mobile banking]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[national security]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2912</guid>
		<description><![CDATA[News of the Week Commentary We posted a special blog this week in response to FBI Director Robert Mueller&#8217;s testimony to the U.S. House Permanent Select Committee on Intelligence. Mueller stated that he believes “the cyber threat will equal or surpass the threat from counter terrorism in the foreseeable future.” Human nature being what it [...]]]></description>
			<content:encoded><![CDATA[<h3>News of the Week Commentary</h3>
<p>We posted a <a href="http://www.citadel-information.com/2012/02/fbi-we-need-to-improve-ability-to-gather-share-analyze-and-use-cyber-information/" target="_blank">special blog </a>this week in response to FBI Director Robert Mueller&#8217;s testimony to the U.S. House Permanent Select Committee on Intelligence. Mueller stated that he believes “<a href="http://www.cbsnews.com/8301-3460_162-57370682/fbi-cyber-threat-might-surpass-terror-threat/?tag=strip" target="_blank">the cyber threat will equal or surpass the threat from counter terrorism in the foreseeable future</a>.”</p>
<p>Human nature being what it is, cyber crime and hacktivism will get worse before things get better. While we can hope to avoid cybergeddon, we also have to remember that hope is not a strategy. Lest there be any doubt, take a look at the <a href="http://www.huffingtonpost.com/2012/01/30/anonymous-internet-war_n_1233977.html" target="_blank">face of Anonymous described in the Huffington Post</a> or any of the other articles we&#8217;ve posted recently describing the cyber criminal and hacktivist communities.</p>
<p>As we <a href="http://www.citadel-information.com/2012/02/fbi-we-need-to-improve-ability-to-gather-share-analyze-and-use-cyber-information/" target="_blank">wrote in our blog</a>, organizations of all types and sizes need to take a hard look at their cyber security management, asking themselves how they can better gather, share, analyze and use cyber information to strengthen their security posture and improve their ability to withstand cyber attacks.</p>
<h3>Warnings</h3>
<p><a href="http://www.infosecurity-us.com/view/23606/update-windows-media-player-vulnerability/">Update: Windows Media Player vulnerability:</a> New research from M86 Labs adds further insight on the MIDI exploit first highlighted by Trend Micro last week. <em>InfoSecurity, February 1, 2012</em></p>
<p><a href="http://www.pcworld.com/article/249287/facebook_malware_scam_takes_hold.html">Facebook Malware Scam Takes Hold:</a> A &#8220;worrying number&#8221; of Facebook users are sharing a link to a malware-laden fake CNN news page reporting the U.S. has attacked Iran and Saudi Arabia, security firm Sophos said Friday. <em>PC World, February 3, 2012</em></p>
<h3>Information at Risk</h3>
<p><a href="http://www.businessweek.com/news/2012-02-03/china-based-hackers-target-law-firms-to-get-secret-deal-data.html">China-Based Hackers Target Law Firms to Get Secret Deal Data:</a> Jan. 31 (Bloomberg) &#8212; China-based hackers looking to derail the $40 billion acquisition of the world’s largest potash producer by an Australian mining giant zeroed in on offices on Toronto’s Bay Street, home of the Canadian law firms handling the deal. <em>Bloomberg, February 3, 2012</em></p>
<p><a href="http://www.theage.com.au/it-pro/security-it/hackers-infiltrate-domain-name-auction-house-20120201-1qtgk.html">Hackers infiltrate domain name auction house:</a> Computer hackers have penetrated the database of Australia&#8217;s biggest internet domain name auction house, possibly accessing client home addresses and encrypted credit card numbers. <em>TheAge.com, February 2, 2012</em></p>
<p><a href="http://blogs.wsj.com/tech-europe/2012/01/30/have-5-million-android-users-fallen-victim-to-malware-attack/?mod=google_news_blog">Have 5 Million Android Users Fallen Victim to Malware Attack?:</a> For as long as there has been advertising on the Internet there has been a fuzzy line dividing subterfuge and acceptable tricks to attract clicks. The problem of distinguishing between the legitimate and illegitimate now appears to have extended to smartphone apps as well. <em>The Wall Street Journal, January 30, 2012</em></p>
<h3>Cyber Security Management</h3>
<p><a href="http://attorneyjournal.us/blog/2012/01/17/cyber-liability-do-you-need-to-safeguard-your-firm-against-cyber-crimes/">Cyber Liability: Do You Need To Safeguard Your Firm Against Cyber Crimes?:</a> It’s no secret that cyber crime is on the rise. From identity theft, to credit card fraud, cyber criminals become more sophisticated by the day. That means that data breaches are skyrocketing and victims of online theft are multiplying exponentially. Furthermore, there is an emerging trend in cyber crime that is slowly starting to make headlines. That being that victims of cyber crimes are no longer just major credit card companies or large businesses. In fact, according to an article published in the Wall Street Journal in July of 2011, a whopping 63% of data breaches occurring in 2010 were at companies with less than 100 employees. <em>Attorney Journal, January 17, 2012</em></p>
<h3>Vulnerability Management — Ray of Sunshine</h3>
<p><a href="http://news.cnet.com/8301-27080_3-57370650-245/google-now-scanning-android-apps-for-malware/">Google now scanning Android apps for malware:</a> Google has added an automated scanning process that is designed to keep malicious apps out of the Android Market, the company announced today. <em>Cnet, February 2, 2012</em></p>
<h3>Mobile Banking (In)security</h3>
