• MS-DEFCON 2: Black Tuesday – no need to patch if you don’t use Internet Explorer

    Microsoft just released four security bulletins, covering seven separately identified security holes. A couple of them could turn into something nasty, if the bad guys figure out how, but for now if you don’t use Internet Explorer 7, you should be OK.

    Yes, I said IE 7. The patch doesn’t involve IE 6.

    SANS Internet Storm center reports no known exploits for any of the new security bulletins, except the SQL Server fix, MS09-004 / KB 959420. Microsoft only rates that’n as “Important” because “An attacker would need to either authenticate to exploit the vulnerability or take advantage of a SQL injection vulnerability in a Web application that is able to authenticate.”

    No need to patch yet, unless you insist upon using Internet Explorer 7. Let’s sit tight and see what breaks.