CompUSA
Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

Thursday, December 9, 2010

GFI Software Announces Top 10 Malware Threats for November

(BUSINESS WIRE)--GFI Software, a leading IT solutions provider for small and medium-sized enterprises, today announced the top 10 most prevalent malware threats for the month of November 2010. The report, compiled from monthly scans performed by GFI's award-winning anti-malware solution, VIPRE® Antivirus, and its antispyware tool, CounterSpy®, is a service of GFI Labs™.

As in recent months, Trojans dominated the threat landscape in November. ThreatNet data revealed that seven of the top 10 malware threats were classified as Trojans. The number-one detection, Trojan.Win32.Generic!BT, is a Trojan comprising over 20 percent of the ThreatNet detections.

Tom Kelchner, GFI Software communications and research analyst said, “There is another picture in the top-10 numbers. Three of them go after applications or server software that hasn’t been patched. The number six detection, Exploit.PDF-JS.Gen (v), tries to exploit a security flaw in PDF files with embedded JavaScript. That’s aiming at Adobe products. It often installs downloaders that pull down other malware from remote Web sites.”

Worm.Win32.Downad.Gen (v,) the Downadup worm (also called Conficker and Kido) in the number seven spot, is a worm that spreads across a network by taking advantage of a vulnerability in Windows Server service which allows remote code execution when file sharing is enabled. This vulnerability was patched some time ago.

Trojan.ASF.Wimad (v), in the number nine spot, is a VIPRE detection for a group of Trojanized Windows media files that exploit an old vulnerability in Windows Media Player. It redirects the victim’s browser to a web site to download malicious files. This is also is an old vulnerability that’s been fixed.

“If this malcode is still circulating, it means that the malcode writers are seeing a landscape with lots of unpatched and vulnerable machines. The conclusion is pretty clear for both enterprises and consumers: update Windows operating systems (including servers), browsers, Adobe products and media players and keep them updated,” said Kelchner.

ThreatNet is GFI Lab’s monitoring system that retrieves real-time data from VIPRE installations. Statistics come from tens of thousands of machines running VIPRE.

Top 10 detections for November
Detection
 
Type
 
Percent
 
1. Trojan.Win32.Generic!BT Trojan 22.44
2. Trojan-Spy.Win32.Zbot.gen Trojan 3.88
3. Trojan.Win32.Generic.pak!cobra Trojan 3.53
4. Trojan.Win32.Generic!SB.0 Trojan 3.46
5. INF.Autorun (v) Trojan 1.83
6. Exploit.PDF-JS.Gen (v) Exploit 1.45
7. Worm.Win32.Downad.Gen (v) Worm.W32 1.42
8. Trojan.Win32.Malware.a Trojan 0.83
9. Trojan.ASF.Wimad (v) Trojan 0.76
10. Trojan.Win32.Meredrop Trojan Downloader 0.68

------
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG
www.FayetteFrontPage.com
Twitter: @FayetteFP

Tuesday, September 14, 2010

Damballa Discovers New Wide-Spread Global Botnet Offering ‘Commercial’ DDoS Services

(BUSINESS WIRE)--Damballa Inc., the company transforming the fight against cyber threats, today announced the discovery of a new botnet that offers pay-for-delivery Distributed Denial of Service (DDoS) attacks. The ‘IMDDOS’ Botnet, named after the commercial name on the botnet website, has grown to be one of the largest active global botnets in less than four months from initial testing. According to Damballa, the infected hosts used in the DDoS attacks have become unwitting participants in the botnet and are widespread. The vast majority of infected hosts are in China, with the United States being in the top 10 countries affected. Internet Service Providers (ISPs) worldwide were affected, including the majority of North American ISPs, and a number of major corporate networks are hosting bot agents for the IMDDOS Botnet.

“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting”

The IMDDOS Botnet offers a commercial service for delivering DDoS attacks against any desired target. Hosted in China, this publicly available service is available for lease to anyone willing to establish an online account, input the domain(s) they wish to attack, and pay for the service. Throughout the Damballa period of study, the botnet grew large very quickly. Following testing by the criminal operators in April 2010, it reached a production peak of activity with 25,000 unique Recursive DNS (RDNS) lookups per hour attempting to resolve to the botnet’s command-and-control (CnC) servers. Damballa is currently working with ISPs and law enforcement officials to contain and nullify the threat.

