Give your Desktop a Mozaic Touch

Experience the Windows 8 Metro Stlye UI on your Computer

Windows 7 God Mode

Get an Advanced Control Panel in Windows7 by enabling God Mode

Download Internet Explorer 9

Enjoy The Internet in a New and Secure Way

Microsoft Office 2010 Professional Activation

Activator for Microsoft Office 2010 Professional 100% Working..!!

Flash Wallpapers for Mobile

More than 175 Flash/SWF wallpapers for Mobile with System Info

Showing posts with label Corporate catch. Show all posts
Showing posts with label Corporate catch. Show all posts

Wednesday, May 2, 2012

Shocking Statistics From The Latest Internet Threat Report

Anti malware company Symantec released its threat report for 2011 on Monday. The statistics are as follows:-


A.      Religious and ideological sites have triple the average number of threats per infected sites that pornographic Web sites contain.

B.      Top 10 categories of most infected Web sites:
1.       Blogs
2.       Web communications
3.       Religious websites
4.       Personally hosted sites
5.       Business sites
6.       Shopping education
7.       Automative themed sites
8.       Health and medicine sites
9.       Porn sites

C.      3/4 spam messages were pharma themed. ¼ spam messages were Sex and dating-themed.

D.      Spam volumes dropped by around 20 billion messages year over year, to an average of 75% of all e-mail last year, compared with 88.5% in 2010.

E.       U.S. was the top source of every category of malicious activity.

F.       India leads in creation of malware and the use of spam zombies. (I am proud of it.) ;-)

G.     Around 13% of bot activity originated in the U.S. and around 34% of Web based attacks. Close to half of all phishing Web sites were based in the U.S.

H.      China saw a steep drop in malicious activity by about 10%. 

I.        Reports of vulnerabilities in industrial control and SCADA systems rose from 15 in 2010 to 129 in 2011.

Friday, December 9, 2011

Charlie Miller now working with DoD for Cyber Security

          Charlie Miller is a former hacker who has become an information security consultant now working with Department of Defense (DoD) for helping out with cyber security. He was invited to the conference on cyber conflict held by the NATO Cooperative Cyber Defense Center of Excellence in Tallinn, where he talked about the vulnerability of information systems. In a recent video released he talks about the ways he works.
           He spent five years working for the National Security Agency. Miller demonstrated his hacks publicly on products manufactured by Apple. In 2008 he won a $10,000 cash prize at the hacker conference Pwn2Own in Vancouver Canada for being the first to find a critical bug in the ultrathin MacBook Air. The next year, he won $5,000 for cracking Safari. In 2009 he also demonstrated an SMS processing vulnerability that allowed for complete compromise of the Apple iPhone and denial-of-service attacks on other phones.
           In 2011 he found a security hole in an iPhone's or iPad's security, whereby an application can contact a remote computer to download new unapproved software that can execute any command that could steal personal data or otherwise using iOS applications functions for malicious purposes. As a proof of concept, Miller created an application called Instastock that got approved by Apple's App Store. He then informed Apple about the security hole, who then promptly expelled him from the App Store.

Yahoo wins $610m lottery scam case

          Spammers sent mails to people falsely informing them that they were winners in a lottery of Yahoo. A New York federal district court judge awarded Yahoo $610m in a lawsuit against spammers who sent mails to people falsely informing them that they were winners in a lottery of Yahoo.

          The judge ordered defendants to pay Yahoo $27m for trademark infringement and $583m for violating the US Can-Spam Act. Yahoo filed the lawsuit in 2008 against spammers using their email system to defraud people. Yahoo traced the guilty, who included Nigerian and Taiwanese nationals, through internet records.

          Yahoo legal director of global brand protection Christian Dowell said that the company takes the protection of its users and its brand very seriously. "Our ultimate goal is to ensure that users continue to trust Yahoo as the leading U.S. e-mail provider," Dowell stated. The scammers tricked people into divulging their personal information such as passwords and credit card numbers and sold them.

