<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class="">In this issue:</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">1. OpenSSL Project Fixes 12 Security Issues</div>
<div style="margin: 0px; font-family: Arial;" class="">2. Apple Security Update</div>
<div style="margin: 0px; font-family: Arial;" class="">3. Security Training By SANS</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">————————————————————</div>
<div style="margin: 0px; font-family: Arial;" class="">1. OpenSSL Project Fixes 12 Security Issues</div>
<div style="margin: 0px; font-family: Arial;" class="">————————————————————</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">The OpenSSL Project has released fixes to address a dozen flaws in the open source cryptographic protocol implementation (<a href="https://www.openssl.org/news/secadv_20150319.txt" class="">OpenSSL Security
Advisory</a>). One of the vulnerabilities has been classified as high severity; it could be exploited to cause denial-of-service (DoS) conditions.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Users should update, however it’s nowhere near serious as Heartbleed was. </div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Who this affects: clients that connect to an OpenSSL 1.0.2 server. Earlier versions of OpenSSL are not affected.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class=""><a href="http://www.computerworld.com/article/2899482/openssl-fixes-serious-denial-of-service-bug-11-other-flaws.html" class="">Read the story in the news</a>.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">———————————</div>
<div style="margin: 0px; font-family: Arial;" class="">2. Apple Security Update</div>
<div style="margin: 0px; font-family: Arial;" class="">——————————— </div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Apple has issued its second security update this month. Turns out the security holes fixed the previous week
<a href="http://www.theregister.co.uk/2015/03/20/apple_remember_those_security_holes_we_fixed_last_week_yeah_youre_going_to_need_to_patch_them_again/" class="">
needed a repatch</a>. The company released security update 2015-003 for OS X Yosemite last week, addressing 2 vulnerabilities. One vulnerability could potentially allow an attacker with a "privileged network position" to execute arbitrary code. The other
vulnerability is an privilege escalation issue.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Users can update by going to the App Store and clicking Updates. To receive updates automatically, go to System Preferences > App Store, then check the boxes for installing and downloading available updates. </div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class=""><a href="https://support.apple.com/en-us/HT204563" class="">Learn more about this security update.</a></div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">—————————————</div>
<div style="margin: 0px; font-family: Arial;" class="">3. Security Training By SANS</div>
<div style="margin: 0px; font-family: Arial;" class="">—————————————</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">SANS (<a href="http://sans.org" class="">sans.org</a>) offers all kinds of training for professionals who are involved in cybersecurity. There are various ways to access their quality training material:
by attending a live conference, accessing your training on demand (online) or hosting a training session in your community.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Courses include a range of topics including: hacker tools and techniques, forensic analysis, intrusion detection, network penetration testing, incident response and many more.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Find a training by course, location or date:
<a href="http://www.sans.org/find-training/" class="">http://www.sans.org/find-training/</a></div>
<div style="margin: 0px; font-family: Arial;" class="">Find or host a training in your community:
<a href="http://www.sans.org/community/" class="">http://www.sans.org/community/</a></div>
<div style="margin: 0px; font-family: Arial;" class="">On demand training: <a href="http://www.sans.org/ondemand/" class="">
http://www.sans.org/ondemand/</a></div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">=======================================================================================</div>
<div style="margin: 0px; font-family: Helvetica;" class="">Read all archived Security FYI Newsletter articles and submit comments online at
<a href="http://securityfyi.wordpress.com/" class=""><span style="color: rgb(4, 46, 238);" class="">http://securityfyi.wordpress.com/</span></a>.</div>
<div style="margin: 0px; font-family: Helvetica;" class="">=======================================================================================</div>
<div class=""><br class="">
</div>
<br class="">
<br class="">
<div apple-content-edited="true" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Monique Buchanan<br class="">
Social Communications Specialist<br class="">
Information Systems & Technology (IS&T)<br class="">
Massachusetts Institute of Technology<br class="">
<a href="http://ist.mit.edu" class="">http://ist.mit.edu</a><br class="">
tel: 617.253.2715</div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
</div>
<br class="Apple-interchange-newline">
</div>
</div>
</div>
<br class="">
</div>
<br class="Apple-interchange-newline">
<br class="Apple-interchange-newline">
</div>
<br class="">
</body>
</html>