<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>US-CERT Current Activity</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current"/>
<link rel="self" type="application/atom+xml" hreflang="en" href="http://www.us-cert.gov/current/index.atom"/>
<updated>2012-02-09T16:06:17-05:00</updated>
<author>
<name>US-CERT</name>
<email>info@us-cert.gov</email>
<uri>http://www.us-cert.gov</uri>
</author>
<id>http://www.us-cert.gov/</id>
<subtitle>The US-CERT Current Activity web
        page is a regularly updated summary of the most frequent, high-impact types of security
        incidents currently being reported to the US-CERT.</subtitle>
<rights>Copyright 2012 Carnegie Mellon University</rights>
<entry>
<title>U.S. Tax Season Phishing Scams and Malware Campaigns</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#us_tax_season_phishing_scams1"/>
<id>http://www.us-cert.gov/current/index.html#us_tax_season_phishing_scams1</id>
<published>2012-02-08T11:10:01-05:00</published>
<updated>2012-02-10T11:51:16-05:00</updated>
<content type="html">          In the past, US-CERT has received reports of an increased number of phishing scams and malware campaigns that take advantage of the United States tax season. Due to the upcoming tax deadline, US-CERT reminds users to remain cautious when receiving unsolicited email that could be part of a potential phishing scam or malware campaign.&lt;BR&gt;&lt;BR&gt;These phishing scams and malware campaigns may include, but are not limited to, the following:&lt;BR&gt;
&lt;UL&gt;
&lt;LI&gt;information that refers to a tax refund, 
&lt;LI&gt;warnings about unreported or under-reported income, 
&lt;LI&gt;offers to assist in filing for a refund, and 
&lt;LI&gt;details about fake e-file websites.&lt;/LI&gt;&lt;/UL&gt;These messages, which may appear to be from the IRS, may ask users to submit personal information via email or may instruct the user to follow a link to a website that requests personal information or contains malicious code.&lt;BR&gt;&lt;BR&gt;US-CERT encourages users and administrators to take the following measures to protect themselves from these types of phishing scams and malware campaigns:&lt;BR&gt;
&lt;UL&gt;
&lt;LI&gt;Do not follow unsolicited web links in email messages. 
&lt;LI&gt;Maintain up-to-date antivirus software. 
&lt;LI&gt;Refer to the &lt;A href="http://www.irs.gov/privacy/article/0,,id=179820,00.html?portlet=5" target=_self&gt;IRS website&lt;/A&gt; related to phishing, email, and bogus website scams for scam samples and reporting information. 
&lt;LI&gt;Refer to the &lt;A href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target=_self&gt;Recognizing and Avoiding Email Scams&lt;/A&gt; (pdf) document for more information on avoiding email scams. 
&lt;LI&gt;Refer to the &lt;A href="http://www.us-cert.gov/cas/tips/ST04-014.html" target=_self&gt;Avoiding Social Engineering and Phishing Attacks&lt;/A&gt; document for more information on social engineering attacks. 
&lt;LI&gt;Forward suspected phishing emails to &lt;A href="mailto:phishing@irs.gov"&gt;phishing@irs.gov&lt;/A&gt;.&lt;BR&gt;&lt;/LI&gt;&lt;/UL&gt;
  </content>
</entry>
<entry>
<title>Microsoft Releases Advance Notification for February Security Bulletin</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#microsoft_releases_advanced_notification_for6"/>
<id>http://www.us-cert.gov/current/index.html#microsoft_releases_advanced_notification_for6</id>
<published>2012-02-09T16:06:17-05:00</published>
<updated>2012-02-09T16:06:17-05:00</updated>
<content type="html">          




Microsoft has issued a &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb" target="_self"&gt;Security Bulletin Advance Notification&lt;/a&gt; indicating that its February releases will contain nine bulletins. These bulletins will have the severity rating of critical and important and will be for Microsoft Windows, Internet Explorer, Microsoft Silverlight, Microsoft Server Software, Microsoft Office, and Microsoft .NET Framework. These bulletins are scheduled to be released on Tuesday, February 14, 2012.&lt;br&gt;&lt;br&gt;US-CERT will provide additional information as it becomes available. &lt;br&gt;










