Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, July 26, 2009

Malware Expected to Set Records This Year


Security firm McAfee has identified more than 1.2 million different types of malware in the first half of 2009.

McAfee said that this is over double the 500,000 unqiue pieces of malware it identified in the same period in 2008. In total, the security firm identified 1.5 milliion types of malware in 2008, and it expects the 2009 figure to top this.

"In the first half of 2009, we have seen about three times the unique malware discovered in the same period in 2008," said Dave Marcus, director of security research and communications at McAfee.
"This tremendous growth is a signal of daunting times for users, as malware infiltrates more and more of the platforms we trust."

McAfee also revealed that around 40 percent of all password-stealing Trojans can be found on websites connected to gaming and virtual worlds, while 80 percent of all banking e-mail recieved by Web users are phishing scams.

McAfee also said on average victim's of phishing scams lose £520 per scam.

Adobe Flash Flaw Exploited in Web Sites, Researcher Warns


A vulnerability that Adobe has confirmed to exist in a number of its Reader, Flash Player, and Acrobat products is being exploited through malicious Flash code in Web pages, according to one researcher.

[As reported previously, the vulnerability is also being exploited via a malicious PDF file attack that can potentially crash Windows, Macintosh, and Linux operating systems and according to Adobe, "potentially allow an attacker to take control of the affected system."]

However, there is also another way the Adobe Flash vulnerability is being exploited, according to Paul Royal, principal researcher at Purewire, says the Adobe Flash vulnerability is being exploited through Web pages with the Flash exploit embedded in them as multimedia.

Royal described this form of attack as including "a Flash movie of one-frame length. This malicious Flash file is being embedded in Web pages, sometimes of legitimate Web sites that are compromised."Purewire's research indicates this malicious Flash movie file is just different enough from the PDF file exploit that it isn't being detected by many anti-malware software packages yet.

But Royal adds that just last week more anti-malware vendors have worked to update their software to detect the malicious PDF file exploit, generally sent as an e-mail spam attachment. The malicious PDF file appears to be used mostly in targeted attacks against specific corporations.

In its advisory, which is being updated as needed, Adobe states "A critical vulnerability exists in the current versions of Flash Player (v9.0159.0 and v.10.022.87) for Windows, Macintosh and Linux operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat v.9x for Windows, Macintosh and Unix operating systems. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system."

Adobe, which says it is in contact with several antivirus and security firms concerning the Flash vulnerability, states it intends to provides fixes for most of the affected products by the end of the month.

Sunday, July 19, 2009

Firefox 3.5.1 Fixes Critical Security Flaw


The Mozilla Corp. has released Firefox 3.5.1, a new version of their Web browser. The new release corrects a security problem the company acknowledged earlier this week as “critical.” Firefox is available for free download from the Web site.

Firefox 3.5.1 corrects the security flaw identified in Mozilla Foundation Security Advisory 2009-41: a problem with the software’s “Just-In-Time” (JIT) compiler used for JavaScript. A crash could result in an exploitable memory corruption problem that could, under certain cases, be exploited by an attacker to run arbitrary code, like malware.