Click here

Security News: Archive: January 2011 

Former Salesforce.com Execs Launch Security Firm

The company, called Okta, offers an on-demand identity and access management service.

Amazon.com Security Flaw Found

The flaw allows customers to log in using several variations of an eight-character password.

Kaspersky Anti-Virus Source Code Leaked

The code covers the anti-virus engine, as well as the anti-phishing, anti-dialer, anti-spam, parental control, and other modules.

RealPlayer Gets Security Update

RealPlayer for Windows 11.0 to 11.1, 14.0.0 and 14.0.1 are affected.

SourceForge Hacked

Several services were taken offline in response to the attack, including the CVS system, Web-based code browsing, file upload capability and interactive shell services.

Russia: Stuxnet Malware Could Have Caused New Chernobyl

The country's ambassador to NATO called the virus 'very toxic, very dangerous.'

Phishing Campaign Targets First Data Merchants

The e-mails ask for the merchant's store number, user ID, tax ID, phone number and password.

Opera Update Patches Critical Security Flaw

Version 11.01 fixes a total of five vulnerabilities.

Hackers Target Connected Printers

Researcher Deral Heiland says printers are not typically secured as stringently as computers.

Rogue Anti-Virus Vendors Settle with FTC for $8.2 Million

The FTC says Marc D'Souza and Maurice D'Souza sold more than a million fake anti-virus products.

Goatse Security Hacked

An individual security professional at #Sigdie on EFnet IRC claimed responsibility for the attack.

Hackers Turn to Telnet Attacks

According to Akamai, 10 percent of attacks from mobile networks in the third quarter of 2010 were directed at Port 23.

Microsoft Warns on New Windows Zero-Day Hole

Microsoft has released a security advisory about a newly disclosed security hole and proof of concept code, but no attacks yet.

Anonymous Hackers Target Egyptian Sites

At least three government Web sites were knocked offline.

UK Police Nab 5 Members of 'Anonymous' Pro-WikiLeaks Hacker Ring

The WikiLeaks fallout continues as British authorities have detained alleged hackers involved with a group that targeted companies that cut off service to the whistleblower site.

Senator Seeks Device Privacy Protections

Ron Wyden plans to introduce a bill requiring that law enforcement agencies receive a warrant before accessing location data.

Cyber Attacks Hit South African Newspaper

The Mail & Guardian was recently taken offline after a series of attacks.

Security Lapse at University of Missouri

Employees' health benefit statements were delivered to the wrong addresses.

Avast! Free Anti-Virus to Add Sandboxing

Version 6.0 will include sandboxing virtualization technology.

Startup Offers Free Cloud Security Services

CloudPassage recently announced the availability of Halo SVM and Halo Firewall.

Merged SpyEye/Zeus Trojan Surfaces

Version 1.3.05 of the SpyEye builder appears to be the result of the merger, according to Trend Micro.

New Jersey School System Hacked

School lunch prices were reset to $9,000 per meal.

Windows Guru Publishes Cybercrime Novel

'Zero Day' was written by Microsoft Technical Fellow Mark Russinovich.

FFIEC Considers New Security Guidelines

The Federal Financial Institutions Examination Council may seek to clarify its existing guidelines on authenticating users.

Fedora Project Hacked

The intrusion doesn't appear to have resulted in any changes to the Fedora software.

Hackers Access Zuckerberg's Facebook Fan Page

Facebook CEO learns firsthand just how vulnerable everyone using social networking sites can be after someone accessed his fan page and began posting status updates.

Free Version of Darkness Botnet Tool Released

An older version of the bot code was recently made available for free in several underground forums.

Sarkozy's Facebook Account Hacked

The hackers posted a statement inviting supporters to a restaurant for an 'end-of-term party.'

Scareware Scam Zeros In On ICQ Users

Security software vendor Kaspersky has discovered a new fake anti-virus software campaign making its way around the popular instant messaging service.

Apple Gets New Director of Global Security

Dave Rice is the author of 'Geekonomics' and a former National Security Agency cyber security analyst.

NetWitness Intros Malware Analysis Appliance

The Spectrum appliance is designed to sit at the Internet gateway to examine network traffic.

Fake CCTV Sites Deliver Malware

The malware distributed in the attack has a very low detection rate, according to VirusTotal.

Google Announces Chrome Privacy Extension

The browser extension, called 'Keep My Opt-Outs,' enables users to opt out of tracking cookies from online ad networks.

Application Whitelisting Meets Linux, Mac

CoreTrace is bringing its Bouncer technology to the Linux and Mac platforms to shore up security via to application whitelisting.

