<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spoofed Microsoft Outlook Critical Update spammed in email</title><link>http://msmvps.com/blogs/harrywaldron/archive/2009/06/22/spoofed-microsoft-outlook-critical-update-spammed-in-email.aspx</link><description>As many folks realize Microsoft does not distribute updates by email . However, Microsoft will alert users who have signed up for Patch Tuesday notifications, that new updates are available. In the links below, Trend Labs notes a highly deceptive email</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Spoofed Microsoft Outlook Critical Update spammed in email</title><link>http://msmvps.com/blogs/harrywaldron/archive/2009/06/22/spoofed-microsoft-outlook-critical-update-spammed-in-email.aspx#1696688</link><pubDate>Thu, 25 Jun 2009 09:08:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1696688</guid><dc:creator>Richard South</dc:creator><description>&lt;p&gt;Thanks, that email is arriving with current (25/06/09) date.&lt;/p&gt;
&lt;p&gt;Your infor has allowed me to issue warning with confidence to my collegues&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1696688" width="1" height="1"&gt;</description></item><item><title>re: Spoofed Microsoft Outlook Critical Update spammed in email</title><link>http://msmvps.com/blogs/harrywaldron/archive/2009/06/22/spoofed-microsoft-outlook-critical-update-spammed-in-email.aspx#1696574</link><pubDate>Wed, 24 Jun 2009 12:31:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1696574</guid><dc:creator>Filo Hirota</dc:creator><description>&lt;p&gt;Good that I found this page. Otherwise,there is not way to know that the mail was spoofed. Is there anyway that Microsoft could alert its users of this kind of danger?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1696574" width="1" height="1"&gt;</description></item><item><title>re: Spoofed Microsoft Outlook Critical Update spammed in email</title><link>http://msmvps.com/blogs/harrywaldron/archive/2009/06/22/spoofed-microsoft-outlook-critical-update-spammed-in-email.aspx#1696394</link><pubDate>Tue, 23 Jun 2009 15:23:56 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1696394</guid><dc:creator>SARGE</dc:creator><description>&lt;p&gt;Useful info.&lt;/p&gt;
&lt;p&gt;with regards to &lt;/p&gt;
&lt;p&gt;&amp;quot;best practice of hovering over email links would reveal a different one than shown in the document.&amp;quot;&lt;/p&gt;
&lt;p&gt;i noticed the real microsoft link begins:&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;a rel="nofollow" target="_new" href="http://update.microsoft.com&amp;quot;"&gt;http://update.microsoft.com&amp;quot;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;however in this instance they&amp;#39;ve snuck in &amp;quot;llik1i&amp;quot; after the word microsoft. (as per below)&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;a rel="nofollow" target="_new" href="http://update.microsoft.llik1i.com&amp;quot;"&gt;http://update.microsoft.llik1i.com&amp;quot;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;i&amp;#39;m guessing they chose l&amp;#39;s 1&amp;#39;s and i&amp;#39;s as they are the thinest characters on a keyboard&lt;/p&gt;
&lt;p&gt;may they die horribly.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1696394" width="1" height="1"&gt;</description></item></channel></rss>