Tuesday, December 27, 2011

Update to Firefox 9 and 3.6.25

Earlier today, the Mozilla Foundation released Firefox 9 and Firefox 3.6.25 to address multiple vulnerabilities that would allow an attacker to execute arbitrary code, cause a denial-of-service condition, or perform a cross-site scripting attack.  (In other words, they could control your browser or PC, cause it not to function, or steal information.)   Campus computers will be updated automatically; however, you are encouraged to update your Firefox installations on personal devices as soon as possible

For additional information, review the Mozilla Foundation Security Advisories for Firefox 9 and Firefox 3.6.25.

Android Devices are High on the Target List

For those of you who own an Android device:  you might want to take a look at these two recent news releases.  Unfortunately, Android's lack of review\approval for Android apps that are available for download plays a huge part in the potential for malicious apps making their way onto your phone or tablet.  There is still no known malware attack against stock iPhones (although jailbroken iPhones are vulnerable).

McAfee:  Nearly All New Mobile Malware in Q3 Targeted at Android  (you can read the full McAfee Threat report here)

Researcher Develops Remote Access Android Exploit

Monday, December 19, 2011

Funny New Phishing Video: "Phishing Bells"

Thanks to our talented friends at the University of Rochester for posting their most recent production of "Phishing Bells", a video about the do's and don'ts when it comes to spam email.  Enjoy!

Thursday, December 15, 2011

Erroneous Virus Message on Windows XP

This morning, the Help Desk has received a number of calls from users indicating that McAfee Antivirus detected and deleted a virus. This has been researched by Information Resourses and identified as a false positive by the antivirus software. This message will only be displayed if the computer you are using is running Windows XP. This does not occur on Windows 7 computers.

A fix has been put in place but it may take a few hours to propagate to all systems across campus. If you see this popup message, just close the message box and click "Cancel" when prompted to perform a file restore. This will clear the message and the system will run normally. If you still have questions or concerns, contact the Customer Support Help Desk at 913-588-7995.

Wednesday, December 14, 2011

Phishing Email: Chase Email Change Notification

Click on the image of the email to view bigger.



























The URL has been blocked from on-campus access. Member of the KUMC community are encouraged to delete this scam email if they receive it.

Phishing Email: Subject line is "N/A"

Click on the image of the email to view bigger.

The link goes to a compromised server belonging to the Westview High School.  We've notified them of the issue and the link is now dead.  Members of the KUMC community who receive this phishing email should delete it.

Tuesday, December 13, 2011

Microsoft Patch Notifications for December 2011

Microsoft released 13 patches today designed to address 20 vulnerabilities, including the one exploited by the Duqu worm.  One of the patches, MS11-087 or KB2639417, addresses a currently exploited issue in the way that the Windows kernel-mode driver handles TrueType font files and has been given a "PATCH NOW" rating by SANS for workstations and a Critical rating for servers.  In addition, there are 7 other patches rated critical for workstations.  Windows, Office and Internet Explorer are all affected and many of the updates will require you to restart your computer.

Members of the KUMC community will have these patches deployed automatically to your on-campus computers, so no further action is needed.  However, you should ensure that your personal computer are updated as soon as possible.

For more information see: http://technet.microsoft.com/en-us/security/bulletin/ms11-dec