Malware Leveraging MIDI Remote Code Execution Vulnerability Found

Earlier today, we encountered a malware that exploits a recently (and publicly) disclosed vulnerability, the MIDI Remote Code Execution Vulnerability (CVE-2012-0003). The said vulnerability is triggered when Windows Multimedia Library in Windows Media Player (WMP) fails to handle a specially crafted MIDI file, consequently allowing remote attackers to execute arbitrary code. In the attack that we [...]

How Private Is My Online Information?

At a time when the web is flooded with user information and entire platforms are built and run on sharing just about every piece of information about oneself, you have to wonder, “Are we really living in the post-privacy era?” For 2012, we believe that the new social networking generation will redefine privacy. Our [...]

Towards A More Secure Industrial Control Systems Security Posture

ICS (Industrial Control Systems) Networks have been really big news lately, due to a spate of vulnerabilities, high-publicized breaches, and various other security concerns. ICS Networks are defined as networks or collections of networks that consist of elements that control and provide telemetry data on electromechanical components. Such components include valves, regulators, switches, and [...]

Tax Season Opens, Tax Spam Follows

The IRS officially kicked off the beginning of tax season in the US, and just right in time for it are the cybercriminals who are already taking advantage and using tax-related messages as a social engineering lure. We’ve recently spotted samples of spammed messages posing as a notice from Fidelity Investments, a well-known American financial [...]

The Ins and Outs of One-Click Billing Fraud

What is this “one-click billing fraud” (also “one-click fraud”) all about? Contrary to the name, you need more than just one click to become a victim. This type of attack primarily targets users who want to view adult videos. Users go either to video-sharing websites or adult blogs in order to watch adult videos online. [...]