facebook

As seems to be the trend lately, anytime a vulnerability is disclosed in an ActiveX control, it is only a short time before it is bundled into the Web attack toolkits. For this Facebook vulnerability, it was less than a day from the vulnerability being disclosed on February 12th to it first showing up on our honeypots on February 13th. So far, the exploits that have shown up are encoded versions of the public exploit, bundled with an exploit for Yahoo Jukebox and several other routinely exploitable vulner read more »
addto Add this link to... report Bury 
If you use Internet Explorer (versions 6 or 7) to browse the Web, listen up: Criminals are starting to exploit security holes in several widely installed IE plug-ins to plant invasive software when users are coerced or tricked into visiting one of several Web sites. In an alert posted Friday evening, security software vendor Symantec said it is seeing malicious Web sites popping up trying to exploit vulnerabilities in a set of ActiveX controls produced...Please click on the title to continue reading this e read more »
addto Add this link to... report Bury 
Zuckerberg's private moments on display tooA week after Facebook executives introduced new security features to great fanfare, a glitch on the popular social networking site has exposed private pictures of Paris Hilton to anyone with an internet connection.… read more »
addto Add this link to... report Bury 
http://technology.timesonline.co.uk/tol/news/tech_and_web/article3617360.eceBy Jonathan RichardsTimes OnlineMarch 25, 2008A security lapse on Facebook has allowed its users to gain access to vast libraries of private photographs, including one of Paris Hilton drinking beer with her friends.A Canadian hacker exploited a recent upgrade to the networking site's privacy settings to view pictures that were intended to be private, including some of Paris Hilton partying with her brother, Barron Nicholas, at the read more »
addto Add this link to... report Bury 
'Joe Job' social networking attackSecurity personality Graham Cluley has become the target of a hate campaign after a "troll" criticising the British army posted a picture of the anti-virus expert in his Facebook profile.… read more »
addto Add this link to... report Bury 
http://news.bbc.co.uk/2/hi/middle_east/7364091.stmBBC News23 April 2008Israel has sentenced a soldier to 19 days in jail for uploading a photograph taken on his military base to the social networking website, Facebook.The Israeli military declined to comment on the nature of the image, but said the soldier was serving with an elite intelligence unit.Local media say it is the first such conviction for an Israeli soldier.The case follows widespread reports about the potential security risk of soldiers postin read more »
addto Add this link to... report Bury 
Reining in Web 2.0 predatorsFacebook has reached an agreement with 50 attorneys general to permanently deploy measures designed to rein in pedophiles and other predators on the social networking site.… read more »
addto Add this link to... report Bury 
Social spammingFacebook is vulnerable to a cross site scripting flaw that leaves its users at risk from scripting attacks.… read more »
addto Add this link to... report Bury 
Social engineering used to whip up Storm wormAn FBI-backed organisation has warned computer users to ignore claims that the Feds are scouring Facebook for terrorists.… read more »
addto Add this link to... report Bury 
'Paris Hilton Tosses Dwarf On The Street'Miscreants have created a pair of worms targeting MySpace and Facebook users. Two variants of a new worm - dubbed Koobface - are the first to use social engineering sites to press-gang infected machines into botnets, warns net security firm Kaspersky Lab.… read more »
addto Add this link to... report Bury 
Websense Security Labs has been tracking various Facebook attacks for many years. We've had to create numerous tools and methods to detect these types of attacks because most Web 2.0 social networking sites are difficult to track due to limited public access to most accounts. Most social networking accounts can only be viewed if the account holder explicitly accepts or requests another account to be added as a "friend". A generic Web crawler and even a search engine Web crawler would not be able to mine th read more »
addto Add this link to... report Bury