<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.microsoft.co.il/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Idan &amp;amp; Ohad Plotnik&amp;#39;s  Forefront Blog</title><link>http://blogs.microsoft.co.il/blogs/plotniko/</link><description>Forefront MVP - 



www.ForefrontSecurity.ORG</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><item><title>Expanding the areas of knowledge sharing in the blog - Microsoft Identity And Security Blog.</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/05/05/expanding-the-areas-of-knowledge-sharing-in-the-blog-microsoft-identity-and-security-blog.aspx</link><pubDate>Sun, 05 May 2013 14:14:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1997678</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1997678</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/05/05/expanding-the-areas-of-knowledge-sharing-in-the-blog-microsoft-identity-and-security-blog.aspx#comments</comments><description>&lt;p&gt;Hi guys,&lt;br /&gt;&amp;nbsp;&lt;br /&gt;So it&amp;#39;s been 4 years :)&lt;br /&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/plotniko/archive/2009/06.aspx"&gt;http://blogs.microsoft.co.il/blogs/plotniko/archive/2009/06.aspx&lt;/a&gt;&lt;br /&gt;That I’m writing this blog and sharing the Forefront security \ protection information with you.&lt;/p&gt;&lt;p&gt;My specialty over the years has focused on securing information in the Microsoft environment, and i tried sharing my experience with you.&lt;br /&gt;If so, and with the changes that have happened recently,&lt;br /&gt;I will expand the blog expertise, and focus on the general field of information security in Microsoft including:&lt;br /&gt;The growing field of identity and security - &lt;br /&gt;AD DS security&lt;br /&gt;AD FS&lt;br /&gt;AD LDS&lt;br /&gt;AD RMS&lt;br /&gt;FIM&lt;br /&gt;And more... &lt;/p&gt;&lt;p&gt;Hope you will enjoy my blog,&lt;br /&gt;And that I’ll help you expand your knowledge, install, implement, troubleshoot, explore and develop information security products, in the Microsoft world, and in your Microsoft infrastructure systems.&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;VP Professional Services, MVP &lt;br /&gt;Aorato LTD.&lt;br /&gt;Never been hacked? You’re not looking close enough.&lt;br /&gt;&lt;a href="http://www.Aorato.com"&gt;www.Aorato.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1997678" width="1" height="1"&gt;</description></item><item><title> Securing Active Directory</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/05/05/securing-active-directory.aspx</link><pubDate>Sun, 05 May 2013 13:25:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1997656</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1997656</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/05/05/securing-active-directory.aspx#comments</comments><description>&lt;p&gt;Hi Guys!&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The threat of compromise to IT infrastructures from external attack is rapidly growing and evolving. The Active Directory environment is often the target for these attacks. This article details steps that your organization can take to protect its Active Directory environment.&lt;/p&gt;&lt;p&gt;The document Contains recommendations to enhance the security of Active Directory installations, discusses common attacks against Active Directory and countermeasures to reduce the attack surface, and offers recommendations for recovery.&lt;/p&gt;&lt;p&gt;For the following operating systems:&lt;br /&gt;Windows Server 2008, Windows Server 2008 R2, Windows Server 2012&lt;/p&gt;&lt;p&gt;So, Securing Active Directory: An Overview of Best Practices:&lt;br /&gt;&lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=38815&amp;amp;WT.mc_id=rss_alldownloads_all"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=38815&amp;amp;WT.mc_id=rss_alldownloads_all&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The Best Practices for Securing Active Directory:&lt;br /&gt;&lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=38785"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=38785&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The chapters:&lt;/p&gt;&lt;p&gt;Executive Summary&lt;br /&gt;Introduction&lt;br /&gt;Avenues to Compromise&lt;br /&gt;Reducing the Active Directory Attack Surface&lt;br /&gt;Monitoring Active Directory for Signs of Compromise&lt;br /&gt;Planning For Compromise&lt;br /&gt;Summary of Best Practices&lt;br /&gt;Appendices&lt;/p&gt;&lt;p&gt;&lt;br /&gt;I really recommend the appendices section! You can get a lot of valuable information there.