Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

11 May 2014

Still on Windows XP? Norton and Qihoo 360 can help

The Germany-based AV-Test Institute has found Chinese Internet platform company Qihoo 360's Internet Security 9 and Norton Internet Security 2014 to be the most effective software out of 10 antivirus solutions for protection against Windows XP threats.

Source: Qihoo 360. AV-TEST Report: Exploit Protection on Windows XP

The institute created 54 samples, targeting seven different vulnerabilities, combined with different obfuscation and evasion options as well as different payloads to simulate a wide variety of possible malware attacks. Ten antivirus solutions were tested, including Qihoo 360, Avast, AVG, Avira, Bitdefender, Eset, Kaspersky, and Norton. 

The average block rate among the solutions evaluated was 73.5%. Qihoo 360 and Norton achieved a 100% block rate, detecting/blocking all 54 attacks, while Tencent PC Manager was ranked at the bottom with an 18.5% block rate. 

Microsoft ended support of the Windows XP operating system on April 8, but there are still Windows XP PCs in use. According to Qihoo 360, nearly 20% of PC users are still using Windows XP in China. 

Read the report here

11 March 2014

New McAfee Threats Report identifies two major security challenges

McAfee Labs has released the McAfee Labs Threats Report: Fourth Quarter 2013, highlighting the increased threat from credit card theft. The company also said problem software is increasingly disguised to look legitimate, making the likelihood of getting infected more likely.

Each quarter, the McAfee Labs team of 500 multidisciplinary researchers in 30 countries follows the complete range of threats in real time, identifying application vulnerabilities, analysing and correlating risks, and helping to protect enterprises and the public.  

Detailed research of the high-profile Q4 credit card data breaches found that the point-of-sale (POS) malware used in the attacks were relatively unsophisticated and likely purchased “off the shelf”. McAfee Labs’ ongoing research into underground markets further identified the attempted sale of stolen credit card numbers and personal information known to have been compromised in the Q4 retail breaches. The researchers found the thieves offering for sale some of the 40 million credit card numbers reported stolen in batches of between 1 million and 4 million at a time. 

“The fourth quarter of 2013 will be remembered as the period when cybercrime became ‘real’ for more people than ever before,” said Vincent Weafer, Senior VP for McAfee Labs. “These cyber thefts occurred at a time when most people were focused on their holiday shopping and when the industry wanted people to feel secure and confident in their purchases. The impact of these attacks will be felt both at the kitchen table as well as the boardroom table."

In the fourth quarter alone, McAfee Labs found more than 2.3 million new malicious signed applications, a 52% increase from the previous quarter. The practice of code-signing software validates the identity of the developer who produced the code and ensures the code has not been tampered with since the issue of its digital certificate. The vast majority of growth is due to dubious content development networks (CDNs). These are websites and companies that allow developers to upload their programs, or a URL that links to an external application, and then 'wrap' it in a signed installer. 

“We can see from the threat statistics in the Q4 report that Asia Pacific comes in third place after North America and the Europe-Middle East market, with 8.4% of servers hosting suspect content here,” said Wahab Yusoff, Vice President for McAfee South Asia. 

“Although only a rather small number of suspicious content is hosted in Asia, we should remain vigilant and monitor the situation as cyber attacks don’t know physical borders.” 

The McAfee Labs team warns that the growing number of maliciously signed files could create confusion among users and administrators, and even call into question the continued viability of the long-established certificate authority (CA) model for authenticating “safe” software. 

“Although the expansion of the CA and CDN industries has dramatically lowered the cost of developing and issuing software for developers, the standards for qualifying the identity of the publisher have also decreased dramatically,” said Weafer. 

“We will need to learn to place more trust in the reputation of the vendor that signed the file, and less trust in the simple presence of a certificate.” 

Click here to read the full McAfee Labs Threats Report: Fourth Quarter 2013 report.

