Browser Bug Could Allow Phishing Without Email

Monday, January 12th, 2009

A bug found in all major browsers could make it easier for criminals to steal online banking credentials using a new type of attack called "in-session phishing," according to researchers at security vendor Trusteer. In-session phishing (pdf) gives the bad guys a solution to the biggest problem facing phishers these days: ...

Hacker Leaves Message for Microsoft in Trojan Code

Monday, January 12th, 2009

Here's a new way to get Microsoft to pay attention to you: Slip a brief message into the malicious Trojan horse program you just wrote. That's what an unnamed Russian hacker did recently with a variation of Win32/Zlob, a Trojan program victims are being tricked into installing on their computers. The message ...

Google adds HTTPS-only browsing to Chrome

Friday, January 9th, 2009

Google has quietly released a pre-beta version of Google Chrome 2.0 with a new HTTPS-only browsing mode. The new feature lets users add “force-https to your Google Chrome shortcut” to only load Web sites with valid security certificates.   “Sites with SSL certificate errors will not load,” the company explained. The newest Chrome ...

Downadup Blocklist

Friday, January 9th, 2009

Here's a list of domains that are currently distributing the Downadup worm: http://www.f-secure.com/weblog/archives/downadup_domain_blocklist.txt

Storm Worm botnet cracked wide open

Friday, January 9th, 2009

A team of researchers from Bonn University and RWTH Aachen University have analysed the notorious Storm Worm botnet, and concluded it certainly isn't as invulnerable as it once seemed. Quite the reverse, for in theory it can be rapidly eliminated using software developed and at least partially disclosed by Georg ...