Tuesday, May 08, 2012

Summarizing Webroot's Threat Blog Posts for April


The following is a brief summary of all of my posts at Webroot's Threat Blog for April, 2012. You can subscribe to my Webroot's Threat Blog RSS Feed or follow me on Twitter:

01. Adobe patches critical security flaws, introduces auto-updating mechanism
02. Email hacking for hire going mainstream – part two
03. Spamvertised ‘US Airways’ themed emails serving client-side exploits and malware
04. New underground service offers access to hundreds of hacked PCs
05. Google’s Chrome patches 12 ‘high risk’ security vulnerabilities
06. Adobe plans to issue Acrobat Reader ‘security update’ next week
07. Microsoft issues 6 security bulletins on ‘Patch Tuesday’
08. Adobe patches critical Reader and Acrobat security vulnerabilities
09. Hewlett-Packard shipping malware-infected compact flash cards
10. New DIY email harvester released in the wild
11. Upcoming Webroot briefing at InfoSec, 2012, London – “Current and Emerging Trends Within the Cybercrime Ecosystem”

This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.

Summarizing ZDNet's Zero Day Posts for April


The following is a brief summary of all of my posts at ZDNet's Zero Day for April, 2012. You can subscribe to my personal RSS feedZero Day's main feed, or follow me on Twitter:
01. Researcher: 50 percent of Mac OS X users still running outdated Java versions
02. Malicious version of Angry Birds Space spotted in the wild
03. French gaming site serving ZeuS crimeware for over 8 weeks
04. New ransomware variants spotted in the wild
05. Nuclear Pack exploit kit introduces anti-honeyclient crawling feature

This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.

Monday, April 09, 2012

Summarizing Webroot's Threat Blog Posts for March

The following is a brief summary of all of my posts at Webroot's Threat Blog for March, 2012. You can subscribe to my Webroot's Threat Blog RSS Feed or follow me on Twitter:

01. New service converts malware-infected hosts into anonymization proxies
02. Spamvertised ‘Temporary Limit Access To Your Account’ emails lead to Citi phishing emails
03. A peek inside the Darkness (Optima) DDoS Bot
04. Research: proper screening could have prevented 67% of abusive domain registrations
05. Spamvertised ‘Your accountant license can be revoked’ emails lead to client-side exploits and malware
06. Spamvertised ‘Google Pharmacy’ themed emails lead to pharmaceutical scams
07. Research: U.S accounts for 72% of fraudulent pharmaceutical orders
08. Millions of harvested U.S government and U.S military email addresses offered for sale
09. Spamvertised ‘Your tax return appeal is declined’ emails serving client-side exploits and malware
10. Malicious USPS-themed emails circulating in the wild
11. Spamvertised LinkedIn notifications serving client-side exploits and malware
12. Tens of thousands of web sites affected in ongoing mass SQL injection attack
13. Spamvertised Verizon-themed ‘Your Bill Is Now Available’ emails lead to ZeuS crimeware
14. Spamvertised ‘Scan from a Hewlett-Packard ScanJet’ emails lead to client-side exploits and malware

This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.