<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title><![CDATA[Security articles from Norman]]></title><link>http://www.norman.com/feeds/security_articles.rss/it</link>
<description><![CDATA[]]></description>
<pubDate>Mon, 13 Feb 2012 07:44:30 +0100</pubDate>
<generator>Lime CMS 3.6</generator>
<atom:link href="http://www.norman.com/feeds/security_articles.rss/it/index_html" rel="self" type="application/rss+xml" />
  <item>
  <title><![CDATA[Critical vulnerabilities in Adobe Flash player - updates available]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/adobe_security_bulletin_11-28/it</link>
  <description><![CDATA[<p>Several critical vulnerabilitiies have been identified in Adobe&nbsp;Flash player 11.0.1.152 and earlier versions.</p>
<p><em><strong>Critical is Adobe's highest vulnerability rating and could when exploited allow malicious native-code to execute, potentially without a user being aware.</strong></em></p>
<p>More information&nbsp;is available in&nbsp;<a target="_blank" href="https://www.adobe.com/support/security/bulletins/apsb11-28.html">Adobe's security bulletin 11-28</a>, which also has links to update downloads.</p>
<p>Norman recommends that affected users update their Adobe Flash player as soon as possible.</p>]]></description>
  <pubDate>Fri, 11 Nov 2011 16:10:00 +0100</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/adobe_security_bulletin_11-28/it</guid>
  
  </item>
  
  <item>
  <title><![CDATA[One critical update for Microsoft systems in November 2011]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_2011_11/it</link>
  <description><![CDATA[<p>In its security bulletin summary for November 2011 Microsoft has published one update for critical, two updates for important, and one update for moderate vulnerabilities in its operating systems / applications.</p>
<p><em><strong>Critical is Microsoft's highest vulnerability rating. </strong></em></p>
<p>A summary describing briefly the vulnerabilities is available from <a target="_blank" href="http://technet.microsoft.com/en-us/security/bulletin/ms11-nov">Microsoft's Security Bulletin Summary for&nbsp;November 2011</a>. <br />
From this page you will also find links to more detailed information in Microsoft's Security Bulletins MS11-083 - MS11-086.</p>
<p>The critical update addresses the following issue:</p>
<ul>
    <li>One privately reported vulnerability in TCP/IP.&nbsp;</li>
</ul>
<p>As expected Microsoft did not include any update for the recently discovered zero-day <a target="_blank" href="http://technet.microsoft.com/en-us/security/advisory/2639658">vulnerability in TrueType Font Parsing</a>, which is used by <a href="http://blogs.norman.com/2011/security-exposed/w32duqu-stuxnet-lite">Duqu</a>. An out-of-band update for this is likely. Until a security update is available, Microsoft has&nbsp;published <a target="_blank" href="http://support.microsoft.com/kb/2639658">a workaround in the form of a fixit solution</a>.</p>
<p>Updates that fixes the vulnerabilities&nbsp;addressed in the November bulletins are available from Windows automatic update mechanism.<br />
To manually check for updates Click the <strong>Start </strong>button, click<strong> All Programs </strong>and then click <strong>Windows Update</strong>. <br />
<br />
Norman advices all affected users to download the relevant security updates as soon as possible, to be protected from potential exploits.</p>]]></description>
  <pubDate>Wed, 09 Nov 2011 08:54:00 +0100</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_2011_11/it</guid>
  
  </item>
  
  <item>
  <title><![CDATA[An approach to an organization's risk factors (part 3)]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_3/it</link>
  <description><![CDATA[<h2>Introduction</h2>
<p>This is part&nbsp;three of our multi-part series &quot;An approach to an organization's risk factors&quot;.</p>
<p>We strongly recommend that you read these articles sequentially, starting with <a href="http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_1/it">part 1 here</a>.</p>
<p><a href="http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_1/it">The first article</a> discussed different <strong>procedures and systems </strong>that could be invoked in order to mitigate risk. <a href="http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_2/it">The second article</a> discussed <strong>Electronic factors </strong>as an area of risk. In this third and final part we will&nbsp;examine&nbsp;<strong>Human&nbsp;attack factors</strong> and<strong> Physical factors</strong>.</p>
<h2>3. Human attack factors</h2>
<p></p>
<p>By human attack&hellip;</p></p>]]></description>
  <pubDate>Fri, 04 Nov 2011 13:05:00 +0100</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_3/it</guid>
  <enclosure url="http://www.norman.com/images/general_pictures/illustrations/fishing_hook_with_berry.jpg/it?size=preview" length="5667" type="image/jpeg" />  
  </item>
  
  <item>
  <title><![CDATA[Microsoft Security Bulletins advance notification]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_advance_notification_november/it</link>
  <description><![CDATA[]]></description>
  <pubDate>Fri, 04 Nov 2011 08:24:00 +0100</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_advance_notification_november/it</guid>
  
  </item>
  
  <item>
  <title><![CDATA[An approach to an organization's risk factors (part 2)]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_2/it</link>
  <description><![CDATA[<h2>Introduction</h2>
<p>This is the second part of of our multi-part series &quot;An approach to an organization's risk factors&quot;.</p>
<p>We strongly recommend that you read these articles sequentially, starting with <a href="http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_1/it">part 1 here</a>.</p>
<p>The previous article discussed different procedures and systems that could be invoked in order to mitigate risk. In subsequent parts we will&nbsp;examine areas at risk, starting with Electronic factors.</p>
<h2>2. Electronic factors</h2>
<p>By electronic factors, we will include all types of issues with the organization&hellip;</p>]]></description>
  <pubDate>Thu, 03 Nov 2011 15:45:00 +0100</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_2/it</guid>
  <enclosure url="http://www.norman.com/images/general_pictures/illustrations/laptop_worm.jpg/it?size=preview" length="7501" type="image/jpeg" />  
  </item>
  
  <item>
  <title><![CDATA[An approach to an organization's risk factors (part 1)]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_1/it</link>
  <description><![CDATA[<h2>Introduction</h2>
<p>Any organization is exposed to some kind of risks. How an organization deals with this fact, however differs widely.</p>
<p>The larger organizations are probably better equipped to allocate sufficient resources to implement the systems that are available in security standards. Smaller organizations may feel that these are not so well suited for their needs.</p>
<p></p>
<p>However, the organization may find it useful to perform a systematic analysis of its vulnerabilities, the probability for their exploitation,&hellip;</p>]]></description>
  <pubDate>Thu, 03 Nov 2011 10:05:00 +0100</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/an_approach_to_risk_factors_part_1/it</guid>
  <enclosure url="http://www.norman.com/images/general_pictures/illustrations/female_mercenary_with_gun.png/it?size=preview" length="13831" type="image/png" />  
  </item>
  
  <item>
  <title><![CDATA[Denial of Service attacks against secure web sites]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/dos_attacks_against_secure_web_sites/it</link>
  <description><![CDATA[<h2>Introduction</h2><p>Secure communication has been the target of several types of attack this year.  In our security article in June, <a href="/security_center/security_center_archive/2011/secure_tokens_turn_insecure/">Secure tokens turn insecure</a>, we wrote about the attack against RSA, an event that turned out to have serious consequences for several high-profile vendors of military systems.  In September we wrote about breaches in the security authorization model in <a href="/security_center/security_center_archive/2011/secure_browsing_turns_insecure_again/">Secure browsing turns insecure (again)</a>. And earlier this month we wrote about <a href="/security_center/security_center_archive/2011/beast/">BEAST (Browser Exploit Against SSL/TLS)</a>.</p><h2>Yet another&hellip;</h2>]]></description>
  <pubDate>Fri, 28 Oct 2011 10:05:00 +0200</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/dos_attacks_against_secure_web_sites/it</guid>
  <enclosure url="http://www.norman.com/images/general_pictures/illustrations/female_mercenary_with_gun.png/it?size=preview" length="13831" type="image/png" />  
  </item>
  
  <item>
  <title><![CDATA[Two critical updates for Microsoft systems in October 2011]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_2011_10/it</link>
  <description><![CDATA[<p>In its security bulletin summary for October 2011 Microsoft has published two updates for critical and six updates for important vulnerabilities in its operating systems / applications.</p>
<p><em><strong>Critical is Microsoft's highest vulnerability rating. </strong></em></p>
<p>A summary describing briefly the vulnerabilities is available from <a target="_blank" href="http://technet.microsoft.com/en-us/security/bulletin/ms11-oct">Microsoft's Security Bulletin Summary for&nbsp;October 2011</a>. <br />
From this page you will also find links to more detailed information in Microsoft's Security Bulletins MS11-075 - MS11-082.</p>
<p>The critical&hellip;</p>]]></description>
  <pubDate>Wed, 12 Oct 2011 08:40:00 +0200</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_2011_10/it</guid>
  
  </item>
  
  <item>
  <title><![CDATA[Malicious images (codes)]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/malicious_images_or_codes/it</link>
  <description><![CDATA[<h2>Introduction</h2>
<p>One popular way to trick users into infecting themselves is to use links in emails. However, the criminals are constantly looking at new ways to trick us. In this article, we shall examine a new one.</p>
<h2>Background</h2>
<p></p>
<p>In recent years, the most popular way to spread malicious software has been through web sites. Many different techniques are used, and several of our&nbsp;previous articles have&nbsp;discussed these. Among the more common types are</p>
<ul>
    <li>the <em><strong>real</strong></em> link in an email is a different than the&hellip;</li></ul>]]></description>
  <pubDate>Fri, 07 Oct 2011 12:05:00 +0200</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/malicious_images_or_codes/it</guid>
  <enclosure url="http://www.norman.com/images/general_pictures/illustrations/child_monster_200x140.jpg/it?size=preview" length="7105" type="image/jpeg" />  
  </item>
  
  <item>
  <title><![CDATA[Microsoft Security Bulletins advance notification]]></title>
  <link>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_advance_notification_october/it</link>
  <description><![CDATA[]]></description>
  <pubDate>Fri, 07 Oct 2011 08:29:00 +0200</pubDate>
  
  <guid>http://www.norman.com/security_center/security_center_archive/2011/microsoft_security_bulletins_advance_notification_october/it</guid>
  
  </item>
  </channel></rss>
