<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>The Security Blog» Latest InfoSec Threat Research &amp; News | TheSecurityBlog.com</title> <link>http://www.thesecurityblog.com</link> <description>Security Threat Research News</description> <lastBuildDate>Fri, 03 Sep 2010 13:09:50 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0.1</generator> <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/TheSecurityBlog" /><feedburner:info uri="thesecurityblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>TheSecurityBlog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>Security vulnerabilities in Pligg CMS version 1.0.4</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/u4ERN9sM0po/</link> <comments>http://www.thesecurityblog.com/2010/09/security-vulnerabilities-in-pligg-cms-version-1-0-4/#comments</comments> <pubDate>Fri, 03 Sep 2010 13:09:50 +0000</pubDate> <dc:creator>Acunetix</dc:creator> <category><![CDATA[Articles]]></category> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Acunetix]]></category> <category><![CDATA[Acunetix WVS]]></category> <category><![CDATA[advisory]]></category> <category><![CDATA[cross site scripting]]></category> <category><![CDATA[pligg]]></category> <category><![CDATA[sql injection]]></category> <category><![CDATA[Web Application Security]]></category> <category><![CDATA[web security zone]]></category> <category><![CDATA[web vulnerabilities]]></category> <category><![CDATA[xss]]></category><guid isPermaLink="false">http://www.acunetix.com/blog/?p=2011</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/f_Gcn6aRpN_ACJfuTtrG7lXXins/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/f_Gcn6aRpN_ACJfuTtrG7lXXins/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/f_Gcn6aRpN_ACJfuTtrG7lXXins/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/f_Gcn6aRpN_ACJfuTtrG7lXXins/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;While beta testing the latest version of Acunetix WVS v7, we found a large number of security vulnerabilities in various web applications. In the following days we will publish some of these vulnerabilities.  Note that ...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/u4ERN9sM0po" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/security-vulnerabilities-in-pligg-cms-version-1-0-4/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/security-vulnerabilities-in-pligg-cms-version-1-0-4/</feedburner:origLink></item> <item><title>The correct CV(or malware)</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/yEPycZ-KjVk/</link> <comments>http://www.thesecurityblog.com/2010/09/the-correct-cvor-malware/#comments</comments> <pubDate>Fri, 03 Sep 2010 08:09:57 +0000</pubDate> <dc:creator>Xinran</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Malware]]></category> <category><![CDATA[sophos]]></category> <category><![CDATA[SophosLabs]]></category> <category><![CDATA[vulnerabilities]]></category><guid isPermaLink="false">http://www.sophos.com/blogs/sophoslabs/?p=10921</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LEPBEEavvyiKNmzWe1To8RtWkgg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LEPBEEavvyiKNmzWe1To8RtWkgg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LEPBEEavvyiKNmzWe1To8RtWkgg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LEPBEEavvyiKNmzWe1To8RtWkgg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Today we have observed some messages which at first glance appeared to be somebody trying to correct their mistakes on the CV they sent out.
All messages had the same body text that read as follows:
Thank you for the chat yesterday, it really helped me get a clearer idea
of recruitment as well as exploring any potential [...]&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/yEPycZ-KjVk" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/the-correct-cvor-malware/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/the-correct-cvor-malware/</feedburner:origLink></item> <item><title>Zombie game inspires scammers to target your brains</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/-EX4X_iUyy8/</link> <comments>http://www.thesecurityblog.com/2010/09/zombie-game-inspires-scammers-to-target-your-brains/#comments</comments> <pubDate>Fri, 03 Sep 2010 07:17:00 +0000</pubDate> <dc:creator>paperghost</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Sunbelt Software]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fLPvISl7LHjFWpgWYDuI_fj92Z0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fLPvISl7LHjFWpgWYDuI_fj92Z0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fLPvISl7LHjFWpgWYDuI_fj92Z0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fLPvISl7LHjFWpgWYDuI_fj92Z0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Zombies. Whether they’re shuffling Romero types, the wisecracking “send more cops” variety or even the crumbling Fulci efforts it’s important to be prepared (no, I’m not counting the ones that run. Those are stupid).As you can see, I’m re...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/-EX4X_iUyy8" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/zombie-game-inspires-scammers-to-target-your-brains/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/zombie-game-inspires-scammers-to-target-your-brains/</feedburner:origLink></item> <item><title>We are good at finding names</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/h2hFpqU-X8w/</link> <comments>http://www.thesecurityblog.com/2010/09/we-are-good-at-finding-names/#comments</comments> <pubDate>Fri, 03 Sep 2010 01:30:54 +0000</pubDate> <dc:creator>PandaLabs Blog</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Panda]]></category> <category><![CDATA[PandaLabs]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Ofab2HzUl7lA6a1OYTMRlzrI8DM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Ofab2HzUl7lA6a1OYTMRlzrI8DM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Ofab2HzUl7lA6a1OYTMRlzrI8DM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Ofab2HzUl7lA6a1OYTMRlzrI8DM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;We have received this file today. Rogue creators are spending less time creating interface and spending more time to find a new name.Malware name: Adware/MySecurityShieldVirusTotal
File name: 622ed7d54cbeb06ef977ee111e2b97ddf3f78dd5
Submission date...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/h2hFpqU-X8w" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/we-are-good-at-finding-names/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/we-are-good-at-finding-names/</feedburner:origLink></item> <item><title>To infinity and beyond</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/nlyU4Jx3ahA/</link> <comments>http://www.thesecurityblog.com/2010/09/to-infinity-and-beyond/#comments</comments> <pubDate>Fri, 03 Sep 2010 00:02:51 +0000</pubDate> <dc:creator>Sophos</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[General]]></category> <category><![CDATA[sophos]]></category> <category><![CDATA[SophosLabs]]></category><guid isPermaLink="false">http://www.sophos.com/blogs/sophoslabs/?p=10857</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/VHL01ZcOvUSNnJo-BM2gB9gbvCQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/VHL01ZcOvUSNnJo-BM2gB9gbvCQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/VHL01ZcOvUSNnJo-BM2gB9gbvCQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/VHL01ZcOvUSNnJo-BM2gB9gbvCQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;SophosLabs has discovered a technique in anti-virus marketing, which we detect as Spin/BigNumber-P. Typical behaviour involves phrases such as &amp;#8220;Product detects X viruses!&amp;#8221;, where X is a large, rather exact-sounding number. Some variants involve high-tech numerical displays updated in real-time with ever growing numbers. This technique has been spotted in the wild.
Never one to be [...]&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/nlyU4Jx3ahA" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/to-infinity-and-beyond/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/to-infinity-and-beyond/</feedburner:origLink></item> <item><title>Organized Web Mobsters Getting Jobs Inside Corporations</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/LMPWqp7Uo74/</link> <comments>http://www.thesecurityblog.com/2010/09/organized-web-mobsters-getting-jobs-inside-corporations/#comments</comments> <pubDate>Fri, 03 Sep 2010 00:01:14 +0000</pubDate> <dc:creator>Robert Siciliano</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Corporate Responsibility]]></category> <category><![CDATA[data breach]]></category> <category><![CDATA[identity protection]]></category> <category><![CDATA[identity theft]]></category> <category><![CDATA[insiders]]></category> <category><![CDATA[Malware]]></category> <category><![CDATA[McAfee]]></category> <category><![CDATA[McAfee Security Insights]]></category> <category><![CDATA[organized crime]]></category> <category><![CDATA[Robert Siciliano]]></category><guid isPermaLink="false">http://siblog.mcafee.com/?p=3907</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/y-P6QwI5SDo0bDtz786XLYeYbrU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/y-P6QwI5SDo0bDtz786XLYeYbrU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/y-P6QwI5SDo0bDtz786XLYeYbrU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/y-P6QwI5SDo0bDtz786XLYeYbrU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;In 2009, there were a reported 140 million records compromised, compared to 360 million in 2008. In 2010 there have been almost 13 million records stolen. But don’t have a party just yet. Criminals are fine-tuning their craft and getting better. The industry just isn’t making it as easy. 97% of those records were stolen [...]&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/LMPWqp7Uo74" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/organized-web-mobsters-getting-jobs-inside-corporations/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/organized-web-mobsters-getting-jobs-inside-corporations/</feedburner:origLink></item> <item><title>Putting BitTorrent Under the Spotlight</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/bEUlgn4USM8/</link> <comments>http://www.thesecurityblog.com/2010/09/putting-bittorrent-under-the-spotlight/#comments</comments> <pubDate>Thu, 02 Sep 2010 21:48:57 +0000</pubDate> <dc:creator>Wade</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Palo Alto Networks]]></category> <category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">http://www.paloaltonetworks.com/researchcenter/?p=1239</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2i4ffhvYnG2fNXqJiyVLSqTpUXM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2i4ffhvYnG2fNXqJiyVLSqTpUXM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2i4ffhvYnG2fNXqJiyVLSqTpUXM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2i4ffhvYnG2fNXqJiyVLSqTpUXM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;We have added a new video that introduces the key security concerns swirling around BitTorrent and specifically how to manage the risks that this incredibly popular application brings to your networks. We will cover how BitTorrent has evolved to avoid detection by traditional firewalls and IPS, how hackers are using BitTorrent to control malware, and [...]&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/bEUlgn4USM8" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/putting-bittorrent-under-the-spotlight/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/putting-bittorrent-under-the-spotlight/</feedburner:origLink></item> <item><title>Ben Franklin’s Endpoint Security Advice</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/XRMxqGgZg7c/</link> <comments>http://www.thesecurityblog.com/2010/09/ben-franklin%e2%80%99s-endpoint-security-advice/#comments</comments> <pubDate>Thu, 02 Sep 2010 20:17:57 +0000</pubDate> <dc:creator>Lumension</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Endpoint Protection]]></category> <category><![CDATA[endpoint security]]></category> <category><![CDATA[IT Security]]></category> <category><![CDATA[Lumension]]></category><guid isPermaLink="false">http://blog.lumension.com/?p=3309</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1z7ZYQjfpj0_QSn2cC-xWBkSUBs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1z7ZYQjfpj0_QSn2cC-xWBkSUBs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1z7ZYQjfpj0_QSn2cC-xWBkSUBs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1z7ZYQjfpj0_QSn2cC-xWBkSUBs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Ben Franklin dished out some pretty good security advice in his day. In fact, he was one of the most well known security professionals of his time. Many of you may realize it was Franklin that coined the saying ‘An ounce of prevention is worth a pound of cure’ but what you might not know [...]&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/XRMxqGgZg7c" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/ben-franklin%e2%80%99s-endpoint-security-advice/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/ben-franklin%e2%80%99s-endpoint-security-advice/</feedburner:origLink></item> <item><title>Safe Web Surfing Rule # 1: READ the URL</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/KJuPmB4tZbY/</link> <comments>http://www.thesecurityblog.com/2010/09/safe-web-surfing-rule-1-read-the-url/#comments</comments> <pubDate>Thu, 02 Sep 2010 19:54:00 +0000</pubDate> <dc:creator>Tom Kelchner</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Sunbelt Software]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/IUNMEejVYFrD5r8QwjdQGL9cQZ8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IUNMEejVYFrD5r8QwjdQGL9cQZ8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/IUNMEejVYFrD5r8QwjdQGL9cQZ8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IUNMEejVYFrD5r8QwjdQGL9cQZ8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Safe Web Surfing Rule # 2: See Rule # 1Email and social networking sites might be a global phenomena, but English remains widely used in URLs and elsewhere on the Internet. In the English verbiage in malicious email, URLs and web sites there are words ...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/KJuPmB4tZbY" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/safe-web-surfing-rule-1-read-the-url/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <enclosure url="" length="" type="" /> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/safe-web-surfing-rule-1-read-the-url/</feedburner:origLink></item> <item><title>U.S. Labor Day: phishers won’t be on holiday</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/wIKfy6pBaQE/</link> <comments>http://www.thesecurityblog.com/2010/09/u-s-labor-day-phishers-won%e2%80%99t-be-on-holiday/#comments</comments> <pubDate>Thu, 02 Sep 2010 17:18:00 +0000</pubDate> <dc:creator>Tom Kelchner</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Sunbelt Software]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/17AGZKXC5324PS76NS8z-3xTy2E/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/17AGZKXC5324PS76NS8z-3xTy2E/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/17AGZKXC5324PS76NS8z-3xTy2E/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/17AGZKXC5324PS76NS8z-3xTy2E/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Holidays are times when we see a big uptick in email retail advertising. They are also a time when we should be especially aware of threats from phishing schemes in all those ads.In that surge of emails promoting holiday sales we can expect fraudulent ...