Malware

Google using custom malware scanner for Android apps

February 02, 2012

Google appears to be on a mission to dispel the public perception that its Android Market has become a prime vector for malicious activity.
 

U.K. MPs bite the cyber bullet...

David Harley, ESET senior research fellow • February 02, 2012

The Science and Technology Committee seems to be taking malware and cyber crime seriously.
 

Indiana University hospital hacked to steal data

February 01, 2012

Malware may have allowed attackers to make off with the personal information of thousands of people connected to Indiana University Health Goshen Hospital.
 

Twitter acquires web malware fighter Dasient

January 24, 2012

Twitter, a hotbed of malware due to its extreme popularity, has made one of its first-ever security acquisitions with the purchase of Dasient.
 

The five new laws of anti-malware

Zulfikar Ramzan, chief scientist, Sourcefire • January 23, 2012

Today, the best overall security solution includes technologies that can help you quickly respond to an inevitable attack.
 

Campus relief: Kilgore College and Viewfinity

January 20, 2012

A community college in Texas found a tool that enabled it to fend off viruses while coming into compliance, reports Greg Masters.
 

DoD ID cards under attack

January 18, 2012

The ID cards that every DoD employee uses to access networks across the entire bureau have fallen victim to malware.
 

Retrophitted Retrophish

David Harley, ESET senior research fellow • January 11, 2012

Malware that uses US-CERT and the Anti-Phishing Working Group to "legitimize" itself.
 

Chrome adds malware download warning functionality

January 09, 2012

A new beta version of the Google Chrome browser contains malware download protection.
 

Spam drop, but targeted attack rise, is key 2011 takeaway

December 20, 2011

Spam volume dropped dramatically from 379 billion messages daily in August 2010 to 124 billion this November, according to Cisco, as crooks opted for more pinpointed attacks that could fly under the radar.
 

Yahoo Messenger exploit enables status message hijacking

December 05, 2011

A newly discovered zero-day exploit against Yahoo Messenger can allow an attacker to hijack users' status updates, according to researchers at anti-virus firm BitDefender.
 

New Java exploit one of many impacting firms

December 01, 2011

A new exploit, which has made its way into the Metasploit framework, underscores the danger posed by Java vulnerabilities, which are responsible for many of today's enterprise malware threats.
 

Game play: A case study in security

December 01, 2011

It's not all fun and games at Brady Distribution Co., a supplier of arcade entertainment, especially when malware and DDoS attacks are involved. Learn how the organization fought against the threat.
 

Crooks using Zeus in new Facebook attacks

November 30, 2011

Variants of the Zeus trojan are being used in new Facebook and banking heists, security researchers and law enforcement are warning.
 

Bug allows HP printers to be remotely hacked, set on fire

November 29, 2011

HP LaserJet printers do not validate the origin of remote firmware updates before applying them, meaning anyone could potentially reprogram them to access a corporate network -- or even light them on fire.
 

Most spam subject lines contain fake order, ticket numbers

November 21, 2011

Most spam messages sent in recent days have been delivered with subject lines containing fake order or ticket numbers, delivery invoices, payment notices or tax information, according to researchers from security firm Websense.
 

ACH debit transfer emails leading to malware

November 10, 2011

Attackers have been circulating a trojan via email messages with subjects such as "ACH payroll payment was not accepted by Central Trust and Savings Bank."
 

Part Two: Duqu: father, son, or unholy ghost of Stuxnet?

Jeremy Sparks, Robert M. Lee, and Paul Brandau, cyberspace officers November 09, 2011

Three U.S. Air Force information security experts, independent of their role in the military, studied the Duqu trojan, and you might be surprised by what they found. This is the second article in a two-part series that examines the sophisticated threat that everyone is talking about.
 

Microsoft issues workaround for Duqu malware

November 04, 2011

Microsoft issued a temporary fix for a vulnerability in the Windows kernel used to spread Duqu, the so-called "son of Stuxnet" trojan.
 

The virus problem is worse than you think

Dan Emory, leader, information assurance practice, TKC Global November 03, 2011

With record numbers of threats and the increasing inability to detect them through traditional means, the time is now for the anti-virus industry to reinvent itself.
 

Duqu trojan spreads through 0-day Microsoft bug

November 01, 2011

A piece of malware that has drawn comparisons to the notorious Stuxnet worm is using an unknown Windows kernel vulnerability to infect its targets.
 

"DevilRobber" trojan targets Mac OS X for Bitcoins

October 31, 2011

The complex trojan aims to steal digital currency and use infected computers for Bitcoin mining.
 

Researcher finds way to send executable file on Facebook

October 28, 2011

Researchers have discovered a way to evade Facebook security controls to deliver a message that could come outfitted with a malicious attachment.
 

Your security will fail, but is this the right attitude?

Sean Martin, founder, imsmartin consulting October 27, 2011

IT professionals wishing to protect their systems from sophisticated attacks are receiving mixed messages of how to combat the problem. Their confusion is understandable, but the most important takeaway message is to not accept failure.
 

New Mac OS X backdoor trojan "Tsunami" discovered

October 26, 2011

The so-called "Tsunami" backdoor trojan is derived from an older Linux family of backdoors around since at least 2002.
 

Trojan found on Japanese government computers

Darren Pauli, editor, SC Magazine, Australia/New Zealand October 26, 2011

Following an attack on a major Japanese defense contractor, the nation's government computers were targets in an ambush that sought to monitor and steal sensitive communications.
 

FCC to release free protection tool for small businesses

October 25, 2011

As small businesses increase their dependence on the internet, one federal agency is helping to pave the way for them to conduct secure operations.
 

Bug may enable remote code execution in Chrome

October 24, 2011

Google Chrome suffers from a security flaw that could allow an attacker to silently execute remote code on a target machine, but the tech giant doesn't view the issue as much of a threat.
 

Duqu underscores trouble AV industry has in stopping threats

October 21, 2011

The slowness by which an offspring of Stuxnet was discovered may be further proof that attackers have a significant leg up on the security community.
 

ASP.NET attacks growing in reach

Darren Pauli, editor, SC Magazine, Australia/New Zealand edition October 20, 2011

Another mass SQL injection attack, similar to "Liza Moon" from earlier this year, is impacting more than a million websites.