It's been reported that a fake email claiming to be from Redhat has been circulating. The fake message urges Redhat and Fedora users to download and apply a security update from fedora-redhat. Note that the real fedora site is located at http://fedora.redhat.com.
The "upgrade" is actually a tarred binary that installs a trojan on the system.
Note from redhat regarding this issue: