Click here

Articles by eSecurityPlanet Staff 

Malware Easy to Find in China

Many malware products are openly advertised through search engines like Baidu.com.

Second PA Student Files Webcam Privacy Lawsuit

Jalil Hasan's laptop took screenshots and photographs of him for nearly two months.

Software Developers Ignore Microsoft Security Warnings

Developers patched only 45 percent of the vulnerabilities that Microsoft's security team reported to them between July 2009 and June 2010.

BlackBerry May Be Banned in India

The government may ban the BlackBerry service if its security concerns aren't resolved.

Google Leads in Search Engine Malware

According to Barracuda Labs, Google distributes more than twice as much malware as Bing, Twitter and Yahoo! combined.

TYPO3 Update Patches Security Flaws

Administrators are urged to upgrade to versions 4.1.14, 4.2.13, 4.3.4 or 4.4.1.

Trojan Disguised as iPhone Jailbreaking Software

A new email campaign delivers a generic keylogger Trojan.

Insider Security Breaches on the Rise

The 2010 Verizon Data Breach Investigations Report states that malicious insiders were involved in 48 percent of security breaches.

Malware Masquerades as Browser Update

The attack uses the familiar Firefox 'Just Updated' page to trick victims into downloading malware.

Researchers Uncover Counterfeiting via Botnet

A Russian group has been using botnets to assist with counterfeiting checks in the US.

Safari Update Patches Autofill Security Flaw

Version 5.0.1 of the browser patches the well-publicized vulnerability.

UK MoD Releases Security Breach Data

A recent report states that the Ministry of Defense lost more than 1,000 storage devices over the past two years, and most were not encrypted.

Cloud Security Alliance Launches Certification Program

The Certificate of Cloud Security Knowledge is intended to ensure that those responsible for cloud computing are aware of key security issues.

Researchers Warn of Smart Meter Security Flaws

According to University of Cambridge researchers, smart meters could allow hackers to control the gas and electricity supply grid.

Most Rogue Anti-Virus Victims Stay Silent

Relatively few people who are victimized by rogue anti-virus scams dispute the charges.

US Commerce Secretary Seeks Improved Cyber Security

Gary Locke has asked commercial, academic and public sector interests to submit ideas on improving security in the commercial sector.

Media Giants Sued over Privacy

Web sites including MTV, ESPN, ABC, NBC and others are accused of violating computer intrusion laws.

Sourcefire Intros Razorback Security Project

The open source project is designed to identify malware, including zero day exploits.

Rite Aid Pays $1 Million for Privacy Breach

The drug store chain has reached a settlement over potential violations of the HIPAA Privacy Rule.

Critical QuickTime Security Flaw Found

Secunia has discovered the flaw in the newest version of QuickTime 7 for Windows.

Australian Hacker Pleads Guilty

Anthony Scott Harrison infected 3,000 computers with a banking Trojan.

Google Patches Chrome Security Flaws

Chrome 5.0.375.125 patches seven vulnerabilities.

Lookout Warns of iPhone, Android App Security Issues

The security firm's App Genome Project has examined 300,000 Android and iPhone apps.

Juniper Buys Mobile Security Firm SMobile

Juniper Networks will integrate SMobile Systems' security solutions into its Junos Pulse software.

UK Cyber Security Challenge Launched

The aim is to attract new talent to the IT security industry.

Phishing Attack Targets WoW Players

The emails ask players to click on a link in order to update their passwords.

Stuxnet Malware Targets Computers in Iran

Nearly 60 percent of all systems infected by the worm are located in Iran.

Yahoo Considers Funding Hackers

The company says hackers and Open Hack Days have proven to be important sources of new ideas and technologies.

Citi Warns of Security Flaw in iPhone App

The company is urging customers to upgrade to the latest version of its mobile banking application.

WPA2 Security Flaw Found

AirTight Networks researcher Md Sohail Ahmad discovered the exploit.

EU Climate Exchange Site Hacked

The site was hacked to protest the idea of applying a market-based approach to the problem of carbon emissions.

UAE Says BlackBerry Poses Security Threat

The government of the United Arab Emirates says the device is open to misuse.

