Security

Pierluigi Paganini February 13, 2013
Cybersecurity Strategy of the European Union – the proposal

Last week the European Commission and Catherine Ashton, the High Representative of the European Union for Foreign Affairs and Security Policy, have  submitted to the Council and the European Parliament a draft of “Cybersecurity Strategy of the European Union” The document is a first of its kind with regard to the institutions mentioned despite since several years the […]

Pierluigi Paganini February 12, 2013
Adobe 0-days exploited for IEEE aerospace spearphishing attacks

Last week Adobe released a patch for Adobe Flash that fixed a zero day vulnerability, CVE-2013-0633, that is being exploited using Microsoft Office files with embedded flash content delivered via email. The vulnerability is not isolated, it is circulating the news of a new one coded CVE-2013-0634 being exploited trough web browsers such as Firefox and Safari […]

Pierluigi Paganini February 11, 2013
PandaLabs has published the annual report 2012

Security Software Company PandaLabs has published the annual report on cyber threats proposing interesting statistics on the diffusion of malicious agent on personal computers during 2012. Malware diffusion has registered new records, the security firm detected 27 million new malicious codes, around 74,000 new samples per day, the attacks have targeted government offices and multinational […]

Pierluigi Paganini February 10, 2013
Bit9 hacked, stolen digital certificates to sign malware

The week ended in the worst way for the security company Bit9 that last Friday announced that hackers had stolen digital certificates from its network and have utilized it to sign malicious code. Bit9 is a popular a company that provides software and network security services to a lot of important private firms and also to […]

Pierluigi Paganini February 07, 2013
Operation Beebus, another chinese cyber espionage campaign

Security Firm FireEye revealed to have discovered an APT campaign targeting companies in the defense and aerospace sector and that has been originated from China to steal intellectual property and industrial secrets from US companies. In this period many other attacks have been linked to China such as the cyber espionage campaign against NYT and […]

Pierluigi Paganini February 06, 2013
Threat Report H2 2012 proposed by F-Secure

Today the principal channel for malware diffusion is considered internet, large diffusion of exploit kits and crimeware such as BlackHole, Cool Exploit and Incognito have automated the infection process over the network. Majority of attacks exploits vulnerabilities in large use applications, such as browsers, and the leak of responsive patch management expose users to serious […]

Pierluigi Paganini February 05, 2013
US Department of Energy hit by a sophisticated cyber attack

It seems that suddenly US have discovered to be victim of a serious of cyber espionage campaigns that are targeting every sector from media to military and every time seems that is a must to blame the nightmare China. A report published in 2012 by the U.S. China Economic and Security Review Commission revealed that “U.S. industry […]

Pierluigi Paganini February 02, 2013
How to fix the BYOD security issues in the workplace

Bring your own device (BYOD) is starting to take off in the workplace, as an increasing number of businesses encourage their employees to use smart phones, tablets or laptops to save costs and to allow their employees to work from any location. Unfortunately, as with all new technologies, there are also a number of risks […]

Pierluigi Paganini January 31, 2013
How PokerAgent botnet has stolen Facebook credentials

We never tire of repeating, social networks are an ideal conduit, due their large diffusion, for the spread of malware, they are used by cybercrime to realize complex fraud schema and by military to conduct offensive operations or cyber espionage campaigns. ESET Security Research has published an interesting analysis on the ‘PokerAgent’ botnet detected during 2012 […]

Pierluigi Paganini January 30, 2013
Security flaws in Universal Plug and Play expose million devices

Rapid7 security firm has published an interesting whitepaper entitled “Security Flaws in Universal Plug and Play” in which reports the result of a research conducted in the second half of 2012 that evaluated the global exposure of UPnP-enabled network devices. Security world has become accustomed to so surprising data, over 80 million unique IPs were identified […]