Showing posts with label Phishing Attack. Show all posts
Showing posts with label Phishing Attack. Show all posts

Wednesday, 18 November 2015

Public Wifi Especially Risky In Airports And Hotels



Most of unsafe open Wi-Fi networks can be found in airports and hotels. There is the chance that you log in to a hotspot of a malicious greatest. That's Janne Pirttilahti, Director of Product Management Next Gen Security at F-Secure, said Tuesday.

Pirttilahti demonstrated during Wifi Now in Amsterdam how easy it is to create a fake hotspot and people in the area to let the network use with the aim to steal private information from them.

Hotels And Airports

Hotels and airports are the easiest locations to set up fake hotspots around because there are a lot of businessmen or people who have to spend money, says Pirttilahti talking. "There are interesting targets, while falls in those locations do not like someone pops open a laptop with antennas. Sometimes it can even from a hotel room. But in a coffee shop is much faster suspicious."

Research by F-Secure among UK consumers also shows that many consumers are well aware of the risks they run if they use public Wi-Fi networks. A whopping 52 percent of consumers surveyed avoid using public Wi-Fi networks because they are afraid that their personal information into the hands of hackers.

VPN Connection

59 percent says open Wi-Fi networks not to use it because they are afraid of viruses or malware. Still, says nearly one in every three month to use at least once and sometimes daily public wifi networks. The advice is to at public Wi-Fi networks in any event using a VPN connection.

Monday, 16 November 2015

Google Chrome Now Also Protects Against Social Engineering


Google Chrome has the protection of its users expanded. Chrome previously protected its users against all phishing sites and websites with malware, social engineering is now also added. Social engineering attack websites posing as a trusted party and want to make the visitor believe that the web content is provided by the trusted party.

Warning

According to the Internet giant is going beyond traditional social engineering and phishing involves more instances of misleading web content. As an example, a website that uses the Google Chrome logo and offering a so-called update for the browser, or a page that occurs as Google support and the user requests a number to call. If Chrome detects such misleading websites let users now see a warning.

Friday, 23 October 2015

Google Will Implement Stricter DMARC Policies For Gmail


Google next year, the emails that Gmail users receive stringent filtering, as the Internet giant announced. Emails that do not meet the requirements will be refused DMARC from June 2016.DMARC (Domain-based Message Authentication, Reporting and Conformance) is a standard developed by fifteen leading Internet companies, including Microsoft, Facebook, LinkedIn and Google.


Through the new policy change, Google will soon emails from Gmail.com refuse which addresses claiming to be from Google's servers, but do not originate in reality. This should for instance prevent spoofing or phishing attacks. The stricter DMARC standard was already through AOL set and Yahoo. Yahoo will DMARC next month also ymail.com and rocketmail.com's set.

Google also announced to support the new ARC protocol. The Authenticated Received Chain (ARC) protocol is designed to prevent problems with DMARC. It is in this case added to a cryptographically signed header to the message. At present, many legitimate emails from forwarding services and mailing lists rejected because they do not meet the DMARC requirements. The ARC-protocol must ensure that such services the forwarded e-mails still can authenticate that they are accepted.

Friday, 4 September 2015

Two-Factor Authentication Frustrates Phishers


Turning on two-factor authentication for email accounts appears to be a difficult problem for phishers, let examination of Canadian Citizen Lab see. The organization writes a sizeable phishing campaign against Iranian people and a director of the American civil rights organization EFF.

Two-factor authentication ensures that must be entered when logging an additional code. This code is received via SMS or can be generated via an app. However, the code has a limited validity. This allows phishers to try in real-time to get both the password of the account if the two-factor code. During the phishing campaign Citizen Lab describes using various tactics.Thus users received a text message which seemed to come from Google and suggested that there was someone else at the account login.

Shortly after the SMS was sent a phishing mail that warned of the accused login attempt. The message was a link to enable users to reset their password. The link pointed to a phishing site where the password must be entered as a two-factor code.The attack failed when the attackers in a short time more than ten text messages sent out to the target to increase the pressure.

Journalist

In the case of the EFF headmistress she got a call from someone posing as a journalist and wanted to interview her. Then the director received an e-mail with a link to a document on the phishing page. Since the link has not been opened to the phisher was frustrated and sent a new message. Eventually he called the director frustrated and asked if she wanted to open the link, since the mail was now sent from his personal account.

According to Citizen Lab shows the campaign that two-factor authentication, and the attention of users, ensures that attackers need to do much more effort to gain access to an account. In addition, users are advised to use an app to generate the two-factor code, as it offers more security than a text message.

Tuesday, 11 August 2015

Hacked French Television Channel TV5 Still Without Internet


The French television channel TV5 in early April by a massive hack was hit still has no access to the Internet. That the director of the station Yves Bigot recently told France Info let you know. "We are still without wifi, Skype or scanner, because we still can not connect to the Internet."

First the French internet security agency ANSSI must have completed the examination and consent. Also, a more secure network built. Therefore, employees are working as if they are part of the television series "Lost," said Bigot. The damage of the attack is between 4.3 and 5 million euros for this year. For the next three years there will be further € 11 million, bringing the total amount of loss comes to 15 million euros.

The attackers used a phishing attack to gain access to the transmitter. Because of the attack was also tightened security policies. Henceforth, more complex passwords must be chosen, which will also be changed frequently.

Wednesday, 29 July 2015

App Store And iTunes Exposed Significant Vulnerabilities: Relates To System Security



Security experts recently discovered a major flaw in Apple's iTunes App Store and invoice systems. An attacker who exploited this vulnerability could hijack sessions, the malicious manipulation of the invoice. Vulnerability Lab's security researcher Benjamin Kunz Mejri announced its discovery of this vulnerability this week. The major drawback is that the injection-side input validation web application vulnerabilities. The security researcher said in the announcement, can contribute to the flawed content features and services modules inject malicious script code through this vulnerability a remote attacker.

Mejri introduction represents an attacker could exploit the vulnerability approach is to replace the malicious script code to control the value of the invoice module name. If the device is in the Apple store to buy, the backend will use the name value to add coding control condition, which can generate an invoice before the invoice is sent to the seller. The consequences of this will lead to is to have the application side scripting code execution Apple invoice. The severity rating of the vulnerability is CVSS 5.8 (universal vulnerability rating system).

In addition the network attacker can also interact with other Apple applications store account users to control this vulnerability by continuing operating environment, irrespective of the user is the sender or recipient will not affect them take advantage of this loophole. The security researcher said invoice is available to sellers and buyers of both sides, this will give the buyer, the seller or the Apple web administrators / developers to bring great risk.

An attacker can also exploit this vulnerability to hijack user sessions, constantly launch phishing attacks, create links to external resources redirected lasting, influence or manipulation is connected to the service module.

After Mejri found the vulnerability in June 8 was the notification and coordination, then it would be for Apple's product security team issued a notice supplier, Apple after notification responded and feedback, Apple Developer Group provides repair After notice vulnerability, Vulnerability Laboratory was recently disclosed that they discovered this vulnerability.

Earlier this month, Apple's new version of iOS and OS X operating system, the existence of many security vulnerabilities were patched. In a security bulletin, Apple said they released the iOS 8.4 contains 20 multiple patches, the existence of remote code execution, the application terminates, encrypted traffic interception and other issues were corrected.

In these updates, the one called "Logjam" defects has been resolved. It is used in the Diffie-Hellman key exchange algorithm encryption vulnerabilities, the technology is widely used to share key and create a secure communication channel in the Internet protocol. That could allow hundreds of thousands of websites and servers using HTTPS exposed to the risk of theft and traffic is intercepted, and thus may be subject to-middle attack.

At least one of these issues will have a direct impact on Apple Watch. The problem exists in the application installation link, malicious applications can exploit the vulnerability Watch prevent application launch.

Proof of Concept



Sunday, 26 July 2015

US Government Attacked Via Flash Player Flaw


Several agencies of the US government in June and July attacked via a Flash Player vulnerability that was discovered by the Italian Hacking Team and true at the time of the attacks had no patch yet, says the FBI. Details about the vulnerability were found in the data that were stolen from the Italian surveillance company. However, the break-in at Hacking Team was made ​​public on July 6.

Now, according to information from the FBI's Flash Player flaw had been since June 8 by assailants known and actively used to penetrate US government agencies. Previously had anti-virus company Trend Micro already know that the vulnerability before the disclosure in targeted attacks against targets in Korea and Japan had begun, namely July 1 . The FBI goes in the case for the attacks against US government agencies for two campaigns which probably gathering information aim.

Campaigns

The first phishing campaign took place on 8, 9 and 11 June, the second was observed on July 8, according to a warning that spread the FBI and by Public Intelligence online ( pdf is put). Both attacks emails were sent with a link. The link pointed to an exploit that took advantage of the vulnerability in Flash Player. The attack on July 8, the FBI more information mentioned in the warning. Thus, the government received a spear phishing e-mail with a link to a PDF document. When users opened a website loaded there the link containing JavaScript code. This code then loaded a malicious Flash file that vulnerability in Flash Player attacked to infect your computer with malware.

The spear phishing emails had different topics such as 'BBW Analysis report - 2015', 'Tomorrow Morning New Starts', "Perry Dale Club for Leadership: Financial Literacy 101", "FAS Analysis Report - 2015", "AEP Energy Program Update: 2015 Program Year Kick Off ',' Review Link "and" PLS Account A42660861. All spear phishing emails that were submitted in July had the same sender. The timing of the attack in July is remarkable, because on July 8 wrote poetry namely the vulnerability in Adobe Flash Player version 18.0.0.194 and earlier on an emergency patch . In the warning, the FBI also recorded several IP addresses and domains that were used by the attackers and can help detect a possible attack.

Saturday, 18 July 2015

Google's Tougher Action Against Unwanted Software


Google Chrome users in the coming weeks will see more warnings from the browser get that warn against unwanted software. Programs that are undesirable in Internet hijack the browser and then inject all kinds of ads are a gigantic problem, as shown by previous research by Google and the University of California.

The researchers wanted to know how big the problem of "ad injectors" actually was. This is software that injects ads on websites or existing ads replace.Google had in the first few months of this year, more than 100,000 complaints received ad injectors. During the investigation it was found that 5.5% of all IP addresses that Google sites visits with one or more ad injectors infected. In total, the researchers discovered more than 85,000 applications that hijack the browser and inject ads.

Detection

The detection of Google has been improved to detect this type of unwanted software, making short-term Chrome users more warnings will be given. "The mandate remains unchanged," says Stephan Somogyi from the Google Safe Browsing team. "We focus only on protecting users from malware, phishing, unwanted software, and similar evil. You will see a warning SafeBrowsing not get another reason to see."

According Somogyi unwanted software is distributed through a variety of ways, including the above-mentioned ad injectors. In many cases, Google's Safe Browsing technology is the last layer of defense, commented Google employee. Besides Safari and Firefox, Chrome also make use of Google's Safe Browsing technology.

Sunday, 31 May 2015

DNS Changing Malware Worldwide Institutions Routers


Recently, a well-known security researcher showed that vulnerabilities in popular routers actively attacked by malware, but also weak and default passwords appear to be a way through which attackers take control of the devices. Anti-virus company Trend Micro warns of DNS changer malware. The malware executes from the internal network user brute force attacks on the administrator interface of the router.

Then, the DNS settings are adjusted. The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. By adjusting the DNS of the router can fit criminals traffic from users via their server run.Most operating systems are configured to use the DNS settings of the router. Once a computer or other device connected to the router, the custom DNS settings will be used. This allows users of the assailants attacked router forwarding to as phishing sites or into downloading malware.

"Keep Custom DNS settings that users do not know if they navigate to reliable or fake websites," says Fernando Merces. He notes that users who have not changed the default password of the router particular risk. The attack begins via a phishing attack, which points to a page with a script. This script then runs from the internal network brute-force attack on the router.Because the browser is running the script, the traffic is sent to the router as an internal request.

The script use the assailants attempting to both the IP address and password of the router councils. The script supports different models and manufacturers, among others TP-Link and D-Link. The attacks seem focused on Brazil, where 88.3% of the attacked device was observed, followed by the US (2.9%) and Japan (1.3%). Users are advised to use secure passwords for all accounts on the router, change the default IP address and disable the remote management features. In addition, Firefox NoScript is recommended that the execution of scripts can block in the browser.

Monday, 4 May 2015

Cat-And-Mouse Game Around Google Password Alert Continues



There is now a real cat-and-mouse game developed around the Password Alert extension from Google that should protect Chrome users from phishing attacks, but has become an attractive target of investigators still trying to bypass the expansion and there also manage.

Password Alert allows users to enter their Google password on a phishing site get a warning. It is then possible to change the password from the warning. Earlier this week succeeded the British security consultant Paul Moore managed to evade Password Alert via a script of seven lines. Users were given in this case, no warning when their Google password on a phishing site filled in.

Google launched an update to version 1.4, which was also by Moore circumvented . Again, Google published a new version, 1.5, which the Dutch security company Securify came up with a way to bypass the warning. It did not take long before Google had this attack captured and released version 1.6. Researchers have now also passed this version, which is the latest version, to circumvent .

"Today, we have again found a new way to bypass Password Alert. By the login form to load an iframe which Javascript is disabled, it is no longer possible for Password Alert to capture keystrokes. This detection does not work anymore" says Yorick Koster of Securify. "In fact, this is a cat-and-mouse game, the extension checks if a user Google account information entered:. Email address and password When one of the two no longer good comes through, then the detection is not working.."

Saturday, 2 May 2015

Google Password Alert Patched And Again Circumvented



Wednesday, Google unveiled an extension for Chrome that Google password to protect the users against phishing attacks. Once users to a phishing site have completed their password they get a warning Password Alert , as the extension is called, and the ability to change their Google password.


The operation was not infallible, because not a day later, the British security consultant Paul Moore Password Alert via a script of seven lines circumvented , as he made ​​via Twitter announced. The script, which the consultant claimed it made ​​in two minutes, ensured that users were given no warning to be seen. Today Google launched an update to version 1.4 to address the onslaught of Moore. An hour ago, Moore, however, managed to also get around this version, let him again via Twitter know.

Update May 2

The Dutch security company Securify published yesterday a comprehensive proof-of-concept in order to avoid the extension, but it seems that Google has solved this attack since yesterday version 1.5 appeared.

Tuesday, 21 April 2015

JavaScript Annex Spreads CryptoWall-Ransomware


In many email attacks are used executables and Office documents, but there are spammers that use JavaScript attachments. Before warns Trustwave. The security company recently discovered a spam campaign where emails were sent that contain supposedly a resume laity.

There was a zip file as an attachment sent with it a Javascript file, ending .js. Once the recipient opened the file the script tried to download an executable, which turned out to be a variant of the CryptoWall-ransomware. This ransomware encrypts all kinds of files on the computer and then asks hundreds of dollars for decrypting it.

On another spam campaign Trustwave discovered a phishing attack that also made ​​use of JavaScript. In this case, an HTML file was sent to JavaScript which recipients must enter their account details. "If an e-mail telling you to enable JavaScript that you should not really do," says analyst Brian Bebeau. "Despite the use of executable files and other exploits you can not ignore JavaScript attachments in your e-mail traffic. They can both your users and yourself cause problems."

Saturday, 14 March 2015

US Sees 245 Successful Attacks On industrial Systems


US industrial systems include critical infrastructure faced last year with 245 successful attacks. That the Industrial Control Systems Cyber ​​Emergency Response Team (ICS-CERT) of the Department of Homeland Security in a new report ( pdf ) let you know.

Most attacks were directed against the energy sector. Furthermore, 55% of the 245 reported incidents would be the work of advanced persistent threats (APT) or "sophisticated actors" are. Other incidents appeared the work of hacktivists, insiders and criminals. In many cases, the attackers because of lack of data could not be traced.

Attack Methods

The attackers used different ways to access the systems, such as the use of zero-day vulnerabilities in control systems and software, SQL Injection in Web applications, network scans, spear phishing and "watering hole attacks." There were also incidents of control systems that were not connected to the Internet, the so-called air-gapped systems were infected with malware. It may be used for this purpose infected removable media.

In most cases it is unknown how the attackers gained access to the systems. ICS-CERT further argues that the actual number of incidents is probably higher than the 245 incidents reported. Organizations in the vital infrastructure are therefore urged to report all incidents, even when there is no need support, so that any other incidents can be found and the method of attackers is clear.

Saturday, 7 March 2015

British Police Arrest 57 People Due To Cybercrime


British police last week arrested 57 people on suspicion of cybercrime. The arrested persons are suspected of breaking into multinationals and government and steal data, performing DDoS attacks, cyber fraud and developing malware.

This would have a 21-year-old man 400,000 email addresses and passwords of Yahoo stolen and published in 2012. A 33-year-old man is suspected of having a DDoS attack on a competitor performed in order to gain a competitive advantage. A third suspect would have carried out a phishing attack in which £ 15,000 was captured. A 23-year-old man is suspected of breaking into the Pentagon, where he information about a satellite service would have captured.


In addition to maintaining all the suspects said the British National Crime Agency (NCA), which this week also SMEs, hosting companies and ISPs helped identify threats to their infrastructure. So got 60 companies visited by the police and became their IT environment controlled. This resulted in more than 5,500 hacked servers.

Through these servers could send cybercriminals spam, perform DDoS attacks and hosting phishing sites. If organizations follow the advice of the NCA, it could halve the phishing attacks in Britain, according to the investigation department. Police Chief Executive Peter Goodman calls geburikers organizations and therefore to take simple measures that help to be safe on the Internet and make it harder for criminals to get away with it.

Tuesday, 3 March 2015

Anti-virus company: Europol Operation Failed Against Botnet


The operation against the Ramnit botnet that Europol several European investigative services and security last week performed partly failed, causing hundreds of thousands of computers controlled by cybercriminals, according to the Russian anti-virus company Doctor Web.

In the operation were seized hundreds of domains that the botnet used to communicate with infected computers, as well as different servers. The Ramnit malware did over a period of almost five years in total to infect 3.2 million computers. The last half year were approximately 500,000 computers have been infected with the malware.

Doctor Web suggests that there are several variations of Ramnit are active, including one which since September 2011 has been announced. This version can steal all kinds of passwords and FTP programs would have on hundreds of thousands of computers are active every day. "Despite the message in the media about a successful operation against the Ramnit botnet, our analysts have no decrease seen botnets that monitors the anti-virus laboratory," the anti-virus company.

According to researchers from the virus fighter would definitely twelve Ramnit botnets operate. Two of these botnets exist together from more than 500,000 infected computers. "The figures show that the parties behind the operation to destroy the botnet Ramnit evidently not been able to turn off all servers of this botnet," as the researchers conclude whatsoever.

Wednesday, 25 February 2015

Large Botnet Achieved By Europol In The Air


Europol has partnered with European investigation services a large botnet off the air that had infected 3.2 million computers worldwide. It involves Ramnit botnet that for years was active and on infected computers include passwords booty made ​​and other data.

Computers were infected by opening links in spam emails and visiting infected websites. Ramnit is also a so-called "file infector" who .exe, .dll- and .html files on hard drives and connected storage devices infected. Once a computer became infected malware added the infected code in these files, and as soon as they were started spreading the infection further. Also were found public FTP servers that were used for distributing Ramnit.

In addition to investigative agencies from the Netherlands, Italy, Germany and Britain Europol coordinated the operation with Microsoft, Symantec and Anubis Networks . During the operation of the botnet Command & Control servers were turned off, and the 300 domains that were used to control infected computers.

"This successful operation demonstrates the importance of cooperation between international investigative agencies and private industry in combating cybercrime. We will remain committed to disable botnets and disrupting the infrastructure used by criminals for cyber crime," said Wil van Gemert, Deputy Director of Europol. Microsoft and Symantec have now been delivered solutions to remove the malware from infected computers.

Monday, 23 February 2015

Mozilla Is Considering Blacklist For Superfish Certificate


Mozilla is considering to put the Superfish certificate was installed on laptops from Lenovo on a blacklist.According to a discussion on Mozilla's Bugzilla where developers discuss issues and bugs in Mozilla software. By putting the certificate on a blacklist would user certificate warnings that are displayed when using the Superfish certificate can not ignore.

Through the root certificate that installs Superfish on the root store of computers, where all root certificates are stored, SSL connections can be intercepted. Superfish late because all SSL connections run through its own certificate. Researchers managed to crack the password using the private key of the Superfish certificate. This makes it possible in some cases to Man-in-the-middle attacks against systems that perform Superfish and certificate are active.

"Every certificate that is added to root stores by commonly used software and whose private key is known, is a risk," said Gervase Markham on Bugzilla. He notes that the behavior of software installation certificates or not install on computers can change. A program can one week show no suspicious behavior and that a week later do it again. "Without extensive research, we do not know exactly how they work, and in what cases can modify software root lists and also what root lists."

Although Mozilla employees were initially quite hesitant to put the certificate on the blacklist, the decision by Microsoft to the Superfish application and the certificate by using Windows Defender and Security Essentials to remove changed this. "This paves the way for us free to revoke the certificate," said Mozilla's Richard Barnes . Since Microsoft already has the certificate on many computers removed the impact of any blacklisting will therefore be easy. "It just adds to the disinfection," Barnes continues. However, if and when the certificate on the blacklist will not yet decided.

Weak "Superfish Certificate" Found In More Software


It is not just the owners of a Lenovo laptop that ran through the Super Fish-adware risk that their SSL traffic was intercepted, also all kinds of other programs using the same kind of certificate. That security researchers discovered Marc Rogers and Filippo Valsorda , both working for CloudFlare. The certificate used Superfish was from Komodia, an Israeli company.

The company shows the framework that for Superfish also used to have used other software. This relates to Keep My Family Secure, Easy hide IP Classic, Lavasoft Ad-aware Web Companion, Staffcop version 5.6 and 5.8, Kurupira Webfilter and Qustodio's parental control software. Also hide-my-ip is called by Rogers, only this software does not use SSL man-in-the-Middle and the certificate used is slightly different with the other programs. Yet it still uses an unrestricted root certificate with a simple password in plain text. Furthermore, the certificates Komodia for these programs used weak and the password is always Komodia.

"I think it's safe to assume that every SSL interception product sold by Komodia or Komodia SDK is based on the same method will be used," said Rogers. This means that the dangerous certificates are not only restricted to the laptops from Lenovo. Everyone who has come into contact with a product or Komodia parental control software installed check that it is not at risk.

"This problem is much bigger than we thought," warns Rogers. By using weak certificates, an attacker can eavesdrop on traffic or manipulate, without requiring users to see this. Even if the SSL connection is checked, the user sees only the strength of the connection between the Komodia software and its browser, and not the connection which goes over the internet. Users can use this page to check if it is installed on their computer, one of the Komodia certificates.
Superfish

Meanwhile Superfish puts the blame down to Komodia. The company leaves opposite the Associated Press that the vulnerability was inadvertently caused by a third party in the software. Superfish CEO Adi Pinhas also denounces the "false and misleading messages" in the media.

Researcher Late MITM Attack With Superfish Certificate See


An American security researcher demonstrated how he set up via a malicious WiFi network and the Superfish certificate Lenovo users may attack. Previously showed researcher Robert Graham already see how the password cracked that the private key of the Superfish certificate used.

Something for which he needed about three hours. Then he wanted to demonstrate that an attack with the obtained certificate would not only theoretically, as the CTO of Lenovo claimed, but also practical. For this, Graham chose as a hardware Raspberry Pi2 combined with Alpha-WiFi adapter. Through " RPI Wireless Hotspot "he changed the Raspberry Pi2 into a wifi hotspot, while sslsplit to perform the Man-in-the-middle attack used. In total, cost of setting up the hotspot also three hours.

Graham leaves on his blog how a simulated user via its Wi-Fi hotspot is internet banking can be intercepted, even though the user gets when visiting his bank site to see a valid SSL icon. According to Graham he used for performing the attack only commonly available tools. "The only special feature is sslplit, but it is a tool that companies use often for security purposes, and does not have a special hacking purpose. '" The researcher therefore concludes that this attack is really practical and not just theoretical.

Saturday, 21 February 2015

Lenovo Warns Customers For Super Fish-Adware


Lenovo has a security bulletin released which warns customers for the Super Fish-adware that was installed previously on laptops. According to the manufacturer discovered several vulnerabilities in Superfish, including the installation of a self-signed root certificate.

Consumers can remove Superfish, but Superfish certificate but will remain on the system. Since Superfish according Lenovo SSL traffic intercepted this is a "security concern". Therefore, the manufacturer removal instructions put online, and a list of vulnerable laptops. These laptops in E, Flex, G, M, S, U, Y Yoga and Z-series that are delivered between September 2014 and February 2015. Together account for more than 40 models.

Customers who leave running the certificate in certain scenarios, for example when an open Wi-Fi network, the risk of being attacked by a man-in-the-Middle. Users will also be advised to remove the certificate. Furthermore Superfish would be asked to turn off all server activity of the software. Via Twitter Lenovo announces that it is busy working to rectify the problem and regain the trust of customers.

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University now has a warning issued for the certificate and advises users to delete it. There are EFF by the American civil rights movement removal instructions put online, including for Firefox users.