May 30–June 5, 2011The Cyber Risk Report is a strategic intelligence product that highlights current security activity and mid- to long-range perspectives. The report addresses seven major risk management categories: vulnerability, physical, legal, trust, identity, human, and geopolitical. Cyber Risk Reports are powered by Cisco Security Intelligence Operations, an advanced security infrastructure that identifies, analyzes, and defends against threats to keep organizations informed and protected. Cyber Risk Reports are the collaborative efforts of Cisco security analysts from the following teams: IntelliShield, Applied Intelligence, Remote Management Services, Intrusion Prevention System Signature Development, Cisco Product Security Incident Response, Cisco Malware Research, Strategic Technology Assessment Team, Infrastructure Security Research & Development, IronPort Email and Web Threat Research, Critical Infrastructure Assurance Group, Advanced Services, Security Sales and Engineering, Corporate Security Programs, Government Affairs, and Legal Support. VulnerabilityVulnerability activity for the period was slightly increased, impacted somewhat by the U.S. holiday on Monday, May 30, 2011. Highlights for the period include security updates from Cisco for multiple vulnerabilities; HP for Java; Apple for MacDefender; VMware for multiple vulnerabilities; Red Hat for multiple vulnerabilities; Symantec for vulnerabilities in Backup Exec and PRZ file processing in multiple products; IBM, Tivoli, and Wireshark for multiple vulnerabilities; and Adobe for Flash Player. Vulnerability metrics for May and 2011 have surpassed those of 2010. The increase trend for the first 5 months of 2011 has now reached 2,183 alerts, compared to 2,062 alerts at this time in 2010. This is a significant increase for a 5-month period, and shows a substantial increase in vulnerability activity for 2011 following the declining trend through 2009 and 2010. Cisco released four security advisories for multiple vulnerabilities in Cisco Unified IP Phones and Cisco AnyConnect Secure Mobility Client, a default credentials vulnerability in Cisco Network Registrar, and a default credentials vulnerability for the Cisco Media Experience Engine. These security advisories, IntelliShield alerts, IPS signatures, and Applied Mitigation Bulletin are available at the Cisco Security Intelligence Operations website. Wireshark released version 1.4.7 to correct multiple vulnerabilities in prior versions. Due to Wireshark's wide use by network administrators, these vulnerabilities impact systems with elevated privileges. HP released multiple advisories, including Java updates reported in the April Oracle Critical Patch Update. Java vulnerabilities continue to be highly targeted in exploits and attacks, making these updates a priority for HP systems. Apple released a security advisory and updates for the MacDefender malware currently targeting Apple Mac OS X systems. The update is in addition to the previously released advisory with recommendations. Multiple antivirus sources reported activity of the Droid Dream Light malware that targets Android operating system smart phones. The malware was identified in multiple applications for the Google Android Market, which have now been removed from the market. However, thousands of Android users have reported being impacted by the malware. Additional detail on this malware is available in IntelliShield Alert 23296. In upcoming activity, World IPv6 Day is scheduled for June 8, 2011. On this date, several major Internet companies will offer IPv6 services for organizations and individuals to test their systems for IPv6 functionality. Additional information about the event is available at the Internet Society website, Cisco's World IPv6 Day website, and multiple vendor websites. IntelliShield published 91 events last week: 42 new events and 49 updated events. Of the 91 events, 63 were Vulnerability Alerts, five were Security Activity Bulletins, four were Security Issue Alerts, 17 were Threat Outbreak Alerts, one was a Malicious Code Alert, and one was a Cyber Risk Report. The alert publication totals are as follows: Weekly Alert Totals
2011 Monthly Alert Totals
Significant Alerts for the Time PeriodApple Mac OS X MacDefender Fake Antivirus Malicious Software Previous Alerts That Still Represent Significant RiskMicrosoft Office Excel Array Indexing Vulnerability HP, IBM, and Oracle Multiple Java Products Security Update Multiple Vendor Issue Revocation for Fraudulent SSL Certificates Microsoft Windows MHTML Protocol Handler Script Execution Vulnerability Multiple Adobe Products SWF File Processing Arbitrary Code Execution Vulnerability LizaMoon SQL Script Injection Attacks RSA Breach Exposes SecurID Information Multiple Apple Products Security Update on March 2, 2011 Linux Kernel video4linux and compat_mc_getsockopt() Privilege Escalation Vulnerability EXIM Mail Transfer Agent Arbitrary Configuration Loading root Privilege Escalation Vulnerability PhysicalThere was no significant activity in this category during the time period. LegalElectronic Frontier Foundation Tor ChallengeThe Electronic Frontier Foundation (EFF) has created a program to establish more anonymous relays for the Tor network, which provides anonymous network access for activists to protect their identity and bypass internet filtering and controls in their host countries. The EFF is attempting to recruit individuals to sign up for the challenge, providing