<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="http://www.securelist.com/en/rss/allupdates" rel="self" type="application/rss+xml" />
<title>Securelist / All Updates</title>
<link>http://www.securelist.com/en/</link>
<description></description>
<lastBuildDate>19 Jun 2013 10:30:13 +0400</lastBuildDate>
<image>
<title>Securelist / All Updates</title>
<url>http://www.securelist.com/en/rss/klogo.gif</url>
<link>http://www.securelist.com/en/</link>	
</image>
	<item>
		<author>webmaster@securelist.com (Konstantin Markov)</author>
		<description></description>
		<guid>http://www.securelist.com/en/blog/8107/AutoRun_Reloaded</guid>
		<link>http://www.securelist.com/en/blog/8107/AutoRun_Reloaded</link>
		<pubDate>13 Jun 2013 15:17:00 +0400</pubDate>
		<title>Blog: AutoRun. Reloaded</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roman Unuchek)</author>
		<description>Recently, an Android application came to us for analysis. At a glance, we knew this one was special. All strings in the DEX file were encrypted, and the code was obfuscated.</description>
		<guid>http://www.securelist.com/en/blog/8106/The_most_sophisticated_Android_Trojan</guid>
		<link>http://www.securelist.com/en/blog/8106/The_most_sophisticated_Android_Trojan</link>
		<pubDate>06 Jun 2013 19:01:00 +0400</pubDate>
		<title>Blog: The most sophisticated Android Trojan</title>
	</item>
	<item>
		<author>webmaster@securelist.com (GReAT)</author>
		<description> Over the last few years, we have been monitoring a cyber-espionage campaign that has successfully compromised more than 350 high profile victims in 40 countries. The main tool used by the threat actors during these attacks is NetTraveler, a malicious program used for covert computer surveillance</description>
		<guid>http://www.securelist.com/en/blog/8105/NetTraveler_is_Running_Red_Star_APT_Attacks_Compromise_High_Profile_Victims</guid>
		<link>http://www.securelist.com/en/blog/8105/NetTraveler_is_Running_Red_Star_APT_Attacks_Compromise_High_Profile_Victims</link>
		<pubDate>04 Jun 2013 18:01:18 +0400</pubDate>
		<title>Blog: &quot;NetTraveler is Running!&quot; - Red Star APT Attacks Compromise High-Profile Victims</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kirill Kruglov)</author>
		<description></description>
		<guid>http://www.securelist.com/en/blog/8104/Security_policies_portable_applications</guid>
		<link>http://www.securelist.com/en/blog/8104/Security_policies_portable_applications</link>
		<pubDate>03 Jun 2013 17:08:00 +0400</pubDate>
		<title>Blog: Security policies: portable applications</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Konstantin Ignatev)</author>
		<description></description>
		<guid>http://www.securelist.com/en/blog/8103/What_are_children_doing_online</guid>
		<link>http://www.securelist.com/en/blog/8103/What_are_children_doing_online</link>
		<pubDate>03 Jun 2013 13:14:00 +0400</pubDate>
		<title>Blog: What are children doing online?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Jorge Mieres )</author>
		<description>We know that the family of malware called Trojan.MSIL.Jumcar and Trojan.Win32.Jumcar was developed in Peru with the primary aim of attacking Peruvian users. We also know that Chilean and Peruvian users have latterly been targeted as well.</description>
		<guid>http://www.securelist.com/en/blog/208195060/Jumcar_Peruvian_navy_Who_could_be_behind_it_Third_part</guid>
		<link>http://www.securelist.com/en/blog/208195060/Jumcar_Peruvian_navy_Who_could_be_behind_it_Third_part</link>
		<pubDate>03 Jun 2013 05:44:05 +0400</pubDate>
		<title>Blog: Jumcar. Peruvian navy? Who could be behind it? [Third part]</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Darya Gudkova)</author>
		<description></description>
		<guid>http://www.securelist.com/en/blog/8102/Caution_Fraud</guid>
		<link>http://www.securelist.com/en/blog/8102/Caution_Fraud</link>
		<pubDate>30 May 2013 13:39:00 +0400</pubDate>
		<title>Blog: Caution! Fraud!</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Jorge Mieres )</author>
		<description>Jumcar stands out from other malicious code developed in Latin America because of its particularly aggressive features. At the moment three generations of this malware family exist, which basically use symmetric algorithms in the first and second generation, and an asymmetric algorithm in the third.</description>
		<guid>http://www.securelist.com/en/blog/208195049/Jumcar_Timeline_crypto_and_specific_functions_Second_part</guid>
		<link>http://www.securelist.com/en/blog/208195049/Jumcar_Timeline_crypto_and_specific_functions_Second_part</link>
		<pubDate>27 May 2013 16:48:06 +0400</pubDate>
		<title>Blog: Jumcar. Timeline, crypto, and specific functions. [Second part]</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Tatyana Shcherbakova, Darya Gudkova)</author>
		<category>Spam and  phishing</category>
		<description>The percentage of spam in email traffic was up 2.1 percentage points compared with March and averaged 72.2%.</description>
		<guid>http://www.securelist.com/en/analysis/204792293/Spam_in_April_2013</guid>
		<link>http://www.securelist.com/en/analysis/204792293/Spam_in_April_2013</link>
		<pubDate>23 May 2013 17:40:00 +0400</pubDate>
		<title>Analysis: Spam in April 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Jorge Mieres )</author>
		<description>“Jumcar” is the name we have given to a family of malicious code developed in Latin America – particularly in Peru – and which, according to our research, has been deploying attack maneuvers since March 2012.</description>
		<guid>http://www.securelist.com/en/blog/208195041/Jumcar_From_Peru_with_a_focus_on_Latin_America_First_part</guid>
		<link>http://www.securelist.com/en/blog/208195041/Jumcar_From_Peru_with_a_focus_on_Latin_America_First_part</link>
		<pubDate>20 May 2013 08:06:07 +0400</pubDate>
		<title>Blog: Jumcar. From Peru with a focus on Latin America [First part]</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Stefano Ortolani)</author>
		<description>Fostering knowledge exchange among different generations of security researchers is maybe one of the best traits of a good security conference. Judging by its attendance, NoSuchCon can easily claim to be one of these. It's rare to see such a mix of young researchers and old gurus exchanging ideas and getting to know each other. Organized this year in Paris, NoSuchCon takes place in the premises of the &lt;strong&gt;Espace Oscar Niemeyer&lt;/strong&gt;; admittedly, indeed a nice move putting a security conference within an art exposition center (congrats to the organizers :)).</description>
		<guid>http://www.securelist.com/en/blog/208195029/NoSuchCon_2013</guid>
		<link>http://www.securelist.com/en/blog/208195029/NoSuchCon_2013</link>
		<pubDate>18 May 2013 16:00:51 +0400</pubDate>
		<title>Blog: NoSuchCon 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Fabio Assolini)</author>
		<description>Malicious PACs used by Brazilian bad guys aiming to steal bitcoins</description>
		<guid>http://www.securelist.com/en/blog/208195033/Malicious_PACs_and_Bitcoins</guid>
		<link>http://www.securelist.com/en/blog/208195033/Malicious_PACs_and_Bitcoins</link>
		<pubDate>17 May 2013 17:58:17 +0400</pubDate>
		<title>Blog: Malicious PACs and Bitcoins</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Denis Maslennikov)</author>
		<category>What we  detect, Vulnerabilities  and hackers</category>
		<description>According to KSN data, Kaspersky Lab products detected and neutralized 1 345 570 352 threats in Q1 2013.</description>
		<guid>http://www.securelist.com/en/analysis/204792292/IT_Threat_Evolution_Q1_2013</guid>
		<link>http://www.securelist.com/en/analysis/204792292/IT_Threat_Evolution_Q1_2013</link>
		<pubDate>16 May 2013 17:06:00 +0400</pubDate>
		<title>Analysis: IT Threat Evolution: Q1 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt;
Microsoft released a long list of updates for Microsoft software today. The most interesting appear to be those patching Internet Explorer and the kernel software vulnerabilities. In all, ten critical &quot;use-after-free&quot; vulnerabilities are patched in IE along with one important Information Disclosure vulnerability, and three elevation of privilege vulnerabilities are being patched as well. Almost all of these IE vulnerabilities were reported by external security researchers working through HP's Zero Day Initiative.
&lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208195028/Microsoft_Updates_May_2013_Slew_of_Internet_Explorer_Critical_Vulnerabilities_Kernel_EoP_and_Others</guid>
		<link>http://www.securelist.com/en/blog/208195028/Microsoft_Updates_May_2013_Slew_of_Internet_Explorer_Critical_Vulnerabilities_Kernel_EoP_and_Others</link>
		<pubDate>14 May 2013 22:06:28 +0400</pubDate>
		<title>Blog: Microsoft Updates May 2013 - Slew of Internet Explorer Critical Vulnerabilities, Kernel EoP, and Others</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dong Yan)</author>
		<description>In China telecom fraud has become an increasingly common crime.</description>
		<guid>http://www.securelist.com/en/blog/877/Telecom_fraud_phishing_and_Trojans_combined</guid>
		<link>http://www.securelist.com/en/blog/877/Telecom_fraud_phishing_and_Trojans_combined</link>
		<pubDate>13 May 2013 11:15:00 +0400</pubDate>
		<title>Blog: Telecom fraud - phishing and Trojans combined</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Darya Gudkova)</author>
		<category>Spam and  phishing</category>
		<description>The percentage of spam in total mail traffic was up by 0.5 percentage points in the first quarter, averaging 66.5%.</description>
		<guid>http://www.securelist.com/en/analysis/204792291/Spam_in_Q1_2013</guid>
		<link>http://www.securelist.com/en/analysis/204792291/Spam_in_Q1_2013</link>
		<pubDate>08 May 2013 15:00:00 +0400</pubDate>
		<title>Analysis: Spam in Q1 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Michael)</author>
		<description>The Counter eCrime Operations Summit VII (CeCOS VII) engages questions of operational challenges and the development of common resources for the first responders and forensic professionals who protect consumers and enterprises from the electronic-crime threat every day.

The annual event, organized by the Anti-Phishing Working Group (APWG) is this time held in Buenos Aires (Argentina).</description>
		<guid>http://www.securelist.com/en/blog/208194246/CeCOS_VII</guid>
		<link>http://www.securelist.com/en/blog/208194246/CeCOS_VII</link>
		<pubDate>27 Apr 2013 00:49:47 +0400</pubDate>
		<title>Blog: CeCOS VII</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kirill Kruglov)</author>
		<description></description>
		<guid>http://www.securelist.com/en/blog/876/Security_policies_remote_access_programs</guid>
		<link>http://www.securelist.com/en/blog/876/Security_policies_remote_access_programs</link>
		<pubDate>25 Apr 2013 19:44:00 +0400</pubDate>
		<title>Blog: Security policies: remote access programs</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Sergey Golovanov)</author>
		<category>What we  detect</category>
		<description>This article is based on technical data from KL experts and their analysis of the Korablin and Morcut malicious programs. A number of conclusions based on open source data.</description>
		<guid>http://www.securelist.com/en/analysis/204792290/Spyware_HackingTeam</guid>
		<link>http://www.securelist.com/en/analysis/204792290/Spyware_HackingTeam</link>
		<pubDate>23 Apr 2013 14:43:00 +0400</pubDate>
		<title>Analysis: Spyware. HackingTeam</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Sergey Golovanov)</author>
		<description>It has been three years since we published Lock, stock and two smoking Trojans in our blog. The article describes the first piece of malware designed to attack users of online banking software developed by a company called BIFIT. There are now several malicious programs with similar functionality.</description>
		<guid>http://www.securelist.com/en/blog/861/Lock_stock_and_two_smoking_Trojans_2</guid>
		<link>http://www.securelist.com/en/blog/861/Lock_stock_and_two_smoking_Trojans_2</link>
		<pubDate>22 Apr 2013 20:24:00 +0400</pubDate>
		<title>Blog: Lock, stock and two smoking Trojans-2</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Vicente Diaz)</author>
		<description>In my presentation in Source I talked about fraud in Twitter. 
These days we find a lot of spam bots in this social network, both blindly sending unsolicited direct messages to other users or doing some previous semantic analysis, depending on your tweets, for a more targeted message.</description>
		<guid>http://www.securelist.com/en/blog/208194237/Is_digital_marketing_the_new_spam</guid>
		<link>http://www.securelist.com/en/blog/208194237/Is_digital_marketing_the_new_spam</link>
		<pubDate>22 Apr 2013 09:54:12 +0400</pubDate>
		<title>Blog: Is digital marketing the new spam?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Tatyana Shcherbakova, Darya Gudkova)</author>
		<category>Spam and  phishing</category>
		<description>The percentage of spam in email traffic was down 1 percentage point compared with February and averaged 70.1%</description>
		<guid>http://www.securelist.com/en/analysis/204792289/Spam_in_March_2013</guid>
		<link>http://www.securelist.com/en/analysis/204792289/Spam_in_March_2013</link>
		<pubDate>18 Apr 2013 15:54:00 +0400</pubDate>
		<title>Analysis: Spam in March 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Michael)</author>
		<description>While many are still in shock after the Boston Marathon bombings on 16 April, it didn't take long for cyber criminals to abuse that tragic incident for their dirty deeds.
Today we already started receiving emails containing links to malicious locations with names like &quot;news.html&quot;.</description>
		<guid>http://www.securelist.com/en/blog/208194228/Boston_Aftermath</guid>
		<link>http://www.securelist.com/en/blog/208194228/Boston_Aftermath</link>
		<pubDate>17 Apr 2013 08:02:51 +0400</pubDate>
		<title>Blog: Boston Aftermath</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Tarakanov)</author>
		<description>Continuing our investigation into Winnti, in this post we describe how the group tried to re-infect a certain gaming company and what malware they used. After discovering that the company-s servers were infected, we began to clean them up in conjunction with the company-s system administrator, removing malicious files from the corporate network. This took a while because it was not clear at first exactly how the cybercriminals had penetrated the corporate network; we couldn-t find a way to completely stop attacks penetrating the network and malicious files kept appearing. An analysis performed by the gaming company itself led us to the conclusion that the infection started after establishing working contacts with a South Korean gaming company. This was also confirmed by our research: as we wrote before, the Winnti group is most active in East Asia and we identified 14 infected gaming companies in South Korea.</description>
		<guid>http://www.securelist.com/en/blog/208194224/Winnti_returns_with_PlugX</guid>
		<link>http://www.securelist.com/en/blog/208194224/Winnti_returns_with_PlugX</link>
		<pubDate>15 Apr 2013 16:30:00 +0400</pubDate>
		<title>Blog: Winnti returns with PlugX</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roel)</author>
		<description>Today is the second and last day of Infiltrate 2013 which is taking place in Miami Beach.
It's my first time at Infiltrate and so far I've been really impressed with the quality of the conference.
</description>
		<guid>http://www.securelist.com/en/blog/208194226/Hello_from_Infiltrate_2013</guid>
		<link>http://www.securelist.com/en/blog/208194226/Hello_from_Infiltrate_2013</link>
		<pubDate>12 Apr 2013 21:51:22 +0400</pubDate>
		<title>Blog: Hello from Infiltrate 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt;
A new-ish Flash exploit is on the loose for attack around the web. This time, the attackers have compromised a caregiver site providing support for Tibetan refugee children and are spreading malware signed with Winnti stolen certificates with Flash exploits.
&lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194218/Winnti_Stolen_Digital_Certificates_Re_Used_in_Current_Watering_Hole_Attacks_on_Tibetan_and_Uyghur_Groups</guid>
		<link>http://www.securelist.com/en/blog/208194218/Winnti_Stolen_Digital_Certificates_Re_Used_in_Current_Watering_Hole_Attacks_on_Tibetan_and_Uyghur_Groups</link>
		<pubDate>12 Apr 2013 04:31:18 +0400</pubDate>
		<title>Blog: Winnti-Stolen Digital Certificates Re-Used in Current Watering Hole Attacks on Tibetan and Uyghur Groups</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Tarakanov)</author>
		<description>During our research on the Winnti group we have managed to discovered quite a considerable amount of Winnti samples targeting different gaming companies. With the help ofUsing thisat sophisticatedcomplicated malicious program cybercriminals gained remote access to infected workstations and then carried out further they activityed manually.</description>
		<guid>http://www.securelist.com/en/blog/851/The_Winnti_honeypot_luring_intruders</guid>
		<link>http://www.securelist.com/en/blog/851/The_Winnti_honeypot_luring_intruders</link>
		<pubDate>11 Apr 2013 17:23:00 +0400</pubDate>
		<title>Blog: The Winnti honeypot - luring intruders</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Global Research &#x26; Analysis Team (GReAT), Kaspersky Lab)</author>
		<category>What we  detect</category>
		<description>The study shed light on the activities of a group that has persistently targeted online gaming companies for several years.</description>
		<guid>http://www.securelist.com/en/analysis/204792287/Winnti_More_than_just_a_game</guid>
		<link>http://www.securelist.com/en/analysis/204792287/Winnti_More_than_just_a_game</link>
		<pubDate>11 Apr 2013 17:00:00 +0400</pubDate>
		<title>Analysis: Winnti. More than just a game</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>Microsoft released two Bulletins this month patching 3 critical vulnerabilities. Along with these immediate issues, they released five other rated &quot;Important&quot;. It appears that the two Bulletins address use-after-free vulnerabilities that can all be attacked through Internet Explorer.</description>
		<guid>http://www.securelist.com/en/blog/208194217/Microsoft_Updates_April_2013_3_Critical_Vulnerabilities</guid>
		<link>http://www.securelist.com/en/blog/208194217/Microsoft_Updates_April_2013_3_Critical_Vulnerabilities</link>
		<pubDate>09 Apr 2013 22:23:20 +0400</pubDate>
		<title>Blog: Microsoft Updates April 2013 - 3 Critical Vulnerabilities</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Bestuzhev)</author>
		<description>New very active malicious campaign in Skype with almost 3 clicks (potential infections) per second</description>
		<guid>http://www.securelist.com/en/blog/208194206/An_avalanche_in_Skype</guid>
		<link>http://www.securelist.com/en/blog/208194206/An_avalanche_in_Skype</link>
		<pubDate>04 Apr 2013 18:40:19 +0400</pubDate>
		<title>Blog: An avalanche in Skype</title>
	</item>
	<item>
		<author>webmaster@securelist.com (David)</author>
		<description>Virus calendar wallpapers for 2013</description>
		<guid>http://www.securelist.com/en/blog/208194204/Virus_calendar_wallpapers_for_2013</guid>
		<link>http://www.securelist.com/en/blog/208194204/Virus_calendar_wallpapers_for_2013</link>
		<pubDate>04 Apr 2013 12:06:20 +0400</pubDate>
		<title>Blog: Virus calendar wallpapers for 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roel)</author>
		<description>&quot;If the Internet felt a bit more sluggish for you over the last few days in Europe, this may be part of the reason why.&quot;</description>
		<guid>http://www.securelist.com/en/blog/208194203/The_Biggest_DDoS_Ever_that_Almost_Broke_the_Internet</guid>
		<link>http://www.securelist.com/en/blog/208194203/The_Biggest_DDoS_Ever_that_Almost_Broke_the_Internet</link>
		<pubDate>30 Mar 2013 08:25:45 +0400</pubDate>
		<title>Blog: The Biggest DDoS Ever that &quot;Almost Broke the Internet&quot;?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Ben Godwood)</author>
		<description>Over the last few months we have seen a series of very similar targeted attacks being blocked in our Linux Mail Security Product.</description>
		<guid>http://www.securelist.com/en/blog/846/Military_Hardware_and_Mens_Health</guid>
		<link>http://www.securelist.com/en/blog/846/Military_Hardware_and_Mens_Health</link>
		<pubDate>29 Mar 2013 16:40:47 +0400</pubDate>
		<title>Blog: Military Hardware and Men’s Health</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Costin Raiu)</author>
		<description>In the past, we've seen targeted attacks against Tibetan and Uyghur activists on Windows and Mac OS X platforms. We've documented several interesting attacks which used ZIP files as well as DOC, XLS and PDF documents rigged with exploits. 
Several days ago, the e-mail account of a high-profile Tibetan activist was hacked and used to send targeted attacks to other activists and human rights advocates. Perhaps the most interesting part is that the attack e-mails had an APK attachment - a malicious program for Android.</description>
		<guid>http://www.securelist.com/en/blog/208194186/Android_Trojan_Found_in_Targeted_Attack</guid>
		<link>http://www.securelist.com/en/blog/208194186/Android_Trojan_Found_in_Targeted_Attack</link>
		<pubDate>26 Mar 2013 16:14:19 +0400</pubDate>
		<title>Blog: Android Trojan Found in Targeted Attack</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Tatyana Shcherbakova, Darya Gudkova)</author>
		<category>Spam and  phishing</category>
		<description>The percentage of spam in email traffic was up 12.8 percentage points compared with January and averaged 71.1%.</description>
		<guid>http://www.securelist.com/en/analysis/204792284/Spam_in_February_2013</guid>
		<link>http://www.securelist.com/en/analysis/204792284/Spam_in_February_2013</link>
		<pubDate>21 Mar 2013 16:00:00 +0400</pubDate>
		<title>Analysis: Spam in February 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (GReAT)</author>
		<description>Earlier today, the Laboratory of Cryptography and System Security (CrySyS Lab), together with the Hungarian National Security Authority (NBF), published details on a high profile targeted attack against Hungary. The details about the exact targets are not known and the incident remains classified.

Considering the high level classification of the attack, Kaspersky Lab’s Global Research &amp; Analysis Team performed a detailed technical analysis of the campaign and related malware samples.

You can read our short FAQ below and you can download our technical analysis paper linked at the end of the blogpost.
</description>
		<guid>http://www.securelist.com/en/blog/208194185/The_TeamSpy_Crew_Attacks_Abusing_TeamViewer_for_Cyberespionage</guid>
		<link>http://www.securelist.com/en/blog/208194185/The_TeamSpy_Crew_Attacks_Abusing_TeamViewer_for_Cyberespionage</link>
		<pubDate>20 Mar 2013 21:23:19 +0400</pubDate>
		<title>Blog: The TeamSpy Crew Attacks - Abusing TeamViewer for Cyberespionage</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Fabio Assolini)</author>
		<description>Attacks already started using the end of MSN Messenger to infect users</description>
		<guid>http://www.securelist.com/en/blog/208194178/The_end_of_MSN_Messenger_the_beginning_of_attacks</guid>
		<link>http://www.securelist.com/en/blog/208194178/The_end_of_MSN_Messenger_the_beginning_of_attacks</link>
		<pubDate>19 Mar 2013 15:27:02 +0400</pubDate>
		<title>Blog: The end of MSN Messenger, the beginning of attacks</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roman Unuchek)</author>
		<description></description>
		<guid>http://www.securelist.com/en/blog/845/Hello_from_Malaysia</guid>
		<link>http://www.securelist.com/en/blog/845/Hello_from_Malaysia</link>
		<pubDate>15 Mar 2013 18:48:00 +0400</pubDate>
		<title>Blog: Hello from Malaysia</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Stefano Ortolani)</author>
		<description>Every year as Europe wakes up from the cold winter to the warm days of spring, BlackHat traditionally descends to Amsterdam. This year’s conference is taking place on March 14-15 at the NH Grand Hotel Krasnapolsky, right Dam Square, the heart of Amsterdam. As spring doesn’t necessarily equal warm days here in Europe right now, the 500 or so BlackHat participants hit the conference rooms to attend quite a few interesting talks. Here’s a summary of the best talks at BlackHat Europe 2013.</description>
		<guid>http://www.securelist.com/en/blog/208194175/Highlights_from_BlackHat_Europe_2013_in_Amsterdam</guid>
		<link>http://www.securelist.com/en/blog/208194175/Highlights_from_BlackHat_Europe_2013_in_Amsterdam</link>
		<pubDate>15 Mar 2013 18:41:50 +0400</pubDate>
		<title>Blog: Highlights from BlackHat Europe 2013 in Amsterdam</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Ben Godwood)</author>
		<description>On March 4&lt;sup&gt;th&lt;/sup&gt; we spotted a large number of unusual emails being blocked by our Linux Mail Security product.</description>
		<guid>http://www.securelist.com/en/blog/837/Reminder_be_careful_opening_invoices_on_the_21st_March</guid>
		<link>http://www.securelist.com/en/blog/837/Reminder_be_careful_opening_invoices_on_the_21st_March</link>
		<pubDate>14 Mar 2013 19:23:00 +0400</pubDate>
		<title>Blog: Reminder: be careful opening invoices on the 21st March</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Costin Raiu)</author>
		<description>On Feb 12th 2013, FireEye announced the discovery of an Adobe Reader 0-day exploit which is used to drop a previously unknown, advanced piece of malware. We called this new malware &quot;ItaDuke&quot; because it reminded us of Duqu and because of the ancient Italian comments in the shellcode copied from Dante Alighieri's &quot;Divine Comedy&quot;.

Previously, we posted about another campaign hitting Governments and other institutions, named Miniduke, which was also using the same 'Divine Comedy' PDF exploits.

In the meantime, we've come by other attacks which piggyback on the same high level exploit code, only this time the targets are different: Uyghur activists.

Together with our partner at AlienVault Labs, we analyzed these new exploits. </description>
		<guid>http://www.securelist.com/en/blog/208194165/New_Uyghur_and_Tibetan_Themed_Attacks_Using_PDF_Exploits</guid>
		<link>http://www.securelist.com/en/blog/208194165/New_Uyghur_and_Tibetan_Themed_Attacks_Using_PDF_Exploits</link>
		<pubDate>14 Mar 2013 14:55:00 +0400</pubDate>
		<title>Blog: New Uyghur and Tibetan Themed Attacks Using PDF Exploits</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt;
Microsoft releases nine March Security Bulletins. Four of the Bulletins are rated critical, but of the 20 vulnerabilities being patched, 12 are rated critical and enable remote code execution and elevation of privilege. Microsoft software being patched with critical priority include Internet Explorer, Silverlight, Visio Viewer, and SharePoint. So, pretty much every consumer running Windows, and lots of Microsoft shops, should be diligently patching systems today.
&lt;/P&gt;
</description>
		<guid>http://www.securelist.com/en/blog/208194164/March_2013_Microsoft_Security_Bulletins_Low_Impact_from_Pwn2Own_Watch_USB_Drives_for_Another_Stuxnet</guid>
		<link>http://www.securelist.com/en/blog/208194164/March_2013_Microsoft_Security_Bulletins_Low_Impact_from_Pwn2Own_Watch_USB_Drives_for_Another_Stuxnet</link>
		<pubDate>12 Mar 2013 21:13:01 +0400</pubDate>
		<title>Blog: March 2013 Microsoft Security Bulletins - Low Impact from Pwn2Own, Watch USB Drives for Another Stuxnet</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Igor Soumenkov)</author>
		<description>Together with our partner CrySyS Lab, we've discovered two new, previously-unknown infection mechanisms for Miniduke. These new infection vectors rely on Java and IE vulnerabilities to infect the victim's PC.</description>
		<guid>http://www.securelist.com/en/blog/208194159/Miniduke_web_based_infection_vector</guid>
		<link>http://www.securelist.com/en/blog/208194159/Miniduke_web_based_infection_vector</link>
		<pubDate>11 Mar 2013 15:43:45 +0400</pubDate>
		<title>Blog: Miniduke: web based infection vector</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Fabio Assolini)</author>
		<description>&lt;p&gt;The 2014 FIFA World Cup has already kicked off, at least for Brazilian bad guys. Next year’s big event in Brazil has become one of the most prominent tactics used by Latin American cybercriminals as they unleash a real avalanche of phishing messages, fraudulent prizes and giveaways, malicious domains, fake tickets, credit card cloning, banking Trojans and a lot of social engineering.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194146/The_Brazilian_Phishing_World_Cup</guid>
		<link>http://www.securelist.com/en/blog/208194146/The_Brazilian_Phishing_World_Cup</link>
		<pubDate>11 Mar 2013 15:19:17 +0400</pubDate>
		<title>Blog: The Brazilian Phishing World Cup</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Bestuzhev)</author>
		<description>This is the topic that cybercriminals are speculating about and using as a hook to infect victims. The campaign is based on the Blackhole v2.0</description>
