Web Application Security

March 12, 2010, 10:54AM

Domains Using .Org to Have Tighter Security

The Public Interest Registry will add an extra layer of security known as DNS Security Extensions (DNSSEC) to the .org domain in June -- a move that will protect millions of non-profit organizations and their donors from hacking attacks known as cache poisoning. Read the full article. [Network World]

Shorten URL: http://threatpost.com/en_us/3Jv. Click to copy to clipboard or post to Twitter

March 12, 2010, 7:24AM

Another TJX Accomplice Gets Nearly 4-Year Sentence

Humza Zaman, a co-conspirator in the hack of TJX and other companies, was sentenced Thursday in Boston to 46 months in prison and fined $75,000 for his role in the conspiracy. The sentence matches what prosecutors were seeking. Read the full article. [Wired]

Shorten URL: http://threatpost.com/en_us/3JK. Click to copy to clipboard or post to Twitter

March 12, 2010, 7:09AM

Botnets Find New Internet Homes Quickly

The takedown of 100 servers used to control Zeus-related botnets may be a short-lived victory, security researchers said after discovering that about a third of the orphaned channels were able to regain connectivity in less than 48 hours. The resurrection of at least 30 command and control channels came after their ISP found a new upstream provider to provide connectivity to the outside world, autonomous system records showed. Read the full article. [The Register]

Shorten URL: http://threatpost.com/en_us/3JZ. Click to copy to clipboard or post to Twitter

March 12, 2010, 6:52AM

ISP Known for Distributing Malware Goes Dark

A network frequently used for malware delivery was shut down Wednesday night, probably against the will of its operators. Troyak.org, an Internet service provider well-known for serving Zeus botnets and other malware delivery methods, went dark overnight, resulting in the shutdown of as many as 25 percent of the world's Zeus botnets, according to researchers. Read the full article. [Dark Reading]

Shorten URL: http://threatpost.com/en_us/3JD. Click to copy to clipboard or post to Twitter

March 12, 2010, 6:34AM

ZeuS Botnet Module Gives Total PC Control

New capabilities are strengthening the ZeuS botnet, which criminals use to steal financial credentials and execute unauthorized transactions in online banking, automated clearing house (ACH) networks and payroll systems. The latest version of this cybercrime toolkit offers a $10,000 module that can let attackers completely take control of a compromised PC. Read the full article. [Network World]

Shorten URL: http://threatpost.com/en_us/3JT. Click to copy to clipboard or post to Twitter

March 11, 2010, 11:41AM

Taher Elgamal on Encryption, SSL, The Cloud

In this wide ranging interview, cryptographer, Taher Elgamal, chief security officer of Axway Inc. and  initial driving force behind SSL, explains how applications may be better adapted to defend against attacks and how cloud computing may alter data protection and authentication. Read the full article. [TechTarget]

Shorten URL: http://threatpost.com/en_us/3uU. Click to copy to clipboard or post to Twitter

March 11, 2010, 11:25AM

Win Update Scareware Pushes Drive-By Downloads

Cybercriminals are using a fake Windows Update installation dialogue box to sell a bogus security product called Anti-malware Defender, security researchers have warned. Read the full article. [Computer Weekly]

Shorten URL: http://threatpost.com/en_us/3un. Click to copy to clipboard or post to Twitter

March 11, 2010, 10:09AM Threatpost Original

Koobface Worm Doubles C&C Servers in 48 Hours

By Stefan Tanase

Yesterday's shut down of Troyak-as was definitely good news for the whole IT security community. Seeing cybercriminals getting kicked out from the Internet and then trying to get back inside calls for popcorn and soda.

But unfortunately, as some botnets struggle, others stay unaffected: Koobface, for example, which uses compromised legitimate websites as proxies for their main command and control server.

Shorten URL: http://threatpost.com/en_us/3uj. Click to copy to clipboard or post to Twitter

March 11, 2010, 8:59AM

DDoS Worm Creator Heading to Prison

An Estonian virus writer has been jailed for two and a half years for creating a Windows worm family that launched denial of service attacks on the websites of a local insurance firm and ISP. Read the full article. [The Register]

Shorten URL: http://threatpost.com/en_us/3ux. Click to copy to clipboard or post to Twitter

March 10, 2010, 3:08PM Podcast Threatpost Original

Paul Judge on Twitter Crime and Web Security

Digital Underground podcast with Dennis Fisher

You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

Dennis Fisher talks with Paul Judge of Barracuda Networks about the company’s new report on Twitter phishing trends, search engine poisoning, Web security and what can be done about the spam pandemic.

Shorten URL: http://threatpost.com/en_us/3zU. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy