<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0">
	<channel>
		<title>iDefense Labs News</title>
		<link>http://labs.idefense.com/labs/</link>
		<description>Latest news feed from labs.idefense.com</description>
		<copyright>Copyright 2010 iDefense Labs</copyright>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		<language>en-US</language>
		<pubDate>Fri, 12 Mar 2010 18:09:40 UTC</pubDate>
		<lastBuildDate>Fri, 12 Mar 2010 18:09:40 UTC</lastBuildDate>
		<item>
			<title>Microsoft Security Bulletin: July 2009</title>
			<link>http://labs.idefense.com/news/msft/2009-07-14.php</link>
			<description>Microsoft Corp. has released six Security Bulletins encompassing nine vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 14 Jul 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: June 2009</title>
			<link>http://labs.idefense.com/news/msft/2009-06-09.php</link>
			<description>Microsoft Corp. has released 10 Security Bulletins encompassing 31 vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 09 Jun 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: May 2009</title>
			<link>http://labs.idefense.com/news/msft/2009-05-12.php</link>
			<description>Microsoft Corp. has released one Security Bulletin encompassing 14 vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 12 May 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: April 2009</title>
			<link>http://labs.idefense.com/news/msft/2009-04-14.php</link>
			<description>Microsoft Corp. has released eight Security Bulletins encompassing 23 vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 14 Apr 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: March 2009</title>
			<link>http://labs.idefense.com/news/msft/2009-03-10.php</link>
			<description>Microsoft Corp. has released three Security Bulletins encompassing eight vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 10 Mar 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: February 2009</title>
			<link>http://labs.idefense.com/news/msft/2009-02-10.php</link>
			<description>Microsoft Corp. has released four Security Bulletins encompassing eight vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 10 Feb 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>iDefense Awards $50,000 VCP Challenge Prize</title>
			<link>http://labs.idefense.com</link>
			<description>&lt;p&gt; Today VeriSign's iDefense Labs announced the list of winners for the First Annual Vulnerability Contributor Program (VCP) Challenge.  In 2008 iDefense scrapped their old Quarterly Challenge Program, whose prizes averaged around $5,000, for an annual program with more substantial prizes.  Says Andrew Scholnick, Director of the iDefense Labs and its VCP; &quot;Our intention in the VCP is to provide substantial reward to those vulnerability researchers who choose the ethical path outlined by our Responsible Disclosure policy.  It is a firm belief at iDefense that Full Disclosure programs, and even the more restrained Partial Disclosure policies of certain 'high profile' researchers, simply cause too much damage.  We are trying to make the point to all vulnerability researchers that, although the Responsible Disclosure process can be slower than less ethical methods at times, it is the most appropriate way to receive competitive compensation and recognition for their efforts.&quot; &lt;/p&gt;
&lt;p&gt; The new Annual Challenge awards prizes for the top overall contributors to the iDefense Labs VCP and/or the top quality individual VCP submissions processed by iDefense within a challenge year.  The prizes being awarded today include: &lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Grand Prize &amp;ndash; $50,000 (US) &amp;ndash; Michal &quot;regenrecht&quot; Luczaj&lt;/li&gt;
  &lt;li&gt;First Prize &amp;ndash; $25,000 (US) &amp;ndash; VCP researcher &quot;Zdenda&quot;&lt;/li&gt;
  &lt;li&gt;Second Prize &amp;ndash; $10,000 (US) &amp;ndash; An anonymous contributor from Russia&lt;/li&gt;
  &lt;li&gt;Tied for Third Prize &amp;ndash; $5,000 (US) &amp;ndash; VCP researcher &quot;sef0cus&quot;&lt;/li&gt;
  &lt;li&gt;Tied for Third Prize &amp;ndash; $5,000 (US) &amp;ndash; Silvio Cesare of Australia&lt;/li&gt;
  &lt;li&gt;Honorable Mention &amp;ndash; iPod nano &amp;ndash; Javier Vicente Vallejo&lt;/li&gt;
  &lt;li&gt;Honorable Mention &amp;ndash; iPod nano &amp;ndash; Stephen Fewer of Harmony Security&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; &lt;strong&gt;About the Winners:&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt; Michal Luczaj was selected as the Grand Prize winner this year both for a 'Sun Java JRE Decompression' vulnerability he submitted in September (disclosed by Sun Microsystems on December 2), and the consistent high quality of his research submissions (over a dozen this year).   Aside from being the first winner of the annual $50,000 Grand Prize, Mr. Luczaj has seen his average payments from iDefense more than double in the past six months as a result of the new payment structure in the VCP. &lt;/p&gt;
