Secure List feed for B2B

Syndicate content Securelist / All Updates
Updated: 1 hour 57 min ago

Analysis: Spam in February 2013

Thu, 03/21/2013 - 08:00
The percentage of spam in email traffic was up 12.8 percentage points compared with January and averaged 71.1%.

Blog: The TeamSpy Crew Attacks - Abusing TeamViewer for Cyberespionage

Wed, 03/20/2013 - 13:23
Earlier today, the Laboratory of Cryptography and System Security (CrySyS Lab), together with the Hungarian National Security Authority (NBF), published details on a high profile targeted attack against Hungary. The details about the exact targets are not known and the incident remains classified. Considering the high level classification of the attack, Kaspersky Lab’s Global Research & Analysis Team performed a detailed technical analysis of the campaign and related malware samples. You can read our short FAQ below and you can download our technical analysis paper linked at the end of the blogpost.

Blog: South Korean 'Whois Team' attacks

Wed, 03/20/2013 - 08:09
Earlier today, reports of a number of cyberattacks against various South Korean targets hit the news. (see http://www.nknews.org/2013/03/south-korean-banks-broadcasters-paralyzed-by-cyber-attack/) The attackers, going by the handle “Whois Team” left a number of messages during the defacements

Blog: The end of MSN Messenger, the beginning of attacks

Tue, 03/19/2013 - 07:27
Attacks already started using the end of MSN Messenger to infect users

Blog: Hello from Malaysia

Fri, 03/15/2013 - 10:48

Blog: Highlights from BlackHat Europe 2013 in Amsterdam

Fri, 03/15/2013 - 10:41
Every year as Europe wakes up from the cold winter to the warm days of spring, BlackHat traditionally descends to Amsterdam. This year’s conference is taking place on March 14-15 at the NH Grand Hotel Krasnapolsky, right Dam Square, the heart of Amsterdam. As spring doesn’t necessarily equal warm days here in Europe right now, the 500 or so BlackHat participants hit the conference rooms to attend quite a few interesting talks. Here’s a summary of the best talks at BlackHat Europe 2013.

Blog: Reminder: be careful opening invoices on the 21st March

Thu, 03/14/2013 - 11:23
On March 4th we spotted a large number of unusual emails being blocked by our Linux Mail Security product.

Blog: New Uyghur and Tibetan Themed Attacks Using PDF Exploits

Thu, 03/14/2013 - 06:55
On Feb 12th 2013, FireEye announced the discovery of an Adobe Reader 0-day exploit which is used to drop a previously unknown, advanced piece of malware. We called this new malware "ItaDuke" because it reminded us of Duqu and because of the ancient Italian comments in the shellcode copied from Dante Alighieri's "Divine Comedy". Previously, we posted about another campaign hitting Governments and other institutions, named Miniduke, which was also using the same 'Divine Comedy' PDF exploits. In the meantime, we've come by other attacks which piggyback on the same high level exploit code, only this time the targets are different: Uyghur activists. Together with our partner at AlienVault Labs, we analyzed these new exploits.

Blog: March 2013 Microsoft Security Bulletins - Low Impact from Pwn2Own, Watch USB Drives for Another Stuxnet

Tue, 03/12/2013 - 13:13

Microsoft releases nine March Security Bulletins. Four of the Bulletins are rated critical, but of the 20 vulnerabilities being patched, 12 are rated critical and enable remote code execution and elevation of privilege. Microsoft software being patched with critical priority include Internet Explorer, Silverlight, Visio Viewer, and SharePoint. So, pretty much every consumer running Windows, and lots of Microsoft shops, should be diligently patching systems today.

Blog: Miniduke: web based infection vector

Mon, 03/11/2013 - 07:43
Together with our partner CrySyS Lab, we've discovered two new, previously-unknown infection mechanisms for Miniduke. These new infection vectors rely on Java and IE vulnerabilities to infect the victim's PC.

Blog: The Brazilian Phishing World Cup

Mon, 03/11/2013 - 07:19

The 2014 FIFA World Cup has already kicked off, at least for Brazilian bad guys. Next year’s big event in Brazil has become one of the most prominent tactics used by Latin American cybercriminals as they unleash a real avalanche of phishing messages, fraudulent prizes and giveaways, malicious domains, fake tickets, credit card cloning, banking Trojans and a lot of social engineering.

Blog: CIA "DELETED" Venezuela's Hugo Chavez?

Fri, 03/08/2013 - 13:28
This is the topic that cybercriminals are speculating about and using as a hook to infect victims. The campaign is based on the Blackhole v2.0

Blog: AlbaBotnet, another new crime wave in Latin American cyberspace

Mon, 03/04/2013 - 19:06
After the recent emergence of the criminal PiceBOT in Latin America, AlbaBotnet has joined the growing ranks of regional IT crime.

Analysis: Mobile Malware Evolution: Part 6

Thu, 02/28/2013 - 05:00
The fifth part of our regular overview of mobile malware evolution was published one year ago, and now it’s time to review the events of 2012 to see just how accurate our forecasts were