Click here

Security News: Archive: April 2012 

Columbia University Acknowledges Security Breach

Names, addresses, Social Security numbers and bank account numbers were published online.

Skype Privacy Flaw Found

A simple process can reveal any Skype user's remote and local IP addresses.

Cryptic Studios Hacked

The breach occurred in December 2010, but was only recently uncovered by the company.

Symantec: More Malware on Religious Sites Than Porn Sites

Pornographic Web sites are less likely to be infected than religious, automotive or health sites, according to the company.

International Police Association Hacked

The hackers defaced the site's main page with a statement alleging that admin passwords were stored in plain text.

Microsoft Security Essentials Updated to Version 4.0

The company says the new version improves both scanning performance and malware detection rates.

Despite Veto Threat, CISPA Clears House

The House of Representatives passes the controversial cybersecurity legislation, but opponents vow to stop it in the name of online privacy.

Almost All SSL Web Sites Are Insecure, Say Researchers

Only 19,024 of 200,000 sites studied are 'genuinely secure,' according to the research results.

Backdoor Found in RuggedCom Industrial Control Systems

The Rugged Operating System (ROS) comes with a static username and an easily identifiable password.

Microsoft Patches Critical Security Flaw in Hotmail

Hackers have been offering to exploit the bug for as little as $20 per account.

Two Plus Two Poker Forum Acknowledges Security Breach

The forum was shut down after a hacker demonstrated the ability to access e-mail addresses and passwords.

LinkedIn Blog Hacked by Syrian Electronic Army

The hackers redirected visitors to a page supportive of the country's president.

Kaspersky: Apple Security Is '10 Years Behind Microsoft'

Eugene Kaspersky says Apple has a lot of catching up to do.

LulzSec Hacker Publishes VMware Source Code

The code for VMware ESX dates from the 2003 to 2004 timeframe, according to the company.

Study: 1 in 10 Used Hard Drives Contains Recoverable Data

In response to the findings, the ICO has published guidelines to help people delete all data from used hard drives.

Researcher Warns of Vulnerabilities in Samsung Devices

Luigi Auriemma says he came across the issue by accident while trying to play a practical joke on his brother.

Context Warns of Significant Cloud Security Flaws

A vulnerability could give attackers access to other users' data.

HITRUST Launches Security Response Center for Healthcare Industry

The center is aimed at helping the industry identify and remediate cyber attacks and threats.

Facebook Partners with Five Security Firms

Six-month trials of five different security solutions are available in the company's Anti-Virus Marketplace.

1 in 5 Macs Infected with Windows Malware

According to Sophos, 20 percent of Macs are infected with Windows malware, while 2.7 percent are infected with Mac malware.

Cybercrime Does Pay: Russian Hackers Made $4.5 Billion Last Year

Russian-speaking cybercriminals doubled their annual income from 2010 to 2011, according to Group-IB.

IBM Gets Behind Snort, Expands Anomaly Detection

Big Blue embraces the open-source IPS signature system.

Intego Warns of New Flashback Malware Variant

The new version, Flashback.S, doesn't request an administrative password prior to installation.

London Marathon Suffers Massive Security Breach

All entrants' home and e-mail addresses were published online. 

Lookout, Deutsche Telekom Partner on Mobile Device Security

The companies will work together on research and development, and will make Lookout's security app available to Deutsche Telekom's customers.

Google Announces Huge Increase in Vulnerability Rewards

The maximum bounty has been increased to $20,000.00.

Nissan Hacked

The company says user IDs and hashed passwords were stolen.

WordPress 3.3.2 Patches Security Flaws

Vulnerabilities were patched both in the platform itself and in three external libraries.

Penn State, IBM Researchers Develop TapLogger Android Trojan

The proof-of-concept malware uses the device's motion sensors to steal passwords and other user data.

Sophos: India Leads the World in Spam

The country was responsible for 9.3 percent of all spam between January and March of this year.

Anonymous Hackers Dominate IT Security Pros' Fears

Sixty-one percent of survey respondents expect to be attacked by Anonymous within the next six months.

Malware Attack Targets Iran's Oil Industry

The Iranian government has acknowledged that some data was stolen.

FBI Investigates CSU Student for Election Fraud, Identity Theft

Matt Weaver is accused of stealing approximately 700 students' user IDs and passwords in order to affect the results of an election for student body president.

Abortion Provider Hit by 2,500 Cyber Attacks Following Hacker's Arrest

Almost half of the attacks came from North America, according to BBC News.

