| 

‘Botnet' sends out spam as malware spreads on Android phones: researcher

  • Post author: Omid Farhang
  • Post published: July 15, 2012
  • Reading Time: 2 min
  • Word Count: 307 words

Malware has been spreading on Android mobile phones that takes control of certain email accounts to create a “botnet” to send out spam, a security researcher says. Microsoft security engineer Terry Zink says the malware has infected phones of users’ Yahoo email accounts to send out spam messages. “We’ve all heard the rumors, but this is the first time I have seen it – a spammer has control of a botnet that lives on Android devices,” Zink said in a blog post on Tuesday. ...

Continue Reading ‘Botnet' sends out spam as malware spreads on Android phones: researcher

Fake Skype app on Android is malware

  • Post author: Omid Farhang
  • Post published: July 15, 2012
  • Reading Time: 2 min
  • Word Count: 248 words

ZDNet Wrote: A new piece of malware is trying to take advantage of Skype’s increasing popularity, especially on mobile devices. Cybercriminals have created a fake version of the Skype for Android app, designed to earn money from unsuspecting users. Trend Micro, which first discovered the malware, is calling this particular threat JAVA_SMSSEND.AB. The Java in the name should not surprise you, given that Android apps are primarily developed in a custom version of the programming language. Thankfully, this is not a very good fake. The app in question only runs on older (pre Software Installation Script) Symbian phones or Android devices that allow execution of Java MIDlet. ...

Continue Reading Fake Skype app on Android is malware

Chrome 20 update fixes high-risk security vulnerabilities

  • Post author: Omid Farhang
  • Post published: July 13, 2012
  • Reading Time: 2 min
  • Word Count: 264 words

Google has published a new update to the stable 20.x branch of Chrome to close a number of security holes in the WebKit-based web browser. Version 20.0.1132.57 of Chrome addresses a total of three vulnerabilities, all of which are rated as “high severity” by the company. These include two use-after-free errors in counter handling and in layout height tracking that were discovered by a security researcher by the name of “miaubiz”. As part of its Chromium Security Vulnerability Rewards program, Google paid the researcher, who is number three in the company’s Security Hall of Fame, $1,000 for discovering and reporting each of the holes. A third high-risk problem related to object access with JavaScript in PDFs has also been corrected. As usual, further details about the vulnerabilities are being withheld until “a majority of users are up-to-date with the fix”. Other changes include stability improvements, and updates to the V8 JavaScript engine and the built-in Flash player plug-in. ...

Continue Reading Chrome 20 update fixes high-risk security vulnerabilities

Android Forums hacked: 1 million user credentials stolen

  • Post author: Omid Farhang
  • Post published: July 13, 2012
  • Reading Time: 1 min
  • Word Count: 43 words

ZDNet: Phandroid’s AndroidForums.com has been hacked. The database that powers the site was compromised and more than 1 million user account details were stolen. If you use the forum, make sure to change your password asap. Read the whole story at ZDNet: http://www.zdnet.com/android-forums-hacked-1-million-user-credentials-stolen-7000000817/

Continue Reading Android Forums hacked: 1 million user credentials stolen

Yahoo! Voice reportedly compromised, over 453,000 credentials exposed

  • Post author: Omid Farhang
  • Post published: July 12, 2012
  • Reading Time: 1 min
  • Word Count: 209 words

Übergizmo wrote: If you use Yahoo! Voice a lot – Yahoo’s VoIP service via its Yahoo! Messenger instant messaging application, then you will definitely need to hear this report. Earlier today, more than 453,000 user accounts from an unidentified service owned by Yahoo were posted on a hacker site. The hackers reportedly said that they infiltrated the subdomain by using a union-based SQL injection. But the group responsible for the security breach added that the data breach was intended to be a wake-up call for Yahoo. ...

Continue Reading Yahoo! Voice reportedly compromised, over 453,000 credentials exposed

Important: Today is your last chance to keep your internet connection

  • Post author: Omid Farhang
  • Post published: July 8, 2012
  • Reading Time: 1 min
  • Word Count: 66 words

Tomorrow, July 9th, the FBI will shutdown the DNS servers which allow the computers infected with this malware to use the Internet. If you want to make sure you will keep your internet working, act today and check your computer to see if it’s infected by DNS Changer or not, here is a very easy to use tool: Tool available for those affected by the DNS-Changer

Continue Reading Important: Today is your last chance to keep your internet connection

Scarlett Johansson leaked nude photos cost $66,000 for the hacker

  • Post author: Omid Farhang
  • Post published: June 29, 2012
  • Reading Time: 3 min
  • Word Count: 515 words

Copied from LA-Times: A man who hacked the email accounts of celebrities should pay movie star Scarlett Johansson $66,179.46 in compensation, federal prosecutors said. The hacker also should serve 71 months in prison and pay a total of $150,000 in compensation to all his victims, prosecutors said in court papers filed this week. Christopher Chaney, 35, of Jacksonville, Fla., who pleaded guilty in Los Angeles federal court to nine counts of computer hacking, for two years hacked almost daily into email accounts of 50 people in the entertainment industry. ...

Continue Reading Scarlett Johansson leaked nude photos cost $66,000 for the hacker

Third edition of vulnerability spotter Secunia PSI

  • Post author: Omid Farhang
  • Post published: June 29, 2012
  • Reading Time: 1 min
  • Word Count: 176 words

Version 3 of Personal Software Inspector (PSI), Secunia‘s free program updater, has been released with a much simplified user interface, enabling less technically astute users to keep their Windows applications up to date as well. According to Secunia, the automatic updater has also been enhanced. PSI is now able to keep programs from more than 3,000 companies up to date, though, as before, PSI only cares about updates which fix security vulnerabilities. Version 3 also includes additional translations, including German. The software checks the user’s computer for outdated program versions known to contain vulnerabilities and either installs updates or provides links to download them. ...

Continue Reading Third edition of vulnerability spotter Secunia PSI

WordPress 3.4 update closes important security hole

  • Post author: Omid Farhang
  • Post published: June 29, 2012
  • Reading Time: 2 min
  • Word Count: 279 words

The WordPress developers have released version 3.4.1 of their popular open source publishing platform, fixing a number of bugs and closing security holes, one of which is rated as important. WordPress 3.4, which has already been downloaded 3 million times since being released two weeks ago, contains a important privilege escalation flaw that accidentally allowed all administrators and editors on multi-site installations to use unfiltered_html. This could have been exploited by users for cross-site scripting (XSS) attacks by, for example, publishing posts containing malicious code. ...

Continue Reading WordPress 3.4 update closes important security hole

Chrome 20 closes 23 security holes

  • Post author: Omid Farhang
  • Post published: June 27, 2012
  • Reading Time: 1 min
  • Word Count: 203 words

Google has closed a total of 23 vulnerabilities with the release of Chrome 20. Of those vulnerabilities, 14 are rated critical, enabling attackers to execute code in the browser’s sandbox, among other things. Integer overflow vulnerabilities in the code for processing PDF files and Matroska containers (.mkv) have also been fixed. Chrome 20 also includes the latest version of Adobe’s Flash Player on Linux, using the new cross-platform Pepper API. In testing at The H, it was confirmed that the Flash Player support also works on 64-bit Linux systems. ...

Continue Reading Chrome 20 closes 23 security holes