Beware of planned upcoming DDOS attacks. Hackers have been waiting for
Windows support for XP to expire on 4/8. 95% of ATM machines and nearly
30% of desktop PCs still run XP. Large corporations with Microsoft CSA
(custom service agreements) will still receive patches from Microsoft
but the vast majority of XP machines in the wild will be unprotected.
Hackers are planning to use zero day exploits to take over XP machines
and potentially use them as botnets in a coordinated DDOS attack. The
danger doesn't end there. There are reports that these attacks will be
not be simply DDOS attacks but compound attacks where DDOS will be used
to consume security operation center resources while hackers install
malware on vulnerable XP desktops and XP embedded systems.
The attacks may persist for some time since hackers will also attempt
Reverse engineer new patches for Win7/8 platforms and use them on XP.
Last updates for XP (4/8/2014)
The most urgent update is MS14-017 because one of the vulnerabilities it
Addresses is currently being exploited in the wild. Simply opening a
malicious RTF file in Word can compromise a vulnerable system and enable
the attacker to install and execute other malicious code.
The other Critical issue affects Windows XP, but it’s actually the
cumulative patch for Internet Explorer (MS14-018) and impacts all
Versions of Internet Explorer except IE10. The update addresses six
different vulnerabilities, any of which could be exploited remotely to
enable an attacker to remotely execute code with the same rights and
privileges as the logged in user.
The update for Windows—MS14-019—is related to a publicly disclosed
vulnerability in the Windows file handling component. In order to
exploit it, an attacker has to lure users into navigating to a malicious
network directory and somehow trick them into executing the malicious
file. “Because this requires that attackers convince users to run a
specially crafted .BAT or .CMD file provided by the attacker, this
bulletin is of low priority,” says Marc Maiffret, CTO of BeyondTrust.
Finally, there is MS14-020, which deals with a privately disclosed
vulnerability in Microsoft Publisher. Publisher is one of the less used
applications in the Microsoft Office suite, and an attacker would have
to trick a user into opening a specially crafted malicious file in
Publisher to exploit it, so the risk isn't too high. A successful attack
will allow remote code execution with the same privileges as the logged
in user, though, so there is still cause for concern.
Here’s more info:
http://www.digitalattackmap.com/#anim=1&color=0&country=ALL&time=16168&view=map
http://ongoingoperations.com/blog/2013/04/sunset-of-windows-xp-related-to-ddos-attacks/
http://krebsonsecurity.com/2014/04/adobe-microsoft-push-critical-fixes/#more-25555
http://blogs.technet.com/b/security/archive/2014/03/24/cyber-threats-to-windows-xp-and-guidance-for-small-businesses-and-individual-consumers.aspx