Friday, August 18, 2006

Vista gets patched / Spying on botnets / Katrina phisher indicted


Microsoft fixes faulty security patch

Microsoft has issued a fix to address the problems experienced by some users after installing one of the latest critical security patches for Windows. - CNET News.com
Related of interest:
Microsoft to fix patch that crashes IE - InformationWeek

Microsoft adds Vista patches for latest flaws
Microsoft has issued versions of two of this month's security patches for the Beta 2 of Windows Vista. - Computerworld
Related of interest:
Patch Tuesday comes for Vista too - CNET News.com
Microsoft releases Vista patches - Vnunet.com

Zero-Day attackers target Japanese word processor
Attackers are using a zero-day exploit for the Japanese word processor Ichitaro to install a trojan backdoor. - eWEEK

BlackBerry and brethren carry security bull's-eye

Many deployments of the BlackBerry software is vulnerable to attack, security researcher warns. - eWEEK

Botnet eavesdropping: Inside the MocBot attack
LURHQ security researcher Joe Stewart has examined the behavior of the MocBot that exploits the vulnerability fixed by Microsoft patch MS06-040. - eWEEK

Agencies lag on reporting data breaches
Only about one-half of the major U.S. government agencies have reported back on a request for reports on loss or breach of sensitive data within the last three years. - Government Computer News

McAfee faces patent lawsuit over UTM tech
Security vendor Deep Nine has sued McAfee for violating a patent in its unified threat management technology. - InformationWeek

Symantec patches bug that allows remote control
Symantec has issued a fix for a bug in its Veritas NetBackup software that could alow an attacker to bypass the authentication scheme. - InformationWeek

AOL security tool raises adware questions
The EULA for AOL's free Active Virus Shield keeps options open for serving ads to users and collect information. - InfoWorld

China malware war gets personal

A Chinese Internet entrepreneur is locked in a legal battle with Yahoo that involves labeling a Yahoo tool as spyware. - Red Herring

Creator of bogus Hurricane Katrina site indicted
A Miami man is being charged with selling phishing software kits to create fake disaster relief sites related to Hurricane Katrina. - SC Magazine UK/US
Related of interest:
Federal grand jury indicts Katrina phisher - TechWeb

Microsoft Office trojan appears in wake of Patch Tuesday
A low profile trojan exploits a flaw in Microsoft Office and Visual Basic to spread itself in infected Word documents. - SC Magazine UK/US

Security firm disclaims Mac hack demo
SecureWorks has posted a disclaimer stressing that the Wi-Fi hacking demo performed on an Apple MacBook used third party drivers. - InformationWeek

Thursday, August 17, 2006

8 in 10 U.S. firms lost laptops with data / Social sites new spyware nest

Hackers target latest Windows fix
Worms have been spotted in the wild that uses an exploit for the vulnerability addressed by Microsoft's MS06-040 update. - BBC News

AOL looks to strike spammer's gold in Mass.
Internet service provider AOL is seeking the court's permission to dig for gold bars that a convicted spammer may have buried on his family's property. - CIO Magazine
Related of interest:
AOL: You've got gold - InternetWeek.com
AOL to hunt down spammer's gold - Reuters

Bug hunters want vendor disclosure
Security researchers are now asking software vendors for more information about, what the vendors are doing to fix the flaws found by the researchers. - CNET News.com

Windows Vista beta gets two security patches

Two of the recently released critical patches issued by Microsoft is targeted towards Beta 2 of Windows Vista. - Computer Weekly

Berlusconi 'death' trojan targets users
A new trojan disguises itself as a fake news report about the death of Iltaly's Silvio Berlusconi. - Computer Weekly

81 % of U.S. firms lost laptops with sensitive data last year
According to a survey loss of laptops with sensitive information is a widespread problem among U.S. firms. - Computerworld
Related of interest:
DOT says it has lost two laptops this year - Computerworld

