<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy &#187; updates</title>
	<atom:link href="http://hijack-this.co.uk/category/updates/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 05 Apr 2012 14:34:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Adobe Flash player Update 27 March 2012</title>
		<link>http://hijack-this.co.uk/2012/03/adobe-flash-player-update-27-march-2012/</link>
		<comments>http://hijack-this.co.uk/2012/03/adobe-flash-player-update-27-march-2012/#comments</comments>
		<pubDate>Wed, 28 Mar 2012 08:32:29 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=612</guid>
		<description><![CDATA[There seems to have been a security update to 11.2.202.228 but I can find no release notes or information why the update has been issued except general gossip to say to fix undisclosed vulnerabilities Some users have reported problems with installing the update via adobe web based install so an alternative method is to use [...]]]></description>
			<content:encoded><![CDATA[<p>There seems to have been a security update to 11.2.202.228 but I can find no release notes or information why the update has been issued except general gossip to say to fix undisclosed vulnerabilities</p>
<p>Some users have reported problems with installing the update via adobe web based install so an alternative method is to use the full installers on <a href="http://www.adobe.com/products/flashplayer/distribution3.html" target="_blank">http://www.adobe.com/products/flashplayer/distribution3.html</a></p>
<p>I understand that some antiviruses including Eset/Nod have conflicts with the adobe web based installer</p>
<p>Edit:<br />
details here<br />
<a href="http://forums.adobe.com/message/4296259">http://forums.adobe.com/message/4296259</a></p>
<p>it isn&#8217;t a security fix but a whole new version of flashplayer with additional capabilities</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2012%2F03%2Fadobe-flash-player-update-27-march-2012%2F&amp;title=Adobe%20Flash%20player%20Update%2027%20March%202012" id="wpa2a_2"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2012/03/adobe-flash-player-update-27-march-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Make sure your Java is up to date</title>
		<link>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/</link>
		<comments>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 08:19:43 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=600</guid>
		<description><![CDATA[&#160; Public Java Exploit Amps Up Threat Level — Krebs on Security: http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29 &#8220;An exploit for a recently disclosed Java vulnerability that was previously only available for purchase in the criminal underground has now been rolled into the open source Metasploit exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-fareast-font-family: 'Times New Roman';"><span style="font-family: Times New Roman; font-size: small;">Public Java Exploit Amps Up Threat Level — Krebs on Security:<br />
</span><a href="http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29</span></a><br />
<span style="font-family: Times New Roman; font-size: small;"><br />
&#8220;An exploit for a recently disclosed <strong>Java</strong> </span><a title="CVE-2011-3544" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that was previously only available for purchase in the criminal underground has now been rolled into the open source </span><a href="http://metasploit.com/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">Metasploit</span></a><span style="font-family: Times New Roman; font-size: small;"> exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully deliver payloads on a variety of platforms, including the latest <strong>Windows</strong>, <strong>Mac</strong> and <strong>Linux</strong> systems.&#8221;</p>
<p>&#8220;The exploit attacks </span><a title="NIST CVE Listing" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">a vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that exists in <em>Oracle Java SE JDK and JRE 7 and 6 Update 27</em> and earlier. If you are using <em>Java 6 Update 29</em>, or <em>Java 7 Update 1</em>, then you have </span><a title="KrebsOnSecurity: Critical Java Update Fixes 20<br />
      Flaws" href="http://hijack-this.co.uk/2011/10/critical-java-update-fixes-20-flaws/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">the latest version</span></a><span style="font-family: Times New Roman; font-size: small;"> that is patched against this and 19 other security threats. If you are using a vulnerable version of Java, it’s time to update. Not sure whether you have Java or what version you may be running? Check out </span><a title="Java Home<br />
