US CERT Current Activity
Adobe Releases Security Advisory for Adobe Flash Player
- Adobe Flash Player 11.1.102.55 and earlier versions for Windows, Macintosh, Linux, and Solaris operating systems
- Adobe Flash Player 11.1.112.61 and earlier versions for Android 4.x
- Adobe Flash Player 11.1.111.5 and earlier versions for Android 3.x and 2.x
Exploitation of these vulnerabilities may allow an attacker to cause a denial-of-service condition, take control of the affected system, or perform a cross-site scripting attack.
US-CERT encourages users and administrators to review the Adobe Security Bulletin APSB12-03 and apply any necessary updates to help mitigate the risk.
Google Releases Chrome 17.0.963.56
US-CERT encourages users and administrators to review the Google Chrome Release blog entry and update to Chrome 17.0.963.56.
Cisco Releases Security Advisory for Cisco NX-OS
- Cisco Nexus 1000v Series Switches
- Cisco Nexus 5000 Series Switches
- Cisco Nexus 7000 Series Switches
US-CERT encourages users and administrators to review Cisco Security Advisory cisco-sa-20120215 and apply any necessary updates or workarounds to help mitigate the risk.
Oracle Releases Critical Patch Update for February 2012
- JDK and JRE 7 Update 2 and earlier
- JDK and JRE 5 Update 30 and earlier
- JDK and JRE 5.0 Update 33 and earlier
- SDK and JRE 1.4.2_35 and earlier
- JavaFX 2.0.2 and earlier
US-CERT encourages users and administrators to review the Oracle Java SE Critical Patch Update Advisory for February 2012 and apply any necessary updates to help mitigate the risk.
Adobe Releases Security Bulletins for Adobe Shockwave Player and RoboHelp
- Adobe Shockwave Player 11.6.3.633 and earlier versions for Windows and Macintosh
- Adobe RoboHelp 9 or 8 for Word on Windows
Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code or perform a cross-site scripting attack.
US-CERT encourages users and administrators to review Adobe Security Bulletins APSB12-02 and APSB12-04 and apply any necessary updates to help mitigate the risks.
Mozilla Releases Firefox 10.0.1
US-CERT encourages users and administrators to review the Mozilla Foundation Advisory for Firefox 10.0.1 and apply any necessary updates to help mitigate the risk.
Microsoft Releases February Security Bulletin
US-CERT encourages users and administrators to review the bulletin and follow best-practice security policies to determine which updates should be applied.
Google Releases Chrome 17.0.963.46
US-CERT encourages users and administrators to review the Google Chrome Release blog entry and update to Chrome 17.0.963.46.
U.S. Tax Season Phishing Scams and Malware Campaigns
These phishing scams and malware campaigns may include, but are not limited to, the following:
- information that refers to a tax refund,
- warnings about unreported or under-reported income,
- offers to assist in filing for a refund, and
- details about fake e-file websites.
US-CERT encourages users and administrators to take the following measures to protect themselves from these types of phishing scams and malware campaigns:
- Do not follow unsolicited web links in email messages.
- Maintain up-to-date antivirus software.
- Refer to the IRS website related to phishing, email, and bogus website scams for scam samples and reporting information.
- Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
- Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.
- Forward suspected phishing emails to phishing@irs.gov.
Apple Releases Multiple Security Updates
US-CERT encourages users and administrators to review Apple Support Article HT5130 and apply any necessary updates to help mitigate the risks.
Additional information regarding CVE-2011-3449 can be found in US-CERT Vulnerability Note VU#410281.
Additional information regarding CVE-2011-3446 can be found in US-CERT Vulnerability Note VU#403593.
Mozilla Releases Firefox 10 and 3.6.26
US-CERT encourages users and administrators to review the Mozilla Foundation Advisories for Firefox 10 and Firefox 3.6.26 and apply any necessary updates to help mitigate the risk.
CERTuy
- Hispasec - Elevación de privilegios en sudo (en multitud de distribuciones)
- Hispasec - Denegación de servicio en Samba
- Hispasec - Microsoft, ¿No quedamos en dejar de utilizar MD5? (y II)
- Hispasec - Ejecución remota de comandos en Apache Struts
- Hispasec - Múltiples vulnerabilidades en SAP NetWeaver 7




