Latest news
Following Adobe's recent release of Creative Suite 6 and its statement that it will not be patching critical security vulnerabilities in previous versions of the popular software the suite includes, security experts and users have voiced their indignation.According to Adobe, the users had either the option to upgrade to CS6 - and pay $375 for the upgrade - or to keep using CS5 and CS5.5 and "follow security best practices and exercise caution when opening files from unknown or untrusted sources."
"No dot release was scheduled or released for Adobe Photoshop CS5," a company spokeswoman explained the reason behind their decision. "In looking at all aspects, including the vulnerabilities themselves and the threat landscape, the team did not believe the real-world risk to customers warranted an out-of-band release for the CS5 version to resolve these issues."
But a day later, they changed their tune. Faced with a backlash from angry customers, Adobe bowed to the pressure and backpedalled on its original decision, deciding to patch the eight vulnerabilities in question free of charge.
"We are in the process of resolving the vulnerabilities addressed in these security bulletins in Adobe Illustrator CS5.x, Adobe Photoshop CS5.x and Adobe Flash Professional CS5.x, and will update the respective security bulletins once the patches are available," they stated.
They did not say how long it will take for the patches to be issued.


Spotlight

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.