Friday, December 2, 2011

The Spy Files: Wikileaks expose Mobile Phone, Email Hacking capability

          Wikileaks has released (http://spyfiles.org/) dozens of new documents highlighting the state of the once covert, but now lucrative private sector global surveillance industry. According to Assange, over 150 private sector organisations in 25 countries have the ability to not only track mobile devices, but also intercept messages and listen to calls also.

          Site founder Julian Assange has held a press conference, revealing the secrets of the industry.­ The whistleblowing site has published some 287 documents from its huge database, collected from 160 international intelligence contractors. The database includes internal documents of such companies like Gamma corporation in the UK, Ipoque of Germany, Amesys and Vupen in France, VASTech in South Africa, ZTE Corp in China, Phoenexia in the Czech Republic, SS8 and Blue Coat in the US, among others.

From the press release:
          "The Wikileaks Spy Files reveal the details of which companies are making billions selling sophisticated tracking tools to government buyers, flouting export rules, and turning a blind eye to dictatorial regimes that abuse human rights."

          “Who here has a BlackBerry? Who here uses Gmail? Well you are all screwed!” Assange exclaimed. “The reality is intelligence contractors are selling right to countries around the world mass surveillance systems for all of those products. Today we release over 287 files documenting the reality of the international mass surveillance industry – an industry which now sells equipment to dictators and democracies alike in order to intercept entire populations” Assange told reporters.

          Another leaked document from 2011 shows how one UK firm is depended upon by the government, including “law enforcement agencies, intelligence and military agencies & special forces”. Such technologies can be “integrated into bespoke solutions for static, tracking and mobile overt and covert surveillance”.

          The UK, one of the most surveilled countries in the world, with more CCTV cameras per person than any other major city, is one of the most prevalent in Internet monitoring, phone and text messaging analysis, GPS tracking and speech analysis technologies. Last month, it was found that Leeds-based company Datong plc. sold phone tracking and remote-disability technology to Scotland Yard, home of London’s Metropolitan Police, which could then be used to track protestors or disable remotely shut-off mobile phones en masse.

          Wikileaks recently celebrated the first anniversary of the controversial publication of US diplomatic cable leaks a publication that made Julian Assange a household name.Assange is currently under house arrest in London, where he is planning to launch an appeal against the recent ruling of a British court, which decided to extradite the journalist to Sweden, where he is accused of sexually harassing two women. Assange fears that his extradition to Sweden may eventually end up being one to the United States and will be appealing the ruling once again next Monday.

Wednesday, November 23, 2011

UK banks stress test defences against cyber attack

          Traffic infrastructure disruption during the London 2012 Olympics also examined. UK banks have taken part in an exercise designed to test their defences against a possible cyber attack. The tests also examined how financial institutions would cope if there was a major disruption to the transport infrastructure during the London 2012 Olympic Games.

           In total 87 banks, including Barclays, HSBC, Lloyds, and Royal Bank of Scotland, took part in the test. The mock cyber attack was designed to test how well telecommunications and Internet services would stand up in the face of a massive online attack. The scenarios played out included what would happen if an attack took cash machines out of service.

          "We have designed a scenario that will test the ability of participants to respond to a concerted cyber attack on the financial sector," said the FSA in a statement. "Thus, there is a strong focus upon dependencies on telecommunications and the internet as well as managing the return to business as usual." Sian John, UK Security Strategist at Symantec, said that the exercise was very encouraging, as it shows financial institutions are putting security at the top of the agenda.

          "Often you see security being considered at the last minute rather than being engineered into projects and infrastructures from day one so it's very encouraging to see an important sector like this taking part in preventative measures," she said. "Threats are becoming increasingly targeted and focused on accessing information that can be used for malicious gain or sold on via underground markets," she added. "An exercise like this will demonstrate exactly how robust their systems are and where the vulnerabilities lie. It may mean they need to reconsider back up sites for example or rethink security altogether - whatever the results it's a nice illustration that financial institutions are proactively looking to manage risk."

          An Exercise Report will be published early next year discussing the results of the test, alongside a Post Exercise Conference, the FSA said. London 2012 Gerry Pennell recently said it would be very difficult to launch a successful cyber attack on the Games themselves, due to the way his team had built the tech infrastructure. "We will be using a content distribution network to push data out, which means our dependency on a central host architecture is much lower. What that means is that it is very hard to launch a distributed denial of service attack (DDoS), simply because our front-end is so dispersed," he said.

