An email claiming to alert recipients to a patch for a vulnerability in Outlook is a hoax, security experts have warned.
The emails appear to come from Microsoft and have the subject line "Microsoft Security Bulletin MS07-0065". They warn of a flaw in Outlook that has been used to infect 100,000 PCs and turn them into spambots.
"Security bulletins from Microsoft describing vulnerabilities in their software are a common occurrence, and so it comes as no surprise to see hackers adopting this kind of disguise in their attempt to infect Windows PCs," said Graham Cluley, senior technology consultant for Sophos.
"By using people's real names, the Microsoft logo, and legitimate-sounding wording, the hackers are attempting to fool more people into stepping blindly into their bear-trap," continued Cluley.
The email contains a link that directs you to a website with a patch for the problem, which is in fact a Trojan horse.
"Users need to be on their guard against this kind of confidence trick or they risk handing over control of their PC to hackers with criminal intentions. They should also ensure that they are downloading Microsoft security updates from Microsoft itself and not from any other website," Cluley said.
www.sophos.com