Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 25 October 2010

Avalanche spam gang tap the power of ZeuS to boost cybercrime earnings

Posted on 12:30 by Unknown

London, 25th October 2010 - Reports that the world's most prolific phishing gang have diversified their operations over from conventional phishing emails to distributing the ZeuS Trojan is another sign that hackers are becoming incredibly sophisticated, says Imperva, the data security specialist.

More than anything, the attack vectors used by the Avalanche botnet gang, who have taken two years to migrate to the new fraud architecture, indicate that criminal hackers are now using lateral thinking to develop their fraudulent modus operandi, says Amichai Shulman, Imperva's chief technology officer.

"What is apparent from our research is that the Avalanche cybercrime gang - who were reportedly responsible for two-thirds of the world's phishing attacks this time last year - are also using advanced programming techniques" he said.

The Imperva CTO continues, “The problem is that the banks, nor the users, are realizing that the client browser is actually under the control of the hacker. So although a user is in fact authenticated to the bank, all transactions are actually being performed from that moment on by the Trojan.”

Imperva's research teams, he went on to say, concluded that using a man-in-the-browser attack, similarly to those uncovered in September, enables the electronic criminals to  stage automated withdrawals. The problem of detecting this type of fraud is made all the more difficult as the banks are not aware that the initiator of the transaction is not the actual owner of the account but basically, an automated process," he said.

"This is why some financial institutions, such as Sainsbury's Bank (http://bit.ly/9Xxy9i), now require users to confirm by mobile phone text message when a new account payee is set up," he added.

"Until the banks are able to prevent against this type of complex malware-driven fraud, the cybercriminal gangs will continue to evolve their already sophisticated strategies to beat the banks - and their customers”

For more on the latest hacker e-banking fraud methodologies: http://bit.ly/9uCXWo

For more on Imperva: www.imperva.com

Imperva is the global leader in data security. With more than 1,200 direct customers and 25,000 cloud customers, Imperva’s customers include leading enterprises, government organizations, and managed service providers who rely on Imperva to prevent sensitive data theft from hackers and insiders. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring for databases, applications and file systems.  For more information, visit www.imperva.com, follow us on Twitter or visit our blog.

Source: Eskenzi PR Ltd

This press release is presented without editing for your information only.

Read More
Posted in | No comments

Trusteer Finds Massive Internet Security Hole Remains Unpatched by Users

Posted on 12:28 by Unknown

Two Thirds of Web Users are Still Vulnerable to Attacks that Exploit Flaw in Java

NEW YORK, Oct. 25, 2010 – Trusteer, the leading provider of secure browsing services, today announced that more than a week after Oracle released a critical patch for Java, more than 68% percent of Internet users are still vulnerable to attacks that exploit these vulnerabilities.  This may be the biggest security hole on the Internet today, since 73 percent of Internet users are using Java.  The Trusteer Secure Browsing Service has already warned 14 million users to immediately apply the Java patch and in the mean time protects them against financial malware such as Zeus, that exploit the vulnerabilities in unpatched versions of Java.

According to Oracle due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible. This Critical Patch Update contains 29 new security fixes across Java SE and Java for Business products. http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html

One week after it was released by Oracle, only 7 per cent of Java users have installed the latest update.  This is worrying because the majority of Java users on the Internet are vulnerable to a large and growing number of Java exploits in the wild.  According to Microsoft, the vulnerabilities covered by the critical patch provide ‘...an unprecedented wave of Java exploitation...’  Trusteer believes it is the single most exploitable vulnerability on the web today.  http://blogs.technet.com/b/mmpc/archive/2010/10/18/have-you-checked-the-java.aspx

“From a security threat standpoint Java is very much like Flash in that it is a ubiquitous technology installed on virtually every computer in the world, which makes an ultimate platform for distributing malware,” said Mickey Boodaei, Trusteer's CEO. “Using vulnerabilities in these applications is extremely efficient since it enables criminals to target more than two thirds of Internet users. Oracle is facing some major security challenges and one of its biggest hurdles is its software update mechanism. For some reason, it is not effective enough in distributing security patches to the field. Adobe experienced the very same problem last year and since then Flash has been the subject of multiple attacks. To date Adobe hasn't managed to overcome the problem although they are trying and have plans to introduce more security features in their future releases.”

