Posts

Showing posts from March, 2013

UK InfoSec Review for February 2013

Microsoft issued one its largest ever monthly security updates Released as part ‘Patch Tuesday’ cycle on 12-Feb-13, bulletins MS13-009 to MS13-020 Addresses 57 vulnerabilities in Windows, Office, Internet Explorer, Exchange and the .NET Framework.  5 of these vulnerabilities were rated by Microsoft as ‘Critical’, Microsoft recommends to prioritise against MS13-009, MS13-010 and MS13-020 Adobe release 'Critical' Flash Player update which fixes 2 Zero-Day vulnerabilities (7-Feb) Adobe said in an advisory that one of the vulnerabilities — CVE-2013-0634 - is being exploited in the wild in attacks delivered via malicious Flash content hosted on websites that target Flash Player in Firefox or Safari on the Macintosh platform, as well as attacks designed to trick Windows users into opening a Microsoft Word document delivered as an email attachment New York Times and New York Journ...

UK Data Protection Review for February 2013

ICO fines Nursing and Midwifery Council £150,000 for breaching the DPA The council lost three DVDs related to a nurse’s misconduct hearing, which contained confidential personal information and evidence from two vulnerable children. An ICO investigation found the information was not encrypted. The council had been couriering evidence relating to a ‘fitness to practise’ case to the hearing venue. When the packages were received the discs were not present, though the packages showed no signs of tampering. Following the security breach the council carried out extensive searches to find the DVDs, but they’ve never been recovered ICO stated “failure to ensure these discs were encrypted placed sensitive personal information at unnecessary risk. No policy appeared to exist on how the discs should be handled, and so no thought was given as to whether they should be encrypted before being couriered. H...