<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Naked Security &#187; Exploit</title>
	<atom:link href="http://nakedsecurity.sophos.com/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://nakedsecurity.sophos.com</link>
	<description>Computer Security · News · Opinion · Advice · Research</description>
	<lastBuildDate>Thu, 23 May 2013 06:56:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='nakedsecurity.sophos.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Naked Security &#187; Exploit</title>
		<link>http://nakedsecurity.sophos.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://nakedsecurity.sophos.com/osd.xml" title="Naked Security" />
	<atom:link rel='hub' href='http://nakedsecurity.sophos.com/?pushpress=hub'/>
		<item>
		<title>Mozilla pushes out new Firefox and Thunderbird: 8 security advisories, 3 critical fixes</title>
		<link>http://nakedsecurity.sophos.com/2013/05/14/mozilla-pushes-out-new-firefox-and-thunderbird-8-security-advisories-3-critical-fixes/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/05/14/mozilla-pushes-out-new-firefox-and-thunderbird-8-security-advisories-3-critical-fixes/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Tue, 14 May 2013 22:30:23 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Web Browsers]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[thunderbird]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=226259</guid>
		<description><![CDATA[Not to be outdone by Microsoft and Adobe's Patch Tuesday releases, Mozilla pushed out its latest browser and email client updates today.

There are no bated-breath patches for in-the-wild exploits, but 3 of the 8 security fixes are deemed "critical".<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=226259&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/05/14/mozilla-pushes-out-new-firefox-and-thunderbird-8-security-advisories-3-critical-fixes/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/05/fftb-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/05/fftb-250.png?w=150" medium="image" />

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/fftb-170.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/mfsa-may-14-490.png" medium="image" />
	</item>
		<item>
		<title>Microsoft rushes out CVE-2013-1347 &quot;Fix it&quot; for the latest Internet Explorer zero-day</title>
		<link>http://nakedsecurity.sophos.com/2013/05/09/microsoft-rushes-out-cve-2013-1347-fix-it-for-the-latest-internet-explorer-zero-day/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/05/09/microsoft-rushes-out-cve-2013-1347-fix-it-for-the-latest-internet-explorer-zero-day/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Thu, 09 May 2013 09:19:13 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[cve]]></category>
		<category><![CDATA[department of labor]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Fix it]]></category>
		<category><![CDATA[radiation]]></category>
		<category><![CDATA[SEM]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225813</guid>
		<description><![CDATA[The recent and widely reported US Dept of Labor website hack turned out to be a zero-day exploit against IE.

Good news! Microsoft just published an emergency "Fix it" patch against the vulnerability...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225813&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/05/09/microsoft-rushes-out-cve-2013-1347-fix-it-for-the-latest-internet-explorer-zero-day/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/05/fixit-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/05/fixit-250.png?w=150" medium="image">
			<media:title type="html">fixit-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/dol-170.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/fixit-490.png" medium="image">
			<media:title type="html">Click on the image to leap to the Microsoft SWI blog post...</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/patch-490.png" medium="image">
			<media:title type="html">Click on the image to leap to the Microsoft SWI blog post...</media:title>
		</media:content>
	</item>
		<item>
		<title>SSCC 108 - WW2 crypto, Bitcoin mining, internet cameras, password breaches [PODCAST]</title>
		<link>http://nakedsecurity.sophos.com/2013/05/08/sscc-108-ww2-crypto-bitcoin-mining-internet-cameras-password-breaches-podcast/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/05/08/sscc-108-ww2-crypto-bitcoin-mining-internet-cameras-password-breaches-podcast/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Wed, 08 May 2013 11:06:45 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Associated Press]]></category>
		<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[chet chat]]></category>
		<category><![CDATA[core security]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[d-link]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[esea]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[internet camera]]></category>
		<category><![CDATA[livingsocial]]></category>
		<category><![CDATA[salt]]></category>
		<category><![CDATA[sscc]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Twitter hack]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[world war 2]]></category>
		<category><![CDATA[ww2]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225720</guid>
		<description><![CDATA[Chester calls home from Interop in Las Vegas to record the latest episode of the Sophos Security Chet Chat.

Join Chester and guest Paul Ducklin in their regular quarter-hour podcast as they laugh about (and lament) the latest goings-on in the world of computer security.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225720&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/05/08/sscc-108-ww2-crypto-bitcoin-mining-internet-cameras-password-breaches-podcast/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://sophosnews.files.wordpress.com/2013/05/sophos-security-chet-chat-108.mp3" length="8664002" type="audio/mpeg" />
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/05/image-108-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/05/image-108-250.png?w=150" medium="image">
			<media:title type="html">image-108-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/sscc-108-170.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/sophos-security-chet-chat-108.mp3" medium="audio">
			<media:player url="http://nakedsecurity.sophos.com/wp-content/plugins/audio-player/player.swf?soundFile=http://sophosnews.files.wordpress.com/2013/05/sophos-security-chet-chat-108.mp3" />
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/sophos-security-chet-chat-108.mp3" medium="audio">
			<media:player url="http://nakedsecurity.sophos.com/wp-content/plugins/audio-player/player.swf?soundFile=http://sophosnews.files.wordpress.com/2013/05/sophos-security-chet-chat-108.mp3" />
		</media:content>
	</item>
		<item>
		<title>Lifting the lid on the Redkit exploit kit</title>
		<link>http://nakedsecurity.sophos.com/2013/05/03/lifting-the-lid-on-the-redkit-exploit-kit-part-1/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/05/03/lifting-the-lid-on-the-redkit-exploit-kit-part-1/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Fri, 03 May 2013 15:07:07 +0000</pubDate>
		<dc:creator>Fraser Howard</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Redkit]]></category>
		<category><![CDATA[Redkit exploit kit]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225459</guid>
		<description><![CDATA[In the first of a two part series, Fraser Howard takes a closer look at the Redkit exploit kit.

Learn more about how this kit works and the compromised web servers that are being used to host it.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225459&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/05/03/lifting-the-lid-on-the-redkit-exploit-kit-part-1/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/05/redkit-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit-250.png?w=150" medium="image" />

		<media:content url="http://2.gravatar.com/avatar/8e69986cae5972e972239f0c176287fc?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">fraserhoward</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit115.jpg" medium="image">
			<media:title type="html">redkit115</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/iframe-jg-inject2.jpg" medium="image">
			<media:title type="html">Injected iframe used to redirect victims to Redkit</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_landing.jpg" medium="image">
			<media:title type="html">Redkit landing page</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_landing2.jpg" medium="image">
			<media:title type="html">More recent Redkit landing pages, using JNLP</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit-php.jpg" medium="image">
			<media:title type="html">Snippet of code from PHP shell used by Redkit</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit-overview2.jpg" medium="image">
			<media:title type="html">Overview of how Redkit works</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_country1.jpg" medium="image">
			<media:title type="html">Breakdown of Redkit compromised web servers by host country</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_isp.jpg" medium="image">
			<media:title type="html">Breakdown of ISPs hosting the Redkit compromised web servers</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/redkit_svr.jpg" medium="image">
			<media:title type="html">Web server breakdown for Redkit compromised servers</media:title>
		</media:content>
	</item>
		<item>
		<title>US Department of Labor website hacked, serves malware, now fixed</title>
		<link>http://nakedsecurity.sophos.com/2013/05/02/us-department-of-labor-website-hacked-serves-malware-now-fixed/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/05/02/us-department-of-labor-website-hacked-serves-malware-now-fixed/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Thu, 02 May 2013 10:59:52 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[department of labor]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[labour day]]></category>
		<category><![CDATA[US]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225356</guid>
		<description><![CDATA[A subdomain of the US Department of Labor's main website, running off a separate server - what's known colloquially as a microsite - was modified to serve up malware.

Paul Ducklin takes a quick look at the attack...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225356&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/05/02/us-department-of-labor-website-hacked-serves-malware-now-fixed/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/05/dol-sem-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/05/dol-sem-250.png?w=150" medium="image">
			<media:title type="html">dol-sem-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/dns-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/semdol-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/exploit-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/mz-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/aav-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/05/bitdef-490.png" medium="image" />
	</item>
		<item>
		<title>What WERE they thinking? Internet-enabled cameras under the security lens once again...</title>
		<link>http://nakedsecurity.sophos.com/2013/04/30/what-were-they-thinking-internet-enabled-cameras-under-the-security-lens-once-again/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/30/what-were-they-thinking-internet-enabled-cameras-under-the-security-lens-once-again/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Tue, 30 Apr 2013 13:51:15 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Camera+]]></category>
		<category><![CDATA[CCTV]]></category>
		<category><![CDATA[core]]></category>
		<category><![CDATA[core security]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[firmware]]></category>
		<category><![CDATA[ip camera]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[printer]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225197</guid>
		<description><![CDATA[Vulnerability researchers at Core Security recently turned their attention on internet-enabled cameras, finding lots of holes.

And when security holes arise from features, not bugs, you really do feel like shouting aloud, "What WERE they thinking?"<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225197&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/30/what-were-they-thinking-internet-enabled-cameras-under-the-security-lens-once-again/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/cctv-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/cctv-250.png?w=150" medium="image" />

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/cctv-170.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/hard-pass-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/coffee-pot-1701.png" medium="image">
			<media:title type="html">Click on the greyscale version to view Core Security&#039;s reference shot of &#039;Coffee pot with high hopes.&#039;</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/traversal-490.png" medium="image" />
	</item>
		<item>
		<title>Apple iMessage &quot;censors&quot; mention of Obama: international conspiracy...or software bug?</title>
		<link>http://nakedsecurity.sophos.com/2013/04/29/apple-imessage-censorious-bug/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/29/apple-imessage-censorious-bug/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Mon, 29 Apr 2013 11:10:20 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Bug]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[code horror]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[imessage]]></category>
		<category><![CDATA[obama]]></category>
		<category><![CDATA[off-by-one]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=225072</guid>
		<description><![CDATA[Try sending the message "I could be the next Obama" via the iMessage service from your iPhone or your iPad!

Paul Ducklin takes a look at a humorous bug that teaches us some serious lessons...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=225072&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/29/apple-imessage-censorious-bug/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/messages-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/messages-250.png?w=150" medium="image" />

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/messages-1701.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/whh-1701.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/gc-conspiracy-thing-4901.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/debian-170.png" medium="image" />
	</item>
		<item>
		<title>Oracle and Apple ship critical Java updates - get yours today!</title>
		<link>http://nakedsecurity.sophos.com/2013/04/17/oracle-and-apple-ship-critical-java-updates-get-yours-today/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/17/oracle-and-apple-ship-critical-java-updates-get-yours-today/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Wed, 17 Apr 2013 08:59:33 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[jre]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=224297</guid>
		<description><![CDATA[The security-beleaguered Java ecosystem usually gets updates just once every four months, in February, June and October.

But this year, Oracle has adapted that schedule a number of times, and this is one of them...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=224297&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/17/oracle-and-apple-ship-critical-java-updates-get-yours-today/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/java-now-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/java-now-250.png?w=150" medium="image">
			<media:title type="html">java-now-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/02/javanow-176.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/oracle-upd-490.png" medium="image">
			<media:title type="html">Click on the image to go to Oracle&#039;s official April 2013 Critical Patch Advisory...</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/apple-upd-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/oracle-warning-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/java7u21-warnings-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/trusted-signed-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/expired-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/unsigned-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/selfsigned-490.png" medium="image" />
	</item>
		<item>
		<title>Anatomy of an exploit - Linksys router remote password change hole</title>
		<link>http://nakedsecurity.sophos.com/2013/04/11/anatomy-of-an-exploit-linksys-router-remote-password-change-hole/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/11/anatomy-of-an-exploit-linksys-router-remote-password-change-hole/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Thu, 11 Apr 2013 11:34:10 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[belkin]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[linksys]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=223942</guid>
		<description><![CDATA[A security researcher from California has published a how-to guide detailing a number of exploits against various Linksys routers.

Paul Ducklin looks at the ominous sounding "EA2700 Password Change Insufficient Authentication and CSRF Vulnerability"...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=223942&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/11/anatomy-of-an-exploit-linksys-router-remote-password-change-hole/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/li-placard-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/li-placard-250.png?w=150" medium="image">
			<media:title type="html">li-placard-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/li-hello-psirt-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/li-placard-170.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/li-19218611-post-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/li-private-ips-4901.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/li-goodin-remark-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/li-ea2700-firmware-history-4901.png" medium="image" />
	</item>
		<item>
		<title>Microsoft to issue 9 security updates on Tuesday, critical for all IE versions, reboot required</title>
		<link>http://nakedsecurity.sophos.com/2013/04/07/microsoft-to-issue-9-security-updates-on-tuesday-critical-for-all-ie/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/04/07/microsoft-to-issue-9-security-updates-on-tuesday-critical-for-all-ie/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Sun, 07 Apr 2013 19:00:27 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[critical]]></category>
		<category><![CDATA[EoP]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=223428</guid>
		<description><![CDATA[Microsoft has issued its usual advance notification for the coming week's Patch Tuesday.

If you use Windows you're probably affected, and you'll probably need to reboot all your PCs and most of your servers...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=223428&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/04/07/microsoft-to-issue-9-security-updates-on-tuesday-critical-for-all-ie/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/04/patchme-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/04/patchme-250.png?w=150" medium="image" />

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/patchme-170.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/advancenote-490.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2013/04/pwned-186.png" medium="image" />
	</item>
	</channel>
</rss>
