Email Security

Worm in Twitter invites

Chuck Miller June 18, 2009

A wave of fake email Twitter invitations carry a mass-mailing worm, Symantec researchers said Thursday. The invitations look like they've come from a Twitter account, except the URL that would ordinarily be part of the standard text is missing. What is included is an attachment named "Invitation Card.zip." Clicking it installs a mass-mailing worm that gathers email addresses from the compromised computer and spreads via removable drives. — CAM
 

Latest upgrade to iPhone includes 46 security fixes

Greg Masters June 18, 2009

Apple on Wednesday released the long-anticipated upgrade to its iPhone operating system.
 

Google responds to call for more security

Chuck Miller June 17, 2009

In reaction to a letter from 37 respected names in the computer security field, Google is considering tighter security of its web applications.
 

Iran election protesters use Twitter to recruit hackers

Angela Moscaritolo June 15, 2009

Political unrest resulting from the presidential election in Iran has escalated to a cyberwar between the Iranian government and activists, according to security experts monitoring the situation.
 

Air France crash prompts spam, malware outbreak

Dan Kaplan June 12, 2009

As expected, spammers and malware writers are trying to cash in on the Air France disaster.
 

Army ends ban on Facebook, Flickr, other social media sites

Angela Moscaritolo June 11, 2009

Updated: Certain U.S. Army bases that formerly blocked access to Web 2.0 sites now permit users to surf to sites such as Facebook and Flickr.
 

Pricewert shutdown brought only short-lived drop in spam

Angela Moscaritolo June 10, 2009

Any spam drop that resulted after the takedown of a rogue internet service provider last week was short-lived, researchers said Tuesday.
 

Father's Day phishing plug

Angela Moscaritolo June 08, 2009

The Federal Trade Commission announced Friday that it has created a Father's Day e-card to offer tips on how to avoid becoming a phishing victim. The animated fish-themed card gives examples of typical phishing emails and warns fathers against giving up personal or financial information and to be wary of opening suspicious attachments. The card is available at: http://www.ftc.gov/dad. — AM
 

The many morphs of a phishing/malware scam

Angela Moscaritolo June 03, 2009

A new attack targeting Outlook users has morphed from trying to retrieve login credentials to attempting to infect users with fake anti-virus products.
 

Bank of America certificate scam propagating Waledac, Virut

Angela Moscaritolo June 02, 2009

A new spam campaign disguised as a Bank of America email telling users they need to update their digital certificate is attempting to lure users into installing the Waledac worm.
 

BlackBerry patches PDF flaws

Angela Moscaritolo May 27, 2009

Research In Motion on Tuesday issued a security software update to address multiple vulnerabilities that exist in the PDF Distiller of the BlackBerry Attachment Service component in BlackBerry Enterprise Server. Because of these vulnerabilities, an attacker could create a malicious PDF file, which when opened on a BlackBerry smartphone, could corrupt memory or execute arbitrary code on the computer that hosts the BlackBerry Attachment Service, RIM said in its advisory. — AM
 

Phishers continue to wage war on Facebook, Twitter

Dan Kaplan May 22, 2009

Social networking sites are all the rage within phishing circles these days.
 

Social Security Administration spoofed in phishing scam

Angela Moscaritolo May 11, 2009

Scammers have spoofed the Social Security Administration's website in a phishing scam targeted at those who will be receiving an economic recovery payment this month.
 

Mac worm poses little risk, represents cross-platform innovation

Angela Moscaritolo May 05, 2009

A recently discovered Macintosh worm, known as OSX/Tored.A, remains a low-risk threat but is an indication that malware authors are not turning a blind eye to the Apple platform, researchers said Tuesday.
 

Swine flu spam leveling off, but attacks continue

Dan Kaplan May 01, 2009

As reports of swine flu infections grow across the world, spammers and malware purveyors continue to try to cash in.
 

Facebook neutralizes phishing attack

Dan Kaplan April 30, 2009

Fraudsters, using hijacked Facebook accounts, tried to lure users of the social networking site into divulging their login credentials.
 

