<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>certifiedbug.com</title>
	
	<link>http://certifiedbug.com/blog</link>
	<description>Consumer Security on the web, information to assist you in practicing safe computing</description>
	<lastBuildDate>Thu, 17 May 2012 01:13:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Certifiedbugcom" /><feedburner:info uri="certifiedbugcom" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-sa/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /><feedburner:emailServiceId>Certifiedbugcom</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Certifiedbugcom" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:browserFriendly>Thank you for visiting my blog.</feedburner:browserFriendly><item>
		<title>Washington state AG and Facebook target social media spammers</title>
		<link>http://certifiedbug.com/blog/2012/05/08/washington-state-ag-and-facebook-target-social-media-spammers/</link>
		<comments>http://certifiedbug.com/blog/2012/05/08/washington-state-ag-and-facebook-target-social-media-spammers/#comments</comments>
		<pubDate>Tue, 08 May 2012 15:35:49 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Social-Networking]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5478</guid>
		<description><![CDATA[Alleged “Likejackers” agree to root out Facebook spam Adscend Media LLC also pays $100,000 in attorneys’ fees to state SEATTLE – The owners of a California-based online marketing company have agreed to stop spamming Facebook users. The details were revealed today in a settlement – a consent decree – between Adscend Media LLC and the [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/08/washington-state-ag-and-facebook-target-social-media-spammers/">Washington state AG and Facebook target social media spammers</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><blockquote><p><em>Alleged “Likejackers” agree to root out Facebook spam</em></p>
<p>Adscend Media LLC also pays $100,000 in attorneys’ fees to state</p>
<p>SEATTLE – The owners of a California-based online marketing company have agreed to stop spamming Facebook users. The details were revealed today in a settlement – <a href="http://www.atg.wa.gov/uploadedFiles/Another/News/ConsentDecreeSigned2012-5-7.pdf">a consent decree</a> – between Adscend Media LLC and the Washington State Attorney General’s Office.</p>
<p>“Today’s settlement puts a stop to Adscend’s ‘likejacking’ and other misleading tactics that led Facebook users to fork over personal information or buy subscription services from sites that appeared to be recommended by friends,” said Washington State Attorney General Rob McKenna.</p>
<p>In January, McKenna’s office and Facebook <a href="http://www.atg.wa.gov/pressrelease.aspx?&#038;id=29380">sued</a> Jeremy Bash and Fehzan Ali, the owners of Adscend Media LLC for initiating posts to Facebook pages that appeared to offer visitors an opportunity to view scandalous or provocative content.  However, before being able to view the content, a series of required steps lured Facebook users into eventually visiting commercial websites. Other tactics included “likejacking,” in which Facebook users were tricked into clicking the “like” button, inadvertently spreading the sales pitches to friends.</p>
<p>Adscend, hired to promote products, in turn does business with “affiliates” who create attention-getting marketing messages. Too often, according to the Attorney General’s Office, those messages amounted to social media spam.
</p></blockquote>
<p><a href="http://www.atg.wa.gov/pressrelease.aspx?&#038;id=29716">http://www.atg.wa.gov/pressrelease.aspx?&#038;id=29716</a></p>
<p><a href="http://nakedsecurity.sophos.com/2012/05/08/facebook-clickjacking/">http://nakedsecurity.sophos.com/2012/05/08/facebook-clickjacking/</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/08/washington-state-ag-and-facebook-target-social-media-spammers/">Washington state AG and Facebook target social media spammers</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=uIuF3MPWkg0:-0CRrtQZk58:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=uIuF3MPWkg0:-0CRrtQZk58:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=uIuF3MPWkg0:-0CRrtQZk58:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=uIuF3MPWkg0:-0CRrtQZk58:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/05/08/washington-state-ag-and-facebook-target-social-media-spammers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Bulletin Summary for May 2012</title>
		<link>http://certifiedbug.com/blog/2012/05/03/microsoft-security-bulletin-summary-for-may-2012/</link>
		<comments>http://certifiedbug.com/blog/2012/05/03/microsoft-security-bulletin-summary-for-may-2012/#comments</comments>
		<pubDate>Fri, 04 May 2012 01:07:58 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vulnerability-Windows-Update]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5482</guid>
