Current Activity Calendar
| August 12, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Microsoft Releases August Security Bulletinadded August 12, 2008 at 02:24 pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows, Office, Internet Explorer, Outlook Express, Windows Mail, and Windows Messenger as part of the Microsoft Security Bulletin Summary for August 2008. These vulnerabilities may allow an attacker to execute arbitrary code or obtain sensitive information. Webex Meeting Manager ActiveX Control Vulnerabilityadded August 11, 2008 at 12:41 pm
US-CERT is aware of public reports of a vulnerability that affects Webex Meeting Manager. This vulnerability is due to improper handling of arguments passed to the "NewObject()" method within the WebexUCFObject ActiveX control (atucfobj.dll). By convincing a user to visit a specially crafted web page, a remote attacker may be able to execute arbitrary code. Microsoft Releases Advanced Notification for August Security Bulletinadded August 7, 2008 at 04:27 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that the August release cycle will contain 12 bulletins, seven of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows, Office, and Internet Explorer. There will also be five important bulletins for Microsoft Windows, Office, Outlook Express, Windows Mail, and Windows Messenger. Release of these bulletins is scheduled for Tuesday, August 12. Malware Circulating via Spam Messagesadded August 7, 2008 at 12:06 pm
US-CERT is aware of public reports of malware spreading via spam. It has been reported that malware is spreading in spam messages related to the upcoming Olympics and to fake CNN news reports. If a user clicks the link to one of these fake news reports they are prompted to install a Flash Player update. If users attempt to install the update, malware may be downloaded and installed onto their system.
Oracle Releases Patch for WebLogic Plug-in Vulnerabilityadded August 6, 2008 at 01:09 pm
Oracle has released a patch to address a previously disclosed vulnerability in the WebLogic plug-in for Apache. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition. Malware Targeting Adobe Flash Playeradded August 5, 2008 at 12:43 pm
Adobe has issued a Security Bulletin warning of malware spreading via a fraudulent Flash Player installer. Adobe warns that a worm is making fraudulent posts on social networking sites. These posts include links that lead to fake sites that prompt users to update their versions of Flash Player. If users attempt to use the installer to make the update, malware may be downloaded and installed onto their systems.
CA ARCserve Backup for Laptops and Desktops Server vulnerabilityadded August 4, 2008 at 11:35 am
US-CERT is aware of a vulnerability that affects CA ARCserve Backup for Laptops and Desktops. This vulnerability may allow an attacker to execute arbitrary code or cause a denial-of-service condition on the server. Internet System Consortium releases BIND -P2 patchesadded August 4, 2008 at 11:35 am
The Internet System Consortium has released updates for BIND to address performance and stability issues. Apple Releases Security Update 2008-005added August 1, 2008 at 08:17 am
Apple has released Security Update 2008-005 to address multiple vulnerabilities that affect a number of applications. These vulnerabilities may allow an attacker to conduct DNS cache poisoning attacks, execute arbitrary code, cause a denial-of-service condition, or access the affected system with elevated privileges. Please note that this update addresses recent issues with weaknesses in common DNS implementations; see Vulnerability Note VU#800113 for additional information. Airline E-ticket Email Attackadded July 31, 2008 at 09:15 am
US-CERT is aware of public reports indicating that a new email attack is circulating. This attack uses email messages that appear to be from legitimate airlines and contain information about a bogus e-ticket. These email messages instruct the user to open the attachment to obtain the e-ticket. If a user opens this attachment, a file may be executed to infect the user's system with malicious code.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
