<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Negócio de Risco</title><link>http://blogs.technet.com/b/risco/</link><description>Blog do Time de Segurança da Microsoft Brasil</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Contas Microsoft – Reforço na verificação de segurança</title><link>http://blogs.technet.com/b/risco/archive/2013/05/15/contas-microsoft-refor-231-o-na-verifica-231-227-o-de-seguran-231-a.aspx</link><pubDate>Thu, 16 May 2013 01:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3573014</guid><dc:creator>Daniel Mauser - [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3573014</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/05/15/contas-microsoft-refor-231-o-na-verifica-231-227-o-de-seguran-231-a.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-size: small;"&gt;Come&amp;ccedil;ando&amp;nbsp; dia 07 de maio e at&amp;eacute; os meados de setembro, clientes poder&amp;atilde;o ser prontificados para efetuar uma verifica&amp;ccedil;&amp;atilde;o&amp;nbsp; quando&amp;nbsp; usarem uma &lt;/span&gt;&lt;a href="http://www.microsoft.com/en-us/account/default.aspx"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;conta da Microsoft&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; - contas como Xbox Live, Premier Online, VLSC, Outlook.com . &amp;nbsp;Isso &amp;eacute; para melhorar a seguran&amp;ccedil;a e &amp;eacute; necess&amp;aacute;ria para proteger os nossos clientes. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; &lt;strong&gt;Por que a Microsoft est&amp;aacute; me pedindo para adicionar informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a na minha Conta Microsoft?&lt;/strong&gt;&lt;br /&gt; Para ajudar a proteger seus dados pessoais, a Microsoft est&amp;aacute; pedindo a todos os usu&amp;aacute;rios com uma &lt;/span&gt;&lt;a href="http://www.microsoft.com/en-us/account/default.aspx"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;conta Microsoft&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; para adicionar informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a (n&amp;uacute;mero de telefone ou endere&amp;ccedil;o de e-mail) para certificar-se as informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a associada a sua conta est&amp;atilde;o corretas e atualizadas&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; &lt;strong&gt;Por que eu preciso adicionar os detalhes de seguran&amp;ccedil;a na minha conta da Microsoft?&lt;/strong&gt;&lt;br /&gt; Podemos us&amp;aacute;-lo para verificar a sua identidade, se houver algum problema. Por exemplo, se voc&amp;ecirc; esquecer sua senha, ou se algu&amp;eacute;m tentando acessar a sua conta, a Microsoft utiliza suas informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a para ajud&amp;aacute;-lo a reacessar sua conta.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; &lt;strong&gt;Quanto tempo eu tenho para confirmar a minha seguran&amp;ccedil;a da informa&amp;ccedil;&amp;atilde;o?&lt;/strong&gt;&lt;br /&gt; Voc&amp;ecirc; ter&amp;aacute; 7 dias para verificar as informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a. Se voc&amp;ecirc; n&amp;atilde;o tiver uma conta verificada em 7 dias, sua conta ser&amp;aacute;&amp;nbsp; bloqueada.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; &lt;strong&gt;O que acontece se eu n&amp;atilde;o confirmar a minha informa&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a no prazo de 7 dias?&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Voc&amp;ecirc; n&amp;atilde;o ser&amp;aacute; capaz de entrar novamente at&amp;eacute; que voc&amp;ecirc; tenha verificado as informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; &lt;strong&gt;Por que tanto cuidado?&lt;/strong&gt;&lt;br /&gt; Se voc&amp;ecirc; altera sua conta e acessa diferentes dispositivos com frequ&amp;ecirc;ncia, como PC p&amp;uacute;blico ou compartilhado, o seu tablet, o smartphone, voc&amp;ecirc; vai precisar &amp;nbsp;verificar que este&amp;nbsp; &amp;eacute; um de seu "dispositivo confi&amp;aacute;vel". Uma vez que o dispositivo &amp;eacute; verificado como&amp;nbsp; "confi&amp;aacute;vel", voc&amp;ecirc; n&amp;atilde;o precisar&amp;aacute; verificar no futuro o mesmo dispositivo.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; Para mais informa&amp;ccedil;&amp;otilde;es, consulte &lt;/span&gt;&lt;a href="http://windows.microsoft.com/pt-br/windows-8/what-is-trusted-pc"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;O que &amp;eacute; um dispositivo confi&amp;aacute;vel?&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; &lt;strong&gt;Como eu fa&amp;ccedil;o a verifica&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a?&lt;/strong&gt;&lt;br /&gt; A verifica&amp;ccedil;&amp;atilde;o &amp;eacute; feita em duas etapas para manter sua conta mais segura. Nas duas etapas de verifica&amp;ccedil;&amp;atilde;o ser&amp;aacute; sempre pedir-lhe um c&amp;oacute;digo de seguran&amp;ccedil;a, al&amp;eacute;m de sua senha. Se voc&amp;ecirc; decidir ativar a verifica&amp;ccedil;&amp;atilde;o em duas etapas, &amp;eacute; especialmente importante que suas informa&amp;ccedil;&amp;otilde;es de contato alternativo &amp;eacute; v&amp;aacute;lido, pois voc&amp;ecirc; vai precisar dele para obter os seus c&amp;oacute;digos de seguran&amp;ccedil;a. Para mais informa&amp;ccedil;&amp;otilde;es, consulte &lt;/span&gt;&lt;a href="http://windows.microsoft.com/pt-br/windows/two-step-verification-faq"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Duas ETAPAS da verifica&amp;ccedil;&amp;atilde;o: FAQ&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;.&lt;br /&gt; &lt;br /&gt; Para come&amp;ccedil;ar com a adi&amp;ccedil;&amp;atilde;o de informa&amp;ccedil;&amp;otilde;es de conta de seguran&amp;ccedil;a, siga estes passos:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; 1. Fa&amp;ccedil;a &lt;/span&gt;&lt;a href="http://go.microsoft.com/fwlink/p/?LinkID=263779"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;login&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; em sua conta da Microsoft.&lt;br /&gt; 2. Na p&amp;aacute;gina da sua conta, com senha e&lt;strong&gt; informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a&lt;/strong&gt;, toque ou clique em &lt;strong&gt;Editar informa&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; Se voc&amp;ecirc; for solicitado a digitar um c&amp;oacute;digo de seguran&amp;ccedil;a, verifique o seu e-mail alternativo ou telefone para o c&amp;oacute;digo da equipe de contas da Microsoft. &amp;nbsp;Se voc&amp;ecirc; tiver problemas para receber seu c&amp;oacute;digo de seguran&amp;ccedil;a via mensagem de texto, tente a op&amp;ccedil;&amp;atilde;o de receber uma chamada telef&amp;ocirc;nica autom&amp;aacute;tica.