Malware Alerts

Subscribe to Malware Alerts feed Malware Alerts
Updated: 2 hours 10 min ago

Blog: March 2013 Microsoft Security Bulletins - Low Impact from Pwn2Own, Watch USB Drives for Another Stuxnet

Tue, 03/12/2013 - 13:13

Microsoft releases nine March Security Bulletins. Four of the Bulletins are rated critical, but of the 20 vulnerabilities being patched, 12 are rated critical and enable remote code execution and elevation of privilege. Microsoft software being patched with critical priority include Internet Explorer, Silverlight, Visio Viewer, and SharePoint. So, pretty much every consumer running Windows, and lots of Microsoft shops, should be diligently patching systems today.

Blog: Miniduke: web based infection vector

Mon, 03/11/2013 - 07:43
Together with our partner CrySyS Lab, we've discovered two new, previously-unknown infection mechanisms for Miniduke. These new infection vectors rely on Java and IE vulnerabilities to infect the victim's PC.

Blog: The Brazilian Phishing World Cup

Mon, 03/11/2013 - 07:19

The 2014 FIFA World Cup has already kicked off, at least for Brazilian bad guys. Next year’s big event in Brazil has become one of the most prominent tactics used by Latin American cybercriminals as they unleash a real avalanche of phishing messages, fraudulent prizes and giveaways, malicious domains, fake tickets, credit card cloning, banking Trojans and a lot of social engineering.

Blog: CIA "DELETED" Venezuela's Hugo Chavez?

Fri, 03/08/2013 - 12:28
This is the topic that cybercriminals are speculating about and using as a hook to infect victims. The campaign is based on the Blackhole v2.0

Blog: AlbaBotnet, another new crime wave in Latin American cyberspace

Mon, 03/04/2013 - 18:06
After the recent emergence of the criminal PiceBOT in Latin America, AlbaBotnet has joined the growing ranks of regional IT crime.

Analysis: Mobile Malware Evolution: Part 6

Thu, 02/28/2013 - 04:00
The fifth part of our regular overview of mobile malware evolution was published one year ago, and now it’s time to review the events of 2012 to see just how accurate our forecasts were

Blog: The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor

Wed, 02/27/2013 - 09:00
New Adobe PDFs exploiting CVE-2013-0640 drop sophisticated malware known as "MiniDuke".

Analysis: Spam in January 2013

Thu, 02/21/2013 - 03:54
The percentage of spam in email traffic was down 7.7 percentage points compared with December and averaged 58.3%

Analysis: Application Control: the key to a secure network. Part 1

Tue, 02/19/2013 - 11:43
Corporate network security is one of the most pressing issues for companies today

Analysis: Application Control: the key to a secure network - Part 2

Tue, 02/19/2013 - 11:00
It’s brilliant - but is it user-friendly?

Blog: Trust but verify: when CAs fall short

Tue, 02/19/2013 - 03:31

We’ve recently experienced yet another case of a root certificate authority (CA from now on) losing control of its own certificates. And yet again, we have been waiting for either the CA or the browser to do something about it. This whole mess stems, once again, from both a governance and a technical problem. First, only the very same CA that issued a certificate can later revoke it. Second, although web browsers implement several techniques to check the certificate’s revocation status, errors in the procedure are rarely considered hard failures.

Analysis: Honey traps on the Internet

Thu, 02/14/2013 - 04:59
In the world of espionage, a ‘honey trap’ traditionally involves a seductive encounter designed to coax information out of an agent, or to compromise him in his work.

Blog: Cyber Attacks Against Uyghur Mac OS X Users Intensify

Wed, 02/13/2013 - 11:53
In partnership with researchers at AlienVault Labs, we’ve analysed a series of targeted attacks against Uyghur Mac OS X users which took place during the past months.

Blog: February 2013 Microsoft Security Bulletins - Volume is High but a Handful are Critical

Tue, 02/12/2013 - 13:36

Today's February Microsoft Security Bulletin release patches a long list of vulnerabilities. However, only a subset of these vulnerabilities are critical. Four of them effect client side software and one effect server side - Internet Explorer, DirectShow media processing components (using web browsers or Office software as a vector of delivery), OLE automation components (APT related spearphish), and one effecting the specially licensed "Oracle Outside In" components hosted by Microsoft Exchange that could be used to attack OWA users.

Blog: Adobe Flash Player 0-day and HackingTeam's Remote Control System

Tue, 02/12/2013 - 10:01
Adobe Flash Player CVE-2013-0633 is a critical vulnerability that was discovered and reported to Adobe by Kaspersky Lab researchers Sergey Golovanov and Alexander Polyakov. The exploits for CVE-2013-0633 have been observed while monitoring the so-called ‘legal’ surveillance malware created by the Italian company HackingTeam. In this blog, we will describe some of the attacks and the usage of this 0-day to deploy malware from ‘HackingTeam’ marketed as Remote Control System.

Blog: Brazilian Masquerade

Tue, 02/05/2013 - 14:34
Don't believe your eyes but check if you still have your AV solution. Instead of fighting AV detections, cybercriminals from Brazil just replace them with their own fake solutions.

Blog: New crimeware attacks LatAm bank users

Fri, 02/01/2013 - 13:47
Following in the wake of the vOlk (Mexico) and S.A.P.Z. (Peru) botnets comes PiceBOT, a newbie to the Latin American cybercrime scene. The cost on the black market is currently around $140.

Blog: Mobile attacks!

Fri, 02/01/2013 - 07:31
Users of inexpensive Android smartphones typically look for ways to accelerate their devices, for example, by freeing up memory. Demand for software that makes smartphones work a little faster creates supply, some of which happens to be malicious. In addition to legitimate applications, apps that only pretend to clean up the system have appeared on Google Play.

Analysis: Kaspersky Lab report: Evaluating the threat level of software vulnerabilities

Fri, 02/01/2013 - 05:30
Vulnerable programs are among the most commonplace ways to attack victims and steal personal data.

Descriptions: Trojan-Downloader.JS.Agent.gdn

Thu, 01/31/2013 - 08:21
If your computer has not been protected with anti-virus software and has been infected with malware, you will need to take the following actions to delete this: Delete the original program file (its...

Pages