Security

Turn Off Java — Flashback Trojan Risk

April 5, 2012

Originaly posted on the Mac Performance Guide MacRumors has an unsubstantiated report of infected Macs from the Flashback Trojan, another reason to refuse to run Adobe Flash, and validating Jobs’ brilliant decision to discontinue including it in Mac OS X a few years back, a decision that drew ugly denial-of-reality attacks from Adobe. This latest [...]

Read more…

Trojan masquerades as image files

March 17, 2012

Intego reported that a new version of the Imuler trojan first discovered last September has been found disguised as image files. This has not been found in the wild yet… but use caution! A couple of examples were discovered on a site used by security companies to share malware samples, both zipped archives: “Pictures and [...]

Read more…

More phishing… this time “from” Charles Schwab

March 16, 2012

I got this one today, addressed to me and about 15 others. The “from” address seems legit, but it is clearly forged. The return path is to another Schwab.com address, and the originator is a Rumanian address. Here’s the text of the email: Thank you for entrusting Charles Schwab & Co. with your investments and [...]

Read more…

Another phishing alert for Apple users

March 12, 2012

I just got an email, from the Apple Store (so it appeared) that scared the blazes out of me. It said that my order for over $4,000 had been charged to my credit card… and I didn’t even place an order. A link was provided to view the order, but before I clicked it (my [...]

Read more…

The phishermen are trying to hook US!

March 2, 2012

I just received an email, purportedly from Intuit thanking me for a purchase, with a link to download my complete order at “Intuit small business website.” The email was from INTUIT INC. at noreply@careerbuilder.com, which didn’t look right, and clicking on the link to download the “order” fortunately went to a “Account Suspended” page. The [...]

Read more…

DevilRobber Trojan disguised as PixelMator

November 17, 2011

A new attempt to steal data from Mac users is a bot called DevilRobber. The original version ran embedded in versions of Graphic Converter, but this one only pretends to be PixelMator, and contains none of the legitimate PixelMator code. This new variant tries to steal and generate Bitcoins as the original did, but it [...]

Read more…

iOS 4.3.5 released – Important security update

August 1, 2011

Apple patched a security vulnerability last week with the iOS 4.3.5 release. Certificate validation vulnerabilities were the issue, while 4.3.4 patched PDF vulnerabilities. 4.3.5 applies to the iPad and iPad2, iPod Touch (generation 3 and 4) and the iPhone 3GS and 4 (GSM). The Verizon iPHone4 will upgrade to iOS 4.2.10. I highly recommend all [...]

Read more…

Another phishing scheme… fake UPS email!

June 13, 2011

Technolog has a story from June 9 about email purporting to be from UPS regarding an upcoming delivery, which contains a hidden attached file that can infect computers (PCs, ad far as I know) with malware that could put up a fake anti-virus warning. The idea is to get the user to spend $50 or [...]

Read more…

Adobe to release Reader and Acrobat security patches tomorrow

June 13, 2011

A “pre-notification” from Adobe announced patches for “critical” security flaws in Adobe Acrobat and Adobe Reader for Mac and Windows. The updates are scheduled to be available tomorrow. Adobe is planning to release updates for Adobe Reader X (10.0.1) and earlier versions for Windows, Adobe Reader X (10.0.3) and earlier versions for Macintosh, and Adobe [...]

Read more…

Gmail users may be at risk from a Flash bug

June 7, 2011

 Yesterday (06/06/11) Adobe told the world that the Flash Player bug patched in a release the day before is a risk to Gmail users. Hackers have used it to steal login credentials, which would provide access to email and any other data stored in a Google account. The patch was an emergency fix, as this [...]

Read more…