Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Thursday, March 21, 2013

Beware of "Facebook Black"

"Facebook Black" malware spreading fast on Facebook

A new virus is hitting Facebook users with an Fake Facebook Black template which would allow the users to use an black template instead of the known white template.

The malware is spreading crazy on Facebook as it asks the users to click on a link that will install an application. This Black Facebook scam uses the trust of the Facebook users and then forwards the malware to their network and friends.

So please be warned do not click on the Facebook black template.


Revoke access

This malware uses an Facebook API to gain information. If you wish to revoke the access of the Facebook Black template virus then you have to do the following:

  • Navigate to the following url: http://www.facebook.com/settings?tab=applications
  • Search for the Facebook Black malware and delete it.

Monday, September 24, 2012

New malware "Mirage" targeting energy firms

Malware targets individuals via "spear-phishing" e-mails bearing tainted PDF files

Researchers have uncovered a new cyberespionage campaign being waged on a large Philippine oil company, a Taiwanese military organization and a Canadian energy firm, as well as targets in Brazil, Israel, Egypt and Nigeria. 

The malware being used is called "Mirage" and it leaves a backdoor on the computer that waits for instructions from the attacker, said Silas Cutler, a security researcher at Dell SecureWorks' Counter Threat Unit (CTU). Victims are carefully targeted with so-called "spear-phishing" e-mails with attachments that are "droppers" designed to look and behave like PDF documents.

However, they are actually standalone executable files that open an embedded PDF file and execute the Mirage trojan. The malware disguises its "phone home" communications to resemble Google searches by using Secure Socket Layers (SSL) in order to avoid detection, Cutler wrote in a report this week.

Researchers were able to take over domains being used in the campaign that were no longer registered or had expired and they used them to set up a "sinkhole" designed to receive any communications from infected computers. By pretending to be a command-and-control server they learned that there were about 80 unique IP addresses that appeared to be infected, involving as many as 120 individual computers.

"Deeper analysis of the phone-home requests and correlation with social networking sites allowed CTU researchers to identify a specific individual infected with Mirage. It was an executive-level finance manager of the Phillipine-based oil company," the report says.

Researchers couldn't say what data the attackers were aiming for, but it's not difficult to speculate given that countries are vying for oil and gas exploration rights in the South China Sea. It's unclear who is behind the campaign, but whoever sponsored it is "well funded and very active," said Joe Stewart, director of malware research at Dell SecureWorks.

While he declined to speculate who sponsored the campaign, the report said proxy software used on some of the command-and-control servers was created by a member of a Chinese hacker group called the "Honker Union of China." 

"We interrupted their command chain, so we don't know what documents they're looking for," he said. "Typically it's competitive information." The researchers believe that whoever is responsible also played a part an espionage campaign earlier in the year that targeted Vietnamese oil companies and government ministries, an embassy, a nuclear safety agency and others in various countries.

The command-and-control IP addresses used in the Mirage campaign belong to the China Beijing Province Network, as did three of the IP addresses used in the earlier "Sin Digoo" malware campaign, according to the researchers. This is the latest in a number of reports of international cyberespionage that have cropped up in recent years, with energy, defense and critical infrastructure firms increasingly being targeted.

Wednesday, June 27, 2012

Nobody can halt cyberweapons creation

Interesting read posted by New York Times - A Weapon We Can't Control


The decision by the United States and Israel to develop and then deploy the Stuxnet computer worm against an Iranian nuclear facility late in George W. Bush's presidency marked a significant and dangerous turning point in the gradual militarization of the Internet.


Washington has begun to cross the Rubicon. If it continues, contemporary warfare will change fundamentally as we move into hazardous and uncharted territory. It is one thing to write viruses and lock them away safely for future use should circumstances dictate it. It is quite another to deploy them in peacetime.


Stuxnet has effectively fired the starting gun in a new arms race that is very likely to lead to the spread of similar and still more powerful offensive cyberweaponry across the Internet. Unlike nuclear or chemical weapons, however, countries are developing cyberweapons outside any regulatory framework. There is no international treaty or agreement restricting the use of cyberweapons, which can do anything from controlling an individual laptop to disrupting an entire country's critical telecommunications or banking infrastructure.


It is in the United States' interest to push for one before the monster it has unleashed comes home to roost. Stuxnet was originally deployed with the specific aim of infecting the Natanz uranium enrichment facility in Iran. This required sneaking a memory stick into the plant to introduce the virus to its private and secure "offline" network. But despite Natanz's isolation, Stuxnet somehow escaped into the cyberwild, eventually affecting hundreds of thousands of systems worldwide.


This is one of the frightening dangers of an uncontrolled arms race in cyberspace; once released, virus developers generally lose control of their inventions, which will inevitably seek out and attack the networks of innocent parties. Moreover, all countries that possess an offensive cyber capability will be tempted to use it now that the first shot has been fired. Until recent revelations by The New York Times' David E. Sanger, there was no definitive proof that America was behind Stuxnet.


Now computer security experts have found a clear link between its creators and a newly discovered virus called Flame, which transforms infected computers into multipurpose espionage tools and has infected machines across the Middle East. The United States has long been a commendable leader in combating the spread of malicious computer code, known as malware, that pranksters, criminals, intelligence services and terrorist organizations have been using to further their own ends.


But by introducing such pernicious viruses as Stuxnet and Flame, America has severely undermined its moral and political credibility. Flame circulated on the Web for at least four years and evaded detection by the big antivirus operators like McAfee, Symantec, Kaspersky Labs and F-Secure - companies that are vital to ensuring that law-abiding consumers can go about their business on the Web unmolested by the army of malware writers, who release nasty computer code onto the Internet to steal our money, data, intellectual property or identities. But senior industry figures have now expressed deep worries about the state-sponsored release of the most potent malware ever seen.


During the cold war, countries' chief assets were missiles with nuclear warheads. Generally their number and location was common knowledge, as was the damage they could inflict and how long it would take them to inflict it. Advanced cyberwar is different: A country's assets lie as much in the weaknesses of enemy computer defenses as in the power of the weapons it possesses. So in order to assess one's own capability, there is a strong temptation to penetrate the enemy's systems before a conflict erupts. It is no good trying to hit them once hostilities have broken out; they will be prepared and there's a risk that they already will have infected your systems.


Once the logic of cyberwarfare takes hold, it is worryingly pre-emptive and can lead to the uncontrolled spread of malware. Until now, America has been reluctant to discuss regulation of the Internet with Russia and China. Washington believes any moves toward a treaty might undermine its presumed superiority in the field of cyberweaponry and robotics. And it fears that Moscow and Beijing would exploit a global regulation of military activity on the Web, in order to justify and further strengthen the powerful tools they already use to restrict their citizens' freedom on the Net.


The United States must now consider entering into discussions, anathema though they may be, with the world's major powers about the rules governing the Internet as a military domain. Any agreement should regulate only military uses of the Internet and should specifically avoid any clauses that might affect private or commercial use of the Web.


Nobody can halt the worldwide rush to create cyberweapons, but a treaty could prevent their deployment in peacetime and allow for a collective response to countries or organizations that violate it. Technical superiority is not written in stone, and the United States is arguably more dependent on networked computer systems than any other country in the world.


Washington must halt the spiral toward an arms race, which, in the long term, it is not guaranteed to win.


Source: New York Times

Thursday, May 24, 2012

Beware fake Chrome installers for Windows.

Fake Google Chrome Installer Steals Banking Details


A file named "ChromeSetup.exe" is being offered for download on various websites, and the link to the file appears to be legitimately hosted on Facebook and Google domains. In reality, the software won't install Google's Chrome browser, but an information-stealing Trojan application known as Banker, according to antivirus vendor Trend Micro.


