Click here

Security News: Archive: May 2011 

Mac OS Update Targets MacDefender Malware

Security Update 2011-003 finds and removes known variants of the malware.

Honda Canada Sued Over Security Breach

The class action lawsuit seeks $200 million in damages.

Fake Strauss-Kahn Video Delivers Mac Malware

The link takes users to a fake anti-virus page that tries to install the MacDefender Trojan on the user's computer.

Python Gets Security Update

Version 2.5.6 fixes several medium security issues.

PBS Hacked

LulzSec hackers defaced the PBS.org site and posted stolen company information online.

Google Pulls Malware-Laden Apps from Android Market

Up to 120,000 users may have been affected by the malware before the apps were removed.

Safety Scanner Finds 5 Percent of Windows PCs Infected

Microsoft recently reported that 20,000 of the 420,000 downloads of its new Safety Scanner found malware on PCs.

BofA Data Theft Costs $10 Million

Scammers stole names, addresses, Social Security numbers, mother's maiden names and more.

Lockheed Martin Suffers Possible Security Breach

The company has reset passwords following a 'major internal computer network problem.'

Become a Hacker in 15 Minutes or Less

YouTube tutorials can teach anyone how to hack someone's Facebook or Paypal account in less than 15 minutes.

Mac Malware Linked to ChronoPay

According to Brian Krebs, victims are being directed to domains owned by the Russian payment processor.

Trend Micro Questions Chrome OS Security

Company director of security research Rik Ferguson says the operating system isn't as secure as it might appear to be.

U.S. Government Sees 15,000 Cyber Attacks a Day

A DHS official said the government's network intrusion detection system registered a total of 5.4 million 'hits' in 2010.

Comodo Reseller Hacked

Hackers stole a wide range of sensitive data including certificate authority name, e-mail, fax, phone number and more.

Honda Canada Acknowledges Security Breach

Customer names, addresses and Vehicle Identification Numbers were accessed.

Google Releases Chrome Security Update

Version 11.0.696.71 fixes four security flaws.

WordPress Gets Clickjacking Protection

The latest update of popular open source blogging platform gets improved security and dumps IE6 support.

New Mac Malware Doesn't Require Admin Password

Removing the need for a password is a significant advanced for the Mac Defender malware.

Taipei Seeks Information on Sony Security Breach

City officials wants more information on how the PlayStation Network was breached.

WordPress Security Update Released

Version 3.1.3 fixes several security issues.

Researchers Warn of CAPTCHA Security Flaws

New software is able to defeat audio CAPTCHAs with a 41 to 89 percent success rate.

Spammers Leverage Fake URL Shortening

According to Symantec researchers, spammers have begun establishing their own fake URL shortening services.

Lawsuit Accuses Disney of Security Lapse

Two employees say the company embedded easily readable social security numbers in workers' ID cards.

Travel, Education, Financial Services Most Vulnerable to Phishing

According to KnowBe4, employees in those sectors are most likely to click on links in phishing e-mails.

Phishing Scam Targets Apple App Customers

The e-mails appear to be timed to coincide with actual purchases from Apple's App Store.

Symantec Warns of New Fakefrag Trojan

The Trojan hides all files on the user's hard drive, then demands $79.50 to recover them.

73 Percent of Network Devices Have Security Flaws

The majority of the flaws are due to one specific vulnerability, according to researchers at Dimension Data.

Security Update Released for Apache HTTP Server

Version 2.2.19 patches a denial of service vulnerability rated as moderately critical.

Sony Ericsson, Sony BMG Japan Hacked

The attacks were carried out by the hacker groups Idahca and Lulz Sec.

Researcher Says Siemens Downplayed Security Flaws

Dillon Beresford says Siemens' claims that he was working under 'special laboratory conditions' and had 'unlimited access to protocols' aren't true.

Microsoft Patches Hotmail Security Vulnerability

The flaw enabled attackers to access a user's e-mails and contacts.

Clarified Networks Acquired by Security Testing Firm

Codenomicon says the acquisition will expand its solutions for system analysis and situational awareness.

So-net Entertainment Hacked

A hacker accessed e-mail accounts and stole customer rewards points from the Sony subsidiary.

Sony Says PlayStation Security Breach Will Cost $170 Million

The costs include identity theft protection for users, free games, and associated legal costs, according to the company.

Former BofA Employee Sentenced for Security Breach

Rodney Reed Caverly has been sentenced to 27 months in jail, and has been ordered to pay $419,310.90 in restitution.

Researcher Warns of LinkedIn Security Flaws

Rishi Narang says the access token stored in the site's LEO_AUTH_TOKEN cookie doesn't appear to expire.

Norwegian Military Hit by Cyber Attack

A day after the country's fighter jets bombed Libya, a military computer was compromised.

Goal.com Continues to Serve Malware

After an initial infection was cleaned, the site began serving malicious code again.

Sony Thailand Hacked

One of the company's servers has been used to host a phishing site.

Senator Questions Facebook's Privacy, Security Efforts

Jay Rockefeller called the social network's use of only 100 employees to ensure that underage children aren't using the site 'completely indefensible.'

ICASI Launches Security Flaw Reporting Framework

The CVRF is intended to standardize the reporting of security vulnerabilities.

Fedora 15 Boosts Linux Security

New release of Red Hat's community Linux distro debuts new dynamic firewall technology that could revolutionize how we all secure our server and desktop infrastructures.

Spam Volumes Dropped in April

The amount of spam worldwide declined by 65.42 percent between April 2010 and April 2011.

Kaspersky: Mobile Malware Will Double in 2011

Researchers say the increase will be driven by the growth in popularity of the Android operating system.

Facebook to Offer Rewards for Security Vulnerabilities

The company's chief security officer announced the plans at the Hack in the Box conference in Amsterdam.

SpyEye Trojan Targeted Verizon Customers

The Trojan was used to targeted the company's online billing page.

Researcher Warns of Mac App Store Security Issue

Joshua Long discovered that Apple is publishing outdated software.

DHS Cyber Security Chief Resigns

Philip Reitinger says he's leaving the job to spend more time with his family.

Student Hacker Sentenced for Using Trojan

Paul McLouglin received a suspended sentence for tricking victims into downloading password-stealing software.

Clearwell Systems Acquired by Symantec

Symantec will combine Clearwell's legal document analysis and archiving with its Enterprise Vault e-discovery software.

Cyber Criminals Moving Operations to Canada

Websense uncovers 300% increase in hosted crimeware coming from our friends to the north.

Security Researchers Cancel SCADA Hack Demo

Siemens and ICS-CERT had asked Dillon Beresford and Brian Meixell to cancel their presentation.

Opera Gets Security Update

Version 11.11 patches a critical security flaw.

Ronaldinho Hacked

The Brazilian soccer star's Web site was recently defaced with anti-American messages.

FCC Launches SMB Security Web Site

The site offers a wide range of materials aimed at helping small businesses improve their cyber security.

US Warns of Military Response to Cyber Attacks

The White House says military force will only be used when all other options are exhausted.

Sophos Expands Enterprise Security Portfolio

Sophos Mobile Control is designed to help IT departments protect all employee devices.

NASA's Earth Observation System Hacked

Hacker TinKode has published screenshots from an FTP server at Goddard Space Flight Center.

CA Sells Anti-Virus Division

Purchaser Updata Partners plans to launch a new firm, provisionally called Total Defense, Inc.

Journalist Arrested at Australian Security Conference

Ben Grubb was arrested after writing an article on a demonstration of Facebook vulnerabilities.

Massachusetts Security Breach Enabled by Malware

The W32.QAKBOT virus infected computers at the Departments of Unemployment Assistance and Career Services.

Security Flaw Found in Almost All Android Smartphones

While the vulnerability in patched in the newest version of the operating system, 99.7 of all Android devices run older versions.

AT&T Plans Mobile Security Service for Consumers

According to a company executive, the service will be made available to consumers starting in 2012.

Heroku Hit by Cyber Attack

A denial of service attack recently caused connection problems.

Cyber Attack Hits UK Public Sector Union

The union's Web site is being hit by a denial of service attack as it prepares for its annual conference in Brighton.

New Version of Alureon Malware Found

The update adds new ways of avoiding detection by anti-virus solutions.

California Considers Social Networking Privacy Law

If it passes, SB 242 would have a significant impact on the privacy policies of all social networking sites.

FTC Complaint Questions Dropbox Security

Christopher Soghoian says Dropbox can access the contents of the files it stores, and doesn't encrypt all traffic to and from a mobile device.

Teen Hackers Sentenced for Cyber Attacks

Police found data for thousands of compromised payment cards on the teenagers' computers.

Geek.com Hacked

The site has been infecting visitors with malware, according to Zscaler researchers.

Hoyos Announces EyeLock Security Device

The iris-scanning device, the company claims, is unhackable.

Senators Seek U.S. Security Breach Disclosure Guidelines

The senators have asked the SEC to issue national guidelines on data breach disclosures.

Facebook Adds Security Enhancements

The new features include two-factor authentication and warnings about malicious links.

Google Releases Security Update for Chrome 11

Version 11.0.696.68 patches two vulnerabilities.

Fox Hacked

Hackers recently published almost 400 employees' names and passwords online.

White House Intros Cyber Security Proposals

The recommendations include the adoption of a federal statute regarding data breach notifications.

Adobe Updates to Flash 10.3 for Security

Latest Flash Player update fixes 11 security flaws and provides new privacy protection.

US-CERT Warns of Iconics Security Flaw

The company has released a patch to address the vulnerability.

Google Responds to Android SMS Trojan

The company has removed 11 apps containing suspicious code from the Android Market.

Cyber Attack Hits Eidos Interactive

The Web sites for the game developer and its game Deus Ex were recently defaced.

Microsoft Warns of Rise in Phishing Attacks Based on Social Networks

The number of phishing attacks using social networking as a lure increased by 1,200 percent last year.

Pravda Hacked

F-Secure researchers report that the newspaper's English language site has been infecting visitors with malware.

Apache HTTP Server Gets Security Update

Version 2.2.18 patches a denial of service vulnerability.

Cyberthugs Using 'Marketing-like' Scams

As more obvious ways to rob users get blocked, sophisticated cybercriminals try a 'marketing' approach.

Michaels Security Breach Expands

The company has removed approximately 7,200 PIN pads from its stores nationwide.

Researchers Warn of New Sunspot Trojan

According to Trusteer, there are already confirmed fraud losses associated with Sunspot.

WatchGuard Announces Next-Generation Firewall

The WatchGuard XTM 2050 is designed for large enterprises and data centers.

Former ACS:Law Owner Fined for Security Breach

The ICO says the £1,000 fine could have been £200,000 if the firm was still trading.

Investment Firm Buys Security Company Tripwire

The acquisition is expected to close by the end of May.

Finnish Police Arrest Banking Trojan Gang

The gang used a variant of the Gozi trojan to steal online banking credentials from 89 customers of Nordea Finland.

Shavlik Launches Free Security Advisor

The solution is designed to help SMBs track down missing patches that provide significant security risks.

ATM Hacker Gets Three Years in Jail

Thor Alexander Morris planned to hit at least 35 ATMs in the Houston area that were vulnerable to attacks.

Symantec Warns of Facebook Security Flaw

Researchers say the bug may have provided access to millions of users' photos, profiles and other personal data.

AnonOps Hacked

A former member and IRC operator appears to have launched the attack.

Researcher Warns of WebGL Security Flaws

Context Information Security's James Forshaw has noted two possible types of attacks.

Zeus Malware Source Code Leaked

Files containing the source code for the crimeware kit recently started to appear on various online forums.

Government Lagging Industry in Protecting Consumers

Only 26 percent of websites adequately protect their visitors from malicious activity.

Microsoft Releases Critical Patch for Windows Servers

The company only has one 'critical' bug to patch for May's 'Patch Tuesday' drop, but it's still one that could bite IT departments.

OpenID Warns of Security Flaw

Some sites are not confirming that the information passed through Attribute Exchange was signed.

TalkTalk Intros Network Level Security Service

The HomeSafe service provides customers with malware alerts and parental control tools.

CyanogenMod Gets Security Update

Version 7.0.3 contains bug fixes for the update notification, as well as an important security fix.

Symantec Enhances Security Offerings

The changes are intended to streamline information management and protection.

Security Vulnerability Found in Skype for Mac

The flaw could allow an attacker to take control of a victim's computer.

BIND Update Patches Security Flaw

Update 9.8.0-P1 closes a potential denial of service vulnerability.

Cyber Attack Targets Syrian Facebook Users

The EFF says the Syrian government has replaced Facebook's security certificate with a forged one.

Metasploit 3.7 Takes Aim at Apple iOS

Open source vulnerability testing framework takes aim at Apple's iOS and improves overall performance for security researchers.

McAfee Warns of Cross-Platform Malware

IncognitoRAT targets both Mac and Windows users.

Store Faces Lawsuit for Installing Spyware in Rented PC

The device allegedly enables store employees to capture screen shots, keystrokes and webcam pictures.

Best Buy Acknowledges Security Breach

The incident is unrelated to the recent Epsilon breach.

Sophos Buys Network Security Company Astaro

Astaro provides integrated security offerings including VPN, firewall and intrusion prevention technology.

Hackers Plan Third Attack on Sony

The hackers claim they already have access to some of the company's servers.

Sony Connects Anonymous to Cyber Attack

A file found on a Sony Entertainment server was named 'Anonymous,' and included the catchphrase, 'We are Legion.'

Apple Issues iOS Privacy Update

The update makes changes to the iOS crowd-sourced location database cache.

Anonymous Hackers Target New Zealand

The group announced plans to attack New Zealand's government following the passage of an anti-piracy law.

Microsoft Plans Light Patch Tuesday

The company will fix two vulnerabilities, including a critical flaw affecting Microsoft Windows.

Netflix Employee Fired for Data Theft

The worker accessed customers' credit card data without authorization.

LastPass Warns of Possible Security Breach

The company is telling its users to change their master passwords.

FTC Settles with Ceridian, Lookout over Security Breaches

Both companies are required to implement information security programs and conduct regular security audits.

FBI Warns of Malware in Fake Bin Laden Photos

The messages, the FBI notes, will likely include a virus designed to steal information.

Security Flaws Found in ZyWall Appliances

The vulnerabilities can allow attackers to access data and reconfigure devices.

Microsoft Releases Windows Phone 7 Security Update

The update blacklists nine digital certificates acquired by a hacker in March.

Huawei Symantec Debuts 80 Gbps Firewall

Chinese networking giant comes to the U.S. in joint venture with Symantec and drops a 'great wall' for network security.

X Factor Hacked

Contestants' names, e-mail addresses, postal codes, phone numbers, and other data may have been accessed.

Admins Losing Sleep over Security Breaches

Forty-one percent of network and systems administrators say security breaches keep them up at night.

North Korea Blamed for Bank Cyber Attack

The malware strain used in the attack matches those used in previous attacks that came from North Korea.

Police Car Hacked

Kevin Finisterre recently found he could view audio and video captured from equipment mounted on the cruiser's dashboard.

Whisper Systems Launches Free Android Firewall App

WhisperMonitor gives Android users the ability to control what each installed app can do.

Intego Warns of Fake Mac Anti-Virus

The software, called MAC Defender, is being spread via SEO poisoning.

Data Breach Hits 25 Million More Sony Customers

Personal information was stolen from customer accounts at Sony Online Entertainment.

Goal.com Hacked

The site was found to be serving malware on April 27 and 28.

Bin Laden Searches Link to Malware

Scammers are already leveraging the news of Osama Bin Laden's death.

Firefox 4 Gets Security Update

Version 4.0.1 fixes two vulnerabilities.

NSA Publishes Home Network Security Advice

The document provides an overview of what home users should be doing to keep their networks safe.

Anonymous Hackers Target Iran

'Operation Iran' was launched on May 1.

Researchers Find New Apple Malware Toolkit

The Weyland-Yutani BOT recently appeared on underground forums.

Researcher Faces Lawsuit for Reporting Security Flaw

Magix AG has threatened Acidgen with a lawsuit for disclosing a buffer overflow vulnerability in the company's software.