NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Headlines

»NIST to Fund Pilot Projects that Advance Trusted Identities in Cyberspacenbsp Proposers' Conference Set for Feb. 15
»NIST Publishes Draft Implementation Guidance for Continuously Monitoring an Organizations IT System Security
»NIST Issues Cloud Computing Guidelines for Managing Security and Privacy
»International Community Gathers at NIST in March to Discuss Biometric Performance and Testing
»March Workshop to Support Trusted IDs in Cyberspace
»NIST SBIR Program Soliciting Proposals to Solve Manufacturing and IT Challenges
»Text Retrieval Conference 2012 Seeks Information Retrieval Experts for Data Digging
»Protecting Computers at Start-Up: New NIST Guidelines
»NIST Special Publication Expands Government Authentication Options
»New NIST Biometric Data Standard Adds DNA, Footmarks and Enhanced Fingerprint Descriptions
»NIST Improves Tool for Hardening Software Against Cyber Attack
»New HIPAA Tool Helps Organizations Meet Security Requirements
»Romine Named Director of NISTs Information Technology Laboratory
»NICE Issues Cybersecurity Workforce Framework for Public Comment
»Draft Roadmap for Cloud Computing Technology


Date published: not known
Details

»Apple Releases Multiple Security Updates
»Mozilla Releases Firefox 10 and 3.6.26
»Denial-of-Service Malware Campaign
»Google Releases Chrome 16.0.912.77
»Symantec pcAnywhere Hotfix
»Best Practices for Recovery from the Malicious Erasure of Files
»Oracle Releases Critical Patch Update for January 2012
»Phishing Campaign Using Spoofed US-CERT Email Addresses
»Microsoft Releases January Security Bulletin
»Adobe Releases Security Advisory for Adobe Reader and Acrobat


Date published: not known
Details

»U-095: HP Data Protector Media Operations Lets Remote Users Execute Arbitrary Code
HP Data Protector Media Operations Lets Remote Users Execute Arbitrary Code
»U-094: EMC Documentum Content Server Lets Local Administrative Users Gain Elevated Privileges
EMC Documentum Content Server Lets Local Administrative Users Gain Elevated Privileges
»U-093: Mozilla Firefox Multiple Flaws Permit Remote Code Execution, Information Disclosure, and Cross-Site Scripting Attacks
Mozilla Firefox Multiple Flaws Permit Remote Code Execution, Information Disclosure, and Cross-Site ...
»U-092: Sudo Format String Bug Lets Local Users Gain Elevated Privileges
Sudo Format String Bug Lets Local Users Gain Elevated Privileges
»U-091: cURL Lets Remote Users Decrypt SSL/TLS Traffic
cURL Lets Remote Users Decrypt SSL/TLS Traffic
»U-090: RSA enVision Discloses Environment Variable Information to Remote Users
RSA enVision Discloses Environment Variable Information to Remote Users
»U-089: U-089:Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
U-089:Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands
»U-088: Symantec pcAnywhere Bugs Let Remote Users Execute Arbitrary Code
Symantec pcAnywhere Bugs Let Remote Users Execute Arbitrary Code
»U-087: HP-UX update for Java
HP-UX update for Java
»U-086: Linux Kernel /proc//mem Privilege Escalation Vulnerability
Linux Kernel /proc//mem Privilege Escalation Vulnerability
»U-085: OpenSSL DTLS Bug Lets Remote Users Deny Service
OpenSSL DTLS Bug Lets Remote Users Deny Service
»U-084: Cisco Digital Media Manager Lets Remote Authenticated Users Gain Elevated Privileges
Cisco Digital Media Manager Lets Remote Authenticated Users Gain Elevated Privileges
»U-083: Oracle Critical Patch Update Advisory - January 2012
Oracle Critical Patch Update Advisory - January 2012
»U-082: PHP Null Pointer Dereference in zend_strndup() Lets Local Users Deny Service
PHP Null Pointer Dereference in zend_strndup() Lets Local Users Deny Service
»U-081: McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code
McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code


Date published: not known
Details

»February issue of VB published
The February issue of Virus Bulletin is now available for subscribers to download.
»Hacktivists hijack DNS of popular websites
Security at registrars may be weak link.
»New RFC describes best practices for running DNS-based lists
DNSBL users advised to avoid those lists that charge for delisting.
»Vulnerability turns McAfee's anti-malware solution into open relay
Flaw allows for spam to be sent through customers' PCs.
»AV-Test releases latest results
Business and consumer products achieve high pass rate.
»Sykipot trojan used to target smart cards
Defence companies among small number of targets.
»Spammers link to site containing QR code
Curious users may scan URL and end up on pharma websites.
»January issue of VB published
The January issue of Virus Bulletin is now available for subscribers to download.
»Spammers using Google open redirect
Vulnerability 'not worthy of bug bounty program'.


