Adobe warns of fake Flash installers

Opinion
Aug 7, 20084 mins

* Patches from Gentoo, rPath * 419 Mail Targets Musicians * Microsoft to give vendors an early peek at patches, and other interesting reading

With many security folks converging in Las Vegas for Black Hat, alerts have been a little slow this week. But there should be a ton of new patches and warnings coming over the next few days as more presenters at the conference unveil holes in systems and applications that will leave vendors scrambling for fixes. One thing to be wary of, fake Flash Player installers that could result in malicious code being downloaded to an affected system.

Adobe warns over bogus Flash Player installers

Hackers are trying to dupe people into downloading malicious software labeled as Adobe Systems’ Flash Player, prompting a warning from the company. Adobe is advising users to ignore links on social-networking sites that lead to other Web sites purportedly hosting Flash Player, as those sites often have malicious software. IDG News Service, 08/05/2008.

**********

Four new patches from Gentoo:

Wireshark (denial of service)

Mozilla Firefox, Thunderbird, et al (multiple flaws)

Net-SNMP (multiple flaws)

xine-lib (buffer overflows, code execution)

**********

Two new updates from rPath:

Gaim (multiple flaws)

cups (integer overflow, code execution)

**********

Today’s malware news

419 Mail Targets Musicians

There are plenty of musicians promoting their music on their websites, blogs, fan sites and forums – which presents scammers with a huge selection of targets to choose from. Be on your guard… The SpywareGuide Greynets Blog, 08/06/2008.

**********

From the interesting reading department:

Microsoft to give vendors an early peek at patches

Microsoft plans to give security vendors a head start in what has become a monthly race against the hackers. Starting in October, the company will provide security vendors with early access to technical details of its monthly security patches before the software updates are actually released. IDG News Service, 08/05/2008.

Cisco routers again take hacker spotlight

The Cisco hacking scene has been pretty quiet for the past three years, but at this week’s Black Hat hacker conference in Las Vegas, there’s going to be a little noise. IDG News Service, 08/05/2008.

What you don’t know about security can hurt you

I’ve just received an early release of a security survey conducted by the RSA Conference where security professionals were polled about their attitudes and experiences around information security. There were two findings that caught my attention. Network World, 08/05/2008.

Snooping into a co-worker’s e-mail? You could be arrested

Ever pass by a co-worker’s unattended computer and consider taking a peek at her e-mails? Or have you ever thought it would be a funny prank to figure out your cube mate’s e-mail password and break into his work account to mess with him? Computerworld, 08/03/2008.

Olympic ticket scams just the start, says researcher

Scammers have duped hundreds of people out of thousands of dollars each using bogus Olympic ticket-selling sites, reports said today. A security expert warned that more will follow. Computerworld, 08/04/2008.

Symantec: Buyer Beware – Scam Olympic Ticketing Sites About

How to carjack a top Google exec, according to Google

The National Legal and Policy Center (NLPC) in the U.S. has turned the tables on Google by using the company’s controversial Street View technology along with Google Earth to compile and make public a detailed dossier on a “top Google executive.” Computerworld, 08/04/2008.

Missing laptop grounds U.S. Registered Traveler program

The U.S. Transportation Security Administration has temporarily stopped a vendor from signing up new customers for its Registered Traveler program after a company laptop containing the unencrypted personal data of 33,000 people went missing at the San Francisco International Airport. IDG News Service, 08/05/2008.

Symantec State of Spam Report – August

As we enter August, Symantec takes note in the State of Spam Report that spammers are continuing to attempt to entice users to open their messages by sensationalizing false news events. Popular targets of this headline or tabloid spam include current public events and figures, such as Obama and McCain. Symantec Security Response, 08/05/2008.

Strange Digg.com Spamming

Porn spam starting to pop up on Digg. Who’s to blame? The SpywareGuide Greynets Blog, 08/06/2008.