CERT Activity

Syndicate content
The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Copyright 2008 Carnegie Mellon University
Updated: 29 min 55 sec ago

Adobe Releases Update for AIR

Tue, 11/18/2008 - 1:03pm
Adobe has released a security bulletin to address a vulnerability in Adobe AIR. This vulnerability can be triggered if an Adobe AIR application loads data from an untrusted source. Exploitation of this vulnerability may allow a remote attacker to execute JavaScript code with elevated privileges.

US-CERT encourages users to review Adobe Security Bulletin APSB08-23 and upgrade to Adobe AIR 1.5 to help mitigate the risks.
Categories: Security

Apple Releases Security Updates for Safari

Fri, 11/14/2008 - 1:53pm
Apple has released Safari 3.2 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or obtain sensitive information.

US-CERT encourages users to review Apple Article HT3298 and apply any necessary updates.
Categories: Security

U.S. Federal Reserve Fraudulent Email Scam

Fri, 11/14/2008 - 12:04am
US-CERT is aware of public reports of a fraudulent email scam circulating via messages that falsely appear to be from the U.S. Federal Reserve. These email messages contain information about a phishing scam and links for users to follow to obtain additional information about the scam. If a user follows the links, they will be redirected to a malicious website where a PDF exploit is used to install malicious code on the affected system.

US-CERT encourages users to do the following to help mitigate the risks:
Categories: Security

Mozilla Releases Updates to Address Vulnerabilities in Multiple Products

Thu, 11/13/2008 - 1:34pm
Mozilla has released Firefox 2.0.0.18, Firefox 3.0.4, and SeaMonkey 1.1.13 to address multiple vulnerabilities. The impacts of these vulnerabilities include arbitrary code execution, privilege escalation, security bypass, cross-site scripting, denial of service, and information disclosure. As described in the Mozilla Foundation security advisories, some of these vulnerabilities may also affect Thunderbird.

US-CERT encourages users to review the Mozilla Foundation security advisories and apply any necessary updates to help mitigate the risks.
Categories: Security

Apple Releases iLife Support 8.3.1

Wed, 11/12/2008 - 1:36pm
Apple has released iLife Support 8.3.1 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

US-CERT encourages users to review Apple Article HT3276 and apply any necessary updates to help mitigate the risks.
Categories: Security

Microsoft Releases November Security Bulletin

Tue, 11/11/2008 - 6:45pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows as part of the Microsoft Security Bulletin Summary for November 2008. These vulnerabilities could allow an attacker to execute arbitrary code.

US-CERT encourages users and administrators to review the bulletins and follow best-practice security policies to determine which updates should be applied.
Categories: Security

VMware Releases Security Advisory VMSA-2008-0018 and Updates VMSA-2008-0016.1

Mon, 11/10/2008 - 2:03pm
VMware has released Security Advisory VMSA-2008-0018 and has updated Security Advisory VMSA-2008-0016.1 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to conduct directory traversal attacks, operate with escalated privileges, or obtain sensitive information.

US-CERT encourages users and administrators to review VMware Security Advisories VMSA-2008-0018 and VMSA-2008-0016.1 and apply any necessary updates to help mitigate the risks.
Categories: Security

Adobe Reader Exploit Circulating

Fri, 11/07/2008 - 8:19pm
US-CERT is aware of public reports of active exploitation of a recent Adobe Reader vulnerability. This exploit appears to arrive in the form of a maliciously crafted PDF file and leverages the JavaScript buffer overflow vulnerability addressed in Adobe Security Bulletin APSB08-19. Successful exploitation may allow an attacker to execute arbitrary code or cause a denial-of-service condition. Additionally, the reports indicate that this exploit is currently undetectable by common antivirus applications.

US-CERT encourages users and administrators to do the following to help mitigate the risk:
  • Review Adobe Security Bulletin APS08-19 and update to Adobe Reader 9.
  • Use caution when opening untrusted files.
  • Install antivirus software and keep the virus signatures up to date.
Categories: Security

Microsoft Releases Advance Notification for November Security Bulletin

Fri, 11/07/2008 - 1:35pm
Microsoft has issued a Security Bulletin Advance Notification indicating that its November release cycle will contain two bulletins, one of which will have the severity rating of Critical. The notification states that this Critical bulletin is for Microsoft Windows and Office. There will also be one Important bulletin for Microsoft Windows. Release of these bulletins is scheduled for Tuesday,  November 11.

US-CERT will provide additional information as it becomes available.
Categories: Security

Torpig Trojan Horse Attack Activity

Thu, 11/06/2008 - 10:06pm
US-CERT is aware of public reports of a high volume of financial accounts compromised by the Torpig (also known as Sinowal or Anserin) Trojan horse. This Trojan horse uses HTML injection to add fields to web pages in order to convince users to provide additional user credentials or financial account information. Systems compromised by this Trojan horse are being used by attackers to obtain FTP credentials, email addresses, and digital certificates of the current user.

This Trojan horse uses an MBR rootkit known as Mebroot. This rootkit contains configuration information for the Trojan horse as well as techniques used to keep the Trojan horse undetectable.

US-CERT encourages users to do the following preventative measures to mitigate the security risks:
  • Install antivirus software, and keep the virus signatures up to date.
  • Investigate anomalous or slow-running machines, looking for unknown processes or unexpected Internet connections as this may be a sign of malicious programs operating in the background.
  • Examine firewall logs of systems for connections to or from anomalous IP addresses.
  • Consider traffic analysis to identify compromised systems that are exfiltrating data.
Categories: Security

Adobe Releases Security Bulletin to Address Flash Player Vulnerabilities

Thu, 11/06/2008 - 3:31pm
Adobe has released a Security Bulletin to address multiple vulnerabilities in Flash Player. These vulnerabilities may allow an attacker to bypass security restrictions or obtain sensitive information.

