Monthly Archives: August 2009

Security leaders form industry group to improve collaboration

Image (1) ieee-logo.jpg for post 14776

The IEEE Standards Group has today publicly announced the formation of the Industry Connections Security Group (ICSG), with the intention of improving collaboration between security vendors. Sophos is joined as a founding member of the ICSG by our friends at Read more…

Share

More Phacebook fishing.

Image (1) sssapp1.jpg for post 24251

Earlier this morning I was asked to check out what appeared to be another Facebook phishing attack, as detailed here. Sure enough, a domain registered a couple of days ago is being used to harvest Facebook login credentials from unsuspecting Read more…

Share

Visual Basic worm (re)discovers old trick

Image (1) sillyvb.png for post 24242

The simplest type of hash-buster in malware typically consists of a few (or many) appended random bytes, changing the files checksum while not altering its functionality. More advanced hash-busters incorporate patching of inconsequential bytes within the files code or data Read more…

Share

Aftertaste - The domain tasting era has quietened to a whisper

Default image

On Thursday a report was released by ICANN supplying data that implies the practice of domain tasting has come to an end. The traditional definition of domain tasting is the practice of purchasing a domain for the purpose of hosting Read more…

Share

Aftertaste - The domain tasting era has quietened to a whisper

Image (2) canadian-pharmacy.jpg for post 2771

On Thursday a report [PDF] was released by ICANN supplying data that implies the practice of domain tasting has come to an end. The traditional definition of domain tasting is the practice of purchasing a domain for the purpose of Read more…

Share

Scribble piggybacks Koobface

Image (2) koobfacescribble.jpg for post 24238

In recent weeks we've seen Koobface move its updating mechanism to the vast array of bots it controls. Now when you download the latest version of the Trojan, you end up fetching it directly from the machine of someone else Read more…

Share

Same, same (but different)

Image (4) same_same.jpg for post 24233

Through following unsubscribe links in unsolicited email advertisements, one can often reach the home pages of the self-proclaimed "advertising agencies" that send the spam. Examples of such pages include: As well as this site: Hang on a sec, those pages are Read more…

Share

Ashley Greene dirty pics lead to Mac and Windows malware danger

Image (4) ashley-greene-dmg.jpg for post 14768

Nude photos of "Twilight" film star Ashley Greene have been leaked onto the net, propelling her name high in the chart of most commonly searched for phrases at the moment. However, if you're foolish enough to go hunting for the Read more…

Share

How to stop Spotify

Image (1) spotify-logo.jpg for post 14759

At the end of July Spotify announced on its blog that it had submitted an iPhone edition of its popular music-streaming app over to "the nice people at Apple" for approval. That all sounds very simple doesn't it? Well, think Read more…

Share

AutoCAD virus is a blast from the past

Image (1) autocad-virus-alert.jpg for post 14751

Thanks are due to my SophosLabs colleague Paul Baccas who today brought my attention to a fairly unusual sighting in the malware world - an AutoCAD virus. It turns out that Autodesk, the makers of AutoCAD, blogged last week about Read more…

Share

AutoCAD malware: ACAD.VLX

Default image

At the end of last month, I saw some malicious AutoCAD files (AL/Utax-A) which caused me to put AutoCAD on my research to-do list. The last time I seriously looked at AutoCAD malware was back in May  2007 (AL/Bursted-Fam). Imagine Read more…

Share

Robert Scoble fails to update WordPress, gets hacked

Image (1) scoble-tweet.jpg for post 14746

Prominent blogger Robert Scoble, who runs the Scobleizer website, has come a cropper after hackers were able to break into his site and post links to pornographic websites. In a posting last night on Twitter, Microsoft's former technical evangelist wrote: Read more…

Share

Fake AV continuing the PDF onslaught

Image (1) pdf-fav0.jpg for post 24221

Throughout 2009 we have been reporting on the large rise in the volume of attacks that use malicious PDF samples to infect victims with malware [2]. If anything, the past few weeks have shown an increase in such attacks. In Read more…

Share

Can you trust Conficker clean-up advice on Twitter?

Default image

I would be cautious of trusting Twitter users who recommend you try Trend Micro to clean-up the Conficker worm. Not because Trend Micro can't help you remove the Conficker worm (I'm sure they can), but because it could be that Read more…

Share

Another day, another security update from Apple

Image (1) bruised-apple.jpg for post 14743

It seems like only yesterday that I was blogging about an important security update from Apple. And wasn't it just last week when we were discussing how boobytrapped images could infect your Mac, and how GarageBand could change your Safari Read more…

Share

The latest... latest, vulnerability analysis

Image (1) telnet.png for post 24224

Well, it's about that time... Microsoft recently released their August 2009 Security Bulletin and, in turn, we've updated our vulnerability analysis page . This month's update patches several important vulnerabilities that even the most diligent security-conscious web users should watch Read more…

Share

Microsoft issues barrage of security updates

Image (1) aug09sevsummary.jpg for post 14740

Microsoft has issued an advisory, informing users of a bumper pack of software updates to fix at least 19 security holes in its operating system and other Windows software. These security updates come as part of Microsoft's regular "Patch Tuesday" Read more…

Share

Six security holes fixed in Safari 4.0.3

Six security holes fixed in Safari 4.0.3

Apple has updated Safari to version 4.0.3, reportedly fixing some stability and compatibility issues but also, most importantly to readers of this blog, plugging a number of security holes. And don't think you can get away with not updating if Read more…

Share

More reports of Apple Mac Trojan horse seen in the wild

Apple Mac

Our friends at Trend Micro have blogged about a Trojan horse for Mac OS X they have recently encountered disguised as MacCinema Installer. This has caught the attention of some reporters and bloggers (such as Dancho Danchev). That's not such Read more…

Share

Twitter knocked out for second time in less than a week

Image (1) twitter-whale.jpg for post 14734

"Fool me once, shame on you; Fool me twice, shame on me" I can't help but feel sorry for Twitter as it tripped up this evening after apparently becoming the unwitting victim of a distributed denial-of-service attack for the second Read more…

Share