Current Activity Calendar
| January 07, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
Microsoft Releases Advance Notification for January Security Bulletinadded January 3, 2008 at 02:29 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its January release cycle will contain 2 bulletins, one of which have a severity rating of Critical. The notification states that both of the bulletins are for the Windows operating system. The release is scheduled for Tuesday, January 8, 2008. Flash File Cross-Site Scripting Vulnerabilitiesadded January 2, 2008 at 03:42 pm | updated January 3, 2008 at 09:47 am
US-CERT is aware of reported vulnerabilities in Flash (SWF) files that may allow a remote, unauthenticated attacker to conduct cross-site scripting attacks on a vulnerable system. The flaws exist in the way that input is validated when passed to embedded ActionScript and JavaScript in the SWF file. Authoring tools that automatically generate Flash files may introduce these vulnerabilities.
Publicly Available Exploit Code for RealPlayeradded January 2, 2008 at 09:48 am
US-CERT is aware of a public report stating that working exploit code is available for RealPlayer. This exploit is reported to affect RealPlayer 11 build 6.0.14.748. Storm Worm Activity Increases During Holiday Seasonadded December 27, 2007 at 12:03 pm | updated December 27, 2007 at 04:41 pm
US-CERT is aware of an increase in Storm Worm related activity. The latest activity is centered around messages related to the New Year. This Trojan is spread via an unsolicited email message that contains a link to a malicious web site. When the malicious link is followed, the Trojan may attempt to exploit an unpatched vulnerability or continue to rely on social engineering to download and install the file on the user's system.
Adobe Flash Player Vulnerabilitiesadded December 19, 2007 at 04:09 pm | updated December 21, 2007 at 09:52 am
Adobe has released updates described in the Adobe Security bulletin to address multiple vulnerabilities in Flash Player. The impacts of these vulnerabilities include arbitrary code execution, privilege escalation, and cross-site scripting. The Adobe Security bulletin states that all platforms running a vulnerable version of Flash Player are affected.
Google Orkut Wormadded December 20, 2007 at 04:52 pm
US-CERT is aware of public reports of a worm propagating via Google's social network, Orkut. It has been reported that this worm spreads by sending messages to Orkut users. When a user visits an infected Orkut profile, the user becomes infected by a "scrap" that references a remote, malicious javascript file (virus.js).
MSRC Releases Update to MS07-069added December 19, 2007 at 04:09 pm
The Microsoft Security Response Center(MSRC) has released an update to MS07-069 to address an installation error on Windows XP Service Pack 2. After installation, Internet Explorer 6 may stop responding when visiting a web site. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
