I must admit that I was puzzled for a second when I saw an email with a suicide note as subject line in my spam inbox. I wondered what product they might try to sell with that note or which drive-by download site might be hidden behind it. So, I opened it. The email was actually written like a real suicide note. read more »
addto Add this link to... report Bury 
There has been much debate recently that stems from discussions related to Linux kernel development, over whether or not security vulnerabilities should be treated differently than regular software bugs. This has meant there has been a slight departure from the exhausted "full disclosure" debate read more »
addto Add this link to... report Bury 
Notice! The virus-spreading spammer doesn't have your baby but is claiming to. In recent emails observed by Symantec, malicious code is being spread by hoax emails claiming to have pictures of your hijacked [sic] baby. The Subject line makes the claim that someone has read more »
addto Add this link to... report Bury 
The FBI is warning people not to be disturbed by an e-mail scam that threatens your life and orders you to pay up to avoid being the target of a hired hit man. The FBI said its Internet Crime Complaint Center continues to receive thousands of reports concerning the hit man e-mail scheme. The FBI notes that while the content of the missive has evolved since similar hit man scams first surfaced in late 20006,...Please click on the title to continue reading this entry. read more »
addto Add this link to... report Bury 
Last week, I examined a series of Web services that make profiting from cyber crime a point-and-click exercise that even the most novice hackers can master. Today, I'd like to highlight the activities of Atrivo, a Concord, Calif., based network provider that hosts some of these services. Several noted security researchers are releasing a report today that stems from many months of investigating malicious activity emanating from Atrivo's customers. Security experts say that Atrivo, also...Please click on th read more »
addto Add this link to... report Bury 
The Bush administration has ordered all federal agencies to adopt new measures to shore up the security of government Web sites, setting a January 2009 deadline for implementing the changes across all dot-gov domains. Agencies will be required to roll out domain name system security extensions (DNSSEC), a set of security add-ons for the domain name system. DNS is a fundamental piece of the Internet infrastructure that acts as a kind of distributed Internet phone...Please click on the title to continue read read more »
addto Add this link to... report Bury 
The PCI Security Standards Council has released a summary of changes and clarifications for version 1.2 of the PCI-DSS standard, which is scheduled for release on October 1, 2008. In an effort to combat the growing problem of card theft, the Payment Card Industry Data Security Standard has been established to ensure that through the use of imposed regulations, compromises of customer card data will not be easily possible. read more »
addto Add this link to... report Bury 
Here in the Labs, we've recently discovered a new spam worm spreading. It is usually sent with spam that tries to deceive users into clicking a malicious URL contained in the message. Once clicked, the URL redirects users to malicious Web sites that result in an ActiveX Object error. The intention of this error is to manipulate users to download files infected with a virus. read more »
addto Add this link to... report Bury 
Spammers have made great strides this past year in defeating CAPTCHAs, the distorted text used as a security test to ensure a person and not a machine is behind a computer screen. But automated programs that spammers use to thwart CAPTCHAs still aren't nearly as successful as the practice of hiring thousands of people to do nothing but remotely solve the puzzles for clients. This is the business model behind anti-captcha.com, a subscription service that...Please click on the title to continue reading this read more »
addto Add this link to... report Bury 
Some of us know tools that can take a COM Object module (also known as an ActiveX Control) and show us information about it, such as the names of its objects and functions.Two examples of such tools are the OlyView and TLB Viewer.But what if we want to know additional information, such as the virtual address inside themodule that handles each function of our object? read more »
addto Add this link to... report Bury 
The allure of cyber crime lies in its promise of quick riches, much like that of the illegal drug trade. But building a network of hacked personal computers that can distribute your data-stealing malicious software is a time-consuming process that requires a modicum of skill. That is, until recently, when several online services have emerged that promise to help would-be cyber crooks graduate from common street dealers to distributors overnight. Such is the aim of...Please click on the title to continue re read more »
addto Add this link to... report Bury