<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NVDi Support News &#38; Alerts &#187; security patches</title>
	<atom:link href="http://news.nvdi.net/tag/security-patches/feed/" rel="self" type="application/rss+xml" />
	<link>http://news.nvdi.net</link>
	<description>Support information and alerts for NVDi customers and friends</description>
	<lastBuildDate>Sat, 25 Jul 2009 03:06:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Alert: Microsoft to release out-of-band security update July 28th</title>
		<link>http://news.nvdi.net/2009/07/alert-microsoft-to-release-out-of-band-security-update-july-28th/</link>
		<comments>http://news.nvdi.net/2009/07/alert-microsoft-to-release-out-of-band-security-update-july-28th/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 03:06:15 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[Visual Studio]]></category>
		<category><![CDATA[web browser vulnerabilities]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=152</guid>
		<description><![CDATA[Microsoft is releasing a pair of critical Windows security updates on July 28th. This is highly unusual. Microsoft normally issues security fixes on the second Tuesday of the month &#8212; &#8220;Patch Tuesday.&#8221; When they release an out-of-band update like this, it is usually because it deals with a critical vulnerability that is being actively exploited. [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft is releasing a pair of critical Windows security updates on July 28th. <em>This is highly unusual.</em> Microsoft normally issues security fixes on the second Tuesday of the month &#8212; &#8220;Patch Tuesday.&#8221; When they release an out-of-band update like this, it is usually because it deals with a critical vulnerability that is being actively exploited. <a href="http://blogs.technet.com/msrc/archive/2009/07/24/advance-notification-for-july-2009-out-of-band-releases.aspx">According to Microsoft&#8217;s advance notification</a>, the updates will affect Internet Explorer and Visual Studio. For most of us pluggers, it&#8217;s the Internet Explorer patch that will matter.</p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/07/alert-microsoft-to-release-out-of-band-security-update-july-28th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Temporary fix available for new Internet Explorer vulnerability</title>
		<link>http://news.nvdi.net/2009/07/temporary-fix-available-for-new-internet-explorer-vulnerability/</link>
		<comments>http://news.nvdi.net/2009/07/temporary-fix-available-for-new-internet-explorer-vulnerability/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 19:07:17 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[security patches]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=143</guid>
		<description><![CDATA[Just as Microsoft was rolling out this month&#8217;s collection of security patches and software updates, a new Internet Explorer vulnerability cropped up. Basically, it&#8217;s another one of those deals where you could get infected simply by visiting a maliciously crafted web page. Unless the bad guys start exploiting this bug heavily, Microsoft will likely not [...]]]></description>
			<content:encoded><![CDATA[<p>Just as Microsoft was rolling out this month&#8217;s collection of security patches and software updates, a new Internet Explorer vulnerability cropped up. Basically, it&#8217;s another one of those deals where you could get infected simply by visiting a maliciously crafted web page.</p>
<p>Unless the bad guys start exploiting this bug heavily, Microsoft will likely not fix it until the next regular second-Tuesday patch cycle. Until then, there&#8217;s a <a title="Get IE bug temporary fix" href="http://support.microsoft.com/kb/973472">Help and Support page offering a temporary workaround</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/07/temporary-fix-available-for-new-internet-explorer-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July Microsoft patches are available</title>
		<link>http://news.nvdi.net/2009/07/july-microsoft-patches-are-available/</link>
		<comments>http://news.nvdi.net/2009/07/july-microsoft-patches-are-available/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 22:19:58 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[critical updates]]></category>
		<category><![CDATA[security patches]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=137</guid>
		<description><![CDATA[The July Microsoft patches for Windows and layered products, such as Office, are available for download. The servers are slow right now, probably because a whole bunch of people are jumping on them, trying to get at the &#8220;critical&#8221; Internet Explorer updates.]]></description>
			<content:encoded><![CDATA[<p>The July Microsoft patches for Windows and layered products, such as Office, are available for download. The servers are slow right now, probably because a whole bunch of people are jumping on them, trying to get at the &#8220;critical&#8221; Internet Explorer updates.</p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/07/july-microsoft-patches-are-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Alert: May 12th is &#8220;Patch Tuesday&#8221;</title>
		<link>http://news.nvdi.net/2009/05/alert-may-12th-is-patch-tuesday/</link>
		<comments>http://news.nvdi.net/2009/05/alert-may-12th-is-patch-tuesday/#comments</comments>
		<pubDate>Fri, 08 May 2009 17:27:24 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[PowerPoint]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=128</guid>
		<description><![CDATA[May 12th is &#8220;Patch Tuesday,&#8221; the day Microsoft traditionally issues security updates. Adobe is also issuing a patch for Adobe Reader and Acrobat. The sole Microsoft patch fixes a &#8220;critical&#8221; flaw in PowerPoint. &#8220;Critical&#8221; means it&#8217;s a big deal. In this case, opening a maliciously crafted PowerPoint presentation could allow an attacker to execute code [...]]]></description>
			<content:encoded><![CDATA[<p>May 12th is &#8220;Patch Tuesday,&#8221; the day Microsoft traditionally issues security updates. Adobe is also issuing a patch for Adobe Reader and Acrobat.</p>
<p>The sole Microsoft patch fixes a &#8220;critical&#8221; flaw in PowerPoint. &#8220;Critical&#8221; means it&#8217;s a big deal. In this case, opening a maliciously crafted PowerPoint presentation could allow an attacker to execute code remotely on a victim&#8217;s computer. All versions of PowerPoint released in the past 10 years are vulnerable to this one.</p>
<p>Adobe is patching Reader/Acrobat to fix yet another problem associated with embedded JavaScript. This issue, as well as a work-around, was <a href="http://news.nvdi.net/2009/04/alert-more-adobe-reader-flaws-surface/">discussed in an earlier post here</a>.</p>
<p>You can safely assume that the bad guys, knowing that people are often sloppy about security updates, will try to take advantage of both vulnerabilities. The Adobe Reader bug will likely be the primary target. Almost everyone has Adobe Reader installed on their computer and most folks are used to encountering PDF files on web sites.</p>
<p>Be careful out there.</p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/05/alert-may-12th-is-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Tuesday looms</title>
		<link>http://news.nvdi.net/2009/04/patch-tuesday-looms/</link>
		<comments>http://news.nvdi.net/2009/04/patch-tuesday-looms/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 23:35:52 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[critical patches]]></category>
		<category><![CDATA[critical updates]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=90</guid>
		<description><![CDATA[April 14th is &#8220;Patch Tuesday.&#8221; Barring a major panic, Microsoft issues security updates for its products on the second Tuesday of the month. This month, we&#8217;re looking at eight patches, five of them rated &#8220;critical.&#8221; Microsoft&#8217;s offical security bulletin has all the details they&#8217;re willing to share so far. It&#8217;s generally a good idea not [...]]]></description>
			<content:encoded><![CDATA[<p>April 14th is &#8220;Patch Tuesday.&#8221; Barring a major panic, Microsoft issues security updates for its products on the second Tuesday of the month. This month, we&#8217;re looking at eight patches, five of them rated &#8220;critical.&#8221; <a href="http://www.microsoft.com/technet/security/bulletin/ms09-apr.mspx">Microsoft&#8217;s offical security bulletin</a> has all the details they&#8217;re willing to share so far.</p>
<p>It&#8217;s generally a good idea not to let security updates slide for very long. Once the word is out, the bad guys try to reverse-engineer the patches. If they find anything particularly juicy, they take advantage of the fact that many people are remiss about applying the patches. For instance, the primary mode of infection used by the currently infamous Conficker worm is a vulnerability that was fixed several months ago.</p>
<p>A little side-note: April 14, 2009 is also <a href="http://whertra.nvdi.net/2009/04/windows-xp-goes-on-life-support/">the day Windows XP goes on &#8220;extended support.&#8221;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/04/patch-tuesday-looms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