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3573014" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Conta+Microsoft/">Conta Microsoft</category></item><item><title>Endereçando o desafio de compliance/conformidade em um ambiente multiplataforma: Lições dos vírus STUXNET e Flame</title><link>http://blogs.technet.com/b/risco/archive/2013/05/15/endere-231-ando-o-desafio-de-compliance-conformidade-em-um-ambiente-multiplataforma-li-231-245-es-dos-v-237-rus-stuxnet-e-flame.aspx</link><pubDate>Wed, 15 May 2013 20:26:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3572972</guid><dc:creator>Daniel Mauser - [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3572972</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/05/15/endere-231-ando-o-desafio-de-compliance-conformidade-em-um-ambiente-multiplataforma-li-231-245-es-dos-v-237-rus-stuxnet-e-flame.aspx#comments</comments><description>&lt;h1&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Autor: Aylton Souza &amp;ndash; Virtualization &amp;amp; Private Cloud Lead LATAM&lt;/span&gt;&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Com os avan&amp;ccedil;os tecnol&amp;oacute;gicos e sistemas interconectados, diferentes plataformas s&amp;atilde;o a base para importantes elementos da infraestrutura em todo mundo. Incidentes recentes como o Stuxnet (que supostamente afetou usinas nucleares no Ir&amp;atilde; e atrasou o programa de enriquecimento de ur&amp;acirc;nio e ataques recentes a grandes empresas), talvez seja um bom momento para refletirmos sobre o aprendizado dessas ocorr&amp;ecirc;ncias. O problema n&amp;atilde;o est&amp;aacute; restrito a grandes infraestruturas e a lenda urbana de que s&amp;oacute; as grandes empresas podem ser v&amp;iacute;timas desse tipo de ataque &amp;ndash; Isso j&amp;aacute; caiu por terra em tempos da nuvem. Sistemas desatualizados ou falta de um processo de mudan&amp;ccedil;a e controle de atualiza&amp;ccedil;&amp;otilde;es adequado s&amp;atilde;o a raiz do problema desde os anos 80, multiplicados pela onipresen&amp;ccedil;a de novos componentes tecnol&amp;oacute;gicos desde os caixas de supermercados, sem&amp;aacute;foros inteligentes, radares e at&amp;eacute; sistemas cr&amp;iacute;ticos de infraestrutura.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;O que aprendemos desde o Stuxnet e Flame? Se voltarmos 20-30 anos, j&amp;aacute; fiz o questionamento anterior sobre o que aprendemos desde o Morris worm nos anos 80 e o diagn&amp;oacute;stico &amp;eacute; bem similar: O desafio de controlar sistemas multiplataforma e manter conformidade com padr&amp;otilde;es t&amp;eacute;cnicos ou legais que ajudam a controlar o elo mais fraco da corrente. Tanto o stuxnet quanto o flame foram inseridos de forma quase infantil em sistemas desconectados da Internet: Atrav&amp;eacute;s de dispositivos de armazenamento USB (os famosos &amp;ldquo;pen drive&amp;rdquo;) e nesses incidentes, particularidades desse worm continham instru&amp;ccedil;&amp;otilde;es que afetaram sistemas importantes usados em v&amp;aacute;rias industrias baseadas em SCADA (&lt;strong&gt;supervisory control and data acquisition&lt;/strong&gt;), padr&amp;atilde;o de ind&amp;uacute;stria para diversos sistemas cr&amp;iacute;ticos usados desde usinas nucleares, passando por empresas de energia, ind&amp;uacute;stria automobil&amp;iacute;stica e muitas outras.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;O problema n&amp;atilde;o &amp;eacute; novo. Um artigo de 1998 (&lt;/span&gt;&lt;a href="http://www.issues.org/15.1/robins.htm"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;http://www.issues.org/15.1/robins.htm&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;) j&amp;aacute; discute o problema numa era onde a Internet ainda engatinhava, redes sociais e phising n&amp;atilde;o existiam nem mesmo em fic&amp;ccedil;&amp;atilde;o cient&amp;iacute;fica. Os sistemas operacionais e ferramentas de gerenciamento e seguran&amp;ccedil;a evolu&amp;iacute;ram muito desde ent&amp;atilde;o, mas sem evoluir processos na mesma velocidade, as empresas podem ser ref&amp;eacute;ns de seu pr&amp;oacute;prio conservadorismo. Sistemas operacionais j&amp;aacute; fora do ciclo de suporte (seja no desktop ou do lado do servidor) sofrem ainda mais por n&amp;atilde;o incorporarem controles a amea&amp;ccedil;as que simplesmente n&amp;atilde;o existiam &amp;agrave; &amp;eacute;poca em que foram criados. O Windows XP e Windows Server 2003, al&amp;eacute;m de muitos sistemas UNIX e mainframes em uso continuam sustentando muitos sistemas importantes. Hora de pensar em atualizar para Windows 7/8 al&amp;eacute;m do Windows Server 2012 e usar recursos existentes da plataforma, al&amp;eacute;m de elementos que podem ajudar a gerir conformidade e seguran&amp;ccedil;a em ambientes multiplataforma, incluindo Windows, v&amp;aacute;rios sabores de UNIX (como AIX, HP-UX, Solaris) e Linux. Mais do que o impacto em IT, pensemos no impacto em uma ind&amp;uacute;stria, ou fornecimento de energia ou g&amp;aacute;s. A facilidade e crescimento dos recursos de automa&amp;ccedil;&amp;atilde;o nos leva tamb&amp;eacute;m a repensar processos e a forma de manter esses sistemas atualizados e protegidos. No Brasil, um recente caso de sucesso publicado mostra um exemplo de proatividade que protege o gasoduto Brasil-Bol&amp;iacute;via e tem import&amp;acirc;ncia sum&amp;aacute;ria na nossa matriz energ&amp;eacute;tica, usando System Center e tamb&amp;eacute;m as facilidades dos mais novos sistemas operacionais da Microsoft.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Para mais informa&amp;ccedil;&amp;otilde;es:&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Caso de refer&amp;ecirc;ncia Transportadora Brasileira Gasoduto: &lt;a href="http://www.microsoft.com/brasil/Casos/interna.aspx?id=1141"&gt;&lt;span style="color: #0563c1;"&gt;http://www.microsoft.com/brasil/Casos/interna.aspx?id=1141&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Malicious v&amp;iacute;rus targets SCADA Systems: &lt;/span&gt;&lt;a href="http://www.homelandsecuritynewswire.com/malicious-virus-targets-scada-systems"&gt;&lt;span style="color: #0563c1; font-family: Calibri; font-size: small;"&gt;http://www.homelandsecuritynewswire.com/malicious-virus-targets-scada-systems&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Stuxnet: &lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Stuxnet"&gt;&lt;span style="color: #0563c1; font-family: Calibri; font-size: small;"&gt;http://en.wikipedia.org/wiki/Stuxnet&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Virus target industrial OS, reaches Iran&amp;rsquo;s nuclear plant: &lt;/span&gt;&lt;a href="http://readwrite.com/2010/09/27/stuxnet_virus_targets_industrial_os"&gt;&lt;span style="color: #0563c1; font-family: Calibri; font-size: small;"&gt;http://readwrite.com/2010/09/27/stuxnet_virus_targets_industrial_os&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;System Center Process Pack for IT GRC (free) &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd206732.aspx"&gt;&lt;span style="color: #0563c1; font-family: Calibri; font-size: small;"&gt;http://technet.microsoft.com/en-us/library/dd206732.aspx&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Asset and Compliance in System Center 2012: &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/gg682029.aspx"&gt;&lt;span style="color: #0563c1; font-family: Calibri; font-size: small;"&gt;http://technet.microsoft.com/en-us/library/gg682029.aspx&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Conficker: Morris has not left the building: &lt;/span&gt;&lt;a href="http://blogs.technet.com/b/risco/archive/2009/01/28/conficker-li-es-p-s-guerra-morris-has-not-left-the-building.aspx"&gt;&lt;span style="color: #0563c1; font-family: Calibri; font-size: small;"&gt;http://blogs.technet.com/b/risco/archive/2009/01/28/conficker-li-es-p-s-guerra-morris-has-not-left-the-building.aspx&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Aylton Souza &amp;eacute; o Virtualization &amp;amp; Private Cloud Lead da Microsoft para America Latina, baseado na Fl&amp;oacute;rida&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Com mais de 25 anos atuando na &amp;aacute;rea de tecnologia e seguran&amp;ccedil;a da informa&amp;ccedil;&amp;atilde;o, esteve a frente de grandes projetos no Brasil e em outros pa&amp;iacute;ses, sendo parte do time de desenvolvimento de solu&amp;ccedil;&amp;otilde;es de seguran&amp;ccedil;a pioneiras nos anos 80 e 90 e participou da constru&amp;ccedil;&amp;atilde;o dos primeiros provedores comerciais no nascimento da Internet no Brasil. Um dos primeiros CISSP na America Latina, recebeu reconhecimentos como o SECMASTER no Brasil por dois anos consecutivos pela melhor contribui&amp;ccedil;&amp;atilde;o ao setor privado.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3572972" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Aylton+Souza+_2800_Abu_2900_/">Aylton Souza (Abu)</category><category domain="http://blogs.technet.com/b/risco/archive/tags/Complaince/">Complaince</category><category domain="http://blogs.technet.com/b/risco/archive/tags/System+Center/">System Center</category><category domain="http://blogs.technet.com/b/risco/archive/tags/Conformidade/">Conformidade</category></item><item><title>Webcast: Informações sobre os boletins de segurança (Maio 2013)</title><link>http://blogs.technet.com/b/risco/archive/2013/05/14/boletins-de-seguran-231-a-de-maio-2013.aspx</link><pubDate>Tue, 14 May 2013 23:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3572759</guid><dc:creator>Daniel Mauser - [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3572759</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/05/14/boletins-de-seguran-231-a-de-maio-2013.aspx#comments</comments><description>&lt;p&gt;Ol&amp;aacute; Pessoal,&lt;/p&gt;
&lt;p&gt;Estamos de volta este m&amp;ecirc;s de Maio com a publica&amp;ccedil;&amp;atilde;o nesta ter&amp;ccedil;a-feira, 14/05/2013, de 10 (dez) novos boletins de seguran&amp;ccedil;a&amp;nbsp;que corrigem vulnerabilidades de seguran&amp;ccedil;a nos produtos Windows, Internet Explorer, .NET Framework, Lync&amp;nbsp;e Office.&lt;br /&gt;Vale lembrar que teremos a apresenta&amp;ccedil;&amp;atilde;o p&amp;uacute;blica e em portugu&amp;ecirc;s dos boletins deste m&amp;ecirc;s:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a (Maio 2013) em Portugu&amp;ecirc;s&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Quando:&lt;/strong&gt;&amp;nbsp;16 de&amp;nbsp;Maio de 2013 &amp;agrave;s &lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;15:30h&lt;/strong&gt;&lt;/span&gt; (GMT -3:00).&lt;br /&gt;&lt;strong&gt;Acesso/Inscri&amp;ccedil;&amp;atilde;o:&lt;/strong&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540914&amp;amp;Culture=pt-BR&amp;amp;community=0"&gt;Clique Aqui&lt;/a&gt; ou atrav&amp;eacute;s da URL Abaixo:&lt;br /&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540914&amp;amp;Culture=pt-BR&amp;amp;community=0"&gt;https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540914&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/pt-br/security/bulletin/ms13-may"&gt;Clique aqui&lt;/a&gt; para saber mais sobre os boletins deste m&amp;ecirc;s de Maio de 2013.&lt;/p&gt;
&lt;p&gt;Obtenhas os &lt;a href="http://sdrv.ms/18O4MFa"&gt;Slides da Apresenta&amp;ccedil;&amp;atilde;o&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3572759" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Boletins+de+Seguran_26002300_231_3B00_a/">Boletins de Seguran&amp;#231;a</category></item><item><title>Webcast: Informações sobre os boletins de segurança (Março 2013)</title><link>http://blogs.technet.com/b/risco/archive/2013/03/13/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-mar-231-o-2013.aspx</link><pubDate>Wed, 13 Mar 2013 13:48:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3558360</guid><dc:creator>Daniel Pires - MSFT</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3558360</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/03/13/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-mar-231-o-2013.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Ol&amp;aacute; Pessoal,&lt;br /&gt;&lt;br /&gt;Este m&amp;ecirc;s de&amp;nbsp;Mar&amp;ccedil;o temos&amp;nbsp;7 (sete) Boletins de Seguran&amp;ccedil;a que foram publicados pela Microsoft nesta ter&amp;ccedil;a-feira (12/03/2013). Estas atualiza&amp;ccedil;&amp;otilde;es corrigem vulnerabilidades no Internet Explorer, Silverlight 5, Microsoft Visio, Microsoft SharePoint Server e Foundation, OneNote, Microsoft Office e Microsoft Windows. Para saber mais detalhes sobre estes boletins de seguran&amp;ccedil;a assistam o Webcast deste m&amp;ecirc;s, em portugu&amp;ecirc;s, conforme informa&amp;ccedil;&amp;otilde;es abaixo:&lt;/p&gt;
&lt;p&gt;Informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a (Mar&amp;ccedil;o 2013) em Portugu&amp;ecirc;s&lt;br /&gt;Quando: 14 de&amp;nbsp;Mar&amp;ccedil;o de 2013 &amp;agrave;s 15:30h (Bras&amp;iacute;lia).&lt;br /&gt;Acesso/Inscri&amp;ccedil;&amp;atilde;o: Clique Aqui ou atrav&amp;eacute;s da URL Abaixo:&lt;br /&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540910&amp;amp;Culture=pt-BR&amp;amp;community=0"&gt;https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540910&amp;amp;Culture=pt-BR&amp;amp;community=0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;Eacute; importante mencionar que neste Webcast voc&amp;ecirc; ter&amp;aacute; tamb&amp;eacute;m oportunidade de tirar suas duvidas sobre os Boletins de Seguran&amp;ccedil;a deste m&amp;ecirc;s diretamente com time de Seguran&amp;ccedil;a da Microsoft. Aguardamos sua participa&amp;ccedil;&amp;atilde;o.&lt;br /&gt;&lt;br /&gt;Mais informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a de&amp;nbsp;Mar&amp;ccedil;o de 2013 - &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-mar"&gt;Clique Aqui&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3558360" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Boletins+de+Seguran_26002300_231_3B00_a/">Boletins de Seguran&amp;#231;a</category><category domain="http://blogs.technet.com/b/risco/archive/tags/seguranca/">seguranca</category><category domain="http://blogs.technet.com/b/risco/archive/tags/Atualiza_26002300_231_3B0026002300_227_3B00_o+de+Seguran_26002300_231_3B00_a/">Atualiza&amp;#231;&amp;#227;o de Seguran&amp;#231;a</category><category domain="http://blogs.technet.com/b/risco/archive/tags/malware/">malware</category></item><item><title>Webcast: Informações sobre os boletins de segurança (Fevereiro 2013)</title><link>http://blogs.technet.com/b/risco/archive/2013/02/13/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-fevereiro-2013.aspx</link><pubDate>Wed, 13 Feb 2013 16:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3552274</guid><dc:creator>Daniel Mauser - [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3552274</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/02/13/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-fevereiro-2013.aspx#comments</comments><description>&lt;p&gt;Ol&amp;aacute; Pessoal,&lt;/p&gt;