Once the malware--which appears to be targeting Latin American users, especially in Brazil and Peru--is executed, it relays the IP address and operating system version to one of two command-and-control (C&C) servers, then downloads a configuration file. After that, whenever a user of the infected PC visits one of a number of banking websites, the malware intercepts the HTTP request, redirects the user to a fake banking page, and also pops up a dialog box informing the user that new security software will be installed.


In fact, the malware has been designed uninstall GbPlugin, which is "software that protects Brazilian bank customers when performing online banking transactions," said Trend Micro security researcher Brian Cayanan in a blog post. "It does this through the aid of gb_catchme.exe--a legitimate tool from GMER called Catchme, which was originally intended to uninstall malicious software. The bad guys, in this case, are using the tool for their malicious agendas."

Refer here to read further details.

Wednesday, February 22, 2012

Half of the Fortune 500 companies are still infected with DNSChanges Virus!

FBI could take down Internet for millions on March 8

On March 8, the FBI may be forced to shut down DNS servers, originally installed to stop the spread of the DNSChanger virus, which would cut off Internet access to millions of Web users worldwide.

The Federal Bureau of Investigation may soon be forced to shut down a number of key Domain Name System (DNS) servers, which would cut Internet access for millions of Web users around the world, reports BetaBeat.

The DNS servers were installed by the FBI last year, in an effort to stop the spread of a piece of malware known as DNSChanger Trojan. But the court order that allowed the set up of the replacement servers expires on March 8.

In November of last year, authorities arrested six men in Estonia for the creation and spread of DNSChanger, which reconfigures infected computers’ Internet settings, and re-routes users to websites that contain malware, or other illegal sites. DNSChanger also blocks access to websites that might offer solutions for how to rid the computer of its worm, and often comes bundled with other types of malicious software.

By the time the FBI stepped in, DNSChanger had taken over computers in more than 100 countries, including half-a-million computers in the US alone. To help eradicate the widespread malware, the FBI replaced infected servers with new, clean servers, which gave companies and individuals with infected computers time to clean DNSChanger off their machines.

Unfortunately, DNSChanger is still running on computers “at half of the Fortune 500 companies,” and at “27 out of 55 major government entities,” reports cybersecurity journalist Brian Krebs. These computers rely on the FBI-installed DNS servers to access the Web. But if the court order is not extended, the FBI will be legally required to remove the clean servers, which would cut off the Internet for users still infected with DNSChanger.

Companies or other agencies that are unsure whether their systems are infected with DNSChanger can get free assistance here. And private users can find out if they are infected using instructions provided here.

Thursday, February 9, 2012

Trojan rounds up and steals Word and Excel docs

Malware Uses Sendspace to Store Stolen Documents

Beware of bogus FedEx emails asking you to review a shipment notification - the attached Fedex_Invoice.exe is actually a downloader Trojan that opens you computer to other pieces of malware.

In this particular case spotted by Trend Micro researchers, it downloads and executes a Trojan that searches for and snatches MS Word and Excel documents from the infected machine.

"The collected documents are then archived and password-protected using a random-generated password in the user’s temporary folder," they share. And after creating the archive, it sends it to sendspace.com, a file hosting service that allows its users to send, receive, track and share files.

Once the archive is uploaded, the malware retrieves the Sendspace download link, and then sends it to the C&C server operated by the crooks along with the password needed to open it.

This is not the first time that Sendspace has been used by cyber thieves to store stolen data, and the same can be said for other free online hosting services.

Unfortunately, the criminals have realized that these legitimate services allow them to forgo the need of operating their own drop zones.

Saturday, December 3, 2011

Norway hit by major data-theft attack

Industrial secrets from companies were stolen and "sent out digitally from the country

Data from Norway's oil and defense industries may have been stolen in what is feared to be one of the most extensive data espionage cases in the country's history.

Industrial secrets from companies were stolen and "sent out digitally from the country," the Norwegian National Security Authority said, though it did not name any companies or institutions that were targeted.

At least 10 different attacks, mostly aimed at the oil, gas, energy and defense industries, were discovered in the past year, but the agency said it has to assume the number is much higher because many victims have yet to realize that their computers have been hacked.

"This is the first time Norway has unveiled such an extensive and widespread espionage attack," it said.
Spokesman Kjetil Berg Veire added it is likely that more than one person is behind the attacks.

The methods varied, but in some cases individually crafted e-mails that, armed with viruses, would sweep recipients' entire hard-drives for data and steal passwords, documents and confidential documents.

The agency said in a statement that this type of data-theft was "cost-efficient" for foreign intelligence services and that "espionage over the Internet is cheap, provides good results and is low-risk." Veire would not elaborate, but said it was not clear who was behind the attacks.

The attacks often occurred when companies were negotiating large contracts, the agency said.
Important Norwegian institutions have been targeted by hackers before.

In 2010, some two weeks after Chinese dissident and democracy activist Liu Xiaobo was named that year's Nobel Peace Prize winner, Norway's Nobel Institute website came under attack, with a Trojan Horse, a particularly potent computer virus, being installed on it.

Other attacks on the institute in that same period came via email, containing virus-infected attachments.

Refer here to read further details.

Sunday, November 20, 2011

Hackers attack Norway's oil, gas and defence businesses

Oil, gas and defence firms in Norway have been hit by a series of sophisticated hack attacks.

Industrial secrets and information about contract negotiations had been stolen, said Norway's National Security Agency (NSM).

It said 10 firms, and perhaps many more, had been targeted in the biggest wave of attacks to hit the country.

Norway is the latest in a growing list of nations that have lost secrets and intellectual property to cyber thieves.

The attackers won access to corporate networks using customised emails with viruses attached which did not trigger anti-malware detection systems.

Targeted attacks

The NSM said the email messages had been sent to specific named individuals in the target firms and had been carefully crafted to look like they had come from legitimate sources.


Many of the virus-laden emails were sent while the companies were in the middle of negotiations over big contracts.

It said user names, passwords, industrial drawings, contracts and documents had been stolen and taken out of the country.

The NSM believes the attacks are the work of one group, based on its analysis of the methods used to target individuals, code inside the viruses and how the data was extracted.

The agency said it was publishing information about the attacks to serve as a warning and to encourage other targeted firms to come forward.

"This is the first time Norway has revealed extensive and wide computer espionage attacks," the NSM said in a statement.

Singled out

It said it found out about the attacks when "vigilant users" told internal IT security staff, who then informed the agency.


However, the NSM said, it was likely that many of the companies that had been hit did not know that hackers had penetrated their systems and stolen documents.

Security firms report that many other nations and industrial sectors have been targeted by data thieves in recent months.

The chemical industry, hi-tech firms and utilities appear to have been singled out.

Sourced: BBC News

Thursday, August 4, 2011

Conficker found on external HD devices on sale

Aldi recalls Conficker-infected hard drives

Australian supermarket chain ALDI might seem like the last place where one can pick up a Conficker infection, but according to an emergency security alert by the Australian Computer Emergency Response Team, the worm has been discovered on a Fission External 4-in-1 Hard Drive/DVD/USB/Card Reader product the stores offer for sale.

ALDI has effected an immediate recall of the product from its shelves and has urged customers who have bought the product to return it. The chain says that the worm was found on a small number of the devices, and that it can be removed by fully formatting them.

SCMagazine Australia reports that AusCERT has also advised a full format of the device for those who won’t be returning it to the store and to scan their computer with an up-to-date AV solution. Since Conficker is an old threat, the majority of commercial AV solution contain the signature for spotting it.

The worm’s presence on the drives has initially been detected by a Kaspersky AV product, and “the manufacturer recommends that this same software or similar be used to scan all customers’ computers and USB storage devices which have been in contact with the four-in-one hard drive, to detect and remove if present,” an ALDI spokeperson stated.

Thursday, March 10, 2011

Anti-Virus Software - To buy or not to buy?

Free anti-virus software does the job!

To buy or not to buy? That is the question. When it comes to anti-virus software for your computer, most experts agree you need it if you have the Windows operating system and often go online, where dangers lurk.

But name-brand software could set you back $40 to $70 or more a year. Alternatively, some excellent products are available for free. What's a prudent consumer to do?

The short answer is that if you refuse to pay for computer protection software, at least use a free product in lieu of nothing. On that, experts agree. Beyond that, it's difficult to generalize with so many products available. But the difference basically comes down to this: Free software will help you discover a problem, such as a virus, and deal with it.

Paid software has more features that might help keep you from getting a problem in the first place, especially if you're inexperienced online or visit risky websites. Here are some considerations.

Free software

Popular free products include Avira AntiVir Personal, AVG Anti-virus Free Edition, Avast! Free Antivirus and Microsoft's own Security Essentials. Be aware that the many free products, while good at what they do, are essentially a marketing tool to persuade you to buy the same brand's paid version. Microsoft is an exception. It has no upsell.

Some reviewers claim the free anti-virus software might be all you need. Consumer Reports, for example, says that free products are "fine for most people."

Paid software

Experts are quick to point out that you are likely to get broader protection and functionality using security software that you pay for. The free-versus-paid discussion is "an artificial wall," said Dan Nadir, senior director of product management for Norton security software, a paid product. "There is this perception you can get an apples-to-apples free version with a free product; it's not true," he said. "I think the way users should think about this is that if you're going online, you should get a paid product - even the free guys have paid products."

On their websites, many of the free products have charts showing how their paid products have more features that keep you safe online, while banking and shopping, for example.
Nadir conceded that free products do an excellent job of detecting viruses and removing them. "Everyone can do well on these static virus-scanning tests," he said. The value of a paid product is the "real world" protection offered by smarter software that can sniff out a threat even if it's never been told specifically about the threat - all without falsely alarming users, Nadir said.

Examples of features you might get with a paid product that you don't get with a free one are a firewall, parental controls, spam controls and browser toolbars to prevent phishing, scams meant to lure people into releasing sensitive information. Individual free products do many of those things, but a paid software suite gives you a common program to control everything.

Paid software also gives you technical support by phone, which free products generally won't offer. And some paid suites offer a backup function for your files. "Those are extras that are not critical, but are minor to moderate pluses," Reynolds said.

PCWorld magazine, using a recognized security testing company, recently rated highly Symantec Norton Internet Security 2011, which got top billing in many other reviews too. Kaspersky Internet Security 2011 and BitDefender Internet Security 2011 also rated highly.

For technical comparisons, check online at av-test.org and av-comparatives.org.

So, paid or free? PCWorld puts it this way: "With some exceptions, you get better customer support and more comprehensive security features with a paid product, but if you're willing to forgo these, it's definitely worth considering going free."

Thursday, January 13, 2011

Gangsters hiring hackers to make “cyber attacks”

Korean DDoS arrests - be warned, you can be caught

A group of gangsters have been caught hiring hackers to make “cyber attacks” to shut down rival gambling websites. The Korean Times reports the arrest of a pair of hackers over the weekend on DDoS charges. According to prosecutors, the pair, Lee and Park, operated a gambling website on behalf of a crime gang. In an effort to boost traffic to their own site, they used a 50,000-strong botnet to overload 109 rival sites during November and December 2010.

A botnet, of course, is a collection of malware-infected computers (often called "zombies") which can remotely be instructed to initiate network-related activity. Sending spam is a common criminal task for which zombies are used; visiting targeted websites deliberately to waste their bandwidth is another.

Since most web requests look alike, distinguishing the web hits of malevolent time-wasters from those of potential customers can be tricky. Sites which don't usually get a large number of simultaneous requests often aren't built to sustain heavy load.

