On Monday, Microsoft published a security advisory to announce a new vulnerability that can allow remote code execution in Internet Explorer versions 6 and 7 on several different platforms. IE 8 and the protected-mode of IE 7 are not affected, and the current recommendation is to upgrade affected browsers to one of these (as there currently is no patch available for the exploit code).
I was pleased to see that my favorite SaaS web security/web filtering offering (Zscaler) was fast (or first) to fix the vulnerability. Their clients are protected without any action on their part.
Nice…and it reinforces the entire notion of outsourcing certain functions to qualified third parties.
More info:











