Tuesday, August 31, 2010
TDSS Disguised As Tweetdeck Update
Trend Micro warns in their company blog about fake Tweetdeck (popular Twitter application) update that in its true form is a variant of TDSS (aka Alureon, TDL3, Hiloti, Tidserv) rootkit. Tweetdeck has also published a warning announcement on their site.
Saturday, August 28, 2010
MessageLabs Intelligence Report: August 2010
MessageLabs has published their Intelligence report that sums up the latest threat trends for August 2010.
Report highlights:
• Spam – 92.2% in August (an increase of 3.3 percentage points since July)
• Viruses – One in 327.6 emails in August contained malware (a decrease of 0.02 percentage points since July)
• Phishing – One in 363.1 emails comprised a phishing attack (an increase of 0.10 percentage points since July)
• Malicious websites – 3,360 websites blocked per day (a decrease of 24.1% since July)
• 34.3% of all malicious domains blocked were new in August (an increase of 3.8 percentage points since July)
• 12.9% of all web-based malware blocked was new in August (a decrease of 0.2 percentage points since July)
• Battle of the botnets - Rustock remains dominant
• US hosts the greatest number of bots, but Europe becomes home to new botnet hotspots
• Less is more: Rustock moves away from TLS encrypted spam
The report can be found here.
Report highlights:
• Spam – 92.2% in August (an increase of 3.3 percentage points since July)
• Viruses – One in 327.6 emails in August contained malware (a decrease of 0.02 percentage points since July)
• Phishing – One in 363.1 emails comprised a phishing attack (an increase of 0.10 percentage points since July)
• Malicious websites – 3,360 websites blocked per day (a decrease of 24.1% since July)
• 34.3% of all malicious domains blocked were new in August (an increase of 3.8 percentage points since July)
• 12.9% of all web-based malware blocked was new in August (a decrease of 0.2 percentage points since July)
• Battle of the botnets - Rustock remains dominant
• US hosts the greatest number of bots, but Europe becomes home to new botnet hotspots
• Less is more: Rustock moves away from TLS encrypted spam
The report can be found here.
Friday, August 27, 2010
TDL Goes 64-bit
64-bit Windows versions have so far been pretty secure to use. However, that thing is changing now. Researcher Marco Giuliani from Prevx writes in the company blog about new variant of TDL, advanced rootkit, that has successfully rooted itself into 64-bit Windows. Marco's blog post can be read here.
Links to other related articles:
http://www.computerworld.com/s/article/9182238/Rootkit_with_Blue_Screen_history_now_targets_64_bit_Windows
http://www.symantec.com/connect/fr/blogs/tidserv-64-bit-goes-hiding
Links to other related articles:
http://www.computerworld.com/s/article/9182238/Rootkit_with_Blue_Screen_history_now_targets_64_bit_Windows
http://www.symantec.com/connect/fr/blogs/tidserv-64-bit-goes-hiding
Wednesday, August 25, 2010
Adobe Shockwave Player Updated
Adobe has released a new version of their Shockwave Player. Update contains fixes to several critical vulnerabilities that can be exploited to execute arbitrary code in target system.
Users with Shockwave Player 11.5.7.609 or older should update their players. The latest version (11.5.8.612 at the moment) can be downloaded here.
More information can be read from the correspondent security bulletin.
Users with Shockwave Player 11.5.7.609 or older should update their players. The latest version (11.5.8.612 at the moment) can be downloaded here.
More information can be read from the correspondent security bulletin.
Labels:
adobe,
security,
shockwave player,
update,
vulnerability
Monday, August 23, 2010
Rogue Behaving Like A Retrovirus
Symantec writes in their blog about a rogue that pushes user to uninstall present antivirus protection. Rogue named as AnVi Antivirus shows a message about detected, uncertified antivirus software presence. Clicking on "ok" or "close" button (x on the top right corner of the window) triggers uninstall process of current antivirus protection by using that protection's own legit uninstaller.
At least solutions from Symantec, Microsoft, AVG, Spyware Doctor, and Zone Labs are detected by the pest. If any of these are present the pest will push user to uninstall.
Source
At least solutions from Symantec, Microsoft, AVG, Spyware Doctor, and Zone Labs are detected by the pest. If any of these are present the pest will push user to uninstall.
Source
Friday, August 20, 2010
Patches For Adobe Reader And Acrobat Available
Adobe has released their earlier promised out-of-band update for Adobe Reader and Adobe Acrobat.
Affected versions:
Adobe Reader 8.2.3, 9.3.3 and earlier versions
Adobe Acrobat 9.3.3 and earlier versions
Users of vulnerable versions are instructed to update their versions either by using automatic update functionality or by downloading fresh version manually. The default installation configuration runs automatic updates on a regular schedule and can be manually activated by choosing Help > Check for Updates.
Those who want to upgrade manually, can download the latest versions of the links below:
Adobe Reader
Acrobat Standard and Pro
Acrobat Pro Extended
Acrobat 3D
More information about fixed vulnerabilities can be read from Adobe's security bulletin.
Affected versions:
Adobe Reader 8.2.3, 9.3.3 and earlier versions
Adobe Acrobat 9.3.3 and earlier versions
Users of vulnerable versions are instructed to update their versions either by using automatic update functionality or by downloading fresh version manually. The default installation configuration runs automatic updates on a regular schedule and can be manually activated by choosing Help > Check for Updates.
Those who want to upgrade manually, can download the latest versions of the links below:
Adobe Reader
Acrobat Standard and Pro
Acrobat Pro Extended
Acrobat 3D
More information about fixed vulnerabilities can be read from Adobe's security bulletin.
Labels:
adobe,
pdf reader,
security,
update,
vulnerability
Wednesday, August 18, 2010
Opera 10.61 Available
Opera Software has released an update for their Opera web browser. Version 10.61 contains fixes to three found security vulnerabilities (high, moderate and low) and to a batch of other bugs.
Opera users are strongly recommended to update to 10.61 version. New version can be downloaded here.
Opera 10.61 for Windows changelog
Opera users are strongly recommended to update to 10.61 version. New version can be downloaded here.
Opera 10.61 for Windows changelog
Subscribe to:
Posts (Atom)