July 3rd, 2009
EyeWonder malware incident affects popular web sites
During the last couple of hours, visitors of popular and high trafficked web sites such as CNN, BBC, Washington Post, Gamespot, WorldOfWarcraft, Mashable, Chow.com, ITpro.co.uk, AndroidCommunity; Engadget and Chip.de, started reporting that parts of the web sites are unreachable due to malware warnings appearing through the EyeWonder interactive digital advertising provider.
Let’s assess the butterfly effect of a single malware incident affecting an ad network whose ads get syndicated across the entire Web.
July 2nd, 2009
Manchester City Council pays $2.4m in Conficker clean up costs
How severe can the impact of the Conficker worm be on a single city council that has apparently not implemented basic security solutions in place?
Pretty severe according to a recently released a report entitled “Service interruption resulting from ICT disruption in February 2009” which details the financial costs of a Conficker incident affecting Manchester City Council’s network - 1.5 million pounds in clean up costs and lost revenue from the downtime.
Where did all the money go, and can this incident cost be used as an average to draw conclusions from in the long term in respect to assessing Conficker’s financial impact on affected networks? Let’s find out.
June 26th, 2009
Michael Jackson's death themed malware campaigns spreading
The sudden death of Michael Jackson quickly opened a window of opportunity for cybercriminals to capitalize on.
With a malicious spam campaign, blackhat SEO search results poisoning which is serving scareware within the first 100 search results for Michael Jackson’s death, and an opportunistic participant in Zango adware’s network using typosquatting, malicious activity is prone to increase during the next couple of days.
Here are more details on the campaigns currently in circulation:
June 25th, 2009
Secunia: Average insecure program per PC rate remains high
With the time frame for an exploit to become an inseparable part of a web malware exploitation kit shrinking, and with the average Internet user’s over-confidence in an antivirus scanner’s ability to detect and block exploits (Secunia: popular security suites failing to block exploits) it shouldn’t come as a surprise that Secunia’s recently released WorldMap shows a relatively high rate for insecure programs found on a single PC.
The WorldMap of patched and unpatched PCs is released prior to an updated version of Secunia’s Personal Software Inspector, with the latest version finally filling a niche left open potentially undermining the usefulness of the handy tool in general - measuring the exploitability of cross-browser plugins such as Adobe Flash Player, QuickTime, or Sun’s Java.
Let’s take a look at some of their stats.
June 24th, 2009
Guy Kawasaki's Twitter account hijacked, pushes Windows and Mac malware
The Twitter account belonging to venture capitalist and Mac evangelist Guy Kawasaki was hijacked yesterday and used to push malware to some 140,000 Twitter users. The attack (screenshot above) included a link to what purported to be a “sex tape video free download” linked to Gossip Girls star Leighton Meester but, after a series of clicks, the end result was a malicious Trojan.
June 24th, 2009
Critical Adobe Shockwave flaw affects millions
Adobe’s Shockwave Player contains a critical vulnerability that could be exploited by remote hackers to take complete control of Windows computers, according to a warning from the software maker.
The flaw affects Adobe Shockwave Player 11.5.0.596 and earlier versions. Details from Adobe’s advisory:
June 24th, 2009
Remote code execution exploit for Green Dam in the wild
The recently exposed as vulnerable to trivial remotely exploitable flaws Chinese censorware Green Dam, has silently patched the security flaws (China confirms security flaws in Green Dam, rushes to release a patch) outlined in the original analysis detailing the vulnerabilities.
However, not only is the latest Green Dam v3.17 version still vulnerable to remotely exploitable flaws, but also, for over a week now a working zero day exploit (Exploit.GreenDam!IK; W32/GreenDam.A) has been circulating in the wild.
Here are more details on the remote code execution flaw in the latest version:
June 22nd, 2009
Mozilla tackles XSS vulnerabilities with new technology
Mozilla’s security engineers are working on new technology that promises to mitigate a large class of Web application vulnerabilities, especially the cross-site scripting (XSS) plague against modern Web browsers.
The project, called Content Security Policy, is designed to shut down XSS attacks by providing a mechanism for sites to explicitly tell the browser which content is legitimate. It can also help mitigate clickjacking and packet sniffing attacks.
June 18th, 2009
Fake Microsoft patches themed malware campaigns spreading
Researchers from Computer Associates (NASDAQ:CA) and Sophos are reporting on three currently active malware campaigns using fake Microsoft patch themes as a social engineering tactic to spread over email.
The first one is spreading as an “Important Windows XP/Vista Security Update” and is offering a bogus Conficker removal tool, the second is using an “Outlook re-configuration” — also spammed earlier this month — and the third one is using an out-of-the-band “Update for Microsoft Outlook / Outlook Express (KB910721)” theme, which in reality is nothing else but a trojan.
June 17th, 2009
Apple iPhone OS 3.0 update plugs 46 security holes
Apple’s latest iPhone OS 3.0 software updates includes patches for multiple vulnerabilities, some with serious security implications.
The update, which is only available for download via iTunes, covers a total of 46 documented vulnerabilities, including several that allows malicious code execution if a user simply visits a rigged Web site or views a manipulated image.
Ryan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.
For daily updates on Ryan's activities, follow him on Twitter.
Subscribe to Zero Day via Email alerts or RSS.
SponsoredWhite Papers, Webcasts, and Downloads
- Building the Virtualized Enterprise with VMware Iinfrastructure VMware VMware virtualization software has been adopted by over 120,000 enterprise ... Download Now
- The Impact of Virtualization Software on Operating Environments VMware Today's use of virtualization technology allows IT professionals to ... Download Now
- VMware Infrastructure: A Guide to Bottom-Line Benefits VMware Frustrated by the high cost of maintaining or building ever-larger data centers? Get the facts you need to formulate your Virtualization Action Plan. Download Now
Recent Entries
- EyeWonder malware incident affects popular web sites
- Manchester City Council pays $2.4m in Conficker clean up costs
- Michael Jackson’s death themed malware campaigns spreading
- Secunia: Average insecure program per PC rate remains high
- Guy Kawasaki’s Twitter account hijacked, pushes Windows and Mac malware
Blogs From Our Sponsors
Most Popular Posts
- Critical Adobe Shockwave flaw affects millions
- Fake Microsoft patches themed malware campaigns spreading
- Guy Kawasaki's Twitter account hijacked, pushes Windows and Mac malware
- Apple iPhone OS 3.0 update plugs 46 security holes
- Michael Jackson's death themed malware campaigns spreading
- Iranian opposition launches organized cyber attack against pro-Ahmadinejad sites
Top Rated
- Critical Adobe Shockwave flaw affects millions+48 votes
- Fake Microsoft patches themed malware campaigns spreading+29 votes
- Microsoft patches 31 Windows, IE, Office security holes+29 votes
- FTC shuts down notorious botnet ISP+26 votes
- Mozilla slaps band-aid on 11 Firefox flaws+25 votes
- StrongWebmail CEO's mail account hacked via XSS+20 votes
- Apple Safari jumbo patch: 50+ vulnerabilities fixed+17 votes
- Guy Kawasaki's Twitter account hijacked, pushes Windows and Mac malware+15 votes
Archives
ZDNet Blogs
- All About Microsoft
- The Apple Core
- Between the Lines
- BriefingsDirect
- Collaboration 2.0
- Community, Incorporated
- CRM 2.0: The Conversation
- Dev Connection
- Digital Cameras & Camcorders
- Ed Bott's Microsoft Report
- Emerging Tech
- Enterprise Web 2.0
- Forrester Research
- Googling Google
- GreenTech Pastures
- Hardware 2.0
- Home Theater
- iGeneration
- Irregular Enterprise
- IT Facts
- IT Project Failures
- Laptops & Desktops
- Lawgarithms
- Linux and Open Source
- Managing L'unix
- The Mobile Gadgeteer
- On Sustainability
- Rational Rants
- The Semantic Web
- Service Oriented
- Smartphones and Cell Phones
- Social Business
- Software & Services Safari
- Software as Services
- SOHO Networking
- Storage Bits
- Team Think
- Tech Broiler
- Technology and the Global Supply Chain
- Tom Foremski: IMHO
- The ToyBox
- Virtually Speaking
- The Web Life
- ZDNet Education
- ZDNet Government
- ZDNet Healthcare
- Zero Day
White Papers, Webcasts, and Downloads
- VMware Infrastructure: A Guide to Bottom-Line Benefits VMware Frustrated by the high cost of maintaining or building ever-larger data centers? Get the facts you need to formulate your Virtualization Action Plan. Download Now
- Five Steps to Determine When to Virtualize YourServers VMware Thinking of virtualizing the servers at your company? Use this step-by-step guide to determine when's the best time to make your big move. Download Now
- Dell Helps Medical University of South Carolina Bring the Intelligent Classroom to Life Dell Established in 1824, Medical University of South Carolina (MUSC) is one of ... Download Now
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study


