A calm before the storm?

Opinion
Mar 3, 20083 mins

* Patches from rPath, Mandriva * Windows Mobile Trojan InfoJack * U.K. gov't laptop with confidential disc sold on eBay, and other interesting reading

The week is starting off slow for patches, but phishers are out in force with new eBay scams, an Orkut worm, and IRS scheme targeting people looking for tax refunds. Let’s not get lulled into a false sense of security though over the lack of patches – could just be the calm before a big storm.

Today’s malware news:

Windows Mobile Trojan InfoJack

There’s been some news this week about a Windows Mobile trojan called InfoJack. Our detection name is Trojan:WinCE/InfoJack. F-Secure blog, 02/29/08.

The Orkut Worm – Digging Deeper

Due to some confusion with this particular threat, we’ve decided to provide some further details on the Orkut worm we blogged on earlier in the week. The worm, recently renamed to W32.Scrapkut, uses active code injection as a vehicle to propagate to the Orkut friends of its unfortunate victim. Symantec Security Response blog, 02/29/08.

New Twist in IRS Phishing Scams

Earlier today I got a new phishing scam in my inbox, this one for the IRS. I’d love a tax refund, but I don’t think this is how they normally notify you. The lure email is shown below, and is quite standard in its formatting. It even threatens you with criminal prosecution if you lie. Security to the Core Blog, 02/28/08

**********

Today’s bug patches and security alerts:

Eight new patches from rPath:

Kernel (denial of service)

thunderbird (multiple flaws)

wireshark (denial of service)

CUPS (denial of service)

am-utils (file overwrite)

PCRE (buffer overflow, code execution)

lighttpd (denial of service)

espgs (buffer overflow, code execution)

**********

Three new fixes from Mandriva:

gnumeric (code execution)

ghostscript (buffer overflow, code execution)

dbus (privilege escalation)

**********

From the interesting reading department:

Anatomy of a Rock

F-Secure takes a look at the construction of a eBay phishing attack. F-Secure blog, 02/29/08.

U.K. gov’t laptop with confidential disc sold on eBay

The Home Office has launched an investigation after a buyer acquired a laptop on eBay that contained a disc with confidential information. Computerworld, 02/28/08.

FTC data: Telcos, banks are top targets for ID theft

Compromised accounts within just 25 companies account for nearly half of the identity theft complaints filed with the U.S. Federal Trade Commission, according to recently released FTC data compiled by the University of California, Berkeley. IDG News Service, 02/28/08.

Rebuking the New School

As any regular reader of security industry news will tell you, over the past few years the quality that is most prized by malicious coders is stealth. Loud, reputation-enhancing attacks are strictly for the teenage malcontents of a previous century. Today’s malicious coders are professionals who prefer a more commercial model, which aims to compromise as many machines as possible, as quietly as possible, with the minimum amount of effort – and they are adopting increasingly diversified tactics to this end. Symantec Security Response blog, 02/28/08.