&lt;p&gt; Zdenda received the First Prize for a vulnerability that has yet to be disclosed, that was submitted to iDefense in July of 2008.  Compensation for this contributor's individual contributions have increased tenfold over what was paid in 2007. &lt;/p&gt;
&lt;p&gt; A Russian Contributor, who prefers to remain anonymous, took the Second Place prize for a vulnerability that has yet to be disclosed, that was submitted to iDefense in April of 2008.  This individual is one of our most prolific contributors, with over 30 submissions in the past year. &lt;/p&gt;
&lt;p&gt; Silvio Cesare of Australia won one of two Third Place prizes for a 'SNORT IP Fragment TTL Evasion' vulnerability submitted in January of 2008.  The other Third Place prize went to sef0cus for a vulnerability that has yet to be disclosed, that was submitted to iDefense in August of 2008. &lt;/p&gt;
&lt;p&gt; Two Honorable Mention prizes were also awarded to Stephen Fewer of Harmony Security and Javier Vicente Vallejo. &lt;/p&gt;</description>
			<pubDate>Thu, 15 Jan 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: January 2009</title>
			<link>http://labs.idefense.com/news/msft/2009-01-13.php</link>
			<description>Microsoft Corp. has released one Security Bulletin encompassing three vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 13 Jan 2009 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: December 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-12-09.php</link>
			<description>Microsoft Corp. has released eight Security Bulletins encompassing 28 vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 09 Dec 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: November 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-11-11.php</link>
			<description>Microsoft Corp. has released two Security Bulletins encompassing four vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 11 Nov 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: October 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-10-14.php</link>
			<description>Microsoft Corp. has released 11 Security Bulletins encompassing 20 vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 14 Oct 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: September 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-09-09.php</link>
			<description>Microsoft Corp. has released four Security Bulletins encompassing eight vulnerabilities. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 09 Sep 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: August 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-08-12.php</link>
			<description>Microsoft Corp. has released 11 security bulletins encompassing 26 vulnerabilities. This report provides 
an initial summary of these pending issues.</description>
			<pubDate>Tue, 12 Aug 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: July 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-07-08.php</link>
			<description>Microsoft Corp. has released four security bulletins encompassing nine vulnerabilities. This report provides 
an initial summary of these pending issues.</description>
			<pubDate>Tue, 08 Jul 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>2008: $50,000 Annual Vulnerability Challenge</title>
			<link>http://labs.idefense.com/vcp/challenge.php#more_2008%3A+%2450%2C000+annual+vulnerability+challenge</link>
			<description>&lt;p&gt;
      Prior to 2008, the old Challenge Program had awarded cash prizes for the best research submission targeting a specific technology over a 90 day period.  Many iDefense VCP contributors had complained that 90 days was simply not enough time to properly research a good vulnerability, and informed the VCP that more time was needed.  Recognizing that this was a fundamentally valid assertion, iDefense decided to &amp;lsquo;take the hint&amp;rsquo; and restructure the entire iDefense VCP Challenge Program. &lt;/p&gt;
    &lt;p&gt; As of July 1, 2008 the new VCP Challenge Program takes effect, considering all qualifying research submissions through the end of the calendar year (31 December).  Thereafter, the Challenge will consider all qualifying research accepted and compensated by the VCP Program that were received between the first day of January and the last day of December in each subsequent year.  Following the acceptance deadline the iDefense Labs Vulnerability Research Team (VRT) will determine the winners and award the prizes.  iDefense will award all cash prizes within thirty (30) days of the Challenge deadline.  Under no circumstances will any submission be considered for any of the current year&amp;rsquo;s Challenge prizes if the contributor has not accepted the iDefense VCP&amp;rsquo;s offer for compensation for the submission. &lt;/p&gt;</description>
