<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>&#34;The CTI Blog&#34;</title>
	<atom:link href="http://cyberthreat.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://cyberthreat.wordpress.com</link>
	<description>A Daily View into the World of Cyber Threat Intelligence</description>
	<lastBuildDate>Wed, 16 Mar 2011 15:30:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='cyberthreat.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>&#34;The CTI Blog&#34;</title>
		<link>http://cyberthreat.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://cyberthreat.wordpress.com/osd.xml" title="&#34;The CTI Blog&#34;" />
	<atom:link rel='hub' href='http://cyberthreat.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Health Net slow to tell members of security breach</title>
		<link>http://cyberthreat.wordpress.com/2011/03/16/health-net-slow-to-tell-members-of-security-breach/</link>
		<comments>http://cyberthreat.wordpress.com/2011/03/16/health-net-slow-to-tell-members-of-security-breach/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 15:30:37 +0000</pubDate>
		<dc:creator>pmakohon</dc:creator>
				<category><![CDATA[Health Industry]]></category>
		<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=596</guid>
		<description><![CDATA[Health Net slow to tell members of security breach: &#8220;&#8221; (Via .)<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=596&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2011/03/15/BANN1IBTRK.DTL">Health Net slow to tell members of security breach</a>: &#8220;&#8221;</p>
<p>(Via <a></a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/596/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/596/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/596/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=596&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2011/03/16/health-net-slow-to-tell-members-of-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5560b0a4fe610d44ae10d6cae8812ac0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pmakohon</media:title>
		</media:content>
	</item>
		<item>
		<title>University in &#8216;serious&#8217; data breach; Publishes 17,000 students&#8217; data &#124; ZDNet</title>
		<link>http://cyberthreat.wordpress.com/2011/03/16/university-in-serious-data-breach-publishes-17000-students-data-zdnet/</link>
		<comments>http://cyberthreat.wordpress.com/2011/03/16/university-in-serious-data-breach-publishes-17000-students-data-zdnet/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 14:51:46 +0000</pubDate>
		<dc:creator>pmakohon</dc:creator>
				<category><![CDATA[Education Sector]]></category>
		<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=594</guid>
		<description><![CDATA[University in &#8216;serious&#8217; data breach; Publishes 17,000 students&#8217; data &#124; ZDNet: &#8220;&#8221; (Via .)<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=594&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.zdnet.com/blog/igeneration/university-in-serious-data-breach-publishes-17000-students-data/8915">University in &#8216;serious&#8217; data breach; Publishes 17,000 students&#8217; data | ZDNet</a>: &#8220;&#8221;</p>
<p>(Via <a></a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/594/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=594&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2011/03/16/university-in-serious-data-breach-publishes-17000-students-data-zdnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5560b0a4fe610d44ae10d6cae8812ac0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pmakohon</media:title>
		</media:content>
	</item>
		<item>
		<title>UK firms failing to understand security threat :: Hack In The Box :: Keeping Knowledge Free</title>
		<link>http://cyberthreat.wordpress.com/2011/03/15/uk-firms-failing-to-understand-security-threat-hack-in-the-box-keeping-knowledge-free/</link>
		<comments>http://cyberthreat.wordpress.com/2011/03/15/uk-firms-failing-to-understand-security-threat-hack-in-the-box-keeping-knowledge-free/#comments</comments>
		<pubDate>Tue, 15 Mar 2011 13:54:50 +0000</pubDate>
		<dc:creator>pmakohon</dc:creator>
				<category><![CDATA[UK Threat Landscape]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=592</guid>
		<description><![CDATA[  UK firms failing to understand security threat :: Hack In The Box :: Keeping Knowledge Free: &#8220;     (Via .)<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=592&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p> </p>
<p><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=40481">UK firms failing to understand security threat :: Hack In The Box :: Keeping Knowledge Free</a>: &#8220;</p>
<p> </p>
<p> </p>
<p>(Via <a></a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/592/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/592/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/592/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=592&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2011/03/15/uk-firms-failing-to-understand-security-threat-hack-in-the-box-keeping-knowledge-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5560b0a4fe610d44ae10d6cae8812ac0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pmakohon</media:title>
		</media:content>
	</item>
		<item>
		<title>One-Third of All Malware in Existence Appeared in 2010</title>
		<link>http://cyberthreat.wordpress.com/2011/01/13/one-third-of-all-malware-in-existence-appeared-in-2010/</link>
		<comments>http://cyberthreat.wordpress.com/2011/01/13/one-third-of-all-malware-in-existence-appeared-in-2010/#comments</comments>
		<pubDate>Thu, 13 Jan 2011 16:05:59 +0000</pubDate>
		<dc:creator>skeoseyan</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[#malware]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=590</guid>
		<description><![CDATA[One-Third of All Malware in Existence Appeared in 2010: &#8220;&#8216;More than a third of all malware that has ever existed was created by criminal gangs in 2010 alone according to the latest PandaLabs Annual Report. To be precise, the company found that 34 percent of all existing malware has been concocted by cybercriminals in the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=590&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.layeredsec.com/2011/01/one-third-of-all-malware-in-existence.html">One-Third of All Malware in Existence Appeared in 2010</a>: &#8220;&#8216;More than a third of all malware that has ever existed was created by criminal gangs in 2010 alone according to the latest PandaLabs Annual Report.</p>
<p>To be precise, the company found that 34 percent of all existing malware has been concocted by cybercriminals in the last year, banishing forever the image of the disgruntled geek creating viruses in his bedsit.&#8217;</p>
<p><a href="http://www.pcworld.com/article/215951/onethird_of_all_malware_appeared_in_2010.html">Read more&#8230;</a></p>
<div><img src="https://blogger.googleusercontent.com/tracker/380924510879034818-1964161457311994733?l=blog.layeredsec.com" alt="" width="1" height="1" /></div>
<p>&#8220;</p>
<p> </p>
<p>(Via <a href="http://blog.layeredsec.com/">.:[ Layered Security ]:.</a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/590/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=590&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2011/01/13/one-third-of-all-malware-in-existence-appeared-in-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1d57baf4bb553031a706dbbce958aab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">skeoseyan</media:title>
		</media:content>

