SpyEye/ZeuS Toolkit v1.3.05 Beta Part 2

Since our previous blog post, we continued to investigate whether or not SpyEye 1.3.x is indeed the result of the ZeuS-SpyEye merger. So far, we realized that the included documentation doesn’t say much about ZeuS. It only compared the behaviors of several options/configurations of the two malware families. At present, we have only been able to identify three different [...]

From RSA 2011: Adobe Exploits, ZeusiLeaks, and Safe Browsing

I very recently attended the RSA Conference along with my colleagues in San Francisco. Like my colleague Marco who shared some of his key takeaways from the conference, I was able to learn a lot from the presentations. Below are a few of the topics I found particularly interesting. Adobe—Evaluating the World’s Most Exploited Software I [...]

From RSA 2011: Last Nail in the Coffin for Signature-Based AV

For the last two decades, the RSA Conference has enabled some of the best minds in the security industry to gather and engage in valuable discussions. For engineers like me, however, one goes to security conferences to watch and soak up the industry talk and see real, compelling security issues as they are inspected [...]

The country of Facebook recognizes civil unions

The 600 million user social networking behemoth made a small change to its ‘Relationship Status’ drop down box, and in doing so recognized ‘In a civil union’ and ‘In a domestic partnership’ as valid choices in the way one can report their personal situation on the site.

Read entire article

[...]

Microsoft confirms Windows BROWSER protocol zero-day

A security researcher has released proof-of-concept code for an unpatched security vulnerability affecting all versions of Windows, prompting a warning from Microsoft that remote code execution attacks are theoretically possible.

Read entire article

[...]