&lt;p&gt;Este m&amp;ecirc;s de&amp;nbsp;Fevereiro temos 12&amp;nbsp;(doze) Boletins de Seguran&amp;ccedil;a que&amp;nbsp;foram publicados pela Microsoft nesta ter&amp;ccedil;a-feira (12/02/2013). Estas atualiza&amp;ccedil;&amp;otilde;es corrigem vulnerabilidades no&amp;nbsp;Windows,&amp;nbsp;.NET Framework,&amp;nbsp;Exchange Server, Office e Internet Explorer. Para saber mais detalhes sobre estes boletins de seguran&amp;ccedil;a assistam o Webcast deste m&amp;ecirc;s, em portugu&amp;ecirc;s,&amp;nbsp;conforme informa&amp;ccedil;&amp;otilde;es abaixo:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a (Fevereiro 2013) em Portugu&amp;ecirc;s&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Quando:&lt;/strong&gt;&amp;nbsp;14 de&amp;nbsp;Fevereiro de 2013 &amp;agrave;s &lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;15:30h&lt;/strong&gt;&lt;/span&gt; (Bras&amp;iacute;lia).&lt;br /&gt;&lt;strong&gt;Acesso/Inscri&amp;ccedil;&amp;atilde;o:&lt;/strong&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540908&amp;amp;Culture=pt-BR"&gt;Clique Aqui&lt;/a&gt; ou atrav&amp;eacute;s da URL Abaixo:&lt;br /&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540908&amp;amp;Culture=pt-BR"&gt;https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540908&amp;amp;Culture=pt-BR&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;Eacute; importante mencionar que neste Webcast voc&amp;ecirc; ter&amp;aacute; tamb&amp;eacute;m oportunidade de tirar suas duvidas sobre os Boletins de Seguran&amp;ccedil;a deste m&amp;ecirc;s diretamente com time de Seguran&amp;ccedil;a da Microsoft. Aguardamos sua participa&amp;ccedil;&amp;atilde;o.&lt;br /&gt;Mais informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a de Fevereiro de&amp;nbsp;2013 - &lt;a href="http://technet.microsoft.com/pt-br/security/bulletin/ms13-feb"&gt;Clique Aqui&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3552274" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Boletins+de+Seguran_26002300_231_3B00_a/">Boletins de Seguran&amp;#231;a</category></item><item><title>Como utilizar recursos existentes da plataforma Microsoft para reduzir exposição a riscos ligados ao Oracle Java 7 Security Advisory (CERT)</title><link>http://blogs.technet.com/b/risco/archive/2013/01/30/como-utilizar-recursos-existentes-da-plataforma-microsoft-para-reduzir-exposi-231-227-o-a-riscos-ligados-ao-oracle-java-7-security-advisory-cert.aspx</link><pubDate>Wed, 30 Jan 2013 12:03:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3549237</guid><dc:creator>brzsec</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3549237</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/01/30/como-utilizar-recursos-existentes-da-plataforma-microsoft-para-reduzir-exposi-231-227-o-a-riscos-ligados-ao-oracle-java-7-security-advisory-cert.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Background&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Nos &amp;uacute;ltimos anos, perdi a conta de quantos artigos sobre gest&amp;atilde;o de&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;incidentes, mudan&amp;ccedil;as e pr&amp;aacute;ticas de governan&amp;ccedil;a ajudam a se defender contra&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;amea&amp;ccedil;as de v&amp;aacute;rios tipos, sabores e gera&amp;ccedil;&amp;otilde;es. CodeRed, Nimda, Zotob e mais&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;recentemente ataques dirigidos como o Flame e Stuxnet. As vulnerabilidades&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;ligadas ao Oracle Java no entanto, est&amp;atilde;o em outra categoria: Zero Day. Esse&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;detalhe significa que existe c&amp;oacute;digo para que cyber bandidos possam explorar&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;essa vulnerabilidade antes que o fabricante tenha disponibilizado uma corre&amp;ccedil;&amp;atilde;o&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;efetiva. Este artigo n&amp;atilde;o tem a pretens&amp;atilde;o de ser um &amp;ldquo;tratado definitivo&amp;rdquo; sobre o&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;problema. Por outro lado, se destina a sugerir algumas formas de identificar e&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;mitigar os riscos associados a exposi&amp;ccedil;&amp;atilde;o de uma vulnerabilidade cr&amp;iacute;tica ainda&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;sem corre&amp;ccedil;&amp;atilde;o que afeta plataformas Oracle Java.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Hist&amp;oacute;rico&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Foi emitido e atualizado um alerta de seguran&amp;ccedil;a que afeta plataformas&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;baseadas em Oracle Java 7. Com uma s&amp;eacute;rie de plataformas que usam Java e a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;exist&amp;ecirc;ncia de malware j&amp;aacute; dispon&amp;iacute;vel com o objetivo de explorar tais&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;vulnerabilidades, &amp;eacute; fundamental tratar essa quest&amp;atilde;o com o n&amp;iacute;vel de seriedade&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;requerido.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;Um dos pontos cr&amp;iacute;ticos ligados a essa vulnerabilidade &amp;eacute; o fato de que mesmo sistemas&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;com os &amp;uacute;ltimas atualiza&amp;ccedil;&amp;otilde;es de Java est&amp;atilde;o vulner&amp;aacute;veis. A Oracle publicou uma&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;atualiza&amp;ccedil;&amp;atilde;o para o Java no dia 15 de Janeiro.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Impacto&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Uma medida fundamental &amp;eacute; identificar claramente quais aplica&amp;ccedil;&amp;otilde;es cr&amp;iacute;ticas&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;corporativas necessitam do Java de forma leg&amp;iacute;tima. Para esses casos vale a pena&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;considerar medidas espec&amp;iacute;ficas incluindo restringir o acesso dessas m&amp;aacute;quinas a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;servidores externos. Parece extremo, mas com o tamanho da exposi&amp;ccedil;&amp;atilde;o e a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;quantidade de dias sem uma corre&amp;ccedil;&amp;atilde;o, n&amp;atilde;o chega a ser um exagero. J&amp;aacute; existem&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;not&amp;iacute;cias (fonte: Kaspersky) de que os ataques na plataforma Java estavam sendo&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;explorados j&amp;aacute; h&amp;aacute; algum tempo, incluindo acusa&amp;ccedil;&amp;otilde;es de espionagem usando essas&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;vulnerabilidades para atacar entidades governamentais (incluindo no Brasil).