Current Activity Calendar
| January 09, 2009 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Malicious Code Circulating via Israel/Hamas Conflict Spam Messagesadded January 9, 2009 at 09:25 am
US-CERT is aware of public reports of malicious code circulating via spam email messages related to the Israel/Hamas conflict in Gaza. These messages may contain factual information about the conflict and appear to come from CNN. Additionally, the messages indicate that additional news coverage of the conflict can be viewed by following a link provided in the email body. If users click on this link, they are redirected to a bogus CNN website that appears to contain a video. Users who attempt to view this video will be prompted to update to a new version of Adobe Flash Player in order to view the video. This update is not a legitimate Adobe Flash Player update; it is malicious code. If users download this executable file, malicious code may be installed on their systems.
Microsoft Releases Advance Notification for January Security Bulletinadded January 8, 2009 at 01:22 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that the January release cycle will contain one bulletin, which will have a severity rating of Critical. The notification states that this Critical bulletin is for Microsoft Windows. Release of this bulletin is scheduled for Tuesday, January 13. Cisco Releases Security Advisory for Global Site Selectoradded January 8, 2009 at 09:03 am
Cisco has released a Security Advisory to address a vulnerability in the Application Control Engine Global Site Selector (GSS). By sending a specially crafted sequence of DNS requests, a remote attacker may be able to cause a denial-of-service condition. OpenSSL Releases Security Advisoryadded January 8, 2009 at 08:47 am
The OpenSSL project has released a Security Advisory to address a vulnerability in OpenSSL. This vulnerability results from several incorrect checks of the result of the EVP_VerifyFinal function when performing signature checks on DSA and ECDSA keys used with SSL/TLS. As a result, a malformed signature could be treated as valid. Exploitation of this vulnerability may allow a remote attacker to bypass signature checks and conduct spoofing attacks. Rogue MD5 SSL Certificate Vulnerabilityadded December 30, 2008 at 05:05 pm | updated December 31, 2008 at 05:54 pm
US-CERT is aware of a public report describing how MD5 collisions can be leveraged to generate rogue SSL CA certificates. A rogue CA certificate could be used by an attacker to generate valid SSL certificates for arbitrary web sites. Using these certificates in DNS redirection attacks, an attacker could spoof an SSL protected web site and obtain sensitive information. Worm Exploiting Vulnerability described in MS08-067added December 31, 2008 at 02:04 pm | updated December 31, 2008 at 05:54 pm
US-CERT is aware of a public report of a worm circulating that has the capability of exploiting the patched vulnerability described in Microsoft Security Bulletin MS08-067.
US-CERT will continue to monitor this activity and provide updates as needed. Malware Spreading via Malicious Ecardsadded December 31, 2008 at 02:04 pm | updated December 31, 2008 at 05:54 pm
US-CERT is aware of public reports of malware spreading via malicious electronic greeting cards (ecards) related to the Christmas and New Year's holidays. The reports indicate that the malware is spreading via emails containing a link to a malicious ecard. If a user clicks on the link, they will be prompted to download an executable file. If the user accepts the download, malware may be installed onto their system.
Mozilla Releases Thunderbird 2.0.0.19added December 31, 2008 at 02:04 pm
Mozilla has released Thunderbird 2.0.0.19 to address multiple vulnerabilities. The impacts of these vulnerabilities include arbitrary code execution, information disclosure, and denial of service. As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities also affect Firefox but were addressed in the previously released Firefox 3.0.5 update. Trend Micro Releases Updates for HouseCalladded December 23, 2008 at 10:53 am
Trend Micro has released a patch to address a vulnerability in HouseCall 6.6. This vulnerability may allow an attacker to execute arbitrary code. Visitors to the publicly available HouseCall application may receive an older, vulnerable version of the control. Microsoft Releases Security Advisory (961040)added December 23, 2008 at 08:29 am | updated December 23, 2008 at 10:44 am
Microsoft has released Security Advisory 961040 to address reports of attacks against a new vulnerability in Microsoft SQL Server 2000, Microsoft SQL Server 2005, Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine, Microsoft SQL Server 2000 Desktop Engine, and Windows Internal Database. The vulnerability occurs in the extended stored procedure "sp_replwriteovarbin." Exploitation of this vulnerability may allow an authenticated attacker to execute arbitrary code. Additionally, if a web application is vulnerable to SQL injection, an unauthenticated, remote attacker may be able to execute arbitrary code. |
|||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
