VERT Threat Alert: January 2017 Patch Tuesday Analysis

Today’s VERT Alert addresses 4 new Microsoft Security Bulletins. VERT is actively working on coverage for these bulletins in order to meet our 24-hour SLA and expects to ship ASPL-706 on Wednesday, January 11th. Ease of Use (published exploits) to Risk Table Automated Exploit Easy  MS17-001 Moderate Difficult Extremely Difficult  MS17-004 No Known Exploit   […]… Read More

The post VERT Threat Alert: January 2017 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: January 2017 Patch Tuesday Analysis

Security Hygiene for Dorm Life

Going back to school, especially college, is a fun time of year. One of the best experiences, by far, is living with other people in a dorm or private shared housing. You can make awesome friends, have amazing parties, and make excellent memories. It’s important to note in these shared living situations that hygiene is […]… Read More

The post Security Hygiene for Dorm Life appeared first on The State of Security.

Continue reading Security Hygiene for Dorm Life

Warning: This Post Contains Graphic NVIDIA Content

Back in March, I headed down to Alpharetta, GA to spend time with the American half of our Vulnerability and Exposure Research Team (VERT). While the Sunday travel was a nightmare (issues with customs, car rental and hotel), the week proved to be incredibly valuable. Just prior to my trip, a customer had complained that […]… Read More

The post Warning: This Post Contains Graphic NVIDIA Content appeared first on The State of Security.

Continue reading Warning: This Post Contains Graphic NVIDIA Content

CVSSv3 Disappointment

I was incredibly happy with the initial release of CVSSv3. While it wasn’t perfect, it was a huge improvement over CVSSv2 in that a couple of the weaknesses in v2 were removed. The first of two particularly great changes was the language related to the network attack vector in the specification document: A vulnerability exploitable […]… Read More

The post CVSSv3 Disappointment appeared first on The State of Security.

Continue reading CVSSv3 Disappointment

VERT Threat Alert: August 2016 Patch Tuesday Analysis

Today’s VERT Alert addresses 9 new Microsoft Security Bulletins. VERT is actively working on coverage for these bulletins in order to meet our 24-hour SLA and expects to ship ASPL-684 on Wednesday, August 10th. EASE OF USE (PUBLISHED EXPLOITS) TO RISK TABLE Automated Exploit Easy Moderate Difficult Extremely Difficult No Known Exploit MS16-100 MS16-103   […]… Read More

The post VERT Threat Alert: August 2016 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: August 2016 Patch Tuesday Analysis

Reviving the Forgotten Principle of Responsible Disclosure

In today’s vulnerability market, vendors want to squeeze every ounce of publicity out of their security researchers. As a result, responsible disclosure often falls by the wayside. The same is true of independent researchers in search of their 15 minutes of fame. A fatal flaw in a major product is akin to Kennedy’s dream of landing […]… Read More

The post Reviving the Forgotten Principle of Responsible Disclosure appeared first on The State of Security.

Continue reading Reviving the Forgotten Principle of Responsible Disclosure

VERT Threat Alert: July 2016 Patch Tuesday Analysis

Today’s VERT Alert addresses 11 new Microsoft Security Bulletins. VERT is actively working on coverage for these bulletins in order to meet our 24-hour SLA and expects to ship ASPL-680 on Wednesday, July 13th. Ease of Use (published exploits) to Risk Table Automated Exploit Easy Moderate Difficult Extremely Difficult No Known Exploit MS16-089 MS16-091 MS16-092 […]… Read More

The post VERT Threat Alert: July 2016 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: July 2016 Patch Tuesday Analysis

VERT Threat Alert: June 2016 Patch Tuesday Analysis

Today’s VERT Alert addresses 16 new Microsoft Security Bulletins. VERT is actively working on coverage for these bulletins in order to meet our 24-hour SLA and expects to ship ASPL-675 on Wednesday, June 15th. Ease of Use (published exploits) to Risk Table Automated Exploit Easy Moderate Difficult Extremely Difficult  MS16-082  MS16-075 No Known Exploit MS16-077 […]… Read More

The post VERT Threat Alert: June 2016 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: June 2016 Patch Tuesday Analysis

VERT Threat Alert: May 2016 Patch Tuesday Analysis

Today’s VERT Alert addresses 17 new Microsoft Security Bulletins. VERT is actively working on coverage for these bulletins in order to meet our 24-hour SLA and expects to ship ASPL-670 on Wednesday, May 11th. Ease of Use (published exploits) to Risk Table Automated Exploit Easy MS16-051 MS16-053 Moderate Difficult Extremely Difficult MS16-065 No Known Exploit […]… Read More

The post VERT Threat Alert: May 2016 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: May 2016 Patch Tuesday Analysis