No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

, gives, vendors, six, months, fix, vulnerabilities
Microsoft is planning to dish up heapin' helpin' of security bulletins next week. So...
Multiple vulnerabilities exist in Allen Bradley Micrologix 1100 and 1400 PLCs. Details remain sketchy, but...
Security firm McAfee did not have its finest hour last week. First it discovered...
The day of reckoning has arrived for Symantec, McAfee, Kapersky and the myriad of...
The Asia Pacific vice president of patch management software vendor, Patchlink, believes that is...

HP gives vendors six months to fix vulnerabilities

Business IT - Security

HP's TippingPoint operation will publicly disclose security vulnerabilities six months after they are reported.


The TippingPoint Zero Day Initiative (ZDI) was set up to reward security researchers for responsibly disclosing vulnerabilities, while giving TippingPoint a head start in blocking the corresponding exploits in its intrusion protection system (IPS) products.

TippingPoint came under the HP umbrella as a result of the acquisition of 3Com.

TippingPoint's previous practice has been to give vendors "a reasonable period of time develop a fix to the identified vulnerability" according to the specific circumstances.

The company has now set a time limit of six months, after which it will publish "limited details of the vulnerabilities so end-users can take precautionary measures." HP officials said the purpose of the change was to encourage vendors to fix affected software quickly, reducing the risk of potential security attacks.

"Comprehensive protection of critical data assets requires organisations to keep their defences up to date as malicious activity reaches new levels and applications become more complex,' said Aaron Portnoy, manager, Security Research, TippingPoint, HP.

"This policy change is critical for staying ahead of threats so users can reduce data, financial and productivity loss," he added.

So which vendors are currently taking more than six months to patch vulnerabilities? You might be in for a surprise if you read on.