Threat Level: green Handler on Duty: Brad Duncan

SANS ISC Diaries by Keyword

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!


2011-04-10Raul SilesRecent security enhancements in web browsers (e.g. Google Chrome)
2011-03-23Johannes UllrichFirefox 4 Security Features


2015-08-07/a>Tony CarothersCritical Firefox Update Today
2014-10-14/a>Johannes UllrichUpdates for Firefox and Thunderbird.
2014-04-29/a>Russ McReeFirefox 29.0 & Thunderbird 24.5 released:
2014-03-19/a>Mark HofmanMozilla released updates for Firefox ( v 28.0), Thunderbird (v 24.4) and Firefox Extended Support Release (ESR) updates to 24.4.0 (Fixes include the issues highlighted at the pwn2own contest.)
2014-02-04/a>Johannes UllrichFirefox 27 Available
2013-11-02/a>Rick WannerProtecting Your Family's Computers
2013-08-07/a>Johannes UllrichFirefox 23 and Mixed Active Content
2013-06-25/a>Bojan ZdrnjaMozilla Firefox 22 released, fixes 14 security vulnerabilities, more info at
2013-05-14/a>Swa FrantzenFirefox & Thunderbird released
2013-04-03/a>Mark HofmanFirefox 20 and Thunderbird 17.0.5 updates
2013-02-19/a>Johannes UllrichFirefox 19 Release with various security fixes.
2013-02-06/a>Kevin ShorttFirefox updated to 18.02 ->
2013-01-15/a>Rob VandenBrinkWhen Disabling IE6 (or Java, or whatever) is not an Option...
2013-01-09/a>Rob VandenBrinkFirefox and Thunderbird Updates
2013-01-08/a>Richard PorterFirefox 18 Released, Security Fixes
2012-12-01/a>Guy BruneauFirefox 17.0.1 Bug Fixes -
2012-10-28/a>Tony CarothersFirefox 16.02 Released
2012-10-11/a>Rob VandenBrinkFirefox 16 / Thunderbird 16 updates
2012-08-28/a>Johannes UllrichFirefox 15 Released (includes silent future updates)
2012-07-17/a>Jim ClausingFirefox 14.0.1, Thunderbird 14.0 out - both claim security fixes, but release notes not updated yet with security details
2012-06-20/a>Raul SilesFirefox 13.0.1 Update
2012-06-06/a>Jim ClausingFirefox, Thunderbird, and Seamonkey Security Updates
2012-03-27/a>Johannes UllrichFirefox 3.6 EOL
2012-02-11/a>Mark HofmanYet another version of Firefox has been released. One security fix. More info can be found here:
2012-01-31/a>Russ McReeFirefox 10 and VMWare advisories and updates
2011-12-22/a>Johannes UllrichFirefox 9 Security Fixes
2011-12-21/a>Chris MohanFirefox 9 has been released patching known vulnerabilities
2011-11-08/a>Swa FrantzenFirefox 8.0 released
2011-09-30/a>Tony CarothersFirefox v. 7.0.1 Is Live
2011-09-27/a>Jason LamFirefox 3.6.23 security update is out and so is version 7 (time to break some add-on)
2011-09-06/a>Guy BruneauFirefox 6.0.2 released to removed trust to DigiNotar certificate authority
2011-08-31/a>Johannes UllrichFirefox/Thunderbird 6.0.1 released to blacklist bad DigiNotar SSL certificates
2011-08-16/a>Scott FendleyFirefox 3.6.20 Corrects Several Critical Vulnerabilities
2011-08-14/a>Guy BruneauFireCAT 2.0 Released
2011-07-13/a>Kevin ShorttFirefox Update 5.0.1 Available -
2011-06-21/a>Guy BruneauFirefox 5.0 is out with support Do Not Track on Multiple Platform -
2011-06-09/a>Richard PorterOne Browser to Rule them All?