<p><a href="http://www.ababj.com/tech-topics-plus/why-corporate-mobile-banking-is-scary-2689.html">Why corporate mobile banking is scary:</a> In its December report on the emergence of corporate mobile banking, Celent wrote that “a slew of new devices, cheaper data plans, and faster networks are upon us. Business mobile users have the opportunity to take advantage of rich and powerful mobile banking services, provided their bank has an offering,” Sound pretty good. But the report, “Corporate Mobile Banking: Revolutionizing Cash Management,” authored by Jacob Jegher, also raises red flags about security. <em>ABA Banking Journal</em></p>
<p><a href="http://www.bizcoachinfo.com/archives/5105">Our Mobile-Banking Warnings about Security Prove Prophetic:</a> There’s another warning about mobile banking — even the American Bankers Association in this published report: “Why corporate mobile banking is scary.” The banking-industry article explains the difference between corporate and retail mobile banking. Corporate mobile banking is used by high net worth executives. Retail mobile banking refers to use by the masses. <em>The Biz Coach, February 1, 2012 [This article, by our colleague, Terry Corbell, continues to document the challenges of mobile banking security. Dr. Stahl is quoted extensively.]<br />
</em></p>
<h3>Identity Theft Protection</h3>
<p><a href="http://www.therepublic.com/view/story/e6b97287190c4dc4a887e9bae8efabfa/UT--Child-Identity-Theft/">Utah attorney general unveils program to combat ID theft targeting children:</a> SALT LAKE CITY — Utah&#8217;s attorney general and credit reporting company TransUnion unveiled a program Tuesday that seeks to protect children from identity theft, a growing problem in the U.S. that authorities say is difficult to detect and prosecute. <em>The Republic, January 31, 2012</em></p>
<h3>Hack Journalism</h3>
<p><a href="http://www.nytimes.com/2012/02/03/world/europe/times-of-london-in-phone-hacking-inquiry.html?_r=2&amp;hp">Questions on Hacking for Times of London:</a> LONDON — Questions about illegal computer hacking by The Times of London were raised on Thursday when officials at the judicial inquiry into press ethics said they would recall the paper’s editor for further testimony and the police confirmed that they were investigating an incident in 2009 in which one of the paper’s reporters apparently hacked an e-mail account. <em>The New York Times, February 2, 2012</em></p>
<h3>Keystone Cyber Cops</h3>
<p><a href="http://www.telegraph.co.uk/technology/news/9059580/Anonymous-hackers-intercept-conversation-between-FBI-and-Scotland-Yard-on-how-to-deal-with-hackers.html">&#8216;Anonymous&#8217; hackers intercept conversation between FBI and Scotland Yard on how to deal with hackers:</a> The conversation covered updates to on-going court cases, the recent arrest of a 15-year-old for hacking his school website, and even touched on cheese and the merits of Sheffield. <em>The Telegraph, February 3, 2012</em></p>
<h3>Breach Disclosure</h3>
<p><a href="http://www.wired.com/threatlevel/2012/02/verisign-hacked-in-2010/">VeriSign Hit by Hackers in 2010:</a> Internet giant VeriSign was hacked repeatedly in 2010 resulting in the theft of undisclosed information and raising questions about the integrity of security certificates issued by the company as well as its domain name service. <em>Wired, February 2, 2012</em></p>
<h3>Hactivists</h3>
<p><a href="http://www.huffingtonpost.com/2012/01/30/anonymous-internet-war_n_1233977.html">Anonymous And The War Over The Internet:</a> Late in the afternoon of Jan. 19, the U.S. Department of Justice website vanished from the Internet. Anyone attempting to visit it to report a crime or submit a complaint received a message saying the site was unable to load. More websites disappeared in rapid succession. The Recording Industry Association of America. The Motion Picture Association of America. Universal Music. Warner Brothers. The FBI. <em>Huffington Post, January 30, 2012</em></p>
<p><a href="http://www.huffingtonpost.com/2012/01/31/anonymous-war-over-internet_n_1237058.html">Anonymous And The War Over The Internet (Part II):</a> If Anonymous spans the moral range between the idealistic revolutionary and the nihilistic imp, Phoenix stands all the way at the idealistic end. His base of operations is a network of chat rooms called AnonOps, which birthed many of the overtly political attacks that have made Anonymous a front-page story during the last two years. <em>Huffington Post, January 31, 2012</em></p>
<p><a href="http://www.google.com/hostednews/afp/article/ALeqM5hJDwwAqFejQjK4oUbJyDv5vFuZNA?docId=CNG.700849e3f913fe85bcfa4ab200e6f620.4a1">Hackers deface website of lawyers for US Marine:</a> Members of the hacker group Anonymous defaced the website on Friday of the law firm that defended a US Marine who faced charges in connection with the 2005 killing of 24 Iraqi civilians. <em>AFP, February 4, 2012</em></p>
<p><a href="http://www.newsday.com/business/law-enforcement-websites-under-attack-by-hackers-1.3501931?qr=1">Law enforcement websites under attack by hackers:</a> SALT LAKE CITY &#8211; (AP) &#8212; Saboteurs stole passwords and sensitive information on tipsters while hacking into the websites of several law enforcement agencies worldwide in attacks attributed to the collective known as Anonymous. <em>Newsday, February 3, 2012</em></p>
<p><a href="http://www.haaretz.com/news/diplomacy-defense/pro-palestinian-hackers-claim-to-publish-details-of-26-000-more-israeli-credit-cards-1.410634">Pro-Palestinian hackers claim to publish details of 26,000 more Israeli credit cards:</a> An international group of hackers claimed Thursday to have published the details of 26,000 credit cards overnight, in the latest addition to a series of cyber attacks between pro-Palestinian and pro-Israeli hackers. <em>Haaretz.com, February 2, 2012</em></p>
<h3>National Cyber Security</h3>
<p><a href="http://abcnews.go.com/blogs/politics/2012/01/fbi-director-says-cyberthreat-will-surpass-threat-from-terrorists/">FBI Director Says Cyberthreat Will Surpass Threat From Terrorists:</a> Threats from cyber-espionage, computer crime, and attacks on critical infrastructure will surpass terrorism as the number one threat facing the United States, FBI Director Robert Mueller testified today. <em>ABC News, January 31, 2012</em></p>
