Click here

Security News: Archive: September 2010 

US Leads Malware Production

The country has overtaken India and Russia to become the world's biggest virus producer.

Targeted Malware Hits Florida Restaurant

The malware was specifically designed to compromise the restaurant's POS system.

State CISOs Anticipate Cyber Security Budget Cuts

A survey by Deloitte and NASCIO has found that nearly half of state CISOs report reduced budgets last year, even as the threat landscape for states worsens.

UK Police Arrest 19 Cybercrime Suspects

The group is accused of being collectively responsible for the theft of more than £6 million over the last three months.

FBI Busts 37 in $3 Million Zeus Trojan Scam

The FBI and the U.S. Attorney's office in Southern New York filed charges against 37 people suspected of orchestrating a sophisticated international malware scam that stole more than $3 million from victims' bank accounts.

Two Degrees of Separation from Malware

According to Websense, the top 1,000 web sites are typically two clicks away from malicious content.

Fake USPS Emails Deliver Trojan

The spam emails, posing as package delivery failure notifications from the US Postal Service, distribute the Oficla Trojan.

Vulnerability Found in Zeus Botnet

The flaw was discovered by researcher Billy Rios.

US Undergoes Simulated Cyber Attack

The Department of Homeland Security has launched Cyber Storm III, a three-day cyber security exercise.

Conviction Upheld for Palin Hacker

US District Judge Thomas Phillips rejected the arguments of David Kernell's lawyers.

Researchers Develop GPU-Assisted Malware

The malware is designed to avoid detection by running on a computer's graphics processor.

Spammers Target LinkedIn Users

The emails were designed to trick users into downloading the Zeus Trojan.

AVG Updates Free Anti-Virus Software

The company recently announced the launch of AVG Anti-Virus Free 2011.

Homeland Security Hosts Cyberwar Simulation

Department of Homeland Security convening officials from half a dozen other agencies and departments as well as a gaggle of foreign countries to test readiness and coordination mechanisms in response to a major cyberattack.

Security Flaw Found in Orkut

After more than 400,000 users were affected, Google fixed the vulnerability.

RIM, UAE Approaching Security Agreement

The security general at Abu Dhabi's executive council says the UAE is confident an agreement will be reached.

Zeus Botnet Targets Mobile Banking Apps

A Zeus variant is specifically targeting users who perform online banking transactions on their mobile phones.

Hackers Targeting Online Gamers

According to Kaspersky, hackers have designed malware specifically to take control of gamers' accounts.

Microsoft Enhances Hotmail Security

The company is in the process of introducing a range of new security features.

Concerns Regarding Web 2.0 Security

A McAfee survey has found that executives are worried about the security issues that come with Web 2.0 technologies.

Three in Ohio Plead Guilty to Identity Theft

Katura Mozelle, Kinte Green and Fatima Green used information from a government web site to steal victims' identities.

Spam Scam Targets LinkedIn Community

Security researchers at Cisco say the social network for professionals has been hit with a massive malware campaign designed to steal users' online banking credentials.

Cyber Attack Targets Anti-Piracy Lawyers

The attack follows DDoS attacks against the MPAA's and RIAA's web sites.

My Opera Service Hosting Malware

Kaspersky Lab researchers have found malware on the free web hosting service.

Iran Acknowledges Massive Malware Infection

Government officials say the Stuxnet worm has infected at least 30,000 PCs in Iran.

Comcast Hackers Sentenced to 18 Months in Jail

Christopher Lewis and Michael Nebel were convicted of briefly defacing Comcast's web site.

Stuxnet Worm Tags Iranian Nuclear Plant

Iran's official news agency said the worm had managed to infect computers operating at its first nuclear power plant, but had thus far only caused minor damage.

VoIP Hacker Gets 10 Years

Edwin Andres Pena was also ordered to pay more than $1 million in restitution.

NASA Fails Security Audit

The Office of the Chief Information Officer did not follow best practices, according to a recent report.

Phishing Scam Targeted eBay Employees

Liviu Mihail Concioiu is accused of stealing more than $3 million.

Botnet Creator Convicted

Bruce Raisley faces a maximum sentence of 10 years in jail and a fine of up to $250,000.

Microsoft Announces Free SMB Security Offering

The company will soon make its Security Essentials software available to small businesses for free.

Cisco Intros iPhone Security Software

The company's AnyConnect Secure Mobility software for iOS 4.1 is now available in Apple's Apple Store.

ChoicePoint Data Breach Victims Await Their Pittance

Two years after the data warehousing company admitted it once again failed to secure consumer data, its victims are starting to receive their compensation -- all $18.17 of it.

Google Sues Pharma Spammers

The company has filed a civil lawsuit against fraudulent pharmacies that advertise on its search site.

White House Leads Review of Federal Cyber Authorities

Pentagon cyber boss Gen. Keith Alexander outlines the daunting challenges ahead for military and civilian cybersecurity. Meanwhile, congressional efforts to overhaul the federal policy framework appear to have stalled.

New Mobile Security Option for iPhone

Enterprises concerned about iPhone security have a new option courtesy of Cisco.

Maine Limits Damage Claims for Security Breach

The ruling limits consumers' ability to claim compensation for time and effort spent updating their accounts after a breach.

Tea Party Hacked

Visitors to the photo section of the teaparty.org site were diverted to other sites.

US Search Settles FTC Privacy Complaint

The online data broker will refund fees paid by almost 5,000 customers to have their records protected.

New Email Solution Protects Privacy

VaporStream's software is designed to combine the ease of use of e-mail with the privacy and security of an in-person chat.

Privacy Flaw Found in Vodafone UK Site

Enter a phone number, and the site returns that user's email address.

One Fifth of UK College Students Have Hacked

More than a third of the students said they simply did it for fun.

Canada Ends Facebook Privacy Probe

Still, Privacy Commissioner Jennifer Stoddart says she will continue to monitor the web site.

Oracle Launches Security Governor for Healthcare

The new tool is designed to help organizations identify and prevent malicious activity.

Stuxnet Malware May Be Designed for Bushehr Reactor

Security researcher Ralph Langer says the worm may have been created specifically to attack Iran's Bushehr nuclear reactor.

Dynamics Enhances Card Security

The company has developed a new card that provides additional protection against theft by concealing part of the card number.

Cybercrime Suspect Extradited to United States

Dmitry M. Naskovets was recently transferred from the Czech Republic to federal prosecutors in Manhattan.

Apple Patches Snow Leopard Security Flaw

The update fixes a flaw that gave hackers access to shared folders and files.

Accuvant Buys Security Firm Ciphent

Ciphent's CEO will become part of Accuvant's management team.

Adobe Releases Early Patch for Flash Player Security Flaw

The company released the fix at least a week earlier than original planned.

Cyber Attack Targets RIAA, MPAA Sites

According to Panda Security, the attack was launched in retaliation for similar DDoS attacks aimed at The Pirate Bay.

Microsoft Scrambles to Patch Encryption Hole

Hole in server encryption could leave many systems open to attack, researchers and Microsoft officials say.

Mouseover Hack Ravages Twitter Site

A piece of malicious JavaScript code embedded in the URLs of tweets is sending thousands of users to porn sites and other potentially dangerous locales.

ZoneAlarm Firewall Software Uses Scareware Tactics

Pop-up warnings appear to be designed to scare users into buying the paid version of the software.

Contractors Indicted for Nuclear Security Breach

A scientist and his wife are accused of providing classified nuclear weapons data to an FBI agent posing as a Venezuelan government official.

Hackers Deface Swedish Right-Wing Web Site

The home page of the Sweden Democrats was replaced with an image of a birthday cake.

Security Vulnerability Found on Visa Site

The flaw was discovered by security researcher d3v1l.

MI5 Calls Cyber Security 'Relatively Straightforward'

Jonathan Evans, head of MI5, says it isn't difficult to plug key vulnerabilities if you're aware of them.

Hospital Employee Charged with HIPAA Privacy Violation

Paul C. Pepala is accused of accessing the names, birth dates and Social Security numbers of patients for personal gain.

DoJ Charges 53 with Conspiracy, Identity Theft

The gang sold Social Security cards stolen from Asian immigrants working in American territories.

Identity Theft Hits Interpol Chief

The fraud was only recently discovered by Interpol's Security Incident Response Team.

NIST Evaluates New Cell Phone Security Solution

Using a soliton to transmit a call could make the signal harder to intercept.

Cyber Attack Targets Go Daddy Sites

The infected sites redirect visitors to a scareware distribution web site.

Google Improves Its Cloud Application Security

Free two-factor authentication feature is designed to add an extra layer of protection to Google's cloud applications.

Rice University Exposes Student, Employee Data

Officials at Rice University are warning 7,000-plus staffers and students that their personal information was exposed after a portable storage device was stolen.

Security Flaws Found in Diaspora Social Network

The open source alternative to Facebook has been found to contain several vulnerabilities.

Hackers Love FarmVille

The game is being used to harvest Facebook user names and passwords.

Home Robberies Highlight Facebook Privacy Concerns

A gang in New Hampshire monitored Facebook pages to determine when victims would be out of their homes.

SafeNet, NetApp Partner on Cloud Storage Security

The companies are collaborating on a new approach to storage security solutions.

Lawsuit Alleges Shaq Hacked

The basketball star has been accused of hacking into the voicemail of his former employee and mistress.

QuickTime Update Patches Two Security Vulnerabilities

One of the flaws was discovered by security researcher Ruben Santamarta in late August.

Google Engineer Fired for Violating User Privacy

David Barksdale was fired in July after accessing at least four user accounts.

(ISC)2 Launches Social Network for Security Pros

The site, InterSeC, currently has more than 8,500 members.

SAP Announces Security Patch Day

The company has scheduled a regular patch day to coincide with Microsoft's Patch Tuesday each month.

Better Twitter May Come with Security Risks

M86 Security says Twitter's planned redesign may lead to criminal abuse.

UK Cyber Security Challenge Reveals Entrants' E-mail Addresses

A confirmation email was recently CCed to 370 recipients, providing a complete e-mail list to all entrants.

Identity Theft Results in Stolen House

The scam appears to be the first of its kind in Australia.

Forrester Expects More Security Acquisitions

The research firm says large companies are likely to continue acquiring smaller security providers over the next several months.

Samba Update Patches Security Flaw

Version 3.5.5 patches a stack overflow vulnerability.

Pirate Bay Ads Deliver Malware

The ads expose users to Windows Trojans via drive-by download attacks.

Iranian Privacy Tool Withdrawn

Members of the Censorship Research Center have asked that all remaining copies of the Haystack tool be destroyed.

Mozilla Stops Providing Firefox Security Updates

There's no word yet on when updates will be reactivated.

PwC Anticipates Rise in Data Security Spending

PricewaterhouseCoopers says corporate spending on data security will soon increase sharply.

Adobe Warns of New Zero Day Vulnerability

A critical vulnerability in Adobe Flash Player is being actively exploited in the wild, according to the company.

Google Blocks BBC Radio 3 Site for Malware Infection

The company's Safe Browsing service recently blacklisted the site.

Hacker Claims Responsibility for 'Here You Have' Worm

The unidentified hacker stated that the attack was intended as a propaganda tool.

Damballa Warns of Commercial DDoS Botnet

The IMDDOS botnet was created specifically to offer DDoS attacks on demand as a commercial service.

More Than 99 Percent of Malware Targets Windows OS

According to GData, only 0.6 percent of new malware targets other operating systems.

University of Oxford Enhances Network Security

The university is now using CryptoCard's CRYPTO-MAS authentication service.

Security Firms Warn of 'Here You Have' Worm

The virus installs on the Windows directory as a file called CSRSS.EXE.

Perception of Online Security Threats Varies by Country

F-Secure reports that web users' worries about online privacy and security differ worldwide.

FIFA Employees Accused of Data Theft

Personal data on more than 35,000 English soccer fans may have been accessed and sold on the black market.

Malware Spam Surged in August

Symantec reports that malware spam more than tripled during the month.

RBS WorldPay Hacker Gets Suspended Sentence

Viktor Pleshchuk received a six-year suspended sentence in exchange for providing information to authorities.

CCNY Students Feel Sting of Data Security Mishap

More than 7,000 students attending City College of New York this week are receiving the bad news that their most sensitive personal information is up for grabs.

California Hospital Appeals Security Breach Fine

Stanford University's Lucile Packard Children's Hospital is appealing a $250,000 fine for delayed reporting of a data breach.

'Here You Have' Spam Outbreak Leaves Enterprises Reeling

IT administrators are still cleaning up their email servers after last week's potent 'Here You Have' virus inundated corporate servers with billions of spam messages.

HP Acquiring ArcSight for $1.5 Billion

Computing giant HP expands its security lineup with the acquisition of ArcSight's risk management and compliance offerings.

Opera Update Patches Security Vulnerability

Version 10.62 of the browser was recently released.

Cisco Patches WLAN Controller Security Flaws

The company has released software updates to address vulnerabilities in its Wireless LAN Controller and Wireless Services Module products.

Security Flaws Remain in Symantec Rap Contest Site

The HackIsWack web site is still vulnerable to rickrolling.

Majority of Web Users Have Been Hit by Cybercrime

A recent Symantec study found that 65 percent of web users worldwide have been hit by some form of cybercrime.

New Android Trojan Variant Identified

The malware sends SMS messages to premium rate numbers, at a cost of as much as $6 each.

New Managed Security Service Focuses on SAP GRC

Security firm su53 Solutions says the service is the first of its kind for SAP systems.

NIST Publishes Smart Grid Security Guide

The 537-page guide focuses on protecting the power grid from cyber attacks.

HEI Hotels & Resorts Discloses Security Breach

Customers have been informed that their credit cards' number, expiration date, security code and encoded magstripe data are at risk.

Phishing Campaign Targets Gmail Users

The emails ask users to update their Google account information.

The Security Risks of Remote Working

According to a recent survey, nearly a third of remote workers use their own computers, and many have no form of network login.

Symantec Intros Free Scareware Eradication Tool

Norton Power Eraser is designed to detect and eliminate a scareware infection.

Safari Update Patches Security Vulnerabilities

Safari 5.0.2 and Safari 4.1.2 patch three flaws that expose users to drive-by download attacks.

Is Microsoft Looking to Buy Symantec?

Rumors and speculation over the possible takeover of Symantec, a valuable IT security acquisition, appear to have started a small buying spree for Symantec's stock.

Hackers Exploit Twitter XSS Flaw

Kaspersky Lab researchers say more than 100,000 users have already clicked on one malicious link.

Jamaican Cybercrime Suspects Charged

The two men are the first to be charged under the country's new cybercrime law.

Security Lapse Reveals Confidential Police Data

A USB drive containing unencrypted information was recently found on a UK street.

Phishing Attacks Target US Troops

The attacks have been timed to coincide with a real Bank of America Military Bank service update.

TechCrunch Europe Infected with Zeus Trojan

The infection was initially reported on Twitter by security blogger The Harmony Guy.

Phishing Attacks Exploit UK Tax Errors

Around 4.3 million people in the UK are due for a refund.

Apple Hustles to Rid Ping of Spam

New social network on iTunes attracts more than one million users and more than its fair share of spam.

Nigerian Spammer Jailed

Okpako Diamreyan was also ordered to pay $1.02 million in restitution.

Spammers Love iTunes Ping

Sophos researchers report that Apple's new social network has been flooded with spam in the days since its launch.

Google to Settle Buzz Privacy Suit

The company has agreed to spend $8.5 million to settle a class action lawsuit.

Security Flaws Found in Symantec's HackIsWack Site

The company recently acknowledged that the site was riddled with security vulnerabilities.

Former Sprint Employees Charged with Identity Theft

Nine former employees have been accused of cloning customers' cell phones in order to make approximately $15 million worth of calls.

Google Researcher Finds New MSFT Zero-Day Exploit

Microsoft was caught off guard by public disclosure of a new zero-day hole in Internet Explorer 8. But the hacker who published the exploit says he notified Microsoft in advance and only acted after the company ignored him.

Pentagon Cybersecurity Boss Vows Privacy Protections

At O'Reilly Gov 2.0 Summit, Gen. Keith Alexander, head of U.S. Cyber Command pledges that national security and individual privacy are not working at cross purposes.

Google Simplifies Privacy Policy

The new version, intended to be more transparent and understandable, will take effect on October 3.

Symantec, Snoop Dogg Announce Cybercrime Rap Contest

The creator of the best rap video on the subject of malware, hacking and botnets will win a trip to LA.

Security Flaw Found in HP Printers

Zscaler's Michael Sutton has discovered a vulnerability that could provide hackers with remote access to copies of scanned documents.

Floridian Pleads Guilty to Identity Theft

Juan Javier Cardenas emailed more than 1,500 stolen credit card numbers to co-conspirators between March and May of 2009.

Chrome Update Patches Security Flaws

Google Chrome 6 repairs 14 security vulnerabilities.

Heartland to Pay Discover $5 Million for Security Breach

The payment processor has already agreed to pay $60 million to Visa, $3.6 million to American Express, and more than $41 million to MasterCard.

Apple Patches iTunes Security Vulnerabilities

In addition to new social networking features and GUI improvements, iTunes 10 patches 13 known vulnerabilities.

Microsoft Looks to 'Mitigate' Security Flaws With Updated Tool

Microsoft says it is shipping the newest version of an administrator's tool that helps manage key mitigation parameters in order to help corporate customers stay safer.

German Drugstore Chain Acknowledges Privacy Lapse

Personal data on 150,000 Schlecker customers was recently made available online.

Russian Police Arrest Cybercrime Gang

The group is accused of disabling victims' PCs via the WinLock Trojan, then demanding payment to repair the damage.

Hackers Steal $1 Million from University of Virginia

The funds were stolen after a computer belonging to the university's comptroller was compromised.

Researcher Warns of Orange Spain Privacy Flaw

The mobile phone company provides the user's phone number in response to any HTTP request sent by a web site.

Check Point Intros Virtual Security Gateway

Security Gateway Virtual Edition can be managed from the same platform as the physical version of Security Gateway.

Twitter Retools App, Link Policies, Sparks Privacy Worries

Microblogging service alerts users to two changes to how third-party applications integrate with the site, raising privacy concerns in the process.

Trojan Blamed for Diner Thefts

Infected PCs had been forwarding credit card details to criminals believed to be in Russia.

New Malware Targets IM Clients

The worm can send messages in 13 different languages.

Hackers Love Misconfigured Networks

In a recent study, the vast majority of respondents said misconfigured networks are the easiest IT resource to attack.

Trojan Masquerades as TweetDeck Update

The malware has been spreading via hacked Twitter accounts.

India Leads Global Virus Production

The country overtook the US during the month of August, according to security firm Network Box.

Cloud Security Alliance Launches Certification Program

The Certificate of Cloud Security Knowledge exam is available via the CSA web site.

Trend Micro Intros SecureCloud, Deep Security 7.5

The announcement was made in conjunction with the VMworld 2010 conference in San Francisco.