<?xml version="1.0" ?>

<?xml-stylesheet type="text/xsl" href="http://www.m86security.com/rss/marshalfeedrss.xsl" ?>

<rss version="2.0" xmlns:marshal="http://www.m86security.com/rss/extras/">

<channel>
<image>
<link>http://www.m86security.com</link>
<width>120</width>
<title>M86 Security</title>
<url>http://www.m86security.com/images/logos/m86_logo_120x38.jpg</url>
<height>38</height>
</image>
<title>M86 Security Labs Blog</title>
<link>http://www.m86security.com/labs/</link>
<description>News and commentary about Internet-borne security threats from M86 Security.</description>
<ttl>1440</ttl>
<language>en-us</language> 
<lastBuildDate>Wed, 16 May 2012 23:38:59 GMT</lastBuildDate>
<copyright>Copyright 2012 M86 Security. All Rights Reserved.</copyright>
<webMaster>webmaster@m86security.com (M86 Security Webmaster)</webMaster>
<marshal:feedLink>http://www.m86security.com/rss/trace.asp</marshal:feedLink>
<item>
<title>M86 Security Labs now part of Trustwave&#8217;s SpiderLabs</title>
<link>http://labs.m86security.com/2012/04/m86-security-labs-now-part-of-trustwaves-spiderlabs/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4482</guid>
<description>Many of you are probably already aware of the acquisition of M86 Security by Trustwave. As part of the acquisition, we are pleased to announce that M86 Security Labs is combining with Trustwave&#8217;s SpiderLabs. We are excited by the move, as we become part of a larger and more diverse team of security professionals that [...]</description>
	<pubDate>Sun, 01 Apr 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1333238400" uniqueId="24482" />
</item>
<item>
<title>The Cridex Trojan Targets 137 Financial Organizations in One Go</title>
<link>http://labs.m86security.com/2012/03/the-cridex-trojan-targets-137-financial-organizations-in-one-go/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4455</guid>
<description>A few weeks ago M86 Security Labs alerted that cybercriminals managed to compromise hundreds of WordPress-based sites. These attacks started with several large spam campaigns as reported in our most recent blog post on Cutwail. These emails included embedded URL links or HTML attachments that tricked the user to browse to the compromised Web sites. [...]</description>
	<pubDate>Thu, 01 Mar 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1330560000" uniqueId="24455" />
</item>
<item>
<title>Cutwail Drives Spike in Malicious HTML Attachment Spam</title>
<link>http://labs.m86security.com/2012/02/cutwail-drives-spike-in-malicious-html-attachment-spam/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4367</guid>
<description>Over the past month, we have observed several large spam campaigns with malicious HTML attachments. We believe the botnet behind these campaigns is&#160;Cutwail.&#160;Here is data we collected, starting from the first day of 2012, illustrating spikes of spam with malicious HTML attachments: Attaching an HTML file to an email is a tactic we have seen [...]</description>
	<pubDate>Thu, 16 Feb 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1329350400" uniqueId="24367" />
</item>
<item>
<title>M86 Security Threat Report for the Second Half of 2011 is Now Available</title>
<link>http://labs.m86security.com/2012/02/m86-security-threat-report-for-the-second-half-of-2011-is-now-available/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4357</guid>
<description>We are releasing today our bi-annual Threat Report for 2H 2011. The report relies on M86 Security Labs analysis of spam and malware activity, including the current use of exploit kits, fraudulent digital certificates and social networking schemes. Key points from the M86 Security Labs for the second half of 2011 are: 1. Targeted attacks [...]</description>
	<pubDate>Wed, 08 Feb 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1328659200" uniqueId="24357" />
</item>
<item>
<title>MIDI Files &#8211; Mid-Way to Infection</title>
<link>http://labs.m86security.com/2012/01/midi-files-mid-way-to-infection/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4335</guid>
