NIST Site Search
Google
Web NIST.org
NIST.gov
Product Research

Advertise on this site
Headlines

»Creative Software AutoUpdate Engine ActiveX stack buffer overflow
The Creative Software AutoUpdate Engine ActiveX control is a component that provides automatic updat ...
»Internet Connection Sharing DoS
A denial of service vulnerability exists within the Internet Connection Sharing service in Microsoft ...
»RPC Memory Exhaustion
The three referenced exploits take advantage of an inherent problem in RPC, in which an attacker get ...


Date published: Thu, 3 Jul 2008 20:41:00 PST
Details

»Forecast for July: Mostly sunny, 100% chance of spam
Spam volumes have been on the decline, but they are still double what they were at this time last ye ...
»Patch fixes antivirus glitch in XP
Hot fix for Windows XP Service Pack 3 "could resolve" a Windows registry corruption problem associat ...
»Report: IE is least-patched browser
More than 40 percent of Internet surfers don't use browsers with up-to-date securitypatches—and ...
»Data breaches up, but not in government sector
Reported data breaches increased sharply in 2008, but the percentage of breaches in the government s ...
»NIST revises IT security guides
The National Institute of Standards and Technology has released final revisions to three of its 800 ...
»William Jackson | The FISMA paradigm
Cybereye—commentary: Security policies remain a burden to federal IT managers, but they are pro ...
»Symantec compliance suite offers end-to-end automation
Control Compliance Suite 9.0 software is designed to help automate key IT governance, risk and compl ...
»Trust Digital mobile security meets DISA specs
Trust Digital 's smartphone security software client meets the latest updates to the Defense Informa ...


Date published: Thu, 03 Jul 2008 19:58:29 GMT
Details

»Microsoft Releases Advanced Notification for July Security Bulletin
»Mozilla Releases Firefox 2.0.0.15
»Apple Releases Security Updates
»Microsoft Releases Security Advisory
»Cisco Releases Security Advisory
»Microsoft Internet Explorer 6 Cross-Domain Vulnerability
»Microsoft Releases Security Advisory
»Adobe Releases Security Bulletin
»Critical Vulnerability in Microsoft Bluetooth Stack
»Apple Releases Safari v3.1.2 for Windows


Date published: not known
Details

»News: Web surfers, it's time to patch
Web surfers, it's time to patch
»News: Breach-notification laws not working?
Breach-notification laws not working?
»News: Ransomware resisting crypto cracking efforts
Ransomware resisting crypto cracking efforts

>> Advertisement <<
Can yo ...
»News: Boycott spotlights antivirus testing issues
Boycott spotlights antivirus testing issues
»Brief: Apple closes holes in Mac OS X, Safari
Apple closes holes in Mac OS X, Safari


Date published: not known
Details

»XSSFilter Released
You may have already seen the news about the new XSSFilter in IE8.0 but I wanted to echo it here as ...
»Searchable SWFs
I got forwarded this link today from businesswire about how Google and Yahoo are now going to be arm ...
»Blackhat Breach/OWASP/WASC Party
Notice how I’m always fashionably late to the party? Well anyway, this time is no different, ...
»Yahoo SEM Logic Flaw
In the wake of a few different speeches by Jeremiah Grossman and Billy Hoffman on logic flaws, I tho ...
»Allbots.info Imagetotext.com
If the title of this post sounds awfully spammy, that’s because it is. Someone sent me a link ...
»Flying Woes
I’m with Bruce Schneier. I never really spent enough time on airplanes to be particularly anno ...
»Key Point SMiShing
Yesterday, my gfnd got a SMiShing text to her phone against Key Point Credit Union. The obvious tip ...
»Lifelock CEO Gets Identity Stolen
I got sent this link today and I actually laughed out loud when I saw it - Todd Davis (CEO of LifeLo ...
»TJX Whistle Blower
I had some very disturbing news today from one of the forum users - he had just been fired by TJX fo ...
»Google Health
It must be a Wednesday because it’s feeling a lot like “pick on Google” day! Let& ...


