Yearly Archives: 2012

Norman Declares War on Security Shield, a Fake AntiVirus Software

Fake AntiVirus

Our Research & Development team always keeps up-to-date with the latest malware threats – it’s just part of the job. But when malware pretends to be antivirus software, well, then it gets personal. So to the criminals behind Security Shield: we’re onto you. We’re raising the alert over Security Shield … Read More

The Shiqiang Gang

In a series of blog posts our colleagues at Trend and AlienVault have detailed recent attacks on NGO’s, and how trojanized RTF files have been used as vehicles to plant various remote access trojans on unsuspecting users using the CVE-2012-0158 vulnerability. In addition, they both mention that apparently stolen digital  … Read More

Tags:

Understanding Hacker Strategies – Part 2

Many security teams think that if they have a couple of firewalls, an IPS and antivirus software implemented, they’re home free.  The servers get patched, the team is alerted when network traffic behaves badly and viruses are quickly killed. Hackers know, however, there are many ways to probe, some do … Read More

Those Pesky Passwords

As I mentioned in a previous post, the long-ago patched Conficker worm is continuing to infect millions of new computers. Researchers have found that nearly every incident, 92 percent, is due to a single practice – poor password security. Unfortunately, the spread of Conficker is far from the only problem … Read More

Tags:

Watch Out for the Windows Telephone Scam

Photograph: Corbis

I used to be excited when I came home to six messages on my answering machine. But that was before a fake Windows telephone scam started calling five times a day, trying to convince me to give them my money. The caller will claim to be either a member of … Read More

Understanding Hacker Strategies

I’m always amazed at how easy it can be to obtain company information.  SearchSecurity has an excellent series to help us better understand hacker attack techniques and tactics.  Serious hackers typically perform extensive reconnaissance prior to hacking into a network.  Often, employees will make this work much easier than it … Read More

Internet Advice to Kids: Stop. Think. Connect.

boy_laptop1

Parents often ask us for advice on how to their keep children safe online. While we’re more than willing to give our advice, EMC Corporation and RSA have gone one step further and produced a whole music video dedicated to enforcing a web safety message for kids. The video, called … Read More

Unusual cyber attack targets continue: This time Ethiopia

Despite reports that digitally signed malware is becoming more common, it still calls for a bit of attention when a new stolen certificate is found.  Much signed malware is either signed with a certificate which is known to be on the loose, signed with a self-signed (and thus untrusted) certificate, … Read More

Tags:

Religious Websites Worse Than Porn (For Viruses)

Religious sites are key malware distribution points

Religious websites might be useful for finding salvation, but they certainly won’t save your soul from computer viruses. A recent study stated that religious and ideological websites host three times more malware than porn websites. The research detailed how many threats were found on websites, with religious pages scoring the … Read More

Security Doesn’t Need to be Complicated

As hard as it is to believe, the three-year old Conficker worm, long patched, is still causing significant security problems in many businesses, according to Microsoft’s recently released bi-annual Security Intelligence Report. Conficker infections have increased 225 percent each quarter since its discovery in late 2008. Researchers report that the … Read More