Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts

Friday, January 31, 2014

Spam drops in 2013, says security software firm


MANILA, Philippines—Could the days of spam or unwanted and unsolicited messages received through email be over?

According to a study by international computer security software company Kaspersky, there was fewer number of spam messages in emails in 2013 compared to previous years.

“The percentage of spam in total email traffic decreased by 2.5 percentage points in comparison with the previous year and came to 69.6 percent,” Kaspersky said in its security bulletin posted on its computer security website securelist.com in January 2014.

“For the first time in many years the average annual spam percentage is less than 70 percent,” it said. Also the amount of spam messages has decreased by 10.7 percent over the last three years.

China and the United States were both seen as the top sources of worldwide spam email with 23 percent from China and 18 percent from the US.

“The amount of spam advertising legitimate goods and services is gradually decreasing. Advertisers increasingly prefer legitimate advertising to spam: more varied types of online advertising are becoming available, and these generate higher response rates at lower costs than spam can offer,” Kasperskysaid.

More malicious emails

Kaspersky however said that it detected more fake messages containing viruses or malicious software (malware) that can steal confidential information from the user.

“Fake confirmations of hotel or airplane ticket reservations have become a common part of spam; we saw such messages in spam traffic throughout the year. Instead of booking confirmations, files attached to such messages include malware,” it said.

Certain spam messages were also found to be impersonating anti-virus companies urging the recipient to download a file that supposedly updates their anti-virus program but actually contains a virus.

The fake file, known as a Trojan, “is designed to steal sensitive user data, particularly financial info,”Kasperksy said.

“The malware is capable of modifying the contents of bank websites loaded on the browser by embedding malicious scripts in order to obtain authentication data such as logins, passwords and security codes,” it said.

Shift to social media

Kaspersky noted the increase in attacks on Social Media through phishing, or stealing personal information by pretending to be a legitimate entity asking for certain information.

“In 2013, we saw phishers targeting more organizations that have no direct link to any financial data or service. There was a 7.6 percentage points increase in attacks using social networks,” it said.

“This can be partly explained by the fact that today’s email accounts often give access to a lot of content, including email, social networking, instant messaging, cloud storages and sometimes even a credit card,” Kaspersky said.

It noted that cybercriminals are constantly looking for different ways to steal information from people because they have become more aware of spam messages as security threats.

“Spam is changing and as traditional advertising declines we see far more fraud, malware and phishing. As a result, even experienced Internet users have to be more alert than ever to avoid stumbling into a cybercriminal’s trap,” Kaspersky said.

source: technology.inquirer.net

Thursday, December 5, 2013

Tech Tips: Guide to protecting Internet accounts


NEW YORK, United States — Security experts say passwords for more than 2 million Facebook, Google and other accounts have been compromised and circulated online, just the latest example of breaches involving leading Internet companies.

Some services including Twitter have responded by disabling the affected passwords. But there are several things you can do to minimize further threats —even if your account isn’t among the 2 million that were compromised.


Here are some tips to help you secure your online accounts:

— ONE THING LEADS TO ANOTHER:

When a malicious hacker gets a password to one account, it’s often a stepping stone to a more serious breach, especially because many people use the same passwords on multiple accounts. So if someone breaks into your Facebook account, that person might try the same password on your banking or Amazon account. Suddenly, it’s not just about fake messages being posted to your social media accounts. It’s about your hard-earned money.

It’s particularly bad if the compromised password is for an email account. That’s because when you click on a link on a site saying you’ve forgotten your password, the service will typically send a reset message by email. People who are able to break into your email account, therefore, can use it to create their own passwords for all sorts of accounts. You’ll be locked out as they shop and spend, courtesy of you.

If the compromised password is one you use for work, someone can use it to break in to your employer’s network, where there are files with trade secrets or customers’ credit card numbers.

