Tuesday, 29 April 2014

Even Homeland Security Says Not to Use Internet Explorer

How scary is the latest Internet Explorer security vulnerability? Even the U.S. government says not to use IE until the browser is fixed.

The flaw, which affects Internet Explorer versions 6 and up, allows bad guys to gain complete access to a PC via a malicious website. Dubbed "Operation Clandestine Fox" by the security firm FireEye, the threat is real. And dangerous.

The U.S. Department of Homeland Security doesn't issue security alerts for computer software very often, but this time, it made an exception. Many agencies within the U.S. government use versions of IE.

Homeland Security recommends that users or administrators "enable Microsoft EMET where possible" and to "consider employing an alternative web browser until an official update is available."

That's good advice. Microsoft's next schedule "Patch Tuesday" isn't until May 13, although the company may push out an unscheduled update earlier. If you're using an unsupported version of Windows — like Windows XP — don't expect to get any updates.

For Windows XP users, the best course of action is to move to Google Chrome or Mozilla Firefox now.


Read full Article…

Sunday, 27 April 2014

Microsoft Web Browser Security Bug Could Impact Millions of Users

Microsoft issued a security advisory on Saturday warning users of a vulnerability in its Internet Explorer web browser that could allow malicious "remote code execution."

The vulnerability affects all versions of the browser and, as of this writing, there is no patch available to fix the issue.

Revealing the vulnerability on its website, Microsoft stated:
The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.
FireEye, the security firm taking credit for finding the vulnerability, posted a notice on its website alerting users to the issue. "Threat actors are actively using this exploit in an ongoing campaign which we have named 'Operation Clandestine Fox,'” reads the statement on FireEye's website.

Security firm Symantec issued its own alert regarding the issue, highlighting the fact that Windows XP users are particularly susceptible, stating, " especially XP users are not safe anymore and this is the first vulnerability that will be not patched for their system."

This last point is no small issue as Microsoft officially ended support for Windows XP earlier this month, which means no more security updates for the millions still using the operating system.

According to NetMarketshare, Internet Explorer accounts for roughly 58% of the world's desktop browsers.

At present, the safest option might be to use another browser until Microsoft issues a security patch.

For its part, Microsoft says that at the completion of its investigation it will "take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs."

Read full Article…

Tuesday, 8 April 2014

Microsoft Ends Support for Windows XP



It's the end of the line for Microsoft's Windows XP: as of today, the company will no longer release security updates for the 12-year-old operating system.

"Microsoft has provided support for Windows XP for the past 12 years. But now the time has come for us, along with our hardware and software partners, to invest our resources toward supporting more recent technologies so that we can continue to deliver great new experiences," wrote Microsoft in an announcement.

Microsoft's Office 2003 is another product that will not get security updates after this date.

Launched on October 25, 2001, Windows XP is one of the most successful Microsoft products ever; its successor, Windows Vista, was quickly replaced with Windows 7, and it took as long as September 2012 for Windows 7 to overtake XP as the most popular desktop operating system.

Microsoft released three Service Packs for Windows XP; the last one, SP3, was launched in May 2008. In April 2009, Microsoft ended Mainstream Support for the OS, meaning it stopped providing free technical support and accepting warranty claims. Up until today, the company provided Extended Support, which included paid technical support and security updates.

What does it mean for the end user? Simply put, you can continue to use Windows XP and Office 2003, but as time goes on, they will be more and more vulnerable to malware and other security risks.

For users still running Windows XP, Microsoft recommends upgrading their PC to a model that can run the latest version of Windows, 8.1. For instructions for moving your data from Windows XP to 8.1, go here.

Image: Microsoft

Read full Article…