* Patches from Oracle, Microsoft, Gentoo, others * Fake-CNN spam mutates as attacks * Court halts subway hacker talk, and other interesting reading
endif; ?>If the Black Hat/Defcon news over the weekend is not enough for you, Microsoft is delivering a dozen new updates tomorrow to keep your plate full. The updates cover most of Microsoft’s major products, including critical fixes for Office, Windows, and Internet Explorer. Also, Oracle issued an out-of-cycle update for its Oracle WebLogic Server and Express products after announcing the flaw last week.
Oracle issues out-of-cycle patch for flaw
Oracle has released an emergency patch for a flaw the company issued a rare security alert for last week. Administrators should not apply the work-arounds the company previously recommended and apply the patch, Oracle said.
**********
A dozen patches from Microsoft this week
Microsoft Corp. today said it will deliver a dozen security updates next week to fix critical vulnerabilities in Windows, Office, Internet Explorer (IE) and the media player bundled with Vista. Of the 12 updates it sketched out in the advance notification issued this morning, Microsoft pegged seven as “critical,” its highest threat rating. The remaining five were labeled “important,” the second-highest ranking. Computerworld, 08/07/2008.
**********
ActiveX Vulnerabilities: Even When You Aren’t Vulnerable, You May Be Vulnerable
Recently, we came across a rather unfortunate exploit case for the Access Snapshot Viewer ActiveX Vulnerability that took advantage of a property of the ActiveX system to exploit IE users who did not have the vulnerable control installed. How does one exploit a vulnerability that does not exist on a system you say? Sadly, attackers have found a way to install the vulnerable Access Snapshot Viewer ActiveX control through Internet Explorer prior to exploiting it. Symantec Security Response blog, 08/06/2008.
**********
Five new patches from Gentoo:
ISC DHCP (buffer overflow, denial of service)
stunnel (authentication bypass)
libxslt (heap overflow, code execution)**********
Four new updates from Mandriva:
Python for Mandriva 2007.1 and greater (multiple flaws)
Python for Corporate 4.0 (multiple flaws)
rxvt (denial of service)**********
Today’s malware news:
SQL Injection Attacks Targeting Chinese-oriented SitesWith all the attention on China these days, especially in conjunction with the Beijing 2008 Olympics Games, and with ‘China’ being one of the more popular search engine keywords at the moment, it makes sense for malware writers to focus their attention on the Chinese web — and we’ve been seeing some interesting examples of SQL injection attacks specifically targeting website designed for a Chinese audience, whether from the mainland or overseas. F-Secure, 08/08/2008.Fake IE7 Downloads Advertised Via EMailThere seem to be quite a few of these in circulation over the past day or so. Microsoft does not send out EMails asking you to download files from random, non-Microsoft Web sites. The SpywareGuide Greynets Blog, 08/07/2008.Fake-CNN spam mutates as attacks continueThe massive attack that has infected PCs by tricking users into clicking links in fake messages from CNN.com shows little sign of ending soon, security researchers said Friday. Computerworld, 08/09/2008.
**********
From the interesting reading department:
Researcher: Intel fixed two critical flaws in its chipsA Russian researcher who plans to demonstrate this fall how he could take advantage of flaws in Intel Corp.’s chips, said the chip maker has told him it has fixed two critical bugs. Computerworld, 08/08/2008.Kaminsky: Many ways to attack with DNSThere were 6 a.m. calls from Finnish certificate authorities and also some pretty harsh words from his peers in the security community, even an accidentally leaked Black Hat presentation, but after managing the response to one of the most highly publicized Internet flaws in recent memory, Dan Kaminsky said Wednesday that he’d do it all over again. IDG News Service, 08/06/2008.What it’s like to work overseas for CIA IT group”I have a million stories to tell,” says the senior CIA IT person, staring at me through the CIA’s videoconferencing system. Unfortunately, he can’t share any with me. (He cites national security reasons, of course.) CIO, 08/06/2008.Court halts subway hacker talkA U.S. District Court judge ordered the cancellation of a Defcon conference talk scheduled for Sunday that would have detailed flaws in the Massachusetts Bay Transportation Authority electronic ticketing system. IDG News Service, 08/09/2008.iPhone hackers warn against v.2.0.1 updateHackers working to develop software that unlocks the iPhone for use on non-approved networks and in order to install unauthorized applications are warning users not to install iPhone Software 2.0.1. Macworld, 08/06/2008.New Flash spamA new spam tactic has proliferated over the last few weeks which consists of sending junk mail with links to Macromedia Flash files that automatically redirect to a spammer site. Panda Security, 08/02/2008.Marketing Bot Allows Insertion of Custom Facebook Feed MessagesIf a bad actor buys their own Bot, imagine the Myspace-style spam campaigns that could take place…everything from malicious URLs to obnoxious flashing banners could be the order of the day. The SpywareGuide Greynets Blog, 08/11/2008.Microsoft to rate exploit potentialMicrosoft Corp. will soon edge into the crystal-ball business in its security bulletins by predicting how likely it is that software flaws will be exploited. Starting in October, Microsoft will add an “Exploitability Index” that gives bugs one of three ratings, based on the likelihood that attackers will be able to develop code to take advantage of the flaws. Computerworld, 08/11/2008.ID theft ring attacked retailers on multiple levelsA ring of identity thieves that targeted U.S. retailers used sophisticated and multifaceted attacks to steal more than 40 million credit and debit card numbers from TJX, OfficeMax, Barnes & Noble and other companies, according to court documents. IDG News Service, 08/06/2008.Spammers leverage interest in OlympicsPublic interest in the Olympic Games is helping spammers, who are using text related to the games in e-mails to get users to click through to their malware and phishing Web sites, or to go to product sites, according to an executive at Symantec. IDG News Service, 08/07/2008.




