<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
   <channel>
      <title>IT Security &amp; Policy Alerts</title>
      <link>http://www.lsu.edu/itsecurity</link>
      <description>Alerts from the IT Security &amp; Policy Office at LSU</description>
      <language>en-us</language>
      <pubDate>Wed, 09 May 2012 10:00:00 CDT</pubDate>
      <lastBuildDate>Wed, 09 May 2012 10:00:00 CDT</lastBuildDate>
      <generator>Rhythmyx</generator>
      <managingEditor>its-security@lsu.edu (ITS)</managingEditor>
      <webMaster>its-security@lsu.edu (ITS)</webMaster>
	  <atom:link href="http://itsweb.lsu.edu/..//ITS_Security/Alerts/IT Security &amp; Policy Alerts_rss.xml" rel="self" type="application/rss+xml" />
	  
	                            <item>
<title>Microsoft and Adobe Updates for May 2012 </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item47589.html</link>
<description>&lt;p&gt;&lt;b&gt;Microsoft Updates&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Microsoft released 7 security bulletins (3 rated critical and 4 rated important) that address 23 vulnerabilities in Microsoft Windows, Office, Silverlight, and .NET Framework.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;LSU computers will download and install the updates as scheduled by either its group policy or local security center settings. Remember to close all applications at the end of work day today because several updates require a reboot to complete installation.&lt;br /&gt;&lt;br /&gt;More information on the Microsoft bulletins &#8211; &lt;a href=&quot;http://technet.microsoft.com/en-us/security/bulletin/ms12-may&quot;&gt;http://technet.microsoft.com/en-us/security/bulletin/ms12-may&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Adobe Updates&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Adobe released 5 security bulletins that address critical vulnerabilities in Adobe Shockwave Player, Flash, Photoshop, and Illustrator. Users should update to the latest supported versions. Please note that the Adobe Flash Player update has a &quot;Priority 1&quot; rating by Adobe and should be applied first. A Secunia package has already been created and is being deployed to computers subscribed to the LSU Secunia CSI service.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Security bulletins from Adobe&lt;/p&gt;&lt;ul&gt;&lt;li&gt;APSB12-09 Priority 1 security update for Adobe Flash Player (&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb12-09.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb12-09.html&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;APSB12-09 Priority 3 security update for Adobe Illustrator (&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb12-10.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb12-10.html&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;APSB12-09 Priority 3 security update for Adobe Photoshop (&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb12-11.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb12-11.html&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;APSB12-09 Priority 3 security update for Adobe Flash Professional (&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb12-12.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb12-12.html&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;APSB12-09 Priority 2 security update for Adobe Shockwave Player (&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb12-13.html&quot;&gt;http://www.adobes.com/support/security/bulletins/apsb12-13.html&lt;/a&gt;)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;Priority Level Definitions&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Priority 1&lt;/b&gt;: This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform. Adobe recommends administrators install the update as soon as possible. (for instance, within 72 hours).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Priority 2&lt;/b&gt;: This update resolves vulnerabilities in a product that has historically been at elevated risk. There are currently no known exploits. Adobe recommends administrators install the update soon (for instance, within 30 days).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Priority 3&lt;/b&gt;: This update resolves vulnerabilities in a product that has historically not been a target for attackers. Adobe recommends administrators install the update at their discretion.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;</description>
<pubDate>Tue, 08 May 2012 00:00:00 CDT</pubDate> 
<guid isPermaLink="false">1-101-47589</guid>
</item>


                    <item>
<title>Metadata </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item45926.html</link>
<description>&lt;p&gt;Every day computer users share photos, word processing documents, spreadsheets, presentations, audio clips, and other types of digital files with people around the world. What you may not know is that these files may inadvertently include private or sensitive information about you or your organization in the form of metadata. To help you maintain both your privacy and security, we will explain what metadata is, how you can find and remove it, and some steps to take to protect yourself.&lt;br /&gt;&lt;br /&gt;OUCH! Newsletter for April 2012: &lt;a href=&quot;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201204_en.pdf&quot;&gt;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201204_en.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The OUCH! newsletter is a monthly security awareness publication by the SANS Securing the Human program.&lt;/p&gt;</description>
<pubDate>Tue, 10 Apr 2012 12:27:59 CDT</pubDate> 
<guid isPermaLink="false">1-101-45926</guid>
</item>


