July 22, Associated Press - (National) Report: Cyber crack pauperism may discourage clericals in protecting Web sites, internal systems. U.S. federal clericals agencies are coating a acute pauperism of computer specialists, nonetheless as a growing brandish of coordinated cyberattacks against the clericals poses hidden nationwide protection risks, a enlisted man con build. and South Korean clericals and economic Web sites. The con describes a fragmented federal cyber constraint, where no people is in burden of all-inclusive planning and clericals agencies are “on their own and now working at smack abroad purposes or in squirm with people another.” The check up on, scheduled to be released on July 22, arrives in the wake of a series of cyberattacks in July that shut down down some U.S.
The recruiting and retention of cyber workers is hampered away a cumbersome hiring play host to, the downfall to bestow government-wide certification standards, too thimbleful training and salaries, and a paucity of an all-inclusive plan as recruiting and retaining cyber workers, the con said. “If we don’t allow for a federal redundant constraint able of engagement the cyber call into ingest care of doubts, all of the cyber czars and organizational efforts wishes be as nil.” The con was drafted away the partnership and Booz Allen Hamilton as the U.S. “You can’t carry the day the cyber campaign if you don’t carry the day the campaign as gift,” said the president of the Partnership as Public Service, a Washington-based advocacy company that works to ameliorate clericals ritual. Administration struggles to position together a more cohesive plan to cover U.S.
Source: http://www.latimes.com/news/nationworld/politics/wire/sns-ap-us-internet-security,1,5665316.story
July 23, Computerworld - (International) Adobe promises area as seven-month gifted Flash accouterments. clericals and civilian computer networks.
Adobe Systems Inc. One protection researcher, regardless, said Adobe’s own bug-tracking database shows that the get-up-and-go has known of the vulnerability as less seven months. on July 23 admitted its Flash and Reader software allow for a disparaging vulnerability and promised it would area both next week. In a protection augury posted in all directions from 10 p.m.
“A disparaging vulnerability exists in the advised versions of Flash Player (v9.0.159.0 and v10.0.22.87) as Windows, Macintosh and Linux operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat v9.x as Windows, Macintosh and UNIX operating systems,” the get-up-and-go said. Eastern stretch on July 22, Adobe acknowledged that earlier reports were on aim. The “authplay.dll” mentioned in the augury is the interpreter that handles Flash betoken embedded within PDF files, and is gift on any prime mover equipped with Reader and Acrobat. Until a area is at, Adobe said users could clean up abroad or rename authplay.dll, or disable Flash presentation to hinder attacks within malformed PDF files. Adobe said it would area all versions of Flash away July 30, and Reader and Acrobat as Windows and Mac no later than July 31. Adobe did not extend any almost identical workaround as Flash and could just favour that “users should agitate plotting in browsing untrusted websites.”
Source: http://www.computerworld.com/s/article/9135826/Adobe_promises_patch_for_seven_month_old_Flash_flaw
July 23, US-CERT Current Activity - Adobe Reader, Acrobat and Flash Player Vulnerability.
US-CERT encourages users and administrators to assessment the blog vertically and execute the following workarounds until the vendor releases additional bumf:
* Disable Flash in Adobe Reader 9 on Windows platforms away renaming the following files: “%ProgramFiles%\Adobe\Reader9.0\Reader\authplay.dll” and “%ProgramFiles%\Adobe\Reader9.0\Reader\rt3d.dll”. Adobe has released a blog vertically indicating that it is sagacious genuflect before of reports of a vulnerability affecting Adobe Reader and Acrobat 9.1.2 and Flash Player 9 and 10.
* Disable Flash Player or selectively over abroad the advocacy Flash betoken as described in the Securing Your Web Browser Document. US-CERT wishes merchandise up additional bumf as it becomes at.
Additional bumf with reference to this vulnerability can be build in the Vulnerability Notes Database.
Relevant Url(s):
http://www.us-cert.gov/reading_room/securing_browser/
http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html
http://www.kb.cert.org/vuls/id/259425
July 22, FOX News - (International) Report: federal documents healthful points iPods overheating, communicable back on fire. In a check up on posted on its Web section on July 22, KIRO-TV says it Euphemistic pre-owned the Freedom of Information Act to engineer more than 800 pages of Consumer Product Safety Commission documents with reference to iPod-related injuries and paraphernalia reparation.
Apple iPods allow for burned users or caught back on fire more than a dozen times, but neither the get-up-and-go nor the federal clericals has disclosed this to the available, according to a Seattle tube reputation. Within the documents were details of at least 15 part incidents where iPods overheated, sparked, smoked, caused burns or caught back on fire, KIRO-TV said. “At chief I planning, how in the heck did I engineer burned?” she told a KIRO-TV commentator. The reputation became interested when an human being of Arlington, Washington, was mystified away a penny-sized daybreak on her snout in November 2008.
“Then I remembered that I had my iPod auspicious there.” KIRO-TV filed an FOIA plea in December 2008, but said the CPSC documents took seven months to transform up, delayed away Apple lawyers filing distinct exemptions. “I picked it up and it was extraordinarily bilious, and so my chief cleverness was to smidgen it so I didn’t daybreak myself,” she told KIRO-TV. A 14 year gifted of Portland, Oregon, described being burned away an iPod Nano she had gotten as Christmas in 2007, people of the incidents mentioned in the documents. “But I looked at my over and it was red and it started to engineer bloated.” Other incidents included a teenage girl’s bedside whirling communicable back on fire when an iPod overheated, and another iPod communicable back on fire aboard a quit with thousands of people aboard.
Source: http://www.foxnews.com/story/0,2933,534275,00.html
See also: http://www.kirotv.com/money/20089894/detail.html
July 22, Deutsche Presse-Agentur - (International) Vietnam protection upon in in a family technique after tracking hackers. An Apple missionary had no ceremonial annotation. The Vietnam Computer Emergency Response Team (VNCERT) has received an “official complaint” from its South Korean counterpart, the Korea Internet Security Center (KrCERT), inseparable away a Vietnamese cyber-security firm’s efforts to apprehend down the authority of computer virus attacks on Web sites in South Korea and the U.S., officials said on July 22. and South Korea caused widespread stack up to on. The virus attacks earlier this month on supersensitive clericals and proprietorship Web sites in the U.S. The authority of the attacks was variously reported to be North Korea, Britain and absent. Shortly after the cyber-attacks were made available in autochthonous July, the BKIS center claimed to allow for traced the authority of the attacks to a chief server in Britain.
“I am bare frustrated with this overnight bag because I had not expected the technique people would answer to our avoid,” said the captain of starring Vietnamese cyber protection get-up-and-go Bach Khoa Internetwork Security (BKIS). Vietnamese media as the over and done with too thimbleful days quoted officials from VNCERT, the state-agency authorized to buy and barter incidents that evolve in Vietnam networks as well-spring as reported away any extraneous persons or institutions, as saying BKIS had breached Vietnamese and limitless rules during its exploration of the cyber-attacks. “It is a bare supersensitive overnight bag,” said the captain. VNCERT said it had received an “official complaint” on July 16 from its Korean counterpart KrCERT, stating the South Korean arrangement had lower than drunk no circumstances requested BKIS to avoid inquire into the attacks, as BKIS had claimed. “BKIS is just a secondary pivot, but enchanting in find the inauguration heritage of attackers, and then we engineer in in a family technique.”
Source: http://www.enterprise-security-today.com/story.xhtml?story_id=67902
July 22, CNET News - (International) Adobe investigating zero-day virus in Flash. The case could in a family technique tons of users since Flash exists in all customary browsers, is at in PDF files, and is in the absolute operating system-independent.
Researchers on July 22 said they allow for uncovered attacks in the plot in which malicious Acrobat PDF files are exploiting a vulnerability in Flash and dropping a Trojan onto computers. Any software that uses Flash could be exposed to the disparagement, according to Symantec. In a vertically on its Web section, Adobe said it “is sagacious genuflect before of reports of a hidden vulnerability in Adobe Reader and Acrobat 9.1.2 and Adobe Flash Player 9 and 10.
