<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Business Information Technologies, LLC</title>
	<atom:link href="http://www.bit0101.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bit0101.com</link>
	<description>Business Information Technologies, LLC.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:50:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Mozilla Releases Firefox 10 and 3.6.26</title>
		<link>http://www.bit0101.com/2012/02/mozilla-releases-firefox-10-and-3-6-26/</link>
		<comments>http://www.bit0101.com/2012/02/mozilla-releases-firefox-10-and-3-6-26/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 14:50:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/02/mozilla-releases-firefox-10-and-3-6-26/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: February 1, 2012 10:15:03 EST Mozilla Releases Firefox 10 and 3.6.26 added &#8230; <a href="http://www.bit0101.com/2012/02/mozilla-releases-firefox-10-and-3-6-26/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/fb5e2_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/fb5e2_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: February 1, 2012 10:15:03 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Mozilla Releases Firefox 10 and 3.6.26--><br /><a name="mozilla_releases_firefox_10_and" id="mozilla_releases_firefox_10_and"></a><br />
<h2>Mozilla Releases Firefox 10 and 3.6.26</h2>
<p><i>added February 1, 2012 at 09:50 am</i><br />

<p>The Mozilla Foundation has released Firefox 10 and Firefox 3.6.26 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or perform a cross-site scripting attack.</p>
<p>US-CERT encourages users and administrators to review the Mozilla Foundation Advisories for <a href="http://www.mozilla.org/security/known-vulnerabilities/firefox.html#firefox10" target="_self">Firefox 10</a> and <a href="http://www.mozilla.org/security/known-vulnerabilities/firefox36.html" target="_self">Firefox 3.6.26</a> and apply any necessary updates to help mitigate the risk. </p>
<p><!--Denial-of-Service Malware Campaign--><br />
<br /><a name="anonymous_activities" id="anonymous_activities"></a><br />
<h2>Denial-of-Service Malware Campaign</h2>
<p><i>added January 24, 2012 at 05:35 pm</i>
<p>          US-CERT is aware of public reports of ongoing distributed denial-of-service attacks against entities in the government and private sector.<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_10_and">http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_10_and</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/02/mozilla-releases-firefox-10-and-3-6-26/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Denial-of-Service Malware Campaign</title>
		<link>http://www.bit0101.com/2012/01/denial-of-service-malware-campaign/</link>
		<comments>http://www.bit0101.com/2012/01/denial-of-service-malware-campaign/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 22:35:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/01/denial-of-service-malware-campaign/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: January 24, 2012 17:50:04 EST Denial-of-Service Malware Campaign added January 24, 2012 &#8230; <a href="http://www.bit0101.com/2012/01/denial-of-service-malware-campaign/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/1e545_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/9d23d_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: January 24, 2012 17:50:04 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Denial-of-Service Malware Campaign--><br /><a name="anonymous_activities" id="anonymous_activities"></a><br />
<h2>Denial-of-Service Malware Campaign</h2>
<p><i>added January 24, 2012 at 05:35 pm</i>
<p>          US-CERT is aware of public reports of ongoing distributed denial-of-service attacks against entities in the government and private sector. According to the reports, these attacks are being attributed to the hacker group Anonymous.</p>
<p>US-CERT encourages users and administrators to do the following to reduce the risk associated with this and other malware campaigns: </p>
<ul>
<li>Do not open attachments in email messages from unknown sources.
</li>
<li>Install anti-virus software and keep virus signatures files up to date.
</li>
<li>Refer to the <a href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.
</li>
<li>Refer to the <a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for information on social engineering attacks. 
</li>
<li>Refer to<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#anonymous_activities">http://www.us-cert.gov/current/index.html#anonymous_activities</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/01/denial-of-service-malware-campaign/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Releases Chrome 16.0.912.77</title>
		<link>http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-77/</link>
		<comments>http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-77/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 18:03:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-77/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: January 24, 2012 17:50:04 EST Denial-of-Service Malware Campaign added January 24, 2012 &#8230; <a href="http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-77/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/b77d9_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/a676f_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: January 24, 2012 17:50:04 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Denial-of-Service Malware Campaign--><br /><a name="anonymous_activities" id="anonymous_activities"></a><br />
<h2>Denial-of-Service Malware Campaign</h2>
<p><i>added January 24, 2012 at 05:35 pm</i>
<p>          US-CERT is aware of public reports of ongoing distributed denial-of-service attacks against entities in the government and private sector. According to the reports, these attacks are being attributed to the hacker group Anonymous.</p>
<p>US-CERT encourages users and administrators to do the following to reduce the risk associated with this and other malware campaigns: </p>
<ul>
<li>Do not open attachments in email messages from unknown sources.