Researchers Develop Personal Firewall Solution for Pacemakers, Insulin Pumps

The MedMon device is intended to protect wireless medical devices from cyber attacks.

Anonymous Hackers Target Formula One Over Bahrain Race

The action was taken to protest ongoing human rights abuses in the country.

South Carolina Man Arrested for Medicaid Data Theft

Christopher Lykes is accused of stealing 228,435 people's personal data, including names, phone numbers, dates of birth and Medicaid account numbers.

Rogue Anti-Virus Software Being Spread via Twitter

According to Kaspersky researchers, hundreds of compromised accounts are currently spamming as many as eight messages per second.

Google Issues Malware Infection Warnings to 20,000 Web Sites

The sites appeared to be redirecting visitors to malicious Web sites.

Emory Healthcare Acknowledges Massive Data Breach

Ten misplaced backup discs contained personal data on approximately 315,000 patients.

Anonymous Hackers Launch Pastebin Alternative

The AnonPaste service is based on the open source ZeroBin software.

Russian Charged with Hacking Brokerage Firms, Stealing Identities

Petr Murmylyuk is accused of causing $1 million in losses to brokerage firms, and stealing the identities of more than 300 people.

Symantec Reports Gradual Decline in Flashback Infections

The security firm says the number of infected computers is now down to 140,000.

Trusteer Warns of Malware Targeting Hotel POS Systems

The Trojan is being sold on underground forums for $280.

Researchers Warn of Malware in Fake Instagram App for Android

The malicious apps are being offered on Web sites that mimic the official Instagram site.

China, U.S. Conducting Cyber War Games

The first exercises were held in Beijing last June, and in Washington last December.

Teen Hacks 259 Web Sites in 3 Months

The 15-year-old was caught when his anonymizing software failed.

Trend Micro Names BlackBerry 7 Most Enterprise-Ready Mobile OS

The operating system scored well for its security, authentication, device wipe functionality, firewall and virtualization.

Texas A&M University Acknowledges Data Breach

Personal information on almost 4,000 former students was mistakenly attached to an e-mail.

FBI Used Metadata to Catch CabinCr3w Hacker

Higino O. Ochoa III posted a photo without purging the metadata -- which included the GPS location where the pic was taken.

New Windows Ransomware Found

The new variant stops the operating system from loading until a ransom is paid.

Accused Utah Police Hacker Pleads Not Guilty

John Anthony Borell III faces up to 10 years in prison and a fine of $250,000.

Mozilla Enhances Plug-in Control in Firefox

Software engineer Jared Wein says the aim is to improve security, reduce memory usage, and open up the Web.

Survey Finds Steady Increase in Healthcare Data Breaches

A recent study found that 27 percent of respondents reported at least one security breach in the past 12 months.

Android Trojan found on Google Play

McAfee says the malware has already been downloaded by at least 70,000 users.

New Sabpab Mac Malware Found

The Trojan doesn't require any user interaction to infect a victim's machine.

Anti-Abortion Hacker Gets 32 Months in Jail

James Jeffery accessed the names, e-mail addresses and phone numbers of approximately 10,000 women.

Report: Stuxnet Malware Was Planted by Iranian Double Agent

Intelligence sources say the virus was planted at the Natanz nuclear facility using a memory stick.

Accused TeaMp0isoN Hackers Arrested Over Scotland Yard Attack

The two teenagers were arrested by members of the UK's Police Central e-Crime Unit.

Study Warns of Security Flaws in Open Source Components

More than 80 percent of enterprise software applications built in-house use open source components that may contain vulnerabilities.

Boeing Plans High-Security Android Smartphone

The company says it's nearing the end of the development cycle and plans to launch the phone in late 2012.

Apple Releases Flashback Malware Removal Tool

The latest Mac OS X Lion update also disables the automatic execution of Java applets.

Apple Enhances Account Security

Some users are being required to select and answer three security questions before purchasing apps.

Samba Update Patches Security Flaw

The updates patch a vulnerability that could be exploited to execute arbitrary code.

Android Malware Poses as Angry Birds Space App

The Trojan connects to a remote Web site to download and install additional malware on the victim's device.

HP Warns of ProCurve Switches with Malware-Laden Flash Cards

The company says  HP 5400 zl series switches purchased after April 30, 2011 may be affected.

Adobe Releases Security Updates for Reader, Acrobat

The updates patch four vulnerabilities that could lead to arbitrary code execution.

Surge in DDoS Attacks on Financial Services Firms

Prolexic says it mitigated more attack traffic in the first quarter of 2012 than it did in all of 2011.

Android Apps Can Access Key Data Regardless of Permissions

Researcher Paul Brodeur created a proof of concept app that was able to access system information, along with data on the device's SD card.

Apple to Release Flashback Malware Detection, Removal Tool

The company hasn't yet said when it expects the tool to be made available.

Smart Meter Hacks Cost a Single Utility $400 Million a Year

Brian Krebs reports that hackers are charging between $300 and $3,000 to modify a meter.

New Zeus Malware Variant Targets Ceridian Payroll Services

The malware is designed to steal Ceridian users' IDs, passwords, company numbers and image-based authentication icons.

Utah Medicaid Breach Affected 780,000 People

The state's Department of Technology Services says it will send letters to every person affected.

Anonymous Hackers Hit USTelecom, TechAmerica

The attacks were launched in protest of the organizations' support for CISPA.

Microsoft Fixes Critical Vulnerability in Windows Common Controls

April's Patch Tuesday update delivers six bulletins -- including a critical fix for a core flaw that affects a long list of Microsoft applications.

How to Check Your Mac for Flashback Infection

Two free tools are now available that make it easy to check for infection.

Anonymous Hackers Target Tunisian Government

The group says the attack was launched in support of human rights and freedom of expression in Tunisia.

Etsy Announces $50,000 in Grants for Female Hackers

The aim is to bring 20 women into Hacker School's 2012 summer session.

Anonymous Hackers Take Down UK Government Sites

The group is threatening to launch similar attacks every Saturday.

Google Patches Chrome 18 for Flash Flaws

Latest browser update includes a Flash fix that no other platform will receive.

Accused LulzSec Hacker Pleads Guilty

Cody Kretsinger faces up to 15 years in prison.

Sophos Partner Portal Hit by Cyber Attack

Names, e-mail addresses, business addresses, contact information and hashed passwords may have been accessed.

Hacker Claims Breach of Chinese Military Contractor

'Hardcore Charlie' has published data on Pastebin and Photobucket.

New TigerBot Android Malware Found

The malware can record phone calls, change network settings, upload the current GPS location, reboot the phone, and more.

Security Flaw Found in Facebook Mobile Apps

The vulnerability was discovered by UK app developer Gareth Wright.

Al Qaeda Sites Taken Down by Cyber Attack

Five key online forums were taken down two weeks ago by an apparent DDoS attack.

Hackers Steal Thousands of Medicaid Records

Names, addresses and Social Security numbers may have been accessed.

Over Half a Million Macs Infected by Flashback Trojan

The majority of the infected computers are located in the U.S. and Canada, according to Doctor Web.

Lookout Warns of New Android Malware Variant

The new version of the LeNa malware doesn't require any user interaction to gain root access.

Comodo Launches Free Malware Scanning Service

The free service includes daily recurring scans of any three pages of a domain.

Arrested CabinCr3w Hacker Posts Statement on Pastebin

Hacker Higinio Ochoa says eight FBI agents stormed his apartment on March 20.

Apple Patches OS X Java Security Flaws

A recent update patched 12 vulnerabilities, including one that was being actively exploited.

European Union Publishes Cloud Security Guide

The guide is aimed at improving the public sector's understanding of cloud security.

New Version of Ice IX Malware Targets Facebook Users

The new configuration tries to trick victims into disclosing their credit card information.

Adobe Intros Open Source Malware Classifier

The Adobe Malware Classifier is available for download from SourceForge.

US Airways Spam Distributes Malware

The e-mails are disguised as airline check-in notifications.

NQ Mobile Warns of New Android Malware Variant

The company has already found more than 100 files infected by DKFBootKit.

UK Hacker Jailed for Identity Theft

Edward Pearson has been sentenced to 26 months in jail.

Hacker Ryan Cleary Back in Jail

Cleary violated his bail conditions by contacting FBI informant Sabu online.

Pastebin Seeks to Block Hackers

The site currently gets more than 1,200 abuse reports a day.

Anonymous Hackers Deface 400 Chinese Web Sites

The sites were defaced with a warning to the government and messages of encouragement to the Chinese people.

TweetDeck Security Flaw Found

Twitter says the vulnerability was not exploited maliciously.

Global Payments: Breach Contained, But Damage Done

Visa drops credit card processor Global Payments Inc. from registry of secure providers as details emerge about theft of 1.5 million card records.

PBS Hacked

User names and password hashes were published online.

Christian Liberty Financial E-mails Deliver Malware

An attached ZIP file infects the recipient's PC with malware identified as Mal/BredoZp-B.