		<description><![CDATA[The Microsoft Security Response Center (MSRC) Today we’re releasing our advance notification for the May security bulletin release, which is scheduled for Tuesday, May 8. This month’s release includes 7 bulletins addressing 23 vulnerabilities in Microsoft Windows, Office, Silverlight, and .NET Framework. All 7 bulletins will be released on Tuesday, May 8 at approximately 10 [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/03/microsoft-security-bulletin-summary-for-may-2012/">Microsoft Security Bulletin Summary for May 2012</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://blogs.technet.com/b/msrc/archive/2012/05/03/advanced-notification-service-for-may-2012-security-bulletin-release.aspx">The Microsoft Security Response Center (MSRC)</a></p>
<blockquote><p>Today we’re releasing our advance notification for the May security bulletin release, which is scheduled for Tuesday, May 8. This month’s release includes 7 bulletins addressing 23 vulnerabilities in Microsoft Windows, Office, Silverlight, and .NET Framework. All 7 bulletins will be released on Tuesday, May 8 at approximately 10 a.m. PDT. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.</p>
<p>As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.</p></blockquote>
<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may">http://technet.microsoft.com/en-us/security/bulletin/ms12-may</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/03/microsoft-security-bulletin-summary-for-may-2012/">Microsoft Security Bulletin Summary for May 2012</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=JuMRDwozgbo:SIcxT07uMFU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=JuMRDwozgbo:SIcxT07uMFU:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=JuMRDwozgbo:SIcxT07uMFU:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=JuMRDwozgbo:SIcxT07uMFU:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/05/03/microsoft-security-bulletin-summary-for-may-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thunderbird 12.0.1 released</title>
		<link>http://certifiedbug.com/blog/2012/05/02/thunderbird-12-0-1-released/</link>
		<comments>http://certifiedbug.com/blog/2012/05/02/thunderbird-12-0-1-released/#comments</comments>
		<pubDate>Wed, 02 May 2012 22:11:07 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[email-Thunderbird-Update]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5475</guid>
		<description><![CDATA[Fix various issues relating to new mail notifications and filtering on POP3 based accounts Fixes an occasional startup crash seen in TB 12.0 Fixes an issue with corrrupted message bodies when using movemail http://www.mozilla.org/en-US/thunderbird/12.0.1/releasenotes/ If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu. Or [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/02/thunderbird-12-0-1-released/">Thunderbird 12.0.1 released</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Fix various issues relating to new mail notifications and filtering on POP3 based accounts<br />
Fixes an occasional startup crash seen in TB 12.0<br />
Fixes an issue with corrrupted message bodies when using movemail</p>
<p><a href="http://www.mozilla.org/en-US/thunderbird/12.0.1/releasenotes/">http://www.mozilla.org/en-US/thunderbird/12.0.1/releasenotes/</a></p>
<p>If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu.</p>
<p>Or download: <a href="http://www.mozilla.org/en-US/thunderbird/all.html">http://www.mozilla.org/en-US/thunderbird/all.html</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/02/thunderbird-12-0-1-released/">Thunderbird 12.0.1 released</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=GhGx8NH5BrY:9H4Fs09AMaw:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=GhGx8NH5BrY:9H4Fs09AMaw:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=GhGx8NH5BrY:9H4Fs09AMaw:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=GhGx8NH5BrY:9H4Fs09AMaw:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/05/02/thunderbird-12-0-1-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox ShowIP add-on privacy concerns</title>
		<link>http://certifiedbug.com/blog/2012/05/01/firefox-showip-add-on-privacy-concerns/</link>
		<comments>http://certifiedbug.com/blog/2012/05/01/firefox-showip-add-on-privacy-concerns/#comments</comments>
		<pubDate>Wed, 02 May 2012 01:28:15 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Add-on]]></category>
		<category><![CDATA[Cluley]]></category>
		<category><![CDATA[Firefox]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5471</guid>
		<description><![CDATA[Sophos A popular Firefox add-on appears to have started leaking private information about every website that users visit to a third-party server, including sensitive data which could identify individuals or reduce their security. Naked Security reader Rob Sanders alerted us to the activities of the recently updated ShowIP add-on for the Firefox browser. Currently over [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/01/firefox-showip-add-on-privacy-concerns/">Firefox ShowIP add-on privacy concerns</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Sophos</p>
<blockquote><p>A popular Firefox add-on appears to have started leaking private information about every website that users visit to a third-party server, including sensitive data which could identify individuals or reduce their security.</p>
<p>Naked Security reader Rob Sanders alerted us to the activities of the recently updated ShowIP add-on for the Firefox browser.
