<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Naked Security &#187; Java</title>
	<atom:link href="http://nakedsecurity.sophos.com/category/technologies/java/feed/" rel="self" type="application/rss+xml" />
	<link>http://nakedsecurity.sophos.com</link>
	<description>Computer Security · News · Opinion · Advice · Research</description>
	<lastBuildDate>Sun, 19 May 2013 08:03:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='nakedsecurity.sophos.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Naked Security &#187; Java</title>
		<link>http://nakedsecurity.sophos.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://nakedsecurity.sophos.com/osd.xml" title="Naked Security" />
	<atom:link rel='hub' href='http://nakedsecurity.sophos.com/?pushpress=hub'/>
		<item>
		<title>A closer look at the malicious Redkit exploit kit</title>
		<link>http://nakedsecurity.sophos.com/2013/05/09/redkit-exploit-kit-part-2/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/05/09/redkit-exploit-kit-part-2/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Thu, 09 May 2013 11:03:49 +0000</pubDate>
		<dc:creator>Fraser Howard</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Redkit exploit kit]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225752</guid>
		<description><![CDATA[In the second technical article of this series, Fraser Howard investigates deeper into the workings of Redkit exploit kit.

Learn more about the internals of this kit; bypassing of security mechanisms within Java, the use of file encryption, and delivery of multiple payloads.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225752&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/05/09/redkit-exploit-kit-part-2/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/05/red-eye-thumb.jpg?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/05/red-eye-thumb.jpg?w=150" medium="image">
			<media:title type="html">A closer look at the malicious Redkit exploit kit</media:title>
		</media:content>

		<media:content url="http://2.gravatar.com/avatar/8e69986cae5972e972239f0c176287fc?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">fraserhoward</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/red-eye-170.jpg" medium="image">
			<media:title type="html">Red eye. Image from Shutterstock</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_obfurl2.jpg" medium="image">
			<media:title type="html">Obfuscated payload URL passed into Java</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_subst.jpg" medium="image">
			<media:title type="html">Java code to decode payload URL</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_ssv.jpg" medium="image">
			<media:title type="html">Security bypass in Redkit</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_aes.jpg" medium="image">
			<media:title type="html">Reversed AES/CBC/NoPadding string</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_enc2.jpg" medium="image">
			<media:title type="html">Start of encrypted, downloaded file</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_keys.jpg" medium="image">
			<media:title type="html">Decryption key and iv parameter within the Java code</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_marker.jpg" medium="image">
			<media:title type="html">Java code to check for marker in decoded file</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_logic21.jpg" medium="image">
			<media:title type="html">Logic to save and execute one or two payload executables</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_sandwich.jpg" medium="image">
			<media:title type="html">Decoded payload showing marker separating the two malicious executables</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit2_overview.jpg" medium="image">
			<media:title type="html">Summary of Redkit exploitation process</media:title>
		</media:content>
	</item>
		<item>
		<title>Lifting the lid on the Redkit exploit kit</title>
		<link>http://nakedsecurity.sophos.com/2013/05/03/lifting-the-lid-on-the-redkit-exploit-kit-part-1/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/05/03/lifting-the-lid-on-the-redkit-exploit-kit-part-1/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Fri, 03 May 2013 15:07:07 +0000</pubDate>
		<dc:creator>Fraser Howard</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Redkit]]></category>
		<category><![CDATA[Redkit exploit kit]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225459</guid>
		<description><![CDATA[In the first of a two part series, Fraser Howard takes a closer look at the Redkit exploit kit.

