Friday, August 25, 2006

Spammers affect stocks / Cisco warns of flaws / Hacker faces prison

Spammers manipulate stock markets
Spam-mails promoting penny stocks has enough effect on the stock market to earn the spammers up to 6 percent on pump-and-dump schemes. - BBC News

Spyware attacks hit new high
Security firm Webroot reports that it has registered the highest rate of spyware infections since 2004. - Computer Weekly
Related of interest:
Nine in 10 PCs infected with spyware - Vnunet.com

Postponed IE-patch re-released by Microsoft
Microsoft has finally released the updated version of a recent patch for Internet Explorer that turned out to cause a new risk. - Computer Weekly

IT execs on firing line over security breaches

The dismissal of AOL's CTO earlier this week is just the latest in a row of episodes, where the IT execs takes the blame for security breaches. - Computerworld

Cisco flaws leave firewalls, VPNs vulnerable
Cisco has issued a warning about a flaw in some of its products that could allow passwords to be changed. - eWEEK
Related of interest:
Cisco releases two security advisories - SC Magazine UK/US

Inside attacks generally launched by problem employees
According to U.S. Secret Service inside attacks are generally launched by disgruntled and repeatedly troublesome employees. - InformationWeek
Related of interest:
Study highlights insider threats - InformationWeek

Hacker faces prison for PC attacks
A 20-year old U.S. hacker that created a virus that put patients at a hospital in jeopardy could get six years in prison, when sentenced. - NewsFactor

Man-in-the-middle PayPal attack in the works
Finnish anti-virus firm F-Secure warns about a potential phishing attack against PayPal users that could use man-in-the-middle tactics. - SC Magazine UK/US

Online retailer sentenced for arranging computer attacks on rivals

A 19-year old man has been sentenced to 30 months in prison for hiring another teenager to launch a computer attack against competitors to his online business. - AP/SiliconValley.com

Ransomware data kidnapping on the rise
Anti-virus firm Panda reports of a 30 percent rise in the amount of ransomware. - Vnunet.com

Experts warn of email-bombing campaigns
The recent sentencing of a U.K. teenager for burying his former employer's email server with spam only shows that it could have gone much worse, experts warn. - Vnunet.com

Thursday, August 24, 2006

Student data exposed / Unpatched bugs proliferate / Old bug haunts PowerPoint

U.K. tops spyware infection charts
According to Webroot U.K. suffers from the highest infection rate for spyware in Europe. - Computerworld

Five reasons you need a new approach to AV security
Changes in malware tactics mean that there are new demands for what anti-virus software must be able to do. - Computerworld

Investigator: Report cybercrime
Reporting incidents of cybercrime can prove beneficial to the attacked, as it will help building better defenses. - InfoWorld

Keeping up with the hackers
Five areas of IT security that can help an organization stay up to date with current threats. - InternetWeek.com

Student borrowers' personal data posted
The U.S. Education Department says that up to 21,000 people with federal student loans will receive free credit monitoring after weekend breach. - AP/Los Angeles Times

PowerPoint attacks use old bug, not new flaw

Reports of attacks using a zero-day flaw in PowerPoint is incorrect, according to Microsoft. The attacks uses a bug fixed in March. - TechWeb

Unpatched enterprise security bugs proliferate
Security firm NGS Software reports a backlog of 175 unresolved vulnerabilities that the company have found, but vendors have yet to fix. - The Register

Wednesday, August 23, 2006

Spam teen gets curfew / Troubled IE patch / Mocbot breeds zombies

Mass email attack teen sentenced
Two years after bombarding a U.K. insurance company with over five million emails, a 19 year old man has been given a two-month curfew. - BBC News
Related of interest:
U.K. spammer gets two-month curfew - CNET News.com

Confidential data really at risk
Perspective on the problems about potential loss of confidential data pinpointed by a recent survey. - CNET News.com

IE patch carries security bug
On some Windows systems the recent MS06-042 update from Microsoft has opened a new security hole. - CNET News.com
Related of interest:
Microsoft delays reissue of critical patch - Computer Weekly
Microsoft will re-release 'butchered' patch - Computerworld
Why did Microsoft delay IE patch? - eWEEK
Microsoft nixes IE repatch, chides researcher - TechWeb

Network intrusions put net-centricity at risk
Over 60 serious attacks against U.S. army networks so far this year puts the network-centered structure at risk. - Government Computer News

