Tampilkan postingan dengan label google. Tampilkan semua postingan
Tampilkan postingan dengan label google. Tampilkan semua postingan

Selasa, 23 Agustus 2011

Android becomes most attacked mobile platform

security.cbronline.com

Going rate of one million stolen email addresses is $25, says cyber security company

Google's operating system (OS) for mobile phones, Android, has become a favourite target for cyber criminals with the amount of malware targeted at Android devices jumping 76% since last quarter, to become the most attacked mobile OS.

According to computer security company McAfee's latest 'Threats Report: Second Quarter 2011', this year has also resulted in the busiest ever first half-year in malware history.

In the second quarter (2Q) of 2011, Android OS-based malware surpassed Symbian OS for the most popular target for mobile malware developers.

The report also said that while Symbian OS and Java ME remain the most targeted to date, the rapid rise in Android malware indicates that the platform could become an increasing target for cybercriminals - affecting everything from calendar apps, to SMS messages to a fake Angry Birds updates.

McAfee Labs senior vice-president Vincent Weafer said, "This year we've seen record-breaking numbers of malware, especially on mobile devices, where the uptick is in direct correlation to popularity."

Weafer also said that cyber criminals are building sophisticated malware which are difficult to detect.

More...

Sabtu, 30 Juli 2011

ZeuS Trojan for Google Android Spotted

krebsonsecurity.com

Criminals have developed a component of the ZeuS Trojan designed to run on Google Android phones. The new strain of malware comes as security experts are warning about the threat from mobile malware that may use tainted ads and drive-by downloads.

Researchers at Fortinet said the malicious file is a new version of “Zitmo,” a family of mobile malware first spotted last year that stands for “ZeuS in the mobile.” The Zitmo variant, disguised as a security application, is designed to intercept the one-time passcodes that banks send to mobile users as an added security feature. It masquerades as a component of Rapport, a banking activation application from Trusteer. Once installed, the malware lies in wait for incoming text messages, and forwards them to a remote Web server.

More...

Selasa, 07 Juni 2011

Spear Phishing: More than Spam, it's Espionage

pcworld.com
The most frequent comment I see on stories reporting some new dramatically successful phishing attack is from an overly nearly well-informed technophile who thinks people who fall for phishing schemes are just stupid.

Despite a success rate so high it's become standard operating procedure for Chinese military and government cyber-espionage groups, people who respond to phishing e-mails are treated like they're one walker-assisted step above the elderly shut-ins who send money to help Nigerian princes and ministers of finance mysteriously down on their luck.

If only the stupid fell for phishing scams the successful attacks against companies with sophisticated security -- Google, Lockheed Martin, HB Gary, PayPal, various other U.S. military and intelligence agencies -- would have been able to shut down the breaches quickly. Others with security at least as good -- CitiBank, Bank of America, AOL, Western Union -- wouldn't have to send out alerts every 10 minutes warning people that they weren't sending out alerts, so don't mail in your usernames and passwords.

Phishing works, for the same reason grifting works -- given a set of facts that seem to fit all their expectations and experience, and the opportunity to either help out a co-worker or profit from something that's very little trouble for them, most people will take the risk. (See also "4 Security Tips Spurred by Recent Phishing Attacks on Gmail, Hotmail, and Yahoo").

More...

Kamis, 02 Juni 2011

Google breaks up Gmail spying campaign

scmagazineus.com

Google has identified and disrupted a campaign operating out of eastern China meant to hijack and monitor the Gmail accounts belonging to hundreds of users, the technology giant revealed Wednesday.

Victims included U.S. and Asian government officials -- mostly from South Korea, military members, journalists and Chinese political activists, said Eric Grosse, engineering director of the Google's security team, in a blog post.

The campaign appears to trace back to Jinan, China and involves the theft of user's Gmail passwords, likely through phishing, he said. Google was able to disrupt the campaign, secure the affected accounts and notify the targeted individuals.

"The goal of this effort seems to have been to monitor the contents of these users' emails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Grosse wrote. "Google enables you to forward your emails automatically, as well as grant others access to your account."

More...

Sabtu, 28 Mei 2011

PayPal and eBay accuse Google of corporate espionage

timesofoman.com
SAN FRANCISCO: Google faced a lawsuit after it unveiled a free mobile application that turns a smartphone into an electronic wallet and is designed to replace plastic credit cards.

PayPal and eBay filed a lawsuit in a California state court on Thursday charging that the Internet giant tapped into trade secrets for its newly released Google Wallet. Google did not immediately respond to the allegations.

PayPal spent three years trying to work out a deal in which it would handle payments for Android smartphones, only to see Google scuttle the talks and hire its lead negotiator Osama Bedier, according to court documents.

Bedier worked at the eBay-owned online financial services unit as a vice-president of platform, mobile, and new ventures until being hired in January by Google.

He played a central role at Google’s official unveiling in New York with financial partners Citibank, MasterCard and First Data and telecom ally Sprint, saying Google Wallet is being field tested and will be available this summer.

Google Wallet will initially work with Google’s Nexus S 4G smartphone from Sprint, the third-largest US wireless provider, and will eventually be expanded to other phones equipped with near field communication (NFC) technology.

More...

Kamis, 26 Mei 2011

Smart Phone Spy Software


Beware of the "Stealth Genie"....
From the manufacturers website:

Stealth Genie is a monitoring software which is easy to install and use for Android, Blackberry and Windows Mobile smart phones. The software is very feature rich and takes less than a minute to install. It is also 100% undetectable. All you have to do is install the software on to the mobile phone of the person you wish to monitor and our product does the rest.

Stealth Genie works in the background on a phone without disrupting its functionality. It allows you to track your employees and the delivery staff out in the field through its geo location feature (GPS). Through this software you can listen in to their calls, read their messages, emails and record their surroundings. You can also access their contacts, memo’s and appointment books. Our software enables you to see videos, pictures and internet browsing history on your subjects’ mobile phone as well.

Be aware...Stay tuned..JDL

Rabu, 18 Mei 2011

Military Tracking Tech, From Super Scents to Quantum Dots

wired
Scents that make you trackable, indoors and out. Nanocrystals that stick to your body, and light up on night-vision goggles. Miniradar that maps your location on Google Earth.

You can run, but you'll learn it's hard to hide from a new range of military tech. The Defense Department calls it “tagging, tracking and locating,” or TTL, this business of finding and following high-value targets on the battlefield. Ever since SEAL Team 6 took out Osama bin Laden, we’ve learned a lot about the technology used by special operators to find and reach their targets, from stealth helicopters to biometric identification devices. TTL gear, though, ranks among the spookiest Special Operations’ extremely spooky arsenal.

More...

Selasa, 17 Mei 2011

Android Malware Quadrupled in Six Months

pcmag.com
Android malware samples quadrupled between June 2010 and January 2011, according to a report from Juniper Networks and BullGuard mobile security released Monday.

The figure itself means little, since the size of the Android Market more than tripled from 80,000 to 300,000 apps between August 2010 and May 2011, but as cybercriminals become more sophisticated Android users need to start protecting their phones like they would their computers.

See PCMag's pick of the top 15 Mobile Security Tools for more information.

The greatest mobile malware risk comes from legitimate apps that have been injected with malicious software and re-packaged for app stores, Juniper wrote. DroidDream, HongTouTou, and Geinimi all used this method.

More...

Senin, 11 April 2011

On The Internet, No One Watches The Wiretappers

Note: Heads up, this just in from our friend "Mike"...JDL
forbes.com
When Twitter revealed in January that it had received a Department of Justice order to hand over information on three users associated with WikiLeaks, the real surprise wasn’t that an Internet company had been asked to secretly spill user data for a criminal investigation. It was that, for once, the firm didn’t kept quiet about it.

Chris Soghoian, a privacy researcher at Indiana University and the Center for Applied Cybersecurity Research, has been following that Twitter case closely as a potentially precedent-shaping test for how and when the government can nab users’ online information. And now he’s released a paper that puts the case in context, outlining just how little Americans are told about the extent of government surveillance on the Internet.

More...

Minggu, 10 April 2011

DOJ To Congress: We Shouldn’t Need A Warrant To Snoop Through Gmail


For years, privacy advocacy groups have been trying to make sure digital data has the same kinds of search and seizure protections that physical documents have. In recent times, even some major companies like Microsoft (NSDQ: MSFT) and AT&T (NYSE: T) have joined together in the Digital Due Process coalition, which wants to modernize the nation’s out-of-date wiretapping laws. Those corporations want law enforcement agents to get a warrant issued by a judge before they are able to tap into sources of data stored in the cloud, such as web email. It’s been an uphill fight—to say the least—and today, the Department of Justice took a position that’s going to make their quest even harder.

