<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security e Virtualization Blog di Feliciano Intini (e il suo team PCfSV2) : Vulnerability Handling</title><link>http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx</link><description>Tags: Vulnerability Handling</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Ecco il bollettino straordinario MS08-078 su IE, ed alcune considerazioni sullo scenario di rischio</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/12/18/ecco-il-bollettino-straordinario-ms08-078-su-ie-ed-alcune-considerazioni-sullo-scenario-di-rischio.aspx</link><pubDate>Thu, 18 Dec 2008 04:19:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3170578</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3170578.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3170578</wfw:commentRss><description>Puntuale rispetto al preavviso, stasera Microsoft ha rilasciato il bollettino straordinario " MS08-078 - Security Update for Internet Explorer (960714) ". L'analisi di rischio è presto fatta (anche perché la maggior parte dei dettagli importanti è stata...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/12/18/ecco-il-bollettino-straordinario-ms08-078-su-ie-ed-alcune-considerazioni-sullo-scenario-di-rischio.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3170578" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/3.0+Operating+System+Security/default.aspx">3.0 Operating System Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Vista+Security/default.aspx">Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_/default.aspx">Security Development Lifecycle (SDL)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2008+Security/default.aspx">Windows Server 2008 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Bulletin+and+Advisory+Risk+Analysis/default.aspx">Security Bulletin and Advisory Risk Analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+XP+Security/default.aspx">Windows XP Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Responsible_2F00_full+disclosure/default.aspx">Responsible/full disclosure</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+2000+Security/default.aspx">Windows 2000 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2003+Security/default.aspx">Windows Server 2003 Security</category></item><item><title>“Sicurezza, open source, codice proprietario, interoperabilità” alla 2a Giornata della sicurezza in Sardegna</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/11/03/sicurezza-open-source-codice-proprietario-interoperabilit-alla-2a-giornata-della-sicurezza-in-sardegna.aspx</link><pubDate>Mon, 03 Nov 2008 13:56:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3146335</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3146335.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3146335</wfw:commentRss><description>Mercoled&amp;#236; prossimo, 5 novembre 2008, sar&amp;#242; ospite della seconda edizione della &amp;quot; Giornata della sicurezza informatica in Sardegna &amp;quot;, organizzata da Sardegna Ricerche e dal Lab. Intelligenza d'ambiente di Sardegna DistrICT . Come riporta...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/11/03/sicurezza-open-source-codice-proprietario-interoperabilit-alla-2a-giornata-della-sicurezza-in-sardegna.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3146335" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Incident+Response/default.aspx">Security Incident Response</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Management/default.aspx">Security Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/z-Eventi/default.aspx">z-Eventi</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_/default.aspx">Security Development Lifecycle (SDL)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Responsible_2F00_full+disclosure/default.aspx">Responsible/full disclosure</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Open+Source+Software+Security/default.aspx">Open Source Software Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category></item><item><title>Black Hat 2008: Microsoft Security Vulnerability Research (MSVR)</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/09/08/black-hat-2008-microsoft-security-vulnerability-research-msvr.aspx</link><pubDate>Mon, 08 Sep 2008 17:23:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3120991</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3120991.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3120991</wfw:commentRss><description>Riprendendo il filo da dove l'avevo interrotto (scappando in ferie ;-) mi restava da condividere l'ultimo annuncio fatto da Microsoft in occasione del Black Hat 2008 , che, tra l'altro, non mi sembra sia stato ripreso da altre fonti informative: Microsoft...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/09/08/black-hat-2008-microsoft-security-vulnerability-research-msvr.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3120991" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Update+Management/default.aspx">Security Update Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Development+Lifecycle+_2800_SDL_2900_/default.aspx">Security Development Lifecycle (SDL)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Responsible_2F00_full+disclosure/default.aspx">Responsible/full disclosure</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Black+Hat/default.aspx">Black Hat</category></item><item><title>Black Hat 2008: Microsoft Active Protections Program (MAPP)</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/08/06/black-hat-2008-microsoft-active-protections-program-mapp.aspx</link><pubDate>Wed, 06 Aug 2008 19:06:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3100764</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3100764.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3100764</wfw:commentRss><description>Come per l'annuncio del Microsoft Exploitability Index nel post precedente , anche per quest'annuncio pu&amp;#242; essere utile darvi un po' di indicazioni storiche e di contesto. Forse, infatti, non tutti sanno che fino ad ora l'approccio di Microsoft nel...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/08/06/black-hat-2008-microsoft-active-protections-program-mapp.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3100764" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/8.0+Security+Foundations+_2800_Processes_2900_/default.aspx">8.0 Security Foundations (Processes)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Update+Management/default.aspx">Security Update Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Black+Hat/default.aspx">Black Hat</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Microsoft+Active+Protections+Program+_2800_MAPP_2900_/default.aspx">Microsoft Active Protections Program (MAPP)</category></item><item><title>Black Hat 2008: Microsoft Exploitability Index</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/08/06/black-hat-2008-microsoft-exploitability-index.aspx</link><pubDate>Wed, 06 Aug 2008 17:04:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3100575</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3100575.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3100575</wfw:commentRss><description>La parola che molti clienti diranno alla vista di questo annuncio &amp;#232;: finalmente! L'attivit&amp;#224; di security advisoring che io e il mio team Premier Center for Security (PCfS) abbiamo da sempre realizzato in corrispondenza del rilascio dei bollettini...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/08/06/black-hat-2008-microsoft-exploitability-index.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3100575" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/8.0+Security+Foundations+_2800_Processes_2900_/default.aspx">8.0 Security Foundations (Processes)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/7.0+Security+Foundations+_2800_Technology_2900_/default.aspx">7.0 Security Foundations (Technology)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Update+Management/default.aspx">Security Update Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Malware+and+Attack+analysis/default.aspx">Malware and Attack analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Bulletin+and+Advisory+Risk+Analysis/default.aspx">Security Bulletin and Advisory Risk Analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Black+Hat/default.aspx">Black Hat</category></item><item><title>Black Hat 2008: si parte con il nuovo blog del team MSRC Ecosystem Strategy!</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/08/05/black-hat-2008-si-parte-con-il-nuovo-blog-del-team-msrc-ecosystem-strategy.aspx</link><pubDate>Tue, 05 Aug 2008 13:00:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3098771</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>12</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3098771.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3098771</wfw:commentRss><description>Ho appena lanciato su MClips la chiave di lettura dell'importante partecipazione di Microsoft all'evento di sicurezza pi&amp;#249; atteso dell'anno, il Black Hat ! Black Hat 2008: &amp;#232; tempo di Community-Based Defense! Come ho indicato, sar&amp;#224; una settimana...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/08/05/black-hat-2008-si-parte-con-il-nuovo-blog-del-team-msrc-ecosystem-strategy.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3098771" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0+Microsoft+Strategy+and+Initiatives/default.aspx">0.0.0.0 Microsoft Strategy and Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/z-Eventi/default.aspx">z-Eventi</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0+Security+and+Privacy/default.aspx">0.1.0.0 Security and Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/z-MClips/default.aspx">z-MClips</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.1+End+to+End+Trust/default.aspx">0.1.1.1 End to End Trust</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.1.0+Trustworthy+Computing+_2800_TwC_2900_+/default.aspx">0.1.1.0 Trustworthy Computing (TwC) </category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Vulnerability+Handling/default.aspx">Vulnerability Handling</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Black+Hat/default.aspx">Black Hat</category></item></channel></rss>