phishing

Phishing for Apple

To paraphrase an old expression: Give a man an apple and you feed him for a day; teach a man to phish apple IDs and you feed him for a lifetime -- with stolen data. That's what some bold phishers are hoping for, according to a new report by security intelligence company Trend Micro, which documents a major phishing scam that has already compromised 110 sites in a plan to steal Apple IDs.

According to Trend Micro, all of these sites are "hosted at the IP address 70.86.13.17, which is registered to an ISP in … Read more

Twitter aiming to slash phishing e-mails sent from 'Twitter.com'

If you get an e-mail saying it's from Twitter, the social-networking company wants to assure you that it's really from Twitter and that there's no need to worry that someone's out to steal your password.

At least, it's almost certain that the e-mail you just got from a Twitter.com address is not a phishing attack, the company said in a blog post today.

Twitter said it has adopted a new security protocol known as DMARC that was designed by a consortium in order to cut way down on phishing attempts.

DMARC solves a couple … Read more

White House confirms 'spearphishing' intrusion

The White House has confirmed that one of its internal computer networks -- reportedly a military office in charge of the president's communications -- has been targeted in a successful "spearphishing" attack.

An article yesterday published by the conservative FreeBeacon.com Web site said that hackers with ties to China's government had recently breached an unclassified "system used by the White House Military Office for nuclear commands," including the so-called nuclear football.

Spearphishing means an attacker is targeting a specific person or group, typically by sending fake e-mail that masquerades as legitimate correspondence.

The … Read more

Phishing attacks via text spiked this week -- researcher

A surge in SMS phishing attacks this week took security experts by surprise and tricked victims into providing credit card and other sensitive information to scammers, a researcher said today.

The phishing onslaught, which targeted customers of the major cellular carriers in the U.S., started on Tuesday, said Mary Landesman, senior security researcher at security provider Cloudmark.

The number of SMS-based phishing attempts observed by security firm Cloudmark based on reports from consumers rose more than 900 percent during the first week of September from what would be expected over that period in a normal month, she said in … Read more

Kaspersky 2013 ups the ante with exploit prevention

The 2013 updates to the Kaspersky protection suites bring to consumers some of the most advanced security technology currently available. It involves introducing an exploit prevention engine as part of the security suite, but also a Safe Money banking protection tool that you can interact directly with. The suite's scans aren't the fastest, but it definitely will protect you.

Installation Installing Kaspersky has been dramatically simplified over the past two years. Following on 2012's fuss-free install, the installer for 2013 will remove conflicting security programs and any detected malware automatically.

You're still on the hook for … Read more

Protect yourself from smishing (video)

We've all heard about phishing attacks -- those spammy e-mails you get in your in-box imploring you to divulge your personal information. Now those annoying scams are coming to a cell phone near you -- it's called smishing, or phishing via SMS text message.

Text messaging is the most common nonvoice use of a mobile phone, and scam artists are taking full advantage of that. In fact, according to security firm Cloudmark , about 30 million smishing messages are sent to cell phone users across North America, Europe, and the U.K. Smishing is part of the much larger … Read more

Facebook battles phishing by reaching out to users

Most everyone has seen them, those annoying clickable phishing ads in the news feed or posted on friend's Facebook walls: "Get free tickets to Jamaica," "Win a free iPad," or "Friend, I need money urgently."

Phishing has been the bane of Facebook's existence for years, and today it announced that it is making a new attempt to curb the practice. It's launching a select e-mail address, phish@fb.com, where users can send notices of phishing they've seen on the social network.

"By providing Facebook with reports, we can … Read more

Bitdefender Total Security 2013 brings secure browsing to the top shelf

The bottom line: Bitdefender Total Security 2013 remains one of the best high-end security suites around. This update gives you a fully isolated Web browser for secure financial transactions.

Review: Bitdefender Total Security 2013 presents a convincing alternative to its better-known competitors. It's a strong program, with all the major tools that users expect, and some additional useful tricks in its arsenal. When it comes to efficacy, Bitdefender isn't the best in every area, but it's definitely competitive.

Editors' note: Portions of this review are based on CNET's review of Bitdefender Total Security 2012.

Installation Bitdefender … Read more

How attacks on social networks work

SAN FRANCISCO--Symantec detailed some of the dirty secrets of Facebook, Twitter, and Google+ threats at its annual reviewers' workshop here today, and revealed a planned project to protect you from social networking manipulators.

The project from Norton Labs, currently called Norton App Advisor, combines Norton's Safe Web data with social network open API data to provide a safety rating for apps. It aims to prevent malicious apps that prey on your social network activity from collecting data on you and your friends, which Symantec representatives said was a major security concern.

"Social networks have a trust model built … Read more

Google warns Gmail users about state-sponsored email hacking

Google hasn't been shy about wagging its finger at China recently. And in what appears to be another veiled snipe at Chinese authorities, the tech company says it is now warning users if state-sponsored phishing or malware attacks appear to have targeted their Gmail accounts.

"We are constantly on the lookout for malicious activity on our systems, in particular attempts by third parties to log into users' accounts unauthorized," Eric Grosse, vice president of security engineering at Google, wrote in a blog post today. "When we have specific intelligence -- either directly from users or from … Read more