<rss version="2.0"><channel><title>SecurePurdue - Advisory Alerts</title><link>http://www.purdue.edu/securepurdue/news/securePurdueRSS_5.xml</link><description>Collaborating to create the university of the future through IT. Service quality, powerful partnerships, and a great place to work.</description><pubDate>Wed, 25 Aug 2010 09:28:24 -0400</pubDate><generator>Cascade Server</generator><webMaster>itap@purdue.edu</webMaster><item><title>Phishing Email Alert: Important Notification - Purdue Career Account Access</title><link>http://www.purdue.edu/securepurdue/news/2013/advisory-phishing-email-alert-important-notification---purdue-career-account-access.cfm</link><description>New spear phishing attempt targeting Purdue students, faculty, and staff.</description><pubDate>Tue, 07 May 2013 00:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/7a7273d1ac1e8c3501abdd25777bd9f3</guid></item><item><title>Phishing Email - "Your myMail Account is on Restriction"</title><link>http://www.purdue.edu/securepurdue/news/2013/phishing_your-mymail-account-is-on-restriction.cfm</link><description>There was recently a spear-phishing attempt that was sent out to Purdue users that attempted to trick them into logging into a fake myMail login page.</description><pubDate>Fri, 19 Apr 2013 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/22d33c47ac1e8c3600ea72119ee5b679</guid></item><item><title>Phishing Email Alert: **{Suspension Of Your purdue.edu Account}**</title><link>http://www.purdue.edu/securepurdue/news/2013/phishing-email-alert-suspension-of-your-purdue.edu-account1.cfm</link><description>New spear phishing attempt targeting Purdue students, faculty, and staff.</description><pubDate>Sun, 27 Jan 2013 13:00:00 -0500</pubDate><guid>http://www.purdue.edu/securepurdue/7d39a1bbac1e8c3501b1ce68da9d830b</guid></item><item><title> Phishing Email Alert: [Your Webmail Account is on Restriction]</title><link>http://www.purdue.edu/securepurdue/news/2013/advisory - phishingemailalert-yourwebmailaccountisonrestriction.cfm</link><description>A spear-phishing attempt is circulating targeting Purdue users.</description><pubDate>Thu, 24 Jan 2013 15:36:00 -0500</pubDate><guid>http://www.purdue.edu/securepurdue/6e7a9f8dac1e8c36011199f02b766ce4</guid></item><item><title>(UPDATED 1/14) Java 7 Zero Day Vulnerability</title><link>http://www.purdue.edu/securepurdue/news/2013/java-7-zero-day-vulnerability.cfm</link><description>On January 10, 2013, security researchers reported an unpatched vulnerability in Oracle Java 1.7u10.</description><pubDate>Fri, 11 Jan 2013 01:00:00 -0500</pubDate><guid>http://www.purdue.edu/securepurdue/2bba0f7eac1e8c3501ba1c47e7430cec</guid></item><item><title>Java Zero-Day Patched</title><link>http://www.purdue.edu/securepurdue/news/2010/java-zero-day-patched.cfm</link><description>Sun Java vulnerability caused by an input handling error that can be exploited to execute Java based programs has been reported.
NOTE: Patch Available  </description><pubDate>Fri, 16 Apr 2010 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c2b0e7c80d2073500284206b1f1a44a</guid></item><item><title>Microsoft Server Message Block (SMB) Vulnerability allows for Remote Code Execution</title><link>http://www.purdue.edu/securepurdue/news/2009/microsoft-server-message-block-smb-vulnerability-allows-for-remote-code-execution.cfm</link><description>Update 2: Microsoft has released a "Fix-it" tool to automatically disable the SMBv2 service, which is presently the only known mitigation technique other than implementing firewall rules to block SMB traffic.</description><pubDate>Fri, 02 Oct 2009 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c34e83580d207350028420640f170f9</guid></item><item><title>Microsoft Office Web Components ActiveX Remote Code Execution Vulnerability</title><link>http://www.purdue.edu/securepurdue/news/2009/microsoft-office-web-components-activex-remote-code-execution-vulnerability.cfm</link><description>The Microsoft Office Web Components ActiveX control used by Internet Explorer contains a vulnerability that when exploited will allow an attacker to gain rights of the local user and allow remote code execution.</description><pubDate>Mon, 13 Jul 2009 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c36c66e80d2073500284206beed4933</guid></item><item><title>Critical Unpatched Internet Explorer Issue</title><link>http://www.purdue.edu/securepurdue/news/2008/critical-unpatched-internet-explorer-issue.cfm</link><description>An unpatched vulnerability exists in Internet Explorer 7 which may allow
an attacker to compromise a user's system simply by having the user
browse to a specially crafted web page. User's should be EXTREMELY
cautious while browsing the web with IE7 before a patch is released and
downloaded, and it is suggested that an alternate web browser be used.