“The spike in Java exploits shows every sign of continuing. Just 120 hours after a Google researcher published details of an unpatched Java exploit late last week, hackers had reportedly already started exploiting the vulnerability.  The fact that the time between an exploit being discovered and then being used by hackers in the real world is shortening is of great concern. And with so few users updating their systems, this means that a majority of users' computers are wide open to this new type of attack vector,” he explained. 

According to Trusteer, the Java exploit posted to the Full Disclosure mailing list late last week appears to have been picked up by Russian hackers, who are currently exploiting an iFrame-compromised song lyrics site, which re-routes Internet users to a Russia-based malware server.  This multi-level attack vector will have taken time to organise, which leads Trusteer to believe that hackers are now monitoring bug disclosure lists on a regular basis, and then mobilising their resources very quickly to create new zero day exploits.

Recommendations from Trusteer

For enterprises: identify all browser add-ons and browser technologies, not just Flash and Java. Make sure to block unnecessary services and quickly update vulnerable add-ons and browsers. Use browser security technologies that can minimize and control the threat within the organization.  Patch browsers and browser add-ons as soon as fixes are available.

For end-users: don't disregard vendor software update messages. If a software program is not needed, it should be removed. Otherwise it should be kept up-to-date. Use browser security technologies which can minimize, block, and alert on new threats.

Trusteer, the world’s leading provider of secure browsing services, helps secure computers against Man in the Middle, Man in the Browser, and Phishing attacks. Trusteer is currently used by more than 70 leading financial organizations and enterprises in North America and Europe, and by more than 14 million end users to protect their online banking, shopping and other communication against sophisticated malware attacks and fraud. HSBC, Santander, The Royal Bank of Scotland, SunTrust, Fifth Third, ING DIRECT, and Bank of Montreal are just a few of the banks using Trusteer’s technology. Trusteer's service for enterprises prevents malware from accessing enterprise network resources and sensitive information through SSL - VPN connections and unmanaged devices. Trusteer is a privately held corporation led by former executives from RSA Security, Imperva, and Juniper. Follow us on www.Twitter.com/Trusteer. For more information about our products and services, please visit www.trusteer.com

Source: Eskenzi PR Ltd.

This press release is presented without editing for your information only.

Read More
Posted in | No comments

Sunday, 24 October 2010

Vacation 2.0 – Danger of burglary due to vacation notifications given on Social Networks

Posted on 08:05 by Unknown

by Michael Smith (Veshengro)

There is a serious danger of experiencing a burglary in one's home and/or office if, like so many, one announces that one is going on vacation on social networks.

Time and again on an almost daily basis, even amongst the people that I am in contact with, someone will post a notification that he or she is going to be away for a couple of days or weeks because of vacationing or trip to here or there, etc.

This is a virtual and real invitation to any criminal to scoot over and have a look at your place with the view of liberating a few of your possessions.

This is especially dangerous if you use Facebook's location service or it you happen to be careless with your personal information on Facebook or elsewhere in your profile. Neither your address nor other sensitive info belong there.

If you want to, at some stage, share this with someone you have come to know as trustworthy then that is a different story. On the general profile such information has nothing to do.

Also, unless you know that no one knows your direct location do not tweet or blog (on Facebook or elsewhere) as to your location of anything of that nature, e.g. being away on vacation in Timbuktu or even just in Blackpool.

Facebook plugins such as the “My Location” or whatever it may be called also does not belong onto your cell phone or laptop. While it may be nice to let everyone of your friends know how things are where you are there is a much better and safer way; it is called email.

Vacation updates on social networks are also a very bad ideas, as indicated, and should be an absolute no, no, and that even if you have not disclosed your location, your address, etc., in any of your profiles. Chances are that some criminal reading the entries might just know where you live and bingo. A nice opportunity burglary. Not something you would want.

