Bogus ‘MS Update’ Comes With Malicious Attachment

Just in time for Microsoft’s most recent security advisory, spammers are now distributing yet another fake Microsoft Update. It arrives with the subject Security Update for OS Microsoft Windows and purports to come from the Microsoft Official Update Center. It even includes a Pretty Good Privacy (PGP) Signature block to give it more authenticity. [...]

Debate around ‘partial disclosure’ heats up

There are many ways of telling the world about a security vulnerability. A vulnerability can be announced without telling the vendor, it can be announced after giving the vendor a period of time to fix the issue, or it may just be circulated amongst the underground without ever coming to the surface. Over [...]

[...]

Yoggie Announces Gatekeeper Pico, Gatekeeper Card Pro for Macs

Yoggie Announces Gatekeeper Pico, Gatekeeper Card Pro for Macs October 13th, 2008 Yoggie Security Systems today launched the Gatekeeper Pico for Mac and Gatekeeper Card Pro for Mac, the “world’s first miniature hardware internet security devices for MacBooks and Mac desktop computers”. The devices provide 12 internet security applications on a dedicated hardware. Security [...]

‘Bad Blog’ Can Give Facebook Users More Than a Bad Name

If you think a derogatory blog about you is bad, the real reason is worse than you think. Recently, another fake message containing a link to a malware was reportedly being spammed to friends of compromised Facebook accounts. The message looks something like this: {Friend’s name}, have you heard about that blog that was about [...]

Yahoo! Marketing Gets Phished

Advertisers beware! Trend Micro researchers recently discovered a phishing attack that targets Yahoo! Search Marketing users. A phishing email that pretends to help update the recipient’s account is spammed to users, hoping to convince them into giving out account credentials. Screenshots below:

Figure 1: Spammed phishing email containing link to phishing page

Figure 2: Phishing [...]