|
Biting the hand that feeds IT Copyright: Copyright 2009, Situation Publishing Fri, 09 Jan 2009 01:54:16 +0100 Rolling the dice with the internet's futureAnalysis After being publicly outed issuing web credentials that were vulnerable to attacks that could allow criminals to spoof the encryption certificates of any website on the internet, VeriSign has issued assurances it has neutralized any real-world threat.… Thu, 08 Jan 2009 22:23:32 +0100 Taking a leakUS organisations lost even more sensitive data in a greater number of information security screw-ups last year, according to a new survey.… Thu, 08 Jan 2009 20:16:57 +0100 Website admins go AWOLOnce again, Major League Baseball's website has been caught serving ads designed to infect its considerable base of visitors with malware that trashes their machines.… Thu, 08 Jan 2009 17:28:47 +0100 Ukrainian boards Midnight ExpressA Ukrainian fraudster linked to the infamous TJX hack was sentenced to a 30 year prison sentence in Turkey on unrelated charges this week.… Thu, 08 Jan 2009 16:13:39 +0100 Skin-flick codec scams follow MSN Spaces abuseInternet scoundrels have begun abusing Google code hosting projects to distribute malware and promote smut. The assault follows a bout of the same kind of abuse against Microsoft's comparable MSN Spaces beta site dating back a year, net security firm McAfee reports.… Thu, 08 Jan 2009 15:30:03 +0100 Death and taxes and crimeThe Treasury has taken the unusual step of warning UK taxpayers of a phishing scam doing the rounds, which looks to ensnare frantic last-minute tax return filers.… Thu, 08 Jan 2009 12:48:02 +0100 Wiping-tech confidence collapse insanityWhich? Computing has lost faith in wiping technology and advised punters to take a hammer to hard discs they intend to get rid of. Reg readers and experts have slammed the advice as misguided and irresponsible.… Wed, 07 Jan 2009 23:28:03 +0100 The telltale cursorA British IT admin was ordered to pay more than £3,000 and given a three-months jail sentence after being accused of hacking into his former employer's computer system so he could install spyware and delete emails.… Wed, 07 Jan 2009 17:26:12 +0100 The pursuit of 'happiness'Miscreants broke into Twitter's admin system on Sunday night using a simple password guessing hack, it has emerged.… Wed, 07 Jan 2009 15:34:35 +0100 Survey highlights serious spoofabilityOne in seven digital certificates that stamp the authenticity of secure web sites use a vulnerable signature algorithm, according to a new survey. The shortcoming underlines the need to drop the insecure signing mechanism before its shortcomings are exploited in more convincing phishing attacks.… Wed, 07 Jan 2009 12:39:03 +0100 Unlocked and loadedA practical attack on Intel's trusted execution technology (TXT) is due to be demonstrated at a hacking conference next month.… Tue, 06 Jan 2009 21:32:33 +0100 Blasphemy on Jobsian high holy dayAs unfounded as they may be, reports of Steve Jobs's demise have spread to a live feed of Macworld Expo provided by Apple gossip site MacRumors after griefers managed to breach the website's security.… Tue, 06 Jan 2009 17:34:00 +0100 Beyoncé's not your friend, you berkBogus profiles on social networking website LinkedIn are punting malware to the credulous and starstruck.… Tue, 06 Jan 2009 16:41:49 +0100 Blogspot exploits and Gmail scams slammedGoogle has leapfrogged Microsoft to reach third place in a blacklist of spam-friendly ISPs and hosting firms, compiled by anti-spam organisation Spamhaus.org.… Tue, 06 Jan 2009 14:06:32 +0100 Cyberspace becomes battleground in Gaza conflictIsraeli military forces have reportedly hacked into a Hamas-run TV station to broadcast propaganda.… Tue, 06 Jan 2009 02:52:38 +0100 Attack of the TweatsMicro-blogging site Twitter had to temporarily suspend accounts belonging to Barack Obama, Britney Spears and other celebrities after they were hijacked by miscreants and used to spread scandalous and false information that appeared to come from their owners.… Mon, 05 Jan 2009 20:06:27 +0100 Curse of the ROMmonA researcher has discovered a way to reliably exploit a known security vulnerability in a wide class of Cisco System routers, a finding that for the first time allows attackers to hijack millions of devices with a single piece of code.… Fri, 02 Jan 2009 15:09:14 +0100 Not a word, so farComment Did you have a quiet Christmas? What about New Year? While New Years Eve is the busiest time for text messages, maybe you didn’t get any. And if you're a Nokia user, there may be a reason for that.… Fri, 02 Jan 2009 12:08:03 +0100 Old bug, new tricksMobile phone security vendors were rejoicing last night when it emerged that an obscure bug in an old version of the Symbian OS could allow an attacker to crash a target's mobile phone with a specially-formatted text message.… Wed, 31 Dec 2008 15:36:51 +0100 Security bypass attackConversations relayed through cordless household phones might be far easier to snoop upon than previously suspected.… Wed, 31 Dec 2008 12:43:51 +0100 The good, the bad and the uglySecurity pundits are fond are characterising personalties in information security with reference to Westerns - hence hackers wear either a "black hat" or a "white hat" like their cowboy counterparts.… Tue, 30 Dec 2008 15:18:20 +0100 PS3 fleet spoofs SSL certsResearchers have uncovered a weakness in the internet's digital certificate system that allows them to forge counterfeit credentials needed to impersonate virtually any website that relies on the widely used security measure.… Tue, 30 Dec 2008 11:41:31 +0100 Security pantomimeResearchers reckon a security bug in Windows Media Player creates a means for hackers to inject hostile code onto vulnerable systems. However Microsoft has denied this, saying that the bug only creates a means to crash the software without posing a more damaging security risk.… Tue, 30 Dec 2008 10:47:49 +0100 Mark your diaryFraudsters are using Google's Calendar service as a means to develop a new strain of phishing scam.… Mon, 29 Dec 2008 16:03:53 +0100 Payment processor buries bad newsRBS WorldPay belatedly admitted last week that hackers broke into its systems.… Mon, 29 Dec 2008 13:49:49 +0100 Sad demise of volunteer security communityUpdated CastleCops, the volunteer security community, has called it a day.… Mon, 29 Dec 2008 12:32:28 +0100 Snafu highlights wider trust problemSecurity researchers have uncovered weaknesses in low-assurance digital certificates that create a means for miscreants to mount more convincing man-in-the-middle (MITM) attacks.… Mon, 29 Dec 2008 11:23:14 +0100 You've been iframedChristmas gifts of Samsung Digital Picture frames could come with the unwelcome gift of malware, Amazon has warned.… Wed, 24 Dec 2008 21:48:42 +0100 Fined $8,000 a dayA federal judge has fined a Belize-based company $8,000 for each day it continues to flout his order to halt a major internet operation alleged to have duped more than 1 million computer users into buying bogus malware protection.… Tue, 23 Dec 2008 22:01:50 +0100 Attack of the open redirectsMiscreants are exploiting weaknesses in more than one million webpages operated by the federal government, media companies, and even Microsoft to trick unwitting visitors into installing harmful software that takes over their computers.… Tue, 23 Dec 2008 16:39:20 +0100 Unauthorised drilling in a protected areaA top manager at a US software developer has avoided jail after pleading guilty to lifting password-protected files from the website of a business rival.… Tue, 23 Dec 2008 16:00:17 +0100 Exploit code for 0day fails to ping on Redmond's radarMicrosoft came clean and admitted its SQL Server database software is vulnerable to code injection attacks. It's not a new flaw but the same bug in the database software that emerged around the time of Microsoft's monthly Patch Tuesday update earlier this month.… Tue, 23 Dec 2008 13:04:05 +0100 If I offered you
|