According to a report from CNET, a DOJ lawyer told a Senate committee that if cops are required to get a search warrant to tap into email stored online, it could have an “adverse impact” on investigations. “Speed is essential,” he said. “If Congress slows down the process, this would have real-life consequences, particularly where human life is involved.”

More...

Selasa, 15 Maret 2011

Hacking of DuPont, J&J, GE Were Undisclosed Google-Type Attacks

businessweek.com

March 9 (Bloomberg) -- The FBI broke the news to executives at DuPont Co. late last year that hackers had cracked the company’s computer networks for the second time in 12 months, according to a confidential Dec. 9, 2010, e-mail discussing the investigation.

About a year earlier, DuPont had been hit by the same China- based hackers who struck Google Inc. and unlike Google, DuPont kept the intrusion secret, internal e-mails from cyber-security firm HBGary Inc. show. As DuPont probed the incidents, executives concluded they were the target of a campaign of industrial spying, the e-mails show.

The attacks on DuPont and on more than a dozen other companies are discussed in about 60,000 confidential e-mails that HBGary, hired by some of targeted businesses, said were stolen from it on Feb. 6 and posted on the Internet by a group of hacker-activists known as Anonymous. The companies attacked include Walt Disney Co., Sony Corp., Johnson & Johnson, and GE, the e-mails show.

More...

Selasa, 26 Oktober 2010

Google in trouble, acknowledges spying on passwords, emails of users

topinews.com
Things could not have gone worse for the search engine major Google as it has finally acknowledged that it was spying on the emails and passwords of the users across Britain. This is definitely a major security breach and as is to be expected, Google is having a hard time giving proper explanation.

However, Google has already apologized for the reported incident and claimed that it has unwittingly downloaded personal data from wireless networks when its vehicles were driving down residential roads for taking photos for its Street View project. Most of the data, as the company informed, is fragmentary but in a few cases, web addresses, emails and even passwords of users were captured. However, Alan Eustace, Google’s Vice-President of engineering and research said that they were quick to delete those data and thereby they had managed to overcome a serious security related crisis.

More...

Jumat, 09 Juli 2010

Google's Street View 'snoops' on Congress members

news.bbc.co.uk
Google's popular Street View project may have collected personal information of members of Congress, including some involved in national security issues.

The claim was made by leading advocacy group, Consumer Watchdog which wants Congress to hold hearings into what data Google's Street View possesses.

Google admitted it mistakenly collected information, transmitted over unsecured wireless networks, as its cars filmed locations for mapping purposes.

Google said the problem began in 2006.

The issue came to light when German authorities asked to audit the data.

The search giant said the snippets could include parts of an email, text, photograph, or even the website someone might be viewing.

"We think the Google Wi-Spy effort is one of the biggest wire tapping scandals in US history," John Simpson of Consumer Watchdog told BBC News.

More...

Jumat, 28 Mei 2010

Protecting the smartphone from malware

connectedplanetonline.com

Despite the increasing sophistication of smartphones and other mobile devices, viruses and malware don’t plague the wireless industry the way they do the personal and business computing worlds. But computer protection software giant Symantec has decided to dive into the smartphone space regardless, in anticipation of future security threats and to stake a claim in the growing applications market.

Symantec (NASDAQ:SYMC) today announced the launch of Norton Everywhere a suite of services and applications targeting Android and Apple iPhone devices as well the growing number of non-PC devices connected to the Internet via Wi-Fi and home networks. The most familiar service in that suite is a mobile version of its Norton Antivirus software, initially for Android phones only, which identifies malicious applications and software before they’re downloaded and installed onto a device. It will also scan applications already installed on a device to see if they are doing anything suspicious, such as accessing phone logs and phone books and relaying that information across the network, and warn users about just what their apps are doing.

Norton Mobile will be available as a Beta application in June, and while Symantec is investigating optimizing the security solution for other platforms, it felt Android was the best place to start. Unlike the iPhone, which uses a closed application distribution model driven by Apple’s App Store, Android software can come from anywhere — the Web, third-party app stores, even embedded in an e-mail, said Dan Nadir, director of product management for Symantec.

