Patch pre-notification from Adobe and Microsoft, (Fri, Jan 4th)
Tuesday will bring seven patches from Microsoft, as well as a set of fixes from Adobe to address critical vulnerabilities in Adobe Reader and Adobe Acrobat....
View Article"FixIt" Patch for CVE-2012-4792 Bypassed, (Fri, Jan 4th)
On the 1 Jan 2013, Johannes posted a diary on a Microsoft FixIt made available for IE as a way of mitigating the CVE-2012-4792 zero day attack. Researchers at Exodus Intelligence reported today they...
View ArticleAdobe ColdFusion Security Advisory, (Sat, Jan 5th)
Adobe released a security advisory which identifies three vulnerabilities (CVE-2013-0625, CVE-2013-0629, CVE-2013-0631) affecting ColdFusion for Windows, Macintosh and Unix. They have received reports...
View ArticleD-link Wireless-G Router Year Issue (Y2K-plus-13), (Sat, Jan 5th)
We have received a report from Melvin indicating that he discovered an issue with a D-Link WBR-1310 Version D Release 4.13 router expired when a computer could no longer get a new lease from the...
View ArticleA Bit About the NVIDIA Vulnerability, (Sun, Jan 6th)
Geoff writes in this morning asking for more eploration around the Nvidia vulnerability patch that was released yesterday....
View ArticleISC StormCast for Monday, January 7th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticlePlease consider participating in our 2013 ISC StormCast survey at...
Post suggestions or comments in the section below or send us any questions or comments in the contact form on https://isc.sans.edu/contact.html#contact-form -- Adam Swanger, Web Developer (GWEB,...
View ArticleSecurity Updates for Adobe Flash -...
=============== Rob VandenBrink Metafore (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMicrosoft January 2013 Black Tuesday Update - Overview, (Tue, Jan 8th)
Overview of the January 2013 Microsoft patches and their status. # Affected Contra Indications - KB Known Exploits Microsoft rating(**) ISC rating(*) clients servers MS13-001 Print Spooler Remote Code...
View ArticleThe 80's called - They Want Their Mainframe Back!, (Wed, Jan 9th)
When I see TCP Port 992 open, I always get a warm feeling Im taken back to my first IT job, as a night operator on MVS and VM systems at IBM in the early 80s. And yes, we had Virtual Machines (thats...
View ArticleNew Format for Monthly Threat Update, (Wed, Jan 9th)
Due to a scheduling conflict with another webcast, we had to cancle todays monthly threat update. However, we will use this opportunity to try something new. We had some complaints in the past with...
View ArticleSQL Injection Flaw in Ruby on Rails, (Wed, Jan 9th)
A SQL Injection Flaw (CVE-2012-5664) was announced last week (Jan 2) in Ruby on Rails, but I think we missed reporting on it (thanks to one of our readers for pointing this out). Updates that resolve...
View ArticleHotmail seeing some temporary access issues, (Wed, Jan 9th)
Thanks to our reader James for letting us know about some current (but temporary) system issues at Hotmail - details at https://status.live.com/detail/Hotmail UPDATE: As of now (10:30 on Jan 9),...
View ArticleSecurity Update - Cisco Prime LMS (cisco-sa-20130109-lms - remote execution...
=============== Rob VandenBrink Metafore (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleSecurity Update - Cisco 7900 Phones - cisco-sa-20130109-uipphone privilege...
=============== Rob VandenBrink Metafore (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Thursday, January 10th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleJanuary 2013 OUCH! - Java...
Post suggestions or comments in the section below or send us any questions or comments in the contact form on https://isc.sans.edu/contact.html#contact-form -- Adam Swanger, Web Developer (GWEB,...
View ArticleJava is still exploitable and is likely going to remain so., (Thu, Jan 10th)
We havent had an unpatched Java vulnerability in a while (a month?). To make up for this lack of Java exploitability, the creators of the Blackhole and Nuclear exploit pack included an exploit for a...
View ArticleWhat Else runs Telnets? Or, Pentesters Love Video Conferencing Units Too!,...
As a side note to todays iSeries / Mainframe story, and a follow-up to one I wrote last year (https://isc.sans.edu/diary/12103), another thing Im seeing is more and more on telnets (tcp port 992 -...
View ArticleISC StormCast for Friday, January 11th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article