Legal concerns stop researchers from disrupting the Storm Worm botnet

What if security researchers were able to disrupt the leftovers of the Storm Worm botnet thanks to a flaw in its communication model allowing them to redirect infected hosts and eventually disinfect them, but fearing legal action have their hands tied? At the 25th Chaos Communication Congress, which took place in December, 2008, German [...]

GoDaddy hit by a DDoS attack

Domain name registrar and web hosting provider GoDaddy.com, was hit by a DDoS attack on Wednesday affecting thousands of its shared hosting customers for several hours. GoDaddy’s Communications Manager Nick Fuller confirmed the attack originally speculated to be an “outage”, and responded to several questions about it. Q: Was Wednesday’s GoDaddy.com “outage” an actual [...]

Security Policy for Dummies – how to avoid WORM_DOWNAD infection

Quite a few Security Websites and Media outlets have reported on the current wave of WORM_DOWNAD.AD detections over the last few weeks. And last weekend seemed to be a busy time for the worm infecting a considerable number of machines.

Whats noteworthy about this particular beastie is not only the scale of the [...]

Don’t be Fooled by Obama Inauguration Scams

Barack Obama’s campaign and eventual election to the United States presidency proved an excellent opportunity for cybercriminals in their malicious operations. News about the president-elect was a popular, and most of the time effective, social engineering technique used to trick unknowing Web users into downloading and installing malicious files in their PCs. Web threats that [...]

Phishing without bait: The in-session password theft attack

Skilled identity thieves can pilfer user names, passwords and other sensitive data for banking sites without using e-mail lures and other other social engineering tactics. According to a security advisory from Trusteer, hackers can launch what is described as “in-session phishing attacks” using pop-up messages during an active browser session.   The attack technique is somewhat [...]