Archive for February, 2009

MS09-002 exploit in the wild

Continue Reading Add comment February 19th, 2009

The Internet Storm Center is reporting that several AV vendors have confirmed that the recently patch IE 7 vulnerability (MS-09-002 Uninitialized Memory Corruption) has been reverse engineered by the malware writers (so quickly!)

IRS stimulus Phishing scam

Add comment February 6th, 2009

Phishing

US-CERT Current Activity

IRS Stimulus Package Phishing Scam

Original release date: February 6, 2009 at 10:03 am Last revised: February 6, 2009 at 10:03 am

US-CERT is aware of public reports indicating that phishing scams are circulating via fraudulent U.S. Internal Revenue Service emails offering users stimulus package payments. These emails include text that attempts to convince users to follow a link to a website or to complete an attached document. The website and document request that the user provide personal information.

US-CERT encourages users to do the following to help mitigate the risks:

* Do not follow unsolicited web links received in email messages.
* Refer to the Recognizing and Avoiding Email Scams (pdf) document
for more information on avoiding email scams.
* Refer to the Avoiding Social Engineering and Phishing Attacks
(pdf) document for more information on social engineering attacks.

Relevant Url(s):

====

This entry is available at: http://www.us-cert.gov/current/index.html#irs_stimulus_package_phishing_scam


Our Author

Shaun Sturby, MCSE Technical Services Manager, and Optrics' point person for email security
Shaun Sturby, MCSE