                    <item>
<title>Microsoft and Adobe Updates for April 2012 </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item45927.html</link>
<description>&lt;p&gt;&lt;b&gt;Microsoft Updates&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Microsoft released 6 security bulletins (4 rated critical and 2 rated important) that address 7 vulnerabilities in Microsoft products.&lt;br /&gt;&lt;br /&gt;The following two updates should be applied as soon as possible because they pose the greatest risk&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;MS12-027 (Windows Common Controls)&lt;/b&gt;: This security update resolves a CVE in the MSCOMCTL.OCX ActiveX control, which could allow remote code execution if a user visits a website containing specially crafted content designed to exploit the vulnerability.&lt;/li&gt;&lt;li&gt;&lt;b&gt;MS12-023 (Internet Explorer)&lt;/b&gt;: This security update resolves five CVEs in Internet Explorer, which could allow a third party to gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;LSU computers will download and install the updates as scheduled by either its group policy or local security center settings. Remember to close all applications at the end of work day today because several updates require a reboot to complete installation.&lt;br /&gt;&lt;br /&gt;More information on the Microsoft bulletins &#8211; &lt;a href=&quot;http://technet.microsoft.com/en-us/security/bulletin/ms12-apr&quot;&gt;http://technet.microsoft.com/en-us/security/bulletin/ms12-apr&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Adobe Updates&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Adobe released a security bulletin that address critical vulnerabilities in Adobe Reader and Acrobat. Users should update to the latest supported versions.&lt;br /&gt;&lt;br /&gt;The vulnerability affects the following versions of Adobe Reader and Acrobat.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Adobe Reader X (10.1.2) and earlier 10.x versions for Windows and Macintosh (Priority 2)&lt;/li&gt;&lt;li&gt;Adobe Reader 9.5 and earlier 9.x versions for Windows and Macintosh (Priority 1)&lt;/li&gt;&lt;li&gt;Adobe Reader 9.5 and earlier 9.x versions for Macintosh (Priority 2)&lt;/li&gt;&lt;li&gt;Adobe Reader 9.4.6 and earlier 9.x versions for Linux (Priority 2)&lt;/li&gt;&lt;li&gt;Adobe Acrobat X (10.1.2) and earlier 10.x versions for Windows and Macintosh (Priority 2)&lt;/li&gt;&lt;li&gt;Adobe Acrobat 9.5 and earlier 9.x versions for Windows (Priority 1)&lt;/li&gt;&lt;li&gt;Adobe Acrobat 9.5 and earlier 9.x versions for Macintosh (Priority 2)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;Priority Level Definitions&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Priority 1&lt;/b&gt;: This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform. Adobe recommends administrators install the update as soon as possible. (for instance, within 72 hours).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Priority 2&lt;/b&gt;: This update resolves vulnerabilities in a product that has historically been at elevated risk. There are currently no known exploits. Adobe recommends administrators install the update soon (for instance, within 30 days).&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;Adobe recommends users of Adobe Reader X and Acrobat X 10.1.2 and earlier versions for Windows and Macintosh update to 10.1.3. Users of Adobe Reader and Acrobat 9.5 and earlier versions for Windows, Macintosh, and Linux should update to 9.5.1. Departments participating in the Secunia Service from ITS will receive the update for Windows through WSUS when it becomes available. To learn more about the Secunia Service visit &lt;a href=&quot;https://its-secunia.lsu.edu&quot;&gt;https://its-secunia.lsu.edu&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More information on Adobe&apos;s Security Bulletin APSB12-08 - &lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb12-08.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb12-08.html&lt;/a&gt;&lt;/p&gt;</description>
<pubDate>Tue, 10 Apr 2012 00:00:00 CDT</pubDate> 
<guid isPermaLink="false">2-101-45927</guid>
</item>


                    <item>
<title>Phishing Attempt &quot;Important Message From Helpdesk!!&quot; </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item45772.html</link>
<description>&lt;p&gt;University IT security analyst have received alerts concerning a phishing attempt with a subject line &quot;Important Message From Helpdesk!!&quot;. The message is states that your mailbox has exceeded one or more size limits set by your administrator. It asks you to click on a link to reset your account. &lt;b&gt;This e-mail is a fraudulent message. Please delete the message.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;A copy of the message for reference is posted below.&lt;br /&gt;&lt;img alt=&quot;&quot; src=&quot;/ITS_Security/images/item45774.png&quot; /&gt;&lt;/p&gt;</description>
<pubDate>Wed, 04 Apr 2012 10:39:05 CDT</pubDate> 
<guid isPermaLink="false">1-101-45772</guid>
</item>


