Ryan Naraine

Microsoft Says Recovery from Malware Becoming Impossible

LAKE BUENA VISTA, Fla.—In a rare discussion about the severity of the Windows malware scourge, a Microsoft security official said businesses should consider investing in an automated process to wipe hard drives and reinstall operating systems as a practical way to recover from malware infestation. “When you are dealing with rootkits and some advanced spyware […]

Eolas: Changing IE User Experience a Shame

Eolas Technologies says the decision by Microsoft to modify its Internet Explorer browser at the expense of a seamless user experience is a “disappointment” and a “shame.” Reacting to news that the next cumulative IE security update will require an extra mouse-click to interact with certain embedded multimedia content, Eolas Chief Operating Officer Mark Swords […]

Hackers Use BBC News as IE Attack Lure

The ongoing zero-day attacks against users of Microsofts Internet Explorer browser have taken an ominous, social-engineering twist. According to an alert issued by Websense Security Labs, in San Diego, excerpts from actual BBC News stories are being used to lure IE users to Web sites that launch drive-by downloads of bots, spyware, back doors and […]

Hackers Serve Rootkits with Bagles

Malicious hackers have fitted rootkit features into the newest mutants of the Bagle worm, adding a stealthy new danger to an already virulent threat. According to virus hunters at F-Secure, of Helsinki, Finland, the latest Bagle.GE variant loads a kernel-mode driver to hide the processes and registry keys of itself and other Bagle-related malware from […]

Déjà Vu as Third Parties Ship IE Patches

Two well-respected Internet security companies have shipped unofficial patches for a critical flaw in Microsofts Internet Explorer browser a full two weeks before the software makers scheduled release of a comprehensive update. With a wave of zero day attacks underway, eEye Digital Security and Determina offered separate hotfixes to provide temporary protection for IE users, […]

Microsoft Delays IEs ActiveX D-Day

Microsoft is moving full steam ahead with a plan to permanently modify the way Internet Explorer renders multimedia content on Web pages, but in what amounts to an admission that the changes could be disruptive, the software maker plans to give Web developers an extra 60 days to continue making preparations. The IE update, which […]

Drive-By IE Attacks Subside; Threat Remains

The wave of zero-day attacks against a gaping hole in Microsofts Internet Explorer browser appears to have subsided, but in the absence of a patch, security experts warn that the risk remains significant. During the weekend of March 25-26, malware hunters discovered more than 200 unique URLs using the unpatched IE flaw to launch drive-by […]

Check Point Aborts Sourcefire Acquisition

Facing intense pressure from U.S. government investigators, Israeli security company Check Point Software Technologies has aborted its acquisition of Sourcefire. Less than six months after announcing plans to shell out $225 in cash and stock to purchase Sourcefire, Check Point pulled out of the deal, citing “lengthy ongoing delays” in a U.S. government investigation and […]

IE Under Attack: Microsoft Ponders Emergency Patch

Malicious hackers are using hijacked Web servers and compromised sites to launch a wave of zero-day attacks against an unpatched flaw in Microsofts Internet Explorer browser. The first wave of drive-by downloads was spotted on March 25, and security experts tracking the attack say the threat is growing at a rate of 10 new malicious […]

Do-It-Yourself Spyware Kit Sells for $20

A do-it-yourself malware creation kit is being hawked on a Russian Web site for less than $20, according to security researchers tracking the seedier side of the Internet. Virus hunters at SophosLabs discovered the spyware kit, called WebAttacker, on a Web site run by self-professed spyware and adware developers. The kit is available for sale […]