Click here

Security News: Archive: November 2011 

FBI Warns of Cyber Attacks on Banks

The attackers are using a modified version of the Zeus Trojan called Gameover.

Sophos Warns of Malware in Postal Service E-mails

The e-mails come with attached ZIP files containing a Trojan.

Hackers Announce Operation Robin Hood

Members of Anonymous and TeaMp0isoN plan to steal  money from banks and donate it to charities and protest movements.

HP Says Hackers Can't Make Printers Catch Fire

The company says its LaserJet printers have a 'thermal breaker' designed specifically to prevent overheating.

E-mail Security Startup Agari Launches

Early customers include Facebook and YouSendIt.

University of California Hit by Security Breach

Credit card numbers, cardholder names, expiration dates, and encrypted debit card PIN numbers may have been accessed.

UK MoD Acknowledges Security Lapse

The Ministry of Defense says the loss of more than 150 laptops was 'almost inevitable.'

Sourcefire Immunizes 2 Million PCs with Immunet

Leveraging open source ClamAV and the cloud, Sourcefire layers its antivirus tech on top of other vendors solutions.

MyBB Software Gets Security Update

Version 1.6.5 patches three security flaws.

New Facebook Worm Found

The worm links to malware-laden sites containing a variant of the Zeus Trojan.

United Nations Hacked

Members of TeaMp0isoN recently published more than 1,000 UN staff e-mail addresses, user names and passwords.

Kaspersky Warns of New Android Trojan

The fake messaging app sends SMS messages to premium rate numbers.

Researchers Warn of HP Printer Security Vulnerability

Salvatore Stolfo and Ang Cui say the vulnerability could be exploited to cause a printer to catch fire.

Open Source FFmpeg Project Gets Security Updates

Versions 0.7.8 and 0.8.7 patch several vulnerabilities.

Security Breach Affects 250,000 Members of Youth Forum

Names, user names, passwords and location information were accessed.

Apache Server Hit by Reverse Proxy

Dangerous flaw puts internal Web servers at risk, but there is a fix in the works.

13 Million Gamers Affected by Nexon Security Breach

Names, user names, encrypted resident registration numbers and passwords of players of the game Maple Story may have been accessed.

Twitter Buys Android Security Startup

Whisper Systems announced the acquisition in a blog post on Monday.

Hacker Arrested After Trying to Blackmail Marriott

The company eventually caught hacker Attila Nemeth with the help of the U.S. Secret Service.

Alleged AT&T Hackers Tied to Terrorist Group

The four hackers were allegedly financed by Jemaah Islamiyah.

WineLibrary.com Acknowledges Security Breach

Customers' credit card information may have been compromised.

Law Enforcement Malware Leverages iTunes Vulnerability

The FinFisher spyware application exploits a flaw that was patched in iTunes 10.5.1.

FBI, DHS Deny Reports of Cyber Attack on Water Utility

According to an e-mailed statement, 'there was no malicious or unauthorized traffic from Russia or any foreign entities.'

YMCA Members Affected by Security Breach

Names, addresses, phone numbers, bank accounts and credit card information may have been accessed.

Google Enhances Security for Gmail, Other Services

The company is enabling 'forward secrecy' for Gmail, Google Docs, SSL Search and Google +.

Sutter Health Sued Over Massive Security Breach

The lawsuit contends that the health care system was negligent in its security, and took too long to notify victims of the breach.

ADP Australia Acknowledges Security Breach

A list of customer e-mail addresses was made available online by mistake.

Siri Hacked to Control Other Devices

Developer plamoni has demonstrated a hack that enables the solution to control an Internet-connected thermostat.

Centrify Updates Active Directory Integration Solution

Centrify Express 2012 seeks to ease the pain of IT professionals tasked with integrating Unix, Linux and Mac with Active Directory.

Microsoft Seeks Security Essentials Beta Testers

The new version will be made available to the general public by the end of 2011.

Nearly All Mobile Malware Targets Android OS

The amount of malware aimed at Android devices increased by 37 percent from the second quarter to the third quarter of this year.

Hackers Bring iPhone 4S to T-Mobile

Michael Capozzi and Daniel Scaleb have posted detailed instruction on how to make an iPhone 4S compatible with T-Mobile's network.

