{"id":790,"date":"2006-08-17T00:00:00","date_gmt":"2006-08-17T00:00:00","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/2006\/08\/17\/august-patch-management-woes-strike-again\/"},"modified":"2021-12-30T11:38:11","modified_gmt":"2021-12-30T11:38:11","slug":"august-patch-management-woes-strike-again","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=790","title":{"rendered":"August patch management woes strike again"},"content":{"rendered":"<p>A suggestion for security pros: Don&#8217;t take your vacation in August.  Indeed, a pattern has emerged in recent years in which attackers take a recently disclosed Microsoft flaw and exploit it in dramatic fashion, often in the first two weeks of the month.  This year, security experts are sounding the alarm because of a critical Windows Server Service flaw that Microsoft addressed with its August patch release.  By Sunday, attackers were targeting the Windows Server Services flaw with malware in a bid to expand their IRC-controlled botnets.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Something always happens during the Christmas holiday, and it wrecks the holidays for IT administrators, and something always seems to happen in August to wreck their summer vacations,&#8221; she said.  &#8220;Also, System Administrator Day is July 28, so maybe things happen in August to reinforce the appreciation everyone has for us.&#8221;<\/p>\n<p>Paul Asadoorian, lead IT security engineer for Brown University in Providence, R.I., speculated that the annual Black Hat hacker event in Las Vegas is a factor.  &#8220;People go to Black Hat and pick up all this knowledge about how to exploit various technologies,&#8221; Asadoorian said, &#8220;then they decide to use Patch Tuesday to practice their newest skills.&#8221;   That&#8217;s especially problematic in a university environment, he said, since students returning to campus in August tend to come with computers that are infected with malware.<\/p>\n<p>In the case of the Windows Server Service flaw, Bradley and Asadoorian are bracing for what may be another awful August.  &#8220;We separate student computers from the rest of the campus and check them for problems before letting them on the network.  Network access and\/or endpoint assurance are two technologies every organization should try to take advantage of, something that checks the host when it tries to plug into the network,&#8221; Asadoorian said.  &#8220;The good news is that the newer platforms are in wider use,&#8221; she said, noting that her environment is now made up of machines running Windows XP SP2 and Windows 2003.<\/p>\n<p>Bradley&#8217;s advice for dealing with the current threat is to separate the MS06-040 patch from the rest of this month&#8217;s urgent updates and deal with that one first.<\/p>\n<p>http:\/\/searchsecurity.techtarget.com\/originalContent\/0,289142,sid14_gci1210536,00.html<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29],"tags":[],"class_list":["post-790","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=790"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/790\/revisions"}],"predecessor-version":[{"id":3277,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/790\/revisions\/3277"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}