Date published: not known
Details

»INTERPOL Set To Open Global Cybercrime Center In 2014
Director of cybersecurity at INTERPOL working on secure online presence for police worldwide to work ...
»Passive Network Fingerprinting; p0f Gets Fresh Rewrite
Passive network analysis can reveal OS, service, and even vulnerabilities--just by sniffing the netw ...
»Can Glass Box Scanning Find Your Real Bugs?
When it works, hybrid -- or "glass box" scanning -- combines dynamic, black-box analysis with static ...
»Slide Show: Technologies That Are Changing The Sports Security Game
Digital technology is increasingly playing a major role in sports security operations
»How To Spot A Fake Facebook Profile
Barracuda Networks gathers telltale characteristics of the phony Facebook "Friend"
»Adobe Calls For Defensive Approach In Security Research
Mitigation methods the emphasis at Adobe
»Poisoning The Data Well
A Q&A with Forrester's John Kindervag about how encryption makes data worthless to the criminals
»FDIC Warns Of 'High Risk' Payment Processors
Some third-party payment processing services may not be secure, commission says
»Attackers Divert Bank Phone Calls to Cover Tracks
Researchers at Trusteer uncover banking malware that steals telephone information to help attackers ...


Date published: not known
Details
Welcome to NIST.org
Welcome to NIST.org

Make NIST.org your morning IT Security wakeup call. Important security news is automatically added day and night, so you can see at a glance what threats you'll be facing. You'll find this information in the sidebars and in the Newsfeed section. Less time sensitive articles are posted below where topics are looked at more in-depth.

News articles are updated multiple times per day and the IT Security newsfeeds are automatically updated hourly (see main menu). Subscribe to this site's RSS Newsfeed to stay up to date on what's really important.

Be sure to Page Down to see current IT Security News on he sidebars or visit our Newsfeeds page for several more IT Security News sources. Now featuring security news headlines from eEye's Zero-day Tracker, GovExec.com, SecurityFocus, and Ha.ckers.org. Headlines link to the full stories.

  • Announcing: New Small Screen Security News - 'nist.org/m' [...more]

Registration to NIST.org is Free and removes this Welcome message, as well as some of the advertising [...more]
Free Online Antivirus, Spyware, and Firewall Scanners Review
You might be doing everything right with your anti-virus and spyware malware protection. But no product is perfect and a "second opinion" is always valuable. We get a lot of questions on what to do about viruses, spyware, intrusions, etc. There are so many Anti-Spyware scams, fake products, and Trojans out there that we've put together this (non-affliate) list of free help sites. Starting off with a review of free online virus and spyware scanning tools. (updated 3/31/09)No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 04 May 2009 - 21:16:00 | |printer friendly
NIST Computer Security Division Released Special Publication 800-38E
NIST released Special Publication 800-38E which approves the XTS-AES mode of the AES algorithm for data on storage devices.
No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 25 January 2010 - 20:38:27 | |printer friendly
DRAFT Special Publication 800-37 Revision 1 Available
Final Public DRAFT Special Publication 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach is now available.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Tuesday 17 November 2009 - 20:41:18 | |printer friendly
News Blog: "Mass Panic! The iPhone Has a Vulnerability"
This can't be good - Researchers at the Black Hat security conference on Thursday showed an iPhone security flaw which exploits a weakness in SMS text messaging to take control of the device. From ComputerWorld
Posted by NIST.org on Thursday 30 July 2009 - 21:09:54 | |printer friendly
First ZeroDay Exploit Hits Firefox
The Mozilla Firefox browser has its first ever Zeroday exploit. The bug is rated as 'highly critical' by several security organizations. Successful exploit can lead to a hacker having full control over the target computer. (FIXED. See below) No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 20 July 2009 - 05:11:54 | |printer friendly
"FBI Probes Hacker's $10 Million Ransom Demand for Stolen Virginia Medical Records"
A hacker has allegedly stolen 8.3 million patient records from a Virginia government Web site that tracks prescription drug abuse. The hacker also is claiming that all of the backup copies on their system have been destroyed. They're demanding a $10 million ransom to return the data and agree not to sell it on the open market (where, according to some experts, it may actually command a fee higher than $10 million).

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 06 May 2009 - 19:51:28 | |printer friendly
Conflicker Worm / Botnet Downloads Mystery Payload – April 9th update
Not a lot of information but Conflicker has apparently downloaded new instructions and a keylogger.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 09 April 2009 - 22:51:20 | |printer friendly
Conflicker Worm - April Fools Day Likely To Make Fools Out Of Us Either Way
The "Conflicker" worm is set to trigger on April 1st. This one is certainly getting a lot of press. If it goes off and causes a lot of harm everyone will look like fools for not taking it seriously. But if everyone spends tons of additional time and effort on detection and prevention and nothing happens you'll still look foolish. We've included links to basic prevention and removal information below.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 30 March 2009 - 21:21:27 | |printer friendly
ESET NOD32 False Positive for Kryptik.JX Causing Problems
The ESET antivirus program NOD32 triggered a false alarm on a couple of important Windows files and quarantined them. The fix is pretty easy, simply restore them quarantine. Instructions below. No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 09 March 2009 - 05:12:29 | |printer friendly
New Report Shows 92 Percent of Critical Microsoft Vulnerabilities are Mitigated by Eliminating Admin Rights
A new study by BeyondTrust found that 92% of critical Microsoft vulnerabilities could have been stopped or mitigated by stopping the practice of giving users "Administrator" rights.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Tuesday 03 February 2009 - 21:25:55 | |printer friendly
Federal Employees At Risk Again From Monster.com Compromise
USAJOBS.GOV is reporting that government employee data was (again) lost by illegal access at Monster.com where the data is hosted. Monster.com users are also affected. There is a high likelihood of phishing attempts from this compromise.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 25 January 2009 - 17:57:36 | |printer friendly
Microsoft Windows Does Not Disable AutoRun Properly - Technical Cyber Security Alert TA09-020A
Disabling AutoRun on Microsoft Windows systems can help prevent the spread of malicious code. However, Microsoft's guidelines for disabling AutoRun are not fully effective, which could be considered a vulnerability. Technical Cyber Security Alert TA09-020A by: US-CERTNo Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 21 January 2009 - 05:16:25 | |printer friendly
Internet Explorer XML Exploit Allows Remote Code Execution
Released the day after patch Tuesday this Extremely Critical IE exploit is completely different than the IE vulnerability fixed in the Dec 9th patch. This one allows remote code execution if the user visits a web page containing a specially crafted XML document.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Sunday 14 December 2008 - 22:17:44 | |printer friendly
Microsoft Has Released An Extremely Urgent Out of Band Windows Update
Microsoft unexpectedly released a critical Out of Band Windows update that affects Windows 2000, Windows XP and Windows 2003 systems. Exploits have been reported in the wild. Windows Vista can be exploited as well but requires authentication.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 23 October 2008 - 21:33:11 | |printer friendly
If You Haven't Patched Your DNS Server Yet You're Simply Negligent
The recent DNS cache poisoning vulnerability is being exploited and everyone is vulnerable to it. If you haven't upgraded your DNS servers yet you're putting everyone at risk.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Wednesday 06 August 2008 - 21:14:30 | |printer friendly
Firefox 3.0 Vulnerabilities, 2.0.x Also Vulnerable
Within hours after its release TippingPoint received a vulnerability that affects Firefox 3.0 and previous 2.0.x versions. The vulnerability allows and attacker to execute arbitrary code on the victims computer.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Saturday 21 June 2008 - 10:27:49 | |printer friendly
Ransomware Will Win The War
The well respected Antivirus firm Kaspersky Lab is calling for a massive group effort to break the encryption used by the latest Ransomware. They're asking competitors, governments, and cryptographers to join the effort. But even a massive worldwide computer grid won't win this war.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 16 June 2008 - 05:57:58 | |printer friendly
WordPress Sites Need To Upgrade, The Rest Of Us Need To Watch This Too.
A major security vulnerability has been discovered in the popular WordPress blogging software. The vulnerability may allow an attacker to bypass security restrictions. Being able to bypass security restrictions would allow someone the ability to post malicious code that could attack visitors to that site.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 01 May 2008 - 05:09:19 | |printer friendly
SQL Injections Continue – 100s of Thousands of URL's Infected
No one is sure of the number of server databases are infected but the guess is over 100,000. The Google searches are over 500,000 hits but many servers have more than one URL showing the infection.No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Monday 28 April 2008 - 06:06:25 | |printer friendly
Symantec Raises Threat Level Due To In The Wild Image File Exploits
Symantec has raised the Threatcon to Level 2 due to detection of an in the wild exploit of MS08-021 which allows remote code execution. FrSIRT ranks this as "Critical".No Longer Supported

[ Read the rest of the article... ]
Posted by NIST.org on Thursday 10 April 2008 - 20:28:48 | |printer friendly
Go to page       >>  
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




Main Menu
· Home

Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» Apple Security Advisory 2012-001 v1.1, (Sat, Feb 4th)
[03 Feb 2012 05:58pm]

» Sophos 2012 Security Threat Report, (Fri, Feb 3rd)
[03 Feb 2012 03:34pm]

» ISC StormCast for Friday, February 3rd 2012 http://isc.sans.edu/podcastdetail.html?id=2302, (Fri, Feb 3rd)
[02 Feb 2012 11:25pm]

» Critical PHP bug patched, (Fri, Feb 3rd)
[02 Feb 2012 10:40pm]

» New Poll - What security issue concerns you the most this year?, (Fri, Feb 3rd)
[02 Feb 2012 06:19pm]

» PHP 5.3.10 Released, Fixes CVE-2012-0830 available for download http://www.php.net/archive/2012.php#id2012-02-02-1, (Fri, Feb 3rd)
[02 Feb 2012 05:56pm]

» ISC StormCast for Thursday, February 2nd 2012 http://isc.sans.edu/podcastdetail.html?id=2299, (Thu, Feb 2nd)
[01 Feb 2012 10:06pm]

» Apple and Apache security fixes and releases, (Wed, Feb 1st)
[01 Feb 2012 03:02pm]

» Oracle Security Alert: http://www.oracle.com/technetwork/topics/security/alert-cve-2011-5035-1506603.html, (Wed, Feb 1st)
[01 Feb 2012 02:40pm]

***
CNET News.com

» Anti-SOPA forces have ISP snooping bill in their crosshairs
[03 Feb 2012 03:18pm]

» EU officials want Google to suspend privacy policy change
[03 Feb 2012 01:51pm]

» Anonymous hacks lawyers for Marine accused of Iraq massacre
[03 Feb 2012 12:49pm]

» Facebook users polled 'unlike' new Timeline feature
[03 Feb 2012 10:30am]

» Google's response on new privacy policy ticks off congresswoman
[03 Feb 2012 09:29am]

» Google's response on new privacy policy ticks off Congress
[03 Feb 2012 09:29am]

» Anonymous claims to have snooped FBI cybercrime call
[03 Feb 2012 09:11am]

» Anonymous: We snooped an FBI cybercrime call
[03 Feb 2012 09:11am]

» Mystery and mayhem surrounding MegaUpload (roundup)
[03 Feb 2012 04:22am]

» Kelihos botnet makes a comeback
[02 Feb 2012 09:50pm]

» Feds seize illegal sports-streaming sites
[02 Feb 2012 08:22pm]

» Teen finds bugs in Google, Facebook, Apple, Microsoft code
[02 Feb 2012 03:53pm]

» How to identify fake Facebook accounts
[02 Feb 2012 03:41pm]

» Security concerns on Apple's FileVault decryption via FireWire
[02 Feb 2012 01:33pm]

» Google now scanning Android apps for malware
[02 Feb 2012 01:30pm]

***
Computerworld Security News

» Hungarian hacker gets 30 months for extortion plot on Marriott
[03 Feb 2012 02:02pm]

» Anonymous grabs email from firm that defended Marine in Haditha case
[03 Feb 2012 12:34pm]

» German gov't endorses Chrome as most secure browser
[03 Feb 2012 11:09am]

» PHP 5.3.10 fixes critical remote code execution vulnerability
[03 Feb 2012 08:19am]

» Google reveals Android malware 'Bouncer,' scans all apps
[03 Feb 2012 05:25am]

» Lawsuit raises questions about email privacy at work
[03 Feb 2012 05:08am]

» More Security News

***


***


More IT Security
News Feeds
More Sponsors

Advertise on this site
NIST - Books You Need

NIST Bookstore
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Symantec News
Welcome
Username:

Password:


Remember me

[ ]
[ ]
[ ]

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}