		<media:content url="//blogger.googleusercontent.com/tracker/380924510879034818-1964161457311994733?l=blog.layeredsec.com" medium="image" />
	</item>
		<item>
		<title>&#8216;Patriot Act&#8217; Phishing E-mails Resurface, FDIC Warns</title>
		<link>http://cyberthreat.wordpress.com/2011/01/13/patriot-act-phishing-e-mails-resurface-fdic-warns/</link>
		<comments>http://cyberthreat.wordpress.com/2011/01/13/patriot-act-phishing-e-mails-resurface-fdic-warns/#comments</comments>
		<pubDate>Thu, 13 Jan 2011 02:24:52 +0000</pubDate>
		<dc:creator>skeoseyan</dc:creator>
				<category><![CDATA[Criminal Techniques]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=586</guid>
		<description><![CDATA[&#8216;Patriot Act&#8217; Phishing E-mails Resurface, FDIC Warns: &#8220;Scammers are trying to steal banking information using fake e-mails that look like they&#8217;ve come from the U.S. Federal Deposit Insurance Corporation, the FDIC&#8230; &#8220; (Via PC World Latest Technology News.)<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=586&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://feeds.pcworld.com/click.phdo?i=c0c9fa0676e489cae3f6d9ea335bd496">&#8216;Patriot Act&#8217; Phishing E-mails Resurface, FDIC Warns</a>: &#8220;Scammers are trying to steal banking information using fake e-mails that look like they&#8217;ve come from the U.S. Federal Deposit Insurance Corporation, the FDIC&#8230;<br style="clear:both;" /> <br style="clear:both;" /><img src="http://segment-pixel.invitemedia.com/pixel?code=TechCons&amp;partnerID=167&amp;key=segment" border="0" alt="" width="0" height="0" /><img src="http://pixel.quantserve.com/pixel/p-8bUhLiluj0fAw.gif?labels=pub.29764.rss.TechCons.10481,cat.TechCons.rss" border="0" alt="" width="0" height="0" /><img src="http://haku.vizu.com/a.gif?cid=1361;adid=300x250;siteid=pheedo;" border="0" alt="" width="0" height="0" />&#8220;</p>
<p>(Via <a href="http://www.pcworld.com">PC World Latest Technology News</a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/586/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/586/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/586/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/586/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/586/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/586/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/586/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/586/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/586/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/586/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/586/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/586/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/586/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/586/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=586&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2011/01/13/patriot-act-phishing-e-mails-resurface-fdic-warns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1d57baf4bb553031a706dbbce958aab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">skeoseyan</media:title>
		</media:content>

		<media:content url="http://segment-pixel.invitemedia.com/pixel?code=TechCons&#38;partnerID=167&#38;key=segment" medium="image" />

		<media:content url="http://pixel.quantserve.com/pixel/p-8bUhLiluj0fAw.gif?labels=pub.29764.rss.TechCons.10481,cat.TechCons.rss" medium="image" />

		<media:content url="http://haku.vizu.com/a.gif?cid=1361;adid=300x250;siteid=pheedo;" medium="image" />
	</item>
		<item>
		<title>Infected PC Compromises Pentagon Credit Union</title>
		<link>http://cyberthreat.wordpress.com/2011/01/12/infected-pc-compromises-pentagon-credit-union/</link>
		<comments>http://cyberthreat.wordpress.com/2011/01/12/infected-pc-compromises-pentagon-credit-union/#comments</comments>
		<pubDate>Wed, 12 Jan 2011 19:00:36 +0000</pubDate>
		<dc:creator>skeoseyan</dc:creator>
				<category><![CDATA[Financial Services]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Military & Defense]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=582</guid>
		<description><![CDATA[Infected PC Compromises Pentagon Credit Union: &#8220; The credit union used by members of the U.S. armed forces and their families has admitted that a laptop infected with malware was used to access a database containing the personal and financial information of customers. &#8220;   (Via threatpost &#8211; The First Stop for Security News.)<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=582&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://threatpost.com/en_us/blogs/infected-pc-compromises-pentagon-credit-union-011211#comments">Infected PC Compromises Pentagon Credit Union</a>: &#8220;</p>
<p>The credit union used by members of the U.S. armed forces and their families has admitted that a laptop infected with malware was used to access a database containing the personal and financial information of customers.</p>
<p>&#8220;</p>
<p> </p>
<p>(Via <a href="http://threatpost.com/en_us/frontpage">threatpost &#8211; The First Stop for Security News</a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/582/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=582&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2011/01/12/infected-pc-compromises-pentagon-credit-union/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1d57baf4bb553031a706dbbce958aab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">skeoseyan</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Plugs Three Windows Security Holes</title>
		<link>http://cyberthreat.wordpress.com/2011/01/12/microsoft-plugs-three-windows-security-holes/</link>
		<comments>http://cyberthreat.wordpress.com/2011/01/12/microsoft-plugs-three-windows-security-holes/#comments</comments>
		<pubDate>Wed, 12 Jan 2011 18:23:13 +0000</pubDate>
		<dc:creator>skeoseyan</dc:creator>
				<category><![CDATA[Windows Vulnerabilities]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=580</guid>
		<description><![CDATA[Microsoft Plugs Three Windows Security Holes: &#8220; Microsoft today released security updates to fix at least three vulnerabilities in its Windows operating systems, including one labeled ‘critical,’ the company’s most serious rating. However, none of the patches address five zero-day flaws that can be used to attack Windows users. The critical update targets two weaknesses [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=580&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://krebsonsecurity.com/2011/01/microsoft-plugs-three-windows-security-holes/#comments">Microsoft Plugs Three Windows Security Holes</a>: &#8220;</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2010/01/winicon.jpg"><img class="alignright size-full wp-image-409" title="winicon" src="http://krebsonsecurity.com/wp-content/uploads/2010/01/winicon.jpg" alt="" width="139" height="123" /></a><strong>Microsoft </strong>today released security updates to fix at least three vulnerabilities in its <strong>Windows</strong> operating systems, including one labeled ‘critical,’ the company’s most serious rating. However, none of the patches address five zero-day flaws that can be used to attack Windows users.</p>
