ZeuS Source Code Already in the Wild

For about two weeks now, the ZeuS source code has been making its way around to different people. Many people have offered it up for sale on multiple forums, but lots of times it is only pieces of the code and not everything. There are also conflicting reports about important pieces of the code [...]

Man-in-the-Browser attacks target the enterprise

With firewalls, antivirus and other security mechanisms protecting corporate networks, how do attackers manage to penetrate enterprise computer systems? Simply by exploiting the weakest link in the security chain. One of the newest methods is tunnelling in via employees’ browsers using an attack known as “Man-in-the-Browser” (MitB).

Read entire article

LizaMoon, Etc. SQL Injection Attack Still On-going

We’re currently monitoring a still-ongoing mass compromise involving a great number of websites. The compromised sites have been injected with a malicious script that triggers redirects to certain URLs which lead to malware such as FAKEAV. Based on Google searches, there is no common denominator in terms of the industry to which the compromised [...]