<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OIT Information Security Office</title>
	<atom:link href="http://blog.uta.edu/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.uta.edu/security</link>
	<description>The Official Web Log of the OIT Information Security Office.    www.uta.edu/security</description>
	<lastBuildDate>Wed, 09 Mar 2011 20:33:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Super Tuesday Summary – February 2011</title>
		<link>http://blog.uta.edu/security/2011/03/09/super-tuesday-summary-%e2%80%93-february-2011/</link>
		<comments>http://blog.uta.edu/security/2011/03/09/super-tuesday-summary-%e2%80%93-february-2011/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 20:32:57 +0000</pubDate>
		<dc:creator>mfager</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Patches]]></category>

		<guid isPermaLink="false">http://blog.uta.edu/security/?p=255</guid>
		<description><![CDATA[The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release [...]]]></description>
			<content:encoded><![CDATA[<p>The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release their scheduled patches as well.  So     regardless of your OS of choice please check with your update service     for any new items.</p>
<p><strong>Microsoft Users</strong></p>
<p>Microsoft released three (3) patches this month.</p>
<p>One (1) of the patches is listed as critical and should be applied  immediately.</p>
<p>MS11-015 &#8211; <span style="color: #ff0000">Critical (high)</span> &#8211; Vulnerabilities in Windows Media Could Allow Remote Code Execution (2510030)<br />
MS11-016 &#8211; <span style="color: #ff6600">Important  (medium)</span> &#8211; Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2508062)<br />
MS11-017 &#8211; <span style="color: #ff6600">Important  (medium)</span> &#8211; Vulnerability in Microsoft Groove Could Allow Remote Code Execution (2494047)</p>
<p>Microsoft also released the usual updates and signatures for the<br />
- Anti-Malware definitions for FCS and SE<br />
- Malicious Software Removal Tool<br />
- Outlook / Mail email junk filters</p>
<p>For more information on MS patches see,</p>
<p><a href="https://www.microsoft.com/technet/security/Bulletin/MS11-jan.mspx">https://www.microsoft.com/technet/security/Bulletin/MS11-jan.mspx</a><br />
<a href="https://blogs.technet.com/msrc/">https://blogs.technet.com/msrc/</a><br />
<a href="https://blogs.technet.com/swi/">https://blogs.technet.com/swi/</a></p>
<p><strong>Macintosh and Apple Software users</strong></p>
<p>Apple released<br />
Java for Mac OS X v10.5 Update 9 &#8211;  <span style="color: #ff0000">ISO   Recommended Critical</span><br />
Java for Mac OS X v10.6 Update 4 &#8211;  <span style="color: #ff0000">ISO   Recommended Critical</span><br />
iTunes 10.2 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span></p>
<p>For more information on Apple updates see, <a href="https://support.apple.com/kb/HT1222"></a></p>
<p><a href="https://support.apple.com/kb/HT1222">https://support.apple.com/kb/HT1222</a><br />
<a href="https://www.apple.com/support/security/guides/">https://www.apple.com/support/security/guides/<br />
</a></p>
<p><strong>Linux users</strong></p>
<p>The popular distributions all released updates for their respective      package repositories<br />
Redhat,  Fedora, Ubuntu, Debian, Gentoo, Slackware, Suse, etc.</p>
<p>As always, run your distro / package manager of choice on a regular     basis.</p>
<p>Current Distro Releases</p>
<p><a href="http://www.redhat.com/">RedHat Enterprise Linux 6</a><br />
<a href="http://fedoraproject.org/">Fedora 14</a><br />
<a href="http://www.ubuntu.com/">Ubuntu 10.10</a></p>
<p><strong>Browser Security</strong></p>
<p>More and more of the exploits are targeting web browsers.  Regardless     of what operating system you are running the web browser is the    biggest  open door into your system.<br />
All the major browsers released updated and patched versions this month.      Take a moment to verify that your browser is up to date.</p>
<p>Current browser versions:</p>
<p><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx">IE</a> &#8211; IE8  (8.0.6001.18702)<br />
<a href="http://www.mozilla.com/en-US/firefox/personal.html">Firefox</a> &#8211; 3.6.15<span style="color: #ff0000"> **new version </span><br />
<a href="http://www.apple.com/safari/">Safari</a> &#8211; 5.0.4  (7533.20.27)<span style="color: #ff0000"> </span> <span style="color: #ff0000"> **new version </span><br />
<a href="http://www.opera.com/">Opera</a> -11.01  (build 1190) <span style="color: #ff0000"> **new version </span><br />
<a href="http://www.google.com/chrome">Google Chrome</a> &#8211; 10.0.648.127  <span style="color: #ff0000"> **new  version </span></p>
<p><strong>Other Applications</strong></p>
<p>Adobe released</p>
<p>APSB11-01 Adobe Shockwave &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-02 Adobe Flash &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-03 Adobe Reader and Acrobat &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-04 Adobe Coldfusion &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span></p>
<p>- &#8211; -</p>
<p>Happy patching and we’ll see you next month.</p>
<p>**All UT Arlington Windows based assets should be registered with the     UTA domain and should receive critical MS patches automatically via     SCCM. If your device is not registered or not receiving patches  please    contact the OIT HelpDesk at 2-2208.</p>
<div id="_mcePaste" style="width: 1px;height: 1px;overflow: hidden">
<div class="O1" style="line-height: 90%;margin-top: 3.84pt;margin-bottom: 0pt;margin-left: 0.81in;text-indent: -0.31in;text-align: left;direction: ltr;vertical-align: baseline"><span style="font-size: 16pt"><span>–</span></span><span style="font-size: 16pt;font-family: Arial;color: black">Time Capsule and AirPort Base Station (802.11n) Firmware 7.5.2</span></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.uta.edu/security/2011/03/09/super-tuesday-summary-%e2%80%93-february-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tax Forms and Personal Data</title>
		<link>http://blog.uta.edu/security/2011/01/13/tax-forms-and-personal-data/</link>
		<comments>http://blog.uta.edu/security/2011/01/13/tax-forms-and-personal-data/#comments</comments>
		<pubDate>Thu, 13 Jan 2011 15:38:48 +0000</pubDate>
		<dc:creator>mfager</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://blog.uta.edu/security/?p=241</guid>
		<description><![CDATA[Today it was announced in the MavWire that you can claim your W-2.
However they left off one important point.
DO NOT EMAIL YOUR W-2 AFTER CLAIMING IT!
Your W-2 contains personal data that can be used to steal your identity, or even being used to complete a tax return in your name  before you file, leaving [...]]]></description>
			<content:encoded><![CDATA[<p>Today it was announced in the <a href="http://www.uta.edu/ucomm/internalcommunications/mavwire/">MavWire</a> that you can claim your W-2.</p>
<p>However they left off one important point.</p>
<p><span style="color: #ff0000">DO NOT EMAIL YOUR W-2 AFTER CLAIMING IT!</span></p>
<p>Your W-2 contains personal data that can be used to steal your identity, or even being used to complete a tax return in your name  before you file, leaving you with nothing.</p>
<p>Email is not a secure communication and can be intercepted and read by anybody.</p>
<p>Once you have claimed and downloaded your W2, please remember not to email it to yourself/someone else.  Email is not a secure protocol and your personal information (including your social security number) is easily read off of W2’s sent in email.  Instead, consider using <a href="https://mavspace.uta.edu">MavSpace</a> (<a href="https://mavspace.uta.edu">https://mavspace.uta.edu</a>) to store your W2, as it is secured and available from anywhere with internet access.  You can also save your W2 to a CD or flash drive if MavSpace is not a viable alternative for you.</p>
<p>Quote from the <a href="http://www.uta.edu/ucomm/internalcommunications/mavwire/">MavWire</a> for 13 Jan 2011.</p>
<h3>&#8220;W-2 forms available online</h3>
<p>The 2010 W-2 forms are now available on UTDirect. Access and print your W-2 from the <a href="https://utdirect.utexas.edu/payroll/w2/w2.WBX">Web</a>.</p>
