Skip to content

customize
Current Activity Calendar
Left Arrow
November 2007
Right Arrow
Su M Tu W Th F Sa
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • November 19, 2007 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    November 19Trojan Spreading via MSN Messenger
    November 15Mac OS X Leopard Firewall Changes
    November 15Apple Releases Security Updates to Address Multiple Vulnerabilities
    November 15False Microsoft Update Emails Circulating
    November 13Microsoft Releases November Security Bulletins
    November 9Public Exploit for Oracle Database Server Vulnerability
    November 8Microsoft Releases Advance Notification for November Security Bulletin



    Trojan Spreading via MSN Messenger

    added November 19, 2007 at 11:12 am

    US-CERT is aware of reports of a Trojan spreading via MSN Messenger.  The Trojan arrives as a chat message that appears to contain an image file, that when opened, downloads and installs a Internet Relay Chat Bot. These messages may appear to come from a known contact.

    US-CERT urges users and administrators to take the following preventative measures to help mitigate the security risks:


    Mac OS X Leopard Firewall Changes

    added November 5, 2007 at 05:06 pm | updated November 15, 2007 at 02:35 pm

    Apple's Mac OS X Leopard includes an application-based firewall feature. US-CERT is aware of ambiguities in the way the firewall components supplied with Leopard report the status of the firewall configuration. Users may be misinformed of the status of their firewall rule set, thus placing listening network services at an increased risk.

    Apple has published Mac OS X v10.5.1 Update to address this issue.  US-CERT encourages users to apply this update to mitigate this risk.


    Apple Releases Security Updates to Address Multiple Vulnerabilities

    added November 15, 2007 at 08:43 am | updated November 15, 2007 at 01:31 pm

    Apple has released Mac OS X 10.4.11 and Security Update 2007-008 to address multiple vulnerabilities.  These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or access the system with escalated privileges.

    More information regarding the vulnerabilities and remediation information can be found in:

    US-CERT strongly encourages users to review the bulletins and follow best-practice security policies to determine which updates should be applied. 


    False Microsoft Update Emails Circulating

    added November 15, 2007 at 10:37 am

    US-CERT is aware of false Microsoft Update email messages being publicly circulated.  These messages contain multiple links that may direct a user to a malicious web site.  The impact of following these links is currently unknown, more information will be provided as it becomes available.

    US-CERT encourages users to take the following measures to protect themselves:

    • Do not follow unsolicited web links in email messages
    • Follow the Microsoft guidelines for recognizing fraudulent email messages


    Microsoft Releases November Security Bulletins

    added November 13, 2007 at 01:26 pm | updated November 13, 2007 at 03:23 pm

    Microsoft has released updates to address vulnerabilities in Windows as part of the Microsoft Security Bulletin Summary for November 2007.

    More information about these vulnerabilities can be found in Technical Cyber Security Alert TA07-317A.

    US-CERT strongly encourages users to review the bulletins and follow best-practice security policies to determine which updates should be applied.


    Public Exploit for Oracle Database Server Vulnerability

    added November 9, 2007 at 02:42 pm

    US-CERT is aware of publicly available exploit code for a vulnerability that affects Oracle Database Server. This vulnerability may allow a remote, authenticated attacker to execute arbitrary code on affected systems. 

    US-CERT will provide more information as it becomes available.


    Microsoft Releases Advance Notification for November Security Bulletin

    added November 8, 2007 at 02:09 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that its November release cycle will contain two bulletins, one of which has a severity rating of Critical. The notification states that both bulletins are for Windows.  The release is scheduled for Tuesday, November 13, 2007.

    US-CERT will provide additional information as it becomes available.