2011-05-16/a>Jason LamFirefox 3.5 forced upgrade coming soon
2011-04-29/a>Guy BruneauFirefox, Thunderbird and SeaMonkey Security Updates
2011-04-10/a>Raul SilesRecent security enhancements in web browsers (e.g. Google Chrome)
2011-03-23/a>Johannes UllrichFirefox 4 Security Features
2011-03-23/a>Johannes UllrichFirefox 3 Updates and SSL Blacklist extension
2011-03-04/a>Mark HofmanAnd a new version of Firefox (thx all) hits the road, Version 3.6.15 more details here (and I agree it was a bit quick after 3.6.14)
2011-03-02/a>Chris MohanUpdates: Firefox 3.6.14/3.5.17, Thunderbird 3.1.8, Adobe Flash v10.2.152.32 & WireShark 1.4.4
2011-02-26/a>Rick WannerFirefox 4 Beta 12 released
2011-01-10/a>Manuel Humberto Santander PelaezVirusTotal VTzilla firefox/chrome plugin
2010-12-09/a>Mark HofmanFirefox version 3.6.13 is being pushed out, time to update (thanks Vincent). Thunderbird 3.1.7 and 3.0.11 can also be added to the list as well as SeaMonkey 2.0.11. - M
2010-11-15/a>Stephen HallMozilla Firefox 3.6.12 Remote Denial Of Service
2010-10-28/a>Rick WannerFirefox 3.6.12 available -
2010-10-26/a>Pedro BuenoFirefox news
2010-10-20/a>Jim ClausingFirefox 3.6.11 and 3.5.14 released, includes security updates ( )
2010-08-23/a>Manuel Humberto Santander PelaezFirefox plugins to perform penetration testing activities
2010-07-25/a>Rick WannerNew Firefox Version, 3.6.8
2010-07-25/a>Rick WannerMozilla advisory for Firefox...Upgrade to 3.6.8.
2010-07-23/a>Mark HofmanFirefox 3.6.8 is out. Yes it only seems like yesterday when you installed FF 3.6.7 (it was for me). The release notes say a stability issue has been fixed in this release.
2010-06-27/a>Jim ClausingFirefox 3.6.6 out - fixes issues with "crash protection"
2010-06-23/a>Scott FendleyMozilla Firefox Updates
2010-04-02/a>Guy BruneauFirefox 3.6.3 fix for CVE-2010-1121
2010-03-20/a>Scott FendleyFirefox 3.6.2 to be released March 30
2010-03-12/a>Mark HofmanFirefox 3.6 is being pushed out to users.
2010-01-21/a>Chris CarboniFirefox Upgrade Available
2010-01-06/a>Guy BruneauFirefox security and stability update for version 3.5.7 and 3.0.17 available for download
2009-12-17/a>Daniel Wesemannoverlay.xul is back
2009-12-16/a>Mark HofmanFirefox 3.5.6 is available, time to update.
2009-11-06/a>Mark HofmanA new version of Firefox (3.5.5) just became available. According to the release notes they are stability improvements.
2009-10-28/a>Johannes UllrichFirefox 3.5.4 released. Lots of security bug fixes. (thanks Gilbert!)
2009-10-17/a>Rick WannerMozilla disables Microsoft plug-ins?
2009-10-16/a>Adrien de BeaupreDisable MS09-054 patch, or Firefox Plugin?
2009-10-08/a>Johannes UllrichFirefox Plugin Collections
2009-09-10/a>Guy BruneauFirefox 3.5.3 and 3.0.14 has been released
2009-08-04/a>Mark HofmanFirefox Updates
2009-07-22/a>Chris CarboniFirefox 3.0.12 is Available
2009-07-19/a>Marcus SachsMozilla Comments on Firefox 3.5.1 issue
2009-07-17/a>Stephen HallFirefox 3.5.1 has been released
2009-07-14/a>Swa FrantzenFirefox new exploit
2009-06-30/a>Chris CarboniFirefox 3.5 is available
2009-06-11/a>Rick WannerFirefox 3.0.11 is available
2009-03-27/a>David GoldsmithFirefox 3.0.8 Released
2009-03-19/a>Mark HofmanBrowsers Tumble at CanSecWest
2009-03-04/a>Deborah HaleFirefox Releases version 3.0.7
2009-02-04/a>Daniel WesemannFirefox 3.0.6
2008-12-17/a>donald smithFirefox 3.0.5 fixes several security issues.
2008-11-13/a>Jim ClausingNew Firefoxen out
2008-09-26/a>Patrick NolanFirefox v2.0.0.17 and Thunderbird v2.0.0.17 release fixes vulnerabilities
2008-09-25/a>Jim ClausingFirefox 3.0.3 will be out probably tomorrow
2008-07-17/a>Mari NicholsFirefox Releases 3.0.1 and fixes 3 security vulnerabilities
2008-07-16/a>Maarten Van HorenbeeckFirefox fixes two security vulnerabilities
2008-07-02/a>Jim ClausingFirefox is out
2008-06-19/a>William StearnsFirefox vunerability
2008-06-16/a>Marcus SachsFirefox 3.0 to be Released on Tuesday
2008-04-17/a>Chris CarboniFirefox Update
2008-03-26/a>Raul SilesFirefox is out
2008-03-24/a>Raul SilesNext-generation Web browsers?


2015-07-05/a>Didier StevensWorking with base64
2015-06-16/a>John BambenekCVE-2014-4114 and an Interesting AV Bypass Technique
2015-04-15/a>Johannes UllrichMS15-034: HTTP.sys (IIS) DoS And Possible Remote Code Execution. PATCH NOW
2014-10-09/a>Johannes UllrichCSAM: My servers started speaking IRC, and that is when I started to listen!
2014-10-06/a>Johannes UllrichCSAM: Patch and get pw0ned (not OR).
2014-10-03/a>Johannes UllrichCSAM: The Power of Virustotal to Turn Harmless Binaries Malicious
2014-10-02/a>Johannes UllrichCSAM: My Storage Array SSHs Outbound!
2014-09-25/a>Johannes UllrichUpdate on CVE-2014-6271: Vulnerability in bash (shellshock)
2014-09-24/a>Pedro BuenoAttention *NIX admins, time to patch!
2014-09-22/a>Johannes UllrichCyber Security Awareness Month: What's your favorite/most scary false positive
2014-08-17/a>Rick WannerPart 2: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-07-07/a>Johannes UllrichMulti Platform *Coin Miner Attacking Routers on Port 32764
2014-06-30/a>Johannes UllrichShould I setup a Honeypot? [SANSFIRE]
2014-06-12/a>Johannes UllrichMetasploit now includes module to exploit CVE-2014-0195 (OpenSSL DTLS Fragment Vuln.)
2014-05-23/a>Richard PorterHighlights from Cisco Live 2014 - The Internet of Everything
2014-05-21/a>John BambenekNew, Unpatched IE 0 Day published at ZDI
2014-04-08/a>Guy BruneauOpenSSL CVE-2014-0160 Fixed
2014-03-24/a>Johannes UllrichNew Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks
2014-03-02/a>Stephen HallSymantec goes yellow
2014-02-07/a>Rob VandenBrinkNew ISO Standards on Vulnerability Handling and Disclosure
2013-12-06/a>Guy BruneauVMware ESX 4.x Security Advisory
2013-11-14/a>Johannes UllrichiOS 7.0.4 released. Fixes issue with unauthorized in App purchases
2013-06-20/a>Guy BruneauHP iLO3/iLO4 Remote Unauthorized Access with Single-Sign-On
2013-05-09/a>Johannes UllrichMicrosoft released a Fix-it for the Internet Explorer 8 Vulnerability
2013-03-25/a>Johannes UllrichIPv6 Focus Month: IPv6 over IPv4 Preference
2013-03-18/a>Kevin ShorttCisco IOS Type 4 Password Issue:
2013-03-09/a>Guy BruneauIPv6 Focus Month: IPv6 Encapsulation - Protocol 41
2013-02-22/a>Chris MohanPHP 5.4.12 and PHP 5.3.22 released
2013-01-19/a>Guy BruneauJava 7 Update 11 Still has a Flaw
2013-01-04/a>Guy Bruneau"FixIt" Patch for CVE-2012-4792 Bypassed
2012-09-21/a>Guy BruneauIE Cumulative Updates MS12-063 - KB2744842
2012-07-18/a>Rob VandenBrinkVote NO to Weak Keys!
2012-06-25/a>Guy BruneauIssues with Windows Update Agent
2012-04-12/a>Guy BruneauHP ProCurve 5400 zl Switch, Flash Cards Infected with Malware
2012-01-12/a>Rob VandenBrinkPHP 5.39 was release on the 10th, amongst other things, it addresses CVE-2011-4885 (prevents attacks based on hash collisions) and CVE-2011-4566 (integer overflow when parsing invalid exif header)
2011-08-11/a>Johannes UllrichAs part of this weeks patch tuesday, microsoft also re-release MS11-043 to address stability issues.
2011-08-05/a>Johannes UllrichCommon Web Attacks. A quick 404 project update
2011-07-28/a>Johannes UllrichAnnouncing: The "404 Project"
2011-07-02/a>Pedro BuenoBootkits, they are back at full speed...
2011-06-01/a>Johannes UllrichEnabling Privacy Enhanced Addresses for IPv6
2011-04-28/a>Chris MohanGathering and use of location information fears - or is it all a bit too late
2011-04-25/a>Rob VandenBrinkWhat's Your (IP) Address Worth?
2011-04-21/a>Guy BruneauSilverlight Update Available
2011-04-10/a>Raul SilesRecent security enhancements in web browsers (e.g. Google Chrome)
2011-03-23/a>Johannes UllrichFirefox 4 Security Features
2011-02-23/a>Manuel Humberto Santander PelaezBind DOS vulnerability (CVE-2011-0414)
2011-02-01/a>Johannes UllrichThe End Of IP As We Know It
2010-11-16/a>Guy Bruneau OpenSSL TLS Extension Parsing Race Condition
2010-10-28/a>Manuel Humberto Santander PelaezCVE-2010-3654 - New dangerous 0-day authplay library adobe products vulnerability
2010-09-17/a>Robert DanfordCirca 2007 Linux Kernel Vulnerability Resurfaces (Was CVE-2007-4573, Now CVE-2010-3301)
2010-03-24/a>Kyle HaugsnessWax nostalgic - commodore64 updated to present time
2010-02-23/a>Mark HofmanWhat is your firewall telling you and what is TCP249?
2010-02-21/a>Tony CarothersTCP Port 12174 Request For Packets
2010-01-19/a>Jim ClausingThe IE saga continues, out-of-cycle patch coming soon
2010-01-19/a>Jim Clausing49Gbps DDoS, IPv4 exhaustion, and DNSSEC, oh my!
2010-01-15/a>Kevin ListonExploit code available for CVE-2010-0249
2010-01-04/a>Bojan ZdrnjaSophisticated, targeted malicious PDF documents exploiting CVE-2009-4324
2009-12-29/a>Rick WannerWhat's up with port 12174? Possible Symantec server compromise?
2009-11-11/a>Rob VandenBrinkApple Safari 4.0.4 Released
2009-10-30/a>Rob VandenBrinkNew version of NIST 800-41, Firewalls and Firewall Policy Guidelines
2009-10-28/a>Johannes UllrichSniffing SSL: RFC 4366 and TLS Extensions
2009-10-25/a>Lorna HutchesonCyber Security Awareness Month - Day 25 - Port 80 and 443
2009-10-15/a>Deborah HaleCyber Security Awareness Month - Day 15 - Ports 995, 465, and 993 - Secure Email
2009-09-07/a>Jim ClausingRequest for packets
2009-05-27/a>donald smithWebDAV write-up
2009-03-28/a>Rick WannerNew Beta release of Nmap
2009-03-05/a>Mark HofmanWhat's up with port 445?
2008-06-10/a>Swa FrantzenRansomware keybreaking
2006-10-05/a>Swa FrantzenMS06-053 revisited ?
2006-09-15/a>Swa FrantzenMSIE DirectAnimation ActiveX 0-day update
2006-08-31/a>Joel EslerMS06-040 Worm