logo
Home News Corporate Security FAQ Log-In Contact
IAC RESOURCES
Webinar - TBA
Because of demand, we are scheduling a second session of our "Creating and Maintaining a Meaningful Security Program" webinar. Keep an eye out here for sign up details.
 
IAC Help Document
Saving A Cisco Configuration
 
VULNERABILITY SUMMARY
VULNERABILITIES
Bckdr-QPF
Pushdo-S
Zapchas-EG
Agent-HNJ
Downloader-BJY
Bdoor-ANN
SWFDlDr-F
More Virus Information...
About
Internet Explorer 7 Popup Address Bar Spoofing Test
LATEST VIRUS INFO
VIRUS/WORMREPORT DATE
Downloader-BJY08/28/2008
PWS-Gamania.gen.a08/28/2008
W32/Autorun.worm.eb08/27/2008
MultiDropper-JD08/26/2008
ALS/Dwgun.a08/26/2008
Suspicious IFrame.e08/26/2008
Exploit-TaroDrop.e08/26/2008
Spy-Agent.bw.gen.f08/25/2008
FakeAlert-AG08/25/2008
Generic BackDoor.s08/24/2008
IAC ALERT SUMMARY
May 2007 Cisco Unpatched Vulnerability in IPS and IOS
Cisco is reporting that a malicious user could utilize an unpatched flaw
in Cisco's Intrusion Prevention System (IPS) and Internetwork Operating
System (IOS) with Firewall/IPS Feature Set to evade security restrictions
and launch attacks.
 
Feb. 2007 Microsoft Pre-Patch Notification
Tuesday, Feb. 13, 2007, at roughly 1000 PT, Microsoft will be releasing
their next set of patches. There will be twelve...
 
MSIE VML Vulnerability
We are seeing a large uptick in activity meant to drive users to
compromised servers that are serving malicious sites aimed at exploiting
the latest MS Internet ...
 
Multiple Patch Releases: MS, Apple, Adobe

There are multiple patch related issues that network administrators should be aware of and prepared to address:

MS has re-issued MS06-...

 
Microsoft Word Remote Code Execution Vulnerability

We are aware of a Microsoft Word vulnerability that is currently being
actively exploited. This vulnerability allows for remote code execution
via a Word documen...
 
Cisco Unauthorized Access Flaw

We have noted a Cisco advisory concerning a vulnerability that has the
potential to allow unauthorized users EXEC access to an affected Cisco
device. Authorize...
 
Microsoft Issues Updated Patch

Microsoft has issued an update to their recent MS06-042 patch that fixed
the issues it was made for, but also opened up an additional remote code
execution vulner...
 
MS06-034 Installation Failures

Microsoft has issued a notice to Windows 2003 SP1 administrators regarding
silent failures of the MS06-034 patch released last week. Based on the
information supp...
 
July Microsoft Patch Release

The releases by Microsoft yesterday included patches for several MS Office
vulnerabilities as well as one in particular that involves the "Server"
service.

 
SECURITY NEWS
Internet Explorer 8 Beta 2 Privacy Features Find Support Among IE Users
Microsoft Internet Explorer 8 Beta 2 includes a number of security and privacy features that allow it to keep pace with competing browsers such as Firefox and Safari. Many users of Internet Explorer seem to be behind Microsoft's privacy protections, which are designed to protect users' browsing information.
- Much has been made the new security features in Microsoft Internet Explorer 8 Beta 2 (IE 8). As users and testers bang on the beta version of the browser, Microsoft appears to have gotten a lot right when it comes to privacy. In the beta 2 version of Internet Explorer 8, Microsoft has added a nu
 
iPhone Security Flaw Exposes Private Data
A security flaw in the Apple iPhone allows unauthorized users to gain easy access to private contacts and e-mails even when the device is locked, but the company said a fix is on the way. Popular technology blog Gizmodo and an online forum run by the Mac Rumors site showed that it took only three taps to gain access to locked iPhones, which run the latest 2.02 Apple iPhone software. A spokeswoman said in an e-mail that Apple was aware of the problem and was readying a software update to fix it. In the meantime, she recommended users set the iPhone's Home button to open up the phone's iPod music collection rather than the phone's Favorites menu.
- NEW YORK (Reuters) - A security flaw in Apple Inc's iPhone allows unauthorized users to gain easy access to private contacts and e-mails even when the device is locked, but the company said a fix is on the way. Popular technology blog Gizmodo and an online forum run by the Mac Rumors site show
 
Accused British Hacker Gary McKinnon Loses Appeal to Block Extradition
A British man accused of hacking into U.S. military computers lost a major court battle today and could be extradited to the United States within weeks. Gary McKinnon is alleged to have illegally accessed computers belonging to the Pentagon, NASA and the U.S. Army and Navy in 2001 and 2002. McKinnon lost his appeal today to the European Court of Human Rights to block his extradition.
- A British man accused by the United States of quot;the biggest military hack of all time quot; lost an appeal on Thursday and could be extradited to the United States within weeks. Gary McKinnon, 42, had asked the European Court of Human Rights to block his extradition, complaining that he could
 
WhiteHat Report Finds Web Site Security Vulnerabilities Persist
WhiteHat Security's latest report on Web site security shows cross-site scripting remains the most common Web site vulnerability. But cross-site forgery requests also made WhiteHat's list of top 10 Web site security flaws. On a positive note, the majority of the vulnerabilities discovered by WhiteHat were remediated.
- WhiteHat Security's latest report on Web site vulnerabilities has found the Internet in slightly better shape emphasis on slightly. In the fifth installment of the quot;WhiteHat Website Security Statistics Report, quot; the company has found that 82 percent of the 687 Web sites assessed by the
 
Apple iPhone Password Bypass Made Public
The passcode feature on the latest version of Apple's iPhone can be bypassed in a few simple steps. Apple issued a fix for the issue when it released iPhone v1.1.3 back in January. While iPhone users wait for another fix, information about an easy workaround has been made available.
- The passcode feature on the latest version of Apples iPhone can be bypassed, potentially allowing an unauthorized person to access data on the device if it is lost or stolen. The issue was posted to a MacRumors.com discussion forum and affects iPhone 2.02. Users can lock the iPhone with a four-d