Archive for March, 2010

Will SMS Bring You Free Vouchers?

March 30, 2010 - Symantec Security Response has become aware of multiple reports from mainland China and Hong Kong of an SMS worm targeting the Symbian S60 platform. The worm is detected as SymbOS.Merogo.There are two main reasons that helped the threat in (continue reading...) Read more

Be Savvy, Get Six Months of Internet Security

March 29, 2010 - F-Secure has an additional blog that launched today. It's called Safe and Savvy.You'll notice that the name is pink. That's part of our new brand (continue reading...) Read more

Credit Card Pricing: Do You Check Your Statements?

March 29, 2010 - While I mostly deal with PCI and PCI-related issues, the topic of acquirer pricing does come up occasionally. Today I saw an article about payment card pricing that I think is worth your consideration. The topic (continue reading...) Read more

EXEs in word docs

March 29, 2010 - Today, our friends at Trend Micro blogged about a new attack vector using Microsoft Word documents. We saw this as well last week, and have written a detection for the dropped trojan.It’s not just a “lawsuit” (continue reading...) Read more

Search for News on Moscow Subway Explosions Result in FAKEAV

March 29, 2010 - News of a twin bombing attack in Russia shocked the world on Monday morning as two female suicide bombers blew themselves up in Moscow subway stations. According to news reports, the attacks killed at least 38 and wounded more than (continue reading...) Read more

Microsoft out-of-band patch tomorrow

March 29, 2010 - Microsoft said today it will issue an out-of-band patch tomorrow for a vulnerability in Internet Explorer 6 and 7 that is being actively exploited.“The vulnerability exists due to an invalid pointer reference being used within (continue reading...) Read more

Exploring Heap-Based Buffer Overflows with the Application Verifier

March 29, 2010 - Isolating the root cause of a heap-based buffer overflow can be tricky at best. Thankfully, Microsoft provides a great tool called the Application verifier, which makes the process significantly gentler. In this post, we will look at how to (continue reading...) Read more

Scams Increase During U.S. Tax Season

March 29, 2010 - Scams based on the United States Internal Revenue Service requirements increase every year during tax season. It’s common to see online threats and tactics in which identity thieves and hackers try to convince taxpayers to reveal their personal and financial (continue reading...) Read more

Internet Explorer Cumulative Update Releasing Out-of-Band

March 29, 2010 - Today we issued our Advanced Notification Service (ANS) to advise customers that we (continue reading...) Read more

Adobe Update Trojan Claims are Invalid

March 29, 2010 - Over the weekend, Vietnamese antivirus vendor Bkis blogged about new malware that was allegedly overwriting the legitimate adobeupdater.exe file. From the Bkis blog: Once having infected victims’ computers, malware will overwrite such update programs. and The malware overwrites AdobeUpdater.exe file in the folder (continue reading...) Read more

Cooperation Grows in Fight Against Cybercrime

March 29, 2010 - Last week in Strasbourg, France, the Council of Europe organized the Octopus Interface Conference 2010. More than 300 experts from all over the world, representing governments, law enforcement authorities, international organizations, and the Internet industry gathered to discuss the “Cooperation (continue reading...) Read more

MessageLabs Intelligence Warns of Tax Season Phishing Scams

March 29, 2010 - By Mathew Nisbet, Malware Data Analyst ‘Phishing’ has been around since 1996, and refers to the attempted theft of sensitive information such as usernames, passwords, or credit card details by impersonating a trustworthy source such as a bank. Below is a typical (continue reading...) Read more

Cybercrime and Hacktivism in the Headlines

March 29, 2010 - All over the world, individuals and many organized crime and mafia groups have found that the Internet can help them make a lot of money. Others are motivated by ideology: Manipulated by or acting in accordance with an ethos, they (continue reading...) Read more

How to obtain thousands World of Warcraft accounts for free

March 29, 2010 - In the last weeks we've seen several phishing campaigns targeting World of Warcraft players. This is one of the messages that have been circulating: If you click on the link included in the message, you will get to the following web (continue reading...) Read more

Why does www.avast.eu not take me to Avast? Or, Misdirection on the Internet

March 29, 2010 - Having over 100 million users has its downside—it means that users searching for Avast are also a prime target of scammers as well as legitimate companies trying to piggy-back on our name recognition. Every day we receive complaints from people (continue reading...) Read more

Downadup/Conficker and April Fool’s Day: One Year Later

March 29, 2010 - As we approach April Fool’s Day 2010, we recognize the one-year anniversary of the Downadup/Conficker threat’s April 1, 2009, “trigger” date. A year ago, the security industry monitored Downadup/Conficker activities to be fortified against the criminal or criminals behind the (continue reading...) Read more

XBox Live Director’s Account Compromised

March 29, 2010 - It seems Larry Hryb, Director of XBox Live Programming, had his account taken over at the weekend. However, there are a number of faintly hysterical headlines claiming he was “hacked” along with “are you next?” taglines (such as this (continue reading...) Read more

Treating Software as a Strategic Technology

March 29, 2010 - Lately I've been thinking a lot about the problem of software security - "lately" being the last 15 years of my life, give or take. It seems to be a topic that's perennially on the horizon, because only a few (continue reading...) Read more

“Lawsuits” Spur Spam Attacks

March 28, 2010 - TrendLabs received sample spammed messages claiming to be lawsuit notices. The messages informed recipients of a copyright infringement lawsuit that has been filed against them. The email supposedly came from legitimate law firms such as Marcus Law Center and Crosby (continue reading...) Read more

The Phishing of Indian Job Sites

March 28, 2010 - Despite the global economic slowdown, India witnessed a high number of new jobs in the country during the first quarter of 2010. With the job market looking positive, job sites seem to have benefited with more users accessing their websites. Below (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.