Skip to content

customize
Current Activity Calendar
Left Arrow
October 2007
Right Arrow
Su M Tu W Th F Sa
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • October 26, 2007 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    October 26Active Exploitation of Microsoft Windows URI Protocol Handling Vulnerability
    October 26New Storm Worm Variant Disables Security Software
    October 26California Wildfires Spawn Phishing Sites
    October 24RealNetworks Issues Security Update for RealPlayer Vulnerability
    October 24Active Exploitation of Vulnerabilities in Adobe Acrobat and Adobe Reader
    October 19Mozilla Releases Security Advisories to Address Multiple Vulnerabilities
    October 19Active Exploitation of a Vulnerability in RealPlayer



    Active Exploitation of Microsoft Windows URI Protocol Handling Vulnerability

    added October 26, 2007 at 03:15 pm

    Microsoft has released a revision to Microsoft Security Advisory (943521), which was previously reported by US-CERT in the Microsoft Windows URI Protocol Handling Vulnerability Current Activity. This revision states that because of an active exploitation the severity rating has been increased.

    More information regarding this vulnerability can be found in the following:


    New Storm Worm Variant Disables Security Software

    added October 26, 2007 at 03:15 pm

    US-CERT is aware of a new Storm Worm variant. Functionality in this variant can cause certain types of programs, including anti-virus and network access control programs, to appear as if they are functioning correctly, though the process(es) have been disabled by the worm.

    More information can be found in the eWEEK Security News and Sophos Security Information Blog.

    US-CERT urges users and administrators to take the following preventative measures to mitigate the security risks:


    California Wildfires Spawn Phishing Sites

    added October 26, 2007 at 03:15 pm

    US-CERT has received reports of multiple phishing sites that attempt to trick users into donating funds to fraudulent foundations in the aftermath of the California Wildfires. US-CERT warns users to expect an increase in targeted phishing emails due to the recent events in California.

    Phishing emails may appear as requests from a charitable organization asking the users to click on a link that will then take them to a fraudulent site that appears to be a legitimate charity. The users are then asked to provide personal information that can further expose them to future compromises.

    Users are encouraged to take the following measures to protect themselves from this type of phishing attack:

    1. Do not follow unsolicited web links received in email messages.
    2. Contact your financial institution immediately if you believe your account/and or financial information has been compromised.
    For additional information regarding phishing, US-CERT recommends reading the Avoiding Social Engineering and Phishing Attacks document.

    RealNetworks Issues Security Update for RealPlayer Vulnerability

    added October 20, 2007 at 02:32 pm | updated October 24, 2007 at 01:31 pm

    RealNetworks has issued a Security Update to address the previously reported buffer overflow vulnerability in RealPlayer. This vulnerability could allow an attacker to execute arbitrary code on an affected system by enticing a user to view a specially crafted HTML document.

    US-CERT recommends that users apply the update as described in the Security Update from RealNetworks.

    More information regarding this vulnerability can be found in Vulnerability Note VU#871673 and in Technical Cyber Security Alert TA07-297A.


    Active Exploitation of Vulnerabilities in Adobe Acrobat and Adobe Reader

    added October 23, 2007 at 02:28 pm | updated October 24, 2007 at 01:18 pm

    US-CERT is aware of active exploitation of a previously reported vulnerability in Adobe Acrobat, Adobe Reader, and other Adobe PDF products. Adobe has released an update and provided a workaround to address this vulnerability.

    US-CERT encourages users to apply the update or workaround as soon as possible to mitigate this risk.

    More information is available in the Adobe Security Advisory APSB07-18.


    Mozilla Releases Security Advisories to Address Multiple Vulnerabilities

    added October 19, 2007 at 08:13 am | updated October 19, 2007 at 03:10 pm

    Mozilla has released Security Advisories to address several vulnerabilities in Firefox, Thunderbird, and SeaMonkey. These vulnerabilities may allow an attacker to hide the window title bar, execute arbitrary code or commands, or access arbitrary information on an affected system.

    More information regarding these vulnerabilities can be found in the Vulnerability Notes Database.

    US-CERT encourages users to upgrade to the latest versions as described in the Security Advisories.


    Active Exploitation of a Vulnerability in RealPlayer

    added October 19, 2007 at 10:29 am

    US-CERT is aware of active exploitation of a buffer overflow vulnerability in RealPlayer. This vulnerability affects RealPlayer version 9 and later, and may allow an attacker to execute arbitrary code on an affected system.

    Until a fix becomes available, US-CERT recommends that users disable ActiveX as described in the Securing Your Web Browser document to help mitigate the security risk.

    US-CERT will continue to investigate and provide additional information as it becomes available.