Click here

Security News: Archive: December 2011 

NIST Intros New BIOS Security Guidelines

The document focuses on two key integrity measurement mechanisms.

Hackers Release More Information from STRATFOR

Members of Anonymous published data on almost a million people.

Anonymous, TeaMp0isoN Hackers Plan Op Free Palestine

The hackers have announced plans to target Israeli Web sites in the coming year.

Zscaler: Botnets Are Leading Source of Enterprise Threats

The company says botnets have accounted for almost 80 percent of the security blocks at Zscaler over the past month.

Denial of Service Vulnerability Found in Ruby

The flaw was discovered by security researchers Alexander Klink and Julian Waelde.

Researcher Warns of Vulnerabilities in Train Switching Systems

Professor Stefan Katzenbeisser says the vulnerabilities could be exploited to cause extensive service disruptions.

Kaspersky: Same Teams Developed Stuxnet, Duqu Malware

The company also says the same software development environment was used to build both viruses.

Researchers Demo New Cyber Attack on GSM Phones

The researchers say the attack method is already being actively exploited.

Reaver Tool Published to Exploit WPS Security Flaw

The WPS attack tool was released this week by Tactical Network Solutions.

Microsoft Releases Emergency Patch for ASP.NET Flaw

The update was released approximately two weeks before the company's regularly scheduled security update.

Hackers Publish Information on 90 Million in China

User names, passwords, e-mail addresses and other data were posted online.

Kaspersky Warns of Rogue Anti-Virus for Android Devices

The malicious software is detected by Kaspersky as Trojan-SMS.AndroidOS.Scavir.

McAfee Warns of Cyber Attacks on Infrastructure in 2012

The company says cyber criminals will target utility systems in the coming year.

STRATFOR Claims Damage from Security Breach Was Limited

The security think tank says Anonymous hackers weren't able to access its confidential client list.

DHS Warns of New SCADA Security Flaw

The vulnerability in the Sielco Sistemi Winlog application could be exploited to execute arbitrary code.

SpecialForces.com Hacked

Anonymous hackers claim to have stolen 14,000 passwords and 8,000 credit card numbers from the equipment retailer.

Microsoft Warns of ASP.NET Zero Day Vulnerability

The unpatched flaw affects all versions of the Microsoft .NET Framework.

Hacker Brings Siri to Apple's iPhone 4

The tool, Spire, was introduced via a post on hacker chpwn's blog.

HP Firmware Update Mitigates Printer Security Flaw

The update is designed to mitigate a vulnerability that was discovered by researchers in late November.

Australian Retailer Sells Malware-Infected Hard Drive

Filmmaker Darryl Manson purchased the drive from retailer Dick Smith, only to find that it contained both malware and pirated movies.

FreeBSD Releases Five Security Advisories

One of the flaws was being actively exploited in wild, according to FreeBSD security officer Colin Percival.

Turkish Hackers Deface French MP's Web Site

Valerie Boyer's site was defaced in retaliation for her authoring of a bill that criminalizes the public denial of the Armenian Genocide.

Apple Customers Targeted by Phishing Campaign

According to Intego researchers, the campaign tries to trick victims into disclosing their credit card information.

Security Flaw Found in Wi-Fi Protected Setup

The vulnerability was discovered by researcher Stefan Viehbock, who reported it to US-CERT.

Siemens to Patch ICS Security Vulnerabilities

The company plans to release patches for the flaws in January.

Anonymous Hackers Take Down Egyptian Web Sites

Sites targeted included the president's Web site and the tourism bureau.

phpMyAdmin Update Patches Two Security Flaws

Version 3.4.9 patches vulnerabilities that could be exploited for XSS attacks.

City of Edinburgh Council Hit by Cyber Attack

A total of 8,745 debt advice records were accessed by hackers.

UCLA Health System Sued Over Security Breach

The class action lawsuit seeks $16 million, or $1,000 per patient.

STRATFOR Hacked

Approximately 200 GB of sensitive information, including credit card data, was stolen.

Vulnerability Found in Kaspersky Security Software

The flaw can be exploited to crash the complete software process.

Avast Intros Free Android Security Solution

Key features include privacy reports, call and SMS filtering, SIM card change notifications, firewall and application management.

Kim Jong-il's Death Used to Spread Malware

Trend Micro researchers report that the North Korean leader's death is being leveraged to distribute a Trojan.

