AntiSpyCheck Removal

This is a new infection that is running rampant among the many security forums.  The problem is that if you do a search for how to remove it on the search engines, most of the responses are for sites trying to scam you.  If you become infected with AntiSpyCheck I suggest you try this guide [...]

HSBC sites vulnerable to XSS flaws, could aid phishing attacks

What would the perfect phishing attack from a social engineering perspective? The one that compared to using typosquatted domains impersonating the bank’s web application directory structure is in fact using the bank’s legitimate domain names as redirectors due to XSS flaws within. It’s even more interesting to measure the average time it takes for a [...]

Internet Explorer ‘feature’ causing drive-by malware attacks

My colleague at Kaspersky Lab Roel Schouwenberg (see disclosure) has discovered a drive-by malware download taking advantage of what Microsoft describes as an Internet Explorer “feature” to launch cross-site scripting attacks.
The attack, discovered at a compromised legitimate site, is using a modified GIF file to exploit the cross-site scripting feature/vulnerability. [Read More...]
Source: Zdnet

Critical security alert issued for Tor

If you use Tor for anonymity/privacy on the Web, you might want to pay attention to this critical security announcement from project leader Roger Dingledine.
According to the advisory, a known vulnerability in the Debian GNU/Linux distribution’s OpenSSL package could allow an attacker to figure out private keys generated by these buggy versions of the OpenSSL [...]