<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance &#187; Microsoft</title>
	<atom:link href="http://blog.kraasecurity.com/tag/microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 06 Jul 2011 01:12:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Facebook’s new security features and the Zuckerberg hacking incident</title>
		<link>http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/</link>
		<comments>http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/#comments</comments>
		<pubDate>Fri, 28 Jan 2011 22:06:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Mark Zuckerberg]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Muhammad Yunus]]></category>
		<category><![CDATA[Nobel Prize]]></category>
		<category><![CDATA[Social business]]></category>
		<category><![CDATA[Social network service]]></category>
		<category><![CDATA[TechCrunch]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=297</guid>
		<description><![CDATA[Facebook’s new security features and the Zuckerberg hacking incident]]></description>
			<content:encoded><![CDATA[<p>This past week was eventful for <a class="zem_slink freebase/en/facebook" title="Facebook" rel="homepage" href="http://facebook.com/">Facebook</a> and for <a class="zem_slink freebase/en/mark_zuckerberg" title="Mark Zuckerberg" rel="myspaceeverything" href="http://www.myspace.com/everything/mark-zuckerberg">Mark Zuckerberg</a>. The Facebook page was hacked as first reported by <a class="zem_slink freebase/en/techcrunch" title="TechCrunch" rel="homepage" href="http://www.techcrunch.com/">Techcrunch</a> ““Let The Hacking Begin” Declares Person Who Hacked Zuckerberg’s Facebook Fan Page”  (<a href="http://techcrunch.com/2011/01/25/zuckerberg-fan-page-hack/">http://techcrunch.com/2011/01/25/zuckerberg-fan-page-hack/</a>) . The message left on the page was:</p>
<p><em>“Let the hacking begin. If facebook needs money, instead of going to the banks, why doesn&#8217;t Facebook let its users invest in Facebook in a social way? Why not transform Facebook into a &#8216;social business&#8217; the way Nobel Price winner Muhammad Yunus described it? http://bit.ly/fs6rT3 What do you think? #hackercup2011”</em><em> </em></p>
<p>Facebook then said it was a “bug” as reported by the BBC “Facebook blames bug for Zuckerberg &#8216;hacking&#8217;” (<a href="http://www.bbc.co.uk/news/technology-12286377">http://www.bbc.co.uk/news/technology-12286377</a>). Well I guess they can speak to Microsoft about “bugs” and letting their software be hackable. Not much more was explained.</p>
<p>One other interesting event that was also news with Facebook was the launch of their encrypted login process as reported by the Huffingtonpost “What Facebook&#8217;s New Security Features Mean For You”. This has actually been around for a while but not published. What does this mean? Well when you go to Facebook.com now, just go to <a href="https://www.facebook.com/">https://www.facebook.com</a>.  The “https” will allow you to have your login encrypted so the guy sitting next to you in Starbuck and capture your traffic on the wireless network and steal your login ID and password by running Firesheep or other sniffing program. You can also do this with many social networking sites even though they do not publicize it.</p>
<p>To turn on this feature automatically go to “Accounts” -&gt; “Account Setting” -&gt; “Account Security” -&gt; “Change” and select “Browse Facebook on a secure connection (https) whenever possible”. If you have never played with the Privacy Setting you should probably check those out as well. Stop sharing everything about yourself with “Everyone”!</p>
<div id="attachment_302" class="wp-caption alignnone" style="width: 310px"><a rel="attachment wp-att-302" href="http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/facebook-privacy/"><img class="size-medium wp-image-302" title="Facebook privacy settings" src="http://blog.kraasecurity.com/wp-content/uploads/2011/01/facebook-privacy-300x223.png" alt="Facebook privacy settings" width="300" height="223" /></a><p class="wp-caption-text">Facebook privacy settings</p></div>
<p><a class="zem_slink" title="gary bahadur" rel="homepage" href="http://www.kraasecurity.com/">Gary Bahadur</a></p>
<p>CEO KRAA Security, <a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="../">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Police Development</p>
<p>*PGP Security</p>
<p>*Free Website Security Test</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.devicemag.com/2011/01/28/mark-zuckerbergs-facebook-hacked/">Mark Zuckerberg&#8217;s Facebook Hacked</a> (devicemag.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=1b100e50-ce67-4217-8def-0bf7804faac3" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2011/01/28/facebook%e2%80%99s-new-security-features-and-the-zuckerberg-hacking-incident/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Media Warfare: Are you attacking or defending?</title>
