<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.us-cert.gov/ncas/current-activity.xml" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title> US-CERT Current Activity</title>
    <link>https://www.us-cert.gov/ncas/current-activity.xml</link>
    <description>A regularly updated summary of the most frequent, high-impact security incidents currently being reported to the US-CERT.</description>
    <language>en</language>
     <atom:link href="https://www.us-cert.gov/ncas/current-activity.xml" rel="self" type="application/rss+xml" />
    
<item>
	<title>Apple Releases Multiple Security Updates</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/24/Apple-Releases-Multiple-Security-Updates</link>
	<description><![CDATA[
		Original release date: April 24, 2018<br />
	
		<p>Apple has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.</p><p>NCCIC encourages users and administrators to review Apple security pages for the following products and apply the necessary updates:</p><ul><li><a href="https://support.apple.com/en-us/HT208741">Safari 11.1</a></li><li><a href="https://support.apple.com/en-us/HT208742">macOS High Sierra 10.13.4</a></li><li><a href="https://support.apple.com/en-us/HT208743">iOS 11.3.1</a></li></ul>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Tue, 24 Apr 2018 20:30:56 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10856 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Drupal Releases Security Updates</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/18/Drupal-Releases-Security-Updates</link>
	<description><![CDATA[
		Original release date: April 18, 2018<br />
	
		<p>Drupal has released updates addressing a vulnerability in Drupal 8 and 7. A remote attacker could exploit this vulnerability to gain access to sensitive information.</p><p>NCCIC encourages users and administrators to review the <a href="https://www.drupal.org/sa-core-2018-003">Drupal Security Advisory</a> for additional information and apply the necessary updates.</p>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Thu, 19 Apr 2018 00:23:26 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10848 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Cisco Releases Security Updates for Multiple Products</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/18/Cisco-Releases-Security-Updates-Multiple-Products</link>
	<description><![CDATA[
		Original release date: April 18, 2018<br />
	
		<p>Cisco has released several updates to address vulnerabilities affecting multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.</p><p>NCCIC encourages users and administrators to review the following Cisco Security Advisories and apply the necessary updates:</p><ul><li>Cisco WebEx Clients Remote Code Execution Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-wbs">cisco-sa-20180418-wbs</a></li><li>Cisco UCS Director Virtual Machine Information Disclosure Vulnerability for End User Portal <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-uscd">cisco-sa-20180418-uscd</a></li><li>Cisco StarOS Interface Forwarding Denial of Service Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-staros">cisco-sa-20180418-staros</a></li><li>Cisco IOS XR Software UDP Broadcast Forwarding Denial of Service Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-iosxr">cisco-sa-20180418-iosxr</a></li><li>Cisco Firepower Detection Engine Secure Sockets Layer Denial of Service Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fpsnort">cisco-sa-20180418-fpsnort</a></li><li>Cisco Firepower 2100 Series Security Appliances IP Fragmentation Denial of Service Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fp2100">cisco-sa-20180418-fp2100</a></li><li>Cisco ASA Software, FTD Software, and AnyConnect Secure Mobility Client SAML Authentication Session Fixation Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asaanyconnect">cisco-sa-20180418-asaanyconnect</a></li><li>Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect">cisco-sa-20180418-asa_inspect</a></li><li>Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3">cisco-sa-20180418-asa3</a></li><li>Cisco Adaptive Security Appliance Flow Creation Denial of Service Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa2">cisco-sa-20180418-asa2</a></li><li>Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa1">cisco-sa-20180418-asa1</a></li></ul>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Wed, 18 Apr 2018 20:19:34 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10845 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Google Releases Security Update for Chrome</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/18/Google-Releases-Security-Update-Chrome</link>
	<description><![CDATA[
		Original release date: April 18, 2018<br />
	
		<p>Google has released Chrome version 66.0.3359.117 for Windows, Mac, and Linux. This version addresses vulnerabilities that a remote attacker could exploit to take control of an affected system.</p><p>NCCIC encourages users and administrators to review the <a href="https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html">Chrome Releases</a> page and apply the necessary update.</p>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Wed, 18 Apr 2018 16:59:01 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10843 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Oracle Releases April 2018 Security Bulletin</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/17/Oracle-Releases-April-2018-Security-Bulletin</link>
	<description><![CDATA[
		Original release date: April 17, 2018<br />
	
		<p>Oracle has released its Critical Patch Update for April 2018 to address 254 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.</p><p>NCCIC encourages users and administrators to review the Oracle <a href="http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html">April 2018 Critical Patch Update</a> and apply the necessary updates.</p>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Tue, 17 Apr 2018 22:11:30 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10841 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Russian Malicious Cyber Activity</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/16/Russian-Malicious-Cyber-Activity</link>
	<description><![CDATA[
		Original release date: April 16, 2018<br />
	
		<p>The Department of Homeland Security (DHS), Federal Bureau of Investigation (FBI), and the United Kingdom’s (UK) National Cyber Security Centre (NCSC) released a joint Technical Alert (TA) about malicious cyber activity carried out by the Russian Government. The U.S. Government refers to malicious cyber activity by the Russian government as GRIZZLY STEPPE.</p><p>NCCIC encourages users and administrators to review the <a href="https://www.us-cert.gov/GRIZZLY-STEPPE-Russian-Malicious-Cyber-Activity">GRIZZLY STEPPE - Russian Malicious Cyber Activity page</a>, which links to TA18-106A - Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices, for more information.</p>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Mon, 16 Apr 2018 16:01:54 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10833 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>VMware Releases Security Updates </title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/13/VMware-Releases-Security-Updates</link>
	<description><![CDATA[
		Original release date: April 13, 2018<br />
	