<p><a href="http://www.cbsnews.com/8301-3460_162-57370682/fbi-cyber-threat-might-surpass-terror-threat/?tag=strip">FBI: Cyber threat might surpass terror threat:</a> Today, FBI Director Robert Mueller told the U.S. House Permanent Select Committee on Intelligence that he believes &#8220;the cyber threat will equal or surpass the threat from counter terrorism in the foreseeable future. <em>CBS News,  February 2, 2012</em></p>
<p><a href="http://thehill.com/blogs/congress-blog/technology/208579-rep-dan-lungren-r-calif">Cybersecurity is a &#8216;team sport&#8217;: </a>The federal government possesses cybersecurity threat information and technical capabilities that private enterprises simply do not have. But what is the proper role of the government in the cyber realm? Should it provide cybersecurity for the private sector, or should the government require that the private sector secure its own networks to a particular standard? These topics are currently under great debate in both the House and Senate. <em>The Hill, February 3, 2012</em></p>
<h3>Never Mind…</h3>
<p><a href="http://www.computerworld.com/s/article/9223893/Symantec_recants_Android_malware_claims?taxonomyId=77">Symantec recants Android malware claims:</a> Symantec has backtracked from assertions last week that 13 Android apps distributed by Google&#8217;s Android Market were malicious, and now says that the code in question comes from an aggressive ad network that provides revenue to the smartphone programs. <em>Computer World, February 1, 2012</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/02/cyber-security-news-of-the-week-february-5-2012-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBI: We Need to Improve Ability to Gather, Share, Analyze and Use Cyber Information</title>
		<link>http://www.citadel-information.com/2012/02/fbi-we-need-to-improve-ability-to-gather-share-analyze-and-use-cyber-information/</link>
		<comments>http://www.citadel-information.com/2012/02/fbi-we-need-to-improve-ability-to-gather-share-analyze-and-use-cyber-information/#comments</comments>
		<pubDate>Sat, 04 Feb 2012 23:48:18 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Citadel: Thinking about Security]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2898</guid>
		<description><![CDATA[FBI Director Robert Mueller told the U.S. House Permanent Select Committee on Intelligence this week that he believes &#8220;the cyber threat will equal or surpass the threat from counter terrorism in the foreseeable future.&#8221; Elaborating on the breadth of the threat, he said &#8220;there is very little we do in this day and age that [...]]]></description>
			<content:encoded><![CDATA[<p>FBI Director Robert Mueller told the U.S. House Permanent Select Committee on Intelligence this week that he believes &#8220;<a href="http://www.cbsnews.com/8301-3460_162-57370682/fbi-cyber-threat-might-surpass-terror-threat/?tag=strip" target="_blank">the cyber threat will equal or surpass the threat from counter terrorism in the foreseeable future</a>.&#8221; Elaborating on the breadth of the threat, he said &#8220;there is very little we do in this day and age that is not on or somehow associated with the internet. The theft of intellectual property, the theft of research and development, the theft of the plans and programs of a corporation for the future, of all which are vulnerable to being exploited by attackers.&#8221;</p>
<p>It is not just our sensitive information that is threatened. The Internet itself is threatened &#8230; and extremely vulnerable. In the last several weeks, we&#8217;ve seen successful <em>Distributed Denial of Service (DDoS)</em> attacks against banks, governments, law enforcement and the entertainment industry. We&#8217;ve seen Israeli and Palestinian cyber-vigilantes launch DDos attacks against each others web sites. What happens when  radical organizations discover they can launch a DDoS attack against their enemies? We should not be surprised to see the Internet become a battleground in America&#8217;s culture wars.</p>
<p>In his testimony, Mueller recommended that we need to become better at gathering, sharing, analyzing and using cyber information, offering several specific suggestions to the Committee for needed changes at the Bureau, throughout government and in new legislation.</p>
<p>His recommendation apply as well to individual organizations, as our work with clients continue to demonstrate. Every organization with sensitive information needs to continually ask itself: Are we gathering the information we need to understand our cyber threat and the quality of our cyber defenses? Are we effectively analyzing this information, using it to better secure our information? Are we sharing it with the necessary parties? In particular, is management getting the information they need to proactively manage information risk?</p>
<p>One highly critical defensive measure, for example, is to rigorously keep software patched. One of the easiest ways for a cyber criminal to take control of a computer is to exploit a vulnerability in unpatched software. That&#8217;s why we publish our <a href="http://www.citadel-information.com/blog/" target="_blank">Weekend Patch and Vulnerability Report</a>, alerting readers to major patches.</p>
<p>Patching needs to be on the Weekly Must-Do list of every IT Department and IT vendor. Yet, when we assess the patch levels of organizations, we are not surprised to often see more than 100 unpatched vulnerabilities on desktops. Does IT gather vulnerability information? Do they analyze it, taking appropriate action to keep vulnerabilities to a minimum? Is it shared with Senior Management? Does Senior Management know that IT must patch vulnerabilities to comply with laws like HIPAA HITECH or contractual obligations like the Payment Card Industry&#8217;s Data Security Standard? Does Senior Management regularly monitor &#8220;weekly vulnerability trends?&#8221;</p>