More...

Minggu, 16 Mei 2010

Google's Wi-Fi Spying: What Were They Thinking?

pcworld.com
"Don't be evil" has gone all 1984 on us. Or so it seems after Google revealed Friday that its Street View cars, in addition to snapping photos of the world's roadways, have also been collecting sensitive personal information from unencrypted wireless networks.

It was no secret that Google's cars had already been collecting publicly broadcast SSID information (Wi-Fi network names) and MAC addresses (unique numbers for devices like Wi-Fi routers). But this techie data, which is used for location-based services such as Google Maps, didn't include any "payload data," or personal information sent over the network.

Or so "Big Brother" Google claimed on April 27. But yesterday the search behemoth 'fessed up to a security gaffe of Orwellian proportions. Due to a piece of code written in 2006 by an engineer for an experimental Wi-Fi project, Google had in fact been collecting those private bits after all.

More...

Kamis, 04 Februari 2010

Google Asks NSA to Help Secure Its Network


wired.com

Google is teaming up with the National Security Agency to investigate the recent hack attack against its network in a bid to prevent another assault, according to The Washington Post.

The internet search giant is working on an agreement with the controversial agency to determine the attacker’s methods and what Google can do to shore up its network.

Sources assured the Post that the deal does not mean the NSA will have access to users’ searches or e-mail communications and accounts. Nor will Google share proprietary data with the agency.

But the move is raising concerns among privacy and civil rights advocates.

The Electronic Privacy Information Center filed a Freedom of Information Act request on Thursday, shortly after the agreement was made public, seeking more information about the arrangement. (.pdf)

Rabu, 20 Januari 2010

Cyber war expanding to new front

spokesman.com

The scale and sophistication of the cyber attacks on Google Inc. and other large U.S. corporations by hackers in China is raising national security concerns that the Asian superpower is escalating its industrial espionage efforts on the Internet.

While the U.S. focus has been primarily on protecting military and state secrets from cyber spying, a new battle is being waged in which corporate computers and the lucrative intellectual property they hold have become as much of a target of foreign governments as those run by the Pentagon and the CIA.

“This is a watershed moment in the cyber war,” James Mulvenon, director of the national-security firm, Center for Intelligence Research and Analysis at Defense Group Inc., said last week. “Before, the Chinese were going after defense targets to modernize the country’s military machine. But these intrusions strike at the heart of American innovation community.”

More...

Sabtu, 16 Januari 2010

Chinese hackers pose a growing threat to U.S. firms

latimes.com
Escalating cyber attacks on Google and other companies alarm government officials who say the U.S. may be powerless to stop the online industrial espionage.


The scale and sophistication of the cyber attacks on Google Inc. and other large U.S. corporations by hackers in China is raising national security concerns that the Asian superpower is escalating its industrial espionage efforts on the Internet.

While the U.S. focus has been primarily on protecting military and state secrets from cyber spying, a new battle is being waged in which corporate computers and the valuable intellectual property they hold have become as much a target of foreign governments as those run by the Pentagon and the CIA.

"This is a watershed moment in the cyber war," James Mulvenon, director of the Center for Intelligence Research and Analysis at Defense Group Inc., a national-security firm, said Thursday. "Before, the Chinese were going after defense targets to modernize the country's military machine. But these intrusions strike at the heart of the American innovation community."

More...

Rabu, 13 Januari 2010

Google attack part of widespread spying effort

computerworld.com

IDG News Service - Google's decision Tuesday to risk walking away from the world's largest Internet market may have come as a shock, but security experts see it as the most public admission of a top IT problem for U.S. companies: ongoing corporate espionage originating from China.

It's a problem that the U.S. lawmakers have complained about loudly. In the corporate world, online attacks that appear to come from China have been an ongoing problem for years, but big companies haven't said much about this, eager to remain in the good graces of the world's powerhouse economy.

Google, by implying that Beijing had sponsored the attack, has placed itself in the center of an international controversy, exposing what appears to be a state-sponsored corporate espionage campaign that compromised more than 30 technology, financial and media companies, most of them global Fortune 500 enterprises.

More...
Related Posts Plugin for WordPress, Blogger...