&lt;/p&gt;&lt;p&gt;As part of the protection faze, if your organization is using any monitoring mechanism (SIEM for example), read the &amp;quot;Events to Monitor&amp;quot; appendix.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Just a reminder:&lt;/p&gt;&lt;p&gt;A year and a half ago, we presented the &amp;quot;Hacking and Securing Active Directory&amp;quot; security group meeting:&lt;br /&gt;Hacking &amp;amp; Securing Active Directory:&lt;br /&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/plotniko/archive/2011/12/17/hacking-amp-securing-active-directory.aspx"&gt;http://blogs.microsoft.co.il/blogs/plotniko/archive/2011/12/17/hacking-amp-securing-active-directory.aspx&lt;/a&gt;&lt;/p&gt;&lt;p&gt;It was a very valuable meeting, and it was great hearing from the community their opinion on AD security today.&lt;/p&gt;&lt;p&gt;We are planning another session like that, I’ll update.&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;VP Professional Services, MVP &lt;br /&gt;Aorato LTD.&lt;br /&gt;Never been hacked? You’re not looking close enough.&lt;br /&gt;&lt;a href="http://www.Aorato.com"&gt;www.Aorato.com&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1997656" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Update Rollup 1 for Active Directory Rights Management Services Client 2.0 (KB2821183)</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/04/14/update-rollup-1-for-active-directory-rights-management-services-client-2-0-kb2821183.aspx</link><pubDate>Sun, 14 Apr 2013 08:40:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1898231</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1898231</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/04/14/update-rollup-1-for-active-directory-rights-management-services-client-2-0-kb2821183.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp;Hi Guys,&lt;/p&gt;&lt;p&gt;&amp;nbsp;So, There is a new update rollup 1 for the AD RMS client 2.0.&lt;/p&gt;&lt;p&gt;&amp;nbsp;Installed and checked in my lab.&lt;/p&gt;&lt;p&gt;FYI:&lt;/p&gt;&lt;p&gt;This update fixes the problems described in KB article 2821183. Active Directory Rights Management Services Client 2.1 (AD RMS Client 2.1) is software designed for your client computers to help protect access to and usage of information flowing through applications that use AD RMS whether installed on your premises or in a Microsoft datacenter. AD RMS Client 2.1 provides numerous updates and bug fixes found in AD RMS Client 2.0. AD RMS Client 2.1 also adds support for automation document protection.&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;VP Professional Services, MVP &lt;br /&gt;Aorato LTD.&lt;br /&gt;Never been hacked? You’re not looking close enough.&lt;br /&gt;&lt;a href="http://www.Aorato.com"&gt;www.Aorato.com&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1898231" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Important! Vulnerability in Active Directory Could Lead to Denial of Service (2830914)</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/04/11/important-vulnerability-in-active-directory-could-lead-to-denial-of-service-2830914.aspx</link><pubDate>Thu, 11 Apr 2013 17:04:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1886187</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1886187</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/04/11/important-vulnerability-in-active-directory-could-lead-to-denial-of-service-2830914.aspx#comments</comments><description>&lt;p&gt;Guys!&lt;/p&gt;&lt;p&gt;This vulnerability Is critical! &lt;/p&gt;&lt;p&gt;Affected on AD servers (Domain Controllers) till Windows Server 2012 ! &lt;/p&gt;&lt;p&gt;Windows Server 2008 for Itanium-based Systems is not affected.&lt;/p&gt;&lt;p&gt;Please review and take actions:&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-032"&gt;http://technet.microsoft.com/en-us/security/bulletin/ms13-032&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;VP Professional Services, MVP &lt;br /&gt;Aorato LTD.&lt;br /&gt;Never been hacked? You’re not looking close enough.&lt;br /&gt;&lt;a href="http://www.Aorato.com"&gt;www.Aorato.com&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1886187" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>FIM 2010 R2 SP1 has been Released!</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/01/09/fim-2010-r2-sp1-has-been-released.aspx</link><pubDate>Wed, 09 Jan 2013 09:05:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1644259</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1644259</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2013/01/09/fim-2010-r2-sp1-has-been-released.