Google Search

Showing posts with label emails. Show all posts
Showing posts with label emails. Show all posts

Monday, November 26, 2012

Warning: Here are three emails you don't want to see in your inbox

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Here are three emails you don't want to see in your inbox today.

Malicious email

Malicious email

Malicious email

Although the emails may claim to have been sent by the likes of LinkedIn, YouTube and Google the truth is that the headers are forged, and the emails have been specially crafted to look like legitimate communications from online firms.

Clicking on the links could send your computer to Canadian pharmacy-like spam sites offering to sell you Viagra, or even webpages hosting malicious payloads.

Always be careful about clicking on links in unsolicited emails. Hover over links with your mouse to tell where it's really going to before clicking, and keep your anti-virus and anti-spam protection updated.

If you're careless you could be falling into the spammers' trap, and putting your finances and data in danger.

(Oh, and we've just seen emails claiming to come from Amazon too).

http://twitter.com/gcluley

View the original article here

Thursday, August 2, 2012

Yahoo Voices hacked, nearly half a million emails and passwords stolen

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Yahoo logoYesterday, we reported on the Formspring website hack. Today, it's Yahoo Voices that has been compromised.

Yahoo Voices, which defines itself as "where your expertise and perspectives take center stage!", allows Yahoo users to post their own articles, videos and slideshows online.

This morning, hacker group D33DS Company, published the 453,491 email addresses and passwords online in plain text, in a document marked "Owned and Exposed".

Owned and exposed

The hackers say they used a "Union-based SQL Injection" to steal the data and posted the information as a "wake-up call"

We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat.

But even if this hacker group themselves aren't planning to use the information for ill-gotten gains, the data is available for anyone to access.

The only silver lining on the cloud is that the website hosting the passwords is temperamental, and people are experiencing difficulties accessing the information. But maybe the access problems are being caused by so many people trying to access the stolen passwords at once?

D33Ds email addresses

Unfortunately, the list of compromised websites just seems to keep growing. In a little over a month, we've reported on breaches of Formspring, Last.fm, LinkedIn and eHarmony.

If you use Yahoo Voices, you should probably change your password now.

Don't forget to make sure that your password is unique, hard to guess, and that you use a different password on every website you use. If you use the same password in multiple places you are just asking for trouble.

At the time of writing, there is no official word from Yahoo regarding the security breach.

There are certainly questions which need to be answered - such as how were the hackers able to gain access to the information, and what measures was the site taking to ensure that even if its databases were breached, the passwords would not be easy to convert into plain text.

If your company runs a website which stores users' information, don't feel too smug about Yahoo's misfortune. Are you taking enough care of your visitors' credentials and ensuring that they are properly secured?

Follow @NakedSecurity

View the original article here

Friday, July 20, 2012

You pig! Malware-laced emails spammed out posing as incriminating photos

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A widespread malware attack has been spammed out, posing as incriminating photos of the recipient which could get them in trouble with their partner.

The emails, which have the subject line "You pig!", are designed to infect Windows users and carry a malware attachment posing as a digital photograph.

Malicious email

Subject: You pig!

Message body:
You should be stoping ignoring me or i will send this photos to your spouse!!!

Attached file: DCIM.zip

The emails can claim to come from a variety of different places, including LinkedIn, UPS and Hotmail.

Although the malware-laden emails are poorly spelt, it wouldn't be a surprise at all to hear that many people would be tricked by the aggressive tone to open the attachment. Unfortunately, the contents of the ZIP file are designed to infect Windows computers with a Trojan horse.

The subject line "You pig!" is certainly enough to make many people stop in their tracks, and wonder what has just arrived in their inbox.

SPAM®It strikes me that even those who rightly suspect the email is spam, might be bemused enough (considering the main ingredient of what Hormel Foods nearly called flappertanknibbles) to open the messages and explore further.

