Microsoft: No More Pick-and-Choose Patching

Adobe and Microsoft today each issued updates to fix critical security flaws in their products. Adobe’s got fixes for Acrobat and Flash Player ready. Microsoft’s patch bundle for October includes fixes for at least five separate “zero-day” vulnerabilities — dangerous flaws that attackers were already exploiting prior to today’s patch release. Also notable this month is that Microsoft is changing how it deploys security updates, removing the ability for Windows users to pick and choose which individual patches to install. Continue reading Microsoft: No More Pick-and-Choose Patching

Smart-Screen filter still complains, despite I signed the executable, why?

First and foremost, this is my very first experience with Code Signing.

I bought Standard Code Signing from Certum for 3 years.

I intend to publish applications in Czech republic mostly.

But to the point, on Windows 10, when I download … Continue reading Smart-Screen filter still complains, despite I signed the executable, why?

Threatpost News Wrap, September 16, 2016

The news of the week is discussed, including Schneier’s DDoS article, a patched IE/Edge zero day, a new OS X malware detection method, and Google’s Project Zero prize. Continue reading Threatpost News Wrap, September 16, 2016

Adobe, Microsoft Push Critical Updates

Adobe and Microsoft on Tuesday each issued updates to fix multiple critical security vulnerabilities in their software. Adobe pushed a patch that addresses 29 security holes in its Flash Player software. Microsoft released some 14 patch bundles to correct at least 50 flaws in Windows and associated software, including a zero-day bug in Internet Explorer. Continue reading Adobe, Microsoft Push Critical Updates

Microsoft ends Tuesday patches

Yesterday was a big day for Patch Tuesday. It was the last traditional Windows Patch Tuesday as Microsoft is moving to a new patching release model. In the future, patches will be bundled together and users will no longer be able to pick and choose which updates to install. Furthermore, these new ‘monthly update packs’ will be combined, so for instance, the November update will include all the patches from October as well. We have … More Continue reading Microsoft ends Tuesday patches

Microsoft releases five critical updates

Microsoft continued a trend of fewer updates than we are used to with only 9 bulletins (5 critical and 4 important) released this month. It stands to reason that Microsoft may have kept things simple so as not to over shadow the release of their Windows 10 Anniversary update. As far as the new patches go, there are some typical remote code execution browser exploits for Internet Explorer and Edge. In both cases, the user … More Continue reading Microsoft releases five critical updates

VERT Threat Alert: August 2016 Patch Tuesday Analysis

Today’s VERT Alert addresses 9 new Microsoft Security Bulletins. VERT is actively working on coverage for these bulletins in order to meet our 24-hour SLA and expects to ship ASPL-684 on Wednesday, August 10th. EASE OF USE (PUBLISHED EXPLOITS) TO RISK TABLE Automated Exploit Easy Moderate Difficult Extremely Difficult No Known Exploit MS16-100 MS16-103   […]… Read More

The post VERT Threat Alert: August 2016 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: August 2016 Patch Tuesday Analysis