— BETTER PASSWORDS:

Many breaches occur because passwords are too easy to guess. There’s no evidence that guessing was how these 2 million accounts got compromised, but it’s still a good reminder to strengthen your passwords. Researchers at security company Trustwave analyzed the passwords compromised and found that only 5 percent were excellent and 17 percent were good. The rest were moderate or worse.

What makes a password strong?

— Make them long. The minimum should be eight characters, but even longer is better.

— Use combinations of letters and numbers, upper and lower case and symbols such as the exclamation mark. Try to vary it as much as you can. “My!PaSsWoRd-32″ is far better than “mypassword32.”

— Avoid words that are in dictionaries, as there are programs that can crack passwords by going through databases of known words. These programs know about such tricks as adding numbers and symbols, so you’ll want to make sure the words you use aren’t in the databases. One trick is to think of a sentence and use just the first letter of each word — as in “tqbfjotld” for “the quick brown fox jumps over the lazy dog.”

— Avoid easy-to-guess words, even if they aren’t in the dictionary. Avoid your name, company name or hometown, for instance. Avoid pets and relatives’ names, too. Likewise, avoid things that can be looked up, such as your birthday or ZIP code.

One other thing to consider: Many sites let you reset your password by answering a security question, but these answers —such as your pet or mother’s maiden name— are possible to look up. So try to make these answers complex just like passwords, by adding numbers and special characters and making up responses.

— A SECOND LAYER:

Many services offer a second level of authentication when you’re accessing them from a computer or device for the first time. These services will send you a text message to a phone number on file, for instance. The text message contains a code that you need in addition to your password. The idea is that a hacker may have your password, but won’t have ready access to your phone.

Facebook, Google, Microsoft and Twitter are among the services offering this dual authentication. It’s typically an option, something you have to turn on. Do that. It may be a pain, but it will save you grief later. In most cases, you won’t be asked for this second code when you return to a computer you’ve used before, but be sure to decline that option if you’re in a public place such as a library or Internet cafe.

— ONE FINAL THOUGHT:

Change your passwords regularly. It’s possible your account information is already circulating. If you have a regular schedule for changing passwords for major accounts, you reduce the amount of time that someone can do harm with that information.

You’ll need to decide what counts as a major account. Banking and shopping sites are obvious, as are email and social-networking services. It probably doesn’t matter much if someone breaks into the account you use to read newspaper articles (unless it’s a subscription).

And strong passwords alone won’t completely keep you safe. Make sure your computer is running the latest software, as older versions can have flaws that hackers have been known to exploit. Be careful when clicking on email attachments, as they may contain malicious software for stealing passwords. Use firewalls and other security programs, many of which are available for free.

source: technology.inquirer.net

Wednesday, March 27, 2013

Wells Fargo site hit by denial-of-service attack


Wells Fargo was the target of another distributed denial-of-service attack.

The bank's Web site was slowed down by the attack yesterday, affecting a certain number of customers, according to Fox Business News.



"Yesterday we saw an unusually high volume of Web site traffic which we believe was a denial of service attack," a Wells Fargo spokeswoman told CNET today. "The vast majority of customers were not impacted and customer information is safe. For customers who had difficulty accessing the site, we encouraged them to call us by phone, use ATMs or try logging on again as the disruption is usually intermittent. We apologize to our customers for any inconvenience during that time."

The attack did not affect actual bank branches, ATMs, or mobile bank applications, according to Wells Fargo

The bank didn't reveal the source of the attack. But a group called Izz ad-Din al-Qassam Cyber Fighters posted a warning on Pastebin yesterday, saying that it was launching denial of service attacks against several major U.S. banks, including BB&T, PNC, Chase, Citibank, U.S. Bancorp, Suntrust, Fifth Third Bancor, and Wells Fargo.

The group claims to be targeting banks in protest over the "Innocence of Muslims," a YouTube video that has aroused anger from those who consider it anti-Islam.