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Identificando sistemas vulner&amp;aacute;veis&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;Uma medida para simplificar essa a&amp;ccedil;&amp;atilde;o &amp;eacute; utilizar as&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;facilidades de invent&amp;aacute;rio e relacionamento entre usu&amp;aacute;rios e aplica&amp;ccedil;&amp;otilde;es da&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;fam&amp;iacute;lia System Center.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Independente da vers&amp;atilde;o de Java, a medida mais importante recomendada &amp;eacute;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;desabilitar Java dos browsers (todos). &lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Implementando controles&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Aplica&amp;ccedil;&amp;otilde;es de alguns bancos precisam de Java. Uma alternativa a essa&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;abordagem para usu&amp;aacute;rios de Windows 8 &amp;eacute; utilizar a app do banco dispon&amp;iacute;vel para&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;essa plataforma. Espero que os bancos estejam atentos a essa quest&amp;atilde;o e deixem de&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;oferecer Java como alternativa de seus m&amp;oacute;dulos de &amp;ldquo;seguran&amp;ccedil;a&amp;rdquo;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Um dos desafios de se desabilitar ou desinstalar o Java de forma&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;program&amp;aacute;tica, &amp;eacute; que durante a instala&amp;ccedil;&amp;atilde;o, o &amp;ldquo;ID&amp;rdquo; da aplica&amp;ccedil;&amp;atilde;o varia de build&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;para build ou vers&amp;atilde;o para vers&amp;atilde;o. Pode-se utilizar um passo a passo descrito&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;abaixo para identificar esse ID ou utilizar uma medida extrema que desabilita o&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;Java usando uma chave no registry que eu chamaria de &amp;ldquo;bot&amp;atilde;o de emerg&amp;ecirc;ncia&amp;rdquo;, e&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;que &amp;eacute; bem &amp;uacute;til com a situa&amp;ccedil;&amp;atilde;o atual, tamb&amp;eacute;m descrita abai&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Embora as recomenda&amp;ccedil;&amp;otilde;es atuais sejam desabilitam o Java no browser,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;inclui nesse artigo instru&amp;ccedil;&amp;otilde;es para desabilitar ou remover (para o caso de&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;ambientes mais cr&amp;iacute;ticos ou para o caso de os incidentes ou vulnerabilidades&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;divulgadas se agravarem). Com atualiza&amp;ccedil;&amp;atilde;o publicada pela Oracle, &amp;eacute; poss&amp;iacute;vel&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;usar as facilidades de distribui&amp;ccedil;&amp;atilde;o de aplica&amp;ccedil;&amp;otilde;es e atualiza&amp;ccedil;&amp;otilde;es do System&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;Center para assegurar-se de que todos os sistemas est&amp;atilde;o atualizados.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Exemplos de utiliza&amp;ccedil;&amp;atilde;o&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Como identificar Java em&lt;br /&gt;desktops e servidores:&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Utilizando o System Center Configuration Manager e sua base de invent&amp;aacute;rio&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;para identificar clientes que tenham Java. Exemplo para a vers&amp;atilde;o 6.0.200&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;select * from&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;SMS_R_System where SMS_R_System.ResourceID not in (select&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;SMS_G_System_ADD_REMOVE_PROGRAMS.ResourceID from&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;SMS_G_System_ADD_REMOVE_PROGRAMS where&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;SMS_G_System_ADD_REMOVE_PROGRAMS.DisplayName = "Java(TM)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;6 Update 20" and SMS_G_System_ADD_REMOVE_PROGRAMS.Version =&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;"6.0.200")&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;Limite a collection associada aos clientes ou servidores que deseja&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;incluir na pesquisa .&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Uma forma de flexibilizar&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;a query &amp;eacute; usar o wildcard (%). Exemplo: No lugar de 6.0.200, poderia ser 7.% ou&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;6.%&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Uma policy para&lt;br /&gt;desabilitar todas as vers&amp;otilde;es de Java &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Uma ferramenta pouco conhecida (e gr&amp;aacute;tis) &amp;eacute; o Microsoft Security&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;Compliance Manager. Atrav&amp;eacute;s dessa ferramenta &amp;eacute; poss&amp;iacute;vel definir configura&amp;ccedil;&amp;otilde;es&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;de seguran&amp;ccedil;a para o Windows, Office e praticamente todas as plataformas&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;Microsoft.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Uma vantagem do SCM &amp;eacute; poder exportar essas configura&amp;ccedil;&amp;otilde;es para a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;utiliza&amp;ccedil;&amp;atilde;o integrada com o System Center ou anda como group policy.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Ap&amp;oacute;s gerar a configura&amp;ccedil;&amp;atilde;o com o SCM, pode-se utilizar a op&amp;ccedil;&amp;atilde;o &amp;ldquo;Export&amp;rdquo;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;para gerar arquivos de configura&amp;ccedil;&amp;atilde;o como group policy ou para arquivos de&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;SCM/DCM para o System Center Configuration Manager. Com essa configura&amp;ccedil;&amp;atilde;o,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;basta importar utilizando o System Center Configuration Manager e aplicar a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;cole&amp;ccedil;&amp;atilde;o de desktops/servidores adequada.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Kill Bit (Use com cuidado)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Importante: &lt;/strong&gt;&amp;nbsp;Essa sess&amp;atilde;o cont&amp;eacute;m m&amp;eacute;todos e&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;sugest&amp;otilde;es que incluem modifica&amp;ccedil;&amp;otilde;es no registry. Problemas s&amp;eacute;rios e muitas vezes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;irrevers&amp;iacute;veis podem ocorrer se as modifica&amp;ccedil;&amp;otilde;es forem realizadas de forma&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;incorreta ou de acordo com configura&amp;ccedil;&amp;otilde;es espec&amp;iacute;ficas de cada sustema. Use esses&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;passos com cuidado e lembre-se que est&amp;atilde;o nesse artigo de forma educativa e como&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;refer&amp;ecirc;ncia. Recomendo backup de tudo antes de realizar essas modifica&amp;ccedil;&amp;otilde;es. Para&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;mais informa&amp;ccedil;oes sobre como fazer backup e restore do registry, consulte o&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;artigo : &lt;a href="http://support.microsoft.com/kb/322756"&gt;322756&lt;/a&gt; ((http://support.microsoft.com/kb/322756/ )&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;How to back up and restore the registry in Windows)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Existe uma configura&amp;ccedil;&amp;atilde;o que define o chamado &amp;ldquo;kill bit&amp;rdquo; para CLSIDs espec&amp;iacute;ficos&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;que tem o efeito de desabilitar o Java. S&amp;atilde;o eles:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;{8AD9C840-044E-11D1-B3E9-00805F499D93},&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0001-FFFF-ABCDEFFEDCBA},&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;{CAFEEFAC-0017-0002-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0003-FFFF-ABCDEFFEDCBA},&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA},&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;{CAFEEFAC-0017-0005-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0006-FFFF-ABCDEFFEDCBA},&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Para um exemplo pronto de arquivo .reg que usa esse killbit para&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;desabilitar Java:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;How to disable the Java web plug-in in Internet&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;Explorer &lt;a href="http://support.microsoft.com/kb/2751647"&gt;&lt;strong&gt;http://support.microsoft.com/kb/2751647&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;Voce pode utilizar esse exemplo e automatizar a distribui&amp;ccedil;&amp;atilde;o atrav&amp;eacute;s do&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;System Center Configuration Manager. Para mais informa&amp;ccedil;&amp;otilde;es, inclui na leitura&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;de refer&amp;ecirc;ncia um Virtual Lab: Dessa forma voc&amp;ecirc; poder&amp;aacute; aprender mais sobre como&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;utilizar os recursos do System Center para essa e outras facilidades de gest&amp;atilde;o&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;de conformidade.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Leitura de referencia&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;What you need to know about the Oracle&lt;br /&gt;Java Vulnerability:&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;a href="https://krebsonsecurity.com/2013/01/what-you-need-to-know-about-the-java-exploit/"&gt;&lt;strong&gt;https://krebsonsecurity.com/2013/01/what-you-need-to-know-about-the-java-exploit/&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Microsoft FixIt: &lt;/strong&gt;&lt;a href="http://support.microsoft.com/mats/Program_Install_and_Uninstall/en"&gt;&lt;strong&gt;http://support.microsoft.com/mats/Program_Install_and_Uninstall/en&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;How to manually disable Java in the&lt;br /&gt;browser: &lt;/strong&gt;&lt;a href="http://www.java.com/en/download/help/disable_browser.xml"&gt;&lt;strong&gt;http://www.java.com/en/download/help/disable_browser.xml&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Alert: Oracle Java allow security bypass&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;a href="http://www.us-cert.gov/cas/techalerts/TA13-010A.html"&gt;&lt;strong&gt;http://www.us-cert.gov/cas/techalerts/TA13-010A.html&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Vulnerability Note:&amp;nbsp; &lt;/strong&gt;Java 7 fails to restrict access to&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: medium;"&gt;privileged code&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;a href="http://www.kb.cert.org/vuls/id/625617"&gt;&lt;strong&gt;http://www.kb.cert.org/vuls/id/625617&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Security Compliance Manager (Free) :&lt;br /&gt;Como usar esse Security Accelerator:&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;a href="http://technet.microsoft.com/en-us/video/jose-jeff-discuss-the-security-compliance-manager-2-scm-solution-accelerator.aspx"&gt;&lt;strong&gt;http://technet.microsoft.com/en-us/video/jose-jeff-discuss-the-security-compliance-manager-2-scm-solution-accelerator.aspx&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;How to Disable Java in the web&lt;br /&gt;browser:&amp;nbsp; &lt;/strong&gt;&lt;a href="http://support.microsoft.com/kb/2751647"&gt;&lt;strong&gt;http://support.microsoft.com/kb/2751647&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Flame/Stuxnet: &lt;/strong&gt;&lt;a href="https://www.tofinosecurity.com/blog/flame-malware-and-scada-security-what-are-impacts"&gt;&lt;strong&gt;https://www.tofinosecurity.com/blog/flame-malware-and-scada-security-what-are-impacts&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;a href="http://www.networkworld.com/community/blog/critical-infrastructure-malware-infections-ics-cert-report-scada-strangelove"&gt;&lt;strong&gt;http://www.networkworld.com/community/blog/critical-infrastructure-malware-infections-ics-cert-report-scada-strangelove&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Update publicado pelo&lt;br /&gt;fabricante (Oracle) : &lt;/strong&gt;&lt;a href="http://www.latimes.com/business/technology/la-fi-tn-java-oracle-vulnerability-fixed-20130114,0,5276008.story"&gt;&lt;strong&gt;http://www.latimes.com/business/technology/la-fi-tn-java-oracle-vulnerability-fixed-20130114,0,5276008.story&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Java updates, Feds maintain warning: &lt;/strong&gt;&lt;a href="http://news.yahoo.com/oracle-issues-java-fix-feds-maintain-warning-222135696--finance.html"&gt;&lt;strong&gt;http://news.yahoo.com/oracle-issues-java-fix-feds-maintain-warning-222135696--finance.html&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Virtual labs: System Center&lt;br /&gt;Configuration Manager 2012 &lt;/strong&gt;&lt;a