Security threats Toolkit
Story: Downadup worm infects 3.5m PCs
Challenge your IT team - ask about their patch management strategy
The continued growth of the MS08-67 RPC issue really drives home the point that while firewalls and antivirus have evolved to become mainstays in network defense, all too many fail to realise that vulnerability management and patching is in fact a critical component of the very foundation of network security. Firewalls and AV are only one level of defence and really are insufficient if they are deployed on top of a weak foundation – lacking underlying vulnerability and patch management.
Take note:
SANS recently reported a clever social engineering trick by the malware – when the autorun.inf triggers the pop up autoplay dialog it changes the executable icon to that of a folder. The user is then tricked into clicking on the folder thinking they are simply going to view the files, NOT knowing that they were actually causing the execution of the malicious program when they click on the folder icon.
Ask about your own organisations patch management approach - the tools we have today are easy to deploy and automate the whole patch management process across a corporate network to really take control by identifying and remediating known vulnerabilities.
Beyond that, ask about Application Control - it can be used effectively to stop this type of infection in it's tracks by preventing the malware from executing in the first place.
Full Talkback thread









