Latest Articles

How to protect yourself from Facebook Places

How to protect yourself from Facebook Places

After earlier roll-outs in the USA and Japan, Facebook has now opened up its location-sharing service in the UK. In a breakfast briefing in London, Facebook explained that the new service would make it easier for users to share where Read more…

Share

License to code: should security companies be the artiber of good or bad code

License to code

None of us would want to be operated on by an unlicensed surgeon so why should we put trust in software applications written by unlicensed, uncertified programmers? Apple have seemingly taken the high-road by requiring programmers to register as Apple Read more…

Share

Somerset County Council website victim of Blackhat SEO and malware injection

Somerset County Council website victim of Blackhat SEO and malware injection

Sophos users over the past few months may have noticed that they haven't been able to access parts of the Somerset Information Exchange (SiX) due to instances of Mal/Badsrc-C on the site. The problems for the SiX microsite, hosted on Read more…

Share

Infected Phish targeting Commonwealth Bank of Australia

Image (1) infected-phish.jpg for post 20060

This week we've seen more phishing spam targeting the Commonwealth Bank of Australia, an institution that many scammers have aimed at in the past. The emails have a subject of "Update your Commonwealth Bank" and look like this: The text Read more…

Share

September 2010 Patch Tuesday

September Patch Tuesday

There are 9 new releases in this month's Microsoft patch release. Four of these are ranked by Microsoft as Critical; due to lack of exploitation in the wild, none have been ranked higher than Medium by SophosLabs. Today also brings Read more…

Share

Free Facebook Credits? It's another scam spreading virally

Free Facebook Credits? It's another scam spreading virally

Scam messages appearing to offer free Facebook credits are being seen on Facebook. Here's an example: Want Free Facebook credits go to <link> Free Faceebook credits Want free facebook credits? (Note that they spell Facebook incorrectly in many of the Read more…

Share

Adobe races to patch zero-day vulnerability in Flash Player

Adobe Flash

Adobe has issued a security advisory about an as-yet unpatched vulnerability in its popular Flash Player software, affecting users of Windows, Mac, Linux, Solaris and even Google Android. The critical security hole could allow an attacker to take control of Read more…

Share

Facebook burglary gang suspects arrested by police

Image (2) facebook-burglar-suspects.jpg for post 17650

Police in Nashua, New Hampshire, have arrested a group of men suspected of being part of a burglary ring that targeted Facebook users who had reported they were away from home. According to local news reports, between $100,000 to $200,000 Read more…

Share

No certificate for you! Verisign revokes cert from malware fiends

Image (1) crlpdfa-350.png for post 3503

I spent some time last week looking into the digital signature involved with the recent zero day malware targeting Adobe Reader. Similar to the Stuxnet situation, Verisign has revoked the signing certificate used to sign the payload associated with this Read more…

Share

Digging Deeper on the TechCrunch Zbot

Digging Deeper on the TechCrunch Zbot

Last week the website belonging to TechCrunch Europe had malicious code planted on it, the payload of which was a variant of Zbot - Troj/Zbot-YP. There are several interesting aspects of this variant that are worth exploring in a little Read more…

Share

'Here you have' virus interest exploited by YouTube scammers

'Here you have' virus interest exploited by YouTube scammers

The big news on the security front at the end of the working week was the widely-reported "Here you have" virus which arrived in inboxes with a waft of nostalgia, in the style of old-school mass-mailing malware. What has brought Read more…

Share

Oz election outcome – I was right!

Image (1) 1300th-goal.jpg for post 1606

The dust has finally settled on the Australian federal election. As everyone ought to know, the previous ruling party, and the previous Prime Minister, managed to cling somewhat precariously to power. They didn't really win, since they ended up with Read more…

Share

Google Instant - reaching further into your subconscious?

Guest blog: Google Instant - reaching further into your subconscious?

Rich Baldry looks after some of our web protection products here at Sophos, and he's been thinking about some of the possible implications of Google Instant. Over to you Rich.. So, Google has announced Google Instant - a new enhancement Read more…

Share

'Here you have' virus strikes email inboxes

Here you have virus strikes email inboxes

If you were reading the SophosLabs blog overnight you'll have seen Boris Lau's report of a mass-mailing worm that has been reported widely. Email messages with the subject line "Here you have" are pretending to point to documents or free Read more…

Share

The "Here you have" worm

The "Here you have" worm

Just a quick update that we are seeing reports of an old-school mass-mailing worm doing the rounds currently. The emails it sends contain a link that pretends to point to a PDF, but it in fact points to a VisualBasic Read more…

Share

Name Sophos's new blog, win an iPod Touch

Name Sophos's new blog, win an iPod Touch

It's competition time! We're all very excited here at Sophos Towers because next month we hope to roll out a whole new blog for you, our faithful readers. We'll be bringing together our star bloggers (Chet and Duck, and yours Read more…

Share

Cheerleaders Gone Wild clickjacking spreads virally across Facebook

Cheerleaders gone wild, spread virally on Facebook

We're seeing many messages right now being posted from the accounts of Facebook users saying: Cheerleaders gone wild - have to see this accompanied by the image of a midriff-baring cheerleader carrying two pom-poms. If that's enough to tempt you Read more…

Share

APSA10-02: BOPs and the Adobe 0-day

APSA10-02: BOPs and the Adobe 0-day

Just a quick update on the latest Adobe zero-day vulnerability (APSA10-02) that has come to light this week. You may well have already watched the video Chet posted yesterday. We have also published an advisory page for this vulnerability as Read more…

Share

Hacker behind $9 million RBS WorldPay ATM heist avoids Russian jail

cashmachine

Russian prosecutors have served a hacker with a six year suspended sentence after he admitted his involvement in a worldwide hack that withdrew $9 million from ATM cash machines. 29-year-old Viktor Pleshchuk, of St. Petersburg, Russia, received a reduced sentence, Read more…

Share

iOS 4.1: Critical security update for iPhone and iPod Touch users

iOS 4.1: Critical security update for iPhone and iPod Touch users

Apple has released iOS 4.1, an updated version of its mobile operating system for the iPhone and iPod Touch. New features vary depending on which device you own, and how old it is, but some folks will benefit from better Read more…

Share