Palo Alto Networks Researcher Discovers Critical IE Vulnerability

Palo Alto Networks researcher Hui Gao was credited with discovery of a new critical Internet Explorer (IE) vulnerability affecting IE versions 6, 7, 8, 9, 10 and 11. CVE-2015-2548 is included in Microsoft’s October 2015 Security Bulletin and documented in Microsoft Security Bulletin MS15-109.

In our continuing commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors. (As of this writing, Microsoft researcher Bo Qu was also credited with critical IE vulnerability discoveries in August and July, acknowledged in revisions to Microsoft Security Bulletins MS15-065 and MS15-079.)

Palo Alto Networks is a regular contributor to vulnerability research. Previous critical IE vulnerability discoveries from the past 18 months included three in September, one in Augustthree in July (revised from two), three in Junethree in Mayone in Marchfive in February (revised from three), three in November 2014one in October 201415 in September 2014three in August 201410 in July 2014, and 22 in June 2014 (revised from 21).

By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing weapons used by attackers to compromise enterprise, government and service provider networks.

[Palo Alto Networks Blog]

The Value of Shared Threat Intelligence

In a recent column for SecurityWeek, Scott Simkin examines the challenge of sharing threat intelligence among security vendors, but notes how vendors who treat threat intelligence as intellectual property are doing more harm than good when it comes to stopping cyber attacks.

As Scott writes, “When vendors and individuals try to keep threat intelligence private, they limit the ability of the entire group to identify and mitigate new threats as they are developed and launched against organizations.”

Read Scott’s article at SecurityWeek.com here.
Learn about Palo Alto Networks AutoFocus and actionable threat intelligence here.
Learn more about the Cyber Threat Alliance here.

[Palo Alto Networks Blog]

English
Exit mobile version