Microsoft is releasing Windows 8, the newest version of the Windows operating system, for general availability on October 26. Although Windows 8 offers enhanced security features, it also raises new security concerns because of changes to the graphical user interface and a new online app store. We’re offering the following eight security tips to help you stay secure as you move to Windows 8.
1. Exercise caution with apps for the new Windows 8 user interface (formerly known as Metro)
Some familiar applications have been completely re-written for the new Windows 8 UI. As a result they may work completely differently, despite looking the same. For example, an application historically delivered as an executable could now be entirely web-based. This impacts the visibility your existing security and monitoring tools have into these apps.
2. Use the Windows 8 style UI version of Internet Explorer
By default, plugins are disabled, blocking a major target for exploit kits and Blackhole attacks.
3. Make sure your security vendor can flag malicious Windows 8 UI apps
Windows 8 UI apps have important differences from regular applications, and your security product should be able to distinguish the two. The security product should correctly flag malicious or modified Windows 8 UI applications (tampered, modified, invalid license).
4. Disable hard drive encryption hibernation
Hard drive encryption is a cornerstone of data protection. If possible, disable the hibernation option in Windows 8 through group policy, as it doesn’t always work well with encryption.
5. Make sure your hardware carries the “Designed for Windows 8” logo
To carry this logo, hardware must be UEFI compliant. This means you can take advantage of the secure boot functionality available in Windows 8. Secure boot is designed to ensure the pre-OS environment is secure in order to minimize the risk from boot loader attacks.
6. Make application control a priority
The Windows 8 app store makes application control increasingly important for both malware prevention and productivity control. While the Windows Store will be secured, history shows that malicious apps are likely to slip through. Disable the use of apps that aren’t relevant to your organization.
7. Treat Windows RT (ARM) devices like any other mobile devices
Make sure you impose the same security levels on Windows RT devices as all others. You should have the ability to control, track, remote wipe and encrypt them.
8. Review application permissions in the Windows Store
Applications in the Windows Store must list any resources they require. Carefully review these permissions in the details tab as some will grant access by default to your location information, calendar, etc.
You should still run a full security suite for superior filtering and centralized management and reporting. While Microsoft has included a minimalist antivirus and firewall, most organizations will still require commercial-grade security. And of course, all the old security rules also apply with Window 8. It’s still a bad idea to allow automatic log-on. Above all, remain vigilant.
Antivirus and general malware protection topics. Latest news concerning data protection.
Saturday, September 29, 2012
Monday, September 3, 2012
‘Flame’ Virus explained: How it works and who’s behind it
Flame may be the most powerful computer virus in history, and a nation-state is most likely to blame for unleashing it on the World Wide Web.Kaspersky's chief malware expert Vitaly Kamlyuk shared with RT the ins and outs of Stuxnet on steroids.
Iran appears to be the primary target of the data-snatching virus that has swept through the Middle East, though other countries have also been affected.The sheer complexity of the virus and its targets has led Moscow-based Kaspersky Lab to believe a state is behind the attack.
Kaspersky first spotted the virus in 2010, though it may have been wrecking havoc on computer systems for many years.Vitaly Kamlyuk told RT how his company discovered it, just what makes Flame so significant, features of the virus that could point towards its creator, and why we all lose out in this intensifying cyber-war.
RT: So, how did you spot the malware, was it a planned investigation, or did it come by surprise?
Vitaly Kamlyuk: It was by surprise. We were initially searching for a [different form of] malware. We were aware of the malware that had spread throughout the Middle East, attacked hundreds of computers and wiped their hard drives, making the systems unbootable after that. It was actually after an inquiry from the International Telecommunications Union, which is a part of the United Nations, who actually asked us to start conducting research. When we started looking for this mysterious malware in the Middle East, we discovered this suspicious application that turned out to be even more interesting than the initial target of our search.
RT: According to one of your experts, 'Flame' does not appear to cause physical damage, so why has it been dubbed the most hazardous cyber-attacks in history?
VK: It’s actually on the same level as the notoriously known Stuxnet and Duqu [attacks], because we suspect that there is a nation state behind the development of this cyber attack, and there are reasons for that. This application doesn’t fit into any of the existing groups of developed cyber attack tools. There are currently three groups. There are traditional cyber criminals who are hunting users’ data (like log-ins and passwords) to access bank accounts over the Internet and steal money, send spam, or conduct dubious attacks.This [Flame] doesn’t fit into the group of traditional cyber criminal malware. Also, it doesn’t fit into the activists’ malware who are using typically free and open source tools to attack computers on the Internet. And the third known group [at this time] is nation-states.
RT: What makes this malware different from all other Spyware programs and what damage can it do?
VK: It’s pretty advanced – one of the most sophisticated [examples of] malware we’ve ever seen. Even its size – it’s over 20 megabytes if you sum up all the sizes of the modules that are part of the attacking toolkit. It’s very big compared to Stuxnet, which was just hundreds of kilobytes of code: it’s over 20 megabyes. And the Stuxnet analysis took us several months, so you can imagine that a full analysis of this threat may take us up to a year. So we think it is one of the most sophisticated malware [programs] out there.
It’s also quite unique in the way it steals information. It’s possible to steal different types of information with the help of this spyware tool. It can record audio if a microphone is attached to the infected system, it can do screen captures and transmit visual data. It can steal information from the input boxes when they are hidden behind asterisks, password fields; it can get information from there.Also it can scan for locally visible Bluetooth devices if there is a Bluetooth adapter attached to the local system.
RT: Is there a connection between this new cyber threat and previous large-scale virus attacks?
VK: We are trying to compare and find similarities between this development and previous [ones] of course, but there are so few of them – Stuxnet or Duqu mostly. There is no reliable relation between Stuxnet and Flame as we call it…they are completely different. Because Stuxnet was a small application developed for a particular target with the specific objective to interact with industrial control systems and break them down. And Flame is a universal attacking tool kit used mostly for cyber espionage. So there are so things that [Flame] shares in common with Stuxnet and Duqu, and these are the vulnerabilities that are used by both [types of] malware. Probably one malware simply copied vulnerabilities from the other malware program when they were published.
RT: So this means that cyber warfare is evolving rapidly, and 'Flame' vividly confirms this trend. Can less technologically developed nations resist such attacks, or is it game over for them?
VK: It’s never game over in this area, because even if the country isn’t technologically developed in this area, it doesn’t prevent them from cooperating with organizations like ours and with private companies in the security industry that can provide them with valuable pieces of information which can actually result in the discovery of such threats. And when we discover such threats, we permanently add them to antivirus databases, and users from those nations can use freely available trial tools and commercial antivirus [software] to protect their systems.
RT: This enormous stratum of data that 'Flame' can gather, who would need it and is it really possible to analyze such an avalanche of information?
VK: First of all, when we’re talking about the size of data that is to be analyzed, we know that the attackers do not infect as many victims as possible. Their resources are limited; it seems that they understand that. They are keeping the number of infected machines more or less the same. So it’s the same level. When they finish analyzing data that has been stolen from one network, they remove the malware and switch to another.So we think that it’s still possible the extract only the data they are interested in.
RT: So can we call this a cyber war, and if so?
VK: Stuxnet and Duqu were bright examples of cyber weapons which could even physically destroy infrastructure, and this [Flame] is a continuation of this story. So this is another development in this roe which continues in addition to Stuxnet and Duqu.There are also nation stations supporting [these] developments. We think that cyber warfare has been going on for years already. People were just probably not aware of it because cyber warfare has a unique feature: it’s hidden. Nobody knows when cyber warfare operations are going on. This is the key feature of it.
RT: Who is behind these cyber attacks?
VK: Like with Stuxnet and Duqu, it’s currently unclear who is behind it. It’s very hard to find out who is behind it because when we try to follow the traces, who controls the application – it connects to the command and control centers – it turns out to be… dozens or even more servers spread around different countries around the world. More than 80 or 90 domains are associated with those servers. Most of them are registered with fake identities. So they’re pretty well protected and hidden. So it is unclear who is behind that, and we try not to speculate who could be behind such attacks. We try to base it on pure facts like the language we extract from the code. In this case, we only found traces of good English used inside the code.
RT: So who do you think is winning this war?
VK: I think that humanity is losing to be honest, because we are fighting between each other instead of fighting against global problems which everyone faces in their lives.
Article Source
Iran appears to be the primary target of the data-snatching virus that has swept through the Middle East, though other countries have also been affected.The sheer complexity of the virus and its targets has led Moscow-based Kaspersky Lab to believe a state is behind the attack.
Kaspersky first spotted the virus in 2010, though it may have been wrecking havoc on computer systems for many years.Vitaly Kamlyuk told RT how his company discovered it, just what makes Flame so significant, features of the virus that could point towards its creator, and why we all lose out in this intensifying cyber-war.
RT: So, how did you spot the malware, was it a planned investigation, or did it come by surprise?
Vitaly Kamlyuk: It was by surprise. We were initially searching for a [different form of] malware. We were aware of the malware that had spread throughout the Middle East, attacked hundreds of computers and wiped their hard drives, making the systems unbootable after that. It was actually after an inquiry from the International Telecommunications Union, which is a part of the United Nations, who actually asked us to start conducting research. When we started looking for this mysterious malware in the Middle East, we discovered this suspicious application that turned out to be even more interesting than the initial target of our search.
RT: According to one of your experts, 'Flame' does not appear to cause physical damage, so why has it been dubbed the most hazardous cyber-attacks in history?
VK: It’s actually on the same level as the notoriously known Stuxnet and Duqu [attacks], because we suspect that there is a nation state behind the development of this cyber attack, and there are reasons for that. This application doesn’t fit into any of the existing groups of developed cyber attack tools. There are currently three groups. There are traditional cyber criminals who are hunting users’ data (like log-ins and passwords) to access bank accounts over the Internet and steal money, send spam, or conduct dubious attacks.This [Flame] doesn’t fit into the group of traditional cyber criminal malware. Also, it doesn’t fit into the activists’ malware who are using typically free and open source tools to attack computers on the Internet. And the third known group [at this time] is nation-states.
RT: What makes this malware different from all other Spyware programs and what damage can it do?
VK: It’s pretty advanced – one of the most sophisticated [examples of] malware we’ve ever seen. Even its size – it’s over 20 megabytes if you sum up all the sizes of the modules that are part of the attacking toolkit. It’s very big compared to Stuxnet, which was just hundreds of kilobytes of code: it’s over 20 megabyes. And the Stuxnet analysis took us several months, so you can imagine that a full analysis of this threat may take us up to a year. So we think it is one of the most sophisticated malware [programs] out there.
It’s also quite unique in the way it steals information. It’s possible to steal different types of information with the help of this spyware tool. It can record audio if a microphone is attached to the infected system, it can do screen captures and transmit visual data. It can steal information from the input boxes when they are hidden behind asterisks, password fields; it can get information from there.Also it can scan for locally visible Bluetooth devices if there is a Bluetooth adapter attached to the local system.
RT: Is there a connection between this new cyber threat and previous large-scale virus attacks?
VK: We are trying to compare and find similarities between this development and previous [ones] of course, but there are so few of them – Stuxnet or Duqu mostly. There is no reliable relation between Stuxnet and Flame as we call it…they are completely different. Because Stuxnet was a small application developed for a particular target with the specific objective to interact with industrial control systems and break them down. And Flame is a universal attacking tool kit used mostly for cyber espionage. So there are so things that [Flame] shares in common with Stuxnet and Duqu, and these are the vulnerabilities that are used by both [types of] malware. Probably one malware simply copied vulnerabilities from the other malware program when they were published.
RT: So this means that cyber warfare is evolving rapidly, and 'Flame' vividly confirms this trend. Can less technologically developed nations resist such attacks, or is it game over for them?
VK: It’s never game over in this area, because even if the country isn’t technologically developed in this area, it doesn’t prevent them from cooperating with organizations like ours and with private companies in the security industry that can provide them with valuable pieces of information which can actually result in the discovery of such threats. And when we discover such threats, we permanently add them to antivirus databases, and users from those nations can use freely available trial tools and commercial antivirus [software] to protect their systems.
RT: This enormous stratum of data that 'Flame' can gather, who would need it and is it really possible to analyze such an avalanche of information?
VK: First of all, when we’re talking about the size of data that is to be analyzed, we know that the attackers do not infect as many victims as possible. Their resources are limited; it seems that they understand that. They are keeping the number of infected machines more or less the same. So it’s the same level. When they finish analyzing data that has been stolen from one network, they remove the malware and switch to another.So we think that it’s still possible the extract only the data they are interested in.
RT: So can we call this a cyber war, and if so?
VK: Stuxnet and Duqu were bright examples of cyber weapons which could even physically destroy infrastructure, and this [Flame] is a continuation of this story. So this is another development in this roe which continues in addition to Stuxnet and Duqu.There are also nation stations supporting [these] developments. We think that cyber warfare has been going on for years already. People were just probably not aware of it because cyber warfare has a unique feature: it’s hidden. Nobody knows when cyber warfare operations are going on. This is the key feature of it.
RT: Who is behind these cyber attacks?
VK: Like with Stuxnet and Duqu, it’s currently unclear who is behind it. It’s very hard to find out who is behind it because when we try to follow the traces, who controls the application – it connects to the command and control centers – it turns out to be… dozens or even more servers spread around different countries around the world. More than 80 or 90 domains are associated with those servers. Most of them are registered with fake identities. So they’re pretty well protected and hidden. So it is unclear who is behind that, and we try not to speculate who could be behind such attacks. We try to base it on pure facts like the language we extract from the code. In this case, we only found traces of good English used inside the code.
RT: So who do you think is winning this war?
VK: I think that humanity is losing to be honest, because we are fighting between each other instead of fighting against global problems which everyone faces in their lives.
Article Source
Sunday, September 2, 2012
Fake antiviruses
Basic description
Fake antivirus software is a scam commonly used by malicious software creators in order to sell fake security software to unwitting victims. The scam will typically involve a webpage or pop-up that informs the user they have viruses or other malware on their computer, even though they do not. It then offers to clean the infection. When the user opts to clean up they are required to pay to obtain a version of the fake software the will perform the cleanup. After the victim pays the software may or may not cease the fake warnings.
Technical detail
Fake antivirus, also known as rogue antivirus or scareware, is one of the leading ways for malicious hackers to make money from unsuspecting Internet users. The fake antivirus software typically warns the user that they have various fictional security threats present on their computer. The warnings themselves are false but they are often backed up by believable descriptions of the supposed malware.
When the user chooses to remove the threats they are asked to purchase or register the product and taken to a website that will process the payment details.
The webpages that users are taken to may look like one of these:
Article Source
Fake antivirus software is a scam commonly used by malicious software creators in order to sell fake security software to unwitting victims. The scam will typically involve a webpage or pop-up that informs the user they have viruses or other malware on their computer, even though they do not. It then offers to clean the infection. When the user opts to clean up they are required to pay to obtain a version of the fake software the will perform the cleanup. After the victim pays the software may or may not cease the fake warnings.
Technical detail
Fake antivirus, also known as rogue antivirus or scareware, is one of the leading ways for malicious hackers to make money from unsuspecting Internet users. The fake antivirus software typically warns the user that they have various fictional security threats present on their computer. The warnings themselves are false but they are often backed up by believable descriptions of the supposed malware.
When the user chooses to remove the threats they are asked to purchase or register the product and taken to a website that will process the payment details.
The webpages that users are taken to may look like one of these:
Fake antivirus is spread using a variety of methods, all designed to draw an unsuspecting user into installing the software.
Email and messaging
Criminals send spam email and social network messages with the software installer attached, using a social engineering lure to persuade the recipient to open the attachment. Common lures include tax refund information, package delivery notifications or pictures of topical news stories.
Search engine poisoning
Hackers create pages related to common or topical search terms and design them to appear high in search engine results. This makes it likely that people will encounter the page during their usual search activity. The webpages may either display warnings about infection that encourage the user to purchase the fake antivirus, or they download a video player which is actually the fake antivirus installer.
Compromised websites
Cybercriminals often break into other websites in order to spread their software, relying on the site's popularity to draw innocent users. The hackers will then install extra code into the compromised pages, again with the goal of either displaying fake security warnings or exploiting a browser vulnerability to install their software directly. Cybercriminals will often combine these techniques to increase the effectiveness of their fraud.
The fake antivirus software makers use a variety of names for their software to make it appear legitimate. Examples of these names include:
AntiSpywarePro
Antivirus Plus
Antivirus Soft
Antivirus XP
Smart Internet Protection
Security Defender
Some will also steal the names of legitimate security software.
Email and messaging
Criminals send spam email and social network messages with the software installer attached, using a social engineering lure to persuade the recipient to open the attachment. Common lures include tax refund information, package delivery notifications or pictures of topical news stories.
Search engine poisoning
Hackers create pages related to common or topical search terms and design them to appear high in search engine results. This makes it likely that people will encounter the page during their usual search activity. The webpages may either display warnings about infection that encourage the user to purchase the fake antivirus, or they download a video player which is actually the fake antivirus installer.
Compromised websites
Cybercriminals often break into other websites in order to spread their software, relying on the site's popularity to draw innocent users. The hackers will then install extra code into the compromised pages, again with the goal of either displaying fake security warnings or exploiting a browser vulnerability to install their software directly. Cybercriminals will often combine these techniques to increase the effectiveness of their fraud.
The fake antivirus software makers use a variety of names for their software to make it appear legitimate. Examples of these names include:
AntiSpywarePro
Antivirus Plus
Antivirus Soft
Antivirus XP
Smart Internet Protection
Security Defender
Some will also steal the names of legitimate security software.
Article Source
Friday, August 31, 2012
Bitdefender Relaunches Clueful as Free Social Web-Guide on iOS App Behavior
Former iOS Privacy App made available again with more features for consumers to learn how Apps treat their data and privacy
Bitdefender, the award-winning provider of innovative antivirussolutions, today announced the relaunch of Clueful, the first security application to empower iPhone owners to distinguish privacy violating apps. Replacing the controversially removed iOS App Store version, Clueful returns as a free web-app globally.
Available for free at http://www.cluefulapp.com via iPhones, iPads and PCs alike, the new Clueful adds more features and more vital privacy information for users. Users are informed of Apps that are careless with usernames and passwords, track location, read and use address books, access calendars, drain a device’s battery, overly target users with ads, don't encrypt personal data or transmissions, track and aggregate the owner’s usage through multiple analytics networks, and more.
Alongside access to Top App listing information, users can now add comments on any App’s clue card and comment on how developers handle their privacy.
“The iPhone is the most personal of your personal devices, storing large amounts of private information that app developers would love to access. We feel Clueful is one of the most useful and valuable tools available to consumers and are excited to relaunch it,” said Bitdefender’s Chief Security Researcher, Catalin Cosoi. “We’re putting Clueful out as a comprehensive, full-featured guide to iOS apps with added social features and are preparing further advances for this new technology. There will be much more about Clueful coming soon.”
Bitdefender®, the award-winning provider of innovative antivirussolutions, continues to work with Apple to bringing the initially approved and later pulled Clueful back on the App Store.
ZUHGRGUVN872
Article Source
Bitdefender, the award-winning provider of innovative antivirussolutions, today announced the relaunch of Clueful, the first security application to empower iPhone owners to distinguish privacy violating apps. Replacing the controversially removed iOS App Store version, Clueful returns as a free web-app globally.
Available for free at http://www.cluefulapp.com via iPhones, iPads and PCs alike, the new Clueful adds more features and more vital privacy information for users. Users are informed of Apps that are careless with usernames and passwords, track location, read and use address books, access calendars, drain a device’s battery, overly target users with ads, don't encrypt personal data or transmissions, track and aggregate the owner’s usage through multiple analytics networks, and more.
Alongside access to Top App listing information, users can now add comments on any App’s clue card and comment on how developers handle their privacy.
“The iPhone is the most personal of your personal devices, storing large amounts of private information that app developers would love to access. We feel Clueful is one of the most useful and valuable tools available to consumers and are excited to relaunch it,” said Bitdefender’s Chief Security Researcher, Catalin Cosoi. “We’re putting Clueful out as a comprehensive, full-featured guide to iOS apps with added social features and are preparing further advances for this new technology. There will be much more about Clueful coming soon.”
Bitdefender®, the award-winning provider of innovative antivirussolutions, continues to work with Apple to bringing the initially approved and later pulled Clueful back on the App Store.
ZUHGRGUVN872
Article Source
Thursday, August 30, 2012
PandaLabs Offers Security Tips to Stay Safe This Summer
PandaLabs, the anti-malware laboratory of Panda Security, The Cloud Security Company, today published its annual security tips for consumers to stay safe this summer and avoid falling victim to computer fraud. During the summer, people (especially children) have more spare time on their hands for using computers and connecting to the Internet more frequently, thus increasing the risk of falling victim to malicious code.
One of the newest scams that has surfaced recently involves sending fake flight confirmation emails. The potential victim receives a fake confirmation for ‘recently purchased tickets’ with instructions on how to open an attachment to view the ticket. The file, however, is a Trojan of the Sinowal family that is designed to steal users’ confidential information.
Article Source
One of the newest scams that has surfaced recently involves sending fake flight confirmation emails. The potential victim receives a fake confirmation for ‘recently purchased tickets’ with instructions on how to open an attachment to view the ticket. The file, however, is a Trojan of the Sinowal family that is designed to steal users’ confidential information.
“In the summer, many people book flights online to get to their holiday destinations,” said Luis Corrons, technical director of PandaLabs. “Cyber-crooks are taking advantage of this situation to send a new wave of fake emails aimed at tricking users into opening the attachments and infecting their computers.”
Security Tips for Summer Vacation
PandaLabs is continually analyzing the latest Internet trends, and with this in mind, offers the following advice to help safeguard users’ security this season:
Use caution with social networking sites: People give out too much information about their holiday plans on social networking sites, even tipping criminals off about their empty homes. Check privacy settings and avoid sharing private information on social networks.
- Install parental controls: Children spend more time in front of computers during summer vacation. Installing a good parental control program on the computer will help minimize children’s vulnerability on the Internet.
- If you can avoid it, never use a shared computer: If using a shared or public computer on vacation is a must, prevent identity theft by making sure your account doesn’t automatically save your password and user ID. If you suspect the computer’s security has been compromised by a virus, leave it and use another. Take care when connecting an external device to the computer, as it may become infected without your knowledge.
- Take care with email: Email is one of the main virus entry points, so pay special attention to it. Do not open messages from unknown senders or click on dubious links.
- Beware of public Wi-Fi networks: You could be hooking up to a network set up by hackers to steal any information that you share across the Internet. When you connect to email, social networking sites or online stores, make sure you are using a secure connection (https), so that traffic is encrypted and no one else can access the information.
- Keep your computer up-to-date: Malware seeks to exploit existing security holes in systems to infect them. Make sure all necessary security patches and updates are properly installed.
- Protect your computer: Make sure you have reliable, up-to-date protection installed on your computer. There are many free, reliable solutions on the market, like Panda Cloud Antivirus, available for download at www.cloudantivirus.com.
“By following PandaLabs’ tips for staying secure, users can enjoy their summer vacations with greater peace of mind. Just as people would lock all doors and windows before going on vacation, consumers should also take great care to protect their digital worlds,” added Corrons.
Article Source
Wednesday, August 29, 2012
50% of users cannot recognize a phishing message
The standard data theft method is social engineering – a potential victim is lured onto an infected web-page or is duped into opening a file attached to an e-mail. It is not always easy to recognize such a message, as a survey conducted in May 2012 by O+ K Research at the request of Kaspersky Lab demonstrates. During the survey, 50% claimed they are incapable of recognizing a phishing message or a forged web-site.
The overwhelming majority of phishing messages are delivered through e-mail or social networks. The reason is simple: these are currently the most wide-spread means of communication. According the same research, 86% of PC users check their e-mails regularly, and 73% communicate in social networks. 54% of users chat on the Internet regularly with their smartphones. Cybercriminals who use phishing as a tool to steal data are primarily interested in gaining unauthorized access to social network accounts, accounts in online banking and payment systems, and e-shops. According Kaspersky Lab, in June 68% of phishing messages related to such services were targeted at data theft.
The results give indirect evidence that the mass messaging method bears fruit: about half of the O+K Research respondents noticed they have already encountered suspicious correspondence in social networks or e-mail. Thus, 47% of PC users got a message with a suspicious link or an attachment, and 29% of respondents got letters on the name of a bank (social network, another service, etc.) with a request for confidential information.
Moreover 26% of users admitted that their computers had been infected as a result of opening an attachment to a letter, and 13% of respondents had entered personal or financial data at suspicious pages. Therefore when fighting against fake and infected messages and web-sites, instead of relying upon your own efforts it is better to use specific solutions. The new Safe Money technology, presented as a part of Kaspersky Internet Security 2013, helps to detect and block attempts to steal your sensitive data via phishing web-pages and malware linked to online shopping or banking services.
Quite a high percentage of users fell prey to phishing on their mobile devices. 24% of tablet users and 18% of smartphone owners received correspondence with suspicious links and attachments. 14% and 11% respectively had letters on behalf of a bank or social network. One can presume that as we see more and more mobile devices going online, the amount of phishing letters for mobile platforms will also grow. Therefore it is high time to think of protecting you mobile devices with specific anti-phishing solutions. This function is already available in Kaspersky Mobile Security and Kaspersky Tablet Security.
Article Source
The overwhelming majority of phishing messages are delivered through e-mail or social networks. The reason is simple: these are currently the most wide-spread means of communication. According the same research, 86% of PC users check their e-mails regularly, and 73% communicate in social networks. 54% of users chat on the Internet regularly with their smartphones. Cybercriminals who use phishing as a tool to steal data are primarily interested in gaining unauthorized access to social network accounts, accounts in online banking and payment systems, and e-shops. According Kaspersky Lab, in June 68% of phishing messages related to such services were targeted at data theft.
The results give indirect evidence that the mass messaging method bears fruit: about half of the O+K Research respondents noticed they have already encountered suspicious correspondence in social networks or e-mail. Thus, 47% of PC users got a message with a suspicious link or an attachment, and 29% of respondents got letters on the name of a bank (social network, another service, etc.) with a request for confidential information.
Moreover 26% of users admitted that their computers had been infected as a result of opening an attachment to a letter, and 13% of respondents had entered personal or financial data at suspicious pages. Therefore when fighting against fake and infected messages and web-sites, instead of relying upon your own efforts it is better to use specific solutions. The new Safe Money technology, presented as a part of Kaspersky Internet Security 2013, helps to detect and block attempts to steal your sensitive data via phishing web-pages and malware linked to online shopping or banking services.
Quite a high percentage of users fell prey to phishing on their mobile devices. 24% of tablet users and 18% of smartphone owners received correspondence with suspicious links and attachments. 14% and 11% respectively had letters on behalf of a bank or social network. One can presume that as we see more and more mobile devices going online, the amount of phishing letters for mobile platforms will also grow. Therefore it is high time to think of protecting you mobile devices with specific anti-phishing solutions. This function is already available in Kaspersky Mobile Security and Kaspersky Tablet Security.
Article Source
Monday, August 27, 2012
Facebook connects users to free antivirus software
Facebook is now directing users who think their computer might be infected to sites where they can get free antivirus software.
The Malware Checkpoint for Facebook sends people either to sign up for Microsoft Security Essentials or McAfee Scan and Repair. Mac users are referred to an Apple Security Updates site.
Facebook already notifies users when the site detects a possible malware infection on an individual machine, and provides these users free antivirus software to clean up the infection. The social network has now opened up its anti-malware campaign to all users in order to them them proactively protect themselves, according to a post on the Facebook Security page:
If you are concerned that your device may have been infected by malware, you can visit http://on.fb.me/infectedMSE or http://on.fb.me/infectedMcA to be self-enrolled in either our Microsoft Security Essentials or McAfee Scan and Repair malware checkpoints...
1. The McAfee option will download a small program onto your Windows computer to perform a one-time scan of your system for malware. It will not interfere with your existing anti-virus or other security products. After it scans your system, it will give you the option to automatically or manually remove the files it flags as malicious.
2. The Microsoft Security Essentials option is a full anti-virus product. Upon download and install, it will add anti-virus software to your computer that will continue to protect your system with the latest anti-virus signatures from Microsoft.
Last year, Facebook added new security features, including Login Approvals and warnings when users are about to get hit by clickjacking and cross-site scripting attacks or malicious links on sites. Earlier this year, the site began offering free antivirus assistance and improved its external blacklist system to protect users from malicious Web sites.
Article Source
The Malware Checkpoint for Facebook sends people either to sign up for Microsoft Security Essentials or McAfee Scan and Repair. Mac users are referred to an Apple Security Updates site.
Facebook already notifies users when the site detects a possible malware infection on an individual machine, and provides these users free antivirus software to clean up the infection. The social network has now opened up its anti-malware campaign to all users in order to them them proactively protect themselves, according to a post on the Facebook Security page:
If you are concerned that your device may have been infected by malware, you can visit http://on.fb.me/infectedMSE or http://on.fb.me/infectedMcA to be self-enrolled in either our Microsoft Security Essentials or McAfee Scan and Repair malware checkpoints...
1. The McAfee option will download a small program onto your Windows computer to perform a one-time scan of your system for malware. It will not interfere with your existing anti-virus or other security products. After it scans your system, it will give you the option to automatically or manually remove the files it flags as malicious.
2. The Microsoft Security Essentials option is a full anti-virus product. Upon download and install, it will add anti-virus software to your computer that will continue to protect your system with the latest anti-virus signatures from Microsoft.
Last year, Facebook added new security features, including Login Approvals and warnings when users are about to get hit by clickjacking and cross-site scripting attacks or malicious links on sites. Earlier this year, the site began offering free antivirus assistance and improved its external blacklist system to protect users from malicious Web sites.
Article Source
Subscribe to:
Posts (Atom)