instructions on creating different types of relays and how to register the relay for use. IntelliShield Analysis: Many enterprises and organizations may already block access to the Tor network due to legal issues of intellectual property and copyright infringement, but the EFF Tor Challenge opens another consideration in the use of this network. While this may be a compelling cause for individuals, the use of business systems to support the EFF efforts could have legal repercussions to the business or organization as the owners of those systems. Malicious or attack activity could also be attracted to the relay systems. The relays could consume large amounts of bandwidth if they become actively used, which could also impact individual users who may have bandwidth limits on their service provider accounts. TrustThere was no significant activity in this category during the time period. IdentityThere was no significant activity in this category during the time period. HumanGoogle Reports Account Phishing CampaignGoogle reported that it identified and disrupted a malicious phishing campaign targeting Google Gmail accounts and attempting to monitor e-mail from those accounts. Google reported that their systems had not been compromised, but the phishing campaign was targeted at individual Gmail users. Google reported notifying the impacted account owners. Google also notified government officials because some of the identified accounts belonged to government officials in the U.S. and Asian governments as well as to activists and journalists. IntelliShield Analysis: Credit Google for identifying and disrupting this phishing attack and quickly notifying users and government officials. While the phishing campaign was traceable to a city in China, that in itself does not attribute the attack to China or even a Chinese attacker. It does demonstrate the risks associated with individuals who use web-based mail accounts, particularly those who hold sensitive positions in business, politics, or the military. The attackers apparently thought they would be able to monitor sensitive information from these accounts, and they were likely correct. While many users maintain personal e-mail accounts outside their official or business accounts, the risk of information leaking in to those messages and the inadvertent disclosure of sensitive information is high. Individuals should be regularly reminded and aware of the risks of letting information slip between their official and personal accounts and constantly on guard to prevent that leakage. GeopoliticalSaudi Arabia and the Arab SpringYemeni President Ali Abdullah Saleh, injured in a rocket attack against his palace last week, was flown to Saudi Arabia for treatment. Press reports speculated that he might not return to Yemen, following weeks of increasingly violent protests against his continued presidency and failed negotiations on his peaceful departure. Saudi Arabia's offer of medical treatment and refuge for the widely reviled Saleh draws attention to Saudi Arabia's role in the Arab Spring. With the notable exception of demonstrations in Shia-dominated eastern Saudi Arabia near the border with Bahrain, protests in the kingdom this spring have been muted. Most citizens appear to favor gradual reform while maintaining the existing monarchy. The kingdom is not immune from regional winds of change, however, and social media plays a familiar role. A Twitter campaign is calling for women to drive cars in public on June 17 in defiance of the standing prohibition. Women also launched a Facebook page protesting exclusion from voting in long-delayed municipal elections this fall. IntelliShield Analysis: Regional unrest has added urgency to the Saudi Royal Family's ongoing efforts to invest oil wealth wisely to create a sustainable, knowledge-based economy. The 87-year-old King Abdullah has announced more than $100 billion in new public spending projects in the past few months, while some fear that the political upheaval in neighboring countries may have slowed the pace of social reforms. Efforts to attract foreign academics and technology innovators through mega-projects such as the King Abdullah University for Science and Technology and the King Abdullah Economic City have enjoyed some success, particularly in netting participants from emerging markets. However, technology multinationals may be able to support Saudi education officials in promoting the kingdom's resources as a virtual innovation hub, allowing people to participate without relocating physically to the kingdom. Saudi Arabia's conservative social policies and active monitoring of data networks, meanwhile, may mean that foreign companies will want to concentrate business focus on supporting the kingdom's stated public spending priorities, which include education, health care, maximizing scarce natural resources, and building infrastructure. Upcoming Security ActivityCiscoLive Bahrain: Postponed National elections in Thailand and Mexico: July 3, 2011 Additional InformationFor more information about the vulnerabilities contained in this report or the Cisco Security IntelliShield Alert Manager Service, please visit For information on obtaining a free trial of the Cisco Security IntelliShield Alert Manager Service, please visit This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document or materials linked from the document is at your own risk. Cisco reserves the right to change or update this document at any time. |