The Malicious Intent of the “Here You Have” Mail Worm, Part 2

Previously, we discussed the “Here You Have” mail attack and the associated malware, WORM_MEYLME.B. Today, let’s look into the backdoor payload, BKDR_BIFROSE.SMU. The “Here You Have” payload: A powerful backdoor Not all backdoor applications are created equal. As such, it can be said that the cybercriminals behind WORM_MEYLE.B deliberately opted to use a BIFROSE [...]

New Attack Disguised as DHL Parcel Delivery Notice

Some malware attacks are exceedingly clever and innovative, while others just rely on tried and true techniques that are fairly reliable no matter how much users are told to avoid them. AppRiver is reporting a new threat that falls into this latter category–a fake DHL shipping receipt designed with a malicious file attachment.

Read [...]

Beware Fake Microsoft Security Essentials

Microsoft Security Essentials is fake. Well, it is and it isn’t. Microsoft Security Essentials is a free antimalware protection program from Microsoft, but a new malware threat identified by security software vendor F-Secure is also masquerading as Microsoft Security Essentials. You want to avoid that one.

Read entire article

12-year-old finds critical Firefox flaw, earns $3,000 bounty

The security researcher who found and reported this critical buffer overflow and memory corruption vulnerability in Mozilla’s Firefox browser is none other than Alex Miller, a 12-year-old boy who earned a $3,000 bounty for his discovery.

Read entire article

[...]

The Malicious Intent of the “Here You Have” Mail Worm, Part 1

In early September, the “Here You Have” wave of spammed messages hit user inboxes. It was discussed in the Malware Blog in the following posts: Old Malware Out of Its Shell From Alicia to Africa to Anywhere Else: Possible Origin of the ‘Here you have’ Spam Campaign At that time, attention was focused on the [...]