India Issues Banking Security Guidelines

A Reserve Bank of India working group has issued more than 60 recommendations to help banks improve their information security.

Carberp Trojan Updated

The new variant adds RC4-based encryption for the communication protocol, among other enhancements.

Hacked Military Websites for Sale

Prices range from $33 to $499, depending on the importance or popularity of the site.

Zeus Trojan Targets Online Payment Providers

Trusteer has detected 26 Zeus configurations that target Money Bookers, and another 13 that target Web Money.

Critical Opera Security Flaw Found

The bug affects the latest version of the browser running on Windows 7 and Windows XP SP3.

Lush Cosmetics Hacked

Credit card details submitted to lush.co.uk between October 4 and January 20 may have been compromised.

Trapster Hacked

The company says its users' e-mail addresses and passwords may have been compromised.

Soundminer Trojan Targets Android Devices

The malware is designed to steal data from mobile devices running Android.

Bohu Trojan Blocks Cloud-Based Anti-Virus

The Trojan is designed to block access to cloud-based services from Chinese firms Kingsoft, Qihoo, and Rising.

Hackers Deliver Malware via Job Applications

More than $150,000 was stolen from a single business after the company received an e-mail containing malware.

Security Flaw Exposed USyd Student Data

The data included names, mailing addresses, e-mail addresses, courses attended, and cost of those courses.

Voicemail Phishing Scam Targets WikiLeaks Visitors

The scam threatens victims with a fine for having visited WikiLeaks.

Phishing Campaign Targets Brazilian Credit Card Users

The scam tries to lure victims with the promise of MasterCard rewards.

Malware Campaign Targets McDonald's Customers

New phishing scam detected by security software vendor AppRiver attempts to steal customers' banking, credit card data.

UK Doctor Disciplined Over Security Lapse

Patients' names, dates of birth and treatment information were exposed.

Twitter Worm Lures Victims into Scareware Trap

Security researchers at Kaspersky Lab are warning of a new fast-moving Twitter worm that's redirecting people to a bogus anti-virus software site.

E-mail Privacy Not Protected by Attorney-Client Privilege

According to a recent California appeals court ruling, e-mails between an attorney and a client are not confidential if they're sent from the client's work e-mail account.

Phishing Campaign Targets RuneScape Players

The e-mail asks the player to apply for a staff position, then collects his or her user name and password.

Security Flaws Found in Tamper-Evident Devices

Jamie Schwettmann and Eric Michaud recently warned of severe flaws in the security devices used to alert inspectors to tampering.

GAO Warns of Smart Grid Security Vulnerabilities

The Government Accountability Office says the rapid adoption of smart grid technology could leave the U.S. open to cyber attacks.

Carbon Trading Registry Hacked

The registry was disconnected from the EU and UN carbon trading registries in response to the attack.

DOJ Files Criminal Charges Against iPad Hackers

Daniel Spitler and Andrew Auernheimer will each be charged with one count of conspiracy to access a computer without authorization and one count of fraud.

Security Blogger May Have Been Hospitalized

Dnevnik.org reports that Danchev has been hospitalized since December 11, 2010.

DHS Gives USC $16 Million for Security Testbed

The DETERlab testbed provides an isolated 400-node mini-Internet for investing malware and other threats.

Tor Project Gets Security Update

Version 0.2.1.29 of the software addresses several vulnerabilities.

F-Secure Leads Anti-Virus Software Review

AV-Comparatives recently gave its Product of the Year award to F-Secure Internet Security 2011.

Sybase Patches EAServer Security Flaws

A recent update patches two security vulnerabilities.

Reid Looks to Fast-Track Cybersecurity Legislation

While a final bill still must still overcome significant jurisdictional hurdles, aide to Senate majority leader says bringing cybersecurity legislation to a floor vote is a priority this year.

Black Hat: Microsoft Donates Security Tools

What better place to give out tools aimed at making systems more secure than one of the premier hackers' conferences?

NASA Gets New Information Security Chief

Valarie Burks is the agency's new deputy CIO for Information Technology Security.

Stuxnet Cyber Attack Tied to US, Israel

According to the New York Times, the two countries jointly developed the worm in order to sabotage Iran's nuclear program.

Facebook Apps Raise New Privacy Concerns

The social networking site has begun providing app developers with access to users' addresses and phone numbers.

Cyber Security Firm Covertix Gets $1 Million

The funding will be used to enter the European security market, strengthen product offerings, and boost international sales and marketing.

FDIC Warns of Patriot Act Phishing Campaign

The e-mails claim that recipients' accounts have been suspended because of violations of the Patriot Act.

Spammers Use Fake Airline Charges as Lure

A new spam campaign alleges that the recipient has been charged a fee by a leading German airline.

Selena Gomez Hacked

A hacker calling himself 'PkinJ0r' took credit for the attack.

Vodafone Employees Fired Over Security Breach

Several employees were fired after millions of customer records were exposed online.

Hackers Host Call of Duty on Medical Server

The hacked server stored patients' names, social security numbers, medical diagnosis codes, addresses, and other details.

Leading Web Sites Hacked

High profile sites have been redirecting users to fake online stores.

Security Blogger Missing

Dancho Danchev has been missing since August of 2010.

Porn Malware Snares 2,500 Victims

Worm_Rixobot.A has been spreading via infected porn sites, IM applications and infected USB drives.

BitDefender Launches Free Malware Removal Tool

The tool is designed to remove Backdoor.Lavandos.A.

Palin Hacker Jailed

Despite the judge's recommendation that he serve his time at a halfway house, David Kernell is now in federal prison.

Irish Democratic Unionist Party Hacked

Three sites run by the DUP were recently replaced with Irish language versions.

Cancer Researchers Disclose Laptop Security Lapse

A stolen laptop contained years of cancer research data which had never been backed up.

Kama Sutra PowerPoint Delivers Malware

The file installs a Trojan identified by Sophos as Bckdr-FRM.

Wireshark Gets Security Updates

Versions 1.2.14 and 1.4.3 were recently released.

RIM Patches BES Security Flaw

The company also published a workaround for administrators who can't apply the patch immediately.

VASCO Data Security Buys DigiNotar

DigiNotar is licensed as an official Dutch certification authority.

Former TSA Worker Jailed for Planting Malware

The malware was found on the system before it was able to cause damage.

Sony Sues PS3 Hackers

The company is also seeking a temporary restraining order against the group.

NSF Funds Texas Cyber Security Students

Students studying cyber security at the University of Texas at San Antonio will receive up to $56,000 during their last two years of study.

SAP Buys SECUDE Security Software

The acquisition is intended to provide SAP's customers with improved security.

Cracking Wi-Fi Password Protection with Amazon EC2

Thomas Roth used custom software running on EC2 to break into a WPA-PSK protected network in about 20 minutes.

Statistics Canada Failed to Disclose Security Breaches

The agency recently experienced several data breaches that it didn't report publicly.

Koreans Arrested for Cyber Attacks on Gambling Sites

The two suspects are accused of launching denial of service attacks against rival sites.

Spammers Back in Business

The drop in spam volumes over the holidays remains unexplained.

UM to Spend $2.6 Million on Cyber Security

An audit of the University of Maine's IT systems found four areas of high risk.

Researcher Publishes Chinese SCADA Security Exploit

Dillon Beresford says he tried to contact the vendor but received no reply.

Researcher Breaks Wi-Fi Passwords Using Cloud Computing Power

Does cheaper compute power – thanks to the cloud – mean that hackers can use publicly-available resources to break into low-cost networks?

New Phishing Gimmick Targets Coca-Cola

The soda giant is being targeted by a phishing scam that offers some quick cash in exchange for a litany of personal information.

DeveloperWorks Hacked

The site was recently hacked and defaced.

Hackers Target Kim Jong Un

The North Korean heir apparent's YouTube channel and Twitter account were recently compromised.

Photo Album Malware Hits Facebook

The worm lures victims with the promise of a photo viewing application.

New Botnet Service Launched

The service is designed to help people get Zeus botnets up and running.

Fine Gael Hacked

The hack resulted in the compromise of personal information on 2,000 supporters of the Irish political party.

Mono Gets Security Update

Mono 2.8.2 patches a security flaw in the software platform.

Trend Micro Intros Android Security App

The application is designed to protect Android devices in four key ways.

PHP Gets Security Update

Versions 5.3.5 and 5.2.17 were recently released.

Researcher Develops Trojan Mouse

Adrian Crenshaw has developed a keystroke logger that can be concealed in a mouse.

Video Poker Hackers Charged

John Kane and Andre Nestor have been charged with computer hacking and conspiracy.

Hackers Put Android 2.3 on iPhone 3G

Nick Pack and others have installed Gingerbread on an iPhone 3G.

Visa Updates Security Tools

The company says the updates will improve fraud detection by 29 percent.

New Phishing Scam Targets PayPal Users

Latest security threat to the online payment service attempts to snare users' login and password credentials.

Mac App Store Comes with Security Update

Mac OS X 10.6.6 includes a single security fix.

Sourcefire Buys Anti-Virus Vendor

The company purchased Immunet for $21 million.

Security Breach at Pentagon Federal Credit Union

The attackers accessed a database containing a wide range of personal information on members, owners, employees and beneficiaries.

Hackers Auction Stolen iTunes Accounts

The hacked accounts are being sold at taobao.com.

Spammers Take a Break

MessageLabs reports that spam volumes have dropped more than 50 percent since Christmas.

Researcher Bypasses Adobe Flash Security

Google researcher Billy Rios published the method on his personal Web site.

Apple's Mac Apps Store Causes Anti-Piracy Concerns

The new apps store for Apple's Macs opened its doors on time and had a spectacular showing on its first day, but perhaps the company opened them too broadly, if the complaints about the store's anti-piracy protections are to be believed.

ITRC Calls for Universal Data Breach Reporting

Non-profit identity theft prevention organization says shoddy reporting keeps consumers in the dark and at greater risk.

Commerce Secretary Pushes Trusted Identities in Cyberspace

U.S. Commerce Secretary Gary Locke announces a National Program Office focused on steps to ensure trusted online transactions. Can it work?

Construction Begins on $1.2 Billion Cyber Security Center

The center is being built as part of the White House's Comprehensive National Security Initiative.

Audit Finds Weaknesses in GSA Cyber Security

The audit determined that the agency needs to strengthen cyber security in four key areas.

Dubai Assassins Leveraged E-mail Trojan

Mahmud al-Mabhouh's computer was bugged prior to his assassination in January 2010.

Banks Struggling with Cyber Security

According to Information Security Media, 48 percent of small and mid sized banks faced phishing attacks in 2010.

Google Adds Email Authentication to Fight Spam

Google Apps users now have the option of adding email authentication to validate email and head off spam messages.

Phishing Attack Targets AOL Customers

The e-mails are designed to trick subscribers into disclosing a wide range of personal information.

One Third of All Malware Created in 2010

Last year saw the creation of 34 percent of all malware that has ever existed.

Piwik Gets Security Update

Version 1.1 of the open source web analytics solution patches several vulnerabilities.

Security Vulnerability Found in ImgBurn

Security researchers are warning of a highly critical vulnerability in the disk burning application.

Microsoft Warns of Windows Graphics Security Flaw

The company says it has not yet detected any attempts by attackers to target the vulnerability.

Kenyan Police Web Site Hacked

The attack was dedicated to Facebook CEO Mark Zuckerberg.

Mobile Users Most Vulnerable to Phishing

Trusteer reports that mobile users are three times more likely to submit their login details to phishing sites than desktop users.

Security Flaw Found in VLC Media Player

Users are advised not to open files from unknown sources until a patch is released.

Microsoft Warns on Windows Graphics Rendering Bug

Microsoft issued a security advisory for a bug in Windows’ Graphics Rendering Engine, and is working on a patch.

Kokoda Warns of Weakness in Australian Cyber Security

The foundation says cyber security has become a 'fundamental weakness' in Australia's national security.

Stuxnet Malware May Have Taken Out 1,000 Centrifuges

The ISIS says IAEA reports support the possibility that Stuxnet was responsible for the issues with the centrifuges.

Cyber Attack Spoofs White House Holiday Greeting

The attack has successfully stolen gigabytes of data from dozens of victims.

Japan Seeks to Criminalize Malware Creation

A similar bill was introduced, unsuccessfully, in 2004 and 2005.

Pro-WikiLeaks Hackers Target Tunisian Web Sites

The attack was launched in response to the Tunisian's government's ban on access to WikiLeaks.

Dell Snaps Up SecureWorks

The Security-as-a-Service provider expands Dell's IT portfolio with a number of security, threat management and compliance services.

WSU Students Linked to Cybercrime Ring

The Department of Homeland Security says Tram Vo and Khoi Van are responsible for $1.25 million in fraudulent charges.

The Return of the Storm Botnet

Researchers at the Shadowserver Foundation are warning of a new attack.

Nook Color Hacked

Step-by-step instructions are available for rooting the device, allowing users to download and run Android apps.

FireEye Researcher Warns of PDF Security Flaws

At the 27th Chaos Communication Congress, Julia Wolf recently described several significant flaws in the standard.

Hackers Demo GSM Eavesdropping

Karsten Nohl and Silvain Munaut recently demonstrated a toolkit that enables them to eavesdrop on phone calls and text messages.

Google Researcher Posts Internet Explorer Fuzzer

A Google security researcher has written and released a hacker's tool to help find flaws in browsers, particularly Internet Explorer.

UKCA Tries to Stop Security Research

The UK Cards Association has tried to block publication of a paper that reveals some of the limitations of chip-and-pin tech.

Pro-WikiLeaks Hackers Hit Zimbabwe

Government web sites were recently targeted by a denial of service attack.