Consumer group slammed for creating 'test' viruses
ConsumerReports.org is being criticized by anti-virus firms for creating 5.500 new viruses as part of a test of anti-virus products. - Computerworld

Internet crimes reach record high in Japan

Internet related crimes are rising in Japan, where especially Internet auctions are a major concern. - Computerworld
Related of interest:
Web auction fraud leads surge in Japan cybercrime - Reuters

FTC, AG blame 'extorsionware' for pop-up hell
The U.S. Federal Trade Commission and the state of Washington has sued a number of people involved with software that delivers pop-ups that tells the user to pay to get rid of the ads. - InformationWeek

Military research aims to develop secure wireless nets

Funded by the U.S. Department of Defense research fund DARPA, researchers are working on a self-configuring secure wireless network. - Network World Fusion

Spyware infection rates on the rise
Social network sites such as MySpace.com is becoming a new hotbed for spyware distribution. - NewsFactor
Related of interest:
Social sites open door to malware - Vnunet.com

Yahoo plugs another web mail hole
Yahoo has fixed a vulnerability in the company's popular webbased mail service that could have given hackers access to users' mailboxes. - SC Magazine UK/US

Treasury report: IRS email systems insecure
The majority of employees of the U.S. Internal Revenue Service violates the personal use policy for the department's email systems. - SC Magazine UK/US

Monday, August 14, 2006

Site update: Off to Linuxworld Tuesday & Wednesday

I will be at Linuxworld in San Francisco Tuesday and Wednesday, so most likely I will not have time to update the site those two days. I will be back again Thursday.

Worms and hackers exploit Windows flaw / OpenOffice security questioned


U.K. bank details sold in Nigeria

Bank details of Britons are being sold in Nigeria, after they have been found on old PCs sent there from the U.K. with data left on the hard drives. - BBC News

OpenOffice security is questioned
A report from the French Ministry of Defense finds that the general security of OpenOffice is insufficient. - CNET News.com
Related of interest:
Is OpenOffice a bigger risk than MS Office? - Computerworld

Why Internet security continues to fail
Perspective on how the security industry has failed to fix the underlying weaknesses that is the source of security risks. - CNET News.com

Spam carrying embedded images designed to evade filters doubles
Image-based spam continues to be a growing portion of the total amount of spam, peaking at up to 30 percent. - Computer Weekly

Hackers hunting for unpatched Microsoft computers
As predicted hackers have begun using an exploit for the vulnerability fixed by MS06-040 to attack unpatched systems. - Computerworld
Related of interest:
Botnet herders attack MS06-040 worm hole - eWEEK
Hackers exploit Windows security vulnerability - InformationWeek
Microsoft issues advisory about MS06-040 attack - InformationWeek
Bot exploiting critical Windows flaw is here - SC Magazine UK/US
How to protect against the MS06-040 attack - TechWeb
Major Windows worm attack 'imminent' - Vnunet.com
Cuebot worms exploit Microsoft vulnerability - Vnunet.com

VA to encrypt all computers
The U.S. Department of Veterans Affairs has signed a contract to put encryption on all the department's laptops. - eWEEK

Microsoft Office under siege
Hackers are flocking around Microsoft Office in an attempt to find more zero-day flaws in the software. - eWEEK

Cisco, Microsoft face scrutiny following barrage of security alerts
A vendor's response to a newly discovered vulnerability can be just as important in the opinion of the customer as the existance of the vulnerability. - InformationWeek

Hackers beware: You are what you type
Your typing style, rythm and language can be used by forensics to build a profile of who you are. - InfoWorld

Beyond NAC: The internal controls
Smaller security vendors are focusing on how to secure the network inside the perimeter. - NewsFactor

Video nasty - adware nastier, say experts of online ad

A controversial video ad at british newspaper The Guardian may be more controversial not because of the video, but because clicking on the ad leads users to adware. - Silicon.com

75 percent of Chinese PCs hit by viruses
The Chinese government estimates that as many as three out of four PCs in the country is hit by viruses. - The Inquirer