Microsoft Releases Out of Band Update Before Year Ends

Microsoft has released an advisory alerting its users about a critical vulnerability in ASP.NET (CVE-2011-3414). An attacker could potentially bring down a server (Denial of Service) with specially crafted requests. Given that all versions of ASP.NET are vulnerable, its exposure is pretty big. This advisory was in response to a public advisory presented in [...]

Christmas Theme for Facebook Profile Leads to Malspam

Attacks that use the holidays as a social engineering lure are starting to pour in as the Christmas day draws near. We recently found a page on Facebook that offers a Christmas theme on one’s profile. The page leads to a malware that comes in the form of browser plugin. Once users click the [...]

2011 in Review: Security Wins

…if there’s actual evidence, I have no doubt that law enforcement will act. However, I think this is highly unlikely. —Konstantin Poltev (spokesman of Esthost/Rove Digital), October 13, 2008 In the past, some cybercriminals have been so brazen that they publicly declared chances they will ever be caught are slim. Today, however, it is [...]

Season’s Warnings: iPhone 4S Scam and Other Holiday Threats

Looking for cheaper iPhone 4S this holiday season? Be wary, because cybercriminals can trick you into giving out your online financial credentials. We’ve recently found a phishing attack that specifically targets users who are out to purchase an iPhone 4S through eBay. The attack involves domains that display replicated eBay posts for iPhone 4S units. [...]

New “Unfollowed You” Scam Hits Twitter Trending Topics

Twitter‘s list of trending topics appears to have been hit hard by another variant of the familiar “see who unfollowed you” scam: Significant numbers of Tweets are being sent out that contain the above message: saying that a certain number of people have unfollowed them, and to find out who unfollowed you, click on the [...]