If, as I have said already, you wish to share holiday information with friends and family do not do that via Facebook or Twitter or LinkedIn or MySpace or what-have-you.

Use email or instant messenger. You never know who is reading your blog entries and that includes material on platforms such as Blogger, etc. Blog about your vacation, you trip to wherever, or whatever, when you are back home safely.. Much better, in my opinion.

Let's remember that it is a jungle out there and the animals in this jungle do not play fair and by the rules.

© 2010

Read More
Posted in | No comments

Saturday, 23 October 2010

AVG Link Scanner seen as Spam

Posted on 00:20 by Unknown

AVG Link Scanner seen as Spam by Facebook

by Michael Smith (Veshengro)

The part of the AVG Link Scanner that check links going into Facebook and puts a message there stating that the link has been checked and thus safe, is seen, suddenly, by Facebook as Spam.

Messages with links or links attempted to be sent to Facebook with the link scanner active will not be allowed. Unless Link Scanner's part for Facebook and MySpace is deactivated posts with any links are impossible to be posted to Facebook.

That, at least, was the state of play on Friday, October 22, 2010.

Therefore I advise users experiencing this problem to go into the Link Scanner part of AVG and remove the tick from the box that says “Add 'Secured by Link Scanner' to any sent Facebook...”

You will have to click on the link that says “Tools and advanced settings...” to get to that area where you can disable that function. Do not uncheck any of the other boxes on that page. Only the 'Secured by Link Scanner' box needs unchecking.

I hope that this helps those that may be experiencing problems. It worked for me.

© 2010

Read More
Posted in AVG Link Scanner, Facebook, spam | No comments

Wednesday, 20 October 2010

Infosecurity Europe says industry ready to meet cyber-attacks challenge identified in Spending Review

Posted on 05:25 by Unknown

Infosecurity Europe says IT industry is ready to meet the challenge of terrorism and cyber-attacks identified as major threat to UK PLC

Responding to the government's newly-unveiled security strategy, the organisers of the InfoSecurity Europe event, held each spring in the UK, says that the UK's IT industry is ready to take on the challenges that the new decade of cybercrime will create. Infosecurity Europe's will be held at Earls Court, London 19-21 April 2011 www.infosec.co.uk

Claire Sellick, Infosecurity Europe's Event Director, said that the current - and ongoing - convergence of technologies in the IT sector means that business life can be made significantly easier, with information available on a 24-7 basis, even when out and about, using a mobile Internet-enabled device.

"Even without access to a laptop and mobile broadband dongle, business professionals can still hold a lot of computing power in the palm of their hand, in the shape of a smartphone. But just as these mobile Internet-enabled devices are threatened by cyber-crminals, our research suggests that, with the right technology in place, the Internet users of UK PLC are more than ready for the security threats that hackers and criminals throw at them," she said.

"The government has committed half a billion pounds to help defend the UK national infrastructure which, when viewed against a backdrop of budget cuts elsewhere in Whitehall, is a very positive move, for which the cross-party review team are to be applauded," she added.

According to Sellick, the conclusions of the cross-party Strategic Defence Review lays the foundations for a new period of UK defences, with the battle lines of the future being drawn in both the traditional physical landscape, as well as the equally important cyber landscape.

We are seeing, she said, a growing number of terrorists that eschew their traditional tools for the electronic weaponry that the Internet now offers them.

The UK IT security industry, she explained, has been supplying its clients with the latest computer defences for several years, creating an electronic ring of steel around business IT systems that few people truly understand, and even fewer can attack effectively.

"The rapid pace of electronic hackery and espionage, however, is such that crackers will develop new attacks and methodologies that can be employed for fraudulent, and well as terrorist means," she said.

"We're confident that, with the latest technology at their fingertips, today's British businesses can better defend themselves against the coming wave of security threats," she added.