Nook Tablet Hacked

The device was rooted by the same developers who rooted Amazon's Kindle Fire.

APEC Host Committee Hit by Possible Cyber Attack

Stolen information may have included Social Security numbers, birth dates and other data.

Anonymous Hackers Target California Special Agent

The group published 38,000 e-mails from the account of cybercrime investigator Fred Baclagan.

Data Security Analyst Salaries to Rise in 2012

IT salaries overall are expected to increase by 4.5 percent next year, and data security analysts' salaries will rise by 6 percent.

Hacker Claims Responsibility for Water Utility Attacks

The hacker, who calls himself 'pr0f,' says he has hacked into several SCADA systems.

AT&T Wireless Hit by Cyber Attack

The company has warned targeted subscribers of an 'organized attempt' to access their online accounts.

Stuxnet Malware May Have Caused Deadly Explosion

The blast at an Iranian Revolutionary Guard missile base killed all attending technicians.

Rails Security Updates Patch XSS Vulnerability

The flaw could allow an attacker to insert arbitrary code into a page.

New Tool Bypasses Windows 8 Secure Boot

Security researcher Peter Kleissner has developed a new version of his Stoned Bootkit.

Norway Hit by Widespread Data Theft

At least 10 different cyber attacks were discovered in the last year.

Reid Plans Debate on Cyber Security Bill

The Senate Majority Leader plans to bring cyber security legislation to the floor of the Senate for debate early next year.

Backdoor Trojan Being Distributed via Facebook

A variety of messages lead to fake YouTube pages, where victims are tricked into downloading malware.

Nasdaq Hack Attributed to Weak Security

Computers had out of date software, missing security patches and misconfigured firewalls.

Google Leads in Reported Vulnerabilities

The company led the quarter with 82 reported flaws, followed by Oracle and Microsoft.

Joomla Open Source CMS Gets Security Updates

The updates patch a vulnerability that could be exploited to change a user's password.

Chrome Gets 2nd Critical Fix in a Week

In a rare move, Google is updating Chrome for a single security fix.

Hackers Target Water Utility, Destroy Pump

The attackers were able to burn out the pump after accessing its industrial control system.

Bitdefender Warns of Malware Disguised as Microsoft Office Tool

The fake version of Office Genuine Advantage is spreading via Yahoo Messenger.

Data on 4.2 Million Patients Stolen from Healthcare Company

A stolen computer contained patient names, addresses, dates of birth, phone numbers and more.

DevilRobber Trojan Gets New Disguise

The new version is being distributed as the image-editing program PixelMator.

Virginia Commonwealth University Hit by Security Breach

Hackers may have accessed 176,567 current and former students' and employees' Social Security numbers, names,  e-mail addresses and more.

Siri Security Protocol Hacked

Developers have managed to port the voice control solution to other iPhones.

Security Flaw Found in BIND

The vulnerability can cause the open source DNS software to crash unexpectedly.

Hackers Post Porn on Facebook

Violent images and porn were posted on several users' profile pages.

Romanian Hacker Charged with NASA Security Breach

Robert Butyka is accused of causing $500,000 worth of damage.

Researchers Report Surge in Android Malware

Juniper Networks says the volume of Android malware has increased by 472 percent since July.

AV-Test Warns of Weakness in Free Android Anti-Virus

Among seven apps tested, even the top-rated app only detected 32 percent of malware.

RSA DLP Suite Upgrade Secures Smartphones, Tablets

Seeking to help organizations control the lifecycle of their sensitive data, RSA introduces enhancements to DLP Suite 9.0 that helps them address smartphones, tablets and social media.

Anonymous Hackers Target Mining Company

The hackers say the company is leaking sodium sulfate into a local lake, polluting the air and turning snow black.

Title Insurance Company Sues Bank Over Security Breach

Global Title Services is suing its bank over more than $200,000 in losses.

University, FBI Investigate Grade-Changing Hacker

More than 60 current and former students' grades were changed.

Ambulance System Disabled by Malware

St. John Ambulance dispatchers were unable to access mobile data and paging services, and were forced to use manual backup systems.

