* Patches from Apple, Microsoft, rPath * Fake "Parcel Delivery" Text Message: Don't Fall For It! * How to exploit a down economy to get special security needs satisfied, and other interesting reading
endif; ?>While virus/malware writers are using the down economy as a way to push their illicit wares, security professionals can benefit as well. Network World’s Ellen Messmer has a piece on how you can push your vendors for those “special” projects since they’re probably more eager for business with the down econonmy. During downtimes, the low hanging fruit can keep them satisifed enough that they can ignore the tougher customer requests. Now, they are more willing to respond “How high?” when you ask them to jump. Check out the story in our related links section.
Adobe fixes ‘clickjacking’ flaw
Adobe Systems has released a new version of its Flash Player software, fixing a critical security bug that could make the Internet a dangerous place for Web surfers. IDG News Service, 10/15/2008.
**********
Attack unleashed for new Microsoft mainframe bugHackers have released code that could be used to take control of a server running Microsoft’s Host Integration Server 2006, used to connect mainframe applications to Windows PCs. The software was released Wednesday as part of the Metasploit hacking toolkit. IDG News Service, 10/16/2008.Related Microsoft patch
**********
Three new patches from rPath:
postfix (privilege escalation)
mono (cross site scripting)**********
Today’s malware news:
Fake “Parcel Delivery” Text Message: Don’t Fall For It!New text attack convinces the victim they have a parcel “awaiting delivery,” then encourages them to ring an Austrian number. Once connected, an automated system asks the victim to enter their number, but then repeats it back to the victim with numbers intentionally incorrect. At that point, the victim wastes time and effort going round in circles with a system designed to beat them every time. The SpywareGuide Greynets Blog, 10/17/2008.Twitter and MSN: Driving Malcode DistributionWe recently came across a bot that merged MSN Messenger link spam with Twitter to get users to download malcode. Twitter malcode is nothing new, but this one adds a twist to those that monitor IM link spam bots. You have to do an extra level or two of link analysis to figure it out. Security to the Core, 10/17/2008.
**********
From the interesting reading department:
How to exploit a down economy to get special security needs satisfiedWhen there’s not quite the right fit in network security gear to meet your needs and goals, you might wind up settling for some distant second choice, if one exists. But enterprise technology managers are proving you can get what you want by pushing vendors to innovate — a trend that may be growing because of the economic downturn. Network World, 10/16/2008.Up next: Cellular botnets, cyber militiasThe ability of malware writers to consistently stay ahead of those seeking to stop them has been a constant factor in the security industry over the past several years. Looking to 2009, don’t expect that situation to change, security analysts and vendors concede glumly. In fact, with cybercrime getting more organized and as more money is poured into malware development, it will be a challenge to stop cybercrooks from pulling even further ahead, according to the authors of a report on emerging cyberthreats for 2009 and beyond. Computerworld, 10/18/2008.Report: Two new IRS systems have major security weaknessesTwo key systems that the Internal Revenue Service is deploying contain serious security vulnerabilities that pose a direct risk to taxpayer data, according to a report by the Treasury Inspector General for Tax Administration. Computerworld, 10/19/2008.
Keep It Simple StupidWhen someone is asked to present an analysis of a modern threat, the explanation often becomes complicated very quickly. Here I will present a brief analysis of a Trojan that uses the KISS approach-“keep it simple, stupid.” Symantec Security Response, 10/16/2008.30 million computers are infected by fake antivirus programIt’s not new and it’s not original, but the number of infections caused by fake antiviruses continues to increase rapidly. The creators of these programs only have one aim: to profit financially from their creations, and they are achieving this. Panda Security, 10/17/2008.FBI says Dark Market sting netted 56 arrestsA two-year undercover FBI sting operation targeting online fraudsters has netted 56 arrests and prevented millions of dollars in economic losses, the FBI said Thursday. IDG News Service, 10/16/2008.Groups Release More Analysis on the Georgia-Russia Cyber AttacksIt’s been a couple of months since this summer’s Russia-Georgia cyberattacks. Briefly, these attacks started in mid-July with denial of service attacks on the Georgian president’s website. When Russian forces entered Georgia and warfare broke out in early August, more attacks began. We tracked some of the denial of service attacks and botnet activity, and we’ve looked into the some of the routing changes during the attacks, as well. Security to the Core, 10/16/2008.




