<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/spam" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Spam ]]></title>
                <link>https://www.itpro.com/tag/spam</link>
        <description><![CDATA[ All the latest spam content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 15 Sep 2017 11:14:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Malicious WordPress plugin installed backdoor on thousands of websites ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hackers have used a WordPress plugin to install backdoors on up to 200,000 websites, allowng spam to be uploaded onto unsuspecting websites. </p><p>According to <a href="https://www.wordfence.com/blog/2017/09/display-widgets-malware">research</a> carried out by IT security firm WordFence, the plugin, known as Display Widgets, should be removed immediately by website owners. The firm said that the last three releases of the plugin have contained code that allows the author to publish any content on an affected site.</p><p>"The authors of this plugin have been using the backdoor to publish spam content to sites running their plugin. During the past three months the plugin has been removed and readmitted to the WordPress.org plugin repository a total of four times," said Mark Maunder, CEO of WordFence. </p><p>Maunder said that the plugin was originally developed by its original author as an open-source plugin but was then sold to others on 21 June. An updated version, 2.6.0 was released by its new owner immediately. WordFence was informed by David Law, a UK based SEO consultant, that the widget had begin installing additional code and then started downloading data from Law's on server.</p><p>On 23 June, WordFence removed Display Widget, and a week later, the new owner released version 2.6.1 of the plugin. This release contained a file called geolocation.php which, no one realised at the time, contained malicious code. This code allowed the plugin author to post new content to any website running the plugin, to a URL of their choosing. </p><p>"Furthermore, the malicious code prevented any logged-in user from seeing the content. In other words, site owners would not see the malicious content. David Law again contacted the plugin team and let them know that the plugin is logging visits to each website to an external server, which has privacy implications," said Maunder.</p><p>On 1 July, the plugin was pulled from the WordPress repository, but then followed by version 2.6.2 on 6 July. Again, included the malicious code referenced above which had still gone unnoticed by anyone. </p><p>It was on 23 July when a user, by the name of Calvin Ngan <a href="https://core.trac.wordpress.org/ticket/41414" target="_blank">opened a Trac ticket reporting</a> that Display Widgets was injecting spammy content into his website. He included a link to Google results that had indexed the spam and said the malicious code is in geolocation.php.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/633661/wordpress-drops-ie6-support" data-original-url="/633661/wordpress-drops-ie6-support">WordPress drops IE6 support</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/97589/spam-at-epic-levels" data-original-url="/97589/spam-at-epic-levels">Spam at epic levels</a></p></div></div><p>In September, version 2.6.3 of the plugin was released and it included the same malicious code. Last week, a forum user on WordPress.org <a href="https://wordpress.org/support/topic/payday-loans-seo-spam/#post-9478878" target="_blank">reported</a> that spam has been injected into their website on the Display Widgets plugin support forum. </p><p>"The authors of the plugin are actively maintaining their malicious code, switching between sources for spam and working to obfuscate (hide) the domain they are fetching spam from," said Maunder.</p><p>The widget was removed permanentely on 8 September, but Maunder tracked down the plugin's new buyer to a service called WP Devs, which buys old and abandoned plugins.</p><p>His investigations found that the company appears to be run by one person in the US and possibly another in Eastern Europe, judging by linguistic errors made by the poster.</p><p>Maunder said that people in the WordPress community should not "start any witch hunts". </p><p>"Occasionally plugins change ownership and very rarely, that doesn't go well. That appears to be what happened in this case," he said.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/29486/malicious-wordpress-plugin-installed-backdoor-on-thousands-of-websites</link>
                                                                            <description>
                            <![CDATA[ Widget plugin spewed spam to unsuspecting victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q3MJZyGCg2V47nzCesEPaT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FkTDJSeCMXjKpVbRSuNXvm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Sep 2017 11:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FkTDJSeCMXjKpVbRSuNXvm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FkTDJSeCMXjKpVbRSuNXvm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have used a WordPress plugin to install backdoors on up to 200,000 websites, allowng spam to be uploaded onto unsuspecting websites. </p><p>According to <a href="https://www.wordfence.com/blog/2017/09/display-widgets-malware">research</a> carried out by IT security firm WordFence, the plugin, known as Display Widgets, should be removed immediately by website owners. The firm said that the last three releases of the plugin have contained code that allows the author to publish any content on an affected site.</p><p>"The authors of this plugin have been using the backdoor to publish spam content to sites running their plugin. During the past three months the plugin has been removed and readmitted to the WordPress.org plugin repository a total of four times," said Mark Maunder, CEO of WordFence. </p><p>Maunder said that the plugin was originally developed by its original author as an open-source plugin but was then sold to others on 21 June. An updated version, 2.6.0 was released by its new owner immediately. WordFence was informed by David Law, a UK based SEO consultant, that the widget had begin installing additional code and then started downloading data from Law's on server.</p><p>On 23 June, WordFence removed Display Widget, and a week later, the new owner released version 2.6.1 of the plugin. This release contained a file called geolocation.php which, no one realised at the time, contained malicious code. This code allowed the plugin author to post new content to any website running the plugin, to a URL of their choosing. </p><p>"Furthermore, the malicious code prevented any logged-in user from seeing the content. In other words, site owners would not see the malicious content. David Law again contacted the plugin team and let them know that the plugin is logging visits to each website to an external server, which has privacy implications," said Maunder.</p><p>On 1 July, the plugin was pulled from the WordPress repository, but then followed by version 2.6.2 on 6 July. Again, included the malicious code referenced above which had still gone unnoticed by anyone. </p><p>It was on 23 July when a user, by the name of Calvin Ngan <a href="https://core.trac.wordpress.org/ticket/41414" target="_blank">opened a Trac ticket reporting</a> that Display Widgets was injecting spammy content into his website. He included a link to Google results that had indexed the spam and said the malicious code is in geolocation.php.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/633661/wordpress-drops-ie6-support" data-original-url="/633661/wordpress-drops-ie6-support">WordPress drops IE6 support</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/97589/spam-at-epic-levels" data-original-url="/97589/spam-at-epic-levels">Spam at epic levels</a></p></div></div><p>In September, version 2.6.3 of the plugin was released and it included the same malicious code. Last week, a forum user on WordPress.org <a href="https://wordpress.org/support/topic/payday-loans-seo-spam/#post-9478878" target="_blank">reported</a> that spam has been injected into their website on the Display Widgets plugin support forum. </p><p>"The authors of the plugin are actively maintaining their malicious code, switching between sources for spam and working to obfuscate (hide) the domain they are fetching spam from," said Maunder.</p><p>The widget was removed permanentely on 8 September, but Maunder tracked down the plugin's new buyer to a service called WP Devs, which buys old and abandoned plugins.</p><p>His investigations found that the company appears to be run by one person in the US and possibly another in Eastern Europe, judging by linguistic errors made by the poster.</p><p>Maunder said that people in the WordPress community should not "start any witch hunts". </p><p>"Occasionally plugins change ownership and very rarely, that doesn't go well. That appears to be what happened in this case," he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 711 million data records revealed in spambot dump ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A huge spam list composed of 711 million records was uncovered last week in the Netherlands.</p><p>Troy Hunt, founder of <a href="https://haveibeenpwned.com" target="_blank">Have I been pwned? (HIBP)</a>, was notified of the list through <a href="https://benkowlab.blogspot.co.uk" target="_blank">Benkow mouq</a>, a malware hunter, and added it to his website so that users can check if their details are in the list.</p><p>In a <a href="https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump" target="_blank">blog post</a>, Hunt explains how the 711 million records are the largest data set he has loaded into HIBP. He claims: "...that's almost one address for every single man, woman, and child in all of Europe."</p><p>Hunt said: "The gap I want to fill here is to explain what I can about the data because there'll be a very large number of people finding themselves on HIBP and wondering what on earth is going on."</p><p>He outlines that the listing contains "masses and masses" of email addresses which are used to deliver spam to. He said that "a single file may contain tens or even hundreds of millions of addresses."</p><p>In some cases, there are even email addresses and passwords. Hunt's own email address appears in the records twice.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/902614543884361729"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/902614543884361729"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>However, even though there are 711 million email addresses, the number of real humans in the data is less as some of the emails have "junk", such as an HTML file name, prefixed to the address. Hunt suggests parsing wasn't done very well because of this.</p><p>Hunt also found email addresses which had passwords paired with them. He randomly selected a dozen email addresses, checked them against HIBP, and found that all of them had been exposed in the <a href="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale" target="_blank" data-original-url="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale">LinkedIn data breach</a>.</p><p>Hunt encountered data from the <a href="https://www.itpro.com/security/28607/breach-site-finds-1-billion-accounts-in-hacked-datasets" target="_blank" data-original-url="https://www.itpro.com/security/28607/breach-site-finds-1-billion-accounts-in-hacked-datasets">Exploit.In combo list</a>. "A similar file (with a similar naming structure) contains 4.2 million email address and password pairs, this time with every single account having a hit on the massive Exploit.In combo list," he said. "This should give you an appreciation of how our data is redistributed over and over again once it's out there in the public domain."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale" data-original-url="/security/26572/117m-linkedin-account-details-for-sale">117m LinkedIn account details for sale</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack" data-original-url="/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack">Reddit resets 100,000 passwords in wake of LinkedIn hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27290/how-to-check-if-youve-been-hacked" data-original-url="/security/27290/how-to-check-if-youve-been-hacked">How to check if you've been hacked</a></p></div></div><p>One file contains over 3,000 records with email, password, SMTP server and port which Hunt says gives spammers a range of mail servers to send their messages from.</p><p>Hunt highlighted the breadth of this breach: "It took HIBP 110 data breaches over a period of two and a half years to accumulate 711m addresses and here we go, in one fell swoop, with that many concentrated in a single location. It's a mind-boggling amount of data."</p><p>The largest data set which Hunt had uploaded into the website prior to this was the 393 million records from River City Media in January 2017.</p><p>The IP address of the spambot is based in the Netherlands and Hunt and Benkow have been communicating with authorities in order to get it shut down.</p><p>Hunt suggests checking HIBP to see whether you have been affected.</p><p>It also emerged today that <a href="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack" target="_blank" data-original-url="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack">two million customers were hit by a CeX hack</a>. CeX told customers last night that it had been hacked and personal details, such as name, email address, phone number and in some cases passwords, had been accessed. CeX advises customers to change their login details as soon as they can.</p><p><em>Image source: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/29348/711-million-data-records-revealed-in-spambot-dump</link>
                                                                            <description>
                            <![CDATA[ The data contains email addresses, passwords and server information too ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jWFa1ZwjS6dM2PXBiEWJRW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uyJUqCCx2b6CWknyB655AB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Aug 2017 11:26:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uyJUqCCx2b6CWknyB655AB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uyJUqCCx2b6CWknyB655AB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A huge spam list composed of 711 million records was uncovered last week in the Netherlands.</p><p>Troy Hunt, founder of <a href="https://haveibeenpwned.com" target="_blank">Have I been pwned? (HIBP)</a>, was notified of the list through <a href="https://benkowlab.blogspot.co.uk" target="_blank">Benkow mouq</a>, a malware hunter, and added it to his website so that users can check if their details are in the list.</p><p>In a <a href="https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump" target="_blank">blog post</a>, Hunt explains how the 711 million records are the largest data set he has loaded into HIBP. He claims: "...that's almost one address for every single man, woman, and child in all of Europe."</p><p>Hunt said: "The gap I want to fill here is to explain what I can about the data because there'll be a very large number of people finding themselves on HIBP and wondering what on earth is going on."</p><p>He outlines that the listing contains "masses and masses" of email addresses which are used to deliver spam to. He said that "a single file may contain tens or even hundreds of millions of addresses."</p><p>In some cases, there are even email addresses and passwords. Hunt's own email address appears in the records twice.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/902614543884361729"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/902614543884361729"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>However, even though there are 711 million email addresses, the number of real humans in the data is less as some of the emails have "junk", such as an HTML file name, prefixed to the address. Hunt suggests parsing wasn't done very well because of this.</p><p>Hunt also found email addresses which had passwords paired with them. He randomly selected a dozen email addresses, checked them against HIBP, and found that all of them had been exposed in the <a href="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale" target="_blank" data-original-url="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale">LinkedIn data breach</a>.</p><p>Hunt encountered data from the <a href="https://www.itpro.com/security/28607/breach-site-finds-1-billion-accounts-in-hacked-datasets" target="_blank" data-original-url="https://www.itpro.com/security/28607/breach-site-finds-1-billion-accounts-in-hacked-datasets">Exploit.In combo list</a>. "A similar file (with a similar naming structure) contains 4.2 million email address and password pairs, this time with every single account having a hit on the massive Exploit.In combo list," he said. "This should give you an appreciation of how our data is redistributed over and over again once it's out there in the public domain."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale" data-original-url="/security/26572/117m-linkedin-account-details-for-sale">117m LinkedIn account details for sale</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack" data-original-url="/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack">Reddit resets 100,000 passwords in wake of LinkedIn hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27290/how-to-check-if-youve-been-hacked" data-original-url="/security/27290/how-to-check-if-youve-been-hacked">How to check if you've been hacked</a></p></div></div><p>One file contains over 3,000 records with email, password, SMTP server and port which Hunt says gives spammers a range of mail servers to send their messages from.</p><p>Hunt highlighted the breadth of this breach: "It took HIBP 110 data breaches over a period of two and a half years to accumulate 711m addresses and here we go, in one fell swoop, with that many concentrated in a single location. It's a mind-boggling amount of data."</p><p>The largest data set which Hunt had uploaded into the website prior to this was the 393 million records from River City Media in January 2017.</p><p>The IP address of the spambot is based in the Netherlands and Hunt and Benkow have been communicating with authorities in order to get it shut down.</p><p>Hunt suggests checking HIBP to see whether you have been affected.</p><p>It also emerged today that <a href="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack" target="_blank" data-original-url="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack">two million customers were hit by a CeX hack</a>. CeX told customers last night that it had been hacked and personal details, such as name, email address, phone number and in some cases passwords, had been accessed. CeX advises customers to change their login details as soon as they can.</p><p><em>Image source: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple fixes its spammy calendar with Report Junk feature ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple has introduced a 'Report Junk' feature that addresses the spam issue users have encountered in their iCloud calendars, according to <a href="https://9to5mac.com/2016/12/11/apple-rolling-out-report-junk-feature-for-icloud-calendar-invites-from-unknown-senders-to-address-spam" target="_blank"><em>9to5Mac</em></a>.</p><p>Over the past few weeks, Apple users have reported that invites to spam events were randomly appearing on their iCloud calendars.</p><p>These spam invites, usually sent from email addresses with Chinese names, were advertising deals on products such as Ray-Ban sunglasses or Ugg boots.</p><p>This issue originated from spam emails, as Apple's devices automatically scanned users' inboxes and notified them of calendar invitations present inside.</p><p>Users were therefore notified of these invites promoting sales, present within spam emails that had made their way into their inbox.</p><p>The new 'Report Junk' option can currently only be accessed through the iCloud calendar web app, but according to <em>9to5Mac</em>, Apple might extend this feature to both iOS and Mac-based Calendar apps in upcoming updates.</p><p>Users who wish to delete and report a spam invite can go to iCloud.com, log in using their Apple ID, click on the invite in question and flag it by clicking Report Junk.</p><p>The option is only available for calendar invites from senders who are not within a user's contact list.</p><p><strong>01/12/2016: Apple apologises for calendar spam</strong></p><p>Apple has apologised for an issue with its Calendar app that led to iCloud users being spammed with events related to supposed Black Friday deals on products such as Ray-Ban glasses, Uggs Boots or Pandora bracelets.</p><p>The issue originated from spam emails, as Apple's iOS and MacOS operating systems scan users' inboxes and notify them of any calendar invitations.</p><p>The idea behind the feature is that users will automatically have events mentioned in emails noted down on their calendar, but in this case spam messages advertising sales of counterfeit consumer products have also been automatically generating invitations.</p><p>Some users also received spam invitations to edit reminders or view photo groups.</p><p>In a <a href="https://twitter.com/reneritchie/status/804081476904042496" target="_blank">statement</a> sent to Rene Ritchie, editorial director of the news blog iMore, Apple wrote: "We are sorry that some of our users are receiving spam calendar invitations. We are actively working to address this issue by identifying and blocking suspicious senders and spam in the invites being sent."</p><p>There is currently no way of only blocking these specific messages on iOS and MacOS, but users can get rid of them by blocking automatic in-app Calendar notifications.</p><p><strong>How to get rid of spam calendar events notifications</strong> 1. Go to iCloud.com and login to your account2. Go to the calendar section3. Click on the cog button on the bottom left corner and then on Advanced4. Change Invitations from 'In-app notifications' to 'Email to..'</p><p>This will ensure you receive calendar invites as emails other than notifications within the Calendar app.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27300/an-ios-10-flaw-exposes-your-backed-up-iphone-data-to-hackers" data-original-url="/hacking/27300/an-ios-10-flaw-exposes-your-backed-up-iphone-data-to-hackers">An iOS 10 flaw exposes your backed up iPhone data to hackers</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/macs/27695/apple-fixes-its-spammy-calendar-with-report-junk-feature</link>
                                                                            <description>
                            <![CDATA[ The new option lets you block spam iCloud calendar invites ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b3tXy33hQYQNe4MKL57tS7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rqwgULYjNkg765Gh5vQEUE-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 12 Dec 2016 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ingrid Fadelli ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/rqwgULYjNkg765Gh5vQEUE-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rqwgULYjNkg765Gh5vQEUE-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has introduced a 'Report Junk' feature that addresses the spam issue users have encountered in their iCloud calendars, according to <a href="https://9to5mac.com/2016/12/11/apple-rolling-out-report-junk-feature-for-icloud-calendar-invites-from-unknown-senders-to-address-spam" target="_blank"><em>9to5Mac</em></a>.</p><p>Over the past few weeks, Apple users have reported that invites to spam events were randomly appearing on their iCloud calendars.</p><p>These spam invites, usually sent from email addresses with Chinese names, were advertising deals on products such as Ray-Ban sunglasses or Ugg boots.</p><p>This issue originated from spam emails, as Apple's devices automatically scanned users' inboxes and notified them of calendar invitations present inside.</p><p>Users were therefore notified of these invites promoting sales, present within spam emails that had made their way into their inbox.</p><p>The new 'Report Junk' option can currently only be accessed through the iCloud calendar web app, but according to <em>9to5Mac</em>, Apple might extend this feature to both iOS and Mac-based Calendar apps in upcoming updates.</p><p>Users who wish to delete and report a spam invite can go to iCloud.com, log in using their Apple ID, click on the invite in question and flag it by clicking Report Junk.</p><p>The option is only available for calendar invites from senders who are not within a user's contact list.</p><p><strong>01/12/2016: Apple apologises for calendar spam</strong></p><p>Apple has apologised for an issue with its Calendar app that led to iCloud users being spammed with events related to supposed Black Friday deals on products such as Ray-Ban glasses, Uggs Boots or Pandora bracelets.</p><p>The issue originated from spam emails, as Apple's iOS and MacOS operating systems scan users' inboxes and notify them of any calendar invitations.</p><p>The idea behind the feature is that users will automatically have events mentioned in emails noted down on their calendar, but in this case spam messages advertising sales of counterfeit consumer products have also been automatically generating invitations.</p><p>Some users also received spam invitations to edit reminders or view photo groups.</p><p>In a <a href="https://twitter.com/reneritchie/status/804081476904042496" target="_blank">statement</a> sent to Rene Ritchie, editorial director of the news blog iMore, Apple wrote: "We are sorry that some of our users are receiving spam calendar invitations. We are actively working to address this issue by identifying and blocking suspicious senders and spam in the invites being sent."</p><p>There is currently no way of only blocking these specific messages on iOS and MacOS, but users can get rid of them by blocking automatic in-app Calendar notifications.</p><p><strong>How to get rid of spam calendar events notifications</strong> 1. Go to iCloud.com and login to your account2. Go to the calendar section3. Click on the cog button on the bottom left corner and then on Advanced4. Change Invitations from 'In-app notifications' to 'Email to..'</p><p>This will ensure you receive calendar invites as emails other than notifications within the Calendar app.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27300/an-ios-10-flaw-exposes-your-backed-up-iphone-data-to-hackers" data-original-url="/hacking/27300/an-ios-10-flaw-exposes-your-backed-up-iphone-data-to-hackers">An iOS 10 flaw exposes your backed up iPhone data to hackers</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts uncover Tinder porn site spam scheme ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Security experts have spotted a Tinder scam that tricks users into signing up for porn site membership in exchange for 'verification'.</p><p>The scam, identified by <a href="http://www.symantec.com/connect/blogs/tinder-safe-dating-spam-uses-safety-scam-users-out-money" target="_blank">cyber security firm Symantec</a>, uses chatbots to initiate conversations with the dating app's male users. After luring victims in with witty banter, the bots ask them if they are "verified by Tinder".</p><p>Note that this is separate to Twitter-style 'blue tick' verification, which Tinder launched last year for celebrities and public figures. Instead, the bots explain that this verification is "a free service tinder put up, to verify the person you wanna meet isn't a serial killer lol".</p><p>Victims are directed to an external site, which uses copycat formatting, fonts and logos of Tinder's branding. It promises that after completing the verification form, users will receive a code that they can send to their match for confirmation.</p><p>The verification form is, perhaps unsurprisingly, a scam. After providing a user name, password and email, victims must 'verify their age' using a credit card.</p><p>The site proudly proclaims that there is "no charge to become verified", but included at the bottom of the page is fine print revealing that unless they specifically uncheck the box, they are opting in to "special FREE bonus offer".</p><p>This 'bonus offer' consists of memberships to porn and explicit webcam sites, which have a total value of 118.76. These sites operate on an affiliate model, which means that the scammers receive a cut of the membership fees for every user they bring to it.</p><p>"Scammers are naturally attracted to large online communities and the surge in online dating amongst millennials makes these sites a prime target," said Nick Shaw, Norton's EMEA vice president and general manager.</p><p>"In the online world, as with anything in life, people aren't always what they seem," he said. "Therefore it's important that you are vigilant so you can enjoy dating online without placing yourself in a vulnerable position."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/26978/security-experts-uncover-tinder-porn-site-spam-scheme</link>
                                                                            <description>
                            <![CDATA[ Chatbots use verification offers to lure in victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kbbp8Yh5vHmGgPdM8y6K3m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CAAdYpBxSPS2dTTKtxv6pd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Jul 2016 14:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CAAdYpBxSPS2dTTKtxv6pd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CAAdYpBxSPS2dTTKtxv6pd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have spotted a Tinder scam that tricks users into signing up for porn site membership in exchange for 'verification'.</p><p>The scam, identified by <a href="http://www.symantec.com/connect/blogs/tinder-safe-dating-spam-uses-safety-scam-users-out-money" target="_blank">cyber security firm Symantec</a>, uses chatbots to initiate conversations with the dating app's male users. After luring victims in with witty banter, the bots ask them if they are "verified by Tinder".</p><p>Note that this is separate to Twitter-style 'blue tick' verification, which Tinder launched last year for celebrities and public figures. Instead, the bots explain that this verification is "a free service tinder put up, to verify the person you wanna meet isn't a serial killer lol".</p><p>Victims are directed to an external site, which uses copycat formatting, fonts and logos of Tinder's branding. It promises that after completing the verification form, users will receive a code that they can send to their match for confirmation.</p><p>The verification form is, perhaps unsurprisingly, a scam. After providing a user name, password and email, victims must 'verify their age' using a credit card.</p><p>The site proudly proclaims that there is "no charge to become verified", but included at the bottom of the page is fine print revealing that unless they specifically uncheck the box, they are opting in to "special FREE bonus offer".</p><p>This 'bonus offer' consists of memberships to porn and explicit webcam sites, which have a total value of 118.76. These sites operate on an affiliate model, which means that the scammers receive a cut of the membership fees for every user they bring to it.</p><p>"Scammers are naturally attracted to large online communities and the surge in online dating amongst millennials makes these sites a prime target," said Nick Shaw, Norton's EMEA vice president and general manager.</p><p>"In the online world, as with anything in life, people aren't always what they seem," he said. "Therefore it's important that you are vigilant so you can enjoy dating online without placing yourself in a vulnerable position."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Outlook and Hotmail email accounts hit by spam attack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has apparently now fixed an issue with its Hotmail and Outlook spam filters that meant its users were being flooded with spam emails.</p><p>The company admitted on its support page that it had uncovered a problem, saying, "Some users may be receiving excessive spam mail," although it would not reveal exactly what went wrong.</p><p>Shortly after releasing the update on its service page, Microsoft rolled out updates to Hotmail and Outlook that fixed the filters and its own infrastructure to prevent it happening again.</p><p>"One will provide short term relief preventing spam reaching your inbox," reveals Microsoft. "The second will be a longer term fix which should stop spam reaching our infrastructure," the company explained.</p><p>The problems went on for around 17 hours according to users, which certainly left a bad taste in thier mouths. As expected, annoyed users posted messages of frustration on social media, ensuring Microsoft and their friends and followers knew of the problems.</p><p><a href="https://twitter.com/imbeingerica/status/737943818218143744?ref_src=twsrc%5Etfw">Erica Jean</a> wrote on Twitter: "HEY <a href="https://twitter.com/Outlook">@Outlook</a> <a href="https://twitter.com/hotmail">@hotmail</a> WHAT IS GOING ON WITH THE SPAM EMAILS TODAY? I've had almost 60 overnight and they're NOT GOING AWAY," while other users seemed to be in competition to announce how many spam emails they had received.</p><p>However, some users saw the lighter side of being spammed by spam.</p><p>"Look at all of these great deals I've been missing out on for years," <a href="https://www.reddit.com/user/peck_ed">Peck Ed wrote on Reddit</a>. "Now if you chaps will excuse me, I'm off to become a... millionaire getting a great deal on my car insurance with my new Russian bride at the Casino with my free bets."</p><p>Jonathan Lakeman joked on Twitter: "Thanks to <a href="https://twitter.com/hotmail">@hotmail</a> the only genuine e-mail I got all day was from my desolate Nigerian Uncle (I didn't know I had). <a href="https://twitter.com/hashtag/slamdunkthejunk?src=hash">#slamdunkthejunk</a> <a href="https://twitter.com/hashtag/spam?src=hash">#spam</a>."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/email-delivery/26659/outlook-and-hotmail-email-accounts-hit-by-spam-attack</link>
                                                                            <description>
                            <![CDATA[ Users were bombarded by spam emails apparently because Microsoft's spam filters weren't working properly ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4TWY8kgxC4WpVE8P4DZfAG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZmySkqeVBcCvcJot88Ns3k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jun 2016 07:42:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Email Providers]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZmySkqeVBcCvcJot88Ns3k-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[spam]]></media:description>                                                            <media:text><![CDATA[spam]]></media:text>
                                <media:title type="plain"><![CDATA[spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZmySkqeVBcCvcJot88Ns3k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has apparently now fixed an issue with its Hotmail and Outlook spam filters that meant its users were being flooded with spam emails.</p><p>The company admitted on its support page that it had uncovered a problem, saying, "Some users may be receiving excessive spam mail," although it would not reveal exactly what went wrong.</p><p>Shortly after releasing the update on its service page, Microsoft rolled out updates to Hotmail and Outlook that fixed the filters and its own infrastructure to prevent it happening again.</p><p>"One will provide short term relief preventing spam reaching your inbox," reveals Microsoft. "The second will be a longer term fix which should stop spam reaching our infrastructure," the company explained.</p><p>The problems went on for around 17 hours according to users, which certainly left a bad taste in thier mouths. As expected, annoyed users posted messages of frustration on social media, ensuring Microsoft and their friends and followers knew of the problems.</p><p><a href="https://twitter.com/imbeingerica/status/737943818218143744?ref_src=twsrc%5Etfw">Erica Jean</a> wrote on Twitter: "HEY <a href="https://twitter.com/Outlook">@Outlook</a> <a href="https://twitter.com/hotmail">@hotmail</a> WHAT IS GOING ON WITH THE SPAM EMAILS TODAY? I've had almost 60 overnight and they're NOT GOING AWAY," while other users seemed to be in competition to announce how many spam emails they had received.</p><p>However, some users saw the lighter side of being spammed by spam.</p><p>"Look at all of these great deals I've been missing out on for years," <a href="https://www.reddit.com/user/peck_ed">Peck Ed wrote on Reddit</a>. "Now if you chaps will excuse me, I'm off to become a... millionaire getting a great deal on my car insurance with my new Russian bride at the Casino with my free bets."</p><p>Jonathan Lakeman joked on Twitter: "Thanks to <a href="https://twitter.com/hotmail">@hotmail</a> the only genuine e-mail I got all day was from my desolate Nigerian Uncle (I didn't know I had). <a href="https://twitter.com/hashtag/slamdunkthejunk?src=hash">#slamdunkthejunk</a> <a href="https://twitter.com/hashtag/spam?src=hash">#spam</a>."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Spammers selling fake tickets for Rio Olympics 2016 ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Scammers have been selling fake tickets to the 2016 Olympic Games in Rio De Janiero for more than a year in advance of the opening ceremony, Kaspersky Lab has found.</p><p>In its report on spam and phishing for Q1 2016, released today, the cybersecurity firm found fraudsters have been using a variety of methods to trick sports fans into giving over their personal and financial details.</p><p>As with any major cultural or sporting event, some spammers are attempting to fool users into thinking that they have won free tickets in a lottery draw, organised by the Brazilian government or the International Olympic Committee.</p><p>However, some enterprising cybercriminals have stepped their efforts up, creating bogus ticketing websites to harvest payment information.</p><p>These sites can be surprisingly sophisticated, with some even purchasing SSL certificates in order to appear more legitimate.</p><p>SSL is an encryption method that can prevent hackers from intercepting traffic to an otherwise trustworthy site, but is meaningless if the site is owned and operated by the hackers themselves.</p><p>"The creation of these sites is normally carried out by gangs, which split individual tasks among each other," said Kaspersky Labs' head of UK retail, David Mole.</p><p>"For example, one group may be responsible for setting up the fake website's domain, and the other may be responsible for creating the actual website."</p><p>"It's no surprise that cybercriminals are using the Olympic Games as a ploy to extort money and personal information from unsuspecting recipients," Mole said.</p><p>"We recommend that fans everywhere be very cautious when purchasing tickets or souvenirs. Users need to make sure that they are only trusting authorised resellers, despite how appealing the low prices may be from alternate resources."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/26548/spammers-selling-fake-tickets-for-rio-olympics-2016</link>
                                                                            <description>
                            <![CDATA[ Fraudsters have created fake ticketing websites to trick users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mz9cHQSuh7bzu2wMKQosCf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xh9LALFhZeH7eZHWgDU84e-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 May 2016 16:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xh9LALFhZeH7eZHWgDU84e-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xh9LALFhZeH7eZHWgDU84e-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Scammers have been selling fake tickets to the 2016 Olympic Games in Rio De Janiero for more than a year in advance of the opening ceremony, Kaspersky Lab has found.</p><p>In its report on spam and phishing for Q1 2016, released today, the cybersecurity firm found fraudsters have been using a variety of methods to trick sports fans into giving over their personal and financial details.</p><p>As with any major cultural or sporting event, some spammers are attempting to fool users into thinking that they have won free tickets in a lottery draw, organised by the Brazilian government or the International Olympic Committee.</p><p>However, some enterprising cybercriminals have stepped their efforts up, creating bogus ticketing websites to harvest payment information.</p><p>These sites can be surprisingly sophisticated, with some even purchasing SSL certificates in order to appear more legitimate.</p><p>SSL is an encryption method that can prevent hackers from intercepting traffic to an otherwise trustworthy site, but is meaningless if the site is owned and operated by the hackers themselves.</p><p>"The creation of these sites is normally carried out by gangs, which split individual tasks among each other," said Kaspersky Labs' head of UK retail, David Mole.</p><p>"For example, one group may be responsible for setting up the fake website's domain, and the other may be responsible for creating the actual website."</p><p>"It's no surprise that cybercriminals are using the Olympic Games as a ploy to extort money and personal information from unsuspecting recipients," Mole said.</p><p>"We recommend that fans everywhere be very cautious when purchasing tickets or souvenirs. Users need to make sure that they are only trusting authorised resellers, despite how appealing the low prices may be from alternate resources."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ PPI companies punished for sending spam texts ]]></title>
                                                                                                <dc:content><![CDATA[ <p>PPI company UKMS Money Solutions Limited (UKMS) has been fined 80,000 for sending 1.3m spam text messages to mobile phone users in the ICO's crackdown on such companies.</p><p>UKMS bought the phone numbers from brokers, encouraging victims to apply for PPI, even if they were not aware they had signed up to such services when taking out credit cards or loans.</p><p>However, the company was fined for not first checking the mobile phone users had opted in to receive marketing messages and as such, was operating against the law.</p><p>The ICO said almost 1,500 people complained directly to the regulator and using the text message spam line 7726 set up by the organisation during UKMS's intensive marketing campaign between April and June this year.</p><p>"UKMS relied on their data suppliers' word that the people on the lists had agreed to be contacted. That's simply not good enough," Andy Curry, enforcement manager at the ICO, said.</p><p>"UKMS should have known that the responsibility to ensure they had the right consent to send messages to people rests with them."</p><p>The regulator intends to send out fines totalling 250,000 to three companies who have been sending out unsolicited text messages promoting their services. So far, the ICO has collected more than 1m in fines from companies sending unsolicited text messages to prospects.</p><p>Working with the Claims Management Regulation Unit (CMRU), the ICO will also audit an additional five claims management companies to ensure they are complying with the law.</p><p>The next stage in the ICO's crackdown on nuisance marketing text messages is to contact the brokers who sell such marketing lists to find out how they collect the data and comply with the law when it comes to selling these lists on.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/strategy/25645/ppi-companies-punished-for-sending-spam-texts</link>
                                                                            <description>
                            <![CDATA[ One company was fined £80,000 for sending 1.3 million texts to unsuspecting victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tWi1h4YUnv3eYNbCLAvbUo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mkZpnUaLqpjg3MYFzsoG4V-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Nov 2015 09:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mkZpnUaLqpjg3MYFzsoG4V-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mkZpnUaLqpjg3MYFzsoG4V-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>PPI company UKMS Money Solutions Limited (UKMS) has been fined 80,000 for sending 1.3m spam text messages to mobile phone users in the ICO's crackdown on such companies.</p><p>UKMS bought the phone numbers from brokers, encouraging victims to apply for PPI, even if they were not aware they had signed up to such services when taking out credit cards or loans.</p><p>However, the company was fined for not first checking the mobile phone users had opted in to receive marketing messages and as such, was operating against the law.</p><p>The ICO said almost 1,500 people complained directly to the regulator and using the text message spam line 7726 set up by the organisation during UKMS's intensive marketing campaign between April and June this year.</p><p>"UKMS relied on their data suppliers' word that the people on the lists had agreed to be contacted. That's simply not good enough," Andy Curry, enforcement manager at the ICO, said.</p><p>"UKMS should have known that the responsibility to ensure they had the right consent to send messages to people rests with them."</p><p>The regulator intends to send out fines totalling 250,000 to three companies who have been sending out unsolicited text messages promoting their services. So far, the ICO has collected more than 1m in fines from companies sending unsolicited text messages to prospects.</p><p>Working with the Claims Management Regulation Unit (CMRU), the ICO will also audit an additional five claims management companies to ensure they are complying with the law.</p><p>The next stage in the ICO's crackdown on nuisance marketing text messages is to contact the brokers who sell such marketing lists to find out how they collect the data and comply with the law when it comes to selling these lists on.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Spam King’ of Facebook faces up to three years in jail ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Sanford Wallace, one of the internet's most prolific spammers and scam artists, has pleaded guilty to charges of fraud and criminal contempt after spamming millions of Facebook users with unsolicited messages. </p><p>Wallace is due to be sentenced on 7 December, and faces up to three years of prison time and a fine of up to 160,000. This follows an unspecified plea deal, after he was arrested in Las Vegas in 2011 for breaking a court order.</p><p>The 47-year-old American also known as Spamford Wallace' and the Spam King' - hacked into roughly half a million Facebook accounts, using them to post links to malicious websites.</p><p>The sites would harvest users' personal details and account credentials, before redirecting them to affiliate links which earned Wallace money.</p><p>The scam which spanned five months in 2008 and 2009 is estimated to have resulted in over 30 million spurious Facebook posts.</p><p>This resulted in a civil suit from Facebook, who were awarded over $700 million in damages. Wallace was also ordered to stay off Facebook, a ruling he breached to earn him the current contempt charge.</p><p>These offences are the latest in a long and storied career. In the 1990s, his company Cyber Promotions was responsible for over 30 million spam emails a day, and he was also hit by a court case from MySpace after he pulled a phishing stunt similar to his Facebook crimes.</p><p>Prior to that, he also had a case brought against him by ISP Earthlink, the loss of which cost Wallace a further $2 million.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/25195/spam-king-of-facebook-faces-up-to-three-years-in-jail</link>
                                                                            <description>
                            <![CDATA[ Scammer guilty of 30 million dodgy Facebook posts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6hYhpPEPR5oA8wdFuTbEKB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BGHjYtaA6jzGfUxs7K6GNJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2015 12:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BGHjYtaA6jzGfUxs7K6GNJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Jail]]></media:description>                                                            <media:text><![CDATA[Jail]]></media:text>
                                <media:title type="plain"><![CDATA[Jail]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BGHjYtaA6jzGfUxs7K6GNJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sanford Wallace, one of the internet's most prolific spammers and scam artists, has pleaded guilty to charges of fraud and criminal contempt after spamming millions of Facebook users with unsolicited messages. </p><p>Wallace is due to be sentenced on 7 December, and faces up to three years of prison time and a fine of up to 160,000. This follows an unspecified plea deal, after he was arrested in Las Vegas in 2011 for breaking a court order.</p><p>The 47-year-old American also known as Spamford Wallace' and the Spam King' - hacked into roughly half a million Facebook accounts, using them to post links to malicious websites.</p><p>The sites would harvest users' personal details and account credentials, before redirecting them to affiliate links which earned Wallace money.</p><p>The scam which spanned five months in 2008 and 2009 is estimated to have resulted in over 30 million spurious Facebook posts.</p><p>This resulted in a civil suit from Facebook, who were awarded over $700 million in damages. Wallace was also ordered to stay off Facebook, a ruling he breached to earn him the current contempt charge.</p><p>These offences are the latest in a long and storied career. In the 1990s, his company Cyber Promotions was responsible for over 30 million spam emails a day, and he was also hit by a court case from MySpace after he pulled a phishing stunt similar to his Facebook crimes.</p><p>Prior to that, he also had a case brought against him by ISP Earthlink, the loss of which cost Wallace a further $2 million.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake WHO email about Ebola spreads malware ]]></title>
                                                                                                <dc:content><![CDATA[ <p>An IT security company has uncovered a malware-laden email that claims to come from the World Health Organisation that is designed to prey on fears over the Ebola virus.</p><p>According to researchers at Trustwave, the malware threat disguises itself in an email from the World Health Organization (WHO), complete with an attached file.</p><p>The message reads that it has information on how to prevent the Ebola spread in the file. However, the file is in fact an executable that installs the DarkComet Remote Access Trojan (RAT).</p><p>The Trojan makes use of its heavily obfuscated script to run undetected by antivirus software. This then creates a randomly named folder in the Windows Application Data drive and copies all of its component files into that folder. </p><p>As well as keylogging, the Trojan can capture webcam images and sounds. It can remotely access the desktop as well as uploading and executing other files.</p><p>The malware also gathers system information, modifies system host files, executes shell commands, steals passwords and torrent files, lists processes and runs remote scripts. </p><p>The Trojan then sends all this information to a remote server. At present, researchers said they have only seen one sample from the campaign so far.</p><p>"At this time we don't have reason to believe it is a widespread campaign. The address it was sent to was an old honeypot address, so it's not exactly targeted either," the researchers said in a <a href="http://blog.spiderlabs.com/2014/10/spam-campaign-taking-advantage-of-ebola-scare-may-lead-to-malware-infections.html">blog post</a>.</p><p>"These facts taken together suggest a low volume campaign (sent to whatever address list the spammer is using) in an attempt to infect random users in the hope of gaining some data that can be used or sold."</p><p>The firm said another campaign pretended to be from the Mexican Government with an advisory of the Ebola situation in Mexico. Trustwave said just last week the United States Computer Readiness Team (US-CERT) published an <a href="https://www.us-cert.gov/ncas/current-activity/2014/10/16/Ebola-Phishing-Scams-and-Malware-Campaigns">advisory</a> warning users of scams and spam campaigns using the Ebola virus as a social engineering theme.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/23358/fake-who-email-about-ebola-spreads-malware</link>
                                                                            <description>
                            <![CDATA[ Advice email from “World Health Organization” harbours its own virus ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dupTuaRzoATi5sf2sRbzid</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SRcyAeMpkrrL5kawjGXtuX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Oct 2014 08:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SRcyAeMpkrrL5kawjGXtuX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Click here for malware]]></media:description>                                                            <media:text><![CDATA[Click here for malware]]></media:text>
                                <media:title type="plain"><![CDATA[Click here for malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SRcyAeMpkrrL5kawjGXtuX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An IT security company has uncovered a malware-laden email that claims to come from the World Health Organisation that is designed to prey on fears over the Ebola virus.</p><p>According to researchers at Trustwave, the malware threat disguises itself in an email from the World Health Organization (WHO), complete with an attached file.</p><p>The message reads that it has information on how to prevent the Ebola spread in the file. However, the file is in fact an executable that installs the DarkComet Remote Access Trojan (RAT).</p><p>The Trojan makes use of its heavily obfuscated script to run undetected by antivirus software. This then creates a randomly named folder in the Windows Application Data drive and copies all of its component files into that folder. </p><p>As well as keylogging, the Trojan can capture webcam images and sounds. It can remotely access the desktop as well as uploading and executing other files.</p><p>The malware also gathers system information, modifies system host files, executes shell commands, steals passwords and torrent files, lists processes and runs remote scripts. </p><p>The Trojan then sends all this information to a remote server. At present, researchers said they have only seen one sample from the campaign so far.</p><p>"At this time we don't have reason to believe it is a widespread campaign. The address it was sent to was an old honeypot address, so it's not exactly targeted either," the researchers said in a <a href="http://blog.spiderlabs.com/2014/10/spam-campaign-taking-advantage-of-ebola-scare-may-lead-to-malware-infections.html">blog post</a>.</p><p>"These facts taken together suggest a low volume campaign (sent to whatever address list the spammer is using) in an attempt to infect random users in the hope of gaining some data that can be used or sold."</p><p>The firm said another campaign pretended to be from the Mexican Government with an advisory of the Ebola situation in Mexico. Trustwave said just last week the United States Computer Readiness Team (US-CERT) published an <a href="https://www.us-cert.gov/ncas/current-activity/2014/10/16/Ebola-Phishing-Scams-and-Malware-Campaigns">advisory</a> warning users of scams and spam campaigns using the Ebola virus as a social engineering theme.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EE fixes spam Orange "Magic Numbers" text message glitch ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Mobile operator EE has confirmed a scripting fault is to blame for the deluge of marketing-related text messages customers have received over the past several days, and has assured them it has now been fixed. </p><p>The company, which operates T-Mobile and Orange network brands in the UK, has been criticised on social media sites and user forums in recent days for sending out multiple promotional SMS text alerts to its customers.</p><p>In most cases, the texts refer to Orange's Magic Numbers service, which allows the firm's customers to call certain numbers they nominate in advance for free.</p><p>According to numerous posts on the social networking site Twitter, Orange customers have been repeatedly receiving the same message, notifying them that they can now add "another" Magic Number to their frequent callers list since the weekend.</p><p>Many users have reported receiving between 18 to 50 text messages a day, and EE has now moved to assure customers the issue has been fixed.</p><p>In a statement to IT Pro this afternoon, the company said: "The text issue that was affecting some Orange customers has now been fixed. The duplicate texts were caused by a script issue with one of our database suppliers, and we apologise for any inconvenience caused."</p><p>In a post on the <a href="http://community.ee.co.uk/t5/Other-EE-Services/Magic-Number-Texts/m-p/171987">EE Community web forum</a>, the company apologised for inundating users with Magic Numbers-related text message reminders and confirmed users will not be charged for receiving them.</p><p>As of this morning, EE and Orange customers were still waiting on the issue to be rectified, prompting the following statement. "We're sorry that some Orange customers are receiving duplicate reminder texts about Orange Magic Numbers. This is being caused by a technical error which we're working hard to fix," it explained.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/mobile/22751/ee-fixes-spam-orange-magic-numbers-text-message-glitch</link>
                                                                            <description>
                            <![CDATA[ EE in firing line over deluge of spam messages sent to customers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f3XeQUs29YzGB9sR9MVhos</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sMYiUwStcKATpGuXDa9ZLP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Jul 2014 13:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sMYiUwStcKATpGuXDa9ZLP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EE store]]></media:description>                                                            <media:text><![CDATA[EE store]]></media:text>
                                <media:title type="plain"><![CDATA[EE store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sMYiUwStcKATpGuXDa9ZLP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Mobile operator EE has confirmed a scripting fault is to blame for the deluge of marketing-related text messages customers have received over the past several days, and has assured them it has now been fixed. </p><p>The company, which operates T-Mobile and Orange network brands in the UK, has been criticised on social media sites and user forums in recent days for sending out multiple promotional SMS text alerts to its customers.</p><p>In most cases, the texts refer to Orange's Magic Numbers service, which allows the firm's customers to call certain numbers they nominate in advance for free.</p><p>According to numerous posts on the social networking site Twitter, Orange customers have been repeatedly receiving the same message, notifying them that they can now add "another" Magic Number to their frequent callers list since the weekend.</p><p>Many users have reported receiving between 18 to 50 text messages a day, and EE has now moved to assure customers the issue has been fixed.</p><p>In a statement to IT Pro this afternoon, the company said: "The text issue that was affecting some Orange customers has now been fixed. The duplicate texts were caused by a script issue with one of our database suppliers, and we apologise for any inconvenience caused."</p><p>In a post on the <a href="http://community.ee.co.uk/t5/Other-EE-Services/Magic-Number-Texts/m-p/171987">EE Community web forum</a>, the company apologised for inundating users with Magic Numbers-related text message reminders and confirmed users will not be charged for receiving them.</p><p>As of this morning, EE and Orange customers were still waiting on the issue to be rectified, prompting the following statement. "We're sorry that some Orange customers are receiving duplicate reminder texts about Orange Magic Numbers. This is being caused by a technical error which we're working hard to fix," it explained.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why security vendors need a red card during the World Cup ]]></title>
                                                                                                <dc:content><![CDATA[ <p><strong>OPINION:</strong> Unlike many people, I am not a fan of football and the inescapable hype surrounding the ongoing kicking competition known as the World Cup irritates me. On a professional level, however, it makes me mad.</p><p>It's not just the football World Cup, but any and every major sporting occasion attracts the data security chancers. The sad thing is there are chancers on both sides of the security divide and I want both to be shown a red card.</p><p>There is no doubt that the scammers, spammers, phishers and the malware distributors of this world will be rubbing their hands with glee at yet another chance to exploit the naivety of the average internet user.</p><p>There is also no doubt the volume of online bait (be it email or web-based) using the World Cup as a hook will be peaking during the coming few weeks as we reach the climactic final stages of the competition.</p><p>That should be taken as a given by any enterprise that deploys a sensible education programme warning staff about how the bad guys work. Apart from a gentle reminder to be on guard at such a time, there's really no need to go overboard with the World Cup data danger warnings.</p><div><blockquote><p>There's no doubt the volume of online bait (be it email or web-based) using the World Cup as a hook will be peaking during the coming few weeks.</p></blockquote></div><p>What about the chancers on the security vendor side of the fence? In an effort to shift product, more often than not, events like the World Cup are met with a veritable hail of press releases warning users not to click on that World Cup news report, visit that site selling cheap World Cup tickets or download that fake World Cup results app.</p><p>It's all good advice, for sure, but it's all good general advice that applies every day of the year and not just during a big event. This jumping on the hype bandwagon only serves to dull interest in the message, rather than sharpen attention to it.</p><p>Worse, the sheer glut of World Cup-related security stories which appear every four years serves to drown out potentially important warnings that could actually help prevent data loss.</p><p>In the case of the World Cup, for example, I have received no less than 139 separate press releases claiming to be of urgent priority to my readers and urging me to pass the information on.</p><p>Of these, only half a dozen cover two topics that can genuinely be said to have any real impact or value to the enterprise.</p><p>One being news of the Anonymous #OpWorldCup DDoS attack strategy, which just about cuts the relevance mustard, and the other details how malicious USB charging points can be used to steal data.</p><p><strong>DDoS alerts</strong></p><p>The Anonymous DDoS attacks have been threatened for some time, and the actual impact is debatable. I'm inclined to say the 'you need DDoS mitigation' advice being pedalled on the back of this still falls under the World Cup FUD category, although enterprises that have even a loose affiliation to targeted commercial or governmental sites may do well to ensure their strategic plans are up to date.</p><p>Of far more interest to me, and I suspect anyone who has staff that travel a lot, is news about the deployment of fake battery chargers in Brazil.</p><p>I had not previously heard of these devices, which look like genuine AC/DC power sockets complete with a handy USB port for charging, and appear in public places such as bus depots, train stations and cafes.</p><p>The malicious bit comes courtesy of the unit being plugged into a real socket so it will still charge your mobile or tablet, while stealing data via the USB port or even installing malware in some cases.</p><p>The best advice being that staff should always carry a spare battery pack or booster, and be wary of using any chargers in public places. Add this to your educational advice about not using free Wi-Fi and you could prevent an own goal.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/22502/why-security-vendors-need-a-red-card-during-the-world-cup</link>
                                                                            <description>
                            <![CDATA[ The World Cup is being seized on by security vendors to spread FUD. Davey Winder's not impressed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wt1bTqdbGUL2u8ihhgxnMx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KuVe6uHqAV6YCTvUqPYMjZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Jun 2014 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KuVe6uHqAV6YCTvUqPYMjZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Football]]></media:description>                                                            <media:text><![CDATA[Football]]></media:text>
                                <media:title type="plain"><![CDATA[Football]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KuVe6uHqAV6YCTvUqPYMjZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>OPINION:</strong> Unlike many people, I am not a fan of football and the inescapable hype surrounding the ongoing kicking competition known as the World Cup irritates me. On a professional level, however, it makes me mad.</p><p>It's not just the football World Cup, but any and every major sporting occasion attracts the data security chancers. The sad thing is there are chancers on both sides of the security divide and I want both to be shown a red card.</p><p>There is no doubt that the scammers, spammers, phishers and the malware distributors of this world will be rubbing their hands with glee at yet another chance to exploit the naivety of the average internet user.</p><p>There is also no doubt the volume of online bait (be it email or web-based) using the World Cup as a hook will be peaking during the coming few weeks as we reach the climactic final stages of the competition.</p><p>That should be taken as a given by any enterprise that deploys a sensible education programme warning staff about how the bad guys work. Apart from a gentle reminder to be on guard at such a time, there's really no need to go overboard with the World Cup data danger warnings.</p><div><blockquote><p>There's no doubt the volume of online bait (be it email or web-based) using the World Cup as a hook will be peaking during the coming few weeks.</p></blockquote></div><p>What about the chancers on the security vendor side of the fence? In an effort to shift product, more often than not, events like the World Cup are met with a veritable hail of press releases warning users not to click on that World Cup news report, visit that site selling cheap World Cup tickets or download that fake World Cup results app.</p><p>It's all good advice, for sure, but it's all good general advice that applies every day of the year and not just during a big event. This jumping on the hype bandwagon only serves to dull interest in the message, rather than sharpen attention to it.</p><p>Worse, the sheer glut of World Cup-related security stories which appear every four years serves to drown out potentially important warnings that could actually help prevent data loss.</p><p>In the case of the World Cup, for example, I have received no less than 139 separate press releases claiming to be of urgent priority to my readers and urging me to pass the information on.</p><p>Of these, only half a dozen cover two topics that can genuinely be said to have any real impact or value to the enterprise.</p><p>One being news of the Anonymous #OpWorldCup DDoS attack strategy, which just about cuts the relevance mustard, and the other details how malicious USB charging points can be used to steal data.</p><p><strong>DDoS alerts</strong></p><p>The Anonymous DDoS attacks have been threatened for some time, and the actual impact is debatable. I'm inclined to say the 'you need DDoS mitigation' advice being pedalled on the back of this still falls under the World Cup FUD category, although enterprises that have even a loose affiliation to targeted commercial or governmental sites may do well to ensure their strategic plans are up to date.</p><p>Of far more interest to me, and I suspect anyone who has staff that travel a lot, is news about the deployment of fake battery chargers in Brazil.</p><p>I had not previously heard of these devices, which look like genuine AC/DC power sockets complete with a handy USB port for charging, and appear in public places such as bus depots, train stations and cafes.</p><p>The malicious bit comes courtesy of the unit being plugged into a real socket so it will still charge your mobile or tablet, while stealing data via the USB port or even installing malware in some cases.</p><p>The best advice being that staff should always carry a spare battery pack or booster, and be wary of using any chargers in public places. Add this to your educational advice about not using free Wi-Fi and you could prevent an own goal.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ICO and mobile networks join forces to cut spam text messages ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Four of the major UK mobile networks have signed up to cut spam text messages with the help of the GSMA.</p><p>EE, O2, Three, Vodafone will work alongside data protection watchdog the Information Commissioner's Office (ICO) to encourage customers to report any spam messages they receive.</p><p>The solution, powered by <a href="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings" data-original-url="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings">Cloudmark</a>, allows consumers to report unsolicited text messages by forwarding them to 7726, or 'SPAM'.</p><p>The initiative is part of the GSMA's Spam Reporting Service, which aims to cut down spam messaging around the world.</p><p>John Hoffman, CEO of the GSMA, said: "The GSMA Spam Reporting Service provides operators with a tool to measure the extent of fraud and phishing and provides the insight needed to address sophisticated messaging threats that could harm users.</p><p>"By working closely with the ICO, the UK's operators are making it more difficult for spammers and fraudsters to target mobile phone users in this country."</p><p>Steve Eckersley, Head of Enforcement at the ICO, explained the scheme will provide his organisation with real-time information about spam attacks, allowing the organisation to track down and deal with repeat offenders more effectively. </p><p>If a company is found to be breaching the Privacy of Electronic Communication Regulations (PECR), they can be fined by the ICO.</p><p>Last year, a number of companies breaching PECR were fined for bombarding mobile phone users with text messages. </p><p>One <a href="https://www.itpro.com/data-protection/21256/payday-loan-firm-hit-by-175k-fine-for-sending-spam-texts" data-original-url="https://www.itpro.com/data-protection/21256/payday-loan-firm-hit-by-175k-fine-for-sending-spam-texts">Payday loan lender was served a 175,000 penalty</a> for sending texts encouraging unsuspecting victims to sign up to high-interest loans. In this instance, the ICO received more than 4,000 complaints from people who were sent the messages.</p><p>Increasingly, companies are targeting consumers with low credit scores in the hope they will sign up to a payday loan or a better deal on a phone contract. </p><p>Neil Cook, chief technology officer at CloudMark, said these vulnerable people were increasingly targeted because they have inadvertently signed up to other services.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/mobile/21883/ico-and-mobile-networks-join-forces-to-cut-spam-text-messages</link>
                                                                            <description>
                            <![CDATA[ EE, O2, Three, Vodafone have all signed up to the scheme that will rely on consumers reporting spam texts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fdS9AtYWWzPJSjBzqHtD2U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Mar 2014 08:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam email]]></media:description>                                                            <media:text><![CDATA[Spam email]]></media:text>
                                <media:title type="plain"><![CDATA[Spam email]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Four of the major UK mobile networks have signed up to cut spam text messages with the help of the GSMA.</p><p>EE, O2, Three, Vodafone will work alongside data protection watchdog the Information Commissioner's Office (ICO) to encourage customers to report any spam messages they receive.</p><p>The solution, powered by <a href="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings" data-original-url="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings">Cloudmark</a>, allows consumers to report unsolicited text messages by forwarding them to 7726, or 'SPAM'.</p><p>The initiative is part of the GSMA's Spam Reporting Service, which aims to cut down spam messaging around the world.</p><p>John Hoffman, CEO of the GSMA, said: "The GSMA Spam Reporting Service provides operators with a tool to measure the extent of fraud and phishing and provides the insight needed to address sophisticated messaging threats that could harm users.</p><p>"By working closely with the ICO, the UK's operators are making it more difficult for spammers and fraudsters to target mobile phone users in this country."</p><p>Steve Eckersley, Head of Enforcement at the ICO, explained the scheme will provide his organisation with real-time information about spam attacks, allowing the organisation to track down and deal with repeat offenders more effectively. </p><p>If a company is found to be breaching the Privacy of Electronic Communication Regulations (PECR), they can be fined by the ICO.</p><p>Last year, a number of companies breaching PECR were fined for bombarding mobile phone users with text messages. </p><p>One <a href="https://www.itpro.com/data-protection/21256/payday-loan-firm-hit-by-175k-fine-for-sending-spam-texts" data-original-url="https://www.itpro.com/data-protection/21256/payday-loan-firm-hit-by-175k-fine-for-sending-spam-texts">Payday loan lender was served a 175,000 penalty</a> for sending texts encouraging unsuspecting victims to sign up to high-interest loans. In this instance, the ICO received more than 4,000 complaints from people who were sent the messages.</p><p>Increasingly, companies are targeting consumers with low credit scores in the hope they will sign up to a payday loan or a better deal on a phone contract. </p><p>Neil Cook, chief technology officer at CloudMark, said these vulnerable people were increasingly targeted because they have inadvertently signed up to other services.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Universal Credit, roaming charges, SMS spam: IT Pro's web comments round-up ]]></title>
                                                                                                <dc:content><![CDATA[ <p>No-one could ever accuse the <em>IT Pro</em> community of being backward in coming forward, especially when it comes to airing their views on the week's biggest stories.</p><p>This week, the vast majority of the online chatter has focused on SMS spam artists, wasted Government IT investments, and Three's plans to abolish roaming charges in certain countries.</p><p><strong>Universally speaking</strong></p><p>Plans to replace <strong>six means-tested benefits with the all-encompassing Universal Credit payment</strong> was always going to be a complex, costly and ambitious affair.</p><p>The National Audit Office's bean counters released a report into the progress the Department for Work and Pensions (DWP) has made on the project earlier this week, and the results weren't pretty.</p><p>The spending watchdog said the programme's implementation has been let down by "weak management, ineffective control and poor governance," before warning it might miss its 2017 deployment deadline.</p><div><blockquote><p>I've lost faith in the Government. Can I bring in outside help?</p></blockquote></div><p>And that's not even the worst of it. The report revealed that 70 per cent of the 425 million that has been spent on the project to date has been invested in the development of new IT systems to support it.</p><p>This equates to more than 300 million of IT spend, and 34 million of this has been written off for undisclosed reasons.</p><p>Unsurprisingly, the <em>IT Pro</em> community hasn't taken too kindly to this revelation, with one reader picking up on Work and Pensions Secretary Iain Duncan Smith's declaration that civil servants were to blame for the waste.</p><p>Smith said he'd "lost faith in the ability of civil servants to manage this programme," to which <em>IT Pro</em> reader <strong>Haywarda1</strong> retorted: "[That's] exactly how we feel about the Government. Shame we can't bring in outside help."</p><p>Meanwhile, <strong>BrianM101</strong> said he'd like to see someone held to account over this. "How about the people responsible paying the money back," he asked. Yeah, you tell em, Brian.</p><p><strong>Three is the magic number</strong></p><p>Debate has raged in recent weeks about whether or not the <strong><a target="_blank" href="https://www.itpro.com/government-it-strategy/20560/eu-roaming-charge-ban-draft-law-leaks" data-original-url="https://www.itpro.com/government-it-strategy/20560/eu-roaming-charge-ban-draft-law-leaks">European Commission will abolish international roaming charges for mobile phone users</a></strong> that visit EU member states. While we await the outcome of that, mobile operator Three announced that it's already doing this for its customers.</p><p>The company announced plans to axe international roaming costs in seven countries. A decision that was cautiously welcomed by <em>IT Pro</em> readers, with one claiming the firm offered something similar several years ago and then swiftly withdrew it.</p><div><blockquote><p>If they're not following EU data protection laws, it's illegal and not inadvertent.</p></blockquote></div><p>However, well travelled <strong>Ian Sankey</strong> welcomed the move. "I often wonder, when I go to Ireland (or anywhere else), why my Vodafone connects to the same Vodafone network yet I get charged [up to] 20 times the price.</p><p>"It's just pure greed. Well done Three," he added.</p><p><strong>Can the spam</strong></p><p>Messaging security vendor CloudMark recently talked to <em>IT Pro</em> <strong><a target="_blank" href="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings" data-original-url="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings">about the issue of SMS spammers targeting mobile phone users with bad credit</a></strong>; a trend the company described as "disturbing."</p><p>"They often do target the vulnerable people in society, because they're not [aiming] this at people who are on a 50 a month contract with Vodafone," Neil Cook, chief technology officer at CloudMark, told <em>IT Pro</em>.</p><p>"They're targeting people [with phrases like] 'if you've been refused a mobile phone contract before we'll try to get one for you'. It's definitely a concern."</p><p>When asked how spammers know who to target, Cook said it's usually because victims have responded to similar messages in the past or have been "inadvertently" signed up to receive them when their details have been sold on to a third party.</p><p>The latter comment was seized on by regular <em>IT Pro</em> commenter <strong>Stoatwblr</strong> who said the Advertising Standards Authority code of practice prohibits the sending of such missives without the recipient's express permission.</p><p>In response, <strong>Fredfnord</strong> said, even though the practice is banned, <strong>Stoatwblr</strong> is wrong to assume that all companies abide by the rules.</p><p>"Self-evidently, you're wrong. Unless you somehow believe that everyone in Europe (let alone the rest of the world) is following EU data protection laws," <strong>Fredfnord</strong> sniffed.</p><p>To which <strong>Stoatwblr</strong> replied: "If they're not following EU data protection laws, it's illegal and not inadvertent."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/strategy/20561/universal-credit-roaming-charges-sms-spam-it-pros-web-comments-round</link>
                                                                            <description>
                            <![CDATA[ Find out what IT Pro readers make of the Universal Credit IT debacle and Three's decision to abolish international roaming charges... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fyNzju5QLfLs2p1sbSMNd3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8CryRLxGEXXYVfJdqmJbMJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Sep 2013 16:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8CryRLxGEXXYVfJdqmJbMJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Comments]]></media:description>                                                            <media:text><![CDATA[Comments]]></media:text>
