Friday, September 13, 2013

Shockwave Player Update Available

Adobe have released an updated version of their Shockwave Player. The new version fixes one security vulnerability that may allow an attacker to run arbitrary code on the affected system. The update is categorized as critical with priority level as 1.

Users of Adobe Shockwave Player 12.0.3.133 and earlier should update to Adobe Shockwave Player 12.0.4.144.

More about fixed vulnerabilities and other information can be read from Adobe's security bulletin.

Thursday, September 12, 2013

Microsoft Security Updates For September 2013

Microsoft have released security updates for September 2013. This month update contains 13 security bulletins of which four critical and nine important.

A new version of Windows Malicious Software Removal Tool (MSRT) was released too.

More information can be read from the bulletin summary.

Saturday, September 7, 2013

Hesperbot Banking Trojan

There has been discovered a new banking trojan that seems to target online banking users mainly in Turkey, the Czech Republic, Portugal and the United Kingdom. This Hesperbot named trojan uses very credible-looking phishing-like campaigns, related to trustworthy organizations, to lure victims into running the malware.

"Despite being a “new kid on the block”, it appears that Win32/Spy.Hesperbot is a very potent banking trojan which features common functionalities, such as keystroke logging, creation of screenshots and video capture, and setting up a remote proxy, but also includes some more advanced tricks, such as creating a hidden VNC server on the infected system. And of course the banking trojan feature list wouldn’t be complete without network traffic interception and HTML injection capabilities. Win32/Spy.Hesperbot does all this in quite a sophisticated manner."

More about Hesperbot can be read in Robert Lipovsky's blog post.

Friday, September 6, 2013

ESET Global Threat Report for August 2013

ESET have published a report discussing global threats of August 2013.

TOP 10 threats list (previous ranking listed too):

1. HTML/Iframe (5.)
2. WIN32/Bundpil (1.)
3. HTML/ScrInject (2.)
4. Win32/Sality (4.)
5. INF/Autorun (3.)
6. Win32/Conficker (7.)
7. Win32/Dorkbot (7.)
8. Win32/Ramnit (9.)
9. Win32/Qhost (10.)
10. Win32/Virut (-)


Complete report (with a description about each of the above listed threats) can be downloaded here (in PDF format).

Saturday, August 31, 2013

Java 6 Vulnerability Exploited

Security researchers have spot in-the-wild exploit that targets vulnerability CVE-2013-2463 in Java 6. Since Java 6 has been retired (further updates are available for paying customers only) only option is to upgrade to latest Java 7 version (currently update 25).

Source: InformationWeek article

If Java is not needed then even better option is to uninstall completely or at least turn it off in web browsers (instructions).

Opera 16 Released

Opera have released version 16 of their Opera web browser. Among bug fixes new version contains some new features.

Latest version can be downloaded here.

Thursday, August 29, 2013

RealPlayer Update

RealNetworks has released updated version of their RealPlayer. New version contains fixes to two vulnerabilities.

Users of affected versions are advised to update their RealPlayer to the latest one available. More information can be read from related security advisory.