Advance notice of Microsoft patches to be issued on December 11

Microsoft just announced the December patches that are scheduled to be released on December 11 – see http://technet.microsoft.com/en-us/security/bulletin/ms12-dec  There are a total of seven patches to be released. Five of the patches are designated as CRITICAL, and two designated as IMPORTANT. The Critical bulletins address vulnerabilities in Microsoft Windows, Word, Windows Server and Internet Explorer. …

Advance notice of November Microsoft Patches to be released on November 13

Microsoft just announced the November patches that are scheduled to be released on November 13. There are a total of six patches to be released. Four of the patches are designated as CRITICAL, one designated as IMPORTANT, and one designated as MODERATE. The critical patches apply to the following Microsoft products: Workstation Operating Systems Windows …

Advance notice of October Microsoft patches – to be released on October 9

Microsoft has provided their advance notice of patches scheduled to be released on October 9.   There is only one CRITICAL patch and six IMPORTANT patches.  The one critical patch is specifically applicable the following packages: Microsoft Word on Office 2003sp3, Office 2007sp2 and sp3, Office 2010 (32 and 64bit), Word Viewer, Office Compatibility Pack SP2 …

Possible compromised version of phpMyAdmin has been distributed from sourceforge mirrors

If you are running phpMyAdmin, and have recently performed an update, you might have a compromised version.  In short, any version that was downloaded from the SourceForge Mirror site – cdnetworks-kr-1 and contains file – server_sync.php. probably contains a backdoor. As this vulnerability is classified as EXTREMELY CRITICAL, I would suggest you verify that no …

Zero day exploit identified for all current versions of Internet Explorer – IE6-9

On Monday, September 17, a zero day exploit was identified for all current versions of Internet Explorer.  Suggestions by many of the security resources were that IE should not be used for accessing the Internet until the vulnerability was addressed.  See the following resources for information: http://technet.microsoft.com/en-us/security/advisory/2757760 http://isc.sans.edu/diary.html?storyid=14107 http://secunia.com/advisories/50626/ Update September 20 On Wednesday, September …

Advance notice of September Microsoft patches – only two to be released for sept 11

Microsoft has just sent their advance notice of the patches that are scheduled to be released on September 11, 2012.  There are a total of two patches to be released for September 2012.  Both of the patches are designated as IMPORTANT.  Based on the information currently available, there is no urgency in applying these patches …

Zero day exploit for version 1.7.06 of Java

On Monday, August 27, a zero day exploit was identified for version 1.7.06 of Java.  For those that don’t require it, the ideal solution would be to uninstall Java completely.  However, as I understand it, the EIS Compass application requires version 1.6.  That requires we consider the second best option which is make sure your …

Advance notice of August Microsoft patches – to be released on August 14

Microsoft has just sent their advance notice of the patches that are scheduled to be released on August 14, 2012.  There are a total of 9 patches to be released for August 2012. Five of the patches are designated as CRITICAL and the remaining four patches are designated as IMPORTANT. Exceptions are noted where applicable …

Advance notice of Microsoft patches to be released on July 10

Microsoft has just sent their advance notice of the patches that are scheduled to be released on July 9, 2012. There are a total of 9 patches to be released for July 2012. Three of the patches are designated as CRITICAL and the remaining six patches are designated as IMPORTANT. Exceptions are noted where applicable …

July9 – DNSchanger infected machines could lose connectivity

http://internetidentity.com/news/blog/686-iid-finds-12-of-fortune-500-still-infected-with-dnschanger IID finds 12% of Fortune 500 still infected with DNSChanger Written by Heidi Harris Thursday, 28 June 2012 00:00 In the wake of the massive DNSChanger malware infections, the FBI replaced rogue DNS servers with clean servers while affected computers were cleaned up. On July 9th, those servers are coming down barring a last-minute …