has been responding to security incidents and sharing vulnerability information since the Morris Worm hit in 1986. This archive combines their technical security alerts, bulletins, tips, and current activity lists.
Cyber Security Tip ST04-016 -- Recognizing and Avoiding Spyware
US-CERT Security Tips (Nov 19)
National Cyber Alert System
Cyber Security Tip ST04-016
Recognizing and Avoiding Spyware
Because of its popularity, the internet has become an ideal target for
advertising. As a result, spyware, or adware, has become increasingly
prevalent. When troubleshooting problems with your computer, you may
discover that the source of the problem is spyware software that has been
installed on your machine without your knowledge....
SB09-320 -- Vulnerability Summary for the Week of November 9, 2009
US-CERT Security Bulletins (Nov 16)
Vulnerability Summary for the Week of November 9, 2009
This bulletin provides a summary of new vulnerabilities that have been
recorded by the National Institute of Standards and Technology (NIST)
National Vulnerability Database (NVD) the week of November 9, 2009. It is
available here:
http://www.us-cert.gov/cas/bulletins/SB09-320.html
For instructions on subscribing to or unsubscribing from this
mailing list, visit <...
Current Activity - Microsoft Releases Security Advisory 977544
Current Activity (Nov 16)
US-CERT Current Activity
Microsoft Releases Security Advisory 977544
Original release date: November 16, 2009 at 9:21 am
Last revised: November 16, 2009 at 9:21 am
Microsoft has released security advisory 977544 to address a
vulnerability in the Server Message Block (SMB) protocol. This
vulnerability may allow an attacker to cause a denial-of-service
condition. This vulnerability only affects Windows 7 and Server 2008
software.
US-CERT...
Current Activity - Apple Releases Safari 4.0.4
Current Activity (Nov 12)
US-CERT Current Activity
Apple Releases Safari 4.0.4
Original release date: November 12, 2009 at 8:08 am
Last revised: November 12, 2009 at 8:08 am
Apple has released Safari 4.0.4 to address multiple vulnerabilities in
a number of components. Exploitation of these vulnerabilities may
allow an attacker to execute arbitrary code, cause a denial-of-service
condition, conduct cross-site request forgery, or obtain sensitive
information. These...
TA09-314A -- Microsoft Updates for Multiple Vulnerabilities
US-CERT Technical Alerts (Nov 10)
National Cyber Alert System
Technical Cyber Security Alert TA09-314A
Microsoft Updates for Multiple Vulnerabilities
Original release date:
Last revised: --
Source: US-CERT
Systems Affected
* Microsoft Windows and Windows Server
* Microsoft Office Word and Excel
Overview
Microsoft has released updates to address vulnerabilities in
Microsoft Windows and Windows Server and Office...
Current Activity - Microsoft Releases November Security Bulletin
Current Activity (Nov 10)
US-CERT Current Activity
Microsoft Releases November Security Bulletin
Original release date: November 10, 2009 at 1:50 pm
Last revised: November 10, 2009 at 1:50 pm
Microsoft has released an update to address vulnerabilities in
Microsoft Windows and Office as part of the Microsoft Security
Bulletin Summary for November 2009. These vulnerabilities may allow an
attacker to execute arbitrary code, cause a denial-of-service
condition, or operate...
Current Activity - Apple Releases Mac OS X v10.6.2 and Security Update 2009-006
Current Activity (Nov 10)
US-CERT Current Activity
Apple Releases Mac OS X v10.6.2 and Security Update 2009-006
Original release date: November 10, 2009 at 8:02 am
Last revised: November 10, 2009 at 8:02 am
Apple has released Mac OS X v10.6.2 and Security Update 2009-006 to
address multiple vulnerabilities in a number of applications. These
vulnerabilities may allow an attacker to execute arbitrary code, cause
a denial-of-service condition, conduct a man-in-the-middle...