			<pubDate>Wed, 02 Jul 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: June 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-06-10.php</link>
			<description>Microsoft Corp. has released seven security bulletins encompassing 10 vulnerabilities. This report provides 
an initial summary of these pending issues.</description>
			<pubDate>Tue, 10 Jun 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Spear Phishing and Whaling Attacks Reach Record Levels</title>
			<link>http://labs.idefense.com/news/press/display.php?id=37</link>
			<description>Targeted social engineering attacks against corporations have reached new highs during April and May 2008. These e-mail-based attacks, often referred to as &quot;spear phishing&quot; or &quot;whaling,' target individual users and contain personal information such as name, company, mailing address and phone number. Many of these attacks target senior executives and other high profile individuals</description>
			<pubDate>Sat, 07 Jun 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Symantec Moves to Threatcon 2 Based on Flash Vuln...</title>
			<link>http://labs.idefense.com/news/press/display.php?id=36</link>
			<description>On May 27, 2008, Symantec moved to Threatcon 2 based on information that a new and unpatched vulnerability in Adobe's Flash player was being exploited in the wild. Based on analysis of the sites provided by Symantec and exploit sites gathered from internal data, it is clear that an older vulnerability is currently being exploited. The vulnerability in question was found by Mark Dowd of ISS in a paper in which he describes a novel technique for exploiting null pointer dereference bugs.</description>
			<pubDate>Wed, 28 May 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: May 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-05-13.php</link>
			<description>Microsoft Corp. has released four security bulletins encompassing six vulnerabilities. This report provides 
an initial summary of these pending issues.</description>
			<pubDate>Tue, 13 May 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: April 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-04-08.php</link>
			<description>Microsoft Corp. has released eight security bulletins encompassing 10 vulnerabilities. Please note that Microsoft combined two similar iDefense Exclusive reports into one fix. Also note that iDefense has created a separate Threat report to include third-party ActiveX kill bits. This report provides an initial summary of these pending issues.</description>
			<pubDate>Tue, 08 Apr 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: March 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-03-11.php</link>
			<description>Microsoft Corp. has released four security bulletins encompassing 12 vulnerabilities. This report provides an 
initial summary of these pending issues.</description>
			<pubDate>Tue, 11 Mar 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: February 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-02-12.php</link>
			<description>Microsoft Corp. has released 11 security bulletins encompassing 17 vulnerabilities. This report provides an 
initial summary of these pending issues.</description>
			<pubDate>Tue, 12 Feb 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: January 2008</title>
			<link>http://labs.idefense.com/news/msft/2008-01-08.php</link>
			<description>Microsoft Corp. has released two security bulletins encompassing three vulnerabilities. This report provides an 
initial summary of these pending issues.</description>
			<pubDate>Tue, 08 Jan 2008 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: December 2007</title>
			<link>http://labs.idefense.com/news/msft/2007-12-11.php</link>
			<description>Microsoft Corp. has released seven security bulletins encompassing 11 vulnerabilities. This report provides an 
initial summary of these pending issues.</description>
			<pubDate>Tue, 11 Dec 2007 05:00:00 UTC</pubDate>
		</item>
		<item>
			<title>Microsoft Security Bulletin: November 2007</title>
			<link>http://labs.idefense.com/news/msft/2007-11-13.php</link>
			<description>Microsoft Corp. has released two security bulletins encompassing two vulnerabilities. This report provides an 
initial summary of these pending issues.</description>
			<pubDate>Tue, 13 Nov 2007 05:00:00 UTC</pubDate>
		</item>
	</channel>
</rss>