  </content>
</entry>
<entry>
<title>Google Releases Chrome 17.0.963.46</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#google_releases_chrome_17_0"/>
<id>http://www.us-cert.gov/current/index.html#google_releases_chrome_17_0</id>
<published>2012-02-08T15:16:54-05:00</published>
<updated>2012-02-08T15:16:54-05:00</updated>
<content type="html">          

Google has released Chrome 17.0.963.46 for Linux, Mac, Windows, and Google Chrome Frame to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code and cause a denial-of-service condition. &lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review the Google Chrome Release &lt;a href="http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+GoogleChromeReleases+%28Google+Chrome+Releases%29&amp;amp;utm_content=FeedBurner" target="_self"&gt;blog entry&lt;/a&gt; and update to Chrome 17.0.963.46.&lt;br&gt;




  </content>
</entry>
<entry>
<title>Apple Releases Multiple Security Updates</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#apple_releases_multiple_security_updates1"/>
<id>http://www.us-cert.gov/current/index.html#apple_releases_multiple_security_updates1</id>
<published>2012-02-02T12:15:36-05:00</published>
<updated>2012-02-02T12:15:36-05:00</updated>
<content type="html">          





Apple has released security updates for Apple OS X Lion 10.7 to 10.7.2, OS X Lion Server 10.7 to 10.7.2, Mac OS 10.6.8, and Mac OS X Server v 10.6.8 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, and bypass security restrictions.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review &lt;a href="http://support.apple.com/kb/HT5130" target="_self"&gt;Apple Support Article HT5130&lt;/a&gt; and apply any necessary updates to help mitigate the risks.&lt;br&gt;&lt;br&gt;Additional information regarding CVE-2011-3449 can be found in US-CERT Vulnerability Note &lt;a href="http://www.kb.cert.org/vuls/id/410281" target="_self"&gt;VU#410281&lt;/a&gt;.&lt;br&gt;&lt;br&gt;Additional information regarding CVE-2011-3446 can be found in US-CERT Vulnerability Note &lt;a href="http://www.kb.cert.org/vuls/id/403593" target="_self"&gt;VU#403593&lt;/a&gt;.&lt;a href="http://www.kb.cert.org/vuls/id/403593" target="_self"&gt;&lt;/a&gt;












  </content>
</entry>
<entry>
<title>Mozilla Releases Firefox 10 and 3.6.26</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_10_and"/>
<id>http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_10_and</id>
<published>2012-02-01T09:50:28-05:00</published>
<updated>2012-02-01T09:50:28-05:00</updated>
<content type="html">          

The Mozilla Foundation has released Firefox 10 and Firefox 3.6.26 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or perform a cross-site scripting attack.&lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review the Mozilla Foundation Advisories for &lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox.html#firefox10" target="_self"&gt;Firefox 10&lt;/a&gt; and &lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox36.html" target="_self"&gt;Firefox 3.6.26&lt;/a&gt; and apply any necessary updates to help mitigate the risk. &lt;br&gt;




