Microsoft has discovered a serious flaw in the program Microsoft Office. If you use it correctly, you can capture virtually any computer with a version of the operating system Windows. Beware dubious PowerPoint-presentations.
Representatives Corporation reported that the bug is already in operation, but only in a limited number of attacks. The error occurs in Windows Vista, Windows Server 2008, Windows 7, Windows 8, Windows Server 2012 and Windows RT. XP version is not mentioned, because Microsoft does not support it more, but it can also be given vulnerability.
IT Safety News - Your source for network security news, opinion, product comparisons and reviews. Virus, Worms, Antivirus and Security Information.
Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts
Tuesday, October 28, 2014
Sunday, January 19, 2014
Microsoft extended of the release of the updates for Security Essentials for Windows XP
According to the corporation after April 8 any kind of support of Windows XP, including antivirus solution Microsoft Security Essentials, will stop completely.
Despite the extension of the release of updates, the program can no longer be downloaded since April this year.
Microsoft has announced its intention to extend the release of updates for its antivirus solutions Security Essentials for Windows XP until April 15, 2015. We remind you that the company will discontinue support for the Windows XP after April 8 this year.
Despite the extension of the release of updates, the program can no longer be downloaded since April this year.
Microsoft has announced its intention to extend the release of updates for its antivirus solutions Security Essentials for Windows XP until April 15, 2015. We remind you that the company will discontinue support for the Windows XP after April 8 this year.
Thursday, September 19, 2013
Critical vulnerabilities found in Internet Explorer
A critical vulnerability found in all supported versions of web browser Internet Explorer, including IE6, IE7, IE8, IE9, IE10 and IE11, - said company Microsoft on portal TechNet.
The vulnerability affects all versions of Windows, from Windows XP, and ending with Windows 8.1, which is scheduled to release only in October.
The vulnerability allows an attacker to remotely execute arbitrary code on a victim's computer after the user visits an infected website. Vulnerability is based on an error, which resulted in IE tries to access an object in memory that has been deleted or has not been placed correctly.
In Microsoft said that in the present study reports on the attacks perpetrated by hackers, focusing mainly on IE8 and IE9.
The vulnerability affects all versions of Windows, from Windows XP, and ending with Windows 8.1, which is scheduled to release only in October.
The vulnerability allows an attacker to remotely execute arbitrary code on a victim's computer after the user visits an infected website. Vulnerability is based on an error, which resulted in IE tries to access an object in memory that has been deleted or has not been placed correctly.
In Microsoft said that in the present study reports on the attacks perpetrated by hackers, focusing mainly on IE8 and IE9.
Tuesday, September 10, 2013
Microsoft and Google are requesting permission to publish data about the number of requests
Microsoft and Google are requesting permission to publish data on the number of requests received from the Government
Companies believe that the government has no evidence that the disclosure of statistical data could harm the state.
In the Monday, September 9, Microsoft, Google, Yahoo! and Facebook are applied to the Court for the U.S. intelligence (US Foreign Intelligence Surveillance Court, FISC) for permission to publish statistics on the number of requests received by companies from the government. Microsoft and Google filed a petition for disclosure of these data are still many weeks ago, but their case was postponed at the request of the government. Negotiations with the government companies have failed, so the proceedings will FISC.
Companies believe that the government has no evidence that the disclosure of statistical data could harm the state.
In the Monday, September 9, Microsoft, Google, Yahoo! and Facebook are applied to the Court for the U.S. intelligence (US Foreign Intelligence Surveillance Court, FISC) for permission to publish statistics on the number of requests received by companies from the government. Microsoft and Google filed a petition for disclosure of these data are still many weeks ago, but their case was postponed at the request of the government. Negotiations with the government companies have failed, so the proceedings will FISC.
Wednesday, August 28, 2013
Website The New York Times was incapacitated by hackers
Attackers hacked domain name registrar, provides services NYT, Yahoo, Google, Microsoft, Ikea and AOL.
Website of Edition The New York Times was disabled on August 27 of this year. Failure of the portal associated with the attack on the Australian domain name registrar - Melbourne IT. At the time of the attack to all employees edition forbidden to send sensitive information via e-mail.
Director of Information Technology NYT Marc Frons said that the failure of the site is the result of an external cyber attacks by the Syrian Electronic Army, or other intruders posing as this hacker group. Initially, in the publication of failure associated with technical problems.
