<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<p style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><span style="font-family: Arial;" class="">In this issue:</span></p>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">1. Microsoft Security Updates for August 2015</div>
<div style="margin: 0px; font-family: Arial;" class="">2. Another Android Flaw Gives Apps Elevated Privileges</div>
<div style="margin: 0px; font-family: Helvetica;" class="">3. The Importance of Backups</div>
<div style="margin: 0px; font-family: Arial;" class="">4. Sophos AV Ends Support for Mac OS X 10.6 and 10.7</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">--------------------------------------------------------------</div>
<div style="margin: 0px; font-family: Arial;" class="">1. Microsoft Security Updates for August 2015</div>
<div style="margin: 0px; font-family: Arial;" class="">--------------------------------------------------------------</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">This week on Patch Tuesday, Microsoft released fourteen
<a href="https://technet.microsoft.com/en-us/library/security/ms15-aug.aspx" class="">
security bulletins</a>, four of which are considered critical.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Systems affected include Windows, Internet Explorer, Office, Silverlight, Microsoft .NET Framework, Microsoft Lync, and Microsoft Server Software. Some of the fixes are for Windows 10, including its newest
browser Microsoft Edge. An attacker could run malicious code on an affected machine if a user visits a specially-crafted webpage, allowing access at the logged-in user level.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Be sure to accept the updates as they occur, or go to the
<a href="http://www.update.microsoft.com/" class="">Windows Update</a> site. You may need to restart your machine after installing patches. </div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class=""><a href="http://www.zdnet.com/article/august-2015-patch-tuesday/" class="">Read the story in the news</a>.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">—————————————————————————</div>
<div style="margin: 0px; font-family: Arial;" class="">2. Another Android Flaw Gives Apps Elevated Privileges</div>
<div style="margin: 0px; font-family: Arial;" class="">---------------------------------------------------------------------------</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Close on the heels of <a href="http://ist.mit.edu/news/stagefright" class="">
Stagefright</a>, another vulnerability has been found to affect Android devices. A flaw in the OpenSSL X509Certificate class allows apps to elevate privileges, allowing them to snoop on vulnerable</div>
<div style="margin: 0px; font-family: Arial;" class="">devices, install malware, and cause other problems. More than half of Android handsets are believed to be vulnerable.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Google has provided a patch, but as with the patch for Stagefright, most people won’t receive it automatically. Ask your mobile carrier if a patch is available and if not, when you can expect it.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class=""><a href="http://www.theregister.co.uk/2015/08/10/another_android_flaw_hitting_55_percent_handsets/" class="">Read the story in the news</a>.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">-----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica;" class="">3. The Importance of Backups</div>
<div style="margin: 0px; font-family: Arial;" class="">-----------------------------------------</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">This month’s issue of OUCH! from SANS focuses on backups. Specifically, what backups are, how they work and how to create the best backup strategy. </div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">Unfortunately, too many people fail to realize how important backups can be. Backups provide peace of mind as well as business continuity. Think about how you would feel if a hard drive crashed and
you lost thousands of your family’s photos, or all of your work files.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class="">With a backup, either by using local storage media such as an external hard drive, or by using a cloud-based service, you can rest assured that everything can be recovered.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class=""><a href="http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201508_en.pdf" class="">Read (and download) the issue here (PDF)</a>.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica;" class=""><a href="http://ist.mit.edu/backup" class="">Learn more about backup options at MIT, including CrashPlan</a>.</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Helvetica; min-height: 17px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">—————————————————————————</div>
<div style="margin: 0px; font-family: Arial;" class="">4. Sophos AV Ends Support for Mac OS X 10.6 and 10.7</div>
<div style="margin: 0px; font-family: Arial;" class="">—————————————————————————</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Sophos Anti-Virus is ending support for Mac OS X 10.6 (Snow Leopard) and 10.7 (Lion) on
<b class="">October 31, 2015</b>. Computers running those operating systems will stop receiving Sophos updates after that date. Information regarding this change can be found at: </div>
<div style="margin: 0px; font-family: Arial;" class=""><a href="https://www.sophos.com/en-us/support/knowledgebase/122477.aspx" class="">https://www.sophos.com/en-us/support/knowledgebase/122477.aspx</a> </div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">Apple stopped releasing security updates for both OS X 10.6 (in February 2014) and 10.7 (in September 2014), so continuing to run computers with those operating systems on the network is not recommended.
IS&T strongly encourages you to upgrade those machines to the latest Mac OS if possible to ensure that they are protected.</div>
<div style="margin: 0px; font-family: Arial; min-height: 16px;" class=""><br class="">
</div>
<div style="margin: 0px; font-family: Arial;" class="">As always, MIT users who need help or have questions, can contact the IS&T Help Desk at 617.253.1101 or <a href="mailto:computing-help@mit.edu" class="">helpdesk@mit.edu</a>, or
<a href="http://ist.mit.edu/support" class="">submit a request online</a>. </div>
<div apple-content-edited="true" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
</div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
</div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
</div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
A copy of this newsletter can be read at: <font face="Avenir-Book" class=""><a href="https://ist.mit.edu/news/security_newsletter/08.14.2015" class="">https://ist.mit.edu/news/security_newsletter/08.14.2015</a></font></div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
</div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
Monique Buchanan<br class="">
Communications Specialist<br class="">
Information Systems & Technology (IS&T)<br class="">
Massachusetts Institute of Technology<br class="">
<a href="http://ist.mit.edu" class="">http://ist.mit.edu</a><br class="">
tel: 617.253.2715</div>
<div style="color: rgb(0, 0, 0); font-family: Avenir; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<br class="">
</div>
<br class="Apple-interchange-newline">
</div>
</div>
</div>
<br class="">
</div>
<br class="Apple-interchange-newline">
</div>
<br class="Apple-interchange-newline">
<br class="Apple-interchange-newline">
</div>
<br class="">
</body>
</html>