Security Flaw in vBulletin Exposes Passwords

The vulnerability in version 3.8.6 makes it easy to access sensitive data.

New Malware Targets Windows LNK Vulnerability

Eset researchers have uncovered two new types of malware exploiting the Windows shell LNK flaw.

Microsoft Says IE8 Blocked a Billion Malware Downloads

The company says the browser's SmartScreen Filter has blocked 1 billion attempts to download malware.

Safari Privacy Flaw Discovered

WhiteHat Security's Jeremiah Grossman has found a flaw in Safari that could give hackers access to a user's personal information.

Free Phishing Kit Targets Newbies

The majority of stolen credentials are sent to the kit's authors, not to the hackers using it.

Dell Blames Malware Infection on Human Error

The company won't say whether or not it was running anti-virus software at its factory.

Microsoft Won't Pay for Security Flaws

Unlike Mozilla and Google, Microsoft says it won't be rewarding researchers who find bugs in the company's products.

PHP Update Patches Security Vulnerabilities

Version 5.3.3 fixes approximately 100 bugs.

McAfee Intros Mac Security Tools

The two new products for Mac users are McAfee Internet Security and Family Protection for Macs.

Lloyds Web Site Security Flaw Discovered

A customer recently discovered the flaw in the bank's web site.

Georgia Businesses Hit by Identity Theft

State officials say scammers are forging corporate identities to commit fraud.

Slovenian Police Arrest Botnet Suspects

The four suspects are accused of being involved in the development of the Mariposa botnet.

Gawker Hacked

A series of attacks by hackers at 4chan recently made the blog intermittently unavailable.

Cisco Warns of CDS Security Flaw

The company has issued an advisory warning of a serious security hole in Cisco Internet Streamer.

Security Certifications a Good Career Investment

If Information Systems Security is your game, earning a few top certifications can also earn you top dollar.

VeriSign Adds Malware Scanning

VeriSign's SSL certificates will now include an online malware scanning service that will help to determine if a website is at risk from security vulnerabilities.

Privacy Flaw Exposes Online Gambling Data

The flaw resulted in the shutdown of PlayNow.com just hours after it was first launched.

Hacker Denies Porn Extortion

Luis Mijangos has pleaded not guilty to extorting sexually explicit videos from female victims.

Google Increases Reward for Security Flaws

The company will now pay $3,133.70 for severe Chromium bugs.

Adobe to Improve PDF Security

The next version of Adobe Reader will implement sandboxing as an additional security measure.

Toy Story 3 Used as Malware Bait

The popular film is being used to attract victims to fake survey sites and pop-up software scams.

Pros and Cons of Security-as-a-Service

Although more and more security functionality is being built into these offerings, security-as-a-service still has its pros and cons.

Security Breach Hits South Shore Hospital

Personal information on approximately 800,000 patients was recently lost.

Dell Warns of Spyware on Motherboards

The PowerEdge R410 Rack Server has spyware in its embedded systems management software.

OISF Intros Open Source Security Tool

The Suricata Engine is designed to be a replacement for Snort.

Security Breach Hits Siemens Customer

An unnamed German company was recently attacked by the Stuxnet worm.

Firefox, Thunderbird Get Security Updates

Mozilla has patched 14 bugs in Firefox and six in Thunderbird.

MSR Hires New Managing Director

Fresh from DARPA, Peter Lee will head up Microsoft's basic research organization.

How Cloud Security is Like Y2K

A Deloitte venture capitalist believes cloud computing will force companies that have deferred investment to become more efficient by buying new systems, among other things.

Coke Phishing Scam Hits Facebook

The scam promises access to a video that will persuade viewers never to drink Coca Cola again.

New Operating System Offers No Security

Damn Vulnerable Linux is designed for learning and research.

Qualys Intros Free Browser Security Check

BrowserCheck has been in development for almost 18 months.

German Webcam Hacker Arrested

The unnamed person has been charged with hacking into webcams to spy on schoolgirls.

Apple iTunes Update Patches Critical Security Flaw

The vulnerability was reported to Apple by Clint Ruoho of Laconic Security.