</li>
<li>Install anti-virus software and keep virus signatures files up to date.
</li>
<li>Refer to the <a href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.
</li>
<li>Refer to the <a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for information on social engineering attacks. 
</li>
<li>Refer to<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#google_releases_chrome_16_02">http://www.us-cert.gov/current/index.html#google_releases_chrome_16_02</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-77/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec pcAnywhere Hotfix</title>
		<link>http://www.bit0101.com/2012/01/symantec-pcanywhere-hotfix/</link>
		<comments>http://www.bit0101.com/2012/01/symantec-pcanywhere-hotfix/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 16:30:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/01/symantec-pcanywhere-hotfix/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: January 24, 2012 12:10:43 EST Symantec pcAnywhere Hotfix added January 24, 2012 &#8230; <a href="http://www.bit0101.com/2012/01/symantec-pcanywhere-hotfix/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/507bf_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/507bf_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: January 24, 2012 12:10:43 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Symantec pcAnywhere Hotfix--><br /><a name="symantec_pcanywhere_hotfix" id="symantec_pcanywhere_hotfix"></a><br />
<h2>Symantec pcAnywhere Hotfix</h2>
<p><i>added January 24, 2012 at 11:30 am</i><br />

<p>Symantec has released an update for pcAnywhere to address multiple vulnerabilities for the following software versions running on Windows:</p>
<ul>
<li>pcAnywhere 12.5 SP3</li>
<li>pcAnywhere Solutions 7.1 GA, SP 1, and SP 2</li>
</ul>
<p>US-CERT encourages users and administrators to review the <a href="http://clientui-kb.symantec.com/kb/index?page=contentpmv=printimpressions=viewlocale=id=TECH179526" target="_self">Symantec pcAnywhere hot fix</a> and apply any necessary updates to help mitigate the risk. </p>
<p>US-CERT will provide additional information as it becomes available. <br /><!--Best Practices for Recovery from the Malicious Erasure of Files--><br /><a name="best_practices_for_recovery_from" id="best_practices_for_recovery_from"></a><br />
<h2>Best Practices for Recovery from the Malicious Erasure of Files</h2>
<p><i>added January 19, 2012 at 04:12 pm | updated January 20, 2012 at 09:49 am</i><br />

<p>There are many ways in which cyber criminals can damage computer systems and data, including changing or<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#symantec_pcanywhere_hotfix">http://www.us-cert.gov/current/index.html#symantec_pcanywhere_hotfix</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/01/symantec-pcanywhere-hotfix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best Practices for Recovery from the Malicious Erasure of Files</title>
		<link>http://www.bit0101.com/2012/01/best-practices-for-recovery-from-the-malicious-erasure-of-files/</link>
		<comments>http://www.bit0101.com/2012/01/best-practices-for-recovery-from-the-malicious-erasure-of-files/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 21:12:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/01/best-practices-for-recovery-from-the-malicious-erasure-of-files/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: January 19, 2012 16:13:02 EST Best Practices for Recovery from the Malicious &#8230; <a href="http://www.bit0101.com/2012/01/best-practices-for-recovery-from-the-malicious-erasure-of-files/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/8f288_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/8f288_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: January 19, 2012 16:13:02 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Best Practices for Recovery from the Malicious Erasure of Files--><br /><a name="best_practices_for_recovery_from" id="best_practices_for_recovery_from"></a><br />
<h2>Best Practices for Recovery from the Malicious Erasure of Files</h2>
<p><i>added January 19, 2012 at 04:12 pm</i><br />

<p>Cyber criminals can damage their victim&#8217;s computer systems and data by changing or deleting files, wiping hard drives, or erasing backups to hide some or all of their malicious activity and tradecraft. By wiping, or &#8220;zeroing out,&#8221; the hard disk drives, which overwrites good data with zeroes or other characters, the criminals effectively erase or alter all existing data, greatly impeding restoration. This sort of criminal activity makes it difficult to determine whether criminals merely accessed the network, stole information, or altered network access and configurations files. Completing network restoration efforts and business damage assessments may be also hampered. </p>
