<?xml version="1.0" ?>

<?xml-stylesheet type="text/xsl" href="http://www.m86security.com/rss/marshalfeedrss.xsl" ?>

<rss version="2.0" xmlns:marshal="http://www.m86security.com/rss/extras/">

<channel>
<image>
<link>http://www.m86security.com</link>
<width>120</width>
<title>M86 Security</title>
<url>http://www.m86security.com/images/logos/m86_logo_120x38.jpg</url>
<height>38</height>
</image>
<title>M86 Security Labs Blog</title>
<link>http://www.m86security.com/labs/</link>
<description>News and commentary about Internet-borne security threats from M86 Security.</description>
<ttl>1440</ttl>
<language>en-us</language> 
<lastBuildDate>Sat, 04 Feb 2012 06:31:52 GMT</lastBuildDate>
<copyright>Copyright 2012 M86 Security. All Rights Reserved.</copyright>
<webMaster>webmaster@m86security.com (M86 Security Webmaster)</webMaster>
<marshal:feedLink>http://www.m86security.com/rss/trace.asp</marshal:feedLink>
<item>
<title>MIDI Files &#8211; Mid-Way to Infection</title>
<link>http://labs.m86security.com/2012/01/midi-files-mid-way-to-infection/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4335</guid>
<description>Microsoft&#8217;s January patch MS12-004 addressed a few vulnerabilities in Windows Media components. One particular issue, CVE-2012-0003, can be exploited via Windows Media Player ActiveX, as it leverages a heap overflow occurring in &#8216;midiOutPlayNextPolyEvent&#8217; function within the Windows Multimedia Library, winmm.dll.&#160;The bad guys didn&#8217;t waste time and this vulnerability is now exploited in the wild as [...]</description>
	<pubDate>Tue, 31 Jan 2012 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1327968000" uniqueId="24335" />
</item>
<item>
<title>Massive Compromise of WordPress-based Sites but &#8216;Everything will be Fine&#8217;</title>
<link>http://labs.m86security.com/2012/01/massive-compromise-of-wordpress-based-sites-but-%e2%80%98everything-will-be-fine%e2%80%99/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4299</guid>
<description>A few days ago, hundreds of websites, based on WordPress 3.2.1, were compromised. The attacker uploaded an HTML page to the standard Uploads folder and that page redirects the user to the Phoenix Exploit Kit. Its logs show that users from at least four hundred compromised sites were redirected to Phoenix exploit pages.&#160; Here is [...]</description>
	<pubDate>Mon, 30 Jan 2012 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1327881600" uniqueId="24299" />
</item>
<item>
<title>Zbot Trojan spreads through fake ConEdison billing notification email</title>
<link>http://labs.m86security.com/2012/01/zbot-trojan-spreads-through-fake-conedison-billing-notification-email/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4276</guid>
<description>Today we came&#160;across a new malicious spam campaign that is actively sent out by the Cutwail spam botnet. The suspicious email claims to be a bill summary from the New York-based energy company Con Edison, Inc. It may use the subject line &amp;#8220;ConEdison Billing Summary as of &amp;#60;DATE&amp;#62;&amp;#8221; and the attachment uses the filename format [...]</description>
	<pubDate>Fri, 13 Jan 2012 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1326412800" uniqueId="24276" />
</item>
<item>
<title>Web Hijacks with AJAX</title>
<link>http://labs.m86security.com/2012/01/web-hijacks-with-ajax/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4257</guid>
<description>Malware authors always seem to closely monitor trends in Web security development in order to create a variety of browser-based attacks. Just to name a few, techniques such as code obfuscation, plug-in detection and affiliate management are often used. This is why we, at M86 Security, weren&amp;#8217;t surprised to see a malicious site which loads [...]</description>
	<pubDate>Tue, 03 Jan 2012 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1325548800" uniqueId="24257" />
</item>
<item>
<title>Prevalent Exploit Kits Updated with a New Java Exploit</title>
<link>http://labs.m86security.com/2011/12/prevalent-exploit-kits-updated-with-a-new-java-exploit/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4213</guid>
