<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Patch Updates Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/category/patch-updates/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/category/patch-updates/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Tue, 23 Jan 2018 17:55:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>Patch Updates Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/category/patch-updates/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Patching Nightmare – Please Forward to Your IT Pros</title>
		<link>https://fosterinstitute.com/patching-nightmare-please-forward-to-your-it-pros/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Tue, 23 Jan 2018 17:55:51 +0000</pubDate>
				<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Flash]]></category>
		<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Patch Updates]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Preventative IT Security Breach]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[CPU Chip Flaws]]></category>
		<category><![CDATA[CPU Chips]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[deploying patches]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[Java SE patch]]></category>
		<category><![CDATA[Oracle patches]]></category>
		<category><![CDATA[patching nightmare]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[tech support]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2607</guid>

					<description><![CDATA[<p>Intel says, again, to stop deploying patches. Java and other new patches need handling. Intel advises that IT Professionals stop deploying the current versions of patches for the recently discovered security flaws in CPU chips. Find details, just updated, by searching: Root Cause of Reboot Issue Identified Updated Guidance for Customers and Partners site:intel.com Do [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/patching-nightmare-please-forward-to-your-it-pros/">Patching Nightmare – Please Forward to Your IT Pros</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Intel says, again, to stop deploying patches. Java and other new patches need handling.<span id="more-2607"></span></p>
<p>Intel advises that IT Professionals stop deploying the current versions of patches for the recently discovered security flaws in CPU chips. Find details, just updated, by searching:<br />
Root Cause of Reboot Issue Identified Updated Guidance for Customers and Partners site:intel.com</p>
<p>Do not insert a space after the colon.</p>
<p>For most of you, deploying Microsoft patches is easy compared to managing Flash, Java, and browser updates. Oracle is releasing multiple security patches for Java SE. Additionally, if you are upgrading Chrome to the 64 bit version, Google is releasing new patches for that browser.</p>
<p>For executives wondering what to do at home, you may find it best to download fresh versions of any non-Microsoft browsers you use, and reinstall the most recent versions of Flash and Java, if you still use either, from <a href="https://get.adobe.com/flashplayer/">https://get.adobe dot com/flashplayer/</a> or <a href="https://www.java.com/en/">java dot com</a> . Your Microsoft and/or Apple patches are likely configured to install automatically.</p>
<p>For both organizations and home office users, if you can remove Flash and/or Java from some or all of your computers, then you can forget about patching them. If you haven’t already, try it on a few computers. You may find that all of the websites essential to your business no longer require either. Worst case, you can re-install the most recent version.</p>
<p>Executives, please forward this to your IT Professionals. Be sure to, if you have not already, have a conversation with them about how aggressive you want them to be with patching. They can share the pros and cons with you. These days, an aggressive posture related to patches can increase your security dramatically, when handled properly. Provide them time to test the patches, test un-installing the patches, and then to deploy the patches in stages. They will also need to contact your cloud providers to discuss how they are handling the flaws and patches.</p>
<p>The post <a href="https://fosterinstitute.com/patching-nightmare-please-forward-to-your-it-pros/">Patching Nightmare – Please Forward to Your IT Pros</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Get Apple’s Urgent Patches that Fix Dozens of Security Holes</title>
		<link>https://fosterinstitute.com/get-apples-urgent-patches-that-fix-dozens-of-security-holes/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Wed, 17 May 2017 16:08:20 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Loss Prevention]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Patch Release]]></category>
		<category><![CDATA[Patch Updates]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<category><![CDATA[apple patch]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[fix security holes]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[how to apply apple patch]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[ipad updates]]></category>
		<category><![CDATA[iphone updates]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[updating apple products]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2495</guid>

					<description><![CDATA[<p>For those of you with Apple products, Apple just released some important updates. Knowing that updates might cause a problem, please back up your computer first. You are backing up all the time already, right? Time Machine is a wonderful tool and is built in. If you want to supplement Time Machine with an additional [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/get-apples-urgent-patches-that-fix-dozens-of-security-holes/">Get Apple’s Urgent Patches that Fix Dozens of Security Holes</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>For those of you with Apple products, Apple just released some important updates.</p>