Yahoo adds anti-phishing sign-in seal
Internet portal Yahoo has added a new seal at user sign-in that is tied to the user's pc in an attempt to prevent phishing. - InformationWeek

Big boost in zombie PCs seen from latest Windows exploit

According to security firm CipherTrust the worm using the latest Windows exploit has created about 50,000 new zombie PCs. - InformationWeek
Related of interest:
Porn spam spike due to Windows hole - Silicon.com
Worm mutation breeds zombies - Vnunet.com

AV vendors flip over CU's 'dummy viruses'
While anti-virus firms agree that Consumer Union's creation of 5,500 new viruses to test AV applications was a bad idea, analyst says the test found a soft spot. - Internetnews.com

Experts divided over rootkit detection and removal
The security industry is split over the difficulties involved with detecting and removing rootkits from infected systems. - Network World Fusion

Viruses and spyware cost users $7.8 billion
U.S. consumers spent up to $7.8 billion on repairing or replacing computers hit by viruses and spyware, survey finds. - NewsFactor

Spammer's grandparents to allow initial gold search by AOL

AOL will be allowed to search for a spammer's hidden gold on his grandparents' property by radar and sonar. - AP/SiliconValley.com

U.K. heads EU spyware chart
U.K. is the worst hit country in the EU when it comes to spyware infected PCs according to Webroot. - Vnunet.com

Tuesday, August 22, 2006

Microsoft dismiss PowerPoint flaw / Zombies march on / AOL reviews privacy

Due to technical difficulties with Mozilla Firefox under Windows XP, today's summary will be cut short, as I lost most of the post, when my Firefox client crashed.

Microsoft dismisses PowerPoint zero-day warning
Microsoft denies that the exploit reported by Trend Micro is a new one, but instead has been fixed by the recent update for MS Office. - eWEEK

Chinese begin anti-spam enforcement
Authorities have fined a Chinese company in what may be the first case against a spammer in the country. - Computerworld

Kevin Mitnick website hacked
Hackers managed to deface famous hacker Kevin Mitnicks website after an attack against his hosting firm. - Silicon.com

Student found Myspace security flaw
A U.K. student may have found a flaw that could indicate a problem with passwords for Myspace.com. - The Inquirer

AOL moves to increase privacy on search queries
Internet service provider AOL will review its privacy policies and security measures after the publishing of user search information. - The New York Times

Worm sparks rise in zombie PCs
New botnet worms are fueling a rise in the number of new zombie PCs, CipherTrust reports. - ZDNet UK

Charity defends PC recycling after data theft claims
A charity organization now urges corporations to not dismiss donating old PCs to developing countries after claims of theft of data on old recycled hard drives. - ZDNet UK

Monday, August 21, 2006

Fresh PowerPoint exploit / Bots build spam-networks / Web scammers arrested

Vanishing laptops plague businesses
Four out of five firms report having lost laptops that could contain sensitive data in the past year, survey finds. - Computer Weekly

Stanford University's password hash phish fighter
A browser-plugin that uses a hash to lock a password to a specific website to foil phishing attempts, has been awarded by Computerworld. - Computerworld

FBI investigating theft of 10 hospital computers
10 computers stolen from Hospital Corporation of America earlier this month could contains thousands of files about unpaid medical bills. - eWEEK

British police arrest two over web scams
A man and a woman have been arrested by British police, charged with scamming people into buying nonexisting vacations over the web. - Reuters/eWEEK

Red storm rising
The U.S. Department of Defense reports that its networks are under constant scrutiny by civilian units from inside China. - Government Computer News

Internet industry calls for a law against password theft
German IT association Bitkom asks for legislation against password theft to provide legal basis for the fight against phishing. - Heise online

Bot builds spam-spreading zombie army
The malware MocBot that exploits recently patched Microsoft flaws is building a botnet that is being used for spam, LURHQ eavesdropping documents. - InformationWeek

PowerPoint users warned of flaw
A new and unpatched flaw in Microsoft PowerPoint is being exploited by a trojan. - SC Magazine UK/US

ID scams require taking a hammer to used hard drives

Reports of used hard drives being purchased by scammers in Africa make security expert advise users to physically destroy old hard drives. - TechWeb

Romanians crack Internet crime rings
Romanian police have arrested 23 persons as part of an investigation into criminal organisations behind phishing frauds. - The Inquirer

IT managers admit network vulnerabilities
According to a survey, four out of five organisations believe that their network is open to security breaches. - Vnunet.com