NIST Site Search
Google
Web NIST.org
NIST.gov
Product Research

Advertise on this site
Headlines

»Mac OS X ARDAgent Local Privilege Escalation
ARDAgent in Apple Mac OS X 10.5 and 10.4 allows local users to gain privileges via an osascript tell ...
»Creative Software AutoUpdate Engine ActiveX stack buffer overflow
The Creative Software AutoUpdate Engine ActiveX control is a component that provides automatic updat ...
»Internet Connection Sharing DoS
A denial of service vulnerability exists within the Internet Connection Sharing service in Microsoft ...
»RPC Memory Exhaustion
The three referenced exploits take advantage of an inherent problem in RPC, in which an attacker get ...


Date published: Thu, 28 Aug 2008 02:05:00 PST
Details

»Report: Lab certifying voting equipment failed to meet requirements
The National Voluntary Laboratory Accreditation Program has accused SysTest Labs of not meeting the ...
»Scott Vanstone | Cryptography thrown an elliptic curve
GCN Interview: One of the inventors of elliptic curve cryptography talks about ECC’s emerging r ...
»Cybereye | The threats ahead
Infrastructure networking technology figures to be the hot topic during the next year when it comes ...
»Cyber chief argues for new approaches
STRATCOM commander proposes switch to white listing, more sensors and greater training and accountab ...
»NETCOM commander weighs in on security
Brig. Gen. Susan Lawrence, speaking at the 2008 LandWarNet Conference, said that data and network se ...
»Army cyber ops faces forensic backlog
Col. Barry Hensley spoke at the 2008 LandWarNet Conference, regarding the challenge of conducting fo ...
»NIST releases draft revision of guidelines for authorizing operation IT systems
Publication is part of an interagency project to harmonize C&A process across civilian, military ...
»Layer 3 support for PDAs
Array Networks offers Layer 3 VPN support for Windows Mobile devices and other PDAs.


Date published: Tue, 26 Aug 2008 20:39:27 GMT
Details

»SSH Key-based Attacks
»Microsoft Revised Security Bulletin MS08-051
»Red Hat Releases OpenSSH Security Update
»Malware Circulating via Russia/Georgia Conflict Spam Messages
»Opera Releases Version 9.52
»Webex Meeting Manager ActiveX Control Vulnerability
»Joomla! Password Reset Vulnerability
»Apple MobileMe Phishing Scam
»Microsoft Releases August Security Bulletin
»Microsoft Releases Advanced Notification for August Security Bulletin


Date published: not known
Details

»News: Online intruders hit Red Hat, Fedora Project
Online intruders hit Red Hat, Fedora Project
»News: Researchers race to zero in record time
Researchers race to zero in record time
»News: Gov't charges alleged TJX credit-card thieves
Gov't charges alleged TJX credit-card thieves

>> Advertisement <<
Can y ...
»News: Poisoned DNS servers pop up as ISPs patch
Poisoned DNS servers pop up as ISPs patch
»Brief: Denial, hype cloud report of Best Western breach
Denial, hype cloud report of Best Western breach


Date published: not known
Details

»Timing Precision
If you’ve been watching the Olympics you might have see the pretty amazingly close call betwee ...
»MySQL Truncation Etc…
Stefan Esser has a really good article about how MySQL and SQL truncate columns which can lead to se ...
»HTML 5.0
On good authority I was told to take a good hard look at the newly proposed HTML 5.0 spec that’ ...
»MSN IP Search
I’ve been meaning to write something about this for a while now, and a number of people have k ...
»Firefox Security Model Growth
Okay, I can bet I’m going to get a lot of flack for this post, so before I start, this is only ...
»History Hack Male vs. Female and Beyond
Strangely enough there’s been a ton of things happening in the CSS history hacking world latel ...
»Private Investigator or Forensics Expert
What do I have in common with Magnum PI? What does id have in common with Dog the Bounty Hunter? W ...
»WebAppSec Survey Time Plus A Fast Approaching DefCon and Blackhat
Yup, it’s about that time again. Jeremiah has put up yet another webappsec professional surve ...
»Redirection Report
Brian Krebs had an interesting report over at the Washington Post that cited a report from Indiana.e ...
»Dialogs Of Doom
So maluc and I went down the rabbit hole (again) looking for ways to screen scrape across domains us ...


Date published: not known
Details

»Powering Down?
»'YouTubing' Training Games
»U.S. Losing E-Gov Race
»Meyerrose to Leave ODNI
»Can You Trust Your Database?
»Internet Search: When More is Less?
»Malicious Thumb Drives in Justice
»Time for a Handheld Project Post Mortem
»Hot Insider Entries
»GSA becomes first civilian agency to implement IPv6
»Speculation: Meyerrose to Leave ODNI
»Paperless government? Only sometimes.
»Army CIO predicts two years of uncertainty in IT program funding
»British hacker’s extradition to U.S. held up
»The New Dynamics of Cyber War


Date published: not known
Details

»S-371: CupsSYS Vulnerabilities
Several remote vulnerabilities have been discovered in the Common Unix Printing System (CUPS). The ...
»S-370: Afuse Vulnerability
It was discovered that afuse, an automounting file system in user-space, did not properly escape met ...
»S-369: BlackBerry Attachment Service PDF Distiller Vulnerability
The PDF Distiller service that is provided with BlackBerry Enterprise Server contains a vulnerabilit ...
»S-368: RealNetworks Vulnerabilities
RealPlayer contains a buffer overflow vulnerability that may allow an attacker to execute code on a ...
»S-367: Oracle Weblogic Apache Connector Vulnerability
An exploit has been public which may impact the availability, confidentiality or integrity of WebLog ...
»S-366: Gaim Vulnerability
It was discovered that Gaim, an multi-protocol instant messaging client, was vulnerable to several i ...
»S-365: Ruby 1.8 Vulnerabilities
Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lea ...
»S-364: ClamAV Vulnerabilities
A vulnerability in the ClamAV anti-virus toolkit's parsing of Petite-packed Win32 executables. The w ...
»S-363: libexslt Vulnerability
It was discovered that a buffer overflow in the RC4 functions of libexslt may lead to the execution ...
»S-362: OpenSC
It was discovered that OpenSC, a library and utilities to handle smart cards, would initialise smart ...
»S-361: Oracle Critical Patch Update - July 2008
Oracle has released a critical patch update for multiple security vulnerabilities. The risk is MEDI ...
»CIACTech08-003: Understanding Cross-Site Scripting (XSS)
Cross-Site Scripting has become an increasingly prevalent attack vector that can be leveraged to per ...
»CIACTech08-002: Understanding Windows Hash Dumpers and Crackers
Windows hash dumping tools are often spotlighted as hacker tools that can somehow magically extract ...
»CIACTech08-001: Understanding PHP Exploits
Many websites use the PHP programming language to build web pages on the fly from individual files a ...
»CIACTech07-001: MOICE - Microsoft Office Isolated Conversion Environment
A common cyber attack is to send a user an Office document (Word, Excel, PowerPoint) containing mal ...


Date published: not known
Details
Welcome to NIST.org
Welcome to NIST.org

Make NIST.org your morning IT Security wakeup call. Important security news is automatically added day and night, so you can see at a glance what threats you'll be facing. You'll find this information in the sidebars and in the Newsfeed section. Less time sensitive articles are posted below where topics are looked at more in-depth.

News articles are updated multiple times per day and the IT Security newsfeeds are automatically updated hourly (see main menu). Subscribe to this site's RSS Newsfeed to stay up to date on what's really important.

Be sure to Page Down to see current IT Security News on he sidebars or visit our Newsfeeds page for several more IT Security News sources. Now featuring security news headlines from eEye's Zero-day Tracker, GovExec.com, SecurityFocus, and Ha.ckers.org. Headlines link to the full stories.

  • Announcing: New Small Screen Security News - 'nist.org/m' [...more]

Registration to NIST.org is Free and removes this Welcome message, as well as some of the advertising [...more]
If You Haven't Patched Your DNS Server Yet You're Simply Negligent
The recent DNS cache poisoning vulnerability is being exploited and everyone is vulnerable to it. If you haven't upgraded your DNS servers yet you're putting everyone at risk.