Sophos detects the malware inside the ZIP files as Troj/Agent-WXL and the ZIP files themselves as Troj/BredoZp-KP. If you are a user of a product from other vendors check that your software is up-to-date and intercepting the malware.

http://twitter.com/gcluley

View the original article here

Wednesday, January 4, 2012

Hackers target emails of UK's Gordon Brown - report - Reuters India

Former British Prime Minister Gordon Brown delivers his speech during the opening session of the Global Progress Foundation Conference in Madrid October 18, 2011. REUTERS/Sergio Perez/Files

Former British Prime Minister Gordon Brown delivers his speech during the opening session of the Global Progress Foundation Conference in Madrid October 18, 2011.

Credit: Reuters/Sergio Perez/Files

LONDON | Mon Jan 2, 2012 5:25pm IST

LONDON (Reuters) - British police have found evidence that private investigators working for newspapers hacked into the email account of former Prime Minister Gordon Brown while he was finance minister, The Independent newspaper reported on Monday.

Hundreds of other people may have also had their emails intercepted, perhaps as many as were caught up in the phone hacking scandal at News International's now defunct News of the World tabloid, the paper said.

Detectives were looking at evidence from about 20 computers seized from private investigators, the newspaper reported.

The team at London's Scotland Yard police headquarters were looking into the possibility that several newspaper titles commissioned private detectives to access computers, The Independent said, citing an unnamed source.

The Brown emails under scrutiny dated from the time he was Britain's finance minister before he became prime minister in 2007. Former Labour advisor and lobbyist Derek Draper was also targeted, The Independent said.

The Metropolitan police would not comment on the report.

"We are not prepared to give a running commentary on this investigation," a spokesman said.

News International, the British newspaper arm of Rupert Murdoch's News Corporation (NWSA.O), also declined to comment.

The group closed the News of the World in July 2011 after evidence emerged that investigators working for the title hacked into the mobile phone voicemails of celebrities, politicians and even murder victims.

It is the only newspaper that has admitted phone hacking, although some journalists and celebrities have said the practice was widespread in the tabloid press.

News International's titles were not singled out in the Independent's report on email hacking.

(Reporting by Paul Sandle; Editing by Andrew Heavens)


View the original article here

Tuesday, January 3, 2012

Hackers target emails of UK's Gordon Brown: report

LONDON (Reuters) - British police have found evidence that private investigators working for newspapers hacked into the email account of former Prime Minister Gordon Brown while he was finance minister, The Independent newspaper reported on Monday.

Hundreds of other people may have also had their emails intercepted, perhaps as many as were caught up in the phone hacking scandal at News International's now defunct News of the World tabloid, the paper said.

Detectives were looking at evidence from about 20 computers seized from private investigators, the newspaper reported.

The team at London's Scotland Yard police headquarters were looking into the possibility that several newspaper titles commissioned private detectives to access computers, The Independent said, citing an unnamed source.

The Brown emails under scrutiny dated from the time he was Britain's finance minister before he became prime minister in 2007. Former Labour advisor and lobbyist Derek Draper was also targeted, The Independent said.

The Metropolitan police would not comment on the report.

"We are not prepared to give a running commentary on this investigation," a spokesman said.

News International, the British newspaper arm of Rupert Murdoch's News Corporation, also declined to comment.

The group closed the News of the World in July 2011 after evidence emerged that investigators working for the title hacked into the mobile phone voicemails of celebrities, politicians and even murder victims.

It is the only newspaper that has admitted phone hacking, although some journalists and celebrities have said the practice was widespread in the tabloid press.

News International's titles were not singled out in the Independent's report on email hacking.

(Reporting by Paul Sandle; Editing by Andrew Heavens)


View the original article here

Monday, January 2, 2012

Hackers target emails of Gordon Brown - report

LONDON (Reuters) - Police have found evidence that private investigators working for newspapers hacked into the email account of former Prime Minister Gordon Brown while he was finance minister, The Independent newspaper reported on Monday.

Hundreds of other people may have also had their emails intercepted, perhaps as many as were caught up in the phone hacking scandal at News International's now defunct News of the World tabloid, the paper said.

Detectives were looking at evidence from about 20 computers seized from private investigators, the newspaper reported.

The team at London's Scotland Yard police headquarters were looking into the possibility that several newspaper titles commissioned private detectives to access computers, The Independent said, citing an unnamed source.

