US-CERT Current Activity
The US-CERT Current Activity web page is a regularly updated summary
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
Last reviewed: June 5, 2010 11:32:37 EDT
Adobe Releases Security Advisory for Flash Player, Reader, and Acrobat
added June 5, 2010 at 10:28 am
Adobe has released a security advisory to notify users of a vulnerability in Adobe Flash Player, Reader, and Acrobat. Exploitation of this vulnerability may allow an attacker to execute arbitrary code and take control of the affected system. The advisory indicates that Adobe is aware of active exploitation of this vulnerability.
US-CERT encourages users and administrators to review Adobe security advisory APSA10-01 and apply any necessary workarounds until a fix is released by the vendor.
US-CERT will provide additional information as it becomes available.
Microsoft Releases Advance Notification for June Security Bulletin
added June 4, 2010 at 08:16 am
Microsoft has issued a Security Bulletin Advance Notification, indicating that its June release will contain ten bulletins. Three of these bulletins will have the severity rating of critical and will be for Microsoft Windows and Internet Explorer. The remaining bulletins will have the severity rating of important and will be for Microsoft Windows, Microsoft Office, and Microsoft Sharepoint Services. Release of these bulletins is scheduled for Tuesday, June 8, 2010.
US-CERT will provide additional information as it becomes available.
Cisco Network Building Manager Vulnerabilities
added May 27, 2010 at 07:57 am
Cisco has released a security advisory to address multiple vulnerabilities in Network Building Manager. The advisory indicates that the legacy Richards-Zeta Mediator products are also affected by these vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to operate with escalated privileges or obtain sensitive information.
US-CERT encourages users and administrators to review Cisco security advisory cisco-sa-20100526-mediator and apply any necessary updates to help mitigate the risks.
Google Releases Chrome 5.0.375.55
added May 26, 2010 at 08:16 am
Google has released Chrome 5.0.375.55 for Linux, Mac, and Windows to address multiple vulnerabilities. These vulnerabilities may allow an attacker to bypass security restrictions, execute script in an unsafe context, or mislead users.
US-CERT encourages users and administrators to review the Google Chrome Releases blog entry and update to Chrome 5.0.375.55 to help mitigate the risks.
Apple Releases Updates for Java Mac OS X 10.5 and 10.6
added May 19, 2010 at 08:56 am
Apple has released Java for Mac OS X 10.5 Update 7 and Java for Mac OS X 10.6 Update 2 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
US-CERT encourages users and administrators to review Apple Article HT4170 and HT4171 and apply any necessary updates to help mitigate the risks.
Cisco Releases Updates for PGW Softswitch
added May 13, 2010 at 08:18 am
Cisco has released updates to address multiple vulnerabilities in Cisco PGW Softswitch. These vulnerabilities may allow an attacker to cause a denial-of-service condition.
US-CERT encourages users and administrators to review Cisco security advisory cisco-sa-20100512-pgw and apply any necessary updates to help mitigate the risks.
Adobe Releases Update for Shockwave Player
added May 12, 2010 at 07:51 am
Adobe has released a security update to address multiple vulnerabilities in Adobe Shockwave Player 11.5.6.606 and earlier versions for both Windows and Macintosh operating systems. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code.
US-CERT encourages users and administrators to review Adobe security bulletin APSB10-12 and update to Adobe Shockwave Player 11.5.7.609 to help mitigate the risks.
Microsoft Releases May Security Bulletin
added May 11, 2010 at 01:29 pm
Microsoft has released updates to address vulnerabilities in Microsoft Windows, Office, and Visual Basic for Applications as part of the Microsoft Security Bulletin Summary for May 2010. These vulnerabilities may allow an attacker to execute arbitrary code.
US-CERT encourages users and administrators to review the bulletins and follow best-practice security policies to determine which updates should be applied.
Apple Safari Vulnerability
added May 10, 2010 at 10:57 am
US-CERT is aware of a vulnerability affecting Apple Safari. By convincing a user to open a specially crafted web page, an attacker may be able to execute arbitrary code. Exploit code for this vulnerability is publicly available.
US-CERT encourages users and administrators to disable JavaScript as detailed in the Securing Your Web Browser document until a fix is provided by the vendor. Additional information regarding this vulnerability can be found in the Vulnerability Notes Database.
US-CERT will provide additional information as it becomes available.
Microsoft Releases Advance Notification for May Security Bulletin
added May 7, 2010 at 08:38 am
Microsoft has issued a Security Bulletin Advance Notification, indicating that its May release cycle will contain two bulletins. Both of these bulletins will have the severity rating of critical and will be for Microsoft Windows, Office, and Visual Basic for Applications. Release of these bulletins is scheduled for Tuesday, May 11, 2010.
US-CERT will provide additional information as it becomes available.