<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Core Security</title>
	<atom:link href="http://blog.coresecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.coresecurity.com</link>
	<description>Security Intelligence and Vulnerability Management</description>
	<lastBuildDate>Thu, 10 May 2012 23:22:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Top Three Continuous Monitoring Challenges in Meeting NIST Requirements</title>
		<link>http://blog.coresecurity.com/2012/05/10/top-three-continuous-monitoring-challenges-in-meeting-nist-requirements/</link>
		<comments>http://blog.coresecurity.com/2012/05/10/top-three-continuous-monitoring-challenges-in-meeting-nist-requirements/#comments</comments>
		<pubDate>Thu, 10 May 2012 20:47:36 +0000</pubDate>
		<dc:creator>Seema Sheth-Voss</dc:creator>
				<category><![CDATA[Assessing defenses]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[controls validation]]></category>
		<category><![CDATA[Data breach legislation]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Government policy]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[Security measurement]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability assessment]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=28801</guid>
		<description><![CDATA[I recently caught up with Rick Doten, VP Cyber Security at DMI.  (For those of you who might not be familiar with Rick, he is a leading IT security expert with prior leadership posts at Gartner, Lockheed Martin and Verizon &#8211; more about Rick’s work is at the end of this post…). While Rick is [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/05/10/top-three-continuous-monitoring-challenges-in-meeting-nist-requirements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Big Trick Behind Exploit MS12-034</title>
		<link>http://blog.coresecurity.com/2012/05/10/the-big-trick-behind-exploit-ms12-034/</link>
		<comments>http://blog.coresecurity.com/2012/05/10/the-big-trick-behind-exploit-ms12-034/#comments</comments>
		<pubDate>Thu, 10 May 2012 19:22:25 +0000</pubDate>
		<dc:creator>Nicolas Economou</dc:creator>
				<category><![CDATA[Assessing defenses]]></category>
		<category><![CDATA[Brute force attacks]]></category>
		<category><![CDATA[CoreLabs]]></category>
		<category><![CDATA[Ethical hacking]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration testing]]></category>
		<category><![CDATA[Source code analysis]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability advisories]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=27671</guid>
		<description><![CDATA[My name is Nicolas Economou and I am a senior member on the Exploit Writing Team here at CORE Labs - specializing in Windows kernel exploitation -  where we work tirelessly to discover vulnerabilities within countless technologies so we can provide our customers with new tools to test and assess their networks. In this post, I&#8217;m going to [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/05/10/the-big-trick-behind-exploit-ms12-034/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Down to the CORE: April 2012 IMPACT Report</title>
		<link>http://blog.coresecurity.com/2012/05/10/down-to-the-core-april-2012-impact-report/</link>
		<comments>http://blog.coresecurity.com/2012/05/10/down-to-the-core-april-2012-impact-report/#comments</comments>
		<pubDate>Thu, 10 May 2012 16:16:50 +0000</pubDate>
		<dc:creator>Alex</dc:creator>
				<category><![CDATA[Client side testing]]></category>
		<category><![CDATA[CORE IMPACT Pro]]></category>
		<category><![CDATA[CoreLabs]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Penetration testing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability assessment]]></category>
		<category><![CDATA[Vulnerability research]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=27661</guid>
		<description><![CDATA[It was an exciting month getting ready for the release of CORE Impact Pro v12.3 &#8211; including a lot of phone calls with customers to review how their feature requests were being implemented into Impact &#8211;  and lots of fun planning with internal builds of the new version. We were also busy working with some [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/05/10/down-to-the-core-april-2012-impact-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CORE Labs Discovery of Six Vulnerabilities within SAP Netweaver</title>
		<link>http://blog.coresecurity.com/2012/05/09/core-labs-discovery-of-six-vulnerabilities-within-sap-netweaver/</link>
		<comments>http://blog.coresecurity.com/2012/05/09/core-labs-discovery-of-six-vulnerabilities-within-sap-netweaver/#comments</comments>
		<pubDate>Wed, 09 May 2012 15:01:07 +0000</pubDate>
		<dc:creator>Martin Gallo</dc:creator>
				<category><![CDATA[Assessing defenses]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Conducting Tests]]></category>
		<category><![CDATA[controls validation]]></category>
		<category><![CDATA[CoreLabs]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability assessment]]></category>
		<category><![CDATA[Vulnerability research]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=27131</guid>
		<description><![CDATA[As a security researcher and member of the CORE Security Consulting Services team, and close partner with CORE Labs here in Buenos Aires, I need to perform security analysis of complex enterprise IT environments with software installations from any number of vendors. These environments’ technologies are often both poorly documented and maintained. Our job here [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/05/09/core-labs-discovery-of-six-vulnerabilities-within-sap-netweaver/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Test the Weakest Link and Phish Your Users</title>
		<link>http://blog.coresecurity.com/2012/05/07/test-the-weakest-link-and-phish-your-users/</link>
		<comments>http://blog.coresecurity.com/2012/05/07/test-the-weakest-link-and-phish-your-users/#comments</comments>
		<pubDate>Mon, 07 May 2012 19:33:15 +0000</pubDate>
		<dc:creator>Alex</dc:creator>
				<category><![CDATA[Automated penetration testing]]></category>
		<category><![CDATA[Client side testing]]></category>
		<category><![CDATA[Conducting Tests]]></category>
		<category><![CDATA[CORE IMPACT Pro]]></category>
		<category><![CDATA[Ethical hacking]]></category>
		<category><![CDATA[Penetration testing]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability assessment]]></category>
		<category><![CDATA[Web App Penetration Testing]]></category>
		<category><![CDATA[WiFi Penetration Testing]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=26971</guid>
		<description><![CDATA[I’ve been advocating for the use of email born phishing tests against the user population within companies for over six years now, and I have to admit the fight is a complex one. Most of the network and security analysts I talk to about this agree with me and want to leverage this type of [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/05/07/test-the-weakest-link-and-phish-your-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Importantly Critical</title>
		<link>http://blog.coresecurity.com/2012/05/03/importantly-critical/</link>
		<comments>http://blog.coresecurity.com/2012/05/03/importantly-critical/#comments</comments>
		<pubDate>Thu, 03 May 2012 22:37:10 +0000</pubDate>
		<dc:creator>Alex</dc:creator>
				<category><![CDATA[Assessing defenses]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability advisories]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=26861</guid>
		<description><![CDATA[Looking at the Microsoft Security Bulletin for May 2012 just issued this afternoon I suspect we will see a lot of noise regarding Bulletins 1, 2 and 3. However, it would be dangerous for IT professionals to not take Bulletins 6 and 7 quite seriously simply because they relate to Elevation of Privilege. Their common [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/05/03/importantly-critical/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Espionage Got You Down? Hire a Hacker</title>
		<link>http://blog.coresecurity.com/2012/04/26/espionage-got-you-down-hire-a-hacker/</link>
		<comments>http://blog.coresecurity.com/2012/04/26/espionage-got-you-down-hire-a-hacker/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 19:32:58 +0000</pubDate>
		<dc:creator>Ken Pickering</dc:creator>
				<category><![CDATA[Assessing defenses]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Data breach incidents]]></category>
		<category><![CDATA[Ethical hacking]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=26591</guid>
		<description><![CDATA[Corporate espionage is a huge problem for businesses and individuals alike as there is both intellectual property (IP) and  employee/customer data at risk. Your HR department has a lot of information about you, including bank account numbers for direct deposits. Your company’s digital IP ranges from proprietary drug/chemical formulas to a Internet search algorithm and its loss can break [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/04/26/espionage-got-you-down-hire-a-hacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Version 2.0</title>
		<link>http://blog.coresecurity.com/2012/04/24/version-2-0/</link>
		<comments>http://blog.coresecurity.com/2012/04/24/version-2-0/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 20:25:31 +0000</pubDate>
		<dc:creator>Ken Pickering</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[CORE INSIGHT Enterprise]]></category>
		<category><![CDATA[Data breach incidents]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=26381</guid>
		<description><![CDATA[I started here at Core a bit over two years ago. Since that time, I’ve seen our CORE Insight product evolve from pre-Alpha code/proof of concept to the mature product it is today. It’s something I and the rest of my team are exceptionally proud of. Everyone in this group has been cranking on this [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/04/24/version-2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Code Theft is Not Really Theft</title>
		<link>http://blog.coresecurity.com/2012/04/12/code-theft-is-not-really-theft/</link>
		<comments>http://blog.coresecurity.com/2012/04/12/code-theft-is-not-really-theft/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 19:55:28 +0000</pubDate>
		<dc:creator>Ken Pickering</dc:creator>
				<category><![CDATA[Assessing defenses]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=26241</guid>
		<description><![CDATA[The government ruling that “code theft” does not constitute as actual criminal theft might not seem at first to be a huge deal. But in reality – at least to software companies that produce their own intellectual property – it does pose a significant challenge. How do you safeguard your IP in a meaningful way [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/04/12/code-theft-is-not-really-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Down to the CORE: March 2012 IMPACT Report</title>
		<link>http://blog.coresecurity.com/2012/04/12/down-to-the-core-march-2012-impact-report/</link>
		<comments>http://blog.coresecurity.com/2012/04/12/down-to-the-core-march-2012-impact-report/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 16:10:29 +0000</pubDate>
		<dc:creator>Alex</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration testing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vulnerability assessment]]></category>
		<category><![CDATA[Vulnerability research]]></category>

		<guid isPermaLink="false">http://blog.coresecurity.com/?p=26091</guid>
		<description><![CDATA[&#160; Online attackers never stand still and neither does the Exploit Writing Team stationed at CORE Labs. This past March, we added 25 exploit modules to our Security Testing framework that cover a wide range of technologies and target the biggest online threats our customers face every day. Add this to the total number of [...]]]></description>
		<wfw:commentRss>http://blog.coresecurity.com/2012/04/12/down-to-the-core-march-2012-impact-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

