Current Activity Calendar
| June 18, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Microsoft Releases June Security Bulletinadded June 10, 2008 at 01:48 pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows and Internet Explorer as part of the Microsoft Security Bulletin Summary for June 2008. These vulnerabilities may allow an attacker to execute arbitrary code, obtain sensitive information, or cause a denial-of-service condition. SNMPv3 Authentication Bypass Vulnerabilityadded June 10, 2008 at 10:41 am
US-CERT is aware of a vulnerability in implementations of SNMPv3. This vulnerability is due to an error in the way the authenticator field handles shortened hash message authentication code (HMAC). Exploitation of this vulnerability may allow an attacker to read and modify any SNMP object or the configuration of the affected device using the credentials that got them onto the system. Apple Releases QuickTime 7.5added June 10, 2008 at 09:05 am
Apple has released QuickTime 7.5 to address multiple vulnerabilities. These vulnerabilities include the following:
Microsoft Releases Advance Notification for June Security Bulletinadded June 5, 2008 at 03:07 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its June release cycle will contain seven bulletins, three of which will have the severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows and Internet Explorer. The notification also states that there will be three Important bulletins for Microsoft Windows. The last of these bulletins has the severity rating of Moderate and is for Microsoft Windows. Release of these bulletins is scheduled for Tuesday, June 10. Skype Releases Security Bulletinadded June 5, 2008 at 11:38 am
Skype has released a security bulletin to address a vulnerability. This vulnerability is due to an error in the handling of "file:" URIs. By convincing a user to click on a specially crafted "file:" URI, a remote, unauthenticated attacker may be able to execute arbitrary code. Cisco Releases Security Advisoryadded June 5, 2008 at 10:07 am
Cisco has released a Security Advisory to address multiple vulnerabilities in the PIX and ASA security appliances. These vulnerabilities include the following:
HP Instant Support ActiveX Control Vulnerabilitiesadded June 4, 2008 at 02:37 pm
HP has released a support document to address multiple vulnerabilities in the Instant Support ActiveX control (HPISDataManager.dll). These vulnerabilities may allow a remote attacker to execute arbitrary code. Sun Releases Java ASP Server 4.0.3added June 4, 2008 at 02:12 pm
Sun has released Java ASP Server 4.0.3 to address multiple vulnerabilities. These vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the root user or the user running the Sun Java ASP server, obtain sensitive information, or bypass security restrictions. United States Tax Court Phishing Attackadded May 15, 2008 at 03:15 pm | updated June 4, 2008 at 01:10 pm
US-CERT is aware of public reports of a phishing attack circulating via email messages that claim to be petitions from the US Tax Court. These messages appear to be legitimate because they may contain very specific information about the message recipient. The message requests that the user follow a link to download additional information or documents. If a user clicks on this link, the website attempts to use JavaScript to install a bogus root certificate that is supposedly issued by "VeriSign Trust Network." The user will normally receive several warnings when the JavaScript code attempts to install the certificate.
Microsoft Releases Security Advisoryadded June 2, 2008 at 11:47 am
Microsoft has released Security Advisory 953818 to address reports of a blended threat that affects Windows users who have installed Apple's Safari web browser. According to the advisory, by convincing a user to visit a specially crafted website, an attacker may be able to execute arbitrary code on an affected system due to Safari's default file downloading behavior and the way that Windows Internet Explorer handles the downloaded files. |
||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