<p>Mueller&#8217;s recommendation that we become better at gathering, sharing, analyzing and using cyber information apply to our communities as well. That&#8217;s what led our Los Angeles ISSA Chapter to launch our <em>Community Outreach Program</em> 5 years ago. It&#8217;s our mission to be the premier catalyst and information source in Los Angeles for improving the practice of information security. It&#8217;s the genesis of our tag: <em>It Takes the Village to Secure the Village</em>. <sup>SM</sup>   It&#8217;s the orientation of our newly designed <a href="http://www.issala.org/" target="_blank">website</a>. And it&#8217;s the focus of our forthcoming <em>Fourth Information Security Summit</em>, being held May 16, 2012 at the Universal Hilton Hotel.</p>
<p>Human nature being what it is, cyber crime and hacktivism will likely get worse before things get better. While we can hope to avoid cybergeddon, we also have to remember that hope is not a strategy.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/02/fbi-we-need-to-improve-ability-to-gather-share-analyze-and-use-cyber-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekend Patch and Vulnerability Report, January 29, 2012</title>
		<link>http://www.citadel-information.com/2012/01/weekend-patch-and-vulnerability-report-january-29-2012/</link>
		<comments>http://www.citadel-information.com/2012/01/weekend-patch-and-vulnerability-report-january-29-2012/#comments</comments>
		<pubDate>Sun, 29 Jan 2012 19:30:13 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Security Alert: Vulnerability Management]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2819</guid>
		<description><![CDATA[Important Security Updates Google Chrome 16.0.912.77: Google has released an update to patch several highly critical vulnerabilities. Updates are available through the program. Symantec pcAnywhere 12.x: Symantec has released hotfixes to patch several moderately critical vulnerabilities in pcAnywhere. Information on applying these hotfixes is available from Symantec in notes TECH179526 and TECH 179960. WARNING: Symantec [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Important Security Updates<br />
</strong></h3>
<p><strong>Google Chrome 16.0.912.77: </strong>Google has released an update to patch several highly critical vulnerabilities. Updates are available through the program. <strong><br />
</strong></p>
<p><strong>Symantec pcAnywhere 12.x:</strong> Symantec has released hotfixes to patch several moderately critical vulnerabilities in pcAnywhere. Information on applying these hotfixes is available from Symantec in notes <a href="http://www.symantec.com/business/support/index?page=content&amp;id=TECH179526" target="_blank">TECH179526 </a>and <a href="http://www.symantec.com/business/support/index?page=content&amp;id=TECH179960" target="_blank">TECH 179960</a>.<strong> WARNING: Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code. </strong>See our<a href="http://www.citadel-information.com/2012/01/cyber-security-news-of-the-week-january-29-2012/" target="_blank"> Cyber Security News of the Week</a> for more information.<strong><br />
</strong></p>
<h3>Current Software Versions</h3>
<p>Adobe Flash 11.1.102.55 [Warning; see below]</p>
<p>Adobe Reader 10.1.2</p>
<p>Apple QuickTime 7.7.1</p>
<p>Apple Safari 5.1.2  [Warning; see below]</p>
<p>Google Chrome 16.0.912.77</p>
<p>Internet Explorer 9.0.8112.16421</p>
<p>Java SE 6 Update 30</p>
<p>Mozilla Firefox 9.0.1 [Warning; see below]</p>
<h3><strong>Newly Announced Unpatched Vulnerabilities</strong></h3>
<p>None</p>
<h3><strong>For Your IT Department</strong></h3>
<div>
<p><strong>Trend Micro DataArmor and DriveArmor: </strong> Trend Micro reports a less critical vulnerability in these programs. Patches are available from Trend Micro.</p>
<p><strong>Symantec Altiris IT Management Suite:</strong> The same vulnerabilities affecting pcAnywhere also <a href="http://secunia.com/advisories/47744/" target="_blank">impact </a>Altiris IT Management. Additional information is available from Symantec in notes <a href="http://www.symantec.com/business/support/index?page=content&amp;id=TECH179526" target="_blank">TECH179526 </a>and <a href="http://www.symantec.com/business/support/index?page=content&amp;id=TECH179960" target="_blank">TECH 179960</a>.</p>
<h3><strong>Important Unpatched Vulnerabilities</strong></h3>
<p><strong>ACDSee Photo: </strong>Several highly critical vulnerabilities have been identified in various ACDSee photo products. Vulnerabilities have been identified in <a href="http://secunia.com/advisories/43564/" target="_blank">FotoSlate</a>, <a href="http://secunia.com/advisories/43563/" target="_blank">Photo Editor 2008</a>, and <a href="http://secunia.com/advisories/43562/" target="_blank">Picture Frame Manager</a>. No patches are available at this time. Readers should refrain from using ACDSee to open untrusted files. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/weekend-vulnerability-patch-report-june-12-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 12, 2011</a>. We alerted readers to a second vulnerability in <a href="http://secunia.com/advisories/44722/" target="_blank">FotoSlate </a>in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/weekend-vulnerability-and-patch-report-september-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, September 18, 2011</a>.</p>