<p>If you have not upgraded your UT EID security level, go to one of the following departments and show your driver&#8217;s license or passport:</p>
<ul>
<li>DEFINE Education, Accounting/Business Services, 219 W. Main, 2-2138</li>
<li>Employment and Staff Development, Continuing Education Workforce Building, 140 W. Mitchell, Room B200, 2-3461</li>
<li>Human Resources, Wetsel Building, 1225 W. Mitchell, Room 213, 2-5554</li>
<li>Payroll Services, Wetsel Building, 1225 W. Mitchell, Room 207, 2-5426</li>
</ul>
<p>If you do not claim your 2010 W-2 form on UTDirect by Jan. 27, Payroll Services will print and mail a copy to your home address. Contact Payroll Services at <a href="mailto:payroll@uta.edu">payroll@uta.edu</a> for more information.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.uta.edu/security/2011/01/13/tax-forms-and-personal-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Super Tuesday Summary – January 2011</title>
		<link>http://blog.uta.edu/security/2011/01/12/super-tuesday-summary-%e2%80%93-january-2011/</link>
		<comments>http://blog.uta.edu/security/2011/01/12/super-tuesday-summary-%e2%80%93-january-2011/#comments</comments>
		<pubDate>Wed, 12 Jan 2011 21:17:44 +0000</pubDate>
		<dc:creator>mfager</dc:creator>
				<category><![CDATA[Patches]]></category>

		<guid isPermaLink="false">http://blog.uta.edu/security/?p=233</guid>
		<description><![CDATA[The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release [...]]]></description>
			<content:encoded><![CDATA[<p>The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release their scheduled patches as well.  So     regardless of your OS of choice please check with your update service     for any new items.</p>
<p><strong>Microsoft Users</strong></p>
<p>Microsoft released two (2) patches this month.</p>
<p>One (1) of the patches is listed as critical and should be applied  immediately.</p>
<p>MS11-001 &#8211; <span style="color: #ff6600">Important  (medium)</span> &#8211; Vulnerability in Windows Backup Manager Could Allow Remote Code Execution (2478935)<br />
MS11-002 &#8211; <span style="color: #ff0000">Critical (high)</span> &#8211; Vulnerabilities in Microsoft Data Access Components Could Allow Remote Code Execution (2451910)</p>
<p>Microsoft also released the usual updates and signatures for the<br />
- Anti-Malware definitions for FCS and SE<br />
- Malicious Software Removal Tool<br />
- Outlook / Mail email junk filters</p>
<p>For more information on MS patches see,</p>
<p><a href="https://www.microsoft.com/technet/security/Bulletin/MS11-jan.mspx">https://www.microsoft.com/technet/security/Bulletin/MS11-jan.mspx</a><br />
<a href="https://blogs.technet.com/msrc/">https://blogs.technet.com/msrc/</a><br />
<a href="https://blogs.technet.com/swi/">https://blogs.technet.com/swi/</a></p>
<p><strong>Macintosh and Apple Software users</strong></p>
<p>Apple released<br />
Mac OS X v10.6.6 &#8211;  <span style="color: #ff0000">ISO   Recommended Critical</span><br />
Time Capsule and AirPort Base Station (802.11n) Firmware 7.5.2 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
QuickTime 7.6.9 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span></p>
<p>For more information on Apple updates see, <a href="https://support.apple.com/kb/HT1222"></a></p>
<p><a href="https://support.apple.com/kb/HT1222">https://support.apple.com/kb/HT1222</a><br />
<a href="https://www.apple.com/support/security/guides/">https://www.apple.com/support/security/guides/<br />
</a></p>
<p><strong>Linux users</strong></p>
<p>The popular distributions all released updates for their respective      package repositories<br />
Redhat,  Fedora, Ubuntu, Debian, Gentoo, Slackware, Suse, etc.</p>
<p>As always, run your distro / package manager of choice on a regular     basis.</p>
<p>Current Distro Releases</p>
<p><a href="http://www.redhat.com/">RedHat Enterprise Linux 6</a><br />
<a href="http://fedoraproject.org/">Fedora 14</a><br />
<a href="http://www.ubuntu.com/">Ubuntu 10.10</a></p>
<p><strong>Browser Security</strong></p>
<p>More and more of the exploits are targeting web browsers.  Regardless     of what operating system you are running the web browser is the    biggest  open door into your system.<br />
