Monthly Archives: May 2010

Facebook - Promises, malware, and spam, part 1

Image (1) zuckerbergarm250.jpg for post 2811

Is anyone else sick of the Facebook saga? I'm ready for them to get their act together so I can move on to other topics, but I can't ignore an issue that impacts the security and privacy of over 300 Read more…

Share

Facebook responds privately - Too little, too late?

Image (1) zuckemailtoscoble.png for post 2810

Robert Scoble has just (with permission) published a personal email dialog between himself and Facebook CEO Mark Zuckerberg related to the privacy beating Facebook has taken in the press this month. From Scoble's GMail Zuckerberg said: Hey, We've been listening Read more…

Share

Hot chick on Twitter? Bet it's a spammer

Hot chick on Twitter? Bet it's a spammer

A new Twitter follower whose profile picture is a hot girl is usually a clue that you may be led to a spam. Especially if they are following hundreds of people and don't have a lot of followers. Fortunately this Read more…

Share

Distracting Beach Babes video attack hits Facebook users

Distracting Beach Babes video attack hits Facebook users

Updated Thousands of Facebook users are reporting that they have been hit by a malware attack posing as a video of young bikini-clad women on a beach. The messages are posted on the walls of Facebook members, seemingly from their Read more…

Share

Don't panic! The Pacman virus hasn't infected Google

Image (1) google-pacman.jpg for post 16634

Those hoopy froods at Google are having some fun today - they've changed their Google logo to a playable version of the legendary Pacman game, which apparently is celebrating its 30th birthday. (Notice how they've even cutely changed one of Read more…

Share

Try not to laugh xD: Worm spreads via Facebook status messages

Image (1) try-not-to-laugh.jpg for post 16628

A clickjacking worm spread quickly across Facebook earlier today, tricking users into posting it to their status updates. The worm, which some have dubbed Fbhole because of the domain it points to, posts a message like the following: try not Read more…

Share

Friday evening @ Sydney Uni – time for some crypto!

Image (1) usyd.jpg for post 1521

Dear Diary, This afternoon I'm giving a guest lecture at the University of Sydney. It'll be a tough gig, but not just because it's at the end of the semester, doesn't affect the final course mark in any way, and Read more…

Share

IBM distributes USB malware cocktail at AusCERT security conference

Image (2) ibm-auscert-malware.jpg for post 16625

Sheesh. This must rank as one of the most embarrassing things a security company can do at a security conference. IBM has admitted that the complimentary USB drives it handed out this week at the AusCERT conference on the Gold Read more…

Share

Facebook leaks more private data: deja  vu all over again

Image (1) facebookxkcd550.png for post 2808

The F, A, C, E, B, O, and K keys on my keyboard are becoming well worn. The Wall Street Journal is reporting another major privacy gaffe by Facebook and a few other social networking sites. This time, counter to Read more…

Share

iPhone encryption? Not really

Image (1) iphone3gsfolders-300.jpg for post 2807

Sean Richmond from our Sydney, Australia office sent me a note yesterday asking if I had been following a thread on the Full Disclosure mailing list. The author of the message noted that when he plugged in his iPhone 3GS Read more…

Share

The Facebook 'Stupidity' virus warning meme

Image (1) stupidity-facebook-virus.jpg for post 16621

In the wake of the recent headlines about privacy concerns and the widespread "sexiest video ever" malware attack against Facebook users earlier this week, I've been keeping a close eye on the messages people post publicly to see how they're Read more…

Share

Twitterbot kit activity continued

Image (1) tbot1.png for post 25462

There has been quite a lot of talk recently about botnets controlled through Twitter accounts. The other day I came across an interesting blog post by our colleagues at Sunbelt. Chet has also posted a post about a captured command Read more…

Share

Sophos iPhone app sneak preview

Sophos iPhone app sneak preview

I hate to be a tease, but I thought some of you might be interested in a sneak preview of some new software we have coming out soon. The-powers-that-be won't let me say very much, so I'll let this picture Read more…

Share

Cybercrime underworld ISP 3FN is permanently shut down

Image (1) 3fn-logo.jpg for post 16612

An ISP which made its fortune largely by hosting content for malware authors, identity thieves, child pornographers and spammers, has been permanently dismantled and put out of business by authorities in the United States. San Jose-based 3FN.net (which used a Read more…

Share

British Home Secretary reconsiders extradition of Gary McKinnon

Image (1) theresa-may.jpg for post 16607

The UK's recent change of government will no doubt be getting the thumbs-up from supporters of computer hacker Gary McKinnon, after it was announced that the new Home Secretary, Theresa May, has put his extradition to the United States on Read more…

Share

Daily Telegraph website hit by Canadian Pharmacy spammers

Image (1) telegraph-spam.jpg for post 16600

Spammers have created their own blogs on the website of one of the UK's leading newspapers, and stuffed them with adverts to purchase drugs from Canadian Pharmacy stores. A post by blogger Paul Carpenter, an SEO consultant, brought my attention Read more…

Share

Watch_video.zip malware attack

Image (1) porn-subject-lines.jpg for post 16595

Heads up folks! There's a major new malware attack happening right now. Email messages are being spammed out with a variety of lurid x-rated subject lines. Attached to the emails is a file called watch_video.zip, which contains malware that (at Read more…

Share

60% of Facebook users consider quitting over privacy

Image (1) facebook-quit-poll.jpg for post 16589

Over the last few days we've been running an online poll asking Facebook users if privacy concerns might make them consider quitting the service. The votes have now been counted, and reveal the extent of members' concerns regarding the popular Read more…

Share

Embarrassing privacy flaw found on Facebook

Image (1) facebook-patch.jpg for post 16584

A researcher has found a critical security flaw on Facebook that could be exploited by hackers to expose sensitive information about users. M J Keith, a senior security analyst with security firm Alert Logic, discovered the vulnerability which could lead Read more…

Share

Apple Java update, MS advisory and SSCC 10

Image (1) rtfmmug-250.jpg for post 2806

Apple has released an update today for OS X 10.5 and 10.6. Java 1.6 update 18 patches more than 28 vulnerabilities in the Oracle (Man that sounds weird) Java runtime environment. In this case Apple only took five months to Read more…

Share