About :: Members :: Projects :: Keen Veracity :: Buy Stuff! :: Contact :: Mailing List :: Binary Bombermen

Current News

Update! Update!
Posted by Digital Ebola @ Wednesday 29th 2009f July 2009 04:04:31 PM
It seems that many of us will be at Defcon. Looking forward to the trip, as it should be informative and entertaining.

 
 


Latest Advisories

Microsoft

  • MS10-017 - Important: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)
  • MS10-016 - Important: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561)
  • MS10-015 - Important: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)
  • MS10-014 - Important: Vulnerability in Kerberos Could Allow Denial of Service (977290)
  • MS10-013 - Critical: Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (977935)
  • MS10-012 - Important: Vulnerabilities in SMB Server Could Allow Remote Code Execution (971468)
  • MS10-011 - Important: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (978037)
  • MS10-010 - Important: Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service (977894)
  • MS10-009 - Critical: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (974145)
  • MS10-008 - Critical: Cumulative Security Update of ActiveX Kill Bits (978262)

    SecurityFocus Vulnerabilities

  • Vuln: Microsoft Internet Explorer 'iepeers.dll' Remote Code Execution Vulnerability
  • Vuln: Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability
  • Vuln: Sun VirtualBox Guest Additions Local Denial Of Service Vulnerability
  • Vuln: Apache Subrequest Handling Information Disclosure Vulnerability
  • Bugtraq: [USN-908-1] Apache vulnerabilities
  • Bugtraq: [ MDVSA-2010:059 ] virtualbox

    CERT Coordination Center

  • TA10-068A: Microsoft Updates for Multiple Vulnerabilities
  • SB10-067: Vulnerability Summary for the Week of March 1, 2010
  • SB10-060: Vulnerability Summary for the Week of February 22, 2010
  • TA10-055A: Malicious Activity Associated with quot;Auroraquot; Internet Explorer Exploit
  • SB10-053: Vulnerability Summary for the Week of February 15, 2010
  • SB10-046: Vulnerability Summary for the Week of February 8, 2010
  • TA10-040A: Microsoft Updates for Multiple Vulnerabilities
  • SB10-040: Vulnerability Summary for the Week of February 1, 2010
  • TA10-021A: Microsoft Internet Explorer Vulnerabilities
  • SB10-018: Vulnerability Summary for the Week of January 11, 2010

    Packetstorm

    Botan-1.9.4.tgz

    gnupg-2.0.15.tar.bz2

    fwbuilder-4.0.0.tar.gz

    anantasoft-xsrf.txt

    secunia-etsdisclose.txt

    secunia-etssql.txt


    News and Discussion

    SecurityFocus

  • News: Change in Focus
  • News: Twitter attacker had proper credentials
  • News: PhotoDNA scans images for child abuse
  • News: Conficker data highlights infected networks
  • Brief: Google offers bounty on browser bugs
  • Brief: Cyberattacks from U.S. "greatest concern"
  • Brief: Microsoft patches as fraudsters target IE flaw
  • Brief: Attack on IE 0-day refined by researchers
  • News: Monster botnet held 800,000 people's details
  • News: Google: 'no timetable' on China talks
  • News: Latvian hacker tweets hard on banking whistle
  • News: MS uses court order to take out Waledac botnet

    Cisco

  • Oversun-Mercury Starts Commercial Operation of Data Center Based on Cisco Technology
  • Cisco's Security Strategy Explained
  • Cisco Delivers 'Security Without Borders'
  • Talk2Cisco: Live, Social Video Broadcast with Cisco Leaders
  • Cisco, NetApp and VMware Collaborate to Deliver New Capabilities for the Dynamic Data Center

    BugTraq Mailing List

  • Friendly-Tech FriendlyTR69 CPE Remote Management V2.8.9 SQL Injection Vulnerability
  • CVE-2010-0624: Heap-based buffer overflow in GNU Tar and GNU Cpio
  • [SECURITY] [DSA-2010-1] New kvm packages fix several vulnerabilities
  • [SECURITY] [DSA 2009-1] New tdiary packages fix cross-site scripting
  • [USN-908-1] Apache vulnerabilities
  • Secunia Research: XnView DICOM Parsing Integer Overflow Vulnerability
  • [ MDVSA-2010:059 ] virtualbox
  • iDefense Security Advisory 03.09.10: Microsoft Excel MDXSET Record Heap Overflow Vulnerability
  • Secunia Research: Employee Timeclock Software Backup Information Disclosure
  • iDefense Security Advisory 03.09.10: Microsoft Excel MDXTUPLE Record Heap Overflow Vulnerability
  • iDefense Security Advisory 03.09.10: Microsoft Excel Sheet Object Type Confusion Vulnerability
  • [ MDVSA-2010:058 ] php
  • Vulnerabilities in Hydra Engine
  • VUPEN Security Research - Microsoft Office Excel Record Processing Code Execution Vulnerability
  • Secunia Research: Employee Timeclock Software "mysqldump" Password Disclosure

    Vuln-Dev Mailing List

    InfoWorld Security

  • IBM sees Conficker hitting 4 percent of PCs
  • Hackers seize on 0-day flaw in Microsoft's PowerPoint
  • IBM continues push for Sun, but will the deal kill Solaris?
  • Bill would give feds role in private sector cybersecurity
  • Conficker may be more widespread than previously thought
  • Forrester now says '09 U.S. IT spend to drop 3.1 percent
  • Conficker activation passes quietly, but threat isn't over
  • Gartner: IT spending drop-off worse than after dot-com bust
  • China denies cyberespionage charges
  • Fake security software scammers jump on Conficker

    CNET News.com on Security

  • Twitter to block malicious links
  • WhitePages.com halts ad networks over malware
  • LifeLock to pay $12 million to settle deceptive-practices claim
  • Malware found on HTC Android phone from Vodafone
  • Microsoft warns of zero-day IE hole on Patch Tuesday
  • Drudge Report accused of serving malware, again
  • Backdoor found in Energizer Duo USB battery charger
  • Police get Webcam pictures in school spy case
  • RSA 2010: Taking on cyberthreats
  • Microsoft to fix eight Windows and Office holes

    Computerworld Security News

  • Former TSA analyst charged with computer tampering
  • Hackers love to exploit PDF bugs, says researcher
  • Zeus botnet dealt a blow as ISP Troyak knocked out
  • Hackers exploit latest IE zero-day with drive-by attacks
  • Cyberattacks raise e-banking security fears
  • Indian banker charged with online funds fraud

    Internet Storm Center

    Microsoft re-release of KB973811 - attacks on Extended Protection for Authentication
    Infocon: green



  • Trend Micro










    Hate Comcast? Use the banner!