December 10th, 2009 . by DarkFiber Consulting
Adobe has released a security bulletin to address multiple vulnerabilities in Adobe Flash Player 10.0.32.18 and earlier and Adobe AIR1.5.2 and earlier. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or obtain sensitive information.
DarkFiber Consulting encourages users and administrators to review Adobe security bulletin APSB09-19 and update to Adobe Flash Player 10.0.42.34 and Adobe AIR 1.5.3.
Posted in Security Alerts | No Comments »
Tagged With: Address • Adobe 5 • Adobe Flash Player • Adobe Flash Player 10 • Adobe Updates • Air 1 • Air1 • Arbitrary Code • Attacker • Denial Of Service • Flash 32 • Flash Player 10 • Security Bulletin • Security Updates • Vulnerabilities
December 10th, 2009 . by DarkFiber Consulting
Microsoft has released an update to address vulnerabilities in Microsoft Windows and Office as part of the Microsoft Security Bulletin Summary for December 2009. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review the bulletins and follow best-practice security policies to determine which updates should be applied.
Posted in Security Alerts | No Comments »
Tagged With: Address • Arbitrary Code • Attacker • Bulletins • Denial Of Service • Microsoft • Microsoft Office • Microsoft Security Bulletin • Microsoft Windows • Security Policies • Vulnerabilities
December 10th, 2009 . by DarkFiber Consulting
Sun has released update 17 for Java SE JDK 6 and Java SE JRE 6 to address multiple vulnerabilities. The impacts of these vulnerabilities include arbitrary code execution, privilege escalation, denial of service, and information disclosure.
DarkFiber Consulting encourages users and administrators to review the Java SE 6 Update 17 release notes and apply any necessary updates to help mitigate the risks.
Apple has released Java for Mac OS X 10.6 Update 1 and Java for Mac OS X 10.5 Update 6 to address these vulnerabilities. Mac users are encouraged to review Apple articles HT3969 and HT3970 and apply any necessary updates to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Apple Mac • Apple Os • Arbitrary Code Execution • Denial Of Service • Escalation • Information Disclosure • Java Jdk • Java Mac • Java Notes • Java Os • Java Sun • Java Update • Jdk 6 • Mac Os X • Mac Users • Necessary Updates • Os X • Privilege • Sun Java • Sun Releases
December 10th, 2009 . by DarkFiber Consulting
Microsoft has issued a Security Bulletin Advance Notification indicating that its December release cycle will contain six bulletins, three of which will have a severity rating of Critical. The notification states that these Critical bulletins are for Microsoft Windows, Microsoft Office, and Internet Explorer. There will also be three important bulletins for Microsoft Windows and Microsoft Office. Release of these bulletins is scheduled for Tuesday, December 8.
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Advance Notification • Amp Nbsp • Bulletins • December 8 • Internet Explorer • Microsoft • Microsoft Internet • Microsoft Office • Microsoft Security • Microsoft Windows • Security Bulletin • Severity Rating • Windows Microsoft
December 10th, 2009 . by DarkFiber Consulting
DarkFiber Consulting is aware of public reports of a malware campaign circulating. This campaign is circulating via email messages offering information regarding the H1N1 vaccination. This email messages contain a link to a bogus Centers for Disease Control and Prevention website. Users who click on this link may become infected with malware. Public reports indicate that these email messages are noted as having subject lines such as: “Governmental registration program on the H1N1 vaccination” and “Your personal vaccination profile.” Please note that subject lines may change at any time.
DarkFiber Consulting encourages users to take the following precautions to help mitigate the risks:
- Install antivirus software, and keep the signature files up to date.
- Do not follow unsolicited links and do not open unsolicited email messages.
- Use caution when visiting untrusted websites.
- Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
- Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on avoiding social engineering attacks.