All the major browsers released updated and patched versions this month.      Take a moment to verify that your browser is up to date.</p>
<p>Current browser versions:</p>
<p><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx">IE</a> &#8211; IE8  (8.0.6001.18702)<br />
<a href="http://www.mozilla.com/en-US/firefox/personal.html">Firefox</a> &#8211; 3.6.13<span style="color: #ff0000"> **new version </span><br />
<a href="http://www.apple.com/safari/">Safari</a> &#8211; 5.0.2  (7533.19.4)<span style="color: #ff0000"> </span> <span style="color: #ff0000"> **new version </span><br />
<a href="http://www.opera.com/">Opera</a> -11.00  (build 1156) <span style="color: #ff0000"> **new version </span><br />
<a href="http://www.google.com/chrome">Google Chrome</a> &#8211; 8.0.552.224  <span style="color: #ff0000"> **new  version </span></p>
<p><strong>Other Applications</strong></p>
<p>Adobe released</p>
<p>APSB10-28 Adobe Reader and Acrobat &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-29 Adobe Illustrator CS5 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-30 Adobe PhotoShop CS5 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span></p>
<p>- &#8211; -</p>
<p>Happy patching and we’ll see you next month.</p>
<p>**All UT Arlington Windows based assets should be registered with the     UTA domain and should receive critical MS patches automatically via     SCCM. If your device is not registered or not receiving patches  please    contact the OIT HelpDesk at 2-2208.</p>
<div id="_mcePaste" style="width: 1px;height: 1px;overflow: hidden">
<div class="O1" style="line-height: 90%;margin-top: 3.84pt;margin-bottom: 0pt;margin-left: 0.81in;text-indent: -0.31in;text-align: left;direction: ltr;vertical-align: baseline"><span style="font-size: 16pt"><span>–</span></span><span style="font-size: 16pt;font-family: Arial;color: black">Time Capsule and AirPort Base Station (802.11n) Firmware 7.5.2</span></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.uta.edu/security/2011/01/12/super-tuesday-summary-%e2%80%93-january-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Super Tuesday Summary – November 2010</title>
		<link>http://blog.uta.edu/security/2010/11/11/super-tuesday-summary-%e2%80%93-november-2010/</link>
		<comments>http://blog.uta.edu/security/2010/11/11/super-tuesday-summary-%e2%80%93-november-2010/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 18:17:32 +0000</pubDate>
		<dc:creator>mfager</dc:creator>
				<category><![CDATA[Patches]]></category>

		<guid isPermaLink="false">http://blog.uta.edu/security/?p=225</guid>
		<description><![CDATA[The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release [...]]]></description>
			<content:encoded><![CDATA[<p>The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release their scheduled patches as well.  So     regardless of your OS of choice please check with your update service     for any new items.</p>
<p><strong>Microsoft Users</strong></p>
<p>Microsoft released three (3) patches this month.</p>
<p>One (1) of the patches is listed as critical and should be applied  immediately.</p>
<p>MS10-087 &#8211; <span style="color: #ff0000">Critical (high)</span> &#8211; Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930)<br />
MS10-088 &#8211; <span style="color: #ff6600">Important  (medium)</span> &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2293386)<br />
MS10-089 &#8211; <span style="color: #ff6600">Important  (medium)</span> &#8211; Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Elevation of Privilege (2316074)</p>
<p>Microsoft also released the usual updates and signatures for the<br />
- Anti-Malware definitions for FCS and SE<br />
- Malicious Software Removal Tool<br />
- Outlook / Mail email junk filters</p>
<p>For more information on MS patches see,</p>
<p><a href="https://www.microsoft.com/technet/security/Bulletin/MS10-jul.mspx">https://www.microsoft.com/technet/security/Bulletin/MS10-jul.mspx</a><br />
<a href="https://blogs.technet.com/msrc/">https://blogs.technet.com/msrc/</a><br />
<a href="https://blogs.technet.com/swi/">https://blogs.technet.com/swi/</a></p>
