Skip to content

customize
Current Activity Calendar
Left Arrow
September 2007
Right Arrow
Su M Tu W Th F Sa
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • September 10, 2007 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    September 10Storm Worm Variant Spreads by Fictitious NFL Email
    September 6Microsoft Releases Advance Notification for September Security Bulletins
    September 6Apple Releases Security Update to Address Vulnerability in iTunes
    September 5Cisco Addresses Vulnerabilities in Content Switching Module and Video Surveillance Products
    September 4Multiple Vulnerabilities in Kerberos Administration Daemon
    August 30USAJOBS and Monster Resume Database Compromise
    August 29Quiksoft EasyMail SMTP ActiveX Control Vulnerabilities



    Storm Worm Variant Spreads by Fictitious NFL Email

    added September 10, 2007 at 02:47 pm

    US-CERT is aware of public reports that the Storm Worm variant, previously reported in the US-CERT Current Activity on 29-June-2007, is currently spreading by email messages purporting to be an NFL (National Football League) game statistics website. This variant of the Storm Worm arrives as an email message and contains a link to a malicious website that, when visited, installs malware on the user's system.

    US-CERT urges users and administrators to take the following preventative measures to mitigate the security risks:


    Microsoft Releases Advance Notification for September Security Bulletins

    added September 6, 2007 at 01:50 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that their September release cycle will contain five bulletins, some of which have a maximum severity rating of Critical. The notification further states that the bulletins are for Windows, Visual Studio, Windows Services for UNIX, Subsystem for UNIX-based Applications, MSN Messenger, Windows Live Messenger, and SharePoint Server. The release is scheduled for Tuesday, September 11, 2007.

    US-CERT will provide additional information as it becomes available.


    Apple Releases Security Update to Address Vulnerability in iTunes

    added September 6, 2007 at 01:19 pm

    Apple has released iTunes 7.4 to address a vulnerability in the way that iTunes processes album cover art. By enticing a user to open a specially crafted music file, an attacker may be able to execute arbitrary code on an affected system.

    US-CERT recommends that users update to iTunes version 7.4 as soon as possible. 


    Cisco Addresses Vulnerabilities in Content Switching Module and Video Surveillance Products

    added September 5, 2007 at 02:19 pm

    Cisco has issued two Security Advisories to address vulnerabilities in their Content Switching Module, Video Surveillance IP Gateway, Services Platform, and Integrated Services Platform devices. These vulnerabilities may allow a remote, unauthenticated user to cause a denial-of-service condition or gain complete administrative control of an affected device.

    For more information about these vulnerabilities and affected products, see "Denial of Service Vulnerabilities in Content Switching Module" and "Cisco Video Surveillance IP Gateway and Services Platform Authentication Vulnerabilities."

    US-CERT strongly recommends that administrators review the advisories and follow best-practice security policies to determine what updates or workarounds should be applied.


    Multiple Vulnerabilities in Kerberos Administration Daemon

    added September 4, 2007 at 03:15 pm

    US-CERT is aware of multiple vulnerabilities in the Kerberos administration daemon that may allow a remote user to execute arbitrary code or cause a denial-of-service condition on an affected system.

    More information regarding these vulnerabilities may be found in the following:

    US-CERT strongly encourages users and administrators to review the documents above and apply the patches as described in MIT krb5 Security Advisory 2007-006 to address these vulnerabilities.


    USAJOBS and Monster Resume Database Compromise

    added August 30, 2007 at 02:29 pm

    US-CERT is aware of a database compromise affecting Monster.com. Reports indicate that the resume database was targeted and that subscriber names, addresses, phone numbers, and email addresses were disclosed to the attacker. This compromise also affects USAJOBS.gov subscribers as Monster Worldwide is the technology provider for USAJOBS. Monster states that social security numbers have not been compromised as USAJOBS has security policies in place to safeguard them.

    More information may be found at the following:

    Users are encouraged to take the following measures to protect themselves from potential phishing attacks that may result from this compromise:

        * Do not follow unsolicited web links received in email messages.
        * Contact your financial institution immediately if you believe your account and/or financial information has been compromised.
        * Verify the legitimacy of the email by contacting the company directly through a trusted contact number.
        * Visit the Anti-Phishing Working Group for more information on known phishing attacks.

    For additional information regarding phishing, US-CERT recommends reading the following documents:

       1. Technical Trends in Phishing Attacks
       2. Recognizing and Avoiding Email Scams
       3. Avoiding Social Engineering and Phishing Attacks


    Quiksoft EasyMail SMTP ActiveX Control Vulnerabilities

    added August 29, 2007 at 03:56 pm

    US-CERT is aware of publicly available exploit code for vulnerabilities in the Quiksoft EasyMail SMTP ActiveX control. This control is packaged with several applications, including Earthlink internet access software. These stack buffer overflow vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. 

    More information about this vulnerability can be found in the Vulnerability Note VU#281977.

    US-CERT recommends the workarounds as described in Vulnerability Note VU#281977 to help mitigate the security risks.