                                <media:title type="plain"><![CDATA[Comments]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8CryRLxGEXXYVfJdqmJbMJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>No-one could ever accuse the <em>IT Pro</em> community of being backward in coming forward, especially when it comes to airing their views on the week's biggest stories.</p><p>This week, the vast majority of the online chatter has focused on SMS spam artists, wasted Government IT investments, and Three's plans to abolish roaming charges in certain countries.</p><p><strong>Universally speaking</strong></p><p>Plans to replace <strong>six means-tested benefits with the all-encompassing Universal Credit payment</strong> was always going to be a complex, costly and ambitious affair.</p><p>The National Audit Office's bean counters released a report into the progress the Department for Work and Pensions (DWP) has made on the project earlier this week, and the results weren't pretty.</p><p>The spending watchdog said the programme's implementation has been let down by "weak management, ineffective control and poor governance," before warning it might miss its 2017 deployment deadline.</p><div><blockquote><p>I've lost faith in the Government. Can I bring in outside help?</p></blockquote></div><p>And that's not even the worst of it. The report revealed that 70 per cent of the 425 million that has been spent on the project to date has been invested in the development of new IT systems to support it.</p><p>This equates to more than 300 million of IT spend, and 34 million of this has been written off for undisclosed reasons.</p><p>Unsurprisingly, the <em>IT Pro</em> community hasn't taken too kindly to this revelation, with one reader picking up on Work and Pensions Secretary Iain Duncan Smith's declaration that civil servants were to blame for the waste.</p><p>Smith said he'd "lost faith in the ability of civil servants to manage this programme," to which <em>IT Pro</em> reader <strong>Haywarda1</strong> retorted: "[That's] exactly how we feel about the Government. Shame we can't bring in outside help."</p><p>Meanwhile, <strong>BrianM101</strong> said he'd like to see someone held to account over this. "How about the people responsible paying the money back," he asked. Yeah, you tell em, Brian.</p><p><strong>Three is the magic number</strong></p><p>Debate has raged in recent weeks about whether or not the <strong><a target="_blank" href="https://www.itpro.com/government-it-strategy/20560/eu-roaming-charge-ban-draft-law-leaks" data-original-url="https://www.itpro.com/government-it-strategy/20560/eu-roaming-charge-ban-draft-law-leaks">European Commission will abolish international roaming charges for mobile phone users</a></strong> that visit EU member states. While we await the outcome of that, mobile operator Three announced that it's already doing this for its customers.</p><p>The company announced plans to axe international roaming costs in seven countries. A decision that was cautiously welcomed by <em>IT Pro</em> readers, with one claiming the firm offered something similar several years ago and then swiftly withdrew it.</p><div><blockquote><p>If they're not following EU data protection laws, it's illegal and not inadvertent.</p></blockquote></div><p>However, well travelled <strong>Ian Sankey</strong> welcomed the move. "I often wonder, when I go to Ireland (or anywhere else), why my Vodafone connects to the same Vodafone network yet I get charged [up to] 20 times the price.</p><p>"It's just pure greed. Well done Three," he added.</p><p><strong>Can the spam</strong></p><p>Messaging security vendor CloudMark recently talked to <em>IT Pro</em> <strong><a target="_blank" href="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings" data-original-url="https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings">about the issue of SMS spammers targeting mobile phone users with bad credit</a></strong>; a trend the company described as "disturbing."</p><p>"They often do target the vulnerable people in society, because they're not [aiming] this at people who are on a 50 a month contract with Vodafone," Neil Cook, chief technology officer at CloudMark, told <em>IT Pro</em>.</p><p>"They're targeting people [with phrases like] 'if you've been refused a mobile phone contract before we'll try to get one for you'. It's definitely a concern."</p><p>When asked how spammers know who to target, Cook said it's usually because victims have responded to similar messages in the past or have been "inadvertently" signed up to receive them when their details have been sold on to a third party.</p><p>The latter comment was seized on by regular <em>IT Pro</em> commenter <strong>Stoatwblr</strong> who said the Advertising Standards Authority code of practice prohibits the sending of such missives without the recipient's express permission.</p><p>In response, <strong>Fredfnord</strong> said, even though the practice is banned, <strong>Stoatwblr</strong> is wrong to assume that all companies abide by the rules.</p><p>"Self-evidently, you're wrong. Unless you somehow believe that everyone in Europe (let alone the rest of the world) is following EU data protection laws," <strong>Fredfnord</strong> sniffed.</p><p>To which <strong>Stoatwblr</strong> replied: "If they're not following EU data protection laws, it's illegal and not inadvertent."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Alarm sounded over uptick in SMS spam aimed at people with bad credit ratings ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Messaging security vendor CloudMark is leading calls for a clampdown on firms that deliberately target SMS spam at people with bad credit.</p><p>The company makes software that is used by internet service providers, including Virgin Media and BT, to protect their customers from spam emails, phishing attacks and viruses, for example.</p><div><blockquote><p>Effectively, your details get sold on ad infinitum and they end up on the lists of these spammers.</p></blockquote></div><p>During the summer months, the company claims to have seen a marked rise in the number of messages that fall under the "product information spam" category advertising smartphone and mobile contracts deals.</p><p>Speaking to <em>IT Pro</em>, Neil Cook, chief technology officer at CloudMark, said these types of messages are often targeted at people with bad credit, which he described as a "disturbing" trend.</p><p>"They often do target the vulnerable people in society, because they're not [aiming] this at people who are on a 50 a month contract with Vodafone," he explained.</p><p>"They're targeting people [with phrases like] 'if you've been refused a mobile phone contract before we'll try to get one for you'. It's definitely a concern."</p><p>He said these types of individuals usually end up on the spammers' radar because they've responded to messages of a similar nature before, or have been "inadvertently" signed up when their details have been sold or passed on to a third party.</p><p>"Effectively, your details get sold on ad infinitum and they end up on the lists of these spammers," he said.</p><p>In a similar vein, Cook said around 40-50 per cent of the spam reports his company receives are associated with payday loans, although this has dipped a little since the start of the summer.</p><p>This is a trend Cook has attributed to the recent clampdown on payday loan providers by the Office of Fair Trading, which has already prompted several firms to exit the market.</p><p>"If you look at compared to the beginning of the summer, it's slightly down, but it's still 40-50 per cent of the spam reports we see which, if you were the governor of the Bank of England, wouldn't make you terribly confident [about the UK's economic prospects]," he added.</p><p>Cook is quick to point out though, it's rarely mobile operators, phone manufacturers and payday loan firms that are directly responsible for these messages being sent out.</p><p>Instead, they're usually the work of affiliates who make money every time someone clicks on a link contained in the message.</p><p>"We often see affiliate programmes continue even...though the company they are working with, which often is a legitimate firm, is disavowing their practices," he explained.</p><p>"But on the back end these companies are quite disjointed so that there affiliate programme is [quite removed] from their own marketing activities."</p><p>Consumer watchdogs are getting tougher on companies that target society's more vulnerable types, he added, but it is a difficult area to clampdown on.</p><p>"We're trying to work with the industry to stop people getting this spam in the first place and to clean up the industry, and the networks. That's what our software does," he explained.</p><p>Educating users about the risks associated with responding to spam text messages only goes so far, he added, as there will always be people these types of missives appeal to.</p><p>"It's easy if you're, say, middle class and have no money worries don't click on these things, but to some people they might appear to be offering them a lifeline," Cook said.</p><p>However, those that don't want to receive any more of these types of messages can forward messages to the spam reporting service, 7726, which is then used by mobile operators to stop similar ones being sent to their subscribers in the future, he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/mobile/20495/alarm-sounded-over-uptick-sms-spam-aimed-people-bad-credit-ratings</link>
                                                                            <description>
                            <![CDATA[ CloudMark claims educating users not to respond to messages can only do so much. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oomht63cAVTLPEnYvtAz93</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 29 Aug 2013 15:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam email]]></media:description>                                                            <media:text><![CDATA[Spam email]]></media:text>
                                <media:title type="plain"><![CDATA[Spam email]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Messaging security vendor CloudMark is leading calls for a clampdown on firms that deliberately target SMS spam at people with bad credit.</p><p>The company makes software that is used by internet service providers, including Virgin Media and BT, to protect their customers from spam emails, phishing attacks and viruses, for example.</p><div><blockquote><p>Effectively, your details get sold on ad infinitum and they end up on the lists of these spammers.</p></blockquote></div><p>During the summer months, the company claims to have seen a marked rise in the number of messages that fall under the "product information spam" category advertising smartphone and mobile contracts deals.</p><p>Speaking to <em>IT Pro</em>, Neil Cook, chief technology officer at CloudMark, said these types of messages are often targeted at people with bad credit, which he described as a "disturbing" trend.</p><p>"They often do target the vulnerable people in society, because they're not [aiming] this at people who are on a 50 a month contract with Vodafone," he explained.</p><p>"They're targeting people [with phrases like] 'if you've been refused a mobile phone contract before we'll try to get one for you'. It's definitely a concern."</p><p>He said these types of individuals usually end up on the spammers' radar because they've responded to messages of a similar nature before, or have been "inadvertently" signed up when their details have been sold or passed on to a third party.</p><p>"Effectively, your details get sold on ad infinitum and they end up on the lists of these spammers," he said.</p><p>In a similar vein, Cook said around 40-50 per cent of the spam reports his company receives are associated with payday loans, although this has dipped a little since the start of the summer.</p><p>This is a trend Cook has attributed to the recent clampdown on payday loan providers by the Office of Fair Trading, which has already prompted several firms to exit the market.</p><p>"If you look at compared to the beginning of the summer, it's slightly down, but it's still 40-50 per cent of the spam reports we see which, if you were the governor of the Bank of England, wouldn't make you terribly confident [about the UK's economic prospects]," he added.</p><p>Cook is quick to point out though, it's rarely mobile operators, phone manufacturers and payday loan firms that are directly responsible for these messages being sent out.</p><p>Instead, they're usually the work of affiliates who make money every time someone clicks on a link contained in the message.</p><p>"We often see affiliate programmes continue even...though the company they are working with, which often is a legitimate firm, is disavowing their practices," he explained.</p><p>"But on the back end these companies are quite disjointed so that there affiliate programme is [quite removed] from their own marketing activities."</p><p>Consumer watchdogs are getting tougher on companies that target society's more vulnerable types, he added, but it is a difficult area to clampdown on.</p><p>"We're trying to work with the industry to stop people getting this spam in the first place and to clean up the industry, and the networks. That's what our software does," he explained.</p><p>Educating users about the risks associated with responding to spam text messages only goes so far, he added, as there will always be people these types of missives appeal to.</p><p>"It's easy if you're, say, middle class and have no money worries don't click on these things, but to some people they might appear to be offering them a lifeline," Cook said.</p><p>However, those that don't want to receive any more of these types of messages can forward messages to the spam reporting service, 7726, which is then used by mobile operators to stop similar ones being sent to their subscribers in the future, he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Phishing, spam and porn are the biggest threats to your smartphone ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cyber criminals continue to revamp commonly used techniques such as phishing, spam and pornography to trick mobile users into installing malware.</p><p>In particular, phishing emails from prominent sites such as Paypal and advertisements to download fake applications claiming to be Angry Birds pose a threat to smartphone users, according to a Blue Coat Systems 2013 Mobile Malware Report.</p><p>As the usage of mobile devices continue to grow and the BYOD trend becomes more prevalent, smartphones are increasingly at greater risk of contracting malware, the research warned.</p><p>Among the many causes of mobile malware, pornography poses the biggest risk for mobile users.</p><p>Although mobile malware that can truly break the security of a phone is still undeveloped, the Mobile Malware Report suggests that this will change as the amount of businesses providing access to corporate assets through mobile devices continues to increase.</p><p>"Mobile malware that truly breaks the security model of the phone is still in its infancy with little evidence of attacks beyond a few incidents that targeted the Android platform," the report said. "In 2013, this is likely to change as adoption of mobile devices continues to grow rapidly and businesses increasingly provide access to corporate assets."</p><p>The report added that knowledge about the tools and practices needed to make safe choices on mobile devices is lacking.</p><p>Potential malware issues that mobile usage can cause include:</p><p>Increased risk of passwords being exposed to onlookers because they are not completed masked.</p><p>Difficulty recognising phishing attacks through links because of the shortened format.</p><p>Fake sites are harder to spot because they usually appear differently on mobile devices.</p><p>Mobile versions of websites are often crafted and hosted by third parties, which conditions users to become comfortable visiting unknown URLs.</p><p>New mobile application developers constantly emerge, making it difficult to chose between the reputable applications and the harmful ones.</p><p>"Globally, it's the simple phishing techniques that are most likely to succeed," said Chris Pace, director of product and solutions marketing at Blue Coat Systems.</p><p>"Shortened URLs are common and a smartphone or tablet user may be less prepared for dealing with these kinds of links on a shiny new mobile device than they were with their trusty laptop," he continued.</p><p>The report notes that in order to understand the risks of mobile malware, one must look at the behavioural patterns of people that use mobile devices.</p><p>The average amount of time that a person spends browsing the mobile web is 72 minutes a day (independent of the time spent on native applications). Within that time, about 11 minutes are used for content related to computers/internet.</p><p>Furthermore, one hour is used for content consumption ranging from social networking, shopping, business/economy and entertainment.</p><p>Among the many causes of mobile malware, pornography poses the biggest risk for mobile users.</p><p>"More than 20 percent of the time that a user went to a malicious site, they were coming from a pornography site," the report read.</p><p>Pornography was also the leading source of malware for desktops when it was introduced to the internet. Now, search engine poisoning (SEP) has taken its spot as the leading cause of desktop malware.</p><p>The report noted that it is reasonable to expect the future of mobile malware to follow in the path of desktops, targeting larger platforms as they become easier to infiltrate.</p><p>A few prevention methods for mobile malware that the reports suggests are:</p><p>- Block all content to mobile and desktop devices from dangerous categories, including pornography, phishing and spam.</p><p>- Block executable content from un- rated domains and categories that typical host malware, such as Dynamic DNS hosts.</p><p>The report also advises businesses to enforce policies on web applications (desktops browsing), mobile web applications (mobile browsing) and native mobile applications that are running on its network, especially for businesses moving towards BYOD initiatives.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/645607/phishing-spam-and-porn-are-the-biggest-threats-to-your-smartphone</link>
                                                                            <description>
                            <![CDATA[ Prominent names such as PayPal and Angry Birds are being used to trick users into installing malware, research has found. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mDWLxkCM6iVuLZiqkz79vE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SfyG6pkZbohJe2YvJZvsNE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Feb 2013 09:01:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ JoVona Taylor ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SfyG6pkZbohJe2YvJZvsNE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile malware]]></media:description>                                                            <media:text><![CDATA[Mobile malware]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SfyG6pkZbohJe2YvJZvsNE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals continue to revamp commonly used techniques such as phishing, spam and pornography to trick mobile users into installing malware.</p><p>In particular, phishing emails from prominent sites such as Paypal and advertisements to download fake applications claiming to be Angry Birds pose a threat to smartphone users, according to a Blue Coat Systems 2013 Mobile Malware Report.</p><p>As the usage of mobile devices continue to grow and the BYOD trend becomes more prevalent, smartphones are increasingly at greater risk of contracting malware, the research warned.</p><p>Among the many causes of mobile malware, pornography poses the biggest risk for mobile users.</p><p>Although mobile malware that can truly break the security of a phone is still undeveloped, the Mobile Malware Report suggests that this will change as the amount of businesses providing access to corporate assets through mobile devices continues to increase.</p><p>"Mobile malware that truly breaks the security model of the phone is still in its infancy with little evidence of attacks beyond a few incidents that targeted the Android platform," the report said. "In 2013, this is likely to change as adoption of mobile devices continues to grow rapidly and businesses increasingly provide access to corporate assets."</p><p>The report added that knowledge about the tools and practices needed to make safe choices on mobile devices is lacking.</p><p>Potential malware issues that mobile usage can cause include:</p><p>Increased risk of passwords being exposed to onlookers because they are not completed masked.</p><p>Difficulty recognising phishing attacks through links because of the shortened format.</p><p>Fake sites are harder to spot because they usually appear differently on mobile devices.</p><p>Mobile versions of websites are often crafted and hosted by third parties, which conditions users to become comfortable visiting unknown URLs.</p><p>New mobile application developers constantly emerge, making it difficult to chose between the reputable applications and the harmful ones.</p><p>"Globally, it's the simple phishing techniques that are most likely to succeed," said Chris Pace, director of product and solutions marketing at Blue Coat Systems.</p><p>"Shortened URLs are common and a smartphone or tablet user may be less prepared for dealing with these kinds of links on a shiny new mobile device than they were with their trusty laptop," he continued.</p><p>The report notes that in order to understand the risks of mobile malware, one must look at the behavioural patterns of people that use mobile devices.</p><p>The average amount of time that a person spends browsing the mobile web is 72 minutes a day (independent of the time spent on native applications). Within that time, about 11 minutes are used for content related to computers/internet.</p><p>Furthermore, one hour is used for content consumption ranging from social networking, shopping, business/economy and entertainment.</p><p>Among the many causes of mobile malware, pornography poses the biggest risk for mobile users.</p><p>"More than 20 percent of the time that a user went to a malicious site, they were coming from a pornography site," the report read.</p><p>Pornography was also the leading source of malware for desktops when it was introduced to the internet. Now, search engine poisoning (SEP) has taken its spot as the leading cause of desktop malware.</p><p>The report noted that it is reasonable to expect the future of mobile malware to follow in the path of desktops, targeting larger platforms as they become easier to infiltrate.</p><p>A few prevention methods for mobile malware that the reports suggests are:</p><p>- Block all content to mobile and desktop devices from dangerous categories, including pornography, phishing and spam.</p><p>- Block executable content from un- rated domains and categories that typical host malware, such as Dynamic DNS hosts.</p><p>The report also advises businesses to enforce policies on web applications (desktops browsing), mobile web applications (mobile browsing) and native mobile applications that are running on its network, especially for businesses moving towards BYOD initiatives.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tumblr spammers blast blog site over slow response to attack warning ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The group responsible for carrying out an attack on Tumblr, which resulted in abusive messages being posted on thousands of users' blogs, claim they warned the site an attack could happen weeks ago.</p><p>The blogging site was hit by a spamming group called GNAA yesterday who used the platform to post a 200-word anti-Tumblr rant on thousands of the firm's blogs.</p><p>"This is in response to the seemingly pandemic growth and worldwide propagation of the most F******G WORTHLESS, CONTRIVED, BOURGEOISIE, SELF-CONGRATULATING AND DECADENT B******T THE INTERNET EVER HAD THE MISFORTUNE OF FACILITATING," the post stated.</p><p>We contacted Tumblr two weeks ago...but they never got back to us.</p><p>In an interview with news site <em>Gawker</em>, <a href="http://gawker.com/5965196/hackers-behind-tumblr-worm-say-they-warned-tumblr-of-vulnerability-weeks-ago?tag=the-internet" target="blank">a person reporting to be a GNAA spokesperson</a>, said the group warned Tumblr an attack could take place weeks ago.</p><p>"Someone would have done a lot worse than just posting a message over and over if they didn't fix it right away," said the spokesperson.</p><p>"We contacted Tumblr about it about two weeks ago. We used the 'can't find what you're looking for' link at the bottom of the email troubleshooting page. They never got back to us."</p><p>The site is used to publish more than 70 million posts a day and reportedly hosts nearly 71 million blogs.</p><p>In a blog post, a Tumblr spokesperson said the firm had moved quickly to resolve the issue.</p><p>"We quickly identified the source, removed the posts, and restored service to normal," the post stated.</p><p>"No accounts have been compromised, and you don't need to take any further action."</p><p>In a further post on the Naked Security blog, Graham Cluley, senior technology consultant at security software vendor Sophos, was able to shed some light on how the attack was carried out.</p><p>"The worm took advantage of Tumblr's reblogging feature, meaning that anyone who was logged into Tumblr would automatically reblog the infectious post if they visited one of the offending pages," wrote Cluley.</p><p>"Each affected post had some malicious code embedded inside them...If your computer was logged into Tumblr, it would result in the GNAA content being reblogged on your own Tumblr," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/644488/tumblr-spammers-blast-blog-site-over-slow-response-to-attack-warning</link>
                                                                            <description>
                            <![CDATA[ Blogging platform falls victim to spammers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HJkb6at1CHnkZUypotYfZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t2cMUd9yCWBF4pMxxyouGP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Dec 2012 13:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t2cMUd9yCWBF4pMxxyouGP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hackers]]></media:description>                                                            <media:text><![CDATA[Hackers]]></media:text>
                                <media:title type="plain"><![CDATA[Hackers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t2cMUd9yCWBF4pMxxyouGP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The group responsible for carrying out an attack on Tumblr, which resulted in abusive messages being posted on thousands of users' blogs, claim they warned the site an attack could happen weeks ago.</p><p>The blogging site was hit by a spamming group called GNAA yesterday who used the platform to post a 200-word anti-Tumblr rant on thousands of the firm's blogs.</p><p>"This is in response to the seemingly pandemic growth and worldwide propagation of the most F******G WORTHLESS, CONTRIVED, BOURGEOISIE, SELF-CONGRATULATING AND DECADENT B******T THE INTERNET EVER HAD THE MISFORTUNE OF FACILITATING," the post stated.</p><p>We contacted Tumblr two weeks ago...but they never got back to us.</p><p>In an interview with news site <em>Gawker</em>, <a href="http://gawker.com/5965196/hackers-behind-tumblr-worm-say-they-warned-tumblr-of-vulnerability-weeks-ago?tag=the-internet" target="blank">a person reporting to be a GNAA spokesperson</a>, said the group warned Tumblr an attack could take place weeks ago.</p><p>"Someone would have done a lot worse than just posting a message over and over if they didn't fix it right away," said the spokesperson.</p><p>"We contacted Tumblr about it about two weeks ago. We used the 'can't find what you're looking for' link at the bottom of the email troubleshooting page. They never got back to us."</p><p>The site is used to publish more than 70 million posts a day and reportedly hosts nearly 71 million blogs.</p><p>In a blog post, a Tumblr spokesperson said the firm had moved quickly to resolve the issue.</p><p>"We quickly identified the source, removed the posts, and restored service to normal," the post stated.</p><p>"No accounts have been compromised, and you don't need to take any further action."</p><p>In a further post on the Naked Security blog, Graham Cluley, senior technology consultant at security software vendor Sophos, was able to shed some light on how the attack was carried out.</p><p>"The worm took advantage of Tumblr's reblogging feature, meaning that anyone who was logged into Tumblr would automatically reblog the infectious post if they visited one of the offending pages," wrote Cluley.</p><p>"Each affected post had some malicious code embedded inside them...If your computer was logged into Tumblr, it would result in the GNAA content being reblogged on your own Tumblr," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Symantec detects rise in file extension spam ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Symantec security researchers have discovered a spamming tactic designed to fool users into clicking on links disguised as common file extensions.</p><p>The firm said the spam first appeared around two weeks ago and is linked to online pharmacy websites.</p><p>According to Anand Muralidharan, a researcher at Symantec, the emails contain the usual spam content - such as references to news events, images and video files - but the links seem to end with common file extensions.</p><p>These extensions include .pdf, .mp3 and .doc as well as .asp and .mpeg. However, instead of opening up files associated with them, they point users to pharmacy sites.</p><p>He said the source domain was registered in Russia and its servers were located in Hong Kong and the Ukraine.</p><p>In order to populate these types of attacks, also known as RSS news-feed spam, attackers use news feeds in the spam email.</p><p>Spammers have also used the recent death of legendary astronaut Neil Armstrong in this spam sample, Muralidharan added.</p><p>"The intention of using these particular file extensions could be to evade content filters, which typically look for other types of file extensions," he said in a blog post.</p><p>"Another reason could be to fool users who would expect the links to open the relevant file type."</p><p>He advised users to keep their security software up-to-date, in order to evade these types of online scams.</p><p>Scammers have also been sending out emails claiming to be from Symantec and other security companies, warning users their email account may be blocked because it has been sending out "infected" emails.</p><p>The link in the message points to a file that is named removaltool.exe, but contains a Trojan that downloads other malware to infect target machines.</p><p>The new attack was first spotted by security vendor Websense.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/642577/symantec-detects-rise-in-file-extension-spam</link>
                                                                            <description>
                            <![CDATA[ Security vendor claims spammers are increasingly using rogue file extensions to lure unsuspecting users to online pharmacy sites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7rudTvN8QyGTqv2JcF1rPb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TLvnBESfrCjUdcaz7kwmuM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Aug 2012 11:16:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TLvnBESfrCjUdcaz7kwmuM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TLvnBESfrCjUdcaz7kwmuM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Symantec security researchers have discovered a spamming tactic designed to fool users into clicking on links disguised as common file extensions.</p><p>The firm said the spam first appeared around two weeks ago and is linked to online pharmacy websites.</p><p>According to Anand Muralidharan, a researcher at Symantec, the emails contain the usual spam content - such as references to news events, images and video files - but the links seem to end with common file extensions.</p><p>These extensions include .pdf, .mp3 and .doc as well as .asp and .mpeg. However, instead of opening up files associated with them, they point users to pharmacy sites.</p><p>He said the source domain was registered in Russia and its servers were located in Hong Kong and the Ukraine.</p><p>In order to populate these types of attacks, also known as RSS news-feed spam, attackers use news feeds in the spam email.</p><p>Spammers have also used the recent death of legendary astronaut Neil Armstrong in this spam sample, Muralidharan added.</p><p>"The intention of using these particular file extensions could be to evade content filters, which typically look for other types of file extensions," he said in a blog post.</p><p>"Another reason could be to fool users who would expect the links to open the relevant file type."</p><p>He advised users to keep their security software up-to-date, in order to evade these types of online scams.</p><p>Scammers have also been sending out emails claiming to be from Symantec and other security companies, warning users their email account may be blocked because it has been sending out "infected" emails.</p><p>The link in the message points to a file that is named removaltool.exe, but contains a Trojan that downloads other malware to infect target machines.</p><p>The new attack was first spotted by security vendor Websense.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dropbox in password reuse security breach ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Dropbox has admitted that a number of customers have been spammed following a breach of its infrastructure that led to a number of accounts being compromised.</p><p>The cloud storage provider said that it was made aware of the breach when account holders reported receiving unwanted messages in email accounts used only for Dropbox communications.</p><p>The company said in a blog post that it had taken action to investigate claims.</p><p>"A couple weeks ago, we started getting emails from some users about spam they were receiving at email addresses used only for Dropbox. We've been working hard to get to the bottom of this, and want to give you an update," said Aditya Agarwal, vice president of Engineering at Dropbox.</p><p>"Our investigation found that usernames and passwords recently stolen from other websites were used to sign in to a small number of Dropbox accounts. We've contacted these users and have helped them protect their accounts."</p><p>The company confirmed that several other accounts were also compromised when an employee's Dropbox account also got hacked.</p><p>"A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses," said the company.</p><p>"We believe this improper access is what led to the spam."</p><p>Dropbox apologised for the breach and said it would now put additional controls in place to help make sure it doesn't happen again.</p><p>The company has now reset affected customers' passwords and will be implementing two-factor authentication including temporary codes sent to mobile phones when signing in.</p><p>It also plans to introduce automated mechanisms to help identify suspicious activity. Dropbox said it would also continue to add more of these over time.</p><p>Neil Cook, chief technology officer of security company Cloudmark said that the breach was "unsophisticated".</p><p>"The offending messages were hitting a handful of spammy fingerprints at once," he said. "If this were an exam, the spammer would receive an ungraded' mark for lack of message complexity or originality."</p><p>Cook added that recent data from Cloudmark's Global Threat Network found that there were 264 different domains in use by this spammer.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/642064/dropbox-in-password-reuse-security-breach</link>
                                                                            <description>
                            <![CDATA[ Same password used on multiple sites results in Dropbox account compromisation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">21VA2cPBLdeyqdJzDV3QHr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zQYiv4dyFeuZDyQygwqFqP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Aug 2012 15:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zQYiv4dyFeuZDyQygwqFqP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security]]></media:description>                                                            <media:text><![CDATA[Cloud security]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zQYiv4dyFeuZDyQygwqFqP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Dropbox has admitted that a number of customers have been spammed following a breach of its infrastructure that led to a number of accounts being compromised.</p><p>The cloud storage provider said that it was made aware of the breach when account holders reported receiving unwanted messages in email accounts used only for Dropbox communications.</p><p>The company said in a blog post that it had taken action to investigate claims.</p><p>"A couple weeks ago, we started getting emails from some users about spam they were receiving at email addresses used only for Dropbox. We've been working hard to get to the bottom of this, and want to give you an update," said Aditya Agarwal, vice president of Engineering at Dropbox.</p><p>"Our investigation found that usernames and passwords recently stolen from other websites were used to sign in to a small number of Dropbox accounts. We've contacted these users and have helped them protect their accounts."</p><p>The company confirmed that several other accounts were also compromised when an employee's Dropbox account also got hacked.</p><p>"A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses," said the company.</p><p>"We believe this improper access is what led to the spam."</p><p>Dropbox apologised for the breach and said it would now put additional controls in place to help make sure it doesn't happen again.</p><p>The company has now reset affected customers' passwords and will be implementing two-factor authentication including temporary codes sent to mobile phones when signing in.</p><p>It also plans to introduce automated mechanisms to help identify suspicious activity. Dropbox said it would also continue to add more of these over time.</p><p>Neil Cook, chief technology officer of security company Cloudmark said that the breach was "unsophisticated".</p><p>"The offending messages were hitting a handful of spammy fingerprints at once," he said. "If this were an exam, the spammer would receive an ungraded' mark for lack of message complexity or originality."</p><p>Cook added that recent data from Cloudmark's Global Threat Network found that there were 264 different domains in use by this spammer.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World's third largest botnet taken down ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Security researchers have taken down a four year old botnet responsible for generating around 18 billion spam emails a day.</p><p>The Grum botnet was credited with creating more than 33 per cent of the world's spam email at the peak of its power in January 2012. In recent times, this figure is understood to have slumped to 18 per cent.</p><p>The botnet's demise was confirmed by security vendor FireEye in a blog post after several overseas command and control (CnC) servers, which were responsible for powering Grum, were shut down.</p><p>The posts states that Grum's termination was the result of a group effort, which saw FireEye security researcher, Atif Mushtaq, team up with spam monitoring specialist Spamhaus, ISPs and several other research teams from across the globe.</p><p>"After they got all the evidence from my side, they moved quickly passing this intelligence back to their contacts in Ukraine and Russia," said Mushtaq in his blog post.</p><p>"As a result of this overnight operation, all six servers [currently powering Grum] in the Ukraine and the original Russian server were dead as of today.</p><p>"Grum's takedown resulted from the efforts of many individuals. This collaboration is sending a strong message to all scammers," he added.</p><p>According to Spamhaus' figures, Grum used an average of 120,000 IP addresses to distribute its emails. This figure was slashed to 21,505 as soon as the CnC servers were shut off.</p><p>"Most of the spam botnets that used to keep their CnCs in the USA and Europe have moved to countries like Panama, Russia, and Ukraine thinking that no one can touch them in these comfort zones. We have proven them wrong this time," Mushtaq added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/641809/worlds-third-largest-botnet-taken-down</link>
                                                                            <description>
                            <![CDATA[ Grum, the botnet credited with sending out around 18 billion spam emails a day, has been shutdown. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ct6i53Ldk9Z6ycCnLTXaFd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Jul 2012 11:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam email]]></media:description>                                                            <media:text><![CDATA[Spam email]]></media:text>
                                <media:title type="plain"><![CDATA[Spam email]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/npyio8WiqHtQ2RAMquMChQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have taken down a four year old botnet responsible for generating around 18 billion spam emails a day.</p><p>The Grum botnet was credited with creating more than 33 per cent of the world's spam email at the peak of its power in January 2012. In recent times, this figure is understood to have slumped to 18 per cent.</p><p>The botnet's demise was confirmed by security vendor FireEye in a blog post after several overseas command and control (CnC) servers, which were responsible for powering Grum, were shut down.</p><p>The posts states that Grum's termination was the result of a group effort, which saw FireEye security researcher, Atif Mushtaq, team up with spam monitoring specialist Spamhaus, ISPs and several other research teams from across the globe.</p><p>"After they got all the evidence from my side, they moved quickly passing this intelligence back to their contacts in Ukraine and Russia," said Mushtaq in his blog post.</p><p>"As a result of this overnight operation, all six servers [currently powering Grum] in the Ukraine and the original Russian server were dead as of today.</p><p>"Grum's takedown resulted from the efforts of many individuals. This collaboration is sending a strong message to all scammers," he added.</p><p>According to Spamhaus' figures, Grum used an average of 120,000 IP addresses to distribute its emails. This figure was slashed to 21,505 as soon as the CnC servers were shut off.</p><p>"Most of the spam botnets that used to keep their CnCs in the USA and Europe have moved to countries like Panama, Russia, and Ukraine thinking that no one can touch them in these comfort zones. We have proven them wrong this time," Mushtaq added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The truth about spam ]]></title>
