Fake antivirus peddlers helped by Microsoft, IRS

Just weeks after the U.S. Federal Trade Commission shut down two companies accused of selling fake antivirus software, a new player has moved into the market, aided by glitches in the Microsoft and U.S. Internal Revenue Service Web sites.

Read entire article

Two Credit Unions Phished

The Trend Micro Content Security Team discovered two phishing URLs just within hours of each other that use legitimate credit unions to trick unknowing users into giving out confidential information. Here’s a screenshot of a page that spoofs the O Bee Credit Union:

Figure 1. Sample phishing page. The page is hosted in the [...]

Speed camera ‘pimping’ attack highlights public identity weaknesses

In a brilliant physical-world example of what happens when too much value is placed upon open identification systems for determining reputation, a group of high school students are setting off speeding enforcement cameras using fake license plates belonging to their enemies.

According to an article in the D.C. area Montgomery County Sentinel, high school [...]

Microsoft confirms critical SQL Server vulnerability

Microsoft late Monday issued a pre-patch advisory confirming a remote code execution vulnerability affecting its SQL Server line. The vulnerability, publicly disclosed with exploit code more than two weeks ago, affects Microsoft SQL Server 2000, Microsoft SQL Server 2005, Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL [...]

PlayStation Home virtual world hacked

Hackers are using a combination of DNS redirection, software vulnerabilities and the open-source Apache Web server to exploit holes in Sony’s new PlayStation Home virtual world, according to a Telegraph report. The hack is allowing developers to customize their PlayStation Home experience beyond the options provided by Sony but there’s a worrysome component [...]

Read [...]