                    <item>
<title>Critical Priority 2 Update for Adobe Flash Player </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item45487.html</link>
<description>&lt;p&gt;Adobe has released an update for Adobe Flash Player that is categorized as Critical Priority 2.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Critical:&lt;/b&gt; A vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Priority 2:&lt;/b&gt; This update resolves vulnerabilities in a product that has historically been at elevated risk. There are currently no known exploits. Adobe recommends administrators install the update soon (for instance, within 30 days).&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;The vulnerability affects the following versions of Adobe Flash Player.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Adobe Flash Player 11.1.102.63 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems&lt;/li&gt;&lt;li&gt;Adobe Flash Player 11.1.111.7 and earlier versions for Android 3.x and 2.x&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;Adobe recommends users of Adobe Flash Player 11.1.102.63 and earlier versions for Windows, Macintosh and Linux update to Adobe Flash Player 11.2.202.228. Users of Adobe Flash Player 11.1.102.63 and earlier versions for Solaris should update to Adobe Flash Player 11.2.202.223. Departments participating in the Secunia Service from ITS will receive the update through WSUS when it becomes available.&lt;br /&gt;&lt;br /&gt;For users who cannot update to Flash Player 11.2.202.228, Adobe has developed a patched version of Flash Player 10.3, Flash Player 10.3.183.18. Users with Flash Player 9 or previous should upgrade to Flash Player 10 or 11 as soon as possible.&lt;br /&gt;&lt;br /&gt;Users of Adobe Flash Player 11.1.111.7 and earlier versions for Android 3.x and earlier versions should update to Flash Player 11.1.111.8 by browsing to the Android Marketplace on an Android device.&lt;br /&gt;&lt;br /&gt;For more information on this update, read Adobe&apos;s Security Bulletin APSB12-07 (&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb12-07.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb12-07.html&lt;/a&gt;)&lt;/p&gt;</description>
<pubDate>Wed, 28 Mar 2012 10:29:54 CDT</pubDate> 
<guid isPermaLink="false">1-101-45487</guid>
</item>


                    <item>
<title>Microsoft Remote Desktop Protocol Exploit </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item44916.html</link>
<description>&lt;p&gt;The exploit code for the dangerous vulnerability in Microsoft Remote Desktop Protocol(RDP) has been released in the wild.&#160; Currently, the exploit code remotely causes the target computer to blue screen, but it won&apos;t be long before someone figures out how to make it run arbitrary codes.&#160; *All* versions of Windows are affected.&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;MS12-020 was patched by Microsoft this Tuesday.&#160; Windows machines on the LSU domain with default Windows Update policy should have already installed the patch automatically and rebooted.&#160; However, please make sure that your critical servers and workstations have this patch and got rebooted.&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;In addition, it is highly recommended that you restrict RDP port 3389/TCP on all Windows machines that you manage to specific machines or subnet(s).&#160; This will cut down on the attack surface for this vulnerability as well as the RDP brute force attacks that we experience constantly.&#160; On Windows Vista, 7, Server 2008, 2008R2, network level authentication should be enabled for RDP.&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;For more information, please visit:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://technet.microsoft.com/en-us/security/bulletin/ms12-020&quot;&gt;http://technet.microsoft.com/en-us/security/bulletin/ms12-020&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://www.zdnet.com/blog/security/exploit-code-published-for-rdp-worm-hole-does-microsoft-have-a-leak/10860&quot;&gt;http://www.zdnet.com/blog/security/exploit-code-published-for-rdp-worm-hole-does-microsoft-have-a-leak/10860&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://aluigi.org/adv/ms12-020_leak.txt&quot;&gt;http://aluigi.org/adv/ms12-020_leak.txt&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://www.scmagazine.com.au/News/293996,rdp-proof-of-concept-triggers-blue-screen-of-death.aspx&quot;&gt;http://www.scmagazine.com.au/News/293996,rdp-proof-of-concept-triggers-blue-screen-of-death.aspx&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;As always, if you have any questions or concerns, please feel free to contact us (&lt;a href=&quot;mailto:its-security@lsu.edu&quot;&gt;its-security@lsu.edu&lt;/a&gt;).&lt;/p&gt;</description>
<pubDate>Fri, 16 Mar 2012 16:44:30 CDT</pubDate> 
<guid isPermaLink="false">1-101-44916</guid>
</item>