Wells Fargo and other banks were the victims of similar denial of service attacks last September. Izz ad-Din al-Qassam Cyber Fighters also claimed responsibility for those, vowing to continue the attacks until the "Innocence of Muslims" video is removed from the Internet.

source: news.cnet.com

Monday, September 10, 2012

Emma Watson Named Web's Most Dangerous Celebrity in 2012


Emma Watson lands atop McAfee's annual list of Most Dangerous Celebrity in Cyberspace. The "The Perks of Being a Wallflower" actress replaces last year's No. 1 champ Heidi Klum on the yearly list released by the Internet security firm.

According to McAfee, "searching for the latest Emma Watson pictures and downloads yields more than a 12.6% chance of landing on a website that has tested positive for online threats, such as spyware, adware, spam, phishing, viruses and other malware."




Sitting behind the "Harry Potter" star on the second place is Jessica Biel. The fiancee of Justin Timberlake occupied the first place in 2009 and sat at the fourth spot last year. Rounding up the top 3 is a new addition to the list, actress Eva Mendes.



Klum is out of the top-10 list, while 2010's most dangerous celebrity Cameron Diaz claims the eighth place, six spots lower than last year's position. Others are Selena Gomez, Halle Berry, Megan Fox, Shakira, Salma Hayek and Sofia Vergara.


  1. Emma Watson
  2. Jessica Biel
  3. Eva Mendes
  4. Selena Gomez
  5. Halle Berry
  6. Megan Fox
  7. Shakira
  8. Cameron Diaz
  9. Salma Hayek
  10. Sofia Vergara
source: aceshowbiz.com


Sunday, December 25, 2011

Internet users warned of scams during holidays

SAN FRANCISCO—The holiday season brings with it increased chances for online scams as Internet users hunt for gift bargains and cyber crooks expand arsenals to include false offers of tremendous deals on hot items.

According to study results released on Thursday, Internet users are suckers for online scams, especially if the promised prize is a chance at a hip new gadget such as a tablet computer.

In a Ponemon Institute study backed by an Internet security firm, PC Tools, more than half of those surveyed indicated they would reveal mobile phone numbers, e-mail addresses or other information when told they might get something for nothing.

“Even in scenarios where people realize it is too good to be true, they are falling for it,” said Eric Klein, PC Tools senior manager of online strategy.

“I don’t know why people keep falling for it, really,” Klein added.

Cyber crooks have long exploited human nature with scams relying on “social engineering” to get people to reveal secrets such as passwords or unwittingly install computer viruses.

Manipulations can range from telling people they will be entered in prize drawings after filling out detailed surveys or getting them to open booby-trapped files said to contain sexy or graphic imagery.

“The results found a clear difference between how aware consumers think they are of scams and how likely they are to be taken in by the given scenarios,” concluded researchers of the Ponemon Institute.

“It is clear from the findings that the threat posed by scams is still being underestimated,” they added.

Scenarios that people fell for included offers of supposed free antivirus software to install in computers and get-rich-quick opportunities, according to Ponemon.

People were particularly susceptible to biting when ploys were baited with promises of chances to win tech prizes such as mobile phone ring tones or tablet computers.

“People in the United States were, frankly, more cheap and looking for something to get out of it,” Klein said.

“The idea of getting rich made them more likely to put security aside,” he continued.

Versions of the study were also done in Australia and Britain—with Australians being unlikely to fall for ploys while British Internet users were more susceptible but far more wary than those in the United States.

Strong lures

Tablet computers made particularly strong lures in all three countries, according to surveys.

“Whenever those gadgets are being hyped, they are trendy things to have,” Klein said. “People interpret it as status, so they will go to great lengths to get one.”

“It is really about tricking people into giving up information,” he explained. “Some of the data is pretty alarming.”

People were advised to check for secure “https” website addresses for transactions and to watch for misspellings that could signal a ruse.

Klein recommended avoiding websites with addresses in Eastern Europe, particularly Russia, due to the number of scams originating there.

“Take your time, double check what site you are on and look for hints they are not legit,” he said. “Before you give out any personal details make sure it is a real offer.”

source: http://technology.inquirer.net/7113/internet-users-warned-of-scams-during-holidays/