Current Activity Calendar
| March 17, 2009 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Waledac Trojan Horse Spam Campaign Circulatingadded March 17, 2009 at 09:08 am
US-CERT is aware of public reports of malicious code circulating via spam email messages related to bogus terror attacks in the recipient's local area. These messages use subject lines implying that a fatal bomb attack has occurred near the recipient and contain a link to "breaking news." Users who click on the link will be taken to a site posing as a Reuters news article that contains a bogus news story about the fatal bomb attack. The systems serving the bogus news story check a visiting user's IP address to obtain a geographical location to insert a nearby placename into the bogus article. The articles also contain links to video content, claiming that the latest Flash Player is required to view the video. If users attempt to update or install the Flash Player from the link provided in the article, their systems may become infected with malicious code.
Adobe Releases Security Updates for Reader 9 and Acrobat 9added March 11, 2009 at 09:45 am | updated March 11, 2009 at 11:18 am
Adobe has released Reader 9.1 and Acrobat 9.1 to address a vulnerability. This vulnerability is due to a buffer overflow condition that exists in the way Adobe Acrobat Reader handles JBIG2 streams. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition. Adobe has indicated that it is aware of reports of active exploitation. New Attack Vectors for Adobe JBIG2 Vulnerabilityadded March 10, 2009 at 04:52 pm
US-CERT is aware of public reports of two new attack vectors for a vulnerability affecting Adobe Reader and Acrobat. This vulnerability is due to a buffer overflow condition that exists in the way Adobe Acrobat Reader handles JBIG2 Streams.
US-CERT will provide additional information as it becomes available. Microsoft Releases March Security Bulletin Summaryadded March 10, 2009 at 01:30 pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows as part of the Microsoft Security Bulletin Summary for March 2009. These vulnerabilities may allow an attacker to execute arbitrary code, redirect network traffic, or allow spoofing. Economic Stimulus Email and Website Scamsadded March 5, 2009 at 04:08 pm
US-CERT is aware of reports of economic stimulus scams circulating. These scams are being conducted through both email and malicious websites.
Microsoft Releases Advanced Notification for March Security Bulletinadded March 5, 2009 at 03:12 pm
Microsoft has issued a Security Bulletin Advanced Notification indicating that the March release cycle will contain three bulletins, one of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows. There will also be two Important bulletins for Microsoft Windows. Release of these bulletins is scheduled for Tuesday, March 10. Mozilla Foundation Releases Firefox 3.0.7added March 5, 2009 at 08:44 am
Mozilla Foundation has released Firefox 3.0.7 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or spoof the location bar. The Mozilla Foundation Security Advisories also indicate that these vulnerabilities affect Thunderbird and SeaMonkey.
Malicious Code Targeting Social Networking Site Usersadded March 4, 2009 at 11:53 am
US-CERT is aware of public reports of malicious code spreading via popular social networking sites including myspace.com, facebook.com, hi5.com, friendster.com, myyearbook.com, bebo.com, and livejournal.com. The reports indicate that the malware, named Koobface, is spreading through invitations from a user's contact that include a link to view a video. If the users click on the link in this invitation, they are prompted to update Adobe Flash Player. This update is not a legitimate Adobe Flash Player update, it is malicious code.
Opera Software Releases Opera Browser 9.64added March 3, 2009 at 08:48 am
Opera Software has released Opera 9.64 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or conduct cross-domain scripting attacks. Cisco Releases Security Advisory for ACE 4710 Appliance and ACE Moduleadded February 27, 2009 at 09:26 am
Cisco has released a Security Advisory to address multiple vulnerabilities in the ACE Application Control Engine Module, ACE 4710 Application Control Engine. These vulnerabilities may allow an attacker to obtain administrative level access, operate with escalated privileges, or cause a denial-of-service condition. |
|||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
