News

MS to release out-of-band patch for critical IE vulnerability

Users advised to patch ASAP.

17 December 2008

IE zero-day danger growing

Large numbers of users vulnerable to unpatched problem.

16 December 2008

VB100 update

MicroWorld eScan added to list of VB100 successes for December.

16 December 2008

FTC goes after scareware scammers

Courts crack down on pushers of rogue anti-malware.

11 December 2008

Patch Tuesday released closely followed by emergency update

Bumper crop of patches plus further fix leave known holes open.

11 December 2008

December issue of VB published

The December issue of Virus Bulletin is now available for subscribers to download.

1 December 2008

Worm targets MS08-067 vulnerability

Exploit attack patches flaw once system penetrated.

1 December 2008

Microsoft to replace OneCare with free AV product

OneCare retirement announced, new product will be lighter on systems and pockets.

19 November 2008

ICANN pulls plug on registrar favoured by cyber crooks

After a week's stay of execution, ICANN decides EstDomains will be terminated.

14 November 2008

Disconnection of dubious provider sees spam levels plummet

Web-hosting firm believed to be responsible for 75% of spam.

13 November 2008

Two updates in Microsoft's November's patch release

Just two updates released by Microsoft this month: one rated critical, one important.

12 November 2008

Riders on a Storm

Researchers hijack botnet - and find spam success rates lower than previously believed.

11 November 2008

November issue of VB published

The November issue of Virus Bulletin is now available for subscribers to download.

31 October 2008

Microsoft issues emergency patch

Out-of-cycle update fixes serious, wormable flaw.

24 October 2008

US ISPs urged to snoop on traffic

NY Attorny General promotes deep packet inspection to AOL.

22 October 2008

Latest VB100 announced

Products for 64-bit Vista to be put through paces.

22 October 2008

McAfee false positive flags Vista component

Innocent file labelled trojan.

22 October 2008

Sarkozy bank account raided by cybercrooks

Hackers steal from French president - phish suspected.

22 October 2008

Security dominates software sales charts

AV, IS and anti-spyware products represent nine of last month's top 20 bestsellers.

20 October 2008

Ham disguised as spam

Webshop makes mass-mailing look like phishing scam.

17 October 2008

Vulnerability test raises hackles

Secunia suite trial slates lack of PoC detection, but test methods called into question.

17 October 2008

Researchers urge anti-phishing companies to share data

Estimate over $300 million lost annually because data is not shared.

16 October 2008

Four critical updates this Patch Tuesday

11 updates to be issued by Microsoft in October's monthly patch release: 4 critical.

14 October 2008

VB2008 photos online

VB delegates at work, rest and play in Ottawa.

14 October 2008

MessageLabs acquired by Symantec

Acquisition deal valued at $695m.

08 October 2008

October issue of VB published

The October issue of Virus Bulletin is now available for subscribers to download.

26 September 2008

McAfee to buy Secure Computing

Acquisition deal valued at $465m.

22 September 2008

Free speech argument overturns AOL spammer conviction

Virginia court upholds notorious Jaynes' right to express himself in bulk.

16 September 2008

Last-minute papers announced for VB2008

Schedule for hot-topic technical 'turbo' talks announced.

16 September 2008

Four critical updates in Patch Tuesday release

Monthly security update small but vital.

10 September 2008

Tough weekend for AV giants as FPs and DNS issues hit

Trend false alert cripples users' systems, Sophos sites taken out by DNS mixup.

10 September 2008

Google shows off in-house browser beta

Open-source 'Chrome' promises security as well as efficiency.

03 September 2008

AV-Test release latest results

Major test of suite products completed

02 September 2008

September issue of VB published

The September issue of Virus Bulletin is now available for subscribers to download.

01 September 2008

Malware reaches space station

Autorun worm found on non-critical systems.

29 August 2008

Best Western database hack exposes info on 8m customers

Hotel chain data heist latest in string of major security leaks.

26 August 2008

AMTSO releases draft guidelines for public comment

First major publication emerges from testing standards body.

26 August 2008

Symantec to acquire PC Tools

Industry giant adds spyware specialist to growing portfolio.

20 August 2008

Latest VB100 announced

September 2nd deadline set for Windows Server 2008 test

20 August 2008

Net threats cost US $8.5 billion in two years

Study measures scale of scamming and other web worries.