A 16-page analysis of the discovery can be viewed at: www.damballa.com/IMDDOS. This analysis includes details of the technical infrastructure of the botnet and associated malware as well as an animated illustration of the IMDDOS Botnet’s global growth and impact from early testing stage to peak activity rendered in hourly increments.

A Denial of Service (DoS) attack is a technique used to overwhelm a website/domain in an effort to reduce its responsiveness or completely eliminate its ability to respond to new connection attempts. DoS attacks have historically been used to ‘take down’ political sites, abuse sites, commercial business websites and even military command centers as part of a coordinated targeted campaign.

A DDoS attack utilizes multiple PCs or servers to initiate a coordinated attack against a targeted system. The more assets involved in the attack, the larger the flood of requests and data that can be targeted at the victim. To create a very large army of assets that can launch DDoS attacks, botnets are used to rally and command unwitting victim machines into participating in the attacks.

“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting,” stated Gunter Ollmann, vice president of research for Damballa. “The public website hosting the DDoS service offering, with various ‘plans’ and attack options, speaks to the ease with which anyone can leverage criminal infrastructure. The malware used is simplistic, yet it was successful in spreading rapidly. And while it appears to be primarily a DDoS delivery platform, the size of the botnet reached impressive proportions, certainly large enough to wreak major havoc on any victim organization should it be pointed in the right direction.”

This discovery was made possible due to a global array of Damballa sensors, which provide worldwide visibility into CnC activity, combined with the understanding and quantification of statistical heuristics that can explain, and most importantly, quickly detect, the malicious nature of this botnet operation. Damballa tracks thousands of botnet operators and their growing cache of botnets every day. Each criminal botnet building campaign is observed, analyzed, automatically catalogued and categorized using a sophisticated array of clustering and machine learning systems. As the criminal botnet operators attempt to grow the botnet, their investments and modifications to their CnC hosting infrastructure are tracked and used as markers for eventual attribution. Damballa customers benefit from this advanced knowledge of the threat, being alerted to the presence of the malware and being able to terminate the CnC communications.

“Botnets are recognized by industry experts as being the delivery mechanism of choice for the vast majority of today’s cyber threats that plague corporate and ISP networks,” said Val Rahmani, CEO of Damballa. “Botnets and other cyber threats are attacking corporate networks and service providers at an alarmingly high rate and are causing security teams around the world to reevaluate their security investments. Damballa leads the security industry in delivering solutions that detect and terminate botnets and cyber threats, and our research and product teams are constantly innovating and bringing more powerful and automated weapons to the war against cybercrime.”

-----
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter:  @GAFrontPage

Thursday, June 3, 2010

Op Ed: We Need a New System for Interrogating Terrorists

It's been nearly nine years since 9/11, but we still have no established procedures for interrogating terrorist suspects detained inside the United States. The military-based system developed during the Bush Administration disregards civil liberties. The criminal justice model used in many terrorism cases inhibits intelligence collection. We need a better system.

To meet our counterterrorism objectives, Congress should enact a law that allows the government to interrogate a suspect for intelligence purposes, without counsel present, for up to seven days. To protect the suspect's constitutional rights, the information gained during this time could not be used as evidence against him in a criminal trial.

Once the interrogation is complete, the suspect would be turned over to the criminal justice system for a normal prosecution, with all the usual civil liberties protections. Such a system would maximize the chances of gaining valuable intelligence while leaving our criminal justice system undisturbed.

While civil libertarians will decry this proposal as a form of administrative detention, it's far more protective of civil liberties than the system devised during the Bush Administration (and affirmed by the Supreme Court). Under this military system, suspected terrorists (including U.S. citizens) can be designated enemy combatants by the president, placed in military custody and held indefinitely without trial. Judicial review of the lawfulness of the detention does not take place for months, even years. 
High-ranking Bush lawyer Jack Goldsmith, upon seeing 22-year-old U.S. citizen Yasser Hamdi isolated in a naval brig after being designated an enemy combatant, said, "Something seemed wrong. ... This is what habeas corpus is for."

But, as critics have pointed out, the criminal justice procedures used following the failed bombing of Flight 253 to Detroit and the botched car-bomb attack in Times Square could squander opportunities to gain intelligence. Normally, when a suspect is arrested, he is read Miranda rights and given the opportunity to see a lawyer. In most cases, suspects are advised to stop providing information, at least until the lawyer can evaluate the case. Even if a suspect waives his Miranda rights and submits to an interrogation, he must be "presented" in court "without unreasonable delay." These procedures create obstacles to collecting intelligence in national security cases.