<description>Microsoft&#8217;s January patch MS12-004 addressed a few vulnerabilities in Windows Media components. One particular issue, CVE-2012-0003, can be exploited via Windows Media Player ActiveX, as it leverages a heap overflow occurring in &#8216;midiOutPlayNextPolyEvent&#8217; function within the Windows Multimedia Library, winmm.dll.&#160;The bad guys didn&#8217;t waste time and this vulnerability is now exploited in the wild as [...]</description>
	<pubDate>Tue, 31 Jan 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1327968000" uniqueId="24335" />
</item>
<item>
<title>Massive Compromise of WordPress-based Sites but &#8216;Everything will be Fine&#8217;</title>
<link>http://labs.m86security.com/2012/01/massive-compromise-of-wordpress-based-sites-but-%e2%80%98everything-will-be-fine%e2%80%99/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4299</guid>
<description>A few days ago, hundreds of websites, based on WordPress 3.2.1, were compromised. The attacker uploaded an HTML page to the standard Uploads folder and that page redirects the user to the Phoenix Exploit Kit. Its logs show that users from at least four hundred compromised sites were redirected to Phoenix exploit pages.&#160; Here is [...]</description>
	<pubDate>Mon, 30 Jan 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1327881600" uniqueId="24299" />
</item>
<item>
<title>Zbot Trojan spreads through fake ConEdison billing notification email</title>
<link>http://labs.m86security.com/2012/01/zbot-trojan-spreads-through-fake-conedison-billing-notification-email/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4276</guid>
<description>Today we came&#160;across a new malicious spam campaign that is actively sent out by the Cutwail spam botnet. The suspicious email claims to be a bill summary from the New York-based energy company Con Edison, Inc. It may use the subject line &amp;#8220;ConEdison Billing Summary as of &amp;#60;DATE&amp;#62;&amp;#8221; and the attachment uses the filename format [...]</description>
	<pubDate>Fri, 13 Jan 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1326412800" uniqueId="24276" />
</item>
<item>
<title>Web Hijacks with AJAX</title>
<link>http://labs.m86security.com/2012/01/web-hijacks-with-ajax/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4257</guid>
<description>Malware authors always seem to closely monitor trends in Web security development in order to create a variety of browser-based attacks. Just to name a few, techniques such as code obfuscation, plug-in detection and affiliate management are often used. This is why we, at M86 Security, weren&amp;#8217;t surprised to see a malicious site which loads [...]</description>
	<pubDate>Tue, 03 Jan 2012 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1325548800" uniqueId="24257" />
</item>
<item>
<title>Prevalent Exploit Kits Updated with a New Java Exploit</title>
<link>http://labs.m86security.com/2011/12/prevalent-exploit-kits-updated-with-a-new-java-exploit/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4213</guid>
<description>Until recently, most of the vulnerabilities exploited by popular exploit kits were found last year or even earlier. Moreover, it would take authors at least a month to update their kits with the new exploits that had been discovered in the wild. However, in the past few weeks, authors released an updated version of their [...]</description>
	<pubDate>Fri, 16 Dec 2011 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1323993600" uniqueId="24213" />
</item>
<item>
<title>A new Adobe 0-day In the Wild &#8211; &#8211; But No Worries, You are Already Protected with Our Secure Web Gateway!</title>
<link>http://labs.m86security.com/2011/12/a-new-adobe-0-day-in-the-wild-%e2%80%93-%e2%80%93-but-no-worries-you-are-already-protected-with-our-secure-web-gateway/</link>
<guid isPermaLink="false">http://labs.m86security.com/?p=4205</guid>
<description>Yesterday Adobe released an advisory for a vulnerability in the Adobe Reader and Adobe Acrobat products. The vulnerability, titled &amp;#8216;U3D Memory Corruption Vulnerability&amp;#8217; was part of a targeted attack and discovered by Lockheed Martin&amp;#8217;s Computer Incident Response Team. This is not the first time a targeted attack has been aimed at the US defense industry. [...]</description>
	<pubDate>Wed, 07 Dec 2011 07:00:00 GMT</pubDate>
<marshal:parameters timestamp="1323216000" uniqueId="24205" />
</item>
</channel>
</rss>