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 06 August 2008 - 21:14:30 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Firefox 3.0 Vulnerabilities, 2.0.x Also Vulnerable
Within hours after its release TippingPoint received a vulnerability that affects Firefox 3.0 and previous 2.0.x versions. The vulnerability allows and attacker to execute arbitrary code on the victims computer.

[ Read the rest of the article... ]
Posted by NIST.org on Saturday 21 June 2008 - 10:27:49 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Ransomware Will Win The War
The well respected Antivirus firm Kaspersky Lab is calling for a massive group effort to break the encryption used by the latest Ransomware. They're asking competitors, governments, and cryptographers to join the effort. But even a massive worldwide computer grid won't win this war.

[ Read the rest of the article... ]
Posted by NIST.org on Monday 16 June 2008 - 05:57:58 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
WordPress Sites Need To Upgrade, The Rest Of Us Need To Watch This Too.
A major security vulnerability has been discovered in the popular WordPress blogging software. The vulnerability may allow an attacker to bypass security restrictions. Being able to bypass security restrictions would allow someone the ability to post malicious code that could attack visitors to that site.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 01 May 2008 - 05:09:19 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
SQL Injections Continue – 100s of Thousands of URL's Infected
No one is sure of the number of server databases are infected but the guess is over 100,000. The Google searches are over 500,000 hits but many servers have more than one URL showing the infection.

[ Read the rest of the article... ]
Posted by NIST.org on Monday 28 April 2008 - 06:06:25 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Symantec Raises Threat Level Due To In The Wild Image File Exploits
Symantec has raised the Threatcon to Level 2 due to detection of an in the wild exploit of MS08-021 which allows remote code execution. FrSIRT ranks this as "Critical".

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 10 April 2008 - 20:28:48 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
SANS Internet Storm Center Starts Monthly Podcast
If you don't have the time or interest to read about the latest IT security news the SANS.org podcast or some of the other security podcasts might help you keep up.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 10 April 2008 - 17:04:25 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
FBI Reports Online Crime At All Time High
The U.S. FBI reports that online crime is at an all time high. So why are we hearing so little about it?

[ Read the rest of the article... ]
Posted by NIST.org on Monday 07 April 2008 - 05:51:39 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Symantec Antivirus ActiveX Vulnerability
Vulnerabilities have been discovered in an ActiveX control that ships with several Symantec products, including Norton AntiVirus, Norton Internet Security, Norton 360, and Norton SystemWorks.

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 06 April 2008 - 12:40:30 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
MS Excel "Extremely Critical" Vulnerability Allows Remote Code Execution
Microsoft has posted information about a new "Extremely Critical" zeroday vulnerability in MS Excel. This vulnerability effects most versions of Excel on both Windows and Mac OS X.

[ Read the rest of the article... ]
Posted by NIST.org on Friday 18 January 2008 - 06:05:59 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
RealPlayer Buffer Overflow Vulnerability – Highly Critical
If you haven't updated your users RealPlayer from October's RealPlayer playlist name stack buffer overflow now you have another one to worry about.

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 06 January 2008 - 16:55:51 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Highly Critical and Extremely Critical Vulnerabilities in Lotus Notes and Apple Quicktime
Lotus Notes R6.5.x through R8.x contains a Highly Critical vulnerability with its Lotus 123 viewer. Successful exploitation allows execution of arbitrary code. Apple Quicktime contains an Extremely Critical vulnerability that can be exploited via an email attachment or by visiting a malicious website.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 29 November 2007 - 04:35:47 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
New Phishing Scam Hitting Hard, No Clicks Required
A new method is being used to phish for credit card numbers that is fooling a lot more people. In this scam the user never has to figure out if a link is good or not because they never have to click on anything. Its all very familiar to them because they've done it before.

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 15 November 2007 - 17:54:17 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
RealPlayer Extremely Critical Vulnerability
RealNetworks has released a fix for an Extremely Critical vulnerability. Successful exploitation, through a playlist file, allows execution of arbitrary code.

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 24 October 2007 - 20:48:14 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Transient Electromagnetic Devices (TEDs) Can Threaten Our IT Infrastructure
Many people recognize an old term – electromagnetic pulse or EMP. The ElectroMagnetic Pulse (EMP) effect was first observed during the early testing of high altitude airburst nuclear weapons. In the past EMP's generally required the use of a nuclear detonation. Today a destructive EMP can be produced without the use of a nuclear device. The development of Transient Electromagnetic Devices (TEDs) now makes the threat of an EMP attack much more likely.