		<link>http://blog.kraasecurity.com/2010/09/06/social-media-warfare-are-you-attacking-or-defending/</link>
		<comments>http://blog.kraasecurity.com/2010/09/06/social-media-warfare-are-you-attacking-or-defending/#comments</comments>
		<pubDate>Tue, 07 Sep 2010 01:33:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Entrepreneur]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[social media policy]]></category>
		<category><![CDATA[social media security]]></category>
		<category><![CDATA[social media war]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=276</guid>
		<description><![CDATA[Image via CrunchBase Is there such a thing as Social Media Warfare? We have had cyber warfare going on for years now. So it should be an obvious &#8220;YES&#8221; that Social Media warfare exists. But is that true?  To get to a full blown war opposing sides go through an escalation process. Where are we [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 255px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/company/facebook"><img title="Image representing Facebook as depicted in Cru..." src="http://www.crunchbase.com/assets/images/resized/0000/4561/4561v1-max-450x450.png" alt="Image representing Facebook as depicted in Cru..." width="135" height="55" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com">CrunchBase</a></dd>
</dl>
</div>
</div>
<p>Is there such a thing as Social Media Warfare? We have had cyber warfare going on for years now. So it should be an obvious &#8220;YES&#8221; that Social Media warfare exists. But is that true?  To get to a full blown war opposing sides go through an escalation process. Where are we in this process? From a pure cyber warfare perspective, we are in world war three, many opposing sides, lots of new and improved weapons, completely escalating attacks and no end in sight. Companies are used to conducting <a title="vulnerability assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">vulnerability management</a> and<a title="risk assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/roadmap-strategy-development"> risk assessment</a>. This new war will require new tactics and defense strategies.</p>
<p>I think we have seen the first skirmishes of the war. It started with all the spammers morphing their tools into <a class="zem_slink freebase/en/facebook" title="Facebook" rel="homepage" href="http://facebook.com">Facebook</a> and <a class="zem_slink freebase/en/twitter" title="Twitter" rel="homepage" href="http://twitter.com">Twitter</a> hacking. Then moving into phishing. Then into negative attacks on your reputation by disgruntled customers and competitors. So what is the progression of this coming war? Is there a similarity to how &#8220;normal&#8221; cyber  warfare started? But why is this war inevitable?</p>
<p>The attack vectors in the Social Media War are probably categorized into personal use and corporate use. If these are the assets that needs to be protected, we can then figure out how the assets will be attacked, how will the enemies do reconnaissance, what alliances will be formed and what should be the defense strategies and weapons for defense.</p>
<p>The progression of of this war will follow different patterns and there is probably no end in sight.</p>
<table style="border-color: #f9051d; border-width: 1px; width: 677px; height: 585px;" border="1" align="left">
<tbody>
<tr>
<td><strong>Action</strong></td>
<td><strong>Personal</strong></td>
<td><strong>Corporate</strong></td>
</tr>
<tr>
<td>Skirmish</td>
<td>Home users receiving spam and phishing attacks and scams</td>
<td>Corporate users seeing more phishing attacks, attackers going through Linkedin profiles</td>
</tr>
<tr>
<td>Protest Actions</td>
<td>Users might complain to attorney generals, or write nasty messages about Microsoft <a class="zem_slink freebase/en/adobe_systems" title="Adobe Systems" rel="homepage" href="http://www.adobe.com/">Adobe</a> or <a class="zem_slink freebase/en/apple_inc" title="Apple" rel="homepage" href="http://www.apple.com">Apple</a> security weaknesses</td>
<td>The IT department is inundated with help desk calls. Companies have the ability to complain to ISPs or event countries about originating attacks.</td>
</tr>
<tr>
<td>Negotiations</td>
<td>There really isn&#8217;t anyone to negotiate with. Writing on your Facebook wall will not do a darn thing.</td>
<td>Companies definitely do not want to negotiate. But will see blackmail more and more.</td>
</tr>
<tr>
<td>Failed Negotiations</td>
<td>The home user is bascially screwed anyway.</td>
<td>Succumbing to blackmail will only lead down a bad path.</td>
</tr>
<tr>
<td>Declaration of War</td>
<td>This is a defacto state with the home user. They are at war whether they know it or not.</td>
<td>Companies have to take a proactive approach to security versus reactive. Anticipate the next types of attacks and have a budget to address it.</td>