For more on the government's national security strategy: http://bit.ly/aByYrL

Infosecurity Europe, celebrating 16 years at the heart of the industry in 2011, is Europe’s number one Information Security event. Featuring over 300 exhibitors, the most diverse range of new products and services, an unrivalled education programme and visitors from every segment of the industry, it is the most important date in the calendar for Information Security professionals across Europe. Organised by Reed Exhibitions, the world’s largest tradeshow organiser, Infosecurity Europe is one of five Infosecurity events around the world with events also running in Belgium, Netherlands and Russia. Infosecurity Europe runs from the 19th – 21st April 2011, in Earls Court, London. For further information please visit www.infosec.co.uk

For more on the Infosecurity Europe show: www.infosec.co.uk

Read More
Posted in | No comments

Idappcom welcomes government's revitalised cybersecurity strategy; calls for greater private/public co-operation

Posted on 02:45 by Unknown

London, October 2010 - Responding to the UK defence review, which builds on the government's new security strategy, which was announced yesterday, Idappcom, the data traffic analysis and security specialist, says it welcomes the pragmatic approach the coalition government is taking on all aspects of security.

According to Ray Bryant, Idappcom's CEO, it is reassuring to hear that the government now classes a hostile Internet attack on the UK's IT infrastructure in the same `tier 1' security category as an act of international terrorism.

"For too long, governments have focused on physical disasters - and potential disasters - such as a major accident or a natural hazard such as serious flu outbreak, in their assessment of serious threats against the integrity of the UK," he said.

"It's therefore reassuring that, with Monday's security strategy announcement, and today's defence review, the government is demonstrating that it truly understands the importance of cybersecurity defences, as well as joined-up thinking on how this integrates with our national security," he added.

Idappcom's CEO went on to say that the defence cutbacks, whilst painful in some areas, will free up funding to allow the armed forces to lay the foundations of an effective UK cybersecurity defence strategy.

As private industry - especially in the IT industry - has demonstrated over the last few years, it is perfectly possible to meet the needs of implementing a good IT security strategy whilst at the same time cutting costs to meet budgetary constraints, he explained.

"And it's against this backdrop that we would encourage small companies to form partnerships with the government when it comes to developing an effective cybersecurity strategy, as the lessons being learned in the private sector can also be applied to the public sector," he said.

"It is to be hoped that the private sector can work with the public sector in better defending UK PLC's digital assets against all forms of cyberterrorism and - along the way - helping each other in achieving the budget savings that are clearly required," he added.

"Our observations are that, in order to weather the current economic storm, small companies need to form partnerships with the government, including the Ministry of Defence, as there is so much that both sides of the public/private sector divide can learn from each other."

For more on the UK's cybersecurity strategy: http://bbc.in/9ilqH8

For more on idappcom: www.idappcom.com

Read More
Posted in | No comments

Trusteer Secure Browsing Service for Enterprises Protects Against Man in the Browser Attacks

Posted on 02:43 by Unknown

New Offering Secures Sensitive Enterprise Applications Accessed from Remote and Unmanaged Computers

NEW YORK, Oct. 19, 2010 – Trusteer, the leading provider of secure browsing services, today announced the Trusteer Secure Browsing Service for Enterprises which protects enterprises against Man in the Browser attacks launched from malware controlled computers used by mobile employees, tele-workers and contractors. The Trusteer Secure Browsing Service creates a virtual firewall within the browser that blocks malware from entering or using the browser during a connection to enterprise applications. It is based on technology currently deployed by more than 70 financial institutions around the globe and more than 13 million online banking customers.  

Cyber criminals are targeting enterprises to steal intellectual property, log-in credentials, financial data and other sensitive information that resides inside corporate networks or in web applications. Targeted attacks, like the recent LinkedIn email phishing campaign, and search engine optimization techniques are being used to install sophisticated malware such as Zeus, Bugat, and Clampi on unmanaged computers that operate outside corporate networks. These malware programs conceal themselves inside the browser and are virtually invisible to anti-virus solutions. When infected unmanaged computers access enterprise resources via VPN connections and web portals the malware is able to elude perimeter security mechanisms like networks access control (NAC) systems to capture sensitive information and transmit it back to the criminals.

