Threat Research

Should having autism be a legal defence to hacking charges?

February 10th, 2012

 - Gary McKinnon and Ryan Cleary have raised the profile of hackers with autism. With this week marking the 10th anniversary of Gary McKinnon's arrest, and with his fate still hanging in the balance, how (continue reading...)

Avast! Free Mobile Security Contest results.

February 10th, 2012

 - 
Since you asked for avast! Free Mobile Security (for Android) and we gave it to you, we wanted to celebrate its launch with our (continue reading...)

Apple supplier Foxconn hacked not for bad factory conditions but for kicks

February 10th, 2012

 - Foxconn, a Taiwanese manufacturer of Apple's iPhone and iPad infamous for inhumane working conditions, has been hacked by a group calling itself Swagg Security.

VIDEO: Boston Police hits back at Anonymous with sarcasm

February 10th, 2012

 - Anonymous is proud of saying that an idea can't be arrested or killed, but it seems like the Boston Police Department has thought of one way of fighting back: sarcasm. (continue reading...)

Is Waledac Spam Dirtying the Russian 2012 Elections?

February 10th, 2012

 - Recently there have been several reports about the re-emergence of a botnet variant (Kelihos), which Symantec detects as W32.Waledac.C. The Waledac family is a threat that has been monitored by Symantec for (continue reading...)

Facebook/app data privacy – sharing gone wild

February 9th, 2012

 - So you browse your favorite restaurant review site and settle on a great Mediterranean restaurant, and “magically” a variety of preferences get fed back to your Facebook profile, to be shared, re-shared and re-shared, ricocheting (continue reading...)

Google Wallet PINs easily stolen from rooted devices

February 9th, 2012

 - A researcher at zvelo has discovered that he can recover the PIN used to make payments with Google Wallet in just seconds on a rooted Android device. (continue reading...)

Getting Value from Your DLP Investment

February 9th, 2012

 - People can sometimes feel overwhelmed when they think about deploying data loss prevention (DLP) at their organization. Some common concerns I hear from prospects are:

First I want to classify my data.  How can I do (continue reading...)

February 2012 Patch Tuesday Preview

February 9th, 2012

 - 
Microsoft published its Patch Tuesday Preview for February of 2012 and as expected we are getting a larger batch of nine bulletins addressing a total of (continue reading...)

ANS for February 2012, and some notes on SDL

February 9th, 2012

 - Hello. Today we’re releasing our advance notification for the February security bulletin release, which is scheduled for Tuesday, February 14. This month’s release includes nine bulletins addressing 21 vulnerabilities in Microsoft Windows, Office, Internet (continue reading...)

Cracking Open Your (Google) Wallet

February 9th, 2012

 - We suggested earlier that instead of going after the Secure Element chip and the information it keeps safe, attackers would go after the weaker point of the Google (continue reading...)

#EpicFail for U.S. student who used keylogger to increase grades

February 9th, 2012

 - 31-year-old student from Warrington admits to trying to improve his grades at Temple University Ambler Campus, near Philadelphia, by hacking into the university’s computerised grading system.

Is this the resurgence of Blackhat SEO?

February 9th, 2012

 - Take a dive into some recent blackhat SEO attacks in this post to explore the facts behind the recent rise in reports of this threat. Site administrators in particular may be interested in some of (continue reading...)

Man charged with NASA hack, on 10th anniversary of Gary McKinnon’s arrest

February 9th, 2012

 - It's ten years since British hacker Gary McKinnon was arrested, and now another hacker has been indicted for allegedly hacking into NASA computers.

Better Business Bureau malware attack spammed out

February 9th, 2012

 - Have you received an email claiming to come from the Better Business Bureau (BBB) today? If you did, be careful.

M-unition 2.0: Changes on the Horizon

February 9th, 2012

 - With the new year comes some exciting changes for MANDIANT’s M-unition blog. We began the blog back in 2008 to share interesting research, new tools and new ideas.  But we’ve seen the industry (and the (continue reading...)

New Targeted Attack Using Office Exploit Found In The Wild

February 9th, 2012

 - Contribution: Takayoshi Nakayama
I was going through some files we acquired related to targeted attacks the other day and an unusual set of files caught my eyes. We did some analysis on the files and it (continue reading...)

Is Digital Pearl Harbor THE most tasteless term in IT security?

February 9th, 2012

 - Can hackers really cause as much bloodshed as 353 Imperial Japanese Navy fighters, bombers and torpedo planes launched from six aircraft carriers?

Can hackers really kill 2,402 U.S. citizens, leave 1,282 wounded, lose 65 of their (continue reading...)

VIPRE Report for January 2012 Released

February 8th, 2012

 - Social engineering ploys doesn’t grow old—probably never will considering how effective they are no (continue reading...)

Infostealer.Offsupload: 20,000+ Archives Containing Stolen Data Uploaded to Third Party File-Sharing Site

February 8th, 2012

 - Upwards of 20,000 stolen archives have been uploaded to a third party file-sharing site from hosts infected with a new threat called Infostealer.Offsupload. The following heatmap indicates the U.S. is the primary target of infection, (continue reading...)

Copyright © 2012 The Security Blog. All rights reserved.