Some simple warnings come out of this:

* Make sure your PC isn't infected with malware. Otherwise, it might be aiding and abetting criminal activity. In most countries, you can't yet be prosecuted for unknowingly having a zombified computer, but you may get cut off by your ISP - and quite rightly, too! The "offence" will be that you failed to act for the greater good of everyone else on the internet.

* If you're flirting with joining the ranks of the cybervandal group Anonymous when it urges people to join in DDoS attacks, typically in an effort to deny free speech in an effort to protest the denial of free speech, don't assume that you won't get caught. And don't expect much sympathy if you do.

* DDoSing a prospective customer is a high-risk sales technique.

Wednesday, January 12, 2011

Beware - Facebook phishing scam

Facebook phishing email

The email, which resembles genuine friend requests, includes the message `Hi, the following person invited you to be their friend on Facebook’ and an invitation to join the social networking site.

Symantec security channel product manager, Robert Pregnell, said the email can be identified as a fake because it has no confirm button and there is no prompt for an email address to sign up to the site.

“At this time we can’t say that this particular email is of a particularly aggressive or high-profile attack,” he said.

According to Pregnell, the emails can be stopped by checking the privacy policy and user account settings on the social networking site. He also advised users to have separate passwords for different accounts and regularly update their internet security.

“Have a different password for each online account and stay updated,” he said. “Make sure your antivirus, internet security, operating system and web browser software is up-to-date.”

“Multi-layered internet security programs offer additional protection with strong, non-obtrusive firewalls, watching for personal details going out of your computer, and for suspicious behaviour, even by legitimate programs on your computer.”

McAfee Asia Pacific chief technology officer, Michael Sentonas, said the Facebook phishing scam is designed to trick the recipient into going through the login process in order to accept the new friend request.

“For the unsuspecting people that do click on this and submit their login information, they may appear to login as they would normally, however, their credentials are almost always sent to the scammer as well,” he said.

He said research conducted by McAfee has shown that as much as 85 per cent of emails in some months are spam, including these types of phishing scams.

Monday, September 27, 2010

Stuxnet worm infected at least 30,000 Windows PCs

Iran confirms massive Stuxnet infection of industrial systems

Officials in Iran have confirmed that the Stuxnet worm infected at least 30,000 Windows PCs in the country, multiple Iranian news services reported on Saturday. Experts from Iran's Atomic Energy Organization also reportedly met this week to discuss how to remove the malware.

Stuxnet, considered by many security researchers to be the most sophisticated malware ever, was first spotted in mid-June by VirusBlokAda, a little-known security firm based in Belarus. A month later Microsoft acknowledged that the worm targeted Windows PCs that managed large-scale industrial-control systems in manufacturing and utility companies.

Those control systems, called SCADA, for "supervisory control and data acquisition," operate everything from power plants and factory machinery to oil pipelines and military installations.

Refer here to read more details.

Friday, September 17, 2010

Beware: Old-style email worm spreading

“Here you have” email worm spreads

An old-style email worm was spreading Thursday, antivirus vendors reported. The malware, named “Here you have” for the message it carries in the subject line, includes a link that appears to be a PDF file but instead is a malicious program, according to McAfee.

If someone clicks on the link, the malware sends itself to all the contacts in the recipient’s address book and tries to disable security software. The worm harkens back to the “I LOVE YOU” virus that inundated email boxes 10 years ago. In fact, the Anna Kournikova mass-mailer from 2001 also used “Here you have” in its subject line.

ABC News reported that it was hit by the new worm, along with NASA, Wells Fargo, Comcast and Disney. McAfee rated the malware as a medium risk.

Tuesday, September 7, 2010

IBM X-Force Mid-Year Trend and Risk Report

2010 Mid-year highlights

The IBM X-Force 2010 Mid-Year Trend and Risk Report reveals several key trends that demonstrate how, in the first half of 2010, attackers seeking to steal money or personal data increasingly targeted their victims via the Internet. The IBM X-Force Trend and Risk Report is produced twice per year: once at mid-year and once at year-end. This report provides statistical information about all aspects of threats that affect Internet security, including software vulnerabilities and public exploitation, malware, spam, phishing, web-based threats, and general cyber criminal activity.