Learn more about how this kit works and the compromised web servers that are being used to host it.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225459&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/05/03/lifting-the-lid-on-the-redkit-exploit-kit-part-1/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/05/redkit-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit-250.png?w=150" medium="image" />

		<media:content url="http://2.gravatar.com/avatar/8e69986cae5972e972239f0c176287fc?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">fraserhoward</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit115.jpg" medium="image">
			<media:title type="html">redkit115</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/iframe-jg-inject2.jpg" medium="image">
			<media:title type="html">Injected iframe used to redirect victims to Redkit</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_landing.jpg" medium="image">
			<media:title type="html">Redkit landing page</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_landing2.jpg" medium="image">
			<media:title type="html">More recent Redkit landing pages, using JNLP</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit-php.jpg" medium="image">
			<media:title type="html">Snippet of code from PHP shell used by Redkit</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit-overview2.jpg" medium="image">
			<media:title type="html">Overview of how Redkit works</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_country1.jpg" medium="image">
			<media:title type="html">Breakdown of Redkit compromised web servers by host country</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_isp.jpg" medium="image">
			<media:title type="html">Breakdown of ISPs hosting the Redkit compromised web servers</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_svr.jpg" medium="image">
			<media:title type="html">Web server breakdown for Redkit compromised servers</media:title>
		</media:content>
	</item>
		<item>
		<title>Monday review - the hot 20 stories of the week</title>
		<link>http://nakedsecurity.sophos.com/2013/04/29/monday-review-the-hot-20-stories-of-the-week-3/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/29/monday-review-the-hot-20-stories-of-the-week-3/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Mon, 29 Apr 2013 09:16:46 +0000</pubDate>
		<dc:creator>Anna Brading</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Data loss]]></category>
		<category><![CDATA[Denial of Service]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Law & order]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[Associated Press]]></category>
		<category><![CDATA[boston bomb]]></category>
		<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[facial recognition]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Living social]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[Matthew Keys]]></category>
		<category><![CDATA[password check]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[play store]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Redkit]]></category>
		<category><![CDATA[Reuters]]></category>
		<category><![CDATA[Spamhaus]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Viber]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225056</guid>
		<description><![CDATA[Catch up with all the security news from the last seven days - it's weekly roundup time.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225056&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/29/monday-review-the-hot-20-stories-of-the-week-3/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/dow-2503.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/dow-2503.png?w=150" medium="image">
			<media:title type="html">Monday review</media:title>
		</media:content>

		<media:content url="http://2.gravatar.com/avatar/b2c72340090fc126218d98955474943b?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">annabrading</media:title>
		</media:content>
	</item>
		<item>
		<title>Yet another unpatched security hole found in Java</title>
		<link>http://nakedsecurity.sophos.com/2013/04/23/unpatched-security-hole-java/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/23/unpatched-security-hole-java/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Tue, 23 Apr 2013 13:36:56 +0000</pubDate>
		<dc:creator>Graham Cluley</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Security Explorations]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=224744</guid>
		<description><![CDATA[Just last week you were congratulating yourself for patching your computer against a Java security hole.

Now another zero-day unpatched vulnerability has been found in Oracle's widely used software.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=224744&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/23/unpatched-security-hole-java/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
<enclosure url="http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" length="11762364" type="audio/mpeg" />
<enclosure url="http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" length="11762364" type="audio/mpeg" />
<enclosure url="http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" length="11762364" type="audio/mpeg" />
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/spilt-coffee-thumb.jpg?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/spilt-coffee-thumb.jpg?w=150" medium="image">
			<media:title type="html">Yet another unpatched security hole found in Java</media:title>
		</media:content>

		<media:content url="http://2.gravatar.com/avatar/5fdc27b8b6f6fd69e77aa017a53cceb5?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">gcluley</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2012/09/adam.jpg" medium="image">
			<media:title type="html">Adam Gowdiak</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/spilt-coffee-170.jpg" medium="image">
			<media:title type="html">Spilt coffee</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" medium="audio">
			<media:player url="http://nakedsecurity.sophos.com/wp-content/plugins/audio-player/player.swf?soundFile=http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" />
		</media:content>
	</item>
		<item>
		<title>SSCC 107 - Hostgator, Safari, Java, pwning planes with Android, and Facebook Home [PODCAST]</title>
		<link>http://nakedsecurity.sophos.com/2013/04/23/sscc-107-hostgator-safari-pwning-planes-facebook-home-podcast/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/23/sscc-107-hostgator-safari-pwning-planes-facebook-home-podcast/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Tue, 23 Apr 2013 10:38:21 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Safari]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Law & order]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[aerpolane]]></category>
		<category><![CDATA[airplane]]></category>
		<category><![CDATA[applets]]></category>
		<category><![CDATA[chet chat]]></category>
		<category><![CDATA[Cover Feed]]></category>
		<category><![CDATA[FAA]]></category>
		<category><![CDATA[Facebook Home]]></category>
		<category><![CDATA[hitb]]></category>
		<category><![CDATA[hostgator]]></category>
		<category><![CDATA[lock screen]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[simplicity]]></category>
		<category><![CDATA[sscc]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=224716</guid>
		<description><![CDATA[Here's the latest episode in the popular "Chet Chat" series.

