Today there are, as usual, a number of active botnets, zero day exploits and purveyors of miscellaneous malware. The one that has received all the publicity is the Windows LNK file exploit which seems to be designed to attack Siemens SCADA systems. Another one that popped up  on the Shadow server listserv is a new sort of malware that packed in such a way that it is not detected by any current anti-virus program - and that will mutate easily to evade the detection algorithms of most anti-virus programs.

For a network admin or similar, both of these are nasty because the proactive workarounds to protect against both are intrusive and result in significantly degraded user experience assuming you can actually apply them to all the computers under your control.

If you are in charge of a network and aren't a ThreatSTOP subscriber then you will probably spend a lot of time trying to figure out how serious these threats are, whether your users/servers have got infected and how to stop the inevitable "call home" from the infected computers on your network to the C&C hosts of the cyber-criminals who seeded the malware. And quite possibly you will decide that there really aren't enough hours in the day to permit any worthwhile countermeasures and drown your sorrows in drink.

