Microsoft Tuesday Coverage for November 2009
A number of advisories from Microsoft this month, expect us to cover the most pressing ones in our upcoming Vulnerability Report. For now, here's a quick overview: Microsoft Security Advisory MS09-063: The Web Services on Devices API (WSDAPI) in Microsoft Windows Vista conta
DoJoSec meeting - November 5th
Tonight's DoJoSec has a change in lineup, since Lurene is on the PUP list for today, Matt Olney is stepping in to take her place and give a talk on "Custom Intrusion Detection Techniques for Monitoring Web Applications". This is something similar to the presentation
DoJoSec and DoJoCon
Tomorrow evening, starting at 6:00 pm, Capitol College, Laurel MD. Lurene Grenier will be giving a presentation on Byakugan. Following this event, on Friday morning, our Senior Director of the Vulnerability Research Team, Matt Watchinski, will be speaking at DoJoCon. Check here
Rule release for today - November 3rd, 2009
Adobe Adobe Adobe Adobe, we thought you only did patch releases once per quarter, guess we were wrong. Anyway, a few vulnerabilities with Shockwave. Get your rules on here: http://www.snort.org/vrt/advisories/2009/11/03/vrt-rules-2009-11-03.html
Paranoia and the rise of fake antivirus
This weekend I got a call from my father, who wanted my advice as the computer security guy in the family. It seems that my younger sister's laptop had become infected with a nasty little virus called Block Watcher, which had popped up a series of messages telling her that he
Rule release for today - October 22nd, 2009
A few modifications in this release, most notably a fix for a false positive issue that raised it's ugly head from the Microsoft Tuesday release. Microsoft Security Advisory (MS09-059): A vulnerability in the Microsoft Local Security Authority Subsystem Service (LSASS) may a
Snort 2.8.5.1 Release
Hot on the heels of the Snort 2.8.5 release, a new Snort tarball is now available that fixes a few issues: * Fixed syslog output when running on Windows. * Fixed potential segfault when printing IPv6 packets using the -v option. Thanks to Laurent Gaffie for reporting this
Rapid7 make bold statement acquiring Metasploit Project
Normally the acquisition of an Open Source product by a commercial product wouldn’t make the VRT blog, but in this case I believe this acquisition is going to cause some interesting developments in the threat landscape and in the vulnerability management space. I also think this
Vulnerability Report now available via iTunes
Yes, that's right, our monthly vulnerability report is now available for your convenience, via iTunes. To subscribe, hit up this link: http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=336370330 Note that the video is large due to it being in high definition,