NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Headlines

»NIST Publishes Draft Implementation Guidance for Continuously Monitoring an Organizations IT System Security
»NIST Issues Cloud Computing Guidelines for Managing Security and Privacy
»International Community Gathers at NIST in March to Discuss Biometric Performance and Testing
»March Workshop to Support Trusted IDs in Cyberspace
»NIST SBIR Program Soliciting Proposals to Solve Manufacturing and IT Challenges
»Text Retrieval Conference 2012 Seeks Information Retrieval Experts for Data Digging
»Protecting Computers at Start-Up: New NIST Guidelines
»NIST Special Publication Expands Government Authentication Options
»New NIST Biometric Data Standard Adds DNA, Footmarks and Enhanced Fingerprint Descriptions
»NIST Improves Tool for Hardening Software Against Cyber Attack
»New HIPAA Tool Helps Organizations Meet Security Requirements
»Romine Named Director of NISTs Information Technology Laboratory
»NICE Issues Cybersecurity Workforce Framework for Public Comment
»Draft Roadmap for Cloud Computing Technology
»NIST Signs Agreement to Enhance Cybersecurity Education Programs


Date published: not known
Details

»Denial-of-Service Malware Campaign
»Google Releases Chrome 16.0.912.77
»Symantec pcAnywhere Hotfix
»Best Practices for Recovery from the Malicious Erasure of Files
»Oracle Releases Critical Patch Update for January 2012
»Phishing Campaign Using Spoofed US-CERT Email Addresses
»Microsoft Releases January Security Bulletin
»Adobe Releases Security Advisory for Adobe Reader and Acrobat
»Google Releases Chrome 16.0.912.75
»Multiple Programming Language Implementations Vulnerable to Hash Table Collision Attacks


Date published: not known
Details

»U-090: RSA enVision Discloses Environment Variable Information to Remote Users
RSA enVision Discloses Environment Variable Information to Remote Users
»U-089: U-089:Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
U-089:Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
»U-088: Symantec pcAnywhere Bugs Let Remote Users Execute Arbitrary Code
Symantec pcAnywhere Bugs Let Remote Users Execute Arbitrary Code
»U-087: HP-UX update for Java
HP-UX update for Java
»U-086: Linux Kernel /proc//mem Privilege Escalation Vulnerability
Linux Kernel /proc//mem Privilege Escalation Vulnerability
»U-085: OpenSSL DTLS Bug Lets Remote Users Deny Service
OpenSSL DTLS Bug Lets Remote Users Deny Service
»U-084: Cisco Digital Media Manager Lets Remote Authenticated Users Gain Elevated Privileges
Cisco Digital Media Manager Lets Remote Authenticated Users Gain Elevated Privileges
»U-083: Oracle Critical Patch Update Advisory - January 2012
Oracle Critical Patch Update Advisory - January 2012
»U-082: PHP Null Pointer Dereference in zend_strndup() Lets Local Users Deny Service
PHP Null Pointer Dereference in zend_strndup() Lets Local Users Deny Service
»U-081: McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code
McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code
»U-080: Linux Kernel XFS Heap Overflow May Let Remote Users Execute Arbitrary Code
Linux Kernel XFS Heap Overflow May Let Remote Users Execute Arbitrary Code
»U-079: Adobe Acrobat/Reader Multiple Bugs Let Remote Users Execute Arbitrary Code
Adobe Acrobat/Reader Multiple Bugs Let Remote Users Execute Arbitrary Code
»U-078: Microsoft Security Bulletin Advance Notification for January 2012
Microsoft Security Bulletin Advance Notification for January 2012
»U-077: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code
Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code
»U-076: OpenSSL Bugs Let Remote Users Deny Service, Obtain Information, and Potentially Execute Arbitrary Code
OpenSSL Bugs Let Remote Users Deny Service, Obtain Information, and Potentially Execute Arbitrary Co ...


Date published: not known
Details

»Hacktivists hijack DNS of popular websites
Security at registrars may be weak link.
»New RFC describes best practices for running DNS-based lists
DNSBL users advised to avoid those lists that charge for delisting.
»Vulnerability turns McAfee's anti-malware solution into open relay
Flaw allows for spam to be sent through customers' PCs.
»AV-Test releases latest results
Business and consumer products achieve high pass rate.
»Sykipot trojan used to target smart cards
Defence companies among small number of targets.
»Spammers link to site containing QR code
Curious users may scan URL and end up on pharma websites.
»January issue of VB published
The January issue of Virus Bulletin is now available for subscribers to download.
»Spammers using Google open redirect
Vulnerability 'not worthy of bug bounty program'.
»Compromised websites used to mine bitcoins
In-the-browser botnet turns victims' CPU cycles into cash for the attackers.


