Monthly Archives: January 2009

Man loses $150,000 in London terror email scam

Default image

A 22-year-old man from Southern Ontario says he owes his friends and family an astonishing CDN $150,000 after he fell victim to an international email scam. Unemployed Canadian John Rempel told journalists that in 2007 he opened an email claiming Read more…

Share

Ex-worker planted malware to crash restaurant systems

Image (1) point-of-sale.gif for post 13347

A 21-year-old man has admitted planting malware on his former employer's computer network after he was fired, according to the US Attorney's Office. David Ernest Everett Jr stopped working on the helpdesk at Wand Corp, a firm which produces integrated Read more…

Share

The Northwest Airlines malware attack

Image (1) airline-infected.gif for post 11955

We're seeing a Trojan horse being widely spammed out at the moment posing as an email from Northwest Airlines. The emails have the following characteristics: From: "Northwest Airlines" <tickets@nwa.com> Subject line: E-ticket #<randomnumber> Attached file: Your_ETicket.zip or eTicket.zip Message body: Read more…

Share

Delete files that don't exist

Default image

Here's a cute malware trick for today, utilising the seemingly infinitely flexible Windows registry to delete files that don't yet exist. The registry allows you to associate a debugger with any program you like. A genuine debugger is specialised software Read more…

Share

Patch released for malicious BlackBerry PDF vulnerability

Image (1) blackberry.gif for post 13339

Research in Motion (RIM) has issued a patch which reportedly fixes multiple vulnerabilities in the way the BlackBerry Attachment Service handles Adobe Acrobat PDF files. According to a security advisory issued by the firm, hackers could send email message with Read more…

Share

Breaking into Twitter accounts with a dictionary password attack

Default image

Last week we discussed how a hacker was able to break into the Twitter accounts of celebrities. It turned out that a Twitter employee, who had administrative access to members' accounts, had her account broken into because she chose a Read more…

Share

January 2009 Microsoft Security Bulletin

Default image

When I received an advanced notice of the January security advisory earlier in the month, I was a bit surprised to see that there is only one security bulletin, which shows that even guys from MSRC are occasionally allowed a Read more…

Share

Serious security vulnerability in Safari web browser reported

Image (1) safari-icon.jpg for post 13334

An open source software engineer with a history of uncovering flaws in Mac OS X, claims to have uncovered a security vulnerability in Apple's web browser Safari, affecting both Windows and Apple Mac users. Brian Mastenbrook has blogged that a Read more…

Share

Continued Fake AV .htaccess attacks

Continued Fake AV .htaccess attacks

A few months ago I blogged about attackers using malicious .htaccess files in order to redirect victims to malware infection sites [1]. Well the trend continues. In the past few days I was dealing with a query from an affected Read more…

Share

Safe-cracker arrested after police post CCTV photos on Facebook

Image (1) safe-cracker.jpg for post 13329

Regular readers of this blog must be getting used to hearing stories about criminals breaking into users' Facebook and Twitter accounts to cause mischief and make a quick buck. Well, here's a story of a rather different break-in that involved Read more…

Share

Medical data on over 6000 prisoners lost on USB stick

Medical data on over 6000 prisoners lost on USB stick

More than 6,000 prisoners and ex-inmates from Her Majesty's Prison Preston, Lancashire, have had their personal medical details exposed by the loss of a memory stick, according to media reports. The memory stick carried data relating to 6,360 prisoners who Read more…

Share

Indian police crack down on unsecured Wi-Fi hotspots

Default image

Police in Mumbai (formerly known as Bombay) are reportedly on the hunt for poorly secured wireless connections, following an incident last year where hackers sent a warning about an imminent bombing from an innocent person's Wi-Fi connection. At a conference Read more…

Share

NASA hacker Gary McKinnon could be prosecuted in Britain

Default image

Gary McKinnon, the infamous hacker who broke into computer systems belonging to NASA, Department of Defense, the US Army, US Navy and US Army, has told the British Crown Prosecution Service (CPS) that he would plead guilty if prosecuted in Read more…

Share

LNK Trojan Downloaders - when the shortcut becomes the program

Default image

Malware authors have recently revived a cunning tactic to get their malicious code onto your machine -- using a Windows Shortcut file both as the attack vector and the downloading payload itself. The use of Windows Shortcuts is nothing new Read more…

Share

Government departments in New Zealand and Bulgaria hit by viruses

Image (1) globe.jpg for post 13326

According to media reports, government ministries in New Zealand and Bulgaria have been hit by computer virus infections, shutting down computer systems and disrupting work. According to minister Mihail Mikov, Bulgaria's Interior Ministry was struck - with traffic police and Read more…

Share

Hackers hide malware behind CNN headlines about Gaza conflict

Image (1) cnn-hamas-israel.gif for post 13323

Hackers love to jump on the tails of breaking news stories in their attempt to infect as many people as possible. One of the latest examples we have seen is a campaign of spammed-out messages that claim to come from Read more…

Share

Anti-Israeli hackers bring cyberwar to Washington DC and NATO

Image (1) mdw-hack.gif for post 13319

The website of the US Army's Military District of Washington - www.mdw.army.mil - was hacked yesterday by hacktivists protesting against Israel's actions in Gaza. The hack, which is still viewable in Google's cache of the website, claims that the site Read more…

Share

A simple way to phish for Twitter passwords?

Image (1) twitter-popup.gif for post 13315

SophosLabs received an interesting email today from a user who believed that high-tech news website Wired.com had been hacked. As Ted Russ posts on his blog, he had a strange dialog box pop up when he visited a page on Read more…

Share

Sacked worker used spyware to read former colleagues' emails

Image (1) i-spy.jpg for post 13310

According to media reports, a British man who lost his IT job after lying about his career history and qualifications hacked into his former employees' network and planted spyware on colleagues' PCs. 46-year-old Julius Oladiran of South Norwood, London, lost Read more…

Share

Should hard drives be destroyed or wiped?

Image (1) hammer-drive.jpg for post 13307

BBC News Online, one of the most popular websites in the UK, is running a story today advising people not to wipe old hard disks, but to take a hammer to them instead. The story claims that secure data erasure Read more…

Share