<p>Knowing that updates might cause a problem, please back up your computer first. You are backing up all the time already, right? Time Machine is a wonderful tool and is built in. If you want to supplement Time Machine with an additional backup, Carbon Copy Cloner from Bombich dot com is very popular and clients experience great results. You’ll need a couple of external USB drives, but the investment is worth it.</p>
<p>In case you are not familiar with how to apply patches, here are instructions:</p>
<p>On your Apple computer, even if your computer is set for automatic updates, it is good to verify that you have the most recent patches. Click on the image of the apple in the top left corner, and choose App Store. If not already selected, choose Updates inside the title bar that already contains the words: Featured, Top Charts, Categories, Purchased, and Updates. You may see many updates for your applications, and those are fine to apply, but the urgent one is the update called macOS Sierra Update and the version is 10.12.5. If you’ve not updated in a while, you may see other macOS updates too.</p>
<p>iPhone and iPad users, press on the Settings icon that looks like a gear. In the left-hand column, select General, and you’ll see Software Update on the right-hand column near the top. The most recent patch is for iOS 10.3.2.</p>
<p>If you want to configure automatic updates for your Apple computers, find instructions by searching for this phrase in Google: Automatic security updates os x site:apple.com</p>
<p>If you want to configure automatic updates for the iPhone and iPad, find instructions by searching for this phrase in Google: Automatic security downloads iOS site:apple.com</p>
<p>Please forward this to everyone you know who uses Apple devices and you want to help be more secure…</p>
<p>The post <a href="https://fosterinstitute.com/get-apples-urgent-patches-that-fix-dozens-of-security-holes/">Get Apple’s Urgent Patches that Fix Dozens of Security Holes</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Patching – 10 Steps to Seal the Holes in Your Armor</title>
		<link>https://fosterinstitute.com/patching-10-steps-to-seal-the-holes-in-your-armor/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 15 May 2017 15:42:19 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[browser security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Loss Prevention]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[Patch Updates]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[applying patches]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[ipad security]]></category>
		<category><![CDATA[iphone Security]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Microsoft patch]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[patch deployment]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[updating patches]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2482</guid>

					<description><![CDATA[<p>You’ve likely heard of the massive ransomware attack that has taken down so many organizations, including hospitals, around the world. The ransomware appears to have exploited a bug for which Microsoft released a fix a little over a month ago. Follow these 10 steps to help protect your organization from this, and from future attacks: [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/patching-10-steps-to-seal-the-holes-in-your-armor/">Patching – 10 Steps to Seal the Holes in Your Armor</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You’ve likely heard of the massive ransomware attack that has taken down so many organizations, including hospitals, around the world. The ransomware appears to have exploited a bug for which Microsoft released a fix a little over a month ago. Follow these 10 steps to help protect your organization from this, and from future attacks:<span id="more-2482"></span></p>
<p>Instructions for Windows and Apple home users are listed below the numbers. For organizations, here are 10 Steps To Avoid Incidents Including the Massive Ransomware Attack:</p>
<p>1. The reality is that most organizations are missing critical security patches and there is a very strong likelihood that yours is too.</p>
<p>2. Provide your team with extra time, and perhaps additional personnel, to test and then deploy patches ASAP. Some organizations are adding a new IT professional to their team whose sole responsibility is to manage patches. If the patch fails testing, then time must be invested to resolve the issue or implement compensating controls.</p>
<p>3. Prioritize critical security patches for the operating system, all the browsers, Flash, Java, your PDF Reader, and Microsoft Office. They are usually the easiest to attack and form your first line of defense.</p>
<p>4. Many IT teams are very reluctant to apply patches for fear of breaking your systems that are already running. Help remove their fears by reassuring them that you take on responsibility if the patch causes a problem. Encourage them to follow a procedure that mitigates risks:</p>
<p>5. Test Patches in a test environment that uses the same applications as the rest of your network. For very small companies, your test environment might be a single computer. For larger organizations, and organizations that stand to lose a great deal in the event of an attack, create a separate testing environment that is isolated from the production environment.</p>
<p>6. Have a pre-tested rollback plan so that, if the patch does cause a problem, your IT team will already know what they need to do right away to roll back a patch that causes an unexpected problem. They will then go back to the testing phase.</p>
