Current Activity Calendar
| September 10, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
U.S. Presidential Election and Phishing Scamsadded September 10, 2008 at 09:18 am
Throughout the United States presidential election campaigns, US-CERT has received reports of phishing scams and email attacks related to the upcoming election. US-CERT reminds users to remain cautious when receiving unsolicited email messages that are related to the presidential election and presidential candidates because the messages may be part of a phishing scam.
Apple Releases Security Updatesadded September 10, 2008 at 09:11 am
Apple has released four security updates to address multiple vulnerabilities in iTunes, QuickTime, iPod touch, and Bonjour for Windows. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct DNS cache poisoning attacks, spoof or hijack TCP sessions, access the system with escalated privileges, or obtain sensitive information.
Microsoft Releases September Security Bulletinadded September 9, 2008 at 01:10 pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows, Internet Explorer, .NET Framework, Office, SQL Server, and Visual Studio as part of the Microsoft Security Bulletin Summary for September 2008. These vulnerabilities may allow an attacker to execute arbitrary code. Google Releases Chrome Version 0.2.149.29added September 9, 2008 at 09:14 am
Google has released Chrome version 0.2.149.29 to address multiple vulnerabilities. The four vulnerabilities are due to the following:
Google has indicated that the fixed version is being applied to all users through automatic updates. US-CERT encourages users to review the Chrome 0.2.149.29 release notes and upgrade if the newest version has not been automatically applied. WordPress Releases Version 2.6.2added September 9, 2008 at 08:47 am
WordPress has released version 2.6.2 to address multiple vulnerabilities. These vulnerabilities are due to SQL column truncation and weaknesses in random number generation. Combined, these vulnerabilities may allow an attacker to reset a user's password and possibly predict the newly generated password. Exploitation of these vulnerabilities could permit an attacker to gain access to a system running WordPress with open registration enabled under the context of a legitimate user. Exploit Code Available for CitectSCADA Vulnerabilityadded September 8, 2008 at 04:15 pm
In June, US-CERT published Vulnerability Note VU#476345 to alert users of a vulnerability affecting Citect CitectSCADA. This vulnerability is due to a buffer overflow condition in the handling of ODBC requests from clients. Exploit code for this vulnerability is publicly available and exploitation may allow an attacker to execute arbitrary code. Cisco Releases Advisory and Security Responseadded September 5, 2008 at 07:55 am
Cisco has released a Cisco Security Advisory to address multiple vulnerabilities in Cisco PIX and ASA. These vulnerabilities may allow an attacker to cause a denial-of-service condition or obtain sensitive information. Additionally, Cisco has released a Security Response to address a vulnerability in Cisco Secure ACS. This vulnerability may allow an attacker to cause a denial-of-service condition on the affected system. Microsoft Releases Advance Notification for September Security Bulletinadded September 4, 2008 at 03:18 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its September release cycle will contain four bulletins, all of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows, Internet Explorer, .NET Framework, Office, SQL Server, and Visual Studio. Release of these bulletins is scheduled for Tuesday, September 9. FCC Releases Public Notice about Phishing Scamadded September 4, 2008 at 03:17 pm
The Federal Communications Commission (FCC) has released a public notice alerting users of a potential phishing attack. The notice indicates that non-government entities may be using websites to misdirect regulatory fee payers to an illegitimate website in an attempt to obtain their financial information. Novell Releases Update for iPrint Vulnerabilityadded September 4, 2008 at 03:15 pm
Novell has released an update to address multiple vulnerabilities in iPrint. These vulnerabilities are due to the following:
US-CERT encourages users to review Novell documents 5034540 and 5034560 and apply any necessary updates. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