</tr>
<tr>
<td>Launch Attacks and Defend</td>
<td>More defend, get your anti-spyware, <a title="Antivirus and AntiSpyware" href="http://www.kraasecurity.com/managed-services/system-defense/antivirus-and-spyware">antivirus</a>, personal firewalls and encryption up to speed. But after that, understand how attackers use Social Media.</td>
<td>Spend massive amounts of money on understanding how so fight in the Social media landscape, security hardware and software are not enough.</td>
</tr>
<tr>
<td>Allies Join the War</td>
<td>The home user can only rely on the Social media companies for basic security.</td>
<td>Their will be more collaboration between companies and governments. Perhaps together they have a fighting chance. Regulations are also going to force changes.</td>
</tr>
<tr>
<td>Years of Conflict &#8211; Never Ending</td>
<td>Whats the next thing after Facebook and Twitter? Whatever it is will have its own security challenges. But by that time the home user will probably have given out every bit of personal information on all the Social Media venues anyway.</td>
<td>A company can only rely on the right process to secure their social media usage. As technologies change and new sites go live, a good process and social media security policy is all you can rely on.</td>
</tr>
<tr>
<td>Winner</td>
<td>The ISP, they get to sell bandwidth.</td>
<td>The VCs who fund companies like Facebook and Twitter.</td>
</tr>
</tbody>
</table>
<p>I will get into more tactics in the coming war in future posts.</p>
<p>Gary Bahadur</p>
<p>CEO KRAA Security,  <a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="../">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p>*<a title="Security management" href="http://www.kraasecurity.com/managed-services/intrusion-defense">Managed Security Services</a></p>
<p>*<a title="Vulnerability scanning" href="http://www.kraasecurity.com/managed-services/vulnerability-defense">Vulnerability Management</a></p>
<p>*<a title="Compliance" href="http://www.kraasecurity.com/compliance/pci-assessment">Compliance &amp; Policy Development</a></p>
<p>*<a title="Email Encryption" href="http://www.kraasecurity.com/products/pgp-enterprise-products">PGP Security</a></p>
<p>*<a title="Website security" href="http://www.kraasecurity.com/free-website-test">FREE Website Security Test</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2267544/public-approval-cyberwarfare">Public gives approval for cyber warfare</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.trendhunter.com/trends/google-vs-facebook-employment-war">Social Media Wars &#8211; The Google vs. Facebook Employment War Gets Messy (GALLERY)</a> (trendhunter.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=18799bf6-d5b7-4e8c-becf-073468d79dc0" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/09/06/social-media-warfare-are-you-attacking-or-defending/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When will Vendors provide Risk Assessments of their products?</title>
		<link>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/</link>
		<comments>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 04:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Supplier Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Systems]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[CIO.com]]></category>
		<category><![CDATA[Cross-site scripting]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Operating system]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=185</guid>
		<description><![CDATA[Image via Wikipedia Vendor risk assessment are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 92px; height: 52px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg"><img title="Adobe Systems Incorporated" src="http://upload.wikimedia.org/wikipedia/en/thumb/d/dd/AdobeSystems.svg/300px-AdobeSystems.svg.png" alt="Adobe Systems Incorporated" width="97" height="65" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><a title="vendor risk assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/supplier-security-assessment"><strong>Vendor risk assessment</strong></a> are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer either. So why do we accepts buggy <a class="zem_slink freebase/en/computer_software" title="Computer software" rel="wikipedia" href="http://en.wikipedia.org/wiki/Computer_software">software</a> that is vulnerable to things like cross site scripting attacks, buffer overflows, malware and such? But we do that everyday.</p>
