Click here

Security News: Archive: January 2012 

Samba Gets Security Update

Version 3.6.3 patches a flaw that could be exploited to cause a denial of service.

High School Hackers Arrested for Changing Grades

Three juniors at Palos Verdes High School are accused of hacking into their school's grading system.

Fifteen Companies Announce E-mail Security Standard

The DMARC framework is intended to protect e-mail at the domain level.

Scottish Council Faces Record Fine for Security Breaches

The Midlothian Council has been fined £140,000 for five separate data breaches.

20-Year-Old Romanian Hacker Arrested

Razvan Manole Cernaianu, allegedly known as 'TinKode,' is accused of stealing data from NASA and Pentagon servers.

Hackers Infect WordPress Web Sites

More than a hundred sites have been compromised, according to Websense.

Cisco Warns of Vulnerability in Security Appliances

Users are advised to deactivate telnet services in order to mitigate the vulnerability.

Malware Uses Google+ Plug-In As Lure

The malware is disguised as a plug-in for Google+ Hangouts.

MetaFlows Intros SaaS Security System

The solution combines local software with a cloud-based service.

Alleged Kelihos Botnet Creator Proclaims Innocence

Andrey Sabelnikov has posted a statement online saying he has no connection to Kelihos or spam.

New Malware Targets Windows Media Player Vulnerability

Researchers at Trend Micro have found malicious HTML designed to exploit the flaw.

Cyber Security Market to Exceed $61 Billion in 2012

Visiongain anticipates an increase in public-private partnerships across several cyber security sectors.

Sourcefire FireAMP Brings Big Data Analytics to Enterprise Security

Large data sets offer new ways to track malware across a network.

Symantec Tells Users to Disable pcAnywhere, Cites Threat from Anonymous

In the wake of a threat by Anonymous to expose Symantec source code, the company advises customers to stop using pcAnywhere -- but says its antivirus software products are not at risk.

Iranian Government Web Sites Hacked

Members of 'IDF Team' launched the attack in retaliation for an assault on Israeli sites on Wednesday.

Anonymous Hackers Target European Parliament

The site was taken down yesterday by a distributed denial of service attack.

Alleged EDF Hackers Arrested in France

The three men are accused of involvement in a cyber attack on the French energy firm.

University of Hawaii Settles Security Breach Lawsuit

As part of the agreement, the university will provide victims with two years of credit and fraud protection services.

McAfee Updates Mobile Security App

Version 2.0 adds control over app permissions, as well as call and text messaging filters.

Symantec Warns of Massive Android Malware Campaign

The malware was found in 13 different apps on the Android Market.

Hackers Take Down Israeli Web Sites

Targets included the Ha'aretz newspaper and the Sheba Medical Center.

New European Privacy Rules Introduced

Under the new rules, fines can be as much as two percent of a company's global annual turnover.

Opera 11.61 Patches Security Flaws

The update addresses a high severity XSS vulnerability, as well as a low severity issue.

Security Flaws Found in WordPress Setup

Because the flaws are in an installation script, WordPress claims there's very little risk of their being exploited.

Google Updates Privacy Policy

Users will not be able to opt out of the new policy.

O2 Acknowledges Security Lapse

For the past two weeks, the carrier provided its users' phone numbers to every Web site they visited.

Zappos Sued Over Security Breach

Texas resident Theresa Stevens has filed a class action lawsuit claiming the company failed to protect customers' personal information.

Joomla! Open Source CMS Gets Security Update

Version 2.5.0 fixes two medium priority XSS vulnerabilities and two low priority information disclosure flaws.

Free Malware Analysis Tool Released

The 'Malwr' tool is a front end for the Cuckoo malware analysis sandbox.

Anonymous Hackers Target Irish Government Sites

The government has confirmed that several servers came under attack last night.

Hackers Disrupt U.S. Rail Service

An unidentified railroad 'was slowed for a short while' in December of last year.

NY Public Service Commission Acknowledges Security Breach

Almost two million customers' personal information was exposed.

Polish Government Sites Hacked

The attacks were launched to protest Poland's plan to support the Anti-Counterfeiting Trade Agreement.

Sourcefire Intros FireAMP Anti-Malware Solution

The technology behind FireAMP came from Sourcefire's acquisition of Immunet in January of 2011.

Chrome 16 Gets Security Update

The update patches four 'high severity' vulnerabilities.

OnGuardOnline.gov Hacked

The hackers say they accessed passwords, bank account information and online dating details.

