Towerwall's InfoSec Blog

Content Type

See all

Patch Tuesday wrap-up, March 2014 - critical fixes from Microsoft and Adobe

network security , security software , Data Security , Security Threat , Information Security , Security , Microsoft , Security Alert , Big Data , Data Privacy , Enterprise , Data Breach

Michelle Drolet

by Paul Ducklin on March 12, 2014 We already wrote about Microsoft's March 2014 patches, noting that, as usually happens, there was an All-Points Bulletin for Internet Explorer coming up. Microsoft doesn't call them APBs, of course - they are Cumulative Security Updates, with one bulletin covering all the numerous versions, bitnesses and CPU flavors of Redmond's IE browser. What we weren't able to tell you in advance was whether the widely-publicized (but fortunately not widely-exploited) false

Towerwall Information Security/Malware Alert Vol 13.67 - Notorious "Gameover" malware gets itself a kernel-mode rootkit...

Data Security , Security Regulations , Security Threat , Information Security , Security , malware , Hackers , Compliance & Privacy , cybercriminals , Security Alert , information security tips , Data Privacy , cybersecurity , Enterprise , Data Breach

Michelle Drolet

Zeus, also known as Zbot, is a malware family that we have written about many times on Naked Security. We've covered it as plain old Zbot. We've covered the Citadel variant, which appeared when the original Zbot code was leaked online. We've even written about the time it pretended to be a Microsoft fix for CryptoLocker, a completely different strain of malware. Currently, the most widespread Zbot derivative is the Gameover bot, also known as Zeus P2P because of its use of peer-to-peer networkfalse

Internet Explorer, .NET, IPv6 and Shockwave top the February 2014 Patch Tuesday list

network security , Security Services , security software , Data Security , Security Regulations , Security Threat , Security , Cloud Security , Shockwave. Internet Explorer , security policy , cybercriminals , Security Alert , cloud services , Data Privacy , cybersecurity , Enterprise , Data Breach

Michelle Drolet

For today's Patch Tuesday, Microsoft released seven bulletins (a surprise after only announcing five last week) and Adobe released one. There are four critical advisories, to me the most important of which is MS14-010 affecting Internet Explorer versions 6 through 10. This patch fixes 24 vulnerabilities, one of which has been publicly disclosed. Considering that 22 of these vulnerabilities can lead to remote code execution, this fix is priority one. MS14-007 is a flaw in the Direct2D graphicsfalse

Why wasn't healthcare.gov security properly tested?

security software , Security Regulations , credit card security , Security Threat , Security Program , Information Security , web server , Application Security , Security , software updates , Hackers , Web Application Firewall , HIPAA , security policy , cybercriminals , penetration testing , information security tips , web users , cybersecurity

Michelle Drolet

When the healthcare.gov website was launched on Oct. 1 it didn't take long for technical issues to hit the headlines. Americans trying to register for health care found the website unusable. There were glitches, extremely long loading times, and serious errors, but most worrying of all for anyone entrusting sensitive data to the system was the lack of security testing. Three white hat hackers, charged with exposing flaws in the security of online systems told a Congress hearing that thefalse

Introducing our Quarterly Newsletter: the Data Security Review

Security Partners , network security , Security Services , security software , Web Storage , Data Security , Government Compliance Regulations , Security Regulations , Heartbleed , credit card security , Mobile Devices , Security Threat , Security Program , Information Security , web server , Application Security , Security , malware , Mobile Apps , Hackers , endpoint security system , Cloud Security , T-Mobile , Web Application Firewall , Apple , Shockwave. Internet Explorer , security policy , cybercriminals , penetration testing , financial security , Security Alert , information security tips , Big Data , Mobile Protection , Data Privacy , Web Browser , security research , vulnerability management , Mobile Security , Third-party Vendor , web users , cybersecurity , Data Breach

Michelle Drolet

I am excited to announce the launch of our quarterly newsletter, the Data Security Review.

Towerwall Security Patch Alert Vol 13.63

security software , Data Security , Security Threat , Information Security , Security , cybercriminals , Security Alert , information security tips , Data Privacy , cybersecurity , Data Breach

Michelle Drolet

Patch Tuesday January 2014 - Microsoft, Adobe and Oracle by Chester Wisniewski As expected Microsoft delivered four patches on patch Tuesday covering Windows XP, 2003, 7, 2008 R2, Word and Dynamics. All four patches are rated important, the first time in memory that none of the fixes were critical. The Word fix applies to all Windows versions and could result in remote code execution. (What does this mean?) The operating system fixes will require a reboot. Adobe also released fixes today forfalse

Towerwall Security/Vulnerability Alert Vol 13.62

Data Security , Security Threat , Information Security , Application Security , Security , Hackers , cybercriminals , Security Alert , information security tips , security research , cannabis , cybersecurity , Enterprise

Michelle Drolet

Recent vulnerabilities for which exploits are available compiled by the Qualys Vulnerability Research Team. This is a list of recent vulnerabilities for which exploits are available. System administrators can use this list to help in prioritization of their remediation activities. The Qualys Vulnerability Research Team compiles this information based on various exploit frameworks, exploit databases, exploit kits and monitoring of internet activity.

Establishing Security Goals

network security , Security Services , security software , Data Security , Security Threat , Security Program , Information Security , Application Security , Security , Hackers , endpoint security system , Cloud Security , security policy , cybercriminals , penetration testing , information security tips , Compliance , security research , vulnerability management , Mobile Security , cybersecurity

Michelle Drolet

Implementing security practices in your organization’s employees’ daily work habits, and ensuring the integrity and confidentiality of information security, the goals of the Security Awareness Program are:

10 Things I Know About ... Passwords

passwords , security software , Data Security , Security Regulations , credit card security , Security Threat , Security Program , Information Security , Application Security , Security , Hackers , Cloud Security , security policy , cybercriminals , information security tips , Big Data , Data Privacy , security research , cybersecurity , Data Breach

Michelle Drolet

MetroWest Chamber of Commerce: 118th Annual Meeting

Data Security , Towerwall , Security Threat , Information Security , Security , Hackers , cybercriminals , Events , cybersecurity

Michelle Drolet

Well, it was certainly a night to remember and much to celebrate With over 325+ people coming to celebrate the 118th MetroWest Chamber of Commerce Annual Meeting! It was a great night with much money raised for United Way’s Feed a Family and our hero's - Military Veterans. Watch some of the fun we had: