Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Tags > phishing attack

Stories about: phishing attack


Rogue Certificates Used in Spam Campaigns

After the scandal formed around DigiNotar, spammers send bank business clients emails informing them that their certificates have expired, urging them to click on a link in order to solve the issue. Most internet browsers and applications banned DigiNotar certificates, a fact which created a lot of confusion and ...

19 September 2011
03:36 GMT

Twitter Phishing Attack Uses Weight Loss Video Lure

Security researchers warn of a new phishing attack on Twitter luring users with messages about their weight that claim to include a link leading to a video.The messages are sent from compromised accounts via Twitter's direct message feature and read: "you look like you lost weight in this video.. [LINK]"The link...

4 August 2011
04:53 GMT

In-Game Phishing Attacks Target Modern Warfare 2 Players on Xbox LIVE

Microsoft warns Xbox LIVE users about phishing messages that resemble official notifications and might appear when playing Call of Duty: Modern Warfare 2.The so-called Service Alert was posted on the Xbox LIVE Status page under the "Matchmaking" category. It reads:"Users may experience difficulties with the following...

28 April 2011
08:48 GMT

Lloyds TSB Customers Targeted in New Phishing Attack

A new phishing campaign is targeting customers of Lloyds TSB with fake emails carrying rogue attachments that claim to come from the bank's security team.The emails try to lure in victims by suggesting they have to receive money through their subject that reads "You have an incoming payment."The body text is la...

19 April 2011
05:57 GMT

Phishers Use Facebook Email Account Reservation Lure

A new phishing attack is tricking Facebook users into exposing their login credentials by encouraging them to sign for a new @facebook.com email account.Last November the social networking site announced a new messaging platform that merges email, SMS and Chat into a single "social inbox."The new feature is being rol...

11 March 2011
10:40 GMT

Phishers Target Italian Credit Card Provider CartaSi

Security researchers from German antivirus vendor Avira warn of several phishing scams targeting customers of CartaSi, an Italian credit card provider.There were a total of four attacks, all of them using different lures to trick users into clicking on the phishing URLs.According to Sorin Mustaca, data security exper...

31 January 2011
04:56 GMT

'Look at You' Facebook Wall Posts Lead to Phishing Site

A new phishing attack targeting Facebook users is rapidly spreading via intriguing wall posts that try to lure people onto a fake page.According to Facecrooks, the wall posts read "Check it out here, Look at you haha:P" and are accompanied by an image from a public event.This social engineering trick, whose purpose i...

21 January 2011
13:56 GMT

Brazilian Phishing Scam Targets MasterCard Reward Program

Security researchers warn of a new phishing attack that targets Brazilian credit card owners by spoofing emails from MasterCard's Surpreenda (surprise) program.The new campaign was spotted by spam analysts from Commtouch, who note that unlike classic phishing schemes where users are threatened into exposing thei...

19 January 2011
13:11 GMT

AOL Customers Targeted in New Phishing Attack

A new phishing attack is targeting AOL subscribers by claiming that they need to update their account billing information in order to avoid facing restrictions.The rogue emails have their header spoofed to appear as originating from "AOL Member Billing Services" <AOLMemberServices@mail.aol.com> and bear a s...

5 January 2011
08:28 GMT

Mobile Users More Susceptible to Phishing

According to an investigation performed by Trusteer, a provider of secure browsing solutions, mobile users are three times more likely to fall victim to phishing attacks.The company's researchers analyzed the access log of several Web servers that hosted phishing websites recently and got some very interesting r...

5 January 2011
02:59 GMT

New Twitter Phish Employs Wrong User/Pass Trick

Security researchers warn of a new phishing attack on Twitter, which tricks users into exposing their credentials by displaying a fake error message about a wrong username and password combination.The attack starts with a direct message sent from compromised accounts, which reads "You have to be the first to see thes...

9 October 2010
08:39 GMT

XSS Flaw Found on Secure American Express Site

A cross-site scripting (XSS) vulnerability has been identified on an American Express website secured with EV SSL and can be exploited to enhance phishing attacks.XSS weaknesses are the result of poor input validation into Web forms and allow attackers to return potentially malicious code to visitors' browsers.E...

5 October 2010
08:00 GMT

Phishers Target WoW Players Through In-Game Mail System

Security researchers from Trend Micro warn that World of Warcraft players are being targeted through the game's internal mail system by phishers looking to steal their Battle.net credentials.World of Warcraft (WoW) is the world's most popular massively multiplayer online role-playing game (MMORPG), with ove...

29 September 2010
10:21 GMT

XSS Weakness Found on Visa USA Website

A cross-site scripting (XSS) vulnerability, which could be used to enhance phishing and other attacks, has been identified on the usa.visa.com website.The weakness was reported yesterday to the XSSed Project by a security researcher, who goes by the online handle of d3v1l.D3v1l's track record involves finding si...

20 September 2010
07:44 GMT

Commonwealth Bank Phishing via DNS Hijacking Trojan

Security researchers from Sophos warn of an unusual phishing attack targeting Commonwealth Bank customers, which makes use of a DNS hijacking trojan to steal login details. The attack starts with spam emails abusing a real Commonwealth Bank email template, which includes the organization's logo, copyright notic...