<p>Everything from vulnerable <a class="zem_slink freebase/en/operating_system" title="Operating system security" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating systems</a> such as Windows to vulnerable applications such as <a class="zem_slink freebase/en/adobe_creative_team" title="Adobe Systems" rel="homepage" href="http://www.adobe.com/">Adobe</a> and weak website such as Facebook. As stated by <a class="zem_slink" title="CIO.com" rel="homepage" href="http://www.cio.com">CIO.com</a>, &#8220;SANS and Mitre, a Bedford, Mass.-based <a class="zem_slink freebase/en/non-profit_organization" title="Non-profit organization" rel="wikipedia" href="http://en.wikipedia.org/wiki/Non-profit_organization">non-profit</a>, federally funded technology <a class="zem_slink freebase/en/research_and_development" title="Research and development" rel="wikipedia" href="http://en.wikipedia.org/wiki/Research_and_development">research and development</a> organization, today is also releasing its second annual CWE/SANS Top 25 list of the most common programming errors currently being made by software <a class="zem_slink freebase/en/software_developer" title="Software developer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Software_developer">developers</a>. The authors say the errors on the list are responsible nearly every major type of cyber attack, including the recent intrusions at Google (<a class="zem_slink freebase/en/google" title="NASDAQ: GOOG" rel="stockexchange" href="http://finance.yahoo.com/q?s=GOOG">GOOG</a>), and numerous utilities and government agencies.&#8221;  The biggest companies are culprits.</p>
<p>So what are we do to about buggy software? How do you force a <strong>vendor risk assessment</strong> on all yoru vendors? Maybe scream &#8220;I&#8217;m mad as hell and I am not going to take it anymore!&#8221;  Might feel good for a second or two, but not going to solve the almost daily patch process we have to go through for our software. <strong><a title="patch management" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">Patch management</a></strong> is a thriving sector!</p>
<p>As I see it, some theoretical things the end user can do to change the deadly cycle of poor software:</p>
<ol>
<li>Sue! I don&#8217;t know if that&#8217;s possible, but if you bought a car with bad acceleration problems (ahem Toyota) you might just sue the manufacturer if you got into an accident. What can we do that if some hacker breaks in through buggy software?</li>
<li>Stop buying from that vendor! <a class="zem_slink" title="Apple Inc." rel="geolocation" href="http://maps.google.com/maps?ll=37.33187,-122.029669&amp;spn=1.0,1.0&amp;q=37.33187,-122.029669%20%28Apple%20Inc.%29&amp;t=h">Apple</a> seems to be taking this tactic by not allowing Flash on the IPad. But can we all move away from <a class="zem_slink freebase/en/microsoft" title="Microsoft" rel="homepage" href="http://www.microsoft.com">Microsoft</a> tomorrow? Probably not.</li>
<li>Make the vendors conduct <strong><a title="application security assessment" href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">Risk Assessments</a></strong> of their products prior to release. A third party risk assessment is probably a good idea. Something with more teeth than a SAS70 type review.</li>
</ol>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p> *Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p> *FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://seekingalpha.com/article/188591-apple-vs-microsoft-making-platform-enemies-and-friends?source=feed">Apple vs. Microsoft: Making Platform Enemies and Friends</a> (seekingalpha.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/">Adobe Reader And Acrobat Get Yet Another Security Update</a> (ghacks.net)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13860_3-10447081-56.html?part=rss&amp;subj=BeyondBinary">Microsoft investigates new Internet Explorer flaw</a> (news.cnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/developer-world/adobe-air-20-full-featured-flash-player-coming-smartphones-253&amp;a=13137035&amp;rid=5940a61e-7193-4971-a98b-6547400ef860&amp;e=5d602d8d9add939e9717afe63232605d">Google readies Flash for Android devices</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9162258/IBM_Vulnerabilities_fell_in_09_but_other_risks_abound?source=rss_security">IBM: Vulnerabilities fell in &#8217;09, but other risks abound</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9157558/Update_Adobe_issues_emergency_PDF_patches?source=rss_security">Update: Adobe issues emergency PDF patches</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2009/12/22/mass_flash_file_vulnerability/">Serious web vuln found in 8 million Flash files</a> (theregister.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/347250/Hold_Vendors_Liable_for_Buggy_Software?source=rss_dev">Hold vendors liable for buggy software, group says</a> (computerworld.com)</li>
</ul>
<p>Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="../">http://blog.kraasecurity.com</a></p>
<p><a onclick="pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/5940a61e-7193-4971-a98b-6547400ef860/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=5940a61e-7193-4971-a98b-6547400ef860" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

