DNS Flaw Underscores Danger of Taking Web Security for Granted

Thursday, August 7th, 2008

Perhaps more than any other flaw in the last several years, the DNS protocol vulnerability discovered by security researcher Dan Kaminsky has shown that the circle of trust on the Internet can be broken more easily than we feared.After listening to Kaminsky’s talk Aug. 6 at the Black Hat conference ...

Malicious Botnet Stole Bank, Credit Union Credentials

Wednesday, August 6th, 2008

The researcher who first discovered a motherlode of stolen enterprise user names and passwords in June has found that nearly 9,000 of them are bank and credit-card account credentials from around the world that were grabbed by an old but crafty botnet. And it turns out the initial 50 gigabytes' ...

Social engineering on Twitter

Monday, August 4th, 2008

This week it’s Twitter’s turn to host an attack - one that is targeting both Twitter users and the Internet community at large. In this case it's a malicious Twitter profile twitter.com/[skip]/ with a name that is Portuguese for ‘pretty rabbit’ which has a photo advertising a video with girls ...

Wi-Fi networks suffer ‘autoimmune’ attacks

Monday, August 4th, 2008

JUST as the body's immune system sometimes mistakenly attacks its own cells, so the security software intended to protect network users can be fooled into attacking them. This could make attacks by hackers even harder to detect and prevent.Security software typically prevents unauthorised access by encrypting most of the data ...

Security researcher publishes exploit toolkit

Tuesday, July 29th, 2008

An Argentinian security researcher has published a security exploit toolkit targeting the update mechanisms of Java, Mac OS X, OpenOffice.org and other software, and relying on man-in-the-middle techniques such as those made possible by the recently disclosed DNS security hole. The toolkit, ISR-Evilgrade 1.0, was released by Francisco Amato, a researcher ...