      Page" href="http://java.com/en/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">this link</span></a><span style="font-family: Times New Roman; font-size: small;">, and then click the “Do I have Java?” link below the big red “Free Java Download” button. Apple </span><a href="http://krebsonsecurity.com/2011/11/adobe-apple-microsoft-mozilla-issue-critical-patches/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">issued its own update</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> to fix this flaw and other Java bugs earlier this month.&#8221; </span></span></span></p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F12%2Fmake-sure-your-java-is-up-to-date%2F&amp;title=Make%20sure%20your%20Java%20is%20up%20to%20date" id="wpa2a_4"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011 Adobe updates</title>
		<link>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/</link>
		<comments>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/#comments</comments>
		<pubDate>Thu, 16 Jun 2011 14:15:44 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=526</guid>
		<description><![CDATA[As if you needed more updates this week&#8230; APSB11-16 &#8211; Security Advisory for Adobe Reader (v10.1) and Acrobat (v10.1 et al.) http://www.adobe.com/support/security/bulletins/apsb11-16.html APSB11-17 &#8211; Security Update Available for Adobe Shockwave Player v11.6.0.626 http://www.adobe.com/support/security/bulletins/apsb11-17.html APSB11-18 &#8211; [Yes, yet another] Security update available for Adobe Flash&#160; Player (v10.3.181.26) http://www.adobe.com/support/security/bulletins/apsb11-18.html]]></description>
			<content:encoded><![CDATA[<p>As if you needed more updates this week&#8230;</p>
<p>APSB11-16 &#8211; Security Advisory for Adobe Reader (v10.1) and Acrobat (v10.1 et al.)<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-16.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-16.html</a></p>
<p>APSB11-17 &#8211; Security Update Available for Adobe Shockwave Player v11.6.0.626<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-17.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-17.html</a></p>
<p>APSB11-18 &#8211; [Yes, yet another] Security update available for Adobe Flash&nbsp; Player (v10.3.181.26)<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-18.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-18.html</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F06%2Fjune-2011-adobe-updates%2F&amp;title=June%202011%20Adobe%20updates" id="wpa2a_6"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another new URGENT Adobe flash security update</title>
		<link>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/</link>
		<comments>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/#comments</comments>
		<pubDate>Mon, 06 Jun 2011 08:24:34 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=499</guid>
		<description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb11-13.html An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user&#8217;s behalf on any website or webmail provider, if the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.adobe.com/support/security/bulletins/apsb11-13.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-13.html</a><br />
An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user&#8217;s behalf on any website or webmail provider, if the user visits a malicious website. There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.<br />
Adobe recommends users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 (10.3.181.23 for ActiveX). Adobe expects to make available an update for Flash Player 10.3.185.22 for Android during the week of June 6, 2011.</p>
<p>Adobe is still investigating the impact to the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems. Adobe is not aware of any attacks targeting Adobe Reader or Acrobat in the wild.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F06%2Fanother-new-urgent-adobe-flash-security-update%2F&amp;title=Another%20new%20URGENT%20Adobe%20flash%20security%20update" id="wpa2a_8"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft security bulletin feedback</title>
		<link>http://hijack-this.co.uk/2011/05/microsoft-wants-your-feedback-on-security-bulletin-information/</link>
		<comments>http://hijack-this.co.uk/2011/05/microsoft-wants-your-feedback-on-security-bulletin-information/#comments</comments>
		<pubDate>Fri, 27 May 2011 07:03:07 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[microsoft]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=487</guid>
		<description><![CDATA[Microsoft wants your feedback on security bulletin information. Survey here: Security Bulletin Survey]]></description>
			<content:encoded><![CDATA[<p>Microsoft wants your feedback on security bulletin information. Survey here: <a title="Security Bulletin Survey" href="http://support.microsoft.com/common/survey.aspx?scid=sw;en;1876&amp;showpage=1&amp;altStyle=narrow&amp;renderOption=OverrideDefault" target="_blank">Security Bulletin Survey</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fmicrosoft-wants-your-feedback-on-security-bulletin-information%2F&amp;title=Microsoft%20security%20bulletin%20feedback" id="wpa2a_10"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/microsoft-wants-your-feedback-on-security-bulletin-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft is aware of nine fraudulent digital certificates issued by Comodo</title>
