Security Alert from the Office of the CTO
Dear Customer,
Whether you are a McAfee customer or not, you are receiving this email because we wanted to make you aware of the latest attack on Corporate America. We hope this attack has not affected your organization and that your security solution of choice has protected your environment. As the attack described above, which McAfee has dubbed “Operation Aurora”, has now been known to have compromised data at Google and at least 30 other companies, McAfee is quickly reaching out to help eliminate further impact from this malware. Since the full extent of this attack is not yet known, McAfee is taking steps to help customers understand what to do now in order to determine if you are attacked, and if so, how to remediate the problem and prevent future attacks.
McAfee Labs identified a zero-day vulnerability in Microsoft Internet Explorer that was used as an entry point for “Operation Aurora” to exploit Google and at least 30 other companies. Microsoft has issued a security advisory and McAfee is working closely with them on this matter. “Operation Aurora” was a coordinated attack which included a piece of computer code that exploits a vulnerability in Internet Explorer to gain access to computer systems. This exploit is then extended to download and activate malware within the systems. The attack, which was initiated surreptitiously when targeted users accessed a malicious Web page (likely because they believed it to be reputable), ultimately connected those computer systems to a remote server. That connection was used to steal company intellectual property and, in Google’s case, gain access to user accounts.
Researchers at McAfee Labs are delivering behavioral and content signatures, Web security, IPS, and IP security updates, product configuration suggestions, and advice on a continuous basis on the McAfee Labs blog. McAfee has built a 5 step action plan to help customers address Aurora immediately:
- Helping customers understand if they are affected
- Recommending upgrades to protect customer systems
- Remediating customer systems that have been compromised
- Preventing new attacks from impacting customers
- Providing online real-time resources
I would like to meet with you to review the details of this plan with you and offer our help to ensure that your systems, network and data are completely protected. I am also attaching an email from McAfee’s CTO, George Kurtz, which outlines some of the details around the steps McAfee can offer to help you. I want to make sure you are aware of all the services and solutions that are available to you at this critical time:
Incident response services. If you believe you may have been attacked by Aurora, McAfee is offering free, onsite Incident Response Services to qualified companies.
Endpoint Security Solution. To help protect your organization from Aurora take advantage of a free trial of McAfee Total Protection for Endpoint with our all-in-one anti-malware technology, intrusion prevention, Web protection, and endpoint firewall solution.
White listing solution. Take advantage of a free trial of McAfee Application Control, our industry-leading application white listing solution that does not require any signature updates and helps prevent zero day attacks.
Network Security Solutions. Secure your network from the Aurora attack today with McAfee’s advanced Network Security technologies.
I will be following up with you shortly to confirm your availability for a discussion focused on protecting your environment both today and in the future. If you’d like to contact me earlier, I’ve included my contact information below.
Please follow these links for more detailed information about Aurora and how to address it:
McAfee’s free Support Notification Service to get the latest critical alerts, notices, and bulletins
McAfee Labs Security Advisories
McAfee Worldwide CTO George Kurtz's blog
McAfee Labs blog
Learn more about McAfee Labs Global Threat Intelligence