                                                                                                <dc:content><![CDATA[ <p>COMMENT: Spam filtering has, without any shadow of a doubt, improved beyond recognition compared to just a few years ago.</p><p>Server-side systems have evolved to the point where relatively little spam gets through the defences, and are intelligent enough to ensure few false positives leading to genuine correspondence being flushed away with it.</p><p>So why am I insisting that spam is still a problem for your business?</p><p>In the words of Aleksandr Orlov, the TV advertising meerkat rather than a Russian security researcher, simples. While the little spam that does breach enterprise defences can perhaps be thought of as a minimal nuisance as far as employee productivity is concerned, that's far from the big picture.</p><p>When Opinion Matters on behalf of GFI Software recently conducted an independent and blind survey of more than 200 UK businesses, the results were perhaps rather shocking. The volume of spam, as far as decision makers within the SMBs polled were concerned, is not going down, it's going up.</p><p>Some 61 per cent said spam volumes had risen during the last 12 months and a further 21 per cent had seen no reduction in spam traffic rates.</p><p>And that's not all. Some 40 per cent of them admitted their business had suffered a data breach as a direct result of spam.</p><p>Wait a minute, spam-based data breaches? Surely not? Actually, when you think about it, the real response should be 'nothing new there.' After all, the favourite method of getting access to your data is to get someone within the enterprise to follow a malicious link or open a malicious file in order to execute a Trojan payload of some kind. And amongst many other methods, distribution of those links and attachments via spam is a hugely popular delivery route.</p><p>The thing is that, as I see it, the malicious spam threat has never gone away. Instead it has been downplayed by a tunnel vision in enterprise security strategy, which relies upon those evolved anti-spam filters to deal with it at the expense of taking a more layered approach to the problem. The survey found that 46 per cent of the businesses questioned relied solely upon the anti-spam component of their favoured anti-virus solution to deal with it.</p><p>What I find surprising about nearly half of those asked relying upon this one-chance-only spam filtering solution is that 62 per cent also admitted their anti-spam strategy was only marginally effective, with 8 per cent stating it wasn't effective at all. Amazing, especially when you consider the top concern shown by these same companies about spam was it may harbour malicious content that could compromise their networks.</p><p>Finally, some 14 per cent of those asked didn't have any education programme in place to ensure employees were aware of the spam threat, could recognise the dangers and be able to deal with them appropriately.</p><p>Until this situation changes, until those responsible for the security of the network take off the rose-tinted spectacles and admit both server/cloud and client-side approaches are needed to trap the most spam possible, the spam problem will not be going anywhere.</p><p>So, what can you do about? Well the obvious bullet points to concentrate on have to be user education and a bit of a rethink on the filtering technology front. The latter is vital if you are to actually have a more effective method of ensuring your business stays as spam-free as possible.</p><p>Simply having blind faith in your existing anti-spam solution is of little real world use if spam is still actually getting through in enough volume to cause the kind of problems outlined in this report. Actually, I'd say that a single malicious spam is one too many, but I appreciate we do not live in an ideal world.</p><p>Throwing money at the perceived non-problem of spam is not going to be an easy sell, I grant you, but the bean counters have to factor in the risk of malicious linkage and file attachments getting through when determining the true value of a little investment to the business.</p><p>User education is vital to ensure that when those rogue junk mails do slip through they are not actioned in a way that will compromise the security of your data. The danger is that those same bean counters will see education as the cheaper option and follow that course at the expense (every pun intended) of a technology review. This, in my never humble opinion, would be a big mistake: the one is diluted too much without the other.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/639829/the-truth-about-spam</link>
                                                                            <description>
                            <![CDATA[ It's very easy these days to think that spam has been filtered out of existence and is no longer a problem for your business. Davey Winder argues it's more of a problem than ever. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rCsHdEveRP2hRfeWkBNKGn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tDAkdLLvRajBiey2zxPsWK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 29 Mar 2012 09:17:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tDAkdLLvRajBiey2zxPsWK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tDAkdLLvRajBiey2zxPsWK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>COMMENT: Spam filtering has, without any shadow of a doubt, improved beyond recognition compared to just a few years ago.</p><p>Server-side systems have evolved to the point where relatively little spam gets through the defences, and are intelligent enough to ensure few false positives leading to genuine correspondence being flushed away with it.</p><p>So why am I insisting that spam is still a problem for your business?</p><p>In the words of Aleksandr Orlov, the TV advertising meerkat rather than a Russian security researcher, simples. While the little spam that does breach enterprise defences can perhaps be thought of as a minimal nuisance as far as employee productivity is concerned, that's far from the big picture.</p><p>When Opinion Matters on behalf of GFI Software recently conducted an independent and blind survey of more than 200 UK businesses, the results were perhaps rather shocking. The volume of spam, as far as decision makers within the SMBs polled were concerned, is not going down, it's going up.</p><p>Some 61 per cent said spam volumes had risen during the last 12 months and a further 21 per cent had seen no reduction in spam traffic rates.</p><p>And that's not all. Some 40 per cent of them admitted their business had suffered a data breach as a direct result of spam.</p><p>Wait a minute, spam-based data breaches? Surely not? Actually, when you think about it, the real response should be 'nothing new there.' After all, the favourite method of getting access to your data is to get someone within the enterprise to follow a malicious link or open a malicious file in order to execute a Trojan payload of some kind. And amongst many other methods, distribution of those links and attachments via spam is a hugely popular delivery route.</p><p>The thing is that, as I see it, the malicious spam threat has never gone away. Instead it has been downplayed by a tunnel vision in enterprise security strategy, which relies upon those evolved anti-spam filters to deal with it at the expense of taking a more layered approach to the problem. The survey found that 46 per cent of the businesses questioned relied solely upon the anti-spam component of their favoured anti-virus solution to deal with it.</p><p>What I find surprising about nearly half of those asked relying upon this one-chance-only spam filtering solution is that 62 per cent also admitted their anti-spam strategy was only marginally effective, with 8 per cent stating it wasn't effective at all. Amazing, especially when you consider the top concern shown by these same companies about spam was it may harbour malicious content that could compromise their networks.</p><p>Finally, some 14 per cent of those asked didn't have any education programme in place to ensure employees were aware of the spam threat, could recognise the dangers and be able to deal with them appropriately.</p><p>Until this situation changes, until those responsible for the security of the network take off the rose-tinted spectacles and admit both server/cloud and client-side approaches are needed to trap the most spam possible, the spam problem will not be going anywhere.</p><p>So, what can you do about? Well the obvious bullet points to concentrate on have to be user education and a bit of a rethink on the filtering technology front. The latter is vital if you are to actually have a more effective method of ensuring your business stays as spam-free as possible.</p><p>Simply having blind faith in your existing anti-spam solution is of little real world use if spam is still actually getting through in enough volume to cause the kind of problems outlined in this report. Actually, I'd say that a single malicious spam is one too many, but I appreciate we do not live in an ideal world.</p><p>Throwing money at the perceived non-problem of spam is not going to be an easy sell, I grant you, but the bean counters have to factor in the risk of malicious linkage and file attachments getting through when determining the true value of a little investment to the business.</p><p>User education is vital to ensure that when those rogue junk mails do slip through they are not actioned in a way that will compromise the security of your data. The danger is that those same bean counters will see education as the cheaper option and follow that course at the expense (every pun intended) of a technology review. This, in my never humble opinion, would be a big mistake: the one is diluted too much without the other.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Researchers see security improve ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Researchers have found that overall safety online is improving overall, but that criminals are adapting their techniques to compensate.</p><p>Results from the IBM X-Force 2011 Trend and Risk report show an improvement to online security practices. 2011 saw a 50 per cent decline in spam email, against 2010 figures. Patching of security vulnerabilities by software vendors improved as well, with a seven per cent decrease in the number of vulnerabilities remaining unpatched. The report shows that cross-site scripting is half as likely to exist in clients' software as it was four years ago.</p><p>However, the advancements in security measures has prompted online criminals to evolve their techniques. Mobile exploits, automated password guessing, and phishing attacks are on the rise.</p><p>"In 2011 we've seen surprisingly good progress in the fight against computer crime through the IT industry's efforts to improve the quality of software," said Tom Cross, manager of threat intelligence and strategy for IBM X-Force.</p><p>"In response, criminals continue to evolve their techniques to find new avenues into an organisation. As long as attackers profit from cyber crime, organisations must remain diligent in prioritising and addressing their security vulnerabilities."</p><p>Some of the top examples of security improvements in 2011 include a 30 per cent decline in the availability of exploit codes, a 50 per cent reduction in cross-site scripting, and an overall decline in spam.</p><p>IBM noted new attack trends being used by hackers. According to the report, there are documented increases in three key areas of attack activity.</p><p>Attacks targeting shell command injection vulnerabilities have more than doubled. As improvements have been made to prevent SQL injections, which allow hackers to manipulate the database behind a website, attackers are now targeting shell command injection vulnerabilities instead. This type of vulnerability enables the attacker to execute commands directly on a web server. IBM is encouraging web application developers to pay close attention to these types of attacks, as they have increased by two to three times over the course of 2011.</p><p>There have been increases in phishing attacks that impersonate social networking sties and mail parcel services. Phishing attacks have returned to the scene reaching volumes that not seen since 2008. The emails entice victims to click on links to web pages that my try to infect their PCs with malware.</p><p>Social networking is helping hackers to make phishing emails more persuasive. People who share too much information on social networking sites such as Facebook and Twitter make it easy for criminals to use their information to target phishing ads and spam specifically at them, making attacks more personal and convincing.</p><p>New technologies are accompanied by new avenues for virtual attacks. According to IBM, mobile and cloud computing in particular continue to cause problems for security in enterprises. 2011 also saw a number of high-profile company cloud breaches.</p><p>"IT security staff should carefully consider what workloads they should send to third-party cloud providers and what should be kept in-house due to sensitivity of data," the report said.</p><p>"Cloud security requires foresight on the part of the customer as well as flexibility, skills, and a willingness to negotiate on the part of the cloud provider."</p><p>The X-Force report recommends service level agreements (SLAs) for managing security in the cloud, because of the limited control an organisation can exercise over cloud computing services.</p><p>"Many cloud customers tapping a service worry about securing the technology. Depending upon the type of cloud deployment, most, if not all, of the technology is outside of the customer's control," said Ryan Berg, IBM security cloud strategist.</p><p>"They should focus on information security requirements of the data destined for the cloud, and through due diligence, make certain their cloud provider has the capability to adequately secure the workload."</p><p>IBM recommends performing regular third-party external and internal security audits, segmentation of sensitive systems and information and training end users about phishing and spear phishing. Enterprises should also examine the security policies of business partners.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/639709/researchers-see-security-improve</link>
                                                                            <description>
                            <![CDATA[ Firms are improving security performance but threats continue to grow, says IBM. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fnb48JZS5NTUJGABjTCumG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/p2Ezgqnvt7ih8Mv3VqM7Ld-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Mar 2012 14:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kellan Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/p2Ezgqnvt7ih8Mv3VqM7Ld-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Are you secure?]]></media:description>                                                            <media:text><![CDATA[Are you secure?]]></media:text>
                                <media:title type="plain"><![CDATA[Are you secure?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/p2Ezgqnvt7ih8Mv3VqM7Ld-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have found that overall safety online is improving overall, but that criminals are adapting their techniques to compensate.</p><p>Results from the IBM X-Force 2011 Trend and Risk report show an improvement to online security practices. 2011 saw a 50 per cent decline in spam email, against 2010 figures. Patching of security vulnerabilities by software vendors improved as well, with a seven per cent decrease in the number of vulnerabilities remaining unpatched. The report shows that cross-site scripting is half as likely to exist in clients' software as it was four years ago.</p><p>However, the advancements in security measures has prompted online criminals to evolve their techniques. Mobile exploits, automated password guessing, and phishing attacks are on the rise.</p><p>"In 2011 we've seen surprisingly good progress in the fight against computer crime through the IT industry's efforts to improve the quality of software," said Tom Cross, manager of threat intelligence and strategy for IBM X-Force.</p><p>"In response, criminals continue to evolve their techniques to find new avenues into an organisation. As long as attackers profit from cyber crime, organisations must remain diligent in prioritising and addressing their security vulnerabilities."</p><p>Some of the top examples of security improvements in 2011 include a 30 per cent decline in the availability of exploit codes, a 50 per cent reduction in cross-site scripting, and an overall decline in spam.</p><p>IBM noted new attack trends being used by hackers. According to the report, there are documented increases in three key areas of attack activity.</p><p>Attacks targeting shell command injection vulnerabilities have more than doubled. As improvements have been made to prevent SQL injections, which allow hackers to manipulate the database behind a website, attackers are now targeting shell command injection vulnerabilities instead. This type of vulnerability enables the attacker to execute commands directly on a web server. IBM is encouraging web application developers to pay close attention to these types of attacks, as they have increased by two to three times over the course of 2011.</p><p>There have been increases in phishing attacks that impersonate social networking sties and mail parcel services. Phishing attacks have returned to the scene reaching volumes that not seen since 2008. The emails entice victims to click on links to web pages that my try to infect their PCs with malware.</p><p>Social networking is helping hackers to make phishing emails more persuasive. People who share too much information on social networking sites such as Facebook and Twitter make it easy for criminals to use their information to target phishing ads and spam specifically at them, making attacks more personal and convincing.</p><p>New technologies are accompanied by new avenues for virtual attacks. According to IBM, mobile and cloud computing in particular continue to cause problems for security in enterprises. 2011 also saw a number of high-profile company cloud breaches.</p><p>"IT security staff should carefully consider what workloads they should send to third-party cloud providers and what should be kept in-house due to sensitivity of data," the report said.</p><p>"Cloud security requires foresight on the part of the customer as well as flexibility, skills, and a willingness to negotiate on the part of the cloud provider."</p><p>The X-Force report recommends service level agreements (SLAs) for managing security in the cloud, because of the limited control an organisation can exercise over cloud computing services.</p><p>"Many cloud customers tapping a service worry about securing the technology. Depending upon the type of cloud deployment, most, if not all, of the technology is outside of the customer's control," said Ryan Berg, IBM security cloud strategist.</p><p>"They should focus on information security requirements of the data destined for the cloud, and through due diligence, make certain their cloud provider has the capability to adequately secure the workload."</p><p>IBM recommends performing regular third-party external and internal security audits, segmentation of sensitive systems and information and training end users about phishing and spear phishing. Enterprises should also examine the security policies of business partners.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malware trying to trick anti-Putin protesters ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Security giant Symantec has spotted a spam campaign designed to get <a href="https://www.itpro.com/639448/researchers-uncover-duqus-secret-language" target="_blank" data-original-url="https://www.itpro.com/639448/researchers-uncover-duqus-secret-language">malware</a> on anti-Putin campaigner PCs.</p><p>Vladimir Putin was re-elected as president of Russia last week, but there have been protests against his rule both pre and post-election.</p><p>Now, spam messages have been sent out purporting to contain instructions for rallies against Putin.</p><p>The emails included an attachment detected by Symantec as Trojan.Dropper, but those who see the document are presented with details of an apparent anti-Putin meeting that even features a map.</p><p>From a spam perspective, this attack is quite unusual mainly because of its size.</p><p>However, malicious macros, if enabled, will be running in the background and "a particularly nasty Trojan" is activated, the security giant found.</p><p>Various files are then deleted from the user's machine, including .doc, .exe, .xls and .zip files.</p><p>"The Trojan also attempts to connect to IP address 193.104.153.31 (down at the time of analysis), which contains links to the notorious Trojan.Smoaler threat," said Symantec's Stephen Doherty, in a <a href="http://www.symantec.com/connect/blogs/malware-targets-demonstrators-opposed-putins-re-election" target="_blank">blog post</a>.</p><p>"Smoaler recently used the surero48421.ru domain as part of its command-and-control server and this website formerly resolved to the above IP address.</p><p>"Once it has destroyed all of the above files by overwriting them, it then runs code to cause the computer to crash (blue screen) through a call to the RtlSetProcessIsCritical API."</p><p>Symantec also noted how unusual the spam attack was, pointing to the size of the emails.</p><p>"From a spam perspective, this attack is quite unusual mainly because of its size (average of more than 500 KB). Most spam messages do not exceed 10 KB," Doherty added.</p><p>"For example, in the latest Symantec Intelligence report, 56 per cent of all February spam messages were less than 5 KB with 30 per cent between 5 - 10 KB and only 13 per cent greater than 10 KB."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/639460/malware-trying-to-trick-anti-putin-protesters</link>
                                                                            <description>
                            <![CDATA[ Spam messages claim to include details on anti-Putin protests but only lead to nasty malware being installed on user machines. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">muyJBtT8wA3aLA8MuZ8Sus</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Mar 2012 13:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security giant Symantec has spotted a spam campaign designed to get <a href="https://www.itpro.com/639448/researchers-uncover-duqus-secret-language" target="_blank" data-original-url="https://www.itpro.com/639448/researchers-uncover-duqus-secret-language">malware</a> on anti-Putin campaigner PCs.</p><p>Vladimir Putin was re-elected as president of Russia last week, but there have been protests against his rule both pre and post-election.</p><p>Now, spam messages have been sent out purporting to contain instructions for rallies against Putin.</p><p>The emails included an attachment detected by Symantec as Trojan.Dropper, but those who see the document are presented with details of an apparent anti-Putin meeting that even features a map.</p><p>From a spam perspective, this attack is quite unusual mainly because of its size.</p><p>However, malicious macros, if enabled, will be running in the background and "a particularly nasty Trojan" is activated, the security giant found.</p><p>Various files are then deleted from the user's machine, including .doc, .exe, .xls and .zip files.</p><p>"The Trojan also attempts to connect to IP address 193.104.153.31 (down at the time of analysis), which contains links to the notorious Trojan.Smoaler threat," said Symantec's Stephen Doherty, in a <a href="http://www.symantec.com/connect/blogs/malware-targets-demonstrators-opposed-putins-re-election" target="_blank">blog post</a>.</p><p>"Smoaler recently used the surero48421.ru domain as part of its command-and-control server and this website formerly resolved to the above IP address.</p><p>"Once it has destroyed all of the above files by overwriting them, it then runs code to cause the computer to crash (blue screen) through a call to the RtlSetProcessIsCritical API."</p><p>Symantec also noted how unusual the spam attack was, pointing to the size of the emails.</p><p>"From a spam perspective, this attack is quite unusual mainly because of its size (average of more than 500 KB). Most spam messages do not exceed 10 KB," Doherty added.</p><p>"For example, in the latest Symantec Intelligence report, 56 per cent of all February spam messages were less than 5 KB with 30 per cent between 5 - 10 KB and only 13 per cent greater than 10 KB."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ICO claims 'significant progress' in war on spam texts ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.itpro.com/637720/ico-hands-its-biggest-ever-fine-to-welsh-council" target="_blank" data-original-url="https://www.itpro.com/637720/ico-hands-its-biggest-ever-fine-to-welsh-council">Information Commissioner's Office</a> (ICO) claims to have made significant progress in finding those responsible for bothering UK citizens with mobile <a href="https://www.itpro.com/635623/malicous-spam-hits-epic-levels" target="_blank" data-original-url="https://www.itpro.com/635623/malicous-spam-hits-epic-levels">spam</a>.</p><p>The data protection watchdog today said it was almost certain it knew who was behind spam messages, but it needed more evidence to punish them.</p><p>The ICO has learned messages are being sent from unregistered pay-as-you-go SIM cards and has raided an office in the north of England as part of its investigations.</p><p>We've built a case that these people are causing damage and distress.</p><p>It said it was planning to execute more search warrants in the future.</p><p>"We've built a case that these people are causing damage and distress," an ICO spokesperson told <em>IT Pro</em>. "What we need to do is to be able to enforce action against them, is to gather more evidence.</p><p>"We are urging people to come forward with any information."</p><p>She confirmed the ICO would be able to fine those responsible up to 500,000.</p><p>The ICO has been working with various bodies in the UK to crack down on spam texting, including the Ministry of Justice, Ofcom and the Office of Fair Trading.</p><p>Data has indicated around 8 million spam texts are sent in the UK every day.</p><p>An ICO survey found 681 of 1,014 respondents said they had received a concerning spam text, feeling troubled about how their data had been obtained. Another 205 complained of the texts being inconvenient.</p><p>"There is also clearly a lot to be gained in raising public awareness about these messages. People need to realise that the numbers are randomly generated and that they shouldn't respond, even when encouraged to text back 'stop,' said director of operations Simon Entwisle.</p><p>"One particular concern is the distress these texts may be causing to vulnerable people. Our survey has shown that 12 people found the texts helpful and had used the service it offered - unfortunately that may be enough incentive for the individuals behind this to carry on sending them."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/637768/ico-claims-significant-progress-in-war-on-spam-texts</link>
                                                                            <description>
                            <![CDATA[ The watchdog thinks it is close to catching those guilty of spam texting in the UK, after raiding an office in the north of England. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8iHwCyvMgbCKGHmeZxNG28</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDgriGbxHQeKiB5b7qsbcf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Dec 2011 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Phones]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDgriGbxHQeKiB5b7qsbcf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDgriGbxHQeKiB5b7qsbcf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/637720/ico-hands-its-biggest-ever-fine-to-welsh-council" target="_blank" data-original-url="https://www.itpro.com/637720/ico-hands-its-biggest-ever-fine-to-welsh-council">Information Commissioner's Office</a> (ICO) claims to have made significant progress in finding those responsible for bothering UK citizens with mobile <a href="https://www.itpro.com/635623/malicous-spam-hits-epic-levels" target="_blank" data-original-url="https://www.itpro.com/635623/malicous-spam-hits-epic-levels">spam</a>.</p><p>The data protection watchdog today said it was almost certain it knew who was behind spam messages, but it needed more evidence to punish them.</p><p>The ICO has learned messages are being sent from unregistered pay-as-you-go SIM cards and has raided an office in the north of England as part of its investigations.</p><p>We've built a case that these people are causing damage and distress.</p><p>It said it was planning to execute more search warrants in the future.</p><p>"We've built a case that these people are causing damage and distress," an ICO spokesperson told <em>IT Pro</em>. "What we need to do is to be able to enforce action against them, is to gather more evidence.</p><p>"We are urging people to come forward with any information."</p><p>She confirmed the ICO would be able to fine those responsible up to 500,000.</p><p>The ICO has been working with various bodies in the UK to crack down on spam texting, including the Ministry of Justice, Ofcom and the Office of Fair Trading.</p><p>Data has indicated around 8 million spam texts are sent in the UK every day.</p><p>An ICO survey found 681 of 1,014 respondents said they had received a concerning spam text, feeling troubled about how their data had been obtained. Another 205 complained of the texts being inconvenient.</p><p>"There is also clearly a lot to be gained in raising public awareness about these messages. People need to realise that the numbers are randomly generated and that they shouldn't respond, even when encouraged to text back 'stop,' said director of operations Simon Entwisle.</p><p>"One particular concern is the distress these texts may be causing to vulnerable people. Our survey has shown that 12 people found the texts helpful and had used the service it offered - unfortunately that may be enough incentive for the individuals behind this to carry on sending them."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicous spam hits ‘epic’ levels ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.itpro.com/633604/spam-down-65-per-cent-year-on-year" target="_blank" data-original-url="https://www.itpro.com/633604/spam-down-65-per-cent-year-on-year">spammers</a> have returned with a vengeance as malicious spam hit "epic" levels in August, according to security experts.</p><p>M86 Security said it saw a "huge surge" in malicious spam which has far exceeded anything it has seen in the past two years.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9caCGkrqNCEaQoKBDpNU2k" name="" alt="Spam chart" src="https://cdn.mos.cms.futurecdn.net/9caCGkrqNCEaQoKBDpNU2k.jpg" mos="https://cdn.mos.cms.futurecdn.net/9caCGkrqNCEaQoKBDpNU2k.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The majority of the spam was put out by the notorious Cutwail botnet, with the Festi and Asprox botnets showing themselves to be significant contributors too.</p><p>Last week, 13 per cent of the overall spam volume consisted of malicious spam, marking an "unusual" jump, according to M86. On Monday, that proportion increased to 24 per cent.</p><p>"Four of the campaigns, which we identified as originating from the Cutwail botnet are mostly recycled spam themes Fedex, credit card, changelogs and invoices," M86 explained in a <a href="http://labs.m86security.com/2011/08/massive-rise-in-malicious-spam" target="_blank">blog post</a>.</p><p>"The malware is attached within a compressed ZIP archive and is a Trojan that downloads additional malware including Fake AV, SpyEye and the Cutwail spambot itself."</p><p>Spammers used typical tricks, such as telling users there credit card had been blocked, promising more information in an attached file. Anyone opening the attachment would risk infecting their machines.</p><p>It seems spammers have returned from a holiday break and are enthusiastically back to work.</p><p>Other spam offered rebates on purported accidental charges from hotels, as well as messages appearing to confirm UPS deliveries.</p><p>"This is an epic amount of malicious spam. After multiple recent botnet takedowns, cyber criminal groups remain resilient, clearly looking to build their botnets and distribute more fake AV in the process," M86 added.</p><p>"It seems spammers have returned from a holiday break and are enthusiastically back to work."</p><p>Spam had seen a significant drop earlier this year, largely thanks to a <a href="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown" target="_blank" data-original-url="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown">Microsoft-led operation taking on the Rustock super spammer botnet</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/635623/malicous-spam-hits-epic-levels</link>
                                                                            <description>
                            <![CDATA[ This month has seen a serious rise in malicious spam, according to M86 data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tkUjeGcb2wfJmMNo9PoQDd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/va9rAh3s4efjheZytzv7Fk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Aug 2011 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/va9rAh3s4efjheZytzv7Fk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/va9rAh3s4efjheZytzv7Fk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/633604/spam-down-65-per-cent-year-on-year" target="_blank" data-original-url="https://www.itpro.com/633604/spam-down-65-per-cent-year-on-year">spammers</a> have returned with a vengeance as malicious spam hit "epic" levels in August, according to security experts.</p><p>M86 Security said it saw a "huge surge" in malicious spam which has far exceeded anything it has seen in the past two years.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9caCGkrqNCEaQoKBDpNU2k" name="" alt="Spam chart" src="https://cdn.mos.cms.futurecdn.net/9caCGkrqNCEaQoKBDpNU2k.jpg" mos="https://cdn.mos.cms.futurecdn.net/9caCGkrqNCEaQoKBDpNU2k.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The majority of the spam was put out by the notorious Cutwail botnet, with the Festi and Asprox botnets showing themselves to be significant contributors too.</p><p>Last week, 13 per cent of the overall spam volume consisted of malicious spam, marking an "unusual" jump, according to M86. On Monday, that proportion increased to 24 per cent.</p><p>"Four of the campaigns, which we identified as originating from the Cutwail botnet are mostly recycled spam themes Fedex, credit card, changelogs and invoices," M86 explained in a <a href="http://labs.m86security.com/2011/08/massive-rise-in-malicious-spam" target="_blank">blog post</a>.</p><p>"The malware is attached within a compressed ZIP archive and is a Trojan that downloads additional malware including Fake AV, SpyEye and the Cutwail spambot itself."</p><p>Spammers used typical tricks, such as telling users there credit card had been blocked, promising more information in an attached file. Anyone opening the attachment would risk infecting their machines.</p><p>It seems spammers have returned from a holiday break and are enthusiastically back to work.</p><p>Other spam offered rebates on purported accidental charges from hotels, as well as messages appearing to confirm UPS deliveries.</p><p>"This is an epic amount of malicious spam. After multiple recent botnet takedowns, cyber criminal groups remain resilient, clearly looking to build their botnets and distribute more fake AV in the process," M86 added.</p><p>"It seems spammers have returned from a holiday break and are enthusiastically back to work."</p><p>Spam had seen a significant drop earlier this year, largely thanks to a <a href="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown" target="_blank" data-original-url="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown">Microsoft-led operation taking on the Rustock super spammer botnet</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Cisco email services to enhance security and management ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cisco has announced two new appliance-based email services that could help businesses handle compliance, management and security issues.</p><p>IronPort Outbreak Filters uses a combination of a malware-signature database and on-the-fly analytics to scan incoming emails to determine if any are spam or link to malicious payloads. Cisco claims the Filters can analyse not only text, but images, attachments, hidden code and scripts too.</p><p>If a user clicks on a link leading to a malware-infested webpage, the user will be redirected to a warning page instead.</p><p>Meanwhile, IronPort Business Class Email apparently includes extensive email security controls, such as recalling messages, message expiration and deciding who can forward an email and to whom. Depending on what other infrastructure their company has in place and what other services they use, Business Class Email users may also be able to use their email account user name and password to log into other services.</p><p>Administrators will also be able to enforce minimum levels of password complexity.</p><p>According to Soni Jiandani, Cisco's senior vice president of the Server Access and Virtualisation Technology Group, the IronPort services are examples of the benefits of proactive network-based security that customers can reply on instead of having to install and manage their own endpoint security checks.</p><p>Both Outbreak Filters and Business Class Email run on top of Cisco's existing range of C-series email security appliances which are available now.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/634894/new-cisco-email-services-to-enhance-security-and-management</link>
                                                                            <description>
                            <![CDATA[ Cisco's new email services could put Exchange's laughable email recall and receipts features to shame. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uLKvbBacCqC4fqhTkEAXqM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LoFe7iGCxrVDbdsfLxNysb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Jul 2011 05:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Email Providers]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alan Lu ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LoFe7iGCxrVDbdsfLxNysb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Cisco IronPort appliance]]></media:description>                                                            <media:text><![CDATA[A Cisco IronPort appliance]]></media:text>
                                <media:title type="plain"><![CDATA[A Cisco IronPort appliance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LoFe7iGCxrVDbdsfLxNysb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cisco has announced two new appliance-based email services that could help businesses handle compliance, management and security issues.</p><p>IronPort Outbreak Filters uses a combination of a malware-signature database and on-the-fly analytics to scan incoming emails to determine if any are spam or link to malicious payloads. Cisco claims the Filters can analyse not only text, but images, attachments, hidden code and scripts too.</p><p>If a user clicks on a link leading to a malware-infested webpage, the user will be redirected to a warning page instead.</p><p>Meanwhile, IronPort Business Class Email apparently includes extensive email security controls, such as recalling messages, message expiration and deciding who can forward an email and to whom. Depending on what other infrastructure their company has in place and what other services they use, Business Class Email users may also be able to use their email account user name and password to log into other services.</p><p>Administrators will also be able to enforce minimum levels of password complexity.</p><p>According to Soni Jiandani, Cisco's senior vice president of the Server Access and Virtualisation Technology Group, the IronPort services are examples of the benefits of proactive network-based security that customers can reply on instead of having to install and manage their own endpoint security checks.</p><p>Both Outbreak Filters and Business Class Email run on top of Cisco's existing range of C-series email security appliances which are available now.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos Endpoint Security and Data Protection 9.7 review ]]></title>
                                                                                                <dc:content><![CDATA[ <figure role="gallery"><figure><img src="https://cdn.mos.cms.futurecdn.net/CdZhKG6EJaMjXtEMBkEEDE.jpg" alt="Sophos Endpoint Security and Data Protection 9.7" /><figcaption>Sophos Endpoint Security and Data Protection 9.7</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/m5BprG5vv3TzuBVqAJXjqS.jpg" alt="The Enterprise Console provides good access to the main ESDP components and is very quick to post alerts and warnings when vi" /><figcaption>The Enterprise Console provides good access to the main ESDP components and is very quick to post alerts and warnings when vi</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/xc3zvchhTc2AJNt3S8Zg4T.jpg" alt="A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container." /><figcaption>A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container.</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/Axyb8WLSgMJpgx7UUsdffA.png" alt="Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re" /><figcaption>Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/G4RnaKz3owtqcCJTAxw2nn.png" alt="End users can use the local ESDP utility to run their own anti-virus scans, but will require local admin rights to configure " /><figcaption>End users can use the local ESDP utility to run their own anti-virus scans, but will require local admin rights to configure </figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/VfTWy9fz6NDkbRXfiV5pxm.jpg" alt="The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles." /><figcaption>The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles.</figcaption></figure></figure><p>Best known for its anti-virus software, Sophos also wants to provide full protection for your workstations and its latest Endpoint Security and Data Protection (ESDP) 9.7 software has a veritable feast of security measures. Naturally, its anti-virus software is at the top of the list, but ESDP partners this with firewall, intrusion prevention plus controls for removable devices, data and applications and tops them off with NAC (network access control) and disk encryption.</p><p>Sophos provides an import wizard that works directly with Active Directory</p><p>We found installation initially straightforward as you load the Enterprise Console on a designated management system and then introduce your client systems to it. Sophos provides an import wizard that works directly with Active Directory and we had no problems selecting the AD Computers container and adding all our Windows XP, 7, Server 2003 and Server 2008 R2 systems to the console.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xc3zvchhTc2AJNt3S8Zg4T" name="" alt="A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container." src="https://cdn.mos.cms.futurecdn.net/xc3zvchhTc2AJNt3S8Zg4T.jpg" mos="https://cdn.mos.cms.futurecdn.net/xc3zvchhTc2AJNt3S8Zg4T.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container. </span></figcaption></figure><p>A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container.</p><p>To deploy the agent you select all required systems from the lower pane in the console and choose the Protect Computer menu option. Before doing this some work was needed on our Windows 7 systems as we had to enable the remote registry service, turn off UAC completely and modify the advanced share settings as instructed in the manual.</p><p>You can choose which components to install on clients and we opted to leave Sophos' firewall out of the equation as the lab's gateway security appliance does a good enough job for our LAN-based systems. Once the agent had been installed, each system was added into a new group in the console ready to receive its instructions.</p><p>Policies are used to control endpoints and ESDP comes with a complete set of predefined ones. These should cover most eventualities, but you can create custom policies and assign them to selected groups.</p><p>An update policy is enabled by default and defines how often group members receive software updates. Other active policies cover anti-virus, intrusion prevention and the firewall. Policies for application, device and data control and tamper protection are disabled by default.</p><p>For anti-virus policies, you can decide how infected files are handled, create schedules for full systems scans and set up email alerts. Live protection can be enabled so if ESDP can't identify a suspicious file from the local signature files it'll pop online and check it against Sophos' hosted database service.</p><p>ESDP had no problems when we introduced some genuine viruses to our endpoints as these were blocked and placed in a local quarantine area. The agent notified the console each time which then flagged up a virus alert within a few seconds.</p><p>Application control policies are as easy to use and Sophos includes a heap of predefined applications which is just as well as you can't add your own. We were able to block access to utilities such as FTP clients, email apps including Windows Mail and Outlook Express and various browsers, although for Microsoft Office you can only block the entire suite.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Axyb8WLSgMJpgx7UUsdffA" name="" alt="Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re" src="https://cdn.mos.cms.futurecdn.net/Axyb8WLSgMJpgx7UUsdffA.png" mos="https://cdn.mos.cms.futurecdn.net/Axyb8WLSgMJpgx7UUsdffA.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re </span></figcaption></figure><p>Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to removable storage.</p><p>ESDP's device control isn't a patch on <a href="https://www.itpro.com/633769/devicelock-7-review" target="_blank" data-original-url="https://www.itpro.com/633769/devicelock-7-review">DeviceLock</a> as it can only control access to floppy, optical and USB removable storage plus modems, wireless and Bluetooth devices. However, you can passively monitor and log usage on each endpoint, block access entirely or allow read-only or full access. With a policy set to block all usage we inserted USB sticks on some of our endpoints and received pop up warnings advising us that access wasn't permitted.</p><p>Data control policies allow you to apply file matching rules to stop them being copied or emailed. File contents can also be checked for keywords, phrases and patterns and Sophos provides a huge predefined list of patterns which includes those required for compliancy with HIPAA, PCI-DSS and PII standards.</p><p>Although an entry in the ESDP console is provided for NAC, all you can do is list its policies as all configuration is done from a completely separate console. Another NAC agent is required on endpoints but this can be deployed from the ESDP console.</p><p>NAC policies combine profiles that look for specific software on endpoints before it'll allow them network access. Profiles include checks for operating systems, patches and service packs along with the ESDP anti-virus and firewall components. The policies also provide remediation services in other words users can be sent to a location where the necessary software can be found.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VfTWy9fz6NDkbRXfiV5pxm" name="" alt="The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles." src="https://cdn.mos.cms.futurecdn.net/VfTWy9fz6NDkbRXfiV5pxm.jpg" mos="https://cdn.mos.cms.futurecdn.net/VfTWy9fz6NDkbRXfiV5pxm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles. </span></figcaption></figure><p>The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles.</p><p>Last up is the SafeGuard encryption utility which is completely separate to ESDP. It provides tools to automate full disk encryption on endpoints with sensitive data, but uses a separate server component to handle key management and encryption policies and needs yet more agents installed on endpoints which must be run manually.</p><p>Leaving NAC and SafeGuard to one side, we found ESDP easy to deploy and use and capable of providing an extensive set of security measures for workstations and laptops. The ESDP console simplifies management and is suitable for large user bases, but adding in the NAC and SafeGuard components will complicate things immensely.</p><p><a href="https://www.itpro.com/634795/sophos-endpoint-security-and-data-protection-97-review" target="_blank" data-original-url="https://www.itpro.com/634795/sophos-endpoint-security-and-data-protection-97-review">So what's our verdict?</a></p><h2 id="verdict">Verdict</h2><p>The main ESDP software provides an impressive range of data security measures for the price and includes some useful controls for screening applications, data and devices which worked well during testing. If you stick with these alone then management will be fairly easy, even for larger businesses, but adding in the poorly-integrated NAC and SafeGuard components will almost certainly require dedicated support staff to handle them.</p><p>SYSTEM REQUIREMENTS FOR THE ENTERPRISE CONSOLE Memory: 1GB Hard disk: 500MB OS: Windows 7, Server 2003, Server 2008, Server 2008 R2 (32- and 64-bit for all operating systems)</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/634795/sophos-endpoint-security-and-data-protection-97-review</link>
                                                                            <description>
                            <![CDATA[ Sophos' latest Endpoint Security and Data Protection suite provides a wealth of features for protecting workstation and mobile data. It looks very good value, but managing it all may not be so simple. Dave Mitchell finds out if Sophos has gone a step too far. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wGYHpkaHQ7ktyV94q8WWm9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CdZhKG6EJaMjXtEMBkEEDE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Jul 2011 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CdZhKG6EJaMjXtEMBkEEDE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[The Enterprise Console provides good access to the main ESDP components and is very quick to post alerts and warnings when vi]]></media:description>                                                            <media:text><![CDATA[Sophos Endpoint Security and Data Protection 9.7]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos Endpoint Security and Data Protection 9.7]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CdZhKG6EJaMjXtEMBkEEDE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure role="gallery"><figure><img src="https://cdn.mos.cms.futurecdn.net/CdZhKG6EJaMjXtEMBkEEDE.jpg" alt="Sophos Endpoint Security and Data Protection 9.7" /><figcaption>Sophos Endpoint Security and Data Protection 9.7</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/m5BprG5vv3TzuBVqAJXjqS.jpg" alt="The Enterprise Console provides good access to the main ESDP components and is very quick to post alerts and warnings when vi" /><figcaption>The Enterprise Console provides good access to the main ESDP components and is very quick to post alerts and warnings when vi</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/xc3zvchhTc2AJNt3S8Zg4T.jpg" alt="A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container." /><figcaption>A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container.</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/Axyb8WLSgMJpgx7UUsdffA.png" alt="Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re" /><figcaption>Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/G4RnaKz3owtqcCJTAxw2nn.png" alt="End users can use the local ESDP utility to run their own anti-virus scans, but will require local admin rights to configure " /><figcaption>End users can use the local ESDP utility to run their own anti-virus scans, but will require local admin rights to configure </figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/VfTWy9fz6NDkbRXfiV5pxm.jpg" alt="The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles." /><figcaption>The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles.</figcaption></figure></figure><p>Best known for its anti-virus software, Sophos also wants to provide full protection for your workstations and its latest Endpoint Security and Data Protection (ESDP) 9.7 software has a veritable feast of security measures. Naturally, its anti-virus software is at the top of the list, but ESDP partners this with firewall, intrusion prevention plus controls for removable devices, data and applications and tops them off with NAC (network access control) and disk encryption.</p><p>Sophos provides an import wizard that works directly with Active Directory</p><p>We found installation initially straightforward as you load the Enterprise Console on a designated management system and then introduce your client systems to it. Sophos provides an import wizard that works directly with Active Directory and we had no problems selecting the AD Computers container and adding all our Windows XP, 7, Server 2003 and Server 2008 R2 systems to the console.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xc3zvchhTc2AJNt3S8Zg4T" name="" alt="A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container." src="https://cdn.mos.cms.futurecdn.net/xc3zvchhTc2AJNt3S8Zg4T.jpg" mos="https://cdn.mos.cms.futurecdn.net/xc3zvchhTc2AJNt3S8Zg4T.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container. </span></figcaption></figure><p>A wizard helps to add computers to the console and we had no problems importing our Active Directory Computers container.</p><p>To deploy the agent you select all required systems from the lower pane in the console and choose the Protect Computer menu option. Before doing this some work was needed on our Windows 7 systems as we had to enable the remote registry service, turn off UAC completely and modify the advanced share settings as instructed in the manual.</p><p>You can choose which components to install on clients and we opted to leave Sophos' firewall out of the equation as the lab's gateway security appliance does a good enough job for our LAN-based systems. Once the agent had been installed, each system was added into a new group in the console ready to receive its instructions.</p><p>Policies are used to control endpoints and ESDP comes with a complete set of predefined ones. These should cover most eventualities, but you can create custom policies and assign them to selected groups.</p><p>An update policy is enabled by default and defines how often group members receive software updates. Other active policies cover anti-virus, intrusion prevention and the firewall. Policies for application, device and data control and tamper protection are disabled by default.</p><p>For anti-virus policies, you can decide how infected files are handled, create schedules for full systems scans and set up email alerts. Live protection can be enabled so if ESDP can't identify a suspicious file from the local signature files it'll pop online and check it against Sophos' hosted database service.</p><p>ESDP had no problems when we introduced some genuine viruses to our endpoints as these were blocked and placed in a local quarantine area. The agent notified the console each time which then flagged up a virus alert within a few seconds.</p><p>Application control policies are as easy to use and Sophos includes a heap of predefined applications which is just as well as you can't add your own. We were able to block access to utilities such as FTP clients, email apps including Windows Mail and Outlook Express and various browsers, although for Microsoft Office you can only block the entire suite.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Axyb8WLSgMJpgx7UUsdffA" name="" alt="Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re" src="https://cdn.mos.cms.futurecdn.net/Axyb8WLSgMJpgx7UUsdffA.png" mos="https://cdn.mos.cms.futurecdn.net/Axyb8WLSgMJpgx7UUsdffA.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to re </span></figcaption></figure><p>Policies are used for each ESDP component and allow you to control the anti-virus scanner, application usage and access to removable storage.</p><p>ESDP's device control isn't a patch on <a href="https://www.itpro.com/633769/devicelock-7-review" target="_blank" data-original-url="https://www.itpro.com/633769/devicelock-7-review">DeviceLock</a> as it can only control access to floppy, optical and USB removable storage plus modems, wireless and Bluetooth devices. However, you can passively monitor and log usage on each endpoint, block access entirely or allow read-only or full access. With a policy set to block all usage we inserted USB sticks on some of our endpoints and received pop up warnings advising us that access wasn't permitted.</p><p>Data control policies allow you to apply file matching rules to stop them being copied or emailed. File contents can also be checked for keywords, phrases and patterns and Sophos provides a huge predefined list of patterns which includes those required for compliancy with HIPAA, PCI-DSS and PII standards.</p><p>Although an entry in the ESDP console is provided for NAC, all you can do is list its policies as all configuration is done from a completely separate console. Another NAC agent is required on endpoints but this can be deployed from the ESDP console.</p><p>NAC policies combine profiles that look for specific software on endpoints before it'll allow them network access. Profiles include checks for operating systems, patches and service packs along with the ESDP anti-virus and firewall components. The policies also provide remediation services in other words users can be sent to a location where the necessary software can be found.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VfTWy9fz6NDkbRXfiV5pxm" name="" alt="The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles." src="https://cdn.mos.cms.futurecdn.net/VfTWy9fz6NDkbRXfiV5pxm.jpg" mos="https://cdn.mos.cms.futurecdn.net/VfTWy9fz6NDkbRXfiV5pxm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles. </span></figcaption></figure><p>The NAC and SafeGuard components steepen the learning curve as they each have their own policy management consoles.</p><p>Last up is the SafeGuard encryption utility which is completely separate to ESDP. It provides tools to automate full disk encryption on endpoints with sensitive data, but uses a separate server component to handle key management and encryption policies and needs yet more agents installed on endpoints which must be run manually.</p><p>Leaving NAC and SafeGuard to one side, we found ESDP easy to deploy and use and capable of providing an extensive set of security measures for workstations and laptops. The ESDP console simplifies management and is suitable for large user bases, but adding in the NAC and SafeGuard components will complicate things immensely.</p><p><a href="https://www.itpro.com/634795/sophos-endpoint-security-and-data-protection-97-review" target="_blank" data-original-url="https://www.itpro.com/634795/sophos-endpoint-security-and-data-protection-97-review">So what's our verdict?</a></p><h2 id="verdict">Verdict</h2><p>The main ESDP software provides an impressive range of data security measures for the price and includes some useful controls for screening applications, data and devices which worked well during testing. If you stick with these alone then management will be fairly easy, even for larger businesses, but adding in the poorly-integrated NAC and SafeGuard components will almost certainly require dedicated support staff to handle them.</p><p>SYSTEM REQUIREMENTS FOR THE ENTERPRISE CONSOLE Memory: 1GB Hard disk: 500MB OS: Windows 7, Server 2003, Server 2008, Server 2008 R2 (32- and 64-bit for all operating systems)</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google+ spams users after disk space shortage ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Google has apologised to users of its new social networking service after inadvertently spamming them with notification messages.</p><p>The company said a glitch occurred after the Google+ service that keeps tabs on notifications ran out of disk space.</p><p>"For about 80 minutes we ran out of disk space on the service that keeps track of notifications. Hence our system continued to try sending notifications. Over, and over again. Yikes," said Vic Gundotra, senior vice president of social for Google, in a <a href="https://plus.google.com/107117483540235115863/posts/YUniwagZuKZ" target="_blank">blog post</a>.</p><p>"We didn't expect to hit these high thresholds so quickly, but we should have."</p><p>Google was "very sorry for the spam," Gundotra added.</p><p>Google's so-called Facebook rival has been hit by a few minor snags since it was unveiled towards the end of June.</p><p>The most significant problem has not been of Google's making, but of spammers.</p><p>A plethora of <a href="https://www.itpro.com/634666/spammers-spewing-on-google" target="_blank" data-original-url="https://www.itpro.com/634666/spammers-spewing-on-google">phony Google+ invitations</a> were sent out earlier this month, pointing recipients to the Canadian Family Pharmacy rather than the hyped Facebook rival.</p><p>Google has also been busy <a href="https://www.itpro.com/634786/google-business-profiles-being-deleted" target="_blank" data-original-url="https://www.itpro.com/634786/google-business-profiles-being-deleted">deleting company profiles</a> from the service, but only in preparation for a bespoke business service, expected to launch before the end of the year.</p><p>Facebook, meanwhile, has been trying to cement its dominance in the social networking space, adding Skype functionality last week.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/634813/google-spams-users-after-disk-space-shortage</link>
                                                                            <description>
                            <![CDATA[ Users receive a gushing apology after Google spams them after disk space shortage. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uZZT4pS1Z8tYuXqRhtrERu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/taZLdZUaLRP4ic329gnPt8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Jul 2011 10:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/taZLdZUaLRP4ic329gnPt8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google+]]></media:description>                                                            <media:text><![CDATA[Google+]]></media:text>
                                <media:title type="plain"><![CDATA[Google+]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/taZLdZUaLRP4ic329gnPt8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has apologised to users of its new social networking service after inadvertently spamming them with notification messages.</p><p>The company said a glitch occurred after the Google+ service that keeps tabs on notifications ran out of disk space.</p><p>"For about 80 minutes we ran out of disk space on the service that keeps track of notifications. Hence our system continued to try sending notifications. Over, and over again. Yikes," said Vic Gundotra, senior vice president of social for Google, in a <a href="https://plus.google.com/107117483540235115863/posts/YUniwagZuKZ" target="_blank">blog post</a>.</p><p>"We didn't expect to hit these high thresholds so quickly, but we should have."</p><p>Google was "very sorry for the spam," Gundotra added.</p><p>Google's so-called Facebook rival has been hit by a few minor snags since it was unveiled towards the end of June.</p><p>The most significant problem has not been of Google's making, but of spammers.</p><p>A plethora of <a href="https://www.itpro.com/634666/spammers-spewing-on-google" target="_blank" data-original-url="https://www.itpro.com/634666/spammers-spewing-on-google">phony Google+ invitations</a> were sent out earlier this month, pointing recipients to the Canadian Family Pharmacy rather than the hyped Facebook rival.</p><p>Google has also been busy <a href="https://www.itpro.com/634786/google-business-profiles-being-deleted" target="_blank" data-original-url="https://www.itpro.com/634786/google-business-profiles-being-deleted">deleting company profiles</a> from the service, but only in preparation for a bespoke business service, expected to launch before the end of the year.</p><p>Facebook, meanwhile, has been trying to cement its dominance in the social networking space, adding Skype functionality last week.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Spammers spewing on Google+ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cyber criminals have latched onto excitement surrounding the new Google social network, using spam to exploit users.</p><p>A host of fake Google+ invitations have been sent out, pointing recipients to the Canadian Family Pharmacy rather than the hyped Facebook rival.</p><p>"The spammers are no doubt hoping that the email will be hard to resist, as many people are eager to see what is being billed as Google's answer to Facebook," said Graham Cluley, senior technology consultant at Sophos.</p><p>"It's unclear just how many users will be tempted to buy drugs online, however research shows that last year alone, 36 million Americans bought drugs from online pharmacies, so this is a technique that is clearly continuing to work for spammers."</p><p>There has been plenty of intrigue around Google+, which was announced just last week. The service is not yet open to the wider public - those wanting to try out the social network need an invite.</p><p>Anything which arouses such excitement will also gain the attention of cyber criminals, as has always been the case.</p><p>"Due to the high demand of G+ invites being thrown at Google, to the point that the company actually had to cease the invitation process for the beta release of their fledgling social networking site, it is no surprise that spammers have latched onto this one as their latest target (and growing favourite?) to date," said GFI Labs researcher Jovi Umawing, in a <a href="http://sunbeltblog.blogspot.com/2011/07/spammers-hone-in-on-google.html" target="_blank">blog post</a>.</p><p>"Better than having malware there, if you ask me."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/634666/spammers-spewing-on-google</link>
                                                                            <description>
                            <![CDATA[ Google+ is unsurprisingly already getting the attention of spammers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wiq7bpuaKbnjC4H6xsZM7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YCsj4XXfV5uiMAm2deB9sj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Jul 2011 10:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YCsj4XXfV5uiMAm2deB9sj-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google]]></media:description>                                                            <media:text><![CDATA[Google]]></media:text>
                                <media:title type="plain"><![CDATA[Google]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YCsj4XXfV5uiMAm2deB9sj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals have latched onto excitement surrounding the new Google social network, using spam to exploit users.</p><p>A host of fake Google+ invitations have been sent out, pointing recipients to the Canadian Family Pharmacy rather than the hyped Facebook rival.</p><p>"The spammers are no doubt hoping that the email will be hard to resist, as many people are eager to see what is being billed as Google's answer to Facebook," said Graham Cluley, senior technology consultant at Sophos.</p><p>"It's unclear just how many users will be tempted to buy drugs online, however research shows that last year alone, 36 million Americans bought drugs from online pharmacies, so this is a technique that is clearly continuing to work for spammers."</p><p>There has been plenty of intrigue around Google+, which was announced just last week. The service is not yet open to the wider public - those wanting to try out the social network need an invite.</p><p>Anything which arouses such excitement will also gain the attention of cyber criminals, as has always been the case.</p><p>"Due to the high demand of G+ invites being thrown at Google, to the point that the company actually had to cease the invitation process for the beta release of their fledgling social networking site, it is no surprise that spammers have latched onto this one as their latest target (and growing favourite?) to date," said GFI Labs researcher Jovi Umawing, in a <a href="http://sunbeltblog.blogspot.com/2011/07/spammers-hone-in-on-google.html" target="_blank">blog post</a>.</p><p>"Better than having malware there, if you ask me."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Travelodge hit by data breach ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Travelodge customers have been with spammed fake job ads as a result of a <a href="https://www.itpro.com/632047/data-breach-cost-hits-19-million" target="_blank" data-original-url="https://www.itpro.com/632047/data-breach-cost-hits-19-million">data breach</a> at the hotel chain. The extent of the breach is as yet unclear, as is how system access was gained and what the motivation behind the hack was.</p><p>The company is currently investigating the issue, according to a <a href="http://www2.travelodge.co.uk/protect_your_data/Customer_Letter.pdf" target="_blank">letter</a> sent to customers yesterday by chief executive Guy Parsons.</p><p>"Our main priority is to ensure the security of our customers' data, which is why I wanted to make you aware that a small number of you may have received a spam email via the email address you have registered with us," the letter stated.</p><p>"The safety and security of your personal information is of the upmost importance to us and as a result we are currently conducting a comprehensive investigation into this issue."</p><p>Although it is not clear how many customers have been affected by the breach, more than six million people stayed at a Travelodge last year, according to the company's website. Some 87 per cent of customers also used its website to make reservations.</p><p>Parsons' letter sought to reassure worried customers the company had "not sold any customer data and no financial information has been compromised."</p><p>A Travelodge press spokeswoman confirmed reports of the breach were correct and advised a statement would be issued shortly.</p><p>The chain has informed the Information Commissioner's Office <a href="https://www.itpro.com/633925/breach-of-the-data-protection-peace" target="_blank" data-original-url="https://www.itpro.com/633925/breach-of-the-data-protection-peace">(ICO)</a> of the breach, according to reports.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/634450/travelodge-hit-by-data-breach</link>
                                                                            <description>
                            <![CDATA[ Customers of the hotel chain have been spammed following a data breach. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ppsVPL4gvaju5mYH1JhGNo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jZ3SSPWVdugBrG7kgzeAn7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jun 2011 12:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Centres]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Maggie Holland ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jZ3SSPWVdugBrG7kgzeAn7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Travelodge home page]]></media:description>                                                            <media:text><![CDATA[Travelodge home page]]></media:text>
                                <media:title type="plain"><![CDATA[Travelodge home page]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jZ3SSPWVdugBrG7kgzeAn7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Travelodge customers have been with spammed fake job ads as a result of a <a href="https://www.itpro.com/632047/data-breach-cost-hits-19-million" target="_blank" data-original-url="https://www.itpro.com/632047/data-breach-cost-hits-19-million">data breach</a> at the hotel chain. The extent of the breach is as yet unclear, as is how system access was gained and what the motivation behind the hack was.</p><p>The company is currently investigating the issue, according to a <a href="http://www2.travelodge.co.uk/protect_your_data/Customer_Letter.pdf" target="_blank">letter</a> sent to customers yesterday by chief executive Guy Parsons.</p><p>"Our main priority is to ensure the security of our customers' data, which is why I wanted to make you aware that a small number of you may have received a spam email via the email address you have registered with us," the letter stated.</p><p>"The safety and security of your personal information is of the upmost importance to us and as a result we are currently conducting a comprehensive investigation into this issue."</p><p>Although it is not clear how many customers have been affected by the breach, more than six million people stayed at a Travelodge last year, according to the company's website. Some 87 per cent of customers also used its website to make reservations.</p><p>Parsons' letter sought to reassure worried customers the company had "not sold any customer data and no financial information has been compromised."</p><p>A Travelodge press spokeswoman confirmed reports of the breach were correct and advised a statement would be issued shortly.</p><p>The chain has informed the Information Commissioner's Office <a href="https://www.itpro.com/633925/breach-of-the-data-protection-peace" target="_blank" data-original-url="https://www.itpro.com/633925/breach-of-the-data-protection-peace">(ICO)</a> of the breach, according to reports.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Spam down 65 per cent year-on-year ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Spam has dropped 65.42 per cent year-on-year as the <a href="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown" target="_blank" data-original-url="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown">Rustock takedown</a> continues to have an impact, a report has shown.</p><p>Having fallen 27.43 per cent in March, average daily <a href="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown" target="_blank" data-original-url="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown">spam</a> went down by another 5.35 per cent in April, Symantec discovered.</p><p>In April 2010, spam made up 89.22 per cent of all messages, compared to 74.81 per cent this year.</p><p>Despite the decline, spammers still latched onto some major news events as part of their campaigns.</p><p>In particular, they jumped on the death of Osama Bin Laden, poisoning messages and claiming to show unseen footage of the killing.</p><p>"Following a historical pattern, we observed more legitimate messages than spam immediately following the death," Symantec said in its report.</p><p>"After 24-48 hours, however, we saw more targeted and sophisticated spam attacks leveraging this event."</p><p>In one example, Symantec saw a major news organisation spoofed within an email claiming to show uncensored photos and videos from the CIA-led raid.</p><p>Recent research from uSwitch.com found, in total, British consumers were being sent 111 million spam emails and text messages every day.</p><p>Getting phishy with it</p><p>Phishing increased 15.61 per cent in April when compared to March, as cyber criminals made further use of automated toolkits and unique domains.</p><p>Phishing websites created by automated toolkits increased by around 26.19 per cent, whilst unique URLs went up 12.29 per cent.</p><p>Scammers also used multi-lingual techniques to snare users. The number of non-English phishing sites rose 16.23 per cent, with Portuguese, Italian and Spanish the most commonly used languages outside of English.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/633604/spam-down-65-per-cent-year-on-year</link>
                                                                            <description>
                            <![CDATA[ Following the Rustock shutdown, spam takes another hit in April. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uSREgw2HxrJdtU3Ycifiip</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2sssCVWLgZjhDLCnmipBwi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 May 2011 10:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2sssCVWLgZjhDLCnmipBwi-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2sssCVWLgZjhDLCnmipBwi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Spam has dropped 65.42 per cent year-on-year as the <a href="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown" target="_blank" data-original-url="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown">Rustock takedown</a> continues to have an impact, a report has shown.</p><p>Having fallen 27.43 per cent in March, average daily <a href="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown" target="_blank" data-original-url="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown">spam</a> went down by another 5.35 per cent in April, Symantec discovered.</p><p>In April 2010, spam made up 89.22 per cent of all messages, compared to 74.81 per cent this year.</p><p>Despite the decline, spammers still latched onto some major news events as part of their campaigns.</p><p>In particular, they jumped on the death of Osama Bin Laden, poisoning messages and claiming to show unseen footage of the killing.</p><p>"Following a historical pattern, we observed more legitimate messages than spam immediately following the death," Symantec said in its report.</p><p>"After 24-48 hours, however, we saw more targeted and sophisticated spam attacks leveraging this event."</p><p>In one example, Symantec saw a major news organisation spoofed within an email claiming to show uncensored photos and videos from the CIA-led raid.</p><p>Recent research from uSwitch.com found, in total, British consumers were being sent 111 million spam emails and text messages every day.</p><p>Getting phishy with it</p><p>Phishing increased 15.61 per cent in April when compared to March, as cyber criminals made further use of automated toolkits and unique domains.</p><p>Phishing websites created by automated toolkits increased by around 26.19 per cent, whilst unique URLs went up 12.29 per cent.</p><p>Scammers also used multi-lingual techniques to snare users. The number of non-English phishing sites rose 16.23 per cent, with Portuguese, Italian and Spanish the most commonly used languages outside of English.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI warns of Osama Bin Laden photo malware ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The FBI has warned computer users may be hit by <a href="https://www.itpro.com/631642/trojans-still-reigning-in-malware-top-10" target="_blank" data-original-url="https://www.itpro.com/631642/trojans-still-reigning-in-malware-top-10">malware</a> if they click on emails claiming to offer pictures of Osama Bin Laden's corpse.</p><p>Even if the messages appear to come from a known sender, recipients should still not download any files claiming to be photos or videos of Bin Laden, the FBI said.</p><p>"This malicious software, or 'malware,' can embed itself in computers and spread to users' contact lists, thereby infecting the systems of associates, friends and family members," the law enforcement body said in a statement.</p><p>"These viruses are often programmed to steal your personally identifiable information."</p><p>The former Al Qaeda leader may be gone, but scams using Bin Laden are very much alive, as cyber criminals look to popular web services to try and dupe users.</p><p>Symantec warned spam, malware and phishing attacks have flourished since the news broke.</p><p>"Currently, our decoy probes are receiving multiple malicious spam samples in Portuguese, French and Spanish," the firm revealed in a <a href="http://www.symantec.com/connect/blogs/malware-and-phishing-attacks-flourish-following-news-osama-s-death" target="_blank">blog</a> post.</p><p>"Analysis of these attacks shows that most of the malicious attacks have originated from Brazil, Europe and the US."</p><p>Facebook has played home to a raft of scams based on the news story, with one asking users to copy and paste code into their address bar to view a video of Bin Laden being killed.</p><p>Users are then prompted to carry out a survey, which will earn the scammers money.</p><p>BitDefender research, meanwhile, has indicated 11.21 per cent of Facebook scams in the last 24 hours were themed around Bin Laden's death.</p><p>Yesterday, <a href="https://www.itpro.com/633163/mac-os-x-gets-first-ever-crimeware-kit" target="_blank" data-original-url="https://www.itpro.com/633163/mac-os-x-gets-first-ever-crimeware-kit">Sophos warned of poisoned SEO attacks</a> on Google designed to ensnare those looking for information on the death of Bin Laden.</p><p>The end game for the cyber criminals in these attacks has been to get fake antivirus installed on users' systems.</p><p>On Sunday, between 6pm and 9pm PDT, Google saw a one million per cent increase in searches for the term "bin laden."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/633211/fbi-warns-of-osama-bin-laden-photo-malware</link>
                                                                            <description>
                            <![CDATA[ Osama Bin Laden may be dead, but the FBI has warned of emails claiming to contain images of the former Al Qaeda leader. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dWfKZRDnukdBM2QXkSQMXr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FSEjaDiGcJKT6XUqe4NLtM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 May 2011 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FSEjaDiGcJKT6XUqe4NLtM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[scam]]></media:description>                                                            <media:text><![CDATA[scam]]></media:text>
