Adobe have released an updated version of their Shockwave Player. The new version fixes one security vulnerability that may allow an attacker to run arbitrary code on the affected system. The update is categorized as critical with priority level as 1.
Users of Adobe Shockwave Player 12.0.3.133 and earlier should update to Adobe Shockwave Player 12.0.4.144.
More about fixed vulnerabilities and other information can be read from Adobe's security bulletin.
Friday, September 13, 2013
Thursday, September 12, 2013
Microsoft Security Updates For September 2013
Microsoft have released security updates for September 2013. This month update contains 13 security bulletins of which four critical and nine important.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
A new version of Windows Malicious Software Removal Tool (MSRT) was released too.
More information can be read from the bulletin summary.
Saturday, September 7, 2013
Hesperbot Banking Trojan
There has been discovered a new banking trojan that seems to target online banking users mainly in Turkey, the Czech Republic, Portugal and the United Kingdom. This Hesperbot named trojan uses very credible-looking phishing-like campaigns, related to
trustworthy organizations, to lure victims into running the malware.
"Despite being a “new kid on the block”, it appears that Win32/Spy.Hesperbot is a very potent banking trojan which features common functionalities, such as keystroke logging, creation of screenshots and video capture, and setting up a remote proxy, but also includes some more advanced tricks, such as creating a hidden VNC server on the infected system. And of course the banking trojan feature list wouldn’t be complete without network traffic interception and HTML injection capabilities. Win32/Spy.Hesperbot does all this in quite a sophisticated manner."
More about Hesperbot can be read in Robert Lipovsky's blog post.
"Despite being a “new kid on the block”, it appears that Win32/Spy.Hesperbot is a very potent banking trojan which features common functionalities, such as keystroke logging, creation of screenshots and video capture, and setting up a remote proxy, but also includes some more advanced tricks, such as creating a hidden VNC server on the infected system. And of course the banking trojan feature list wouldn’t be complete without network traffic interception and HTML injection capabilities. Win32/Spy.Hesperbot does all this in quite a sophisticated manner."
More about Hesperbot can be read in Robert Lipovsky's blog post.
Friday, September 6, 2013
ESET Global Threat Report for August 2013
ESET have published a report discussing global threats of August 2013.
TOP 10 threats list (previous ranking listed too):
1. HTML/Iframe (5.)
2. WIN32/Bundpil (1.)
3. HTML/ScrInject (2.)
4. Win32/Sality (4.)
5. INF/Autorun (3.)
6. Win32/Conficker (7.)
7. Win32/Dorkbot (7.)
8. Win32/Ramnit (9.)
9. Win32/Qhost (10.)
10. Win32/Virut (-)
Complete report (with a description about each of the above listed threats) can be downloaded here (in PDF format).
TOP 10 threats list (previous ranking listed too):
1. HTML/Iframe (5.)
2. WIN32/Bundpil (1.)
3. HTML/ScrInject (2.)
4. Win32/Sality (4.)
5. INF/Autorun (3.)
6. Win32/Conficker (7.)
7. Win32/Dorkbot (7.)
8. Win32/Ramnit (9.)
9. Win32/Qhost (10.)
10. Win32/Virut (-)
Complete report (with a description about each of the above listed threats) can be downloaded here (in PDF format).
Saturday, August 31, 2013
Java 6 Vulnerability Exploited
Security researchers have spot in-the-wild exploit that targets vulnerability CVE-2013-2463 in Java 6. Since Java 6 has been retired (further updates are available for paying customers only) only option is to upgrade to latest Java 7 version (currently update 25).
Source: InformationWeek article
If Java is not needed then even better option is to uninstall completely or at least turn it off in web browsers (instructions).
Source: InformationWeek article
If Java is not needed then even better option is to uninstall completely or at least turn it off in web browsers (instructions).
Opera 16 Released
Opera have released version 16 of their Opera web browser. Among bug fixes new version contains some new features.
Latest version can be downloaded here.
Latest version can be downloaded here.
Thursday, August 29, 2013
RealPlayer Update
RealNetworks has released updated version of their RealPlayer. New version contains fixes to two vulnerabilities.
Users of affected versions are advised to update their RealPlayer to the latest one available. More information can be read from related security advisory.
Users of affected versions are advised to update their RealPlayer to the latest one available. More information can be read from related security advisory.
Subscribe to:
Posts (Atom)