Internet Security
Virus News and Alerts
Viruses, they're out there, lurking in the shadows of cyber space just waiting for the perfect moment to invade and infect your machine. Keep up to date on the latest threats, fixes, and preventive measures.
Email Hoax Alerts
Everyone gets them - everyone hates them - those annoying mass forwarded chain emails, and last but not least, those pesky little SPAM hoaxes. The problem now is, how do we differentiate between what is legitimate and what is a hoax. Find out what you need to be on the look out for.
Forwarding Emails
This is a huge, HUGE, big bad no-no, especially in business! We're talking about those emails that have been forwarded to a zillioin-million people and now, poor you, you're one of them. As well intentioned as some of these may seem to be - they are mostly an annoyance, but more importantly, they place your personal or business email address in the hands of SPAMMERS, listers and smart-alecky blankety-blanks who issue emails with viruses attached.
If you receive something in your email that you think is worth sending on, then by all means do this, but do it by copying the fun stuff and then pasting it into your outgoing email.
What to Do About Email Harassment and Scams
Spam, we all get it, but what if the unwanted emails you received were a step beyond Spam and were either threatening or an attempt to thieve you of your identity? How would you be able to report this abuse? The answer to that question is slightly easier than you think.
Canning the SPAM
Each day both inboxes and arteries alike are clogged by this vile substance. So where did this mystery meat of the inbox come from, how did it get distributed to your inbox? Find out.
Keeping Your Kids Safe on the Internet
Did you know that 80 percent of children who use email receive inappropriate, adult oriented SPAM? Did you know that 50 percent of children view the contents of the web without parental guidance? Do you know what your children are doing on the internet? You should. Find out what potential threats children face on the internet and what you can do to keep your children safe on the internet.
Government Information on Internet Security
The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
- Apple Releases Multiple Security Updates
Apple has released security updates for Apple OS X Lion 10.7 to 10.7.2, OS X Lion Server 10.7 to 10.7.2, Mac OS 10.6.8, and Mac OS X Server v 10.6.8 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, and bypass security restrictions.
US-CERT encourages users and administrators to review Apple Support Article HT5130 and apply any necessary updates to help mitigate the risks.
Additional information regarding CVE-2011-3449 can be found in US-CERT Vulnerability Note VU#410281.
Additional information regarding CVE-2011-3446 can be found in US-CERT Vulnerability Note VU#403593. - Mozilla Releases Firefox 10 and 3.6.26
The Mozilla Foundation has released Firefox 10 and Firefox 3.6.26 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or perform a cross-site scripting attack.
US-CERT encourages users and administrators to review the Mozilla Foundation Advisories for Firefox 10 and Firefox 3.6.26 and apply any necessary updates to help mitigate the risk.
- Denial-of-Service Malware Campaign
US-CERT is aware of public reports of ongoing distributed denial-of-service attacks against entities in the government and private sector. According to the reports, these attacks are being attributed to the hacker group Anonymous.
US-CERT encourages users and administrators to do the following to reduce the risk associated with this and other malware campaigns:
- Do not open attachments in email messages from unknown sources.
- Install anti-virus software and keep virus signatures files up to date.
- Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
- Refer to the Avoiding Social Engineering and Phishing Attacks document for information on social engineering attacks.
- Refer to the Recovering from Viruses, Worms, and Trojan Horses document for additional information on how to recover from malware.
- Refer to the Continuing Denial of Service Threats Posed by DNS recursion (v2.0) (pdf) document and Understanding Denial-of-Service Attacks document for additional information on denial-of-service attacks.
- Google Releases Chrome 16.0.912.77
Google has released Chrome 16.0.912.77 for Linux, Mac, Windows, and Chrome Frame to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
US-CERT encourages users and administrators to review the Google Chrome Release blog entry and update to Chrome 16.0.912.77
- Symantec pcAnywhere Hotfix
Symantec has released an update for pcAnywhere to address multiple vulnerabilities for the following software versions running on Windows:- pcAnywhere 12.5 SP3
- pcAnywhere Solutions 7.1 GA, SP 1, and SP 2
US-CERT encourages users and administrators to review the Symantec pcAnywhere hot fix and apply any necessary updates to help mitigate the risk.
US-CERT will provide additional information as it becomes available.