Date published: not known
Details

»New Drive-By Spam Infects Those Who Open Email -- No Attachment Needed
Getting infected just got a whole lot easier, researchers say
»The Mechanics Of Breach Notification
Organizations need to know what constitutes a breach of identity data according to state laws and ho ...
»Security Careers: A Closer Look At Digital Investigations
Security incident response and forensics are, at heart, people problems. Here are some tips for maki ...
»Smartcards: Still A Smart Choice?
Despite recent security compromises, smartcard technology still has high potential
»Study: The Aftermath Of A Breach
New Ponemon-Experian study
»Hopping Aboard The Mobile Payment Bandwagon? Bring A Helmet
Implementing mobile payment systems presents a high risk, high reward opportunity
»Six-Year-Old Breach Comes Back To Haunt Symantec
Security firm warns users to halt use of pcAnywhere until it finishes patching it, but says older No ...
»Hacktivists Turn To DNS Hijacking
Coach, UFC fallvictim to attacks that redirect their Web traffic
»Database Password Storage Exposes Need For Better ID Management
DreamHost and other password breaches show weaknesses in the way passwords are stored


Date published: not known
Details
Welcome to NIST.org
Welcome to NIST.org

Make NIST.org your morning IT Security wakeup call. Important security news is automatically added day and night, so you can see at a glance what threats you'll be facing. You'll find this information in the sidebars and in the Newsfeed section. Less time sensitive articles are posted below where topics are looked at more in-depth.

News articles are updated multiple times per day and the IT Security newsfeeds are automatically updated hourly (see main menu). Subscribe to this site's RSS Newsfeed to stay up to date on what's really important.

Be sure to Page Down to see current IT Security News on he sidebars or visit our Newsfeeds page for several more IT Security News sources. Now featuring security news headlines from eEye's Zero-day Tracker, GovExec.com, SecurityFocus, and Ha.ckers.org. Headlines link to the full stories.

  • Announcing: New Small Screen Security News - 'nist.org/m' [...more]

Registration to NIST.org is Free and removes this Welcome message, as well as some of the advertising [...more]
Free Online Antivirus, Spyware, and Firewall Scanners Review
You might be doing everything right with your anti-virus and spyware malware protection. But no product is perfect and a "second opinion" is always valuable. We get a lot of questions on what to do about viruses, spyware, intrusions, etc. There are so many Anti-Spyware scams, fake products, and Trojans out there that we've put together this (non-affliate) list of free help sites. Starting off with a review of free online virus and spyware scanning tools. (updated 3/31/09)No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 04 May 2009 - 22:16:00 | |printer friendly
NIST Computer Security Division Released Special Publication 800-38E
NIST released Special Publication 800-38E which approves the XTS-AES mode of the AES algorithm for data on storage devices.
No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 25 January 2010 - 21:38:27 | |printer friendly
DRAFT Special Publication 800-37 Revision 1 Available
Final Public DRAFT Special Publication 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach is now available.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Tuesday 17 November 2009 - 21:41:18 | |printer friendly
News Blog: "Mass Panic! The iPhone Has a Vulnerability"
This can't be good - Researchers at the Black Hat security conference on Thursday showed an iPhone security flaw which exploits a weakness in SMS text messaging to take control of the device. From ComputerWorld
Posted by NIST.org on Thursday 30 July 2009 - 22:09:54 | |printer friendly
First ZeroDay Exploit Hits Firefox
The Mozilla Firefox browser has its first ever Zeroday exploit. The bug is rated as 'highly critical' by several security organizations. Successful exploit can lead to a hacker having full control over the target computer. (FIXED. See below) No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 20 July 2009 - 06:11:54 | |printer friendly
"FBI Probes Hacker's $10 Million Ransom Demand for Stolen Virginia Medical Records"
A hacker has allegedly stolen 8.3 million patient records from a Virginia government Web site that tracks prescription drug abuse. The hacker also is claiming that all of the backup copies on their system have been destroyed. They're demanding a $10 million ransom to return the data and agree not to sell it on the open market (where, according to some experts, it may actually command a fee higher than $10 million).