<p>7. Deploy the patches in stages rather than patching all machines simultaneously. That way, even if the patch does cause a problem, not all your machines will be affected.</p>
<p>8. You may decide to empower your IT team with a patch management tool such as Ninite, LANGuard, Shavlik, or others. Allow them to test and choose a tool, and provide them with the means and time to do so, ASAP.</p>
<p>9. Ask IT, perhaps weekly and at least monthly, to provide you with a list of missing patches, not a pie chart.</p>
<p>10. You must upgrade from older operating systems, any of the ones that Microsoft no longer supports. If some machines cannot be upgraded, then they must be isolated or some other compensating control put into place. Microsoft clearly states when they stop producing patches for old operating systems.  So, there was no patch available for Windows XP and others.</p>
<p>Call me if they are not able to apply patches. Let’s team up to help prevent this.</p>
<p>At home, or if your organization is so small that you do not have an IT team or have an outsourced IT company that takes care of your patches, be sure that the option that provides automatic updates to Microsoft is enabled. The instructions are easy to find – just google the phrase: configure automatic updates site:Microsoft.com</p>
<p>Apple computer users, google: Automatic security updates os x site:apple.com</p>
<p>iPhone and iPad users, google: Automatic security downloads ios site:apple.com</p>
<p>Additionally, manually check for updates in Microsoft Office to be sure those are applied. Be sure that automatic updates are enabled in your browsers. Regularly download and apply patches to, or new versions of, Flash, Java, and your PDF reader.</p>
<p>Please forward this to everyone you care about and want to help stay secure.</p>
<p>The post <a href="https://fosterinstitute.com/patching-10-steps-to-seal-the-holes-in-your-armor/">Patching – 10 Steps to Seal the Holes in Your Armor</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Alert Your IT Team &#8211; Urgent Patch for Network Servers</title>
		<link>https://fosterinstitute.com/alert-your-it-team-urgent-patch-for-network-servers/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Tue, 18 Apr 2017 15:36:47 +0000</pubDate>
				<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[Executives and IT]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Patch Release]]></category>
		<category><![CDATA[Patch Updates]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT professionals]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[patch deployment]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[Patching]]></category>
		<category><![CDATA[pre-testing patches]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[VMware]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2460</guid>

					<description><![CDATA[<p>Many organizations use VMware to host their servers. VMware has released an urgent update they label as Critical. Patching VMware, which is often used as a platform for many of your other servers, can be frustrating. If the patch causes a problem, there is a risk that all your servers hosted on that machine will [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/alert-your-it-team-urgent-patch-for-network-servers/">Alert Your IT Team &#8211; Urgent Patch for Network Servers</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Many organizations use VMware to host their servers. VMware has released an urgent update they label as <span id="more-2460"></span>Critical.</p>
<p>Patching VMware, which is often used as a platform for many of your other servers, can be frustrating. If the patch causes a problem, there is a risk that all your servers hosted on that machine will go down.</p>
<p>This is one of those risk vs. benefit decisions that is so important, business executives must be involved.</p>
<p>On the one hand, the patch could interrupt business, but not applying the patch could be considered reckless.</p>
<p>Test the patch prior to deployment, when possible. Having a pre-planned, if not pre-tested, roll-back plan is crucial in case the patch causes a problem.</p>
<p>Preferably patch one server at a time so that, if the patch does cause a problem, at least the interruption is limited to that server.</p>
<p>Without the patch, someone could run programs on your computer, potentially taking control of the server.</p>
<p>The patch fixes a vulnerability in the VMware Customer Experience Improvement Program, even if a customer is not participating in the program.</p>
<p>Please emphasize the last phrase to your IT pros.</p>
<p>Ask your IT pros to look at VMware’s information by searching for VMSA-2017-0007.</p>
<p>Please forward this to everyone who may be using VMware, so that they can alert their IT pros just in case they don’t know already.</p>
<p>The post <a href="https://fosterinstitute.com/alert-your-it-team-urgent-patch-for-network-servers/">Alert Your IT Team &#8211; Urgent Patch for Network Servers</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Alert &#8211; A Popular Password Manager Has Serious Security Flaw Right Now</title>
		<link>https://fosterinstitute.com/alert-a-popular-password-manager-has-serious-security-flaw-right-now/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Tue, 28 Mar 2017 15:33:51 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[LastPass]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Password Safety]]></category>
		<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Patch Updates]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[LastPass Breach]]></category>
		<category><![CDATA[Password Manager Breach]]></category>
		<category><![CDATA[password safety]]></category>
		<category><![CDATA[password security]]></category>
		<category><![CDATA[password storage]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[two step verification]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2456</guid>