This exploit has already been seen in active use in the the wild.</description><pubDate>Fri, 12 Dec 2008 01:00:00 -0500</pubDate><guid>http://www.purdue.edu/securepurdue/5c39fd8a80d2073500284206976df4b5</guid></item><item><title>Phishing Emails Threatening Internet Service Disconnection Carry Virus</title><link>http://www.purdue.edu/securepurdue/news/2008/phishing-emails-threatening-internet-service-disconnection-carry-virus.cfm</link><description>This email has been reported by numerous users of Purdue email systems. In some cases it has been reported that the .exe file contained in the zip file attachment named "user-EA49943X-activities.zip" has propagated automatically to c:\temp\escan\user-EA49943X-activities.zip\user-EA49943X-activities.exe where a virus scanner had flagged its presence. It is unknown by what mechanism this file was unzipped as none of the users reported clicking on or opening the email.</description><pubDate>Wed, 17 Sep 2008 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c3bc7e480d20735002842069de662cd</guid></item><item><title>Critical SSH Issue Involving Education and Research Institutions</title><link>http://www.purdue.edu/securepurdue/news/2008/critical-ssh-issue-involving-education-and-research-institutions.cfm</link><description>Starting in March of this year, a large number of research and education
systems have been compromised using stolen SSH keys.  The keys are used
to gain system access as an unprivileged user, and then local kernel
exploits are used to gain administrative access and install a rootkit
and gather more SSH keys.</description><pubDate>Tue, 26 Aug 2008 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c3ca66a80d207350028420682a22d3e</guid></item><item><title>Multiple reports of attempted and successful SQL injection attacks against campus web sites.</title><link>http://www.purdue.edu/securepurdue/news/2008/multiple-reports-of-attempted-and-successful-sql-injection-attacks-against-campus-web-sites..cfm</link><description>Multiple reports of attempted and successful SQL injection attacks against campus web sites.</description><pubDate>Fri, 18 Jul 2008 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c3d9bf480d20735002842064c16e1bc</guid></item><item><title>Adobe Acrobat and Reader Vulnerability affects Windows and Macs</title><link>http://www.purdue.edu/securepurdue/news/2008/adobe-acrobat-and-reader-vulnerability-affects-windows-and-macs.cfm</link><description>Adobe has reported a critical vulnerability in Acrobat and Reader.  The vulnerability could allow a malicious user to crash an affected machine to gain full access.  Most versions are affected.</description><pubDate>Mon, 30 Jun 2008 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c3e65e280d2073500284206b51196f8</guid></item><item><title>Multiple Xserver and XInput Vulnerabilities</title><link>http://www.purdue.edu/securepurdue/news/2008/multiple-xserver-and-xinput-vulnerabilities.cfm</link><description>Multiple vulnerabilities have been discovered in the server code of the X window system, which can cause an assortment of overflows.  Local exploitation of these overflows cause the X server to crash or allow the execution of arbitrary code in certain situations.</description><pubDate>Wed, 23 Jan 2008 01:00:00 -0500</pubDate><guid>http://www.purdue.edu/securepurdue/5c3f38b080d20735002842064a814065</guid></item><item><title>Critical Vulnerabilities In Adobe Flash Content May Lead to Cross-Site Scripting (XSS) Attacks</title><link>http://www.purdue.edu/securepurdue/news/2008/critical-vulnerabilities-in-adobe-flash-content-may-lead-to-cross-site-scripting-xss-attacks.cfm</link><description>Critical vulnerabilities in Adobe Flash content have been found which leave potentially hundreds of thousands of websites and a considerable percentage of major Internet sites susceptible to Cross-Site Scripting (XSS) attacks that would allow malicious individuals to steal personal details of visitors.</description><pubDate>Mon, 14 Jan 2008 01:00:00 -0500</pubDate><guid>http://www.purdue.edu/securepurdue/5c402bfa80d207350028420682892e52</guid></item><item><title>Adobe Flash Player: Multiple Vulnerabilities</title><link>http://www.purdue.edu/securepurdue/news/2007/adobe-flash-player-multiple-vulnerabilities.cfm</link><description>Adobe Flash Player and Flash Plugin have been found to have multiple
vulnerabilities which could allow an attacker to remotely execute code
on a vulnerable system, obtain sensitive information via browser
keystrokes, and allow cross-site request forgery.  These
vulnerabilities affect all users of Adobe Flash Player regardless of
platform (Win, Mac, Solaris, and Linux).  A new version that addresses
the security issues has been released by Adobe.</description><pubDate>Tue, 17 Jul 2007 01:00:00 -0400</pubDate><guid>http://www.purdue.edu/securepurdue/5c41746580d2073500284206589b9ccb</guid></item></channel></rss>