Stories by Lucian Constantin

Underground calling service helps cybercriminals extract sensitive info

Researchers from security vendor Trusteer have come across a professional calling service that caters to cybercriminals. The business offers to extract sensitive information needed for bank fraud and identity theft from individuals.

Written by Lucian Constantin10 Nov. 11 05:56

NSS Labs claims its new tool can detect all Duqu drivers

Security research firm NSS Labs has released an open source scanning tool that is capable of detecting all malicious drivers used by the new Duqu threat, according to its engineers. However, other security vendors believe that the malware's creators are capable of evading detection at any time.

Written by Lucian Constantin08 Nov. 11 02:30

Romanian eBay hacker and prosecutor both unhappy with appeal ruling

Romanian eBay hacker Vlad Duiculescu, known online as "Vladuz," lost the appeal to get his three-year suspended prison sentence reduced on Tuesday. The court also dismissed the appeal lodged by prosecutors regarding the hacker's acquittal on organized crime charges.

Written by Lucian Constantin04 Nov. 11 03:24

Ongoing drive-by download campaign hijacked MIT server

A server belonging to the Massachusetts Institute of Technology was commandeered by hackers who used it to launch attacks against other websites as part of a larger drive-by download campaign, according to antivirus vendor BitDefender.

Written by Lucian Constantin04 Nov. 11 00:25

Duqu exploits zero-day Windows kernel vulnerability to infect computers

Security researchers from the CrySyS laboratory in Hungary have located an installer for Duqu, the <a href="http://www.pcworld.com/businesscenter/article/242114/duqu_new_malware_is_stuxnet_20.html">Stuxnet-inspired threat</a> that has kept the security industry on its toes for the past couple of weeks, and determined that it exploits a previously unknown vulnerability in the Windows kernel.

Written by Lucian Constantin02 Nov. 11 06:18

Researchers defeat CAPTCHA on popular websites

Researchers from Stanford University have developed an automated tool that is capable of deciphering text-based anti-spam tests used by many popular websites with a significant degree of accuracy.

Written by Lucian Constantin02 Nov. 11 02:47

Old image resize script leaves 1 million Web pages compromised

A serious code injection vulnerability affecting timthumb, a popular image resize script used in many WordPress themes and plugins, has been exploited in recent months to compromise over 1 million Web pages.

Written by Lucian Constantin01 Nov. 11 00:56

Number of fake antivirus attacks has decreased considerably, researchers say

The frequency of attacks that distribute fake antivirus software, a long-time pillar of the underground economy, has decreased considerably in recent months. However, security researchers warn that the industry is not yet dead and new versions of attacks continue to be released.

Written by Lucian Constantin29 Oct. 11 03:04

Attackers trick Facebook users into exposing secret security codes

New social engineering attacks are tricking Facebook users into exposing anti-CSRF tokens associated with their sessions. These security codes allow attackers to make unauthorized requests through the victim's browser.

Written by Lucian Constantin28 Oct. 11 04:36
[]