December patches and a 2007 retrospective
Full article330 words · extracted from securelist.com · click to collapse
Today is ‘Patch Tuesday’ and this month Microsoft has announced that there will be seven security bulletins, three of which it rates ‘Critical’ and four of which it rates ‘Important’.
The Critical bulletins affect DirectX, Windows Media Format Runtime and Internet Explorer.
You can find more information here.
Make sure you patch your system. The easiest way to make sure you stay up-to-date is to enable Automatic Updates. You can find guidelines on applying Automatic Updates here.
The use of unpatched vulnerabilies continues to be a significant part of the threat landscape, so it’s no surprise that Micrsoft has been kept busy this year. Here’s a summary of this year’s patches.
| Critical | Important | Moderate | |
| January | 3 | 1 | – |
| February | 6 | 6 | – |
| March | – | – | – |
| April | 5 | 1 | – |
| May | 7 | – | – |
| June | 4 | 1 | 1 |
| July | 3 | 2 | 1 |
| August | 6 | 3 | – |
| September | 1 | 3 | – |
| October | 4 | 2 | – |
| November | 1 | 1 | – |
| December | 3 | 4 | – |
Patched security vulnerabilities in 2007
The situation in 2007 hasn’t changed noticeably from 2006. Last year there were 49 critical, 23 important, and 5 moderate updates. 2007 brought very slightly fewer patches, with 43 critical, 24 important, and 2 moderate fixes. If you want to take a look at last year’s chart, it’s here.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/december-patches-and-a-2007-retrospective/30387/