href="http://blogs.technet.com/b/johnbaker/archive/2011/12/14/virtual-labs-system-center-configuration-manager-2012.aspx"&gt;&lt;strong&gt;http://blogs.technet.com/b/johnbaker/archive/2011/12/14/virtual-labs-system-center-configuration-manager-2012.aspx&lt;/strong&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;Redigido por : Aylton Souza -&lt;span style="font-family: 'Calibri','sans-serif'; font-size: 11pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;LATAM Virtualization &amp;amp; Private Cloud Lead &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Colabora&amp;ccedil;&amp;atilde;o : Cleber Marques&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: medium;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3549237" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/seguranca/">seguranca</category><category domain="http://blogs.technet.com/b/risco/archive/tags/Falha/">Falha</category><category domain="http://blogs.technet.com/b/risco/archive/tags/Aylton+Souza+_2800_Abu_2900_/">Aylton Souza (Abu)</category><category domain="http://blogs.technet.com/b/risco/archive/tags/JavaScript/">JavaScript</category></item><item><title>Boletim MS13-008 corrige vulnerabilidade crítica no Internet Explorer (6, 7 e 8)</title><link>http://blogs.technet.com/b/risco/archive/2013/01/15/boletim-ms13-008-corrige-vulnerabilidade-cr-237-tica-no-internet-explorer-6-7-e-8.aspx</link><pubDate>Tue, 15 Jan 2013 21:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3546098</guid><dc:creator>Daniel Pires - MSFT</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3546098</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/01/15/boletim-ms13-008-corrige-vulnerabilidade-cr-237-tica-no-internet-explorer-6-7-e-8.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Ol&amp;aacute; Pessoal,&lt;/p&gt;
&lt;p&gt;A Microsoft publicou nesta segunda-feira, 14/01/2013, de forma extraordin&amp;aacute;ria, fora de banda, um boletim de seguran&amp;ccedil;a para endere&amp;ccedil;ar uma vulnerabilidade cr&amp;iacute;tica que afeta as vers&amp;otilde;es do Internet Explorer 6, 7 e 8 (as vers&amp;otilde;es 9 e 10 do Internet Explorer n&amp;atilde;o s&amp;atilde;o afetadas). A vulnerabilidade permite a execu&amp;ccedil;&amp;atilde;o de c&amp;oacute;digo remote caso o usu&amp;aacute;rio, utilizando o Internet Explorer, visite uma p&amp;aacute;gina com o conte&amp;uacute;do malicioso. O atacante que explorar a vulnerabilidade com sucesso pode ganhar os mesmo privil&amp;eacute;gios da v&amp;iacute;tima. Usu&amp;aacute;rios que possuem contas com baixos privil&amp;eacute;gios no sistema operacional Windows tem baixo impacto se comparados com usu&amp;aacute;rios utilizando contas com privil&amp;eacute;gios administrativos ou similares.&lt;/p&gt;
&lt;p&gt;Alguns aspectos importantes sobre esta atualiza&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a:&lt;/p&gt;
&lt;p&gt;P) Esta atualiza&amp;ccedil;&amp;atilde;o, MS13-008, &amp;eacute; uma atualiza&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a cumulativa para o Internet Explorer? &lt;br /&gt;R) N&amp;atilde;o. Essa atualiza&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a, MS13-008, somente aborda a vulnerabilidade descrita neste boletim.&lt;/p&gt;
&lt;p&gt;P) Preciso instalar a &amp;uacute;ltima atualiza&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a cumulativa, MS12-077, para o Internet Explorer? &lt;br /&gt;R) Sim. Em todos os casos, o MS13-008 protege os clientes da vulnerabilidade abordada neste boletim. No entanto, clientes que n&amp;atilde;o instalaram a &amp;uacute;ltima atualiza&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a cumulativa para o Internet Explorer podem enfrentar problemas de compatibilidade depois de instalar a atualiza&amp;ccedil;&amp;atilde;o MS13-008.&lt;/p&gt;
&lt;p&gt;Os clientes devem garantir que a &amp;uacute;ltima atualiza&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a cumulativa para o Internet Explorer, MS12-077, esteja instalada para evitar problemas de compatibilidade.&lt;/p&gt;
&lt;p&gt;P) Se eu apliquei a solu&amp;ccedil;&amp;atilde;o do Microsoft Fix it para o Internet Explorer no Comunicado de Seguran&amp;ccedil;a da Microsoft 2794220, eu preciso desfazer a solu&amp;ccedil;&amp;atilde;o alternativa antes de aplicar esta atualiza&amp;ccedil;&amp;atilde;o ? &lt;br /&gt;R) Os clientes que implementaram a solu&amp;ccedil;&amp;atilde;o do Microsoft Fix it, "Solu&amp;ccedil;&amp;atilde;o alternativa de corre&amp;ccedil;&amp;atilde;o de MSHTML", no Comunicado de seguran&amp;ccedil;a da Microsoft 2794220, n&amp;atilde;o precisam desfazer a solu&amp;ccedil;&amp;atilde;o do Microsoft Fix it antes de aplicar a atualiza&amp;ccedil;&amp;atilde;o. No entanto, visto que a solu&amp;ccedil;&amp;atilde;o alternativa n&amp;atilde;o &amp;eacute; mais necess&amp;aacute;ria, os clientes talvez queiram desfaz&amp;ecirc;-la depois de instalar a atualiza&amp;ccedil;&amp;atilde;o. Consulte as solu&amp;ccedil;&amp;otilde;es alternativas de vulnerabilidade neste boletim para obter mais informa&amp;ccedil;&amp;otilde;es sobre como desfazer a solu&amp;ccedil;&amp;atilde;o alternativa.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;br /&gt;Para maiores informa&amp;ccedil;&amp;otilde;es,&amp;nbsp;esclarecimentos e para obter as &amp;uacute;ltimas not&amp;iacute;cias a respeito deste boletim, por favor, consulte link abaixo:&lt;/p&gt;
&lt;p&gt;Microsoft Security Bulletin MS13-008 - Cr&amp;iacute;tica&lt;br /&gt;Atualiza&amp;ccedil;&amp;atilde;o de seguran&amp;ccedil;a para o Internet Explorer (2799329)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/pt-br/security/bulletin/ms13-008"&gt;http://technet.microsoft.com/pt-br/security/bulletin/ms13-008&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3546098" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Boletins+de+Seguran_26002300_231_3B00_a/">Boletins de Seguran&amp;#231;a</category><category domain="http://blogs.technet.com/b/risco/archive/tags/IE/">IE</category></item><item><title>Webcast: Informações sobre os boletins de segurança (Janeiro 2013)</title><link>http://blogs.technet.com/b/risco/archive/2013/01/08/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-janeiro-2013.aspx</link><pubDate>Tue, 08 Jan 2013 00:26:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3544575</guid><dc:creator>Daniel Mauser - [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3544575</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2013/01/08/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-janeiro-2013.aspx#comments</comments><description>&lt;p&gt;Ol&amp;aacute; Pessoal e Feliz Ano Novo para todos!&lt;/p&gt;