US-CERT encourages users and administrators to review Adobe Security Bulletin APSB08-20 and update to Flash Player version 10.0.12.36 to help mitigate the risks.
Categories: Security

United States Presidential Election Email Attack

Thu, 11/06/2008 - 2:26pm
US-CERT is aware of public reports of email attacks circulating that are related to the recent U.S. presidential election. The email messages appear to be coming from a seemingly legitimate source and contain a message indicating that additional news coverage of the election is available by following a link. The link directs users to a website that appears to contain a video of the president elect. The website will instruct the user to update to a new version of Adobe Flash Player in order to view the video. This update is not a legitimate Adobe Flash Player update; it is malicious code. If the user downloads this executable file, malicious code may be installed on the system.

US-CERT encourages users to take the following preventative measures to mitigate the security risks:
  • Install antivirus software, and keep the virus signatures up to date.
  • Do not follow unsolicited links.
  • Use caution when visiting untrusted websites.
  • Use caution when downloading and installing applications.
  • Obtain software applications and updates directly from the vendor's website.
  • Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
  • Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.
Categories: Security

Adobe Releases Security Bulletin

Tue, 11/04/2008 - 7:03pm
Adobe has released a Security Bulletin to address multiple vulnerabilities in Adobe Reader 8 and Acrobat 8. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

US-CERT encourages users and administrators to review Adobe Security Bulletin APSB08-19 and apply the solution provided in that document to help mitigate the risks.

Additional information and workarounds regarding these vulnerabilities can be found in the Vulnerability Notes Database.
Categories: Security

Sprint Nextel - Cogent Communications Depeering Issue

Mon, 11/03/2008 - 11:27pm
On October 30, 2008, Sprint Nextel severed its peering relationship with Cogent Communications due to a contractual dispute. A temporary repeering between the two providers occurred on November 2, 2008. Please note that this repeering is only temporary and outstanding issues between Sprint Nextel and Cogent Communications still need to be addressed.

As best practice, Internet Service Provider (ISP) diversity is recommended as stated in the NIST Special Publication 800-053A "Guide for Assessing the Security Controls in Federal Information Systems" Section CP-8. Organizations should ensure that critical mission/business functions are available through alternate telecommunications services if their primary service provider is unavailable.

For the latest information from Sprint Nextel and Cogent Communications on this issue, please visit one of the following links:


Categories: Security

Worm Exploiting Microsoft MS08-067 Circulating

Mon, 11/03/2008 - 7:54pm
US-CERT is aware of public reports of a worm circulating that has the capability of exploiting the recently patched vulnerability described in Microsoft Security Bulletin MS08-067.

US-CERT encourages users to do the following to help mitigate the risks:
  • Review Microsoft Security Bulletin MS08-067 and apply the update or workarounds listed.
  • Install antivirus software, and keep the virus signatures up to date.
US-CERT will provide additional information as it becomes available.

Categories: Security

Adobe Releases Security Advisory for PageMaker 7

Fri, 10/31/2008 - 1:31pm
Adobe has released a Security Advisory to address vulnerabilities in PageMaker 7.0.1 and 7.0.2. These vulnerabilities may allow an attacker to execute arbitrary code.

US-CERT encourages users and administrators to review Adobe's Security Advisory ASPA08-10 and apply any necessary updates to help mitigate the risks. Note that the Adobe Security Advisory indicates that an additional vulnerability remains unaddressed by the update.
Categories: Security

VMware Releases Security Advisory VMSA-2008-0017

Fri, 10/31/2008 - 1:00pm
VMware has released a Security Advisory indicating it has updated the ESX packages to address vulnerabilities in libxml2, ucd-snmp, and libtiff. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, spoof authenticated SNMPv3 packets, or cause a denial-of-service condition.

US-CERT encourages users and administrators to review VMware Security Advisory VMSA-2008-0017 and apply any necessary updates to help mitigate the risks.
Categories: Security

OpenOffice.org Releases Two Security Bulletins

Wed, 10/29/2008 - 3:38pm
OpenOffice.org has released bulletins to address two vulnerabilities. These bulletins address heap-based buffer overflow vulnerabilities in the processing of WMF and EMF files. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code.

US-CERT encourages users and administrators to review the following OpenOffice.org security bulletins and apply the resolutions provided by the vendor:
Categories: Security

Microsoft Releases Security Advisory 958963

Tue, 10/28/2008 - 12:16am
Microsoft has released Security Advisory 958963 to alert users that exploit code is publicly available for the Windows Server Service vulnerability addressed in Microsoft Security Bulletin MS08-067. The advisory states that this exploit code has demonstrated arbitrary code execution on Windows 2000, XP and Server 2003.

US-CERT encourages users and administrators to review Microsoft Security Advisory 958963 and apply the update or workarounds listed in Microsoft Security Bulletin MS08-067 to help mitigate the risks.

Additional information regarding the Windows Server Service vulnerability is available in:
Categories: Security

Microsoft Releases Out-of-Band Security Bulletin MS08-067

Thu, 10/23/2008 - 5:08pm
Update: The Microsoft Security Response Center (MSRC) has posted a blog entry to provide additional information regarding the status of this vulnerability and the state of security update deployments. Users and administrators are encouraged to review the blog entry as it provides information about known malicious code targeting this vulnerability.

Microsoft has released Security Bulletin MS08-067 to address a vulnerability in the Windows Server Service. This vulnerability is due to improper handling of specially crafted RPC requests. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.

US-CERT encourages users and administrators to review Microsoft Security Bulletin MS08-067 and apply any necessary updates to help mitigate the risks. Additional information is also available in Vulnerability Note VU#827267.
Categories: Security