Threat Research

#securechat Recap: Cloud Computing

January 26th, 2012

 - Q1: Are you thinking about using cloud storage to manage email, contacts, music, etc? Which one? Q2: What is the most important function of cloud computing in your personal life? Q2 part 2: What features (continue reading...)

Katy Perry and Russell Brand baits to spread a new Facebook worm

January 26th, 2012

 - Once again, user curiosity becomes cyber-criminals’ best ally. Scammers exploit people’s interest in celebrities to infect users. We have recently detected a new Facebook scam that uses a fake video of singer Katy Perry and (continue reading...)

SchmooCon to Cover Hot Mobile Security Topics

January 26th, 2012

 - The ShmooCon security conference takes place in Washington D.C. this weekend. There will be a good number of mobile and embedded talks, covering attacks on and defense of Bluetooth, Android, NFC, RFID, and more.
Disposable computer (continue reading...)

US Police use games consoles in crime investigations

January 26th, 2012

 - Police in the US use XBox 360 and PS3s as key parts of investigations. With police now cooperating more closely with companies like Microsoft, is it time to ask for greater transparency about their relationships? (continue reading...)

Facebook Fakebook: New Trends in Carberp Activity

January 26th, 2012

 - Aleksandr Matrosov, one of my colleagues in Moscow, writes:
This month we discovered some new facts relating to Win32/Carberp trojan activity. We have spent a lot of time writing about Carberp already, but interesting information is (continue reading...)

Opinion: Google’s privacy change – evil or business as usual?

January 26th, 2012

 - Google says it will start tracking us across all its services - Gmail, Search, YouTube, etc. - and that it will share data on our activity across all of them. Does it put into question (continue reading...)

Insight into Sykipot Operations

January 26th, 2012

 - The Sykipot campaign has been persistent in the past few months targeting various industries, the majority of which belong to the defense industry. Each campaign is marked with a unique identifier comprised of a (continue reading...)

Anonymous Anonymous Claims Anonymous is Not Anonymous

January 26th, 2012

 -  You've probably heard about the stratfor.com hack by now. Anonymous claimed responsibility. Then Anonymous denied being responsible.But then today, (continue reading...)

Fake Tumblr Staff Blog Leads to Starbucks Gift Cards

January 26th, 2012

 - We’re seeing a lot of freshly compromised Tumblr accounts, all of which are posting up an image file located here that claims to be a “Tumblr Staff Blog” (it isn’t), proclaiming the joys of “Free (continue reading...)

Phoenix, Phoenix, I need help!

January 25th, 2012

 - The Websense® ThreatSeeker® Network has been tracking an ongoing
malicious email campaign in which a recipient is asked to click a link
to check a bill mistakenly received by another user.  We have been
monitoring campaigns of thousands (continue reading...)

pcAnywhere Users Alert — Patch Now!

January 25th, 2012

 - SANS reports that Symantec has just released a document describing vulnerabilities for pcAnywhere users. You can click here to get details and a link to the document. I know many (continue reading...)

Using DLP to Categorize Your Data and Reduce Risk

January 25th, 2012

 - Data classification is an important – and very challenging – problem. It is all about tagging your data so that it can be found quickly and efficiently.  It is part of the Information Lifecycle (continue reading...)

McAfee Reference Architecture: Obtaining Benefits from PCI

January 25th, 2012

 - The Payment Card Industry (PCI) Security Standards Council is an open global forum, launched in 2006, responsible for the development, management, education and awareness of the PCI Security Standards – including retail standards for (continue reading...)

Symantec: Stop using pcAnywhere, right now

January 25th, 2012

 - Symantec has admitted that blueprints for current versions of its pcAnywhere software were stolen in 2006 and that all users are at risk of attack and should pull the plug. (continue reading...)

Introducing Project Zulu

January 25th, 2012

 - 
I want to personally and publicly thank Julien, Pradeep and Mike for all of their hard work over the past several months, to make today's launch of Project Zulu a (continue reading...)

Fake missing plugin warnings used for spam/spyware

January 25th, 2012

 - 
A key element for a successful spam/malicious page is to establish trust with the visitor so that he will perform the requested actions. Users trust their browser, but not necessarily the (continue reading...)

Spammers continue to take advantage of holidays and events

January 25th, 2012

 - Beginning on New Year's Eve, January 1, 2012 and continuing earlier into the days following, Symantec Intelligence identified spammers taking advantage of the New Year anniversary, seemingly to entice users into clicking on spam links (continue reading...)

Acunetix WVS 8 Released Candidate Now Available!

January 25th, 2012

 - We are pleased to announce a Release Candidate (RC) of the much-awaited Acunetix Web Vulnerability Scanner, version 8. This build fixes issues that (continue reading...)

Chuck Norris is NOT dead – beware the Facebook scam!

January 25th, 2012

 - Messages have been spread on Facebook claiming to link to a video news report of the death of awesome martial arts film star Chuck Norris.

How To Steal A Car: Hack It!

January 25th, 2012

 - No more jimmying doors with a Slim Jim, bricks through windows, extracting lock cylinders with a dent puller, or hot-wiring ignitions. Automobiles today are being built to include wireless capabilities that allow for remote unlock, (continue reading...)

Copyright © 2012 The Security Blog. All rights reserved.