</p></blockquote>
<blockquote><p>Currently over 170,000 people are said to be using ShowIP.</p>
<p>What the add-on&#8217;s description doesn&#8217;t say is that since version 1.3 (released on April 19th 2012) it has also sent &#8211; unencrypted &#8211; the full URL of sites visited using HTTPS, and sites viewed in Private Browsing mode, to a site called ip2info.org.</p>
<p>The user never realises that the data has been shared with a third-party, unless they use special tools to monitor what data is being sent from their computer.</p></blockquote>
<p><a href="http://nakedsecurity.sophos.com/2012/05/01/privacy-concern-showip-firefox-add-on/"></p>
<p>http://nakedsecurity.sophos.com/2012/05/01/privacy-concern-showip-firefox-add-on/</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/05/01/firefox-showip-add-on-privacy-concerns/">Firefox ShowIP add-on privacy concerns</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=xVAn0UC6ENQ:fnk9Z4fa3yc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=xVAn0UC6ENQ:fnk9Z4fa3yc:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=xVAn0UC6ENQ:fnk9Z4fa3yc:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=xVAn0UC6ENQ:fnk9Z4fa3yc:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/05/01/firefox-showip-add-on-privacy-concerns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Intelligence Report Volume 12 Released</title>
		<link>http://certifiedbug.com/blog/2012/04/25/microsoft-security-intelligence-report-volume-12-released/</link>
		<comments>http://certifiedbug.com/blog/2012/04/25/microsoft-security-intelligence-report-volume-12-released/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 21:01:11 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5464</guid>
		<description><![CDATA[Microsoft Security Blog Today we released the latest volume of the Microsoft Security Intelligence Report (SIR) containing a large body of new data and analysis on the threat landscape. This volume of the SIR includes:Latest industry vulnerability disclosure trends and analysis Latest industry vulnerability disclosure trends and analysis Latest data and analysis of global vulnerability [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/25/microsoft-security-intelligence-report-volume-12-released/">Microsoft Security Intelligence Report Volume 12 Released</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Microsoft Security Blog</p>
<blockquote><p>Today we released the latest volume of the Microsoft Security Intelligence Report (SIR) containing a large body of new data and analysis on the threat landscape. This volume of the SIR includes:Latest industry vulnerability disclosure trends and analysis</p>
<ul>
<li>Latest industry vulnerability disclosure trends and analysis</li>
<li>Latest data and analysis of global vulnerability exploit activity</li>
<li>Latest trends and analysis on global malware and potentially unwanted software</li>
<li>Latest analysis of threat trends in more than 100 countries/regions around the world</li>
<li>Latest data and insights on how attackers are using spam and other email threats</li>
<li>Latest global and regional data on malicious websites including phishing sites, malware hosting sites and drive-by download sites</li>
</ul>
<p>In addition, we have included a section in the report focused on how the threat called Conficker continues to propagate.</p></blockquote>
<p><a href="http://blogs.technet.com/b/security/archive/2012/04/25/microsoft-security-intelligence-report-volume-12.aspx">http://blogs.technet.com/b/security/archive/2012/04/25/microsoft-security-intelligence-report-volume-12.aspx</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/25/microsoft-security-intelligence-report-volume-12-released/">Microsoft Security Intelligence Report Volume 12 Released</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=PJittZbtuHY:QeTfgJSOU2c:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=PJittZbtuHY:QeTfgJSOU2c:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=PJittZbtuHY:QeTfgJSOU2c:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=PJittZbtuHY:QeTfgJSOU2c:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/04/25/microsoft-security-intelligence-report-volume-12-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 12.0 released</title>
		<link>http://certifiedbug.com/blog/2012/04/25/firefox-12-0-released/</link>
		<comments>http://certifiedbug.com/blog/2012/04/25/firefox-12-0-released/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 20:42:42 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5460</guid>
