Feed aggregator

Microsoft, Symantec Join Forces to Take Down Bamital Click-Fraud Botnet

Threatpost for B2B - Wed, 02/06/2013 - 18:23

Microsoft and Symantec have shut down a massive click fraud botnet known as Bamital, numerous variants of which have been in circulation since 2009 amassing several million dollars in fraudulent profit for the attackers as well as spreading more malware including scareware.

read more

Business Partners Give Hackers Easy Access to Secure Firms

Threatpost for B2B - Wed, 02/06/2013 - 12:30

As frequently targeted, high-value companies continue fortifying their defenses, FireEye researchers claim that attackers are increasingly setting their sights on the affiliated but not-as-well-protected third-party organizations that do business with them.

read more

Cyberwar Name Game a Dangerous Play

Threatpost for B2B - Wed, 02/06/2013 - 08:00

SAN JUAN, Puerto Rico – The term “cyberwar” is the “zero day” of security jargon; it’s getting so that every bug is a zero day and every attack is hash-tagged cyberwar.

read more

Federal Reserve Admits It was Briefly Hacked During Super Bowl

Threatpost for B2B - Tue, 02/05/2013 - 23:32

Two days after the group Anonymous boasted it had broken into a government Web site and had the data dump to prove it, the U.S. Federal Reserve admitted it was hacked.

"The Federal Reserve system is aware that information was obtained by exploiting a temporary vulnerability in a website vendor product," a spokeswoman told Reuters Tuesday. "Exposure was fixed shortly after discovery and is no longer an issue. This incident did not affect critical operations of the Federal Reserve system."

read more

Researchers Discovery Data-Stealing Malware That Likes to Nap

Threatpost for B2B - Tue, 02/05/2013 - 22:50

Researchers at FireEye's Malware Intelligence Lab say they've found malware that attempts to evade detection with extended sleep calls and uses "the fast flux technique" to hide the attacker's identity.

read more

Phil Zimmermann on Mobile Encryption and Privacy

Threatpost for B2B - Tue, 02/05/2013 - 17:07

Dennis Fisher talks with cryptographer and PGP inventor Phil Zimmermann about the specter of mobile eavesdropping, his new venture Silent Circle and how the threat landscape has changed in recent years.

You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

read more

Phil Zimmermann: 'We Really, Really Don't Have the Keys'

Threatpost for B2B - Tue, 02/05/2013 - 15:58

SAN JUAN, Puerto Rico--Phil Zimmermann has seen more changes in the the threat landscape in his career than he may care to remember. The inventor of the PGP encryption software and one of the key movers in the crypto wars of the early 1990s, Zimmermann is back in the game now with a new mobile crypto system that's designed to help take the prospect of government eavesdropping and criminal attacks on mobile communications off the table.

read more

Blog: Brazilian Masquerade

Secure List feed for B2B - Tue, 02/05/2013 - 15:34
Don't believe your eyes but check if you still have your AV solution. Instead of fighting AV detections, cybercriminals from Brazil just replace them with their own fake solutions.

Predictive Security Analytics Tool Available Free to Researchers

Threatpost for B2B - Tue, 02/05/2013 - 14:59

SAN JUAN, Puerto Rico – Dan Hubbard has lately been a regular face at a lot of big data meet-ups. He’s also often been the lone security face at these meet-ups, which are dominated by analytics, search, social media and advertising professionals. That may change soon for the CTO of DNS and security service provider OpenDNS, who announced today at the Kaspersky Security Analyst Summit that security researchers will have free access to a new tool called Umbrella Security Graph.

read more

SCADA, ICS Bug Brokering Mirrors IT Vulnerability Market

Threatpost for B2B - Tue, 02/05/2013 - 13:23

SAN JUAN, Puerto Rico – The world of SCADA and industrial control system vulnerabilities is starting to mirror that of IT security, not only in the demonstration and exploitation of zero-day vulnerabilities, but in the brokering of flaws and exploits between hackers and organizations interested in buying research.

read more

Chris Soghoian on Wireless Carriers and Android Security

Threatpost for B2B - Tue, 02/05/2013 - 09:25

Chris Soghoian of the ACLU discusses the looming crisis of mobile security caused by the failure of mobile carriers to push Android updates to users at the Kaspersky Lab Security Analyst Summit Monday.

read more

Google Blocks High Profile Sites After Advertising Provider NetSeer is Hacked

Threatpost for B2B - Mon, 02/04/2013 - 22:07

Google Chrome users, among others, couldn't access some of the most popular Web sites Monday after an advertising network's corporate Web site was injected with malware. But, according to the ad company's chief executive, those sites were safe.

read more

FTC Endorses New Privacy Guidelines, Do Not Track for Mobile Apps, Devices

Threatpost for B2B - Mon, 02/04/2013 - 16:04

Hoping to ramp up privacy on mobile devices such as smartphones and tablets, the Federal Trade Commission (FTC) has released a series of suggestions to help app developers, advertising networks and device companies better protect their users online.

read more

Department of Energy Compromised in Sophisticated Attack

Threatpost for B2B - Mon, 02/04/2013 - 15:54

Hackers targeted and compromised computer networks at United States Department of Energy headquarters in Washington DC two weeks ago, according to a report published by the Washington Free Beacon earlier this morning.

read more

Partial Disclosure Leaves Adobe Reader Zero-Day Story in Limbo

Threatpost for B2B - Mon, 02/04/2013 - 15:29

SAN JUAN, Puerto Rico – It’s the vulnerability that never was. Or was it?

read more

Wireless Carriers Put on Notice About Providing Regular Android Security Updates

Threatpost for B2B - Mon, 02/04/2013 - 12:54

SAN JUAN, Puerto Rico -- Activist Chris Soghoian, whom in the past has targeted zero-day brokers with his work, has turned his attention toward wireless carriers and their reluctance to provide regular device updates to Android mobile devices.

read more

How the RSA Attackers Swung and Missed at Lockheed Martin

Threatpost for B2B - Mon, 02/04/2013 - 11:09

SAN JUAN, PUERTO RICO--The attack that resulted in the compromise of RSA's SecurID database in 2011 had a lot of ramifications and sent shockwaves through much of the security industry. But it could have had much broader consequences had the security team at Lockheed Martin not discovered the same attack team on its own network and taken actions to shut them down.

read more

Blog: New crimeware attacks LatAm bank users

Secure List feed for B2B - Fri, 02/01/2013 - 14:47
Following in the wake of the vOlk (Mexico) and S.A.P.Z. (Peru) botnets comes PiceBOT, a newbie to the Latin American cybercrime scene. The cost on the black market is currently around $140.

Citadel Trojan: It’s Not Just for Banking Fraud Anymore

Threatpost for B2B - Fri, 02/01/2013 - 14:08

Banking malware has primarily been just that, an attack tool used against financial institutions to steal money from online bank accounts. But what if cybercrime gangs decided to flip that on its head, and use malware such as the Citadel banking Trojan to steal credentials from not only banks, but government agencies and commercial businesses?

read more

Juniper’s Junos Could Open Routers to TCP Attacks

Threatpost for B2B - Fri, 02/01/2013 - 13:52

Some systems running older versions of Juniper Networks’ Junos OS software could be vulnerable to a transmission control protocol (TCP) flaw that can enable a hacker to crash and reboot certain routers.

read more

Syndicate content