Monthly Archives: December 2008

All I want for Christmas... is a patch

Image (2) datbi.jpg for post 13104

As predicted last week, the volume of attacks looking to exploit the zero day vulnerability in Internet Explorer (advisory 961051) browsers is steadily growing. We are seeing many attacks where the bundle of exploits being used to infect victims now Read more…

Share

Stop viewing porn in Internet Explorer.. for now

Image (2) datbi.jpg for post 13104

Over the weekend the situation regarding the unpatched zero-day vulnerability in Microsoft Internet Explorer got worse. On Saturday, Microsoft blogged that a staggering 0.2% of all internet users may have been exposed to the exploit, which has been seen on Read more…

Share

Opinions on Apple Mac security

Image (1) goldeneye.jpg for post 13102
Share

33 pages of web forum spam

Image (1) viddler-spam.jpg for post 13093

I still find it mind-boggling how little some websites are doing to fight spam on their sites. As we discussed in the 2009 Sophos Security Threat Report, and in the video of the Spike website being abused by malicious porno Read more…

Share

Another data loss scandal strikes Germany

Image (1) microfilm.jpg for post 13088

It sounds like a plot from a a spy novel, but the anonymous delivery to a newspaper of a cardboard box containing microfilm has ripped open a huge story in the German newspapers. Journalists with the Frankfurter Rundschau were sent Read more…

Share

John McCain and Sarah Palin's leaky data

Default image

The dramatic US election campaign brought with it a swathe of computer security stories this year. Amongst other headlines, we saw Sarah Palin's email account being hacked, malware posing as sex videos or victory speeches from Barack Obama, and spammers Read more…

Share

Advertising Trojans?

Image (1) 1.jpg for post 23024

If you get enough traffic to your website, you stand a fair chance of making huge money. However, how do you get people to visit your website? Today we found an interesting sample of a Chinese website, which utilizes a Read more…

Share

Great, One More Friend... Or So You Think.

Image (1) hi5_invite.png for post 23019

Today, I've encountered a phishing spam campaign that could affect members of the hi5.com social network. Messages of that campaign present a fake hi5.com friend request to the recipients and invite them to enter their credentials on a fake replica Read more…

Share

You're a nobody unless someone is faking you

Image (1) fake-vint-cerf-twitter-page.jpg for post 13085

You can't trust anybody on the internet these days. There has been a fake Steve Jobs, a fake Tony Benn (for the benefit of our non-British readers, Tony is a famous left-wing veteran politician), and a truly confusing squabble over Read more…

Share

Unpatched Microsoft Internet Explorer vulnerability being actively exploited

Default image

As many of you who follow the security scene will know, Microsoft released an advisory about a zero-day vulnerability in the Internet Explorer web browser a couple of days ago. Sophos published its own analysis of the severity of the Read more…

Share

Symantec and HP lose laptops - workers warned of identity theft risk

Image (1) symantec-data-loss.gif for post 13079

Hewlett Packard (HP) and Symantec are reported to be warning their workers of the potential risk of identity theft after laptops were stolen containing unencrypted personal information. The Symantec incident occurred in October, when a laptop containing some staff names, Read more…

Share

Lois Lane and the Craigslist fake landlord scam

Image (1) lois-lane.jpg for post 13074

I read an interesting story last night about a woman who was trying to sell her house in Cleveland, Ohio. Sharon Smith hired a real estate agent to advertise her house for sale and, as is normal these days, photographs Read more…

Share

More on the Internet Explorer zero-day

Image (2) cng1_sm.png for post 23013

Readers will have likely read the vulnerability assessment (updated earlier this morning) and the previous blog entry we have posted. Obviously when issues like this arise, and gather some attention in the press, customers get concerned (understandably). Even if a Read more…

Share

Internet Explorer: zero-day exploit

Default image

There is exploit code for a zero-day Internet Explorer vulnerability circulating actively in the wild. This exploit, which has a Microsoft advisory, causes a heap overflow in the XML parser which can then be used for remote code execution. The Read more…

Share

FTC halts fake anti-virus scans that scammed a million people

Image (1) ghost-parade.jpg for post 13071

A US District Court has temporarily halted the operations of two firms accused of tricking internet users into buying bogus security products (also known as scareware or rogueware). According to a statement by the Federal Trade Commission, Innovative Marketing and Read more…

Share

I'd like to buy the world a clue

Image (2) coca-cola-scam.jpg for post 13068

Email scams claiming to come from Coca Cola are nothing new. But today Clu-blog reader Kevin forwarded me a message he had received in his inbox which was a little different. The email Kevin received claims to come from the Read more…

Share

Talking computer security threats in 2008 and 2009

Talking computer security threats in 2008 and 2009

Earlier this week Sophos published its annual threat report - a free-to-download guide about the top computer security threats and trends we saw in 2008, and some predictions as to what we might see in the future. This morning we've Read more…

Share

Animals Suffer from Malware Too

Image (1) originalscript1.jpg for post 23006

Animals already suffer from cruel treatment due to illegal trading and hunting. Now, they have to suffer because of malware as well. Recently, I chanced upon another typical obfuscated VBscript: After de-obfuscating the encrypted layers of code, the Trojan unravels Read more…

Share

December Microsoft Security Bulletins

Default image

It seems that November was quite a busy month for people in Microsoft Security Response Center, finalizing the set of latest security patches. It is a bit worrying that vulnerabilities in 7 out of 8 published bulletins could be used Read more…

Share

Video of a fake anti-virus attack

Default image

Following the video I posted earlier today demonstrating how criminals have planted messages on the Spike website linking to pornographic and malicious attacks, here's another movie. (Enjoy this video? You can check out more on the SophosLabs YouTube channel and Read more…

Share