Monday, 5 October 2015

Interpol And Europol Launch Task Force Against Cyber Crime


Interpol and Europol will together launch a task force to improve the international fight against cyber crime and where law enforcement agencies from other countries can join. There will also be an alliance against abuse of digital currency to be set up by criminals.

These are two of the results of the Europol INTERPOL Cyber Crime Conference, which took place last week in The Hague.The Joint Cooperation & Compatibility Cyber Crime Taskforce Europol and Interpol will create a compatibility list to harmonize the different legal systems and codes for data requests. This should improve cooperation between different law enforcement agencies.

There will also be an alliance against abuse of digital currency for criminal transactions and money laundering. Particular attention was focused on policy, boosting operational cooperation and developing and providing training to combat the criminal use of digital currency. For example, law enforcement agencies empowered to detect digital currency of criminals, seize and confiscate.

Amount Of Mac Malware Is Still Very Limited


All years warn anti-virus companies for Mac malware, but the number of copies that attacks Apple users is still very limited. According to a survey from security company Webroot. Every year appear as two new threats for the Mac.

Often these Trojans posing as an application but in fact malware. The most successful Mac malware was hitherto Flashback, which first appeared in 2011 and in 2012, infecting some 700,000 Macs knew. In recent years, such large infections failed to materialize and in 2015, according to Webroot's still not a big threat appeared for the Mac. According to some experts, adware also the biggest threat for Mac users.

Despite the small number of copies Webroot provides in its own overview Mac malware according to the security firm is indeed a serious threat that will only get bigger. "Even after mentioning all these malware will be people who refuse to believe that their Mac is vulnerable to attack, but trust me. It will now only get worse. Apple increases its market share and thus come opportunities for malware authors to make money, "said analyst Devin Byrd.

According to some experts, is the threat especially in user behavior. Macs could become infected mainly because software users outside the site of the supplier or downloading illegal software use. Recently left the Austrian test lab for anti-virus programs AV-Comparatives know which experienced Mac users also can do without virus.

Encryption Advice To Journalists After TrueCrypt Leak


Recently discovered a researcher at Google two vulnerabilities in the popular encryption program TrueCrypt will not be stopped, but journalists still have options to encrypt their data. This enables the US Committee to Protect Journalists (CPJ).

The organization works worldwide for press freedom. Last year showed the CPJ that journalists TrueCrypt still safe could use, even though the support stop put by the developers. However, journalists were advised in the medium term, software switch. Programs were not mentioned however. Because of the two leak found, the CPJ expressed themselves on how to use TrueCrypt.

According to Geoffrey King, who through the organization dedicated to the digital rights of journalists, now revealed the vulnerabilities could be used by someone who already has a user account on the computer. The first vulnerability is dangerous because someone with a limited user account can gain full administrative rights. The second vulnerability allows an unauthorized user to disconnect an active use TrueCrypt volume. To use either leak must be able to log into an attacker's computer. In addition, it is not possible to decrypt the information via vulnerabilities.

In the on TrueCrypt-based Vera Crypt Two problems have been resolved. The CPJ has not evaluated the safety and reliability of this program. In addition, according King, no solution without risk. He advises journalists to always encrypt their data as unencrypted data is one of the greatest risks. The CPJ recommends therefore to use encryption software that comes with the operating system. In the case of Mac OS X is that FileVault 2, while BitLocker for Windows and Linux LUKS is recommended. Further, a complex and to remember passphrase must be used for the encryption.

McAfee Receives Award For Research Into Botnet


Anti-virus company McAfee has at the Virus Bulletin conference in Prague received an award for research into a botnet which was in collaboration with the Dutch police shut. The botnet, which Beebone, VObfus or AAEH was called, was a polymorphic botnet.


The malware that caused computers part of the botnet had been active since 2009 and spread via infected USB sticks and social engineering. In early April of this year, the botnet was the High Tech Crime Team (THTC) of the Dutch police, the FBI, Europol and security Intel Security, Kaspersky Lab and Shadow Server taken off the air.

To disable the botnet domains were all registered and seized that used the malware to communicate with infected computers. Then the investigating authorities showed these areas to the servers of Internet providers and computer emergency response teams (CERTs) by pointing all over the world, a process also known as "sink holes" is mentioned.Research showed that the malware had infected 12 000 computers.

According to McAfee cooperation between law enforcement agencies and security companies was essential to make the botnet from the air. The anti-virus company wrote a technical report (pdf) on the malware and operation of the botnet.Previously received McAfee last week at the Virus Bulletin conference Peter Szor Award. An annual prize for the best security research named after the anti-virus pioneer deceased in 2013.

Szor began twenty years ago with the analysis of malware and in 2005 wrote the book "The Art of Computer Virus Research and Defense. He worked for Symantec and F-Secure, before he went to work in 2011 at McAfee. In 2013 died he unexpectedly. "This kind of research makes everyone safer, as did the survey conducted late Peter Szor," said Martijn Grooten of Virus Bulletin.

Sunday, 4 October 2015

GitHub Introduces Logging Via USB Key


The popular online platform for developers GitHub has a new method added to allow users to login securely and advises developers to also to add their own software to the login method. It is the Universal 2nd Factor (U2F) standard of FIDO Alliance.

It is an authentication standard that during the next logon password also checks the presence of a U2F USB key. This hardware key acts as a second security factor. The key works only on the real website of GitHub, which as phishing and man-in-the-middle attacks must be prevented. U2F standard supports several platforms and browsers and requires no installation of drivers or software.

There are several manufacturers that offer U2F USB keys, which can all be used, but GitHub has launched an action with Yubico, provider of the YubiKey. Before developers on GitHub can log in via the USB key they need to be first through their account register. Last year, decided Google already U2F in to Google Accounts and set in August did Dropbox so. U2F as said from the FIDO Alliance, an alliance of IT companies like Microsoft, ING, Google and Intel, who want an end to the password and therefore working on alternative solutions.

Android Version Firefox Receives Click-To-Play For Images



To save bandwidth and ensuring that websites load faster Mozilla has released an early test version of Firefox 44 for Android added click-to-play for images. Click-to-play is a mechanism that the browser is now used to activate browser plug-ins.

A user in this case will have to make an extra click before a Web browser plug-in can call. This should prevent users automatically via vulnerable browser plug-ins can be attacked because the user still needs to activate the plug-in. Click-to-play for images but works slightly different and mainly saving data traffic and faster loading websites as the reason. In case an image for a larger view links provides a single tap on the screen that the bigger picture is loaded.

A long tap on the image displays the context menu in which the user can then choose to display the image. The option currently applies to separate images. A user will be on a site with multiple images therefore have to tap several times before the images are displayed on the page, says Soren Hentzschel who discovered the feature. Click-to-play for images present in the Nightly version of Firefox 44 and must itself be activated by users.

Saturday, 3 October 2015

New Malware Works Only On Windows XP



Microsoft may no longer support Windows XP, which does not apply to cyber criminals. It has indeed discovered a new variant of the Upatre malware that works only on the 13-year-old operating system.The malware spreads via email attachments that appear to come from a lawyer.

Once opened, the malware attempts to infect the system, says security firm AppRiver. Remarkably, the malware is that it worked only on Windows XP. On newer machines, the malware stopped once it was implemented. However, it does not seem that this was done deliberately. Also on Windows XP proved malware specimens to crash after some time. Analyst Fred Touchette therefore expected that malware authors will resolve the problem quickly.

Kaspersky Wins Test Malware Removal



Anti-virus software must be able to not only detect malware, including the removal of an infection is part of a good working virus scanner. The Austrian test lab AV-Comparatives therefore decided to test 16 security packages to consumers on malware removal.

In total, were used for the test 35 different malware instances that had to remove the packages. These criteria include being sought for leave of executable files, MBR or registry changes, custom host files and programs that were disabled by the malware and after disinfection is still not working, like Windows Task Manager and the Windows Registry Editor.

The packages were evaluated for the simplicity with which the malware was removed, like removing normal mode, safe mode, using a rescue disk or calling the help desk to remedy the infection. Eventually, the virus could score up to 100 points. Kaspersky Lab sets with 93 points, the highest score down just before Avast (89) and Bitdefender (89). Sophos (72) and Threat Track Viper (65) put the lowest score down. Microsoft Windows Defender ends up with 80 points in the middle.

FBI Gives Five Tips For Safe Surfing


October, both in Europe and in the United States dedicated to safe internet and as part of this initiative, the FBI gave five security tips. Through the National Cyber ​​Security Awareness Month attempt by the US authorities to raise awareness of users.

This is to protect the country against cyber incidents and responding appropriately to enable them could occur. The FBI says that it invests a lot in tracking down cyber criminals and protect networks, but that cyber security is a task for everyone. "Every American who used home or office digital technologies must play a role in cyber security," according to the investigation department. To help people on their way, the FBI five tips compiled:

  1. Set strong passwords and don’t share them with anyone.
  2. Keep a clean machine—your operating system, browser, and other critical software are optimized by installing regular updates.
  3. Maintain an open dialogue with your family, friends, and community about Internet safety.
  4. Limit the amount of personal information you post online and use privacy settings to avoid sharing information widely.
  5. Be cautious about what you receive or read online—if it sounds too good to be true, it probably is.

Friday, 2 October 2015

Avast Close Criticism SSL Vulnerability In Anti-Virus Software



The Czech anti-virus company Avast has a critical vulnerability in the anti-virus software patched it was discovered by a researcher from Google and which allowed an attacker to execute arbitrary code by users. The problem arose in Web Shield, part of the anti-virus software.

The virus Avast scans the contents of this web traffic. To be able to check via HTTPS encrypted traffic install the anti-virus software an own root certificate. A controversial practice that was also used by the Super Fish-adware. The way Avast this had been implemented made ​​it possible for websites to execute arbitrary code on the system remotely via a specially crafted SSL certificate.

The vulnerability was discovered by Google researcher Tavis Ormandy, who also significant problems in the anti-virus software from Sophos, ESET and Kaspersky Lab discovered. Ormandy warned Avast on September 25 and yesterday evening the virus fighter rolled an update for the problem. The researcher shows via Twitter, however, know that there are still more arrive.

Date 15 Million Customers T-Mobile USA Stolen From Experian


Attackers have managed to break in Experian at data processor and credit bureau and got the data of 15 million customers of the US branch of T-Mobile stolen. Experian will check for T-Mobile or its customers or creditworthy. At burglary name, address, date of birth and encrypted social security numbers and ID numbers, such as driver's license or passport, stolen.

Research from Experian shows that the encryption may be compromised. The stolen data comes from customers who between September 1, 2013 and September 16, 2015 an application for credit is made, as T-Mobile CEO John Legere an open letter to let you know. Experian states that on September 15, discovered the break-in on a company server. Doing so would have no payment information or other banking information stolen.

According to the data processor, the attackers had limited time access to the data, but how long is not said. It is also not clear how the attackers were able to gain access to the server. Affected customers can due to the incident two years at no cost to monitor their credit. In the open letter to customers said Legere to be very angry with Experian and will evaluate the cooperation with the company.

Helpful Malware Infected And Secure Routers



Researchers have developed a kind of "helpful" discovered malware that infects Internet routers and IoT devices, and then secure the devices and to remove any existing malware. The malware by security firm Symantec Wifatch called and last year was already discovered by another researcher, who gave the name ifwatch gave.

The malware spreads probably via Telnet and uses weak passwords. Once active, the routers and other devices part of a peer-to-peer network to exchange threat information. Furthermore Wifatch disable the Telnet daemon, so that other attackers can not gain access. The malware also leave a message for the owner behind to change the password, disable Telnet and update the firmware. Wifatch also has a module to remove malware infections on the unit.


Despite the actions that Symantec designates Wifatch executes the program so as malware, partly because it contains a number of general backdoors that the creator can access. The backdoors do require a digital signature, so others can not use.Symantec may be tens of thousands of devices with malware infected, most of them in China and Brazil. Owners of an infected router to remove Wifatch can easily do this by resetting the device.