* Patches from Oracle, Mandriva, Ubuntu, others * Hacked MySpace page serves up fake Windows update * Microsoft sends patch to wrong users, and other interesting reading
Last week it was Microsoft’s Patch Tuesday, this week Oracle delivers a boatload of patches. In all, the company will release 27 updates for its database, e-business suite and application server. Also, while Microsoft did patch a few flaws in its last round, hackers are still exploiting an 18-month-old flaw in Windows. Plus, a QuickTime vulnerability could leave systems open to malicious code.
Oracle to ship critical security patches next week
Oracle plans to fix dozens of flaws in its software products next Tuesday, including critical bugs in the company’s database, e-business suite and application server. In its first security update of 2008, Oracle will ship 27 security fixes, some of which will affect several products. Oracle outlined some details of the upcoming patches in a pre-release announcement posted to the company’s Web site Thursday afternoon.
**********
Old exploit keeps on tickin’ for hackers
In the last two weeks, hackers have exploited an 18-month-old vulnerability in Microsoft Windows in three high-profile attack campaigns to infect PCs with advanced rootkits and launch infections from thousands of compromised Web sites. Since Dec. 28, the same exploit has been used by attackers who jumped on the news of former Pakistani Prime Minister Benazir Bhutto’s assassination, by attackers who earlier had hacked thousands of sites using a robotic SQL injection attack, and by the creators of a sophisticated master boot record rootkit invisible to Windows. Computerworld, 01/11/08.
**********
Security researchers have reported finding a buffer overflow vulnerability in Apple QuickTime RTSP implementation. An attacker could exploit the flaw in a denial-of-service attack and to potentially run malicious code on an affected system. No patch is available as of this writing.
**********
Two new updates from Ubuntu:
Dovecot (authentication bypass)
OpenSSH (privilege escalation)
**********
Six new patches from Mandriva:
rsync (multiple flaws)
autofs (root access)
exiv2 (integer overflow, code execution)
**********
Today’s malware news:
Hacked MySpace page serves up fake Windows update
There’s now one more reason to be security-conscious while using MySpace.com: fake Microsoft updates. Using a hacked MySpace profile, online criminals are trying to trick victims into downloading a malicious Trojan Horse program by disguising it as a Microsoft update, according to researchers at security vendor McAfee. IDG News Service, 01/12/08.
Storm splinters, starts phishing, say researchers
Part of the Storm botnet appears to have been rented out to identity thieves, who are using it to conduct traditional phishing attacks that target customers of a pair of U.K.-based banks, researchers said Wednesday. Computerworld, 01/10/08.
We’ve seen some MSN Messenger worms being spread around this weekend. Once you get infected, your Messenger will start to send web links to all of your contacts. If they follow the links and download the prompted programs, they get infected too. F-Secure Antivirus Research blog, 01/13/08.
**********
From the interesting reading department:
Microsoft sends patch to wrong users
A day after Microsoft accidentally sent a patch to some users running the Windows Vista operating system, the company updated the preview release of Vista Service Pack 1 (SP1) to a small group of testers, the company confirmed Thursday. Computerworld, 01/10/08.
Holiday spirit helped double Storm worm
Some clever, sexy Christmas-themed spam and a long holiday season helped the criminals behind the notorious Storm Worm more than double their network of infected PCs over the past few weeks, security experts say. IDG News Service, 01/11/08.
The January State of Spam report shows that as 2007 ended, spam surged and accounted for 75% of all e-mail, increasing to 83% in the last few days leading up to the holiday season. The December State of Spam report had showed that 72% of e-mail traffic was spam. Symantec Security Response blog, 01/11/08.
8-day IT outage would cripple most companies
A Gartner poll of information security and risk management professionals released Thursday shows that most business continuity plans could not withstand a regional disaster because they are built to overcome severe outages lasting only up to seven days. Computerworld, 01/10/08.