05 August 2008

Malware writing teacher revives old rows

College instructor claims to be fighting industry monopoly.

05 August 2008

August issue of VB published

The August issue of Virus Bulletin is now available for subscribers to browse online or download in PDF format

01 August 2008

DNS flaw exploitation danger growing

Slow patchers targeted by sophisticated attacks.

01 August 2008

McAfee buys data loss firm Reconnex

$46 million acquisition announced as strong profit report released.

01 August 2008

Trend OfficeScan flaws labelled highly critical

Web-delivered products at risk of allowing remote access.

01 August 2008

Sophos makes move to buy Utimaco

€217 million bid launched for encryption specialist.

28 July 2008

Storm mails bring spoof World War 3 news

US-Iran war story used as hook for malware barrage.

10 July 2008

Patch Tuesday sees serious DNS flaws fixed

Nothing marked critical, but some very important patches issued.

10 July 2008

July issue of VB published

The July issue of Virus Bulletin is now available for subscribers to download.

01 July 2008

China hosting over half of malicious sites

StopBadware.org report highlights Chinese dominance in web malware.

30 June 2008

Macs under attack from trojan double whammy

Two new threats in a week spark worries of approaching Mac malware era.

30 June 2008

MAAWG unveils spam and botnet battling policies

Working group of ISPs and net operators issue traffic calming guidelines.

30 June 2008

Trojan-to-worm automation tool spotted

GUI gizmo adds extra spreading menace to any malware.

20 June 2008

LinkScanner could be behind surge in web traffic

Traffic analysts worry as AVG implements web scanning technology.

20 June 2008

Yet more data leaks in UK public services

Confidential health service info exposed after theft.

20 June 2008

41 months plus hefty fine for botherder

Cross-border operation brings adware crook to book.

12 June 2008

Microsoft releases latest Patch Tuesday fixes

7 vulnerabilities, 3 critical, addressed in June security update.

12 June 2008

Spyware gang sneaks millions from SA government

32 arrested but South Africa theft scam thought to be ongoing.

12 June 2008

File encryption blackmail scam returns

Kaspersky warns of new and nasty data-ransom trojan.

05 June 2008

Microsoft increases pressure on Apple to fix Safari blended threat

'Carpet bombing' vulnerability more serious than Apple claims, MS warns.

03 June 2008

Spammers turn to DoubleClick for open redirect

Loophole in Google's AdSense solved, but new flaw quickly uncovered.

03 June 2008

Sourcefire turns down $186 million takeover bid

Unsolicited offer from Barracuda Networks rejected.

03 June 2008

Spam and ID theft attacked from all sides

EU body issues warning, ICANN, Japan and Yahoo! take on spammers and phishers.

03 June 2008

June issue of VB published

The June issue of Virus Bulletin is now available for subscribers to download.

02 June 2008

Flash exploit used to steal gaming passwords

Despite initial panic, threat no longer believed to a zero-day exploit.

29 May 2008

Almost half of users think virus-writing contests are a good idea

Shocking survey results disappoint security experts.

22 May 2008

MySpace wins record payout in case against spammers

'Spam Kings' Wallace and Rines fined maximum amount under federal law.

14 May 2008

Yahoo! searchers to get McAfee site advice

SiteAdvisor data to help check security of search results.

09 May 2008

Security experts gather in Europe

Anti-malware insights pooled at AMTSO, CARO and EICAR meetings.

07 May 2008

Users divided about customer liability for online fraud losses

Many users worried about lack of knowledge.

06 May 2008

May issue of VB published

The May issue of Virus Bulletin is now available for subscribers to download.

01 May 2008

Cracked CAPTCHAs used to create malicious blogs

Blogs on Google's blogging system redirect to spam sites.

25 April 2008

Mass attack infects over half a million web pages

United Nations and UK Government sites among those infected by SQL injection.

24 April 2008

More than 50% of users regularly double-check for false positive spam filtering

Only 12% of users trust their spam filter sufficiently not to bother sifting through spam folder.

16 April 2008

Phishing on rise, but anti-phishers fighting back

As UK banking body reports major increase in phishes, PayPal unveils blocking strategy.

16 April 2008

China-Tibet row spills over into malware attacks

Both sides of debate targeted to spread malicious code.

16 April 2008

'Kraken' monster botnet causing controversy

As latest botnet scare debated, Storm keeps on blowing.

