Botnet

(get it in RSS or Atom)

Monday review - the hot 20 stories of the week

dow-250

It's weekly roundup time!

Here's all the great stuff we've written in the past seven days.

The data breach apocalypse that wasn't - 60 Sec Security [VIDEO]

Malware, spam and hacking - and not all bad news, either!

Watch 60 Second Security for Aug 9, 2014...

SSCC 159 - What can we learn from the "honeybot"? [PODCAST]

For your listening pleasure!

Here's this week's episode of the Sophos Security Chet Chat podcast...

1.2 billion logins scooped up by CyberVor hacking crew - what you need to do

sql-billions-250x250

Hackers have amassed a vast collection of stolen data, including 1.2 billion unique username/password pairs, by compromising over 420,000 websites using SQL injection techniques. This data haul may yet turn out to be a 'Heartbleed' moment for website owners who assume their sites are too small to be of interest to hackers.

How to send 5 million spam emails without even noticing

spam-250

Before you read the article, see if you can guess, to the nearest million, how many spams a 10,000-strong botnet might realistically send each week.

Commit yourself first, and then read the story of the SophosLabs "honeybot"!

Hacking, spamming, rogue SMSes and browsers - 60 Sec Security [VIDEO]

The week's security news, turned into an entertaining lesson, turned into a 1-min video...

60 Sec Security, 26 July 2014

SSCC 157 - Routers, Browsers, Zombies and Sysadmins [PODCAST]

Here it is...this week's Chet Chat security podcast.

In this episode: fixing routers, trusting browsers, killing zombies and showing TLC to sysadmins.

It's all about trust! 60 Sec Security [VIDEO]

Watch 60 Second Security for 19 July 2014 - it's all about trust!

Notorious Shylock banking malware taken out by law enforcement

fire-globe-250

Law enforcement action led by the National Crime Agency (NCA) in the UK has knocked out the infrastructure of a banking malware known as Shylock, because of excerpts from Shakespeare's Merchant of Venice hidden in its code.

Here's how to check to make sure you weren't among the more than 30,000 PCs that were infected.

SSCC 156 - Warbiking in Manhattan, hubris for Google, and how less can be more [PODCAST]

Sophos experts Chester Wisniewski and Paul Ducklin are back with this week's security podcast, turning plain old news into advice you can use.

"Gameover" malware revival - is it really up from the canvas?

newgoz-ko-250

Is the recent re-appearance of the Gameover malware a flash in the pan, or part of a concerted effort at reviving the threat?

What do we need to do to knock it out altogether?

"Gameover" malware returns from the dead...

In early June 2014, a internationally co-ordinated law enforcement effort against the criminals behind the infamous Gameover malware pretty much wiped out their botnet altogether.

Bad news - it looks as though Gameover is back...

Microsoft takes down No-IP DNS domains in cybercrime fight - right or wrong? [POLL]

noip-250

Vote in our poll!

Was Microsoft's takeover of 23 of another company's domain names a justifiable step in dealing with cybercrime, or a disruptive step too far?

Gameover and CryptoLocker revisited - the important lessons we can learn

gocl-robot-250

Which is worse - Gameover or CryptoLocker?

What can we learn from the recent US-led takedown of this notorious crimeware?

More importantly, what advice should we be passing on to other people?

SSCC 150 - TrueCrypt, Gameover, CryptoLocker and whither mobile malware? [PODCAST]

sscc150-thumb-250

This week, Chet and Duck dig into the bafflement of the disappearing TrueCrypt encryption software: did it jump, or was it pushed?

They also look at the takedown of Gameover and CryptoLocker, and look into what we can learn from ten years of mobile malware.

Has CryptoLocker been cracked? Is Gameover over?

bog-250

Gameover is one of the most notorious botnets of recent times. And CryptoLocker is the Big Daddy of the ransomware scene.

But a team of global law enforcement agencies has taken them on...and YOU can help them win!

SSCC 148 - Cloud privacy policies not related to data security [PODCAST]

sscc-148-250

The Chet Chat comes to you this week from Hanoi, Vietnam with special guest Sean Richmond from Sophos Australia.

This week they tackle the FBI's crackdown on the Blackshades malware, more flaws in Chip-and-PIN, the latest Apple updates, and the EFF's "Who has got your back" report.

The Dirty Dozen Spampionship: Who's who in the global spam-sending league?

spampionship-purp-250

It's once again time for our quarterly Spampionship charts.

We looked at the sending countries for all our spam in the first three months of 2014, and turned the figures into a League Table - the sort of league you *don't* want to win!

Zeus malware - nine charged with conspiracy to steal millions of dollars

US charges 9 with stealing millions of dollars with Zeus malware

The US Department of Justice (DOJ) has charged nine individuals over their alleged involvement in a criminal organisation that stole millions of dollars from victims' bank accounts.

Smucker's online store gets stuck in thieves' web

Smucker's online store gets stuck in thieves' web

The US jam and jelly maker is just the latest fly to get stuck in the same web that ensnared dozens of companies last year, including some of the world's largest data brokers and at least one credit card processor.