<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CISS Inc. &#124; Canadian Information Security Solutions</title>
	<atom:link href="http://www.ciss-inc.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ciss-inc.com</link>
	<description>Canadian Information Security Solutions &#124; Official Website</description>
	<lastBuildDate>Wed, 22 Feb 2012 04:27:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Microsoft says Google bypassing IE security too</title>
		<link>http://www.ciss-inc.com/uncategorized/microsoft-says-google-bypassing-ie-security-too/</link>
		<comments>http://www.ciss-inc.com/uncategorized/microsoft-says-google-bypassing-ie-security-too/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 04:27:51 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsfot]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/uncategorized/microsoft-says-google-bypassing-ie-security-too/</guid>
		<description><![CDATA[Microsoft says it has discovered evidence that Google is bypassing security settings in Internet Explorer in order to track users&#8217; movements. The controversy comes less than a week after Google, Facebook and other advertising networks were caught circumnavigating users&#8217; privacy settings on Apple&#8217;s Safari and Safari Mobile browser. Microsoft had initially reacted to the news [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft says it has discovered evidence that Google is bypassing security settings in Internet Explorer in order to track users&#8217; movements.</p>
<p>The controversy comes less than a week after <a href="http://www.techradar.com/news/internet/web/google-and-facebook-bypassing-safari-security-1064088">Google, Facebook and other advertising networks</a> were caught circumnavigating users&#8217; privacy settings on Apple&#8217;s Safari and Safari Mobile browser.</p>
<p>Microsoft had initially reacted to the news by trumpeting IE9s safety, but a <a href="http://blogs.msdn.com/b/ie/archive/2012/02/20/google-bypassing-user-privacy-settings.aspx">blog post on Monday</a> revealed its users had also fallen victim to the snooping, albeit in a slightly different way.</p>
<h3>Stating intent</h3>
<p>&#8220;Google is employing similar methods (to what it employed with Safari) to get around the default privacy protections in IE  and track IE users with cookies,&#8221; said IE boss Dean Hachamovitch.</p>
<p>&#8220;We&#8217;ve also contacted Google and asked  them to commit to honoring P3P privacy settings for users of all  browsers.</p>
<p>&#8220;IE blocks third-party cookies unless the site presents a P3P Compact  Policy Statement indicating how the site will use the cookie and that  the site&#8217;s use does not include tracking the user. </p>
<p>&#8220;Google&#8217;s P3P policy  causes Internet Explorer to accept Google&#8217;s cookies even though the  policy does not state Google&#8217;s intent.&#8221;</p>
<h3>Fix in place</h3>
<p>While it waits for Google to respond, Microsoft already has a fix in place for IE9 users who want to <a href="http://blogs.msdn.com/b/ie/archive/2012/02/20/google-bypassing-user-privacy-settings.aspx">protect themselves</a> from the tracking.</p>
<p>Microsoft also said it is looking into reports that Facebook is guilty of the same tracking technique.</p>
<p>Google <a href="http://www.techradar.com/news/internet/google-hits-back-over-safari-cookie-hoarding-claims-1064305">responded to the claims</a> on Friday, claiming it was not harvesting personal information, but simply establishing which users were signed into Google.</p>
<p>&#8220;Microsoft omitted important information from its blog post today,&#8221; wrote Google&#8217;s Rachel Whetstone later. &#8220;Microsoft uses a &#8220;self-declaration&#8221; protocol (known as &#8220;P3P&#8221;) dating from 2002 under which Microsoft asks websites to represent their privacy practices in machine-readable form. </p>
<p>&#8220;It is well known &#8211; including by Microsoft &#8211; that it is impractical to comply with Microsoft&#8217;s request while providing modern web functionality. We have been open about our approach, as have many other websites.<br /> &#8220;Today the Microsoft policy is widely non-operational.</p>
<p>&#8220;A 2010 research report indicated that over 11,000 websites were not issuing valid P3P policies as requested by Microsoft.&#8221;</p>
<p>It&#8217;s an argument that is likely to run and run, but many will ask whether these public spats are ever really going to be acting in the best interest of the actual users rather than for political point scoring. </p>
<p class="webonly">Via: <a href="http://www.zdnet.com/blog/microsoft/microsoft-google-bypassed-privacy-settings-in-ie-too/11944">Zdnet</a></p>
<p>Article source: <a href="http://www.techradar.com/news/internet/microsoft-says-google-bypassing-ie-security-too-1064918?src=rss">http://www.techradar.com/news/internet/microsoft-says-google-bypassing-ie-security-too-1064918?src=rss</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/uncategorized/microsoft-says-google-bypassing-ie-security-too/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Attacks Google Apps Via &#8216;Googlighting&#8217; Video</title>
		<link>http://www.ciss-inc.com/uncategorized/microsoft-attacks-google-apps-via-googlighting-video/</link>
		<comments>http://www.ciss-inc.com/uncategorized/microsoft-attacks-google-apps-via-googlighting-video/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 04:27:49 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsfot]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/uncategorized/microsoft-attacks-google-apps-via-googlighting-video/</guid>
		<description><![CDATA[One day after Microsoft accused Google of bypassing cookie-related security features in its Internet Explorer browser, a Redmond-backed video has surfaced that attacks Google Apps. The video, dubbed &#8220;Googlighting,&#8221; channels the 80s TV show Moonlighting and was uploaded to YouTube by Microsoft yesterday. It features an over-confident salesman clad in a white suit and a [...]]]></description>
			<content:encoded><![CDATA[<p><span></p>
<p>One day after <a class="" href="http://www.pcmag.com/article2/0,2817,2400479,00.asp">Microsoft accused Google</a> of bypassing cookie-related security features in its Internet Explorer browser, a Redmond-backed video has surfaced that attacks Google Apps.</p>
<p>The video, dubbed &#8220;Googlighting,&#8221; channels the 80s TV show <i>Moonlighting</i> and was uploaded to YouTube by Microsoft yesterday. It features an over-confident salesman clad in a white suit and a multi-colored tie reminiscent of the Google logo. He arrives late to a pitch meeting and makes a rather half-assed attempt to sell Google Apps.</p>
<p>&#8220;Wait, you want us to be your lab rats?&#8221; a female executive asks the Google pitchman after he proposes rolling out Google Apps across her entire company. &#8220;Pioneer,&#8221; he interjects.</p>
<p>Her line of questioning then attacks features Microsoft considers to be lacking in Google Apps, from spell check and sufficient offline access to frequent software updates.</p>
<p>&#8220;I could come to work and the software could be different than the day before?&#8221; the female exec asks.</p>
<p>&#8220;Different, better, completely gone, who knows what the future holds for Google Apps?&#8221; the Google employee responds.</p>
<p>A singer then emerges from the corner to suggest that Google&#8217;s recent <a class="" href="http://www.pcmag.com/article2/0,2817,2392394,00.asp">house-cleaning efforts</a> might ultimately result in the demise of Google Apps. The search giant killed off Gears, Wave, and Buzz &#8211; why not Google Apps? &#8220;If Google Apps meets its grave, your business is hosed,&#8221; the singer croons.</p>
<p>&#8220;Beware the Googlighting Stranger,&#8221; the ad ends.</p>
<p>This is not the first time Microsoft has attacked Google in video form. In July, the Microsoft Office 365 team <a class="" href="http://www.pcmag.com/article2/0,2817,2389379,00.asp">created a spoof video</a> for its sales conference that poked fun at Gmail. &#8220;Gmail Man&#8221; featured an unctuous, cloying mail carrier who looked through people&#8217;s correspondence to identify &#8220;keywords&#8221; for advertising opportunities.</p>
<p>The ad comes as Google is moving in on Microsoft&#8217;s business, offering businesses cloud-based services that are cheaper than Microsoft&#8217;s suite of offerings &#8211; switch out Exchange for Gmail and Apps for Office, for example. Microsoft, however, has hit back on issues of security and reliability. Google, meanwhile, has also gone after Microsoft Windows with its <a class="" href="http://www.pcmag.com/article2/0,2817,2398777,00.asp">Chromebook line</a> of Web-based notebooks.</p>
<p>For more, see <a class="" href="http://www.pcmag.com/article2/0,2817,2387711,00.asp">Why Choose Google Apps Over Office 365? Cost and Fun, Customer Says</a>.</p>
<p><!-- HTML MODULE 3762 -->
<p><i>For more from Chloe, follow her on Twitter <a href="http://twitter.com/ChloeAlbanesius" target="_blank">@ChloeAlbanesius</a>.</i></p>
<p><!-- HTML MODULE 3748 -->
</p>
<p><b><i>For the top stories in tech, follow us on Twitter at <a href="http://twitter.com/pcmag" target="_blank">@PCMag</a>.</i></b><br />
			</span></p>
<p>Article source: <a href="http://www.pcmag.com/article2/0,2817,2400518,00.asp">http://www.pcmag.com/article2/0,2817,2400518,00.asp</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/uncategorized/microsoft-attacks-google-apps-via-googlighting-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FishNet Security Collaborates With Microsoft to Deliver Identity Access and Management for Healthcare</title>
		<link>http://www.ciss-inc.com/uncategorized/fishnet-security-collaborates-with-microsoft-to-deliver-identity-access-and-management-for-healthcare/</link>
		<comments>http://www.ciss-inc.com/uncategorized/fishnet-security-collaborates-with-microsoft-to-deliver-identity-access-and-management-for-healthcare/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 04:27:49 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsfot]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/uncategorized/fishnet-security-collaborates-with-microsoft-to-deliver-identity-access-and-management-for-healthcare/</guid>
		<description><![CDATA[KANSAS CITY, MO — FishNet Security announced today it will collaborate with Microsoft Corp. to provide new software functionality that enables health system customers to provision clinical applications through Microsoft Forefront Identity Manager 2010 (FIM 2010). &#8220;For healthcare providers, the integration between identity management platforms and clinical applications plays an important role in improving caregiver effectiveness,&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p class="i1">
<p><span class="dateline"><a href="http://www.bing.com/maps/?v=2where1=KANSAS CITY, MOsty=hform=msdate" target="_blank">KANSAS CITY, MO</a> — </span><br />
  FishNet Security announced today it will collaborate with Microsoft Corp. to provide new software functionality that enables health system customers to provision clinical applications through Microsoft Forefront Identity Manager 2010 (FIM 2010).</p>
<p>
&#8220;For healthcare providers, the integration between identity management platforms and clinical applications plays an important role in improving caregiver effectiveness,&#8221; said Phil Lentz, chief identity strategist at FishNet Security. &#8220;Efficiencies are a result of fewer IDs and passwords, &#8216;zero day&#8217; account set-up for newly hired caregivers, enablement of caregivers to reset their own passwords, and the establishment of the correct clinical system access demanded by a caregiver&#8217;s job responsibilities.&#8221;
</p>
<p>
FishNet Security is developing the Clinical Application Resource Extension (CARE) to connect the capabilities of proVision, acquired from Sentillion, with FIM 2010. Healthcare organizations soon will be able to use FishNet Security&#8217;s CARE to automate the provisioning of users&#8217; accounts and access entitlements to key healthcare applications.
</p>
<p>
The accelerated adoption of IAM solutions in the healthcare sector has been spurred by HITECH  ARRA, with the desire to best align with Meaningful Use and specifically address the increased HIPAA security requirements. In addition to regulatory alignment and caregiver benefits, maturing the security posture through IAM can help reduce user administration costs through automation and self-service.
</p>
<p>
&#8220;We&#8217;re pleased to collaborate with FishNet Security to ensure health systems can easily apply the power of FIM, an enterprise-class identity and access management solution, to their unique health IT environments,&#8221; said Nate McLemore, general manager, Microsoft health solutions group. &#8220;Hospital IT departments will be able to easily provision user accounts to the applications their caregivers rely on most while benefitting from the scale and self-service benefits of FIM.&#8221;
</p>
<p>
Earl Perkins, research vice president in the Security and Privacy group at Gartner, said: &#8220;Enterprises in healthcare delivery frequently have manual processes for creating identities that depend upon phone calls, emails, spreadsheets and other ad hoc tools. Recording and delivering an audit trail for these processes is very complex. An integrated IAM platform can provide transparency to the fulfillment process and go far in reducing security risks, avoiding delays in receiving vital access to resources, and improving overall productivity of IT and the business.&#8221;
</p>
<p>
While healthcare providers continue to leverage IAM platforms to improve organizational and clinical performance, further value in IAM is being found in support of the acquisition trends of physician groups. In addition to growth, healthcare providers are attempting to mature infrastructure and prepare for future cloud-based applications adoption. Combining these business drivers to an already challenging regulatory compliance roadmap further supports the strategic relationship between FishNet Security and Microsoft.
