UK InfoSec Review for February 2013
Microsoft issued one its largest ever monthly security updates Released as part ‘Patch Tuesday’ cycle on 12-Feb-13, bulletins MS13-009 to MS13-020 Addresses 57 vulnerabilities in Windows, Office, Internet Explorer, Exchange and the .NET Framework. 5 of these vulnerabilities were rated by Microsoft as ‘Critical’, Microsoft recommends to prioritise against MS13-009, MS13-010 and MS13-020 Adobe release 'Critical' Flash Player update which fixes 2 Zero-Day vulnerabilities (7-Feb) Adobe said in an advisory that one of the vulnerabilities — CVE-2013-0634 - is being exploited in the wild in attacks delivered via malicious Flash content hosted on websites that target Flash Player in Firefox or Safari on the Macintosh platform, as well as attacks designed to trick Windows users into opening a Microsoft Word document delivered as an email attachment New York Times and New York Journ...