Review

IMG0893.zip – Your photo all over Facebook? Naked? Malware campaign spammed out

Published: April 23, 2012 Reading time: 2 min

SophosLabs is intercepting a spammed-out malware campaign, pretending to be an email about a revealing photo posted online of the recipient. The emails, which have a variety of subject lines and message bodies, arrive with an attached ZIP file (IMG0893.zip) which contains a Trojan horse. Subject lines used in the spammed-out malware campaign include: RE:Check the attachment you have to react somehow to this picture FW:Check the attachment you have to react somehow to this picture RE:You HAVE to check this photo in attachment man RE:They killed your privacy man your photo is all over facebook! NAKED! RE:Why did you put this photo online? ...

Continue Reading

Free Stuff on Social Networks Not Free

Published: March 29, 2012 Reading time: 4 min

Symantec Connect: In recent years, scammers have flocked towards social networking sites as they have grown and made it easier to access a large number of potential eyeballs to convert into dollars. Brands have found value in leveraging social media to know what their customers are talking about, so, naturally, scammers are doing the exact same thing. Free iPads and iPhones Every time Apple unveils a new iPad or iPhone, you can bet there are scammers out there trying to leverage the announcement for financial gain. In the days leading up to and after the announcement of the new third-generation iPad, Twitter users who tweet about the new tablet most likely will receive some targeted Twitter replies from scammers offering the new device for free: ...

Continue Reading

New privacy guidelines for mobile app developers

Published: March 2, 2012 Reading time: 3 min

SophosLabs: This week has seen the annual Mobile World Congress event. For 2012, the giants of the mobile tech world are back in Barcelona to captivate the imagination of the tech press with their latest smartphone and tablet offerings. The mobile industry trade show has certainly not disappointed. Announcements of smartphones with new quad core processors, phone cameras with huge numbers of megapixels crammed onto its sensor and 3 in 1 smartphone-tablet-netbooks have all provided much excitement. ...

Continue Reading

Phishing via NFC

Published: March 2, 2012 Reading time: 2 min

At the RSA Conference 2012, McAfee’s Chief Technology Officer, Stuart McClure, and several of his colleagues, have demonstrated a whole range of different attacks on mobile devices. For example, they demonstrated an attack on an NFC (Near Field Communication)-enabled smartphone: the attacker simply attaches a modified NFC tag to a legitimate surface such as an advertising poster. For their live demo, the researchers used a Red Cross donations appeal such as those seen at bus stops in various cities across Europe. ...

Continue Reading

Beatles for Sale? It's spam of the day

Published: February 27, 2012 Reading time: 2 min

I’ve owned up to some of the great loves of my life in the past. For instance, I’m a music lover and I’m very partial to board games (even during a denial-of-service attack). Today I can also share that I like The Beatles. In particular, anything from “Rubber Soul” and later when the “Yeah yeah yeah” turned into something rather more “Yeah man. Dig it”. I’ve simply never come across a more talented combination of musicianship and songwriting abilities – for me, you can kick The Stones, The Who, Cream and.. yes.. even MeatLoaf to the kerb, as Lennon, McCartney, Harrison and Starr are the guv’nors. ...

Continue Reading

LibreOffice Update

Published: February 19, 2012 Reading time: 1 min

from Asa Dotzler: Firefox and more I’m not going to apologize for complaining about the terrible, awful, horrible, no good, very bad experience I had when I decided to give LibreOffice a try. It was abysmal and improving that experience should be a top priority for that team if they care about expanding LibreOffice beyond the few Linux users who get it pre-installed. But, I do think I could have done more to propose fixes rather than just rant about the brokenness of the experience so I’ve done just that. ...

Continue Reading

Nessus 5.0 accelerates vulnerability scanning

Published: February 17, 2012 Reading time: 1 min

The H-Online: Tenable has released version 5.0 of Nessus, its popular vulnerability scanner. The new version of the tool includes an updated installation wizard that is said to make installing and configuring the server and client easier and quicker than before. Scan policies can now be created substantially faster than with previous versions, and the developers have also improved the way users navigate through the results of a vulnerability audit. ...

Continue Reading

Malware to Mourn Whitney Houston

Published: February 17, 2012 Reading time: 2 min

Symantec: The world is mourning the loss of another legendary pop singer also known as the queen of pop – Whitney Houston. Spammers are paying homage to the icon with a wicked malware. The malicious email shows a video of the last appearance of the star in a Los Angeles night club and also downloads an executable binary. This file is detected by Symantec Antivirus as WS.Reputation.1. ...

Continue Reading

New CAPTCHA method or just another likejacking scam?

Published: February 13, 2012 Reading time: 1 min

Sorin Mustaca wrote at Avira TechBlog: In case you’ve seen this on Facebook, try to not click on it even if you understand French (it appears to be only in Franch) because it will take you on a road where you don’t want to be. But, we like to live dangerous, so we analyzed this for you. Continue Reading at Avira TechBlog: http://techblog.avira.com/2012/02/13/new-captcha-method-or-just-another-likejacking-scam/en/

Continue Reading

Facebook Hoax: Facebook will end on March 15th 2012

Published: February 13, 2012 Reading time: 2 min

SophosLabs: Have you seen the news? Maybe your friends have shared it with you. Apparently, Facebook is going to shut down on March 15th, 2012. Mark Zuckerberg has reportedly found running the site just too stressful. Here’s the link that many Facebook users have been sharing with each other. Some worried Facebook users have even been sharing this photograph of a news report about the claimed closure of the world’s most popular social network: ...

Continue Reading

Is Waledac spam dirtying the Russian 2012 elections?

Published: February 10, 2012 Reading time: 2 min

Symantec Connect: Recently there have been several reports about the re-emergence of a botnet variant (Kelihos), which Symantec detects as W32.Waledac.C. The Waledac family is a threat that has been monitored by Symantec for many years and was featured in numerous blogs as well as a white paper. In the past, Waledac gained its infamy as a spamming botnet that utilized compromised systems to send out spam. The purpose of these spamming campaigns had usually been for self-propagation of the threat through spam emails containing a link, often (but not always) pointing to a Waledac binary file hosted on a malicious website. The variant W32.Waledac.C is also sending out spam emails, but with a twist. ...

Continue Reading

Is Digital Pearl Harbor THE most tasteless term in IT security?

Published: February 10, 2012 Reading time: 3 min

SophosLabs: Can hackers really cause as much bloodshed as 353 Imperial Japanese Navy fighters, bombers and torpedo planes launched from six aircraft carriers? Can hackers really kill 2,402 U.S. citizens, leave 1,282 wounded, lose 65 of their own attackers in the process, and plunge the United States into a World War? Heaven only knows. Maybe they can. The lack of security around Supervisory Control And Data Acquisition (SCADA) systems is scary. ...

Continue Reading

Malware automatically uploading stolen data to the File sharing sites

Published: February 6, 2012 Reading time: 1 min

The Hacker News: Roland Dela Paz, a threat response engineer with Trend Micro have discovered a piece of malicious software that automatically uploads its stolen data cache to the SendSpace file-sharing service for retrieval. File-storage services offer several advantages for cybercriminals. SendSpace accepts files and then generates a link that can be shared with other people to download the content in the files. The malware has been configured to send files, copy the download link and send it to a command-and-control server along with the password needed to access the archive, Dela Paz wrote. ...

Continue Reading

Facebook IPO comes with a health warning

Published: February 2, 2012 Reading time: 3 min

SophosLabs: Facebook’s IPO is the most hyped initial public offering in years, with much speculation about just how many billions of dollars the social networking phenomenon will be valued at. There’s no doubt that 27-year-old Mark Zuckerberg, the founder of Facebook, is going to become a very rich man – and will be able to buy an even larger wardrobe of hoodies. So, congratulations to Zuck and his management team. Although we have often had our concerns about Facebook when it comes to their stand on privacy and security, there’s no doubt that they’ve done something extraordinary in commercial terms. ...

Continue Reading

Adobe closes Acrobat and Reader security holes

Published: December 17, 2011 Reading time: 2 min

The H-Online: The first patches for the zero-day flaw in Adobe’s Acrobat and Reader applications, which the company confirmed was being exploited in the wild, have been released. The initial problem was caused by a memory corruption when processing Universal 3D (U3D) files, which could allow attackers to potentially take control of an affected system. The patches released also address a newly revealed critical flaw (CVE-2011-4369) which can cause memory corruption when processing Product Representation Compact (PRC) 3D files. ...

Continue Reading

Search