MyVetDirect.com Suffers Security Breach

Customer names, addresses, phone numbers, e-mail addresses, credit card and billing information may have been accessed.

European Audit Leads to Facebook Privacy Changes

Facebook has announced plans to make changes to its site for European users.

More Malware Found in Official Android Market

The malicious apps were disguised as free versions of popular games.

DHS Gets $888 Million for Infrastructure Protection, Information Security

The funds for 2012 include $443 million for cyber security.

VLC Media Player 1.1.13 Patches Security Flaw

The update patches a vulnerability that could be exploited to compromise a victim's system.

New Malware Uses Free Trial as Lure

The Trojan offers to decrypt three files in order to convince victims to pay $69.

Fake Amazon Shipping E-mails Deliver Malware

All of the links in the e-mails redirect victims to a site hosting the BlackHole exploit kit.

Amnesty International Site Infected with Malware

The site serves a malicious Java applet that retrieves a Trojan.

Mozilla Patches Security Flaws in Firefox, Thunderbird, SeaMonkey

The update to version 9.0 patches several vulnerabilities in Firefox.

Comodo Enhances Internet Security Product

Comodo Internet Security 5.9 supports the company's TrustConnect VPN service and adds a new 'quick scan' engine.

Audit Finds Security Flaws at Nuclear Regulatory Commission

The independent audit identified three specific information security program weaknesses.

European Union Examines Maritime Cyber Security

According to a new report, the shipping industry has 'low to non-existent' awareness of cyber security issues.

Canalys Predicts Significant Growth in Anti-Virus Sales

The research firm predicts that anti-virus software sales will increase 6.8 percent year-on-year.

USAA Warns of Malware-Laden Phishing Scam

According to the firm, the phishing e-mails contain an attachment that installs a banking Trojan on victims' PCs.

U.S. Chamber of Commerce Suffers Security Breach

Hackers accessed six weeks of e-mail from four employees who focused on Asia.

Windows 8 to Add New Password Option

The new feature, called Picture Password, supports a combination of gestures for authentication.

Adobe Patches Reader, Acrobat Security Flaws

Both vulnerabilities are being actively exploited.

Lady Gaga's Twitter Account Hacked

A malicious link was posted, along with the promise of free iPad 2s for all followers.

Microsoft Warns of Malware Posing as Police Alerts

The ransomware imitates messages from local police, including the UK Metropolitan Police, the Spanish police, Dutch police, and many others.

Fidelis Anticipates Increase in Advanced Persistent Threats

Company president and CEO Peter George says APTs will grow in volume and sophistication.

Zero Day Vulnerability Found in Windows 7

Proof-of-concept code was recently published on Twitter.

Critical Security Flaw Patched in TYPO3 CMS

According to the developer team, the vulnerability is already being exploited on a large scale.

Canadians Investigate Link Between Data Breach, Violent Crime

The Royal Canadian Mounted Police is looking into a possible connection between a data breach and a series of arson attacks and shootings.

Anonymous Hackers Publish Info on U.S. Senators

The hackers leaked personal information on Senators who had voted for the National Defense Authorization Act (NDAA).

Ukranian General Arrested for Involvement in Cybercrime

Valeriu Gaichuk and two associates were arrested while trying to withdraw $1 million from CEC Bank.

The Age Raided, Journalists Accused of Hacking

The journalists are suspected of hacking into computers belonging to the Australian Labor Party.

Manhattan District Attorney Charges 55 with Cybercrime

The defendants are accused of stealing more than $2 million from several different financial institutions.

Pidgin 2.10.1 Patches Security Vulnerabilities

The new version addresses four denial of service flaws.

Microsoft Plans Silent IE Security Updates

The company will roll out automatic upgrades of Internet Explorer starting next month.

Game Company Square Enix Hit by Cyber Attack

Information on 1.8 million customers may have been accessed.

Iran Claims to Have Hacked U.S. Drone

The Iranians say they leveraged a known vulnerability in the drone's GPS system to trick it into landing in the country.

Box.net Enhances Cloud Storage Security

The improvements are intended to make the solution more attractive for enterprise deployments.

Most Younger Employees Don't Follow IT Security Policies

Fully 70 percent of employees age 21-29 often ignore their companies' security policies, according to a Cisco-sponsored survey.

Adobe Patches ColdFusion Security Flaws

The vulnerabilities could lead to a cross-site scripting attack.

Lookout Warns of Surge in Android Malware

The majority of the malicious apps, the company says, can be found on third-party app stores.

Hacker Arrested for Cyber Attack on Gene Simmons

Kevin George Poe faces charges of unauthorized impairment of a protected computer.

GlobalSign Targeted by Cyber Attack

The company says no customer data was exposed, and its infrastructure and systems were not affected.

Atlanta Hospital Shut Down by Malware

The malware disabled computer connectivity within Gwinnett Medical Center's two facilities.

Visa Investigates Possible Payment Processor Security Breach

Several European banks have already taken steps to limit potential fraud.

DHS Warns of SCADA Security Vulnerabilities

The Department of Homeland Security has re-released a warning from 2010 stating that industrial control systems can be detected by Internet scanners.

FTC to Issue Refunds to Rogue Anti-Virus Victims

The refunds will average $20 per person.

Winamp Update Patches Three Security Flaws

The vulnerabilities were discovered by Secunia's Dmitriy Pletnev and independent researcher Hossein Lotfi.

Google's Chrome 16 Patches 15 Security Flaws

The newest version of the browser addresses six high-risk, seven medium-risk, and two low-risk vulnerabilities.

Three Members of Bulgarian Phishing Gang Arrested

The men were arrested following a joint investigation by the FBI and the Bulgarian Chief Directorate for Combating Organized Crime.

State of California Announces New Cybercrime Unit

The unit, which began operations in August, has already filed charges in 20 cases.

Restaurant Depot Acknowledges Security Breach

Hackers accessed cardholder names, credit card numbers, expiration dates and CCVs.

U.S. Analyst Blames Russia for Stuxnet Malware

Dr. Panayotis A. Yannakogeorgos says the Russians may have intentionally planted a worm with digital U.S. and Israeli fingerprints.

Accuvant Study Finds Chrome is Most Secure Browser

The study was financed by Google, though Accuvant says it was an 'independently designed security analysis.'

TeaMp0isoN Hackers Expose City of Glendale Site Vulnerability

The hackers chose not to exploit the security flaw.

Anonymous Hackers Target Florida Family Association

Some members' e-mail addresses and IP addresses were posted online.

Microsoft Patches Duqu, Leaves BEAST

Final Patch Tuesday release of 2011 tackles 13 bulletins, three rated as critical.

Researcher Warns of SMS Security Flaw in Windows Phone 7.5

The vulnerability has been tested and confirmed on several Windows Phone devices.

Telstra Suffers Massive Privacy Breach

Personal information on more than a million customers was inadvertently made available online.

Defense Department Consults With Hacker Charlie Miller

Miller recently gave a talk at NATO's Cooperative Cyber Defense Center of Excellence in Tallinn.

Study Finds Widespread Security Flaws in Android Apps

According to Veracode, 40 percent of Android apps contain at least one instance of hard-coded cryptographic keys.

Majority of Heartland Security Breach Claims Dismissed

Judge Lee Rosenthal ruled that the banks had failed to state proper claims for seeking damages from the company.

More Malware Found in Android Market

Google recently removed 22 malicious apps from the market.

Six Arrested in UK Over £1 Million Phishing Scam

The scammers stole between £1,000 and £5,000 at a time from hundreds of British students.

Hacker Defaces Leading Pakistani News Site

The Web site dawn.com was defaced, and some database information was published online.

Foxit Reader 5 Gets Security Update

Version 5.1.3 patches a highly critical vulnerability.

U.S. Government Announces Cloud Security Standards

All cloud service providers will have to meet the standards in order to sell their products and services to government agencies.

Researchers Warn of New Zero Day Flash Vulnerabilities

The two security flaws were uncovered by Russian research firm Intevydis.

Microsoft Announces Plans for December Patch Tuesday

The company will release 14 patches to fix 20 vulnerabilities.

Anonymous Hackers Target Monsanto

The group has claimed responsibility for the shutdown of a PR firm that represented Monsanto.

California County Acknowledges Security Lapse

The names of approximately 4,700 residents who owed money to Contra Costa County's Health Service Department were posted online.

HP Faces Lawsuit Over Printer Security Flaw

The class action lawsuit follows recently published research which uncovered a significant vulnerability in HP printers.

84 Percent of Applications Fail Security Testing

It's a big change from Veracode's last set of tests six months ago, in which 42 percent of applications passed.

