In the overwhelming sea of information, access to timely, insightful and independent open-source intelligence (OSINT) analyses is crucial for maintaining the necessary situational awareness to stay on the top of emerging security threats. This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude
Monday, February 04, 2013
Summarizing Webroot's Threat Blog Posts for January
The following is a brief summary of all of my posts at Webroot's Threat Blog for January, 2013. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:
01. Spamvertised ‘Your Recent eBill from Verizon Wireless’ themed emails serve client-side exploits and malware
02. Fake BBB (Better Business Bureau) Notifications lead to Black Hole Exploit Kit
03. ‘Attention! Changes in the bank reports!’ themed emails lead to Black Hole Exploit Kit
04. Fake ‘You have made an Ebay purchase’ themed emails lead to client-side exploits and malware
05. A peek inside a boutique cybercrime-friendly E-shop – part six
06. Black Hole Exploit Kit author’s ‘vertical market integration’ fuels growth in malicious Web activity
07. Spamvertised AICPA themed emails serve client-side exploits and malware
08. ‘Please confirm your U.S Airways online registration’ themed emails lead to Black Hole Exploit Kit
09. Malicious DIY Java applet distribution platforms going mainstream
10. Fake ‘ADP Speedy Notifications’ lead to client-side exploits and malware
11. Cybercriminals release automatic CAPTCHA-solving bogus Youtube account generating tool
12. ‘Batch Payment File Declined’ EFTPS themed emails lead to Black Hole Exploit Kit
13. Cybercriminals resume spamvertising fake Vodafone ‘A new picture or video message’ themed emails, serve malware
14. Leaked DIY malware generating tool spotted in the wild
15. Email hacking for hire going mainstream – part three
16. Android malware spreads through compromised legitimate Web sites
17. Fake Intuit ‘Direct Deposit Service Informer’ themed emails lead to Black Hole Exploit Kit
18. Fake LinkedIn ‘Invitation Notifications’ themed emails lead to client-side exploits and malware
19. Novice cybercriminals experiment with DIY ransomware tools
20. Bogus ‘Your Paypal Transaction Confirmation’ themed emails lead to Black Hole Exploit Kit
21. Fake ‘FedEx Online Billing – Invoice Prepared to be Paid’ themed emails lead to Black Hole Exploit Kit
22. A peek inside a DIY password stealing malware
23. Malicious ‘Facebook Account Cancellation Request” themed emails serve client-side exploits and malware
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
Summarizing ZDNet's Zero Day Posts for January
The following is a brief summary of all of my posts at ZDNet's Zero Day for January, 2013. You can subscribe to Zero Day's main feed, or follow me on Twitter:
01. Dutch security researchers dissect the Pobelka botnet
02. ESPN's ScoreCenter for iOS sends passwords in clear-text, susceptible to XSS flaw
03. Report: AutoRun malware infections continue topping the charts
04. Comparative review: Opera leads in browser anti-phishing protection
05. Italian-language page at MSN redirects to Cool Exploit Kit, serves ransomware
06. WordPress releases version 3.5.1, fixes 3 security issues
07. Targeted attack against UAE activist utilizes CVE-2013-0422, drops malware
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
Wednesday, January 09, 2013
Summarizing Webroot's Threat Blog Posts for December
The following is a brief summary of all of my posts at Webroot's Threat Blog for December, 2012. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:
01. DIY malicious domain name registering service spotted in the wild
02. Fake ‘FedEx Tracking Number’ themed emails lead to malware
03. Bogus ‘Facebook Account Cancellation Request’ themed emails serve client-side exploits and malware
04. Malicious ‘Security Update for Banking Accounts’ emails lead to Black Hole Exploit Kit
05. A peek inside a boutique cybercrime-friendly E-shop – part five
06. Fake ‘Flight Reservation Confirmations’ themed emails lead to Black Hole Exploit Kit
07. Malicious ‘Sendspace File Delivery Notifications’ lead to Black Hole Exploit Kit
08. Fake Chase ‘Merchant Billing Statement’ themed emails lead to malware
09. Cybercriminals entice potential cybercriminals into purchasing bogus credit cards data
10. Fake ‘Change Facebook Color Theme’ events lead to rogue Chrome extensions
11. Fake ‘Citi Account Alert’ themed emails lead to Black Hole Exploit Kit
12. Spamvertised ‘Work at Home” scams impersonating CNBC spotted in the wild
13. Pharmaceutical scammers spamvertise YouTube themed emails, entice users into purchasing counterfeit drugs
14. Cybercriminals resume spamvertising British Airways themed E-ticket receipts, serve malware
15. Fake ‘UPS Delivery Confirmation Failed’ themed emails lead to Black Hole Exploit Kit
16. Webroot’s Threat Blog Most Popular Posts for 2012
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
01. DIY malicious domain name registering service spotted in the wild
02. Fake ‘FedEx Tracking Number’ themed emails lead to malware
03. Bogus ‘Facebook Account Cancellation Request’ themed emails serve client-side exploits and malware
04. Malicious ‘Security Update for Banking Accounts’ emails lead to Black Hole Exploit Kit
05. A peek inside a boutique cybercrime-friendly E-shop – part five
06. Fake ‘Flight Reservation Confirmations’ themed emails lead to Black Hole Exploit Kit
07. Malicious ‘Sendspace File Delivery Notifications’ lead to Black Hole Exploit Kit
08. Fake Chase ‘Merchant Billing Statement’ themed emails lead to malware
09. Cybercriminals entice potential cybercriminals into purchasing bogus credit cards data
10. Fake ‘Change Facebook Color Theme’ events lead to rogue Chrome extensions
11. Fake ‘Citi Account Alert’ themed emails lead to Black Hole Exploit Kit
12. Spamvertised ‘Work at Home” scams impersonating CNBC spotted in the wild
13. Pharmaceutical scammers spamvertise YouTube themed emails, entice users into purchasing counterfeit drugs
14. Cybercriminals resume spamvertising British Airways themed E-ticket receipts, serve malware
15. Fake ‘UPS Delivery Confirmation Failed’ themed emails lead to Black Hole Exploit Kit
16. Webroot’s Threat Blog Most Popular Posts for 2012
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
Subscribe to:
Posts (Atom)