Posted in Security Alerts | No Comments »
Tagged With: Caution • Centers For Disease Control • Centers For Disease Control And Prevention • Disease Control And Prevention • Email Messages • Email Scams • Phishing Attacks • Prevention Website • Registration Program • Signature • Social Engineering • Subject Lines • Unsolicited Email • Untrusted • Vaccination
December 10th, 2009 . by DarkFiber Consulting
Research In Motion has released a security advisory to address multiple vulnerabilities in the PDF distiller of some released versions of the BlackBerry Attachment Service. The advisory lists the affected versions as BlackBerry Enterprise Server 5.0.0 running on Microsoft Windows version 2003 or 2008, BlackBerry Enterprise Server 5.0.0 running on Microsoft Windows 2000, BlackBerry Enterprise Server software versions 4.1.3 through 4.1.7, and BlackBerry Professional Software 4.1.4. By convincing a user to view a specially crafted PDF file, an attacker may be able to execute arbitrary code or cause a denial-of-service condition on the system that hosts the BlackBerry Attachment Service.
DarkFiber Consulting encourages users and administrators to review BlackBerry security advisory KB19860 and apply any necessary updates.
Posted in Security Alerts | No Comments »
Tagged With: Amp Nbsp • Arbitrary Code • Attacker • Blackberry Server • Blackberry Software • Denial Of Service • Enterprise Server Software • Microsoft • Microsoft 2000 • Microsoft Server • Microsoft Software • Microsoft Windows 2000 • Microsoft Windows Version • Necessary Updates • Pdf Distiller • Pdf File • Professional Software • Research In Motion • Software Versions • Windows 2000
December 10th, 2009 . by DarkFiber Consulting
DarkFiber Consulting is aware of public reports of malicious code circulating via phishing email messages that appear to come from the Social Security Administration. The messages indicate that the users’ annual Social Security statements may contain errors and instruct users to follow a link to review their Social Security statement. If users click this link, they will be redirected to a seemingly legitimate website that prompts them for their Social Security number. If users enter their Social Security number and continue to the next page, they will be given an option to generate a statement. If users attempt to generate a statement, malicious code may be installed on their systems. This malicious code attempts to collect online banking traffic to gain access to the users’ bank accounts.
DarkFiber Consulting encourages users and administrators to take the following preventative measures to help mitigate the security risks:
- Install antivirus software, and keep the virus signatures up to date.
- Do not follow unsolicited links and do not open unsolicited email messages.
- Use caution when visiting untrusted websites.
- Use caution when entering personal information online.
- Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
- Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Bank Accounts • Caution • Email Messages • Email Scams • Malicious Code • Phishing Attacks • Preventative Measures • Security Consulting • Security Risks • Social Engineering • Social Security • Social Security Administration • Social Security Number • Social Security Statement • Social Security Statements • Traffic • Unsolicited Email • Virus Signatures
December 10th, 2009 . by DarkFiber Consulting
Microsoft has released security advisory 977981 to address a vulnerability in Microsoft Internet Explorer. This vulnerability may allow an attacker to execute arbitrary code.
DarkFiber Consulting encourages users and administrators to review Microsoft Security Advisory 977981 and implement the suggested workarounds listed in the advisory to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Address • Amp Nbsp • Arbitrary Code • Attacker • Internet Explorer • Microsoft • Microsoft Explorer • Microsoft Internet • Microsoft Releases Security Advisory • Microsoft Security Advisory • Vulnerability • Workarounds
December 10th, 2009 . by DarkFiber Consulting
Microsoft has released security advisory 977544 to address a vulnerability in the Server Message Block (SMB) protocol. This vulnerability may allow an attacker to cause a denial-of-service condition. This vulnerability only affects Windows 7 and Server 2008 software.
DarkFiber Consulting encourages users and administrators to review Microsoft security advisory 977544 and apply the workarounds.
Posted in Security Alerts | No Comments »
Tagged With: Address • Attacker • Denial Of Service • Microsoft • Microsoft Releases Security Advisory • Microsoft Security Advisory • Protocol • Server Message Block • Vulnerability • Workarounds
December 10th, 2009 . by DarkFiber Consulting
DarkFiber Consulting is aware of reports of publicly available exploit code for a vulnerability within the SSL and TLS protocols. Reports indicate that exploitation of this vulnerability may allow an attacker to conduct a man-in-the-middle attack, allowing an attacker to inject plaintext into the beginning of the application protocol stream.
DarkFiber Consulting encourages OpenSSL users and administrators to review the OpenSSL 0.9.8l release and apply any updates.
DarkFiber Consulting has not received any reports of active exploitation and will continue to provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Application Protocol • Attacker • Exploit • Man In The Middle Attack • Protocol Stream • Protocols • Vulnerability