In Case You Missed It: FireEye Top Stories of the Week 7/24

1. Microsoft Plugs
a Hole: The software giant issued an emergency fix for
supported versions of its Windows OS after FireEye research engineer
Genwei Jiang exposed the flaw. The hole essentially allowed attackers
easy
access to control victims’ computers. Coverage of the Microsoft
vulnerability appeared in CNET
News and Before
It’s News.
2. Nigerian Scammers Net $1Million:
FireEye Labs looks at the day-to-day operations of a Nigerian scam.
The criminals are able to hijack
email threads and divert funds from legitimate business
transactions without the victim even realizing it’s happened. Click
here to download
the full FireEye report. Network World, CIO, and Infosecurity
Magazine all covered the report.
3. Facebook of Human Intelligence?
Bloomberg issued a report speculating that China is perhaps running a
distinct campaign to steal
and stockpile information on Americans. The Federal Times
released an article quoting FireEye analyst Jordan Berry, who agreed
that several apparently unrelated incidents over the past two years
could, indeed, indicate “a
clear and apparent shift” toward a coordinated campaign. The
cyberattacks include breaches of American travel companies, health
insurance companies, and the recent breach of the Office of Personnel
Management. China denies any involvement.

4. Choose: Security or Productivity?
FireEye CIO Julie Cullivan’s article “Productivity and
Security, Can You Ever Have Both?” was featured on page 43 of
CIO Review magazine. In it, she addresses three straightforward steps
to managing risk so that enterprises can secure the perimeter of their
network and continue to do business at the same time.