[ Read the rest of the article... ]
Posted by NIST.org on Friday 12 October 2007 - 16:02:23 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Critical Vulnerability in Acrobat and Acrobat Reader can lead to Remote Code Execution
FrSIRT is reporting a Critical vulnerability in several Acrobat products that can be exploited to run arbitrary code. Basically opening a specially crafted PDF file can lead to an attacker running executable code of their choice on your computer. All versions 8.1 and prior are affected.

[ Read the rest of the article... ]
Posted by NIST.org on Monday 08 October 2007 - 18:47:13 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Has Your Webserver Been Compromised?
Unless you have lots of IT staff on-hand or really good monitoring you might not know for weeks that your public webserver has been compromised. Servers aren't always defaced or brought down. One thing that can help is to monitor your abuse@yourdomain.com email.

[ Read the rest of the article... ]
Posted by NIST.org on Tuesday 25 September 2007 - 15:20:44 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
More Coss-Site Scripting Vulnerabilities In Google Search Appliance
ha.ckers.org is reporting more XSS bugs with the Google Search Appliance.


[ Read the rest of the article... ]
Posted by NIST.org on Sunday 23 September 2007 - 21:41:18 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
NIST.gov releases draft of Wireless Network Security for IEEE 802.11a/b/g and Bluetooth
NIST.gov has released an excellent and up to date overview of wireless technologies and associated security concerns. SP800 Rev. 1 is in draft and is a very good read.

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 08 August 2007 - 06:17:10 | Read/Post Comment: 0 |LAN_EMAIL_7 printer friendly
Apple Quicktime and Adobe Flash Highly Critical Vulnerabilities
Both Quicktime and Adobe Flash have highly critical vulnerabilities that can be exploited by simply visiting a page with malicious content. Execution of arbitrary code is possible. Secunia ranks some of these as “Highly Critical”. Apple and Adobe have released updates and upgrading is highly recommended.

[ Read the rest of the article... ]
Posted by NIST.org on Saturday 14 July 2007 - 14:52:28 | Read/Post Comment: 1 |LAN_EMAIL_7 printer friendly
Go to page       >>  
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




NIST Site Menu
·Home

Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» Active attacks using stolen SSH keys, (Tue, Aug 26th)

» Podcast Episode X Record Notice, (Tue, Aug 26th)

» The Latest in Crimeware, (Mon, Aug 25th)

» Thoughts on the Best Western Compromise, (Mon, Aug 25th)

» Warning, it's not from us., (Sun, Aug 24th)

» SQL injections - an update, (Sat, Aug 23rd)

» RedHat compromise sparks a Critical openssh security update, (Fri, Aug 22nd)

***
Dark Reading: Dark Reading News Analysis

» Report: Popular Web Attacks Go Stealth
[27 Aug 2008 03:45pm]

» Microsoft Offers Details on Privacy Features in IE8
[27 Aug 2008 02:46pm]

» The Seven Deadliest Social Networking Hacks
[26 Aug 2008 05:40pm]

» Best Western Denies Report of Massive Data Breach
[25 Aug 2008 02:55pm]

» Life Insurer Takes New Approach to Two-Factor Authentication
[22 Aug 2008 02:32pm]

» Survey: Mid-Sized Firms Shape Up for Security
[22 Aug 2008 07:55am]

***
CNET News.com - Security

» Rising fraud threats in virtual worlds
[27 Aug 2008 05:26pm]

» Security hole opens up password protected iPhones
[27 Aug 2008 03:15pm]

» IE 8 beta gives other browsers a run for their money
[27 Aug 2008 02:33pm]

» Become a remote spy with Swann's new wireless camera
[27 Aug 2008 01:41pm]

» Space: The final frontier for computer viruses
[27 Aug 2008 12:53pm]

» Google Earth shows cows point north
[27 Aug 2008 11:02am]

» Firefox extension protects against man-in-the-middle attacks
[26 Aug 2008 05:53pm]

» Amex, Royal Bank of Scotland, NatWest customer details sold on eBay
[26 Aug 2008 11:57am]

»