Monthly Archives: March 2009

Spammers exploit DHL in another malicious campaign

Sophos security news:
Don’t open dhl_n756512.zip!
More information at Sophos.com

Posted in Sophos Security | Leave a comment

Apple Mac users warned of web-based malware threats

Sophos security news:
RSPlug-F Mac Trojan horse distributed via HDTV website.
More information at Sophos.com

Posted in Sophos Security | Leave a comment

Security at risk as one third of surfers admit they use the same password for all websites, Sophos reports

Sophos security news:
Only 19 percent properly protecting their identities by using unique passwords.
More information at Sophos.com

Posted in Sophos Security | Leave a comment

MS09-008 – Important: Vulnerabilities in DNS and WINS Server Could Allow Spoofing (962238)

Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities and two publicly disclosed vulnerabilities in Windows DNS server and Windows WINS server. These vulnerabilities could allow a remote attacker to redirect network traffic intended for systems on the Internet to the attacker’s own systems.
Go to full Article at Microsoft.com

Posted in MS Security | Leave a comment

MS09-007 - Important: Vulnerability in SChannel Could Allow Spoofing (960225)

Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in the Secure Channel (SChannel) security package in Windows. The vulnerability could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. Customers are only affected when the public key component of the certificate used for [...]

Posted in MS Security | Leave a comment

MS09-006 – Critical: Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690)

Bulletin Severity Rating:Critical - This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system.
Go to full Article at Microsoft.com

Posted in MS Security | Leave a comment

Microsoft Security Advisory (953839): Update Rollup for ActiveX Kill Bits - 3/11/2009

Revision Note: March 11, 2009: Added an entry to Frequently Asked Questions to communicate that for the purpose of automatic updating, this update does not replace the Cumulative Security Update of ActiveX Kill Bits (950760) that is described in Microsoft Security Bulletin MS08-032. Advisory Summary:Microsoft is releasing a new set of ActiveX kill bits with [...]

Posted in MS Security | Leave a comment

Microsoft Security Advisory (968272): Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution - 3/5/2009

Revision Note: V2.1 (March 5, 2009): Removed Open XML File Format Converter for Mac from the affected software listed in the Overview section. The Open XML File Format Converter for Mac is not affected by the vulnerability described in this advisory. Advisory Summary:Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel [...]

Posted in MS Security | Leave a comment

Microsoft Security Advisory (967940): Update for Windows Autorun - 2/24/2009

Revision Note: Advisory published Advisory Summary:Microsoft is announcing the availability of an update that corrects a functionality feature that can help customers in keeping their systems protected. The update corrects an issue that prevents the NoDriveTypeAutoRun registry key from functioning as expected.
Go to full Article at Microsoft.com

Posted in MS Security | Leave a comment

Microsoft Security Advisory (961040): Vulnerability in SQL Server Could Allow Remote Code Execution - 2/10/2009

Revision Note: V2.0 (February 10, 2009): Advisory updated to reflect publication of security bulletin. Advisory Summary:Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-004 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-004. The vulnerability addressed [...]

Posted in MS Security | Leave a comment