  </content>
</entry>
<entry>
<title>Denial-of-Service Malware Campaign</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#anonymous_activities"/>
<id>http://www.us-cert.gov/current/index.html#anonymous_activities</id>
<published>2012-01-24T17:35:42-05:00</published>
<updated>2012-01-24T17:35:42-05:00</updated>
<content type="html">          US-CERT is aware of public reports of ongoing distributed denial-of-service attacks against&amp;nbsp;entities in the government and private sector. According to the reports, these attacks are being attributed to the hacker group Anonymous.&lt;BR&gt;&lt;BR&gt;US-CERT encourages users and administrators to do the following to reduce the risk associated with this and other malware campaigns: &lt;BR&gt;
&lt;UL&gt;
&lt;LI&gt;Do not open attachments in email messages from unknown sources. 
&lt;LI&gt;Install anti-virus software and keep virus signatures files up to date. 
&lt;LI&gt;Refer to the &lt;A href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target=_self&gt;Recognizing and Avoiding Email Scams&lt;/A&gt; (pdf) document for more information on avoiding email scams. 
&lt;LI&gt;Refer to the &lt;A href="http://www.us-cert.gov/cas/tips/ST04-014.html" target=_self&gt;Avoiding Social Engineering and Phishing Attacks&lt;/A&gt; document for information on social engineering attacks.&amp;nbsp; 
&lt;LI&gt;Refer to the&amp;nbsp;&lt;A href="http://www.us-cert.gov/cas/tips/ST05-006.html" target=_self&gt;Recovering from Viruses, Worms, and Trojan Horses&lt;/A&gt; document for additional information on how to recover from malware.&amp;nbsp; 
&lt;LI&gt;Refer to the &lt;A href="http://www.us-cert.gov/reading_room/DNS-recursion033006.pdf" target=_self&gt;Continuing Denial of Service Threats Posed by DNS recursion (v2.0)&lt;/A&gt; (pdf) document&amp;nbsp;and&amp;nbsp;&lt;A href="http://www.us-cert.gov/cas/tips/ST04-015.html" target=_self&gt;Understanding Denial-of-Service Attacks&lt;/A&gt;&amp;nbsp;document for additional information on denial-of-service attacks.&lt;/LI&gt;&lt;/UL&gt;US-CERT will provide additional information as it becomes available. &lt;BR&gt;
  </content>
</entry>
<entry>
<title>Google Releases Chrome 16.0.912.77</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#google_releases_chrome_16_02"/>
<id>http://www.us-cert.gov/current/index.html#google_releases_chrome_16_02</id>
<published>2012-01-24T13:03:34-05:00</published>
<updated>2012-01-24T13:03:34-05:00</updated>
<content type="html">          

Google has released Chrome 16.0.912.77 for Linux, Mac, Windows, and Chrome Frame to address multiple vulnerabilities.&amp;nbsp;These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition. &lt;br&gt;&lt;br&gt;US-CERT encourages users and administrators to review the Google Chrome Release &lt;a href="http://googlechromereleases.blogspot.com/2012/01/stable-channel-update_23.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+GoogleChromeReleases+%28Google+Chrome+Releases%29&amp;amp;utm_content=FeedBurner" target="_self"&gt;blog entry&lt;/a&gt; and update to Chrome 16.0.912.77&lt;br&gt;




  </content>
</entry>
<entry>
<title>Symantec pcAnywhere Hotfix</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#symantec_pcanywhere_hotfix"/>
<id>http://www.us-cert.gov/current/index.html#symantec_pcanywhere_hotfix</id>
<published>2012-01-24T11:30:37-05:00</published>
<updated>2012-01-24T11:30:37-05:00</updated>
<content type="html">          


Symantec has released an update for pcAnywhere to address multiple vulnerabilities for the following software versions running on Windows:&lt;br&gt;&lt;ul&gt;&lt;li&gt;pcAnywhere 12.5 SP3&lt;/li&gt;&lt;li&gt;pcAnywhere Solutions 7.1 GA, SP 1, and SP 2&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;US-CERT encourages users and administrators to review the &lt;a href="http://clientui-kb.symantec.com/kb/index?page=content&amp;amp;pmv=print&amp;amp;impressions=&amp;amp;viewlocale=&amp;amp;id=TECH179526" target="_self"&gt;Symantec pcAnywhere hot fix&lt;/a&gt; and apply any necessary updates to help mitigate the risk. &lt;br&gt;&lt;/p&gt;US-CERT will provide additional information as it becomes available. &lt;br&gt;






  </content>
</entry>
<entry>
<title>Best Practices for Recovery from the Malicious Erasure of Files</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#best_practices_for_recovery_from"/>
<id>http://www.us-cert.gov/current/index.html#best_practices_for_recovery_from</id>
<published>2012-01-19T16:12:18-05:00</published>
<updated>2012-01-20T09:49:53-05:00</updated>
<content type="html">          























There are many ways in which cyber criminals can damage computer systems and data, including changing or deleting files, wiping hard drives, and erasing backups to hide their malicious activity. &lt;br&gt;&lt;br&gt;Hard drives are wiped, or "zeroed out," when the original data is overwritten with zeros or different characters. This allows malicious actors to alter or even erase existing data. In addition to impeding the restoration of the original data, this type of criminal activity makes it difficult to determine whether criminals merely accessed the network, stole information, or altered network access and configuration files. Restoring networks and assessing the damage to a business can be hindered when the full extent of malicious activity is unclear. &lt;br&gt;&lt;br&gt;DHS and the FBI encourage businesses and individuals to employ mitigation strategies and best practices to effectively recover maliciously erased files, such as:&lt;br&gt;&lt;ul&gt;&lt;li&gt;Implementing a data backup and recovery plan. A copy of the sensitive data should be kept in a separate and secure location. Make sure this backup copy is not readily accessible from local networks. &lt;br&gt;&lt;/li&gt;&lt;li&gt;Regularly mirroring and maintaining an image of critical system files.&lt;/li&gt;&lt;li&gt;Encrypting and securing sensitive information.&lt;/li&gt;&lt;li&gt;Using strong passwords, implementing a frequent schedule for changing passwords, and making sure passwords are not reused for multiple accounts. &lt;br&gt;&lt;/li&gt;&lt;li&gt;Enabling network monitoring and logging (when feasible).&lt;/li&gt;&lt;li&gt;Being on guard against social engineering tactics aimed at obtaining sensitive information, such as phishing. &lt;br&gt;&lt;/li&gt;&lt;li&gt;Ensuring that sensitive files are securely eliminated from hard drives when no longer needed or required. &lt;br&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;There are many resources available on the US-CERT website to protect users from this type of malicious activity, including these suggested readings from the National Cyber Alert System:&lt;br&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cyber Security Tip ST04-002: &lt;a href="http://www.us-cert.gov/cas/tips/ST04-002.html" target="_self"&gt;Choosing and protecting Passwords&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Cyber Security Tip ST04-014: &lt;a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self"&gt;Avoiding Social Engineering and Phishing Attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Cyber Security Tip ST05-011: &lt;a href="http://www.us-cert.gov/cas/tips/ST05-011.html" target="_self"&gt;Effectively Erasing Files&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;






































  </content>
</entry>
<entry>
<title>Oracle Releases Critical Patch Update for January 2012</title>
<link rel="alternate" type="text/html" hreflang="en" href="http://www.us-cert.gov/current/index.html#oracle_releases_critical_patch_update16"/>
<id>http://www.us-cert.gov/current/index.html#oracle_releases_critical_patch_update16</id>
<published>2012-01-18T10:58:17-05:00</published>
<updated>2012-01-18T10:58:17-05:00</updated>
<content type="html">          







Oracle has released its &lt;a href="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" target="_self"&gt;Critical Patch Update&lt;/a&gt; for January 2012 to address 78 vulnerabilities across multiple products. This update contains the following security fixes:&lt;br&gt;&lt;ul&gt;&lt;li&gt;2 for Oracle Database Server&lt;/li&gt;&lt;li&gt;1 for Oracle Fusion Middleware&lt;/li&gt;&lt;li&gt;3 for Oracle E-Business Suite&lt;br&gt;&lt;/li&gt;&lt;li&gt;1 for Oracle Supply Chain Products Suite&lt;/li&gt;&lt;li&gt;6 for Oracle PeopleSoft Products&lt;/li&gt;&lt;li&gt;8 for Oracle JD Edwards Products&lt;/li&gt;&lt;li&gt;17 for Oracle Sun Products Suite&lt;/li&gt;&lt;li&gt;3 for Oracle Virtualization&lt;/li&gt;&lt;li&gt;27 for Oracle MySQL&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;US-CERT encourages users and administrators to review the January 2012 &lt;a href="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" target="_self"&gt;Critical Patch Update&lt;/a&gt; and apply any necessary updates to help mitigate the risks. &lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information regarding CVE-2012-0110 can be found in US-CERT Vulnerability Note &lt;a href="http://www.kb.cert.org/vuls/id/738961" target="_self"&gt;VU#738961&lt;/a&gt;.&lt;/p&gt;










  </content>
</entry>
</feed>