Dutch Certificate Authority Gemnet Hacked

The company says the attackers were able to access some private data and documents.

Hackers May Have Rigged FIFA World Cup Bids

The Telegraph is reporting that FBI officials have 'substantial evidence' that attempts were made to hack key e-mail accounts.

Four Hackers Charged With Cyber Attacks on POS Systems

The four Romanian residents have been charged with conspiracy to commit computer fraud, wire fraud and access device fraud.

Congress Investigates SAIC Security Breach

Five members of Congress have sent a letter to TRICARE Management Authority asking for more information on the breach.

Sophos Updates Endpoint Security Solution

Key enhancements in Endpoint 10 include patch management, Web filtering and full-disk encryption.

Anonymous Hackers Hit Toronto Web Sites

More than 50 businesses' Web sites were redirected to the Occupy Toronto site.

Majority of Lost USB Drives Infected with Malware

According to Sophos, 33 of 50 lost USB devices it examined were infected.

Facebook Fixes Photo Privacy Flaw

The company says the bug was created in a 'recent code push' and was only available for a limited period of time.

Spammers Ordered to Pay Yahoo $610 Million

The spammers were accused of sending out fake e-mails telling recipients they had won a lottery sponsored by Yahoo.

Europe Considers Massive Fines for Security Breaches

Companies could face fines of up to five percent of their global turnover.

Opera Update Patches Three Security Flaws

The vulnerabilities are fixed in version 11.60.

Symantec Sees Spam Slowdown

The company says global spam has fallen to its lowest level in three years.

Symantec Unveils Consulting Services to Address Mobile Threats

The new services offering is intended to help organizations assess and mitigate the risk associated with deployment and use of mobile devices.

Poker Site Ultimate Bet Hit by Security Breach

Customers' names, screen names, birth dates, e-mail addresses, phone numbers and mailing and IP addresses were posted online.

International Checkout Hacked

Customers' credit card numbers were accessed.

Adobe Warns of Zero Day Reader, Acrobat Security Flaw

The company says it plans to have a patch available by next week.

MIT Warns of Cyber Attacks on Power Grids

The current system, researchers say, leaves six million miles of electrical lines unprotected.

Sourcefire Debuts Next Gen Firewall System

Next Generation Firewall market moves forward with new release.

Ponemon Sees Surge in Healthcare Data Breaches

According to a recent study, data breaches in the healthcare industry have increased by more than 30 percent.

Russian Media Hit by Cyber Attacks

Several Web sites were taken down by DDoS attacks that may have been coordinated by the Russian government.

Raytheon Buys Security Company Pikewerks

The purchase is Raytheon's ninth cyber security related acquisition since 2007.

Sophos Warns of Amazon Phishing Campaign

E-mails claiming to come from Amazon.com ask for the user's credit card details, date of birth and more.

Security Flaws Found in Verified by Visa, SecureCode

According to Trend Micro, the password reset function makes it disturbingly easy for a hacker to access a user's account.

Google Adds Malware Distribution Warnings

Google's Safe Browsing Alerts will now alert network operators to domains that are responsible for distributing malware.

UK Airport Hit by Security Breach

Hacker Kahuna published over 2,000 titles, names, addresses, e-mail addresses, phone numbers, and more.

Privacy Flaw Found in Skype

A user's location and identity can be exposed, along with any content being downloaded.

Another United Nations Web Site Hacked

Members of Sector 404 leaked Barack Obama's e-mail address, username, password, personal phone number and login ID.

Security Vulnerability Found in Yahoo Messenger

The flaw can allow an attacker to change users' status messages.

Carrier IQ Faces Privacy Lawsuits

The lawsuits claim the company's software violates mobile phone users' privacy.

Duqu Hackers Erased Their Tracks

Kaspersky Labs researchers say all of the command and control servers were wiped clean on October 20.

PwC Researchers Warn of Increase in Cyber Attacks

The number of cases of fraud costing more than $100,000 is also on the rise.

Sophos Warns of Apple Phishing Campaign

The e-mails ask Apple customers to click on a link to update their billing information.

Researchers Discover Significant Android Security Flaw

The vulnerability can enable attackers to record conversations and monitor location data.

BlackBerry PlayBook Hacked

A group of researchers claims to have jailbroken the device.

Adobe Patches Flex Security Vulnerability

The company has released an update to patch a flaw that could enable cross-site scripting attacks.