Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Thursday, January 24, 2008

Cyber criminals move beyond Windows

ORGANISED criminals involved in cyber attacks aimed at stealing IDs and money are moving beyond Windows, and are for the first time knocking loudly at the doors of Macintosh and Linus-based systems, experts warn.

Tech security and control firm Sophos has published in its Security Threat Report 2008 found Apple was a significant target of criminal hackers in 2007, and that the threat would expand in 2008.

While Malware for Macs has been seen before, the Sophos reports that malicious code seemed for the first time to have been written by financially-motivated hackers who saw an opportunity.

“No-one should underestimate the significance of financially-motivated malware arriving for Apple Macs at the end of 2007,” Sophos senior technology consultant Graham Cluley said.

“Although Macs have a long way to go in the popularity stakes before they overtake PCs, particularly in the workplace, their increased attractiveness to consumers has proven irresistible to some criminal cybergangs.,” Mr Cluley said.

The Sophos' Threat Report also reveals that the wider use of new mobile technologies and wi-fi enabled devices, like the iPhone and iPod Touch, may be opening up new vectors of attack for hackers.

Flaws have been found in the mobile email program and Safari browser installed on such devices. But while uptake remains limited cyber-criminals are unlikely to exploit these avenues on a major scale in the near future. However, as personal wi-fi devices grow in popularity, the risks will no doubt increase.

Sophos experts also said that the low cost ultra-mobile PCs, such as the popular Linux-based ASUS EEE laptop, will gain the attention of the cyber underworld as sales continue to grow.

“The ultra-mobile ASUS EEE laptop, like many others, comes pre-installed with Unix, making it automatically immune to the vast majority of spyware and malware attacks,” Mr Cluley said.

For more IT Security news, click here.

Monday, November 26, 2007

Symantec launches SmartPhone protection

US-based tech security specialist has rolled out a suite of consumer mobile security products that provides anti-virus, firewall and anti-spam protection for Windows Mobile and Symbian OS phone operating systems.

Symantec’s Norton Smartphone Security aims to give mobile device users the same level of security that has become standard for laptops and other computing devices.

“Smartphones are expanding consumer freedom to communicate and access important information anytime, anywhere,” said Symantec Consumer Business Unit senior vice-president Rowan Trollope said.

“However, unsecure public WiFi or network connections can put users at risk. In addition, web and e-mail viruses can directly infect smartphones, enabling hackers to remotely control the device, access sensitive information or disable applications,” he said.

“Norton Smartphone Security runs discreetly in the background, providing the confidence and peace of mind to engage in everyday activities like e-mailing, Web browsing or banking online from these handheld devices.”

As more users transact using their mobile devices, the financial incentives for virus writers and mobile hackers increase, Symantec says.

In a U.S. survey of smartphone users conducted by Applied Research, 34 per cent of respondents said they access their bank accounts via their mobile device and 54 per cent of respondents said they access web sites that require a password.

For more IT Security news, click here.

Friday, April 13, 2007

Microsoft patches ‘critical’ Windows security flaws

MICROSOFT has issued five software patches for security problems found in it Windows operating system, including a “critical” flaw in its new Windows Vista operating system.

The company also released a patch for another critical security flaw identified in its Microsoft Content Server platform, warning that the problem could allow hackers remote control of the system.

Five of the six bugs reported in the routine monthly Microsoft Security Bulletin for April were rated as critical, recommending that users update their software immediately.

The bulletin also rated the security hole identified in a Windows Vista messaging function as critical. The problem could lead to hackers taking over a machine, and users should be patched immediately.

“Critical” is the most serious of Microsoft’s four-level security rating system and is defined by the company as “a vulnerability whose exploitation could allow the propagation of an Internet worm without user action.”

Though the security patches were published part of Microsoft’s regular monthly release of fixes, the company last week broke the routine to issue an emergency fix for a problem found in Windows cursor animation files that was being widely exploited by hackers.

Microsoft has also reported that the cursor animation fix, which applied to all current Windows, including Vista, caused problems with some third-party software programs, in particular those related to audio files.

For more IT Security news, click here.

Thursday, April 5, 2007

Patch offered for Windows cursor bug

MICROSOFT is expected to issue a patch outside of its routine monthly security update following the hacker activity focused on an exploit that targets the cursor animation files used in Windows.

The company issued a statement saying its monitoring of attacks found that customer impact had been “limited”, but said it would make a patch available outside of its usual security routines.

Microsoft said it had completed testing on the patch earlier than expected.

The Windows Animated Cursor Handling vulnerability – also known as the ANI exploit – was identified late last week.

“In order for the attack to be carried out, the user must either visit a Web site that contains a web page that is used to exploit the vulnerability, or view a specially-craft email message or email attachment sent to them by the attacker,” Microsoft said in a statement.

Tech security specialist F-Secure said the majority of the attacks could be traced back to different Chinese hacker groups.

“We’ve seen a lot of activity relating to the ANI exploit during the weekend,” F-Secure’s chief research officer Mikko Hypponen said.

“This vulnerability is really tempting for the bad guys. It's easy to modify the exploit, and it can be launched via web or email fairly easily. We hope to see Microsoft release a patch for this exploit very soon.”

Most of the activity around the ANI exploit has been via dozens of malicious websites that attack the user if they visit the page with the most common versions of Internet Explorer. However, on Sunday the first worm using the ANI exploit to spread was found.

For more IT Security news, click here.