The Brown emails under scrutiny dated from the time he was finance minister before he became prime minister in 2007. Former Labour advisor and lobbyist Derek Draper was also targeted, The Independent said.

The Metropolitan police would not comment on the report.

"We are not prepared to give a running commentary on this investigation," a spokesman said.

News International, the British newspaper arm of Rupert Murdoch's News Corporation, also declined to comment.

The group closed the News of the World in July 2011 after evidence emerged that investigators working for the title hacked into the mobile phone voicemails of celebrities, politicians and even murder victims.

It is the only newspaper that has admitted phone hacking, although some journalists and celebrities have said the practice was widespread in the tabloid press.

News International's titles were not singled out in the Independent's report on email hacking.

(Reporting by Paul Sandle; Editing by Andrew Heavens)


View the original article here

Thursday, August 25, 2011

Inter-company invoice emails carry malware

Facebook logoOver 30,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest internet and Facebook security threats. X

Twitter logoHi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats. X

InvoicesHave you received an unexpected "inter-company invoice" from a company for the period January 2010 - December 2010?

If so, chances are that your computer is being targeted by cybercriminals who are using the disguise as a method to infect your computer with a Trojan horse.

Companies such as Beazer Homes, KPMG, Miltek, Kraft Foods, and Safeco are named in different incarnations of the malware campaign, that is designed to trick you into opening the attached ZIP file.

Even if you haven't done business with the company referenced in the email, you might be tempted to open the attachment (which have names like Inv._08.8_D7.zip, Corpinvoice_08.10_N47.zip, and Invoice_08.4_D6.zip) out of curiousity.

Inter-company invoice emails carry malware

Of course, the emails have not really been sent by the companies that are named in them, and the sender's address has been forged.

Sophos products intercept the malware as the Troj/Agent-TBO Trojan horse, and the ZIP files themselves as Troj/Invo-Zip.

Remember, once malicious code has run on your computer, it's up to an unknown hacker what happens next. They can open a backdoor onto your computer to steal information, display fake anti-virus alerts, or compromise your PC to make it part of a botnet.

The best defence is not to fall for such attacks in the first place, by keeping your anti-virus protection up-to-date and keeping your wits about you.

Follow @gcluley

View the original article here

Trojans spammed out in malicious wave of fake DHL emails

Facebook logoOver 30,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest internet and Facebook security threats. X

Twitter logoHi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats. X

DHLThere is a significant wave of malicious emails being spammed out presently, posing as notification messages from DHL.

If you make the mistake of opening the attached ZIP file you will be putting your computer at risk of infection by a Trojan horse.

There's nothing new, of course, about cybercriminals disguising their attacks as notifications from DHL.

This attack, though, is particularly aggressive and - as you can see in the examples below - uses a variety of different DHL-related subject lines, attachment names and message bodies:

Malicious DHL email

HELLO!

Dear Client, Recipient's address is wrong

Print out the invoice copy attached and collect the package at our department

Best wishes , DHL Customer Services

Malicious DHL email

ATTENTION!
DEAR CLIENT , We were not able to deliver the postal package

Please print out the invoice copy attached and collect the package at our department

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

DEAR CUSTOMER, Recipient's address is wrong
PLEASE PRINT OUT THE INVOICE COPY ATTACHED AND COLLECT THE PACKAGE AT OUR DEPARTMENT

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

Dear User , Delivery Confirmation: FAILED
Please print out the invoice copy attached and collect the package at our department
With respect to you, DHL Team

Here are just some of the different disguises we saw in a snapshot of less than one minute in a small selection of our spam traps:

Malicious DHL email subject lines

Sophos products intercept the attack, detecting the ZIP file as Troj/Invo-Zip and the Trojan horse contained within as Mac/EncPk-NS.

Dangerous emails claiming to come from courier companies are nothing new - it has become one of the most commonly-used methods by which hackers socially engineer unsuspecting users into opening a malicious attachment or clicking on a dangerous link.

Make sure that you and your friends are wise to the trick - and think before you click.

Follow @gcluley

View the original article here

Saturday, June 25, 2011

Hackers claim 177K e-mails from Sony Pictures France

Sony's turn as the whipping boy for Internet hackers continued over the weekend. Two hackers posted a list of e-mails they say they took from the Sony Pictures France Web site.