<p>The FBI and<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#best_practices_for_recovery_from">http://www.us-cert.gov/current/index.html#best_practices_for_recovery_from</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/01/best-practices-for-recovery-from-the-malicious-erasure-of-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle Releases Critical Patch Update for January 2012</title>
		<link>http://www.bit0101.com/2012/01/oracle-releases-critical-patch-update-for-january-2012/</link>
		<comments>http://www.bit0101.com/2012/01/oracle-releases-critical-patch-update-for-january-2012/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 15:58:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/01/oracle-releases-critical-patch-update-for-january-2012/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: January 18, 2012 10:59:13 EST Oracle Releases Critical Patch Update for January &#8230; <a href="http://www.bit0101.com/2012/01/oracle-releases-critical-patch-update-for-january-2012/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/898e3_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/34893_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: January 18, 2012 10:59:13 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Oracle Releases Critical Patch Update for January 2012--><br /><a name="oracle_releases_critical_patch_update16" id="oracle_releases_critical_patch_update16"></a><br />
<h2>Oracle Releases Critical Patch Update for January 2012</h2>
<p><i>added January 18, 2012 at 10:58 am</i><br />

<p>Oracle has released its <a href="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" target="_self">Critical Patch Update</a> for January 2012 to address 78 vulnerabilities across multiple products. This update contains the following security fixes:</p>
<ul>
<li>2 for Oracle Database Server</li>
<li>1 for Oracle Fusion Middleware</li>
<li>3 for Oracle E-Business Suite</li>
<li>1 for Oracle Supply Chain Products Suite</li>
<li>6 for Oracle PeopleSoft Products</li>
<li>8 for Oracle JD Edwards Products</li>
<li>17 for Oracle Sun Products Suite</li>
<li>3 for Oracle Virtualization</li>
<li>27 for Oracle MySQL</li>
</ul>
<p>US-CERT encourages users and administrators to review the January 2012 <a href="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" target="_self">Critical Patch Update</a> and apply any necessary updates to help mitigate the risks. </p>
<p>Additional information regarding CVE-2012-0110 can be found in US-CERT Vulnerability Note <a href="http://www.kb.cert.org/vuls/id/738961" target="_self">VU#738961</a>.</p>
<p><!--Phishing Campaign Using Spoofed US-CERT<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#oracle_releases_critical_patch_update16">http://www.us-cert.gov/current/index.html#oracle_releases_critical_patch_update16</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/01/oracle-releases-critical-patch-update-for-january-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing Campaign Using Spoofed US-CERT Email Addresses</title>
		<link>http://www.bit0101.com/2012/01/phishing-campaign-using-spoofed-us-cert-email-addresses/</link>
		<comments>http://www.bit0101.com/2012/01/phishing-campaign-using-spoofed-us-cert-email-addresses/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 19:06:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/01/phishing-campaign-using-spoofed-us-cert-email-addresses/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: January 10, 2012 16:50:28 EST Adobe Releases Security Advisory for Adobe Reader &#8230; <a href="http://www.bit0101.com/2012/01/phishing-campaign-using-spoofed-us-cert-email-addresses/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/59afb_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/59afb_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: January 10, 2012 16:50:28 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Adobe Releases Security Advisory for Adobe Reader and Acrobat--><br /><a name="adobe_releases_security_advisory_for10" id="adobe_releases_security_advisory_for10"></a><br />
<h2>Adobe Releases Security Advisory for Adobe Reader and Acrobat</h2>
<p><i>added January 10, 2012 at 04:40 pm</i><br />

<p>Adobe has released a Security Advisory for Adobe Reader and Acrobat to address multiple vulnerabilities affecting the following software versions:</p>
<ul>
<li>Adobe Reader X (10.1.1) and earlier 10.x versions for Windows and Macintosh</li>
<li>Adobe Reader 9.4.7 and earlier 9.x versions for Windows</li>
<li>Adobe Reader 9.4.6 and earlier 9.x versions for Macintosh</li>
<li>Adobe Acrobat X (10.1.1) and earlier 10.x versions for Windows and Macintosh</li>
<li>Adobe Acrobat 9.4.7 and earlier 9.x versions for Windows</li>
<li>Acrobat 9.4.6 and earlier 9.x versions for Macintosh</li>
</ul>
<p>Exploitation of these vulnerabilities may allow an attacker to cause a denial-of-service condition or take control of the affected system.