</p>
<p>
The development effort for FishNet Security&#8217;s CARE is underway and those considering adoption are encouraged to begin the planning process now. This will help providers address the &#8220;last mile&#8221; of user management, extending the value of FIM to such applications as EMR, CPOE, PACS and clinician portals.
</p>
<p><em>About FishNet Security<br />
<br /></em>FishNet Security is the No. 1 provider of information security solutions that combine technology, services, support and training. Since 1996, the company has enabled clients to manage risk, meet compliance requirements and reduce costs while maximizing security effectiveness and operational efficiency. FishNet Security is committed to information security excellence and has a track record of delivering quality solutions to over 5,000 clients nationwide. For more information about FishNet Security, visit <a href="http://ctt.marketwire.com/?release=853324id=1279465type=1url=http://www.fishnetsecurity.com/">www.fishnetsecurity.com</a>, <a href="http://ctt.marketwire.com/?release=853324id=1279468type=1url=http://www.facebook.com/fishnetsecurity">www.facebook.com/fishnetsecurity</a> and <a href="http://ctt.marketwire.com/?release=853324id=1279471type=1url=http://www.twitter.com/fishnetsecurity">www.twitter.com/fishnetsecurity</a>.</p>
<p><span class="copyright"></p>
<p><em>© Marketwire 2012</em></p>
<p></span></p>
<p><span class="extshare hlist"></p>
<p></span></p>
<p>Article source: <a href="http://www.msnbc.msn.com/id/46452638">http://www.msnbc.msn.com/id/46452638</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/uncategorized/fishnet-security-collaborates-with-microsoft-to-deliver-identity-access-and-management-for-healthcare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>State Officials Have Concerns About &quot;Secure Communities”</title>
		<link>http://www.ciss-inc.com/it-security-news/state-officials-have-concerns-about-secure-communities/</link>
		<comments>http://www.ciss-inc.com/it-security-news/state-officials-have-concerns-about-secure-communities/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 04:18:51 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[IT Security News]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/it-security-news/state-officials-have-concerns-about-secure-communities/</guid>
		<description><![CDATA[advertisement On Wednesday, the federal Department of Homeland Security’s “Secure Communities” program begins statewide in Connecticut and some state officials have concerns about it. “Secure Communities” calls for state and local law enforcement agencies automatically share fingerprints with the U.S. Department of Homeland Security so Immigration and Customs Enforcement can check information against DHS immigration [...]]]></description>
			<content:encoded><![CDATA[<p>               <!--endclickprintinclude--> </p>
<p>        <span class="advertHead">advertisement</span></p>
<p><!-- // start nbc_ad_300_250 \ --></p>
<p>   <a href="http://iv.doubleclick.net/jump/nbcu.lim.har/news-local-article;!category=har;!category=news;!category=;site=har;pid=;sect=news;sub=local;sub2=;contentid=139720183;contentgroup=;kw=;mtfIFPath=/includes/;tile=3;pos=1;sz=300x250,300x600;ord=123456a?" target="_blank"><img src="http://www.ciss-inc.com/wp-content/plugins/rss-poster/cache/7b6a2_%3Btile%3D3%3Bpos%3D1%3Bsz%3D300x250%2C300x600%3Bord%3D123456a" border="0" alt="Click Here!" /></a></p>
<p><!-- \ end nbc_ad_300_250 // --></p>
<p>                                <!--startclickprintinclude--></p>
<p>On Wednesday, the federal Department of Homeland Security’s “Secure Communities” program begins statewide in Connecticut and some state officials have concerns about it.</p>
<p>“Secure Communities” calls for state and local law enforcement agencies automatically share fingerprints with the U.S. Department of Homeland Security so Immigration and Customs Enforcement can check information against DHS immigration databases.</p>
<p>“What this program does is it essentially converts local law enforcement officers into defacto agents of the Immigration and Customs Enforcement Agency,” Mike Lawlor, Under Secretary for Criminal Justice Policy and Planning, said in a statement.</p>
<p><a target="_blank" href="http://www.dhs.gov/xlibrary/assets/hsac-task-force-on-secure-communities.pdf">A report from U.S. Department of Homeland Securit</a>y said the goal of the program is to strengthen the federal government’s ability to target criminals and ensure that resources are not focused on &#8220;low-priorities,&#8221; such as deporting young people who were brought to this country as young children.</p>
<p>Lawlor said Gov. Dannel Malloy shared the concerns that many police chiefs have that the policy could lead to a situation in which victims and witnesses in an immigrant community would be reluctant to cooperate with local and state law enforcement.</p>
<p>In response, Malloy has asked Leo Arnone, the Department of Corrections Commissioner, to review how the program is implemented, what the ramifications are and see if corrective action is needed going forward.</p>
<p>“Decisions on how to respond to each request will be made on a case-by-case basis,” Lawlor said. “As the report itself says: ‘DHS must ensure its immigration enforcement resources are focused on the removal of those who constitute our highest priorities, specifically individuals who pose a threat to public safety such as criminal aliens and national security threats, as well as repeat immigration law violators and recent border entrants. In fact, the expenditure of resources on cases that fall outside our enforcement priorities hinders our public safety mission by clogging immigration court dockets and diverting resources . . . .’”</p>
<p>The program begins just a week after the federal government settled with 11 men who were arrested in a series of ICE raids in 2007 in New Haven.  Legal aides for the men said the raids were done without warrants or consent, and were illegal.</p>
<p>Federal authorities said Monday that the program is meant to take dangerous people off the streets.</p>
<p>&#8220;Secure communities promotes the agency&#8217;s top enforcement priority of finding and removing those who are unlawfully present or otherwise removable and have criminal convictions by relying on an already-existing federal information-sharing program,&#8221; said Ross Feinstein, of Immigration and Customs Enforcement.</p>
<p>New Haven Mayor John DeStefano called on ICE to delay implementing the program.</p>
<p>&#8220;The same thing that they said to us in June of 2007, when we had the raids, was exactly that class of the worst of the worst.  Of those that were picked up, they had one common characteristic: they were brown,&#8221; DeStefano said.</p>
<h5 class="copyright">
</h5>
<p>Article source: <a href="http://www.nbcconnecticut.com/news/local/State-Officials-Have-Concerns-About-Secure-Communities--139720183.html">http://www.nbcconnecticut.com/news/local/State-Officials-Have-Concerns-About-Secure-Communities--139720183.html</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/it-security-news/state-officials-have-concerns-about-secure-communities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CORRECTING and REPLACING DriveSavers Highlights Risks of Data Breaches as &#8230;</title>
		<link>http://www.ciss-inc.com/it-security-news/correcting-and-replacing-drivesavers-highlights-risks-of-data-breaches-as/</link>
		<comments>http://www.ciss-inc.com/it-security-news/correcting-and-replacing-drivesavers-highlights-risks-of-data-breaches-as/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 04:18:51 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[IT Security News]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/it-security-news/correcting-and-replacing-drivesavers-highlights-risks-of-data-breaches-as/</guid>
		<description><![CDATA[LAS VEGAS, Feb 20, 2012 (BUSINESS WIRE) &#8211; Please replace the release with the following corrected version due to multiple revisions. The corrected release reads: DRIVESAVERS HIGHLIGHTS RISKS OF DATA BREACHES AS HEALTHCARE GOES DIGITAL Data breach vulnerabilities overlooked when PHI data disclosed to hospital &#8220;Business Associates&#8221; HIMSS12, Booth #13521&#8211;DriveSavers Data Recovery, the worldwide leader [...]]]></description>
			<content:encoded><![CDATA[<p>		<img src="http://www.ciss-inc.com/wp-content/plugins/rss-poster/cache/7b6a2_PR-Logo-Businesswire.gif" /></p>
<p><!-- Methode filePath: "" -->
<p class="">
</p>
<p class="">
</p>
<p class="">
<p>LAS VEGAS, Feb 20, 2012 (BUSINESS WIRE) &#8211;<br />
Please replace the release with the following corrected version due to<br />
      multiple revisions.</p>
<p class="">
<p>The corrected release reads:</p>
<p class="">
<p>DRIVESAVERS HIGHLIGHTS RISKS OF DATA BREACHES AS HEALTHCARE GOES<br />
      DIGITAL</p>
<p class="">
<p>Data breach vulnerabilities overlooked when PHI data disclosed to<br />
      hospital &#8220;Business Associates&#8221;</p>
<p class="">
<p>HIMSS12, Booth #13521&#8211;DriveSavers Data Recovery, the worldwide leader<br />
      in data recovery<br />
      services, announced today risks that healthcare organizations should be<br />
      aware of when using third party data recovery service providers that are<br />
      not HIPAA compliant or not properly vetted for security protocols. As<br />
      the healthcare industry rapidly becomes digitized, the risks of data<br />
      breach are unprecedented. In 2011, health data breaches in the US<br />
      increased 97 percent over the year before, according to a recent report<br />
      by Redspin,<br />
      a leading provider of IT security assessments. Data breaches cost the<br />
      healthcare industry an estimated $6.5 billion last year. Redspin cites<br />
      insufficient oversight of PHI (protected health information) disclosed<br />
      to hospital &#8220;business associates&#8221; (third party vendors) as one of the<br />
      main reasons for the increase.</p>
<p class="">
<p>According to HIPAA federal law, the legal burden of protecting patient<br />
      data while at a business associate, falls on the health organization<br />
      that contracted the service with that business. Therefore, if a data<br />
      breach occurs while PHI data is being recovered at a third party data<br />
      recovery service provider, the healthcare organization that contracted<br />
      the service is responsible for what could turn out to be a very costly,<br />
      reportable data breach.</p>
<p class="">
<p>How Healthcare Organizations may be Vulnerable to Data Breaches Using<br />
      Data Recovery</p>
<p class="">
<p>There are several areas where a healthcare organization&#8217;s PHI records<br />
      may be vulnerable to data breach when using a data recovery service<br />
      provider.</p>
<p class="">
<p>&#8211;<br />
        Risk of permanent data loss if software tools are used improperly or<br />
        the device is not opened in a ISO-5 cleanroom and media platters are<br />
        exposed to airborne contaminants</p>
<p class="">
<p>&#8211;<br />
        Risk of improper downloading or ID theft of PHI data</p>
<p class="">
<p>&#8211;<br />
        Risk of outside breach from hackers if data is stored on an<br />
        unprotected network</p>
<p class="">
<p>&#8211;<br />
        Risk of PHI data exposure if damaged drives are not destroyed with a<br />
        DoD approved degausser or shredder</p>
<p class="">
<p>&#8211;<br />
        Risk of viruses or malware being returned on new drive with recovered<br />
        data</p>
<p class="">
<p>The consequence of using a data recovery vendor that does not have<br />
      proper protocols in place to protect PHI can lead to loss or theft of<br />
      sensitive and confidential information. As a result, the healthcare<br />
      organization could suffer major disruption in business, huge financial<br />
      and legal fees, damaged brand name, firing of management, IT staff and<br />
      IT security involved in data recovery selection process and in some<br />
      cases, a complete shut down.</p>
<p class="">
<p>NYC Hospital Properly Vets Data Recovery Firm and Safely Recovers<br />
      200,000 Patient Records</p>
<p class="">
<p>Healthcare organizations that have policy and guidelines in place for<br />
      selecting and using data recovery service providers can avoid the risks<br />
      of a data breach. A large public hospital in New York City had a RAID 5<br />
      server fail due to mechanical failure. The server stored the hospital&#8217;s<br />
      database of over 200,000 patient records.</p>
<p class="">
<p>Knowing that healthcare organizations must meet the most stringent data<br />
      security guidelines by law, the NYC hospital&#8217;s IT team thoroughly<br />
      vetted their prospective business associate, DriveSavers, to ensure that<br />
      the company adhered to HIPAA<br />
      Data Security Guidelines before sending PHI data to their<br />
      facilities. DriveSavers has achieved compliance with the data security<br />
      standards outlined in the Health Insurance Portability and<br />
      Accountability Act (HIPAA).</p>
<p class="">
<p>DriveSavers successfully recovered the hospital&#8217;s PHI data in a<br />
      Certified ISO 5 cleanroom that has been audited and certified to meet<br />
      ISO 14644-1 standards. Engineers and employees at DriveSavers have all<br />
      undergone background checks. The data recovered was stored on the<br />
      company&#8217;s certified secure network, which is audited annually as part of<br />
      a SAS<br />
      70 Type II certification process. The hospital&#8217;s IT team received<br />
      the restored data on a new storage device; the old, damaged drive was<br />
      permanently and securely degaussed following HIPAA guidelines for<br />
      destroying hard drives.</p>
<p class="">
<p>DriveSavers is leading the data recovery market by investing in<br />