Mozilla Increases Bounty for Security Flaws

Researchers who report bugs in Mozilla's software will now receive a $3,000 cash reward.

UK Spammers Love Coventry

According to Symantec, Coventry's spam rate leads the UK at 92.8 percent.

UK Businesses Worry About Lax Security Breach Notification Laws

A Sophos survey has found that nearly half of UK businesses think the country's data protection laws are too relaxed.

Phishing Scam Targets BofA Customers

The scam uses compromised sites for redirecting and hosting phishing pages.

HHS Discloses Details on Privacy Breaches

The department recently began identiying entities that were previously listed only as 'private practice.'

Mozilla Disables Add-On Malware

The add-on, called Mozilla Sniffer, was designed to forward users' login data to a remote server.

Security Vulnerability Found in Cisco Switches

The company plans to release a patch in August.

Kaspersky Blocks BBC News for Phishing

The company's security software mistakenly identified the news site as a phishing risk.

Four Spanish Hackers Arrested

The hackers are accused of defacing the web sites of Spain's two leading political parties and of a popular TV gossip show.

White House Releases Cyber Security Progress Report

The report details the steps the US government is taking to protect against cyber attacks.

New USB Malware Identified

The malware leverages a flaw in the way Windows handles shortcut files.

Winamp 5.58 Patches Security Flaws

The vulnerabilities could be used to compromise a user's system.

Malware Targets US Online Banking Customers

Zeus is specifically targeting US banking customers via Verified by Visa and MasterCard SecureCode.

Chatroulette Privacy Flaws Found

Researchers have discovered three attacks that can be launched against Chatroulette users.

Finjan Sues Rival Security Firms

The company is suing Symantec, McAfee, Websense, Sophos and Webroot Software over patents related to anti-virus products and security services.

Courion Intros Compliance Manager for File Shares

The solution is designed to help companies identify the riskiest file share assets in their organization.

Cybercrime-Friendly ISP Partially Shut Down

The main range of IP addresses used by PegasHosting has been null-routed.

GFI Buys Anti-Virus Vendor Sunbelt Software

The companies plan to develop integrated security products for cloud and on-premise use.

Coverity Static Analysis to Integrate with Armorize for Security

The two vendors have announced plans to integrate their software suites.

FreeBSD Security Vulnerability Discovered

The vulnerability can give users the ability to edit files for which they only have read privileges.

Zeus Version 3 Intros New Banking Trojan

The latest version of the Zeus toolkit targets the login details of Spanish, German, UK and US bank customers.

Fake Amazon Emails Deliver Malware

The emails, which contain a malicious attachment, claim to confirm the recipient's purchase of a Sony Bravia television.

Unusually Eccentric Trojan Discovered

The malware disables applications on the affected PC, then demands 30 Ukrainian Grivna for an unlock code.

DHS Gets Cyber Security Oversight

The Department of Homeland Security is now responsible for overseeing federal agencies' compliance with FISMA.

Geotagging Leads to Privacy Concerns

A recent survey found that owners of geolocation-capable mobile devices are worried about a loss of privacy as a result of geotagging.

Oracle Patches 59 Security Flaws

The patches fix vulnerabilities in hundreds of the company's products.

RIM Intros Consumer Security Offering

BlackBerry Protect gives consumers access to advanced security functionality.

Australia Condemns Google Privacy Breach

The country's privacy commissioner says Google's Street View cars broke Australian law.

Desperate Mother Engages in Identity Theft

The woman posed as another parent, asking to have that parent's child removed from a school's waiting list.

Pakistani Hackers Arrested

The Pakistani government recently announced the arrest of five leaders of the PAKBugs hackers forum.

Hackers' Homes Raided by FBI

The Electronik Tribulation Army had been harassing a security researcher involved in Jesse William McGraw's arrest.

New Linux OS Designed for Malware Analysis

Lenny Zeltzer designed the REMnux OS for reverse engineering malware.

Fake Adobe Flash Update Delivers Malware

Barracuda Labs researchers warn that several compromised web pages are delivering malware disguised as an Adobe Flash update.

Hackers Access Cisco Live 2010 Attendee List

The company says details on fewer than 20 percent of those on the list were affected.