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/wIKfy6pBaQE" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/u-s-labor-day-phishers-won%e2%80%99t-be-on-holiday/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/u-s-labor-day-phishers-won%e2%80%99t-be-on-holiday/</feedburner:origLink></item> <item><title>Where’s Waldo? Adjusting Law and Policy for Location-Based Services</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/xvKHT2_RstY/</link> <comments>http://www.thesecurityblog.com/2010/09/where%e2%80%99s-waldo-adjusting-law-and-policy-for-location-based-services/#comments</comments> <pubDate>Thu, 02 Sep 2010 13:46:38 +0000</pubDate> <dc:creator>shanford@cisco.com</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Cisco]]></category> <category><![CDATA[Cisco Security]]></category><guid isPermaLink="false">http://blogs.cisco.com/security/comments/wheres_waldo_adjusting_law_and_policy_for_location-based_services/</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1DVp2rqKNrIa5M9sJlUeCdyW8Cw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1DVp2rqKNrIa5M9sJlUeCdyW8Cw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1DVp2rqKNrIa5M9sJlUeCdyW8Cw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1DVp2rqKNrIa5M9sJlUeCdyW8Cw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Last month, my colleague Christopher Burgess shared some thoughts on the &amp;#8220;double-edged sword&amp;#8221; of location-based services at the Huffington Post. In his post, Christopher highlighted how these services could alternately be a benefit, and whe...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/xvKHT2_RstY" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/where%e2%80%99s-waldo-adjusting-law-and-policy-for-location-based-services/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/where%e2%80%99s-waldo-adjusting-law-and-policy-for-location-based-services/</feedburner:origLink></item> <item><title>Chilean miners tragedy used to distribute malware</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/2JQkhaj3sOQ/</link> <comments>http://www.thesecurityblog.com/2010/09/chilean-miners-tragedy-used-to-distribute-malware/#comments</comments> <pubDate>Thu, 02 Sep 2010 12:00:15 +0000</pubDate> <dc:creator>PandaLabs Blog</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Panda]]></category> <category><![CDATA[PandaLabs]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/15SL1ptLqbTZzK8RtHXvtZaY9WA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/15SL1ptLqbTZzK8RtHXvtZaY9WA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/15SL1ptLqbTZzK8RtHXvtZaY9WA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/15SL1ptLqbTZzK8RtHXvtZaY9WA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;We want to warn you of a Banker Trojan that is using the news of the miners trapped in Chile to be distributed and infect users. It has been detected as Banbra.GUC.The malicious file reaches the computer with the following icon:When this file is ...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/2JQkhaj3sOQ" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/chilean-miners-tragedy-used-to-distribute-malware/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/chilean-miners-tragedy-used-to-distribute-malware/</feedburner:origLink></item> <item><title>Tenable Security Showcase – New York City</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/jAfgXseNRHs/</link> <comments>http://www.thesecurityblog.com/2010/09/tenable-security-showcase-new-york-city/#comments</comments> <pubDate>Thu, 02 Sep 2010 11:00:00 +0000</pubDate> <dc:creator>Paul Asadoorian</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Events]]></category> <category><![CDATA[Nessus]]></category> <category><![CDATA[Tenable Events]]></category> <category><![CDATA[Tenable Network Security]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/CF4AoVMRuNIb2hX6STbcOOxWd24/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/CF4AoVMRuNIb2hX6STbcOOxWd24/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/CF4AoVMRuNIb2hX6STbcOOxWd24/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/CF4AoVMRuNIb2hX6STbcOOxWd24/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Please join Tenable's own Ron Gula, Renaud Deraison, Marcus Ranum and Paul Asadoorian for a Security Showcase on October 6, from 8:30am to 2:00pm at the New York Marriott East Side, 525 Lexington Ave. at 49th Street in New York...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/jAfgXseNRHs" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/tenable-security-showcase-new-york-city/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/tenable-security-showcase-new-york-city/</feedburner:origLink></item> <item><title>Faulty Fiverrs</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/wgcL11kzNjE/</link> <comments>http://www.thesecurityblog.com/2010/09/faulty-fiverrs/#comments</comments> <pubDate>Thu, 02 Sep 2010 10:43:00 +0000</pubDate> <dc:creator>paperghost</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Sunbelt Software]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Xuof8OPA-8VU0O48AyxLKjOCkxE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Xuof8OPA-8VU0O48AyxLKjOCkxE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Xuof8OPA-8VU0O48AyxLKjOCkxE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Xuof8OPA-8VU0O48AyxLKjOCkxE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Fiverr is an excellent site that allows you to buy / sell services – all of which cost $5.There’s all sorts of crazy things on there, but does it attract rogues and individuals who generally want to mess up your day?You bet. With a little furti...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/wgcL11kzNjE" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/faulty-fiverrs/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/faulty-fiverrs/</feedburner:origLink></item> <item><title>FakeAV, now with sounds</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/EO482jdtND0/</link> <comments>http://www.thesecurityblog.com/2010/09/fakeav-now-with-sounds/#comments</comments> <pubDate>Thu, 02 Sep 2010 05:17:23 +0000</pubDate> <dc:creator>Prashant Kumar, SophosLabs AU</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[General]]></category> <category><![CDATA[sophos]]></category> <category><![CDATA[SophosLabs]]></category><guid isPermaLink="false">http://www.sophos.com/blogs/sophoslabs/?p=10866</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/eAfeLHqYnJZg4yjOwoed8bygI8s/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eAfeLHqYnJZg4yjOwoed8bygI8s/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/eAfeLHqYnJZg4yjOwoed8bygI8s/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eAfeLHqYnJZg4yjOwoed8bygI8s/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Recently, creators of Fake Anti Virus software have been getting quite creative and somewhat &amp;#8220;professional&amp;#8221; in designing the look and feel of their fake software.
Today I came across one with sounds.Whenever the malware does a fake scan and finds something wrong with the user’s computer, a lady&amp;#8217;s voice (in typical GPS style, I might add) [...]&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/EO482jdtND0" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/fakeav-now-with-sounds/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/fakeav-now-with-sounds/</feedburner:origLink></item> <item><title>Cyberthieves Hit Another University</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/TRETUR754ho/</link> <comments>http://www.thesecurityblog.com/2010/09/cyberthieves-hit-another-university/#comments</comments> <pubDate>Wed, 01 Sep 2010 23:00:00 +0000</pubDate> <dc:creator>Walt Conway</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[PCI]]></category> <category><![CDATA[PCI Security Standards Council]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/kNnhrSrnY5ipsWfwJ-YqcncNOXY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kNnhrSrnY5ipsWfwJ-YqcncNOXY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/kNnhrSrnY5ipsWfwJ-YqcncNOXY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kNnhrSrnY5ipsWfwJ-YqcncNOXY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;This post isn't PCI-related, but it does address your security and your money, so read on...According to a report in Krebs on Security, cyber thieves made off with nearly $1 million from a University of Virginia satellite campus:According to several so...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/TRETUR754ho" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/cyberthieves-hit-another-university/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/cyberthieves-hit-another-university/</feedburner:origLink></item> <item><title>Security Advisory for NetWare 6.5 OpenSSH</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/A5Uzm_87r7M/</link> <comments>http://www.thesecurityblog.com/2010/09/security-advisory-for-netware-6-5-openssh/#comments</comments> <pubDate>Wed, 01 Sep 2010 22:13:05 +0000</pubDate> <dc:creator>DVLabs: Blogs</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[tippingpoint]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FYUqZhZkiTRlB7xZunhkGw90luc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FYUqZhZkiTRlB7xZunhkGw90luc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/FYUqZhZkiTRlB7xZunhkGw90luc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FYUqZhZkiTRlB7xZunhkGw90luc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Posted by Zef CekajThis is a little information clarifying the exploitability of ZDI-10-169 as discovered by ZDI researcher Francis Provencher.
Novell has classified this bug as a Denial of Service and will not be issuing
a patch. Novell's official s...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/A5Uzm_87r7M" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/security-advisory-for-netware-6-5-openssh/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/security-advisory-for-netware-6-5-openssh/</feedburner:origLink></item> <item><title>GFI/Sunbelt Labs quarterly briefing is on Web</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/C7_YNv9_MPE/</link> <comments>http://www.thesecurityblog.com/2010/09/gfisunbelt-labs-quarterly-briefing-is-on-web/#comments</comments> <pubDate>Wed, 01 Sep 2010 19:38:00 +0000</pubDate> <dc:creator>Tom Kelchner</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Sunbelt Software]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/68_eg9rPagAmKBbnqXn1tDjjmUc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/68_eg9rPagAmKBbnqXn1tDjjmUc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/68_eg9rPagAmKBbnqXn1tDjjmUc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/68_eg9rPagAmKBbnqXn1tDjjmUc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;“Turn the Tables on the Bad Guys, Malware Unmasked”The Sunbelt Labs quarterly briefing “Turn the Tables on the Bad Guys, Malware Unmasked” is available for your viewing pleasure.Schwartzkopf began by describing GFI's recent acquisition of ...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/C7_YNv9_MPE" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/gfisunbelt-labs-quarterly-briefing-is-on-web/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <enclosure url="http://www.blogger.com/video-play.mp4?contentId=344331f42a027c34&amp;amp;type=video/mp4" length="0" type="video/mp4" /> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/gfisunbelt-labs-quarterly-briefing-is-on-web/</feedburner:origLink></item> <item><title>How Do You Find 200,000 Unique Samples a Day?</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/l_LfwZqHzpI/</link> <comments>http://www.thesecurityblog.com/2010/09/how-do-you-find-200000-unique-samples-a-day/#comments</comments> <pubDate>Wed, 01 Sep 2010 17:22:43 +0000</pubDate> <dc:creator>TheSecurityBlogger</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[active heuristics]]></category> <category><![CDATA[ESET]]></category> <category><![CDATA[generic detection]]></category> <category><![CDATA[heuristics]]></category> <category><![CDATA[passive heuristics]]></category> <category><![CDATA[Randy Abrams]]></category> <category><![CDATA[samples]]></category> <category><![CDATA[Threats]]></category><guid isPermaLink="false">http://blog.eset.com/?p=4934</guid> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/YDYNG4liev7jBUhRB54IX9mnkaw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YDYNG4liev7jBUhRB54IX9mnkaw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/YDYNG4liev7jBUhRB54IX9mnkaw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YDYNG4liev7jBUhRB54IX9mnkaw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;I recently received a couple of questions about signatures from a reader.
1- You said that ESET receives around 200000 unique malware samples daily, so does ESET detect most of them or detect only the malwares that their signatures are listed here: http://www.eset.com/threat-center/threatsense-updates ?
2- Nowadays why signatures are written? Are they written to detect malwares initially, ... &lt;a
href="http://blog.eset.com/2010/09/01/how-do-you-find-200000-unique-samples-a-day"&gt;&lt;strong&gt;Read More.&lt;/strong&gt;&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/l_LfwZqHzpI" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/how-do-you-find-200000-unique-samples-a-day/feed/</wfw:commentRss> <slash:comments>0</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/how-do-you-find-200000-unique-samples-a-day/</feedburner:origLink></item> <item><title>Mariposa: the Slovenian story</title><link>http://feedproxy.google.com/~r/TheSecurityBlog/~3/AMgam2GiqLk/</link> <comments>http://www.thesecurityblog.com/2010/09/mariposa-the-slovenian-story/#comments</comments> <pubDate>Wed, 01 Sep 2010 16:00:42 +0000</pubDate> <dc:creator>PandaLabs Blog</dc:creator> <category><![CDATA[Threat Research]]></category> <category><![CDATA[Panda]]></category> <category><![CDATA[PandaLabs]]></category><guid isPermaLink="false" /> <description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/v6t-ndAuq_y07IX5bFo6INIBMDU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/v6t-ndAuq_y07IX5bFo6INIBMDU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/v6t-ndAuq_y07IX5bFo6INIBMDU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/v6t-ndAuq_y07IX5bFo6INIBMDU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Some weeks ago it was announced that the Slovenian police had arrested some individuals who were responsible for selling the bot that was used to build the Mariposa botnet, whose creators were also arrested in Spain last March. Many confusing news have...&lt;img src="http://feeds.feedburner.com/~r/TheSecurityBlog/~4/AMgam2GiqLk" height="1" width="1"/&gt;</description> <wfw:commentRss>http://www.thesecurityblog.com/2010/09/mariposa-the-slovenian-story/feed/</wfw:commentRss> <slash:comments>1</slash:comments> <feedburner:origLink>http://www.thesecurityblog.com/2010/09/mariposa-the-slovenian-story/</feedburner:origLink></item> </channel> </rss><!-- Served from: www.thesecurityblog.com @ 2010-09-03 13:30:54 by W3 Total Cache -->
