Feeds & Podcasts

Enterprise Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

McAfee Labs

Get cutting-edge security as it happens. McAfee Labs Blog delivers the latest research, analysis and insights into the evolving threat landscape, powered by comprehensive, real-time Global Threat Intelligence and a dedicated team of multidisciplinary researchers. Read our experts’ tips and techniques to help you avoid and defeat the latest malware trends, and view portions of the actual research to stay even more informed.

Posts in McAfee Labs

Networked Printers at Risk

Friday, December 30, 2011 at 10:10am by Jimmy Shah
Jimmy Shah

Multifunction printers (MFPs) have been common in offices for years. They let employees print, scan, and copy documents. Two separate talks at the 28th Chaos Communications Congress (28c3) show how attackers can infect these trusted office devices. Hacking MFPs In Andrei Costin’s presentation “Hacking MFPs,” he covered the history of printer and copier hacks from the Read more…

Tags: , , ,

Fighting Mobile Phone Impersonation and Surveillance

Wednesday, December 28, 2011 at 9:56am by Jimmy Shah
Jimmy Shah

Yesterday at the 28th Chaos Communications Congress (28C3), in Berlin, security researchers along with Karsten Nohl and Luca Melette showcased a number of flaws and solutions in GSM mobile phone networks. Day 1 Defeating GSM encryption is not new. Nohl and Melette detailed how attackers can use known network control messages to help decrypt SMS Read more…

Tags: , ,

Zeus Spam Changes Tactics

Saturday, December 17, 2011 at 12:52pm by Eric Peterson
Eric Peterson

McAfee Labs Messaging Security recently observed a new malicious spam campaign pushing password-stealing Trojans associated with the Zeus/Zbot family. This campaign leverages several notable social engineering techniques. For admins and netizens familiar with contemporary email-borne threats, a message purporting an undeliverable DHL, FedEx, or USPS package triggers an immediate red flag. Though still prevalent, those Read more…

Tags: , , , , , ,

Inside Adobe Reader Zero-Day Exploit CVE 2011-2462

Wednesday, December 14, 2011 at 12:26pm by Chintan Shah
Chintan Shah

Recently a critical vulnerability has been identified in Adobe Reader X and Adobe Acrobat X Versions 10.1.1 and earlier for Windows and Mac OS, Reader 9.4.6 and Reader 9.x Versions for Unix. This zero-day vulnerability (CVE-2011-2462) could allow an attacker to execute arbitrary code and silently take the control of a victim’s machine. This flaw is currently Read more…

Tags: , , ,

‘Hacktivity 2011′ Keynote Examines 25 Years of Malware

Friday, December 9, 2011 at 9:10am by Peter Szor
Peter Szor

In September, I had the pleasure of giving the keynote speech at “Hacktivity 2011″ in Budapest, Hungary. I was very excited to see the large audience, about 1,000 visitors, among them very serious and well-known security professionals, instructors, and security enthusiasts. It was also exciting for me because I made the presentation in my native Read more…

Tags: , , , , , , , ,

ZeroAccess Rootkit Launched by Signed Installers

Monday, November 21, 2011 at 12:19pm by Peter Szor and Kevin Beets
Peter Szor

Digital certificates and certificate authorities have been much in the news recently. Attacks–such as those used by Stuxnet, Duqu, and other malware–involving stolen certificates show an increasingly worrisome new security trend. Certificate authorities have been targeted several times in the recent past with some success. There is a large chunk of known malware signed by Read more…

Tags: , , , , , , ,

Is This SCADA Hacking Friday?

Friday, November 18, 2011 at 10:49am by David Marcus
David Marcus

Today’s infosec news focuses on several possible incidents of penetrations at water utility companies. Elinor Mills at C|Net posted a story on a potential compromise last week at a Springfield, Ill., water company that may have resulted in physical damage. Meanwhile Gareth Halfacree at thinq has a writeup on a potential South Houston water supply Read more…

Tags: , , , , , ,

Security 101: Attack Vectors, Part 1

Tuesday, November 15, 2011 at 4:21pm by Francisca Moreno
Francisca Moreno

In the first part of this series, we discussed the entry points that an intruder could use to attack our “building,” our metaphor for network security. In the next few posts, we shall focus on the next level: attack vectors. If vulnerabilities are the entry points, then attack vectors are the ways attackers can launch Read more…

Tags: , , ,

Combating Distributed Denial of Service Attacks in Brazil, Latin America, and Everywhere Else

Thursday, November 3, 2011 at 4:34pm by David Marcus
David Marcus

One of the most disruptive attacks to deal with in today’s threat landscape is the distributed denial of service attack, often called DDoS. Using the resources of many other computers, an attacker can focus a vast amount of packets and power at a single resource and effectively knock it offline for as long a time Read more…

Tags: , , , , ,

French Magazine Suffers Web Hack, Firebombing

Wednesday, November 2, 2011 at 10:28am by Francois Paget
Francois Paget

To celebrate the recent victory of the Tunisian Islamist party, the French satirical magazine “Charlie Hebdo” published a special issue in which it named the prophet Muhammad (also spelled Mohammad) as its editor-in-chief. Late night, the magazine’s offices in Paris were destroyed by a Molotov cocktail attack. The entire French political establishment has condemned this Read more…

Tags: ,