Threat Research

VBMania: When Minutes Count

September 21st, 2010

 - Some malware attacks come so quickly that by the time you react, it’s too late. That was a lesson learned the hard way by thousands of organizations last week with VBMania, otherwise known as (continue reading...)

Chinese Holiday Spam – Celebration of the Moon Festival and National Day

September 21st, 2010

 - Chinese spammers are actively involved in the upcoming celebration of the Mid-Autumn Festival and National day. The Chinese Mid-Autumn Festival (Moon Festival) will occur on September 22 this year andthe government has declared that October (continue reading...)

MouseOver, Game Over

September 21st, 2010

 - In some computer programming languages there is an event called “mouseover”. This command is used to determine what happens when a user put the mouse over a specific object. When you put the mouse over (continue reading...)

IT Risk and Social Web Leverage

September 21st, 2010

 - Leverage in all forms is a powerful thing.  For both good and bad.  The popularity and speed of social
websites provide an amazing degree of leverage for both businesses and hackers.  The Twitter (continue reading...)

Twitter XSS vulnerability fixed

September 21st, 2010

 - Twitterers are still clogging the micro-blogging service with little messages (continue reading...)

Javascript Exploit on Twitter

September 21st, 2010

 - Posted on behalf of Mathew Nisbet, Malware Data Analyst
Today there has been a lot of traffic on Twitter related to a very recently discovered Javascript exploit. It took advantage of the way Twitter handled Javascript (continue reading...)

Twitter OnMouseOver Flaw In The Wild

September 21st, 2010

 - As of this morning we have been monitoring a flaw on twitter.com that delivers pop-ups to Twitter users when they move their mouse cursor over a specially crafted tweet.  There is also the potential to (continue reading...)

Twitter ReTweet Spam (XSS)

September 21st, 2010

 - This morning before I even logged into my system, I was receiving inquiries about the Twitter Spam going around. The source looks like: (continue reading...)

Behind the scenes (science & alchemy)

September 21st, 2010

 - 

Greetings from Central Europe. I’ll not bother to say much about myself (Google is there for any who have a deeper interest), but I’ll tell you that, in summer of 2010, I joined AVAST Software (continue reading...)

Can rogue AV ever be legitimate?

September 21st, 2010

 - Over the past year, the prevalence of search results laced with rogue AV seemed to never end.  Whether the search was about celebrity, politics, calamity, or anything that was hot and trending, blackhat SEO was (continue reading...)

Phishing Attempt Alert!

September 20th, 2010

 -  Someone has been trying to pose as us again, and is sending out an e-mail that looks like this:From: Account SupportDate: Saturday, August 28, 2010 4:33 AM (continue reading...)

CPAlead Spam on YouTube

September 20th, 2010

 -  One of our Safe and Savvy bloggers, Melody-Jane, recently asked me about some "free" offers for F-Secure Internet Security 2010 that she spotted on YouTube. She thought the videos, and their (continue reading...)

Update to Security Advisory 2416728

September 20th, 2010

 - Hi everyone -
We've just updated Microsoft Security Advisory 2416728 as we've begun to see limited attacks with the ASP.NET vulnerability.  We have added questions and answers and encourage customers to review this information (continue reading...)

Memory forensics on Windows 7 (x86 and x64) and Windows 2008 x64

September 20th, 2010

 - Next month Memoryze will be two years old and a lot has changed over that time. There has been a lot of interesting research in the field of memory forensics, and responders are (continue reading...)

Five Irrefutable Laws of Information Security

September 20th, 2010

 - Last week, Forrester held its annual Security Forum 2010 and discussed, among other topics, the need for consistent controls on our endpoint devices to ensure continuous security and network protection. In his keynote entitled (continue reading...)

Evolution to Intelligent Whitelisting: Part 2: Four Whitelisting Misperceptions to Abandon

September 20th, 2010

 - Part 2 of a three-part Q&A podcast series with Pat Clawson, Chairman and CEO, Lumension and Patrick O’Grady, Technology Writer, Phoenix Business Journal
Part 1: Not Your Father’s Whitelisting
Click here to view Part 1: Not (continue reading...)

"Hot Video" pages: analysis of an hijacked site (Part I)

September 20th, 2010

 - I was fortunate enough to find a hijacked site which was being used to host fake "Hot video" pages, which I've blogged about before. However, this time around, the site had directory listings enabled. (continue reading...)

Why do so many people buy into “checklist” audits?

September 20th, 2010

 - Probably my biggest pet peeve related to application security is the claim by many (typically management) that “We know we’re secure, we just had an audit”. (continue reading...)

Bing advert peddles Firefox with Hotbar adware

September 20th, 2010

 - Firefox: how much freer can it get?Alert Sunbelt Blog reader Jesse C alerted us to this one. We’ll just quote his email to describe what’s going (continue reading...)

Zeus Crimeware Toolkit

September 20th, 2010

 - The Zeus botnet has been in the wild since 2007 and it is among the top botnets active today. This bot has an amazing and rarely observed means of stealing personal information–by infecting users’ computers (continue reading...)

Copyright © 2012 The Security Blog. All rights reserved.