<p><strong>ACD Systems Canvas CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45261/" target="_blank">highly critical vulnerability </a>has been found in ACD Systems Canvas which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files. Readers should refrain from opening untrusted files in ACD Systems Canvas. We first alerted readers to this vulnerability in <a href="http://www.citadel-information.com/2011/07/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>Adobe Flash: </strong>The <a href="http://secunia.com/advisories/47161/" target="_blank">highly critical vulnerability </a>we reported in <a href="../2012/01/2011/12/vulnerability-and-patch-report-december-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 11,2011</a> remains unpatched. We recommend users disable the Flash player in their browsers.</p>
<p><strong>Android Browser:</strong> <a href="http://secunia.com/advisories/47315/" target="_blank">Secunia </a>reports a vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Apple Safari:</strong> <a href="http://secunia.com/advisories/47319/" target="_blank">Secunia </a>reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in <a href="http://www.citadel-information.com/2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.<br />
<strong></strong></p>
<p><strong>HTC Mobile Devices: </strong>The <a href="http://secunia.com/advisories/43163/" target="_blank">security vulnerability</a> in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/02/weekend-vulnerability-and-patch-report-february-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, February 11, 2011</a>.</p>
<p><strong>HTC Touch2:</strong> The <a href="http://secunia.com/advisories/47242/" target="_blank">highly critical 0-day vulnerability </a>in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/weekend-vulnerability-and-patch-report-december-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 18, 2011</a>.</p>
<p><strong>McAfee SaaS:</strong> The <a href="http://secunia.com/advisories/47237/" target="_blank">highly critical vulnerability</a> in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in <a href="http://www.citadel-information.com/2012/01/weekend-patch-and-vulnerability-report-january-22-2012/" target="_blank">Weekend Vulnerability and Patch Report, January 22, 2012.</a></p>
<p><strong>Microsoft Windows:</strong> <a href="http://secunia.com/advisories/47237/" target="_blank">Secunia </a>reports a highly critical unpatched vulnerability in Windows 7 Professional 64-bit. Other versions may also be affected. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Microsoft Windows XP: </strong>A <a href="http://secunia.com/advisories/45475/" target="_blank">less-critical security vulnerability </a>has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/weekend-vulnerability-and-patch-report-august-7-2011/" target="_blank">Weekend Vulnerability and Patch Report, August 7, 2011</a>.</p>
<p><strong>Microsoft Word: </strong>A <a href="http://secunia.com/advisories/44923/" target="_blank">highly critical vulnerability </a>has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/weekend-vulnerability-patch-report-june-19-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 19, 2011</a>.</p>
<p><strong>Microsoft Reader: </strong>The <a href="http://secunia.com/advisories/44121/" target="_blank">highly critical vulnerability </a>in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/weekend-vulnerability-and-patch-report-april-15-2011/" target="_blank">Weekend Vulnerability and Patch Report, April 15, 2011</a>.</p>
<p><strong>Mozilla Firefox:</strong> <a href="http://secunia.com/advisories/47400/" target="_blank">Secunia </a>reports a less critical vulnerability in Mozilla Firefox. The vulnerability is confirmed in Mozilla 9.0.1. Other versions may also be affected. No patch is available at this time. Users should exercise extra caution on untrusted websites. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, January 15, 2012</a>.</p>
<p><strong>PDF-Pro:</strong> Several <a href="http://secunia.com/advisories/42805/" target="_blank">highly critical vulnerabilities</a> in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, March 4, 2011</a>.</p>
<p><strong><strong>Photoshop Elements:</strong> </strong>Adobe versions 1 – 8 contain a <a href="http://secunia.com/advisories/46277/" target="_blank">highly critical unpatched vulnerability</a>. The vulnerability is confirmed in version 8.0 20090905.r.605812 and Adobe reports that the vulnerability affects versions 8.0 and earlier. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/weekend-vulnerability-and-patch-report-october-9-2011/" target="_blank">Weekend Vulnerability and Patch Report, October 9, 2011</a>.</p>
<p><strong>Quick View Plus CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45281/" target="_blank">highly critical vulnerability </a>has been found in Quick View Plus which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/weekend-vulnerability-and-patch-report-july-31-2011/" target="_blank">Weekend Vulnerability and Patch Report, July 31, 2011</a>.</p>
<p><strong>VLC Media Player:</strong> VLC has released an <a href="http://www.videolan.org/security/sa1108.html" target="_blank">advisory </a>regarding a highly critical unpatched vulnerability in versions 0.9.0 through 1.1.12. VLC has announced that media player 1.1.13 will address the issue. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><em>If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.</em></p>
<p><em>If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.</em></p>
<p>Vulnerability management is a key element of <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/04/2011/04/2011/04/services/" target="_self"><em>cyber security management</em></a>. Cyber criminals take over user computers by writing computer programs that “exploit” vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer’s computers.</p>
<p><a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/" target="_blank">Citadel</a> publishes our <em>Weekend Vulnerability and Patch Report</em> to alert readers to some of the week’s important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/01/weekend-patch-and-vulnerability-report-january-29-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News of the Week, January 29, 2012</title>