Twitter Buys Anti-Malware Company Dasient

The acquisition follows Twitter's purchase of Whisper Systems in November of last year.

Microsoft IDs Alleged Kelihos Botnet Creator

The company says Andrey Sabelnikov was running the botnet.

iPad 2, iPhone 4S Hacked

The dual-core A5 chip presented a particular challenge to the hackers.

Researchers Demo SCADA Security Flaws

The flaws range from privilege escalation bugs to denial of service vulnerabilities.

Pwn2Own 2012 Gets Serious About Security Vulnerabilities

The HP-sponsored hacking challenge revises its rules in an effort to expose even more vulnerabilities.

Researcher Links Gameover Malware to Zeus Trojan

Don Jackson says Gameover is a 'private version' of Zeus.

Researchers Hack Into Corporate Conference Rooms

The researchers were able to listen in on meetings and control a camera remotely to read information on documents.

DreamHost Hacked

The Web host says customers' billing and personal information were not exposed.

Anonymous Hackers Hit CBS.com, UniversalMusic.com

Following the attack, nothing remained of the official Web site for CBS except an index page with a single file.

Phishing Campaign Targets Seattle Government Employees

Hundreds of people with seattle.gov e-mail addresses recently received phishing e-mails.

OpenSSL Update Patches DoS Security Flaw

Versions 0.9.8t and 1.0.0g patch a vulnerability that was introduced with the release of a previous security update on January 6.

Grindr Hacked

A hacker has discovered a way to access members' profiles.

SafeNet Intros eToken 3500 for Online Banking Security

The device uses an optical sensor to read transaction details from the user's screen, then generate an electronic signature.

AnchorFree Adds Malware Protection to HotSpot Shield

A recent update to the VPN client added a malware site guard.

Anonymous Hackers Retaliate for Megaupload Takedown

The hackers took down Web sites belonging to the FBI, DoJ, MPAA and others.

Security Expert Warns of Online Banking Vulnerability

Yash K.S. has published a video demonstrating a man-in-the-browser attack capable of manipulating HSBC Bank transactions in real time.

UAE Central Bank Site Hacked

The bank's Web site was taken down by a group calling itself 'IDF Team.'

Hacker Leaks Thousands of Facebook Passwords

The hacker claims to have login info for more than 30 million users.

Imperva Warns of XSS Vulnerability in IE

Microsoft says the problem is not considered a vulnerability.

Koobface Botnet Goes Offline

The botnet's command and control server was taken offline, according to a Facebook official.

Romanian Hacker Sentenced for NASA Security Breach

Robert Butyka received a three-year suspended sentence, with a probation period of seven years.

Secunia Shortens Deadline for Vulnerability Disclosures

The research firm has reduced its deadline from one year to six months.

NYT IDs Five Koobface Botnet Suspects

All five are Russians living in St. Petersburg.

Information Security Masters Program Launched

The new program at City University London is intended to help security professionals bridge the gap between security and business.

Israeli Hackers Target Arab Stock Exchange Sites

The hackers say the attack was in retaliation for recent cyber attacks on Israel's Tel Aviv Stock Exchange, El Al Airlines and other sites.

Father, Son Charged with Fraud, Hacking, Identity Theft

Vladimir and Kirill Zdorovenin are accused of stealing hundreds of thousands of dollars through credit card theft and stock manipulation scams.

Oracle Patches 78 Security Flaws

The first Critical Patch Update of 2012 tackles a long list of issues, but only two patches apply to Oracle's namesake database.

New Trojan Variant Targets Facebook Users

A new version of the Carberp Trojan demands login information and $25 to unlock the victim's Facebook account.

F-Secure Sees Surge in New Mac Malware

The company found 58 new Mac threats between April and December of 2011.

Brazilian Hackers Offer to Teach Cybercrime Skills

Kaspersky Lab says courses are available in hacking, defacing, spamming and more.

Symantec Admits Its Own Network Was Hacked

The company had initially blamed a third party for the security breach.

National Security Agency Releases Security Enhanced Android

SE Android is designed to improve upon Android's application security model.

Hackers Steal $6.7 Million from South African Bank

Cybercriminals transferred money from other customers' accounts into their own in early January.

Security Flaw Found in McAfee SaaS Endpoint Protection

The problem was reported by McAfee customers, who found that their IP addresses were being blacklisted for sending spam.