The two hackers who claim responsibility are a Lebanese student who goes by the handle Idahc, and a French friend of his who goes by Auth3ntiq. The two say they copied 177,172 e-mails from the entertainment company's site, but posted only 70 of them on the code-sharing site Pastebin. They say they will not be posting all of the e-mails they found.

Jim Kennedy, Sony Pictures executive vice president of communications, said in a statement, "We are currently investigating this claim."

The brief Pastebin posting says the pair managed to lift the e-mail addresses through an SQL injection.

It's the same method that was used to extract personal data of customers from SonyPictures.com, Sony Pictures Russia, Sony Ericsson, and Sony Music Entertainment Japan in recent weeks.

Idahc isn't a stranger to attacking Sony's sites. He was the one who claimed to have taken data from a Sony Ericsson eShop Web site last month, leaked a database from Sony Europe, and compromised a Sony Portugal site.

Idahc said in an interview with Forbes last week he began hacking for "justice," but now says he's trying to prompt companies like Sony to improve their security.

Attrition.org has been keeping track of the spate of attacks on Sony. It says this is the 20th breach of a Web site or network related to the company in two months, starting with the PlayStation Network breach in April that put the gaming service out of commission for more than three weeks.

This story was updated at 2:28 p.m. PT with comment from Sony.


View the original article here

Friday, June 24, 2011

Hackers hit Sony Pictures France site, grab 177K e-mails - ZDNet (blog)

Sony Pictures France is the latest Sony Web site to suffer at the hands of hackers. This time two hackers have claimed credit and say they copied more than 177,000 e-mails from the site.

The two hackers are identified as a Lebanese student called “Idahc” and “Auth3ntiq,” a friend of his from France. They claim to have exploited a SQL flaw to get the information.

Idahc and Auth3ntic posted information about their feat, along with a sample of the e-mails they took, to the Web site Pastebin.com.

The hackers aren’t doing anything new. The same sort of exploit was used to break into SonyPictures.com, Sony Pictures Russion and other Sony-owned sites in recent weeks. In fact, Idahc seems to be on a crusade to teach Sony a lesson about bad security.

In a recent interview on Forbes.com, Idahc said that he’s attacking global Sony sites to demonstrate Sony’s lax attention to security. “I don’t hack for ‘lulz’ but for moral reasons,” he said.

It’s the latest in more than a dozen and a half attacks on Sony Web sites since Sony pulled its PlayStation Network offline in April, when the company discovered that as-yet unidentified hackers broke in and stole information about tens of millions of customers. Within days Sony discovered that its Sony Online Entertainment servers, which manage access to online PC games, had been similarly compromised. All told, more than 100 million customers had their names, addresses and other personal information taken.

In the wake of that failure, Sony executives pledged to improve security and to hire a new executive to head up security operations for the company. But hacker aren’t slowing down their attacks on the company. What’s causing the frequent attacks?

Sony is, of course, a high-profile target, as they’ve already suffered substantial damages by having to shut down network operations on the PlayStation Network for almost a month.

But there’s more to it. Hackers’ hackles were raised earlier this year when Sony sought to sue George “Geohot” Hotz, a programmer who tried to restore the PlayStation 3’s “OtherOS” capability, which enables it to operate Linux. That’s a feature Sony originally supported on the PlayStation 3 but later removed in a firmware update. After that, the hacker collective that calls itself “Anonymous” declared open war on Sony, only backing off after gamers themselves made their displeasure known.

Hackers’ displeasure with Sony runs much deeper than that, however. Years after the fact, some harbor resentment about Sony BMG’s decision to put rootkit-based DRM software on some of its music CDs back in 2005.

Now hackers are going after Sony with a vengeance. Like sharks detecting blood in the water, they’re unlikely to let up any time soon, especially since Sony’s chronically lax security makes them an easy target.

A long-time veteran of the Apple news business, Peter has also spent more than fifteen years covering games and the game industry. A self-proclaimed Alpha Nerd, Peter also professes a love for anime, sci-fi cons, gadgets of all kinds and various geek subcultures.


View the original article here