sans internet storm center
New SQL injection worm making the rounds
Submitted by secgeeks on Wed, 07/05/2008 - 19:34.The trend toward large-scale attacks against Web sites through the use of SQL injection is continuing, as experts at both the SANS Internet Storm Center and Shadowserver Foundation are tracking a newly discovered SQL injection worm that appears to be exploiting a RealPlayer flaw and dropping malware on vulnerable sites. The attacks are focusing on [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 140 reads
Adobe .pdf attacks multiply
Submitted by secgeeks on Mon, 11/02/2008 - 14:09.With enterprises regularly trading .pdf files back and forth, IT administrators should be aware of some new attacks related to recently-patched flaws in the widely used Adobe Reader. Raul Siles at the SANS Internet Storm Center wrote a warning about the .pdf threat over the weekend on the organization Web site, and included additional advisories [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 257 reads
Happy Valentine’s Day from the Storm Trojan
Submitted by secgeeks on Wed, 16/01/2008 - 12:30.Valentine’s Day isn’t for another month, but that’s not stopping controllers of the Storm Trojan from using the holiday theme to trick users into downloading the malware.A posting on the SANS Internet Storm Center Web site describes another wave of Storm emails with a subject designed to catch the recipient’s attention and an email body [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 247 reads
Mega patch for Mac users
Submitted by secgeeks on Tue, 18/12/2007 - 12:48.Apple users tend to have a false sense of security superiority when it comes to their beloved Mac machines. But you gotta give Apple some credit — when a security hole is discovered, the company is pretty good about patching it quickly.This time around, Apple has released Security Update 2007-009 to fix some 41 flaws [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 132 reads
SANS: Attackers may be attempting Trend Micro exploits
Submitted by secgeeks on Sat, 25/08/2007 - 04:00.The SANS Internet Storm Center (ISC) warns that attackers may be attempting to exploit flaws in Trend Micro products to hijack computer systems.
- Add new comment
- Get Our RSS Feeds
- report as spam
- 144 reads
‘Storm’ of spam attacks continue, ISC warns
Submitted by secgeeks on Mon, 13/08/2007 - 08:59.Friday, I reported on a wave of pump-and-dump spam. According to the SANS Internet Storm Center (ISC), reports of massive spamming runs continued through the weekend.Handler Tony Carothers wrote on the ISC Web site that “some of our friends in Canada have been pounded … by a series of emails from a number of destinations.” [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 165 reads
Symantec gives its ThreatCon a makeover
Submitted by secgeeks on Fri, 20/07/2007 - 09:33.There’s not a lot of passion in the security blogosphere this week over any topic in particular, but there are some nuggets worthy of note, including an announcement in the Symantec Security Response blog about a makeover for the company’s ThreatCon.Many security organizations use a measurement system to give customers a sense of the overall [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 175 reads
Storm worm gets patriotic
Submitted by secgeeks on Thu, 05/07/2007 - 18:55.Maarten Van Horenbeeck at the SANS Internet Storm Center has been tracking the spam subject lines associated with the Sestorm worm. “Happy B-day America,” “Independence Day Party” and other lines to dupe email recipients. We reported in January that the Storm worm has been fairly successful in spreading using a variety of topical headlines. [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 204 reads
Web watchers warn of new Storm attack
Submitted by secgeeks on Fri, 29/06/2007 - 12:04.The prolific Storm malware is on the attack again, according to the folks at the SANS Internet Storm Center (ISC). ISC handler Lorna Hutcheson wrote on the storm center Web site that the latest email attack includes a subject line that says “You’ve received a postcard from a family member!” From there, variations of [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 160 reads
Fake Microsoft security bulletin circulating
Submitted by secgeeks on Fri, 08/06/2007 - 09:58.The folks at the SANS Internet Storm Center are warning of a fake Microsoft security bulletin that’s making the rounds. Here’s what it looks like:Microsoft Security Bulletin MS06-4Cumulative Security Update for Internet Explorer (113742734)Published: June 3, 2007Version: 1.0SummaryWho should read this document: Customers who use Microsoft WindowsImpact of Vulnerability: Remote Code ExecutionMaximum Severity Rating: CriticalRecommendation: [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 177 reads
Major spike in activity on TCP 5168, SANS says
Submitted by secgeeks on Wed, 09/05/2007 - 19:14.The SANS Internet Storm Center is reporting that there has been a spike in activity on TCP port 5168 over the last few days, perhaps attributable to attackers looking to exploit a couple of vulnerabilities in Trend Micro’s ServeProtect. The ISC came across the activity on port 5168 through a report from a user whose [...] read more »
- Add new comment
- Get Our RSS Feeds
- report as spam
- 217 reads