          "We designed our approach to information security into our architecture from the beginning," Pennell continued. "We keep mission-critical Games systems, such as anything to do with distributing results, quite insulated from other components of the network, particularly anything web-facing, thus making it extremely hard for an external attack to succeed."

Tuesday, November 22, 2011

Wikileaks Founder, Julian Assange Hires Pirate Bay Lawyer

          Wikileaks Founder Julian Assange has fired his lawyer in favour of one with experience in batting for The Pirate Bay, according to a Swedish news report. Julian Assange has ditched his Swedish legal counsel and lined up a new defence team in readiness for a likely return to the country to face allegations of sexual molestation and rape against two women.

          Assange has filed a petition with the Stockholm District Court, says the newspaper, and communicated his desire to change his representation to attorneys Per Samuelson and Thomas Olsson. Olsson is reviewing the case already, but has little to say on the motives behind Assange's decision. "He'll have to explain his motivation behind changing defenders," he told The Local. Samuelson previously represented financier Carl Lundström, one of the four defendants in the 2009 Pirate Bay trial, all of whom were found guilty.

Friday, November 18, 2011

Cryptocard acquires IP from stricken GrIDsure

          Authentication vendor now gunning for SMB space. Cryptocard has acquired the patents and IP of troubled tokenless authentication firm GrIDsure, the company has announced. Cryptocard, also playing in the authentication space, did not reveal how much it has paid for GrIDsure's patents and IP. It says the deal will enable it to push its technology towards the SMB space, an area it is not currently particularly strong in.
The portfolio is has acquired from GrIDsure will be integrated with Cryptocard existing BlackShield SaaS platform and enable it to offer customers token or tokenless authentication via the cloud or on-premise, the company said.

          "We made the decision to acquire GrIDsure's pattern authentication IP to build out our already robust token and tokenless offering and to give our customers the widest possible choice," said Neil Hollister, CEO of Cryptocard. "Tokenless technology is incredibly cost-effective and easy to use and is a growing market. By delivering it on Cryptocard's BlackShield Cloud platform, the cost of service delivery is minimal and builds on our vision to make strong authentication universally available to organisations globally, regardless of size," he added.

          It was reported earlier this month that GrIDsure was in talks with a potential buyer after one of its investors had pulled out. It was also suggest that liquidation proceedings had begun.

Thursday, November 17, 2011

Half of SMBs don't consider themselves targets of cyberattacks: Symantec

          It contradicts the evidence provided by Symantec.cloud that revealed 40% of all targeted attacks were on SMBs in 2010 compared to 28% on large enterprises. According to a Symantec survey, half of the small and medium businesses (SMBs) feel that they are not in danger from cyberattacks, despite knowing the dangers of these attacks.

          This is in contrast to data from Symantec.cloud that said since the beginning of 2010, 40% of all targeted attacks have been directed at companies with fewer than 500 employees, compared to only 28% directed at large enterprises. According to the 2011 SMB Threat Awareness Poll, more than half of SMBs are familiar with many different security threats to the business, including targeted attacks, keystroke logging, and the risks that come with using smartphones for company business.

          More than half (54%) stated that malware would cause a loss of productivity, and 36% recognised that hackers could gain access to proprietary information, while 46% stated that a targeted attack would cause a revenue loss and 20% said it would drive customers away. Symantec Corp Worldwide Marketing for SMB and .Cloud, Steve Cullen said their research shows that SMBs are quite vulnerable to cyberattacks, and it's more important than ever for them to take steps to keep their information safe

          "Even with tight budgets and limited resources, simple changes such as education and best practices can significantly strengthen an SMB's security approach to cyberattacks," Cullen said. The survey found that many SMBs are failing to take basic precautions to protect their information as they don't themselves as targets of cyberattacks. A shocking 63% do not secure machines used for online banking and 9% do not take any additional precautions for online banking, while more than half (61%) do not use antivirus on all desktops and 47% do not use security on mail servers/services.