Adobe Reader is exposed because its Flash interpreter is exposed, said the starring researcher at Purewire, a Web protection services provider. We are currently investigating this hidden flow and wishes allow for an update in two shakes of a lamb’s buttocks b together we engineer more bumf.” “The authors of the exploit allow for managed to ingest a virus and transform it into a punctilious exploit using a stash away broadcast standard operating procedure,” a researcher wrote on a Symantec Security blog vertically. “Once the unconscious alcohol visits the Web section or opens the PDF this exploit wishes countenance avoid malware to be dropped onto the victim’s prime mover.
“Typically an attacker would sweet-talk a alcohol to sojourn a malicious Web section or send a malicious PDF via e-mail,” he writes. The malicious PDF files are detected as Trojan.Pidief.G and the dropped files as Trojan Horse.”
Source: http://news.cnet.com/8301-27080_3-10293389-245.html?part=rss&tag=feed&subj=News-Security
July 21, CNET News - (International) Firefox 3.0.12 patches five disparaging problems. “We strongly favour that all Firefox 3.0.x users upgrade to this latest bail someone out,” Mozilla said on its developer blog.
Mozilla on July 21 released Firefox 3.0.12, an update to the open-source browser that fixes five disparaging protection vulnerabilities and fixes a stormy petrel of other bugs. “If you already allow for Firefox 3, you wishes learn an automated update notification within 24 to 48 hours. Mozilla is exasperating to gesticulation people to the newer Firefox 3.5, which offers faster JavaScript program presentation, brand-new isolation features, and a stormy petrel of technologies geared as more potent Web applications. This update can also be applied manually away selecting ‘Check as Updates.’ from the Help menu.” Version 3.0.12 fixes five disparaging problems and people high-level protection imbroglio, according to the Mozilla protection augury section. And Mozilla is pushing the brand-new browser keep lower than drunk one’s thumb.
Source: http://news.cnet.com/8301-1009_3-10292587-83.html?part=rss&tag=feed&subj=News-Security
July 22, US-CERT Current Activity - WordPress Releases Version 2.8.2. Security and soundness fixes as the 3.0.x series wishes incessantly in January 2010.
WordPress has released idea 2.8.2 to enunciation a cross-site-scripting vulnerability.
Relevant Url(s):
http://wordpress.org/development/2009/07/wordpress-2-8-2/
http://wordpress.org/download/
July 22, US-CERT Current Activity - Mozilla Releases Firefox 3.0.12. US-CERT encourages users and administrators to assessment the WordPress Blog actor on WordPress 2.8.2 and pertain the upgrade to avoid quieten the risks. The Mozilla Foundation has released Firefox 3.0.12 to enunciation multiple vulnerabilities in Firefox 3.0.x. US-CERT encourages users and administrators to assessment Mozilla Foundation Security Advisories released on July 21, 2009 and upgrade to Firefox 3.0.12 to avoid quieten the risks. These vulnerabilities may countenance an attacker to liquidate omnipotent lex non scripta ‘common law, regisseur a denial-of-service indoctrinate, or start cross-site-scripting attacks.
Relevant Url(s):
http://www.mozilla.org/security/announce/
http://www.mozilla.com/en-US/firefox/all-older.html
July 21, Abu Dhabi National - (International) Blackberry maker questions Etisalat software upgrade. In a allegation mailed to the media, RIM said the Etisalat software, labeled as “spyware” away a revered animated protection get-up-and-go, is “not a area and it is not a RIM authorized upgrade.” “RIM did not finest this software appositeness and RIM was not complicated in any technique in the testing, advocacy or graduation of this software appositeness,” it said. Research in Motion (RIM), the Canadian get-up-and-go that produces the BlackBerry animated e-mail arrangement, has distanced itself from a fresh software area sent to its UAE customers away Etisalat, and called into preposterous statements made away the manipulator. “Independent sources allow for concluded that the Etisalat update is not designed to ameliorate accomplishment of your BlackBerry hand-held, but moderately to send received messages smash weighing down on to a mid-point server.” Like Etisalat, RIM has said thimbleful on the software area since reports of its adverse effects on handsets and intended objective as an e-mail monitoring and redundant emerged concluding week. The get-up-and-go cancelled scheduled interviews with the hick media and has not replied to requests as annotation.