<p><strong>Macintosh and Apple Software users</strong></p>
<p>Apple released<br />
Security Update 2010-007 (OSX 10.6.5) &#8211;  <span style="color: #ff0000">ISO   Recommended Critical</span><br />
Java for Mac OS X 10.5 Update 8 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
Java for Mac OS X 10.6 Update 3 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span></p>
<p>For more information on Apple updates see, <a href="https://support.apple.com/kb/HT1222">https://support.apple.com/kb/HT1222</a><br />
<a href="https://www.apple.com/support/security/guides/">https://www.apple.com/support/security/guides/<br />
</a></p>
<p><strong>Linux users</strong></p>
<p>The popular distributions all released updates for their respective      package repositories<br />
Redhat,  Fedora, Ubuntu, Debian, Gentoo, Slackware, Suse, etc.</p>
<p>As always, run your distro / package manager of choice on a regular     basis.</p>
<p>New Distro Releases</p>
<p><a href="http://www.redhat.com/">RedHat Enterprise Linux 6</a><br />
<a href="http://fedoraproject.org/">Fedora 14</a><br />
<a href="http://www.ubuntu.com/">Ubuntu 10.10</a></p>
<p><strong>Browser Security</strong></p>
<p>More and more of the exploits are targeting web browsers.  Regardless     of what operating system you are running the web browser is the    biggest  open door into your system.<br />
All the major browsers released updated and patched versions this month.      Take a moment to verify that your browser is up to date.</p>
<p>Current browser versions:</p>
<p><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx">IE</a> &#8211; IE8  (8.0.6001.18702)<br />
<a href="http://www.mozilla.com/en-US/firefox/personal.html">Firefox</a> &#8211; 3.6.12<span style="color: #ff0000"> **new version </span><br />
<a href="http://www.apple.com/safari/">Safari</a> &#8211; 5.0.2  (7533.18.5)<span style="color: #ff0000"> </span><br />
<a href="http://www.opera.com/">Opera</a> -10.63  (build 3516) <span style="color: #ff0000"> **new version </span><br />
<a href="http://www.google.com/chrome">Google Chrome</a> &#8211; 7.0.517.44  <span style="color: #ff0000"> **new  version </span></p>
<p><strong>Other Applications</strong></p>
<p>Adobe released</p>
<p>APSB10-27 Adobe Flash Media Server &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-26 Adobe Flash Player &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-25 Adobe Shockwave Player &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSA10-05 Adobe Reader and Acrobat &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSA10-05 Adobe Shockwave Player &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span></p>
<p>- &#8211; -</p>
<p>Happy patching and we’ll see you next month.</p>
<p>**All UT Arlington Windows based assets should be registered with the     UTA domain and should receive critical MS patches automatically via     SCCM. If your device is not registered or not receiving patches  please    contact the OIT HelpDesk at 2-2208.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.uta.edu/security/2010/11/11/super-tuesday-summary-%e2%80%93-november-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Super Tuesday Summary – October 2010</title>
		<link>http://blog.uta.edu/security/2010/10/19/super-tuesday-summary-%e2%80%93-october-2010/</link>
		<comments>http://blog.uta.edu/security/2010/10/19/super-tuesday-summary-%e2%80%93-october-2010/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 16:55:36 +0000</pubDate>
		<dc:creator>mfager</dc:creator>
				<category><![CDATA[Patches]]></category>

		<guid isPermaLink="false">http://blog.uta.edu/security/?p=219</guid>
		<description><![CDATA[The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release [...]]]></description>
			<content:encoded><![CDATA[<p>The second Tuesday of the month has come and gone and with that we     have a several patches with which to follow-up.  Keep in mind “Super     Tuesday” though initiated by Microsoft has also become a popular day  for    other companies to release their scheduled patches as well.  So     regardless of your OS of choice please check with your update service     for any new items.</p>
