<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cisco Blog &#187; Craig Williams</title>
	<atom:link href="http://blogs.cisco.com/author/CraigWilliams/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.cisco.com</link>
	<description></description>
	<lastBuildDate>Sun, 19 May 2013 20:18:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Department of Labor Watering Hole Attack Confirmed to be 0-Day with Possible Advanced Reconnaissance Capabilities</title>
		<link>http://blogs.cisco.com/security/department-of-labor-watering-hole-attack-confirmed-to-be-0-day-with-possible-advanced-reconnaissance-capabilities/</link>
		<comments>http://blogs.cisco.com/security/department-of-labor-watering-hole-attack-confirmed-to-be-0-day-with-possible-advanced-reconnaissance-capabilities/#comments</comments>
		<pubDate>Sat, 04 May 2013 21:56:28 +0000</pubDate>
		<dc:creator>Craig Williams</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[Cisco Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[targeted attacks]]></category>
		<category><![CDATA[TRAC]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=112409</guid>
		<description><![CDATA[Update 2 5/9/2013: Microsoft has released a &#8220;Microsoft fix it&#8221; as a temporary mitigation for this issue on systems which [...]]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/department-of-labor-watering-hole-attack-confirmed-to-be-0-day-with-possible-advanced-reconnaissance-capabilities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Possible Exploit Vector for DarkLeech Compromises</title>
		<link>http://blogs.cisco.com/security/possible-exploit-vector-for-darkleech-compromises/</link>
		<comments>http://blogs.cisco.com/security/possible-exploit-vector-for-darkleech-compromises/#comments</comments>
		<pubDate>Wed, 24 Apr 2013 12:34:17 +0000</pubDate>
		<dc:creator>Craig Williams</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[Cisco Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=111123</guid>
		<description><![CDATA[Often it is quite surprising how long old, well-known vulnerabilities continue to be exploited. Recently, a friend sent me an example of [...]]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/possible-exploit-vector-for-darkleech-compromises/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Yesterday Boston, Today Waco, Tomorrow Malware</title>
		<link>http://blogs.cisco.com/security/yesterday-boston-today-waco-tomorrow-malware/</link>
		<comments>http://blogs.cisco.com/security/yesterday-boston-today-waco-tomorrow-malware/#comments</comments>
		<pubDate>Thu, 18 Apr 2013 17:18:29 +0000</pubDate>
		<dc:creator>Craig Williams</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=110472</guid>
		<description><![CDATA[At 10:30 UTC one of the botnet spam campaigns we discussed yesterday took a shift to focus on the recent explosion in Texas.  The miscreants responded to the tragic events in Texas almost immediately. The volume of the attack is similar to what we witnessed yesterday with the maximum volume peaking above 50% of all spam sent. We've seen 23 unique sites hosting the malware. This is an attempt to grow the botnet.]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/yesterday-boston-today-waco-tomorrow-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Massive Spam and Malware Campaign Following the Boston Tragedy</title>
		<link>http://blogs.cisco.com/security/massive-spam-and-malware-campaign-following-the-boston-tragedy/</link>
		<comments>http://blogs.cisco.com/security/massive-spam-and-malware-campaign-following-the-boston-tragedy/#comments</comments>
		<pubDate>Wed, 17 Apr 2013 22:18:27 +0000</pubDate>
		<dc:creator>Craig Williams</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cisco sio]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Security Intelligence Operations (SIO)]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=110333</guid>
		<description><![CDATA[Summary On April 16th at 11:00pm GMT, the first of two botnets began a massive spam campaign to take advantage [...]]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/massive-spam-and-malware-campaign-following-the-boston-tragedy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploring a Java Bot: Part 3</title>
		<link>http://blogs.cisco.com/security/exploring-a-java-bot-part-3/</link>
		<comments>http://blogs.cisco.com/security/exploring-a-java-bot-part-3/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 21:18:58 +0000</pubDate>
		<dc:creator>Craig Williams</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security research]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=12912</guid>
		<description><![CDATA[In this post we will examine some of the offensive features incorporated into a botnet designed to launch attacks and maintain control of hosts (aka victims). ]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/exploring-a-java-bot-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploring a Java Bot: Part 2</title>
		<link>http://blogs.cisco.com/security/exploring-a-java-bot-part-2/</link>
		<comments>http://blogs.cisco.com/security/exploring-a-java-bot-part-2/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 21:17:52 +0000</pubDate>
		<dc:creator>Craig Williams</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security research]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=12908</guid>
		<description><![CDATA[When I first started this series my goal was to remove any mystery around botnets. In fact, most botnets, like this one, are relatively simple. In this post we will explore the command-and-control (C&#38;C) infrastructure, as well as the bot's update mechanism.]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/exploring-a-java-bot-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploring a Java Bot: Part 1</title>
		<link>http://blogs.cisco.com/security/exploring_a_java_bot_part_1/</link>
		<comments>http://blogs.cisco.com/security/exploring_a_java_bot_part_1/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 20:00:00 +0000</pubDate>
		<dc:creator>Craig Williams</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/the_journey_to_the_virtualized_data_center_microsoft_and_cisco_collaboratio</guid>
		<description><![CDATA[These days botnets are all over the news. Often we hear them described in vague, ominous terms designed to grab [...]]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/exploring_a_java_bot_part_1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
