Facebook Valentine’s Theme Leads to Malware

It’s never too early to get ready for Valentine’s day, it seems, even when it comes to malicious attacks. Recently, I came across a scam in Facebook that leverages the upcoming occasion. The said attack begins with a post on affected users’ wall inviting other users to install a Valentine’s theme into their Facebook profile. [...]

Post from: TrendLabs | Malware Blog – by Trend Micro

Facebook Valentine’s Theme Leads to Malware

Read entire article

How SCADA highlights the futility of finding security vulnerabilities

Pete Lindstrom argues that ‘irresponsible’ disclosure of security holes in SCADA systems could put human lives at risk and calls on the security research community to start thinking about the vulnerability problem in different ways.




Read entire article

Top APT Research of 2011 (That You Probably Haven’t Heard About)

Throughout 2011, I am sure that you have heard of the compromise of RSA, in which the stolen data regarding RSA’s Secure ID appears to have been used in subsequent attacks and that there were many more victims other than RSA. You’ve probably also head of ShadyRAT, which demonstrated the longevity of command and control infrastructure as [...]

Post from: TrendLabs | Malware Blog – by Trend Micro

Top APT Research of 2011 (That You Probably Haven’t Heard About)

Read entire article

Intego: 2011 offered bumper crop of Mac malware

One of Apple’s chief advantages in the personal computing market has been that its Mac computers have been relatively impervious to viruses and malware, at least when compared to Windows-based PCs. But that advantage may have been more difficult to maintain in 2011–at least, according to a new report from security firm Intego.

Read entire article

Malware Leveraging MIDI Remote Code Execution Vulnerability Found

Earlier today, we encountered a malware that exploits a recently (and publicly) disclosed vulnerability, the MIDI Remote Code Execution Vulnerability (CVE-2012-0003). The said vulnerability is triggered when Windows Multimedia Library in Windows Media Player (WMP) fails to handle a specially crafted MIDI file, consequently allowing remote attackers to execute arbitrary code. In the attack that we found, [...]

Post from: TrendLabs | Malware Blog – by Trend Micro

Malware Leveraging MIDI Remote Code Execution Vulnerability Found

Read entire article