City College of San Francisco Infested with Malware

At least seven viruses were recently detected that had been in place since 1999.

Fortinet Announces New Security Appliances

The company has also introduced several enhancements to the FortiWeb 4.0 MR3 operating system.

CoveritLive Hacked

The company says no financial information was compromised.

Tel Aviv Stock Exchange, El Al Hacked

The Web sites were shut down, but trading and flights were unaffected.

Zappos Security Breach Affects 24 Million

Names, e-mail addresses, phone numbers and password hashes were exposed.

TeaMp0isoN Hackers Hit T-Mobile

Staff and administrator names, e-mail addresses, phone numbers and passwords were leaked.

Netherlands Announces National Cyber Security Center

The center, based in The Hague, is intended to coordinate information and expertise between government agencies.

WEF: Cyber Attacks Lead Global Risks

The World Economic Forum says cyber attacks are among the most likely global risks to occur over the next decade.

Oracle to Patch 78 Security Flaws

Twenty-seven of the vulnerabilities are in the MySQL database.

Kaspersky Warns of New Facebook Chat Phishing Attack

The messages contain a link to an external phishing page that asks for the victim's name, e-mail, password and more.

Sykipot Malware Targets DoD Smart Cards

A new version of the malware is designed to steal smart card credentials from users at the U.S. Department of Defense and other organizations.

Malware Steals Data from Japanese Space Agency

Information about the space agency's unmanned H-2 Transfer Vehicle may have been compromised.

FTC, Upromise Settle Over Security Concerns

Customer data was transmitted unencrypted.

PHP Gets Security Update to Patch DoS Vulnerabilities

Version 5.3.9 patches two security flaws.

Vermont Department of Taxes Acknowledges Security Lapse

Social security numbers and federal ID numbers were posted online.

BlackBerry PlayBook Security Vulnerability Found

Intrepidus Group researchers recently discovered a way to listen in on the connection between the PlayBook and a BlackBerry smartphone.

STRATFOR Admits Credit Card Data Wasn't Encrypted

Company CEO George Friedman attributed the oversight to the company's rapid growth.

NYU, Banks to Establish Cyber Security Center

The plan is for banks to share information with the center, which will then analyze the data to look for suspicious activity.

Department of Energy to Examine Power Grid Cyber Security

The DOE recently unveiled the Electric Sector Cybersecurity Risk Management Maturity project.

Wireshark Updates Patch Several Security Flaws

Versions 1.4.11 and 1.6.5 of the open source network protocol analyzer were recently released.

Sophos Warns of FDIC Malware

The malware is being distributed in zip files attached to fake FDIC e-mails.

Spammers Target Mobile Users with QR Codes

According to Websense researchers, the method offers the 'ultimate URL obfuscator.'

Symantec Warns of New Android Trojan

Android.Qicsomos is a modified version of an open source solution designed to detect Carrier IQ on a mobile device.

Hackers Publish Logins for Israeli SCADA Systems

A list of addresses and logins for several systems was posted today on Pastebin.

Pro-Israel Hackers Target Saudi Arabian Web Sites

The hackers are threatening to publish thousand of Saudi shoppers' credit card numbers.

Restaurant Sues Bank, Processor Over Fines from Alleged Breach

Cisero's was forced to pay fines for a possible security breach that was never actually confirmed.

German Police Hack Was Retaliation for Father Spying on Daughter

A friend of the girl's discovered that her father had planted a Trojan on her computer.

Microsoft Patches SSL BEAST

In the first Patch Tuesday of 2012, Microsoft fixes an old issue and warns about a new security bypass risk.

Anonymous Hackers Target Finland for Blocking The Pirate Bay

The Web sites for two Finnish anti-piracy organizations were taken down by DDoS attacks.

U.S. Expels Venezuelan Diplomat for Planning Cyber Attacks

Livia Antonieta Acosta Noguera was given 72 hours to leave the country.

Microsoft Warns of Malware Disguised as Beta Version of PC Games

The malware poses as betas of Defense of the Ancients 2 and Diablo III.

ICS-CERT Warns of Security Flaws in Siemens FactoryLink

The company has released a security update to patch the vulnerabilities.

Kim Jong-il Video Distributes Malware

A link leads to a site that advises the user to install an add-on called ClickPotato.

Belgian Anonymous Hackers Target Steel Producer

Members of Anonymous Belgium leaked information on ArcelorMittal.com's users and administrators.