Apple Patches iTunes Security Flaw

Version 10.5.1 fixes a vulnerability that could enable man-in-the-middle attacks.

Collective Intelligence Finds 200 Millionth Piece of Malware

Panda Security says its CI engine now detects 73,000 new malware strains a day.

Google Releases Security Update for Chrome 15

Version 15.0.874.120 fixes five 'high-risk' vulnerabilities, as well as several others.

Sky News Twitter Account Hacked

A fake message was posted claiming that James Murdoch had been arrested by London police.

Anonymous Hackers Target Muslim Brotherhood

Four of the organization's main Web sites were taken down following denial of service attacks.

F-Secure Warns of Digitally Signed Trojan

The malware uses a code-signing certificate stolen from the Agricultural Research and Development Institute of Malaysia.

Android 4.0 Face Unlock Security Easily Fooled

The facial recognition feature can be tricked by showing it a photo of the owner's face.

St. Louis Mayor's Web Site Hacked

The hacker posted 2,000 of Mayor Francis Slay's e-mails online.

Adobe Patches 12 Critical Flash Player Security Flaws

Several memory corruption vulnerabilities, the company says, could lead to code execution.

Ubuntu 10.04 Gets Security Update

The update fixes several security vulnerabilities, according to Canonical.

Energy Company Convicted of Hacking Greenpeace

EDF has been fined €1.5 million, and two executives have been jailed.

Steam Hack Confirmed, Affects 35 Million Users

User names, hashed and salted passwords, game purchases, e-mail addresses, billing addresses and encrypted credit card numbers may have been accessed.

Cyclist Found Guilty in Hack of Anti-Doping Lab

While Floyd Landis received a 12-month suspended sentence, hacker Alain Quiros will spend six months in jail.

Lockheed Martin Plans Australian Cyber Security Center

The NextGen Cyber Innovation and Technology Center is expected to open in March 2012.

Apple Releases Java Security Updates for Snow Leopard, Lion

The company says the updates provide 'improved compatibility, security and reliability.'

Former CTO Charged with Hacking into Hoboken Mayor's E-mail

Patrick Ricciardi faces up to 15 years in prison and a $750,000 fine.

Dropbox Releases Security Update

Dropbox version 1.2.48 patches a serious security flaw in the company's client software.

Apple's iOS 5.0.1 Fixes App Security Flaw

The update patches a vulnerability recently uncovered by researcher Charlie Miller.

Firefox 8 Released, Patches Six Security Flaws

Three of the vulnerabilities are rated critical.

Healthcare Organizations Increase Cyber Security Spending

Still, most spend less than 3 percent of their IT budgets on information security.

LANDesk Updates Management, Security Suites

Management Suite 9 and Security Suite 9 are designed to support a broad range of platforms.

Steam Forums Hacked?

Forum users' e-mail addresses may have been accessed.

Security Researchers Warn of Identity Theft Calling Service

The service offers to extract sensitive information for $10 a call.

Seven Charged with Involvement in $14 Million Fraud Scheme

The group is accused of infecting more than four million machines with malware.

Fake Kaspersky Anti-Virus Used as Phishing Lure

Victims are asked for their credit card info and e-mail address in order to 'receive further instructions.'

Adobe Patches Critical Security Flaws in Shockwave Player

The patches affect versions 11.6.1.629 and earlier.

Researchers: Hackers Could Enable Mass Jailbreaks

Vulnerabilities in federal prison control systems could allow hackers to open prison doors and crash CCTV or prison intercom systems.

DARPA Wants Hackers

Dr. Regina Dugan, DARPA's director, has called on 'visionary hackers, academics, and professionals ... to change the dynamic of cyber defense.'

Computershare Acknowledges Massive Security Breach

A lost USB drive could put the 'privacy and financial record of millions of shareholders' at risk, according to the company.

Security Researcher Plants Malware in Apple App Store

Charlie Miller got a fake app approved that could be used to control an iPhone or iPad, or to steal data from it.

Anonymous Hacker Signs Six-Figure Book Deal

Barrett Brown's book will reportedly be called 'Anonymous: Tales From Inside The Accidental Cyberwar.'