<p>The <a href="https://www.microsoft.com/technet/security/bulletin/MS11-002.mspx" target="_blank">critical update</a> targets two weaknesses present in all versions of Windows that Microsoft said hackers could exploit to break into unpatched systems just by getting users to visit a compromised or malicious Web site. A second update fixes a security issue in the Windows backup tool that affects Windows Vista machines.</p>
<p>The vulnerability in the Windows backup tool stems from a weakness that extends to hundreds of third-party, non-Microsoft applications built to run on Windows. I discussed this issue at length in <a href="http://krebsonsecurity.com/2010/09/ms-fix-shores-up-security-for-windows-users" target="_blank">a blog post in September</a>, but the upshot is that Microsoft has made available a FixIt tool to help fortify a number of these applications against a broad swath of security threats that stem from a mix of insecure default behaviors in Windows and poorly-written third party apps. If you haven’t already done so, take a moment to read at least the short version of that post, and apply the supplied FixIt tool from Microsoft.</p>
<p><span id="more-7378"> </span></p>
<p>Microsoft chose not to address a number of outstanding, known vulnerabilities for which exploit code is publicly available. Redmond’s <strong>Jonathan Ness </strong>explains the company’s thinking in holding off on fixing these flaws in a post to the <a href="http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx" target="_blank">Microsoft Security Research and Defense blog</a>.</p>
<p>Microsoft has released two separate FixIt tools to help users mitigate the threat from a couple of the more pressing outstanding vulnerabilities. If you use Windows, and especially if you browse the Web with <strong>Internet Explorer</strong>, you should take a moment to take advantage of these stopgap fixes, available <a href="http://support.microsoft.com/kb/2488013" target="_blank">here</a> and <a href="http://support.microsoft.com/kb/2490606" target="_blank">here</a>.</p>
<p>The updates are available through <a href="https://update.microsoft.com" target="_blank">Windows Update</a> or via the <a href="http://windows.microsoft.com/en-US/windows/help/windows-update" target="_blank">Automatic Update</a> capability built into all supported Windows versions. As always, if you experience any problems or glitches that appear to be related to applying these updates, please drop a note in the comments section.</p>
<p><img src="http://feeds.feedburner.com/~r/KrebsOnSecurity/~4/-e3Z-Xuj0i8" alt="" width="1" height="1" />&#8220;</p>
<p> </p>
<p>(Via <a href="http://krebsonsecurity.com">Krebs on Security</a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/580/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/580/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/580/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/580/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/580/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/580/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/580/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/580/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/580/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/580/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/580/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/580/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/580/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/580/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=580&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2011/01/12/microsoft-plugs-three-windows-security-holes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1d57baf4bb553031a706dbbce958aab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">skeoseyan</media:title>
		</media:content>

		<media:content url="http://krebsonsecurity.com/wp-content/uploads/2010/01/winicon.jpg" medium="image">
			<media:title type="html">winicon</media:title>
		</media:content>

		<media:content url="http://feeds.feedburner.com/~r/KrebsOnSecurity/~4/-e3Z-Xuj0i8" medium="image" />
	</item>
		<item>
		<title>Cyber Security Girl Strikes Again!: Congress Considers Change to &#8216;Red Flags Rule</title>
		<link>http://cyberthreat.wordpress.com/2010/12/05/cyber-security-girl-strikes-again-congress-considers-change-to-red-flags-rule/</link>
		<comments>http://cyberthreat.wordpress.com/2010/12/05/cyber-security-girl-strikes-again-congress-considers-change-to-red-flags-rule/#comments</comments>
		<pubDate>Sun, 05 Dec 2010 12:24:34 +0000</pubDate>
		<dc:creator>pmakohon</dc:creator>
				<category><![CDATA[Regulations]]></category>

		<guid isPermaLink="false">https://cyberthreat.wordpress.com/?p=577</guid>
		<description><![CDATA[  Cyber Security Girl Strikes Again!: Congress Considers Change to &#8216;Red Flags Rule: &#8221; CYBER SECURITY GIRL STRIKES AGAIN! IDENTITY THEFT IS THE #1 FASTEST GROWING WHITE COLLAR CRIME. THE FTC HAS MANDATED A LAW CALLED THE RED FLAGS RULE FOR BUSINESSES TO KEEP CUSTOMER AND EMPLOYEE INFO PROTECTED FROM ID THEFT. THE ENFORCEMENT DATE [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=577&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p> </p>
<p><a href="http://cybersecuritygirlstrikesagain.blogspot.com/2010/12/congress-considers-change-to-red-flags.html">Cyber Security Girl Strikes Again!: Congress Considers Change to &#8216;Red Flags Rule</a>: &#8221; CYBER SECURITY GIRL STRIKES AGAIN! IDENTITY THEFT IS THE #1 FASTEST GROWING WHITE COLLAR CRIME. THE FTC HAS MANDATED A LAW CALLED THE RED FLAGS RULE FOR BUSINESSES TO KEEP CUSTOMER AND EMPLOYEE INFO PROTECTED FROM ID THEFT. THE ENFORCEMENT DATE IS JANUARY 1, 2011. THE FINES FOR NON COMPLIANCE ARE CRIPPLING&#8230;</p>
<p>FRIDAY, DECEMBER 3, 2010</p>
<p>Congress Considers Change to &#8216;Red Flags Rule The American Bar Association has been battling for more than a year to exempt lawyers from new regulations designed to fight identity theft. Now, Congress has decided to step in.</p>
<p>With no fanfare and no recorded vote late Tuesday, the Senate approved legislation that could accomplish what the ABA was hoping to achieve. The bill would narrow the definition of ‘creditor’ under the Fair and Accurate Credit Transition Act of 2003, likely ensuring that lawyers would not meet the new definition.</p>
<p>An ABA spokeswoman said the group is optimistic about House passage, possibly this week.</p>
<p>The regulations over identity&#8221;</p>
<p> </p>
<p>(Via <a></a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/577/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/577/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/577/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/577/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/577/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/577/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/577/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/577/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/577/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/577/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/577/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/577/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/577/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/577/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=577&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2010/12/05/cyber-security-girl-strikes-again-congress-considers-change-to-red-flags-rule/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5560b0a4fe610d44ae10d6cae8812ac0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pmakohon</media:title>
		</media:content>
	</item>
		<item>
		<title>Cops Pull Plug on Rent-a-Fraudster Service for Bank Thieves</title>
		<link>http://cyberthreat.wordpress.com/2010/04/20/cops-pull-plug-on-rent-a-fraudster-service-for-bank-thieves/</link>
		<comments>http://cyberthreat.wordpress.com/2010/04/20/cops-pull-plug-on-rent-a-fraudster-service-for-bank-thieves/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 20:32:50 +0000</pubDate>
		<dc:creator>skeoseyan</dc:creator>
				<category><![CDATA[Criminal Techniques]]></category>
		<category><![CDATA[Cyber Criminals]]></category>

		<guid isPermaLink="false">http://cyberthreat.wordpress.com/?p=575</guid>
		<description><![CDATA[Cops Pull Plug on Rent-a-Fraudster Service for Bank Thieves: &#8221; Two Belarusian nationals suspected of operating a rent-a-fraudster service for bank and identity thieves have been arrested overseas, according to New York authorities, who unsealed an indictment for one of the suspects on Monday. Dmitry Naskovets, 25, and Sergey Semashko, 25, are suspected of creating [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=575&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.wired.com/threatlevel/2010/04/callservicebiz/#comments">Cops Pull Plug on Rent-a-Fraudster Service for Bank Thieves</a>: &#8221;
<p><a href="http://www.wired.com/images_blogs/threatlevel/2010/04/callservicebiz.jpg"><img class="aligncenter size-large wp-image-15570" title="callservicebiz" src="http://www.wired.com/images_blogs/threatlevel/2010/04/callservicebiz-660x330.jpg" alt="callservicebiz" width="660" height="330" /></a></p>
<p>Two Belarusian nationals suspected of operating a rent-a-fraudster service for bank and identity thieves have been arrested overseas, according to New York authorities, who unsealed an indictment for one of the suspects on Monday.</p>
<p>Dmitry Naskovets, 25, and Sergey Semashko, 25, are suspected of creating and operating CallService.biz, a Russian-language site for identity criminals who trafficked in stolen bank-account data and other information. The website <a href="http://callservice.biz/">displayed an FBI logo</a> Monday and the message, ‘This domain has been seized by the Federal Bureau of Investigation.’</p>
<div id="embed" style="float:left;width:60px;height:auto;padding:5px;">
digg_url = &#8216;http://www.wired.com/threatlevel/2010/04/callservicebiz/&#8217;;<br />

</div>
<p>Naskovets has been charged in U.S. District Court for Southern New York with one count each of aggravated identity theft and conspiracy to commit wire fraud and credit card fraud. Semashko has been charged by Belarusian authorities.</p>
<p>Naskovets was arrested in the Czech Republic last Thursday, at the request of U.S. authorities who have filed for extradition. Semashko was arrested the same day in Belarus.</p>
<p>According to the <a href="http://www.wired.com/images_blogs/threatlevel/2010/04/naskovets-dmitry-indictment.pdf">indictment</a> (.pdf), the two entrepreneurs launched the site in Lithuania in June 2007 and filled a much-needed niche in the criminal world — providing English- and German-speaking ‘stand-ins’ to help crooks thwart bank security screening measures.</p>
<p>In order to conduct certain transactions — such as initiating wire transfers, unblocking accounts or changing the contact information on an account — some financial institutions require the legitimate account holder to authorize the transaction by phone.</p>
<p><span id="more-15554"></span></p>
<p>Thieves could provide the stolen account information and biographical information of the account holder to CallService.biz, along with instructions about what needed to be authorized. The biographical information sometimes included the account holder’s name, address, Social Security number, e-mail address and answers to security questions the financial institution might ask, such as the age of the victim’s father when the victim was born, the nickname of the victim’s oldest sibling or the city where the victim was married.</p>
<p>The thieves obtained the information through various means, such as phishing attacks and malware placed on victims’ computers to log their keystrokes.</p>
<p>CallService.biz would then have someone who matched the legitimate account holder’s gender and was proficient in the needed language, pose as the account holder and call the financial institution to authorize the fraudulent transaction.</p>
<p>One client, for example, requested assistance in July 2007 with illegally siphoning $35,000 from a checking account owned by someone in Westchester County, New York. The wire transfer occurred July 17.</p>
<p>The site boasted that its purveyors had served more than 2,000 criminal customers. Authorities wouldn’t say what fees the two allegedly charged or how much they earned from their scheme.</p>
<p>The two advertised their services on other carding sites, such as CardingWorld.cc, which was also operated by Semashko. The ads boasted that their team had conducted more than 5,400 ‘confirmation calls’ to banks.</p>
<p>The FBI seized the domain name pursuant to a seizure warrant.</p>
<p>Additional co-conspirators were also arrested overseas, though authorities didn’t indicate how many.</p>
<p>U.S. Attorney Preet Bharara said in a statement that the site ‘was especially dangerous because it allegedly was specifically designed to bypass the usual security measures that bank and business customers have come to rely on.’</p>
<p>The Department of Justice’s office of international affairs worked with the Belarusian Ministry of Internal Affairs’ high-tech–crime department, the Police Presidium of the Czech Republic  and the Lithuanian Criminal Police Bureau Cybercrime Board to coordinate the investigations and arrests.</p>
<p>If convicted on all three counts, Naskovets faces a maximum sentence of 39½ years in prison.</p>
<p><a href="http://en.wordpress.com/types-of-blogs/"><img src="http://feedads.g.doubleclick.net/~at/2TsLLnL8CdSE08lAFVUytyvDPGQ/0/di" border="0"></img></a><br />
<a href="http://en.wordpress.com/types-of-blogs/"><img src="http://feedads.g.doubleclick.net/~at/2TsLLnL8CdSE08lAFVUytyvDPGQ/1/di" border="0"></img></a></p>
<div class="feedflare">
<a href="http://feeds.wired.com/~ff/wired27b?a=yt25DAYAWr8:6Pasxs9T0wo:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/wired27b?d=cGdyc7Q-1BI" border="0"></img></a> <a href="http://feeds.wired.com/~ff/wired27b?a=yt25DAYAWr8:6Pasxs9T0wo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/wired27b?i=yt25DAYAWr8:6Pasxs9T0wo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.wired.com/~ff/wired27b?a=yt25DAYAWr8:6Pasxs9T0wo:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/wired27b?i=yt25DAYAWr8:6Pasxs9T0wo:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.wired.com/~ff/wired27b?a=yt25DAYAWr8:6Pasxs9T0wo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/wired27b?d=yIl2AUoC8zA" border="0"></img></a>
</div>
<p><img src="http://feeds.feedburner.com/~r/wired27b/~4/yt25DAYAWr8" height="1">&#8220;</p>
<p>(Via <a href="http://www.wired.com/threatlevel">Wired: Threat Level</a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/575/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=575&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2010/04/20/cops-pull-plug-on-rent-a-fraudster-service-for-bank-thieves/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1d57baf4bb553031a706dbbce958aab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">skeoseyan</media:title>
		</media:content>

		<media:content url="http://www.wired.com/images_blogs/threatlevel/2010/04/callservicebiz-660x330.jpg" medium="image">
			<media:title type="html">callservicebiz</media:title>
		</media:content>

		<media:content url="http://feedads.g.doubleclick.net/~at/2TsLLnL8CdSE08lAFVUytyvDPGQ/0/di" medium="image" />

