Since last week, we have seen many specially crafted files exploiting CVE-2012-0158, a vulnerability in MSCOMCTL.OCX in Microsoft Office and some other Microsoft products. This exploit can be implemented in a variety of file formats, including RTF, Word, and Excel files. We have already found crafted RTF and Word files in the wild. In the Read more…
Tags: CVE-2012-0158, exploit, OLE, RTF
On April 16, we found a Pastebin entry selling the latest version of the infamous SpyEye botnet (Version 1.3.48) for a much lower price than we’ve seen elsewhere. (This botnet is mainly used to steal banking information.) The quote was just US$150 including three months hosting, after that it’s $15 per month. This version was Read more…
In my first post on styles of influence, I discussed rationalizing – a style characterized by a logical perspective that does not account for emotional or political considerations. Its utility is limited to circumstances were quantifiable and verifiable metrics dominate the decision-making process. Unfortunately, the analysis of information security risk is handicapped by a lack Read more…
Nitol is a distributed denial of service (DDoS) botnet that seems to be small and not widely known. It mostly operates in China. McAfee Labs recently analyzed a few samples; we offer here the communications protocol and the Trojan’s capabilities. Most of the samples we encountered were not packed and were very easy to reverse Read more…
Your mobile phone may arguably be your new best friend. There are few people, places, or things in our lives today that get as many hours of attention as your mobile phone or is with you as often (and for some of us, that means 24/7). Four out of seven people on the planet have Read more…
Tags: Android, android antivirus, Android security, anti-malware, anti-phishing, anti-spyware, antivirus, Antivirus software, app protection, BlackBerry, computer security, Cybercrime, identity theft, internet security, Mac antivirus, Mac security, malware, McAfee, Mobile, mobile antivirus, mobile security, pc security, phishing, Safe search, safe surfing, scams, site advisor, spam, Symbian, tablet security, Virus protection, web protection, web security
If your PC is bogged down with useless software and your desktop is jammed with icons and documents, then your PC is next to useless as a productivity tool. Even scarier is the increased likelihood that if you have lost track of your files, you could easily have sensitive personal information exposed without your knowledge. Read more…
Tags: anti-malware, anti-phishing, anti-spam, anti-spyware, antivirus, Antivirus software, computer security, Cybercrime, cybercriminals, cybercrooks, firewall, hacking, identity theft, internet security, malware, McAfee, pc security, phishing, Safe search, safe surfing, scams, site advisor, spam, Virus protection, web security
Since March 20, the @Anonw0rmer Twitter account has been silent. Its owner, w0rmer, is known as a member of the CabinCr3w group, a hacker team linked to Anonymous. In early February, as part of the Operations PiggyBank and PigRoast, the CabinCr3w members were suspected of hacking various police department- or law enforcement-related websites including: West Read more…
Tags: Anonymous, Exif, Hacktivism, Open Source
Darkmegi was in the news a couple of months back; it was the first known threat to be delivered through the Microsoft vulnerability CVE-2012-0003 (MIDI Remote Code Execution Vulnerability) exploitation. More recently Darkmegi has been seen in CVE-2011-3544 (Java Runtime Remote Code Execution) drive-by attacks as part of the Gong Da Pack exploit kit. Darkmegi uses Read more…
Tags: Deep Defender, DeepSAFE, rootkit, Stealth
Last month, one of the biggest names in digital and mobile commerce, Global Payments, confirmed a significant security breach affecting 1.5 million credit card holders. Within days, Visa dropped the company from its list of PCI compliant providers. From large enterprises to small online retailers, compliance with the PCI Data Security Standard (PCI DSS) is Read more…
Tags: Global Payments, McAfee SECURE, PCI, PCI DSS
Having just closed my first quarter as the global channels leader at McAfee, I couldn’t be more optimistic about the opportunities for mutual growth in the security market. Now is the ideal time to become a McAfee channel partner. The momentum we are building together already encourages me, especially when you consider our recent industry Read more…
Tags: 2012 Virtual Sales Kickoff, Channel Partner Town Hall, Channel Partners, Channel Program, Channels Town Hall, cloud, Continuing Education, Gavin Struthers, McAfee Partner, McAfee Partner Learning Center, McAfee Partner Program, SMB, SMB Extravaganza, Virtual Sales Kickoff 2012