Current Activity Calendar
| June 29, 2007 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.New Storm Worm Variant Spreads through Social Engineeringadded June 29, 2007 at 01:31 pm
US-CERT is aware of a new variant of the Trojan Worm known as "Storm Worm" that uses social engineering with mass mailing to spread to unsuspecting victims. This variant of Storm Worm arrives as an email message with the subject line "You've received a postcard from a family member!", and contains a link to a malicious website that, when visited, installs malware on the user's system.
Publicly Available Exploit Code for a Vulnerability in RealNetworks Media Playersadded June 28, 2007 at 11:50 am
US-CERT is aware of publicly available exploit code for a buffer overflow vulnerability in RealNetworks media players. By supplying a user with a crafted media file or stream, a remote unauthenticated attacker could execute arbitrary code or cause a denial-of-service condition on a vulnerable system. Justice Department Warns Public of Fraudulent Spam Emailadded June 27, 2007 at 06:41 pm
The United States Department of Justice has released information warning the public of a recent surge in fraudulent spam e-mail messages claiming to be from the DOJ. The messages contain a malicious attachment that supposedly contains information regarding complaints filed against them with the DOJ and IRS, but instead launches malware on the user's system when opened. Multiple Vulnerabilities in Kerberos Administration Daemonadded June 26, 2007 at 02:31 pm | updated June 27, 2007 at 07:43 am
US-CERT is aware of multiple vulnerabilities in the Kerberos administration daemon that may allow a remote user to execute arbitrary code or cause a denial-of-service condition on an affected system.
Apple Releases Security Update 2007-006 and Safari 3 Beta Update 3.0.2 to Address Multiple Vulnerabilitiesadded June 25, 2007 at 10:39 am
Apple has released Security Update 2007-006 and Safari 3 Beta Update 3.0.2 to address multiple vulnerabilities in WebCore, WebKit, and Safari 3 Beta. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct cross-site scripting attacks, or alter the contents of the address bar in the Safari web browser.
CA Releases Updates for Multiple Vulnerabilities in Products that Use the Ingres Databaseadded June 22, 2007 at 03:26 pm
Computer Associates has released updates to address several vulnerabilities in products that use the Ingres database. These vulnerabilities may allow an attacker to execute arbitrary code on an affected system. Cerulean Studios Trillian Instant Messenger Vulnerabilityadded June 20, 2007 at 02:43 pm | updated June 21, 2007 at 04:47 pm
US-CERT is aware of a heap overflow vulnerability in Cerulean Studios Trillian Instant Messenger. The vulnerability may be exploited by viewing a malicious message containing a specially crafted UTF-8 string. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code with the credentials of the currently logged on user. |
|||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