Attack on Melbourne IT not only caused a problem with the site NYT, but with an account in Twitter edition.
Website of Edition The New York Times was disabled on August 27 of this year. Failure of the portal associated with the attack on the Australian domain name registrar - Melbourne IT. At the time of the attack to all employees edition forbidden to send sensitive information via e-mail.
Director of Information Technology NYT Marc Frons said that the failure of the site is the result of an external cyber attacks by the Syrian Electronic Army, or other intruders posing as this hacker group. Initially, in the publication of failure associated with technical problems.
Attack on Melbourne IT not only caused a problem with the site NYT, but with an account in Twitter edition.
Thursday, June 6, 2013
The FBI and Microsoft neutralized large kacker network
FBI and Microsoft jointly neutralized botnet Citadel, by which criminals stole more than $ 500 million. This was reported by the newspaper The Financial Times.
Total number of computers connected by a network Citadel, the two organizations is estimated at five million cars. The network consisted of more than a thousand botnets, each of which, in turn, consisted of thousands of infected computers. Hacking network acted in more than 90 countries.
As stated by the company Microsoft, completely destroy the Citadel is impossible because of its scale and fragmentation. The company has recommended to use antivirus and more frequent updates your computer's OS.
Total number of computers connected by a network Citadel, the two organizations is estimated at five million cars. The network consisted of more than a thousand botnets, each of which, in turn, consisted of thousands of infected computers. Hacking network acted in more than 90 countries.
As stated by the company Microsoft, completely destroy the Citadel is impossible because of its scale and fragmentation. The company has recommended to use antivirus and more frequent updates your computer's OS.
Thursday, April 18, 2013
Microsoft calls not to neglect the antivirus
Microsoft has published a study according to which 25% of the computers in the world there is no anti-virus software that meets modern requirements.
According to figures released by Microsoft in Volume 14 Microsoft Security Intelligence Report, the main reasons for the lack of actual protection on the computers of Internet users has reached the end of the trial period the anti-virus software and malicious actions that disable anti-virus software. As well as elementary carelessness people who believe that their antivirus is simply not necessary.
Friday, April 5, 2013
In April, Microsoft will eliminate two critical vulnerabilities
At Tuesday, April 9, Microsoft will release a security update planned for their products. This month we will face two critical bulletin that will eliminate vulnerabilities in Internet Explorer and Windows.
The first of these will eliminate the vulnerability in Internet Explorer for Windows XP, Windows Vista, Windows 7 and Windows 8 Server Operating Systems Microsoft. The second bulletin describes a vulnerability that applies to all desktop versions of Windows, except Windows 8.
Experts said the corporation, these vulnerabilities could be used by attackers to remotely execute arbitrary code on the target system.
Sunday, February 24, 2013
Following Apple and Facebook hackers attacked Microsoft
While in the United States are trying to find out where I came from hackers, blame the Chinese, they continue their work safely. Who at this time was the victim of the unknown and the mysterious hacker, what information they were able to steal this time found out the news department of the U.S. experts publications for investors "Market Leader".
With the representative of Microsoft became aware that a number of personal computers were infected Corporation malware. When exactly was undertaken cyberattack no information. At the same time, Microsoft officials have assured that the reference to any damage or theft of customer information the company was not, RIA Novosti reported.
Media notes, and the fact that the software company Microsoft after the company Apple, as well as social network Facebook announced on the eve of the "recent" cyber attack on their personal computers, reported Reuters night.
Saturday, February 9, 2013
Microsoft will eliminate 57 vulnerabilities In February
Vulnerabilities that the company intends to fix, are contained in the operating system Windows, web-browser, Internet Explorer, Office and server solutions Microsoft, as well as in . NET framework.
In the security bulletin, which will be released on February 12 of this year, Microsoft will eliminate 57 vulnerabilities in its products.
Five of the twelve critical bulletins fix vulnerabilities that could allow an attacker to remotely execute arbitrary code on vulnerable systems.
One of the bulletins for vulnerabilities in Windows XP, 2003 and Vista, two - critical flaws in IE, and one more - includes updates for Microsoft Exchange, which uses a vulnerable Outside In library from Oracle. The next bulletin applies only to the operating system Windows XP.
