International Telecommunication Union   ITU
 
 
Site Map Contact us Print Version
 Tuesday, August 21, 2007

The 46,000 people reportedly infected by ads on job sites may be only a fraction of the victims of an ambitious, multi-stage attack that's stolen data belonging to several hundred thousand people who posted resumes on Monster.com, a researcher said this weekend.

According to Symantec Security Analyst Amado Hidalgo, a new Trojan horse the company calls Infostealer.Monstres has stolen more than 1.6 million records belonging to several hundred thousand people from the job search service Monster.com. That data is then used to target the Monster.com users with credible phishing mail that plants more malware on their machines.

Read full story

Tuesday, August 21, 2007 12:52:33 PM (W. Europe Standard Time, UTC+01:00)  #     | 

KUALA LUMPUR: The country's information communication technology industry has been given another boost with the launch of four new initiatives to enable Malaysia to compete in the global technology-led environment. 

The initiatives – the Malaysia Animation Creative Content Centre, CyberSecurity Malaysia, KnowledgeGRID Malaysia and eContent Fund Awards – are also expected to help reduce what Prime Minister Datuk Seri Abdullah Ahmad Badawi has described as "digital poverty". 

CyberSecurity Malaysia is the result of the rebranding of the National ICT Security and Emergency Response Centre, to reflect the services and solutions the organisation provides for its clients and the public. 

Read full story

Tuesday, August 21, 2007 12:41:35 PM (W. Europe Standard Time, UTC+01:00)  #     | 
 Wednesday, August 15, 2007
The next big threat to Web security has less to do with phishing and more to do with affiliation networks, according to a recent Web security report by Fijan.

According to Finjan, a San Jose-based Web security provider, hackers are now using sophisticated affiliation networks that provide a hosting model for malicious code. Webmasters and bloggers who include the infected code on their sites are then paid according to the number of infected visitors they accumulate.

In an article at NetworkedWorld, Ben-Itzhak, CTO of Finjan said that "pretty much any site can be at risk, as these affiliation network techniques have even been used when compromising highly popular Web sites or government domains".

Ronald O'Brien, senior security analyst at anti-spam software provider Sophos said that these malware writers are basically introducing business concepts into there operation stressing that "They are actually measuring the effectiveness of their affiliates and paying them accordingly. We have simply never seen this level of sophistication."
Wednesday, August 15, 2007 4:01:21 PM (W. Europe Standard Time, UTC+01:00)  #     | 

"Hackers" defaced the United Nations Web site early Sunday with messages accusing the U.S. and Israel of killing children. As of late afternoon, some sections, including the area devoted to Secretary General Ban Ki-Moon, remained offline. The attack, spelled out by an Italian software developer on his blog and later reported by the BBC, replaced blurbs of recent speeches by Ban with some rather peaceful messages.

More at Networkedworld

Wednesday, August 15, 2007 11:32:58 AM (W. Europe Standard Time, UTC+01:00)  #     | 
 Thursday, August 09, 2007

Michael Ouma explains in his article how Kenya’s cyber law, when enacted, could be adopted as a model law for other countries within the East African Community (EAC) — Tanzania, Uganda, Rwanda and Burundi — which are yet to enact such kind of legislation to give regulatory direction for ICT-related transactions.

Already, a process has been initiated under the auspices of United States Agency for International Development (USAID) Washington’s Economic Growth Agriculture and Trade/Information Technology and Energy (EGAT/IT&E) Bureau to guide the process leading to the development of the legislation in Kenya.

Read full article at Eastern Standard

Thursday, August 09, 2007 5:16:31 PM (W. Europe Standard Time, UTC+01:00)  #     | 
 Wednesday, August 01, 2007
Impact 7.0 lets you set up automated spear-phishing attacks and other types of e-mail-based threats, record how targeted users react to the bait, and collect the results in reports for review. It also can check users' desktop applications for vulnerabilities and need for patch updates.

“With Impact, you can model a spear-phishing attack, and find out which users will click on embedded e-mail that fools them with a ‘You’ve won a vacation prize,’” says Will Aguilar, senior product manager.

More at NetworkedWorld

Wednesday, August 01, 2007 10:31:38 AM (W. Europe Standard Time, UTC+01:00)  #     | 
 Monday, July 30, 2007
Millions of documents, both government and private, containing sensitive and sometimes classified information are floating about freely on file sharing networks after being inadvertently exposed by individuals downloading P2P software on systems that held the data, members of a U.S. House committee were told Tuesday.

Among the documents exposed: The Pentagon's entire secret backbone network infrastructure diagram, complete with IP addresses and password change scripts; contractor data on radio frequency manipulation to beat Improvised Explosive Devices (IED) in Iraq; physical terrorism threat assessments for three major U.S cities; information on five separate Department of Defense information security system audits.

More at NetworkedWorld


Monday, July 30, 2007 5:18:40 PM (W. Europe Standard Time, UTC+01:00)  #     | 
 Friday, July 27, 2007
Botnets -- they're dangerous, deceptive, and very difficult to detect and deal with. What's more, according to recent surveys, the botnet threat is growing...rapidly.

Experts say it's imperative that enterprises become aware of the acute and growing dangers posed by botnets, and take decisive and effective steps to counter them before it's too late.

Read more at NetworkedWorld

Friday, July 27, 2007 10:11:18 AM (W. Europe Standard Time, UTC+01:00)  #     | 
 Thursday, July 26, 2007

Steps have finally been taken by Microsoft to protect millions of exposed networks vulnerable to a .Net exploit that was first discovered nine months ago.

Security-Assessment.com reported close to 90 percent of Web sites upon which the company penetration tested in 2006 had "critical to urgent vulnerabilities"

Microsoft's Patch Tuesday release covered vulnerabilities in Microsoft's .Net Framework, Office Excel, Office Publisher, and three for its Windows operating systems.

Visit NetworkedWorld for more. Story copyrighted NetworkedWorld, Inc


Thursday, July 26, 2007 9:40:48 AM (W. Europe Standard Time, UTC+01:00)  #     | 
 Tuesday, July 24, 2007
According to a Symantec report at the end of 2006, Beijing is now home to the world's largest collection of malware-infected computers, nearly 5% of the world's total. Research by the security company Sophos in April showed that China has overtaken the U.S. in hosting Web pages that secretly install malicious programs on computers to steal private information or send spam e-mails. And another report from Sophos earlier that month showed that Europe produces more spam than any other continent; one Polish Internet service provider alone produces fully 5% of the world's spam.

More at http://www.channelnewsasia.com/stories/technologynews/view/289328/

Tuesday, July 24, 2007 4:08:34 AM (W. Europe Standard Time, UTC+01:00)  #     | 
 Monday, July 16, 2007

TALLINN - Tensions between Estonia and Russia show no signs of declining any time soon and the latest manifestation of ill-will concerns the spring ‘cyber attacks’ on Estonia which are widely believed to have emanated from Russia in the immediate aftermath of the ‘Bronze Soldier’ controversy.

Earlier this week, the Russian embassy in Tallinn said that it has not witheld assistance with regard to an ongoing Estonian probe in to the attacks, but didn’t help because the authorities’ request was not formulated properly.b

Quoting the impenetrable legalese of the Russian Prosecutor General's Office, the embassy said that the existing bilateral legal assistance agreement implies procedural actions prescribed by the laws of both parties and does not envision search actions aimed at establishing the whereabouts of individuals concerning the investigation.

http://www.baltictimes.com/news/articles/18284/

Monday, July 16, 2007 4:16:24 AM (W. Europe Standard Time, UTC+01:00)  #     | 
 Wednesday, May 30, 2007

For many countries, the events of the past weeks have been a loud wake-up call. Estonia, one of the most wired nations in Europe, actually survived pretty well. Other countries would have fared worse, NATO specialists reckon.

The International Telecommunication Union, which unites all 191 countries that use the world telephone system, hopes to take the lead in pushing for a global convention against cybercrime. Alexander Ntoko, its expert on cyberwarfare, says the key issue is anonymity: “We are in an industry where there is no control, no rules, no identities—it's the wild west. But for critical applications you have to know who you are dealing with.” NATO experts agree. At a minimum, any international cybercrime convention is likely to oblige internet service providers to co-operate in blocking DDOS attacks coming from their subscribers' computers.

Read full story

Wednesday, May 30, 2007 12:01:41 PM (W. Europe Standard Time, UTC+01:00)  #     | 
 Thursday, May 24, 2007
The EU is stepping up the fight against cybercrime, outlining plans to create more meaningful legislation and promote greater, cross-border cooperation.

European Commission said legislation and law enforcement--especially across borders--needs to keep pace with new and evolving opportunities for criminals.

It said cybercrime comes in three forms: established crimes such as fraud, publication of illegal content, and crimes unique to the Internet--such as denial-of-service attacks and hacking.

The commission said laws targeting particular crimes--such as ID theft--and identifying those responsible for enforcing them will currently be more effective than general cybercrime legislation.

Thursday, May 24, 2007 10:13:26 AM (W. Europe Standard Time, UTC+01:00)  #     |