Threatpost for B2B

Syndicate content
The First Stop For Security News
Updated: 1 hour 43 min ago

Shylock Trojan Going Global with New Features, Resilient Infrastructure

Fri, 04/05/2013 - 12:17

The prolific, credential-stealing Shylock banking Trojan is growing increasingly sophisticated as its creators continue adding new modules and functionalities to the man-in-the-browser malware, according to a Symantec report.

read more

AMI Firmware Source Code, Private Key Leaked

Fri, 04/05/2013 - 11:47

Source code and a private signing key for firmware manufactured by a popular PC hardware maker American Megatrends Inc. (AMI) have been found on an open FTP server hosted in Taiwan.

read more

One Percent of User Base Exposed in Scribd Data Breach

Fri, 04/05/2013 - 11:43

Document-sharing website Scribd announced this week it was hacked, the victim of what it’s calling a “deliberate attempt to access the email addresses and passwords of registered Scribd users.”

read more

Skype Malware Stealing Victims' Processing Power to Mine Bitcoins

Fri, 04/05/2013 - 09:57

Bitcoin may still be a virtual unknown quantity for most people, but the digital currency has not escaped the notice of attackers, many of whom are turning their attention to finding ways to use the system for their own gains. The attacks against Bitcoin exchange Mt. Gox and hack of Instawallet this week are the latest evidence, but now there is a piece of malware in circulation that is using Skype as a spreading mechanism and then using infected machines' processing power to mine Bitcoins.

read more

Microsoft Expected to Patch Pwn2Own IE Vulnerabilities

Thu, 04/04/2013 - 14:44

Appropriately enough for the start of the baseball season, Microsoft is going to go 4-for-4 and release another set of critical Internet Explorer patches on Tuesday, the fourth consecutive month in which serious vulnerabilities in the browser are being addressed in Microsoft’s Patch Tuesday monthly security updates.

read more

Skype, Dropbox Patch Critical Facebook Authentication Bugs

Thu, 04/04/2013 - 13:47

UPDATE Popular applications Skype and Dropbox fixed holes in their websites this week that could have allowed an attacker to gain control of users’ Facebook accounts. In what’s technically being referred to as an “open direct vulnerability,” both applications failed to validate sites before sending users and their access tokens to them.

read more

Vulnerability Patched in PostgreSQL Database Server

Thu, 04/04/2013 - 10:41

The maintainers of the PostgreSQL database software have patched a security vulnerability, which, in some very limited circumstances, could be used to run arbitrary code on vulnerable servers. The vulnerability, which affects versions 9.0, 9.1 and 9.2, also can be used to cause a denial-of-service by any remote attacker.

read more

DDoS Attack, Database Breach Take Down Two Bitcoin Services

Thu, 04/04/2013 - 10:04

As with any asset of monetary value, once said asset reaches a noteworthy level, cybercriminals’ interest is going to pique. Such is the current situation with virtual currency Bitcoin, which hit a high of $142 yesterday and the value of all Bitcoins in circulation has soared to more than $1 billion.

read more

Organizations on Average Hit Every Three Minutes with Malware

Wed, 04/03/2013 - 21:52

A report released Wednesday indicates an organization on average experiences a malware-related event every three minutes, often involving business-related spear phishing and targeting technology companies.

read more

Activists on Front Lines Bringing Computer Security to Oppressed People

Wed, 04/03/2013 - 13:23

Security-related policy or legislation is enacted and then enforced to protect corporate, government or military interests. Civil organizations are often left flailing in the wind, fending for themselves with fewer IT resources and experience than a Middle America mom-and-pop operation. Yet these non-governmental—and not-for-profit—organizations have tasked themselves with helping those targeted by lethal adversaries who aren’t just after corporate secrets, but are out to deny people their freedom or, in some cases, their lives.

read more

Clues About Flashback Creator Come Together

Wed, 04/03/2013 - 12:43

Nearly a year since the Flashback Trojan surfaced and ultimately infected more than 600,000 Apple OS X computers, the author of the malware may haven been discovered.

read more

Hackers Compromise The War Z Forum, Game Databases

Wed, 04/03/2013 - 11:28

Hackers compromised the forum and game database of the massively multiplayer online game, The War Z, forcing the game’s producer OP Productions to temporarily take the game and its forum offline.

read more

California Considers Pushing Data Disclosure Envelope Again

Tue, 04/02/2013 - 21:47

California, which set the standard for data breach notifications nationwide, is again seeking to set a precedent by becoming the first state in the nation to require companies upon request disclose to California consumers the data they've collected and to whom it was shared during the past year. They would be required to respond within 30 days and provide the report for free.

read more

Firefox 20 Fixes 11 Critical Flaws, Adds Per-Tab Private Browsing

Tue, 04/02/2013 - 14:43

Mozilla has added a new privacy feature to Firefox that enables users to begin a new private browsing session in a separate tab while still running a normal session in other tabs. Firefox 20 also includes patches for 11 critical security vulnerabilities.

The new version of Firefox expands the capabilities of the private browsing function in the browser, a feature that allows users to browse without any cookies, logs or any other data retention.

read more

Stealthy BaneChant Trojan Lurks in Word File, Relies on Multiple Mouse Clicks

Tue, 04/02/2013 - 14:12

Much like malware that was discovered last year, a new Trojan has been reported that relies on detecting mouse clicks to evade sandbox analysis. BaneChant masquerades as a Word document and incorporates advanced evasion techniques making it stealthier than its predecessor.

read more

Malware Arsenal Targets Tibetan Activists

Tue, 04/02/2013 - 14:05

Tibetan activists in China as well as those living in exile around the world are being targeted by dangerous malware that not only steals data from infected computers, but also has graduated to reporting location data from mobile devices for surveillance purposes.

read more

DoD Inspector General Calls Out Army CIO For Poor Mobile Device Security

Tue, 04/02/2013 - 10:35

The CIO of the U.S. Army failed to put in place a comprehensive security program capable of protecting data stored on commercial mobile devices such as iPhones and Androids, leaving sensitive information in key Army installations exposed. The Inspector General of the Department of Defense took the Army CIO to task in a new report, saying that the CIO "did not implement an effective cybersecurity program for [commercial mobile devices]".

read more

Some iMessage Accounts Hit Hard by Mass Messaging, DoS Attacks

Mon, 04/01/2013 - 13:44

A handful of Apple developers have found their iMessage accounts the victim of what’s being loosely referred to as a series of denial-of-service attacks. Using rapid-fire AppleScript texts, attackers have been sending many messages at a time to about half a dozen iOS developers over the last week.

read more

Telephony Denial-of-Service Attacks Prompt Federal Attention

Mon, 04/01/2013 - 13:36

The call-center equivalent of network-based denial-of-service attacks, known as telephony denial-of-service (TDoS), have targeted emergency services among other industries, enough to garner attention from the Department of Homeland Security, Federal Bureau of Investigation, Federal Communications Commission and others in an confidential alert memo, Krebs on Security reported.

read more

Google Privacy Director Alma Whitten Leaving

Mon, 04/01/2013 - 12:52

Alma Whitten, the director of privacy at Google, is stepping down from that role and leaves behind her a complicated legacy in regards to user privacy. Whitten has been the company's top product and engineering privacy official since 2010 and was at the helm as the company navigated a number of serious privacy scandals and controversies.

read more