Showing posts with label ops. Show all posts
Showing posts with label ops. Show all posts

Busy month for Ops teams!

This month has seen Ops teams needing to install long list of critical updates coming from Microsoft, Adobe and Java on a very regular basis:

And a Polish security firm found yet other vulnerabilities in Java which have not been patched yet!

My recommendations about this are:

  • Limit the execution of Java applets to a limited list trusted websites only, or better to disable Java applets altogether
  • Auto-update as much as you can on the client side: Java, Flash, Chrome, Firefox, etc.
  • Push Microsoft update very rapidly on workstations, preferably immediatly: The risk (likelihood and impact) of something breaking is lower than the cost of cleaning up the environment/reputation after a breach