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Hello Forefront Guys,&lt;/p&gt;&lt;p&gt;On the Andreas Kjellman talk at the first annual Oxford Computer Group Redmond Identity, Access &amp;amp; Directory Summit at Microsoft HQ, the SP1 for Forefront Identity Manager 2010 R2 was announced!&lt;/p&gt;&lt;p&gt;Not much information about the changes, Part of the changes in the SP1, including support for 2013 releases (Sharepoint etc&amp;#39;...)&lt;/p&gt;&lt;p&gt;you can download via your MSDN subscriber benefits.&lt;/p&gt;&lt;p&gt;The KB that will be released is KB2772429.&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;Identity and Security Architect, MVP &lt;/p&gt;&lt;p&gt;Foreity LTD – Intelligent Security &lt;/p&gt;&lt;p&gt;Forums.ForefrontSecurity.org&lt;br /&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1644259" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Forefront Product Roadmaps</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/09/12/forefront-product-roadmaps.aspx</link><pubDate>Wed, 12 Sep 2012 22:09:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1279743</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1279743</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/09/12/forefront-product-roadmaps.aspx#comments</comments><description>&lt;p&gt;Hello All,&lt;/p&gt;&lt;p&gt;After a lot of Rumors on end of life for TMG etc&amp;#39;...
&lt;/p&gt;&lt;p&gt;Microsoft officially announces today the long-term planning for Forefront products:
&lt;/p&gt;&lt;p&gt;

&amp;quot;Today, as a result of our effort to better align security and protection solutions with the workloads and applications they protect, Microsoft is announcing changes to the roadmaps of some of the security solutions made available under the Forefront brand.&amp;quot;


For More Information:
&lt;/p&gt;&lt;p&gt;&lt;a title="http://blogs.technet.com/b/server-cloud/archive/2012/09/12/important-changes-to-forefront-product-roadmaps.aspx " href="http://blogs.technet.com/b/server-cloud/archive/2012/09/12/important-changes-to-forefront-product-roadmaps.aspx%20" target="_blank"&gt;http://blogs.technet.com/b/server-cloud/archive/2012/09/12/important-changes-to-forefront-product-roadmaps.aspx &lt;/a&gt;&lt;/p&gt;&lt;p&gt;Thanks,
&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;Identity and Security Architect, MVP &lt;/p&gt;&lt;p&gt;Foreity LTD – Intelligent Security &lt;/p&gt;&lt;p&gt;www.ForefrontSecurity.org 

&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1279743" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Microsoft protects against the "Flame" Virus !</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/05/30/microsoft-protects-against-the-quot-flame-quot-virus.aspx</link><pubDate>Wed, 30 May 2012 14:18:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1107071</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1107071</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/05/30/microsoft-protects-against-the-quot-flame-quot-virus.aspx#comments</comments><description>&lt;p&gt;Hello,&lt;/p&gt;&lt;p&gt;We are happy to announce that This threat is detected by the Microsoft antivirus engine.&lt;br /&gt;And the Microsoft MMPC updated the signature and it is now protecting from the new threat.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;For more information:&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://forums.forefrontsecurity.org/default.aspx?g=posts&amp;amp;m=2980#post2980"&gt;http://forums.forefrontsecurity.org/default.aspx?g=posts&amp;amp;m=2980#post2980&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Stay Up To Date !&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;Identity and Security Architect, MVP &lt;/p&gt;&lt;p&gt;Foreity LTD – Intelligent Security &lt;/p&gt;&lt;p&gt;www.ForefrontSecurity.org &lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1107071" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Active Directory Rights Management Service Client 2.0 is out!</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/05/29/active-directory-rights-management-service-client-2-0-is-out.aspx</link><pubDate>Tue, 29 May 2012 14:56:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1105887</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1105887</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/05/29/active-directory-rights-management-service-client-2-0-is-out.aspx#comments</comments><description>&lt;p&gt;Hi Security guys,&lt;/p&gt;&lt;p&gt;Microsoft announced the Active Directory Rights Management Service Client 2.0.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;AD RMS Client 2.0 is software designed for your client computers&lt;br /&gt;To help protect access to and usage of information flowing through applications that use AD RMS whether installed on your premises or in a Microsoft datacenter.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;For more information and download:&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=29892"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=29892&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;br /&gt;Identity and Security Architect, MVP&lt;/p&gt;&lt;p&gt;Foreity LTD – Intelligent Security&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.forefrontsecurity.org/"&gt;&lt;font color="#006bad"&gt;www.ForefrontSecurity.org&lt;/font&gt;&lt;/a&gt; &lt;br /&gt;&lt;/p&gt;&lt;a title="http://www.microsoft.com/en-us/download/details.aspx?id=29892&amp;#13;" href="http://www.microsoft.com/en-us/download/details.aspx?id=29892" rel="nofollow" target="_blank"&gt;&lt;/a&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1105887" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>New Advanced Cyber Threat - Virus "Worm.Win32.Flame" </title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/05/29/new-advanced-cyber-threat-virus-quot-worm-win32-flame-quot.aspx</link><pubDate>Tue, 29 May 2012 14:52:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1105884</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1105884</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/05/29/new-advanced-cyber-threat-virus-quot-worm-win32-flame-quot.aspx#comments</comments><description>&lt;p&gt;Hi Security guys,&lt;/p&gt;&lt;p&gt;


I want to update you that Kaspersky labs announce a sophisticated malicious worm,
 that is actively being used as a cyber-weapon attacking entities in several countries mainly in the Middle East. 


&lt;/p&gt;&lt;p&gt;For more information:


&lt;/p&gt;&lt;p&gt;&lt;a href="http://forums.forefrontsecurity.org/default.aspx?g=posts&amp;amp;m=2978#post2978"&gt;http://forums.forefrontsecurity.org/default.aspx?g=posts&amp;amp;m=2978#post2978&lt;/a&gt;


&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.kaspersky.com/about/news/virus/2012/Kaspersky_Lab_and_ITU_Research_Reveals_New_Advanced_Cyber_Threat"&gt;http://www.kaspersky.com/about/news/virus/2012/Kaspersky_Lab_and_ITU_Research_Reveals_New_Advanced_Cyber_Threat&lt;/a&gt;&lt;/p&gt;&lt;p&gt;


Thanks,


&lt;/p&gt;&lt;p&gt;Ohad Plotnik (Plotniko)&lt;/p&gt;&lt;p&gt;Identity and Security Architect, MVP
 
&lt;/p&gt;&lt;p&gt;Foreity LTD – Intelligent Security
 
&lt;/p&gt;&lt;p&gt;www.ForefrontSecurity.org &lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1105884" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Vulnerability in DNS Server Could Allow Denial of Service MS12-017 - Important</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/03/15/vulnerability-in-dns-server-could-allow-denial-of-service-ms12-017-important.aspx</link><pubDate>Thu, 15 Mar 2012 13:59:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1033817</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1033817</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/03/15/vulnerability-in-dns-server-could-allow-denial-of-service-ms12-017-important.aspx#comments</comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;his security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a remote unauthenticated attacker sends a specially crafted DNS query to the target DNS server.&lt;/p&gt;
&lt;p&gt;This security update is rated Important for all supported editions of Windows Server 2003, 32-bit and x64-based editions of Windows Server 2008, and x64-based editions of Windows Server 2008 R2.&lt;/p&gt;
&lt;p&gt;Please update your systems ASAP!!!&lt;/p&gt;
&lt;p&gt;Info is here:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-017"&gt;http://technet.microsoft.com/en-us/security/bulletin/ms12-017&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Ohad Plotnik (Plotniko)&lt;br /&gt;Identity and Security Architect, MVP&lt;/p&gt;
&lt;p&gt;Foreity LTD – Intelligent Security&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.forefrontsecurity.org/"&gt;www.ForefrontSecurity.org&lt;/a&gt; &lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1033817" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Vulnerability in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege MS12-018 - Important</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/03/15/vulnerability-in-windows-kernel-mode-drivers-could-allow-elevation-of-privilege-ms12-018-important.aspx</link><pubDate>Thu, 15 Mar 2012 13:57:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1033814</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1033814</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/03/15/vulnerability-in-windows-kernel-mode-drivers-could-allow-elevation-of-privilege-ms12-018-important.aspx#comments</comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;This security update is rated Important for all supported releases of Microsoft Windows.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Please update your systems ASAP!!!&lt;/p&gt;