<p>US-CERT encourages users and administrators to review Adobe security advisory <a href="http://www.adobe.com/support/security/bulletins/apsb12-01.html" target="_self">APSB12-01</a><p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#phishing_campaign_using_spoofed_us">http://www.us-cert.gov/current/index.html#phishing_campaign_using_spoofed_us</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/01/phishing-campaign-using-spoofed-us-cert-email-addresses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Releases Chrome 16.0.912.75</title>
		<link>http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-75/</link>
		<comments>http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-75/#comments</comments>
		<pubDate>Fri, 06 Jan 2012 14:26:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-75/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: January 6, 2012 09:29:42 EST Google Releases Chrome 16.0.912.75 added January 6, &#8230; <a href="http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-75/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/2b3bb_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/2b3bb_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: January 6, 2012 09:29:42 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Google Releases Chrome 16.0.912.75--><br /><a name="google_releases_chrome_16_01" id="google_releases_chrome_16_01"></a><br />
<h2>Google Releases Chrome 16.0.912.75</h2>
<p><i>added January 6, 2012 at 09:26 am</i>
<p>Google has released Chrome 16.0.912.75 for Linux, Mac, Windows, and Chrome Frame to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code.</p>
<p>US-CERT encourages users and administrators to review the Google Chrome Releases <a href="http://www.googlechromereleases.blogspot.com/2012/01/stable-channel-update.html" target="_self">blog entry</a> and update to Chrome 16.0.912.75.</p>
<p><!--Microsoft Releases Advance Notification for January Security Bulletin--><br />
<br /><a name="microsoft_releases_advance_notification_for54" id="microsoft_releases_advance_notification_for54"></a><br />
<h2>Microsoft Releases Advance Notification for January Security Bulletin</h2>
<p><i>added January 5, 2012 at 01:24 pm</i>
<p>Microsoft has issued a <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan" target="_self">Security Bulletin Advance Notification</a> indicating that its January release will contain seven bulletins. These bulletins will have the severity rating of critical and important and will be for Microsoft Windows and Microsoft Developer Tools and Software. Release of these bulletins is scheduled<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#google_releases_chrome_16_01">http://www.us-cert.gov/current/index.html#google_releases_chrome_16_01</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2012/01/google-releases-chrome-16-0-912-75/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple Programming Language Implementations Vulnerable to Hash Table Collision Attacks</title>
		<link>http://www.bit0101.com/2011/12/multiple-programming-language-implementations-vulnerable-to-hash-table-collision-attacks/</link>
		<comments>http://www.bit0101.com/2011/12/multiple-programming-language-implementations-vulnerable-to-hash-table-collision-attacks/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 18:04:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2011/12/multiple-programming-language-implementations-vulnerable-to-hash-table-collision-attacks/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: December 28, 2011 13:23:30 EST Multiple Programming Language Implementations Vulnerable to Hash &#8230; <a href="http://www.bit0101.com/2011/12/multiple-programming-language-implementations-vulnerable-to-hash-table-collision-attacks/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/7c112_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/7c112_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: December 28, 2011 13:23:30 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Multiple Programming Language Implementations Vulnerable to Hash Table Collision Attacks--><br /><a name="multiple_vendors_vulnerable_to_hash" id="multiple_vendors_vulnerable_to_hash"></a><br />
<h2>Multiple Programming Language Implementations Vulnerable to Hash Table Collision Attacks</h2>
