• Windows Vista - 90-days vulnerability report

    February 28th marked 90 days that Windows Vista had been available to business customers. December brought the first public disclosure of a vulnerability and February brought the first Security Bulletin affecting Windows Vista. Has it been a good or a bad 90 days for security vulnerabilities?

    http://www.csoonline.com/pdf/Vista_Vuln_Report.pdf

    Blog Reference by Jeff Jones, the author of the paper:
    http://blogs.csoonline.com/windows_vista_90_day_vulnerability_report

    And the only one fixed was not even a true core Windows Vista one! Not to bad of a story in my opinion.
    Urs

     

  • IPTV & Malicious Websites - IBM Internet Security Systems X-Force Threat Insight Monthly (March)

    The March edition of the IBM Internet Security Systems X-Force Threat Insight Monthly has some interesting information on:

    • Internet Protocol Television (IPTV)
    • Modern Profile of the Malicious Web site

    http://www.iss.net/documents/x-force_monthly_reports/ISS_XFTIM_Mar07.pdf

     Urs

     

  • Microsoft Security Awareness Kit

    Well, I thought everyone has seen this announcement already - but I'm wrong! ;-)
    Because of too many questions, here it is again: 

    Your last line of defense is: Well, the user. In order to help you to address this, we published a Security Awareness Kit - pretty cool stuff. You can get it here:http://www.microsoft.com/technet/security/understanding/awareness.mspx

    In February the Microsoft Security Awareness Toolkit was launched at RSA. The toolkit helps our enterprise and upper mid market customers address their last line of defense with resources to implement comprehensive security awareness and training programs. The increase of attacks that target human vulnerability is driving our customers to recognize the importance of security awareness in their overall security strategy. The latest CSI/FBI Computer Crime and Security Survey indicated that 43% of respondents view user awareness training and education as the most critical security issue in their organization. Also our own spy net data indicates that more than 35% of cleaned malware is related to social engineering attacks.

     

    IT security decision-makers and implementers are often asked to develop and deploy a security awareness program in addition to their current responsibilities. These IT managers quickly begin to realize that effective security awareness programs require a considerable amount of planning, content, and integration with the business and they often fall back to their day to day responsibilities of managing a secure infrastructure. Consequently, security awareness programs are often overlooked or incomplete.

    Urs

  • Reverse Engineering Malware (Part 1-4)

    Very cool and technical research on malware! Or, if you're lines of defense are too tight and you haven't seen malware applications lately, a very good explanation on how these applications work. ;-)

    http://www.windowsecurity.com/articles/Reverse-Engineering-Malware-Part1.html

    Urs

  • Notes On Vista Forensics

    Good overview on Windows Vista's new (or improved) security features and the impact to forensic work...

    Notes On Vista Forensics, Part One
    by Jamie Morris
    http://www.securityfocus.com/infocus/1889?ref=rss

    Urs