• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Archives for June 2012

Password (In)security, Revisited

  • Posted on:June 19, 2012 at 11:25 am
  • Posted in:Bad Sites
  • Author:
    Jonathan Leopando (Technical Communications)
1

The month of June is turning into a very bad month for password security. Last week three major sites – Linkedin, eHarmony, and last.fm – all suffered from major leaks that put millions of user passwords online. Earlier this week, it was revealed that the game League of Legends has also suffered its own flaw…

Read More

Evolved Banking Fraud Malware: Automatic Transfer Systems

  • Posted on:June 18, 2012 at 9:41 am
  • Posted in:Malware
  • Author:
    Loucif Kharouni (Senior Threat Researcher)
0

Banks and other financial institutions have put in stricter controls in an attempt to minimize losses that phishing attacks cause. Cybercriminals have not taken this sitting down by producing a new tool to automate online banking fraud — automatic transfer systems (ATSs). In the past, malware families like ZeuS and SpyEye used Webinject files to…

Read More
Tags: ATSAutomatic Transfer SystemSpyEyeZeuS

MySQL Password Verification Bypasses CVE-2012-2122

  • Posted on:June 15, 2012 at 11:54 am
  • Posted in:Exploits, Vulnerabilities
  • Author:
    Pawan Kinger (Director, Deep Security Labs)
0

Recently, security researcher Sergei Golubchik reported a security issue in MySQL in which an attacker could log in to a MySQL database using literally any password. With this entry, I would like to take some time to explain the issue to our customers. The problem is serious in affected systems – but the exposure surface…

Read More
Tags: CVE-2012-2122ExploitLinuxMicrosoftmysqlVulnerabilities

An Aggressive Turn of Tactics Used in Black Hole Exploit Kit Spam Runs

  • Posted on:June 14, 2012 at 10:11 am
  • Posted in:Bad Sites, Exploits, Malware, Spam
  • Author:
    Sandra Cheng (Product Manager) and Jon Oliver (Senior Architecture Director)
0

We’ve been tracking and informing customers about current Black Hole Exploit Kit Spam Run activity and noted that spammers have been changing their methods to better achieve their goals. The most recent development is the aggressive turn in tactics used in these spam runs, which makes it easier for infection to occur. With the latest…

Read More

Trend Micro Protects Users Against Active Exploits on Latest Internet Explorer Vulnerabilities

  • Posted on:June 13, 2012 at 1:16 pm
  • Posted in:Malware, Vulnerabilities
  • Author:
    Pavithra Hanchagaiah (Senior Security Researcher)
0

Apart from the regular monthly patch release Microsoft issued yesterday, which included a patch for relatively large number of vulnerabilities in Internet Explorer (MS12-037), Microsoft also reported another IE vulnerability that has no patch available yet. MS Security Advisory (2719615) specifically identifies the Microsoft XML (MSXML) Core Services as the vulnerable part. MSXML provides a…

Read More
Tags: advisorycve-2012-1875cve-2012-1889deep securityIDFIEInternet Explorerms advisory 2719615ms12-037MSXML
Page 2 of 4 ‹ 123 › »

Security Predictions for 2019

  • Our security predictions for 2019 are based on our experts’ analysis of the progress of current and emerging technologies, user behavior, and market trends, and their impact on the threat landscape. We have categorized them according to the main areas that are likely to be affected, given the sprawling nature of the technological and sociopolitical changes under consideration.
    Read our security predictions for 2019.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Popular Posts

  • Mac Backdoor Linked to Lazarus Targets Korean Users
  • New Magecart Attack Delivered Through Compromised Advertising Supply Chain
  • Microsoft November 2019 Patch Tuesday Reveals 74 Patches Before Major Windows Update
  • September Patch Tuesday Bears More Remote Desktop Vulnerability Fixes and Two Zero-Days
  • Magecart Skimming Attack Targets Mobile Users of Hotel Chain Booking Websites

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.