SB09-313 -- Vulnerability Summary for the Week of November 2, 2009
US-CERT Security Bulletins (Nov 09)
Vulnerability Summary for the Week of November 2, 2009
This bulletin provides a summary of new vulnerabilities that have been
recorded by the National Institute of Standards and Technology (NIST)
National Vulnerability Database (NVD) the week of November 2, 2009. It is
available here:
http://www.us-cert.gov/cas/bulletins/SB09-313.html
For instructions on subscribing to or unsubscribing from this
mailing list, visit <...
Current Activity - SSL and TLS Vulnerable to Man-in-the-middle Attacks
Current Activity (Nov 06)
US-CERT Current Activity
SSL and TLS Vulnerable to Man-in-the-middle Attacks
Original release date: November 6, 2009 at 7:01 pm
Last revised: November 6, 2009 at 7:01 pm
US-CERT is aware of reports of publicly available exploit code for a
vulnerability within the SSL and TLS protocols. Reports indicate that
exploitation of this vulnerability may allow an attacker to conduct a
man-in-the-middle attack, allowing an attacker to inject plaintext...
Current Activity - Microsoft Releases Advance Notification for November Security Bulletin
Current Activity (Nov 05)
US-CERT Current Activity
Microsoft Releases Advance Notification for November Security Bulletin
Original release date: November 5, 2009 at 4:17 pm
Last revised: November 5, 2009 at 4:17 pm
Microsoft has issued a Security Bulletin Advance Notification
indicating that its November release cycle will contain six bulletins,
three of which will have a severity rating of Critical. The
notification states that these Critical bulletins are for...
Current Activity - BlackBerry Desktop Manager Vulnerability
Current Activity (Nov 05)
US-CERT Current Activity
BlackBerry Desktop Manager Vulnerability
Original release date: November 5, 2009 at 8:45 am
Last revised: November 5, 2009 at 8:45 am
Research in Motion has released Security Advisory KB19701 to address a
vulnerability in BlackBerry Desktop Manager. This vulnerability may
allow an attacker to execute arbitrary code.
US-CERT encourages users to review BlackBerry Security Advisory
KB19701 and apply any necessary...
Cyber Security Tip ST04-015 -- Understanding Denial-of-Service Attacks
US-CERT Security Tips (Nov 04)
Cyber Security Tip ST04-015
Understanding Denial-of-Service Attacks
You may have heard of denial-of-service attacks launched against websites,
but you can also be a victim of these attacks. Denial-of-service attacks can
be difficult to distinguish from common network activity, but there are some
indications that an attack is in progress.
What is a denial-of-service (DoS) attack?
In a...
Current Activity - Adobe Releases Update for Shockwave Player
Current Activity (Nov 04)
US-CERT Current Activity
Adobe Releases Update for Shockwave Player
Original release date: November 4, 2009 at 9:04 am
Last revised: November 4, 2009 at 9:04 am
Adobe has released Shockwave Player 11.5.2.602 to address multiple
vulnerabilities. Exploitation of these vulnerabilities may allow an
attacker to run malicious code on the user's machine.
US-CERT encourages users and administrators to review Adobe security
bulletin APSB09-16 and...
Current Activity - Sun Releases Update 17 for Java SE 6
Current Activity (Nov 04)
US-CERT Current Activity
Sun Releases Update 17 for Java SE 6
Original release date: November 4, 2009 at 9:04 am
Last revised: November 4, 2009 at 9:04 am
Sun has released update 17 for Java SE JDK 6 and Java SE JRE 6 to
address multiple vulnerabilities. The impacts of these vulnerabilities
include arbitrary code execution, privilege escalation, denial of
service, and information disclosure.
US-CERT encourages users and administrators to...
SB09-306 -- Vulnerability Summary for the Week of October 26, 2009
US-CERT Security Bulletins (Nov 02)
Vulnerability Summary for the Week of October 26, 2009
This bulletin provides a summary of new vulnerabilities that have been
recorded by the National Institute of Standards and Technology (NIST)
National Vulnerability Database (NVD) the week of October 26, 2009. It is
available here:
http://www.us-cert.gov/cas/bulletins/SB09-306.html
For instructions on subscribing to or unsubscribing from this
mailing list, visit <...