Archive for March, 2010

U.S. cyber crime loss spiked in ’09 to $560 M

March 15, 2010 - Here’s an ugly trend.The U.S. Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) has reported that complaints of cyber crime losses in the U.S. more than doubled from $265 million in 2008 to $560 million in 2009. (continue reading...) Read more

Impressions from the RSA 2010 (USA) Conference

March 15, 2010 - Another RSA Conference has come and gone.  I had the privilege of getting a full “delegate” pass this year, which meant that I had access to attend the sessions, so I’ll try to describe the sessions I attended below.  Due (continue reading...) Read more

Scareware: danger!

March 15, 2010 - On Tuesday 9, McAfee warned consumers that “scareware,” or fake antivirus software, may be the most costly online scam in 2010, causing significant monetary loss and damage to users’ computers. With this blog, I wish to give you some (continue reading...) Read more

‘Scareware’ Poses Danger to Consumers

March 15, 2010 - On March 9 McAfee warned consumers that “scareware,” or fake anti-virus software, may be the most costly online scam in 2010, causing significant monetary loss and damage to users’ computers. In this blog, I’ll give you some additional details (continue reading...) Read more

Analyzing PDF Files

March 15, 2010 - We've been seeing a gradual shift in malicious PDF file coding (no surprise there, we know malware authors can and do adapt their techniques).For a long time, we saw malicious PDF files that were simple enough (continue reading...) Read more

Pacquiao-Clottey Live Streams Lead to FAKEAV

March 14, 2010 - The Saturday night boxing match between Manny Pacquiao and Joshua Clottey was one of the most awaited sports events of 2010. It should not be a surprise then that cybercriminals took advantage of it to spread malware. Another blackhat search (continue reading...) Read more

Search for News on Corey Haim’s Death Leads to FAKEAV

March 14, 2010 - For cybercriminals, another celebrity’s death means a new life for their scams. Earlier today, we discovered new FAKEAV variants that take advantage of the death of the former Canadian teen idol, Corey Haim. Using blackhat search engine optimization (SEO) techniques, a (continue reading...) Read more

A Change From Dirty Laundry…

March 13, 2010 - Yesterday evening my student daughter arrived home for the weekend bringing a bag full of laundry, one full of books and, for a change,  the laptop belonging to one of her housemates. It seems that towards the end of last year the impoverished student (continue reading...) Read more

Update on Security Advisory 981374

March 12, 2010 - Hi everyone, I’m writing to let you know that we have updated Security Advisory 981374 with new workaround information. We are aware that exploit code has been made public for this issue. As with our last update, Internet Explorer (continue reading...) Read more

Facebook Users Suffer From ‘Fram’

March 12, 2010 - About a year or so ago one of the “McMarketeers” decided it would be fun to run a campaign against “fram”–spam that friends send you. As you might guess, we in the Labs have no friends, so it was (continue reading...) Read more

Big Safari fix

March 12, 2010 - Apple yesterday released a huge Safari update that fixes 16 vulnerabilities – six for Windows versions and ten for Mac OS X and Windows. The update, Safari 4.0.5, makes fixes in Tiger, Leopard, Snow Leopard and Windows versions.This (continue reading...) Read more

The PCI Council Speaks

March 12, 2010 - Fellow blogger and good friend Anton Chuvakin (aka, Security Warrior) managed to score an exclusive interview with Bob Russo and Troy Leach of the PCI Council while at the RSA Conference. (I think I'm hurt...Bob only (continue reading...) Read more

Malware Gets Smart with Vodafone Smartphone

March 12, 2010 - Security researchers recently unveiled findings about malware that came preinstalled on a Vodafone mobile phone handset. Its memory card was also believed to carry malware. A leading mobile telecommunication company, Vodafone, has been (continue reading...) Read more

More Adobe Exploits in the Wild

March 12, 2010 - Researchers from Microsoft recently unearthed exploits targeting the CVE-2010-0188 vulnerability. On February 16, Adobe released a security advisory describing a vulnerability in Adobe Reader and Acrobat 8.X and 9.X. Once the (continue reading...) Read more

Q & A: Google Hacking

March 12, 2010 - Question and Answer on Help Net Security; Google Hacking with Robert Abela, Acunetix Technical Manager.  In this intervie we discuss: The importance of Google for security research What kind of information about a (continue reading...) Read more

Phishing craigslist – but is it malware?

March 11, 2010 - Malware has traditionally been easy to spot and classify, mainly because it was created to serve a specific nefarious purpose and nothing else. In the ongoing arms race between malware (continue reading...) Read more

Demonstrating the Latest IE 0-day Vulnerability

March 11, 2010 - Yesterday, Microsoft issued a security advisory for an unpatched and actively exploited invalid reference pointer vulnerability in the Internet Explorer 6 and 7 web browsers.  In the attack we observed, the exploit code will load the TDSS.CQ trojan, which is (continue reading...) Read more

Many Zeus botnet C&C servers taken down

March 11, 2010 - Swiss security blog Abuse.ch has reported that the worst Zeus botnet hosting ISP was taken off line yesterday, cutting the botnet’s number of servers from 249 to 181 – including the six worse ones.Abuse.ch wrote: “As (continue reading...) Read more

You don’t want to go looking for Corey Haim videos

March 11, 2010 - Hollywood celebrity Corey Haim has died in typical tabloid fashion: “under investigation.” And we all know that celebrity death equals Internet scams by the boatload.There are a number of spam runs currently circulating on video sharing sites such (continue reading...) Read more

Rogue security products are the new black

March 11, 2010 - Well, it looks like rogues are going to be in style this season.Our good friends at McAfee AV have predicted that the 400 percent increase in rogues (also called “scareware”) they saw in 2009 will continue (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.