Two unknown sources said that malicious software that worked its way onto a web-based communications platform at NASDAQ last year, allowed the attackers to monitor communications between business leaders using its Director’s Desk system.
According to a recent report from the Government Accountability Office, despite efforts to implement stronger cybersecurity controls, several federal agencies remain in a weakened state. Since 2006, security incident reports have risen over 650-percent.
The week opened with a report that Apple had updated its blacklist of known malware to include the Trojan dropper Revir, and it is closing with reports about the spread of a new Trojan known as Flashback.
On Aug. 9, Microsoft accidentally released information on the five security updates it is planning to release tomorrow as part of this month’s Patch Tuesday.
Dubbed Morto, the worm doesn’t use a vulnerability, but instead propagates by compromising Remote Desktop connections on a network through brute forcing attacks.
The specter of advanced persistent threats (APTs) hangs over a growing number of conversations these days about enterprise security, and has prompted businesses to take a closer look at how they can make their environments less vulnerable. For some, this has reignited discussions about how the security of Apple’s Mac OS X stacks up against Microsoft Windows.
Researchers from Websense Security Labs told SecurityWeek they are seeing an alarming number of Facebook scams already taking advantage of the tragedy. According to Websense, a ‘clickjacking’ attack that replicates itself on users’ walls after they click on fake posts within their news feed is spreading at a rate one user every second.
As with most stories Mac-related, the malware-is-finally-coming story attracted a lot of press. But the desktop Mac OS might not be attractive to attackers as you might think.
We still don't know who created Conficker or what that person’s motivations were. What we do know: Conficker could have proved much more damaging than it ultimately did, but the threat has not entirely disappeared.
Zeus 2.1 now boasts features that help it avoid analysis and hostile takeover from law enforcement, researchers, or competing cybercriminal organizations.
The vulnerability in Windows Shell’s parsing of .LNK (shortcut) files presents some interesting and novel features in terms of its media lifecycle as well as its evolution from zero-day to patched vulnerability. For most of us, the vulnerability first came to light in the context of Win32/Stuxnet, malware that in itself presents some notable quirks.
The anti-malware industry sometimes sees more complicated problems than you might imagine, and they can’t all be fixed by tweaking detection algorithms or giving the marketing team a productivity bonus.
Malvertising - Popular websites, blogs, and ad networks are fast becoming the preferred means of cybercriminals, identity thieves, and hackers to steal consumer information and distribute malicious content.
Anti-virus products scan for malware in two ways. They look for sequences of bits that are found in programs that are known to be “evil” (but which are not commonly found in “good” programs)...
Delivered Twice Each Week, the SecurityWeek Briefing Won't Flood Your InBox, But Will Keep you Well Informed on What's Happening in the Industry, Along with Insightful Columns from Industry Experts.
Privacy: We never sell or share your personal information or email address with any other company and you can unsubscribe instantly at any time.