An exploit selling for $700 may put millions of Yahoo Mail users at risk of having their e-mail account hijacked and their browsers redirected to malicious sites. . Marketed by an allegedly Egyptian hacker on a cybercrime forum, the exploit targets a cross-site scripting (XSS) vulnerability in Yahoo.com that allows attackers to steal and replace tracking cookies, as well as read and send e-mail from a victim's account. Typically, an attacker will encode a malicious link in e-mails; the script is executed when the unsuspecting recipient clicks on the link, allowing access to the cookies and other sensitive information. The link for this article located at CNET is no longer available. . Marketed by an allegedly Egyptian hacker on a cybercrime forum, the exploit targets a cross-site scr. exploit, selling, millions, yahoo, users, having, their, e-mail. . LinuxSecurity.com Team
Security researchers have spotted spam emails that point at URLs featuring embedded Quick Response codes (QR codes).. QR codes are a two-dimensional matrix barcode that can be scanned by a camera phone to link users directly to a website that can host any type of content, malicious or otherwise. By using QR codes (rather than links) as a jump-off point to spamvertised sites, spammers can disguise the ultimate destination of links as well as improving click-through rates. In particular, the approach helps when it comes to targeting mobile users. Spam messages spotted by Websense look like traditional pharmaceutical spam emails, with the twist that they link to a legitimate (but abused in this case) website, 2tag.nl. The legitimate web service allows users to create QR codes for URLs but has in this case been abused to create links that ultimately point to Canadian Pharmacy penis pill sites. The link for this article located at The Register UK is no longer available. . Scammers utilize QR codes within messages that direct users to harmful websites, aiming at mobile device owners with hidden URLs.. QR Code Spam, Mobile Vulnerabilities, Phishing Tactics. . LinuxSecurity.com Team
There is an aggressively distributed spam campaign that uses the MySpace name in an attempt to phish information from music lovers. The emails have been spammed out to hundreds of thousands of computer users around the globe in the last week, luring them into clicking on links to a website posing as an online music store. . IT security firm Sophos has warned of an aggressively distributed spam campaign that uses the name of the popular MySpace social networking site in an attempt to phish information from music lovers. The emails have been spammed out to hundreds of thousands of computer users around the globe in the last week, luring them into clicking on links to a website posing as an online music store. The link for this article located at Help Net Security is no longer available. . Palo Alto Networks warns individuals of a deceptive scheme targeting Facebook enthusiasts, enticing them to follow unsafe links to counterfeit merchandise websites.. MySpace Phishing, Cyber Threats, Spam Campaign, Sophos Alerts. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.