There is a "public safety" exception that was used to justify short interrogations in the Flight 253 and Times Square cases without Miranda warnings. And, in both of these cases, it appears the suspects continued to provide information to law enforcement even after being read their rights. But this is more a matter of good fortune than the result of good policy.

Recognizing this, Attorney General Holder floated the idea of expanding the public safety exception to allow for a longer interrogation without Miranda warnings or a court appearance. Civil libertarians correctly note this proposal would undercut the logic of Miranda and threaten the constitutional protection against self-incrimination. Moreover, if Congress disposes of Miranda warnings in terrorism cases, the argument could be made that this protection can also be circumvented for other national security crimes - like espionage - and then serious violent crimes, and so on.

Allowing an "intelligence-only" interrogation would not raise Fifth Amendment problems because the information would be excluded from any subsequent trial. And, because this limitation would complicate prosecutions, the government is only likely to use it in cases where core national security interests are at stake.

Congress should build multiple levels of protection into this system. First, the government should be forced to establish probable cause of a terrorism crime to justify the interrogation. Second, to prevent this authority from being used to conduct secret interrogations, family members should be notified that a relative has been detained. Third, to protect against abusive treatment, the suspect's entire time in custody should be videotaped.

Congress would set the outer limit for this detention. In the United Kingdom, pre-charge detention is allowed for 28 days. We have a more libertarian tradition than the U.K., so an outer limit of seven days or less might be a reasonable period.

Detention for interrogation is an unsettling concept. But neither the criminal justice system nor law of war is perfectly suited for dealing with terrorism. To deal with this threat that combines aspects of both crime and war, we need to craft flexible institutions and legal procedures.

By David H. Schanzer
Durham, NC 

David Schanzer is the director of the Triangle Center on Terrorism and Homeland Security at Duke and the University of North Carolina, Chapel Hill. This op-ed ran in the Baltimore Sun, Newark Star-Ledger, Allentown Morning Call and the (Raleigh) News & Observer.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter:  @GAFrontPage

Friday, April 9, 2010

Phishing Attacks on Taxpayers Rise in the Weeks Leading up to April 15th IRS Tax Filing

/PRNewswire/-- SonicWALL, Inc. (NASDAQ:SNWL) , a leading secure network infrastructure company, last week began seeing the expected rise in phishing threats related to the upcoming April 15 Internal Revenue Service (IRS) tax filing date. The prominent phishing scam comes when taxpayers are notified from the IRS that their tax refund is now available. Scammers will then ask users to provide their bank card information and identity information to assure that the refund is deposited in the appropriate account.

"As we've seen in the past, the weeks before April 15th are the most likely for taxpayers to see a rise in tax-related phishing emails," said Leon Hilton, Email Security Expert, SonicWALL. "We predict that more than 100 million IRS related phishing emails will be sent to tax payers in the days leading up to and after the April 15 tax filing deadline."

While the IRS does not send e-mail regarding your refund, you may still get legitimate e-mail on the subject. A myriad legitimate online filing services, online consultants who answer tax-related questions and online tax calculators currently exist. For example, if you file your taxes with an online tax preparation service you are likely to get legitimate email from them and the bank which acts as the transfer agent for the transaction for the IRS. Phishers use this opportunity to prey on taxpayers who are filing their tax refund -- asking them for bank card information to deposit the refund and social security number so they can verify a taxpayer's identity. Be wary of these types of inquiries.

To help taxpayers identify tax-related potential phishing schemes, the SonicWALL threat team has outlined several steps to help taxpayers defend against these types of phishing-related security threats:

1. Be aware that the IRS does not send you e-mails which ask for any
financial, personal or identity information. Do not respond to these
e-mails. Official correspondence with the IRS is done through US Mail.
2. If you use an online preparations service, pay close attention to
relevant instructions as e-mail messages you could receive include
details such as bank account numbers and when you can expect your
refund to be deposited. Always go back to the tax preparation website
or call to ensure that the online transaction goes smoothly. Also be
sure to print off any related materials to save for later reference if
needed.
3. If you use a tax filing program you will most likely receive an e-mail
notification when your taxes are filed, letting you know that your tax
forms were accepted or possibly rejected. Do not click on any links in
the e-mail. Go back to the tax preparation program and check for any
notifications.
4. Beware of offers that allow you to get loans on your income tax refund.
While some offers are legitimate many others are not and are spam or
phishing scams.
5. If you have a question about an email confirmation of your online
filing and/or refund information from your software program or online
filing service, contact the phone number of the tax service provider.
6. Improve your phishing IQ. SonicWALL has put together the phishing IQ
test specifically to test your phishing knowledge. Go to:
www.sonicwall.com/phishing/
7. For more information about identity phishing, e-mail scams and bogus
IRS websites, go to
http://www.irs.gov/privacy/article/0,,id=179820,00.html?portlet=1



