<?xml version="1.0" encoding="ISO-8859-1" ?> 
<rss version="2.0">









<channel>
<title>KU IT Security Alerts</title>
<link>http://www.security.ku.edu</link>
<description>
Welcome to the information technology security web site for The University of Kansas-Lawrence campus. This site exists to provide the KU community with tools and resources to maintain the security of information and the technology we use to manage it.
</description>
<language>en-us</language>
<copyright>Copyright @ 2002-2004 University of Kansas</copyright>
<lastBuildDate>Mon, 6 Oct 2008 17:36:01 CDT</lastBuildDate>
<category>Alerts</category>
<managingEditor>itsec@ku.edu</managingEditor>
<webMaster>itsec@ku.edu</webMaster>
<ttl>45</ttl>
<image>
<title>Alerts</title>
<url>http://mockingbird.cc.ku.edu/images/rss_alerts.gif</url>
<link>http://www.security.ku.edu</link>
</image>



<item>
<title>PATCH NOW: Java updates for Mac OS X</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=69</link>
<description>Apple has released critical security updates for Java for Mac OS X and Mac OS X Server.</description><pubDate>Mon, 15 Sep 2008 08:59:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=69</guid>
</item>

<item>
<title>Sophos Anti-Virus 7.6 update will require reboot</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=68</link>
<description>The installation of Sophos Anti-Virus 7.6 via Sophos AutoUpdate will require a reboot.</description><pubDate>Fri, 05 Sep 2008 12:35:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=68</guid>
</item>

<item>
<title>Messages flagged with [VIRUS] -- FYI</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=67</link>
<description>E-mails are arriving in users' inboxes with subject lines flagged with [VIRUS] and a message body indicating a virus file was found and removed from the message.</description><pubDate>Thu, 28 Aug 2008 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=67</guid>
</item>

<item>
<title>Fake e-card e-mail notifications contain links to malware</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=66</link>
<description>The IT Security Office has received multiple reports of e-card notification e-mails which contain links to malicious software.</description><pubDate>Thu, 14 Aug 2008 14:17:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=66</guid>
</item>

<item>
<title>Fake news alerts from multiple sources contain links to malware</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=65</link>
<description>The IT Security Office has received multiple reports of spam claiming to be a "news alert" from multiple sources. Links within these e-mails take the recipient to pages which attempt to download malware onto the victim computer.</description><pubDate>Wed, 13 Aug 2008 14:07:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=65</guid>
</item>

<item>
<title>The KU IT Security Office has received reports of phishing messages coming from "KU Online Services"</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=64</link>
<description>Large numbers of phishing messages from "KU Online Services" with a from address of "onlineservices@ku.edu" and a non-KU reply-to address have been reported to the IT Security Office.</description><pubDate>Sat, 02 Aug 2008 10:16:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=64</guid>
</item>

<item>
<title>Vishing attacks on residents of Lawrence and surrounding areas</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=63</link>
<description>The IT Security Office has received numerous reports of "vishing" phone calls to KU students, faculty, staff, and other residents of Lawrence and surrounding areas.</description><pubDate>Wed, 02 Jul 2008 16:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=63</guid>
</item>

<item>
<title>Mac OS X 10.4 and 10.5 Privilege Escalation via ARDAgent</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=62</link>
<description>In Mac OS X 10.4 and 10.5, the Remote Management agent application used by Apple Remote Desktop can be used to execute code as a superuser.</description><pubDate>Thu, 19 Jun 2008 17:18:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=62</guid>
</item>

<item>
<title>READ THIS NOW! KU Credit Union phishing messages from ku.edu accounts</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=61</link>
<description>KU students, faculty, and staff are receiving phishing messages that advise them to click links, reply to the message, or call a telphone number and disclose sensitive personal information.</description><pubDate>Mon, 02 Jun 2008 11:25:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=61</guid>
</item>

<item>
<title>Severe vulnerabilities in Safari</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=60</link>
<description>The Safari web browser contains three serious vulnerabilities that have not yet been patched by Apple.</description><pubDate>Fri, 30 May 2008 13:23:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=60</guid>
</item>

<item>
<title>New Flash vulnerabilities -- exploits in the wild</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=59</link>
<description>Symantec has discovered an unpatched flaw in the current version of the Adobe Flash Player which is currently being exploited.</description><pubDate>Fri, 30 May 2008 09:56:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=59</guid>
</item>

<item>
<title>Fraudulent KU Credit Union e-mails</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=54</link>
<description>ITSO has received multiple reports of fraudulent KU Credit Union e-mail messages advising the recipient to call a telephone number listed in the message.</description><pubDate>Fri, 09 May 2008 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=54</guid>
</item>

<item>
<title>PATCH NOW: Adobe Flash Player Vulnerabilities</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=58</link>
<description>The Adobe Flash Player contains vulnerabilities that allow an attacker to use a maliciously crafted SWF file to take complete control over a vulnerable system.</description><pubDate>Wed, 09 Apr 2008 09:25:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=58</guid>
</item>

<item>
<title>Phishing e-mails from helpdesk@ku.edu</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=57</link>
<description>The IT Security Office has received reports of phishing e-mails purporting to come from helpdesk@ku.edu or "KU.EDU SUPPORT TEAM"</description><pubDate>Mon, 07 Apr 2008 12:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=57</guid>
</item>

<item>
<title>PATCH NOW: Apple Security Update 2008-002</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=56</link>
<description>Apple Security Update 2008-002 contains critical updates for multiple vulnerabilities in the Mac OS X and Mac OS X Server operating systems as well as software packages installed on those systems.</description><pubDate>Wed, 19 Mar 2008 14:35:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=56</guid>
</item>

<item>
<title>"Death Threat" e-mails reported</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=55</link>
<description>Members of the University community have reported e-mails containing death threats to the IT Security Office</description><pubDate>Wed, 27 Feb 2008 10:43:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=55</guid>
</item>

<item>
<title>Apple QuickTime RTSP Content-Type header stack buffer overflow</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=53</link>
<description>Apple QuickTime contains a stack buffer overflow vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service condition.</description><pubDate>Tue, 27 Nov 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=53</guid>
</item>

<item>
<title>OSX/RSPlug-A installs malicious DNS entries on Mac OS X 10.4, 10.5 systems</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=52</link>
<description>A malicious Trojan Horse has been found on several web sites, claiming to install a video codec necessary to view free videos on Mac OS X computers.</description><pubDate>Thu, 01 Nov 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=52</guid>
</item>

<item>
<title>Spoofed e-mails from FTC contain malware</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=51</link>
<description>A bogus email is circulating that says it is from the Federal Trade Commission, referencing a "complaint" filed with the FTC against the email?s recipient.</description><pubDate>Wed, 31 Oct 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=51</guid>
</item>

<item>
<title>Phishing e-mails instruct users to call a phone number</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=50</link>
<description>ITSO has received reports that identity thieves are using phishing e-mails to entice users to dial a US-based telephone number and provide sensitive personal information due to "irregular activity" on a bank account.</description><pubDate>Mon, 29 Oct 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=50</guid>
</item>

<item>
<title>RealPlayer ierpplug.dll ActiveX Control Playlist Name Stack Buffer Overflow Vulnerability</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=49</link>
<description>RealPlayer is vulnerable to a stack-based buffer-overflow vulnerability involving an ActiveX object in the RealPlayer component ierpplug.dll.</description><pubDate>Tue, 23 Oct 2007 10:25:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=49</guid>
</item>

<item>
<title>Adobe acknowledges Acrobat reader vulnerability, publishes workaround</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=48</link>
<description>Adobe has acknowledged a flaw involving mailto: links in Acrobat Reader and has released a workaround.
</description><pubDate>Fri, 12 Oct 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=48</guid>
</item>

<item>
<title>Novell client buffer overflow vulnerabilities</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=47</link>
<description>The Novell client is vulnerable to multiple buffer-overflow exploits.  The application fails to bounds check user supplied data before copying it into a buffer that is too small.</description><pubDate>Wed, 05 Sep 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=47</guid>
</item>

<item>
<title>Storm worm mutation/"New User" e-mails</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=46</link>
<description>A new mutation of the Storm worm is sending messages claiming to be "new member/new user" e-mails from various websites, clubs, message boards, etc.</description><pubDate>Tue, 21 Aug 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=46</guid>
</item>

<item>
<title>BIND 9 DNS Cache Poisoning vulnerability</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=45</link>
<description>Certain versions of BIND 9 that are being used in a caching server configuration are vulnerabile to a cache poisoning exploit.</description><pubDate>Thu, 26 Jul 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=45</guid>
</item>

<item>
<title>Fake IRS refund e-mail messages</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=44</link>
<description>Phishers are sending messages that appear to come from the IRS in an attempt to convince users to provide bank account numbers and other personal information.</description><pubDate>Mon, 16 Jul 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=44</guid>
</item>

<item>
<title>Fake Microsoft patch/"postcard from a family member" messages</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=43</link>
<description>The IT Security Office is receiving a large volume of reports of fake e-mail messages that contain links to malicious payloads.  Some appear to be from Microsoft while others claim to be a postcard from a friend.</description><pubDate>Thu, 28 Jun 2007 12:17:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=43</guid>
</item>

<item>
<title>Vulnerability in YaBB forum software allows privilege escalation</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=42</link>
<description>Remote exploitation of an input validation error allows malicious users to create an account with admin privileges.</description><pubDate>Wed, 13 Jun 2007 09:45:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=42</guid>
</item>

<item>
<title>"Hit-highlighting" vulnerability in Microsoft IIS 5.x</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=41</link>
<description>The "hit-highlighting" feature in IIS 5.0 can allow unauthenticated users access to documents to which they would not normally be allowed access.</description><pubDate>Mon, 04 Jun 2007 14:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=41</guid>
</item>

<item>
<title>Phishers attempting to take advantage of the VA Tech tragedy</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=40</link>
<description>Phishers are registering domain names in order to steal from people wishing to donate to the victims of the shootings at Virginia Tech</description><pubDate>Wed, 18 Apr 2007 09:40:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=40</guid>
</item>

<item>
<title>McAfee VirusScan On-AccessScanner Long Unicode File Name Buffer Overflow</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=39</link>
<description>Remote exploitation of a buffer overflow vulnerability in McAfee's VirusScan Antivirus application allows attackers to disable the On-Access scanner or potentially execute arbitrary code with SYSTEM privileges.</description><pubDate>Wed, 18 Apr 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=39</guid>
</item>

<item>
<title>Vulnerability in RPC on Windows DNS Server Could Allow Remote Code Execution</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=38</link>
<description>A buffer overflow in the the Remote Procedure Call (RPC) management interface used by the Microsoft Windows Domain Name Service (DNS) service is actively being exploited. This vulnerability may allow a remote attacker to execute arbitrary code with SYSTEM privileges.</description><pubDate>Mon, 16 Apr 2007 15:03:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=38</guid>
</item>

<item>
<title>Microsoft Windows ANI header stack buffer overflow</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=37</link>
<description>An unpatched buffer overflow vulnerability in the way Microsoft Windows handles animated cursor files is actively being exploited.</description><pubDate>Mon, 02 Apr 2007 13:04:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=37</guid>
</item>

<item>
<title>Spoofed messages from admin@microsoft.com</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=36</link>
<description>Spoofed e-mail messages from "admin@microsoft.com" contain a malicious payload</description><pubDate>Fri, 30 Mar 2007 00:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=36</guid>
</item>

<item>
<title>Fraudulent Dell order confirmation messages</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=35</link>
<description>Fraudulent Dell order confirmation e-mails contain links to malicious code.</description><pubDate>Fri, 23 Mar 2007 12:52:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=35</guid>
</item>

<item>
<title>Malicious javascripts could alter DNS settings on routers with default passwords</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=34</link>
<description>Approximately half of all router owners have not changed the default password on their equipment.</description><pubDate>Tue, 20 Feb 2007 16:22:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=34</guid>
</item>

