Sunday, October 01, 2006

Cybercrooks add Windows flaw to arsenal

Cybercrooks add Windows flaw to arsenal | CNET News.com: "Cybercrooks have started exploiting a flaw in the Windows Shell only days after sample attack code for the vulnerability surfaced. Web sites that exploit the vulnerability are popping up and attempt to load malicious software onto vulnerable Windows PCs in a way that is undetectable to users, experts said.
'There are professionals at work using the exploit code,' security firm Websense said in an alert. The miscreants taking advantage of the flaw appear to be part of the same group that in December used another Windows flaw to hoist spyware onto PCs, Websense said. That flaw stemmed from the way Windows handled Windows Metafile, or WMF images. "

No comments: