SecurityWatch
The online world is a sketchy place. Here's what you need to know to stay safe.
Latest Stories
Dotcom's Mega: Privacy and Security Woes
Earlier this month the perpetually flamboyant (and occasionally imprisoned) Kim Dotcom launched an encrypted file storage system called Mega. Highlighting the legal issues which shut down his previous company, Megaupload, Dotcom touted the new service as private, encrypted, and super-secure. It's clear, however, that Mega had some pretty unusual ideas about what that means.
Browsers Beat Security Software in Phishing Protection Test
Antivirus tools can detect malicious programs, but phishing websites scam you into giving away secrets without installing any software at all. A surprising new report reveals that your up-to-date browser is most likely a better protector against phishing than your fancy security suite.
Stay Secure With This Mobile Privacy Chart
Mobile devices seem so tidy and personal that people might forget that their phone or tablet is a target for attack. As part of their ongoing look at emerging mobile threats Trend Micro has released this handy flow chart of security tips for mobile users. It may look a little complicated, but it's good advice.
Konami Code Activates Game in Hacked Gov Websites
Two websites associated with the U.S. court system were recently vandalized, apparently in memorial to Aaron Swartz, by Anonymous. But instead of simply taking over the page, the intruders left a surprise: Asteroids.
Oracle's Java Chief Promises to "Fix" Java
The database giant will "get Java fixed up" to improve security, Milton Smith, Java security lead at Oracle, said during a conference call with Java User Group leaders last week. The conference call came a few weeks after researchers uncovered various attacks exploiting serious vulnerabilities in Java. Even after the company rushed out an emergency update to patch the flaws, researchers found additional bugs.
Zero-Day Not Required: DIY Hacker Kits Target Older Bugs
Contrary to popular perception, most malware attacks aren't targeting zero-day vulnerabilities or exotic flaws. In fact, nearly 60 percent of vulnerabilities used by popular exploit kits are more than two years old, according to a new study from Solutionary.
Your Network Printer is Wide Open To Attack
ViaForensics researcher Sebastian Guerrero recently released a report in which he describes a number of ways attackers could turn your boring, humdrum printer against you. According to his findings, potential vulnerabilities range from having to reset your printer (annoying) to the breach of encrypted documents (terrifying).
China Source of Most CyberAttacks, Says Akamai
China remains the biggest source of cyber-attacks, accounting for a third of all the cyberattacks in the third quarter of 2012, according to Akamai's latest report.
Twitter Bug Changes Application Security Levels on Twitter
Many Web applications allow users to sign in using their Twitter and Facebook accounts instead of creating yet another account. While convenient, the flaw ciykd give these applications could wind up with higher levels of access than they should have.
Censorship Isn't What's Slowing Cuba's New Internet Connection
In February of 2011, Cuba completed the island nation's first submarine fiber-optic cable connection which should have granted greatly increased speeds for Cuban web users. Now, renesys reports that the cable finally became active last week, though not in a normal way.
Foxit Patches Flaw in PDF Reader. Patch now
Foxit released Reader 5.4.5 to fix the boundary error in the company's PDF plug-in for Firefox on Jan. 17. While Foxit released a fixed DLL file on Jan. 11, users are encouraged to download the full update. Users can manually update to the latest version of the software by checking for updates in the program’s "Help" menu, or getting the latest software from the "Download" section of the Foxit website.
Google Prepares to Leave the Password Behind
Tech juggernaut Google seems to be preparing to move away from passwords, which have long been a weak point of digital security, in favor of dedicated devices. But first it just has to convince the rest of the Internet to go along with their scheme.
Watch Out! Malware Posing as Java Update
Following the recent zero-day exploit, the rush is on to download the latest patch for Java. Unfortunately, some users are falling prey to malware disguised as a legitimate Java update. As always: downloader beware.
Microsoft Rebuts Antivirus Test Failure
Microsoft's antivirus failed to achieve certification in the two most recent reports from AV-Test. According to Microsoft sources, the reason is customer-focused prioritization; their customers weren't affected by the samples used in testing. I'm not entirely sure I buy the explanation.
If You Can't Disable Java, What Can You Do?
With the latest zero-day vulnerability in Oracle, the most frequent advice is to dump Java. What if you can't? There are some alternative applications, but what do you do when you don't have a choice?
Red October Used Java Exploit: Update or Disable Java Now
With the recent zero-day exploit for Java, we're beating the "update Java now" drum and playing the "disable Java altogether" fife in the SecurityWatch parade. If that wasn't enough, recent news that the Red October cyber-attack campaign made use of a Java exploit is just one more reason to fall in step.
Microsoft and Others Fail Antivirus Test
AV-Test continually evaluates dozens of popular security solutions and periodically reports their results. In the latest report, Microsoft, AhnLab, and PC Tools failed to receive certification. However, the average score for all tested products is a bit higher than in the previous test.
Why You Shouldn't Trust Google's Free WiFi Network
Last week, Google unveiled plans to build a free wireless Internet zone in Chelsea, a New York City neighborhood. Pretty much every news report and social media conversation focused on the free WiFi, and how this would give people easy access to the Internet. There was no mention of the security issues.
Microsoft Fixes IE Zero-Day Bug with Emergency Update
Microsoft rolled out an update for Internet Explorer to close the the zero-day vulnerability which had already been used in several targeted attacks recently. Microsoft's out-of-band update addresses the critical flaw in Internet Explorer versions 6, 7, and 8, the company said in its security advisory today.
How the 'Red October' Cyber-Attack Campaign Succeeded Beneath the Radar
Kaspersky released the first of a two-part report on "Red October," a malware attack the company believes is infesting high-level government systems throughout Europe and could be specifically targeting classified documents. According to the report, the stolen data is on the order of "hundreds of Terabytes," and went largely undetected for about five years.