Current Activity Calendar
| May 22, 2008 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.IBM Lotus Sametime Vulnerabilityadded May 22, 2008 at 10:23 am
IBM has released a Technote to address a vulnerability in Lotus Sametime. This vulnerability is due to an error in the way long URLs are processed within the Community Services Multiplexer (StMux.exe). By sending a specially crafted URL, an attacker may be able to cause a stack-based buffer overflow and execute arbitrary code. Cisco Releases Security Advisoriesadded May 22, 2008 at 10:06 am
Cisco has released three security advisories to address multiple vulnerabilities in Cisco IOS Secure Shell, Service Control Engine, and Voice Portal. These vulnerabilities may allow an attacker to take control of the affected system or cause a denial-of-service condition.
CA ARCserve Backup Vulnerabilitiesadded May 20, 2008 at 09:32 am
CA has released updates to address two vulnerabilities in BrightStor ARCserve Backup. The first vulnerability is due to an input validation error within the logging service, "caloggerd." The second vulnerability is due to a buffer overflow conditions within multiple "xdr" functions. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code. Natural Disasters and Phishing Scamsadded May 19, 2008 at 07:22 pm
In the past, US-CERT has received reports of an increased number of phishing scams that take advantage of natural disasters. Due to recent natural disasters, US-CERT would like to remind users to remain cautious when receiving unsolicited email that could be a potential phishing scam.
United States Tax Court Spear-Phishing Attackadded May 15, 2008 at 03:15 pm
US-CERT is aware of public reports of a spear-phishing attack circulating via email messages that claim to be petitions from the US Tax Court. These messages appear to be legitimate because they may contain very specific information about the message recipient. The message requests that the user follow a link to download additional information about the petition, but if a user clicks on this link, malicious code may be installed on the system.
Debian and Ubuntu OpenSSL and OpenSSH Vulnerabilitiesadded May 15, 2008 at 08:38 am | updated May 15, 2008 at 11:02 am
Debian and Ubuntu have released multiple security advisories to address vulnerabilities in their OpenSSL package and other cryptographic application packages that rely on it. These vulnerabilities are due to weaknesses in the random number generator that is used to create SSL and SSH cryptographic keys. As a result of the vulnerability, the keys generated using the flawed OpenSSL package may be weak. Exploitation of these vulnerabilities may allow a remote, unauthenticated attacker to conduct brute force attacks and obtain sensitive information. These vulnerabilities may affect any Debian-based systems, such as Ubuntu, and may indirectly affect other systems if these weak keys have been imported into them.
US-CERT will provide more information as it becomes available. Cisco Releases Security Advisoriesadded May 14, 2008 at 12:45 pm
Cisco has released three security advisories to address vulnerabilities in Cisco Unified Communications Manager, Unified Presence, and the Content Switching Module. These vulnerabilities may allow an attacker to cause a denial-of-service condition on the affected system.
Microsoft Releases May Security Bulletinadded May 13, 2008 at 01:51 pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows, Office, Live OneCare, Antigen, Windows Defender, and Forefront Security as part of the Microsoft Security Bulletin Summary for May 2008. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition. Mozilla Releases Thunderbird 2.0.0.14added May 9, 2008 at 09:11 am
Mozilla has released Thunderbird 2.0.0.14 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to escalate privileges or execute arbitrary code. Microsoft Releases Advance Notification for May Security Bulletinadded May 8, 2008 at 03:06 pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its May release cycle will contain four bulletins, three of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows and Office. The notification also states that there will be one Important bulletin for Windows Live OneCare, Antigen, Defender, and Forefront Security. Release of these bulletins is scheduled for Tuesday, May 12. |
|||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