                    <item>
<title>Microsoft and Adobe Updates </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item44761.html</link>
<description>&lt;p&gt;&lt;b&gt;Microsoft Updates&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Microsoft released 6 security bulletins (1 rated critical, 4 rated important, and 1 rated moderate)&lt;/p&gt;&lt;p&gt;that address 7 vulnerabilities in Microsoft products.&#160;&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;Critical Bulletin MS 12-020 is a remote code execution in the Remote Desktop Protocol.&#160; All&lt;/p&gt;&lt;p&gt;versions of Microsoft Windows should apply this update as soon as possible.&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;LSU computers will download and install the updates as scheduled by either its group policy&lt;/p&gt;&lt;p&gt;or local security center settings. Remember to close all applications at the end of work day today&lt;/p&gt;&lt;p&gt;because several updates require a reboot to complete installation.&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;More information on the Microsoft bulletins &#8211; &lt;a href=&quot;http://technet.microsoft.com/en-us/security/bulletin/ms12-mar&quot;&gt;http://technet.microsoft.com/en-us/security/bulletin/ms12-mar&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Adobe Updates&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Adobe released 2 security bulletins that address critical vulnerabilities in Adobe Flash Player&lt;/p&gt;&lt;p&gt;and important vulnerabilities in Coldfusion. Users should update to the latest supported versions.&lt;/p&gt;&lt;p&gt;A Secunia package for Adobe Flash Player should be deployed later this week to patch clients&lt;/p&gt;&lt;p&gt;participating in the Secunia Service from ITS.&lt;/p&gt;&lt;p&gt;&#160;&lt;/p&gt;&lt;p&gt;More information on the Adobe bulletins &#8211; &lt;a href=&quot;http://www.adobe.com/support/security/&quot;&gt;http://www.adobe.com/support/security/&lt;/a&gt;&lt;/p&gt;</description>
<pubDate>Wed, 14 Mar 2012 07:50:11 CDT</pubDate> 
<guid isPermaLink="false">1-101-44761</guid>
</item>


                    <item>
<title>E-mail Dos and Don&apos;ts </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item44777.html</link>
<description>&lt;p&gt;E-mail has become one of the primary ways we communicate, both in our personal and professional lives.&#160;However, e-mail can be confusing to use, resulting in mistakes that can hurt you or your organization &#160;Quite often we can be our own worst enemy when using e-mail. &#160;In this newsletter we will explain the most common mistakes people make with e-mail and how you can avoid them in your day-to-day life.&lt;br /&gt;&lt;br /&gt;OUCH! Newsletter for March 2012: &lt;a href=&quot;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201203_en.pdf&quot;&gt;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201203_en.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The OUCH! newsletter is a monthly security awareness publication by the SANS Securing the Human program.&lt;/p&gt;</description>
<pubDate>Thu, 01 Mar 2012 00:00:00 CST</pubDate> 
<guid isPermaLink="false">1-101-44777</guid>
</item>


                    <item>
<title>Securing Your Mobile Device Apps </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item44778.html</link>
<description>&lt;p&gt;Mobile devices have become one of the primary tools we use in both our personal and professional lives. &#160;One of the things that makes mobile devices so powerful is that there are thousands of apps we can select from and use. &#160;However, with the tremendous power and flexibility of apps come a number of risks you must be aware of. &#160;In this newsletter we cover the dangers of mobile device apps and how you can install, use, and maintain them secure.&lt;br /&gt;&lt;br /&gt;OUCH! Newsletter for February 2012: &lt;a href=&quot;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201202_en.pdf&quot;&gt;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201202_en.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The OUCH! newsletter is a monthly security awareness publication by the SANS Securing the Human program.&lt;/p&gt;</description>
<pubDate>Wed, 01 Feb 2012 00:00:00 CST</pubDate> 
<guid isPermaLink="false">1-101-44778</guid>
</item>


                    <item>
<title>Securing Your Home Wi-Fi Network </title>
<link>http://itsweb.lsu.edu/ITS_Security/Alerts/item44779.html</link>
<description>&lt;p&gt;Wi-Fi networks (sometimes called by their technical name 802.11) allow people to wirelessly connect devices to the Internet, such as smartphones, gaming consoles, tablets, and laptops. Because Wi-Fi networks are simple to setup, many people install their own Wi-Fi networks at home. However, many home Wi-Fi networks are configured insecurely, allowing strangers or unauthorized people to easily access your home network or anonymously abuse your Internet connection. To ensure you have a safe and secure home Wi-Fi network, here are a few simple steps you should take.&lt;br /&gt;&lt;br /&gt;OUCH! Newsletter for January 2012: &lt;a href=&quot;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201201_en.pdf&quot;&gt;http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201201_en.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The OUCH! newsletter is a monthly security awareness publication by the SANS Securing the Human program.&lt;/p&gt;</description>
<pubDate>Sun, 01 Jan 2012 00:00:00 CST</pubDate> 
<guid isPermaLink="false">1-101-44779</guid>
</item>


               	 
   </channel>
</rss>

 