16 January 2014

Mobile security to take a hammering in 2014: McAfee Labs

Expect to receive viruses and other nasty things via social platforms like Facebook, Twitter and Instagram, not just through the computer, but also on your phone. McAfee Labs, the global source for threat research, threat intelligence, and cybersecurity thought leadership, expects threats in 2014 to surface in more areas than ever, especially through the mobile platform. 

According to the company's annual 2014 Predictions Report, released end-December 2013, the trends through its proprietary McAfee Global Threat Intelligence (GTI) service point to virtual currencies such as Bitcoin fuelling the growth of ransomware* across all platforms, including mobile.

“With target audiences so large, financing mechanisms so convenient, and cyber-talent so accessible, robust innovation in criminal technology and tactics will continue its surge forward in 2014,” said Vincent Weafer, Senior VP, McAfee Labs. 


McAfee Labs foresees the following trends in 2014:

1. Mobile malware* will drive growth in both technical innovation and the volume of attacks in the overall malware “market” in 2014. In the last two quarters reported, new PC malware growth was nearly flat, while appearances of new Android samples grew by 33%. 


With businesses and consumers continuing their shift to mobile, McAfee Labs expects to see ransomware aimed at mobile devices, attacks targeting near-field communications (NFC) vulnerabilities, and attacks that corrupt valid apps to extract data without being detected.

2. Virtual currencies will fuel malicious ransomware attacks around the world. Virtual currencies provide cybercriminals with a conveniently unregulated and anonymous payment infrastructure through which to collect money from victims. Currencies such as Bitcoin will enable and accelerate new generations of ransomware such as the Cryptolocker threat of 2013.

3. Criminal gangs and state actors will deploy new stealth attacks that will be harder than ever to identify and stop. There will be broad adoption of advanced evasion techniques, such as the use of sandbox*-aware attacks that do not fully deploy unless they believe they are running directly on an unprotected device. 


4.
Social platforms, such as Facebook and Twitter, will be used more aggressively to target the finances and personal information of consumers, and the intellectual property and trade secrets of business leaders. Such information can be used to target advertising or perpetrate virtual or real-world crimes. 

5. In 2014, new PC attacks will exploit application vulnerabilities in HTML5, a standard which allows websites to come alive with interaction, personalisation, and rich capabilities. On the mobile platform, McAfee Labs is predicting attacks that will breach the browser’s “sandbox” and give attackers direct access to the device and its services. Cybercriminals will increasingly target vulnerabilities below* the operating system, in the storage stack and even in the BIOS*.

6. In 2014, security vendors will continue to add new threat-reputation services and analytics tools that will enable them and their users to identify stealth and advanced persistent threats faster and more accurately than can be done today with basic “blacklisting”* and “whitelisting”* technologies.

7. Deployment of cloud-based corporate applications will create new attack surfaces that will be exploited by cybercriminals. Because they lack sufficient leverage to demand security measures in line with their organisational needs, small businesses that purchase cloud-based services will continue to grapple with security risks that are not addressed by cloud providers’ user agreements and operating procedures.

For a full copy of the 2014 Predictions Report from McAfee Labs, click here.  


*There is a lot of functionality 'below' the operating system which controls fundamental activities such as how data is stored onto a drive, how bright your display is, and what the computer does when the power switch is pressed. This is against the activities 'above' the operating system, such as starting up software like Microsoft Office, playing music when music file is clicked, etc.

*BIOS refers to the code that controls the chips on the motherboard.

*Blacklisting avoids everything in the blacklist as it is not approved, whereas whitelisting embraces everything in the whitelist as it is pre-approved.

*Hypervisors control how data is stored on physical machines so as to create what is known as a cloud, where data can be stored and delivered anytime, anywhere, on any device.

*Malware refers to malicious software.

*Ransomware is malicious software that causes a problem which can only be fixed through paying the hackers money.

*Sandboxes separate suspicious software from the existing system. The suspect software is tested in the sandbox, and only introduced into the system if it is found to be harmless.