      technology, research, equipment, new facilities and training so that it<br />
      meets the rigorous security demands of the healthcare industry. In<br />
      addition to being compliant with HIPAA Data Security Guidelines and<br />
      undergoing annual SAS 70 Type II audits, the company also adheres to US<br />
      Government security protocols, the Gramm-Leach-Bliley Act Data Security<br />
      Rule (GLBA), the Data-At-Rest mandate (DAR) and the Sarbanes-Oxley Act<br />
      (SOX). DriveSavers engineers have received certifications for completing<br />
      extensive training programs from leading encryption software vendors,<br />
      including GuardianEdge, PGP, Pointsec (Check Point Software Technology)<br />
      and Utimaco.</p>
<p class="">
<p>DriveSavers can successfully recover lost data from encrypted hardware,<br />
      software, email, network files, wireless device data and all<br />
      storage/backup devices. Companies that have trusted DriveSavers with<br />
      their critical data include: CompuCom Systems, Inc., eBay, NASA, Weill<br />
      Cornell Medical Center and UCLA Medical Center.</p>
<p class="">
<p>About DriveSavers</p>
<p class="">
<p>DriveSavers Data<br />
      Recovery, the worldwide leader in data recovery services, provides<br />
      the fastest, most reliable and only certified secure data recovery<br />
      service in the industry. DriveSavers is the only data recovery company<br />
      to post proof of annual company-wide SAS<br />
      70 Type II Audit Reports, the Corporate Industry&#8217;s standard for an<br />
      overall control structure. DriveSavers High Security Service adheres to<br />
      US Government security protocols to ensure that no data is ever<br />
      compromised during the data recovery process. DriveSavers maintains the<br />
      most technologically advanced Certified<br />
      ISO 5 (Class 100) cleanroom in the industry and is authorized to<br />
      open drives by all major storage device manufacturers without voiding<br />
      the warranty. DriveSavers engineers recover lost data from all storage<br />
      devices and all operating systems and are trained and certified in all<br />
      leading encryption and forensic technologies. Satisfied customers<br />
      include: Bank of America, Google, Lucasfilm, NASA, Harvard University,<br />
      Salvation Army and The Rolling Stones. (<br />
http://www.drivesaversdatarecovery.com    )</p>
<p class="">
<p>SOURCE: DriveSavers Data Recovery</p>
<pre>

        BLASTmedia for DriveSavers
        Molly Noonan, 317-806-1900 ext. 110
        Molly_noonan@blastmedia.com
</pre>
<p class="">
<p>Copyright Business Wire 2012<br />
                    <span class="endsquare" /></p>
<p class="emphasis">
<p>			<img src="http://www.ciss-inc.com/wp-content/plugins/rss-poster/cache/7b6a2_comtexsmall.jpg" alt="Comtex" /></p>
<p>Article source: <a href="http://www.marketwatch.com/story/correcting-and-replacing-drivesavers-highlights-risks-of-data-breaches-as-healthcare-goes-digital-2012-02-20">http://www.marketwatch.com/story/correcting-and-replacing-drivesavers-highlights-risks-of-data-breaches-as-healthcare-goes-digital-2012-02-20</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/it-security-news/correcting-and-replacing-drivesavers-highlights-risks-of-data-breaches-as/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BeyondTrust Selects the Votacall VoIP Platform for Secure, Reliable and &#8230;</title>
		<link>http://www.ciss-inc.com/it-security-news/beyondtrust-selects-the-votacall-voip-platform-for-secure-reliable-and/</link>
		<comments>http://www.ciss-inc.com/it-security-news/beyondtrust-selects-the-votacall-voip-platform-for-secure-reliable-and/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 04:18:50 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[IT Security News]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/it-security-news/beyondtrust-selects-the-votacall-voip-platform-for-secure-reliable-and/</guid>
		<description><![CDATA[BOSTON, MA, Feb 20, 2012 (MARKETWIRE via COMTEX) &#8211; Votacall, the leading VoIP and cloud-based Unified Communications Provider (UC), today announced that BeyondTrust, a global leader in perimeter based IT security software with offices in California, Washington, Massachusetts and the UK, has selected the Votacall VoIP platform to deliver reliable voice communications amongst locations and [...]]]></description>
			<content:encoded><![CDATA[<p>		<img src="http://www.ciss-inc.com/wp-content/plugins/rss-poster/cache/2d24e_PR-Logo-Marketwire.gif" /></p>
<p><!-- Methode filePath: "" -->
<p class="">
</p>
<p class="">
<p>BOSTON, MA, Feb 20, 2012 (MARKETWIRE via COMTEX) &#8211;<br />
Votacall, the leading VoIP and cloud-based Unified Communications<br />
Provider (UC), today announced that BeyondTrust, a global leader in<br />
perimeter based IT security software with offices in California,<br />
Washington, Massachusetts and the UK, has selected the Votacall VoIP<br />
platform to deliver reliable voice communications amongst locations<br />
and complete solution management while decreasing telecom expenses.<br />
Designed, implemented and managed by All Business Communications, the<br />
Votacall VoIP solution provides the scalability necessary to promote<br />
the organizations&#8217; growth plan while cost effectively addressing<br />
future collaboration needs across the corporate landscape.</p>
<p class="">
<p>BeyondTrust is a security software company which has developed<br />
products that enable IT administrators to eliminate the risk of<br />
intentional, accidental and indirect misuse of privileges on desktops<br />
and servers.</p>
<p class="">
<p>BeyondTrust was utilizing legacy PBX platforms with maintenance<br />
contracts at each office and was considering entering into a contract<br />
for data services to connect all locations seamlessly. This crucial<br />
business communications initiative would have increased the<br />
organization&#8217;s telecommunications expenses by more than 30%. This is<br />
when BeyondTrust was introduced to the Votacall Hosted VoIP Platform.</p>
<p class="">
<p>&#8220;We needed a solution that would be secure, robust and provide a<br />
consistently high quality voice experience,&#8221; said Jay Kaffai,<br />
Director of Information Technology. &#8220;It was also critical that we<br />
could roll out new locations and scale our operations quickly. The<br />
provisioning process for a new location would have taken months with<br />
our old on-premise solution &#8212; with Votacall the process is measured<br />
in days and weeks.&#8221;</p>
<p class="">
<p>Being a security software company, BeyondTrust required that Votacall<br />
have redundant platforms housed in geographically diverse<br />
carrier-class data centers backed by state of the art security tools<br />
to provide the most reliable and secure customer experience. &#8220;As is<br />
the case with most businesses, the phones just need to work. We have<br />
