Latest Articles

Adobe announces Reader X and Acrobat X editions

Adobe announces Reader X and Acrobat X editions

Adobe has announced the long-awaited sandboxed versions of their ubiquitous Adobe Reader and Adobe Acrobat applications, now branded as X. Brad Arkin, Adobe's Senior Director of Product Security and Privacy, first spoke with Sophos about Adobe's plans to better secure Read more…

Share

Facebook faces new privacy problems: top apps leak your data

Facebook faces new privacy problems: top apps leak your data

October 18th's Wall Street Journal is reporting that all of the top ten applications on Facebook are breaching Facebook's privacy policy. To Facebook's credit, this time the problems are not entirely their fault, but this is yet another example of Read more…

Share

Privacy threats to dominate security landscape in 2011?

rPrivacy threats to dominate security landscape in 2011?

At Hack in the Box, we decided to have a bit of fun. My Sophos Malaysia colleagues purchased a veritable flotilla of rubber ducks - in traditional bathtime-duck yellow - and tricked me into an autograph session. Duck signing ducks, geddit?

Share

Stuxnet on the BBC World Service

BBC World Service

Earlier this week I appeared on "Digital Planet", a fun and friendly technology show broadcast every week on the BBC World Service and also available as a podcast. I made an appearance via Skype to discuss the Stuxnet worm, which Read more…

Share

Hack in the Box attack - presenter threatened with arrows

Hack in the Box attack - presenter threatened with arrows

Marco Slaviero, a presenter at Hack in the Box 2010 in Kuala Lumpur, Malaysia, had a narrow escape yesterday after a number of outsized presentation arrows ganged up and threatened to attack him during his talk. Powerpoint was initially suspected.

Share

Sophos Security Chet Chat 30 and VB 2010 roundup

Sophos Security Chet Chat 30 and VB 2010 roundup

There was a lot of security news this week as Michael Argast and I went into our Vancouver studio to record Chet Chat 30. I was on vacation at the beginning of the week, so it is a bit longer Read more…

Share

USA, your poorly protected PCs are polluting the world with spam

Spam around the globe

Latest estimates reported in the press suggest that more than 2.2 million PCs based in the USA were hijacked by cybercriminals in the first half of 2010, and used as part of a botnet. And what's one of the principal Read more…

Share

Hack in the Box - DNS expert swings a punch

Hack in the Box - DNS expert swings a punch

I'm currently in Kuala Lumpur, capital of Malaysia, for HITB - the 8th Hack in the Box conference.

HITB prides itself on being a "deep knowledge" security event - no commercial speeches from vendors and no way to buy a speaking slot.

Share

GCHQ chief talks of cyber attacks

GCHQ chief talks of cyber attacks

Iain Lobban, director of the UK Government's Communications Headquarters (better known as GCHQ), is making the headlines today after he spoke about the threat posed by internet attacks from cybercriminals and hostile nations. British government departments receive more than 20,000 Read more…

Share

Is Facebook's one-time password system safe?

Is Facebook's one-time password safe?

Facebook announced a new feature yesterday, which claims to give you another way to keep your social networking account secure. A one-time password is said by Facebook to: "..make it safer to use public computers in places like hotels, cafes Read more…

Share

Stock Price vs. Spam Keywords

Stock price versus spam keywords

As noted by Bloomberg on 25 September, Apple was valued at $267 billion, ahead of PetroChina's $265.5 billion, becoming the world's second-largest company in terms of market value. Furthermore, back to May this year, Apple had surpassed Microsoft in market Read more…

Share

October Patch Tuesday

danger-zone

Patch Tuesday has arrived again and this time we have a set of ten updates.  Nine from Microsoft and one from Adobe. Nine of these potentially allow remote code execution and the tenth involves information disclosure. For the full list Read more…

Share

Free talk about social networking threats in Oxford

Talking social networking threats in Oxford

If you're in Oxford this Thursday evening, and kicking your heels for something to do, why not learn about cybercrime on social networks? I'm honoured to have been invited by the Oxfordshire chapter of the British Computer Society, to present Read more…

Share

Is it time for Facebook to learn a security lesson from Apple?

iPhone and Facebook

The Apple iPhone and Facebook - both have been incredible phenomenons, capturing the imagination of millions of people and rewriting the rules when it comes to technology today. Both have been extraordinarily successful, but when it comes to security it's Read more…

Share

Sophos awarded VB100 for Windows Server 2003 protection

VB October 2010

Those charming people at Virus Bulletin magazine have published their latest edition, hot on the heels of their successful conference in Vancouver. Of particular interest to us are the results of Virus Bulletin's most recent comparative test of anti-malware products. Read more…

Share

Malware abusing digital signatures: VB2010 presentation highlights

vb2010

I recently presented my paper Want My Autograph? The use and abuse of digital signatures by malware at Virus Bulletin 2010. I will refrain from delving into the gory details of digital signatures heuristics that strongly indicate malware -- those Read more…

Share

Stuxnet begone! Can we worry about EFTPOS now, please?

Image (2) circuit-board.jpg for post 36136

Stuxnet, the malware story which refuses to die, has dominated recent security media coverage. Firstly, Stuxnet targets the Programmable Logic Controllers (PLCs) used in plants and factories. Secondly, Stuxnet's prevalence was apparently greatest in Iran, giving hyperbolistas plenty to dine out on.

Share

Can you see who viewed your Facebook profile? Scammers would like you to think so

Can you see who viewed your profile on Facebook?

Earlier this year I blogged about how scammers were abusing Facebook users' curiousity about who might be viewing their profile. Surprise surprise, they're at it again. Right now we're seeing messages spreading across Facebook claiming to have found a way Read more…

Share

How not to measure PC security tools

How not to measure PC security tools

There's an interesting article by Mark Ward on the BBC News website today, where security firm Prevx (you'll remember them from their part in the BBC Click botnet fiasco) proposes a new way of measuring the effectiveness of anti-virus software. Read more…

Share

OMG? Not txtin again? Beware Facebook rogue applications

OMG! Not txtin again? Facebook scam

Over the weekend I saw a large number of Facebook users were searching my blog for information about a Facebook scam that disguises itself as a status update saying the user will "never text again". A couple of times in Read more…

Share