		<p>VMware has released security updates to address a vulnerability in vRealize Automation. An attacker could exploit this vulnerability to take control of an affected system.</p><p>NCCIC encourages users and administrators to review the VMware Security Advisory <a href="https://www.vmware.com/security/advisories/VMSA-2018-0009.html">VMSA-2018-0009</a> and apply the necessary updates.</p>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Fri, 13 Apr 2018 17:24:39 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10827 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Juniper Networks Releases Security Updates</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/12/Juniper-Networks-Releases-Security-Updates</link>
	<description><![CDATA[
		Original release date: April 12, 2018<br />
	
		<p>Juniper Networks has released security updates to address vulnerabilities affecting multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.</p><p>NCCIC encourages users and administrators to review the following Juniper Security Advisories and apply necessary updates:</p><ul><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10844&amp;cat=SIRT_1&amp;actp=LIST">Junos OS</a>: Kernel crash upon receipt of crafted CLNP packets (CVE-2018-0016)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10845&amp;cat=SIRT_1&amp;actp=LIST">SRX Series</a>: Denial-of-service vulnerability in flowd daemon on devices configured with NAT-PT (CVE-2018-0017)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10846&amp;cat=SIRT_1&amp;actp=LIST">SRX Series</a>: Crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies (CVE-2018-0018)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10847&amp;cat=SIRT_1&amp;actp=LIST">Junos</a>: Denial-of-service vulnerability in SNMP MIB-II subagent daemon (mib2d) (CVE-2018-0019)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10848&amp;cat=SIRT_1&amp;actp=LIST">Junos OS</a>: rpd daemon cores due to malformed BGP UPDATE packet (CVE-2018-0020)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10849&amp;cat=SIRT_1&amp;actp=LIST">Steel-Belted Radius Carrier</a>: Eclipse Jetty information disclosure vulnerability (CVE-2015-2080)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10850&amp;cat=SIRT_1&amp;actp=LIST">NorthStar</a>: Return of Bleichenbacher’s Oracle Threat (ROBOT) RSA SSL attack (CVE-2017-1000385)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10851&amp;cat=SIRT_1&amp;actp=LIST">OpenSSL</a>: Multiple vulnerabilities resolved in OpenSSL</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10852&amp;cat=SIRT_1&amp;actp=LIST">Junos OS</a>: Multiple vulnerabilities in stunnel 5.38</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10853&amp;cat=SIRT_1&amp;actp=LIST">NSM Appliance</a>: Multiple vulnerabilities resolved in CentOS 6.5-based 2012.2R12 release</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10854&amp;cat=SIRT_1&amp;actp=LIST">Junos OS</a>: Short MacSec keys may allow man-in-the-middle attacks</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10855&amp;cat=SIRT_1&amp;actp=LIST">Junos OS</a>: Mbuf leak due to processing MPLS packets in VPLS networks (CVE-2018-0022)</li><li><a href="https://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10856&amp;cat=SIRT_1&amp;actp=LIST">Junos Snapshot Administrator (JSNAPy)</a> world writeable default configuration file permission (CVE-2018-0023)</li></ul>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Fri, 13 Apr 2018 00:34:11 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10825 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Microsoft Releases April 2018 Security Updates</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/10/Microsoft-Releases-April-2018-Security-Updates</link>
	<description><![CDATA[
		Original release date: April 10, 2018<br />
	
		<p>Microsoft has released updates to address vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.</p><p>NCCIC encourages users and administrators to review Microsoft's April 2018 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/abf77563-8612-e811-a966-000d3a33a34d">Security Update Summary</a> and <a href="https://support.microsoft.com/en-us/help/20180410/security-update-deployment-information-april-10-2018">Deployment Information</a> and apply the necessary updates.</p>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Tue, 10 Apr 2018 20:10:58 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10811 at https://www.us-cert.gov</guid>
</item>

<item>
	<title>Adobe Releases Security Updates</title>
	<link>https://www.us-cert.gov/ncas/current-activity/2018/04/10/Adobe-Releases-Security-Updates</link>
	<description><![CDATA[
		Original release date: April 10, 2018<br />
	
		<p>Adobe has released security updates to address vulnerabilities in Adobe PhoneGap Push Plugin, Adobe Digital Editions, Adobe InDesign, Adobe Experience Manager, and Adobe Flash Player. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.  </p><p>NCCIC encourages users and administrators to review Adobe Security Bulletins <a href="https://helpx.adobe.com/security/products/phonegap/apsb18-15.html">APSB18-15</a>, <a href="https://helpx.adobe.com/security/products/Digital-Editions/apsb18-13.html">APSB18-13</a>, <a href="https://helpx.adobe.com/security/products/indesign/apsb18-11.html">APSB18-11</a>, <a href="https://helpx.adobe.com/security/products/experience-manager/apsb18-10.html">APSB18-10</a>, and <a href="https://helpx.adobe.com/security/products/flash-player/apsb18-08.html">APSB18-08</a>, and apply the necessary updates.</p>		
		<hr />
		<p>This product is provided subject to this <a href="http://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="http://www.us-cert.gov/privacy/">Privacy &amp; Use</a> policy.</p>		<br />
	]]>
	
	</description>
	 <pubDate>Tue, 10 Apr 2018 17:12:26 +0000</pubDate>
 <dc:creator>US-CERT</dc:creator>
 <guid isPermaLink="false">10809 at https://www.us-cert.gov</guid>
</item>
  </channel>
</rss>
