Malware

(get it in RSS or Atom)

"Wire transfer canceled"? Watch out for spammed-out malware attack

"Wire transfer canceled"? Watch out for spammed-out malware attack

If you've received an email in your inbox telling you that your wire transfer has been cancelled, take care - as it's the latest attempt by online criminals to infect the general public's Windows computers.

Monday review - the hot 20 stories of the week

Monday review

Catch up with all the security news from the last seven days - it's weekly roundup time.

Google tightens up Play Store policy, officially bans "off-market" updates...

Google has made a number of changes to its Android Play Store ecosystem recently.

There's now a rudimentary anti-virus provided with the OS, a ban on ad blockers, and, most recently, an official policy on sneaky "off-market" updates...

Mac malware found in malformed Word documents - is China to blame?

Mac malware found in malformed Word documents - is China to blame?

Minority groups in China appear to have been targeted by a Mac malware attack, delivered via boobytrapped Word documents.

Who could possibly be interested in targeting their computers?

The Redkit malware exploit gang has a message for security blogger Brian Krebs

The Redkit malware exploit gang has a message for security blogger Brian Krebs

Award-winning security blogger Brian Krebs is loved by everyone on the internet... apart from the criminals.

Find out what they're saying about him in their latest version of the Redkit exploit kit.

New incoming fax message is actually malware - be on your guard!

Example of junk fax

Computer users are warned to be on the lookout for messages in their email inbox, claiming to be an incoming fax.

Beware Twitter "password check" sites - there are fakes, and there are fake fakes!

fakefake-250

After a widely publicised hack or data breach, you'll often find "password check" sites springing up.

Some of them are legitimate, but other password check sites are as bogus as they sound on the surface...

SSCC 107 - Hostgator, Safari, Java, pwning planes with Android, and Facebook Home [PODCAST]

img-107-250

Here's the latest episode in the popular "Chet Chat" series.

Join Chet and Duck as they discuss what we can learn from recent security news in this quarter-hour podcast.

Monday review - the hot 22 stories of the week

Monday review - the hot stories of the week

In case you missed any recent stories, here's everything we wrote in the last seven days.

Anatomy of a phish - how to spot a Man-in-the-Middle attack, and other security tips

Even if you are used to phishing scams, it still pays to take the occasional look at a scam campaign, just to remind yourself not to let your guard down.

Paul Ducklin digs into a recent "tax refund" phish with an added Man-in-the-Middle attack...

How do you know if an anti-virus test is any good?

The truth behind antivirus comparative tests: valuable or useless?

Anti-virus tests are a bit of a minefield. Why are they all different? How do you know who to believe? What makes one test better than another, or are they all equally brilliant/useless/biased/random? John Hawes takes a look.

Warning! Hackers are exploiting Texas explosion news to spread malware

Warning! Hackers are exploiting Waco explosion news to spread malware

Once again, cybercriminals are leaping at the opportunity to take advantage of breaking news stories to spread malware.

Sick malware authors exploit Boston Marathon bombing with Trojan attack

Sick malware authors exploit Boston Marathon bombing with Trojan attack

With sick inevitability, cybercriminals have exploited interest in the breaking news story of the explosions at the Boston Marathon by spreading malware.

Monday review - the hot 21 stories of the week

Monday review

In case you missed anything, here's everything we wrote in the past seven days.

WordPress blogs and more under global attack - check your passwords now!

If you have a web service that supports remote users, you will know that malevolent login attempts are an everyday occurrence.

But hosting providers worldwide are reporting an onslaught at well above average levels...

When is a password not a password? When Excel sees "VelvetSweatshop" [VIDEO]

When is a password not a password? When Excel sees VelvetSweatshop

Malware researcher Paul Baccas reveals how an Excel spreadsheet using the password "VelvetSweatshop" could be designed to put your computer at risk.

Mali offers free .ML domains to anyone. What could *possibly* go wrong?

Mali offers free .ML domains to anyone. What could *possibly* go wrong?

It's good news if you're a cybercriminal.

But probably not something that's going to do much good for one of the world's poorest countries.

Ukrainian and Russian police arrest banking Trojan masterminds

shutterstock_UkrainePoliceCap250

Ukrainian newspaper Kommersant reported on a joint operation by the Ukrainian and Russian federal police arresting 20 people allegedly behind the Carberp banking malware. Is this a sign that we may see more arrests by the FSB and SBU in the future?

Windows XP death watch: 365 days remaining

Windows XP death watch: 365 days remaining

On April 8th, 2014, Microsoft will terminate Extended Support for Windows XP.

That means no more security updates. Be prepared and upgrade now.

German net users targeted by Skype email malware attack

German net users targeted by Skype email malware attack

SophosLabs has intercepted a malware attack, hitting many German internet users today, disguised as an email from Skype with the title "Wir haben Ihre Bestellung geliefert".