Global Security Watch > Q1 2008 - Client OS Vulnerability Scorecard

Jeff Jones Security Bloghttp://blogs.technet.com/security/archive/2008/05/15/q1-2008-client-os-vulnerability-scorecard.aspx [Jeff Jones Security Blog] This paper is a compilation of vulnerability data for client operating systems for the first 3 month, January through March, of 2008. Vulnerabilities and fixes for the following products are discussed:

Some related posts from Technorati and Google.

Domenicohttp://dovellas.spaces.live.com/blog/cns!B957C4A398135A12!1709.entry [Domenico] Q1 2008 - Client OS Vulnerability Scorecard: For January through March of 2008, Mac OS X users experienced the highest number of vulnerabilities as well as the highest number of High severity vulnerabilities while Windows Vista users experienced the fewest and the fewest High severity vulnerabilities.

Schneier on Security[Schneier on Security] Dual-Use Technologies and the Equities Issue: The National Security Agency has referred to this as the "equities issue," and it can be summarized as follows: When a military discovers a vulnerability in a dual-use technology, they can do one of two things. They can alert the manufacturer and fix the vulnerability, thereby protecting both the good guys and the bad guys.

politics News[politics News] America's Dilemma: Close Security Holes, or Exploit Them Ourselves: Because attackers and defenders use the same IT technology, there is a fundamental tension between cyberattack and cyberdefense. The National Security Agency has referred to this as the "equities issue," and it can be summarized as follows: When a military discovers a vulnerability in a dual-use technology, they can do one of two things.

IT Security News and Reviews[IT Security News and Reviews] Dual-Use Technologies and the Equities Issue: and it can be summarized as follows: When a warlike discovers a vulnerability in a dual-use technology, they have power to do one of two things. They can alert the manufacturer and fix the vulnerability, thereby protecting one as well as the other the good guys and the depraved guys.

Breaking Business News latest RSS headlines - Malaysia Sun.comhttp://story.malaysiasun.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/14537016/ [Breaking Business News latest RSS headlines - Malaysia Sun.com] Close Security Holes, or Exploit Them Ourselves: scorecard to tell the difference .It's not just that it's hard to trace people in cyberspace, it's that military and civilian attacks -- and defenses -- look the same.

Errorhttp://www.errorforum.com/security-news/42976-first-integrated-software-service-suite-security-compliance-qualys.html [Error] First Integrated Software-as-a-service Suite for Security and ...: On-demand vulnerability management with Qualysguard was not only easy to deploy – it also massively increased our overall efficiency in combating systems and infrastructure vulnerabilities while allowing each of our many local subsidiaries worldwide to prioritize their security activities more effectively, reduce overall risk and improve performance. This new converged product suite is further evidence of Qualys ability to evolve their service offering to meet our developing business needs with ease and transparency for us – a key strength of the Software-as-a-Service model”

TechNet Blogshttp://blogs.technet.com/security/archive/2007/08/16/july-2007-operating-system-vulnerability-scorecard.aspx [TechNet Blogs] July 2007 - Operating System Vulnerability Scorecard: When I started doing these scorecards, I did two variations - year-to-date and last-3-months - thinking that the latter would reflect short-term bursts of issues and that the former would give an overall view for the year that would incorporate the ups and downs.

Software PRNNhttp://www.prnewsnow.com/Public_Release/Software/199505.html [Software PRNN] Secure Elements Receives OVAL Repository Top Contributor Award for ...: "Secure Elements is proud to support the OVAL community by offering our expertise to accelerate availability of vulnerability checks during the monthly Patch Tuesday exercise," said Scott Carpenter, Chief Security Architect for Secure Elements. "This recognition reflects our commitment to author and contribute to industry leading, publicly available security content initiatives such as the OVAL Repository and for the NIST Information Security Automation Program (ISAP), where we have contributed content for auditing the Federal Desktop Core Configuration (FDCC) for Microsoft Windows XP and Windows Vista.

singleanzeigenhttp://singleanzeigen4856.colossi.se/2008/05/12/dont-want-to-be-a-phish-go-to-the-movies/ [singleanzeigen] Don’t Want To Be a Phish? Go to the Movies!: It is one thing to suggest being alert, paying attention, and raising your awareness of phishers and other Internet con artists, but if you are not used to this way of thinking, it can be hard to keep in mind. Without the habit of awareness, you might be more susceptible to clicking on a link and following instructions that phishers have provided as bait.

Österreichs Weblog[Österreichs Weblog] New Qualys Security and Compliance Suite Provides Reporting ...: Infosecurity Europe Tradeshow, London, UK - 22 April - Qualys today announced QualysGuard 6.0, an upgrade to its flagship solution for vulnerability and compliance management. QualysGuard 6.0 […]

SolidBLOG[SolidBLOG] A Study In Spin: Jones’s Vulnerability Scorecards are just way too narrow in focus to make any meaningful conclusions about the relative security of operating systems. And that goes against the quote you’ll find near the top of his security blog: .

Stop Her Now Blog[Stop Her Now Blog] Instant Debate Reactions: One thing that I would say, though, is that the debate revealed a lot of vulnerability in both candidates. On foreign policy, taxes, guns, social security, and on intangibles such as Clinton’s trustworthiness, Obama’s contortions on Jeremiah Wright and his “cling”

Microsoft TechNet Ireland Bloghttp://blogs.technet.com/ieitpro/archive/2007/06/21/vista-6-month-vulnerability-report.aspx [Microsoft TechNet Ireland Blog] Vista 6-Month Vulnerability Report: In this week's TechNet newsletter I referenced Jeff Jones' security blog and his 'April year to date security vulnerability scorecard'. However, he has just emailed me to let me know that he's literally just published the Windows Vista .

Reflected tags on Technorati: Blog, , , , ,