					<description><![CDATA[<p>A password manager company announced that there is a vulnerability that could allow attackers to gather stored passwords. Password managers are very helpful since they make it so convenient to be secure, and can greatly simplify and speed up the login process at websites. Many people feel password managers are worth the risks, especially when the [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/alert-a-popular-password-manager-has-serious-security-flaw-right-now/">Alert &#8211; A Popular Password Manager Has Serious Security Flaw Right Now</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A password manager company announced that there is a vulnerability that could allow attackers to gather stored passwords.<span id="more-2456"></span></p>
<p>Password managers are very helpful since they make it so convenient to be secure, and can greatly simplify and speed up the login process at websites. Many people feel password managers are worth the risks, especially when the risks can be minimized as summarized below:</p>
<p>First, as you can see, there is no guarantee that password managers are perfect. Never store super-sensitive passwords into your password manager. Store them in your head.</p>
<p>Second, enable two-step verification on all websites. Then, if an unauthorized person obtains your password, they will have a difficult time logging in, if they cannot perform the second step.</p>
<p>Third, one of the ways to launch the exploit involves tricking the user into clicking a link, such as a link in an email message, or getting a script to run on a web page as the user visits the page. Using click-to-play can greatly minimize those risks.</p>
<p>To learn more about the first two, see last week’s newsletter posted at www.fosterinstitute dot com/blog/your-iphone-and-ipad-are-in-danger. Never mind the title; the content addresses the first two steps listed above even if you use Windows or Android.</p>
<p>As for the third point, we&#8217;ll cover click-to-play next week, or you can simply google those terms and get started right away.</p>
<p>The announcement came from LastPass, and don&#8217;t panic if you use it. LastPass says the exploit is very difficult for an attacker to use, but not impossible. Resetting your passwords is not going to help, yet. Only after LastPass develops a patch, and then only when LastPass on your computers are patched. LastPass said this only affects users using the LastPass extension in Chrome, but that researchers have used the exploit in other browsers too. Email us if you want more technical details.</p>
<p>Please forward this to anyone you know who may use a password manager or lets their browsers remember their passwords.</p>
<p>The post <a href="https://fosterinstitute.com/alert-a-popular-password-manager-has-serious-security-flaw-right-now/">Alert &#8211; A Popular Password Manager Has Serious Security Flaw Right Now</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Alert IT to Graphics Component Patches</title>
		<link>https://fosterinstitute.com/alert-it-to-graphics-component-patches/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 09 Feb 2017 16:17:34 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[Executives and IT]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Patch Release]]></category>
		<category><![CDATA[Patch Updates]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[Graphics Component Patches]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Microsoft patches]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[updating patches]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2424</guid>

					<description><![CDATA[<p>Security patches are so important to security, but they are difficult to manage and you always stand the risk of a patch interrupting productivity. And there are some new patches your IT team needs to know about&#8230; Microsoft has released a series of patches related to the Windows Graphics Component. As IT professionals, we are [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/alert-it-to-graphics-component-patches/">Alert IT to Graphics Component Patches</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Security patches are so important to security, but they are difficult to manage and you always stand the risk of a patch interrupting productivity. And there are some new patches your IT team needs to know about&#8230;<span id="more-2424"></span></p>
<p>Microsoft has released a series of patches related to the Windows Graphics Component. As IT professionals, we are tempted to think that, since it only applies to graphics, the patch isn&#8217;t that important.</p>
<p>Actually, the patch is very important. An attacker can execute code on your computers, perhaps even ransomware, if the patch is not installed.</p>
<p>We are seeing a trend during audits, of these patches being missing.</p>
<p>If you are a home user, be sure you are applying patches too. Chances are that you have your computer configured to auto-update.</p>
<p>And at your organization, be sure to alert your IT team that these patches to the graphics component are important too. </p>
<p>As long as your IT team is provided enough time to keep your system backed up, and to test the patches, then their applying your patches isn&#8217;t as ominous as hackers hope they feel it is.</p>
<p>And, as executives, you can help a lot by providing them time to focus on testing and deploying the patches. They are very busy already.</p>
<p>Please forward this to everyone you know whose systems may be missing these seemingly unnecessary patches. It will help stop the attackers!</p>
<p>The post <a href="https://fosterinstitute.com/alert-it-to-graphics-component-patches/">Alert IT to Graphics Component Patches</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
