* Storm Worm rears ugly head(s) for holidays * Patches from Adobe, Apple, Debian, others * HP patches 'bricking' bug in software update service, and other interesting reading
While many of us were taking a break to celebrate the holidays, hackers were busy creating new variations of the Storm Worm and malware authors attempted to take advantage of a high-profile assassination in Pakistan.
Malware news:
Storm Worm rears ugly head(s) for holidays
Interestingly, a few days before Christmas, some of the security blogs were noting with surprise that no new Christmas-themed Storm Worm variations had yet appeared. Turns out it was the calm before the Storm, so to speak. First, a new variant of Storm featuring Christmas-themed strippers hit e-mail inboxes. By New Year’s day, the message changed again, this time with an e-mail featuring a executable files named “happy-2008.exe” and “happynewyear2008.exe”.
Personally, I didn’t see any of the Christmas Storm Worm variants in my various inboxes, but gMail did filter out quite few of the Happy New Year virus into the automated Spam folder. Hopefully, most (or all) corporations are blocking executable attachments at the gateway so this was nothing to worry about.
Some related Storm coverage:
Storm switches tactics third time, adds rootkit
Storm worm tempts with Christmas strip show
F:Secure: It’s a Stormy Christmas Eve…
Arbor Networks Security to the Core: Storm and 2008 – New Campaign
Hackers quickly move to exploit Bhutto assassination
Hackers will use any major event/disaster for a social engineering exploit. The assassination of former Pakistani Prime Minister Benazir Bhutto was no different, creating sites designed to lurn in people searching for news, but instead delivering malware.
Researcher says Sears downloads spyware
Sears and Kmart customers who sign up for a new marketing program may be giving up more private information than they’d bargained for, a prominent anti-spyware researcher claims. IDG News Service, 01/01/08.
Trojan bumps Google ads from Web pages
A security company has identified a Trojan horse program that replaces Google text advertisements on Web pages with ads from another source, depriving Google of revenue and potentially causing problems for end users. IDG News Service, 12/20/07.
**********
Today’s bug patches and security alerts:
Adobe patches nine critical flaws in Flash
Adobe Systems Inc. patched its Flash Player earlier this week, fixing nine critical vulnerabilities that hackers could use to attack Windows, Mac and Linux machines. Computerworld, 12/21/07.
Adobe advisory: Flash Player update available to address security vulnerabilities
US-CERT advisory: Adobe Updates for Multiple Vulnerabilities
**********
Security Update 2007-009 v1.1 for Mac OS X v10.5.1 and Mac OS X v10.4.11 fix a flaw in Apple’s Safari browser that could cause the application to crash when visiting certain sites.
**********
Asterisk patches flaw in SIP channel driver
A flaw in Asterisk 1.4’s implementation of the SIP channel driver could be exploited in a denail of service attack against the PBX software. Users should download version 1.4.14 to fix the problem.
**********
Seven new updates from Debian:
libsndfile (buffer overflow, code execution)
peercast (buffer overflow, code execution)
inotify-tools (buffer overflow, code execution)
**********
11 new patches from Gentoo:
OpenOffice.org (user-assisted code execution)
GTK+ library (user-assisted code execution)
Mozilla Firefox, SeaMonkey (multiple flaws)
Multi-Threaded DAAP Daemon (multiple flaws)
Exiv2 (integer overflow, code execution)
**********
From the interesting reading department:
HP patches ‘bricking’ bug in software update service
HP has fixed flaws in a patch-management program bundled with its computers, printers and other hardware that could be used by hackers to “brick” HP or Compaq PCs. Computerworld, 12/24/07.
Why Did My Next Door Neighbor Erect a 50-Foot Radio Antenna?
Wireless keyboards have been around for several years. After developing the first series of infrared devices, vendors have developed radio-based keyboards that run at 27 MHz. Symantec Security Response blog, 12/28/07.