		<link>http://www.citadel-information.com/2012/01/cyber-security-news-of-the-week-january-29-2012/</link>
		<comments>http://www.citadel-information.com/2012/01/cyber-security-news-of-the-week-january-29-2012/#comments</comments>
		<pubDate>Sun, 29 Jan 2012 13:17:12 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Cyber Security Management]]></category>
		<category><![CDATA[Cyber War]]></category>
		<category><![CDATA[Internet badlands]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2813</guid>
		<description><![CDATA[News of the Week Commentary Symantec&#8217;s warning this week to users to disable PCAnywhere following the theft of its source code stands in contrast to the company&#8217;s assurances a few weeks ago that the theft of its source code posed little risk to users. [See Cyber Security News of the Week, January 8, 2012.] At [...]]]></description>
			<content:encoded><![CDATA[<h3>News of the Week Commentary</h3>
<p>Symantec&#8217;s warning this week to users to disable PCAnywhere following the theft of its source code stands in contrast to the company&#8217;s assurances a few weeks ago that the theft of its source code posed little risk to users. [See <a href="http://www.citadel-information.com/2012/01/cyber-security-news-of-the-week-january-8-2012/" target="_blank">Cyber Security News of the Week, January 8, 2012</a>.]</p>
<p>At issue is the responsibility information security vendors have to their customers when the vendor&#8217;s products may be exposing customers to risk. It&#8217;s common for a company to circle the wagons and fall into a protective mode when bad news comes out. The strategy is usually a losing one as the bad news comes out eventually and the company ends up with egg on its face. So, from the company&#8217;s own perspective, the right strategy is often to own up to the problem from the start.</p>
<p>In cases of security the situation also carries moral and ethical implications. Twenty years ago when Tylenol was confronted with the death of several people after someone put poison in it products, Tylenol immediately removed the product from stores across the country and launched a public relations campaign to warn users.</p>
<p>The loss of information is not the same as the loss of lives, but don&#8217;t those of us in the business of protecting the sensitive information of our clients and customers have the same ethical and moral obligation to warn our users immediately?</p>
<h3>Vulnerability Alert</h3>
<p><a href="http://arstechnica.com/business/news/2012/01/symantec-says-anonymous-stole-source-code-tells-customers-to-disable-security-product.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss">Symantec: Anonymous stole source code, users should disable pcAnywhere:</a> Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. <em>ars technica, January 26, 2012</em></p>
<h3>Cyber Crime &#8211; Online Bank Theft</h3>
<p><a href="http://www.nj.com/salem/index.ssf/2012/01/hackers_tap_salem_co_account_f.html">Hackers tap Salem Co. account for $19,000:</a> Computer hackers have broken in and stolen approximately $19,000 by way of an illegal wire transfer from a Salem County bank account that held more than $13 million in funds. <em>nj.com, January 22, 2012</em></p>
<h3>Internet Badlands</h3>
<p><a href="http://online.wsj.com/article/SB10001424052970203471004577145140543496380.html">Hackers-for-Hire Are Easy to Find:</a> Sitting in his Los Angeles home, Kuwaiti billionaire Bassam Alghanim received an alarming call from a business associate: Hundreds of his personal emails were posted online for anyone to see. <em>The Wall Street Journal, January 23, 2012</em></p>
<h3>Cyber Security Management</h3>
<p><a href="http://www.nytimes.com/2012/01/23/technology/flaws-in-videoconferencing-systems-put-boardrooms-at-risk.html?_r=1">Cameras May Open Up the Board Room to Hackers:</a> One afternoon this month, a hacker took a tour of a dozen conference rooms around the globe via equipment that most every company has in those rooms; videoconferencing equipment. <em>The New York Times, January 23, 2012</em></p>
<h3>Healthcare Privacy &#8211; National Dialogue</h3>
<p><a href="http://online.wsj.com/article/SB10001424052970204124204577154661814932978.html">Should Every Patient Have a Unique ID Number for All Medical Records?:</a> As the U.S. invests billions of dollars to convert from paper-based medical records to electronic ones, has the time come to offer everyone a unique health-care identification number? <em>The Wall Street Journal, January 23, 2012</em></p>
<h3>Cyber War &#8211; The Middle East</h3>
<p><a href="http://www.haaretz.com/news/diplomacy-defense/pro-palestinian-hackers-bring-down-haaretz-hebrew-website-1.409198">Pro-Palestinian hackers bring down Haaretz Hebrew website:</a> Pro-Palestinian hackers brought down Haaretz&#8217;s Hebrew website on Wednesday, after several Israeli websites were targeted earlier in the day. <em>January 25, 2012</em></p>
<h3>Privacy Rights &#8211; European Union</h3>
<p><a href="http://www.pcmag.com/article2/0,2817,2399314,00.asp">EU Data-Privacy Overhaul Gives Consumers More Control:</a> The European Commission on Wednesday proposed an overhaul to its data protection laws, which will provide users with more control over their data and make the process of monitoring data security less complex for agencies across the EU. <em>PC Magazine, January 25, 2012</em></p>
<h3>Ray of Sunshine</h3>
<p><a href="http://news.cnet.com/8301-1023_3-57363594-93/filesonic-disables-file-sharing-in-wake-of-megaupload-arrests/">FileSonic disables file sharing in wake of MegaUpload arrests:</a> Following the MegaUpload shutdown and indictments last week, FileSonic, one of the Internet&#8217;s most popular file-sharing services, has disabled its sharing functionality. <em>Cnet, January 22, 2012</em></p>