Date published: not known
Details

»E-Government's Tough Nut
»Manna From Heaven
»Privacy, E-Discovery and Government
»Lax Security Not Just a U.S. Thing
»The Origin of the CIO
»Who Could Be Obama's Tech Czar?
»Government in a Wiki World, Part 6
»Most Companies Use Games; Shouldn't You?
»Real Security Leaders Don't Ignore Mission Security
»DISA's Conflict-of-Interest Quandary
»Government in a Wiki World: Part 5
»The Next Big Data Breach
»AFGE Reaches Young Voters Via MySpace, Facebook
»Busy British Hacker Fights Extradition to U.S.
»A Plan for the Next President -- Part 1


Date published: not known
Details

»S-331: Kernel Security and Bug Fix Update
There are updated kernel packages that fix various security issues and a bug that are available for ...
»S-330: Cisco Unified Communications Manager Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly Cisco CallManager, contains a denial of servic ...
»S-329: SBLIM Security Update
SBLIM stands for Standards-Based Linux Instrumentation for Manageability. It was discovered that cer ...
»S-328: FreeType Security Update
Multiple flaws were discovered in FreeType's Printer Font Binary (PFB) font-file format parser. The ...
»S-327: IBMJava2 Security Update
Several vulnerabilities were found in IBM Java 2 Runtime Environment and IBM Java 2 Software Develop ...
»S-326: Security Update for Adobe reader and Acrobat 8.1.2
A critical vulnerability has been identified in Adobe Reader and Acrobat 8.1.2. This vulnerability w ...
»S-325: xorg-server Vulnerabilities
Several local vulnerabilities have been discovered in the X Window system, this could lead to a part ...
»S-324: BackWeb Lite Install Runner ActiveX Vulnerabilities
The BackWeb Lite Install Runner ActiveX control contains multiple stack buffer overflows, which can ...
»S-323: Imlib2 Vulnerabilities
Two buffer overflow's were discovered in Imlib's - a powerful image loading and rendering library - ...
»S-322: Deterministic Network Enhancer Vulnerability
The Deterministic Network driver contains a privilege escalation vulnerability, which can allow a lo ...
»S-321: Novell iPrint Client ActiveX Vulnerabilities
The Novell iPrint Client ActiveX control contains multiple stack buffer overflows, which can allow a ...
»CIACTech08-003: Understanding Cross-Site Scripting (XSS)
Cross-Site Scripting has become an increasingly prevalent attack vector that can be leveraged to per ...
»CIACTech08-002: Understanding Windows Hash Dumpers and Crackers
Windows hash dumping tools are often spotlighted as hacker tools that can somehow magically extract ...
»CIACTech08-001: Understanding PHP Exploits
Many websites use the PHP programming language to build web pages on the fly from individual files a ...
»CIACTech07-001: MOICE - Microsoft Office Isolated Conversion Environment
A common cyber attack is to send a user an Office document (Word, Excel, PowerPoint) containing mal ...


Date published: not known
Details
Welcome to NIST.org
Welcome to NIST.org

Make NIST.org your morning IT Security wakeup call. Important security news is automatically added day and night, so you can see at a glance what threats you'll be facing. You'll find this information in the sidebars and in the Newsfeed section. Less time sensitive articles are posted below where topics are looked at more in-depth.

News articles are updated multiple times per day and the IT Security newsfeeds are automatically updated hourly (see main menu). Subscribe to this site's RSS Newsfeed to stay up to date on what's really important.

Be sure to Page Down to see current IT Security News on he sidebars or visit our Newsfeeds page for several more IT Security News sources. Now featuring security news headlines from eEye's Zero-day Tracker, GovExec.com, SecurityFocus, and Ha.ckers.org. Headlines link to the full stories.

  • Announcing: New Small Screen Security News - 'nist.org/m' [...more]

Registration to NIST.org is Free and removes this Welcome message, as well as some of the advertising [...more]
Firefox 3.0 Vulnerabilities, 2.0.x Also Vulnerable
Within hours after its release TippingPoint received a vulnerability that affects Firefox 3.0 and previous 2.0.x versions. The vulnerability allows and attacker to execute arbitrary code on the victims computer.

[ Read the rest of the article... ]
Posted by NIST.org on Saturday 21 June 2008 - 10:27:49 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Ransomware Will Win The War
The well respected Antivirus firm Kaspersky Lab is calling for a massive group effort to break the encryption used by the latest Ransomware. They're asking competitors, governments, and cryptographers to join the effort. But even a massive worldwide computer grid won't win this war.

[ Read the rest of the article... ]
Posted by NIST.org on Monday 16 June 2008 - 05:57:58 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
WordPress Sites Need To Upgrade, The Rest Of Us Need To Watch This Too.
A major security vulnerability has been discovered in the popular WordPress blogging software. The vulnerability may allow an attacker to bypass security restrictions. Being able to bypass security restrictions would allow someone the ability to post malicious code that could attack visitors to that site.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 01 May 2008 - 05:09:19 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
SQL Injections Continue – 100s of Thousands of URL's Infected
No one is sure of the number of server databases are infected but the guess is over 100,000. The Google searches are over 500,000 hits but many servers have more than one URL showing the infection.

[ Read the rest of the article... ]
Posted by NIST.org on Monday 28 April 2008 - 06:06:25 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Symantec Raises Threat Level Due To In The Wild Image File Exploits
Symantec has raised the Threatcon to Level 2 due to detection of an in the wild exploit of MS08-021 which allows remote code execution. FrSIRT ranks this as "Critical".

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 10 April 2008 - 20:28:48 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
SANS Internet Storm Center Starts Monthly Podcast
If you don't have the time or interest to read about the latest IT security news the SANS.org podcast or some of the other security podcasts might help you keep up.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 10 April 2008 - 17:04:25 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
FBI Reports Online Crime At All Time High
The U.S. FBI reports that online crime is at an all time high. So why are we hearing so little about it?

[ Read the rest of the article... ]
Posted by NIST.org on Monday 07 April 2008 - 05:51:39 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Symantec Antivirus ActiveX Vulnerability
Vulnerabilities have been discovered in an ActiveX control that ships with several Symantec products, including Norton AntiVirus, Norton Internet Security, Norton 360, and Norton SystemWorks.

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 06 April 2008 - 12:40:30 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
MS Excel "Extremely Critical" Vulnerability Allows Remote Code Execution
Microsoft has posted information about a new "Extremely Critical" zeroday vulnerability in MS Excel. This vulnerability effects most versions of Excel on both Windows and Mac OS X.

[ Read the rest of the article... ]
Posted by NIST.org on Friday 18 January 2008 - 06:05:59 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
RealPlayer Buffer Overflow Vulnerability – Highly Critical
If you haven't updated your users RealPlayer from October's RealPlayer playlist name stack buffer overflow now you have another one to worry about.

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 06 January 2008 - 16:55:51 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Highly Critical and Extremely Critical Vulnerabilities in Lotus Notes and Apple Quicktime
Lotus Notes R6.5.x through R8.x contains a Highly Critical vulnerability with its Lotus 123 viewer. Successful exploitation allows execution of arbitrary code. Apple Quicktime contains an Extremely Critical vulnerability that can be exploited via an email attachment or by visiting a malicious website.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 29 November 2007 - 04:35:47 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
New Phishing Scam Hitting Hard, No Clicks Required
A new method is being used to phish for credit card numbers that is fooling a lot more people. In this scam the user never has to figure out if a link is good or not because they never have to click on anything. Its all very familiar to them because they've done it before.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 15 November 2007 - 17:54:17 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
RealPlayer Extremely Critical Vulnerability
RealNetworks has released a fix for an Extremely Critical vulnerability. Successful exploitation, through a playlist file, allows execution of arbitrary code.

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 24 October 2007 - 20:48:14 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Transient Electromagnetic Devices (TEDs) Can Threaten Our IT Infrastructure
Many people recognize an old term – electromagnetic pulse or EMP. The ElectroMagnetic Pulse (EMP) effect was first observed during the early testing of high altitude airburst nuclear weapons. In the past EMP's generally required the use of a nuclear detonation. Today a destructive EMP can be produced without the use of a nuclear device. The development of Transient Electromagnetic Devices (TEDs) now makes the threat of an EMP attack much more likely.

[ Read the rest of the article... ]
Posted by NIST.org on Friday 12 October 2007 - 16:02:23 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Critical Vulnerability in Acrobat and Acrobat Reader can lead to Remote Code Execution
FrSIRT is reporting a Critical vulnerability in several Acrobat products that can be exploited to run arbitrary code. Basically opening a specially crafted PDF file can lead to an attacker running executable code of their choice on your computer. All versions 8.1 and prior are affected.

[ Read the rest of the article... ]
Posted by NIST.org on Monday 08 October 2007 - 18:47:13 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Has Your Webserver Been Compromised?
Unless you have lots of IT staff on-hand or really good monitoring you might not know for weeks that your public webserver has been compromised. Servers aren't always defaced or brought down. One thing that can help is to monitor your abuse@yourdomain.com email.

[ Read the rest of the article... ]
Posted by NIST.org on Tuesday 25 September 2007 - 15:20:44 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
More Coss-Site Scripting Vulnerabilities In Google Search Appliance
ha.ckers.org is reporting more XSS bugs with the Google Search Appliance.


[ Read the rest of the article... ]
Posted by NIST.org on Sunday 23 September 2007 - 21:41:18 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
NIST.gov releases draft of Wireless Network Security for IEEE 802.11a/b/g and Bluetooth
NIST.gov has released an excellent and up to date overview of wireless technologies and associated security concerns. SP800 Rev. 1 is in draft and is a very good read.

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 08 August 2007 - 06:17:10 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Apple Quicktime and Adobe Flash Highly Critical Vulnerabilities
Both Quicktime and Adobe Flash have highly critical vulnerabilities that can be exploited by simply visiting a page with malicious content. Execution of arbitrary code is possible. Secunia ranks some of these as “Highly Critical”. Apple and Adobe have released updates and upgrading is highly recommended.

[ Read the rest of the article... ]
Posted by NIST.org on Saturday 14 July 2007 - 14:52:28 | Read/Post Comment: 1 |LAN_EMAIL_7 printer friendly
iPhone, Another Source of Data Leaks
Those responsible for IT Security are still tracking down people connecting iPods to the office computer. Some companies may not care if employees connect their music players and phones to their office computer, but many forbid it. Now the iPhone presents more headaches.

[ Read the rest of the article... ]
Posted by NIST.org on Monday 02 July 2007 - 15:32:16 | Read/Post Comment: 1 |LAN_EMAIL_7 printer friendly
Go to page       >>  
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




NIST Site Menu
·Home

Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» Storm Botnet Celebrates Birthday With Fireworks, (Fri, Jul 4th)

» New Opera v9.51 fixes couple of security issues, (Thu, Jul 3rd)

» Detecting scripts in ASF files (part 2), (Thu, Jul 3rd)

» Another little script I threw together, (Wed, Jul 2nd)

» The scoop on the spike in UDP port 7 traffic, (Wed, Jul 2nd)

» Followup to "What's going on...", (Wed, Jul 2nd)

» Firefox 2.0.0.15 is out, (Wed, Jul 2nd)

***
Dark Reading: Dark Reading News Analysis

» Matasano Unwraps Its 'Firewall Mixer'
[03 Jul 2008 11:35am]

» Laptop Losses Total 12,000 Per Week at US Airports
[02 Jul 2008 04:00pm]

» Insider Threat Doubles; New Program Offers Assessments
[02 Jul 2008 03:35pm]

» PCI Standards Expanded to Include Unattended Devices
[01 Jul 2008 03:40pm]

» New DLP Startup Performs 'DNA Sequencing' of Data
[01 Jul 2008 02:20pm]

» Cracking Physical Identity Theft
[30 Jun 2008 03:50pm]

***
CNET News.com - Security

» Video: Latest in Viacom-Google lawsuit raises questions
[03 Jul 2008 03:48pm]

» Researcher faults Apple iPhone on security updates
[03 Jul 2008 03:22pm]

» Google RatProxy looks for cross-site flaws
[03 Jul 2008 02:51pm]

» Daily Debrief: Celebrating America's independence, questioning our own online
[03 Jul 2008 02:44pm]

» Hundreds of Lithuanian Web sites defaced
[03 Jul 2008 02:35pm]

» Mozilla and Opera fix security flaws
[03 Jul 2008 01:59pm]

» Four security bulletins expected on Patch Tuesday
[03 Jul 2008 01:23pm]

» Stolen: Google employees' personal data
[03 Jul 2008 10:52am]

» Sony PlayStation site victim of SQL-injection attack
[02 Jul 2008 12:35pm]

»