<description>Until recently, most of the vulnerabilities exploited by popular exploit kits were found last year or even earlier. Moreover, it would take authors at least a month to update their kits with the new exploits that had been discovered in the wild. However, in the past few weeks, authors released an updated version of their [...]</description>
	<pubDate>Fri, 16 Dec 2011 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1323993600" uniqueId="24213" />
</item>
<item>
<title>A new Adobe 0-day In the Wild &#8211; &#8211; But No Worries, You are Already Protected with Our Secure Web Gateway!</title>
<link>http://labs.m86security.com/2011/12/a-new-adobe-0-day-in-the-wild-%e2%80%93-%e2%80%93-but-no-worries-you-are-already-protected-with-our-secure-web-gateway/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4205</guid>
<description>Yesterday Adobe released an advisory for a vulnerability in the Adobe Reader and Adobe Acrobat products. The vulnerability, titled &amp;#8216;U3D Memory Corruption Vulnerability&amp;#8217; was part of a targeted attack and discovered by Lockheed Martin&amp;#8217;s Computer Incident Response Team. This is not the first time a targeted attack has been aimed at the US defense industry. [...]</description>
	<pubDate>Wed, 07 Dec 2011 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1323216000" uniqueId="24205" />
</item>
<item>
<title>Cutwail Spam Campaigns Lure Users to Blackhole Exploit Kit</title>
<link>http://labs.m86security.com/2011/12/cutwail-spam-campaigns-lure-users-to-blackhole-exploit-kit/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4176</guid>
<description>Over the past few days the Cutwail botnet has been sending out malicious spam campaigns with a variety of themes such as airline ticket orders, Automated Clearing House (ACH), Facebook notification, and scanned document. These campaigns do not have malware attachments, instead the payload is delivered via links to malicious code hosted on the web. [...]</description>
	<pubDate>Thu, 01 Dec 2011 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1322697600" uniqueId="24176" />
</item>
<item>
<title>TrueType but not Truly Safe: The New Zero-Day Event</title>
<link>http://labs.m86security.com/2011/11/truetype-but-not-truly-safe-the-new-zero-day-event/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4163</guid>
<description>A new vulnerability in Windows, CVE -2011-3402, has been recently identified and is already exploited in the wild.&#160; For now, only a handful of targeted attacks have been found. The vulnerability exists in Windows TrueType Font Parsing Engine and affects most Windows versions, including Windows 7. An attack involves a file which has a maliciously [...]</description>
	<pubDate>Tue, 08 Nov 2011 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1320710400" uniqueId="24163" />
</item>
<item>
<title>&#8220;Steve Jobs Alive!&#8221; Spam Campaign Leads To Exploit Page</title>
<link>http://labs.m86security.com/2011/10/steve-jobs-alive-spam-campaign-leads-to-exploit-page/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4142</guid>
<description>It was a sad day in the technology industry with the recent passing of Apple&#8217;s legendary leader, Steve Jobs.&#160;Unfortunately, the cyber-criminals see this as an opportunity. Today, we started seeing a Steve Jobs spam campaign, with the subject suggesting that he is still alive. Steve Jobs Alive! Steve Jobs Not Dead! Steve Jobs: Not Dead [...]</description>
	<pubDate>Fri, 07 Oct 2011 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1317945600" uniqueId="24142" />
</item>
<item>
<title>New Google AdWords Phish In-the-wild</title>
<link>http://labs.m86security.com/2011/10/new-google-adwords-phish-in-the-wild/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4108</guid>
<description>For those of you who have a Google AdWords account, be wary of a new Google AdWords spam campaign we have seen in-the-wild earlier this week. The spam email may use the following subject lines: Google AdWords: You have a new alert. Google Team: You have a new alert Here is an example of the [...]</description>
	<pubDate>Tue, 04 Oct 2011 08:00:00 GMT</pubDate>
<marshal:parameters timestamp="1317686400" uniqueId="24108" />
</item>
</channel>
</rss>

