Weekly Intelligence Summary: 2010-01-08
Dave KennedyJanuary 9th, 2010
A second attack in as many weeks targeted a large, well-resourced DNS array; on Wednesday, InterNexX a host for 2.9 million domains was attacked and became intermittently available. This follows the attack on UltraDNS on 2009-12-23. Criminal manipulation of search engine optimization resulted in office.microsoft.com’s search function yielding results that redirected users through office.microsoft.com to a site trying to seduce users to install a rogue anti-virus. Millions of bank cards in Germany and Australia, Spam Assassin and Symantec Endpoint Protection failed after rolling from the year 2009 to 2010. The Chairman of the FCC, the president of Iran, four government departments in the Philippines, on-line trading site collective2.com and the Pakistan National Response Center for Cybercrimes all fell victim to intrusions, mostly defacements. These incidents notwithstanding, malicious, JavaScript-laden PDF files sent in targeted attacks remain the most significant risk for Verizon Business enterprise customers. Fortunately, this coming Tuesday brings patches to Adobe Acrobat and Reader, Windows 2000, and “hundreds” of Oracle products. Happy New Year!




