Current Activity Calendar
| August 28, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.SSH Key-based Attacksadded August 26, 2008 at 03:41 pm | updated August 27, 2008 at 03:41 pm
US-CERT is aware of active attacks against linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as "phalanx2" is installed.
US-CERT credits DFN-CERT for their contributions regarding this issue. Microsoft Revised Security Bulletin MS08-051added August 25, 2008 at 09:22 am
Microsoft has revised Security Bulletin MS08-051, which addresses vulnerabilities in Microsoft PowerPoint. This revision describes a rerelease of the standalone update package for Microsoft Office PowerPoint 2003. Red Hat Releases OpenSSH Security Updateadded August 25, 2008 at 09:14 am
Red Hat has released Security Advisory RHSA-2008:0855-6 to address a recent security incident. In the advisory, Red Hat indicates that the incident involved an intrusion on several of their computer systems. During the intrusion, an attacker was able to sign a small number of OpenSSH packages. Red Hat has provided a list of the compromised packages and has released updated versions of the OpenSSH packages as a precautionary measure. Malware Circulating via Russia/Georgia Conflict Spam Messagesadded August 21, 2008 at 09:07 am
US-CERT is aware of public reports of malware circulating via spam email messages related to the Russia/Georgia conflict. These messages contain factual information about the conflict. The messages also contain download instructions for the user to watch a video that is attached to the message. If a user opens the attachment, malware may be downloaded and installed onto their system.
Opera Releases Version 9.52added August 21, 2008 at 08:58 am
Opera Software has released version 9.52 of the Opera web browser to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, inject malicious content into a page on a trusted website, obtain sensitive information, or cause a denial-of-service condition. Webex Meeting Manager ActiveX Control Vulnerabilityadded August 11, 2008 at 12:41 pm | updated August 18, 2008 at 10:44 am
Cisco has released a Security Advisory to address a vulnerability that affects Cisco Webex Meeting Manager. This vulnerability is due to a buffer overflow condition in the "NewObject()" method within the WebexUCFObject ActiveX control (atucfobj.dll). By convincing a user to visit a specially crafted web page, open an e-mail message that contains embedded malicious HTML code, or by sending malicious HTML code via instant messaging applications, a remote attacker may be able to execute arbitrary code. Joomla! Password Reset Vulnerabilityadded August 14, 2008 at 01:20 pm
The Joomla! Project has released an advisory to address a password reset vulnerability in the Joomla! content management system. This vulnerability, which may allow non-validating tokens to be forged, is due to a flaw in the reset token validation mechanism. Exploitation of this vulnerability may allow an unauthenticated attacker to reset the password of the first enabled user, which is typically an administrator user. Apple MobileMe Phishing Scamadded August 13, 2008 at 10:18 am
US-CERT is aware of public reports of a phishing attack circulating via email messages that appear to be targeting Apple MobileMe users. These messages claim that there is a problem with the user's billing information and instruct the user to follow a web link to update personal information. Clicking on this link directs the user to a web page that contains a seemingly legetimate web form requesting personal and financial information. Any information entered in this form is not sent to Apple but rather, to a malicious attacker.
Microsoft Releases August Security Bulletinadded August 12, 2008 at 02:24 pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows, Office, Internet Explorer, Outlook Express, Windows Mail, and Windows Messenger as part of the Microsoft Security Bulletin Summary for August 2008. These vulnerabilities may allow an attacker to execute arbitrary code or obtain sensitive information. Microsoft Releases Advanced Notification for August Security Bulletinadded August 7, 2008 at 04:27 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that the August release cycle will contain 12 bulletins, seven of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows, Office, and Internet Explorer. There will also be five important bulletins for Microsoft Windows, Office, Outlook Express, Windows Mail, and Windows Messenger. Release of these bulletins is scheduled for Tuesday, August 12. |
||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