          In order to keep sensitive corporate information safe, Symantec has recommended SMBs to develop Internet security guidelines and educate employees about Internet safety, security and the latest threats; asses their security status; and advised them to be proactive and develop a security plan.

Monday, November 14, 2011

SAHER HoneyNet : A Tunisian Honeynet Project



          A honeynet is a network set up with intentional vulnerabilities; its purpose is to invite attack, so that an attacker's activities and methods can be studied and that information used to increase network security. A honeynet contains one or more honey pots, which are computer systems on the Internet expressly set up to attract and "trap" people who attempt to penetrate other people's computer systems. Although the primary purpose of a honeynet is to gather information about attackers' methods and motives, the decoy network can benefit its operator in other ways, for example by diverting attackers from a real network and its resources.

        The Tunisian honeynet project “Saher-HoneyNet” is an initiative launched by the Tunisian CERT, in order to mitigate threats related to malicious traffic in order to improve the national cyberspace security by ensuring preventive and response measures to deal with malware infections. The Honeynet Project, a non-profit research organization dedicated to computer security and information sharing, actively promotes the deployment of honeynets.

          The first research activities started in 2004, by deploying few honeyd sensors and testing new detection and prevention techniques to come up with a very powerful detection platform by the year 2008 as more resources are invested in the project. Now, the Tunisian honeynet project is a part of the Tunisian cyber early warning system “SAHER” created to deal with all cyber threats and to coordinate with the international community.

        This project involves all the cyberspace stakeholders, including the government, ISPs, Telcos, and critical information infrastructure, providing them coordination with tools for the detection; procedures to share information and technologies to clean-up the cyberspace and track malicious sources.

Friday, November 11, 2011

Self-styled regulator website asked to shut down by state securities regulators

          The fake site was using content from NASAA's website to mislead investors. The North American Securities Administrators Association (NASAA), an organisation whose mandate is to protect investors, has asked a website, which purported to be representing the "State Securities Commission," to halt its operations by closing its website.

          According to NASAA, the fake site was using content from NASAA's website, possibly for unlawful purposes. This website is one of the many websites that have come up in recent times to mislead investors.
NASAA president Jack Herstein said they are concerned that con artists are attempting to cash in on their reputation for effective investor protection to lure others into an illicit scheme.

          Herstein added that there were no legitiimate state securities regulatory agencies affiliated with the "State Securities Commission." The unauthorised website was urging investors who had suffered market losses to file "claims" by clicking on a link.

Thursday, November 10, 2011

Worldwide security service spending to cross $49b in 2015: Gartner

          Expected to reach $35b in 2011. Security services' spending is expected to reach $35.1b in 2011, up from $31.1b in 2010, according to IT research firm Gartner. The technology research firm forecasts security services spending to surpass $49.1b in 2015.

          The IT management segment of security services is also forecast to grow from $8b currently to $14.9b in 2015. Gartner research director Lawrence Pingree said the security services market has changed rapidly over the last several years with a growing number of security technology providers offering their technologies as services, and customers often preferring services to save on operational costs while they consolidate resources to more strategic security related initiatives.

          North America is the largest market for security services spending, with revenue forecast to grow to $19b in 2015. Western Europe spending for this market is expected to reach $14.4b for the same period, while security services spending in Japan is projected to touch $5.9b in 2015 while in Asia/Pacific the spending will total $7b in 2015, the report adds.

Financial woes force WikiLeaks to shut down

          Whistleblower site WikiLeaks has temporarily suspended operations because of financial constraints.
In a short note posted on its website, WikiLeaks blamed its situation on an "unlawful financial blockade" by several U.S. financial services companies. It also urged supporters to donate to its cause.

          "We are forced to temporarily suspend publishing whilst we secure our economic survival," WikiLeaks said in its post. "We cannot allow giant U.S. finance companies to decide how the whole world votes with its pocket. Our battles are costly. We need your support to fight back."  WikiLeaks claims it has been the target of "aggressive retaliation" from several groups for publishing tens of thousands of classified U.S. State Department cables starting last November.

          The site has accused Bank of America, Visa, MasterCard, PayPal and Western Union of curtailing its ability to receive donations and process payments from supporters. Soon after WikiLeaks started publishing the classified documents, several of these payment sites terminated services to WikiLeaks, citing terms-of-service violations. WikiLeaks said it has had to dip into its cash reserves to stay afloat.

Researcher Charlie Miller kicked out from iOS dev program for Exploiting iOS security flaw

          A major security flaw in Apple’s iOS operating system that could allow hackers to remotely gain unauthorized access to an iPhone, iPod touch or iPad has been uncovered by a security expert "Charlie Miller ".

          Charlie Miller gets a kick of out defeating Apple’s security mechanisms, using his hacking skills to break into Macbooks and iPhones. Now, Apple has kicked the security researcher out of its iOS developer program after word got out that he built a proof-of-concept iPhone app to showcase a bypass of the code signing mechanism.
 
           Hours before, a YouTube video that Miller released went viral. In it, he demonstrated how he hijacked an iPhone to run malicious code after installing his Instastock app, which was admitted into the App Store in September.

           According to the report, Miller plans to reveal the issue in a presentation at the SysCan security conference in Taiwan next week. As part of his presentation, Miller created an app capable of exploiting the flaw, and uploaded it to the App Store. Though App Store staff discovered a few problem APIs in the app, they didn't notice Miller's use of a special memory area, which allows his app to run unsigned code.

          The security expert’s app has since been removed from the App Store and his developer account has been suspended. We've seen plenty of malware on Android, but that's mostly because the Android Market accepts virtually any app and later plucks out the bad weeds. This is a scary first on iOS.

          Miller alerted Apple about the weakness three weeks ago. The company acknowledged it and asked how Miller should be credited in a security bulletin that accompanies most iOS release notes. "I'm sure it is something they will fix quickly," Miller noted, suggesting the fix would likely appear before his presentation in Taiwan. "That's what one would hope they would do. I'm sure they are also working on code fixes for the battery draining issue and stuff that they are going to release patch for."

Thursday, November 3, 2011

More than third of UK firms using social networking for their business: AVG

          Facebook most used compared to LinkedIn and Twitter. With increasing social networking for business purposes, more than a third of small and medium-sized businesses (SMBs) (34%) in the UK and US are using social networking in their business, according to AVG's new SMB Market Landscape Report.
Facebook is the most popular of these, with 30% of SMBs claiming to have a profile or page in it, followed by 19% for LinkedIn and 17% for Twitter, the report said.

          According to the AVG report, the most likely uses of social networking in business are for customer engagement and to share company/product information. The latest tablet and social networking technologies are being embraced by small and medium-sized businesses (SMBs) for greater employee mobility and more personalised customer engagement yet very few are aware of the accompanying security risks. The AVG report said 10% of SMBs are using tablets while more than a third (34%) are using social networking for business, and it showed that only a quarter (27%) of SMBs view the use of mobile phones in business as a threat to IT security.

          Overall, IT security breaches do occur regularly (17% reported experiencing a breach in the past year) and account for an average of 3-4 days labour to fix, the report revealed. The report said that there is an increase in mobile working, with one in five SMBs (19%) are employing Android smartphones; an equal proportion to use BlackBerry phones and employees spend an average of one day a week (20% of their time) working away from the office.

          However, the report indicated that very few SMBs were currently using antivirus or internet security for Smartphones (16%) or offerings for mobile workers (2%). SMBs are still most concerned about more traditional sources of threat, such as email and web viruses comprising 81% and 68%, respectively. With respect to new technology around two-thirds (64%) were not concerned about mobile malware/viruses, while around one in six (16%) are worried about the theft of their data stored in the cloud, the report added.
One in six SMBs (17%) reported having experienced a security breach in the past year, with more physical breaches from computers slowing down (83%), to losing access to files (39%) or programmes (31%) than psychological such as loss of customer data or business reputation.

           A total of 30 million man hours lost to rectifying issues related to security breaches in the past 12 months, while £1.18m (average £990 per business) in the UK and $5.6m (average $1570 per business) in the US were spent on replacing hardware during the same period. UK lost £2.19m (average £2800 per business) and the US lost $11.30m (average $4800 per business) in revenue opportunities during the past 12 months.

Thursday, October 27, 2011

Android becomes top platform for malware: Kaspersky Lab

          Android mobile malicious apps are targeting users' personal data, banking services. Computer security company Kaspersky Lab has revealed that Google's Android platform has established itself as the most popular for mobile malicious programs, overtaking other platforms as well as 'generic' Java malware.
 
          In September 2011 alone, the number of newly discovered malware for Android-based devices increased by more than 30%, according to data form the Moscow-based company. It said that the second half of 2011 has been an active one for cyber criminals, who have been increasingly looking for chances to set up new scams in the mobile device environment.  More alarmingly, Kaspersky Lab said, more and more often malicious mobile apps are targeting users' personal data. In October 2011 the share of particularly Android malicious apps trying to steal personal data went up to 34%.

          An example of a malicious app distributed through the official store is Trojan-Spy.AndroidOS.Antammi.b. This program, masquerading as a simple app for downloading ringtones, appeared on Android Market.  Kaspersky said that the "cover" program is designed for users in Russia, who use it to send text messages to a paid service to receive back desired tunes. This activity is perfectly legitimate; however, the malicious payload activity is simultaneously going on in the background. Like traditional "desktop" malware, Antammi.b steals almost everything: contacts, texts, GPS coordinates and even photos. The activity log is then sent to the criminal behind the scam via a simple e-mail message, and the data is uploaded to a server.

          The company said that the rise in malware on the Android platform is not surprising - due to the platform's leading market share, flexibility and openness, yet at the same time lax control over its software distribution. The result is a share of Android-based malicious programs among all mobile malware currently being higher than 46%, and growing rapidly. More worrying is the fact that mobile malware is also targeting banking services, said Kaspersky Lab.

Monday, October 24, 2011

Data breach more stressful than divorce, say IT managers

          IT managers feel that getting a divorce or losing their job is less stressful than looking after company confidential data.  New research by Websense, a content security and data theft protection company, has found that for IT managers the stress of managing their company confidential data is greater than divorce, managing personal debt, or a minor car accident.

          Websense commissioned independent research firm Dynamic Markets to survey 1,000 IT managers and 1,000 non-IT employees in the US, UK, Canada, and Australia about the latest threats to corporate and personal security, including modern malware and advanced persistent threats (APTs). The research revealed that IR managers are feeling the pressure and saying that data loss incidents put their jobs on the line. The study also highlighted that serious data breaches have occurred compromising CEO and other executives' data, confidential customer data, and data necessary for regulatory compliance.

          In the survey, 72% said protecting company data is more stressful than getting a divorce, managing personal debt, or being in a minor car accident. 14% said losing their job would be less stressful than staying in their current role. In the poll, 86% said that their job would be at risk if a security incident were to occur, including if a CEO or other executive's confidential data is breached (36%); data needed for compliance is lost (34%); and if confidential information is posted on a social networking site (34%). Nearly 37% said that data has been lost by employees. The study found about 20% stating that data affected by regulatory compliance was compromised. While, 20% have seen confidential information posted on social networking sites, 34% of employees who accidentally compromise data wouldn't tell their boss.

          However, Websense said that help is on the horizon. It said data security talk now involves top management. 91% of IT security managers report that new levels of management have engaged in data security conversations in the last year, including the head of IT (43%), managing director (38%), and CEO (33%). This means that until recently, the head of IT was often not involved, said Websense. Websense senior director of Product Marketing Tom Clare said the survey shows that companies need to recalculate their assumptions about how well their data is protected.

          "When asked about real-time protection solutions in place, many respondents listed product and vendor names that don't offer real-time protection at all, Clare said. He continued, "Advanced threats are using attack elements and methods that AV was not designed to address -- and are written and tested specifically to bypass AV. Companies need a robust, layered security strategy -- like our Websense TRITON solutions -- that can truly protect them from modern malware in the wild and effectively keep their confidential data protected however it's being used."