<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Managed Solutions &#187; exploits</title>
	<atom:link href="http://managedsolutions.com/tag/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://managedsolutions.com</link>
	<description>We help organizations improve and grow by more effectively using technology.</description>
	<lastBuildDate>Tue, 17 Jan 2012 22:33:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Duqu in the wild, not the drivers you were looking for.</title>
		<link>http://managedsolutions.com/duqu-in-the-wild-not-the-drivers-you-were-looking-for/</link>
		<comments>http://managedsolutions.com/duqu-in-the-wild-not-the-drivers-you-were-looking-for/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 11:30:45 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[Business/Productivity]]></category>
		<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Duqu]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[RAT]]></category>
		<category><![CDATA[Remote Access Trojan]]></category>
		<category><![CDATA[W32.Duqu]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/?p=1529</guid>
		<description><![CDATA[The Duqu Remote Access Trojan (RAT) that hit the wild in Europe this week is not a character in the latest Star Wars movie. While it sounds like a George Lucas inspired character duqu comes from the ~DQ prefix that researchers noticed this previously unknown malware was adding to files it creates when it was [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1532" class="wp-caption alignright" style="width: 310px"><a href="http://managedsolutions.com/wp-content/uploads/2011/10/5818575782_e11fc9c17a_z.jpg"><img class="size-medium wp-image-1532  colorbox-1529" title="Duqu not Dooku" src="http://managedsolutions.com/wp-content/uploads/2011/10/5818575782_e11fc9c17a_z-500x329.jpg" alt="Duqu not Dooku" width="300" height="197" /></a><p class="wp-caption-text">Duqu not Dooku, Image Credit Tracheotomy Bob</p></div>
<p>The Duqu Remote Access Trojan (RAT) that hit the wild in Europe this week is not a character in the latest Star Wars movie. While it sounds like a George Lucas inspired character duqu comes from the ~DQ prefix that researchers noticed this previously unknown malware was adding to files it creates when it was discovered. I am sure Dairy Queen is happy with their choice. Joking aside this virus is no laughing matter. It seems to have been written by the authors of or with the benefit of the <a title="Stuxnet on Wikipedia" href="http://en.wikipedia.org/wiki/Stuxnet" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Stuxnet?referer=');">Stuxnet</a> source code. Stuxnet is the virus that was believed to have setback the Iranian nuclear program last year. It&#8217;s smaller and appears to be designed to spy on infected computers with a combination of a key stroke logger, a data siphon and remove itself after eluding detection for 36 days.</p>
<h3>A new breed of threat</h3>
<p>One disconcerting aspect of this particular Trojan is that one of the drivers in a variant used a signed certificate of a known organization in Taiwan. That means that a windows machine will treat that driver as a legitimate driver, just like one you&#8217;d download to access a new hardware device on your Windows PC. Luckily the certificate has been revoked. This particular malware mask&#8217;s it&#8217;s presence on the infected machine quite well providing a challenge to detect.</p>
<h3>What can you do to protect yourself?</h3>
<p>All of the best practices that apply to information security will help you avoid Duqu. This includes:</p>
<ol>
<li>Keeping your <a title="Why you should not bypass Java and other Critical Updates" href="http://managedsolutions.com/2010/04/why-you-should-not-bypass-java-and-other-updates/" target="_blank">critical components</a> up to date.</li>
<li><a title="Good Personal Choices in Information Security" href="http://managedsolutions.com/2010/10/good-personal-choices-%E2%80%93-the-most-powerful-information-security-tool/" target="_blank">Cautious web surfing</a> and Email habits.</li>
<li>Avoid <a title="Why you should avoid public charging kiosks" href="http://managedsolutions.com/2011/08/why-you-should-avoid-public-charging-kiosks/" target="_blank">public charging kiosks</a>.</li>
<li>Avoid <a title="Article on USB device security" href="http://managedsolutions.com/2011/01/windows-and-mac-both-vulnerable-to-potential-usb-vulnerability/" target="_blank">flash drives from unknown sources</a>.</li>
</ol>
<div>Did you already get infected? You might want to visit the <a title="Post computer virus opportunity center" href="http://managedsolutions.com/2011/06/welcome-to-the-post-computer-virus-opportunity-center/" target="_blank">post virus opportunity center</a>.</div>
<h3>Can we prevent this?</h3>