		<description><![CDATA[Fixed in Firefox version 12. MFSA 2012-33 Potential site identity spoofing when loading RSS and Atom feeds MFSA 2012-32 HTTP Redirections and remote content can be read by javascript errors MFSA 2012-31 Off-by-one error in OpenType Sanitizer MFSA 2012-30 Crash with WebGL content using textImage2D MFSA 2012-29 Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues MFSA 2012-28 [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/25/firefox-12-0-released/">Firefox 12.0 released</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Fixed in Firefox version 12.<br />
MFSA 2012-33 Potential site identity spoofing when loading RSS and Atom feeds<br />
MFSA 2012-32 HTTP Redirections and remote content can be read by javascript errors<br />
MFSA 2012-31 Off-by-one error in OpenType Sanitizer<br />
MFSA 2012-30 Crash with WebGL content using textImage2D<br />
MFSA 2012-29 Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues<br />
MFSA 2012-28 Ambiguous IPv6 in Origin headers may bypass webserver access restrictions<br />
MFSA 2012-27 Page load short-circuit can lead to XSS<br />
MFSA 2012-26 WebGL.drawElements may read illegal video memory due to FindMaxUshortElement error<br />
MFSA 2012-25 Potential memory corruption during font rendering using cairo-dwrite<br />
MFSA 2012-24 Potential XSS via multibyte content processing errors<br />
MFSA 2012-23 Invalid frees causes heap corruption in gfxImageSurface<br />
MFSA 2012-22 use-after-free in IDBKeyRange<br />
MFSA 2012-21 Multiple security flaws fixed in FreeType v2.4.9<br />
MFSA 2012-20 Miscellaneous memory safety hazards (rv:12.0/ rv:10.0.4)</p>
<p>If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu.</p>
<p><a href="https://www.mozilla.org/firefox/12.0/releasenotes/">https://www.mozilla.org/firefox/12.0/releasenotes/</a></p>
<p>Download:<a href="https://www.mozilla.org/en-US/firefox/all.html"> https://www.mozilla.org/en-US/firefox/all.html</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/25/firefox-12-0-released/">Firefox 12.0 released</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=Dm5pBlopAGg:f4Ehr8juG-o:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=Dm5pBlopAGg:f4Ehr8juG-o:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=Dm5pBlopAGg:f4Ehr8juG-o:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=Dm5pBlopAGg:f4Ehr8juG-o:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/04/25/firefox-12-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sabpab Mac OS X backdoor Trojan</title>
		<link>http://certifiedbug.com/blog/2012/04/13/sabpab-mac-os-x-backdoor-trojan/</link>
		<comments>http://certifiedbug.com/blog/2012/04/13/sabpab-mac-os-x-backdoor-trojan/#comments</comments>
		<pubDate>Sat, 14 Apr 2012 00:11:26 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5450</guid>
		<description><![CDATA[Graham Cluley Sophos &#8220;The Sabpab Trojan horse exploits the same drive-by Java vulnerability used to create the Flashback botnet.&#8221; http://nakedsecurity.sophos.com/2012/04/13/sabpab-new-mac-os-x-backdoor-trojan-horse-discovered/ http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx Certifiedbug.com Sabpab Mac OS X backdoor Trojan<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/13/sabpab-mac-os-x-backdoor-trojan/">Sabpab Mac OS X backdoor Trojan</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Graham Cluley<br />
Sophos</p>
<p>&#8220;The Sabpab Trojan horse exploits the same drive-by Java vulnerability used to create the Flashback botnet.&#8221;<br />
<a href="http://nakedsecurity.sophos.com/2012/04/13/sabpab-new-mac-os-x-backdoor-trojan-horse-discovered/">http://nakedsecurity.sophos.com/2012/04/13/sabpab-new-mac-os-x-backdoor-trojan-horse-discovered/</a></p>
<p><a href="http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx">http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/13/sabpab-mac-os-x-backdoor-trojan/">Sabpab Mac OS X backdoor Trojan</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=TWy_BOgH16k:VgLx8n2ewEc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=TWy_BOgH16k:VgLx8n2ewEc:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=TWy_BOgH16k:VgLx8n2ewEc:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=TWy_BOgH16k:VgLx8n2ewEc:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/04/13/sabpab-mac-os-x-backdoor-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Researchers Estimate 600,000 Macs infected by Flashback Trojan</title>
		<link>http://certifiedbug.com/blog/2012/04/10/researchers-estimate-600000-macs-infected-by-flashback-trojan/</link>
		<comments>http://certifiedbug.com/blog/2012/04/10/researchers-estimate-600000-macs-infected-by-flashback-trojan/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 15:45:37 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Krebs]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5435</guid>
		<description><![CDATA[Apple 8 views&#8230; http://support.apple.com/kb/HT5244 Forbes 4/06/2012 For anyone who doubted that Apple’s long grace period with cybercriminals is over, doubt no more: On Friday, researchers at Russian antivirus firm Kaspersky confirmed findings from another security firm earlier this week that more than 600,000 computers running Mac’s OSX are infected with the Flashback botnet, and half [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/10/researchers-estimate-600000-macs-infected-by-flashback-trojan/">Researchers Estimate 600,000 Macs infected by Flashback Trojan</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Apple<br />
<img src="http://certifiedbug.com/blog/wp-content/uploads/2012/04/apple.png" alt="" title="apple" width="571" height="195" class="aligncenter size-full wp-image-5446" /></p>
<p>8 views&#8230;</p>
<p><a href="http://support.apple.com/kb/HT5244">http://support.apple.com/kb/HT5244</a></p>
<p><img src="http://certifiedbug.com/blog/wp-content/uploads/2012/04/apple1.png" alt="" title="apple1" width="300" height="215" class="aligncenter size-full wp-image-5448" /></p>
<p>Forbes<br />
4/06/2012</p>
<blockquote><p>For anyone who doubted that Apple’s long grace period with cybercriminals is over, doubt no more: On Friday, researchers at Russian antivirus firm Kaspersky confirmed findings from another security firm earlier this week that more than 600,000 computers running Mac’s OSX are infected with the Flashback botnet, and half of those machines are in the United States.</p></blockquote>
<p><a href="http://www.forbes.com/sites/andygreenberg/2012/04/06/researchers-confirm-flashback-trojan-infects-600000-macs-being-used-for-clickfraud/">http://www.forbes.com/sites/andygreenberg/2012/04/06/researchers-confirm-flashback-trojan-infects-600000-macs-being-used-for-clickfraud/</a></p>
<p>Krebs On Security</p>
<blockquote><p>The current custodian of Java – Oracle Corp. – first issued an update to plug this flaw and others back on Feb. 17. I suppose Apple’s performance on this front has improved, but its lackadaisical (and often plain puzzling) response to patching dangerous security holes perpetuates the harmful myth that Mac users don’t need to be concerned about malware attacks.</p></blockquote>
<p><a href="http://krebsonsecurity.com/2012/04/urgent-fix-for-zero-day-mac-java-flaw/">http://krebsonsecurity.com/2012/04/urgent-fix-for-zero-day-mac-java-flaw/</a></p>
<p>Forbes<br />
4/09/2012<br />
<a href="http://www.forbes.com/sites/andygreenberg/2012/04/09/apple-snubs-firm-who-discovered-mac-botnet-tries-to-cut-off-its-server-monitoring-infections/">http://www.forbes.com/sites/andygreenberg/2012/04/09/apple-snubs-firm-who-discovered-mac-botnet-tries-to-cut-off-its-server-monitoring-infections/<br />
</a></p>
<p>Kaspersky Lab</p>
<blockquote><p>“The three month delay in sending a security update was a bad decision on Apple’s part,” said Kaspersky Lab’s Chief Security Expert, Alexander Gostev. “There are a few reasons for this. First, Apple doesn&#8217;t allow Oracle to patch Java for Mac. They do it themselves, usually several months later. This means the window of exposure for Mac users is much longer than PC users. This is especially bad news since Apple’s standard AV update is a rudimentary affair which only adds new signatures when a threat is deemed large enough. Apple knew about this Java vulnerability for three months, and yet neglected to push through an update in all that time! The problem is exacerbated because – up to now – Apple has enjoyed a mythical reputation for being ‘malware free’. Too many users are unaware that their computers have been infected, or that there is a real threat to Mac security.”</p></blockquote>
<p><a href="http://www.kaspersky.com/about/news/virus?time=1333224000">http://www.kaspersky.com/about/news/virus?time=1333224000<br />
</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/10/researchers-estimate-600000-macs-infected-by-flashback-trojan/">Researchers Estimate 600,000 Macs infected by Flashback Trojan</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=tEySpBKGa54:t3tsvykHoH0:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=tEySpBKGa54:t3tsvykHoH0:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=tEySpBKGa54:t3tsvykHoH0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=tEySpBKGa54:t3tsvykHoH0:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/04/10/researchers-estimate-600000-macs-infected-by-flashback-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Bulletin Summary for April 2012</title>
		<link>http://certifiedbug.com/blog/2012/04/05/microsoft-security-bulletin-summary-for-april-2012/</link>
