* Patches from Cisco, Debian, Mandriva * Clickjackers could hijack Webcams, microphones, Adobe warns * Firefox extension blocks dangerous Web attack, and other interesting reading
Cisco has released a patch for its Unity unified messaging platform that fixes an authentication bug that could allow unauthorized users to make configuration changes. VMWare is out with a number of fixes as well for its Hosted products, VirtualCenter Update 3, ESX and ESXi lines. And Adobe finally acknowleged the Clickjacking attack that plagues its Flash player. The company released a workaround for the issue and says a permanent fix should be out at the end of the month.
Authentication bypass flaw in Cisco Unity
A flaw in Cisco’s Unity unified messaging platform could allow unauthorized users to view and change configuration settings on a Unity server. A free update is available.
Also: From Cisco Subnet: Cisco warns of Unity bug
**********
VMWare out with multiple patches
According to the company’s advisory, “VMware addresses a in-guest privilege escalation on 64-bit guest operating systems in ESX, ESXi, and previously released versions of our hosted product line. Updated VMware VirtualCenter Update 3 addresses potential information disclosure and updates Java JRE packages.” Updates are available.
**********
Seven new updates from Debian:
mplayer (integer overflow, code execution)
Feta (symlink, denial of service)**********
Two new patches from Mandriva:
pam_krb5 (privilege escalation)**********
Today’s malware news:
The Art of the Hidden FileThe art of hiding codes via XOR is simple, easy and extremely ancient. Despite its antiquity though, it is still in use today. F-Secure, 10/08/2008.Clickjackers could hijack Webcams, microphones, Adobe warnsAdobe Systems warned users Tuesday that hackers could use recently-reported “clickjacking” attack tactics to secretly turn on a computer’s microphone and Web camera. Computerworld, 10/08/2008.
Adobe: Clickjacking Security Advisory
Trojan.Silentbanker Adds Rootkit FunctionalityTrojan.Silentbanker has been in the wild since late last year; however, the most recent release of this Trojan has had some interesting features added to it. Namely, the most recent version has added rootkit functionality to make the Trojan even stealthier. If you are unfamiliar with Trojan.Silentbanker, have a look at this blog first. Symantec Security Response blog, 10/06/2008.Asus reports virus loaded into Eee Box PCsAsustek Computer’s Japanese arm has alerted owners of its new Eee Box low-cost desktop PC that the machine shipped with a virus. IDG News Service, 10/07/2008.
**********
From the interesting reading department:
Firefox extension blocks dangerous Web attackA popular free security tool for the Firefox browser has been upgraded to block one of the most dangerous and troubling security problems facing the Web today: clickjacking. IDG News Service, 10/08/2008.Symantec to buy e-mail security vendor MessageLabsSymantec will pay $695 million for MessageLabs, a security vendor that offers a hosted spam and Web traffic filtering service. IDG News Service, 10/08/2008.Global SIP Attack ActivityDigging into ATLAS we can start to look at SIP scan and exploit activity over the past 30 days. SIP attacks are uncommon in ATLAS and are usually not visible as a global “top 20”. When we do go looking for it, however, what we see isn’t terribly surprising. Security to the Core, 10/08/2008.U.S. man indicted for hacking Palin’s e-mail accountA 20-year-old Tennessee man has been indicted for hacking into an e-mail account of U.S. vice presidential candidate Sarah Palin, according to court records. IDG News Service, 10/08/2008.Dramatic Spike in the Number of Email Messages Containing MalwareThe trend of spam messages containing URL links to malicious code and/or carrying malicious payloads has dramatically spiked since May of this year. This trend is the focus of our October State of Spam Report, issued today. Symantec Security Response blog, 10/06/2008.O.J. Simpson guilty verdict could lead to malicious spamUsers should be on guard for spam touting the guilty verdict of former professional football star O.J. Simpson, a security company warned Monday. Computerworld, 10/06/2008.Six essential Apple iPhone security tipsIf you’re an Apple iPhone user and security’s not on your mind, you’re at risk; at risk of having a Web mail account hacked; at risk of having your online identity stolen; and at risk of losing valuable personal information, such as wireless service account data, that could result in financial losses, among other disasters. CIO, 10/07/2008.




