Microsoft patches: Take Two

Opinion
Jun 23, 20084 mins

* Patches from Apple, Mandriva, rPath, others * Storm storms back with porn scam * Microsoft security fix clobbers 2 million password stealers, and other interesting reading

Microsoft is working on releasing updates to a couple of its recent patches after they were found to be ineffective in some cases. First, the critical Bluetooth patch that was part of this month’s Patch Tuesday release does not fix Windows XP. And, an update for a flaw in Microsoft’s corporate patch distribution system did not make its way to the company’s Windows Server Update Service. Both new updates should be out shortly. Also, beware of the pesky Storm Worm, which seems to be making a resurgence and is masquerading as a porn scam.

Patch-blocking bug also stymies Microsoft’s WSUS

Just days after fixing a glitch in one of its enterprise patch-distribution tools, Microsoft said that another of its patching programs has been blocking last week’s security updates. Computerworld, 06/21/2008.

Microsoft advisory

Microsoft’s critical Bluetooth patch didn’t work on XP

Microsoft has reissued a critical Windows security patch, saying that the fix didn’t initially work on the most recent versions of Windows XP. Look for a new patch soon from Microsoft. IDG News Service, 06/19/2008.

Microsoft advisory

**********

Apple fixes Safari ‘carpet bomb’ bug

Apple has reversed course and patched a bug in its Safari browser after security researchers showed how it could be used to run unauthorized software on a Windows machine. IDG News Service, 06/19/2008.

Apple advisory

**********

Three new patches from Mandriva:

exiv2 (denial of service)

net-snmp (multiple flaws)

fetchmail (denial of service)

**********

Two new fixes from rPath:

xorg-x11 (multiple flaws)

xorg-server (privilege escalation)

**********

Today’s malware news:

Storm storms back with porn scam

Security researchers Friday warned of a new, massive spam campaign that tries to convince users to install the long-running Storm bot Trojan on their PCs. Computerworld, 06/20/2008.

Security vendors report ‘critical’ Trojan exploit for Mac

SecureMac and Intego are separately reporting the existence of a new security threat for Mac, claiming the existence of multiple variants of a new Trojan horse in the wild that affects Mac OS X 10.4 and 10.5. Macworld, 06/20/2008 .

Malware authors getting clever at writing headlines

Earlier today we saw an big increase in emails going around with all sorts of interesting subjects, not totally unlike the ones used by the latest Storm. So far we’ve seen subjects talking about everything from “White House hit by lightning, catches fire” to “Italy knocked out of Euro 2008” and “Nokia unveils revolutionary new phone design?” F-Secure, 06/20/2008.

New free phishing kits

PandaLabs, Panda Security’s laboratory for detecting and analyzing malware, has detected the distribution of new, free phishing kits used by cyber-crooks to launch fraud attacks. Panda Security, 06/21/08.

**********

From the interesting reading department:

Microsoft security fix clobbers 2 million password stealers

Microsoft’s June security updates were bad news for online criminals who make their living stealing password information from online gamers. IDG News Service, 06/20/2008.

One-third of IT admins admit snooping with privileged passwords

One in three IT administrators say that they or one of their colleagues have used top-level admin passwords to pry into confidential or sensitive information at their workplaces, according to a survey by a password-management vendor. Computerworld, 06/20/2008.

Link seen between fraudulent ATM transactions, bank breach

A flurry of fraudulent ATM transactions in recent days in countries such as Russia, Ukraine, Turkey and the Czech Republic may be tied to a server intrusion at 1st Source Bank in South Bend, Ind. Computerworld, 06/19/2008.

Citibank to Replace ATMs Following Crime Spree

One of my sources, the other day, tipped me off that Citibank was in the process of replacing most of its automated teller machines (ATMs), but the source couldn’t definitively say why. A story today by Wired.com reporter Kevin Poulsen suggests that the financial giant is responding to a computer intrusion into a Citibank server that processes ATM withdrawals, an incident that appears to have led to an ATM crime spree. Security Fix blog, 06/20/2008.

Backscatter (or bounce) Spam, didn’t we already solve this?

Today I heard yet another email administrator complaining about waves of backscatter spam frustrating him and his users- and his complaint was that users were complaining about it instead of just deleting it. Uncommon Sense Security blog, 06/19/08.

Teens charged with loading spyware, changing grades

Two Orange County, California, teenagers have been charged with breaking into high school offices and using stolen usernames and passwords to change lackluster grades to A’s. IDG News Service, 06/18/2008.