&lt;p&gt;Info is here:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-018"&gt;http://technet.microsoft.com/en-us/security/bulletin/MS12-018&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Ohad Plotnik (Plotniko)&lt;br /&gt;Identity and Security Architect, MVP&lt;/p&gt;
&lt;p&gt;Foreity LTD – Intelligent Security&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.forefrontsecurity.org/"&gt;www.ForefrontSecurity.org&lt;/a&gt; &lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1033814" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Microsoft Security Bulletin MS12-020 Critical Vulnerabilities in Remote Desktop Could Allow Remote Code Execution !!! </title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/03/15/microsoft-security-bulletin-ms12-020-critical-vulnerabilities-in-remote-desktop-could-allow-remote-code-execution.aspx</link><pubDate>Thu, 15 Mar 2012 13:38:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1033809</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1033809</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/03/15/microsoft-security-bulletin-ms12-020-critical-vulnerabilities-in-remote-desktop-could-allow-remote-code-execution.aspx#comments</comments><description>&lt;p&gt;Hello, &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This security update resolves two privately reported vulnerabilities in the Remote Desktop Protocol. &lt;/p&gt;
&lt;p&gt;The more severe of these vulnerabilities could allow remote code execution if an attacker sends a sequence of specially crafted RDP packets to an affected system. By default, the Remote Desktop Protocol (RDP) is not enabled on any Windows operating system. Systems that do not have RDP enabled are not at risk. This security update is rated Critical for all supported releases of Microsoft Windows. &lt;/p&gt;
&lt;p&gt;Please update your systems ASAP!!! &lt;/p&gt;
&lt;p&gt;For more information : &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020"&gt;http://technet.microsoft.com/en-us/security/bulletin/ms12-020&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thanks, &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Ohad Plotnik (Plotniko)&lt;br /&gt;Identity and Security Architect, MVP&lt;/p&gt;
&lt;p&gt;Foreity LTD – Intelligent Security&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.forefrontsecurity.org/"&gt;www.ForefrontSecurity.org&lt;/a&gt; &lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1033809" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Microsoft released a signature for Win32/Delf.QR</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/02/08/microsoft-released-a-signature-for-win32-delf-qr.aspx</link><pubDate>Wed, 08 Feb 2012 20:07:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1009633</guid><dc:creator>Plotniko</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=1009633</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/02/08/microsoft-released-a-signature-for-win32-delf-qr.aspx#comments</comments><description>&lt;p&gt;Hello, &lt;/p&gt;
&lt;p&gt;&amp;nbsp;Today I sent a virus sample to the Microsoft MMPC team, &lt;/p&gt;
&lt;p&gt;That was analyzed as the “TrojanDownloader:Win32/Delf.QR” &lt;/p&gt;
&lt;p&gt;The full reply from Microsoft was:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Analysis of the file(s) in Submission ID MMPC12020732034853 is now complete. This is the final email that you will receive regarding this submission. &lt;/p&gt;
&lt;p&gt;The Microsoft Malware Protection Center (MMPC) has investigated the following file(s) which we received on 2/7/2012 11:39:15 AM Pacific Time. Below is the determination for your submission.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;======== Submission ID MMPC12020732034853 Submitted Files ============================================= &lt;/p&gt;
&lt;p&gt;VIRUS.rar [Container] &lt;/p&gt;
&lt;p&gt;+---ForeFront.rar [Container] &lt;/p&gt;
&lt;p&gt;+---EXE.exe [TrojanDownloader:Win32/Delf.QR] &lt;/p&gt;
&lt;p&gt;+---UpdateOffice.rar [Container] &lt;/p&gt;
&lt;p&gt;+---UpdateOffice.exe [TrojanDownloader:Win32/Delf.QR] &lt;/p&gt;
&lt;p&gt;+---UpdateOffice2.rar [Not Malware] &lt;/p&gt;
&lt;p&gt;The following links contain more information regarding the detections listed above: &lt;a href="http://go.microsoft.com/...ownloader:Win32/Delf.QR"&gt;http://go.microsoft.com/...ownloader:Win32/Delf.QR&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Your submission was scanned using antimalware definition version 1.119.1519.0. ======== &lt;/p&gt;
&lt;p&gt;The detections listed above are included in the latest pre-release definition available for download. For more information please visit the pre-release definition update download page available at: http://www.microsoft.com...eReleaseSignatures.aspx Alternatively, detections listed above will be available for users who subscribe to the automatic definition update mechanism in the next regularly scheduled release, as well as users who choose to manually update their definition library available via the MMPC Portal available on: http://www.microsoft.com...al/Definitions/ADL.aspx If you have questions relating to this submission please contact mailto:mmpcres@microsoft.com and reference your submission ID. We would like to find ways to improve our service to you. Please take a few minutes and fill out our short customer survey for this incident.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;You can navigate to our short (6 question) survey here: http://www.zoomerang.com/Survey/WEB22CHRC7QCL5/ ============================================= Additional Help For customers who do not have an antivirus solution, Microsoft Security Essentials can be downloaded at no charge here: http://www.microsoft.com/security_essentials/ For more information about updating definitions and answers to other questions, visit the following link: http://www.microsoft.com...red/Help.aspx#new_defns If you need immediate assistance and information on best practices for removing malware in your environment, additional support options are available at the following websites: For IT Professionals - http://support.microsoft.com/gp/securityitpro For Home Users - &lt;a href="http://support.microsoft...lt.aspx/?pr=securityhome"&gt;http://support.microsoft...lt.aspx?pr=securityhome&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thank you, &lt;/p&gt;
&lt;p&gt;Microsoft Malware Protection Center&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thanks, &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ohad Plotnik (Plotniko) &lt;br /&gt;MVP-Forefront &lt;br /&gt;System&amp;amp;network &lt;br /&gt;Security Architect &lt;br /&gt;ForefrontSecurity.org&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=1009633" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>Security Compliance Manager 2.5 Beta is here!</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/01/27/security-compliance-manager-2-5-beta-is-here.aspx</link><pubDate>Fri, 27 Jan 2012 17:11:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:999118</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=999118</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/01/27/security-compliance-manager-2-5-beta-is-here.aspx#comments</comments><description>&lt;p&gt;PING&lt;/p&gt;
&lt;p&gt;The latest version the Microsoft Security Compliance Manager (SCM) tool—version 2.5—is now available for beta download and review!&lt;/p&gt;
&lt;p&gt;NEW baselines include:&lt;/p&gt;
&lt;p&gt;* Exchange Server 2007 SP3 Security Baseline&lt;/p&gt;
&lt;p&gt;* Exchange Server 2010 SP2 Security Baseline&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Updated client product baselines include:&lt;/p&gt;
&lt;p&gt;* Windows 7 SP1 Security Compliance Baseline&lt;/p&gt;
&lt;p&gt;* Windows Vista SP2 Security Compliance Baseline&lt;/p&gt;
&lt;p&gt;* Windows XP SP3 Security Compliance Baseline&lt;/p&gt;
&lt;p&gt;* Office 2010 SP1 Security Baseline&lt;/p&gt;
&lt;p&gt;* Internet Explorer 8 Security Compliance Baseline&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;SCM 2.5 enables you to quickly configure and manage your desktops and laptops, traditional data center, and private cloud using Group Policy and Microsoft System Center Configuration Manager.&lt;/p&gt;
&lt;p&gt;Get the beta download from Microsoft Connect at &lt;a href="https://connect.microsof....aspx/?DownloadID=40885"&gt;https://connect.microsof....aspx?DownloadID=40885&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;After you download and become familiar with updates in SCM 2.5, please provide us with your feedback.Your opinion is very important to us. We would especially appreciate your feedback in the following areas:&lt;/p&gt;
&lt;p&gt;* Relevance.How relevant is the information for your organization?&lt;/p&gt;
