Adobe Acrobat and Reader Vulnerability
National Cyber Alert System
Technical Cyber Security Alert TA09-051A
Systems Affected
* Adobe Reader version 9 and earlier
* Adobe Acrobat (Professional, 3D, and Standard) version 9 and earlier
Overview
Adobe has released Security Bulletin APSB09-01, which describes a vulnerability that affects Adobe Reader and Acrobat. This vulnerability could allow a remote attacker [...]
Active Exploitation of Microsoft Internet Explorer 7 Vulnerability
US-CERT is aware of a public report indicating active exploitation of a previously patched vulnerability in Microsoft Internet Explorer 7. This vulnerability was addressed in Microsoft Security Advisory MS09-002. Additional information is available in US-CERT Technical Cyber Security Alert TA09-041A.
US-CERT encourages users to apply the update or workarounds as specified in Microsoft Security Advisory MS09-002. [...]
Read More About - Active Exploitation of Microsoft Internet Explorer 7 Vulnerability »
Microsoft Updates for Multiple Vulnerabilities
Systems Affected:
* Microsoft Internet Explorer
* Microsoft Office Visio
* Microsoft Exchange and SQL Server
Overview
Microsoft has released updates that address vulnerabilities in Microsoft Windows and Windows Server.
I. Description
As part of the Microsoft Security Bulletin Summary for February 2009, Microsoft released updates to address vulnerabilities that affect Microsoft Windows, Internet Explorer, Exchange Server, SQL Server, Office, and other [...]
Read More About - Microsoft Updates for Multiple Vulnerabilities »
BlackBerry Security Advisory
Research In Motion has released a Security Advisory to address a vulnerability in the BlackBerry Application Web Loader ActiveX control. By convincing a user to view a specially crafted HTML document, an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause Internet Explorer to crash.
US-CERT [...]
IRS Stimulus Package Phishing Scam
US-CERT is aware of public reports indicating that phishing scams are circulating via fraudulent U.S. Internal Revenue Service emails offering users stimulus package payments. These emails include text that attempts to convince users to follow a link to a website or to complete an attached document. The website and document request the user to provide [...]
Google’s Latitude Tracks Your Every Move
Google has released a new application called Latitude. The service allows a user to share their physical location with friends and family. Using cell phones towers and WIFI connections, Google creates a map that shows your location and movements. Though they claim your privacy is protected, many people are concerned.
Here is how [...]
Read More About - Google’s Latitude Tracks Your Every Move »
Malicious Code Spreading Via Valentine’s Day Spam
US-CERT is aware of public reports of malicious code circulating via spam email messages related to Valentine’s Day. These messages contain a link to a website that contains several images of hearts and instructs users to choose one image. If users click on one of the images, they will be prompted to download an executable [...]
Read More About - Malicious Code Spreading Via Valentine’s Day Spam »
Before You Connect a New Computer to the Internet
by United States Emergency Readiness Team
I. Motivating Factors
The CERT/CC has composed this Tech Tip to address a growing risk to Internet users without dedicated IT support. In recent months, we have observed a trend toward exploitation of new or otherwise unprotected computers in increasingly shorter periods of time. This problem is exacerbated by a number [...]
Read More About - Before You Connect a New Computer to the Internet »
White House (.gov) Email Down Due to Microsoft
The new White House team found out there email systems were down for most of the day on Monday. Press Secretary Robert Gibbs mad the announcement of the technical difficulties at his 1:30 p.m. briefing. He apologized for the e-mail silence and blamed it on a Mircrosoft Outlook server.
Both incoming and outgoing email were [...]
Read More About - White House (.gov) Email Down Due to Microsoft »
Apple QuickTime Updates for Multiple Vulnerabilities
National Cyber Alert System
Technical Cyber Security Alert TA09-022A
Apple QuickTime Updates for Multiple Vulnerabilities
Original release date: January 22, 2009
Source: US-CERT
Systems Affected
Apple QuickTime 7.5 for Windows and Mac OS X
Overview
Apple has released QuickTime 7.6 to correct multiple vulnerabilities affecting QuickTime for Mac OS X and Windows. Attackers may be able to exploit these vulnerabilities to execute arbitrary [...]
Read More About - Apple QuickTime Updates for Multiple Vulnerabilities »