<p><strong>Microsoft Users</strong></p>
<p>Microsoft released sixteen (16) patches this month.</p>
<p>Four (4) of the patches are listed as critical and should be applied  immediately.</p>
<p>MS10-071 &#8211; <span style="color: #ff0000">Critical (high)</span> -Cumulative Security Update for Internet Explorer (2360131)<br />
MS10-072 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerabilities in SafeHTML Could Allow Information Disclosure (2412048)<br />
MS10-073 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957)<br />
MS10-074 &#8211; <span style="color: #990099">Moderate (low)</span> &#8211; Vulnerability in Microsoft Foundation Classes Could Allow Remote Code Execution (2387149)<br />
MS10-075 &#8211; <span style="color: #ff0000">Critical (high)</span> &#8211; Vulnerability in Media Player Network Sharing Service Could Allow Remote Code Execution (2281679)<br />
MS10-076 &#8211; <span style="color: #ff0000">Critical (high)</span> &#8211; Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (982132)<br />
MS10-077 &#8211; <span style="color: #ff0000">Critical (high)</span> &#8211; Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841)<br />
MS10-078 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerabilities in the OpenType Font (OTF) Format Driver Could Allow Elevation of Privilege (2279986)<br />
MS10-079 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194)<br />
MS10-080 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2293211)<br />
MS10-081 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerability in Windows Common Control Library Could Allow Remote Code Execution (2296011)<br />
MS10-082 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111)<br />
MS10-083 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerability in COM Validation in Windows Shell and WordPad Could Allow Remote Code Execution (2405882)<br />
MS10-084 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerability in Windows Local Procedure Call Could Cause Elevation of Privilege (2360937)<br />
MS10-085 &#8211; <span style="color: #ff6600">Important  (medium)</span> -Vulnerability in SChannel Could Allow Denial of Service (2207566)<br />
MS10-086 &#8211; <span style="color: #990099">Moderate (low)</span> &#8211; Vulnerability in Windows Shared Cluster Disks Could Allow Tampering (2294255)</p>
<p>Microsoft also released the usual updates and signatures for the<br />
- Anti-Malware definitions for FCS and SE<br />
- Malicious Software Removal Tool<br />
- Outlook / Mail email junk filters</p>
<p>For more information on MS patches see,</p>
<p><a href="https://www.microsoft.com/technet/security/Bulletin/MS10-jul.mspx">https://www.microsoft.com/technet/security/Bulletin/MS10-jul.mspx</a><br />
<a href="https://blogs.technet.com/msrc/">https://blogs.technet.com/msrc/</a><br />
<a href="https://blogs.technet.com/swi/">https://blogs.technet.com/swi/</a></p>
<p><strong>Macintosh and Apple Software users</strong></p>
<p>Apple released<br />
Security Update 2010-006 (OSX 10.6.4) &#8211;  <span style="color: #ff0000">ISO   Recommended Critical</span><br />
QuickTime 7.6.8 &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span></p>
<p>For more information on Apple updates see, <a href="https://support.apple.com/kb/HT1222">https://support.apple.com/kb/HT1222</a><br />
<a href="https://www.apple.com/support/security/guides/">https://www.apple.com/support/security/guides/<br />
</a></p>
<p><strong>Linux users</strong></p>
<p>The popular distributions all released updates for their respective      package repositories<br />
Redhat,  Fedora, Ubuntu, Debian, Gentoo, Slackware, Suse, etc.</p>
<p>As always, run your distro / package manager of choice on a regular     basis.</p>
<p><strong>Browser Security</strong></p>
<p>More and more of the exploits are targeting web browsers.  Regardless     of what operating system you are running the web browser is the    biggest  open door into your system.<br />
All the major browsers released updated and patched versions this month.      Take a moment to verify that your browser is up to date.</p>
<p>Current browser versions:</p>
<p><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx">IE</a> &#8211; IE8  (8.0.6001.18702)</p>
<p><a href="http://www.mozilla.com/en-US/firefox/personal.html">Firefox</a> &#8211; 3.6.10<span style="color: #ff0000"> **new version </span></p>
<p><a href="http://www.apple.com/safari/">Safari</a> &#8211; 5.0.2  (7533.18.5)<span style="color: #ff0000"> **new version </span></p>
<p><a href="http://www.opera.com/">Opera</a> -10.63  (build 3445) <span style="color: #ff0000"> **new version </span></p>
<p><a href="http://www.google.com/chrome">Google Chrome</a> &#8211; 6.0.472.63  <span style="color: #ff0000"> **new  version </span></p>
<p><strong>Other Applications</strong></p>
<p>Oracle released <span style="color: #ff0000">85 critical</span> patches.</p>
<p>Adobe released<br />
APSB10-21 Security update for Adobe Reader and Acrobat &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-22 Security update for Adobe Flash Player &#8211;  <span style="color: #ff0000">ISO  Recommended Critical</span><br />
APSB10-23 Security update for RoboHelp<br />
APSB10-24 Security update for InDesign</p>
<p>- &#8211; -</p>
<p>Happy patching and we’ll see you next month.</p>
<p>**All UT Arlington Windows based assets should be registered with the     UTA domain and should receive critical MS patches automatically via     SCCM. If your device is not registered or not receiving patches  please    contact the OIT HelpDesk at 2-2208.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.uta.edu/security/2010/10/19/super-tuesday-summary-%e2%80%93-october-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Back to school and back in debt?</title>
		<link>http://blog.uta.edu/security/2010/09/09/back-to-school-and-back-in-debt/</link>
		<comments>http://blog.uta.edu/security/2010/09/09/back-to-school-and-back-in-debt/#comments</comments>
		<pubDate>Thu, 09 Sep 2010 19:22:21 +0000</pubDate>
		<dc:creator>jcordell</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.uta.edu/security/?p=216</guid>
		<description><![CDATA[Are you the kind of person who enjoys breaking things? (Other people&#8217;s things?)
As a youngster did you find yourself surrounded with broken toys because you just had to know how they work?
Do the words 2600, DMCA, side-jacking or  full disclosure mean anything to you?
If so, we may have the job for you &#8211; the ISO [...]]]></description>
			<content:encoded><![CDATA[<p>Are you the kind of person who enjoys breaking things? (Other people&#8217;s things?)</p>
<p>As a youngster did you find yourself surrounded with broken toys because you just had to know how they work?</p>
<p>Do the words 2600, DMCA, side-jacking or  full disclosure mean anything to you?</p>
<p>If so, we may have the job for you &#8211; the ISO has two student worker positions open.  We&#8217;re looking for motivated students who are interested in computer security.  This is a rare opportunity to gain real experience as part of a small team in a large and diverse environment.</p>
<p>Primary job duties include:</p>
<p>Corresponding with clients and administrators via email and phone to remediate security work orders.</p>
<p>Creating, tracking and coordinating resolution of information security related work orders.</p>
<p>Other job duties may include:</p>
<p>Patch installation, malware removal and system recovery.</p>
<p>Creating informational documents and technical instructions.</p>
<p>Prospective individuals must:</p>
<p>Have reliable transportation.  Office is located in Fort Worth, 10 miles from main campus.</p>
<p>Pass a criminal background check.  This is a security sensitive position.</p>
<p>If you are interested, apply through SNAP Jobs at <a href="https://www.myinterfase.com/utahr/student/">https://www.myinterfase.com/utahr/student/</a> before September 14, 2010.  The job number &amp; title is 4907/Assistant Security Technician (Fort Worth).  Any questions about this job can be sent to <a href="mailto:security@uta.edu">security@uta.edu</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.uta.edu/security/2010/09/09/back-to-school-and-back-in-debt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