<item>
<title>New Sophos Anti-Virus Clients are available</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=33</link>
<description>KU has released new Sophos Anti-Virus clients for Windows and MacOSx platforms</description><pubDate>Tue, 16 Jan 2007 10:25:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=33</guid>
</item>

<item>
<title>Critical Microsoft Security Alert</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=31</link>
<description>Vulnerability in Server Service Could Allow Remote Code Execution (Microsoft Security Bulletin MS06-040)
</description><pubDate>Thu, 10 Aug 2006 11:28:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=31</guid>
</item>

<item>
<title>Adobe Acrobat Affected by Vulnerabilities</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=30</link>
<description>The popular Adobe Acrobat PDF Reader has been shown to have a serious security vulnerability</description><pubDate>Tue, 18 Jul 2006 16:10:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=30</guid>
</item>

<item>
<title>Apple Mac Products Affected by Multiple Vulnerabilities</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=29</link>
<description>Apple has released a patch to address a number of security issues in various Apple products.</description><pubDate>Fri, 12 May 2006 12:00:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=29</guid>
</item>

<item>
<title>Virus Alert: Is the FBI/CIA sending me email?</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=28</link>
<description>Latest email virus alert uses ZIP file attachments and may mention CIA and/or FBI as source</description><pubDate>Mon, 21 Nov 2005 16:30:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=28</guid>
</item>

<item>
<title>New Microsoft Exploits require immediate patch application</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=27</link>
<description>Exploits are in the wild for recently released Microsoft Windows OS patches.</description><pubDate>Mon, 17 Oct 2005 08:45:12 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=27</guid>
</item>

<item>
<title>Donations for Katrina victims - be careful of scams</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=26</link>
<description>Multiple fake donation websites and email scams are popping up that take advantage of people seeking to donate money to Hurricane Katrina relief.
</description><pubDate>Thu, 01 Sep 2005 07:49:42 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=26</guid>
</item>

<item>
<title>UPDATED: KU implements a new Password Policy</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=22</link>
<description>Users may be prompted to change their passwords. Passwords will be audited to ensure compliance with the new Password Policy as well as being of sufficient strength.
On Sept 15th 2005 access to resources using non-strong passwords will be disallowed and redirection to the password change page will occur.
</description><pubDate>Tue, 30 Aug 2005 11:12:10 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=22</guid>
</item>

<item>
<title>New virus varient exploting the recent Microsoft Plug and Play Vulnerability</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=24</link>
<description>Virus writers have created a worm that spreads using a Microsoft Plug-and-Play vulnerability disclosed only last week.</description><pubDate>Mon, 15 Aug 2005 08:12:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=24</guid>
</item>

<item>
<title>SOBER-Q/P Virus sending billions of messages worldwide</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=21</link>
<description>New variants of the Sober virus send enormous amounts of email messages in German.</description><pubDate>Mon, 16 May 2005 10:10:32 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=21</guid>
</item>

<item>
<title>Multiple Vulnerabilities in Microsoft Windows Components
</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=20</link>
<description>Microsoft has released a series of patches for the April 2005 patch cycle.  Many are critical and must be applied to maintain a secure computer.</description><pubDate>Tue, 12 Apr 2005 07:12:12 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=20</guid>
</item>

<item>
<title>Instant Messaging viruses increase by 50 per cent a month</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=18</link>
<description>F-Secure detects more than 200 instant messaging worms, 700 IM trojans</description><pubDate>Thu, 17 Mar 2005 16:17:10 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=18</guid>
</item>

<item>
<title>Firefox update fixes multiple vulnerabilities</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=17</link>
<description>The makers of the popular Firefox browser have released an important update to the Firefox web browser.</description><pubDate>Sun, 06 Mar 2005 14:43:15 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=17</guid>
</item>

<item>
<title>Multiple Vulnerabilities in Microsoft Windows Icon and Cursor Processing</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=15</link>
<description>Microsoft Windows contains multiple vulnerabilities in the way that it handles cursor and icon files. Exploit is in the wild.</description><pubDate>Thu, 13 Jan 2005 11:22:32 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=15</guid>
</item>