Brazilian ISPs Hit by Massive Cyber Attack

Police have already made at least one arrest in connection with the attack.

NSS Labs Announces Free Duqu Malware Detection Tool

The tool is designed to detect all malicious drivers used by the new malware.

Los Zetas Release Anonymous Hacker

In response, members of Anonymous have retracted a threat to identify associates of the drug cartel.

Anonymous Hackers Target El Salvador

The president's Web site was taken offline after receiving 30 million hits on Saturday.

Adidas Hacked

The company says the attack was detected on November 3rd.

Security Breach Hits 16,000 in Finland

Social security numbers, home addresses, phone numbers and e-mail address were published online.

Massive Security Breach at UK Council

An unencrypted memory stick containing personal information on more than 18,000 people was lost.

Attachmate Beefs Up Security

Attachmate's terminal emulation family, Reflection 2011 R2, gets upgrades to make users' sessions more secure.

Microsoft Partly to Blame for Spread of Duqu

The TrueType font parsing engine is to blame but Microsoft views the risk as low ... for now.

More Variants of DroidKungFu Mobile Malware Found

Fortinet researchers have uncovered several new variants of the malware.

Hackers Confuse Rugby Web Site with German Stock Exchange

The fan site for the French second division rugby club was unavailable for two weeks, but the German stock exchange was unaffected.

KPN Finds Cyber Attack Tool on Server

The Dutch certificate authority says it's stopped issuing certificates as a precautionary measure.

EU, US Conduct Cyber Security Exercises

Security experts from the US and 27 European Union member states participated.

Hacker's Data-Selling Web Site Hacked

Srblche's site has been used to advertise data stolen from the U.S. Army, the U.S. Department of Defense, and other institutions.

Alleged Celebrity Hacker Pleads Not Guilty

Christopher Chaney has apologized for his actions, but faces up to 121 years in prison.

Australian Government Suffers Security Lapse

Files belonging to Major-General John Cantwell were likely stolen during transit through Kuwait.

Australian ATM Hacker Denied Bail

Luke Angus McLaren faces charges of theft and unauthorized modification of data.

Hackers Leverage MIT Server to Launch Cyber Attacks

The campaign, which started in June, has resulted in more than 100,000 compromised Web sites so far.

Stanford University Researchers Defeat CAPTCHAs

The researchers found that 13 out of 15 CAPTCHA methods from leading Web sites were vulnerable to automated attacks.

eBay Hacker Gets Suspended Sentence

Vlad Duiculescu was given a three-year suspended sentence by a Romanian court.

Secunia Offers Non-Financial Rewards for Security Flaws

The Secunia Vulnerability Coordination Reward Program promises merchandise and access to a security conference.

Two Wireshark Updates Patch Multiple Security Flaws

Some of the vulnerabilities are rated highly critical.

UK Government Warns of Surge in Cyber Attacks

GCHQ director Iain Lobban says major IT systems throughout the UK are facing increasing numbers of attacks.

Cyber Attacks Take Down Phones, Internet in Palestine

Palestinian Communications Minister Mashur Abu Daqqa said the attacks appeared to be state-sponsored.

French Nuclear Power Company Hit by Cyber Attack

Local news reports are unclear, but some systems were left out of action for three days.

Two Jailed in UK for Use of Banking Trojans

Yevhen Kullibaba and Yurly Konovolenko have been sentenced to four years and eight months in jail.

Miley Cyrus Hacker Gets Probation

Josh Holly received three years' probation at a recent sentencing hearing.

Phishing E-mails Mimic Apple Notifications

The legitimate-looking e-mails ask victims to provide their ID and password.

Canadian Children's Ministry Acknowledges Security Lapse

Documents containing clients' names, addresses, birth dates and health card numbers were recently found in a dumpster.

Major Security Flaw Found in NJStar Translation Software

Dillon Beresford says the vulnerability could be used to take control of systems running the software.

WordPress Security Flaw Hits 1 Million Web Pages

A vulnerability in the TimThumb image resizing utility for WordPress sites has had an enormous impact.

College Student Arrested for Identity Theft

Simon Van Neste used forged ID cards to access secure areas of the Whitman College campus.