not had any disruptions in service since migrating to the Votacall<br />
platform nearly six months ago. Any anxiety that I had moving such a<br />
business critical service to a hosted platform has been put to rest<br />
thanks to Votacall,&#8221; adds Kaffai.</p>
<p class="">
<p>The Votacall VoIP platform delivers enterprise level functionality,<br />
reliability and ultimate redundancy with a guarantee of absolute<br />
investment protection. Our mission is to enhance the end-user<br />
communications experience now and into the future. Votacall will be<br />
the last telecommunications decision you will ever make, innovate and<br />
communicate with Votacall.</p>
<p class="">
<p>About BeyondTrust<br />
 Founded in 1985, BeyondTrust is the global leader<br />
in privilege authorization management, access control and security<br />
solutions for physical, virtual, cloud and infrastructure computing<br />
environments. The company&#8217;s products mitigate insider threats and<br />
secure the perimeter within across the enterprise, empowering IT<br />
governance to strengthen security, improve productivity, drive<br />
compliance and reduce expense. More than half of the companies listed<br />
on the Dow Jones Industrial Average rely on BeyondTrust&#8217;s PowerBroker<br />
suite of products to secure their enterprises. Five of the top ten<br />
commercial banks and two of America&#8217;s largest private companies have<br />
adopted PowerBroker to secure guest operating systems and ESX<br />
hypervisors in a virtualized environment. For more information, visit</p>
<p>http://www.beyondtrust.com/</p>
<p class="">
<p>About Votacall<br />
 Votacall is a leading provider of business-class<br />
VoIP and cloud-based Unified Communications (UC) solutions. Votacall<br />
is committed to delivering the latest best in class offerings to our<br />
end users through constant market and product research. Our approach<br />
allows our customer base to stay ahead of the technological curve at<br />
the lowest Total Cost of Ownership (TCO) in the industry. The<br />
Votacall Cloud product suite is fully managed and through the<br />
delivery of innovative Cloud applications, we aim to enhance the<br />
end-user experience. The Votacall tag line states our vision; you<br />
must INNOVATE to effectively COMMUNICATE. We base our organization<br />
and its daily operations on those two words. The world is changing,<br />
technology is changing, organizations are changing, it is of the<br />
utmost significance that you partner with a company that respects and<br />
embraces change. Think Big, Go Votacall. For more information, visit</p>
<p>http://www.votacall.com</p>
<pre>

        Contact Information:
        Andy DeAngelis
        (781) 693-0604
        Email Contact

www.abcna.com
www.votacall.com            
</pre>
<p class="">
<p>SOURCE: Votacall Inc.</p>
<pre>

http://www2.marketwire.com/mw/emailprcntct?id=3061BA2C98FFB27D

http://www.abcna.com/

http://www.votacall.com/
</pre>
<p class="">
<p>Copyright 2012  Marketwire, Inc., All rights reserved.<br />
                    <span class="endsquare" /></p>
<p class="emphasis">
<p>Article source: <a href="http://www.marketwatch.com/story/beyondtrust-selects-the-votacall-voip-platform-for-secure-reliable-and-enhanced-communications-2012-02-20">http://www.marketwatch.com/story/beyondtrust-selects-the-votacall-voip-platform-for-secure-reliable-and-enhanced-communications-2012-02-20</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/it-security-news/beyondtrust-selects-the-votacall-voip-platform-for-secure-reliable-and/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco to Resell Citrix XenDesktop to Deliver Virtual Workspaces Anywhere on Any Device</title>
		<link>http://www.ciss-inc.com/it-security-news/cisco-to-resell-citrix-xendesktop-to-deliver-virtual-workspaces-anywhere-on-any-device/</link>
		<comments>http://www.ciss-inc.com/it-security-news/cisco-to-resell-citrix-xendesktop-to-deliver-virtual-workspaces-anywhere-on-any-device/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 22:13:33 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[IT Security News]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/it-security-news/cisco-to-resell-citrix-xendesktop-to-deliver-virtual-workspaces-anywhere-on-any-device/</guid>
		<description><![CDATA[Sorry, the page you requested either doesn&#8217;t exist or isn&#8217;t available right now! Please check the URL for proper spelling and capitalization. If you&#8217;re having trouble locating a destination on Yahoo!, try visiting the Yahoo! homepage or look through a list of Yahoo!&#8217;s online services. Please try Yahoo Help Central if you need more assistance. [...]]]></description>
			<content:encoded><![CDATA[<h2>Sorry, the page you requested either doesn&#8217;t exist or isn&#8217;t available right now!</h2>
<p>Please check the URL for proper spelling and capitalization. If you&#8217;re having trouble locating a destination on Yahoo!, try visiting the <a href="http://us.yahoo.com/">Yahoo! homepage</a> or look through a list of <a href="http://everything.yahoo.com/">Yahoo!&#8217;s online services</a>.</p>
<p>Please try <a href="http://help.yahoo.com//l/us/yahoo/finance/">Yahoo Help Central</a> if you need more assistance.</p>
<p>Article source: <a href="http://finance.yahoo.com/news/cisco-resell-citrix-xendesktop-deliver-130000870.html">http://finance.yahoo.com/news/cisco-resell-citrix-xendesktop-deliver-130000870.html</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/it-security-news/cisco-to-resell-citrix-xendesktop-to-deliver-virtual-workspaces-anywhere-on-any-device/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft, Oracle, Adobe send patches for Valentine&#8217;s Day</title>
		<link>http://www.ciss-inc.com/uncategorized/microsoft-oracle-adobe-send-patches-for-valentines-day/</link>
		<comments>http://www.ciss-inc.com/uncategorized/microsoft-oracle-adobe-send-patches-for-valentines-day/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 03:42:39 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsfot]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/uncategorized/microsoft-oracle-adobe-send-patches-for-valentines-day/</guid>
		<description><![CDATA[The Valentine&#8217;s Day 2012 edition of Patch Tuesday is upon us, and Microsoft has come forward with details on the nine bulletins it previewed last week. Although Lumension security and forensic analyst Paul Henry are calling it a &#8220;pretty sweet Valentine&#8217;s Day&#8221; for Microsoft, given the relatively light patch load for the month, additional patches [...]]]></description>
			<content:encoded><![CDATA[<p class="first">The Valentine&#8217;s Day 2012 edition of Patch Tuesday is upon us, and <a href="http://www.networkworld.com/subnets/microsoft/">Microsoft</a> <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb">has come forward</a> with details on the nine bulletins it <a href="http://www.networkworld.com/community/node/79781">previewed last week</a>.
</p>
<p>Although Lumension security and forensic analyst Paul Henry are calling it a &#8220;pretty sweet Valentine&#8217;s Day&#8221; for Microsoft,<br />
   given the relatively light patch load for the month, additional patches from Adobe may spoil the mood for others.
</p>
<p><b>VALENTINE&#8217;S DAY PATCH TUESDAY:</b> <a href="http://www.networkworld.com/community/node/79781">Microsoft to issue 9 patches, 4 critical</a></p>
<p>As <a href="http://www.networkworld.com/community/node/79781">previously noted</a>, four of Microsoft&#8217;s nine security bulletins are deemed &#8220;critical.&#8221; The most important, Henry says, are the two bulletins<br />
   that have been publicly disclosed. One is susceptible to remote code execution in <a href="http://www.networkworld.com/topics/windows.html">Windows</a>, while the other addresses a similar vulnerability in Silverlight and the .NET Framework.
</p>
<p>Beyond that, Henry believes the two patches deemed &#8220;important&#8221; should receive higher priority because they have also been<br />
   publicly disclosed. Both are susceptible to remote code execution in Windows, one through the Color Control Panel and the<br />
   other through Indeo Codec.
</p>
<p>However, given the recent spike in browser-based attacks, Qualys CTO Wolfgang Kandek says the patch for four privately discovered<br />
   vulnerabilities in Internet Explorer &#8212; MS12-110 &#8212; should receive the most attention.
</p>
<p>&#8220;We have seen how quickly attackers can react to new vulnerabilities when exploits for MS12-004 appeared within 2 weeks of<br />
   its release on attack sites,&#8221; Kandek says. &#8220;So while none of the vulnerabilities in MS12-010 were publicly known, you should<br />
   install this fix as quickly as possible.&#8221;
</p>
<p>Although it surpassed the seven bulletins released last month, the nine patches issued today is a low for the month of February<br />
   since 2009. That&#8217;s a sign that a focus on security may be paying off for Redmond, Henry says.
</p>
<p>However, a happy Valentine&#8217;s Day for Microsoft doesn&#8217;t necessarily mean the same for the IT department. Citing Oracle&#8217;s concurrent<br />
   release of <a href="http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html">patches for 14 Java vulnerabilities</a>, which have been targeted particularly frequently of late, Henry says some support teams may have their hands full.
</p>
<p>&#8220;The light patch load from Microsoft does not mean IT can sit back and relax however,&#8221; Henry says. &#8220;A significant patch update<br />
   from Oracle came out recently and, as always, threats targeting Java must be addressed, as currently it is the bad guys&#8217; most<br />
   popular attack vector.&#8221;
</p>
<p>Similarly, Adobe released <a href="http://blogs.adobe.com/psirt/2011/08/adobe-product-security-updates-available-2.html">five security bulletins today</a> as well. Four of the patches, specifically those addressing vulnerabilities in Shockwave Player, Flash Media Player <a href="http://www.networkworld.com/topics/server.html">Server</a>, Flash Player and Photoshop, were deemed critical, while another targeting vulnerabilities in Robohelp was rated important.
</p>
<p><i>Colin Neagle covers Microsoft security and <a href="http://www.networkworld.com/topics/network-management.html">network management</a> for Network World. Keep up with his blog: <a href="http://www.networkworld.com/community/blog/26138">Rated Critical</a>, follow him on <a href="http://www.networkworld.com/slideshows/2010/052610-twitter-quiz.html">Twitter</a>: @<a href="http://twitter.com/#!/ntwrkwrldneagle">ntwrkwrldneagle</a>. Colin&#8217;s email is cneagle@nww.com.</i></p>
<p><a href="http://www.networkworld.com/topics/software.html" target="blank">Read more about software</a> in Network World&#8217;s Software section.</p>
<p>Article source: <a href="http://www.networkworld.com/news/2012/021412-microsoft-adobe-oracle-patches-256124.html">http://www.networkworld.com/news/2012/021412-microsoft-adobe-oracle-patches-256124.html</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/uncategorized/microsoft-oracle-adobe-send-patches-for-valentines-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patches Out Google</title>
		<link>http://www.ciss-inc.com/uncategorized/microsoft-patches-out-google/</link>
		<comments>http://www.ciss-inc.com/uncategorized/microsoft-patches-out-google/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 03:42:38 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsfot]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/uncategorized/microsoft-patches-out-google/</guid>
		<description><![CDATA[Security Advisor Microsoft Patches Out Google Plus, February&#8217;s Security Update is here, don&#8217;t save personal info as plain text. By Chris Paoli 02/15/2012 Along with putting together this security blog every week, my duties also include writing any pertinent security news for MCPmag.com and RedmondMag.com. That includes covering Microsoft&#8217;s monthly Security Update, which I took [...]]]></description>
			<content:encoded><![CDATA[
<p class="kicker">Security Advisor</p>
<h3 id="ctl00_ContentPlaceHolder_ctl11_MainHeading" class="title">Microsoft Patches Out Google</h3>
<p class="deck">Plus, February&#8217;s Security Update is here, don&#8217;t save  personal info as plain text. </p>
<ul class="byline">
<li class="author">By <a href="http://mcpmag.com/forms/emailtoauthor.aspx?AuthorItem={D7BC0B29-94B7-45F1-B084-C95F18A036C6}ArticleItem={CF866CE9-3EDB-472C-A967-C7E6A6962982}">Chris Paoli</a></li>
<li class="date">02/15/2012</li>
</ul>
<p>Along with putting together this security blog every week, my duties also  include writing any pertinent security news for MCPmag.com and RedmondMag.com.  That includes covering Microsoft&#8217;s <a href="http://redmondmag.com/articles/2012/02/14/microsoft-february-security-update.aspx">monthly  Security Update</a>, which I took care of Tuesday afternoon.</p>
<p>However, it seems like I missed one key feature in the  rollout. Apparently the patch came with an update for Microsoft&#8217;s Forefront and  Security Essentials antivirus software that now <a href="http://redmondmag.com/articles/2012/02/15/security-update-ids-google.aspx">sees  Google as a &#8220;severe&#8221; target</a>. </p>
<p><a href="http://ad.doubleclick.net/jump/eof.mcp/;Topic=Security;Topic=Windows_Desktop;Topic=Internet;item=cf866ce9_3edb_472c_a967_c7e6a6962982;pos=BOX_A3;tile=10;sz=336x280,300x250;ord=123456789?" target="_blank"><br />
<img src="http://www.ciss-inc.com/wp-content/plugins/rss-poster/cache/1a594_%3BTopic%3DSecurity%3BTopic%3DWindows_Desktop%3BTopic%3DInternet%3Bitem%3Dcf866ce9_3edb_472c_a967_c7e6a6962982%3Bpos%3DBOX_A3%3Btile%3D10%3Bsz%3D336x280%2C300x250%3Bord%3D123456789" border="0" alt="" /></a></p>
<p>
<p>Once the update has been installed, users visiting  Google.com became alerted that the Web site was infected with a Blackhole Exploit  Kit. I would give you more details on what this kit actually does, but I&#8217;m a  little concerned that I may be left open to a Blackhole Exploit if I Google  Blackhole Exploit. </p>
<p>What I do know about it is that a real one recently took  down the U.S. Postal Service&#8217;s Rapid Information Bulletin Board System Web  site. </p>
<p>Stories of false positives after updates are not a rare occurrence,  and are usually fixed fairly quickly.</p>
<p><strong>Microsoft Also  Patches Out Real Vulnerabilities</strong><br />
  Besides the bonus Google warning (MS REALLY wants you to use  Bing), Microsoft&#8217;s February Security Update took care of 21 different holes  across a myriad of MS software with four &#8220;critical&#8221; bulletins and  five items deemed &#8220;important.&#8221; </p>
<p>The four high-priority items all deal with remote code  execution flaws in Windows, Internet Explorer, .NET Framework and Microsoft  Silverlight. </p>
<p>The one that stands out this month is bulletin <a href="http://go.microsoft.com/fwlink/?LinkId=238617">MS12-013</a>, which changes  how the DLL calculates memory data so that attackers couldn&#8217;t gain access to  your computer when you unknowingly click on a malicious media file from an  e-mail or Web site. </p>
<p>Tyler Reguly, technical manager of security research and  development at security firm nCircle, also thinks this item is worth your  attention: &#8220;Everyone is likely to see this critical vulnerability and  freak out,&#8221; he wrote. &#8220;However, it&#8217;s important to note that the  attack vector is limited.&#8221;</p>
<p>While security vulnerabilities and critical patches are  definitely something we should be concerned about, do they ever really garter a  &#8220;freak out&#8221; response, especially when they haven&#8217;t done any damage to  your system yet? </p>
<p>Let me know your plan of attack for this month&#8217;s Security  Update. And also share with me your biggest security &#8220;freak out&#8221;  moment. Send your responses to cpaoli@1105media.com.</p>
<p><strong>How To Not Save Personal  Information Online</strong><br />
  The answer is in a plain text file.</p>
<p>Seems obvious enough. <a href="http://redmondmag.com/articles/2012/02/13/microsoft-india-store-hacked.aspx">Unless  you&#8217;re Microsoft</a>. </p>
<p>Earlier this week it had its India online store attacked by  hackers from a group named Evil Shadow Team (wasn&#8217;t that the name of the bad  guys in Karate Kid II?). Not only did it gain unauthorized access to the  company&#8217;s Web site, but it also made off with usernames and passwords of  customers, which, as stated earlier, was completely unencrypted. </p>
<p>After the attack, Microsoft took the site online (which is  still the case) and e-mailed users that their passwords had been automatically  reset. It also confirmed that billing information, including addresses and  credit card numbers, were safe. </p>
<p> </p>
<p><!-- pager start --><!-- pager end --></p>
<p>Article source: <a href="http://mcpmag.com/Articles/2012/02/15/Microsoft-Patches-Out-Google.aspx?p=1">http://mcpmag.com/Articles/2012/02/15/Microsoft-Patches-Out-Google.aspx?p=1</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/uncategorized/microsoft-patches-out-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft warns of dangerous IE browser vulnerabilities</title>
		<link>http://www.ciss-inc.com/uncategorized/microsoft-warns-of-dangerous-ie-browser-vulnerabilities/</link>
		<comments>http://www.ciss-inc.com/uncategorized/microsoft-warns-of-dangerous-ie-browser-vulnerabilities/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 03:42:36 +0000</pubDate>
		<dc:creator>oleksabublik</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsfot]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ciss-inc.com/uncategorized/microsoft-warns-of-dangerous-ie-browser-vulnerabilities/</guid>
		<description><![CDATA[@toddbottom All operating systems, and all software written has vulnerabilities that can be exploited, but Internet Explorer is just one piece of software that just needs to die. I like Microsoft, I appreciate and use Windows, but IE is a disaster, and has been the one thing standing in the way of progress. It started [...]]]></description>
			<content:encoded><![CDATA[<p>                        @toddbottom All operating systems, and all software written has vulnerabilities that can be exploited, but Internet Explorer is just one piece of software that just needs to die.
<p>I like Microsoft, I appreciate and use Windows, but IE is a disaster, and has been the one thing standing in the way of progress.  It started it&#8217;s life not adhering to the web standards, not adopting W3C outlines, and making the web a fragmented experience.  To add to that, it has been the hacker&#8217;s focal point for the last few generations.  Secure or not, it is the browser of choice for hackers, because it has the market share and is the default install (attractive to non-technical users).</p>
<p>The death of IE has been LONG overdue.                    </p>
<p>Article source: <a href="http://www.zdnet.com/blog/security/microsoft-warns-of-dangerous-ie-browser-vulnerabilities/10285">http://www.zdnet.com/blog/security/microsoft-warns-of-dangerous-ie-browser-vulnerabilities/10285</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciss-inc.com/uncategorized/microsoft-warns-of-dangerous-ie-browser-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

