Ryan Naraine

Security Vendors Clueless Over Rootkit Invasion

Long before Mark Russinovich blew the whistle on Sony BMGs use of stealthy, rootkit-style techniques to cloak its DRM scheme, spyware researchers recall seeing traces of the controversial XCP technology on infected Windows machines. Only one problem—they had no idea what it was. “People had stumbled across this rootkit months and months ago, but we […]

Macromedia Patch Trifecta Plugs Security Holes

Macromedia Inc. on Wednesday released a batch of security patches to cover a trio of flaws affecting some of its enterprise-facing server products. The San Francisco, Calif.-based software and platform provider said the vulnerabilities could put users at risk of denial-of-service and information disclosure attacks. Two of the flaws are rated “moderately critical” by security […]

CMP Media Buys Black Hat

Jeff Moss has sold his Black Hat security think tank to technology publisher CMP Media LLC in a deal valued in the range of $14 million. The deal gives the Manhasset, N.Y.-based CMP Media the assets and intellectual property of Black Hat Inc., one of the most prominent security conferences on the calendar. The DefCon […]

Sober Virus Clones Taunt AV Vendors

A new batch of Sober virus clones has been spammed around the world to seed botnets for malicious use, anti-virus vendors warned Tuesday. The appearance of the latest threat comes 24 hours after law enforcement authorities in Germany predicted the Sober mutants would appear as e-mail attachments in German or English. According to F-Secure Corp., […]

Key Exchange Protocol Flaw Haunts Cisco, Juniper

Security researchers in Finland have discovered a serious security flaw in the way several big-name vendors implement the important Internet Security Association and Key Management Protocol. The flaw could expose vulnerable products to denial-of-service conditions, format string attacks and buffer overflows. In some cases, it may be possible for an attacker to execute code, the […]

Microsoft to Zap Sony DRM Rootkit

Microsoft Corp. will start deleting the rootkit component of the controversial DRM scheme used by Sony BMG Music Entertainment. The software giants Windows AntiSpyware application will be updated to add a detection and removal signature for the rootkit features used in the XCP digital rights management technology. According to Jason Garms, group product manager in […]

Trend Micro Backtracks on MS Trojan Description

Virus researchers at Trend Micro Inc. are wiping eggs off their faces one day after jumping the gun with a warning that a Trojan in the wild was capable of exploiting newly patched Windows security flaws. Just 24 hours after announcing the discovery of TROJ_EMFSPLOIT.A, a proof-of-concept Trojan that exploits a trio of image-rendering vulnerabilities […]

FTC Shuts Down BlogSpot Spyware Ring

The Federal Trade Commission has pulled the plug on a massive spyware operation that allegedly used Google Inc.s BlogSpot service to trick millions of computer users into downloading spyware and adware programs. The FTC on Thursday announced a court order to shut down three California-based companies—Enternet Media Inc., Conspy & Co. Inc. and Networld One—that […]

Trojan Attacks Microsoft Image Rendering Flaw

Anti-virus vendor Trend Micro Inc. has spotted a Trojan in the wild attacking Windows users via the image rendering flaws patched by Microsoft Corp. two days ago. The Trojan, identified as TROJ_EMFSPLOIT.A, causes the “explorer.exe” file to crash, causing the taskbar on unpatched Windows machines to disappear. The “explorer.exe” process is a required file used […]

Microsoft Trains Spotlight on Macromedia Flash Patch

In an unprecedented move, Microsoft Corp. has issued a security advisory to nudge Windows users into applying a critical security update for Macromedia Inc.s ubiquitous Flash Player. It is the first time the software giant has used its security advisories program to warn about potential problems in a third-party product. Microsofts advisory comes just days […]