		<media:content url="http://feedads.g.doubleclick.net/~at/2TsLLnL8CdSE08lAFVUytyvDPGQ/1/di" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?d=cGdyc7Q-1BI" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?i=yt25DAYAWr8:6Pasxs9T0wo:V_sGLiPBpWU" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?i=yt25DAYAWr8:6Pasxs9T0wo:gIN9vFwOqvQ" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?d=yIl2AUoC8zA" medium="image" />

		<media:content url="http://feeds.feedburner.com/~r/wired27b/~4/yt25DAYAWr8" medium="image" />
	</item>
		<item>
		<title>Report: Google Hackers Stole Source Code of Global Password System</title>
		<link>http://cyberthreat.wordpress.com/2010/04/20/report-google-hackers-stole-source-code-of-global-password-system/</link>
		<comments>http://cyberthreat.wordpress.com/2010/04/20/report-google-hackers-stole-source-code-of-global-password-system/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 20:31:45 +0000</pubDate>
		<dc:creator>skeoseyan</dc:creator>
				<category><![CDATA[Criminal Techniques]]></category>
		<category><![CDATA[Security Breaches]]></category>
		<category><![CDATA[Security Reports and Surveys]]></category>

		<guid isPermaLink="false">http://cyberthreat.wordpress.com/?p=573</guid>
		<description><![CDATA[Report: Google Hackers Stole Source Code of Global Password System: &#8221; The hackers who breached Google’s network last year were able to nab the source code for the company’s global password system, according to the New York Times. The Single Sign-On password system, which Google referred to internally as Gaia, allows users to log into [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=573&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.wired.com/threatlevel/2010/04/google-hackers/#comments">Report: Google Hackers Stole Source Code of Global Password System</a>: &#8221;
<p>The hackers who breached Google’s network last year were able to nab the source code for the company’s global password system, according to the <em>New York Times</em>.</p>
<p>The Single Sign-On password system, which Google referred to internally as Gaia, allows users to log into a constellation of services the company offers — GMail, search, business applications and others — using one password.</p>
<p>The hackers, who are still unknown, were able to steal the code <a href="http://www.nytimes.com/2010/04/20/technology/20google.html">after gaining access to the company’s software repository</a>, which stores the crown jewels for its search engine and other programs.</p>
<p>Because the hackers grabbed the software, and do not appear to have grabbed customer passwords, users aren’t directly affected by the theft. But the hackers could study the software for security vulnerabilities to devise ways to breach the system that could later affect users.</p>
<p>Google announced in January that it and <a href="http://www.wired.com/threatlevel/2010/01/google-censorship-china/">numerous other companies had been hacked</a> in a sophisticated attack. The hackers had <a href="http://www.wired.com/threatlevel/2010/01/google-hack-attack/">targeted source code repositories</a> at many of the companies, including Google.</p>
<p>According to the <em>Times</em>, the theft began when an instant message was sent to a Google employee in China who was using Windows Messenger  The message included a link to a malicious website. Once the employee clicked on the link, the intruders were able to gain access to the employee’s computer and from there to computers used by software developers at Google’s headquarters in California.</p>
<p>The intruders seemed to know the names of the Gaia software developers, according to the <em>Times</em>.  The intruders had access to an internal Google corporate directory known as Moma, which lists the work activities of every Google employee.</p>
<p><span id="more-15584"></span></p>
<p>They initially tried to access the programmer’s work computers and ‘then used a set of sophisticated techniques to gain access to the repositories where the source code for the program was stored.’</p>
<p>The <em>Times</em> doesn’t elaborate on the set of sophisticated techniques the hackers used to access the source code, but in March, security firm McAfee released a white paper in relation to the Google hack that describes <a href="http://www.wired.com/threatlevel/2010/03/source-code-hackssource-code-hacks/">serious security vulnerabilities it found in softeware configuration management systems</a> (SCMs) used by companies that were targeed in the hacks.</p>
<p>‘[The SCMs] were wide open,’ Dmitri Alperovitch, McAfee’s vice president for threat research told Threat Level at the time. ‘No one ever thought about securing them, yet these were the crown jewels of most of these companies in many ways — much more valuable than any financial or personally identifiable data that they may have and spend so much time and effort protecting.’</p>
<p>Many of the companies that were attacked used the same source-code management system made by <a href="http://www.perforce.com/perforce/products.html">Perforce</a>, a California-based company, according to McAfee. The paper didn’t indicate, however, whether Google used Perforce or had another system in place with vulnerabilities.</p>
