An effective new phishing technique identified by researchers with Trend Micro allows attackers to go after information without having to spend as much time developing copies of websites. . The attack involves a phishing page containing a proxy program that acts as a relay to a legitimate website, according to a Wednesday post by Noriaki Hayashi, senior threat researcher with Trend Micro. From the user's perspective, they are just browsing the regular site, and the attackers do not have to modify anything until they are ready to steal information. The link for this article located at SC Magazine is no longer available. . The attack involves a phishing page containing a proxy program that acts as a relay to a legitimate . effective, phishing, technique, identified, researchers, trend, micro, allows, attackers. . LinuxSecurity.com Team
A new version of the BlackHole exploit kit is now out on the web and ready to start infecting. The developer of the toolkit, who goes by the handle "Paunch," recently announced the availability of Blackhole 2.0, which removes much of its trove of known and patched exploits, and replaces them with a whole new crop. BlackHole is a widely-used, web-based software package which includes a collection of tools to take advantage of security holes in web browsers to download viruses, botnet trojans, and other forms of nastiness to the computers of unsuspecting victims. The exploit kit is offered both as a "licensed" software product for the intrepid malware server operator and as malware-as-a-service by the author off his own server.. ZeroPoint 3.1 is an online toolkit designed to leverage unpatched flaws in web browsers, enabling cybercriminals to compromise systems and spread malware.. BlackHole Toolkit, Malware Tactics, Cybersecurity Threats, Exploit Alternatives, Web Exploits. . LinuxSecurity.com Team
Attackers don't just lay traps for users; they do it for researchers and rivals as well. A recent case in point is an exploit toolkit linked to a Zeus malware campaign that security pros at The Last Line of Defense report includes a fake administration console that records information about anyone who attempts to access or hack it.. Such traps are not unfamiliar to security researchers. Cyber-crime is a business, and when defending that business, the best defense can be a good offense. "They have been doing this for some time, particularly bot-herders, to protect their botnets," said Jamz Yaneza, advanced threat manager at Trend Micro. "They employ monitoring scripts/stations that once [they] detect threat researchers are lurking ... then instruct the whole botnet The link for this article located at eWeek is no longer available. . Intruders set up sophisticated decoys to confuse cybersecurity analysts and safeguard their activities.. Malware Authors, Cyber Defense, Threat Intelligence. . LinuxSecurity.com Team
Online criminals are turning away from threatening companies with massive cyberattacks in favour of encrypting a victim's data and demanding money to release it, an antivirus expert claimed on Tuesday. Eugene Kaspersky, head of antivirus research at Russia's Kaspersky Labs, told the RSA Conference in San Francisco that the use of so-called "ransomware Trojans" is a key trend for 2007. . This malware infects a PC, encrypts some data, and then displays an alert telling the victim to send money to get the decryption key needed to access their data again. Such malware isn't new. Early examples include Cryzip, discovered in March 2006, and GPCode, discovered in May 2005. The link for this article located at ZDNet UK is no longer available. . Digital malefactors are progressively employing ransomware to seize and lock data, coercing victims into paying to regain access. Discover further details about this alarming trend.. Ransomware Attacks, Data Encryption, Cybercrime Strategies, Online Extortion. . LinuxSecurity.com Team
Among the devilish deeds that can be perpetrated by Trojans is the creation of "zombie networks" -- networks typically composed of home computers surreptitiously controlled by a badware's author. "We estimate that spam zombie networks are responsible for from anywhere to 25 to 30 percent of the spam on the Internet today, and it's growing," said Scott Chasin, CTO of e-mail defense solutions company MX Logic. . . .. Among the devilish deeds that can be perpetrated by Trojans is the creation of "zombie networks" -- networks typically composed of home computers surreptitiously controlled by a badware's author. "We estimate that spam zombie networks are responsible for from anywhere to 25 to 30 percent of the spam on the Internet today, and it's growing," said Scott Chasin, CTO of e-mail defense solutions company MX Logic. The techniques used to develop open-source software like Linux have proven to be so effective that they've been adopted by malware writers to improve their mischievous ways. The link for this article located at John P. Mello Jr. is no longer available. . Among the devilish deeds that can be perpetrated by Trojans is the creation of 'zombie networks' -- . among, devilish, deeds, perpetrated, trojans, creation, 'zombie, networks'. . LinuxSecurity.com Team
The war against hackers is entering a new phase. In the UK and the US, behind the walls of usually bland-looking buildings and shielded from wireless hacking by lead-lined walls, the stuff of Hollywood films is being played out across giant . . . . The war against hackers is entering a new phase. In the UK and the US, behind the walls of usually bland-looking buildings and shielded from wireless hacking by lead-lined walls, the stuff of Hollywood films is being played out across giant plasma screens. Programmers, often working on behalf of government agencies, track, monitor and frenziedly alter code in a bid to patch up vulnerable and sometimes besieged networks. "We are being sucked into an Orwellian nightmare," says one US-based hacker who calls himself Oxblood Ruffin. Oxblood, a member of the influential hacking group Hacktivismo, adds: "This [Magic Lantern] is a powerful tool and basically they have initiated a state-sponsored trojaning campaign with no judicial oversight. If you look at what's possible it's very scary. For instance, if there is no smoking gun, a rogue cop could plant a virtual one. It's possible to upload as well as download or browse the contents of a targeted user's machine. So if there are no kiddie porn pictures [on a computer] for instance, they can be uploaded and the doors kicked in five minutes later. No traces either." The link for this article located at MediaGuardian is no longer available. . The fight against cyber threats is escalating in the UK and US, with both nations enhancing cybersecurity initiatives and fostering collaboration to protect vital information. Cyber Warfare, Hacker Threat, Malware Tactics, Network Protection, State Surveillance. . LinuxSecurity.com Team
Web surfers are in a tug-of-war for control of their home page settings, fighting off increasingly aggressive tactics by Net businesses and online marketers aimed at commandeering first rights to consumers' browsers. Unsuspecting consumers who install software, open attachments or merely . . . . Web surfers are in a tug-of-war for control of their home page settings, fighting off increasingly aggressive tactics by Net businesses and online marketers aimed at commandeering first rights to consumers' browsers. Unsuspecting consumers who install software, open attachments or merely visit certain Web sites can find themselves tethered to an unwanted start page every time they log on to the Net. Security experts say the practice is on the rise, but few people are technically savvy enough to understand what's actually going on when browser settings are switched. The link for this article located at News.com is no longer available. . Web surfers are in a tug-of-war for control of their home page settings, fighting off increasingly a. surfers, tug-of-war, control, their, settings, fighting, increasingly. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.