Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

A story published by online Mac OS-related news site Mac Rumors outlines a new requirement for applications running on iOS 6 – strict privacy enforcement. The requirements were explained in the release notes for iOS 6, and seem to address some of the privacy issues Apple has had to contend with lately.

Just days after several large Web-based organizations united to fight malicious online ads, MLB.com was spotted serving malicious ads and directing visitors to Rouge Anti-Virus. Rogue Anti-Virus applications actually generate decent income for some of the criminals who spread them, as they are paid for getting someone to install it, and will sometimes take a cut of the fee if someone registers it.

Sourcefire’s FireSIGHT and FireAMP Mobile Provide Visibility and Control to Help Discover and Block Mobile Threats on Enterprise NetworksCybersecurity solutions provider Sourcefire today announced new solutions designed to help enterprises protect against advanced threats stemming from mobile devices and the challenges associated with the “Bring Your Own Device” (BYOD) trend.

Automatic Transfer System Circumvents Banking Security Measures, Uses "Man in the Browser" Attack to Automate Bank FraudTrend Micro today released a new report that identifies an Automatic Transfer System (ATS) that enables cybercriminals to circumvent many bank security measures and drain victims' bank accounts without leaving visible signs of malicious activity.

The HoneyNet project has launched a new tool dubbed Ghost, developed by a German student, which aims to combat USB-based malware. The researcher from Bonn University, Sebastian Peoplau, developed his tool as part of his bachelor thesis, but it may end up being a go to resource for prevention on standalone and critical systems.

Vladislav Anatolievich Khorokhorin, better known in some circles as ‘Badb’ – has been extradited from France to the United States in order to face charges for credit card trafficking.Badb, according to the U.S. Department of Justice, is the world’s most prolific sellers of stolen credit cards. He made his first appearance before a U.S. judge last week in Washington, D.C., where he was arraigned and ordered detained pending trial.

Facebook, Google, Twitter, AOL, IAB Unite to Protect Users From Malicious Ads With Creation of Ads Integrity AllianceA new alliance comprised of several large online companies and organizations on Friday, announced the launch of the “Ads Integrity Alliance,” an initiative with a mission to protect users from bad ads and maintain trust in the online advertising world.

Weichao Sun, a Trend Micro mobile threat researcher, has discovered a malicious library file within certain Android applications, which hides its routines within the dynamic library in order to make detection harder and avoid removal.The malicious library, libvadgo, was developed using a common Android development toolset. Once libvadgo is called via Java_com_airpuh_ad_UpdateCheck_DataInit, the phone is scanned for signs of being rooted. If so, then various commands are initiated and a separate file is run.

Earlier this week, an Industrial Control System (ICS) security assessment firm, DigitalBond, posted details on a Phishing attack that was targeting their company. Additional research into the attempt has linked the attackers to similar campaigns targeting defense contractors and universities.

US-CERT has issued a warning to organizations and systems providers focusing on a VM vulnerability, which if exploited, would allow the attacker to leave the guest environment; better known as a guest-to-host virtual machine escape.

On Tuesday, the exploit code needed in order to gain administrative rights on several F5 network appliances was added to the Metasploit framework. The addition comes one week after F5 warned customers about the issue, and advised them to take one of three recommended actions, such as upgrading to a non-vulnerable version.

On Tuesday, Microsoft patched over two dozen vulnerabilities across the Windows platform. At the same time, criminals started targeted a new vulnerability that has now become the topic of interest within the security-focused community, especially when Google announced that it is being actively exploited.

Imation, a company that focuses on data security and storage, announced this week that the latest version of its Stealth Zone mobile workspace (version 2.1) will include a fully functional version of Windows 7.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.