Summary

Attackers are increasingly using covert techniques like Javascript obfuscation and other covert techniques which continue to frustrate IT security professionals. Obfuscation is a technique used by software developers and attackers alike to hide or mask the code used to develop their applications.

Reported vulnerabilities are at an all time high, up 36%. 2010 has seen a significant increase in volume of security vulnerability disclosures, due both to significant increases in public exploit releases and to positive efforts by several large software companies to identify and mitigate security vulnerabilities.

PDF attacks continue to increase as attackers trick users in new ways. To understand why PDFs are targeted, consider that endpoints are typically the weakest link in an enterprise organization. Attackers understand this fact well. For example, although sensitive data may not be present on a particular endpoint, that endpoint may have access to others that do. Or, that endpoint can be used as a practical bounce point to launch attacks on other computers.

The Zeus botnet toolkit continues to wreak havoc on organizations. Early 2010 saw the release of an updated version of the Zeus botnet kit, dubbed Zeus 2.0. Major new features included in this version provide updated functionality to attackers.

Vulnerabilities and exploitation highlights

=> Advanced persistent threat—What concerns X-Force most about these sophisticated attackers is their ability to successfully penetrate well defended networks in spite of significant advances in network security technology and practices. In particular, we are concerned about increasingly obfuscated exploits and covert malware command-and-control channels that fly under the radar of modern security systems.

=> Obfuscation, obfuscation, obfuscation—Attackers continue to find new ways to disguise their malicious traffic via JavaScript and PDF obfuscation. Obfuscation is a technique used by software developers and attackers alike to hide or mask the code used to develop their applications. Things would be easier if network security products could simply block any JavaScript that was obfuscated,but unfortunately, obfuscation techniques are used by many legitimate websites in an attempt to prevent unsophisticated Web developers from stealing their code. These legitimate websites act as cover for the malicious ones, turning the attacks into needles in a haystack.

=> PDF attacks continue to increase as attackers trick users in new ways. To understand why PDFs are targeted, consider that endpoints are typically the weakest link in an enterprise organization. Attackers understand this fact well. For example, although sensitive data may not be present on a particular endpoint, that endpoint may have access to others that do. Or, that endpoint can be used as a practical bounce point to launch attacks on other computers.

=> Reported vulnerabilities are at an all time high—2010 has seen a significant increase in the volume of security vulnerability disclosures, due both to significant increases in public exploit releases and to positive efforts by several large software companies to identify and mitigate security vulnerabilities.

=> Web application vulnerabilities have inched up to the 55 percent mark, accounting for fully half of all vulnerability disclosures in the first part of 2010.

=> Exploit Effort versus Potential Reward—What are attackers really going after? With the number of vulnerability announcements rising and vendors scrambling to provide patches and protection to problem areas, how can enterprises best prioritize the efforts of IT administrators to provide adequate coverage? The Exploit Effort versus Potential Reward Matrix provides a simple model for thinking about vulnerability triage from the perspective of attackers.

Please refer here to download or view the report.

Wednesday, August 4, 2010

IPad's open to attack

Drive-by attack could enslave iPad, iPhone
A newly discovered vulnerability in the software that runs Apple's IPad and IPhone could allow hackers to remotely enslave the popular mobile devices.
The flaw which affects Apple's iOS that also runs the IPod Touch, could allow hackers to take complete control. Attackers could trick a user into visiting a website with a tainted PDF to infect the devices. Apple is now investigating the report.

Saturday, June 26, 2010

World Cup web traffic - the distribution of malicious malware is way up

Cisco Warns Of Rising World Cup Malware


As the world’s legitimate Web traffic increases, so do instances of spam e-mail, Internet-borne malware and general hacker activity. When special or unusual events happen — such as the current Gulf oil spill or the FIFA World Cup soccer tournament in South Africa — communications traffic of all kinds skyrockets. This takes into account text messaging, e-mail, Web searches, cell phone usage, television and Web streaming video, among others.


Cisco ScanSafe SAAS Web security service reported June 18 that after a week of World Cup activities, the global increase in Web traffic is up by an average of 27 percent during World Cup matches.


Japan noted the highest increase (53 percent), followed by the U.K. (37 percent), Germany (32 percent), Australia (20 percent) and Singapore (9 percent). In the United States, the increase worked out to about 8 percent — lower because soccer isn’t the overwhelming phenomenon there as it is worldwide.


Refer here for more details on this news.

Wednesday, June 2, 2010

New computer security threat for wireless networks

Danger in the internet café?

University of Calgary (UC) computer science professors John Aycock and Mea Wang have identified a type of computer security threat, called Typhoid adware, that gains access to computers through wireless networks found in Internet cafes or other areas where users share non-encrypted wireless connections.

"We're looking at a different variant of adware--Typhoid adware--which we haven't seen out there yet, but we believe could be a threat soon," Aycock says. Typhoid adware comes from another person's computer and convinces other laptops to communicate with it and not the legitimate access point. Then the Typhoid adware automatically inserts advertisements in videos and Web pages on the other computers.

Aycock and Wang developed several defenses against Typhoid adware. One solution protects the content of videos to ensure that what users see comes directly from the original source, and another solution offers a way to "tell" laptops they are in an Internet cafe to make them more suspicious of contact from other computers.

Please refer
here to read more details.

Saturday, May 29, 2010

Scientist Infects Himself With Computer Virus

Hacking the Human Body

University of Reading scientist Mark Gasson has deliberately infected himself with a computer virus in order to study the potential risks of implanting electronic devices in humans. Gasson implanted a radio frequency identification chip into his left hand last year.


The chip, which is about the size of a grain of rice, gives him secure access to Reading's buildings and his mobile phone. Gasson then introduced a computer virus into the chip. He says the infected microchip contaminated the system that was used to communicate with it, and notes that it would have infected any other devices it was connected to.

Gasson says the experiment provides a "glimpse at the problems of tomorrow," considering devices such as heart pacemakers and cochlear implants are essentially mini-computers that communicate, store, and manipulate data. "This means that, like mainstream computers, they can be infected by viruses and the technology will need to keep pace with this so that implants, including medical devices, can be safely used in the future," he says.

Refer
here to read more details --May Require Free Registration

Tuesday, May 25, 2010

Facebook told to set up warning system after new sex scam

Sex-video scam, Facebook users warned

Sophos, a major computer security firm urged Facebook on Tuesday to set up an early-warning system after hundreds of thousands of users were hit by a new wave of fake sex-video attacks.

Sophos warned users of the world's biggest social networking site to be on guard against any posting entitled "distracting beach babes", which contains a movie thumbnail of a bikini-clad woman. In a press statement, Sophos said the malicious posts appear as if they are coming from Facebook users' friends, but it urged recipients not to click on the thumbnail.

By clicking on it, users are taken to a rogue Facebook application informing them that they do not have the right player software installed. It tricks users into installing adware, a software package that automatically plays, displays or downloads advertisements to their computer, and the video link is spread further across the network.

Sophos said that "hundreds of thousands" of Facebook users were believed to have received the posts over the past weekend. It followed a similar scam that spread on Facebook the week before involving a fake posting tagged as the "sexiest video ever".

It's time for Facebook to set up an early warning system on their network, through which they can warn their almost 500 million users about breaking threats as they happen.

A simple message appearing on all users' screens warning them of the outbreak would have helped in halting the attack. Unless something is done, it won't be surprising if there is another widespread attack this coming weekend, affecting thousands more users.

The social networking site is already under fire for revealing users' information too freely on the Internet. Facebook chief executive Mark Zuckerberg said Monday that the website "missed the mark" with its complex privacy controls and would reveal simpler features in the coming weeks.