<p><i>added December 28, 2011 at 01:04 pm</i>
<p>US-CERT is aware of reports stating that multiple programming language implementations, including web platforms, are vulnerable to hash table collision attacks. This vulnerability could be used by an attacker to launch a denial-of-service attack against websites using affected products. </p>
<p>The Ruby Security Team has updated Ruby 1.8.7. The Ruby 1.9 series is not affected by this attack. Additional information can be found in the <a href="http://www.ruby-forum.com/topic/3312298" target="_self">ruby 1.8.7 patchlevel 357 release notes</a>.</p>
<p>Microsoft has released a security advisory for ASP.NET containing a workaround. Additional information can be found in <a href="http://technet.microsoft.com/en-us/security/advisory/2659883" target="_self">Microsoft Security Advisory 2659883</a>.</p>
<p>More information regarding this vulnerability can be found in US-CERT Vulnerability Note <a href="http://www.kb.cert.org/vuls/id/903934" target="_self">VU#903934</a> and<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#multiple_vendors_vulnerable_to_hash">http://www.us-cert.gov/current/index.html#multiple_vendors_vulnerable_to_hash</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2011/12/multiple-programming-language-implementations-vulnerable-to-hash-table-collision-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Releases Firefox 9 and 3.6.25</title>
		<link>http://www.bit0101.com/2011/12/mozilla-releases-firefox-9-and-3-6-25/</link>
		<comments>http://www.bit0101.com/2011/12/mozilla-releases-firefox-9-and-3-6-25/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 15:56:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.bit0101.com/2011/12/mozilla-releases-firefox-9-and-3-6-25/</guid>
		<description><![CDATA[The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT. Last reviewed: December 21, 2011 11:40:14 EST Mozilla Releases Firefox 9 and 3.6.25 added &#8230; <a href="http://www.bit0101.com/2011/12/mozilla-releases-firefox-9-and-3-6-25/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/95240_rss_sm.gif" alt="current activity RSS feed" border="0" /> <img src="http://www.bit0101.com/wp-content/plugins/rss-poster/cache/d8187_atom.gif" alt="current activity ATOM feed" border="0" /></p>
<p>
The US-CERT Current Activity web page is a regularly updated summary<br />
of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.
</p>
<p><!-- Date of last review/update --></p>
<p>
<b>Last reviewed: December 21, 2011 11:40:14 EST<br />
</b></p>
<p><!-- *** QUICK LINKS *** --><!-- *** END QUICK LINKS *** --><br />
<hr /><!-- *** CONTENT *** --><!--Mozilla Releases Firefox 9 and 3.6.25--><br /><a name="mozilla_releases_firefox_9_and" id="mozilla_releases_firefox_9_and"></a><br />
<h2>Mozilla Releases Firefox 9 and 3.6.25</h2>
<p><i>added December 21, 2011 at 10:56 am</i><br />

<p>The Mozilla Foundation has released Firefox 9 and Firefox 3.6.25 to<br />
address multiple vulnerabilities. These vulnerabilities may allow an<br />
attacker to execute arbitrary code, cause a denial-of-service condition,<br />
 or perform a cross-site scripting attack.</p>
<p>
US-CERT encourages users and administrators to review the Mozilla Foundation Security Advisories for <a href="http://www.mozilla.org/security/known-vulnerabilities/firefox.html#firefox9" target="_self">Firefox 9</a> and <a href="http://www.mozilla.org/security/known-vulnerabilities/firefox36.html" target="_self">Firefox 3.6.25</a> and apply any necessary updates to help mitigate the risk. </p>
<p><!--USAA Phishing Scam and Malware Campaign--><br />
<br /><a name="usaa_phishing_scam_and_malware" id="usaa_phishing_scam_and_malware"></a><br />
<h2>USAA Phishing Scam and Malware Campaign</h2>
<p><i>added December 20, 2011 at 01:14 pm</i><br />

<p>US-CERT is aware of public reports of an active spear-phishing attack via email messages directed at United Services Automobile Association (USAA) members.<p><code><br /></code>
Read more at: <a href="http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_9_and">http://www.us-cert.gov/current/index.html#mozilla_releases_firefox_9_and</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bit0101.com/2011/12/mozilla-releases-firefox-9-and-3-6-25/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