<item>
<title>Windows XP Services Pack 2 Update</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=14</link>
<description>Starting on January 3rd, Service Pack 2 will be enabled on the central campus SUS Server (Yardbird) and will be automatically installed on machines that are set to point to Yardbird for operating system updates</description><pubDate>Thu, 30 Dec 2004 15:31:19 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=14</guid>
</item>

<item>
<title>Multiple Critical Vulnerabilites in Apple Mac OS X</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=13</link>
<description>Apple has issued a security update for Mac OS X, which fixes various vulnerabilities.</description><pubDate>Thu, 09 Dec 2004 11:16:32 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=13</guid>
</item>

<item>
<title>Multi-Platform/Browser Java Vulnerability</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=12</link>
<description>Issue with Sun's Java Virtual Machine (VM) in versions less than 1.4.2_06 that allows access, via JavaScript, to portions of a browser's Java plug-in that should NOT be available to untrusted applets</description><pubDate>Wed, 24 Nov 2004 10:49:01 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=12</guid>
</item>

<item>
<title>Bofra-B worm poses as PayPal credit card purchase</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=11</link>
<description>New virus imitates Paypal or personal email.</description><pubDate>Tue, 09 Nov 2004 11:33:00 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=11</guid>
</item>

<item>
<title>Email Scams on the Rise Worldwide</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=10</link>
<description>Email scams are increasing at an alarming rate</description><pubDate>Sat, 30 Oct 2004 19:21:02 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=10</guid>
</item>

<item>
<title>New Virus Threat (High)</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=9</link>
<description>A new variant of the Bagle email worm is spreading rapidly across the internet today</description><pubDate>Sat, 30 Oct 2004 05:12:12 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=9</guid>
</item>

<item>
<title>Multiple Vulnerabilities in Microsoft Windows, Internet Explorer, and Excel</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=8</link>
<description>Microsoft has released security updates for a number of products, including Windows, Internet Explorer, and Excel</description><pubDate>Tue, 12 Oct 2004 19:15:10 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=8</guid>
</item>

<item>
<title>Multiple Vulnerabilities in Mozilla Products</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=4</link>
<description>Several vulnerabilities exist in the Mozilla web browser and derived products, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system.</description><pubDate>Mon, 04 Oct 2004 20:05:12 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=4</guid>
</item>

<item>
<title>AOL Instant Messenger vulnerable to buffer overflow</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=5</link>
<description>A vulnerability in the AOL Instant Messenger (AIM) client could allow a remote attacker to execute arbitrary code on a victim system</description><pubDate>Mon, 20 Sep 2004 12:12:51 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=5</guid>
</item>

<item>
<title>Microsoft Windows JPEG component buffer overflow</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=3</link>
<description>Microsoft's Graphic Device Interface Plus (GDI+) contains a vulnerability in the processing of JPEG images. This vulnerability may allow attackers to remotely execute arbitrary code on the affected system.</description><pubDate>Thu, 16 Sep 2004 05:10:12 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=3</guid>
</item>

<item>
<title>Increased IRC Botnet Activity on Campus</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=2</link>
<description>There have been a number of advanced variants of the GAOBOT/AGOBOT/PHATBOT worm released into the wild in the past weeks.  We have seen a significant increase in IRC traffic and RPC scans from on campus hosts.</description><pubDate>Sat, 28 Aug 2004 10:03:14 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=2</guid>
</item>

<item>
<title>Increase in Suspicious Activity</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=1</link>
<description>We are receiving reports of a possible massive attack on the Internet tomorrow</description><pubDate>Wed, 25 Aug 2004 12:55:39 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=1</guid>
</item>

<item>
<title>Critical Vulnerabilities in Microsoft Windows</title>
<link>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=6</link>
<description>Microsoft Internet Explorer contains three vulnerabilities that may allow arbitrary code to be executed</description><pubDate>Sun, 01 Aug 2004 12:42:19 CDT</pubDate>
<guid>http://www.security.ku.edu/alerts/alert-viewer.jsp?id=6</guid>
</item>

        
        
</channel>
</rss>