For more information on the topic of phishing and other related threats, go to: http://anti-spam.sonicwall.com/

SonicWALL is a registered trademark of SonicWALL, Inc. Other product and company names mentioned herein may be trademarks and/or registered trademarks of their respective companies.

Safe Harbor Regarding Forward-Looking Statements

Certain statements in this press release are "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. The forward-looking statements include but are not limited to statements regarding defensive measures to be used to combat attacks concerning news search sites. These forward-looking statements are based on the opinions and estimates of management at the time the statements are made and are subject to certain risks and uncertainties that could cause actual results to differ materially from those anticipated in the forward-looking statements. In addition, please see the "Risk Factors" described in our Securities and Exchange Commission filings, including our Annual Report on Form 10-K for the year ended December 31, 2008, for a more detailed description of the risks facing our business. All forward-looking statements included in this release are based upon information available to SonicWALL as of the date of the release, and we assume no obligation to update any such forward-looking statement.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter:  @GAFrontPage

Friday, December 11, 2009

Pop-up Advertisements Offering Anti-virus Software Pose Threat to Internet Users

An ongoing threat exists for computer users who, while browsing the Internet, began receiving pop-up security warnings that state their computers are infected with numerous viruses.

These pop-ups known as scareware, fake, or rogue anti-virus software look authentic and may even display what appears to be real-time anti-virus scanning of the user's hard drive. The scareware will show a list of reputable software icons; however, the user cannot click a link to go
to the actual site to review or see recommendations.

The scareware is intimidating to most users and extremely aggressive in its attempt to lure the user into purchasing the rogue software that will allegedly remove the viruses from their computer. It is possible that these threats are received as a result of clicking on advertisements contained on a website. Cyber criminals use botnets to push the software and use advertisements on websites to deliver it. This is known as malicious advertising or malvertising.

Once the pop-up appears it cannot be easily closed by clicking "close" or the "X" button. If the user clicks on the pop-up to purchase the software, a form is provided that collects payment information and the user is charged for the bogus product. In some instances, whether the user clicks on the pop-up or not, the scareware can install malicious code onto the computer. By running your computer with an account that has rights to install software, this issue is more likely to occur.

Downloading the software could result in viruses, Trojans and/or keyloggers being installed on the user's computer. The repercussions of downloading the malicious software could prove further financial loss to the victim due to computer repair, as well as, cost to the user and/or financial institutions due to identity theft.

The assertive tactics of the scareware has caused significant losses to users. The FBI is aware of an estimated loss to victims in excess of $150 million.

Be cautious — cyber criminals use easy to remember names and associate them with known applications. Beware of pop-ups that are offering a variation of recognized security software. It is recommended that the user research the exact name of the software being offered.

Take precautions to ensure operating systems are updated and security software is current.

If a user receives these anti-virus pop-ups, it is recommended to close the browser or shut the system down. It is suggested that the user run a full, anti-virus scan whenever the computer is turned back on.

If you have experienced the anti-virus pop-ups or a similar scam, please notify the IC3 by filing a complaint at www.IC3.gov.

----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page

Tuesday, May 19, 2009

Cybersecurity Groups Launch 'Chain of Trust' Initiative to Combat Malware

/PRNewswire / -- Three of the world's leading cybersecurity groups today launched a new initiative to combat malicious software (malware) by establishing a "Chain of Trust" among all organizations and individuals that play a role in securing the Internet.

Developed by the Anti-Spyware Coalition (ASC), National Cyber Security Alliance (NCSA) and StopBadware.org, the Chain of Trust Initiative will link together security vendors, researchers, government agencies, Internet companies, network providers, advocacy and education groups in a systemic effort to stem the rising tide of malware.

Applying many of the same approaches used to bring nuisance adware under control, the Chain of Trust Initiative aims to establish a united front against a threat that continues to grow exponentially. Kaspersky Labs recently reported that malware distributed through social networking sites is successful 10 times more often than scams distributed via email.

