Most of the threat activity for this week was directed towards Facebook
and Twitter users. Large e-mail campaigns for password reset
confirmations led to compromised Facebook accounts and Trojan
installations, with the primary goal of stealing bank account information.
Sun issued advance notification to patch at least six vulnerabilities in Java on
Tuesday, 2009-11-03. There is also an unspecified buffer overflow
vulnerability in the current version of Java System Web Server. The
Guardian Newspaper reported a “sophisticated” intrusion on their jobs
site, and Gawker Media became the victim of a malvertisement similar to
September’s attack on the New York Times.
Exploits:
- Vuln: Mahara Resume Blocktype Cross Site Scripting Vulnerability
- Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
- Vuln: Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
- Vuln: HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability
- Vuln: PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
- Vuln: KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
- Vuln: PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
- Vuln: IBM Rational Products Multiple Cross Site Scripting Vulnerabilities
- Vuln: Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
- Vuln: Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
News
Latest Security News
Weekly Intelligence Summary: 2009 – 10 – 30
Latest Security News
Weekly Intelligence Summary: 2009 – 10 – 30
Most of the threat activity for this week was directed towards Facebook and Twitter users. Large e-mail campaigns for password reset confirmations led to compromised Facebook accounts and Trojan installations, with the primary goal of stealing bank account information. Sun issued advance notification to patch at least six vulnerabilities in Java on Tuesday, 2009-11-03. There is also an [...]
Viewed 19 times so far.
Like this? Tweet it to your followers!
Published in
Subscribe to the RSS feed of Network Security & Hacking News
Network Security & Hacking News
/
Subscribe to the RSS feed of Latest Security News
Latest Security News
Like this? Let your friends know now!
Rate this article
Latest articles from
-
Microsoft: No backdoor in Windows 7
posted on Friday, 20 November 2009 06:37
But NSA admits involvement in OS security guide
-
Mutant Koobface worm attacks Skype accounts
posted on Friday, 20 November 2009 08:46
Probes Wikipedia, YouTube and Google
-
An Ounce of Prevention is Worth a Pound of Cure
posted on Friday, 20 November 2009 09:42
A conversation on Twitter this morning started out like this: @dinozaizovi: Finding vulnerabilities without exploiting…
-
Vuln: Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
posted on Thursday, 19 November 2009 11:00
Apache Tomcat JULI Logging Component Default Security Policy Vulnerability
-
Vuln: Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
posted on Thursday, 19 November 2009 11:00
Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
Latest 'tweets' from GovernmentSecurity
- News Update: Cyber war is coming, the impact could be huge: CBS News reports that cyber.. http://bit.ly/1tx1kr | #Security Link Monday, 09 November 2009 07:35
- News Update: Tenable Network #Security Podcast - Episode 11: Welcome to the Tenable Netw.. http://bit.ly/2Iqd6G | Security Link Monday, 09 November 2009 07:35
- News Update: Consent will be required for cookies in Europe: EDITORIAL: A law that dema.. http://bit.ly/3JYgip | #Security Link Monday, 09 November 2009 07:35
- News Update: CBS 60 Minutes tackles cyber-terrorism: Could hackers get into the compute.. http://bit.ly/2d5Y21 | #Security Link Monday, 09 November 2009 07:35
- Blog Update: We have launched the new GovernmentSecurity.org: We decided to launch th.. http://bit.ly/2G1SSF | #Security Link Saturday, 07 November 2009 17:38
Site Search
Login Form
Disqus Tools