9 April 2008

Latest Patch Tuesday update released

Microsoft announces five 'critical' vulnerabilities need fixing.

9 April 2008

HP ships infected USB keys

Autorun worms found on batch of server setup devices.

9 April 2008

Google Groups and Blogspot used to serve malware

Company finds own IP address to be serving most malware.

7 April 2008

Users of online banking 'should have adequate protection'

New UK banking code says customers who keep their PCs secure will not be responsible for losses due to online theft.

4 April 2008

Less than 30 per cent of smartphone users have AV installed

Experts disagree on the need for specialist mobile AV protection.

3 April 2008

Average spam message size at record low

No decrease of bandwidth usage as number of spam messages keeps increasing.

3 April 2008

April issue of VB published

The April issue of Virus Bulletin is now available for subscribers to download.

02 April 2008

April Storm

April Fools' Day emails contain new variant of infamous worm.

1 April 2008

Almost 90% of Americans feel safe online

Users' confidence does not match up with percentage of properly protected users.

1 April 2008

From Simple Mail to Hypertext

HTTP and FTP take over from SMTP as common malware spreading methods.

31 March 2008

Access flaw exploited via Word

Microsoft's employees hunting vulnerabilities instead of Easter eggs.

25 March 2008

Microsoft acquires Komoku

Anti-rootkit software to become part of Forefront and OneCare.

25 March 2008

Hoax email warns about 'nasty virus'

Phony advice causes removal of site from search engines.

17 March 2008

Legitimate program becomes trojan downloader

Website of FlashGet attacked; malicious 'update' automatically downloaded.

17 March 2008

More 'trusted sites' carrying iframe danger

Big wave of website infections could affect tens of thousands of sites, Trend Micro latest victim.

14 March 2008

AV-test.org issues latest figures

In-depth testing covers multiple factors.

13 March 2008

EU agency research advises sweeping security improvements

ISPs and developers should be held to account, says report.

13 March 2008

Latest Patch Tuesday release

March's Patch Tuesday sees four 'critical' updates.

12 March 2008

Latest AV-Comparatives results released

Detection test shows most products improving.

11 March 2008

Cisco announces 'Patch Wednesdays'

Cisco set to embark on regular release cycle.

11 March 2008

'Olympic' emails contain malicious XLS attachments

Malware writers sprint to use vulnerabilities before next Patch Tuesday.

10 March 2008

IE8 to include malware filtering

New features list includes upgrade to security provision.

07 March 2008

Spammer's free speech defence fails

Appeal against conviction turned down.

07 March 2008

'Search engines should do more to fight malware'

85% of users think that search engines should be doing more.

03 March 2008

Showy malware pushes rogue anti-malware product

MonaRonaDona trojan leads searchers to remover scam.

04 March 2008

Cybercriminals charged in New Zealand, Korea

Law closes in on alleged botnet master and rogue anti-spyware maker.

04 March 2008

March issue of VB published

The March issue of Virus Bulletin is now available for subscribers to download.

03 March 2008

Gmail CAPTCHA cracked

Twenty per cent success rate sufficient to create thousands of spam accounts.

26 February 2008

Trend Micro buys email encryption firm

UK company taken over by security giant.

25 February 2008

Malware going local

Report sees trend toward greater localisation of threats.

22 February 2008

Botnet-herding team arrested in Quebec

Gang held for managing million-machine zombie net.

22 February 2008

Vista SP1 clashing with AV products

Service Pack causing issues for several security suites.

22 February 2008

Vish implanted in phishing warning

Doctored bank alert includes phony phone number.

21 February 2008

ITV site carried scareware ads

Rogue security product pushed by ads on several UK TV sites.

21 February 2008

Habbo trojan steals passwords

Extension decorates your room... with malware.

21 February 2008

VB reveals new website design

Glossary, comments and mobile website among new additions.

20 February 2008

Japanese super-spammer arrested

Tokyo man sent 2.2 billion emails.

19 February 2008

VB100 test on Windows Vista SP1 announced

Products to be tested on new update to Vista platform.

19 February 2008

Microsoft research revives 'friendly worm' ideas

Malware techniques proposed as update-spreading method.

15 February 2008

Phishers phishing phishers' phishes

Scam software secretly sending stolen data to creators.

15 February 2008

Software and OS developers should take responsibility for security

While 51% of users say computer security should be the responsibility of the user, nearly a third of users feel it is up to software and OS developers.

15 February 2008

Meta-phishing

Phishing warning contains link to... phishing site.

15 February 2008

Bumper Patch Tuesday short of one patch

Excel remains vulnerable as expected fix is dropped.

13 February 2008

Trend vs. ClamAV patent row hots up

Free software advocates call for boycott of Trend.

13 February 2008

M&S joins high-street AV retail crowd

Upmarket store to match rivals in security software selling.

13 February 2008

Over 1 per cent of search results include malicious sites

Google research paper confirms significant increase in number of malware-serving websites.

12 February 2008

Storm Valentines run under way

Seasonal spam and malware barrage gets going.

12 February 2008

More PDF exploits seen in wild

Adobe Reader and Acrobat flaws open way for further document attacks.

11 February 2008

Live Mail CAPTCHA system bypassed

Spammers use botnet to register accounts on popular free webmail service.

11 February 2008

Complex attack targets Better Business Bureau

Sophisticated scam uses personalised mails, real site redirects.

07 February 2008

FTC fines spammers over $2.5 million

Drug pushers busted for phony claims and CAN-SPAM breaches.

06 February 2008

Yahoo! jukebox flaw exploits in wild

Zero day vulnerability in music system rapidly targeted.

06 February 2008

New security software testing standards body formed

AMTSO to promote cross-industry debate and higher standards in testing.

04 February 2008

419 scammers plead guilty in US

African trio admit attempts to defraud via spam.

04 February 2008

Fake security blogs lead to malware

Blogger sites play on fears to draw victims to porn, trojans.

04 February 2008

February issue of VB published

The February issue of Virus Bulletin is now available for subscribers to download.

01 February 2008

Barracuda battles Trend Micro patent claims

Trend demands licensing for gateway virus scanning idea.

29 January 2008

First virus-writing arrests in Japan

Winny worm authors brought to book - for copyright violation.

29 January 2008

Polyglot worm spreads through MSN

Worm changes language to target wide audience.

24 January 2008

Ledger poisons Google

Actor's death exploited by malware writers to infect computers.

24 January 2008

Symbian worm sighted in the wild

Malware pretends to be media or image file.

23 January 2008

Google links scam Avira users

Suspect firm advertising via Google found to be specialising in hijacking security brands.

21 January 2008

US agencies report vishing, extortion, danger of hacking

FBI name used in email attacks, CIA warns of power supply hacks.

21 January 2008

Malcode from Mexico and Africa predicted to boom

Developing world expected to contribute heavily to future cybercrime.

17 January 2008

Microsoft alert on Excel vulnerability

Targeted exploitation of zero-day flaw seen in wild.

17 January 2008

Help for victims of e-crime

Cybercrime support website launched.

17 January 2008

Stormy love letters

Storm botnet celebrates birthday with new wave of spam.

16 January 2008

Rogue anti-malware targets Mac users

Scam expands horizons to draw in new market of victims.

15 January 2008

Phishing danger increases as Storm botnet is hired out

Smart new trojan and Storm diversification add to online banking risk.

15 January 2008

Hundreds of legitimate websites being hacked into

New mass infection leaves security researchers puzzled.

14 January 2008

Spam printing proof-of-concept revealed

Lack of security allows websites to send spammish content to network printers.

14 January 2008

SQL attack hacks wide range of sites

CA among victims of major attack linking sites to malware.

08 January 2008

Batch of Dutch MP3 players ships with malware

Worm included as unwanted extra for music lovers.

08 January 2008

Usual fare for holiday season

Storm ecards and social site spyware mark unsurprising year end.

08 January 2008

January issue of VB published

The January issue of Virus Bulletin is now available for subscribers to download.

05 January 2008

 

Latest posts:

In memoriam: Prof. Ross Anderson

We were very sorry to learn of the passing of Professor Ross Anderson a few days ago.

In memoriam: Dr Alan Solomon

We were very sorry to learn of the passing of industry pioneer Dr Alan Solomon earlier this week.

New paper: Nexus Android banking botnet – compromising C&C panels and dissecting mobile AppInjects

In a new paper, researchers Aditya K Sood and Rohit Bansal provide details of a security vulnerability in the Nexus Android botnet C&C panel that was exploited in order to gather threat intelligence, and present a model of mobile AppInjects.

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

VB2021 localhost videos available on YouTube

VB has made all VB2021 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.