<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>WatchGuard Security Center</title>
	
	<link>http://watchguardsecuritycenter.com</link>
	<description>Everything you need to take threats head on</description>
	<lastBuildDate>Sat, 25 May 2013 01:36:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain="watchguardsecuritycenter.com" port="80" path="/?rsscloud=notify" registerProcedure="" protocol="http-post" />
<image><link>http://www.watchguard.com/education/</link><url>http://www.watchguard.com/wgicon.gif</url><title>WatchGuard Wire</title></image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://watchguardsecuritycenter.com/osd.xml" title="WatchGuard Security Center" />
	
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/WatchguardWire" /><feedburner:info uri="watchguardwire" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://watchguardsecuritycenter.com/?pushpress=hub" /><geo:lat>47.598383</geo:lat><geo:long>-122.327537</geo:long><feedburner:emailServiceId>WatchguardWire</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FWatchguardWire" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FWatchguardWire" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FWatchguardWire" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/WatchguardWire" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FWatchguardWire" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FWatchguardWire" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FWatchguardWire" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item>
		<title>WatchGuard Security Week in Review: Episode 64 – AusCERT 2013</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/DKMmOh1itvk/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/24/watchguard-security-week-in-review-episode-64-auscert-2013/#comments</comments>
		<pubDate>Sat, 25 May 2013 01:36:12 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[ATM]]></category>
		<category><![CDATA[cyber heist]]></category>
		<category><![CDATA[Darkleech]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IE8 zero day]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lighthttpd]]></category>
		<category><![CDATA[LiveSecurity]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Syrian Electronic Army]]></category>
		<category><![CDATA[The Onion]]></category>
		<category><![CDATA[Twitter Hack]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[vlog]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[WatchGuard]]></category>
		<category><![CDATA[WatchGuard Security Week in Review]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3992</guid>
		<description><![CDATA[AusCERT, Aurora Updates, and FPS Hacks Do you know the latest information security (infosec) buzz? If not, you&#8217;ve found the right weekly vlog. Every Friday we post a short video sharing the latest network and information security highlights for your consideration. Today&#8217;s episode comes to you from the beautiful Australian Gold Coast, which is why [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3992&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h2>AusCERT, Aurora Updates, and FPS Hacks</h2>
<p>Do you know the latest information security (infosec) buzz? If not, you&#8217;ve found the right weekly vlog. Every Friday we post a short video sharing the latest network and information security highlights for your consideration. Today&#8217;s episode comes to you from the beautiful Australian Gold Coast, which is why I&#8217;ve had to post it a bit late due to travel.</p>
<p>In this episode I share a few highlights from the AusCERT security conference, update you on the old Google Aurora attack, warn about new vulnerabilities affecting many FPS engines, and much more. If you want to stay abreast of the latest network security news, in eight minutes or less, watch the video below.</p>
<p>As always, you can find more detail about the stories from this week&#8217;s episode in the Reference section, as well as a few extras.</p>
<p><em>(Episode Runtime: 7:41)</em></p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='588' height='361' src='http://www.youtube.com/embed/JLbzY_i8TIc?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<p><em>Direct YouTube Link: <a href="http://www.youtube.com/watch?v=JLbzY_i8TIc">http://www.youtube.com/watch?v=JLbzY_i8TIc</a></em></p>
<h4>Episode References:</h4>
<ul>
<li><a href="http://conference.auscert.org.au/conf2013/">AusCERT 2013 Security Conference</a> - <em>AusCERT</em></li>
<li><a href="http://media.risky.biz/auscert2013/hdmauscert.mp3">Audio recording of HD Moore&#8217;s AusCERT presentation</a> - <em>Risky Business</em></li>
<li><a href="http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html">Chrome 27 security update</a> - <em>Google Chrome Blog</em></li>
<li><a href="http://support.apple.com/kb/HT5770">Apple Quicktime security update</a> - <em>Apple</em></li>
<li><a href="http://www.washingtonpost.com/world/national-security/chinese-hackers-who-breached-google-gained-access-to-sensitive-data-us-officials-say/2013/05/20/51330428-be34-11e2-89c9-3be8095fe767_story.html">Chinese Aurora hackers may have stolen government surveillance info</a> - <em>The Washington Post</em></li>
<li><a href="http://arstechnica.com/security/2013/05/reporters-use-google-find-breach-get-branded-as-hackers">Reporters accused of hacking for Google searches</a> - <em>Ars Technica</em></li>
<li><a href="http://www.computerworld.com/s/article/9239433/Researchers_find_critical_vulnerabilities_in_popular_game_engines">Researchers find flaws in most popular FPS engines</a> - <em>Computer World</em></li>
<li><a href="http://techcrunch.com/2013/05/22/twitter-ups-account-security-with-optional-two-factor-authentication-via-sms/">Twitter finally offers two-factor authentication</a> - <em>Tech Crunch</em></li>
<li><a href="http://www.theregister.co.uk/2013/05/17/mac_malware_steals_screenshots"> </a></li>
</ul>
<p><strong>Extras:</strong></p>
<ul>
<li><a href="http://www.csoonline.com/article/733713/opinion-varies-on-action-against-chinese-cyberattacks">Chinese state-sponsered hackers are still at work</a> - <em>CSO Online</em></li>
<li><a href="http://www.theregister.co.uk/2013/05/21/sea_hijacks_telegraph_twitter_feeds/">Syrian Electronic Army hijacks The Telegraph Twitter feed</a> - <em>The Register</em><em><br />
</em></li>
<li><a href="http://www.informationweek.com/security/attacks/fbi-arrests-nypd-detective-on-hacking-ch/240155332">NYPD Detective arrested for hacking</a> - <em>Information Week</em></li>
<li><a href="https://krebsonsecurity.com/2013/05/ragebooter-legit-ddos-service-or-fed-backdoor">DDoS service site claims DDoS are legal</a> - <em>Krebs on Security</em></li>
<li><a href="http://www.computerworld.com/s/article/9239378/Yahoo_Japan_says_22_million_user_IDs_may_have_been_stolen">22 million user IDs stolen from Yahoo Japan</a> - <em>Computer World</em></li>
</ul>
<p><strong><em>— <a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#coreyn">Corey Nachreiner, CISSP</a> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3992/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3992/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3992&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=DKMmOh1itvk:TxnWX2LMpr0:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=DKMmOh1itvk:TxnWX2LMpr0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=DKMmOh1itvk:TxnWX2LMpr0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=DKMmOh1itvk:TxnWX2LMpr0:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=DKMmOh1itvk:TxnWX2LMpr0:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=DKMmOh1itvk:TxnWX2LMpr0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=DKMmOh1itvk:TxnWX2LMpr0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/DKMmOh1itvk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/24/watchguard-security-week-in-review-episode-64-auscert-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/24/watchguard-security-week-in-review-episode-64-auscert-2013/</feedburner:origLink></item>
		<item>
		<title> WatchGuard Announces Fireware XTM and WSM 11.7.3</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/0PsHQ4xNcUU/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/22/%e2%80%a8watchguard-announces-fireware-xtm-and-wsm-11-7-3/#comments</comments>
		<pubDate>Wed, 22 May 2013 21:09:04 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[WatchGuard Software]]></category>
		<category><![CDATA[11.7]]></category>
		<category><![CDATA[11.7.3]]></category>
		<category><![CDATA[Fireware]]></category>
		<category><![CDATA[software update]]></category>
		<category><![CDATA[Wireless AP]]></category>
		<category><![CDATA[WSM]]></category>
		<category><![CDATA[XTM]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3987</guid>
		<description><![CDATA[Available for All XTM Appliances (Except XTM 21/22/23) WatchGuard is pleased to announce the release of Fireware XTM v11.7.3 and WatchGuard System Manager v11.7.3. This maintenance release includes a large number of bugfixes and some enhancements. For full information on the issues fixed in v11.7.3, see the Resolved Issues section of the Release Notes. Enhancements are [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3987&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h2>Available for All XTM Appliances (Except XTM 21/22/23)</h2>
<p>WatchGuard is pleased to announce the release of Fireware XTM v11.7.3 and WatchGuard System Manager v11.7.3. This maintenance release includes a large number of bugfixes and some enhancements. For full information on the issues fixed in v11.7.3, see the Resolved Issues section of the <a href="https://www.watchguard.com/support/release-notes/xtm/11/en-US/EN_ReleaseNotes_FirewareXTM_11_7_3/index.html">Release Notes</a>. Enhancements are outlined in the release notes and also covered in  <a href="http://www.watchguard.com/help/docs/wsm/11_XTM/en-US/whats_new_in_XTM_11_7_3.ppt">What’s New in Fireware XTM v11.7.3 [PPT file]</a>.</p>
<p>Some of the enhancements include:</p>
<ul>
<li>Ability to set the source IP address in Static NAT and server load balancing actions</li>
<li>Modem support for three USB 3G/4G modems</li>
<li>Ability to change the port used for connections to a syslog server</li>
</ul>
<p>There are some notable updates for the new Wireless Access Points and the Gateway Wireless Controller.</p>
<ul>
<li>MAC access control whitelist</li>
<li>Station isolation</li>
<li>No automatic AP device reboot after AP configuration change</li>
</ul>
<p>The 11.7.3 release also provides significant improvements in spam detection based on feedback received since the 11.7.2 release. The release notes also provide some guidance on setting appropriate spam threshold settings with for the new Mailshell engine. Some customers have preferred to set the suspect spam threshold to 80 to reduce the amount of legitimate email that gets categorized as suspect spam.</p>
<p>Fireware XTM 11.7.3 enables XTMv support for the Microsoft Hyper-V hypervisor. The virtual appliance (in VHD format) for Hyper-V is not available at initial v11.7.3 release, but will be released in one to two weeks.</p>
<h3>Does This Release Pertain to Me?</h3>
<p>Fireware XTM 11.7.3 includes many improvements and fixes. If you have a XTM 25/25-W/26/26-W, 3 Series, 5 Series, 8 Series, 800 Series, 1500 Series, 2500 Series, 1050 or 2050 device and wish to take advantage of the updates mentioned in the Release Notes, you should upgrade to version 11.7.3. Please read the <a href="https://www.watchguard.com/support/release-notes/xtm/11/en-US/EN_ReleaseNotes_FirewareXTM_11_7_3/index.html">Release Notes</a> before you upgrade to understand what’s involved.</p>
<p><b>Note:</b> <i>This update does not apply to XTM 21/22/23 appliance owners, or Firebox X e-Series owners.</i></p>
<h3>How Do I Get the Release?</h3>
<p>XTM appliances owners who have a current LiveSecurity Service subscription can obtain this update without additional charge by downloading the applicable packages from the Articles &amp; Support section of WatchGuard’s Support Center. To make it easier to find the relevant software, be sure to uncheck the “Article” and “Known Issue” search options, and press the Go button.</p>
<p>If you need support, please enter a support incident online or call our support staff directly. (When you contact Technical Support, please have your registered Product Serial Number, LiveSecurity Key, or Partner ID available.)</p>
<ul>
<li>U.S. End Users: 877.232.3531</li>
<li>International End Users: +1.206.613.0456</li>
<li>Authorized WatchGuard Resellers: +1.206.521.8375</li>
</ul>
<p>Don’t have an active LiveSecurity subscription for your XTM appliance? It’s easy to renew. Contact your WatchGuard reseller today. <a href="http://findpartner.watchguard.com/">Find a reseller</a> »</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3987/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3987/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3987&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=0PsHQ4xNcUU:pe2OVrfgxbA:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=0PsHQ4xNcUU:pe2OVrfgxbA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=0PsHQ4xNcUU:pe2OVrfgxbA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=0PsHQ4xNcUU:pe2OVrfgxbA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=0PsHQ4xNcUU:pe2OVrfgxbA:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=0PsHQ4xNcUU:pe2OVrfgxbA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=0PsHQ4xNcUU:pe2OVrfgxbA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/0PsHQ4xNcUU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/22/%e2%80%a8watchguard-announces-fireware-xtm-and-wsm-11-7-3/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/22/%e2%80%a8watchguard-announces-fireware-xtm-and-wsm-11-7-3/</feedburner:origLink></item>
		<item>
		<title>WatchGuard Security Week in Review: Episode 63 – Patch Bonanza</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/G6GLozOP5_A/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/17/watchguard-security-week-in-review-episode-63-patch-bonanza/#comments</comments>
		<pubDate>Fri, 17 May 2013 16:02:34 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[ATM]]></category>
		<category><![CDATA[cyber heist]]></category>
		<category><![CDATA[Darkleech]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IE8 zero day]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lighthttpd]]></category>
		<category><![CDATA[LiveSecurity]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Syrian Electronic Army]]></category>
		<category><![CDATA[The Onion]]></category>
		<category><![CDATA[Twitter Hack]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[vlog]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[WatchGuard]]></category>
		<category><![CDATA[WatchGuard Security Week in Review]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3982</guid>
		<description><![CDATA[Zero Day Patches, Nasty New Malware, and Jailed Hackers Ready for a dose of InfoSec news? Your weekly security highlights reel is spooled up and ready to go. This week was all about software updates. Not only did Microsoft and Adobe&#8217;s monthly Patch Day bring us patches for critical zero day vulnerabilities, but we saw [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3982&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h2>Zero Day Patches, Nasty New Malware, and Jailed Hackers</h2>
<p>Ready for a dose of InfoSec news? Your weekly security highlights reel is spooled up and ready to go.</p>
<p>This week was all about software updates. Not only did Microsoft and Adobe&#8217;s monthly Patch Day bring us patches for critical zero day vulnerabilities, but we saw security updates for Firefox and iTunes as well. In today&#8217;s video, I talk about all those updates, as well as two new interesting malware variants, and the sentencing and jailing of a team of well-known hackers. View the video for all the details.</p>
<p>A quick note&#8230; Next week I&#8217;ll be attending the AusCERT security conference in Australia. Though I still expect to bring you a weekly video, I may post it earlier or later than normal due to travel and the time zone differences. Keep safe out there and see you next week.</p>
<p><em>(Episode Runtime: 7:17)</em></p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='588' height='361' src='http://www.youtube.com/embed/gjAx6PdFY0k?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<p><em>Direct YouTube Link: <a href="http://www.youtube.com/watch?v=gjAx6PdFY0k">http://www.youtube.com/watch?v=gjAx6PdFY0k</a></em></p>
<h4>Episode References:</h4>
<ul>
<li>Microsoft Patch Day, May 2013
<ul>
<li><a href="http://watchguardsecuritycenter.com/2013/05/14/microsoft-black-tuesday-fix-for-ie8-zero-day-and-more/">Microsoft May Patch Day Summary</a> - <em>WGSC</em></li>
<li><a href="http://watchguardsecuritycenter.com/2013/05/14/two-critical-ie-bulletins-fix-zero-day-vulnerability-and-more/">Microsoft Patches 0day IE vulnerability and more</a> - <em>WGSC</em></li>
<li><a href="http://watchguardsecuritycenter.com/2013/05/14/trio-of-windows-bulletins-correct-moderate-vulnerabilities/">Microsoft&#8217;s Windows updates for May</a> - <em>WGSC</em></li>
<li><a href="http://watchguardsecuritycenter.com/2013/05/14/office-patches-mend-word-visio-publisher-and-lync/">Microsoft&#8217;s Office updates for May</a> - <em>WGSC</em></li>
<li><a href="http://watchguardsecuritycenter.com/2013/05/14/windows-essentials-free-programs-need-patches-too/">Minor Microsoft Essentials update</a> - <em>WGSC</em></li>
</ul>
</li>
<li><a href="http://watchguardsecuritycenter.com/2013/05/15/adobe-patch-day-update-for-coldfusion-zero-day-and-more/">Adobe fixes Reader, Flash, and ColdFusion flaws</a> - <em>WGSC</em></li>
<li><a href="http://www.mozilla.org/security/known-vulnerabilities/firefox.html#firefox21">Mozilla releases Firefox 21 to fix eight vulnerabilities</a> &#8211; <em>Mozilla</em></li>
<li><a href="http://support.apple.com/kb/HT5766">Latest version of Apple iTunes fixes 41 vulnerabilities</a> - <em>Apple</em></li>
<li><a href="http://www.theregister.co.uk/2013/05/17/mac_malware_steals_screenshots">New Mac malware leverages valid developer ID</a> &#8211; <em>The Register</em></li>
<li><a href="http://securitywatch.pcmag.com/hacking/311408-latest-dorkbot-malware-spread-via-facebook-chat">New Dorkbot variant spreads via Facebook chat and MediaFire </a>- <em>PC Magazine</em></li>
<li><em></em><a href="http://www.wired.com/threatlevel/2013/05/lulzsec-sony-hackers-sentenced/">Four members of Lulzsec sentenced and Jailed</a> &#8211; <em>Wired</em></li>
</ul>
<p><strong>Extras:</strong></p>
<ul>
<li><a href="http://www.h-online.com/open/news/item/Exploit-for-local-Linux-kernel-bug-in-circulation-Update-1863892.html">Linux kernal exploit in circulation</a> - <em>The H Open</em></li>
<li><strong>Breaking:</strong> <a href="http://www.theregister.co.uk/2013/05/17/ft_twitter_hijacked_by_sea/?">Syrian Electronic Army hijacks The Financial Times web site and Twitter</a> - <em>The Register</em><em><br />
</em></li>
<li><a href="http://www.bloomberg.com/news/2013-05-15/car-hacking-threat-prompts-new-effort-by-auto-regulator.html">Auto regulators thinking about car hacking (one of my predictions last year)</a> - <em>Bloomberg</em></li>
<li><a href="http://www.computerworld.com/s/article/9239226/Researchers_uncover_large_cyberfraud_operation_targeting_Australian_bank_customers">Cyber fraud campaign discovered targeting Australian banks</a> - <em>ComputerWorld</em></li>
<li><a href="http://www.theinquirer.net/inquirer/news/2267690/hacking-exploit-pops-up-for-bethesda-s-skyrim-and-fallout">Software vulnerabilities found in Skyrim and Fallout 3 (fairly benign, but interesting) </a>- <em>The Inquirer</em></li>
</ul>
<p><strong><em>— <a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#coreyn">Corey Nachreiner, CISSP</a> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3982/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3982/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3982&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=G6GLozOP5_A:NB6hGKvftMA:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=G6GLozOP5_A:NB6hGKvftMA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=G6GLozOP5_A:NB6hGKvftMA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=G6GLozOP5_A:NB6hGKvftMA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=G6GLozOP5_A:NB6hGKvftMA:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=G6GLozOP5_A:NB6hGKvftMA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=G6GLozOP5_A:NB6hGKvftMA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/G6GLozOP5_A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/17/watchguard-security-week-in-review-episode-63-patch-bonanza/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/17/watchguard-security-week-in-review-episode-63-patch-bonanza/</feedburner:origLink></item>
		<item>
		<title>Adobe Patch Day: Update for ColdFusion Zero Day and More</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/T2N1WhkbaQc/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/15/adobe-patch-day-update-for-coldfusion-zero-day-and-more/#comments</comments>
		<pubDate>Wed, 15 May 2013 17:40:51 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Flash Player]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[shockwave]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3963</guid>
		<description><![CDATA[Severity: High Summary: These vulnerabilities affect: Adobe Reader and Acrobat, Flash Player, and ColdFusion How an attacker exploits them: Multiple vectors of attack, including enticing your users to open malicious files or visit specially crafted web sites Impact: Various results; in the worst case, an attacker can gain complete control of your computer What to do: Install the appropriate [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3963&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h2><span class="Apple-style-span" style="font-size:15px;">Severity: High</span></h2>
<h3>Summary:</h3>
<ul>
<li><strong>These vulnerabilities affect:</strong> Adobe Reader and Acrobat, Flash Player, and ColdFusion</li>
<li><strong>How an attacker exploits them:</strong> Multiple vectors of attack, including enticing your users to open malicious files or visit specially crafted web sites</li>
<li><strong>Impact:</strong> Various results; in the worst case, an attacker can gain complete control of your computer</li>
<li><strong>What to do:</strong> Install the appropriate Adobe patches immediately, or let Adobe&#8217;s updater do it for you.</li>
</ul>
<h3>Exposure:</h3>
<p>Yesterday, Adobe released three security bulletins describing vulnerabilities in Reader and Acrobat, Flash Player, and ColdFusion. A remote attacker could exploit the worst of these flaws to gain complete control of your computer. Attackers have been exploiting one of the ColdFusion issues in the wild, so we recommend you patch quickly.</p>
<p>The summary below details some of the vulnerabilities in these popular software packages.</p>
<p><a href="http://www.adobe.com/support/security/"><img class="aligncenter size-large wp-image-3964" alt="Adobe Patch Day May 2013" src="http://watchguardwire.files.wordpress.com/2013/05/adobepdmay2013.png?w=600&#038;h=195" width="600" height="195" /></a></p>
<ul>
<li><strong><a href="http://www.adobe.com/support/security/bulletins/apsb13-15.html">APSB13-15</a>: Multiple Reader and Acrobat  Memory Corruption Vulnerabilities</strong></li>
</ul>
<blockquote><p><a href="http://www.adobe.com/products/reader.html">Adobe Reader</a> helps you view PDF documents, while <a href="http://www.adobe.com/products/acrobat.html">Acrobat</a> helps you create them. Since PDF documents are very popular, most users install Reader to handle them.</p>
<p>Adobe’s bulletin describes 27 vulnerabilities that affect Adobe Reader and Acrobat X 11.0.2 and earlier, running on any platform (Windows, Mac, Linux).  Adobe’s alert only describes the flaws in minimal detail, but the majority of them involve memory corruption-related vulnerabilities, such as <a href="http://www.watchguard.com/glossary/b.asp#buffer_overflow">buffer overflows</a>,  <a href="http://cwe.mitre.org/data/definitions/190.html">integer overflows</a>, <a href="http://cwe.mitre.org/data/definitions/416.html">use-after-free</a> issues, and so on. For the most part, they share the same scope and impact. If an attacker can entice you into opening a specially crafted PDF file, he can exploit many of these issues to execute code on your computer, with your privileges. If you have root or system administrator privileges, the attacker gains complete control of your machine.</p>
<p><em><a href="http://www.adobe.com/support/security/severity_ratings.html">Adobe Priority Rating</a>: <strong>2</strong> <em>(Patch within 30 days)</em> for most, though <strong>1</strong> for Windows systems with 9.x and below</em></p></blockquote>
<ul>
<li><strong><a href="http://www.adobe.com/support/security/bulletins/apsb13-14.html">APSB13-14</a></strong><strong>: Multiple Flash Player Memory Corruption Flaws<br />
</strong></li>
</ul>
<blockquote><p>Adobe’s bulletin describes 13 vulnerabilities in Flash Player running on all platforms (including Linux and Android). More specifically, the flaws consist of various memory corruption flaws. If an attacker can lure you to a web site, or get you to open a document containing specially crafted Flash content, he could exploit these flaws to execute code on your computer, with your privileges. If you have administrative or root privileges, the attacker could gain full control of your computer.</p>
<p>Adobe rates these flaws with their highest severity rating for Windows computers, but a lesser severity for Mac and Linux machines.</p>
<p><em><a href="http://www.adobe.com/support/security/severity_ratings.html">Adobe Priority Rating</a>: <strong>1</strong> for Windows<strong> </strong>(Patch within 72 hours)</em></p></blockquote>
<ul>
<li><strong><a href="http://www.adobe.com/support/security/bulletins/apsb13-13.html">APSB13-13</a>: Critical Zero Day ColdFusion Vulnerability Patched</strong></li>
</ul>
<div>
<blockquote><p>Adobe <a title="http://www.adobe.com/ap/products/coldfusion/" href="http://www.adobe.com/ap/products/coldfusion/">ColdFusion</a> is an application server that allows you to develop and deploy web applications. This bulletin fixes two serious vulnerabilities; one of which attackers are currently exploiting in the wild. We mentioned this zero day flaw in passing during <a href="http://watchguardsecuritycenter.com/2013/05/10/watchguard-security-week-in-review-episode-62-major-cyber-heist/">last week&#8217;s security news video</a>. Adobe&#8217;s bulletin doesn&#8217;t share many details, but the primary flaw is a remote code execution vulnerability. If you expose certain default ColdFusion directories, an attacker could exploit this flaw to execute code on you web server simply by sending specially crafted HTTP packets. Though not quite as bad, the second vulnerability allows attackers to remotely retrieve sensitive files from your server. Adobe rates these flaws Priority 1, so we highly recommend ColdFusion administrators update immediately&#8211;especially if you have public facing servers.</p>
<p>You can find a bit more detail about the zero day ColdFusion flaw in a <a href="http://www.adobe.com/support/security/advisories/apsa13-03.html">security advisory</a> Adobe released earlier this month.</p>
<p><em><a href="http://www.adobe.com/support/security/severity_ratings.html">Adobe Priority Rating</a>:<em> <strong>1</strong> (Patch within 72 hours)</em></em></p></blockquote>
</div>
<h3>Solution Path:</h3>
<p>Adobe has released updates for all their affected software. If you use any of the software below, we recommend you download and deploy the corresponding updates as soon as possible, or let Adobe’s automatic updater do it for you:<a href="http://www.adobe.com/support/security/bulletins/apsb13-12.html"><br />
</a></p>
<ul>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb13-15.html">APSB13-15</a><strong>: </strong>
<ul>
<li>Adobe Reader X 11.0.3
<ul>
<li><a href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Windows">For Windows</a></li>
<li><a href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Macintosh">For Mac</a></li>
</ul>
</li>
</ul>
<ul>
<li>Adobe Acrobat X 11.0.2
<ul>
<li><a href="http://www.adobe.com/support/downloads/product.jsp?product=1&amp;platform=Windows">Standard and Pro for Windows</a></li>
<li><a href="http://www.adobe.com/support/downloads/product.jsp?product=1&amp;platform=Windows">Pro Extended for Windows</a></li>
<li><a href="http://www.adobe.com/support/downloads/product.jsp?product=1&amp;platform=Macintosh">Pro for Mac</a></li>
</ul>
</li>
</ul>
<ul>
<li>Adobe Reader 9.5.4 <a href="ftp://ftp.adobe.com/pub/adobe/reader/unix/9.x/">for Linux</a></li>
</ul>
</li>
<li><a href="https://www.adobe.com/support/security/bulletins/apsb13-14.html">APSB13-14</a><strong>: </strong>Upgrade to the latest <a href="http://get.adobe.com/flashplayer/">Flash Player</a> <em>(11.7.700.202 for Windows)</em>
<ul>
<li><em><strong>Note:</strong> Android users should update via Google Play. Both Chrome and Internet Explorer (IE) 10 have Flash built in. You need to update these browsers separately. Find more details about the IE10 update <a href="http://technet.microsoft.com/en-us/security/advisory/2755801">here</a>.</em></li>
</ul>
</li>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb13-13.html">APSB13-13</a><strong>: </strong>Apply the corresponding ColdFusion hotfix. More details in this <a href="http://helpx.adobe.com/coldfusion/kb/coldfusion-security-hotfix-apsb13-13.html">Adobe technote</a>.</li>
</ul>
<p>&nbsp;</p>
<p><a href="http://www.adobe.com/go/getreader"><img class="alignleft size-full wp-image-3967" alt="Download Adobe Reader" src="http://watchguardwire.files.wordpress.com/2013/05/get_adobe_reader.gif?w=600"   /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://get.adobe.com/flashplayer/"><img class="alignleft size-full wp-image-3968" alt="Download Adobe Flash Player" src="http://watchguardwire.files.wordpress.com/2013/05/160x41_get_flashplayer-e1368633191634.gif?w=600"   /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h4>For All WatchGuard Users:</h4>
<p>Attackers can exploit these flaws using diverse exploitation methods. However, WatchGuard&#8217;s XTM appliances can help in many ways. First, our IPS and AV services are often capable of detecting the malicious Flash or Reader files attackers are actually using in the wild. If you&#8217;d like, you can also configure our proxies to block Reader or Flash content. This, however, blocks both legitimate and malicious content. If you do want to block this Flash or Reader via the <a href="http://watchguard.com/help/docs/wsm/11_XTM/en-US/index.html#en-US/proxies/http/http_responses_content_types_c.html">Web</a> or <a href="http://watchguard.com/help/docs/wsm/11_XTM/en-US/index.html#en-US/proxies/smtp/proxy_smtp_content_types_c.html">email</a>, see our manual for more details on how to configure our proxy policies&#8217; content-filtering.</p>
<h3>Status:</h3>
<p>Adobe  has released patches correcting these issues.</p>
<h3>References:</h3>
<ul>
<ul>
<li>Adobe Security Update <a href="http://www.adobe.com/support/security/bulletins/apsb13-13.html">APSB13-13</a></li>
<li>Adobe Security Update <a href="https://www.adobe.com/support/security/bulletins/apsb13-14.html">APSB13-14</a></li>
<li>Adobe Security Update <a href="http://www.adobe.com/support/security/bulletins/apsb13-15.html">APSB13-15</a></li>
</ul>
</ul>
<p>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3963/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3963/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3963&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=T2N1WhkbaQc:vQIzq81-3rQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=T2N1WhkbaQc:vQIzq81-3rQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=T2N1WhkbaQc:vQIzq81-3rQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=T2N1WhkbaQc:vQIzq81-3rQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=T2N1WhkbaQc:vQIzq81-3rQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=T2N1WhkbaQc:vQIzq81-3rQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=T2N1WhkbaQc:vQIzq81-3rQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/T2N1WhkbaQc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/15/adobe-patch-day-update-for-coldfusion-zero-day-and-more/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2013/05/adobepdmay2013.png?w=600" medium="image">
			<media:title type="html">Adobe Patch Day May 2013</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2013/05/get_adobe_reader.gif" medium="image">
			<media:title type="html">Download Adobe Reader</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2013/05/160x41_get_flashplayer-e1368633191634.gif" medium="image">
			<media:title type="html">Download Adobe Flash Player</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/15/adobe-patch-day-update-for-coldfusion-zero-day-and-more/</feedburner:origLink></item>
		<item>
		<title>Windows Essentials: Free Programs Need Patches Too</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/fvqBVMX8F4Y/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/14/windows-essentials-free-programs-need-patches-too/#comments</comments>
		<pubDate>Tue, 14 May 2013 23:47:41 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3955</guid>
		<description><![CDATA[Do you use Windows Essentials? If so, let the Windows Automatic Updater do its job, but no hurry. Along with their nine other Patch Day bulletins, Microsoft released a less significant software update for Windows Essentials; a suite of free and optional  productivity applications for Windows. Essentials consists of a menagerie of applications, including basic [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3955&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Do you use Windows Essentials? If so, let the Windows Automatic Updater do its job, but no hurry.</p>
<p>Along with their nine other <a href="http://watchguardsecuritycenter.com/2013/05/14/microsoft-black-tuesday-fix-for-ie8-zero-day-and-more/">Patch Day bulletins</a>, Microsoft released a less significant software update for <a href="http://en.wikipedia.org/wiki/Windows_Essentials">Windows Essentials</a>; a suite of free and optional  productivity applications for Windows. Essentials consists of a menagerie of applications, including basic photo gallery, blogging, email, instant messenger, and movie editing software. Many of the applications are cloud-based.</p>
<p>In any case, according to <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-045">one of today&#8217;s bulletins</a>, Windows Essentials suffers from a relatively minor information disclosure vulnerability. If an attacker can get a Windows Live Writer (the blogging app) user to click a specially crafted link, he can leverage this flaw to overwrite some of that user&#8217;s files. Certainly not a good thing, but also not the worst flaw in the world.</p>
<p>I personally doubt many business user leverage the Essentials suite, so I don&#8217;t think this particular issue poses a huge risk to our readers. That said, if you do use the Windows Essentials Live Writer program, then you certainly wouldn&#8217;t want to lose content based on this sort of attack. So I would definitely apply Microsoft&#8217;s patch, though there&#8217;s no rush. You can find more details about the update in the &#8220;<a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-045#section3">Affected and Non-Affected Software</a>&#8221; section of <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-045">Microsoft&#8217;s bulletin</a>. — <em><a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#corey">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3955/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3955/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3955&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=fvqBVMX8F4Y:hHjxXXbO9Og:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=fvqBVMX8F4Y:hHjxXXbO9Og:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=fvqBVMX8F4Y:hHjxXXbO9Og:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=fvqBVMX8F4Y:hHjxXXbO9Og:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=fvqBVMX8F4Y:hHjxXXbO9Og:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=fvqBVMX8F4Y:hHjxXXbO9Og:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=fvqBVMX8F4Y:hHjxXXbO9Og:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/fvqBVMX8F4Y" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/14/windows-essentials-free-programs-need-patches-too/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/14/windows-essentials-free-programs-need-patches-too/</feedburner:origLink></item>
		<item>
		<title>Office Patches Mend Word, Visio, Publisher, and Lync</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/2TTuRXvRLVU/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/14/office-patches-mend-word-visio-publisher-and-lync/#comments</comments>
		<pubDate>Tue, 14 May 2013 23:07:56 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[Lync]]></category>
		<category><![CDATA[memory corruption]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[publisher]]></category>
		<category><![CDATA[RCE]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[visio]]></category>
		<category><![CDATA[word]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3935</guid>
		<description><![CDATA[Severity: High Summary: These vulnerabilities affect: Microsoft Office related products, including Word, Visio, Publisher, and Lync How an attacker exploits them: Typically by enticing users to open or interact with maliciously crafted Office documents Impact: In the worst case, an attacker can gain complete control of your Windows computer What to do: Install the appropriate Microsoft patches [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3935&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h3>Severity: High</h3>
<h3>Summary:</h3>
<ul type="disc">
<li><strong>These vulnerabilities affect:</strong> Microsoft Office related products, including Word, Visio, Publisher, and Lync</li>
<li><strong>How an attacker exploits them:</strong> Typically by enticing users to open or interact with maliciously crafted Office documents</li>
<li><strong>Impact:</strong> In the worst case, an attacker can gain complete control of your Windows computer</li>
<li><strong>What to do:</strong> Install the appropriate Microsoft patches as soon as possible, or let Windows Automatic Update do it for you.</li>
</ul>
<h3>Exposure:</h3>
<p>Today, Microsoft released four security bulletins that fix 14 vulnerabilities in a range of Microsoft Office products, including Word, Visio, Publisher, and Lync. We summarize these four security bulletins below, in order from highest to lowest severity.</p>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-041">MS13-041</a>: Lync Remote Code Execution (RCE) Vulnerability</strong></li>
</ul>
<blockquote><p> <a href="http://en.wikipedia.org/wiki/Microsoft_Lync">Lync</a> is a unified communications tool that combines voice, IM, audio, video, and web-based communication into one interface. It’s essentially the replacement for Microsoft Communicator. It suffers from an unspecified memory corruption vulnerability that attackers could leverage to execute arbitrary code on your computer. If an attacker can convince one of your users to join a Lync or Communicator session containing specially crafted content, they could execute code on that user&#8217;s computer, with that user&#8217;s privileges. If you grant users local administrator privileges, the attacker could gain complete control of affected computers. This flaw only affects certain versions of Lync and Communicator. See the &#8220;<a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-041#section3">Affected and Non-Affected Software</a>&#8221; section of <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-041">Microsoft&#8217;s bulletin</a> for more details.</p>
<p><em><em>Microsoft rating: </em><strong>Critical</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-042">MS13-042</a>: Multiple Publisher Memory Corruption Vulnerabilities</strong></li>
</ul>
<blockquote><p><a href="http://en.wikipedia.org/wiki/Microsoft_Publisher">Publisher</a> is Microsoft&#8217;s basic desktop publishing and layout program, and part of the Office suite. It suffers from eleven memory corruption vulnerabilities. They all differ technically, but share the same scope and impact. By luring one of your users into downloading and opening a malicious Publisher document, an attacker can exploit any of these flaws to execute code on that user&#8217;s computer, with that user&#8217;s privileges. Again, if your users have local administrator privileges, the attacker gains complete control of their PCs. These flaws affect all versions of Publisher except 2013.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-043"><strong>MS13-043 </strong></a>:  Word RCE Vulnerability</strong></li>
</ul>
<blockquote><p>Word is the popular word processor that ships with Office. It suffers from a remote code execution (RCE) vulnerability having to do with how it handles Word or RTF documents containing maliciously crafted shape data. By enticing one of your users to download and open a specially crafted document, an attacker could leverage this flaw to execute code on that user’s computer, with that user’s privileges. If you grant users local administrator privileges, the attacker would gain complete control of their machines. The flaw only affects Word and Word Viewer 2003.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-044"><strong>MS13-044 </strong></a>: Visio Information Disclosure Vulnerability<strong><br />
</strong></strong></li>
</ul>
<blockquote><p>Microsoft <a href="http://en.wikipedia.org/wiki/Microsoft_Visio">Visio</a> is a popular diagramming program often used to create network diagrams.  Visio suffers from a complex information disclosure vulnerability, involving the way it parses specially crafted <a href="http://en.wikipedia.org/wiki/XML">XML</a> content. At a high level, XTM documents can contain &#8220;external entities;&#8221; essentially text or binary data from an external location. If an attacker can entice one of your users into downloading and opening a malicious Visio document (containing XTM content), he can exploit this flaw to read data from files on the victim&#8217;s computer. This flaw affects all versions of Visio except 2013.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<h3>Solution Path:</h3>
<p>Microsoft has released Office-related patches that correct all of these vulnerabilities. You should download, test, and deploy the appropriate updates throughout your network as soon as possible. If you choose, you can also let Windows Update automatically download and install these updates for you.</p>
<p>The links below point directly to the “Affected and Non-Affected Software” section of each bulletin, where you can find all of Microsoft&#8217;s update links:</p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-041#section3">MS13-041</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-042#section3">MS13-042</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-043#section3">MS13-043</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-044#section3">MS13-044</a></li>
</ul>
<h4>For All WatchGuard Users:</h4>
<p>WatchGuard’s Gateway Antivirus and Intrusion Prevention services can often prevent some of these types of attacks, or the malware they try to distribute. For instance, our IPS signature team has developed a signature that can detect and block the Visio Information Disclosure issue:</p>
<ul>
<li>EXPLOIT Microsoft Visio XML External Entities Resolution Vulnerability (CVE-2013-1301)</li>
</ul>
<p>Your XTM appliance should get this new IPS update shortly.</p>
<p>Nonetheless, we still recommend you install Microsoft’s updates to completely protect yourself from these flaws.</p>
<h3>Status:</h3>
<p>Microsoft has released patches correcting these issues.</p>
<h3>References:</h3>
<ul type="disc">
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-041">MS13-041</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-042">MS13-042</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-043">MS13-043</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-044">MS13-044</a></li>
</ul>
<p><em>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em>.</p>
<div>
<hr size="2" />
</div>
<p>What did you think of this alert? Let us know at <a href="mailto:lsseditor@watchguard.com">your.opinion.matters@watchguard.com</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3935/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3935&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=2TTuRXvRLVU:sDF-UQvbbUg:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=2TTuRXvRLVU:sDF-UQvbbUg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=2TTuRXvRLVU:sDF-UQvbbUg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=2TTuRXvRLVU:sDF-UQvbbUg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=2TTuRXvRLVU:sDF-UQvbbUg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=2TTuRXvRLVU:sDF-UQvbbUg:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=2TTuRXvRLVU:sDF-UQvbbUg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/2TTuRXvRLVU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/14/office-patches-mend-word-visio-publisher-and-lync/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/14/office-patches-mend-word-visio-publisher-and-lync/</feedburner:origLink></item>
		<item>
		<title>Trio of Windows Bulletins Correct Moderate Vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/9qP4E7q851o/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/14/trio-of-windows-bulletins-correct-moderate-vulnerabilities/#comments</comments>
		<pubDate>Tue, 14 May 2013 22:44:12 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[.NET Framework]]></category>
		<category><![CDATA[buffer overflow]]></category>
		<category><![CDATA[elevation of Privilege]]></category>
		<category><![CDATA[HTTP.sys]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Kernel-mode drivers]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3917</guid>
		<description><![CDATA[Severity: Medium Summary: These vulnerabilities affect: All current versions of Windows or components often packaged with it (like the .NET Framework) How an attacker exploits them: Multiple vectors of attack, including sending specially crafted network traffic or running malicious programs locally Impact:  Varies, ranging from a remote Denial of Service (DoS) attack to local attackers gaining [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3917&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h3>Severity: Medium</h3>
<h3>Summary:</h3>
<ul>
<li><strong>These vulnerabilities affect:</strong> All current versions of Windows or components often packaged with it (like the .NET Framework)</li>
<li><strong>How an attacker exploits them:</strong> Multiple vectors of attack, including sending specially crafted network traffic or running malicious programs locally</li>
<li><strong>Impact: </strong> Varies, ranging from a remote Denial of Service (DoS) attack to local attackers gaining complete control of your Windows computer</li>
<li><strong>What to do:</strong> Install the appropriate Microsoft patches as soon as possible, or let Windows Automatic Update do it for you</li>
</ul>
<h3>Exposure:</h3>
<p>Today, Microsoft released three security bulletins that describe six vulnerabilities affecting Windows or components related to it (like the .NET Framework). They only rate these bulletins as <strong>Important</strong>, due to limited impact or mitigating factors. Each of these vulnerabilities affects different versions of Windows to varying degrees. In the worst case, a local attacker could exploit one of these flaws to gain complete control of your Windows PC. We recommend you download, test, and deploy these updates at your earliest convenience.</p>
<p>The summary below lists the vulnerabilities, in order from highest to lowest severity.</p>
<ul>
<li><strong><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-039">MS13-039</a>: HTTP.sys DoS Vulnerability</strong></li>
</ul>
<blockquote><p>The <a href="http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/a2a45c42-38bc-464c-a097-d7a202092a54.mspx">HTTP Protocol Stack (HTTP.sys)</a> is a Windows component that listens for and handles <a href="http://watchguard.com/glossary/h.asp#HTTP">HTTP</a> requests before passing them to a web server like IIS. It suffers from a <a href="http://www.watchguard.com/glossary/d.asp#DoS">Denial of Service (DoS)</a> vulnerability having to do with its inability to properly handle HTTP requests with specially malformed headers. By sending a specially crafted HTTP request, a remote attacker can leverage this flaw to cause your system to stop responding. While this sort of DoS attack doesn&#8217;t result in any breach or data loss, attackers can leverage it to knock your public web server offline, which could have significant business implications. You should download, test, and deploy Microsoft&#8217;s HTTP.sys update as soon as possible.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-040"><strong>MS13-040</strong></a>: <strong>Multiple .NET Framework <strong>Vulnerabilities</strong></strong></strong></li>
</ul>
<blockquote><p><a title="http://en.wikipedia.org/wiki/MP3" href="http://en.wikipedia.org/wiki/MP3">The </a><a title="http://en.wikipedia.org/wiki/.NET_framework" href="http://en.wikipedia.org/wiki/.NET_framework">.NET Framework</a> is a <a title="http://en.wikipedia.org/wiki/Software_framework" href="http://en.wikipedia.org/wiki/Software_framework">software framework</a> used by developers to create custom Windows and web applications. Though it only ships by default with Windows Vista, you&#8217;ll find it on many Windows computers. The .NET Framework component suffers from two new security vulnerabilities.</p>
<p>The first issue is an XML digital signature spoofing vulnerability. <a href="http://en.wikipedia.org/wiki/XML">XML</a> files can contain <a href="http://watchguard.com/glossary/d.asp#digital_signature">digital signatures</a>, which .NET applications can use to verify the integrity of XML files (ensuring they haven&#8217;t been improperly modified). However, the .NET Framework component (<a href="http://en.wikipedia.org/wiki/Common_Language_Runtime">CLR</a>) responsible for validating these signatures doesn&#8217;t do it right. As a result, attackers can modify the contents of an XML file without invalidating the signature. The impact of this flaw depends on if and how your custom .NET applications leverage this functionality.</p>
<p>The second issue is an authentication bypass vulnerability. The <a href="http://msdn.microsoft.com/en-us/library/dd456779.aspx">Windows Communication Foundation (WCF)</a> is essentially a set of .NET <a href="http://watchguard.com/glossary/a.asp#API">API</a>s that developers can use to make applications that communicate securely with one another. However, WCF suffers from an authentication bypass flaw. By sending specially crafted packets, an attacker could gain unauthenticated access to computers that run WCF services. The impact of this bypass depends on your custom .NET application. If you custom application gives your users access to sensitive data, then in can pose a significant risk. If you install the .NET framework, you should download, test, and install Microsoft&#8217;s update as soon as you can.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-046">MS13-046</a>: <strong><strong>Kernel-Mode Driver </strong>Elevation of Privilege <strong>Flaws</strong></strong></strong></li>
</ul>
<blockquote><p>The <a href="http://en.wikipedia.org/wiki/Kernel_%28computing%29">kernel</a> is the core component of any computer operating system. Windows also ships with a kernel-mode device driver (win32k.sys), which handles the OS’s device interactions at a kernel level. The Windows kernel-mode driver suffers from three new local <a href="http://www.watchguard.com/glossary/e.asp#elevation">elevation of privilege</a> flaws. They all differ technically, but share the same basic scope and impact. By running a specially crafted program, a local attacker could leverage this flaw to gain complete control of your Windows computers (or cause it to become unstable). However, in order to run his malicious program, the attacker would first need to gain local access to your computer or trick you into running the program yourself, which significantly lessens the severity of this vulnerability.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<h3>Solution Path:</h3>
<p>Microsoft has released Windows and .NET Framework patches that correct all of these vulnerabilities. You should download, test, and deploy the appropriate updates throughout your network immediately. If you choose, you can also let Windows Update automatically download and install them for you.</p>
<p>The links below point directly to the “Affected and Non-Affected Software” section of each bulletin, where you can find links to the various updates:</p>
<ul>
<li><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-039#section3">MS13-039</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-040#section3">MS13-040</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-046#section3">MS13-046</a></li>
</ul>
<h4>For All WatchGuard Users:</h4>
<p>WatchGuard’s Gateway Antivirus and Intrusion Prevention services can often prevent some of these types of attacks, or the malware they try to distribute. For instance, our IPS signature team has developed signatures that can detect and block a few of the issues described above, including:</p>
<ul>
<li>WEB Microsoft Windows 2012 Server HTTP.sys Denial of Service Vulnerability (CVE-2013-1305)</li>
<li>EXPLOIT Microsoft XML Digital Signature Spoofing Vulnerability (CVE-2013-1336)</li>
</ul>
<p>Your XTM appliance should get this new IPS update shortly.</p>
<p>However, attackers can exploit some of these flaws in other ways, including by convincing users to run executable files locally. Since your gateway appliance can’t protect you against local attacks, we still recommend you install Microsoft’s updates to completely protect yourself from these flaws.</p>
<p><span style="font-size:1.17em;">Status:</span></p>
<p>Microsoft has released patches correcting these issues.</p>
<h3>References:</h3>
<ul>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-039">MS13-039</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-040">MS13-040</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-046">MS13-046</a></li>
<li></li>
</ul>
<p><em>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em>.</p>
<div>
<hr />
</div>
<p>What did you think of this alert? Let us know at <a href="mailto:lsseditor@watchguard.com">your.opinion.matters@watchguard.com</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3917/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3917/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3917&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=9qP4E7q851o:QhxDrNHtdbY:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=9qP4E7q851o:QhxDrNHtdbY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=9qP4E7q851o:QhxDrNHtdbY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=9qP4E7q851o:QhxDrNHtdbY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=9qP4E7q851o:QhxDrNHtdbY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=9qP4E7q851o:QhxDrNHtdbY:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=9qP4E7q851o:QhxDrNHtdbY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/9qP4E7q851o" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/14/trio-of-windows-bulletins-correct-moderate-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/14/trio-of-windows-bulletins-correct-moderate-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>Two Critical IE Bulletins Fix Zero Day Vulnerability and More</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/5Erw5zvavm4/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/14/two-critical-ie-bulletins-fix-zero-day-vulnerability-and-more/#comments</comments>
		<pubDate>Tue, 14 May 2013 21:03:38 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[DoL]]></category>
		<category><![CDATA[drive-by download]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[IE8]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[use after free]]></category>
		<category><![CDATA[zero day]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3903</guid>
		<description><![CDATA[Severity: High Summary: These vulnerabilities affect: Internet Explorer (IE) versions 6 &#8211; 10 How an attacker exploits them: Typically, by enticing one of your users to visit a web page with malicious content Impact: In the worst case, an attacker can execute code on your user&#8217;s computer, often gaining complete control of it What to do: Install Microsoft&#8217;s [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3903&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h3>Severity: High</h3>
<h3>Summary:</h3>
<ul>
<li><strong>These vulnerabilities affect: </strong>Internet Explorer (IE) versions 6 &#8211; 10</li>
<li><strong>How an attacker exploits them:</strong> Typically, by enticing one of your users to visit a web page with malicious content</li>
<li><strong>Impact:</strong> In the worst case, an attacker can execute code on your user&#8217;s computer, often gaining complete control of it</li>
<li><strong>What to do:</strong> Install Microsoft&#8217;s IE updates immediately, or let Windows Automatic Update do it for you</li>
</ul>
<h3>Exposure:</h3>
<p><img class="alignright" alt="" src="http://upload.wikimedia.org/wikipedia/en/1/10/Internet_Explorer_7_Logo.png" width="256" height="256" />As part of today&#8217;s Patch Day, Microsoft released two security bulletins (<a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-037">MS13-037</a>/<a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-038">MS13-038</a>) describing a dozen new security vulnerabilities that affect all current versions of Internet Explorer (IE). They rate both updates as <strong>Critical</strong>.</p>
<p>Over the <a href="http://watchguardsecuritycenter.com/2013/04/09/use-after-free-flaws-a-new-theme-for-ie-vulnerability/">last few months</a>, most of the new flaws affecting IE are what developers call <a href="http://cwe.mitre.org/data/definitions/416.html">&#8220;use after free&#8221; vulnerabilities</a> – a type of memory corruption flaw that attackers can leverage to execute arbitrary code. May&#8217;s duo of IE bulletins continues this theme, with all but one of the vulnerabilities falling under this class of flaw.</p>
<p>Though these dozen vulnerabilities differ technically, they share the same general scope and impact (with one small exception). If an attacker can lure one of your users to a web page containing maliciously crafted HTML, he could exploit any of these vulnerabilities to execute code on that user’s computer, inheriting that user’s privileges. Typically, Windows users have local administrative privileges, in which case the attacker can exploit these flaws to gain complete control of the victim’s computer. Keep in mind, attackers often hijack legitimate web pages and booby trap them with this sort of malicious code, in what the industry refers to as a &#8220;watering hole&#8221; attack.</p>
<p>Typically, Microsoft only releases <em>one</em> IE cumulative update a month. However, over the last few weeks attackers have exploited a <a href="https://en.wikipedia.org/wiki/Zero-day_attack">zero day</a> IE8 vulnerability in the wild—most notably against the <a href="http://www.ehackingnews.com/2013/05/new-ie8-zero-day-was-used-in-dol.html">Department of Labor (DoL) web site</a>. We talked about this exploit in <a href="http://watchguardsecuritycenter.com/2013/05/10/watchguard-security-week-in-review-episode-62-major-cyber-heist/">last week’s security video</a>. Although Microsoft had released a temporary &#8220;FixIt&#8221; to mitigate this serious vulnerability, today&#8217;s second IE bulletin (<a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-038">MS13-038</a>) rectifies the issue more completely. Attackers are still exploiting this flaw in the wild. They&#8217;ve worked it into their underground exploit toolkits, and even the popular Metasploit framework contains a public version of the exploit. We highly recommend you install both of Microsoft&#8217;s IE updates immediately (after testing, of course).</p>
<p>If you’d like more technical detail about any of these flaws, see the “Vulnerability Information” section in both of Microsoft’s bulletins (<a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-037">MS13-037</a>/<a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-038">MS13-038</a>).</p>
<h3>Solution Path:</h3>
<p>You should download, test, and deploy the appropriate IE updates immediately, or let Windows Automatic Update do it for you. You can find links to the various IE updates in the “Affected and Non-Affected Software” section of Microsoft&#8217;s IE security bulletins:</p>
<ul>
<li><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-037#section3">MS13-037</a></li>
<li><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-038#section3">MS13-038</a></li>
</ul>
<h4>For All WatchGuard Users:</h4>
<p>WatchGuard’s Gateway Antivirus and Intrusion Prevention services can often prevent these sorts of attacks, or the malware they try to distribute. For instance, our IPS signature team has developed signatures that can detect and block many of the &#8220;use after free&#8221; vulnerabilities described in Microsoft&#8217;s alert:</p>
<ul>
<li>WEB-CLIENT Microsoft Internet Explorer Use After Free Vulnerability (CVE-2013-2551)</li>
<li>WEB-CLIENT Microsoft Internet Explorer Use After Free Vulnerability (CVE-2013-1309)</li>
<li>WEB-CLIENT Microsoft Internet Explorer Use After Free Vulnerability (CVE-2013-1311)</li>
<li>WEB-CLIENT Microsoft Internet Explorer Use After Free Vulnerability (CVE-2013-1312)</li>
<li>WEB-CLIENT Microsoft Internet Explorer Use After Free Vulnerability (CVE-2013-1307)</li>
<li>WEB-CLIENT Microsoft Internet Explorer Use After Free Vulnerability (CVE-2013-1308)</li>
<li>WEB-CLIENT Microsoft Internet Explorer JSON Array Information Disclosure Vulnerability (CVE-2013-1297)</li>
</ul>
<p>Your XTM appliance should get this new IPS update shortly.</p>
<p>Furthermore, our Reputation Enabled Defense (RED) and WebBlocker services can often prevent your users from accidentally visiting malicious (or legitimate but booby-trapped) web sites that contain these sorts of attacks. Nonetheless, we still recommend you install Microsoft’s updates to completely protect yourself from all of these flaws.</p>
<h3>Status:</h3>
<p>Microsoft has released patches to fix these vulnerabilities.</p>
<h3>References:</h3>
<ul>
<li><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-037">MS Security Bulletin MS13-037</a></li>
<li><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-038">MS Security Bulletin MS13-038</a></li>
</ul>
<p>This alert was researched and written by <strong><em><a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#coreyn">Corey Nachreiner, CISSP</a> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em></strong>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3903/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3903&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=5Erw5zvavm4:d0MhrFx1xI8:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=5Erw5zvavm4:d0MhrFx1xI8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=5Erw5zvavm4:d0MhrFx1xI8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=5Erw5zvavm4:d0MhrFx1xI8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=5Erw5zvavm4:d0MhrFx1xI8:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=5Erw5zvavm4:d0MhrFx1xI8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=5Erw5zvavm4:d0MhrFx1xI8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/5Erw5zvavm4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/14/two-critical-ie-bulletins-fix-zero-day-vulnerability-and-more/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>

		<media:content url="http://upload.wikimedia.org/wikipedia/en/1/10/Internet_Explorer_7_Logo.png" medium="image" />
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/14/two-critical-ie-bulletins-fix-zero-day-vulnerability-and-more/</feedburner:origLink></item>
		<item>
		<title>Microsoft Black Tuesday: Fix for IE8 Zero Day and More</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/FP-pJ26hgXU/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/14/microsoft-black-tuesday-fix-for-ie8-zero-day-and-more/#comments</comments>
		<pubDate>Tue, 14 May 2013 19:26:56 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[.NET Framework]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[Black Tuesday]]></category>
		<category><![CDATA[Department of Labor]]></category>
		<category><![CDATA[DoL]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[IE8]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[Lync]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[MS Patch Day]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[use after free]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Windows Essentials]]></category>
		<category><![CDATA[zero day]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3898</guid>
		<description><![CDATA[Calling all Microsoft administrators. It&#8217;s time to spin up your virtual test machines and download, test, and deploy May&#8217;s batch of Microsoft security updates. This month&#8217;s theme is IE updates; with a focus on a recent IE zero day vulnerability, as well as a continuation of the &#8220;use after free&#8221; vulnerability theme I commented on [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3898&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Calling all Microsoft administrators. It&#8217;s time to spin up your virtual test machines and download, test, and deploy May&#8217;s batch of Microsoft security updates. This month&#8217;s theme is IE updates; with a focus on a recent IE zero day vulnerability, as well as a continuation of the &#8220;<a href="http://cwe.mitre.org/data/definitions/416.html">use after free</a>&#8221; vulnerability theme I <a href="http://watchguardsecuritycenter.com/2013/04/09/use-after-free-flaws-a-new-theme-for-ie-vulnerability/">commented on last month</a>.</p>
<p>According to their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-may">summary post</a>, Microsoft released ten security bulletins today, fixing around 33 security vulnerabilities in many of their popular products. The affected software includes Internet Explorer (IE), Windows and related components, products from the Office suite (Word, Visio, and Publisher), Lync, and Windows Essentials. Microsoft rates the IE updates as <strong>Critical</strong>, and the rest as <strong>Important</strong>.</p>
<p>As I mentioned earlier, today&#8217;s theme definitely centers around IE. <a href="http://watchguardsecuritycenter.com/2013/05/10/watchguard-security-week-in-review-episode-62-major-cyber-heist/">Last week&#8217;s security video</a> covered how attackers have recently been exploiting a <a href="https://en.wikipedia.org/wiki/Zero-day_attack">zero day</a> IE8 vulnerability in the wild—most notably against the Department of Labor web site. One of today&#8217;s <a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-038">updates</a> completely fixes this serious flaw. The other IE update continues to fix more &#8220;use after free&#8221; vulnerabilities, a class of memory corruption flaws that researchers and attackers have focused on lately. I highly recommend you install today&#8217;s IE updates immediately, then follow with the Windows and Office updates.</p>
<p>As an aside, Microsoft also released or updated four security advisories today. One of the updates has to do with one of today&#8217;s bulletins, but the other three are new. Once you&#8217;re finished handling today&#8217;s patches, you should check out Microsoft&#8217;s <a href="http://technet.microsoft.com/en-us/security/advisory">security advisory</a> page as well.</p>
<p>We&#8217;ll share more details about today&#8217;s bulletins in upcoming alerts. Until then, feel free to check out Microsoft&#8217;s <a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-may">May bulletin summary</a>.  — <em><a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#corey">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3898/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3898/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3898&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=FP-pJ26hgXU:jAoKAdUUlwI:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=FP-pJ26hgXU:jAoKAdUUlwI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=FP-pJ26hgXU:jAoKAdUUlwI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=FP-pJ26hgXU:jAoKAdUUlwI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=FP-pJ26hgXU:jAoKAdUUlwI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=FP-pJ26hgXU:jAoKAdUUlwI:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=FP-pJ26hgXU:jAoKAdUUlwI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/FP-pJ26hgXU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/14/microsoft-black-tuesday-fix-for-ie8-zero-day-and-more/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/14/microsoft-black-tuesday-fix-for-ie8-zero-day-and-more/</feedburner:origLink></item>
		<item>
		<title>WatchGuard Security Week in Review: Episode 62 – Major Cyber Heist</title>
		<link>http://feedproxy.google.com/~r/WatchguardWire/~3/mDj9E_trTQ0/</link>
		<comments>http://watchguardsecuritycenter.com/2013/05/10/watchguard-security-week-in-review-episode-62-major-cyber-heist/#comments</comments>
		<pubDate>Sat, 11 May 2013 03:33:14 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[ATM]]></category>
		<category><![CDATA[cyber heist]]></category>
		<category><![CDATA[Darkleech]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IE8 zero day]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lighthttpd]]></category>
		<category><![CDATA[LiveSecurity]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Syrian Electronic Army]]></category>
		<category><![CDATA[The Onion]]></category>
		<category><![CDATA[Twitter Hack]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[vlog]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[WatchGuard]]></category>
		<category><![CDATA[WatchGuard Security Week in Review]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=3892</guid>
		<description><![CDATA[The Onion Hack, IE8 0day, and ATM Cyber Heist Are you an over-worked IT administrator with no time to learn about the latest internet threats? Do you want to keep your network safe, but don&#8217;t know what the bad guys are up to? If that&#8217;s you, then our weekly information security highlights video is just [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3892&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<h2>The Onion Hack, IE8 0day, and ATM Cyber Heist</h2>
<p>Are you an over-worked IT administrator with no time to learn about the latest internet threats? Do you want to keep your network safe, but don&#8217;t know what the bad guys are up to? If that&#8217;s you, then our weekly information security highlights video is just the thing for you. For just three easy payments of&#8230; well, nothing&#8230; you can have all that and more!</p>
<p>Today&#8217;s episode covers Syrian cyber attackers hijacking The Onion&#8217;s twitter feed, a serious zero day vulnerability affecting Internet Explorer 8 (IE8), a major cyber bank heist, and more. For all the details, and some tips to protect yourself, watch the video below or check out the stories in the Reference section.</p>
<p>Have a great weekend.</p>
<p><em>(Episode Runtime: 7:46)</em></p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='588' height='361' src='http://www.youtube.com/embed/hdN9YMjKTXM?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<p><em>Direct YouTube Link: <a href="http://www.youtube.com/watch?v=hdN9YMjKTXM">http://www.youtube.com/watch?v=hdN9YMjKTXM</a></em></p>
<h4>Episode References:</h4>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/advisory/2847140">Microsoft releases FixIT for IE8 0day</a> - <em>Microsoft</em></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-may">Patch day advanced notification for May</a> - <em>Microsoft</em></li>
<li><a href="http://bits.blogs.nytimes.com/2013/05/06/no-joke-syrians-hack-the-onion/">The Onion&#8217;s twitter feed hacked</a> &#8211; <em>NYTimes</em></li>
<li><a href="http://www.theregister.co.uk/2013/05/08/cdorked_latest_details">Darkleech attack now affects nginx and lighthttpd </a>- <em>The Register</em></li>
<li><em></em><a href="http://www.nytimes.com/2013/05/10/nyregion/eight-charged-in-45-million-global-cyber-bank-thefts.html">Crime gang steals 45mil in huge cyber bank heist</a> &#8211; <em>NYTimes</em></li>
</ul>
<p><strong>Extras:</strong></p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/Hackers-gain-access-to-all-edu-domains-1858471.html">Hacking group gains access to .edu domains</a> - <em>The H Security</em></li>
<li><a href="http://nakedsecurity.sophos.com/2013/05/07/alleged-spyeye-mastermind-extradited-to-us">Suspect SpyEye author extradited to US</a> - <em>Naked Security</em><em><br />
</em></li>
<li><a href="http://www.eweek.com/security/opusa-cyber-attacks-fail-to-gather-momentum-during-first-day">Anonymous&#8217; so called OpUSA project an epic fail</a> - <em>eWeek</em></li>
<li><a href="http://arstechnica.com/security/2013/05/amid-a-barrage-of-password-breaches-honeywords-to-the-rescue">&#8220;Honeywords&#8221; may help protect password databases</a> - <em>Ars Technica<br />
</em></li>
<li><a href="http://thenextweb.com/insider/2013/05/08/name-com-discovers-security-breach-says-emails-and-credit-card-info-may-have-been-accessed">Name.com discovers a security breach</a> - <em>The Next Web</em></li>
<li><em></em><a href="http://www.zdnet.com/cispa-dead-in-senate-privacy-concerns-cited-7000014536">Researchers find security flaws in Google&#8217;s &#8220;smart building&#8221; system</a> - Cylance blog</li>
<li><a href="http://www.infoworld.com/d/security/adobe-warns-customers-of-unpatched-critical-flaw-in-coldfusion-218270">Critical 0day Cold Fusion exploit in the wild</a> - InfoWorld</li>
</ul>
<p><strong><em>— <a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#coreyn">Corey Nachreiner, CISSP</a> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/3892/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/3892/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=3892&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" /><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=mDj9E_trTQ0:h2ShKBQwJyE:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=mDj9E_trTQ0:h2ShKBQwJyE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=mDj9E_trTQ0:h2ShKBQwJyE:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=mDj9E_trTQ0:h2ShKBQwJyE:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?i=mDj9E_trTQ0:h2ShKBQwJyE:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=mDj9E_trTQ0:h2ShKBQwJyE:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/WatchguardWire?a=mDj9E_trTQ0:h2ShKBQwJyE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/WatchguardWire?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/WatchguardWire/~4/mDj9E_trTQ0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2013/05/10/watchguard-security-week-in-review-episode-62-major-cyber-heist/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	<feedburner:origLink>http://watchguardsecuritycenter.com/2013/05/10/watchguard-security-week-in-review-episode-62-major-cyber-heist/</feedburner:origLink></item>
	</channel>
</rss>