A Secure Browser Tunnel into the Enterprise

To protect browser-based access to enterprise IT resources located behind the firewall or in the cloud, Trusteer’s lightweight software based service creates a virtual firewall inside the user’s computer that prevents malware from entering or using the browser during a connection with enterprise applications. The Trusteer Secure Browsing Service for Enterprises blocks Man in the Browser attacks and locks down all communication with the enterprise, including VPN and cloud service connections, to protect against eavesdropping and tampering. The service is also capable of detecting, reporting on, and removing elusive Trojans such as Zeus, Bugat, Clampi and Gozi, before a machine can connect to enterprise applications. The service is supported by Trusteer’s 24x7 malware investigation service.

For ease-of-use, the Trusteer Secure Browsing Service for Enterprises remains transparent and is automatically activated without user intervention when a machine connects to enterprise applications. A management console enables IT departments to centrally set and enforce security policies on target machines including unmanaged devices belonging to employees, contractors, and partners, as well as computers with a high-risk profile. 

“The browser has emerged as the weakest link in the enterprise security infrastructure and is being exploited by malware authors and criminals to steal login credentials and plant Trojans in order to break into IT systems undetected,” said Mickey Boodaei, CEO of Trusteer.  “Meanwhile, the growing demand for mobility is challenging IT security’s ability to secure the network from breaches that originate on compromised trusted devices. The Trusteer Secure Browsing Service for Enterprises is a proven solution that reduces the risk of Man in the Browser attacks and can be easily deployed without any impact on users.”

Pricing and Availability

The Trusteer Secure Browser Service for Enterprises is available immediately from Trusteer. Pricing starts at US $25 per user.

About Trusteer

            Trusteer, the world’s leading provider of secure browsing services, helps secure computers against Man in the Middle, Man in the Browser, and Phishing attacks. Trusteer’s Secure Browsing Service has been available since 2008 and is currently used by more than 70 leading financial organizations in North America and Europe and by more than 13 million of their customers to protect their online banking communication against sophisticated malware attacks and fraud. HSBC, Santander, The Royal Bank of Scotland, SunTrust, Fifth Third, ING DIRECT, and Bank of Montreal are just a few of the banks using Trusteer’s technology. Trusteer is a privately held corporation led by former executives from RSA Security, Imperva, and Juniper. Follow us on www.Twitter.com/Trusteer. For more information about our products and services, please visit www.trusteer.com.

Spource: Eskenzi PR Ltd.

Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin unveils new functionality & updated PCI DSS 2.0 compliance reporting
    TUFIN TECHNOLOGIES UNVEILS enhanced firewall operations management functionality and UPDATEd pci dss 2.0 compliance reporting New Perm...
  • Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event
    Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this co...
  • Safer Internet Day - The role of Security within Social Networks
    Amichai Shulman – CTO and co-founder of Imperva Last week researchers unveiled a “ dating database ” consisting of 250,000 users. This was...
  • ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking
    ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking 20-23 March 2011, Manchester, UK Rolling Meadows, IL,...
  • Experts warn about risks of multi-tasking on new iPhone 4.0 OS
    Fortify Software warns companies to beware multi-tasking aspects of new iPhone 4.0 operating system Following a rash of news reports about...
  • Experts says trashed hard drive fiasco at Pfizer could have been avoided with Encryption
    Credant says trashed hard drive at Pfizer would not have happened if data had been encrypted Credant Technologies says that a security gaffe...
  • IT services provider, FORT, brings AVG to Irish market
    by Michael Smith (Veshengro) ISP customers to benefit from complete Internet security solution London, UK – AVG, the world’s most downloaded...
  • Lieberman Software and Q1 Labs Partner to stop insider threats
    Joins Q1 Labs Security Intelligence Partner Program London – February 1, 2011 Organisations seeking to eliminate the potential for anony...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ▼  2012 (1)
    • ▼  January (1)
      • Cool Stand – Product Review
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile