Showing posts with label Thought of the Day. Show all posts
Showing posts with label Thought of the Day. Show all posts

Wednesday, 23 September 2015

Forbes.com Spread Malware Via Infected Adverts


On the very popular website of business magazine Forbes have been infected for some time ads shown to infect visitors with malware tried. Forbes.com state according to market researcher Alexa on the 74th spot of most visited websites in the United States and the 154th place worldwide.

The website is monthly by more than 31 million visited visitors. Those visitors were from 8 to 15 September dished ads so they were undetected to a website with the Angler- and Neutrino-exploit kits. This exploit kits exploit known vulnerabilities include Adobe Flash Player. In case there is no up-to-date software was used silently malware could be installed on the computer, says security firm FireEye.

For what exactly will the malware was not disclosed. The ads were via an advertising service from a third party displayed on the Forbes website. According FireEye use of contaminated advertising remains a popular attack method for criminals.Via advertising platforms, especially those that hold real-time auctions for ad space, attackers can choose exactly where their malicious content is displayed.

In case the infected appear ads on popular websites the chance of massive infection is significantly increased, allowing both users and businesses at risk, according to the security company. After being informed Forbes has removed the infected ads. Last year, even though malware via Forbes.com spread. When attackers used a widget on the website that zero-day vulnerabilities in Internet Explorer and Adobe Flash Player attacked.

Thursday, 12 February 2015

Flash And Unpatched IE Vulnerabilities Used On Forbes.com

Visitors to the popular business magazine Forbes late November attacked via vulnerabilities in Adobe Flash Player and Internet Explorer, which at the time of the attack still no updates were available.According to security iSight Partners and Invincea involved a highly targeted attack.

The attack would be directed cons American defense companies and financial institutions, whose staff Forbes.com visit regularly. The website is according to Alexa on the 68th spot of most visited websites in the US Possible are also other parties and organizations affected by the attack, but it is not yet clear. The same is true for the attack period. Which would have taken place on 28 November to 1 December, but a longer period is not excluded. Besides Forbes would have used several obscure websites for the attack.

The attack took place through the "Thought of the Day" (totd) Adobe Flash widget that appears when someone visits a page or Forbes article. Then, use was made of a zero-day vulnerability in Adobe Flash Player, which eventually on December 9 by Adobe was patched. The attack was combined with a vulnerability in Internet Explorer to bypass the ASLR protection measure in the browser. Bypassing the security measure yesterday evening remedied by Microsoft. How many computers are infected by the attack have both security companies do not know.