Current Activity Calendar
| September 26, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.
Multiple Web Browsers Affected by Clickjackingadded September 26, 2008 at 03:28 pm
US-CERT is aware of public reports of a new cross-browser exploit technique called "Clickjacking." According to one of the reports, Clickjacking gives an attacker the ability to trick a user into clicking on something only barely or momentarily noticeable. Therefore, if a user clicks on a web page, they may actually be clicking on content from another page. A separate report indicates that this flaw affects most web browsers and that no fix is available, but that disabling browser scripting and plug-ins may help mitigate some of the risks. Adobe PDF Exploit Toolkits Circulatingadded September 25, 2008 at 11:27 am | updated September 26, 2008 at 10:55 am
US-CERT is aware of public reports of improved attack toolkits for exploiting vulnerabilities in PDF reader software.
Apple Releases Java Updates for Mac OS X 10.4 and 10.5added September 25, 2008 at 08:22 am
Apple has released updates for Java for Mac OS X 10.4 and 10.5 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code. Veritas NetBackup Server/Enterprise Server Vulnerabilitiesadded September 25, 2008 at 08:13 am
Symantec has released a Security Advisory to address multiple vulnerabilities in the Veritas NetBackup Server/Enterprise Server. These vulnerabilities are due to stack-based buffer overflow conditions and unsafe method calls within an ActiveX control that is part of the scheduler component. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code. Cisco Releases Security Alertsadded September 24, 2008 at 02:42 pm
Cisco has released multiple security alerts to address vulnerabilities in the Unified Communications Manager and IOS. These vulnerabilities may allow a remote unauthenticated attacker to cause a denial-of-service condition, obtain sensitive information, or operate with escalated privileges.
Mozilla Releases Firefox 3.0.2added September 24, 2008 at 09:32 am
Mozilla has released Firefox 3.0.2 to address multiple vulnerabilities. The impacts of these vulnerabilities include arbitrary code execution, enabling cross-site scripting, privilege escalation, information disclosure, and denial of service. As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities may also affect Thunderbird and SeaMonkey.
VMware Releases Security Advisory VMSA-0008-0015added September 19, 2008 at 09:51 am
VMware has released a Security Advisory indicating it has updated the ESXi and ESX 3.5 packages to address a vulnerability in "openwsman". This vulnerability is due to several buffer overflow conditions in the handling of HTTP basic authentication headers. Exploitation of this vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on the host running ESXi or ESX. Adobe Releases Security Advisory for Mac Illustratoradded September 18, 2008 at 08:56 am
Adobe has released a Security Advisory to alert users of potential vulnerabilities affecting the Macintosh version of Illustrator CS2. By convincing a user to open a malicious Adobe Illustrator file, an attacker may be able to execute arbitrary code. Fake Antivirus Software Circulatingadded September 16, 2008 at 12:30 pm
US-CERT is aware of public reports indicating an increase in the instances of fake antivirus software circulating. These software applications are malicious code, not legitimate antivirus applications. These instances of malicious code are noted as being distributed through spam email messages containing malicious links, instant messages containing malicious links, private messages on social networking sites, infection from other malware, and from visiting compromised websites.
Apple Releases Security Updates for Multiple Vulnerabilitiesadded September 16, 2008 at 08:02 am
Apple has released Security Update 2008-006 and Mac OS X v10.5.5 to address multiple vulnerabilities in Mac OS X and related products. The impacts of these vulnerabilities include arbitrary code execution, information disclosure, denial of service, privilege escalation, or DNS cache poisoning. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
