Monthly Archives: April 2009

More Mikeyy worm madness on Twitter

Image (1) twitter-hire-mikeyy.gif for post 12058

What on earth is going on at Twitter? That's the question that many people will be asking after the Easter break, following a wave of cross-site scripting worms that hit the micro-blogging site. After each attack Twitter said that it Read more…

Share

Mikeyy attack hits Twitter users - a bad 24 hours for Web 2.0 security

Image (1) mikeyy.gif for post 13987

The day after messages about StalkDaily swamped the feeds of Twitter users via a cross-site scripting attack, we are seeing another assault on the micro-blogging network - apparently inspired by the suspected author of the previous attack. Thousands of duplicate Read more…

Share

17-year-old claims he is creator of StalkDaily Twitter worm

Image (1) mikeyy-suspended.jpg for post 13981

A 17-year-old youth from Brooklyn, New York, has admitted that he was the author of the StalkDaily cross-site scripting attack that hit Twitter yesterday. Mikeyy Mooney is reported to have told breaking news website BNOnews.com that he coded the attack Read more…

Share

MMX gives FakeAVs a new trick

Image (1) fakeav_mmx.png for post 23483

With the fake antivirus family of malware, it is no wonder the authors are able to develop new complex, custom packers to encrypt their malicious code. With each new packer, thousands of different polymorphic variants are released, making any attempt at signature-base Read more…

Share

StalkDaily - Twitter users warn each other of worm attack

Image (2) stalk-daily-twitter.gif for post 13979

Thousands of Twitter users are warning each other about what appears to be a fast-moving attack affecting the system. Affected Twitter profiles appear to be directing unsuspecting users to the website stalkdaily.com. (Please do not visit this site) (Enjoy this Read more…

Share

Bogus lottery letter ring busted by UK police

Bogus lottery letter ring busted by UK police

Normally Naked Security focuses on computer-related threats, but postal lottery scams are a menace that are particularly worth considering if you have elderly or vulnerable family members. Although many of us are all too accustomed to receiving their email-based cousins Read more…

Share

Many PCs still not patched against Conficker vulnerability

Image (1) endpoint-assessment.jpg for post 12053

Scott Lewis in our Columbus office has been doing some number crunching, and come up with some disturbing statistics after examining the data produced by Sophos's free endpoint assessment test. The Sophos Endpoint Assessment Test is a free tool that Read more…

Share

Microsoft admits Bill Gates was wrong

Image (1) gates-davos.gif for post 13968

Well, maybe not in quite so many words. But it is kind of funny to remember that it was Bill Gates who predicted spam would be dead by 2006 while reading reports from Microsoft this week that spam now makes Read more…

Share

That e-Card may not contain the easter egg you're expecting

Image (1) hallmark-spoof.png for post 23499

Did someone send you an e-card? Check those links before you view it. Messages posing as legitimate greeting cards with titles such as "You've received A Hallmark E-Card! !" have been prevalent on the Internet and filtered by our anti-spam Read more…

Share

New domains and processes blocked by Conficker update

Default image

Our analysis of the new Conficker variant that first appeared around a day ago is ongoing. We now know that as well as the executable component, an update to the Conficker DLL in the system32 folder is installed. Initial analysis Read more…

Share

SophosLabs gets a fresh lick of paint

Image (1) labsblog-170.jpg for post 12051

The guys at SophosLabs have put some spit, polish and good old-fashioned elbow grease to good use and tarted up their blog a little. Hopefully it's a bit more user-friendly now. Check it out at its new home: www.sophos.com/blogs/sophoslabs/ Thanks Read more…

Share

Police arrest suspected banking Trojan gang

Image (1) new-scotland-yard.jpg for post 12050

The British PCeU (Police Central e-crime Unit) has scored its first success, with the arrest of a criminal gang accused of targeting the financial services industry with banking Trojan horses. Four women and five men have been arrested in a Read more…

Share

New Conficker activity

Default image

Although we have expected a flood of new Conficker samples on 1st April it was only late yesterday that we saw some evidence of a potentially new Conficker variant as well as increased activity inside the Conficker P2P network. The Read more…

Share

Fixing a hole? Paul McCartney's website hacked

Image (1) mccartney.jpg for post 12049

I have been on holiday for a couple of days, so sorry if the Clu-blog has been a bit quiet.. but I thought this story was worth a mention. Paul "Thumbs aloft!" McCartney has had his website hacked according to Read more…

Share

Another data leakage blunder...

Image (1) folder.jpg for post 23495

The BBC reported yesterday that Britain's most senior counter-terrorism police officer was carrying top secret documents in full view of photographers whilst visiting Downing Street. This possibly lead to anti-terrorist raids being brought forward and is clearly an embarrassment for Read more…

Share

Conficker Infection Alert!!

Image (1) picture-26.png for post 23480

With all the hype around Conficker recently, it should come as no surprise that scammers are using this highly publicized threat to attempt to spread more malware. We've been seeing spam spreading fake AV malware for quite some time, typically Read more…

Share

to MissPiggy from MalwareAuthor

Image (1) misspiggy.png for post 23440

Gone are the days when viruses were constructed to show off an author's coding prowess and ego, though we do still receive the odd samples which appear to adhere to this oldskool ethos. One such recent sample was a Batch Read more…

Share

Julie Christie supports NASA hacker Gary McKinnon

Image (1) julie-christie.jpg for post 12048

Legendary actress Julie Christie has followed in the footsteps of celebrities such as Sting, Boris Johnson, Terry Waite, Pink Floyd's David Gilmour, and Marillion's keyboard player by supporting hacker Gary McKinnon in his fight to avoid extradition to the United Read more…

Share

Home Office links to X-rated Japanese website

Home Office links to X-rated Japanese porn website

BBC News Online is reporting that the British Home Office found itself in the embarrassing position today of trying to explain why its website was linking to a Japanese pornographic site. As a video report showed, a webpage about the Read more…

Share

Real estate agents accused of hacking into rival's account

Image (1) nicolehayden.jpg for post 12046

Three estate agents (known as realtors in the United States) have been charged with hacking into a rival's account in Rockingham, North Carolina. Between March 1st and March 20th, three agents with RE/MAX Tri City Realty of Rockingham are accused Read more…

Share