<p>Seeing as the machines that were infected with this Trojan were hit when it was &#8220;<a title="Article about Zero Day Exploits" href="http://managedsolutions.com/2007/01/education-the-answer-to-zero-day-exploits/" target="_blank">Zero-Day</a>&#8221; it is prudent to consider what other means may have prevented the infection. If it ends up that this virus communicates with hosts in remote countries that a <a title="Geographic Routing Controls" href="http://joesgonesocial.com/2011/09/for-infosec-geeks-geographic-routing-controls/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/joesgonesocial.com/2011/09/for-infosec-geeks-geographic-routing-controls/?referer=');">security solution</a> I recently proposed would prevent the infection from transferring or downloading any information rendering it useless.</p>
<h3>More information</h3>
<ul>
<li><a title="Symantec White Paper" href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet.pdf" rel="nofollow" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet.pdf?referer=');">Symantec White Paper</a></li>
<li><a title="Wired Article Duqu" href="http://www.wired.com/threatlevel/2011/10/son-of-stuxnet-in-the-wild/h" rel="nofollow" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.wired.com/threatlevel/2011/10/son-of-stuxnet-in-the-wild/h?referer=');">Wired Article</a></li>
</ul>
<p>If you found this article helpful or interesting please share it with your friends.</p>
<img class="colorbox-1529"  src="http://managedsolutions.com/?ak_action=api_record_view&id=1529&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/duqu-in-the-wild-not-the-drivers-you-were-looking-for/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows and Mac both vulnerable to potential USB Vulnerability</title>
		<link>http://managedsolutions.com/windows-and-mac-both-vulnerable-to-potential-usb-vulnerability/</link>
		<comments>http://managedsolutions.com/windows-and-mac-both-vulnerable-to-potential-usb-vulnerability/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 16:51:50 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[Business/Productivity]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Acceptable Usage Policy]]></category>
		<category><![CDATA[AUP]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[HID]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[USB]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/?p=1264</guid>
		<description><![CDATA[There are bulletins at us-cert.gov today for both Windows and Mac OS X being vulnerable to potential Human Interface Device (HID) functionality over USB exploit. The simplest way to explain this vulnerability is that both OS X and Windows lack a warning when you connect a USB connected device such as a smart phone when [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-large wp-image-1266 colorbox-1264" title="USB (in)security" src="http://managedsolutions.com/wp-content/uploads/2011/01/IMG_0969-1024x682.jpg" alt="USB (in)security" width="498" height="331" /></p>
<p>There are bulletins at us-cert.gov today for both <a title="Windows Advisory" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-0638" target="_blank" onclick="pageTracker._trackPageview('/outgoing/web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-0638&amp;referer=');">Windows</a> and <a title="OSX Advisory" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-0639" target="_blank" onclick="pageTracker._trackPageview('/outgoing/web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-0639&amp;referer=');">Mac OS X</a> being vulnerable to potential Human Interface Device (HID) functionality over USB exploit. The simplest way to explain this vulnerability is that both OS X and Windows lack a warning when you connect a USB connected device such as a smart phone when it is given keyboard or mouse capability. This could lead to a number of different compromises of the host system. This vulnerability has existed since USB HID support was added to both operating environments but was only publicly demonstrated recently. An example was demonstrated at the Black Hat DC conference, Cnet ran an <a title="Cnet Article about HID Smart Phone Exploit" href="http://news.cnet.com/8301-27080_3-20028919-245.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/news.cnet.com/8301-27080_3-20028919-245.html?referer=');">article</a> about it on January 19th.</p>
<h3>Other USB related risks</h3>
<p>USB connected devices have become a more common source of virus and malware infections. In 2010 there was actually a worm that spread via USB memory sticks called &#8220;<a title="Conficker Worm" href="http://www.microsoft.com/security/worms/conficker.aspx" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.microsoft.com/security/worms/conficker.aspx?referer=');">Conficker</a>&#8221; worm. As early as 2008 USB was becoming recognized as a much more common vector for virus propagation.</p>
<h3>Protecting yourself</h3>
<p>Since USB devices involve user interaction, it is an area where user education and caution is key. We can count on Apple and Microsoft to respond to this HID issue, but we can also say with certainty that there will be others that will come up in the future. Here are some simple suggestions to prevent becoming a victim:</p>
<p><strong>Tips for individuals</strong></p>
<ol>
<li>Store your USB storage devices in a safe place.</li>
<li>Use memory sticks only from extremely trusted sources.</li>
<li>Do not allow others to use your computer to charge their USB devices.</li>
<li>Purchase memory sticks from trusted sources in clearly sealed packaging.</li>
</ol>
<p><strong>Extra tips for businesses</strong></p>
<ol>
<li>Include an area that governs USB devices in your Acceptable Usage Policy (AUP).</li>
<li>Do not allow third parties to use USB devices or charge phones on your corporate systems.</li>
<li>Consider implementing software or software policies that control access to USB ports on your systems.</li>
</ol>
<p>You might also want to read these related articles on how you can function more securely:</p>
<p><a title="Education: the Answer to Zero Day Exploits" href="http://managedsolutions.com/2007/01/education-the-answer-to-zero-day-exploits/" target="_blank">Education: the Answer to Zero Day Exploits</a><br />
<a title="Good Personal Choices – the most powerful Information Security Tool" href="http://managedsolutions.com/2010/10/good-personal-choices-%E2%80%93-the-most-powerful-information-security-tool/" target="_blank"> Good Personal Choices – the most powerful Information Security Tool</a></p>
<img class="colorbox-1264"  src="http://managedsolutions.com/?ak_action=api_record_view&id=1264&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/windows-and-mac-both-vulnerable-to-potential-usb-vulnerability/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Large batch of Google Chrome Vulnerabilities and How to Protect Yourself</title>
		<link>http://managedsolutions.com/large-batch-of-google-chrome-vulnerabilities-and-how-to-protect-yourself/</link>
		<comments>http://managedsolutions.com/large-batch-of-google-chrome-vulnerabilities-and-how-to-protect-yourself/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 17:23:14 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[HTML]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[SB11-024]]></category>
		<category><![CDATA[Stale Pointer]]></category>
		<category><![CDATA[tips]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/?p=1250</guid>
		<description><![CDATA[There is a rather large batch of critical Chrome Vulnerabilities in this weeks US CERT advisory report SB11-024. The CERT Advisories are part of a US Government effort to keep people informed of product security issues.  Most of them have a factor of 9.3 to 10 out of 10, the highest possible which means if [...]]]></description>
			<content:encoded><![CDATA[<p>There is a rather large batch of critical Chrome Vulnerabilities in this weeks US CERT advisory report <a title="SB11-024 Bulletin" href="http://www.us-cert.gov/cas/bulletins/SB11-024.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.us-cert.gov/cas/bulletins/SB11-024.html?referer=');">SB11-024</a>. The CERT Advisories are part of a US Government effort to keep people informed of product security issues.  Most of them have a factor of 9.3 to 10 out of 10, the highest possible which means if exploited on your computer it is likely that the attacker could gain access to your computer. The actual bulletins include PDF and HTML document handling, denial of service and unknown impacts that lead to &#8220;stale pointer&#8221;. This would most likely occur when accessing a website or a PDF file with a vulnerable version of the Chrome browser.</p>
<h3>Who should care?</h3>
<p>Do you use the Chrome Browser or Chrome OS? If you do then you should take action to confirm that you will not be vulnerable.</p>
<h3>How to tell</h3>
<p>With your Chrome Browser open click the small tool icon in the top right of the browser window pictured below:</p>
<p><img class="aligncenter size-full wp-image-1251 colorbox-1250" title="How to Open About on Google Chrome" src="http://managedsolutions.com/wp-content/uploads/2011/01/about.png" alt="How to Open About on Google Chrome" width="291" height="429" /></p>
<p>Once the above drop-down menu appears click the &#8220;About Google Chrome&#8221; menu item. This will result in a screen that will tell you if your browser is up to date and what version it is running:</p>
<p><img class="aligncenter size-full wp-image-1252 colorbox-1250" title="About Results Google Chrome" src="http://managedsolutions.com/wp-content/uploads/2011/01/aboutresults.png" alt="About Results Google Chrome" width="531" height="306" /></p>
<p>The critical piece of information is the green check mark at the bottom of the page. If Chrome is not update or in this case is a version older than 8.0.552 your browser is vulnerable and needs to be updated. In most cases Chrome will be up to date as it is configured to update automatically. This is actually one of the strengths of this browser platform.</p>
<img class="colorbox-1250"  src="http://managedsolutions.com/?ak_action=api_record_view&id=1250&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/large-batch-of-google-chrome-vulnerabilities-and-how-to-protect-yourself/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joe Reviews SB10-242 Cert Report (Video)</title>
		<link>http://managedsolutions.com/joe-reviews-sb10-242-cert-report-video/</link>
		<comments>http://managedsolutions.com/joe-reviews-sb10-242-cert-report-video/#comments</comments>
		<pubDate>Mon, 30 Aug 2010 08:32:22 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/2010/03/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video/4c603bd4b63274c7c0c9ab807a</guid>
		<description><![CDATA[Here is a review of this weeks Cert Advisory. This includes issues with Adobe products, Chrome and Mozilla Firefox. Be sure to update these products if you haven&#8217;t recently. This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook Fan Page.]]></description>
			<content:encoded><![CDATA[<p>Here is a review of this weeks Cert Advisory. This includes issues with Adobe products, Chrome and Mozilla Firefox. Be sure to update these products if you haven&#8217;t recently. This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook<a title="Managed Solutions Facebook Fan Page" href="http://facebook.com/managedsolutions" target="_blank" onclick="pageTracker._trackPageview('/outgoing/facebook.com/managedsolutions?referer=');"> Fan Page</a>.</p>
<div style="text-align: center;"><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/QvnQPTCdaGw?fs=1&amp;hl=en_US"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/QvnQPTCdaGw?fs=1&amp;hl=en_US" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object></div>
<img class="colorbox-984"  src="http://managedsolutions.com/?ak_action=api_record_view&id=984&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/joe-reviews-sb10-242-cert-report-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joe Reviews SB10-221 Cert Report (Video)</title>
		<link>http://managedsolutions.com/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video-2/</link>
		<comments>http://managedsolutions.com/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video-2/#comments</comments>
		<pubDate>Mon, 09 Aug 2010 19:32:22 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[ITunes]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/2010/03/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video/4c603bd4b6327</guid>
		<description><![CDATA[Here is a review of this weeks Cert Advisory. This update contains issues with Apple iTunes, Safari and Mozilla Firefox. Be sure to update these products if you haven&#8217;t recently. This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a review of this weeks Cert Advisory. This update contains issues with Apple iTunes, Safari and Mozilla Firefox. Be sure to update these products if you haven&#8217;t recently. This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook<a title="Managed Solutions Facebook Fan Page" href="http://facebook.com/managedsolutions" target="_blank" onclick="pageTracker._trackPageview('/outgoing/facebook.com/managedsolutions?referer=');"> Fan Page</a>.</p>
<div style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/2DHrf_xa5vk&amp;hl=en_US&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="560" height="340" src="http://www.youtube.com/v/2DHrf_xa5vk&amp;hl=en_US&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<img class="colorbox-958"  src="http://managedsolutions.com/?ak_action=api_record_view&id=958&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Plague of Adobe Acrobat and Reader Vulnerabilities Continues</title>
		<link>http://managedsolutions.com/plague-of-adobe-acrobat-and-reader-vulnerabilities-continues/</link>
		<comments>http://managedsolutions.com/plague-of-adobe-acrobat-and-reader-vulnerabilities-continues/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 17:33:13 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Managed Solutions]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/?p=842</guid>
		<description><![CDATA[I seem to write a post on this once a month minimum. When I opened this weeks Cert advisory there were 14 9.3 vulnerabilities for Adobe Reader and Acrobat. This plague of vulnerabilities and the related exploits that have popped up remind me of Internet Explorer 5 years ago. So here at Managed Solutions we [...]]]></description>
			<content:encoded><![CDATA[<p>I seem to write a post on this once a month minimum. When I opened this weeks Cert advisory there were 14 9.3 vulnerabilities for Adobe Reader and Acrobat. This plague of vulnerabilities and the related exploits that have popped up remind me of Internet Explorer 5 years ago. So here at Managed Solutions we are once again advising our clients to apply any <a title="Security Updates and Advisories at Adobe.com" rel="nofollow" href="http://bit.ly/ctTv0Y" target="_blank" onclick="pageTracker._trackPageview('/outgoing/bit.ly/ctTv0Y?referer=');">updates</a> to Adobe products when prompted or to exercise extra caution with .pdf files. Here is the menacing list of vulnerabilities announced on 6/30/2010:</p>
<p style="text-align: center;">
<div id="attachment_870" class="wp-caption aligncenter" style="width: 534px"><a href="http://managedsolutions.com/wp-content/uploads/2010/07/SB10186Adobe.png"><img class="size-large wp-image-870  colorbox-842" title="14 Adobe Acrobat Vulnerabilities" src="http://managedsolutions.com/wp-content/uploads/2010/07/SB10186Adobe-655x1024.png" alt="Click to view full size." width="524" height="819" /></a><p class="wp-caption-text">14 Adobe Acrobat Vulnerabilities</p></div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="pageTracker._trackPageview('/outgoing/www.zemanta.com/?referer=');"><img class="zemanta-pixie-img colorbox-842" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=d9df1dea-bde5-4a0d-9579-3c37d6409c31" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
<img class="colorbox-842"  src="http://managedsolutions.com/?ak_action=api_record_view&id=842&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/plague-of-adobe-acrobat-and-reader-vulnerabilities-continues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why you should not bypass Java and other Updates</title>
		<link>http://managedsolutions.com/why-you-should-not-bypass-java-and-other-updates/</link>
		<comments>http://managedsolutions.com/why-you-should-not-bypass-java-and-other-updates/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 23:56:07 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[Business/Productivity]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[Oracle]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/?p=604</guid>
		<description><![CDATA[A very common complaint by end users involves &#8220;automatic updates&#8221; and some people go to great lengths to avoid them. We published this quick tip about when and how to run them to minimize the impact. There are several programs that you should think twice before bypassing or ignoring the update: Windows Critical Updates Adobe [...]]]></description>
			<content:encoded><![CDATA[<p>A very common complaint by end users involves &#8220;automatic updates&#8221; and some people go to great lengths to avoid them. We published this <a title="Quick Tip Windows Updates" href="http://bit.ly/9ZvgDw" target="_self" onclick="pageTracker._trackPageview('/outgoing/bit.ly/9ZvgDw?referer=');">quick tip</a> about when and how to run them to minimize the impact. There are several programs that you should think twice before bypassing or ignoring the update:</p>
<ul>
<li>Windows Critical Updates</li>
<li>Adobe Acrobat</li>
<li>Flash Viewer</li>
<li>Oracle/Sun Java</li>
</ul>
<p>The last item on this list is the primary purpose for this post, check out this <a title="Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2010" href="http://bit.ly/a5JjVv" target="_blank" onclick="pageTracker._trackPageview('/outgoing/bit.ly/a5JjVv?referer=');">bulletin</a> from March 2009 related to Oracle Java. There were a total of <strong>27</strong> new security fixes:</p>
<p>&#8220;<strong>Due to the threat posed by a successful attack, Oracle strongly     recommends that customers apply CPU fixes as soon as possible.</strong> This Critical Patch Update contains 27 new security fixes across all  products.&#8221;</p>
<p>So please, when you get the notices for these updates &#8211; run them. Another great way to avoid many of these problems is to operate your computer with an account that has lower permissions. We will write a follow up describing how to do that and why.</p>
<p>If you&#8217;d like to see a chronological history of the Java updates or see if there are new ones<a title="Critical Patch Updates and Security Alerts at Oracle.com" href="http://bit.ly/9SbQP2" target="_blank" onclick="pageTracker._trackPageview('/outgoing/bit.ly/9SbQP2?referer=');"> go here</a>. You can also add them to your RSS reader<a title="RSS feed of Oracle Security Updates" href="http://bit.ly/darenN" target="_blank" onclick="pageTracker._trackPageview('/outgoing/bit.ly/darenN?referer=');"> here</a>.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/515d61fe-9366-44d4-8a24-69c915746ff2/" onclick="pageTracker._trackPageview('/outgoing/reblog.zemanta.com/zemified/515d61fe-9366-44d4-8a24-69c915746ff2/?referer=');"><img class="zemanta-pixie-img colorbox-604" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=515d61fe-9366-44d4-8a24-69c915746ff2" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
<img class="colorbox-604"  src="http://managedsolutions.com/?ak_action=api_record_view&id=604&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/why-you-should-not-bypass-java-and-other-updates/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Update Microsoft Office Products &#8211; Joe Reviews SB10-074 Cert Report (Video)</title>
		<link>http://managedsolutions.com/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video/</link>
		<comments>http://managedsolutions.com/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 19:24:22 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[arucer.dll]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[Energizer Duo]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/2010/03/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video/</guid>