<p><a href="http://www.nytimes.com/2012/01/26/technology/new-web-piracy-arrest-as-site-founder-is-denied-bail.html?ref=technology">New Web Piracy Arrest as Site Founder Is Denied Bail:</a> THE HAGUE, Netherlands — An Estonian citizen was arrested by Dutch police at the request of American authorities investigating the file-sharing Web site Megaupload, a prosecutor’s office spokeswoman said Wednesday. <em>January 25, 2012</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/01/cyber-security-news-of-the-week-january-29-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekend Patch and Vulnerability Report, January 22, 2012</title>
		<link>http://www.citadel-information.com/2012/01/weekend-patch-and-vulnerability-report-january-22-2012/</link>
		<comments>http://www.citadel-information.com/2012/01/weekend-patch-and-vulnerability-report-january-22-2012/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 22:15:56 +0000</pubDate>
		<dc:creator>Stan Stahl Ph.D.</dc:creator>
				<category><![CDATA[Security Alert: Vulnerability Management]]></category>

		<guid isPermaLink="false">http://www.citadel-information.com/?p=2759</guid>
		<description><![CDATA[Important Security Updates Adobe Reader and Acrobat 10.1.2: Adobe has released an update to patch several highly critical vulnerabilities. For users who cannot upgrade to version X, Adobe has also released version 9.5. Updates are available through the program.  Apple iTunes 10.5.3: Apple has released an update to patch several minor issues, including security. Current [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Important Security Updates<br />
</strong></h3>
<p><strong>Adobe Reader and Acrobat 10.1.2: </strong>Adobe has released an update to patch several highly critical vulnerabilities. For users who cannot upgrade to version X, Adobe has also released version 9.5<strong>.</strong> Updates are available through the program. <strong><br />
</strong></p>
<p><strong>Apple iTunes 10.5.3: </strong>Apple has released an update to patch several minor issues, including security.<strong></strong></p>
<h3>Current Software Versions</h3>
<p>Adobe Flash 11.1.102.55 [Warning; see below]</p>
<p>Adobe Reader 10.1.2</p>
<p>Apple QuickTime 7.7.1</p>
<p>Apple Safari 5.1.2  [Warning; see below]</p>
<p>Google Chrome 16.0.912.75</p>
<p>Internet Explorer 9.0.8112.16421</p>
<p>Java SE 6 Update 30</p>
<p>Mozilla Firefox 9.0.1 [Warning; see below]</p>
<h3><strong>Newly Announced Unpatched Vulnerabilities</strong></h3>
<p><strong>McAfee SaaS:</strong> <a href="http://secunia.com/advisories/47520/" target="_blank">Secunia </a>reports a highly critical vulnerability in McAfee SaaS Endpoint Protection. No patch is available at this time.</p>
<h3>For Your IT Department</h3>
<div>
<p><strong>McAfee GroupShield: </strong><a href="http://secunia.com/advisories/47584/" target="_blank">Secunia </a>reports a highly critical vulnerability in McAfee GroupShield. No patch is available at this time. The vulnerability is reported in version 7.0.716.101. Other versions may also be affected.</p>
<p><strong>Oracle</strong>: <a href="http://www.us-cert.gov/current/#oracle_releases_critical_patch_update16" target="_blank">US-CERT</a> reports Oracle has released its Critical Patch Update for January 2012 to address 78 vulnerabilities across multiple products. Several of these are highly critical.</p>
<p><strong>Sonicwall: </strong><a href="http://secunia.com/advisories/47439/" target="_blank">Secunia </a>reports a less-critical vulnerability in Sonicwall AntiSpam &amp; EMail security. The vulnerability is reported in version 7.3.1 and 7.3.4.5725. Other versions may also be affected. No patch is available at this time.<strong><br />
</strong></p>
<h3><strong>Important Unpatched Vulnerabilities</strong></h3>
<p><strong>ACDSee Photo: </strong>Several highly critical vulnerabilities have been identified in various ACDSee photo products. Vulnerabilities have been identified in <a href="http://secunia.com/advisories/43564/" target="_blank">FotoSlate</a>, <a href="http://secunia.com/advisories/43563/" target="_blank">Photo Editor 2008</a>, and <a href="http://secunia.com/advisories/43562/" target="_blank">Picture Frame Manager</a>. No patches are available at this time. Readers should refrain from using ACDSee to open untrusted files. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/weekend-vulnerability-patch-report-june-12-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 12</a>. We alerted readers to a second vulnerability in <a href="http://secunia.com/advisories/44722/" target="_blank">FotoSlate </a>in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/weekend-vulnerability-and-patch-report-september-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, September 18</a>.</p>
<p><strong>ACD Systems Canvas CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45261/" target="_blank">highly critical vulnerability </a>has been found in ACD Systems Canvas which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files. Readers should refrain from opening untrusted files in ACD Systems Canvas. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/weekend-vulnerability-and-patch-report-july-31-2011/" target="_blank">Weekend Vulnerability and Patch Report, July 31</a>.</p>
<p><strong>Adobe Flash: </strong>The <a href="http://secunia.com/advisories/47161/" target="_blank">highly critical vulnerability </a>we reported in <a href="../2012/01/2011/12/vulnerability-and-patch-report-december-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 11</a> remains unpatched. We recommend users disable the Flash player in their browsers.</p>
<p><strong>Android Browser:</strong> <a href="http://secunia.com/advisories/47315/" target="_blank">Secunia </a>reports a vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Apple Safari:</strong> <a href="http://secunia.com/advisories/47319/" target="_blank">Secunia </a>reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in <a href="http://www.citadel-information.com/2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.<br />