"Strong security in any one organization or sector is not enough to combat an agile, fast evolving threat like malware, which exploits security breakdowns between entities," said Ari Schwartz, ASC Coordinator and Vice President of the Center for Democracy & Technology (CDT). "We all need to work together to build a system that can withstand and repel the next generation of exploits."

The first order of business in the Chain of Trust Initiative is to map the complex, interdependent network of organizations and individuals that make up the chain. Only by identifying all the vulnerable links and understanding how they connect to one another can malware fighters get a handle on the problem and begin to develop consensus solutions.

"Online safety and security is a shared responsibility that requires the involvement of governments, corporations, non-profit institutions and citizens," said Michael Kaiser, Executive Director of the NCSA. "The Chain of Trust Initiative will focus furthering the development of tools that provide better protections. However, we must also continue to ensure that all of us implement universal behaviors online that protect us against a multitude of threats."

ASC, NCSA and StopBadware.org will lead the mapping effort and jointly develop ideas and initiatives to form stronger bonds between links on the chain. Leaders of the initiative have already begun reaching out to key players and identifying critical areas for collaboration. In the next six months, the Chain of Trust Initiative will produce a paper tracking the results of the mapping project and propose initial recommendations to strengthen the chain.

"Organization and collaboration are our best tools against an enemy that doesn't play by any rules," said StopBadware.org manager Maxim Weinstein. "Just by nature of how the Internet works, malware distributors have a technological advantage, but we can respond by strengthening our shared networks and by better understanding our shared responsibilities."

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow on Facebook

Thursday, October 16, 2008

Georgia Tech Information Security Center Releases Emerging Cyber Threats Forecast for 2009

(BUSINESS WIRE)--The Georgia Tech Information Security Center (GTISC), a national leader in information security research and education, today announced the release of the GTISC Emerging Cyber Threats Report for 2009, outlining the top five areas of security concern and risk for consumer and enterprise Internet users for the coming year. The report was released at the annual GTISC Security Summit on Emerging Cyber Security Threats – a gathering of leading industry and academic leaders from organizations with a stake in protecting the online user community.

For 2009, GTISC is forecasting five key cyber security areas where threats are expected to increase and evolve:

* Malware— specifically under the guise of benign social networking links
* Botnets – specifically the spread of botnet attacks to wireless and peer-to-peer networks
* Cyber warfare — including targets on the U.S. economy and infrastructure
* Threats to VoIP and Mobile Convergence—specifically voice fraud and cellular botnets
* The Evolving Cyber Crime Economy – including the rise of sophisticated malware-for-sale kits and programs

According to the report, data will continue to be the primary motive behind future cyber crime – whether targeting traditional fixed computing environments or mobile applications. Experts from across the IT security spectrum – from government to industry to academia – join GTISC’s call for closer coordination between the security industry, Internet Service Providers (ISPs), application developers and government regulators to safeguard the user community and hinder the spread of sophisticated cyber security threats.

“At GTISC, we strongly believe that a proactive approach to understanding emerging threats will help us develop more effective information security technologies and strategies,” said Mustaque Ahamad, director of GTISC. “The annual GTISC Security Summit on Emerging Cyber Security Threats and this report seek to give us a better understanding of the increasingly sophisticated cyber security challenges we will face in the years ahead. We wish to thank the esteemed members of the IT security community who assisted us with the creation of this report.”

More than 300 corporate executives, industry leaders and technologists from across the country attended the GTISC Security Summit on Emerging Cyber Security Threats, keynoted by Lt. General Robert J. Elder, Jr., Commander Eighth Air Force of the Barksdale Air Force Base. Following Lt. Elder’s address on “Global Operations and Mission Assurance in a Contested Cyber Environment” in the morning, Summit panelists engaged in a lively discussion moderated by IT Security Entrepreneur, Thomas E. Noonan. This year’s panelists, from the U.S. Department of Homeland Security, IBM Internet Security Systems, the Georgia Institute of Technology, Cisco, Motorola and SecureWorks, helped to educate the audience on the proliferation of cyber threats, including those listed in the report, and highlighted possible countermeasures to safeguard the user and business communities.

To view the entire GTISC Emerging Cyber Threats for 2009 report or to watch a pre-recorded Web cast of the Summit, please visit http://www.gtiscsecuritysummit.com.

-----
www.georgiafrontpage.com
Georgia Front Page
www.fayettefrontpage.com
Fayette Front Page

News to Use in Fayetteville, Atlanta, Savannah, Peachtree City and all of Georgia