What Microsoft can teach Apple about security response

I guess, I do not have to comment this – right?

What Microsoft can teach Apple about security response

To quote the summary:

Microsoft just released seven security updates to fix 23 vulnerabilities in Windows and other products. In February, Apple released a massive update that covered 51 vulnerabilities and also introduced an embarrassing . . . → Read More: What Microsoft can teach Apple about security response

Build your own sniffing kit

When people look at attackers, they always think that they are extremely smart people. There are really smart people building the kits but the ones applying it? Well, you just need the right guidance:

Hacker’s Tiny Spy Computer Cracks Corporate Networks, Fits In An Altoid Tin

Fairly easy, isn’t it?

Roger

Council of Europe Octopus Conference- Some Thoughts

l am still sitting in the parliament room of the Council of Europe at the celebration event for the Budapest Convention. It was another very good event advancing the challenges fighting Cybercrime. Let me try to summarize a few thoughts:

The Budapest Convention is probably the best convention out there allowing a wide adoption of . . . → Read More: Council of Europe Octopus Conference- Some Thoughts

VeriSign to Take Down Malware Sites?

This is actually an interesting approach: VeriSign Proposes Takedown Procedures and Malware Scanning for .Com. This leads to the discussion I have so often: What is more important? The single website or the greater good? Now, do not get me wrong: I see the risks of VeriSign taking down microsoft.com because a blog hosted there . . . → Read More: VeriSign to Take Down Malware Sites?

Hackers using QR Codes to Push Malware

Always something new… As these kinds of codes are mainly used on mobile phones (or only used on mobile phones) the malware actually addresses smartphones “only” – in this case Android: Hackers using QR codes to push Android malware. If you use a code such as this (source: ZDnet Article referenced):

You will . . . → Read More: Hackers using QR Codes to Push Malware

Update on DigiNotar

And interesting development tonight: Based on what happened with DigiNotar recently (especially with the false certificates for *.google.com), the Dutch government decided to have an official statement and in there to take over operations of the CA. The official statement (in Dutch) can be found here.

The key problem is that the certs were . . . → Read More: Update on DigiNotar

The DigiNotar Story–So Far

I just read an article on SANS: DigiNotar breach – the story so far. To be clear: This is not a Microsoft analysis nor any official statement from us. What we have to say is in the advisory: Microsoft Security Advisory (2607712) – Fraudulent Digital Certificates Could Allow Spoofing. It just gives an interesting overview . . . → Read More: The DigiNotar Story–So Far

Special Intelligence Report on the Rustock Takedown

As you might remember, on Match 16th Microsoft together with other industry players was successfully able to take down the Rustock botnet and thus significantly reducing the spam level.

We now just published a special Intelligence Report on this botnet:

Read an overview of the Win32/Rustock family of rootkit-enabled backdoor Trojans background, functionality, how it . . . → Read More: Special Intelligence Report on the Rustock Takedown

Microsoft Security Update Guide, Second Edition

A while ago we released the Microsoft Security Update Guide to explain how we release security updates and how you should/could work with our updates. It encompasses these themes:

Get to know the security update release process Learn how to evaluate risk See how to mitigate security risks Understand how quickly you need to apply . . . → Read More: Microsoft Security Update Guide, Second Edition

Effectiveness of SecureID reduced?

It seems that RSA got attacked and might have lost some information. They actually took a really courageous step and went public and the Executive Chairman wrote an open letter. To quote:

While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA . . . → Read More: Effectiveness of SecureID reduced?

Calendar

May 2012
M T W T F S S
« Apr    
 123456
78910111213
14151617181920
21222324252627
28293031