Current Activity Calendar
| September 08, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
Exploit Code Available for CitectSCADA Vulnerabilityadded September 8, 2008 at 04:15 pm
In June, US-CERT published Vulnerability Note VU#476345 to alert users of a vulnerability affecting Citect CitectSCADA. This vulnerability is due to a buffer overflow condition in the handling of ODBC requests from clients. Exploit code for this vulnerability is publicly available and exploitation may allow an attacker to execute arbitrary code. Cisco Releases Advisory and Security Responseadded September 5, 2008 at 07:55 am
Cisco has released a Cisco Security Advisory to address multiple vulnerabilities in Cisco PIX and ASA. These vulnerabilities may allow an attacker to cause a denial-of-service condition or obtain sensitive information. Additionally, Cisco has released a Security Response to address a vulnerability in Cisco Secure ACS. This vulnerability may allow an attacker to cause a denial-of-service condition on the affected system. Microsoft Releases Advance Notification for September Security Bulletinadded September 4, 2008 at 03:18 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its September release cycle will contain four bulletins, all of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows, Internet Explorer, .NET Framework, Office, SQL Server, and Visual Studio. Release of these bulletins is scheduled for Tuesday, September 9. FCC Releases Public Notice about Phishing Scamadded September 4, 2008 at 03:17 pm
The Federal Communications Commission (FCC) has released a public notice alerting users of a potential phishing attack. The notice indicates that non-government entities may be using websites to misdirect regulatory fee payers to an illegitimate website in an attempt to obtain their financial information. Novell Releases Update for iPrint Vulnerabilityadded September 4, 2008 at 03:15 pm
Novell has released an update to address multiple vulnerabilities in iPrint. These vulnerabilities are due to the following:
US-CERT encourages users to review Novell documents 5034540 and 5034560 and apply any necessary updates. Google Chrome Download Vulnerabilityadded September 3, 2008 at 01:52 pm
US-CERT is aware of a vulnerability that affects the Google Chrome web browser. This vulnerability is due to a default configuration that allows files to be downloaded without prompting the user. In addition, downloaded files can be opened with a single click, which could allow a user to inadvertently open a malicious file. VMware Releases Security Announcementadded September 2, 2008 at 03:00 pm
VMware has released a security announcement to address multiple vulnerabilities in VMware Workstation, VMware Player, VMware ACE, VMware Server, and VMware ESX. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, access the system with elevated privileges, or obtain sensitive information. Hurricane Gustav and Phishing Scamsadded September 1, 2008 at 12:29 pm
In the past, US-CERT has received reports of an increased number of phishing scams that take advantage of natural disasters. Due to the current situation involving Hurricane Gustav, US-CERT would like to remind users to remain cautious when receiving unsolicited email that could be a potential phishing scam.
SSH Key-based Attacksadded August 26, 2008 at 03:41 pm | updated August 27, 2008 at 03:41 pm
US-CERT is aware of active attacks against linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as "phalanx2" is installed.
US-CERT credits DFN-CERT for their contributions regarding this issue. Microsoft Revised Security Bulletin MS08-051added August 25, 2008 at 09:22 am
Microsoft has revised Security Bulletin MS08-051, which addresses vulnerabilities in Microsoft PowerPoint. This revision describes a rerelease of the standalone update package for Microsoft Office PowerPoint 2003. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
