Friday, 16 October 2009

Kaspersky is here for the MAC!!!

Kaspersky Lab releases Kaspersky Anti-Virus for Macintosh computers


Kaspersky Lab, a leading developer of secure content management solutions, announces the release of a new product that protects Macintosh computers from all types of malware.
Kaspersky Anti-Virus for Mac is based on Kaspersky Lab’s new antivirus engine which dramatically increases system scanning speed thanks to improved processing of objects and optimized use of system resources, particularly on dual- and quad-core processor platforms.
The new product for Mac OS X (versions 10.4.11 and higher) combines the advantages of the new antivirus engine with a security approach that is based on protecting home or corporate networks from multiplatform IT threats. Kaspersky Anti-Virus for Mac protects against Mac OS viruses, worms and Trojans as well as combating similar threats for Windows and Linux operating systems.
The release of Mac OS X made the interaction of multiplatform computers considerably easier and Mac computers have now become an integral part of many corporate and home networks. These unprotected machines are like open gates through which malicious programs can penetrate any computer in a network which, in some organizations, could result in tens of thousands of machines being affected.
In order to protect mixed networks more effectively, Kaspersky Lab’s new product has access to the company’s global antivirus database that includes information on more than 20 million malicious programs for a range of platforms. The antivirus databases for Kaspersky Anti-Virus for Mac are updated hourly, as are the company’s antivirus products for Windows and Unix operating systems. This ensures that users are protected against the very latest malicious programs that appear in large numbers every day on the Internet.
Kaspersky Anti-Virus for Mac scans files and email attachments downloaded from the Internet. The new product is also exceptional for its distributed use of system resources: when user activity increases, the priority of the antivirus scanner declines, offering the user complete access to the computer’s system resources and increasing the performance of user applications.
Kaspersky Anti-Virus for Mac also protects shared folders on virtual machines which are gaining in popularity with both corporate and home users. This prevents the transfer of malware from Windows or Unix virtual systems to the work environment, which is of great importance for those working with several operation systems on a Mac computer.
Being well aware that an attractive interface is a must for Mac applications, Kaspersky Lab has equipped its new product with an animated interface that is user-friendly both for novices and more experienced users. Information about the protection status and any necessary user actions are presented in a graphic format that is easy to understand. The new product includes an automated mode for operations with applications, which means the program takes decisions automatically and doesn’t bother users with unnecessary requests.
Kaspersky Anti-Virus for Mac was especially designed to meet the needs of this operating system, offering complete compatibility with all versions of the OS from 10.4.11. Other technical requirements include: a Macintosh with the Intel processor, 512 MB available RAM and 80 MB available hard drive space.
Find out more information here: www.kaspersky.com/kaspersky-anti-virus-for-mac

New Crimeware Technique Revealed

By Kelly Jackson Higgins
DarkReading
Oct 15, 2009

Attackers have added a new twist to spreading fake antivirus software:
holding a victim's applications for ransom.

Researchers discovered a Trojan attack that basically freezes a user's system unless he purchases the rogueware, which goes for about $79.99.
The Adware/TotalSecurity2009 rogueware attack doesn't just send fake popup security warnings -- it takes over the machine and renders all of its applications useless, except for Internet Explorer, which it uses to receive payment from the victim for the fake antivirus. "The system is completely crippled," says Sean-Paul Correll, threat researcher and security evangelist for PandaLabs, which found the new attack.

Correll says when the rogueware detects any application on the machine starting to execute, it then shuts down the application. "This happens for every file you try to open except IE. The only reason IE works is because that's what's used to allow victims to pay the cybercriminals,"
he says.

Bad guys have used ransom threats in phishing attacks and distributed denial-of-service (DDoS) attacks, but Correll says this is the first time it has been used to force users to buy rogueware. Rogueware distributors typically prompt the victim with pop-up messages, but the user can bypass the purchasing process by ignoring them or clicking through them.

USCYBERCOM

By Mark Rutherford
Military Tech
CNet News
October 15, 2009

A new RAND Corporation report suggests the U.S. may be better off playing defense and pursuing diplomatic, economic, and prosecutorial efforts against cyberattackers, instead of making strategic cyberwarfare an investment priority.

The study comes as the U.S. military fires up its new unified Cyber Command (USCYBERCOM) program this month. The new outfit will be responsible for network-related operations, defense, and attacks and will operate under the U.S. Strategic Command.

Cyberwarfare is better at bothering an adversary than defeating it--given that permanent effects are illusive, author Martin C. Libicki wrote in the report, titled "Cyberdeterrence and Cyberwar."

On offense, cyberwar might be better relegated to support roles, and then only "sparingly and precisely," according to the report. A one-shot strike to silence a surface-to-air missile system, allowing aircraft to penetrate defenses to destroy a nuclear facility, is the example given.

"Attempting a cyberattack in the hopes that success will facilitate a combat operation may be prudent; betting the operation's success on a particular set of results may not be," Libicki wrote. One question planners should ask is whether strategic cyberwar would induce political compliance comparable to what could be produced by, say, strategic air power.

[...]

Homeland Security Department

Homeland Security Department agencies don.t sustain their information security programs year-round or perform continuous monitoring to maintain systems. accreditations and action plans, according to DHS Inspector General Richard Skinner.

The IG's findings come from an annual independent evaluation of the department's information security programs required by the Federal Information Security Management Act (FISMA). The law requires agency IGs to conduct the evaluations and agencies themselves to also conduct an annual information security evaluation.

Overall monthly FISMA information security scores for DHS agencies drop considerably after the annual deadline for FISMA reporting passes, the IG found. Overall scores for how well DHS agencies perform certification and accreditation and plans of action and milestones (POA&M) peak in months when the annual FISMA reporting is done and then quickly drop, the report said.

Meanwhile, Skinner also said DHS. Privacy Office is experiencing delays in reviewing and approving privacy impact assessments (PIAs) that the office is required to perform for many DHS IT systems.

Delta accused of Hacking

By LOREN STEFFY
The Houston Chronicle
Oct. 14, 2009

It started a couple of months ago with a laptop that inexplicably crashed.

Then, someone altered the password on Kate Hanni's desktop computer and when she finally got into it, the files were corrupted.

Microsoft's tech support said she'd been hacked. A few weeks later, all her e-mail disappeared, and AOL told her the same thing.

Hanni, who lives in California, is the founder of the Coalition for an Airline Passengers Bill of Rights, the group that's spearheading efforts in Congress to prevent airlines from imprisoning passengers on delayed flights.

In a lawsuit filed in Houston Tuesday, she claims that Delta Air Lines was behind the hacking, accusing the world's largest carrier of conspiracy and invasion of privacy.

Hanni believes Delta wants to crush her attempts to force better customer service on the airline industry, which has fought mightily to ensure it can treat passengers shabbily.

"Delta stands to lose the most," she told me in an interview at her lawyer's office in Houston. "They overschedule out of New York every day. They can't get those planes off the ground."

Cyber-crime , even cyber criminals are in recession

By Robert McMillan
October 14, 2009
IDG News Service

Cyber-crime just doesn't pay like it used to.

Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. "The barriers to entry in that marketplace are so low you have people basically flooding the market,"
said Jose Nazario, a security researcher with Arbor Networks. "The way you differentiate yourself is on price."

Criminals have gotten better at hacking into unsuspecting computers and linking them together into so-called botnet networks, which can then be centrally controlled. Botnets are used to send spam, steal passwords, and sometimes to launch DDoS attacks, which flood victims' servers with unwanted information. Often these networks are rented out as a kind of criminal software-as-a-service to third parties, who are typically recruited in online discussion boards.

DDoS attacks have been used to censor critics, take down rivals, wipe out online competitors and even extort money from legitimate businesses.
Earlier this year a highly publicized DDoS attack targeted U.S. and South Korean servers, knocking a number of Web sites offline.

Are botnet operators having to cut costs like other businesses in these troubled economic times? Security researchers don't know if that's been a factor, but they do say that the supply of infected machines has been growing. In 2008, Symantec's Internet sensors counted an average of
75,158 active bot-infected computers per day, a 31 percent jump from the previous year.

Wall of Sheep


By Dan Goodin in San Francisco
The Register
15th October 2009

Organizers of last week's SecTor security conference collected names, passwords, and all other traffic passing over two Wi-Fi networks provided to attendees, including one that was encrypted, the event's director has confirmed.

Borrowing a page from the Wall of Sheep at the Defcon hacker conference each year in Las Vegas, the exercise was designed to draw attention to the perils of public networks, conference organizer Brian Bourne told The Reg. Indeed, Bourne - who is the director of Black Arts Illuminated, the company that puts on the event - found partly obscured credentials for his on Twitter account on the SecTor Wall of Shame.

But what made the Wall of Shame different - at least to some attendees - was the sniffing of a network that was represented as secure. The wireless connection carried an SSID named "Sector2009Secured" and was encrypted using the WPA, or Wi-Fi Protected Access, protocol. Before it could be used, attendees had to stop by a booth sponsored by Canadian security vendor eSentire to retrieve the network's pre-shared key.

"In 2009, we still have so many applications leaking credentials onto the wire, and we have people still deploying and using insecure protocols," Bourne said. "Our intention with the Wall of Shame was to highlight that."


emails

a

The Register - Security

IQ test

The Register - Security: Anti-Virus

HackWire - Hacker News