17 September 2010
15:54 GMT

Facebook Chat Spam Directs Users to Phishing Site

Phishers are trying to steal login credentials from Facebook users by spamming them with malicious links through the social network's chat system. The new campaign abusing the Facebook chat feature has been spotted by security researchers from antivirus vendor Trend Micro.The rogue messages coming from compromis...

17 September 2010
11:34 GMT

Researchers Uncover Public Cache of Stolen Facebook Logins

While investigating a basic phishing attack, security researchers from GFI Sunbelt have discovered a public cache containing almost 3,000 stolen Facebook credentials.Sunbelt researcher Christopher Boyd was looking into a rudimentary FarmVille phish, consisting of a blank a plain HTML with only a username/password for...

16 September 2010
01:15 GMT

Skype-Themed Phishing Campaign in Circulation

Researchers from Web and email security vendor Websense warn of a new phishing attack, which tricks users into divulging their and personal information and credit card details by promising fictitious Skype upgrade.The rogue emails have been hitting the security company's spam traps by the thousands and bear a su...

14 September 2010
09:52 GMT

Facebook Misguided Feature Can Enhance Phishing Attacks

A Facebook feature, which displays the profile matching an email address used in a failed login attempt can be leveraged by phishers to increase the credibility of their scams.In a new example of Facebook features being designed with complete disregard for security, whenever a bad password is provided during authenti...

11 August 2010
08:38 GMT

URL Shortners Increasingly Used in Spam

Security researchers from German antivirus vendor Avira, warn that the use of URL shortening services in spam is on an ascending trend. According to data gathered by the company, tinyurl.com is the most abused URL shortner when it comes to phishing attacks, while k.im is preferred for malware distribution.Created in ...

19 July 2010
12:11 GMT

Twitter Starts Filtering Malicious URLs in Direct Messages

Twitter has announced that URLs posted via Direct Messages will be screened by a new service, which blocks phishing and other attacks. The links are automatically shortened to a twt.tl form, so that they can be blocked at any point in the future.Twitter was recently confronted with a wave of highly successful phishin...

10 March 2010
10:38 GMT

Phishing Attacks Continue to Decrease in Number

After the number of phishing attacks drastically declined by 45% in August, the trend continued during September according to Symantec. United States remains the country hosting the most phishing sites, which increased in number due to a lower usage of automated toolkits.Symantec's State of Phishing monthly repo...

12 October 2009
06:33 GMT

New Phishing Attack Features Live Chat

Security researchers have identified what is probably the first case of a phishing scheme including a live-chat component. The attackers pose as bank representatives and try to talk their victims into disclosing their personal information. The new scam was discovered by researchers from the RSA FraudAction Research ...

17 September 2009
06:39 GMT

Tax Refund Scam Targets British Taxpayers

Phishers have launched an e-mail campaign that attempts to trick UK taxpayers into handing out their financial and personal details. The emails are spoofed to appear as being sent by the HM Revenue & Customs (HMRC) and display legit contact details to increase their credibility. "After the annual calculation of your...

6 July 2009
06:56 GMT

Multiple Visa Websites XSSed

Self-confessed ethical hacking outfit Team Elite has recently reported cross-site scripting (XSS) weaknesses in not one, but four different Visa websites. All of the vulnerabilities allowed attackers to prompt arbitrary JavaScript alerts. The XSS vulnerabilities were reported by a grey-hat hacker calling himself Met...

27 May 2009
08:17 GMT

RBS WorldPay Website Vulnerable to Phishing Attacks

A cross-site scripting vulnerability discovered in the website of RBS WorldPay allows attackers to launch efficient phishing attacks against customers. The same flaw can also be exploited to serve malware or prompt rogue alerts. The XSS weakness has been discovered and documented by a Team Elite member, going by the...

23 May 2009
06:22 GMT

Romanian Police Takes Down Cybercriminal Gang

The Romanian Police, together with D.I.I.C.O.T. (the Direction for Investigating Organized Crime and Terrorism), has executed an ample operation that has targeted hackers in the western part of the country. Between 15 and 20 persons have been arrested in the cities of Caransebeş, Lugoj, Timişoara, Hunedoara and Piteş...

13 March 2009
08:10 GMT

iStockphoto Hit by Phishers

The popular photo library iStockphoto has been targeted by cyber-criminals, who have launched a phishing attack on the website's forums and user e-mail service. The attack has been blocked, but users are advised to change their account password. iStockphoto is considered the pioneer of a concept known as micros...

5 March 2009
05:22 GMT

SSL Security Broken

A group of researchers from Europe and U.S. have successfully implemented a theoretical attack that subverts the security of the HTTPS protocol. The hackers generated a rogue Certification Authority (CA) certificate that was trusted by all major browsers and could be used to impersonate any secure website. In a coord...

30 December 2008
11:07 GMT

7 Years in Prison for AOL Phisher

A 24-year-old man from Connecticut was convicted to seven years in prison for scamming AOL subscribers, which resulted in damages in excess of $400,000. Over 250 people are reported to have lost important amounts of money because of several phishing attacks coordinated by Dolan. The seven-year penalty was the maximum...

14 August 2008
05:48 GMT


WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM