Patch Tuesday Archives - The Silicon Underground David L. Farquhar on technology old and new, computer security, and more Mon, 26 Nov 2018 16:22:58 +0000 en-US hourly 1 https://kerosin.digital/rss-chimp16321610 I read Microsoft’s site to a “Microsoft” scammer https://dfarq.homeip.net/read-microsofts-site-microsoft-scammer/?utm_source=rss&utm_medium=rss&utm_campaign=read-microsofts-site-microsoft-scammer https://dfarq.homeip.net/read-microsofts-site-microsoft-scammer/#comments Wed, 22 Jun 2016 11:00:40 +0000 https://dfarq.homeip.net/?p=8487 “Daniel” from “Microsoft” called me the other day. The number looked halfway legit so I picked up. He out and out claimed to be from Microsoft and said he was getting alerts from my computer. His voice sounded familiar–I think

The post I read Microsoft’s site to a “Microsoft” scammer appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/read-microsofts-site-microsoft-scammer/feed/ 1 8487
Expect a rough road ahead for Flash https://dfarq.homeip.net/expect-a-rough-road-ahead-for-flash/?utm_source=rss&utm_medium=rss&utm_campaign=expect-a-rough-road-ahead-for-flash https://dfarq.homeip.net/expect-a-rough-road-ahead-for-flash/#comments Wed, 15 Jul 2015 11:00:05 +0000 https://dfarq.homeip.net/?p=7787 Adobe has patched Flash twice in two weeks now. The reason for this was due to Hacking Team, an Italian company that sells hacking tools to government agencies, getting hacked. Hacking Team, it turns out, knew of at least three

The post Expect a rough road ahead for Flash appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/expect-a-rough-road-ahead-for-flash/feed/ 1 7787
Worried about the wrong things? It’s always the wrong thing. https://dfarq.homeip.net/worried-about-the-wrong-things-its-always-the-wrong-thing/?utm_source=rss&utm_medium=rss&utm_campaign=worried-about-the-wrong-things-its-always-the-wrong-thing Wed, 06 May 2015 11:00:50 +0000 https://dfarq.homeip.net/?p=7688 Guy Wright’s piece titledĀ Internet Security: We were worried about the wrong thingsĀ is a bit old but it’s an important point. Security is a moving target. It’s always a moving target. I disagree, however, with the assertion that SSL (and its

The post Worried about the wrong things? It’s always the wrong thing. appeared first on The Silicon Underground.

]]>
7688
Three things to remember from Verizon’s Data Brach Investigations Report https://dfarq.homeip.net/three-things-to-remember-from-verizons-data-brach-investigations-report/?utm_source=rss&utm_medium=rss&utm_campaign=three-things-to-remember-from-verizons-data-brach-investigations-report Mon, 20 Apr 2015 11:00:22 +0000 https://dfarq.homeip.net/?p=7668 Every year around this time, Verizon releases its Data Breach Investigations Report, referred to in the trade as simply the “DBIR.” Verizon is one of two companies you call if you’ve been breached and you really want to get to

The post Three things to remember from Verizon’s Data Brach Investigations Report appeared first on The Silicon Underground.

]]>
7668
Why Google ratting on Microsoft isn’t all bad https://dfarq.homeip.net/why-automatic-security-disclosure-works/?utm_source=rss&utm_medium=rss&utm_campaign=why-automatic-security-disclosure-works Fri, 02 Jan 2015 11:00:32 +0000 https://dfarq.homeip.net/?p=7500 This week, Google published a vulnerability in Windows 8.1 after a 90-day countdown timer automatically expired. Microsoft has not yet released a patch. Controversy ensued. Obviously, yes, an unpatched, well-known vulnerability in Windows is troubling. But the alternative is worse.

The post Why Google ratting on Microsoft isn’t all bad appeared first on The Silicon Underground.

]]>
7500
What is Winshock? https://dfarq.homeip.net/what-is-winshock/?utm_source=rss&utm_medium=rss&utm_campaign=what-is-winshock Wed, 03 Dec 2014 11:00:47 +0000 https://dfarq.homeip.net/?p=7461 So the other day I got blindsided with a question at work: What are we doing about Winshock. Winshock, I asked? I had to go look it up, and I found that’s what they dubbed what I’ve been calling MS14-066,

The post What is Winshock? appeared first on The Silicon Underground.

]]>
7461
Retracing the Home Depot attackers’ steps https://dfarq.homeip.net/retracing-the-home-depot-attackers-steps/?utm_source=rss&utm_medium=rss&utm_campaign=retracing-the-home-depot-attackers-steps https://dfarq.homeip.net/retracing-the-home-depot-attackers-steps/#comments Fri, 07 Nov 2014 11:00:15 +0000 https://dfarq.homeip.net/?p=7426 New details emerged on the Home Depot attack that left 56 million consumers with compromised credit cards. The interesting thing in the new details is that it could have been much worse, but maybe not for reasons immediately obvious. The

The post Retracing the Home Depot attackers’ steps appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/retracing-the-home-depot-attackers-steps/feed/ 1 7426
Revisiting Microsoft/Sysinternals Du as a batch file https://dfarq.homeip.net/revisiting-microsoftsysinternals-du-as-a-batch-file/?utm_source=rss&utm_medium=rss&utm_campaign=revisiting-microsoftsysinternals-du-as-a-batch-file Fri, 19 Sep 2014 11:00:35 +0000 https://dfarq.homeip.net/?p=7368 My tips for using Sysinternals’ Du.exe were well received last week, and my former coworker Charlie mentioned a GUI tool called Windirstat that I had completely forgotten about. For the command-line averse, it’s an incredibly useful tool. But there’s one

The post Revisiting Microsoft/Sysinternals Du as a batch file appeared first on The Silicon Underground.

]]>
7368
IT jobs shortage? Slide over to security https://dfarq.homeip.net/it-jobs-shortage-slide-over-to-security/?utm_source=rss&utm_medium=rss&utm_campaign=it-jobs-shortage-slide-over-to-security Mon, 08 Sep 2014 11:00:19 +0000 https://dfarq.homeip.net/?p=7354 IT jobs are getting scarce again, and I believe it. I don’t have a cure but I have a suggestion: Specialize. Specifically, specialize in security. Why? Turnover. Turnover in my department is rampant, because other companies offer my coworkers more

The post IT jobs shortage? Slide over to security appeared first on The Silicon Underground.

]]>
7354
Getting started in compliance: Start by doing the right thing https://dfarq.homeip.net/getting-started-in-compliance-start-by-doing-the-right-thing/?utm_source=rss&utm_medium=rss&utm_campaign=getting-started-in-compliance-start-by-doing-the-right-thing Thu, 11 Jul 2013 11:00:30 +0000 https://dfarq.homeip.net/?p=6712 I had a couple of discussions this week about compliance, and the traps of plain old check-the-box compliance, and how to get started in it when regulatory compliance suddenly gets sprung on you. The key is working backwards. Start with

The post Getting started in compliance: Start by doing the right thing appeared first on The Silicon Underground.

]]>
6712