Join Chet and Duck as they discuss what we can learn from recent security news in this quarter-hour podcast.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=224716&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/23/sscc-107-hostgator-safari-pwning-planes-facebook-home-podcast/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://sophosnews.files.wordpress.com/2013/04/sophos-security-chet-chat-107.mp3" length="8382401" type="audio/mpeg" />
<enclosure url="http://sophosnews.files.wordpress.com/2013/04/sophos-security-chet-chat-107.mp3" length="8382401" type="audio/mpeg" />
<enclosure url="http://sophosnews.files.wordpress.com/2013/04/sophos-security-chet-chat-107.mp3" length="8382401" type="audio/mpeg" />
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/img-107-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/img-107-250.png?w=150" medium="image">
			<media:title type="html">img-107-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/img-107-170.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/sophos-security-chet-chat-107.mp3" medium="audio">
			<media:player url="http://nakedsecurity.sophos.com/wp-content/plugins/audio-player/player.swf?soundFile=http://sophosnews.files.wordpress.com/2013/04/sophos-security-chet-chat-107.mp3" />
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/sophos-security-chet-chat-107.mp3" medium="audio">
			<media:player url="http://nakedsecurity.sophos.com/wp-content/plugins/audio-player/player.swf?soundFile=http://sophosnews.files.wordpress.com/2013/04/sophos-security-chet-chat-107.mp3" />
		</media:content>
	</item>
		<item>
		<title>Apple updates Safari, gives better control over Java applets</title>
		<link>http://nakedsecurity.sophos.com/2013/04/18/apple-updates-safari-gives-better-control-over-java-applets/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/18/apple-updates-safari-gives-better-control-over-java-applets/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Thu, 18 Apr 2013 19:57:02 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Safari]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[applet]]></category>
		<category><![CDATA[java. browser]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=224455</guid>
		<description><![CDATA[Apple has pushed out a Safari update to go along with this week's "Java Tuesday" fix.

It's supposed to give you finer-grained control over Java in your browser.

Paul Ducklin puts it through its paces...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=224455&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/18/apple-updates-safari-gives-better-control-over-java-applets/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" length="11762364" type="audio/mpeg" />
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/safari-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/safari-250.png?w=150" medium="image">
			<media:title type="html">safari-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/safari-191.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/saf-security-tab-4901.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/saf-askme-4901.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/saf-4-options-4901.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/saf-update-warning-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/saf-cmd-495.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/saf-plist-495.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/saf-optionstrings-495.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" medium="audio">
			<media:player url="http://nakedsecurity.sophos.com/wp-content/plugins/audio-player/player.swf?soundFile=http://sophosnews.files.wordpress.com/2012/09/sophos-techknow-all-about-java.mp3" />
		</media:content>
	</item>
		<item>
		<title>Oracle and Apple ship critical Java updates - get yours today!</title>
		<link>http://nakedsecurity.sophos.com/2013/04/17/oracle-and-apple-ship-critical-java-updates-get-yours-today/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/17/oracle-and-apple-ship-critical-java-updates-get-yours-today/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Wed, 17 Apr 2013 08:59:33 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[jre]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=224297</guid>
		<description><![CDATA[The security-beleaguered Java ecosystem usually gets updates just once every four months, in February, June and October.

