| Here’s my latest IBM ParnterWorld newsletter: |
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Here’s my latest IBM ParnterWorld newsletter: |
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I received the following weekly newsletter from Toshiba:
|
|
||||||||||||
|
||||||||||||
|
|
||||||||||||
|
Hello Luke Conaway,
Education is valuable at all times, and especially in tough economic times. Possessing a Cisco Career Certification demonstrates both to employers and coworkers, your unquestionable ability to successfully solve problems, implement projects and meet technical challenges. Learning@Cisco addresses technical talent needs across the globe by providing resources, training, certifications, and consulting services.
Take advantage of the many resources available to you:
Register for the Learning@Cisco monthly newsletter to keep yourself updated on new programs, tools, training and exams that allow you to stand out from the crowd in your organization and the market.
Visit the Cisco Learning Network, the online social learning community from Learning@Cisco provides you the ability to discuss top of mind issues, learn about Cisco Career Certifications, share expertise and interact with IT professionals and Cisco experts from around the world.
FREE Self-Assessments which will evaluate what you already know and recommend training and guidance for you to take the next steps on your learning path. Learning@Cisco Self-Assessments are available for Routing and Switching, Voice, Security and Wireless. Take your FREE Self-Assessments here.
Don’t forget to click here to sign up to receive valuable information about Cisco training and certifications.
Learning@Cisco
Cisco Notification Service Alert:
Cisco Notification Alert -All Prod and Tech Messages_Daily-07/30/2009 08:35 GMT
End-of-Sale and End-of-Life Announcements-All Products-07/29/2009 09:15 GMT-07/30/2009 07:39 GMT
No updates available in this time period
For more information you can visit the End-of-Sale and End-of-Life Products index: http://www.cisco.com/en/US/products/hw/tsd_products_support_end-of-sale_and_end-of-life_products_list.html
End-of-Sale and End-of-Life Announcements-All Technologies-07/29/2009 09:15 GMT-07/30/2009 07:39 GMT
No updates available in this time period
For more information you can visit the End-of-Sale and End-of-Life Products index: http://www.cisco.com/en/US/products/hw/tsd_products_support_end-of-sale_and_end-of-life_products_list.html
Field Notices-All Products-07/29/2009 09:15 GMT-07/30/2009 07:39 GMT
No updates available in this time period
For more information you can visit the Product Field Notice Summary: http://www.cisco.com/en/US/support/tsd_products_field_notice_summary.html
Field Notices-All Technologies-07/29/2009 09:15 GMT-07/30/2009 07:39 GMT
No updates available in this time period
For more information you can visit the Product Field Notice Summary: http://www.cisco.com/en/US/support/tsd_products_field_notice_summary.html
Security Advisories-All Products-07/29/2009 09:15 GMT-07/30/2009 07:39 GMT
Title: Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities
Url: http://www.cisco.com/en/US/partner/products/products_security_advisory09186a0080aea4c9.shtml
Description: Recent versions of Cisco IOS Software support RFC4893 (”BGP Support for Four-octet AS Number Space”) and contain two remote denial of service (DoS) vulnerabilities when handling specific Border Gateway Protocol (BGP) updates.
Date: 2009-07-29 07:00:00.0
For more information; you can visit Cisco Security Advisories & Responses Index: http://www.cisco.com/en/US/products/products_security_advisories_listing.html
Security Advisories-All Technologies-07/29/2009 09:15 GMT-07/30/2009 07:39 GMT
No updates available in this time period
For more information; you can visit Cisco Security Advisories & Responses Index: http://www.cisco.com/en/US/products/products_security_advisories_listing.html
Voice Commands and More on your BlackBerry smartphone
Are you thinking about a new BlackBerry® smartphone? Now is the time to check out the new BlackBerry devices available from your carrier. Once you’ve done that, take some time to learn how you can use your BlackBerry smartphone virtually hands-free! You can use your voice for dialing and you can assign functions to specific keys to help enhance usability.
In addition to what exists on your BlackBerry smartphone there are applications available in BlackBerry App World™ to further assist with integrating voice and phone functionality.
Click here to learn more from your desktop computer.
Encourage others to join so they may maximize their BlackBerry smartphone experience.
Click here to invite your friends to the BlackBerry Owners Lounge!
|
||||||
|
Control eDiscovery Costs: Reduce the Volume, Reduce the Expense |
||||||
|
|
||||||
|
Here’s the latest version of Cisco Tech Wise, as usual it’s a good read! Read it! Learn things! It’s good for your brain.
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||
You Have the Power! What would you like to see in future issues? Tell Us. |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||
Message-Id: <20090728081839.5E90.11352-91891@emessages.cisco.com>
![]()
I received the following IPS bulletin:
|
|||||||||
|
|
||||||||||||||
|
|
IN THIS ISSUE: 1. Announcing the S420 Signature Update for IPS 2. The Cisco IPS Active Update Bulletin is changing! 3. Announcing IPS Version 6.0(6)E3 Service Pack 4. Cisco Announces IPS Software 7.0 with Global Correlation 5. Cisco IDS 4235 and IDS 4250 sensors end of signature support 6. EOS and EOL dates for Cisco IPS Sensor Software Version 6.1 7. Cisco IPS Signature correlation available in the Cisco Security IntelliShield Alert Manager Service 8. Subscribe to the Product Alert Tool for IPS Related Field Issues
1. Announcing the S420 Signature Update for IPS The S420 signature update contains the following new signatures:
The S420 signature update contains the following modified signatures: There are no tuned signatures for this release. Modified signature details: None. IMPORTANT NOTES:
All signature updates are cumulative. The S420 signature update contains all previously released signature updates.
You must have a valid Cisco Services for IPS contract per sensor to receive and use software upgrades including
signature updates from Cisco.com.
A Cisco Services for IPS Services License is required for the installation of all signature updates. The Cisco Services
for IPS Services License can be requested from http://www.cisco.com/go/license for all sensors covered by a
maintenance contract.
To manage your maintenance contracts use the Service Contract Center:
http://www.cisco.com/cgi-bin/front.x/scccibdispatch?AppName=ContractAgent
SUPPORTED PLATFORMS:
The S420 signature update can ONLY be applied to E3 sensors.
IPS S420 Software Update Files:
Please note that the signature update download location has changed.
Sensor appliances, IDSM2, NM-CIDS, ASA-SSM-AIP modules: click here
IOS IPS in 12.4(11)T or later T-Train Releases:
http://www.cisco.com/pcgi-bin/tablebuild.pl/ios-v5sigup
Note: Posting of signature release files for IOS IPS may take a few additional days.
CISCO SECURITY MANAGER (CSM) NOTICE:
Note 1:
You can only apply the IPS-CS-MGR-sig-S420-req-E3.zip signature update file to CSM 3.0 or later and IPS MC version 2.2 or
later. The E3 Engine Update packages for sensors are deployed automatically the first time a signature set that requires
E3 is deployed by CSM. E3 updates are not listed or available for selection in the Apply Update Wizard and cannot be
applied independently by CSM. To ensure that the E3 update is applied to your sensors, please ensure
that you push the S366 package to your sensors.
2. The Cisco IPS Active Update Bulletin is changing! As part of our continuous improvements to Cisco IPS, we are updating the Cisco IPS Active Update Bulletin. Expect an improved layout, more information, faster access to the links you need and much more! Watch your inbox – the improved bulletin will arrive in a few short weeks!
3. Announcing IPS Version 6.0(6)E3 Service Pack The 6.0(6)E3 Service Pack for Cisco IPS Version 6.0 sensors is available for download. This release includes bug fixes and stability improvements for the 6.0 sensor code. All customers running 6.0(5)E3 or 6.0(5p2)E3 are encouraged to apply the 6.0(6)E3 update. See the readme file for the details of this release.
Downloads are available here.
4. Cisco Announces IPS Software 7.0 with Global Correlation Cisco is pleased to announce sensor software version 7.0 with Global Correlation. Global Correlation is a new approach to threat management that harnesses the networked power of Cisco Security Intelligence Operations (SIO) to identify and prevent attacks more quickly and effectively than stand-alone security technologies.
With Global Correlation, Cisco IPS receives global threat updates from Cisco every five minutes, gaining rapid visibility into the reputation of known attackers and networked threats, as well as propagation and mutation trends. This added context enables Cisco IPS to stop twice as much malicious activity as traditional IPS systems that rely on local inspection only. Cisco IPS v7.0 with Global Correlation is available now to all Cisco IPS customers with current Cisco Services for IPS support contracts. IPS v7.0 is available for all ASA AIP modules, 4240 4255, 4260, 4270 sensor appliances, NME-IPS, and AIM-IPS Network Modules and the IDSM2 module and can be downloaded from the Cisco Security Software Center using your existing valid support license. The Release notes for IPS 7.0 are available at this location.
5. Cisco IDS 4235 and IDS 4250 sensors end of signature support Cisco IDS 4235 and IDS 4250 sensors have reached end of signature support. If you are still using IDS 4235 and IDS 4250 sensors, please contact your Cisco sales representative regarding migration plans to newer Cisco IPS sensors. More information including recommended migration options is available at this web page: http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/prod_eol_notices_list.html
6. EOS and EOL dates for Cisco IPS Sensor Software Version 6.1 Cisco announces the end-of-sale and end-of life dates for Cisco IPS Sensor Software Version 6.1. After December 14, 2009, signatures and engine updates will no longer be released for Cisco IPS Sensor Software Version 6.1. Customers are encouraged to migrate to Sensor Software Version 6.2 or Sensor Software Version 7.0 with Global Correlation. Click here to download sensor software updates.
More information is available at the End of Sale Page on Cisco.com.
The Cisco IPS Team is pleased to announce the correlation of Cisco IPS Signature information within the IntelliShield Alert Manager Search Access Feature. Cisco Services for IPS clients that subscribe to the service now have access to perform targeted searches to display Cisco IPS Signatures associated with different alerts to ensure they have the most up to date intelligence. Subscribers can view a new IPS Signature list page that is searchable and will display Cisco IPS Signatures associated with IntelliShield Alerts. IntelliShield Alerts also contain the associated Cisco IPS Signature information within each alert.
The IntelliShield Alert Manager Search Access Feature provides clients with access to one of the most extensive collections of vendor-neutral security intelligence alerts in the industry. Clients can access a fully indexed and searchable database that extends back over six years and contains more than 1700 vendors, 5500 products, and 20,000 distinct versions of applications. To obtain access to the IntelliShield Alert Manager Search Access Feature, each user is required to provide either a valid IPS License File or a valid IPS Serial Number to authorize the creation of this user account. Only one user account is permitted for each IPS License File or IPS Serial Number. Please proceed to the registration page at the following link to obtain your access: https://intellishield.cisco.com/security/alertmanager/intelliShieldSearch Email support is available for users of the Cisco Security IntelliShield Alert Manager Service Search Access Feature at intellishieldsearch-support@cisco.com . Support is provided by Cisco during the hours of 7:00 a.m. and 7:00 p.m. Eastern Time.
8. Subscribe to the Product Alert Tool for IPS Related Field Issues Interested in knowing the latest on field notices, product alerts, and end-of-sale information relating to your IDS and IPS hardware? We have recently updated the Cisco Product Alert Tool to include IDS and IPS appliances. Simply visit: http://tools.cisco.com/Support/PAT/do/ViewMyProfiles.do and follow these steps: - Select Create a new Alert Profile. You will be kept up to date with the latest news on your IPS hardware appliances.
If you wish to receive this bulletin, you can subscribe now. Your opinions are important to us. If you have feedback about the Active Update Bulletin, please contact us at ips-news@cisco.com. For technical support, sales or other issues, please contact your authorized Cisco reseller or Cisco TAC. Please note that technical support or sales questions sent to this address will not be answered or redirected. |
|
||||||||||||
|
|
||||||||||||||
|
Additional Information |
|
|
||
|
|
|
|
|
|
||
|
Links
|
I got the following IPS notifications from Cisco TAC.
|
The following alert is now from US-Cert:
US-CERT Current Activity
FCKeditor Releases Version 2.6.4.1
Original release date: July 6, 2009 at 12:37 pm Last revised: July 9, 2009 at 11:39 am
The FCKeditor project has released FCKeditor version 2.6.4.1 to address a vulnerability. This vulnerability is due to improper verification of input passed to the “CurrentFolder” parameter.
Exploitation of this vulnerability may allow an attacker to execute arbitrary code.
Additionally, FCKeditor is part of Adobe ColdFusion 8 and is enabled by default. The Adobe Product Security Incident Response Team (PSIRT) has posted a blog entry indicating that they are aware of public reports of ColdFusion websites being targeted for exploitation of this vulnerability.
US-CERT encourages users and administrators to upgrade to FCKeditor version 2.6.4.1 to help mitigate the risks. ColdFusion 8 users should review Adobe security bulletin APSB09-09 and apply the hotfix to help mitigate the risks.
Relevant Url(s):
<http://www.fckeditor.net/download>
<http://blogs.adobe.com/psirt/2009/07/potential_coldfusion_security.html>
<http://www.adobe.com/support/security/bulletins/apsb09-09.html>
====
This entry is available at
http://www.us-cert.gov/current/index.html#fckeditor_releases_version_2_6