* Patches from Firefox, CA, Gentoo, others * Hackers resurrect notorious attack toolkit * Lock and download: Door security gets boost from Web
Thought it was odd this morning that Firefox was asking me to install a new update when I had just done so late last week. Turns out Mozilla had to rush out another patch to fix a password vulnerability in the popular browser. Be on the lookout. Also, CA Service Desk users should download the latest update, which patches multiple flaws in the trouble ticket tracking system.
After password glitch, another Firefox patch out
Mozilla developers have rushed out a new release of their Firefox browser to fix a bug that has been preventing some Web surfers from using saved passwords this week. Firefox update 3.0.3 should be hitting browsers today, once of my systems was updated this morning when I got into the office. IDG News Service, 09/26/2008.
**********
According to a CA advisory, “CA Service Desk contains multiple vulnerabilities that can allow a remote attacker to conduct cross-site scripting attacks. The vulnerabilities are due to insecure handling of passed variables in multiple web forms. An attacker, who can convince a user to click on a specially crafted link, can potentially conduct cross-site scripting attacks.”
**********
Three new updates from Gentoo:
Git (buffer overflows, code execution)
**********
Two new patches from Mandriva:
**********
Today’s malware news:
Hackers resurrect notorious attack toolkit
Neosploit, the notorious hacker exploit kit that some thought had been retired months ago, has not only returned from the dead, but is responsible for a dramatic increase in attacks, a security researcher claimed Thursday. Computerworld, 09/26/2008.
Security researchers warn of new ‘clickjacking’ browser bugs
Security researchers warned Friday that a new class of vulnerabilities dubbed “clickjacking” puts users of every major browser at risk from attack. Computerworld, 09/28/2008.
Trojan can grab extra personal banking data
A Trojan horse program now available to a growing number of fraudsters can add data entry fields to legitimate online banking sites and entice consumers to give up sensitive information such as bank card numbers and PINs (personal identification numbers). IDG News Service, 09/26/2008.
Imageshack Security Issue Reported, Fixed
Earlier today, we noticed it was possible for malicious users to abuse Imageshack by obtaining the IP Address of anyone who had uploaded an image to the site (considering they have 2+ million uploads a day, that’s an awful lot of people to choose from). Imageshack has fixed the issue. The SpywareGuide Greynets Blog, 09/26/2008.
Chinese malware attacks WoW community
I realize this might not be new to the WoW community, but there are obvious threats out there that need some attention. Recently the team here at Facetime Security Labs has seen one threat in particular that we feel is especially evil. The story begins like most of these stories begin; with someone downloading something without scanning for a virus first. The SpywareGuide Greynets Blog, 09/25/2008.
A Trojan purporting to be a video of the iPhone is at the center of a new pharming attack
The launch of Apple’s iPhone in numerous countries is being exploited by cyber-crooks as bait for attracting users and infecting them with malware. Panda Security, 09/27/2008.
**********
From the interesting reading department:
Lock and download: Door security gets boost from Web
LochIsle, an Ottawa-based company that aspires to “change the locks of the future,” has released iLoch, a Web-based access control program for doors. CSO, 09/25/2008.