Federal Reserve malware ruse

Dan Kaplan April 29, 2009

IT administrators should be on the lookout for a new round of spam claiming to come from the Federal Reserve Bank. It tries to redirect users to a malware-serving website, the Shadowserver Foundation warned Wednesday. The volunteer watchdog said the emails contain a link to a website that attempts to load a number of exploits, including some for PDF and Flash, in the background with hopes of infecting machines with a trojan. Shadowserver listed a number of offending domains being used in the ploy. — DK
 

Swine flu cases cause outbreak of fraud on internet

Dan Kaplan April 27, 2009

Reports of swine flu in Mexico and the United States has caused an outbreak of its own on the internet, with reports of a precipitous rise in spam and rogue internet sites being created to reference the hot news item.
 

Microsoft Forefront now in the clouds

Angela Moscaritolo April 16, 2009

Microsoft has extended its Forefront brand and is now putting messaging security into the cloud.
 

Phishing increased 40 percent in 2008

Angela Moscaritolo April 15, 2009

The percentage of people losing money to phishing attacks is higher than ever -- five million consumers in the United States fell victim during 2008, an increase of 40 percent over 2007, according to a new report from Gartner.
 

Marshal8e6 acquires Avinti

Angela Moscaritolo April 13, 2009

Web and email security vendor Marshal8e6 announced on Tuesday its acquisition of behavioral malware detection vendor Avinti for an undisclosed sum. The acquisition will better equip Marshal8e6 to stop blended email threats -- email that contains active malware content or links to websites where malware is downloaded, according to a statement from Marshal8e6. The acquisition follows the merger of Marshal and 8e6 Technologies last November. — AM
 

Spammers capitalize on Italy earthquake

Chuck Miller April 09, 2009

As the death toll from the earthquake in central Italy grows, spammers have moved to capitalize on the catastrophe.
 

Tax scam season has arrived

Angela Moscaritolo April 09, 2009

With the U.S. tax filing deadline looming, cybercriminals are putting fraud efforts into high gear with tax-related phishing emails and websites designed to lure users into handing over their personal information, security firms are warning.
 

Realtors hack competitor email

Angela Moscaritolo April 07, 2009

Three real estate agents in Rockingham, N.C. were charged with illegally accessing a Hotmail account belonging to the employee of a competitor. RE/MAX Tri City Realty agents Wendy Robson Massagee, 43; Kim Dawn Whitley, 40; and Jamie Moss-Godfrey, 41, allegedly used the victim's username and password to access the account and view work-related emails, according to a report in the Richmond County (N.C.) Daily Journal. All three were released and are scheduled to appear in local court on April 23. - AM
 

Microsoft and Facebook battle Koobface together

Angela Moscaritolo April 06, 2009

With Microsoft's assistance, Facebook has made great strides in fighting Koobface, a worm that has been wreaking havoc on social networking sites since last May.
 

"Nigerian scam" fraudsters go to jail

Chuck Miller April 03, 2009

After pleading guilty last year, two Nigerians and a French citizen were sentenced by a New York federal judge to jail Thursday for scamming $1.2 million through email.
 

GhostNet spy network phishes international victims

Chuck Miller March 30, 2009

The recently uncovered cyberespionage network named GhostNet made use of phishing malware to attack the nearly 1,300 computers that are said to have been compromised by servers traced to China.
 

Fatal attraction: Latest "delivery notice" trojan spews forth

Greg Masters March 27, 2009

A new torrent of spam, disguised as a message from package carrier DHL, is making its way into inboxes.
 

Privacy group urges FTC to investigate Google's cloud services

Angela Moscaritolo March 18, 2009

The Electronic Privacy Information Center, a privacy advocacy group, filed a complaint with the Federal Trade Commission on Tuesday urging an investigation of Google's cloud computing services to determine the adequacy of its privacy and security safeguards.
 

Spam attacks focus on victims' economic gloom

Chuck Miller March 17, 2009

The economy remains the main topic spammers focus on to lure users into opening emails with malicious links.