<strong></strong></p>
<p><strong>HTC Mobile Devices: </strong>The <a href="http://secunia.com/advisories/43163/" target="_blank">security vulnerability</a> in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/02/weekend-vulnerability-and-patch-report-february-11-2011/" target="_blank">Weekend Vulnerability and Patch Report, February 11</a>.</p>
<p><strong>HTC Touch2:</strong> The <a href="http://secunia.com/advisories/47242/" target="_blank">highly critical 0-day vulnerability </a>in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/weekend-vulnerability-and-patch-report-december-18-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 18, 2011</a>.</p>
<p><strong>Microsoft Windows:</strong> <a href="http://secunia.com/advisories/47237/" target="_blank">Secunia </a>reports a highly critical unpatched vulnerability in Windows 7 Professional 64-bit. Other versions may also be affected. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><strong>Microsoft Windows XP: </strong>A <a href="http://secunia.com/advisories/45475/" target="_blank">less-critical security vulnerability </a>has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/weekend-vulnerability-and-patch-report-august-7-2011/" target="_blank">Weekend Vulnerability and Patch Report, August 7</a>.</p>
<p><strong>Microsoft Word: </strong>A <a href="http://secunia.com/advisories/44923/" target="_blank">highly critical vulnerability </a>has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/weekend-vulnerability-patch-report-june-19-2011/" target="_blank">Weekend Vulnerability and Patch Report, June 19</a>.</p>
<p><strong>Microsoft Office for Mac: </strong>A <a href="http://secunia.com/advisories/44539/" target="_blank">highly critical vulnerability </a>has been discovered in Microsoft Office for the Mac which can be exploited by cyber criminals to take control of a user’s computer. Security updates are currently unavailable. Readers should refrain from opening untrusted files in Office. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/weekend-vulnerability-patch-report-may-13-2011/">Weekend Vulnerability &amp; Patch Report, May 13, 2011</a>.</p>
<p><strong>Microsoft Reader: </strong>The <a href="http://secunia.com/advisories/44121/" target="_blank">highly critical vulnerability </a>in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/weekend-vulnerability-and-patch-report-april-15-2011/" target="_blank">Weekend Vulnerability and Patch Report, April 15</a>.</p>
<p><strong>Mozilla Firefox:</strong> Secunia reports a less critical vulnerability in Mozilla Firefox. The vulnerability is confirmed in Mozilla 9.0.1. Other versions may also be affected. No patch is available at this time. Users should exercise extra caution on untrusted websites.</p>
<p><strong>PDF-Pro:</strong> Several <a href="http://secunia.com/advisories/42805/" target="_blank">highly critical vulnerabilities</a> in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/03/weekend-vulnerability-and-patch-report-march-4-2011/" target="_blank">Weekend Vulnerability and Patch Report, March 4</a>.</p>
<p><strong><strong>Photoshop Elements:</strong> </strong>Adobe versions 1 – 8 contain a <a href="http://secunia.com/advisories/46277/" target="_blank">highly critical unpatched vulnerability</a>. The vulnerability is confirmed in version 8.0 20090905.r.605812 and Adobe reports that the vulnerability affects versions 8.0 and earlier. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/weekend-vulnerability-and-patch-report-october-9-2011/" target="_blank">Weekend Vulnerability and Patch Report, October 9, 2011</a>.</p>
<p><strong>Quick View Plus CorelDRAW</strong>: A <a href="http://secunia.com/advisories/45281/" target="_blank">highly critical vulnerability </a>has been found in Quick View Plus which can be exploited by malicious people to compromise a user’s system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/weekend-vulnerability-and-patch-report-july-31-2011/" target="_blank">Weekend Vulnerability and Patch Report, July 31</a>.</p>
<p><strong>VLC Media Player:</strong> VLC has released an <a href="http://www.videolan.org/security/sa1108.html" target="_blank">advisory </a>regarding a highly critical unpatched vulnerability in versions 0.9.0 through 1.1.12. VLC has announced that media player 1.1.13 will address the issue. We first alerted readers to a this vulnerability in <a href="../2011/12/weekend-vulnerability-and-patch-report-december-25-2011/" target="_blank">Weekend Vulnerability and Patch Report, December 25, 2011</a>.</p>
<p><em>If you are responsible for keeping your computer secure, our weekly report is for you. We strongly urge you to take action to keep your workstation secure.</em></p>
<p><em>If someone else is responsible for keeping your computer secure, protect it by forwarding our Weekend Vulnerability and Patch Report to them and following up to make sure your computer has been patched.</em></p>
<p>Vulnerability management is a key element of <a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/2011/08/2011/07/2011/07/2011/07/2011/06/2011/06/2011/06/2011/05/2011/05/2011/04/2011/04/2011/04/2011/04/services/" target="_self"><em>cyber security management</em></a>. Cyber criminals take over user computers by writing computer programs that “exploit” vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer’s computers.</p>
<p><a href="../2012/01/2011/12/2011/12/2011/11/2011/11/2011/11/2011/10/2011/10/2011/10/2011/10/2011/10/2011/09/2011/09/2011/09/" target="_blank">Citadel</a> publishes our <em>Weekend Vulnerability and Patch Report</em> to alert readers to some of the week’s important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.citadel-information.com/2012/01/weekend-patch-and-vulnerability-report-january-22-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

