Cyber Monday, the official start of the online holiday shopping season, is here. Two thirds of computer users plan to shop and / or research online this holiday season. There's little wonder why cyber thieves go into high gear this time of year - they simply follow the money to make the most profits. Surrounded by the comforts of your home, it's easy to lose sights of this.
In response to the volume of malware exploiting Adobe products, Adobe Reader X was released last week with its much anticipated new security feature, Protected Mode.
Protected Mode is based on Microsoft’s "Practical Windows Sandboxing" technique which you can read about here.
What does Protected Mode do? It displays PDF files in a highly restricted and confined environment. The restricted environment will help prevent a booby trapped PDF file from doing anything to your system.
SecurityInspector2010 is a new rogue anti-virus application. It is a another clone of DesktopDefender2010.
Critical vulnerabilities have been identified in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux, and Solaris, and Adobe Flash Player 10.1.95.1 for Android. These vulnerabilities, including CVE-2010-3654 referenced in Security Advisory APSA10-05, could cause the application to crash and could potentially allow an attacker to take control of the affected system.
Full Adobe advisory info here.
Affected software includes:
Microsoft has released a security advisory concerning a vulnerability affecting Internet Explorer versions 6, 7 and 8. This vulnerability may allow an attacker to execute arbitrary code. Full details here.
Visit Microsoft's page here to get full instructions. You can find the workarounds under the "Suggested Actions" twisty.
Over Halloween we saw the usual glut of malicious sites hijacking spooky search engine results. Today looks to bring some more search engine result hijacking opportunities for the bad guys.