Monthly Archives: May 2009

Scammer tricks

Image (1) phish_email.jpg for post 23688

After I leave the lab after a busy day, I often ponder what tricks scammers will use next? For example, we see a constant stream of fake security applications that fraudulently suggest a user should offload a sum of money Read more…

Share

Cybersecurity Czar

Image (1) presseal.jpg for post 23685

This morning President Obama announced that he would be appointing a Cybersecurity Coordinator. The appointment is one of the many recommendations of the 60 day cyberspace policy review (PDF) commissioned in February. Along with publication of the review itself comes Read more…

Share

Guest blog: Single vendor or multi-vendor security - that is the question

Image (3) john-metzger.jpg for post 14237

John Metzger, a product marketing manager in our Columbus office, has found a large pile of Sophos polo-shirts which he would like to give Clu-blog readers. Unfortunately, there's a catch - he wants you to answer his survey. So it's Read more…

Share

109,000 pension holders at risk after laptop stolen

109,000 pension holders at risk after laptop stolen

It seems hardly a day goes past without news of a lost laptop containing sensitive unencrypted data or a mislaid USB memory stick. The latest victims are some 109,000 pension holders whose data was on a laptop computer at the Read more…

Share

A data-stealing trojan under the microscope

Default image

Recently I had received a call to assist a potential customer with a virus outbreak in a segment of their network. The victim had been using a competitor's product, which unfortunately was not protecting them from the spread of this Read more…

Share

Cracked Windows - Microsoft warns of critical flaw

Image (1) fix-it.jpg for post 14225

Microsoft has published a security advisory warning of a critical vulnerability in Microsoft DirectX on older versions of Windows. The problem is in the way that Microsoft DirectShow handles QuickTime format files - meaning that if a user opened a Read more…

Share

Sophos Australia at AusCERT 2009

Sophos Australia at AusCERT 2009

Dear Diary, Last week was AusCERT 2009 - the biggest, and arguably the best, computer security conference and trade show in Australia. The event takes place at the Royal Pines resort in South East Queensland, far from the madding crowds, Read more…

Share

Explore the anatomy of an attack

Image (3) james-lyne.jpg for post 14215

Guest blogger James Lyne has tied me up with bedsheets in order to hijack the Clu-blog for a minute. Below you'll find a blatant advert for an event he's involved in at Sophos's HQ in Oxfordshire. Take it away James.. Read more…

Share

Leaked German poll results lead to Twittergate

Image (1) horst-koehler.jpg for post 14210

According to newspaper reports, Twitter has been at the centre of a political storm in Germany after news of the president's re-election leaked out on the micro-blogging website. Julia Klöckner, of chancellor Angela Merkel's CDU party, posted on Twitter "People, Read more…

Share

Stupid way to end piracy

Image (1) piracy.jpg for post 23681

Here in SophosLabs, we are quite used to seeing popular musician's images and names being used to spread malware. But this piece of malware I saw today attempts to stop global music piracy, which incidentally seems to be on the rise Read more…

Share

Why Geo-tagged Twittering could be bad for security

Image (1) twitter-bird.jpg for post 14206

The web is becoming increasing about where you are, not just what you're doing/saying/reading/writing. For instance, earlier this week I was standing in a horrendously long queue to be admitted into a recording of the BBC TV show QI, hosted Read more…

Share

That guy phishing you could be 14 years old

Image (1) no-fishing-mermaid.jpg for post 14202

The US District Court in Minneapolis has sentenced a 23-year-old Romanian immigrant to 8.5 years in jail for stealing a total of approximately $700,000 from over 7,000 innocent people. Sergiu Daniel Popa spammed out emails pretending to come from financial Read more…

Share

Western Union malware attack rides into inboxes

Image (1) western-union-malware.gif for post 14198

Our labs are seeing a stampede of emails claiming to come from Western Union's support team, but are actually carrying a malicious payload in the form of a Trojan horse. The emails, which pretend to have been sent from support@westernunion.com, Read more…

Share

How to control a BlackBerry Enterprise Server with just a PDF

Default image

Sorry, I'm not actually going to tell you how to do that. But Research In Motion (RIM), the company who make the BlackBerry smartphones beloved by corporate workers worldwide, has warned of a vulnerability in the way its devices handles Read more…

Share

Which they ate with a runcible spoon

Image (1) canadian-pharmacy.jpg for post 23669

Spam campaigns often include text from commonly-available books and websites to try to make them look more like legitimate emails. This week I've seen runs that are using lines from the nonsense poetry of Edward Lear in their hashbuster, for Read more…

Share

NHS accused of "cavalier attitude" after data security leaks

Image (1) ico-logo.jpg for post 14192

The British National Health Service (NHS) has been accused of losing almost as much personal data in the first three months of this year, as the entire private sector. With over 140 security breaches by the NHS logged by the Read more…

Share

Ten years at Sophos

Ten years at Sophos

I didn't believe them when they told me, but apparently today is the 10th anniversary of me joining Sophos. Sophos wasn't my first job in the computer security industry. In December 1991 I went for an interview at S&S International Read more…

Share

Fear of blackmail after RAF loses sensitive personal data

Image (1) raf-logo.jpg for post 14171

Highly personal information about senior officers of the Royal Air Force (RAF) - including details of extra-marital affairs, debt, drug abuse, and the use of prostitutes - is alleged to be amongst the data lost from a base in Innsworth, Read more…

Share

Common Fish

Common Fish

Today I came across a phish, nothing new there but it was targeted at one of Australia's biggest banks, Commonwealth Bank.  The phish claims to be from the Commonwealth Bank, and looks like this -------------------------------------------------------------------------------------------------------------------------------- Dear Member, Your Online banking Read more…

Share

Acai Berry spammers hack Twitter accounts to spread adverts

Acai Berry spammers hack Twitter accounts to spread adverts

Hundreds of innocent user's accounts on the Twitter micro-blogging service appear to have been hacked by spammers. A typical message posted on the compromised accounts will say something similar to the following: Howdy my friend! I just lost 13 pounds Read more…

Share