		<description><![CDATA[Here is a review of this weeks Cert Advisory. This update contains the infamous Arucer.dll that came with the charging software on the Energizer Duo USB. Also definitely recommend updating your Microsoft Office products if you haven&#8217;t recently. This is a weekly feature here at Managed Solutions. If you have questions about this video post [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a review of this weeks Cert Advisory. This update contains the infamous Arucer.dll that came with the charging software on the Energizer Duo USB. Also definitely recommend updating your Microsoft Office products if you haven&#8217;t recently. This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook<a title="Managed Solutions Facebook Fan Page" href="http://facebook.com/managedsolutions" target="_blank" onclick="pageTracker._trackPageview('/outgoing/facebook.com/managedsolutions?referer=');"> Fan Page</a>.</p>
<div style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/y9uH61iLIxk&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="560" height="340" src="http://www.youtube.com/v/y9uH61iLIxk&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/9a711caa-977d-4b42-838c-8e6733164d42/" onclick="pageTracker._trackPageview('/outgoing/reblog.zemanta.com/zemified/9a711caa-977d-4b42-838c-8e6733164d42/?referer=');"><img class="zemanta-pixie-img colorbox-586" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=9a711caa-977d-4b42-838c-8e6733164d42" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
<img class="colorbox-586"  src="http://managedsolutions.com/?ak_action=api_record_view&id=586&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/update-microsoft-office-products-joe-reviews-sb10-074-cert-report-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update Adobe Acrobat, Again &#8211; Joe Reviews SB10-060 Cert Report (Video)</title>
		<link>http://managedsolutions.com/update-adobe-acrobat-again-joe-reviews-sb10-060-cert-report-video/</link>
		<comments>http://managedsolutions.com/update-adobe-acrobat-again-joe-reviews-sb10-060-cert-report-video/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 20:22:57 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/2010/03/update-adobe-acrobat-again-joe-reviews-sb10-060-cert-report-video/</guid>
		<description><![CDATA[Here is a review of this weeks Cert Advisory. Adobe Acrobat has returned, please be sure to update! This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook Fan Page.]]></description>
			<content:encoded><![CDATA[<p>Here is a review of this weeks Cert Advisory. Adobe Acrobat has returned, please be sure to update! This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook<a title="Managed Solutions Facebook Fan Page" href="http://facebook.com/managedsolutions" target="_blank" onclick="pageTracker._trackPageview('/outgoing/facebook.com/managedsolutions?referer=');"> Fan Page</a>.</p>
<div style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/_dTBmlnThqo&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="560" height="340" src="http://www.youtube.com/v/_dTBmlnThqo&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/9a711caa-977d-4b42-838c-8e6733164d42/" onclick="pageTracker._trackPageview('/outgoing/reblog.zemanta.com/zemified/9a711caa-977d-4b42-838c-8e6733164d42/?referer=');"><img class="zemanta-pixie-img colorbox-571" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=9a711caa-977d-4b42-838c-8e6733164d42" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
<img class="colorbox-571"  src="http://managedsolutions.com/?ak_action=api_record_view&id=571&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/update-adobe-acrobat-again-joe-reviews-sb10-060-cert-report-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Chrome Vulnerabilities &#8211; Joe Reviews SB10-053 Cert Report (Video)</title>
		<link>http://managedsolutions.com/google-chrome-vulnerabilities-joe-reviews-sb10-053-cert-report-video/</link>
		<comments>http://managedsolutions.com/google-chrome-vulnerabilities-joe-reviews-sb10-053-cert-report-video/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 04:35:11 +0000</pubDate>
		<dc:creator>Joe Hackman</dc:creator>
				<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Managed Solutions]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://managedsolutions.com/2010/02/google-chrome-vulnerabilities-joe-reviews-sb10-053-cert-report-video/</guid>
		<description><![CDATA[Here is a review of this weeks Cert Advisory. Surprising number of Google Chrome issues this week, luckily Chrome is updated constantly and quietly without prompting. This is a weekly feature here at Managed Solutions.]]></description>
			<content:encoded><![CDATA[<p>Here is a review of this weeks Cert Advisory. Surprising number of Google Chrome issues this week, luckily Chrome is updated constantly and quietly without prompting. This is a weekly feature here at Managed Solutions.</p>
<ol></ol>
<div style="text-align: center;"><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/_M0H1qcs2PQ&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/_M0H1qcs2PQ&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object></div>
<img class="colorbox-556"  src="http://managedsolutions.com/?ak_action=api_record_view&id=556&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://managedsolutions.com/google-chrome-vulnerabilities-joe-reviews-sb10-053-cert-report-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

