<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class="">In this issue:</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">1. Microsoft Security Updates</div>
<div style="margin: 0px; font-family: Helvetica;" class="">2. Security Predictions of 2015</div>
<div style="margin: 0px; font-family: Helvetica;" class="">3. Security Using Mobile Apps</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica;" class="">1. Microsoft Security Updates</div>
<div style="margin: 0px; font-family: Helvetica;" class="">----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">Microsoft has <a href="http://blogs.technet.com/b/msrc/archive/2015/01/07/evolving-advance-notification-service-ans-in-2015.aspx" class="">
changed its Advanced Notification Service</a>, in which they used to provide a public bulletin in advance of upcoming fixes occurring on Patch Tuesdays. The bulletins are no longer publicly available, except to Premier customers. </div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">Because this Security FYI newsletter is often written and sometimes distributed prior to the releases, you may see a change to the Microsoft Security Updates articles within this newsletter. Rather
than providing information about Patch Tuesday releases to you in advance, this newsletter will be reviewing them after they have been released.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class=""><a href="https://technet.microsoft.com/en-us/library/security/ms15-jan.aspx" class="">January’s security bulletins</a> consist of eight updates, one of which is considered critical. All impact Microsoft
Windows and Windows Server (all supported versions).</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">For those who wish to see security bulletins for Microsoft products that you or your work area use, go to
<a href="http://mybulletins.technet.microsoft.com/" class="">myBulletins</a>, where you can view, filter and download security bulletins for the products you select.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class=""><a href="http://www.zdnet.com/article/microsofts-advance-security-notification-service-no-longer-publicly-available/" class="">Read the story in the news</a>.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">-----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica;" class="">2. Security Predictions of 2015</div>
<div style="margin: 0px; font-family: Helvetica;" class="">-----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">What will be this year’s biggest security threats? Each time January rolls around, security professionals look at past threats and try to determine what will happen in the upcoming year. It’s a good
idea to be one step ahead of criminal hackers, but it isn’t always possible.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class=""><a href="http://www.wired.com/2015/01/security-predictions-2015/" class="">This article in Wired</a> reviews several on-going threats it considers at the top of the list:</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<ul class="">
<li style="margin: 0px; font-family: Helvetica;" class="">Nation-State Attacks: government intelligence agencies that
<a href="http://www.wired.com/2014/11/mysteries-of-the-malware-regin/" class="">use malware to eavesdrop</a> on telecommunication systems, for example
</li><li style="margin: 0px; font-family: Helvetica;" class="">Extortion: on a larger scale we saw the attack on Sony Pictures, on a smaller scale there is ransomware that targets individuals
</li><li style="margin: 0px; font-family: Helvetica;" class="">Data Destruction: similar to the ransomware threats, but this malware wipes data and master boot records
</li><li style="margin: 0px; font-family: Helvetica;" class="">Bank Card Breaches: hacking point-of-sale systems, skimmers, and other methods of stealing card data
</li><li style="margin: 0px; font-family: Helvetica;" class="">Third-Party Breaches: a company or service is hacked solely for the purpose of obtaining data from a more important target
</li><li style="margin: 0px; font-family: Helvetica;" class="">Critical Infrastructure: attacks that aim to sabotage various programs or services
</li></ul>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class=""><a href="http://www.wired.com/2015/01/security-predictions-2015/" class="">Read the article in full online.</a></div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica;" class="">3. Security Using Mobile Apps</div>
<div style="margin: 0px; font-family: Helvetica;" class="">----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">Many of you may have received a new mobile device for the holidays.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class=""><a href="http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201501_en.pdf" class="">This month’s issue of OUCH!</a> (.pdf) covers how to securely use mobile apps. Being one of the primary
technologies we use in our professional and personal lives, mobile devices are used to be more productive, communicate, and share information with others or just have fun. However, using the apps on mobile devices can be risky. This issue describes some steps
you can take to securely use and maintain your mobile apps.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">If you have any questions or concerns about using and setting up your mobile device, you can also go to the
<a href="http://kb.mit.edu/confluence/display/istcontrib/Mobile+Device+Support" class="">
Mobile Device Support page in the Knowledge Base</a>.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">=======================================================================================</div>
<div style="margin: 0px; font-family: Helvetica;" class="">Read all archived Security FYI Newsletter articles and submit comments online at
<a href="http://securityfyi.wordpress.com/" class=""><span style="color: rgb(4, 46, 238);" class="">http://securityfyi.wordpress.com/</span></a>.</div>
<div style="margin: 0px; font-family: Helvetica;" class="">=======================================================================================</div>
<div apple-content-edited="true" class="">
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
Monique Buchanan<br class="">
IT Security Communications Coordinator<br class="">
Information Systems & Technology (IS&T)<br class="">
Massachusetts Institute of Technology<br class="">
<a href="http://ist.mit.edu/secure" class="">http://ist.mit.edu/secure</a><br class="">
tel: 617.253.2715</div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
</div>
<br class="Apple-interchange-newline">
</div>
</div>
</div>
<br class="">
<br class="Apple-interchange-newline">
</div>
<br class="">
</body>
</html>