Analyzing the MD5 collision in Flame

Monday, June 11th, 2012

Here is a great analysis of the MD5 collision in Flame by Alex Sotirov. https://trailofbits.files.wordpress.com/2012/06/flame-md5.pdf

Malicious URLs in Fake Craigslist Emails

Friday, June 8th, 2012

Today, Websense® Security Labs™ ThreatSeeker™ Network has seen a barrage of malicious emails pretending to be automated notifications from Craigslist. These emails instruct the recipient to click a link to complete a Craigslist request. The URLs in these emails redirect the user to malicious web sites hosting Blackhole Exploit Kit. So far we have ...

Millions of Last.fm passwords leaked

Friday, June 8th, 2012

A list with several million passwords belonging to users of the music community site Last.fm has been posted on the internet. The site owners have posted a statement saying that the company is investigating the leak and that all users of the service should change their passwords immediately. This is ...

LinkedIn confirms passwords were compromised

Wednesday, June 6th, 2012

LinkedIn said today that some passwords on a list of allegedly stolen hashed passwords belong to its members, but did not say how its site was compromised. "We can confirm that some of the passwords that were compromised correspond to LinkedIn accounts," Vicente Silveira, a director at the professional social networking ...

Microsoft Update and The Nightmare Scenario

Monday, June 4th, 2012

About 900 million Windows computers get their updates from Microsoft Update. In addition to the DNS root servers, this update system has always been considered one of the weak points of the net. Antivirus people have nightmares about a variant of malware spoofing the update mechanism and replicating via it. Turns ...