		<guid>http://www.securelist.com/en/blog/208194155/CIA_DELETED_Venezuela_s_Hugo_Chavez</guid>
		<link>http://www.securelist.com/en/blog/208194155/CIA_DELETED_Venezuela_s_Hugo_Chavez</link>
		<pubDate>08 Mar 2013 21:28:29 +0400</pubDate>
		<title>Blog: CIA &quot;DELETED&quot; Venezuela's Hugo Chavez?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Jorge Mieres )</author>
		<description>After the recent emergence of the criminal PiceBOT in Latin America, AlbaBotnet has joined the growing ranks of regional IT crime.</description>
		<guid>http://www.securelist.com/en/blog/208194134/AlbaBotnet_another_new_crime_wave_in_Latin_American_cyberspace</guid>
		<link>http://www.securelist.com/en/blog/208194134/AlbaBotnet_another_new_crime_wave_in_Latin_American_cyberspace</link>
		<pubDate>05 Mar 2013 03:06:09 +0400</pubDate>
		<title>Blog: AlbaBotnet, another new crime wave in Latin American cyberspace</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Denis Maslennikov)</author>
		<category>What we  detect</category>
		<description>The fifth part of our regular overview of mobile malware evolution was published one year ago, and now it&amp;#8217;s time to review the events of 2012 to see just how accurate our forecasts were</description>
		<guid>http://www.securelist.com/en/analysis/204792283/Mobile_Malware_Evolution_Part_6</guid>
		<link>http://www.securelist.com/en/analysis/204792283/Mobile_Malware_Evolution_Part_6</link>
		<pubDate>28 Feb 2013 13:00:00 +0400</pubDate>
		<title>Analysis: Mobile Malware Evolution: Part 6</title>
	</item>
	<item>
		<author>webmaster@securelist.com (GReAT)</author>
		<description>New Adobe PDFs exploiting CVE-2013-0640 drop sophisticated malware known as &quot;MiniDuke&quot;.</description>
		<guid>http://www.securelist.com/en/blog/208194129/The_MiniDuke_Mystery_PDF_0_day_Government_Spy_Assembler_0x29A_Micro_Backdoor</guid>
		<link>http://www.securelist.com/en/blog/208194129/The_MiniDuke_Mystery_PDF_0_day_Government_Spy_Assembler_0x29A_Micro_Backdoor</link>
		<pubDate>27 Feb 2013 18:00:00 +0400</pubDate>
		<title>Blog: The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor </title>
	</item>
	<item>
		<author>webmaster@securelist.com (Tatyana Shcherbakova, Darya Gudkova)</author>
		<category>Spam and  phishing</category>
		<description>The percentage of spam in email traffic was down 7.7 percentage points compared with December and averaged 58.3%</description>
		<guid>http://www.securelist.com/en/analysis/204792282/Spam_in_January_2013</guid>
		<link>http://www.securelist.com/en/analysis/204792282/Spam_in_January_2013</link>
		<pubDate>21 Feb 2013 12:54:00 +0400</pubDate>
		<title>Analysis: Spam in January 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Andrey Efremov, Vladimir Zapolyansky)</author>
		<category>What we  detect</category>
		<description>Corporate network security is one of the most pressing issues for companies today</description>
		<guid>http://www.securelist.com/en/analysis/204792280/Application_Control_the_key_to_a_secure_network_Part_1</guid>
		<link>http://www.securelist.com/en/analysis/204792280/Application_Control_the_key_to_a_secure_network_Part_1</link>
		<pubDate>19 Feb 2013 20:43:00 +0400</pubDate>
		<title>Analysis: Application Control: the key to a secure network. Part 1</title>
	</item>

</channel>
</rss>