		<link>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/</link>
		<comments>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 17:50:02 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=456</guid>
		<description><![CDATA[The full advisory can be found on the Web at: http://www.microsoft.com/technet/security/advisory/2524375.mspx. =========================== SUMMARY =========================== Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Comodo advised Microsoft on March 16, 2011 that nine certificates had been [...]]]></description>
			<content:encoded><![CDATA[<p>The full advisory can be found on the Web at: <a href="http://www.microsoft.com/technet/security/advisory/2524375.mspx">http://www.microsoft.com/technet/security/advisory/2524375.mspx</a>.</p>
<p>===========================<br />
SUMMARY<br />
===========================<br />
Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Comodo advised Microsoft on March 16, 2011 that nine certificates had been signed on behalf of a third party without sufficiently validating its identity. These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer.</p>
<p>Certificates for the following Web properties are affected:</p>
<p>• login.live.com<br />
• mail.google.com<br />
•www.google.com<br />
• login.yahoo.com (3 certificates)<br />
• login.skype.com<br />
• addons.mozilla.org<br />
• &#8220;Global Trustee&#8221;</p>
<p>Comodo has revoked these certificates, and they are listed in Comodo’s current Certificate Revocation List (CRL). In addition, browsers which have enabled the Online Certificate Status Protocol (OCSP) will interactively validate these certificates and block them from being used.</p>
<p>An update is available for all supported versions of Windows to help address this issue. For more information about this update, see Microsoft Knowledge Base Article 2524375 (<a href="http://support.microsoft.com/kb/2524375">http://support.microsoft.com/kb/2524375</a>).</p>
<p>Typically, no action is required of customers to install this update, because the majority of customers have automatic updating enabled and this update will be downloaded and installed automatically. For more information, including how to manually install this update, see the Suggested Actions section of this advisory.</p>
<p>===========================<br />
RECOMMENDATIONS<br />
===========================<br />
Review Microsoft Security Advisory 2524375 for an overview of the issue, details on affected components, suggested actions, frequently asked questions (FAQ), and links to additional resources. MSRA Security Partners who are experiencing issues believed to be related to the issues described in this advisory should contact us via e-mail or by calling 888-HELPSEC with your custom Access ID.</p>
<p>===========================<br />
ADDITIONAL RESOURCES<br />
===========================<br />
• Microsoft Security Advisory 2524375 – Fraudulent Digital Certificates Could Allow Spoofing –<a href="http://www.microsoft.com/technet/security/advisory/2524375.mspx">http://www.microsoft.com/technet/security/advisory/2524375.mspx</a></p>
<p>• Microsoft Security Response Center (MSRC) Blog: <a href="http://blogs.technet.com/msrc">http://blogs.technet.com/msrc</a></p>
<p>More details on <a href="http://blogs.comodo.com/it-security/data-security/the-recent-ca-compromise/" target="_blank">Comodo blog</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F03%2Fmicrosoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo%2F&amp;title=Microsoft%20is%20aware%20of%20nine%20fraudulent%20digital%20certificates%20issued%20by%20Comodo" id="wpa2a_12"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft update for Windows 7 KB2505438</title>
		<link>http://hijack-this.co.uk/2011/03/microsoft-update-for-windows-7-kb2505438/</link>
		<comments>http://hijack-this.co.uk/2011/03/microsoft-update-for-windows-7-kb2505438/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 08:30:44 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[typo squatting]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[protection]]></category>
		<category><![CDATA[typos quatting]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=442</guid>
		<description><![CDATA[We are seeing on the forums and newsgroups several reports from users of &#8220;worries&#8221; about this update and following the links from the windows update page or the update history page on your computer doesn&#8217;t take you to the correct Microsoft support &#38; information page about the update but to an advertising page Ths is due to [...]]]></description>
			<content:encoded><![CDATA[<p>We are seeing on the forums and newsgroups several reports from users of &#8220;worries&#8221; about this update and following the links from the windows update page or the  update history page on your computer doesn&#8217;t take you to the correct Microsoft support &amp; information page about the update but to an advertising page</p>
<p>Ths is due to a mistype by Microsoft when inserting the link. <span style="color: #ff0000;"><strong>You are NOT infected</strong>. <strong>Microsoft website is NOT infected</strong></span>. It is just a mistype by a Microsoft employee.<br />
Microsoft have fixed the link on the windows update page  and partially have on the history page on your computer. It looks like some of the regional Microsoft update servers are still giving a cached copy of the update with the bad link, but others are giving the correct link.<br />
The correct link for support or information about this update is<br />
<a href="http://support.microsoft.com/kb/2505438" target="_blank">http://support.microsoft.com/kb/2505438</a><br />
The mistyped link was</p>
<p>http://support.micrososft.com/kb/2505438</p>
<p>Note the extra S in microsft<br />
It is an easy typing error to make.<br />
So Don&#8217;t panic about it. I repeat again <strong>you are not infected</strong>, Microsoft website is not infected, it was just a simple typing error that  has been partially corrected and I expect to be fully corrected very soon.</p>
<p>We often see major problems with typo squatting. This is when unscrupulous people buy up every possible combination of mistypes for common domain names, in the hope that they will get money  someone mistypes a URL ( web address)  and lands on their site/landing page instead. This time it is only harmless advertising but in many cases the unscrupulous owner will either attempt to sell you a fake program or even worse install malware from the fake page.<br />
Watch links you follow &amp; make sure that they are spelled correctly<br />
See the screenshots</p>
<div id="attachment_443" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="442" href="http://hijack-this.co.uk/wp-content/uploads/2011/03/2505438.png" ><img class="size-medium wp-image-443" title="2505438" src="http://hijack-this.co.uk/wp-content/uploads/2011/03/2505438-300x159.png" alt="" width="300" height="159" /></a><p class="wp-caption-text">Mistyped url on update history for KB2505438</p></div>
<div id="attachment_444" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="442" href="http://hijack-this.co.uk/wp-content/uploads/2011/03/ATT00008.png" ><img class="size-medium wp-image-444" title="ATT00008" src="http://hijack-this.co.uk/wp-content/uploads/2011/03/ATT00008-300x114.png" alt="" width="300" height="114" /></a><p class="wp-caption-text">Mistyped URL for KB2505438 from Windows update site</p></div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F03%2Fmicrosoft-update-for-windows-7-kb2505438%2F&amp;title=Microsoft%20update%20for%20Windows%207%20KB2505438" id="wpa2a_14"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/03/microsoft-update-for-windows-7-kb2505438/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flash Player update</title>
		<link>http://hijack-this.co.uk/2011/02/flash-player-update/</link>
		<comments>http://hijack-this.co.uk/2011/02/flash-player-update/#comments</comments>
		<pubDate>Mon, 28 Feb 2011 23:13:39 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=438</guid>
		<description><![CDATA[New version of Adobe Flash Player! It&#8217;s 10.2.156.32 and available at the &#8216;usual&#8217; URL; http://get.adobe.com/flashplayer/ No change log or other details yet so unknown whether a bug fix on recent 10.2.156.26 release or whether a new security vulnerability has been found &#038; quietly fixed]]></description>
			<content:encoded><![CDATA[<p>New version of Adobe Flash Player!<br />
It&#8217;s 10.2.156.32 and available at the &#8216;usual&#8217; URL; <a href="http://get.adobe.com/flashplayer/">http://get.adobe.com/flashplayer/</a> </p>
<p>No change log or other details yet so unknown whether a bug fix on recent 10.2.156.26 release or whether a new security vulnerability has been found &#038; quietly fixed </p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F02%2Fflash-player-update%2F&amp;title=Flash%20Player%20update" id="wpa2a_16"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/02/flash-player-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Advisory 979682 Released</title>
		<link>http://hijack-this.co.uk/2010/01/security-advisory-979682-released/</link>
		<comments>http://hijack-this.co.uk/2010/01/security-advisory-979682-released/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 09:37:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=282</guid>
		<description><![CDATA[Security Advisory 979682 Released Today we released Security Advisory 979682 to address an Elevation of Privilege (EoP) vulnerability in the Windows kernel, affecting all currently supported versions of 32-bit Windows. 64-bit versions of Windows, including Windows Server 2008 R2, are not affected. The advisory provides customers with actionable guidance to help with protections against exploit [...]]]></description>
			<content:encoded><![CDATA[<h2>Security Advisory 979682 Released</h2>
<p>Today we released <a href="http://www.microsoft.com/technet/security/advisory/979682.mspx" target="_blank">Security Advisory 979682</a> to address an Elevation of Privilege (EoP) vulnerability in the Windows kernel, affecting all currently supported versions of 32-bit Windows.<strong> 64-bit versions of Windows, including Windows Server 2008 R2, are not affected</strong>. The advisory provides customers with actionable guidance to help with protections against exploit of this vulnerability.</p>
<p>To exploit this vulnerability, an attacker must already have valid logon credentials and be able to log on to a system locally, meaning they must already have an account on the system. An attacker could then elevate their privileges to the administrative level and run programs of their choice on the system.</p>
<p>To help mitigate exploit of this vulnerability, customers who do not require NT Virtual DOS Mode (NTVDM) or support for 16-bit applications, can disable the NTVDM subsystem. Information on this workaround can be found in the Advisory.</p>
<p>We are not currently aware of any active attacks against this vulnerability and believe risk to customers, at this time, is limited. We continue to recommend customers review the mitigations and workarounds detailed in the Security Advisory.</p>
<p>We are also working with our <a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" target="_blank">Microsoft Active Protections Program (MAPP)</a> <a name="_GoBack"></a>partners to help provide broader protections for customers.</p>
<p>Our teams are continuing to work on an update and we will take appropriate action to protect customers when the update has met the quality bar for broad distribution. That may include releasing the update out-of-band.</p>
<p>The Security Advisory will be updated with any new developments so if you are not already subscribed to our <a href="http://technet.microsoft.com/en-us/security/dd252948.aspx" target="_blank">comprehensive alerts</a>, please do so in order to be alerted by email when new information is added.</p>
<p>We will also keep customers apprised of any additional details and updates through the <a href="http://blogs.technet.com/msrc" target="_blank">MSRC Blog.</a></p>
<p>Thanks,</p>
<p>Jerry Bryant</p>
<p>via <a href="http://blogs.technet.com/msrc/archive/2010/01/20/security-advisory-979682-released.aspx" target="_blank">http://blogs.technet.com/msrc/archive/2010/01/20/security-advisory-979682-released.aspx</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2010%2F01%2Fsecurity-advisory-979682-released%2F&amp;title=Security%20Advisory%20979682%20Released" id="wpa2a_18"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/01/security-advisory-979682-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Issues Critical Updates To Flash, AIR &#8211; Security Watch</title>
		<link>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/</link>
		<comments>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 09:11:25 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=276</guid>
		<description><![CDATA[Adobe released new versions of Flash and AIR today to address vulnerabilities in both products. Applying these updates as soon as practicable is a good idea, as Flash vulnerabilities are popular exploit vehicles in the wild. Click here to install Flash 10.0.42.34. Click here to install AIR 1.5.3. The expanded security advisory explains that critical [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe released new versions of Flash and AIR today to address vulnerabilities in both products. Applying these updates as soon as practicable is a good idea, as Flash vulnerabilities are popular exploit vehicles in the wild.</p>
<p><a href="http://get.adobe.com/flashplayer/" target="_blank">Click here to install Flash 10.0.42.34.</a></p>
<p><a href="http://get.adobe.com/air/" target="_blank">Click here to install AIR 1.5.3.</a></p>
<p><a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html" target="_self">The expanded security advisory</a> explains that critical vulnerabilities could provoke crashes or remote code execution. Adobe Flash Player 10.0.32.18 and earlier versions and Adobe AIR 1.5.2 and earlier versions on all platforms are vulnerable.</p>
<p>7 new vulnerabilities are described cursorily. A patch to an eighth and older vulnerability is also updated. Adobe issues thanks to 6 different researchers for the help they provided with the vulnerabilities.</p>
<p>The advisory also adds that Flash Player version 10.1, which Adobe expects to release in the first half of 2010, will be the last to support PowerPC-based G3 Macs. They are discontinuing support, including security updates, past that version because they are implementing performance enhancements not supported in those processors.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2009%2F12%2Fadobe-issues-critical-updates-to-flash-air-security-watch%2F&amp;title=Adobe%20Issues%20Critical%20Updates%20To%20Flash%2C%20AIR%20%E2%80%93%20Security%20Watch" id="wpa2a_20"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

