Current Activity Calendar
| November 06, 2009 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.SSL and TLS Vulnerable to Man-in-the-middle Attacksadded November 6, 2009 at 07:01 pm
US-CERT is aware of reports of publicly available exploit code for a vulnerability within the SSL and TLS protocols. Reports indicate that exploitation of this vulnerability may allow an attacker to conduct a man-in-the-middle attack, allowing an attacker to inject plaintext into the beginning of the application protocol stream. Microsoft Releases Advance Notification for November Security Bulletinadded November 5, 2009 at 04:17 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its November release cycle will contain six bulletins, three of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows. There will also be three important bulletins for Microsoft Windows and Microsoft Office. Release of these bulletins is scheduled for Tuesday, November 10. BlackBerry Desktop Manager Vulnerabilityadded November 5, 2009 at 08:45 am
Research in Motion has released Security Advisory KB19701 to address a vulnerability in BlackBerry Desktop Manager. This vulnerability may allow an attacker to execute arbitrary code. Sun Releases Update 17 for Java SE 6added November 4, 2009 at 09:04 am
Sun has released update 17 for Java SE JDK 6 and Java SE JRE 6 to address multiple vulnerabilities. The impacts of these vulnerabilities include arbitrary code execution, privilege escalation, denial of service, and information disclosure. Adobe Releases Update for Shockwave Playeradded November 4, 2009 at 09:04 am
Adobe has released Shockwave Player 11.5.2.602 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to run malicious code on the user's machine. Mozilla Releases Firefox 3.0.15 and Firefox 3.5.4added October 28, 2009 at 09:13 am
Mozilla has released Firefox 3.0.15 and Firefox 3.5.4 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, execute arbitrary JavaScript with chrome privileges, or cause a denial-of-service condition. As described in the Mozilla Foundation Security Advisories, some of these vulnerabilities may also affect SeaMonkey. Federal Deposit Insurance Corporation Warns Public of Fraudulent Emailadded October 27, 2009 at 11:59 am
The Federal Deposit Insurance Corporation (FDIC) has released information warning the public about fraudulent email messages purporting to come from the FDIC. These email messages provides a link to a fraudulent FDIC website. Users are then instructed to download their "personal FDIC Insurance File."
BlackBerry PhoneSnoop Application Used to Spy on Usersadded October 27, 2009 at 11:59 am
US-CERT is aware of public reports of a new software application called PhoneSnoop. This software allows an attacker to call a user's BlackBerry and listen to personal conversations. In order to install and setup the PhoneSnoop application, attackers must have physical access to the user's device or convince a user to install PhoneSnoop. Oracle Releases Critical Patch Update for October 2009added October 20, 2009 at 04:04 pm
Oracle has released its Critical Patch Update for October 2009 to address 38 vulnerabilities across several products. This update contains the following security fixes:
Malware Spam Messages Related to Microsoft Outlook, SSL Certificatesadded October 15, 2009 at 05:00 pm
US-CERT is aware of public reports of an increased number of spam messages related to Microsoft Outlook or SSL certificates. These messages contain a malicious file or link that claims to provide an update, but in reality, attempts to launch malware on a user's system. Typically, the messages instruct the user to click on a link to save a file or to open an attachment, either of which could infect the user's system. |
||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