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 06 May 2009 - 20:51:28 | |printer friendly
Conflicker Worm / Botnet Downloads Mystery Payload – April 9th update
Not a lot of information but Conflicker has apparently downloaded new instructions and a keylogger.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 09 April 2009 - 23:51:20 | |printer friendly
Conflicker Worm - April Fools Day Likely To Make Fools Out Of Us Either Way
The "Conflicker" worm is set to trigger on April 1st. This one is certainly getting a lot of press. If it goes off and causes a lot of harm everyone will look like fools for not taking it seriously. But if everyone spends tons of additional time and effort on detection and prevention and nothing happens you'll still look foolish. We've included links to basic prevention and removal information below.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 30 March 2009 - 22:21:27 | |printer friendly
ESET NOD32 False Positive for Kryptik.JX Causing Problems
The ESET antivirus program NOD32 triggered a false alarm on a couple of important Windows files and quarantined them. The fix is pretty easy, simply restore them quarantine. Instructions below. No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 09 March 2009 - 06:12:29 | |printer friendly
New Report Shows 92 Percent of Critical Microsoft Vulnerabilities are Mitigated by Eliminating Admin Rights
A new study by BeyondTrust found that 92% of critical Microsoft vulnerabilities could have been stopped or mitigated by stopping the practice of giving users "Administrator" rights.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Tuesday 03 February 2009 - 22:25:55 | |printer friendly
Federal Employees At Risk Again From Monster.com Compromise
USAJOBS.GOV is reporting that government employee data was (again) lost by illegal access at Monster.com where the data is hosted. Monster.com users are also affected. There is a high likelihood of phishing attempts from this compromise.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 25 January 2009 - 18:57:36 | |printer friendly
Microsoft Windows Does Not Disable AutoRun Properly - Technical Cyber Security Alert TA09-020A
Disabling AutoRun on Microsoft Windows systems can help prevent the spread of malicious code. However, Microsoft's guidelines for disabling AutoRun are not fully effective, which could be considered a vulnerability. Technical Cyber Security Alert TA09-020A by: US-CERTNo Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 21 January 2009 - 06:16:25 | |printer friendly
Internet Explorer XML Exploit Allows Remote Code Execution
Released the day after patch Tuesday this Extremely Critical IE exploit is completely different than the IE vulnerability fixed in the Dec 9th patch. This one allows remote code execution if the user visits a web page containing a specially crafted XML document.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 14 December 2008 - 23:17:44 | |printer friendly
Microsoft Has Released An Extremely Urgent Out of Band Windows Update
Microsoft unexpectedly released a critical Out of Band Windows update that affects Windows 2000, Windows XP and Windows 2003 systems. Exploits have been reported in the wild. Windows Vista can be exploited as well but requires authentication.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 23 October 2008 - 22:33:11 | |printer friendly
If You Haven't Patched Your DNS Server Yet You're Simply Negligent
The recent DNS cache poisoning vulnerability is being exploited and everyone is vulnerable to it. If you haven't upgraded your DNS servers yet you're putting everyone at risk.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 06 August 2008 - 22:14:30 | |printer friendly
Firefox 3.0 Vulnerabilities, 2.0.x Also Vulnerable
Within hours after its release TippingPoint received a vulnerability that affects Firefox 3.0 and previous 2.0.x versions. The vulnerability allows and attacker to execute arbitrary code on the victims computer.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Saturday 21 June 2008 - 11:27:49 | |printer friendly
Ransomware Will Win The War
The well respected Antivirus firm Kaspersky Lab is calling for a massive group effort to break the encryption used by the latest Ransomware. They're asking competitors, governments, and cryptographers to join the effort. But even a massive worldwide computer grid won't win this war.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 16 June 2008 - 06:57:58 | |printer friendly
WordPress Sites Need To Upgrade, The Rest Of Us Need To Watch This Too.
A major security vulnerability has been discovered in the popular WordPress blogging software. The vulnerability may allow an attacker to bypass security restrictions. Being able to bypass security restrictions would allow someone the ability to post malicious code that could attack visitors to that site.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 01 May 2008 - 06:09:19 | |printer friendly
SQL Injections Continue – 100s of Thousands of URL's Infected
No one is sure of the number of server databases are infected but the guess is over 100,000. The Google searches are over 500,000 hits but many servers have more than one URL showing the infection.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 28 April 2008 - 07:06:25 | |printer friendly
Symantec Raises Threat Level Due To In The Wild Image File Exploits
Symantec has raised the Threatcon to Level 2 due to detection of an in the wild exploit of MS08-021 which allows remote code execution. FrSIRT ranks this as "Critical".No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 10 April 2008 - 21:28:48 | |printer friendly
Go to page       >>  
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




Main Menu
· Home

Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» SSH Password attacks using domain name elements as userid, (Fri, Jan 27th)
[27 Jan 2012 03:08am]

» CISCO Ironport C & M Series telnet vulnerability, (Fri, Jan 27th)
[27 Jan 2012 02:52am]

» ISC StormCast for Friday, January 27th 2012 http://isc.sans.edu/podcastdetail.html?id=2287, (Fri, Jan 27th)
[26 Jan 2012 09:15pm]

» ISC Feature of the Week: ISC Link Back, (Wed, Jan 25th)
[26 Jan 2012 08:32pm]

» pcAnywhere users – patch now!, (Wed, Jan 25th)
[25 Jan 2012 09:51pm]

» ISC StormCast for Thursday, January 26th 2012 http://isc.sans.edu/podcastdetail.html?id=2284, (Thu, Jan 26th)
[25 Jan 2012 08:12pm]

» ISC StormCast for Wednesday, January 25th 2012 http://isc.sans.edu/podcastdetail.html?id=2281, (Wed, Jan 25th)
[24 Jan 2012 08:21pm]

» Is it time to get rid of NetBIOS?, (Tue, Jan 24th)
[24 Jan 2012 03:29pm]

» ISC StormCast for Tuesday, January 24th 2012 http://isc.sans.edu/podcastdetail.html?id=2278, (Tue, Jan 24th)
[23 Jan 2012 09:03pm]

» Javascript DDoS Tool Analysis, (Sun, Jan 22nd)
[23 Jan 2012 11:16am]

***
CNET News.com

» Anonymous takes aim over Europe's SOPA
[27 Jan 2012 07:36pm]

» Microsoft's Kelihos botnet suspect says he's innocent
[27 Jan 2012 07:27pm]

» Hawaiian politician backs away from Web dossier law
[27 Jan 2012 12:58am]

» Twitter to block tweets locally, not globally
[26 Jan 2012 04:38pm]

» Mobile security app from McAfee hits 2.0
[26 Jan 2012 03:11pm]

» Politicians aim some pointed privacy questions at Google
[26 Jan 2012 03:02pm]

» Hawaii may keep track of all Web sites visited
[26 Jan 2012 01:36am]

» Facebook denies Anonymous 'claims' of takedown
[25 Jan 2012 08:14pm]

» DHS disputes memo on purported railway computer breach
[25 Jan 2012 06:34pm]

» O2 fixes phone number leak, explains blunder
[25 Jan 2012 03:03pm]

» Symantec tells customers to disable PCAnywhere
[25 Jan 2012 02:03pm]

» EU overhauling data-privacy policies to protect consumers
[25 Jan 2012 06:45am]

» European Union overhauls data-privacy policies to protect consumers
[25 Jan 2012 06:45am]

» Grappling with O2's phone number leaks
[25 Jan 2012 06:28am]

» Obama touts alternative energy despite Solyndra's demise
[24 Jan 2012 08:13pm]

***
Computerworld Security News

» Lookout Security rebuts rival's Android malware claims
[27 Jan 2012 05:52pm]

» Adscend denies Facebook, AG allegations
[27 Jan 2012 02:41pm]

» Researchers unearth more Chinese links to defense contractor attacks
[27 Jan 2012 10:18am]

» Drive-by-download attack exploits critical vulnerability in Windows Media Player
[27 Jan 2012 09:48am]

» The real reasons why SOPA and PIPA are real bad
[27 Jan 2012 08:20am]

» CloudPassage launches new security product for public clouds
[27 Jan 2012 07:39am]

» More Security News

***


***


More IT Security
News Feeds
More Sponsors

Advertise on this site
NIST - Books You Need

NIST Bookstore
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Symantec News
Welcome
Username:

Password:


Remember me

[ ]
[ ]
[ ]

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}