		<comments>http://certifiedbug.com/blog/2012/04/05/microsoft-security-bulletin-summary-for-april-2012/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 23:22:39 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vulnerability-Windows-Update]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5455</guid>
		<description><![CDATA[The Microsoft Security Response Center (MSRC) Today we’re releasing our advance notification for the April security bulletin release, which is scheduled for Tuesday, April 10. This month’s release includes 6 bulletins addressing 11 vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Forefront UAG, and .NET Framework. All 6 bulletins will be released on Tuesday, April [...]<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/05/microsoft-security-bulletin-summary-for-april-2012/">Microsoft Security Bulletin Summary for April 2012</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://blogs.technet.com/b/msrc/archive/2012/04/05/advance-notification-service-for-april-2012-security-bulletin-release.aspx">The Microsoft Security Response Center (MSRC)</a></p>
<blockquote><p>Today we’re releasing our <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr">advance notification</a> for the April security bulletin release, which is scheduled for Tuesday, April 10. This month’s release includes 6 bulletins addressing 11 vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Forefront UAG, and .NET Framework. All 6 bulletins will be released on Tuesday, April 10 at approximately 10 a.m. PDT. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.</p>
<p>As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.</p></blockquote>
<p>Microsoft Security Bulletin Summary for April 2012<br />
<a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr">http://technet.microsoft.com/en-us/security/bulletin/ms12-apr</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/04/05/microsoft-security-bulletin-summary-for-april-2012/">Microsoft Security Bulletin Summary for April 2012</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=ExGGbpkPX2M:zdLW_wTCFh4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=ExGGbpkPX2M:zdLW_wTCFh4:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=ExGGbpkPX2M:zdLW_wTCFh4:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=ExGGbpkPX2M:zdLW_wTCFh4:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/04/05/microsoft-security-bulletin-summary-for-april-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MasterCard and VISA Warn of Processor Breach</title>
		<link>http://certifiedbug.com/blog/2012/03/30/mastercard-and-visa-warn-of-processor-breach/</link>
		<comments>http://certifiedbug.com/blog/2012/03/30/mastercard-and-visa-warn-of-processor-breach/#comments</comments>
		<pubDate>Sat, 31 Mar 2012 00:00:44 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[CreditCard]]></category>
		<category><![CDATA[Fraud]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=5432</guid>
		<description><![CDATA[Krebs on Security VISA and MasterCard are alerting banks across the country about a recent major breach at a U.S.-based credit card processor. Sources in the financial sector are calling the breach “massive,” and say it may involve more than 10 million compromised card numbers. http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/ Certifiedbug.com MasterCard and VISA Warn of Processor Breach<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/03/30/mastercard-and-visa-warn-of-processor-breach/">MasterCard and VISA Warn of Processor Breach</a></p>
]]></description>
			<content:encoded><![CDATA[<p></p><p>Krebs on Security</p>
<blockquote><p>VISA and MasterCard are alerting banks across the country about a recent major breach at a U.S.-based credit card processor. Sources in the financial sector are calling the breach “massive,” and say it may involve more than 10 million compromised card numbers.</p></blockquote>
<p><a href="http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/">http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>

<br/><br/><a href="http://certifiedbug.com/blog/2012/03/30/mastercard-and-visa-warn-of-processor-breach/">MasterCard and VISA Warn of Processor Breach</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=-x3zLaDKVFs:0Zz4pcf9TEE:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=-x3zLaDKVFs:0Zz4pcf9TEE:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Certifiedbugcom?a=-x3zLaDKVFs:0Zz4pcf9TEE:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Certifiedbugcom?i=-x3zLaDKVFs:0Zz4pcf9TEE:D7DqB2pKExk" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2012/03/30/mastercard-and-visa-warn-of-processor-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