&lt;p&gt;* Usefulness.How will you use these product baselines? How does the SCM 2.5 tool provide value?&lt;/p&gt;
&lt;p&gt;* Usability. Is the baseline configuration information easy to follow? Can you easily find key content?&lt;/p&gt;
&lt;p&gt;* Consistency. Is the content in the security guides consistent with the setting recommendations and &lt;br /&gt;Vulnerability information?&lt;/p&gt;
&lt;p&gt;* General Quality. Please provide us with your opinion on the general quality of the product baseline content. Would you recommend SCM 2.5 to colleagues?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ohad Plotnik (Plotniko) &lt;br /&gt;MVP-Forefront &lt;br /&gt;System&amp;amp;network &lt;br /&gt;Security Architect &lt;br /&gt;ForefrontSecurity.org&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=999118" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item><item><title>A Guide to Claims-Based Identity and Access Control, Second Edition eBook</title><link>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/01/27/a-guide-to-claims-based-identity-and-access-control-second-edition-ebook.aspx</link><pubDate>Fri, 27 Jan 2012 17:09:00 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:999117</guid><dc:creator>Plotniko</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/plotniko/rsscomments.aspx?PostID=999117</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/plotniko/archive/2012/01/27/a-guide-to-claims-based-identity-and-access-control-second-edition-ebook.aspx#comments</comments><description>&lt;p&gt;Hello&amp;nbsp;All,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Claims-based identity seeks to control the digital experience and allocate &lt;br /&gt;digital resources based on claims made by one party about another. &lt;br /&gt;A party can be a person, organization, government, website, &lt;br /&gt;web service, or even a device. The very simplest example of a claim is &lt;br /&gt;something that a party says about itself.&lt;/p&gt;
&lt;p&gt;As the authors of this book point out, there is nothing new about &lt;br /&gt;the use of claims. As far back as the early days of mainframe computing, &lt;br /&gt;the operating system asked users for passwords and then passed &lt;br /&gt;each new application a “claim” about who was using it. But this world &lt;br /&gt;was based to some extent on wishful thinking because applications &lt;br /&gt;didn’t question what they were told.&lt;/p&gt;
&lt;p&gt;As systems became interconnected and more complicated, we &lt;br /&gt;needed ways to identify parties across multiple computers. One way &lt;br /&gt;to do this was for the parties that used applications on one computer &lt;br /&gt;to authenticate to the applications (and/or operating systems) that &lt;br /&gt;ran on the other computers. This mechanism is still widely used—for &lt;br /&gt;example, when logging on to a great number of Web sites.&lt;/p&gt;
&lt;p&gt;However, this approach becomes unmanageable when you have &lt;br /&gt;many co-operating systems (as is the case, for example, in the enterprise). &lt;br /&gt;Therefore, specialized services were invented that would register &lt;br /&gt;and authenticate users, and subsequently provide claims about &lt;br /&gt;them to interested applications. Some well-known examples are &lt;br /&gt;NTLM, Kerberos, Public Key Infrastructure (PKI), and the Security &lt;br /&gt;Assertion Markup Language (SAML).&lt;/p&gt;
&lt;p&gt;If systems that use claims have been around for so long, how can &lt;br /&gt;claims-based computing be new or important? The answer is a variant &lt;br /&gt;of the old adage, “All tables have legs, but not all legs have tables.” The &lt;br /&gt;claims-based model embraces and subsumes the capabilities of all the &lt;br /&gt;systems that have existed to date, but it also allows many new things &lt;br /&gt;to be accomplished. This book gives a great sense of the resultant &lt;br /&gt;opportunities.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=28362&amp;amp;WT.mc_id=rss_alldownloads_all"&gt;http://www.microsoft.com/download/en/details.aspx?id=28362&amp;amp;WT.mc_id=rss_alldownloads_all&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Enjoy :)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ohad Plotnik (Plotniko) &lt;br /&gt;MVP-Forefront &lt;br /&gt;System&amp;amp;network &lt;br /&gt;Security Architect &lt;br /&gt;ForefrontSecurity.org&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=999117" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/plotniko/archive/tags/Security/default.aspx">Security</category></item></channel></rss>