Monday, January 14, 2013
Microsoft has released an emergency patch for Internet Explorer
After Oracle which has let out emergency updating for Java, the Microsoft corporation let out urgent updating for the Internet Explorer browser where vulnerability which was used actively by hackers at commission of a number of target attacks to computers in a public sector of the various countries was eliminated. Hotfix for Internet Explorer 6, 7 and 8, where it is already placed in the automatic system updates, which will allow most modern Windows users automatically get it.
Dustin Childs, manager of the Microsoft Trustworthy Computing, said that the fix is a given priority because of the increased risk of a bug, and the fact that these attacks have been conducted on people and corporations are known cases of infection with malware number of government systems through a vulnerability in the Internet Explorer.
Microsoft says that the latest version of Internet Explorer 9, and 10 have higher security systems and this bug it basically is not terrible, but for these browsers will later fix is to close the vector danger.
Monday, December 31, 2012
Microsoft warned about vulnerabilities in Internet Explorer
Microsoft in the past weekend reported the discovery of a serious vulnerability in the browser Internet Explorer.
According to the corporation, vulnerability affects versions of IE 6, 7 and 8, where the vulnerability is already in operation on the Internet and potential attackers can now use it. The company said that working hard as soon as possible to release a fix.
In addition, the company's engineers have proposed a temporary maneuver, can significantly reduce the likelihood of execution attacks. In a statement from Microsoft on December 29, said the company is aware of cases in targeted attacks on computers using a browser up to version IE8. Newer versions borauzera, including IE9 and 10 is not affected, however, and for these people the company is also preparing an update to fix a potentially dangerous element.
According to several IT companies, hackers have posted an exploit on the site of the American non-partisan organization Council on Foreign Relations in New York and Washington. So, last Friday the company FireEye reported that the site was compromised and the CFR on it a code, which in closed forums has been fixed on December 21. Code itself initiates an attack like drive-by.
Sunday, December 9, 2012
Updates for Windows 8, Windows RT, Windows Server 2012 и Internet Explorer 10
Microsoft will release an update of its products this week
The company said that in the next release will release a 7 updates for its recently software: Windows 8, Windows RT, Windows Server 2012 and Internet Explorer 10 (IE10).
According to the developers of Microsoft, December 11 this year, the software giant will release seven security bulletins contain fixes for vulnerabilities in software products. With five notifications are assessed by experts as "critical." Fixes to Windows Internet Explorer 8, and will be fixed with patches.
"Five bulletins include fixes for flaws that allow an attacker to remotely execute arbitrary code on the target system. They cover all the operating systems Microsoft, released after Windows XP", - said Alex Horan, a senior product manager at Core Security.
Note that the papers cover such operating software giant as Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012 and Windows RT.
According to Gore, the most important fix would eliminate a critical vulnerability in Microsoft Exchange e-mail server version 2007 SP3, and in 2010 SP1 and 2. "This is my number one of all vulnerabilities," - said the expert.
Recall that in November this year, Microsoft has released only one critical bulletin.
Thursday, October 25, 2012
Google, Microsoft and Yahoo fix serious vulnerabilities in the mail system
Operators of the popular e-mail systems Google, Microsoft and Yahoo at the same time eliminate the vulnerabilities in their server software that allows you to bypass security algorithm verification. This allows potential attackers to exploit the weakest element of the cryptosystem and generate fake messages.
The vulnerability affects DKIM or DomainKeys Identified Mail, which in addition to Google, Yahoo and Microsoft is used by many other mail servers. DKIM provides cryptographic envelope the letter, which verifies the domain name through which a letter that allows you to discard messages with forged addresses (spam) and miss legitimate messages.
The problem was related to the signature key length of 1024 bits. Forge such keys can be on a PC. In the US-Cert report that they were able to recreate the 1024 - and 768-bit keys for RSA-signature. Experts say that in this respect the situation is the worst situation was in the system of Google, which used a 512-bit keys. Independent experts say that they were able to create a fake email claiming to be from a person, Larry Page and Sergey Brin, and run them through DKIM, applied in Google Gmail.
Saturday, August 25, 2012
Microsoft has patented technology total surveillance
Microsoft has patented technology total surveillance for people
Microsoft has patented technology Life Streaming, which can continuously record the important events in life.
Microsoft has patented technology Life Streaming, which allows you to monitor anyone. The official purpose of the development of this technology is the "instant impressions". It is reported CNews referring to the U.S. Patent Office.
Subscribe to:
Posts (Atom)










