General

Security 101: February 2013

Nowadays, a lot of people are shopping online. To do that, they greatly rely on internet banking. What precautionary steps or systems are used to make sure users have a secure transaction? The most important thing to do is to make sure that your computer is not infected with malicious software. For this, you will […]

General

The BKA/Ransom Trojan comes now with child pornography

The so called “BKA Trojan” (BKA stands for German Federal Criminal Police) malware which is also known as the Ransom trojan in other countries, has found a more convincing way to fool computer users to pay. Now, together with other eight possible misdeeds,  the user is accused of hosting and distributing child pornography materials from his computer. […]

General

Security update for Apple: iOS 6.1 fixes browser flaws

Apple has released a new version of iOS, the operating system that powers the iPhone, iPad, iPod. The new version fixes 20 security flaws related to the Safari browser. Some of the vulnerabilities were allowing bypassing of authentication, cross-site scripting attacks, privilege escalations, arbitrary code execution, memory corruptions. Last but not least, the  compromised Türktrust certificates were revoked. […]

General

Malware delivered with fake hotel reservations

We wrote last week about Malware delivered with fake Craigslist fax-to-email notifications.This week’s malware delivery mechanism is a fake email notification from the well-known online hotel reservations portal booking.com.   The malware is delivered when you click on “Print Booking Details” via an archive which should contain the form with the reservation details. In order […]

General

Malware delivered with fake Craigslist fax-to-email notifications

If you receive such a message containing an HTML page attached, don’t open it. The email pretends to come from “craigslist – automated message, do not reply <robot@craigslist.org>” and has the subject ”Efax Corporate”. What I find interesting is that the fraudsters didn’t even bother to write JS code to detect if the script runs in […]

General

Pharma spam using LinkedIn again

We wrote a couple of times already about spams pretending to come from LinkedIn which advertise online pharmacy websites. There is a new spam campaign which changed a bit the way the messages are presented to the users. Now the emails pretend to come from “LinkedIn Co. Technical Support”, “LinkedIn Co. Administration” and from “LinkedIn Reminders”. […]

General

Yet a new Java zero-day exploit?

We don’t know yet if this is a bad joke intended to discredit Oracle and Java, but the media is buzzing about a possible new undetected exploit in Java. This was started by a post of the security researcher Brian Krebs who observed a thread in a known online crime forum where somebody was selling […]