                                <media:title type="plain"><![CDATA[scam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FSEjaDiGcJKT6XUqe4NLtM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has warned computer users may be hit by <a href="https://www.itpro.com/631642/trojans-still-reigning-in-malware-top-10" target="_blank" data-original-url="https://www.itpro.com/631642/trojans-still-reigning-in-malware-top-10">malware</a> if they click on emails claiming to offer pictures of Osama Bin Laden's corpse.</p><p>Even if the messages appear to come from a known sender, recipients should still not download any files claiming to be photos or videos of Bin Laden, the FBI said.</p><p>"This malicious software, or 'malware,' can embed itself in computers and spread to users' contact lists, thereby infecting the systems of associates, friends and family members," the law enforcement body said in a statement.</p><p>"These viruses are often programmed to steal your personally identifiable information."</p><p>The former Al Qaeda leader may be gone, but scams using Bin Laden are very much alive, as cyber criminals look to popular web services to try and dupe users.</p><p>Symantec warned spam, malware and phishing attacks have flourished since the news broke.</p><p>"Currently, our decoy probes are receiving multiple malicious spam samples in Portuguese, French and Spanish," the firm revealed in a <a href="http://www.symantec.com/connect/blogs/malware-and-phishing-attacks-flourish-following-news-osama-s-death" target="_blank">blog</a> post.</p><p>"Analysis of these attacks shows that most of the malicious attacks have originated from Brazil, Europe and the US."</p><p>Facebook has played home to a raft of scams based on the news story, with one asking users to copy and paste code into their address bar to view a video of Bin Laden being killed.</p><p>Users are then prompted to carry out a survey, which will earn the scammers money.</p><p>BitDefender research, meanwhile, has indicated 11.21 per cent of Facebook scams in the last 24 hours were themed around Bin Laden's death.</p><p>Yesterday, <a href="https://www.itpro.com/633163/mac-os-x-gets-first-ever-crimeware-kit" target="_blank" data-original-url="https://www.itpro.com/633163/mac-os-x-gets-first-ever-crimeware-kit">Sophos warned of poisoned SEO attacks</a> on Google designed to ensnare those looking for information on the death of Bin Laden.</p><p>The end game for the cyber criminals in these attacks has been to get fake antivirus installed on users' systems.</p><p>On Sunday, between 6pm and 9pm PDT, Google saw a one million per cent increase in searches for the term "bin laden."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bagle to succeed Rustock as spam king? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A botnet known as Bagle could replace the once dominant spam king Rustock, even though the recent takedown had a significant impact on junk mail levels.</p><p>Spam volumes dropped by 33.6 per cent between 15 and 17 March, according to MessageLabs Intelligence. The decrease came after <a href="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown" target="_blank" data-original-url="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown">Rustock was successfully taken out</a> thanks to a collaborative effort led by Microsoft.</p><p>In the following days, spam accounted for around 33 billion emails a day, compared to an average of 52 billion in the previous week.</p><p>However, other botnets have upped their game, with Bagle usurping Rustock as the most active spamming botnet of 2011.</p><p>Bagle wasn't even in the top 10 spam-sending botnets at the end of 2010, but is now pushing out around 8.31 billion emails a day most of which have been linked to pharmaceutical products.</p><p>Rustock was a notorious pharmaceutical spammer as well.</p><p>Paul Wood, MessageLabs Intelligence senior analyst at Symantec.cloud, said Bagle has been more consistent in sending out spam than Rustock.</p><p>"What happened with Rustock was that every two to three days it would send out a massive burst of spam and then would go quiet," he told <em>IT PRO</em>.</p><p>"The amount of spam now coming from Bagle is consistent every day. Even though it doesn't have as many bots under its control as a botnet like Rustock, it's actually able to send more spam because of that consistency."</p><p>Rustock may not be gone for good either, according to Wood, as the botnet has some backup redundancy in its command and control channels.</p><p>Wood also indicated a "Son of Rustock" could emerge from the ashes of the apparently deceased botnet.</p><p>"We did see that when McColo was taken down, when there was a botnet called Srizbi, which accounted then for about 50 per cent of all spam," Wood added.</p><p>"[After the McColo takedown] it was a matter of months before spam levels returned to previous volumes. We were then seeing other botnets picking up the slack. That might be what we're seeing with Bagle because there is demand there from spammers and affiliates, particularly they want to be able to send this stuff anonymously."</p><p><em>IT PRO</em> recently <a href="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown" target="_blank" data-original-url="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown">spoke to FireEye senior security researcher Alex Lanstein</a>, who worked with Microsoft on the Rustock takedown.</p><p>He suggested the perpetrators may give up on Rustock given the amount of money they would have made from the operation and the fact they face being hunted by law enforcement bodies.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/632323/bagle-to-succeed-rustock-as-spam-king</link>
                                                                            <description>
                            <![CDATA[ There may be a new botnet spamming king in town in the form of Bagle. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kzsVKyC7YkZKB6wGkbFhfC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t46xcCSY83x9LvgRtHBGpd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Mar 2011 12:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t46xcCSY83x9LvgRtHBGpd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t46xcCSY83x9LvgRtHBGpd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A botnet known as Bagle could replace the once dominant spam king Rustock, even though the recent takedown had a significant impact on junk mail levels.</p><p>Spam volumes dropped by 33.6 per cent between 15 and 17 March, according to MessageLabs Intelligence. The decrease came after <a href="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown" target="_blank" data-original-url="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown">Rustock was successfully taken out</a> thanks to a collaborative effort led by Microsoft.</p><p>In the following days, spam accounted for around 33 billion emails a day, compared to an average of 52 billion in the previous week.</p><p>However, other botnets have upped their game, with Bagle usurping Rustock as the most active spamming botnet of 2011.</p><p>Bagle wasn't even in the top 10 spam-sending botnets at the end of 2010, but is now pushing out around 8.31 billion emails a day most of which have been linked to pharmaceutical products.</p><p>Rustock was a notorious pharmaceutical spammer as well.</p><p>Paul Wood, MessageLabs Intelligence senior analyst at Symantec.cloud, said Bagle has been more consistent in sending out spam than Rustock.</p><p>"What happened with Rustock was that every two to three days it would send out a massive burst of spam and then would go quiet," he told <em>IT PRO</em>.</p><p>"The amount of spam now coming from Bagle is consistent every day. Even though it doesn't have as many bots under its control as a botnet like Rustock, it's actually able to send more spam because of that consistency."</p><p>Rustock may not be gone for good either, according to Wood, as the botnet has some backup redundancy in its command and control channels.</p><p>Wood also indicated a "Son of Rustock" could emerge from the ashes of the apparently deceased botnet.</p><p>"We did see that when McColo was taken down, when there was a botnet called Srizbi, which accounted then for about 50 per cent of all spam," Wood added.</p><p>"[After the McColo takedown] it was a matter of months before spam levels returned to previous volumes. We were then seeing other botnets picking up the slack. That might be what we're seeing with Bagle because there is demand there from spammers and affiliates, particularly they want to be able to send this stuff anonymously."</p><p><em>IT PRO</em> recently <a href="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown" target="_blank" data-original-url="https://www.itpro.com/632185/the-impact-of-the-rustock-takedown">spoke to FireEye senior security researcher Alex Lanstein</a>, who worked with Microsoft on the Rustock takedown.</p><p>He suggested the perpetrators may give up on Rustock given the amount of money they would have made from the operation and the fact they face being hunted by law enforcement bodies.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft takes credit for Rustock shutdown ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft was responsible for taking down Rustock the giant spamming botnet which <a href="https://www.itpro.com/631993/mega-botnet-rustock-stops-spamming" target="_blank" data-original-url="https://www.itpro.com/631993/mega-botnet-rustock-stops-spamming">stopped spewing out messages this week</a>.</p><p>Researchers from the likes of M86 Security and Symantec were at a loss as to why Rustock activity had ceased, but now Microsoft has explained how the botnet was killed off.</p><p>The Redmond firm revealed it took out the botnet as part of Operation b107 a joint initiative between Microsoft's Digital Crimes Unit, its Malware Protection Centre and its Trustworthy Computing branch.</p><p>The operation saw the connection between Rustock's command and control structure and the computers operating under its control severed.</p><p>To do this, command and control servers had to be seized in numerous hosting locations.</p><p>Servers were taken and analysed from five hosting providers in seven cities across the US, including Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus.</p><p>Prior to this, Microsoft and its partners, including <a href="https://www.itpro.com/631999/fireeye-looks-to-break-into-uk" target="_blank" data-original-url="https://www.itpro.com/631999/fireeye-looks-to-break-into-uk">FireEye</a> and security experts at the University of Washington, had to prove to the US District Court for the Western District of Washington that Rustock needed taking out.</p><p>Pharmaceutical firm Pfizer was brought in as well, as Rustock helped push out significant amounts of spam flogging fake drugs.</p><p>Outside of the US, Microsoft worked with the Dutch High Tech Crime Unit within the Netherlands Police Agency to put an end to Rustock activity.</p><p>The Redmond firm also blocked registration of domains in China that Rustock could have used for command and control servers.</p><p>Come together, right now</p><p>"With help from the upstream providers, we successfully severed the IP addresses that controlled the botnet, cutting off communication and disabling it," said Richard Boscovich, senior attorney for the Microsoft Digital Crimes Unit, on a <a href="http://blogs.technet.com/b/microsoft_on_the_issues/archive/2011/03/17/taking-down-botnets-microsoft-and-the-rustock-botnet.aspx" target="_blank">blog</a>.</p><p>"This case and this operation are ongoing and our investigators are now inspecting the evidence gathered from the seizures to learn what we can about the botnet's operations."</p><p>He confirmed Microsoft would continue to invest in similar operations in the future. The firm was also a major player in putting an end to the Waledac, or Storm, botnet.</p><p>Boscovich called for greater collaboration across industries to reduce botnet activity.</p><p>"DCU's research shows there may be close to one million computers infected with Rustock malware, all under the control of the person or people operating the network like a remote army, usually without the computer's owner even aware that his computer has been hijacked," Boscovich added.</p><p>"With your help, and the continued public and private cooperation of industry, academia and law enforcement such as Operation b107, we can stop criminals from using botnets to wreak havoc on the internet."</p><p>Last year saw a number of significant botnet takedowns. First came the shut down of <a href="https://www.itpro.com/623914/fear-and-loathing-in-the-mariposa-aftermath" target="_blank" data-original-url="https://www.itpro.com/623914/fear-and-loathing-in-the-mariposa-aftermath">Mariposa</a>, the perpetrators of which were eventually arrested.</p><p>The massive <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab</a> botnet, which had infected over 30 million computers worldwide, was also brought down.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown</link>
                                                                            <description>
                            <![CDATA[ Microsoft and a range of partners were responsible for the takedown of major spamming botnet Rustock. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ibpmqhF9wc7ZoyYtRDk5nb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LgVCHFpVjknCjfEbGNDXSH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Mar 2011 11:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Hosting]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LgVCHFpVjknCjfEbGNDXSH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime]]></media:description>                                                            <media:text><![CDATA[Cyber crime]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LgVCHFpVjknCjfEbGNDXSH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft was responsible for taking down Rustock the giant spamming botnet which <a href="https://www.itpro.com/631993/mega-botnet-rustock-stops-spamming" target="_blank" data-original-url="https://www.itpro.com/631993/mega-botnet-rustock-stops-spamming">stopped spewing out messages this week</a>.</p><p>Researchers from the likes of M86 Security and Symantec were at a loss as to why Rustock activity had ceased, but now Microsoft has explained how the botnet was killed off.</p><p>The Redmond firm revealed it took out the botnet as part of Operation b107 a joint initiative between Microsoft's Digital Crimes Unit, its Malware Protection Centre and its Trustworthy Computing branch.</p><p>The operation saw the connection between Rustock's command and control structure and the computers operating under its control severed.</p><p>To do this, command and control servers had to be seized in numerous hosting locations.</p><p>Servers were taken and analysed from five hosting providers in seven cities across the US, including Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus.</p><p>Prior to this, Microsoft and its partners, including <a href="https://www.itpro.com/631999/fireeye-looks-to-break-into-uk" target="_blank" data-original-url="https://www.itpro.com/631999/fireeye-looks-to-break-into-uk">FireEye</a> and security experts at the University of Washington, had to prove to the US District Court for the Western District of Washington that Rustock needed taking out.</p><p>Pharmaceutical firm Pfizer was brought in as well, as Rustock helped push out significant amounts of spam flogging fake drugs.</p><p>Outside of the US, Microsoft worked with the Dutch High Tech Crime Unit within the Netherlands Police Agency to put an end to Rustock activity.</p><p>The Redmond firm also blocked registration of domains in China that Rustock could have used for command and control servers.</p><p>Come together, right now</p><p>"With help from the upstream providers, we successfully severed the IP addresses that controlled the botnet, cutting off communication and disabling it," said Richard Boscovich, senior attorney for the Microsoft Digital Crimes Unit, on a <a href="http://blogs.technet.com/b/microsoft_on_the_issues/archive/2011/03/17/taking-down-botnets-microsoft-and-the-rustock-botnet.aspx" target="_blank">blog</a>.</p><p>"This case and this operation are ongoing and our investigators are now inspecting the evidence gathered from the seizures to learn what we can about the botnet's operations."</p><p>He confirmed Microsoft would continue to invest in similar operations in the future. The firm was also a major player in putting an end to the Waledac, or Storm, botnet.</p><p>Boscovich called for greater collaboration across industries to reduce botnet activity.</p><p>"DCU's research shows there may be close to one million computers infected with Rustock malware, all under the control of the person or people operating the network like a remote army, usually without the computer's owner even aware that his computer has been hijacked," Boscovich added.</p><p>"With your help, and the continued public and private cooperation of industry, academia and law enforcement such as Operation b107, we can stop criminals from using botnets to wreak havoc on the internet."</p><p>Last year saw a number of significant botnet takedowns. First came the shut down of <a href="https://www.itpro.com/623914/fear-and-loathing-in-the-mariposa-aftermath" target="_blank" data-original-url="https://www.itpro.com/623914/fear-and-loathing-in-the-mariposa-aftermath">Mariposa</a>, the perpetrators of which were eventually arrested.</p><p>The massive <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab</a> botnet, which had infected over 30 million computers worldwide, was also brought down.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mega-botnet Rustock stops spamming ]]></title>
                                                                                                <dc:content><![CDATA[ <p>One of the biggest spamming botnets of all time appears to have stopped spewing out messages, yet no clear explanation has been given as to why.</p><p>The Rustock botnet, which was pushing out 47.5 per cent of all spam by the end of 2010, stopped spamming yesterday afternoon around 3pm GMT.</p><p>Initial reports emerged on the <a href="http://krebsonsecurity.com/2011/03/rustock-botnet-flatlined-spam-volumes-plummet" target="_blank">KrebsonSecurity</a> blog, and both Symantec and M86 Security have confirmed Rustock's decline in spam output.</p><p>"It is unclear yet who or what caused the shutdown. It's also possible it has been abandoned," said Phil Hay, lead security researcher with M86, on a <a href="http://labs.m86security.com/2011/03/rustock-down" target="_blank">blog</a>.</p><p>"Whatever the reason, let's hope this one sticks. Previous attempts at botnet shutdowns have tended to be short lived as the botnet herders simply regroup and start again. It's too early to say bye bye Rustock, but the thought is certainly nice."</p><p>Rustock output was hit last year when Spammit.com, a partner programme responsible for significant amounts of pharmaceutical spam, was <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">shut down</a>.</p><p>Since then other botnets emerged as equally prominent spammers.</p><p>"This increase from other botnets means that so far, the takedown of Rustock hasn't had much noticeable effect on the overall amount of spam tracked by MessageLabs Intelligence," said Paul Wood, MessageLabs Intelligence senior analyst at Symantec Hosted Services, on a <a href="http://www.symantec.com/connect/blogs/has-rustock-botnet-ceased-spamming" target="_blank">blog</a>.</p><p>"Rustock has gone quiet before, over the last holiday season it stopped spamming for several days but came back as strong as ever. Only time will tell if this will happen again."</p><p>Overall spam rose in February, according to data from Symantec, following a lull in activity in the latter half of 2010 and the start of 2011.</p><p>Average daily spam volume increased 8.7 per cent in February month-over-month, as spam made up 80.65 per cent of all messages, compared with 79.55 per cent in January.</p><p>Phishing spike</p><p>Meanwhile, there was a significant spike in phishing last month, with an increase of nearly 40 per cent as hackers jumped on automated tools to help them dupe web users, Symantec said.</p><p>Phishing websites created by automated toolkits went up by around 50.33 per cent when compared to January, whilst phishing sites with unique URLs increased by 33.73 per cent.</p><p>Little changed from the UK perspective, as four per cent of all phishing attacks emanated from the country the same figure as in January.</p><p>There was a notable change in the US though, as phishing attacks originating from the country fell by 10 per cent. The nation still remained the worst offender, however, with a 52 per cent share.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/631993/mega-botnet-rustock-stops-spamming</link>
                                                                            <description>
                            <![CDATA[ Rustock, the once dominant spam botnet, seems to have been taken out of contention. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jDHStDzaugKdph62VezczS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ByLLLrBrhHAGNrrCZ5ujHT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Mar 2011 14:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ByLLLrBrhHAGNrrCZ5ujHT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Botnet]]></media:description>                                                            <media:text><![CDATA[Botnet]]></media:text>
                                <media:title type="plain"><![CDATA[Botnet]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ByLLLrBrhHAGNrrCZ5ujHT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>One of the biggest spamming botnets of all time appears to have stopped spewing out messages, yet no clear explanation has been given as to why.</p><p>The Rustock botnet, which was pushing out 47.5 per cent of all spam by the end of 2010, stopped spamming yesterday afternoon around 3pm GMT.</p><p>Initial reports emerged on the <a href="http://krebsonsecurity.com/2011/03/rustock-botnet-flatlined-spam-volumes-plummet" target="_blank">KrebsonSecurity</a> blog, and both Symantec and M86 Security have confirmed Rustock's decline in spam output.</p><p>"It is unclear yet who or what caused the shutdown. It's also possible it has been abandoned," said Phil Hay, lead security researcher with M86, on a <a href="http://labs.m86security.com/2011/03/rustock-down" target="_blank">blog</a>.</p><p>"Whatever the reason, let's hope this one sticks. Previous attempts at botnet shutdowns have tended to be short lived as the botnet herders simply regroup and start again. It's too early to say bye bye Rustock, but the thought is certainly nice."</p><p>Rustock output was hit last year when Spammit.com, a partner programme responsible for significant amounts of pharmaceutical spam, was <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">shut down</a>.</p><p>Since then other botnets emerged as equally prominent spammers.</p><p>"This increase from other botnets means that so far, the takedown of Rustock hasn't had much noticeable effect on the overall amount of spam tracked by MessageLabs Intelligence," said Paul Wood, MessageLabs Intelligence senior analyst at Symantec Hosted Services, on a <a href="http://www.symantec.com/connect/blogs/has-rustock-botnet-ceased-spamming" target="_blank">blog</a>.</p><p>"Rustock has gone quiet before, over the last holiday season it stopped spamming for several days but came back as strong as ever. Only time will tell if this will happen again."</p><p>Overall spam rose in February, according to data from Symantec, following a lull in activity in the latter half of 2010 and the start of 2011.</p><p>Average daily spam volume increased 8.7 per cent in February month-over-month, as spam made up 80.65 per cent of all messages, compared with 79.55 per cent in January.</p><p>Phishing spike</p><p>Meanwhile, there was a significant spike in phishing last month, with an increase of nearly 40 per cent as hackers jumped on automated tools to help them dupe web users, Symantec said.</p><p>Phishing websites created by automated toolkits went up by around 50.33 per cent when compared to January, whilst phishing sites with unique URLs increased by 33.73 per cent.</p><p>Little changed from the UK perspective, as four per cent of all phishing attacks emanated from the country the same figure as in January.</p><p>There was a notable change in the US though, as phishing attacks originating from the country fell by 10 per cent. The nation still remained the worst offender, however, with a 52 per cent share.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pharmacy spammers abuse Google’s good name ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A pharmacy <a href="https://www.itpro.com/630664/western-europe-spam-drop-significant" target="_blank" data-original-url="https://www.itpro.com/630664/western-europe-spam-drop-significant">spam</a> campaign has stolen Google's brand identity in a bid to snare web users.</p><p>The spammers were seen promoting an online pharmacy supposedly accredited by the search giant, MessageLabs found.</p><p>"This is obvious brand hijacking: Google does not host or approve any pharmacy sites," said Paul Wood, MessageLabs Intelligence senior analyst at Symantec Hosted Services, in a <a href="http://www.symantec.com/connect/blogs/new-pharmacy-spam-campaign-using-google-brand-hijacking" target="_blank">blog post</a>.</p><p>"This type of brand hijacking is a serious problem for well-known brands and can harm their reputation, as users might wrongly associate the nuisance factor of receiving such email with the brand."</p><p>A Google spokesperson said the firm had seen its brand being ripped off by spammers before.</p><p>"Google has a track record of fighting similar types of scams, and we also recommend that users carefully review online offers that look too good to be true before entering any of their information," the spokesperson said.</p><p>Targets were sent messages promoting a hair-loss prevention drug and a link, which directed users to the spammer's blog, where a purportedly Google-sponsored pharmacy was advertised.</p><p>Symantec automatically blocked more than 250 similar spam-created blogs over just two days.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="csCCpSyikXkVSkd94pCJvm" name="" alt="Google" src="https://cdn.mos.cms.futurecdn.net/csCCpSyikXkVSkd94pCJvm.jpg" mos="https://cdn.mos.cms.futurecdn.net/csCCpSyikXkVSkd94pCJvm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>"It is likely that the spammer wants to capitalise on Google's universally known name to add legitimacy to their products," Wood added.</p><p>"With Google's increasing diverse product range, spammers are perhaps hoping that a fake Google-accredited pharmacy will be plausible to some recipients."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/631144/pharmacy-spammers-abuse-googles-good-name</link>
                                                                            <description>
                            <![CDATA[ Spammers are manipulating Google's logo to make it look as though the search giant has accredited a supposed online pharmacy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jqUxryU7yXmbtFrQxiQpFy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KY9oK9Q3RRsQUnmYHdBzNb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Feb 2011 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KY9oK9Q3RRsQUnmYHdBzNb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google]]></media:description>                                                            <media:text><![CDATA[Google]]></media:text>
                                <media:title type="plain"><![CDATA[Google]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KY9oK9Q3RRsQUnmYHdBzNb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A pharmacy <a href="https://www.itpro.com/630664/western-europe-spam-drop-significant" target="_blank" data-original-url="https://www.itpro.com/630664/western-europe-spam-drop-significant">spam</a> campaign has stolen Google's brand identity in a bid to snare web users.</p><p>The spammers were seen promoting an online pharmacy supposedly accredited by the search giant, MessageLabs found.</p><p>"This is obvious brand hijacking: Google does not host or approve any pharmacy sites," said Paul Wood, MessageLabs Intelligence senior analyst at Symantec Hosted Services, in a <a href="http://www.symantec.com/connect/blogs/new-pharmacy-spam-campaign-using-google-brand-hijacking" target="_blank">blog post</a>.</p><p>"This type of brand hijacking is a serious problem for well-known brands and can harm their reputation, as users might wrongly associate the nuisance factor of receiving such email with the brand."</p><p>A Google spokesperson said the firm had seen its brand being ripped off by spammers before.</p><p>"Google has a track record of fighting similar types of scams, and we also recommend that users carefully review online offers that look too good to be true before entering any of their information," the spokesperson said.</p><p>Targets were sent messages promoting a hair-loss prevention drug and a link, which directed users to the spammer's blog, where a purportedly Google-sponsored pharmacy was advertised.</p><p>Symantec automatically blocked more than 250 similar spam-created blogs over just two days.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="csCCpSyikXkVSkd94pCJvm" name="" alt="Google" src="https://cdn.mos.cms.futurecdn.net/csCCpSyikXkVSkd94pCJvm.jpg" mos="https://cdn.mos.cms.futurecdn.net/csCCpSyikXkVSkd94pCJvm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>"It is likely that the spammer wants to capitalise on Google's universally known name to add legitimacy to their products," Wood added.</p><p>"With Google's increasing diverse product range, spammers are perhaps hoping that a fake Google-accredited pharmacy will be plausible to some recipients."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Western Europe spam drop ‘significant’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Both Western Europe and the US have seen a notable fall in spam, according to Kaspersky Lab.</p><p>Despite seeing declines, the UK still put out more than both France and Germany, being responsible for 4.3 per cent of all global spam in December, the Russian security giant found.</p><p>India was the biggest spamming offender, sending out nearly 10 per cent of all spam, whilst Russia came in second place.</p><p>Kaspersky praised the anti-botnet campaigns undertaken in the West for contributing to the fall in spam.</p><p>Last November, <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">a drop in spam</a> was largely attributed to the closure of over 20 control centres used by the Pushdo/Cutwail botnet, as well as the <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab shutdown</a>.</p><p>The UK also saw its share of all malware detected in email traffic drop to below three per cent, meaning the nation fell to 10th place overall, having been in the top three until October.</p><p>"Immediately before the start of the holidays we witnessed a dip in the amount of spam," said Maria Namestnikova, senior spam analyst at Kaspersky Lab.</p><p>"This is a seasonal phenomenon at the end of the year the amount of spam mailings always falls off because a lot of the infected botnet computers are switched off."</p><p>WikiLeaks</p><p>Spammers still used current affairs in December, hitting on the WikiLeaks affair in particular.</p><p>Kaspersky noted numerous cases where spammers had called on users to spread WikiLeaks links, supposedly in support of democracy.</p><p>To get around spam filters, spammers included WikiLeaks in background noise texts, including material actually published from the site.</p><p>Sometimes the culprits had included WikiLeaks in links to try and evade filters.</p><p>"Spam is usually dominated by the Christmas and New Year holiday theme in December, but in 2010 it had to share the limelight with WikiLeaks, which once again underlines just how serious the scandal surrounding the website was at the end of the year," Namestnikova added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/630664/western-europe-spam-drop-significant</link>
                                                                            <description>
                            <![CDATA[ A significant spam drop was seen across Western Europe in December, Kaspersky says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uwiB9Q9pfN4dGPJxLgY5Ya</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NozcAbBtaNSMRZfnqPj9x8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Feb 2011 12:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NozcAbBtaNSMRZfnqPj9x8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NozcAbBtaNSMRZfnqPj9x8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Both Western Europe and the US have seen a notable fall in spam, according to Kaspersky Lab.</p><p>Despite seeing declines, the UK still put out more than both France and Germany, being responsible for 4.3 per cent of all global spam in December, the Russian security giant found.</p><p>India was the biggest spamming offender, sending out nearly 10 per cent of all spam, whilst Russia came in second place.</p><p>Kaspersky praised the anti-botnet campaigns undertaken in the West for contributing to the fall in spam.</p><p>Last November, <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">a drop in spam</a> was largely attributed to the closure of over 20 control centres used by the Pushdo/Cutwail botnet, as well as the <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab shutdown</a>.</p><p>The UK also saw its share of all malware detected in email traffic drop to below three per cent, meaning the nation fell to 10th place overall, having been in the top three until October.</p><p>"Immediately before the start of the holidays we witnessed a dip in the amount of spam," said Maria Namestnikova, senior spam analyst at Kaspersky Lab.</p><p>"This is a seasonal phenomenon at the end of the year the amount of spam mailings always falls off because a lot of the infected botnet computers are switched off."</p><p>WikiLeaks</p><p>Spammers still used current affairs in December, hitting on the WikiLeaks affair in particular.</p><p>Kaspersky noted numerous cases where spammers had called on users to spread WikiLeaks links, supposedly in support of democracy.</p><p>To get around spam filters, spammers included WikiLeaks in background noise texts, including material actually published from the site.</p><p>Sometimes the culprits had included WikiLeaks in links to try and evade filters.</p><p>"Spam is usually dominated by the Christmas and New Year holiday theme in December, but in 2010 it had to share the limelight with WikiLeaks, which once again underlines just how serious the scandal surrounding the website was at the end of the year," Namestnikova added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon Simple Email Service launched ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Amazon Web Services (AWS) has launched a new bulk and transactional email service aimed at businesses and developers.</p><p>Through the offering, named the Amazon Simple Email Service (Amazon SES), users will be able to send a significant number of messages without having to worry about ISP compliance issues and so ending up in spam folders.</p><p>"Amazon SES takes proactive steps to prevent questionable content from being sent, so that ISPs receive consistently high-quality email and therefore view the service as a trusted email origin," the company said.</p><p>"This maximises deliverability and dependability for all of our senders."</p><p>Amazon said its new service would help firms get around time consuming licensing and installing a third-party service, or maintaining an internally hosted email solution.</p><p>"Sending email through Amazon SES is as simple as calling a single API, and Amazon SES makes it easy for you to monitor your sending activity and deliverability statistics," the retail and services firm said.</p><p>Amazon EC2 users can send 2,000 messages for free every day, but outside of that mail messages have been priced at $0.10 per thousand.</p><p>Also included in the service is a built-in feedback loop, which will notify customers of bounce backs and spam complaints, as well as failed and successful delivery attempts.</p><p>Earlier this month, <a href="https://www.itpro.com/629857/amazon-revamps-cloud-computing-support" target="_blank" data-original-url="https://www.itpro.com/629857/amazon-revamps-cloud-computing-support">AWS revamped its cloud support offerings</a> with some revised pricing and the new Bronze and Platinum packages.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/630373/amazon-simple-email-service-launched</link>
                                                                            <description>
                            <![CDATA[ Amazon's cloud side looks to help companies send out bulk emails with its new service. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6Uggg9KyMqVLiuxHKfwNWZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7g68us2xhg3PNWMx277N8S-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Jan 2011 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Email Providers]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7g68us2xhg3PNWMx277N8S-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Email]]></media:description>                                                            <media:text><![CDATA[Email]]></media:text>
                                <media:title type="plain"><![CDATA[Email]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7g68us2xhg3PNWMx277N8S-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon Web Services (AWS) has launched a new bulk and transactional email service aimed at businesses and developers.</p><p>Through the offering, named the Amazon Simple Email Service (Amazon SES), users will be able to send a significant number of messages without having to worry about ISP compliance issues and so ending up in spam folders.</p><p>"Amazon SES takes proactive steps to prevent questionable content from being sent, so that ISPs receive consistently high-quality email and therefore view the service as a trusted email origin," the company said.</p><p>"This maximises deliverability and dependability for all of our senders."</p><p>Amazon said its new service would help firms get around time consuming licensing and installing a third-party service, or maintaining an internally hosted email solution.</p><p>"Sending email through Amazon SES is as simple as calling a single API, and Amazon SES makes it easy for you to monitor your sending activity and deliverability statistics," the retail and services firm said.</p><p>Amazon EC2 users can send 2,000 messages for free every day, but outside of that mail messages have been priced at $0.10 per thousand.</p><p>Also included in the service is a built-in feedback loop, which will notify customers of bounce backs and spam complaints, as well as failed and successful delivery attempts.</p><p>Earlier this month, <a href="https://www.itpro.com/629857/amazon-revamps-cloud-computing-support" target="_blank" data-original-url="https://www.itpro.com/629857/amazon-revamps-cloud-computing-support">AWS revamped its cloud support offerings</a> with some revised pricing and the new Bronze and Platinum packages.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google ups webspam fight ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Google has announced a new feature to help fight against webspam, where sites cheat their way up search rankings.</p><p>Whilst English-language webspam in Google results was less than half what it was five years ago, there has been a slight increase in the past few months.</p><p>To counteract this, Google has introduced a redesigned document-level classifier, making it harder for so-called "webspam" content to rank highly.</p><p>"The new classifier is better at detecting spam on individual web pages, e.g, repeated spammy words - the sort of phrases you tend to see in junky, automated, self-promoting blog comments," said Google principal engineer Matt Cutts, in a <a href="http://googleblog.blogspot.com/2011/01/google-search-and-search-engine-spam.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+blogspot%2FMKuf+%28Official+Google+Blog%29" target="_blank">blog</a>.</p><p>"We've also radically improved our ability to detect hacked sites, which were a major source of spam in 2010. And we're evaluating multiple changes that should help drive spam levels even lower, including one change that primarily affects sites that copy others' content and sites with low levels of original content."</p><p>Google wanted to put to bed the idea the search giant did not take strong action against spammy content if those sites contained Google ads.</p><p>Cutts stressed adding Google ads to sites would not boost their search rankings and Google would take action on any site violating the company's quality guidelines.</p><p>"The fact is that we're not perfect, and combined with users' skyrocketing expectations of Google, these imperfections get magnified in perception," Cutts added.</p><p>"However, we can and should do better."</p><p>In another recent move to shore up security, the search firm <a href="https://www.itpro.com/629860/google-supes-up-email-authentication" target="_blank" data-original-url="https://www.itpro.com/629860/google-supes-up-email-authentication">bolstered its email authentication</a> for Google Apps users.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/630298/google-ups-webspam-fight</link>
                                                                            <description>
                            <![CDATA[ Google promises to up its game in fighting sites breaking its quality guidelines. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hyzhbNoToi2cqggES83CYb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rostyD2MzPacDJNJu4Rz43-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Jan 2011 13:56:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rostyD2MzPacDJNJu4Rz43-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google]]></media:description>                                                            <media:text><![CDATA[Google]]></media:text>
                                <media:title type="plain"><![CDATA[Google]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rostyD2MzPacDJNJu4Rz43-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has announced a new feature to help fight against webspam, where sites cheat their way up search rankings.</p><p>Whilst English-language webspam in Google results was less than half what it was five years ago, there has been a slight increase in the past few months.</p><p>To counteract this, Google has introduced a redesigned document-level classifier, making it harder for so-called "webspam" content to rank highly.</p><p>"The new classifier is better at detecting spam on individual web pages, e.g, repeated spammy words - the sort of phrases you tend to see in junky, automated, self-promoting blog comments," said Google principal engineer Matt Cutts, in a <a href="http://googleblog.blogspot.com/2011/01/google-search-and-search-engine-spam.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+blogspot%2FMKuf+%28Official+Google+Blog%29" target="_blank">blog</a>.</p><p>"We've also radically improved our ability to detect hacked sites, which were a major source of spam in 2010. And we're evaluating multiple changes that should help drive spam levels even lower, including one change that primarily affects sites that copy others' content and sites with low levels of original content."</p><p>Google wanted to put to bed the idea the search giant did not take strong action against spammy content if those sites contained Google ads.</p><p>Cutts stressed adding Google ads to sites would not boost their search rankings and Google would take action on any site violating the company's quality guidelines.</p><p>"The fact is that we're not perfect, and combined with users' skyrocketing expectations of Google, these imperfections get magnified in perception," Cutts added.</p><p>"However, we can and should do better."</p><p>In another recent move to shore up security, the search firm <a href="https://www.itpro.com/629860/google-supes-up-email-authentication" target="_blank" data-original-url="https://www.itpro.com/629860/google-supes-up-email-authentication">bolstered its email authentication</a> for Google Apps users.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK spam doubles despite global decline ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Spam levels rose by almost 100 per cent in the UK last year, even though global volumes dropped for the first time ever.</p><p>Other developed countries saw notable rises in spam, with France posting a whopping 115 per cent increase over 2009, a Cisco report has shown.</p><p>In Brazil, China and Turkey, which were all ranked high up on last year's list of spammed nations, posted significantly lower volumes in 2010.</p><p>Cisco put the fall in spam levels in 2010, the first ever year a decline has been seen since records began, down to some high-profile botnet takedowns, including those of Waledac and Cutwail.</p><p>Spam levels <a href="https://www.itpro.com/629776/christmas-spam-in-shock-fall" target="_blank" data-original-url="https://www.itpro.com/629776/christmas-spam-in-shock-fall">dropped significantly</a> over the Christmas period, when mega-botnets such as Rustock simply stopped sending out irritating messages.</p><p>Security researchers were at a loss to explain why these botnets stopped spamming, but levels look set to return to normal as the <a href="https://www.itpro.com/630052/waledac-back-from-the-dead" target="_blank" data-original-url="https://www.itpro.com/630052/waledac-back-from-the-dead">malicious networks have started up again</a>.</p><p>Spreading the net</p><p>The Cisco report also noted how scammers have spread their wings, moving over to mobile devices and emerging operating systems.</p><p>"Everyone knows the joke about the two hikers and the hungry bear in which the swifter hiker explains his footrace is not against the bear but the other hiker," said Patrick Peterson, fellow at Cisco.</p><p>"The cyber criminal bears have been feasting on the "slowest hiker" Windows platform for the last decade. But with increased security in the Windows operating system and applications, the bears are looking elsewhere to satisfy their hunger."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/630235/uk-spam-doubles-despite-global-decline</link>
                                                                            <description>
                            <![CDATA[ Spam may have dropped globally in 2010, but in the UK the situation got significantly worse. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">teFUq6VPzqXujUsaB3VLLy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nwVtRmmSHonapcaxsz5EcW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jan 2011 15:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nwVtRmmSHonapcaxsz5EcW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nwVtRmmSHonapcaxsz5EcW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Spam levels rose by almost 100 per cent in the UK last year, even though global volumes dropped for the first time ever.</p><p>Other developed countries saw notable rises in spam, with France posting a whopping 115 per cent increase over 2009, a Cisco report has shown.</p><p>In Brazil, China and Turkey, which were all ranked high up on last year's list of spammed nations, posted significantly lower volumes in 2010.</p><p>Cisco put the fall in spam levels in 2010, the first ever year a decline has been seen since records began, down to some high-profile botnet takedowns, including those of Waledac and Cutwail.</p><p>Spam levels <a href="https://www.itpro.com/629776/christmas-spam-in-shock-fall" target="_blank" data-original-url="https://www.itpro.com/629776/christmas-spam-in-shock-fall">dropped significantly</a> over the Christmas period, when mega-botnets such as Rustock simply stopped sending out irritating messages.</p><p>Security researchers were at a loss to explain why these botnets stopped spamming, but levels look set to return to normal as the <a href="https://www.itpro.com/630052/waledac-back-from-the-dead" target="_blank" data-original-url="https://www.itpro.com/630052/waledac-back-from-the-dead">malicious networks have started up again</a>.</p><p>Spreading the net</p><p>The Cisco report also noted how scammers have spread their wings, moving over to mobile devices and emerging operating systems.</p><p>"Everyone knows the joke about the two hikers and the hungry bear in which the swifter hiker explains his footrace is not against the bear but the other hiker," said Patrick Peterson, fellow at Cisco.</p><p>"The cyber criminal bears have been feasting on the "slowest hiker" Windows platform for the last decade. But with increased security in the Windows operating system and applications, the bears are looking elsewhere to satisfy their hunger."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos recommends ‘walled garden’ to Facebook ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Facebook has defended its security efforts after a report suggested it should follow Apple's "walled garden" approach to apps.</p><p>Security firm Sophos said the closed Apple approach "has proven effective in protecting users from maliciously crafted applications."</p><p>A Sophos poll carried out amongst Facebook users found 95.51 per cent of users agreed the Apple approach would be better for security.</p><p>Facebook said it has extensive controls so when a users wants to add an application it only gets access to "very limited data" and the user needs to approve each additional type of data.</p><p>"We have a dedicated team that does robust review of all third-party applications, using a risk-based approach," a spokesperson for the social networking giant said.</p><p>"So, that means that we first look at velocity/number of users/types of data shared, and prioritise. This ensures that the team is focused on addressing the biggest risks, rather than just doing a cursory review at the time that an app is first launched."</p><p>Facebook said it acts fast to remove or sanction any potentially malicious applications before they gain access to user data. In some cases the company said it will go as far as to bring in law enforcement.</p><p>The Sophos report also indicated security threats had risen across social networks, including Facebook.</p><p>"Rogue applications, clickjacking, survey scams all unheard of just a couple of years ago, are now popping up on a daily basis on social networks such as Facebook," said Graham Cluley, senior technology consultant at Sophos.</p><p>"Why aren't Faceboook and other social networks doing more to prevent spam and scams in the first place?"</p><p>The survey showed two-fifths of respondents had been sent malware over social networking sites, representing a 90 per cent increase since summer 2009.</p><p>Eight in 10 respondents said Facebook posed the biggest risk to the security of their systems.</p><p>Facebook again defended its record in securing users from the likes of spam and malicious software.</p><p>"As a result of our efforts, the data we have on interactions of more than 500 million people using Facebook shows that spam, malware and other attacks have decreased in their effectiveness - the opposite conclusion reached by a security vendor," the Facebook spokesperson said.</p><p>"It's much more important to measure effectiveness than it is to measure volume. If your spam filter catches all the spam, does it matter that your filter caught 10 per cent more?"</p><p>Facebook was involved in another privacy debate this week, as users and security professionals complained about a feature allowing developers to access user phone numbers and addresses.</p><p>Facebook <a href="https://www.itpro.com/630136/facebook-backtracks-on-data-sharing-plans" target="_blank" data-original-url="https://www.itpro.com/630136/facebook-backtracks-on-data-sharing-plans">removed the feature</a>, saying it wanted to ensure users were only giving away data they wanted to hand over to third parties.</p><p>An updated version of the feature is expected to appear in the coming weeks.</p><p><em>IT PRO</em>, meanwhile, has discovered photos with privacy restrictions on them <a href="https://www.itpro.com/630160/why-private-facebook-photos-arent-so-private" target="_blank" data-original-url="https://www.itpro.com/630160/why-private-facebook-photos-arent-so-private">could easily be spread across the internet</a> without users' knowledge.</p><p>By simply right clicking and selecting copy image location' on a photo, anyone can then paste the URL to share it with unauthorised users, even those not on Facebook.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/630181/sophos-recommends-walled-garden-to-facebook</link>
                                                                            <description>
                            <![CDATA[ Sophos suggests Facebook could adopt Apple's "walled garden" approach to apps to better protect its users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wYMvWqSf8kPH6cULM7Ar8z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KfTTKb9srxzG8FGggvPWTe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Jan 2011 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KfTTKb9srxzG8FGggvPWTe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook]]></media:description>                                                            <media:text><![CDATA[Facebook]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KfTTKb9srxzG8FGggvPWTe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook has defended its security efforts after a report suggested it should follow Apple's "walled garden" approach to apps.</p><p>Security firm Sophos said the closed Apple approach "has proven effective in protecting users from maliciously crafted applications."</p><p>A Sophos poll carried out amongst Facebook users found 95.51 per cent of users agreed the Apple approach would be better for security.</p><p>Facebook said it has extensive controls so when a users wants to add an application it only gets access to "very limited data" and the user needs to approve each additional type of data.</p><p>"We have a dedicated team that does robust review of all third-party applications, using a risk-based approach," a spokesperson for the social networking giant said.</p><p>"So, that means that we first look at velocity/number of users/types of data shared, and prioritise. This ensures that the team is focused on addressing the biggest risks, rather than just doing a cursory review at the time that an app is first launched."</p><p>Facebook said it acts fast to remove or sanction any potentially malicious applications before they gain access to user data. In some cases the company said it will go as far as to bring in law enforcement.</p><p>The Sophos report also indicated security threats had risen across social networks, including Facebook.</p><p>"Rogue applications, clickjacking, survey scams all unheard of just a couple of years ago, are now popping up on a daily basis on social networks such as Facebook," said Graham Cluley, senior technology consultant at Sophos.</p><p>"Why aren't Faceboook and other social networks doing more to prevent spam and scams in the first place?"</p><p>The survey showed two-fifths of respondents had been sent malware over social networking sites, representing a 90 per cent increase since summer 2009.</p><p>Eight in 10 respondents said Facebook posed the biggest risk to the security of their systems.</p><p>Facebook again defended its record in securing users from the likes of spam and malicious software.</p><p>"As a result of our efforts, the data we have on interactions of more than 500 million people using Facebook shows that spam, malware and other attacks have decreased in their effectiveness - the opposite conclusion reached by a security vendor," the Facebook spokesperson said.</p><p>"It's much more important to measure effectiveness than it is to measure volume. If your spam filter catches all the spam, does it matter that your filter caught 10 per cent more?"</p><p>Facebook was involved in another privacy debate this week, as users and security professionals complained about a feature allowing developers to access user phone numbers and addresses.</p><p>Facebook <a href="https://www.itpro.com/630136/facebook-backtracks-on-data-sharing-plans" target="_blank" data-original-url="https://www.itpro.com/630136/facebook-backtracks-on-data-sharing-plans">removed the feature</a>, saying it wanted to ensure users were only giving away data they wanted to hand over to third parties.</p><p>An updated version of the feature is expected to appear in the coming weeks.</p><p><em>IT PRO</em>, meanwhile, has discovered photos with privacy restrictions on them <a href="https://www.itpro.com/630160/why-private-facebook-photos-arent-so-private" target="_blank" data-original-url="https://www.itpro.com/630160/why-private-facebook-photos-arent-so-private">could easily be spread across the internet</a> without users' knowledge.</p><p>By simply right clicking and selecting copy image location' on a photo, anyone can then paste the URL to share it with unauthorised users, even those not on Facebook.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK fifth worst for spam relaying ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK has been ranked as the fifth worst nation for sending out spam, with the US keeping top spot.</p><p>Between October and December 2010, 4.54 per cent of all spam in the world emanated from the UK, a Sophos report showed.</p><p>Back in August, the UK was <a href="https://www.itpro.com/626347/uk-in-top-four-for-sending-spam" target="_blank" data-original-url="https://www.itpro.com/626347/uk-in-top-four-for-sending-spam">ranked as fourth worst</a> and in the entire third quarter of last year the country was responsible for five per cent of all global spam.</p><p>The US kept the unenviable number one spot, with India, Brazil and Russia making up the rest of the top five.</p><p>Europe remained the continent responsible for sending out more spam than any other, with a 32.11 per cent share. Asia was just behind on 31.89 per cent.</p><p>Whilst there was not much of a shake-up in terms of countries, spammers tactics have altered a little.</p><p>"Spam is certainly here to stay, however, the motivations and the methods are continuing to change in order to reap the greatest rewards for the spammers," explained Graham Cluley, senior technology consultant at Sophos.</p><p>"What's becoming even more prevalent is the mailing of links to poisoned web pages - victims are tricked into clicking a link in an email, and then led to a site that attacks their computer with exploits or attempts to implant fake anti-virus software."</p><p>The return of the spam</p><p>Over the Christmas period, <a href="https://www.itpro.com/629776/christmas-spam-in-shock-fall" target="_blank" data-original-url="https://www.itpro.com/629776/christmas-spam-in-shock-fall">spam reduced massively</a> due to huge botnets such as Rustock going out of contention.</p><p>Now, however, spam has made a return as the relevant botnets have revved up again, with Rustock pumping out plenty of pharmaceutical spam.</p><p>"Rustock has resumed activity, and appears set to continue where it left off on 25 December as the biggest source of global spam," a Symantec Hosted Services blog noted.</p><p>"While levels of Rustock output appears marginally lower than before Christmas, we see no reason they won't reach those previous levels again, bringing global spam levels back up to the approximately 90 per cent levels we had become so used to."</p><p>Security researchers have still not found a verifiable reason for why the likes of Rustock temporarily went out of the spamming business.</p><p>Whilst the botnet did not send out messages over the holiday period, Rustock continued to carry out click fraud on adverts across the web.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/629929/uk-fifth-worst-for-spam-relaying</link>
                                                                            <description>
                            <![CDATA[ The UK is in the top five for spam relaying, whilst overall spam levels look likely to get back to normal. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c7gtDYjcHap6195mFSciHd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wSdZW8APkpPczp8DdcP4VK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Jan 2011 12:21:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wSdZW8APkpPczp8DdcP4VK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[spam]]></media:description>                                                            <media:text><![CDATA[spam]]></media:text>
                                <media:title type="plain"><![CDATA[spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wSdZW8APkpPczp8DdcP4VK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK has been ranked as the fifth worst nation for sending out spam, with the US keeping top spot.</p><p>Between October and December 2010, 4.54 per cent of all spam in the world emanated from the UK, a Sophos report showed.</p><p>Back in August, the UK was <a href="https://www.itpro.com/626347/uk-in-top-four-for-sending-spam" target="_blank" data-original-url="https://www.itpro.com/626347/uk-in-top-four-for-sending-spam">ranked as fourth worst</a> and in the entire third quarter of last year the country was responsible for five per cent of all global spam.</p><p>The US kept the unenviable number one spot, with India, Brazil and Russia making up the rest of the top five.</p><p>Europe remained the continent responsible for sending out more spam than any other, with a 32.11 per cent share. Asia was just behind on 31.89 per cent.</p><p>Whilst there was not much of a shake-up in terms of countries, spammers tactics have altered a little.</p><p>"Spam is certainly here to stay, however, the motivations and the methods are continuing to change in order to reap the greatest rewards for the spammers," explained Graham Cluley, senior technology consultant at Sophos.</p><p>"What's becoming even more prevalent is the mailing of links to poisoned web pages - victims are tricked into clicking a link in an email, and then led to a site that attacks their computer with exploits or attempts to implant fake anti-virus software."</p><p>The return of the spam</p><p>Over the Christmas period, <a href="https://www.itpro.com/629776/christmas-spam-in-shock-fall" target="_blank" data-original-url="https://www.itpro.com/629776/christmas-spam-in-shock-fall">spam reduced massively</a> due to huge botnets such as Rustock going out of contention.</p><p>Now, however, spam has made a return as the relevant botnets have revved up again, with Rustock pumping out plenty of pharmaceutical spam.</p><p>"Rustock has resumed activity, and appears set to continue where it left off on 25 December as the biggest source of global spam," a Symantec Hosted Services blog noted.</p><p>"While levels of Rustock output appears marginally lower than before Christmas, we see no reason they won't reach those previous levels again, bringing global spam levels back up to the approximately 90 per cent levels we had become so used to."</p><p>Security researchers have still not found a verifiable reason for why the likes of Rustock temporarily went out of the spamming business.</p><p>Whilst the botnet did not send out messages over the holiday period, Rustock continued to carry out click fraud on adverts across the web.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google supes up email authentication ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Google has made a move in the battle against spam with the introduction of a new authentication offering.</p><p>The search giant claimed it was the first company to make simple DomainKeys Identified Mail (DKIM) authentication available on a free email client.</p><p>DKIM is a signing standard designed to separate an email from spam and thereby ensure the message reaches the intended recipient. Google has made it available for all Google Apps customers for outgoing messages.</p><p>To enable to DKIM technology, administrators simply need to head to the Advanced Tools tab in the control panel and switch the service on.</p><p>"Once again, the power of the cloud has made it possible for us to bring this feature to millions of customers quickly and affordably," said Adam Dawes, Google enterprise product manager, in a <a href="http://googleenterprise.blogspot.com/2011/01/spam-takes-another-hit-email.html?utm_source=entblog&utm_medium=blog&utm_campaign=Feed%3A+OfficialGoogleEnterpriseBlog+%28Official+Google+Enterprise+Blog%29" target="_blank">blog</a>.</p><p>"As more email providers around the world support DKIM signing, spam fighters will have an even more reliable signal to separate unwanted mail from good mail."</p><p>He claimed spam and phishing "epidemics" were not abating. However, recent figures may hint otherwise.</p><p>Over Christmas there was a <a href="https://www.itpro.com/629776/christmas-spam-in-shock-fall" target="_blank" data-original-url="https://www.itpro.com/629776/christmas-spam-in-shock-fall">serious dip in spam</a> thanks to a number of mega botnets all but shutting down their spamming activities.</p><p>Security researchers have thus far been at a loss to explain why botnets, such as the behemoth that is Rustock, went practically out of contention.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/629860/google-supes-up-email-authentication</link>
                                                                            <description>
                            <![CDATA[ Google Apps customers can now introduce DKIM authentication and help in the fight against spam. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">po2ftq6cHXLC3s5iAZ8kQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bVcrZuxYML8E6rnUw3udg3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Jan 2011 16:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Workspace]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Google]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bVcrZuxYML8E6rnUw3udg3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bVcrZuxYML8E6rnUw3udg3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has made a move in the battle against spam with the introduction of a new authentication offering.</p><p>The search giant claimed it was the first company to make simple DomainKeys Identified Mail (DKIM) authentication available on a free email client.</p><p>DKIM is a signing standard designed to separate an email from spam and thereby ensure the message reaches the intended recipient. Google has made it available for all Google Apps customers for outgoing messages.</p><p>To enable to DKIM technology, administrators simply need to head to the Advanced Tools tab in the control panel and switch the service on.</p><p>"Once again, the power of the cloud has made it possible for us to bring this feature to millions of customers quickly and affordably," said Adam Dawes, Google enterprise product manager, in a <a href="http://googleenterprise.blogspot.com/2011/01/spam-takes-another-hit-email.html?utm_source=entblog&utm_medium=blog&utm_campaign=Feed%3A+OfficialGoogleEnterpriseBlog+%28Official+Google+Enterprise+Blog%29" target="_blank">blog</a>.</p><p>"As more email providers around the world support DKIM signing, spam fighters will have an even more reliable signal to separate unwanted mail from good mail."</p><p>He claimed spam and phishing "epidemics" were not abating. However, recent figures may hint otherwise.</p><p>Over Christmas there was a <a href="https://www.itpro.com/629776/christmas-spam-in-shock-fall" target="_blank" data-original-url="https://www.itpro.com/629776/christmas-spam-in-shock-fall">serious dip in spam</a> thanks to a number of mega botnets all but shutting down their spamming activities.</p><p>Security researchers have thus far been at a loss to explain why botnets, such as the behemoth that is Rustock, went practically out of contention.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Christmas spam in shock fall ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The 2010 Christmas period saw a significant drop in spam levels, Symantec figures have shown.</p><p>This fall has somewhat flummoxed security researchers, especially considering the Christmas holidays are seen as a time of great activity for spammers.</p><p>The central reason behind the drop was the significant fall in activity from some mega botnets, in particular Rustock, which was the most dominant spam botnet in 2010 and appeared to have all but shut down from Christmas Day onwards.</p><p>The major Lethic and Xarvester botnets also saw a dramatic decline in activity. The former produced virtually nothing since 28 December and the latter did very little post New Year's Eve.</p><p>According to Symantec, the amount of spam hitting the security giant's spam honeypots was at its lowest since the <a href="https://www.itpro.com/608238/worldwide-spam-spewing-server-taken-down" target="_blank" data-original-url="https://www.itpro.com/608238/worldwide-spam-spewing-server-taken-down">McColo takedown</a> in November 2008.</p><p>Why these botnets have gone on something of a hiatus remains something of a conundrum, however.</p><p>"At present we don't know why these botnets have stopped spamming, perhaps the botnet herders have decided they need a holiday too?" said Paul Wood, MessageLabs Intelligence senior analyst at Symantec Hosted Services, in a <a href="http://www.symantec.com/connect/blogs/spam-rustock-lethic-and-xarvester-disappears-over-holiday-season" target="_blank">blog</a> post.</p><p>Despite the lack of an answer as to why Rustock et al have taken a break, Wood warned people against complacency.</p><p>"As we saw after the closure of McColo in 2008, and following further takedown attempts in subsequent years, botnets rarely stay quiet for very long," Wood said.</p><p>"Even if these three botnets don't come back soon, we would expect other botnets, even new ones, to pick-up where they have left off - very soon."</p><p>It is not often security pros are left at a loss when something significant happens. The last time a serious drop in spam was recorded, in 2010, the reasons appeared to be clear as some <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">massive botnets had been taken out</a> by law enforcement.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/629776/christmas-spam-in-shock-fall</link>
                                                                            <description>
                            <![CDATA[ Spam fell dramatically over Christmas, much to the befuddlement of security researchers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">krM9Zxcv9Er2bimBaPbYDt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eYHbZ4v6ug6zFXFDV7agsm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jan 2011 14:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eYHbZ4v6ug6zFXFDV7agsm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eYHbZ4v6ug6zFXFDV7agsm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The 2010 Christmas period saw a significant drop in spam levels, Symantec figures have shown.</p><p>This fall has somewhat flummoxed security researchers, especially considering the Christmas holidays are seen as a time of great activity for spammers.</p><p>The central reason behind the drop was the significant fall in activity from some mega botnets, in particular Rustock, which was the most dominant spam botnet in 2010 and appeared to have all but shut down from Christmas Day onwards.</p><p>The major Lethic and Xarvester botnets also saw a dramatic decline in activity. The former produced virtually nothing since 28 December and the latter did very little post New Year's Eve.</p><p>According to Symantec, the amount of spam hitting the security giant's spam honeypots was at its lowest since the <a href="https://www.itpro.com/608238/worldwide-spam-spewing-server-taken-down" target="_blank" data-original-url="https://www.itpro.com/608238/worldwide-spam-spewing-server-taken-down">McColo takedown</a> in November 2008.</p><p>Why these botnets have gone on something of a hiatus remains something of a conundrum, however.</p><p>"At present we don't know why these botnets have stopped spamming, perhaps the botnet herders have decided they need a holiday too?" said Paul Wood, MessageLabs Intelligence senior analyst at Symantec Hosted Services, in a <a href="http://www.symantec.com/connect/blogs/spam-rustock-lethic-and-xarvester-disappears-over-holiday-season" target="_blank">blog</a> post.</p><p>Despite the lack of an answer as to why Rustock et al have taken a break, Wood warned people against complacency.</p><p>"As we saw after the closure of McColo in 2008, and following further takedown attempts in subsequent years, botnets rarely stay quiet for very long," Wood said.</p><p>"Even if these three botnets don't come back soon, we would expect other botnets, even new ones, to pick-up where they have left off - very soon."</p><p>It is not often security pros are left at a loss when something significant happens. The last time a serious drop in spam was recorded, in 2010, the reasons appeared to be clear as some <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">massive botnets had been taken out</a> by law enforcement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MailChimp review ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Email marketing is cheap, effective and a campaign can quickly be set up. However, it can be difficult for small companies to do well. For a start, if you're not careful your campaign will get caught in the recipients' spam filters. It's easy to make design mistakes, such as not creating an alternative plain text version, and it's difficult to track the success of a campaign.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZZRE793LVnmmrzjLSy3d6B" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZZRE793LVnmmrzjLSy3d6B.jpg" mos="https://cdn.mos.cms.futurecdn.net/ZZRE793LVnmmrzjLSy3d6B.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>MailChimp is an online mailing system designed to solve these problems. With it, you can send 6000 emails a month to 1000 recipients for free. If you want to send an unlimited number of emails or you want to target more than 1,000 recipients then you'll need to pay either for a monthly plan or, for less frequent campaigns, on a price-per-email basis. There are<a href="http://www.mailchimp.com/pricing" target="_blank">a huge variety of plans</a> to suit almost any number of recipients.</p><p>You get a range of free, easy to use templates and, more importantly, MailChimp produces fairly comprehensive reports for each campaign. These allow you to see exactly how your campaign went down - who opened your mails, what the clickthrough rate was and so on.</p><p>From signing up for an account to creating and mailing your first campaign, using MailChimp is a doddle. Signing up takes just a minute or two; creating your first mail list about the same. You can either create a list from scratch or import your contacts from a range of online marketing tools and other web services (we did have some problems importing from GMail, but we suspect the problem was at Google's end).</p><p>Once you've created your list, the next step is to start creating emails (each mail is referred to as a "campaign"). The html templates for these aren't offensively bad and can easily be customised using a web interface that's reassuringly like a word processor. It's almost too easy; you can fire out your first campaign within just a few minutes of signing up for the service.</p><p>You can choose to send your mail campaign to an entire list, a pre-defined subgroup or email addresses that you select manually. Before you send, you can preview the email to see what it looks like in html. If you're prepared to pay you can also use MailChimp's Inbox Inspection and Delivery Doctor services to see what the campaign will look like in various email clients and how it will fare against common spam filters.</p><p>It's once your campaign is sent, however, that the magic really starts. Using the Reports feature, you can see how many recipients have received your mail, how many opened it, exactly who opened it and when, the clickthrough rate on any links you included in the mail and so on. You can even run a split campaign, with different versions going out to different control groups. When it's clear which version works best, you send that to the rest of the list. This kind of information is what makes email marketing worthwhile. Without it, the whole thing's a guessing game and you have no idea what your return is.</p><p>As you'd expect, MailChimp also integrates with common social networks. It's currently trialling its "social pro" feature, which queries Facebook, Twitter and other social networks to see who on your list is a member, who follows you on Twitter, how influential they are with other members and so on. Sadly, this is only free until March 2011. Even without it you can still share your campaigns on Facebook and Twitter at the touch of a button.</p><h2 id="verdict-2">Verdict</h2><p>MailChimp is a very good email marketing tool for small businesses. It lets you create good looking campaigns, manage your mailing lists and track the effectiveness of your marketing.</p><p>SYSTEM REQUIREMENTS</p><p>Broadband connection and modern Web browser</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/629080/mailchimp-review</link>
                                                                            <description>
                            <![CDATA[ Is the amusingly-named MailChimp email marketing service sweet as a banana or a bit of a howler? Karl Wright finds out in our review. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h2qyHeEC3PzKy74tk5KhiN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vAUqmdfYGYtWVfW9hJ9bpb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Dec 2010 10:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Email Providers]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Karl Wright ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vAUqmdfYGYtWVfW9hJ9bpb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[mailchimp]]></media:description>                                                            <media:text><![CDATA[mailchimp]]></media:text>
                                <media:title type="plain"><![CDATA[mailchimp]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vAUqmdfYGYtWVfW9hJ9bpb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Email marketing is cheap, effective and a campaign can quickly be set up. However, it can be difficult for small companies to do well. For a start, if you're not careful your campaign will get caught in the recipients' spam filters. It's easy to make design mistakes, such as not creating an alternative plain text version, and it's difficult to track the success of a campaign.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZZRE793LVnmmrzjLSy3d6B" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZZRE793LVnmmrzjLSy3d6B.jpg" mos="https://cdn.mos.cms.futurecdn.net/ZZRE793LVnmmrzjLSy3d6B.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>MailChimp is an online mailing system designed to solve these problems. With it, you can send 6000 emails a month to 1000 recipients for free. If you want to send an unlimited number of emails or you want to target more than 1,000 recipients then you'll need to pay either for a monthly plan or, for less frequent campaigns, on a price-per-email basis. There are<a href="http://www.mailchimp.com/pricing" target="_blank">a huge variety of plans</a> to suit almost any number of recipients.</p><p>You get a range of free, easy to use templates and, more importantly, MailChimp produces fairly comprehensive reports for each campaign. These allow you to see exactly how your campaign went down - who opened your mails, what the clickthrough rate was and so on.</p><p>From signing up for an account to creating and mailing your first campaign, using MailChimp is a doddle. Signing up takes just a minute or two; creating your first mail list about the same. You can either create a list from scratch or import your contacts from a range of online marketing tools and other web services (we did have some problems importing from GMail, but we suspect the problem was at Google's end).</p><p>Once you've created your list, the next step is to start creating emails (each mail is referred to as a "campaign"). The html templates for these aren't offensively bad and can easily be customised using a web interface that's reassuringly like a word processor. It's almost too easy; you can fire out your first campaign within just a few minutes of signing up for the service.</p><p>You can choose to send your mail campaign to an entire list, a pre-defined subgroup or email addresses that you select manually. Before you send, you can preview the email to see what it looks like in html. If you're prepared to pay you can also use MailChimp's Inbox Inspection and Delivery Doctor services to see what the campaign will look like in various email clients and how it will fare against common spam filters.</p><p>It's once your campaign is sent, however, that the magic really starts. Using the Reports feature, you can see how many recipients have received your mail, how many opened it, exactly who opened it and when, the clickthrough rate on any links you included in the mail and so on. You can even run a split campaign, with different versions going out to different control groups. When it's clear which version works best, you send that to the rest of the list. This kind of information is what makes email marketing worthwhile. Without it, the whole thing's a guessing game and you have no idea what your return is.</p><p>As you'd expect, MailChimp also integrates with common social networks. It's currently trialling its "social pro" feature, which queries Facebook, Twitter and other social networks to see who on your list is a member, who follows you on Twitter, how influential they are with other members and so on. Sadly, this is only free until March 2011. Even without it you can still share your campaigns on Facebook and Twitter at the touch of a button.</p><h2 id="verdict-2">Verdict</h2><p>MailChimp is a very good email marketing tool for small businesses. It lets you create good looking campaigns, manage your mailing lists and track the effectiveness of your marketing.</p><p>SYSTEM REQUIREMENTS</p><p>Broadband connection and modern Web browser</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Major m00p hacker sentenced to 18 months ]]></title>
                                                                                                <dc:content><![CDATA[ <p>UPDATED The head of a major cyber gang who targeted many UK homes and businesses has been sentenced to 18 months in prison.</p><p>Matthew Anderson, a 33-year-old security expert, was helping run a collection of cyber criminals known as the m00p group, who sent millions of malicious emails to both homes and businesses.</p><p>A court heard this week that Anderson was using his mother's cottage as a base for launching attacks, according to various reports.</p><p>Last month, <a href="https://www.itpro.com/628021/virus-spreading-snooper-pleads-guilty" target="_blank" data-original-url="https://www.itpro.com/628021/virus-spreading-snooper-pleads-guilty">Anderson pleaded guilty</a> to causing unauthorised modification to the content of computers, contrary to Section 3 of the Computer Misuse Act 1990, but now more details have emerged about his role.</p><p>Southwark crown court heard how the father of five managed to compromise computers to allow him to steal data and take over webcams to snoop on people.</p><p>He collected CVs, wills and medical reports, and on one occasion was believed to have seriously distressed a teenage girl when controlling a webcam.</p><p>The gang targeted hundreds of businesses from 2005 onwards, including Oxford's John Radcliffe Hospital, the publishers Macmillan and car maker Toyota.</p><p>The scam emails used fake anti-virus tactics, adopting the front of an online business offering software called Optom Security, the Metropolitan Police said last month.</p><p>Two other men were arrested as part of the investigation into m00p, one released without any further action, while the other pleaded guilty in Finland in 2008 and received a custodial sentence of 18 days and a community service order.</p><p>Ash Patel, country manager for UK and Ireland at Stonesoft, said the Anderson case proves bedroom hackers are still around.</p><p>"For those old enough to remember, the 1983 film War Games came to represent the hacker with an ego in their bedroom scenario," Patel told <em>IT PRO</em>.</p><p>"Almost 30 years later, the Matthew Anderson case shows us that that hacker is still with us today but, with more money on the table, they're now dwarfed by the number of well-funded, well-organised hackers."</p><p>Patel also suggested law enforcement and security researchers are getting better at identifying and taking down cyber criminals.</p><p>"As hackers are better resourced so are the authorities and they're ably supported by a wiser general public," he added.</p><p>It has been one of the best years yet for cyber crime takedowns, Mikko Hypponen, chief research officer at F-Secure, recently told <em>IT PRO</em>.</p><p>Various botnet takedowns have even managed to <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">reduce the amount of spam</a> doing the rounds.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/628819/major-m00p-hacker-sentenced-to-18-months</link>
                                                                            <description>
                            <![CDATA[ A hacker, who was a major player in the m00p group, has been sentenced to 18 months in prison. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VssV3sR7kFXyKzLAdsPWu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WpakZ8P7wa6yQnWdKecMGm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Nov 2010 09:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WpakZ8P7wa6yQnWdKecMGm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Court]]></media:description>                                                            <media:text><![CDATA[Court]]></media:text>
                                <media:title type="plain"><![CDATA[Court]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WpakZ8P7wa6yQnWdKecMGm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UPDATED The head of a major cyber gang who targeted many UK homes and businesses has been sentenced to 18 months in prison.</p><p>Matthew Anderson, a 33-year-old security expert, was helping run a collection of cyber criminals known as the m00p group, who sent millions of malicious emails to both homes and businesses.</p><p>A court heard this week that Anderson was using his mother's cottage as a base for launching attacks, according to various reports.</p><p>Last month, <a href="https://www.itpro.com/628021/virus-spreading-snooper-pleads-guilty" target="_blank" data-original-url="https://www.itpro.com/628021/virus-spreading-snooper-pleads-guilty">Anderson pleaded guilty</a> to causing unauthorised modification to the content of computers, contrary to Section 3 of the Computer Misuse Act 1990, but now more details have emerged about his role.</p><p>Southwark crown court heard how the father of five managed to compromise computers to allow him to steal data and take over webcams to snoop on people.</p><p>He collected CVs, wills and medical reports, and on one occasion was believed to have seriously distressed a teenage girl when controlling a webcam.</p><p>The gang targeted hundreds of businesses from 2005 onwards, including Oxford's John Radcliffe Hospital, the publishers Macmillan and car maker Toyota.</p><p>The scam emails used fake anti-virus tactics, adopting the front of an online business offering software called Optom Security, the Metropolitan Police said last month.</p><p>Two other men were arrested as part of the investigation into m00p, one released without any further action, while the other pleaded guilty in Finland in 2008 and received a custodial sentence of 18 days and a community service order.</p><p>Ash Patel, country manager for UK and Ireland at Stonesoft, said the Anderson case proves bedroom hackers are still around.</p><p>"For those old enough to remember, the 1983 film War Games came to represent the hacker with an ego in their bedroom scenario," Patel told <em>IT PRO</em>.</p><p>"Almost 30 years later, the Matthew Anderson case shows us that that hacker is still with us today but, with more money on the table, they're now dwarfed by the number of well-funded, well-organised hackers."</p><p>Patel also suggested law enforcement and security researchers are getting better at identifying and taking down cyber criminals.</p><p>"As hackers are better resourced so are the authorities and they're ably supported by a wiser general public," he added.</p><p>It has been one of the best years yet for cyber crime takedowns, Mikko Hypponen, chief research officer at F-Secure, recently told <em>IT PRO</em>.</p><p>Various botnet takedowns have even managed to <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">reduce the amount of spam</a> doing the rounds.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google quick to fix Gmail spam exploit ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A "serious" exploit that allowed spam to be sent to Gmail users without them knowing about it has been shut down.</p><p>Google claimed it was quick to counter the exploit, which caused spam to be sent to logged-in Gmail users when they visited specially-crafted websites.</p><p>"We quickly fixed the issue in the Google Apps Script API that could have allowed for emails to be sent to Gmail users without their permission if they visited a specially designed website while signed into their account," Google explained in a statement.</p><p>"We immediately removed the site that demonstrated this issue, and disabled the functionality soon after. We encourage responsible disclosure of potential application security issues to security@google.com."</p><p>Graham Cluley, senior technology consultant at Sophos, said the flaw was a particularly serious one, even though it appears there was no monetary reward for the scammers.</p><p>"Although this particular exploit appears to have been set up for mischief, more malicious hackers could easily have exploited the vulnerability to spread the typical money-making spam we often see or to distribute malware or a phishing attack," Cluley wrote in a blog post.</p><p>"Security issues like this are a real concern as more and more people rely upon email communications, and their webmail providers to deliver a reliable, filtered inbox. This was a serious security hole."</p><p>Facebook recently made a play in the email sphere with <a href="https://www.itpro.com/628633/facebook-messages-need-to-know" target="_blank" data-original-url="https://www.itpro.com/628633/facebook-messages-need-to-know">Messages</a>, designed to be better at protecting against spam in comparison to other clients.</p><p>The social networking giant last week outlined in a <a href="http://www.facebook.com/note.php?note_id=457318480765&comments" target="_blank">blog</a> how it had "devoted a lot of time and energy to keeping spam and other annoying or malicious communications out."</p><p>"Most importantly, Messages uses your social connections on Facebook to ensure that the inbox only contains messages from your friends and their friends by default," Facebook added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/628780/google-quick-to-fix-gmail-spam-exploit</link>
                                                                            <description>
                            <![CDATA[ Google has addressed an exploit which tried to send spam to Gmail users if they visited specially-crafted websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eSuX8smyzBNNeNcpEJgCpX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gPqL6BUFnzZLaN46NaDnoX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Nov 2010 11:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Workspace]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Google]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gPqL6BUFnzZLaN46NaDnoX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gPqL6BUFnzZLaN46NaDnoX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A "serious" exploit that allowed spam to be sent to Gmail users without them knowing about it has been shut down.</p><p>Google claimed it was quick to counter the exploit, which caused spam to be sent to logged-in Gmail users when they visited specially-crafted websites.</p><p>"We quickly fixed the issue in the Google Apps Script API that could have allowed for emails to be sent to Gmail users without their permission if they visited a specially designed website while signed into their account," Google explained in a statement.</p><p>"We immediately removed the site that demonstrated this issue, and disabled the functionality soon after. We encourage responsible disclosure of potential application security issues to security@google.com."</p><p>Graham Cluley, senior technology consultant at Sophos, said the flaw was a particularly serious one, even though it appears there was no monetary reward for the scammers.</p><p>"Although this particular exploit appears to have been set up for mischief, more malicious hackers could easily have exploited the vulnerability to spread the typical money-making spam we often see or to distribute malware or a phishing attack," Cluley wrote in a blog post.</p><p>"Security issues like this are a real concern as more and more people rely upon email communications, and their webmail providers to deliver a reliable, filtered inbox. This was a serious security hole."</p><p>Facebook recently made a play in the email sphere with <a href="https://www.itpro.com/628633/facebook-messages-need-to-know" target="_blank" data-original-url="https://www.itpro.com/628633/facebook-messages-need-to-know">Messages</a>, designed to be better at protecting against spam in comparison to other clients.</p><p>The social networking giant last week outlined in a <a href="http://www.facebook.com/note.php?note_id=457318480765&comments" target="_blank">blog</a> how it had "devoted a lot of time and energy to keeping spam and other annoying or malicious communications out."</p><p>"Most importantly, Messages uses your social connections on Facebook to ensure that the inbox only contains messages from your friends and their friends by default," Facebook added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kroxxu botnet targets one million users ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A new botnet has been detected which could have potentially affected over a million web users in the last 12 months.</p><p>The Kroxxu botnet currently has its grip on around 100,000 web domains and has been spreading password-stealing malware whilst covering its tracks extremely effectively, <a href="http://www.avast.com/en-gb/index" target="_blank">avast!</a> Virus Lab found.</p><p>The surreptitious nature of the botnet meant researchers were unable to determine how the masterminds had monetised the operation.</p><p>"There are a number of ways they could be supporting themselves," said Jiri Sejtko, head of virus research at the avast! Virus Lab.</p><p>"The four most likely methods are through selling hacked space on infected servers, use of this malware to support the activities of other, more directly profitable malware, selling stolen credentials, or using keyloggers to spread other spam."</p><p>Kroxxu differs from traditional botnets, as its expansion has been achieved solely through infected websites.</p><p>It's owners gained passwords to take control of websites, before making alterations to the site's content in order to upload and modify files on infected servers, avast! explained.</p><p>The operators then spread the botnet to other servers across the world.</p><p>Kroxxu has used redirectors in order to make it difficult to track the botnet's activities. The security company estimated over 10,000 redirectors had been employed by Kroxxu over the last year.</p><p>The malicious network also used alterable components, as each layer of the botnet performs a specific task, giving it greater flexibility.</p><p>"Kroxxu's indirect cross infections are based on the fact that all parts [are] equal and interchangeable," explained Sejtko.</p><p>"If one part is used as an initial redirector, it may also be used as a final distribution part at the same or even a different time. This gives it an enormous range of designed-in duplicity."</p><p>Kroxxu could spread to gain much more traction, avast! said. URL blocking engines may struggle to differentiate between standard malware distribution domains run by the malware authors and hacked zombie domains like those controlled by Kroxxu, the security firm explained.</p><p>There have been a number of successful botnet takedowns this year, which led to a <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">drop in spam</a> in the last quarter.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/628756/kroxxu-botnet-targets-one-million-users</link>
                                                                            <description>
                            <![CDATA[ The Kroxxu botnet is believed to have affected over one million web users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">axgLbbcwNL2jFcpxmBGMFF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ENiNsA2PYCiydgewhXrYKK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Nov 2010 14:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ENiNsA2PYCiydgewhXrYKK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Botnet]]></media:description>                                                            <media:text><![CDATA[Botnet]]></media:text>
                                <media:title type="plain"><![CDATA[Botnet]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ENiNsA2PYCiydgewhXrYKK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new botnet has been detected which could have potentially affected over a million web users in the last 12 months.</p><p>The Kroxxu botnet currently has its grip on around 100,000 web domains and has been spreading password-stealing malware whilst covering its tracks extremely effectively, <a href="http://www.avast.com/en-gb/index" target="_blank">avast!</a> Virus Lab found.</p><p>The surreptitious nature of the botnet meant researchers were unable to determine how the masterminds had monetised the operation.</p><p>"There are a number of ways they could be supporting themselves," said Jiri Sejtko, head of virus research at the avast! Virus Lab.</p><p>"The four most likely methods are through selling hacked space on infected servers, use of this malware to support the activities of other, more directly profitable malware, selling stolen credentials, or using keyloggers to spread other spam."</p><p>Kroxxu differs from traditional botnets, as its expansion has been achieved solely through infected websites.</p><p>It's owners gained passwords to take control of websites, before making alterations to the site's content in order to upload and modify files on infected servers, avast! explained.</p><p>The operators then spread the botnet to other servers across the world.</p><p>Kroxxu has used redirectors in order to make it difficult to track the botnet's activities. The security company estimated over 10,000 redirectors had been employed by Kroxxu over the last year.</p><p>The malicious network also used alterable components, as each layer of the botnet performs a specific task, giving it greater flexibility.</p><p>"Kroxxu's indirect cross infections are based on the fact that all parts [are] equal and interchangeable," explained Sejtko.</p><p>"If one part is used as an initial redirector, it may also be used as a final distribution part at the same or even a different time. This gives it an enormous range of designed-in duplicity."</p><p>Kroxxu could spread to gain much more traction, avast! said. URL blocking engines may struggle to differentiate between standard malware distribution domains run by the malware authors and hacked zombie domains like those controlled by Kroxxu, the security firm explained.</p><p>There have been a number of successful botnet takedowns this year, which led to a <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">drop in spam</a> in the last quarter.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK is Western Europe’s worst spam spewer ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK has been given the unenviable crown of the king of malicious spam in Western Europe, research has shown.</p><p>While <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">spam generally saw a decline</a> in the third quarter, a <a href="http://uk.trendmicro.com/uk/home" target="_blank">Trend Micro</a> report found one in ten spam messages sent by the top 10 spam-sending nations was from the UK.</p><p>Cyber criminals were particularly intent on using spam advertising for quick and simple weight-loss products and programmes.</p><p>Indeed, a quarter of all scams detected by Trend were centred around these spam messages.</p><p>"The research shows that despite media reports about the rise in other online threats, traditional spam techniques are still favored by cyber criminals", said Rik Ferguson, senior security advisor at Trend.</p><p>"Consumers continue to fall prey to these types of scams and that's why they continue to be popular. My advice would be, if it looks too good to be true, it probably is."</p><p>The research was carried out in support of the Get Safe Online week, which <a href="https://www.itpro.com/628579/fake-anti-virus-cold-calling-warning-issued" target="_blank" data-original-url="https://www.itpro.com/628579/fake-anti-virus-cold-calling-warning-issued">kicked off on Monday</a>.</p><p>"It's vital we make people aware of the threats and how to deal with them, to ensure they continue to use the internet safely and confidently," said Tony Neate, managing director of Get Safe Online.</p><p>"It is about education and making people aware that, yes, these dangers are real, but armed with the right knowledge, we can all continue to enjoy using the internet securely."</p><p>Some believe whilst education is indeed needed, the awareness week does not go far enough.</p><p>"We're now seeing malicious emails and rogue or compromised websites become more difficult for the average consumer to identify," said Julian Lovelock, director for commerce markets worldwide at authentication solutions provider <a href="http://www.actividentity.com" target="_blank">ActivIdentity</a>.</p><p>"Get Safe Online week shouldn't be just one week in the year to reflect on security, but an ongoing program of education to help customers and employees guard against these threats."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/628714/uk-is-western-europes-worst-spam-spewer</link>
                                                                            <description>
                            <![CDATA[ The UK is one of the worst spam spewers in the world, Trend says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PY87ddsWfynQYTxQZMaVS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f5ZtZ2SpuUwHdGQeCegmCb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Nov 2010 13:22:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f5ZtZ2SpuUwHdGQeCegmCb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f5ZtZ2SpuUwHdGQeCegmCb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK has been given the unenviable crown of the king of malicious spam in Western Europe, research has shown.</p><p>While <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">spam generally saw a decline</a> in the third quarter, a <a href="http://uk.trendmicro.com/uk/home" target="_blank">Trend Micro</a> report found one in ten spam messages sent by the top 10 spam-sending nations was from the UK.</p><p>Cyber criminals were particularly intent on using spam advertising for quick and simple weight-loss products and programmes.</p><p>Indeed, a quarter of all scams detected by Trend were centred around these spam messages.</p><p>"The research shows that despite media reports about the rise in other online threats, traditional spam techniques are still favored by cyber criminals", said Rik Ferguson, senior security advisor at Trend.</p><p>"Consumers continue to fall prey to these types of scams and that's why they continue to be popular. My advice would be, if it looks too good to be true, it probably is."</p><p>The research was carried out in support of the Get Safe Online week, which <a href="https://www.itpro.com/628579/fake-anti-virus-cold-calling-warning-issued" target="_blank" data-original-url="https://www.itpro.com/628579/fake-anti-virus-cold-calling-warning-issued">kicked off on Monday</a>.</p><p>"It's vital we make people aware of the threats and how to deal with them, to ensure they continue to use the internet safely and confidently," said Tony Neate, managing director of Get Safe Online.</p><p>"It is about education and making people aware that, yes, these dangers are real, but armed with the right knowledge, we can all continue to enjoy using the internet securely."</p><p>Some believe whilst education is indeed needed, the awareness week does not go far enough.</p><p>"We're now seeing malicious emails and rogue or compromised websites become more difficult for the average consumer to identify," said Julian Lovelock, director for commerce markets worldwide at authentication solutions provider <a href="http://www.actividentity.com" target="_blank">ActivIdentity</a>.</p><p>"Get Safe Online week shouldn't be just one week in the year to reflect on security, but an ongoing program of education to help customers and employees guard against these threats."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malware spawning peaks at 60,000 a day ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Daily malware growth hit a new level in the third quarter, with an average of 60,000 new pieces seen every day, <a href="http://www.mcafee.com/us" target="_blank">McAfee</a> has found.</p><p>The <a href="https://www.itpro.com/626215/intel-to-acquire-mcafee-in-768-billion-deal" target="_blank" data-original-url="https://www.itpro.com/626215/intel-to-acquire-mcafee-in-768-billion-deal">recently-acquired</a> security giant also identified more than 14 million unique pieces of malware over the period - one million more than in the third quarter of 2009.</p><p>"Our Q3 Threat report shows that cyber criminals are not only becoming more savvy, but attacks are becoming increasingly more severe," said Mike Gallagher, senior vice president and chief technology officer of global threat intelligence at McAfee.</p><p>The Zeus piece of malware caused plenty of havoc over the period and a mobile version of the highly sophisticated malicious software was created during the quarter.</p><p>McAfee also saw an increase in email campaigns attempting to deliver the Zeus botnet using well-known organisations names, such as Western Union, as part of hackers' social engineering tricks.</p><p>"Cyber criminals are doing their homework and are aware of what's popular, and what's insecure," added Gallagher.</p><p>"They are attacking mobile devices and social networking sites, so education about user activity online, as well as incorporating the proper security technologies are of utmost importance."</p><p>Meanwhile, in line with <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">other reports</a>, McAfee saw spam levels fall over the quarter.</p><p>The decline was largely down to a number of high-profile botnet takedowns, including that of <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab</a>, which had infected around 30 million computers.</p><p>Kaspersky has warned, however, levels are likely to rebound as soon as spamming is just too much of a lucrative business.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/628687/malware-spawning-peaks-at-60000-a-day</link>
                                                                            <description>
                            <![CDATA[ In the third quarter, more malware was produced a day than ever before, McAfee says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tLpL3f8t57SeNWZJe6zU4g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g9Vgh7HuWYF5AjohWbfqZX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Nov 2010 17:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/g9Vgh7HuWYF5AjohWbfqZX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g9Vgh7HuWYF5AjohWbfqZX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Daily malware growth hit a new level in the third quarter, with an average of 60,000 new pieces seen every day, <a href="http://www.mcafee.com/us" target="_blank">McAfee</a> has found.</p><p>The <a href="https://www.itpro.com/626215/intel-to-acquire-mcafee-in-768-billion-deal" target="_blank" data-original-url="https://www.itpro.com/626215/intel-to-acquire-mcafee-in-768-billion-deal">recently-acquired</a> security giant also identified more than 14 million unique pieces of malware over the period - one million more than in the third quarter of 2009.</p><p>"Our Q3 Threat report shows that cyber criminals are not only becoming more savvy, but attacks are becoming increasingly more severe," said Mike Gallagher, senior vice president and chief technology officer of global threat intelligence at McAfee.</p><p>The Zeus piece of malware caused plenty of havoc over the period and a mobile version of the highly sophisticated malicious software was created during the quarter.</p><p>McAfee also saw an increase in email campaigns attempting to deliver the Zeus botnet using well-known organisations names, such as Western Union, as part of hackers' social engineering tricks.</p><p>"Cyber criminals are doing their homework and are aware of what's popular, and what's insecure," added Gallagher.</p><p>"They are attacking mobile devices and social networking sites, so education about user activity online, as well as incorporating the proper security technologies are of utmost importance."</p><p>Meanwhile, in line with <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">other reports</a>, McAfee saw spam levels fall over the quarter.</p><p>The decline was largely down to a number of high-profile botnet takedowns, including that of <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab</a>, which had infected around 30 million computers.</p><p>Kaspersky has warned, however, levels are likely to rebound as soon as spamming is just too much of a lucrative business.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Libra ESVA 2.0 review ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The appeal of the virtual appliance for messaging security hasn't been missed with most vendors now offering versions of their anti-spam software for VMware environments, but <a href="https://www.esva.co.uk" target="_blank" data-original-url="www.esva.co.uk">Italian company Libra</a> goes further. Not only does is its ESVA (email security virtual appliance) product designed to run only in VMware virtual machines (VMs) but it also claims a very high spam detection rate and looks very affordable for smaller businesses.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qdMJS6bCUFG9Fjn3gPPAFh" name="" alt="ITPRO_Value" src="https://cdn.mos.cms.futurecdn.net/qdMJS6bCUFG9Fjn3gPPAFh.jpg" mos="https://cdn.mos.cms.futurecdn.net/qdMJS6bCUFG9Fjn3gPPAFh.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>ESVA is delivered as an OVF file so it can be used with VMware Server, ESX Server, Workstation or Player. Libra has an image available for Microsoft's Virtual PC but stresses that, along with VMware Workstation and Player, this should only be used for evaluation purposes. Libra advised us that it will also be supporting Microsoft's Hyper-V and should have this available by the end of this year.</p><p>The open source community may well have come across ESVA before as it was originally developed by Global Domination and is still available as a free download. However, as with many of these types of projects, support has been very patchy with the developer disappearing for most of this year making it a risky choice to use in a business environment.</p><p>Libra started supporting the project in 2008 but after making substantial improvements to the core functions of the software, went commercial with its own version shortly afterwards. Libra ESVA is now a very different beast to the open source version and the company provides full support for its paying customers.</p><p>Libra claims a ten minute installation process which we can verify. After downloading the OVF file, we deployed it as a template to our ESX Server 4.0 system and had a new VM with the appliance loaded on it in a few minutes.</p><p>Initial setup starts by pointing a web browser at the appliance's default IP address and running through a quick setup wizard. After entering network details, you provide information about your company and email server, create a certificate and you're done.</p><p>The main web console shows how much work Libra has put into development of the GUI as it provides a lot of useful information. Spam statistics for the current week are shown in a graph at the top and valuable information about the VM swap file status and disk usage is provided alongside it.</p><p>A table below shows the day's activity whilst next to it is a big pie chart providing a breakdown of clean messages, spam and infections. You can also browse the last fifteen messages received and these are all colour coded showing clearly how they were classified by ESVA.</p><p>Along with an intuitive web interface, Libra has integrated many new features into ESVA which can all be configured without any knowledge of Linux. The local real time block list (RBL) is unusual as this is created by ESVA using data from its own anti-spam engine for the past day. Any IP address that it thinks is sending too much spam during this period will be automatically blocked.</p><p>Libra has added support for Active Directory and Exchange and only direct LDAP server queries are made by the appliance so it doesn't cache passwords locally. Access controls are good as you can decide which users are allowed to administer the appliance and any authenticated user can login, view their own spam digest and release or delete stored messages.</p><p>The anti-spam engine scores suspect messages as ham or spam and the scoring thresholds for these can be modified. For each category you can decide to quarantine, block, forward, delete or bounce messages, strip out HTML content and tag their subject lines.</p><p>Plenty more controls are provided as clean messages can be delivered normally, tagged and have any HMTL content converted to text. You can also store all messages in the appliance's quarantine area although we found this fills up very quickly so is best turned off.</p><p>Attachment filtering is very basic as you can't create lists of file extensions you want to block and can only declare a single email address that is exempted from attachment scanning. However, Libra advised us that this is one of the features in its to-do list for the next release.</p><p>The MCP (message content protection) feature attempts to prevent unwanted data leaks by scanning for keywords in message subjects and body content and assigns high or low scores to each message. You can adjust the scoring system and apply all the same message controls as for spam.</p><p>Configuring MCP takes a little practise as you use SQL queries. However, Libra provides some basic help in the web interface and it wasn't long before we were able to create quite complex expressions and successfully apply them to inbound and outbound mail.</p><p>To test spam detection rates we allowed the appliance to scan live email and left it on its default scoring settings. All ham and spam was passed to the quarantine area so we could easily see false positives and checking our mail clients allowed us to see if any dodgy messages had slipped through.</p><p>ESVA impressed as after a week it returned a 99.3 per cent success rate against live spam. False positives were also low as over the entire testing period only eight messages were incorrectly identified as spam and placed in the quarantine area.</p><p>SMBs looking for a virtual anti-spam appliance should consider ESVA which has a fine combination of features and performance. Libra has done a good development job with its intuitive web interface, so you don't need to to know any Linux, and the very affordable pricing structure.</p><h2 id="verdict-3">Verdict</h2><p>We were impressed with Libra ESVA as it delivered excellent anti-spam performance in our live tests. The software is very easy to deploy and configure and although we had some criticisms these are likely to be rectified in future versions. Libra’s low prices also make ESVA a worthy choice for SMBs looking to virtualise their network security services.</p><p>SYSTEM REQUIREMENTS OS: VMware Server/ESX/ESXi. For evaluation only - VMware Workstation/Player; Microsoft Virtual PC Memory: 1GB unreserved RAM Hard disk: 20-40GB free space</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/628666/libra-esva-20-review</link>
                                                                            <description>
                            <![CDATA[ Libra ESVA combines an impressive arsenal of anti-spam measures in a VMware virtual appliance. It's surprisingly inexpensive too, but how does it perform in our live lab tests? Read on to find out. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sH6hJ5QqbNDEpqe5JhBmTf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eZd7AiKVLLjvdGS6cGaY7J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Nov 2010 12:22:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eZd7AiKVLLjvdGS6cGaY7J-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eZd7AiKVLLjvdGS6cGaY7J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The appeal of the virtual appliance for messaging security hasn't been missed with most vendors now offering versions of their anti-spam software for VMware environments, but <a href="https://www.esva.co.uk" target="_blank" data-original-url="www.esva.co.uk">Italian company Libra</a> goes further. Not only does is its ESVA (email security virtual appliance) product designed to run only in VMware virtual machines (VMs) but it also claims a very high spam detection rate and looks very affordable for smaller businesses.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qdMJS6bCUFG9Fjn3gPPAFh" name="" alt="ITPRO_Value" src="https://cdn.mos.cms.futurecdn.net/qdMJS6bCUFG9Fjn3gPPAFh.jpg" mos="https://cdn.mos.cms.futurecdn.net/qdMJS6bCUFG9Fjn3gPPAFh.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>ESVA is delivered as an OVF file so it can be used with VMware Server, ESX Server, Workstation or Player. Libra has an image available for Microsoft's Virtual PC but stresses that, along with VMware Workstation and Player, this should only be used for evaluation purposes. Libra advised us that it will also be supporting Microsoft's Hyper-V and should have this available by the end of this year.</p><p>The open source community may well have come across ESVA before as it was originally developed by Global Domination and is still available as a free download. However, as with many of these types of projects, support has been very patchy with the developer disappearing for most of this year making it a risky choice to use in a business environment.</p><p>Libra started supporting the project in 2008 but after making substantial improvements to the core functions of the software, went commercial with its own version shortly afterwards. Libra ESVA is now a very different beast to the open source version and the company provides full support for its paying customers.</p><p>Libra claims a ten minute installation process which we can verify. After downloading the OVF file, we deployed it as a template to our ESX Server 4.0 system and had a new VM with the appliance loaded on it in a few minutes.</p><p>Initial setup starts by pointing a web browser at the appliance's default IP address and running through a quick setup wizard. After entering network details, you provide information about your company and email server, create a certificate and you're done.</p><p>The main web console shows how much work Libra has put into development of the GUI as it provides a lot of useful information. Spam statistics for the current week are shown in a graph at the top and valuable information about the VM swap file status and disk usage is provided alongside it.</p><p>A table below shows the day's activity whilst next to it is a big pie chart providing a breakdown of clean messages, spam and infections. You can also browse the last fifteen messages received and these are all colour coded showing clearly how they were classified by ESVA.</p><p>Along with an intuitive web interface, Libra has integrated many new features into ESVA which can all be configured without any knowledge of Linux. The local real time block list (RBL) is unusual as this is created by ESVA using data from its own anti-spam engine for the past day. Any IP address that it thinks is sending too much spam during this period will be automatically blocked.</p><p>Libra has added support for Active Directory and Exchange and only direct LDAP server queries are made by the appliance so it doesn't cache passwords locally. Access controls are good as you can decide which users are allowed to administer the appliance and any authenticated user can login, view their own spam digest and release or delete stored messages.</p><p>The anti-spam engine scores suspect messages as ham or spam and the scoring thresholds for these can be modified. For each category you can decide to quarantine, block, forward, delete or bounce messages, strip out HTML content and tag their subject lines.</p><p>Plenty more controls are provided as clean messages can be delivered normally, tagged and have any HMTL content converted to text. You can also store all messages in the appliance's quarantine area although we found this fills up very quickly so is best turned off.</p><p>Attachment filtering is very basic as you can't create lists of file extensions you want to block and can only declare a single email address that is exempted from attachment scanning. However, Libra advised us that this is one of the features in its to-do list for the next release.</p><p>The MCP (message content protection) feature attempts to prevent unwanted data leaks by scanning for keywords in message subjects and body content and assigns high or low scores to each message. You can adjust the scoring system and apply all the same message controls as for spam.</p><p>Configuring MCP takes a little practise as you use SQL queries. However, Libra provides some basic help in the web interface and it wasn't long before we were able to create quite complex expressions and successfully apply them to inbound and outbound mail.</p><p>To test spam detection rates we allowed the appliance to scan live email and left it on its default scoring settings. All ham and spam was passed to the quarantine area so we could easily see false positives and checking our mail clients allowed us to see if any dodgy messages had slipped through.</p><p>ESVA impressed as after a week it returned a 99.3 per cent success rate against live spam. False positives were also low as over the entire testing period only eight messages were incorrectly identified as spam and placed in the quarantine area.</p><p>SMBs looking for a virtual anti-spam appliance should consider ESVA which has a fine combination of features and performance. Libra has done a good development job with its intuitive web interface, so you don't need to to know any Linux, and the very affordable pricing structure.</p><h2 id="verdict-3">Verdict</h2><p>We were impressed with Libra ESVA as it delivered excellent anti-spam performance in our live tests. The software is very easy to deploy and configure and although we had some criticisms these are likely to be rectified in future versions. Libra’s low prices also make ESVA a worthy choice for SMBs looking to virtualise their network security services.</p><p>SYSTEM REQUIREMENTS OS: VMware Server/ESX/ESXi. For evaluation only - VMware Workstation/Player; Microsoft Virtual PC Memory: 1GB unreserved RAM Hard disk: 20-40GB free space</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>