Brian Prince

U.K. Police Bust 19 for $9.5M Online Banking Heist

Scotland Yard has arrested 19 people in connection with a cyber-crime ring accused of stealing millions from bank accounts in Europe. Officers from the MPS (Metropolitan Police Services) Police Central e-Crime Unit arrested 15 men and four women in predawn raids Sept. 28 in London. They group is believed to be behind the theft of […]

Web 2.0 Security Losses Total $1.1 Billion, Survey Finds

A survey of more than 1,000 global business decision-makers in 17 countries found more than half were concerned about the security of the Web 2.0 technologies their organizations used, and rightly so. According to the report, six out of 10 organizations suffered large losses averaging $2 million each because of security incidents during the past […]

California Outlaws Online Impersonation Meant to Cause Harm

California Gov. Arnold Schwarzenegger signed legislation Monday that makes it illegal to impersonate someone online with intent to harm, intimidate, threaten or defraud. Senate Bill 1411 passed the legislature unanimously. Under the legislation, “Any person who knowingly and without consent credibly impersonates another actual person through or on an Internet Web site or by other […]

Zeus Malware Purveyors Target Symbian, BlackBerry Devices

Online bank fraudsters are now targeting mobile devices in an attempt to bypass two-factor authentication practices popular among banks in Europe. According to Fortinet, cyber-crooks are using mobile spyware in conjunction with the Zeus Trojan to hijack users’ bank accounts. For detection purposes, Fortinet has dubbed the spyware Zitmo. Going mobile is a necessary next […]

Microsoft Releases Emergency ASP.NET Patch to Block Attacks

Microsoft issued an emergency patch Sept. 28 to address a vulnerability in ASP.NET. The fix was pushed out after reports of attacks on the issue began to surface. ASP.NET is used by developers to build Web applications and XML Web services. Demonstrated earlier this month by researchers at the ekoparty Security Conference in Buenos Aires, […]

Obama Administration Internet Wiretap Plans Dredge Up Old Debate

Reports that federal law enforcement and national security officials want to create new regulations to help them intercept electronic communications raised a sense of d??«j??í vu for Cindy Cohn. Cohn, legal director at the Electronic Frontier Foundation, remembers when these same issues arose in the 1990s, a time when the Clinton administration was pushing the […]

Twitter Users Hit by Another Worm

Twitter users were hit with yet another worm during the weekend. This time, the tweets came bearing the message “WTF” with a link in tow. Clicking on the link automatically generated a post from the victim with a pornographic message. “Clicking on the WTF link would take you to a webpage which contained some trivial […]

Microsoft Hotmail Security Enhancements Coming

Microsoft has begun rolling out new security features for Hotmail users today centered around preventing and detecting account compromises. The changes, which Microsoft first discussed with eWEEK in May, will take about a week to roll out to all users, Dan Lewis, senior product manager for Windows Live Hotmail, told eWEEK. Once they arrive, the […]

Twitter, Cyber-security, Microsoft ASP.NET Attacks Lead Security News

A cross-site scripting vulnerability impacted as many as 500,000 Twitter users and led a busy week of security news. The bug was exploited by worms that spread throughout the microblogging service and affected users ranging from the wife of former British Prime Minister Gordon Brown to White House Press Secretary Robert Gibbs. The vulnerability-which Twitter […]

Microsoft Adds to ASP.NET Vulnerability Advisory

Microsoft added information Sept. 24 to the workaround section of the advisory on the ASP.NET vulnerability that has come under attack. The company updated its advisory to include a step in the workaround requiring the blocking of requests that specify the application error path on the querystring. “This can be done using URLScan, a free […]