Skip to content

customize
Current Activity Calendar
Left Arrow
October 2009
Right Arrow
Su M Tu W Th F Sa
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • October 09, 2009 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    October 8Microsoft Releases Advance Notification for October Security Bulletin
    October 8Adobe Releases Security Bulletin for Critical Vulnerability
    October 6Federal Bureau of Investigation Warns Public of Fraudulent Spam Email
    October 1Research in Motion Releases Security Advisory
    September 28Microsoft Releases Fix It for SMB Vulnerability
    September 28Malicious Code Spreading via IRS Scam
    September 24Cisco Releases Multiple Security Advisories for IOS Vulnerabilities and Unified Communications Manager
    September 23Montgomery County Animal Shelter Search Engine Poisoning Campaign
    September 23Apple Releases iTunes 9.0.1
    September 18Adobe Releases Security Bulletin for RoboHelp Server 8



    Microsoft Releases Advance Notification for October Security Bulletin

    added October 8, 2009 at 04:59 pm

    Microsoft has issued a Security Bulletin Advance Notification indicating that its October release cycle will contain thirteen bulletins, eight of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows, Internet Explorer, Office, Silverlight, SQL Server, Developer Tools, and Forefront. There will also be five important bulletins for Microsoft Windows. Release of these bulletins is scheduled for Tuesday, October 13.

    US-CERT will provide additional information as it becomes available.


    Adobe Releases Security Bulletin for Critical Vulnerability

    added October 8, 2009 at 04:59 pm

    Adobe has released security bulletin APSB09-15 to alert users of a critical vulnerability in Adobe Reader and Acrobat. Adobe indicates that it has received reports of active exploitation of this vulnerability. Release of an update for this vulnerability is scheduled for Tuesday, October 13.

    US-CERT encourages users and administrators to take the following actions to help mitigate the risks:

    • Review Adobe Security Bulletin APSB09-15.
    • Disable JavaScript in Adobe Reader and Acrobat. Acrobat JavaScript can be disabled in the General preferences dialog (Edit, Preferences, JavaScript, and un-check "Enable Acrobat JavaScript").


    Federal Bureau of Investigation Warns Public of Fraudulent Spam Email

    added October 6, 2009 at 03:13 pm

    The Federal Bureau of Investigation (FBI) has released information warning the public about fraudulent email messages purporting to come from the FBI or the Department of Homeland Security. These email messages contain a malicious attachment that claims to provide an intelligence report or bulletin, but in reality attempts to launch malware on the user's system.

    More information regarding these messages can be found in the Federal Bureau of Investigation's New E-Scams and Warnings web site.

    To help protect against this type of attack, US-CERT recommends that users avoid opening attachments contained in unsolicited email messages. Additional tips regarding email attachments can be found in the US-CERT Cyber Security Tip - Using Caution with Email Attachments.


    Research in Motion Releases Security Advisory

    added October 1, 2009 at 10:35 am

    Research in Motion has released a security advisory to address a vulnerability related to how null characters are displayed in a BlackBerry dialog box. This vulnerability may allow an attacker to trick users into believing that they are connecting to a trusted secure site.

    US-CERT encourages users to review the BlackBerry security advisory KB19552 and apply any necessary updates.


    Microsoft Releases Fix It for SMB Vulnerability

    added September 22, 2009 at 10:43 am | updated September 28, 2009 at 07:01 pm

    Microsoft has released Microsoft Knowledge Base Article 975497 to address a previously reported vulnerability in Microsoft Sever Message Block (SMB). This vulnerability may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users and administrators to review Microsoft Knowledge Base Article 975497 and Microsoft Security Advisory 975497 and apply the Fix it tool or workarounds. Microsoft Knowledge Base Article 975497 addresses the vulnerability that was previously reported in the "Microsoft Releases Security Advisory 975497" Current Activity entry.

    US-CERT is aware that exploit code for this vulnerability has been made publicly available as part of the Metasploit Framework. Users and system administrators are strongly encouraged to apply the Microsoft Fix it solution or other workarounds until a patch is released.


    Malicious Code Spreading via IRS Scam

    added September 28, 2009 at 09:00 am

    US-CERT is aware of public reports of malicious code circulating via spam email messages related to the IRS. The attacks arrive via an unsolicited email message and may contain a subject line of "Notice of Underreported  Income." These messages may contain a link or attachment. If users click on this link or open the attachment, they may be infected with malicious code, including the Zeus Trojan.

    US-CERT encourages users and administrators to take the following measures to protect themselves:


    Cisco Releases Multiple Security Advisories for IOS Vulnerabilities and Unified Communications Manager

    added September 24, 2009 at 09:30 am | updated September 24, 2009 at 02:18 pm

    Cisco has released multiple security advisories to address vulnerabilities in IOS Software and Unified Communications Manager. These vulnerabilities may allow an attacker to cause a denial-of-service
    condition, buffer overflow, or access control list bypass.

    US-CERT encourages users and administrators to review the following Cisco security advisories and apply any necessary updates to help mitigate the risks.


    Montgomery County Animal Shelter Search Engine Poisoning Campaign

    added September 23, 2009 at 06:55 pm

    US-CERT is aware of public reports regarding a search engine result poisoning campaign affecting search results for the Montgomery County Animal Shelter. Users seeking details on rumors about the closure of a "Montgomery County Animal Shelter" may be led to click on illegitimate search results which attempt to download malicious code. The rumors are being spread via e-mail, forums, and social networking sites, usually taking the form of a plea for readers to contact the shelter and adopt animals prior to the shelter's closing.

    US-CERT is monitoring the situation and will provide updates as they become available.


    Apple Releases iTunes 9.0.1

    added September 23, 2009 at 09:23 am

    Apple has released iTunes 9.0.1 to address a vulnerability that may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

    US-CERT encourages users to review Apple article HT3884 and apply any necessary updates to help mitigate the risks.


    Adobe Releases Security Bulletin for RoboHelp Server 8

    added September 18, 2009 at 03:53 pm

    Adobe has released security bulletin APSB09-14 to address a vulnerability in RoboHelp Sever 8. This vulnerability may allow a remote attacker to execute arbitrary code.

    US-CERT encourages users and administrators to review Adobe security bulletin APSB09-14 and apply any necessary updates.