Busy month for Ops teams!

This month has seen Ops teams needing to install long list of critical updates coming from Microsoft, Adobe and Java on a very regular basis:

And a Polish security firm found yet other vulnerabilities in Java which have not been patched yet!

My recommendations about this are:

  • Limit the execution of Java applets to a limited list trusted websites only, or better to disable Java applets altogether
  • Auto-update as much as you can on the client side: Java, Flash, Chrome, Firefox, etc.
  • Push Microsoft update very rapidly on workstations, preferably immediatly: The risk (likelihood and impact) of something breaking is lower than the cost of cleaning up the environment/reputation after a breach

No comments:

Post a Comment