Researchers Warn of Smart Meter Security Flaws

Dario Carluccio and Stephan Brinkhaus were able to change a meter's consumption information to -106610 kWh.

FBI Warns of Gameover Malware

The new Zeus variant steals the victim's banking information, then launches a DDoS attack.

Protecting Against SQL Injection Attacks with Oracle Database Firewall

New release gains support for MySQL, helps shield enterprise databases from attack.

Israel Says Cyber Attacks Are Terrorism

The country's deputy foreign minister said cyber attacks are 'a breach of sovereignty comparable to a terrorist operation.'

Pastebin Hit by Second Cyber Attack

The site had already been taken down by another DDoS attack earlier this week.

Singapore University Acknowledges Security Breach

Members of the hacker group Team Intra accessed staff user names, domain information, and hashed passwords.

Microsoft to Fix Eight Vulnerabilities on Patch Tuesday

The updates will patch flaws in Windows and in the company's developer tools software.

OpenSSL Updates Patch Six Security Vulnerabilities

Versions 0.9.8s and 1.0.0f were recently released.

Hackers Steal Symantec Source Code

The company says the compromised code was more than four years old.

Amazon's Silk Browser Hacked

Hacker TyHi successfully deployed the Kindle Fire's Silk browser on a different Android device.

Lilupophilupop Attack Infects Over a Million URLs

The SQL injection attack was first identified and disclosed in early December.

Apache Struts Gets Security Update

Version 2.3.1.1 of the open source web application framework was recently released.

IBM Warns of Security Flaws in Rational Rhapsody

The company says 'multiple high risk security vulnerabilities' could allow an attacker to execute arbitrary code.

Malware Infection Gets Convicted Murderer New Trial

Randy Chaviano got a retrial after a virus deleted transcripts from the court stenographer's computer.

New Version of Ramnit Worm Targets Facebook Users

The malware has already stolen more than 45,000 users' login credentials.

EFF Warns of New AIM Privacy Issues

The latest version of the chat client logs all user conversations by default.

California Hospital Acknowledges Security Breach

More than a thousand patients' private medical records were accessed.

Kaspersky Warns of Scareware for Smartphone Users

Malware creators have begun poisoning Google search results for popular mobile applications.

Security Flaw Patched in WordPress 3.3.1

The new release fixes a cross-site scripting vulnerability.

Tech Consultant Warns of iPhone Photo Security Flaw

Ade Barkah discovered that an incorrect time setting can enable photos to be viewed on a locked device.

Anonymous Hackers Target German Neo-Nazis

Nazi-Leaks.net lists the names and addresses of thousands of supporters of far-right groups.

Pastebin Taken Down by Cyber Attack

The denial of service attack was confirmed via Pastebin's official Twitter account.

Saudi Hackers Breach Israeli Sports Site, Publish User Data

According to a member of Group-X, the data accessed included names, addresses, phone numbers, Social Security numbers, and credit card details.

Kaspersky: India Leads in Spam

Almost 15 percent of all spam in the third quarter of 2011 was sent from India.

Apple's iOS 5.0.1 Jailbroken

The Corona jailbreak tool was developed by researcher pod2g.

Former UK Prime Minister Targeted by Hackers

Gordon Brown may have been targeted when he was Chancellor of the Exchequer.

AntiSec Hackers Target California Law Enforcement Association

Staff e-mails and customer billing information were posted online.

Exploit of Wi-Fi Protected Setup Flaw Poses Risks for Consumers, Not Enterprises

Many home Wi-Fi networks are at risk thanks to an exploit released over the holidays, but enterprise organizations are generally unaffected by the vulnerability.

Fujitsu Developing Malware for Japanese Government

The virus has already been tested in a closed network environment.

F-Secure Warns of Android Trojan Disguised as Greeting Card App

The malware sends the phone model and number, Android version, and IMEI number to a remote server.

Paladion Networks Plans Cybercrime Center in Oman

The center will focus on monitoring and responding to cybercrime in the country.

Amazon Shipment Spam Campaign Delivers Malware

If the recipient clicks on a link in the message, they're taken to a Web site serving Windows malware.

Care2 Acknowledges Security Breach

The site's approximately 18 million users were recently notified that their passwords were being reset.

Hackers Plan Satellite System to Sidestep Censorship

The 'Hackerspace Global Grid' will include satellites in orbit, along with ground stations to track and communicate with them.

Telstra Suffers New Privacy Breach

Customer data, including contact information and dates of birth, was posted to Editgrid.com.