But this year, Oracle has adapted that schedule a number of times, and this is one of them...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=224297&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/17/oracle-and-apple-ship-critical-java-updates-get-yours-today/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/java-now-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/java-now-250.png?w=150" medium="image">
			<media:title type="html">java-now-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/02/javanow-176.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/oracle-upd-490.png" medium="image">
			<media:title type="html">Click on the image to go to Oracle&#039;s official April 2013 Critical Patch Advisory...</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/apple-upd-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/oracle-warning-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/java7u21-warnings-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/trusted-signed-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/expired-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/unsigned-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/selfsigned-490.png" medium="image" />
	</item>
		<item>
		<title>Apple ships OS X 10.8.3 - 11 remote code execution vulns patched, Snow Leopard and Lion get fixes too</title>
		<link>http://nakedsecurity.sophos.com/2013/03/15/apple-ships-os-x-10-8-3-11-remote-code-execution-vulns-patched-snow-leopard-and-lion-get-fixes-too/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/03/15/apple-ships-os-x-10-8-3-11-remote-code-execution-vulns-patched-snow-leopard-and-lion-get-fixes-too/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Fri, 15 Mar 2013 11:21:00 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Apple Safari]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[Lion]]></category>
		<category><![CDATA[Mountain Lion]]></category>
		<category><![CDATA[Snow Leopard]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=220722</guid>
		<description><![CDATA[Apple has shipped the latest point release of its flagship Mountain Lion (OS X 10.8) operating system.

There are plenty of security fixes in there, which Snow Leopard (10.6) and Lion (10.7) users get too, in standalone security updates.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=220722&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/03/15/apple-ships-os-x-10-8-3-11-remote-code-execution-vulns-patched-snow-leopard-and-lion-get-fixes-too/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/03/1083-mountain-lion-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/03/1083-mountain-lion-250.png?w=150" medium="image" />

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/1083-softwareupdate-166.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/1083-java-bug-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/1083-filebug-fixed-4901.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/1083-safari-166.png" medium="image" />
	</item>
		<item>
		<title>PWN2OWN results Day Two - Adobe Reader and Flash owned, Java felled yet again</title>
		<link>http://nakedsecurity.sophos.com/2013/03/08/pwn2own-results-day-two-adobe-reader-and-flash-owned-java-felled-yet-again/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/03/08/pwn2own-results-day-two-adobe-reader-and-flash-owned-java-felled-yet-again/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Fri, 08 Mar 2013 13:04:18 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Flash]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Safari]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[cansecwest]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Pwn2Own]]></category>
		<category><![CDATA[reader]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=219556</guid>
		<description><![CDATA[PWN2OWN 2013 finished off today.

A second scheduled attack on IE 10 didn't happen, so IE 10 didn't get owned again, but Flash and Reader fell once each, and Java was exploited for the fourth time in two days...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=219556&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/03/08/pwn2own-results-day-two-adobe-reader-and-flash-owned-java-felled-yet-again/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/03/pwned-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/03/pwned-250.png?w=150" medium="image" />

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/pwned-176.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/announcement-486.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/results-486.png" medium="image" />
	</item>
		<item>
		<title>PWN2OWN results Day One - Java, Chrome, IE 10 and Firefox owned</title>
		<link>http://nakedsecurity.sophos.com/2013/03/07/pwn2own-results-java-chrome-ie-10-and-firefox-owned-on-day-one/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/03/07/pwn2own-results-java-chrome-ie-10-and-firefox-owned-on-day-one/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Thu, 07 Mar 2013 16:51:25 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Flash]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Safari]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[cansecwest]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Pwn2Own]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=219454</guid>
		<description><![CDATA[Of the Big Four browsers, only Apple's Safari has so far survived the onslaught of the browser-breakers at PWN2OWN 2013.

Java fell three times today; Adobe's Flash and Reader meet their attackers tomorrow...
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=219454&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/03/07/pwn2own-results-java-chrome-ie-10-and-firefox-owned-on-day-one/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/03/pwned-icons-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/03/pwned-icons-250.png?w=150" medium="image" />

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/pwned-icons-176.png" medium="image">
			<media:title type="html">pwned-icons-176</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/03/pwned-486.png" medium="image" />
	</item>
	</channel>
</rss>