<p>According to McAfee’s earlier report, the malicious website the hackers used in the Google hack was hosted in Taiwan. Once the victim clicked on a link to the site, the site downloaded and executed a malicious JavaScript, with a zero-day exploit that attacked a vulnerability in the user’s Internet Explorer browser.</p>
<p>A binary disguised as a JPEG file then downloaded to the user’s system and opened a backdoor onto the computer and set up a connection to the attackers’ command-and-control servers, also hosted in Taiwan.</p>
<p>From that initial access point, the attackers obtained access to the source-code management system or burrowed deeper into the corporate network to gain a persistent hold.</p>
<p>According to the paper, the hackers were successful at accessing source code because many SCMs are not secured out of the box and do not maintain sufficient logs to help forensic investigators examining an attack.</p>
<p>‘Additionally, due to the open nature of most SCM systems today, much of the source code it is built to protect can be copied and managed on the endpoint developer system,’ the whie paper states. ‘It is quite common to have developers copy source code files to their local systems, edit them locally, and then check them back into the source code tree…. As a result, attackers often don’t even need to target and hack the backend SCM systems; they can simply target the individual developer systems to harvest large amounts of source code rather quickly.’</p>
<p>Alperovitch told Threat Level his company had seen no evidence to indicate that source code at any of the hacked companies had been altered.</p>
<p><a href="http://en.wordpress.com/types-of-blogs/"><img src="http://feedads.g.doubleclick.net/~at/VrmqGVHSYyCtCvgPVhj1nZNpesU/0/di" border="0"></img></a><br />
<a href="http://en.wordpress.com/types-of-blogs/"><img src="http://feedads.g.doubleclick.net/~at/VrmqGVHSYyCtCvgPVhj1nZNpesU/1/di" border="0"></img></a></p>
<div class="feedflare">
<a href="http://feeds.wired.com/~ff/wired27b?a=OmFk18sbgPU:tKJ_BUVquAg:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/wired27b?d=cGdyc7Q-1BI" border="0"></img></a> <a href="http://feeds.wired.com/~ff/wired27b?a=OmFk18sbgPU:tKJ_BUVquAg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/wired27b?i=OmFk18sbgPU:tKJ_BUVquAg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.wired.com/~ff/wired27b?a=OmFk18sbgPU:tKJ_BUVquAg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/wired27b?i=OmFk18sbgPU:tKJ_BUVquAg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.wired.com/~ff/wired27b?a=OmFk18sbgPU:tKJ_BUVquAg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/wired27b?d=yIl2AUoC8zA" border="0"></img></a>
</div>
<p><img src="http://feeds.feedburner.com/~r/wired27b/~4/OmFk18sbgPU" height="1">&#8220;</p>
<p>(Via <a href="http://www.wired.com/threatlevel">Wired: Threat Level</a>.)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberthreat.wordpress.com/573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberthreat.wordpress.com/573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberthreat.wordpress.com/573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberthreat.wordpress.com/573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberthreat.wordpress.com/573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberthreat.wordpress.com/573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberthreat.wordpress.com/573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberthreat.wordpress.com/573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberthreat.wordpress.com/573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberthreat.wordpress.com/573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberthreat.wordpress.com/573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberthreat.wordpress.com/573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberthreat.wordpress.com/573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberthreat.wordpress.com/573/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberthreat.wordpress.com&amp;blog=9699928&amp;post=573&amp;subd=cyberthreat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberthreat.wordpress.com/2010/04/20/report-google-hackers-stole-source-code-of-global-password-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1d57baf4bb553031a706dbbce958aab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">skeoseyan</media:title>
		</media:content>

		<media:content url="http://feedads.g.doubleclick.net/~at/VrmqGVHSYyCtCvgPVhj1nZNpesU/0/di" medium="image" />

		<media:content url="http://feedads.g.doubleclick.net/~at/VrmqGVHSYyCtCvgPVhj1nZNpesU/1/di" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?d=cGdyc7Q-1BI" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?i=OmFk18sbgPU:tKJ_BUVquAg:V_sGLiPBpWU" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?i=OmFk18sbgPU:tKJ_BUVquAg:gIN9vFwOqvQ" medium="image" />

		<media:content url="http://feeds.feedburner.com/~ff/wired27b?d=yIl2AUoC8zA" medium="image" />

		<media:content url="http://feeds.feedburner.com/~r/wired27b/~4/OmFk18sbgPU" medium="image" />
	</item>
	</channel>
</rss>
