Showing posts with label not patch tuesday. Show all posts
Showing posts with label not patch tuesday. Show all posts
Thursday, January 4, 2018
Tech Tip Tuesday - Meltdown and Spectre
The vulnerabilities of the year are here and it pretty much effects everything with a processor that was made in the last 20 years. Meltdown and Spectre were responsibly disclosed to manufacturers a few months ago and it is just now becoming public. Microsoft has issued out of cycle (not Patch Tuesday) update and other vendors are doing the same. Here are a couple of good talking points for each vulnerability.
“Meltdown breaks the most fundamental isolation between user applications and the operating system. This attack allows a program to access the memory, and thus also the secrets, of other programs and the operating system.”
“Spectre breaks the isolation between different applications. It allows an attacker to trick error-free programs, which follow best practices, into leaking their secrets. In fact, the safety checks of said best practices actually increase the attack surface and may make applications more susceptible to Spectre”
https://meltdownattack.com/
If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.
Tuesday, February 14, 2017
Tech Tip Tuesday – Microsoft Patch Tues… wait
Microsoft hit the pause button on Patch Tuesday. This is a big deal if you were hoping to patch the SMB version 3 vulnerability which allows attackers to “blue screen” fully patched Windows 10 and 8.1 machines. For now you should block SMB v3 traffic from leaving your network. This at least limits the attack surface to your local network.
https://www.kb.cert.org/vuls/id/867968
If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.
Tuesday, August 18, 2015
Tech Tip Tuesday – Internet Explorer Patch
We don’t normally do patches for TTT but we make an exception for out of band patches from Microsoft. It does not affect Edge but IE7 through IE11 is vulnerable. A user can be owned by just browsing to a malicious site and the bad guy will gain the same rights as the current user. This is why you don’t browse as an administrator.
https://technet.microsoft.com/en-us/library/security/ms15-093
If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.
Subscribe to:
Posts (Atom)