&lt;p&gt;Este m&amp;ecirc;s de&amp;nbsp;Janeiro temos&amp;nbsp;7 (sete) Boletins de Seguran&amp;ccedil;a que&amp;nbsp;foram publicados pela Microsoft nesta ter&amp;ccedil;a-feira (08/01/2013). Estas atualiza&amp;ccedil;&amp;otilde;es corrigem vulnerabilidades no&amp;nbsp;Windows,&amp;nbsp;.NET Framework,&amp;nbsp;System Center&amp;nbsp;e&amp;nbsp;Office. Para saber mais detalhes sobre estes boletins de seguran&amp;ccedil;a assistam o Webcast deste m&amp;ecirc;s, em portugu&amp;ecirc;s,&amp;nbsp;conforme informa&amp;ccedil;&amp;otilde;es abaixo:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a (Janeiro 2013) em Portugu&amp;ecirc;s&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Quando:&lt;/strong&gt;&amp;nbsp;10 de&amp;nbsp;Janeiro de 2013 &amp;agrave;s &lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;15:30h&lt;/strong&gt;&lt;/span&gt; (Bras&amp;iacute;lia).&lt;br /&gt;&lt;strong&gt;Acesso/Inscri&amp;ccedil;&amp;atilde;o:&lt;/strong&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540898&amp;amp;Culture=pt-BR"&gt;Clique Aqui&lt;/a&gt; ou atrav&amp;eacute;s da URL Abaixo:&lt;br /&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540898&amp;amp;Culture=pt-BR"&gt;https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032540898&amp;amp;Culture=pt-BR&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;Eacute; importante mencionar que neste Webcast voc&amp;ecirc; ter&amp;aacute; tamb&amp;eacute;m oportunidade de tirar suas duvidas sobre os Boletins de Seguran&amp;ccedil;a deste m&amp;ecirc;s diretamente com time de Seguran&amp;ccedil;a da Microsoft. Aguardamos sua participa&amp;ccedil;&amp;atilde;o.&lt;br /&gt;Mais informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a de&amp;nbsp;Janeiro de&amp;nbsp;2013 - &lt;a href="http://technet.microsoft.com/pt-br/security/bulletin/ms13-jan"&gt;Clique Aqui&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3544575" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Boletins+de+Seguran_26002300_231_3B00_a/">Boletins de Seguran&amp;#231;a</category></item><item><title>Webcast: Informações sobre os boletins de segurança (Dezembro 2012)</title><link>http://blogs.technet.com/b/risco/archive/2012/12/12/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-dezembro-2012.aspx</link><pubDate>Wed, 12 Dec 2012 05:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3540286</guid><dc:creator>Daniel Mauser - [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3540286</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2012/12/12/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-dezembro-2012.aspx#comments</comments><description>&lt;p&gt;Ol&amp;aacute; Pessoal,&lt;/p&gt;
&lt;p&gt;Este m&amp;ecirc;s de&amp;nbsp;Dezembro temos&amp;nbsp;7 (sete) Boletins de Seguran&amp;ccedil;a que foram publicados pela Microsoft nesta ter&amp;ccedil;a-feira (11/12/2012). Estas atualiza&amp;ccedil;&amp;otilde;es corrigem vulnerabilidades no&amp;nbsp;Windows,&amp;nbsp;Internet Explorer,&amp;nbsp;Exchange Server&amp;nbsp;e&amp;nbsp;Office. Para saber mais detalhes sobre estes boletins de seguran&amp;ccedil;a assistam o Webcast deste m&amp;ecirc;s, em portugu&amp;ecirc;s,&amp;nbsp;conforme informa&amp;ccedil;&amp;otilde;es abaixo:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a (Dezembro 2012) em Portugu&amp;ecirc;s&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Quando:&lt;/strong&gt;&amp;nbsp;13 de&amp;nbsp;Dezembro de 2012 &amp;agrave;s &lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;15:30h&lt;/strong&gt;&lt;/span&gt; (Bras&amp;iacute;lia).&lt;br /&gt;&lt;strong&gt;Acesso/Inscri&amp;ccedil;&amp;atilde;o:&lt;/strong&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032512262&amp;amp;Culture=pt-BR"&gt;Clique Aqui&lt;/a&gt; ou atrav&amp;eacute;s da URL Abaixo:&lt;br /&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032512262&amp;amp;Culture=pt-BR"&gt;https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032512262&amp;amp;Culture=pt-BR&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;Eacute; importante mencionar que neste Webcast voc&amp;ecirc; ter&amp;aacute; tamb&amp;eacute;m oportunidade de tirar suas duvidas sobre os Boletins de Seguran&amp;ccedil;a deste m&amp;ecirc;s diretamente com time de Seguran&amp;ccedil;a da Microsoft. Aguardamos sua participa&amp;ccedil;&amp;atilde;o.&lt;br /&gt;Mais informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a de&amp;nbsp;Dezembro de&amp;nbsp;2012 - &lt;a href="http://technet.microsoft.com/pt-br/security/bulletin/ms12-dec"&gt;Clique Aqui&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3540286" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Boletins+de+Seguran_26002300_231_3B00_a/">Boletins de Seguran&amp;#231;a</category></item><item><title>Webcast: Informações sobre os boletins de segurança (Novembro 2012)</title><link>http://blogs.technet.com/b/risco/archive/2012/11/14/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-novembro-2012.aspx</link><pubDate>Wed, 14 Nov 2012 00:02:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3532418</guid><dc:creator>Daniel Mauser - [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/risco/rsscomments.aspx?WeblogPostID=3532418</wfw:commentRss><comments>http://blogs.technet.com/b/risco/archive/2012/11/14/webcast-informa-231-245-es-sobre-os-boletins-de-seguran-231-a-novembro-2012.aspx#comments</comments><description>&lt;p&gt;Ol&amp;aacute; Pessoal,&lt;/p&gt;
&lt;p&gt;Este m&amp;ecirc;s de&amp;nbsp;Novembro temos&amp;nbsp;6 (seis) Boletins de Seguran&amp;ccedil;a que foram publicados pela Microsoft nesta ter&amp;ccedil;a-feira (13/11/2012). Estas atualiza&amp;ccedil;&amp;otilde;es corrigem vulnerabilidades no&amp;nbsp;Windows, .NET Framework&amp;nbsp;e&amp;nbsp;Office. Para saber mais detalhes sobre estes boletins de seguran&amp;ccedil;a assistam o Webcast deste m&amp;ecirc;s, em portugu&amp;ecirc;s&amp;nbsp;conforme informa&amp;ccedil;&amp;otilde;es abaixo:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a (Novembro 2012) em Portugu&amp;ecirc;s&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Quando:&lt;/strong&gt;&amp;nbsp;14 de&amp;nbsp;Novembro de 2012 &amp;agrave;s &lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;15:30h&lt;/strong&gt;&lt;/span&gt; (Bras&amp;iacute;lia).&lt;br /&gt;&lt;strong&gt;Acesso/Inscri&amp;ccedil;&amp;atilde;o:&lt;/strong&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032512256&amp;amp;Culture=pt-BR"&gt;Clique Aqui&lt;/a&gt; ou atrav&amp;eacute;s da URL Abaixo:&lt;br /&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032512256&amp;amp;Culture=pt-BR"&gt;https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032512256&amp;amp;Culture=pt-BR&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;Eacute; importante mencionar que neste Webcast voc&amp;ecirc; ter&amp;aacute; tamb&amp;eacute;m oportunidade de tirar suas duvidas sobre os Boletins de Seguran&amp;ccedil;a deste m&amp;ecirc;s diretamente com time de Seguran&amp;ccedil;a da Microsoft. Aguardamos sua participa&amp;ccedil;&amp;atilde;o.&lt;br /&gt;Mais informa&amp;ccedil;&amp;otilde;es sobre os boletins de seguran&amp;ccedil;a de&amp;nbsp;Novembro de&amp;nbsp;2012 - &lt;a href="http://technet.microsoft.com/pt-br/security/bulletin/ms12-nov"&gt;Clique Aqui&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Nota:&lt;/strong&gt; O Webcast tamb&amp;eacute;m pode ser acessado sob demanda ap&amp;oacute;s a data acima. Voc&amp;ecirc; pode fazer o acesso pelo mesmo link.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3532418" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/risco/archive/tags/Boletins+de+Seguran_26002300_231_3B00_a/">Boletins de Seguran&amp;#231;a</category></item></channel></rss>