Current Activity Calendar
| January 14, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Attack Vector Targets UPnPadded January 14, 2008 at 03:37 pm
US-CERT is aware of an attack vector targeting networking devices that support UPnP (Universal Plug and Play). This specific attack occurs via a maliciously crafted SWF file that is contained in a web site. When the web site is visited, changes may occur to a router's configuration via UPnP. This may allow an attacker to change any parameter on the router or device that can be set by UPnP. QuickTime Real Time Streaming Protocol Vulnerabilityadded January 10, 2008 at 03:49 pm | updated January 11, 2008 at 11:07 am
US-CERT is aware of a public report of a vulnerability in Apple QuickTime. The flaw is in the way that QuickTime handles Real Time Streaming Protocol (RTSP) Response message headers. By persuading a user to access a specially crafted QuickTime file, or RTSP stream, a remote attacker may be able to execute arbitrary code or cause a denial of service on a vulnerable system. Widespread SQL Injection Attacks Compromising Websitesadded January 10, 2008 at 12:07 pm
US-CERT is aware of widespread SQL injection attacks compromising websites across all sectors. The compromised sites have been modified to include a reference to a malicious JavaScript file. When a user unknowingly visits a compromised site, they are silently re-directed to a series of malicious web pages that attempt to exploit multiple client-side vulnerabilities in a number of applications, including Internet Explorer and RealPlayer.
New iPhone Trojan Spreadingadded January 9, 2008 at 10:10 am
US-CERT has received reports of a new Trojan horse program that affects the Apple iPhone. This Trojan claims to be a tool used to prepare the device for an upgrade to firmware version 1.1.3. When a user installs the Trojan, other application components are altered. If the Trojan is uninstalled, the affected applications may also be removed. Microsoft Releases January Security Bulletinadded January 8, 2008 at 01:49 pm | updated January 8, 2008 at 03:27 pm
Microsoft has released updates to address vulnerabilities in Windows as part of the Microsoft Security Bulletin Summary for January 2008. Microsoft Releases Advance Notification for January Security Bulletinadded January 3, 2008 at 02:29 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its January release cycle will contain 2 bulletins, one of which have a severity rating of Critical. The notification states that both of the bulletins are for the Windows operating system. The release is scheduled for Tuesday, January 8, 2008. Flash File Cross-Site Scripting Vulnerabilitiesadded January 2, 2008 at 03:42 pm | updated January 3, 2008 at 09:47 am
US-CERT is aware of reported vulnerabilities in Flash (SWF) files that may allow a remote, unauthenticated attacker to conduct cross-site scripting attacks on a vulnerable system. The flaws exist in the way that input is validated when passed to embedded ActionScript and JavaScript in the SWF file. Authoring tools that automatically generate Flash files may introduce these vulnerabilities.
|
|||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
