DNS Flaw Underscores Danger of Taking Web Security for Granted

Thursday, August 7th, 2008

Perhaps more than any other flaw in the last several years, the DNS protocol vulnerability discovered by security researcher Dan Kaminsky has shown that the circle of trust on the Internet can be broken more easily than we feared.After listening to Kaminsky’s talk Aug. 6 at the Black Hat conference ...

More Ways to Protect Yourself From Phishing

Wednesday, August 6th, 2008

In my recent Editors' Notes post on Consumer Reports' recommendation that Mac users dump Safari because the Apple browser lacks the anti-phishing tools of Firefox and Opera, I focused on behavioral changes one can make that minimize the risks of phishing attempts. I didn't, however, discuss a relatively simple configuration ...

Malicious Botnet Stole Bank, Credit Union Credentials

Wednesday, August 6th, 2008

The researcher who first discovered a motherlode of stolen enterprise user names and passwords in June has found that nearly 9,000 of them are bank and credit-card account credentials from around the world that were grabbed by an old but crafty botnet. And it turns out the initial 50 gigabytes' ...

Massive faux-CNN spam blitz uses legit sites to deliver fake Flash

Wednesday, August 6th, 2008

More than a thousand hacked Web sites are serving up fake Flash Player software to users duped into clicking on links in mail that's part of a massive spam attack masquerading as CNN.com news notifications, security researchers said today.The bogus messages, which claim to be from the CNN.com news Web ...

Adobe: Beware of fake Flash downloads

Tuesday, August 5th, 2008

Amidst confirmed reports that malicious hackers are starting to use fake Flash Player downloads as social engineering lures for malware, Adobe has issued a call-to-arms for users to validate installers before downloading software updates.The company’s notice comes on the heels of malware attacks on Facebook, MySpace and Twitter that attempt ...