Facebook password-reset spam is Bredolab botnet attack

October 27th, 2009 Posted by Ryan Naraine @ 8:27 amCategories:Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Data theft, Denial of Service (DoS), Facebook, Locally Running Web Servers, Malware, Microsoft, Passwords, Phishing, Social Networking Applications, Spam and Phishing, Spyware and Adware, Viruses and WormsTags:Facebook, Spam, Attack, Virus Hunter, Cyberthreats, E-mail, Identity Theft, Security, Viruses And [...]

Gawker Media tricked into featuring malicious Suzuki ads

A group of cybercriminals have successfully managed to trick Gawker’s ad sales team into featuring malicious ads serving Adobe exploits (CVE-2008-2992; CVE-2009-0927) and scareware, by impersonating a legitimate ad agency inquiring about an upcoming Suzuki ad campaign. According to Gawker Media, the malware distributors were one of the most convincing ones they’ve seen, with [...]

Malware ads served from Gizmodo blog

October 27th, 2009 Posted by Ryan Naraine @ 10:04 amCategories:Adobe, Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Facebook, Flash, Locally Running Web Servers, Malware, Passwords, Social Networking Applications, Spam and Phishing, Spyware and AdwareTags:Advertisement, Blog, Malware, Gizmodo, Ryan Naraine[ UPDATE:Dancho has more details on this attack ]Popular gadget blog Gizmodo has acknowledged falling victim [...]

IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security

Have you ever noticed how security often takes a back-seat when trying something new? When I am trying out a protocol out for the first time I barely skim the Security Considerations section of the RFC. Just the same, as more of us start experimenting with IPv6, the use of tunneling protocols is likely to [...]

Spoofed Contract Carries Malware

Trend Micro researchers found spammed messages with a ZIP file attachment that contains a malware. It bears the subject, “Contract of Settlements” and purports to come from LSM Company. It informs users to open and check the attached file that holds a contract, which in actual is an executable file (contract_1.exe) detected by Trend Micro [...]