Saturday, January 23, 2010
[Lockergnome] Computer Security ~ January 23, 2010
TrendLabs | Malware Blog - by Trend Micro - 2 new articles
"TrendLabs | Malware Blog - by Trend Micro" - 2 new articles
Trend Micro To Help Proactively Protect Against Zero-Day Attacks like the recent IE Explorer ExploitThe recent attacks on Google and other large organizations (currently being referred to by others as Aurora, Google Attacks, Hydraq) were a set of carefully orchestrated, sophisticated and highly complex attacks. They comprised malicious threats to all three communication vectors – email, web and files, plus most notably, a zero-day vulnerability in Internet Explorer. In order to stay protected, businesses and end users need to deploy proactive vulnerability protection plus cloud-based threat mitigation solutions in order to stay one step ahead of the threat. We want to let our readers know that Trend Micro can help users proactively block this malicious attack and others like it – with or without the out of band patch released by Microsoft yesterday. In addition to business solutions like Trend Micro Intrusion Defense Firewall (a plug-in for OfficeScan) and Trend Micro Deep Security, we also offer a free tool – Trend Micro Browser Guard – that proactively protects home users by preventing exploits. Browser Guard protects by detecting buffer overflow and heap spray attempts as well as shellcode, thereby protecting users ahead of the threat. To download Trend Micro Browser Guard, please visit the download center at: http://www.trendmicro.com/download/product.asp?productid=102 In addition to these proactive solutions, Trend Micro recommends companies and home users install and ensure their security software is up to date – preferably that users utilize web reputation capabilities to block users from accessing sites hosting malicious code – like those used in the Google attack. In the recent attacks, targeted spam emails loaded with malware files were sent to users. In addition, users with vulnerable IE browsers may unwittingly access malicious sites containing hidden JavaScript malware that takes advantage of a zero-day vulnerability. Microsoft initially advised users to enable the use of DEP, but cybercriminals countered by introducing new exploit code that bypassed this protection. Microsoft was forced to release a patch outside of its regular Patch Tuesday cycle. While the initial attacks were aimed at specific targets, the threat has since evolved and is now fully in the wild, leaving all users on the Internet potentially at risk. To learn more about these attacks and how to protect yourself and your business please visit www.trendmicro.com. Post from: TrendLabs | Malware Blog - by Trend Micro Haiti: Earthquake Unearths MalwareAfter the earthquake that hit Haiti last week, January 12, the Internet was flooded with requests for financial donations, although it may be noted that not all of which were true to their stated intentions. Martin Roesler, Trend Micro Director of Threat Research, warns users of the internet to be very careful when following links regarding the latest earthquakes in Haiti. “We’ve already seen rogue donation sites, spam, and FakeAV related SEO poisoning using this event as social engineering and their number is still increasing. For all donations that users want to make, be sure that you use only trusted sites, that all security features of your web browser are enabled and double check manually the URL that you are connecting to. Do not trust any email that offers you ‘one click donations’ or similar services.” One such example is the spam email pictured below. Clicking the link leads to a phishing page:
It arrives as a spam mail, posing as call of relief and donations from the UNICEF International Response Fund. The message described the supposed efforts of the agency to assist the victims of the recent Haiti earthquake. Additionally, users searching for information about the event might, instead of proceeding to a legitimate news or charity website, be led to a malicious site, as seen in these suspicious Google search results:
Clicking these poisoned links lead to the installation of TROJ_FAKEAV.ZXS. There have also been reports of certain domains related to the Haiti earthquake being registered. Incidents like these are used by cybercriminals as fuel for their scams. Natural calamities are by no means the only topics taken advantage of. Celebrity deaths, viral videos and controversial stories —or just about anything that makes a huge ruckus on the internet — are the staple of social-engineering tactics employed for online fraud. This has been an alarming trend over the past few years that authorities may have expected its appearance in the Haiti tragedy. Both the Federal Bureau of Investigation and CNET have even released articles that would-be donors should read in order to protect themselves. The Smart Protection Network will be used to protect users from threats like these as they develop. Post from: TrendLabs | Malware Blog - by Trend Micro More Recent Articles |
Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change your subscription or subscribe
Unsubscribe from all current and future newsletters powered by FeedBlitz
| Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498 |
Friday, January 22, 2010
[Lockergnome] Computer Security ~ January 22, 2010
Subscribe to:
Posts (Atom)
Blog Archive
-
►
2012
(71)
- 02/12 - 02/19 (8)
- 02/05 - 02/12 (11)
- 01/29 - 02/05 (10)
- 01/22 - 01/29 (12)
- 01/15 - 01/22 (9)
- 01/08 - 01/15 (12)
- 01/01 - 01/08 (9)
-
►
2011
(706)
- 12/25 - 01/01 (3)
- 12/18 - 12/25 (12)
- 12/11 - 12/18 (14)
- 12/04 - 12/11 (10)
- 11/27 - 12/04 (10)
- 11/20 - 11/27 (3)
- 11/13 - 11/20 (10)
- 11/06 - 11/13 (15)
- 10/30 - 11/06 (10)
- 10/23 - 10/30 (11)
- 10/16 - 10/23 (11)
- 10/09 - 10/16 (8)
- 10/02 - 10/09 (14)
- 09/25 - 10/02 (7)
- 09/18 - 09/25 (14)
- 09/11 - 09/18 (11)
- 09/04 - 09/11 (10)
- 08/28 - 09/04 (11)
- 08/21 - 08/28 (11)
- 08/14 - 08/21 (9)
- 08/07 - 08/14 (12)
- 07/31 - 08/07 (14)
- 07/24 - 07/31 (9)
- 07/17 - 07/24 (11)
- 07/10 - 07/17 (13)
- 07/03 - 07/10 (10)
- 06/26 - 07/03 (9)
- 06/19 - 06/26 (12)
- 06/12 - 06/19 (13)
- 06/05 - 06/12 (18)
- 05/29 - 06/05 (10)
- 05/22 - 05/29 (14)
- 05/15 - 05/22 (11)
- 05/08 - 05/15 (12)
- 05/01 - 05/08 (10)
- 04/24 - 05/01 (13)
- 04/17 - 04/24 (17)
- 04/10 - 04/17 (25)
- 04/03 - 04/10 (18)
- 03/27 - 04/03 (18)
- 03/20 - 03/27 (21)
- 03/13 - 03/20 (21)
- 03/06 - 03/13 (23)
- 02/27 - 03/06 (20)
- 02/20 - 02/27 (15)
- 02/13 - 02/20 (15)
- 02/06 - 02/13 (25)
- 01/30 - 02/06 (23)
- 01/23 - 01/30 (19)
- 01/16 - 01/23 (15)
- 01/09 - 01/16 (18)
- 01/02 - 01/09 (18)
-
▼
2010
(1039)
- 12/26 - 01/02 (10)
- 12/19 - 12/26 (16)
- 12/12 - 12/19 (19)
- 12/05 - 12/12 (18)
- 11/28 - 12/05 (23)
- 11/21 - 11/28 (13)
- 11/14 - 11/21 (20)
- 11/07 - 11/14 (19)
- 10/31 - 11/07 (22)
- 10/24 - 10/31 (22)
- 10/17 - 10/24 (20)
- 10/10 - 10/17 (16)
- 10/03 - 10/10 (14)
- 09/26 - 10/03 (13)
- 09/19 - 09/26 (15)
- 09/12 - 09/19 (24)
- 09/05 - 09/12 (20)
- 08/29 - 09/05 (20)
- 08/22 - 08/29 (22)
- 08/15 - 08/22 (16)
- 08/08 - 08/15 (24)
- 08/01 - 08/08 (21)
- 07/25 - 08/01 (20)
- 07/18 - 07/25 (21)
- 07/11 - 07/18 (19)
- 07/04 - 07/11 (18)
- 06/27 - 07/04 (17)
- 06/20 - 06/27 (17)
- 06/13 - 06/20 (19)
- 06/06 - 06/13 (26)
- 05/30 - 06/06 (17)
- 05/23 - 05/30 (18)
- 05/16 - 05/23 (16)
- 05/09 - 05/16 (24)
- 05/02 - 05/09 (18)
- 04/25 - 05/02 (21)
- 04/18 - 04/25 (21)
- 04/11 - 04/18 (27)
- 04/04 - 04/11 (19)
- 03/28 - 04/04 (24)
- 03/21 - 03/28 (23)
- 03/14 - 03/21 (17)
- 03/07 - 03/14 (28)
- 02/28 - 03/07 (26)
- 02/21 - 02/28 (18)
- 02/14 - 02/21 (18)
- 02/07 - 02/14 (30)
- 01/31 - 02/07 (24)
- 01/24 - 01/31 (19)
- 01/17 - 01/24 (20)
- 01/10 - 01/17 (28)
- 01/03 - 01/10 (19)
-
►
2009
(1033)
- 12/27 - 01/03 (10)
- 12/20 - 12/27 (18)
- 12/13 - 12/20 (20)
- 12/06 - 12/13 (24)
- 11/29 - 12/06 (19)
- 11/22 - 11/29 (15)
- 11/15 - 11/22 (19)
- 11/08 - 11/15 (23)
- 11/01 - 11/08 (23)
- 10/25 - 11/01 (22)
- 10/18 - 10/25 (20)
- 10/11 - 10/18 (23)
- 10/04 - 10/11 (21)
- 09/27 - 10/04 (23)
- 09/20 - 09/27 (21)
- 09/13 - 09/20 (18)
- 09/06 - 09/13 (23)
- 08/30 - 09/06 (18)
- 08/23 - 08/30 (21)
- 08/16 - 08/23 (23)
- 08/09 - 08/16 (20)
- 08/02 - 08/09 (28)
- 07/26 - 08/02 (30)
- 07/19 - 07/26 (25)
- 07/12 - 07/19 (27)
- 07/05 - 07/12 (26)
- 06/28 - 07/05 (17)
- 06/21 - 06/28 (26)
- 06/14 - 06/21 (20)
- 06/07 - 06/14 (30)
- 05/31 - 06/07 (19)
- 05/24 - 05/31 (9)
- 04/12 - 04/19 (7)
- 04/05 - 04/12 (25)
- 03/29 - 04/05 (25)
- 03/22 - 03/29 (27)
- 03/15 - 03/22 (25)
- 03/08 - 03/15 (29)
- 03/01 - 03/08 (22)
- 02/22 - 03/01 (23)
- 02/15 - 02/22 (24)
- 02/08 - 02/15 (22)
- 02/01 - 02/08 (26)
- 01/25 - 02/01 (20)
- 01/18 - 01/25 (19)
- 01/11 - 01/18 (34)
- 01/04 - 01/11 (24)
-
►
2008
(1133)
- 12/28 - 01/04 (19)
- 12/21 - 12/28 (19)
- 12/14 - 12/21 (27)
- 12/07 - 12/14 (39)
- 11/30 - 12/07 (25)
- 11/23 - 11/30 (16)
- 11/16 - 11/23 (20)
- 11/09 - 11/16 (27)
- 11/02 - 11/09 (37)
- 10/26 - 11/02 (29)
- 10/19 - 10/26 (29)
- 10/12 - 10/19 (29)
- 10/05 - 10/12 (25)
- 09/28 - 10/05 (18)
- 09/21 - 09/28 (28)
- 09/14 - 09/21 (23)
- 09/07 - 09/14 (29)
- 08/31 - 09/07 (22)
- 08/24 - 08/31 (18)
- 08/17 - 08/24 (23)
- 08/10 - 08/17 (33)
- 08/03 - 08/10 (23)
- 07/27 - 08/03 (33)
- 07/20 - 07/27 (25)
- 07/13 - 07/20 (27)
- 07/06 - 07/13 (30)
- 06/29 - 07/06 (23)
- 06/22 - 06/29 (21)
- 06/15 - 06/22 (25)
- 06/08 - 06/15 (30)
- 06/01 - 06/08 (36)
- 05/25 - 06/01 (24)
- 05/18 - 05/25 (21)
- 05/11 - 05/18 (25)
- 05/04 - 05/11 (25)
- 04/27 - 05/04 (20)
- 04/20 - 04/27 (22)
- 04/13 - 04/20 (38)
- 04/06 - 04/13 (35)
- 03/30 - 04/06 (28)
- 03/23 - 03/30 (16)
- 03/16 - 03/23 (17)
- 03/09 - 03/16 (23)
- 03/02 - 03/09 (14)
- 02/24 - 03/02 (10)
- 02/17 - 02/24 (7)






