Thousands falling for Microsoft tech support scam; Caller offers to remove virus by remote access

Computer security firms are warning about a Microsoft tech support scam that now appears to be exploding nationwide.

This cold-calling scam first surfaced a couple of years ago. But Microsoft says people are now falling victim to it every day, as it can be very convincing.

http://www.newsnet5.com/dpp/money/consumer/dont_waste_your_money/Thousands-falling-for-Microsoft-tech-support-scam-Caller-offers-to-remove-virus-by-remote-access

Brute-force malware targets email and FTP servers

A piece of malware designed to launch brute-force password guessing attacks against websites built with popular content management systems like WordPress and Joomla has started being used to also attack email and FTP servers.

The malware is known as Fort Disco and was documented in August by researchers from DDoS mitigation vendor Arbor Networks who estimated that it had infected over 25,000 Windows computers and had been used to guess administrator account passwords on over 6,000 WordPress, Joomla and Datalife Engine websites.

http://www.networkworld.com/news/2013/093013-brute-force-malware-targets-email-and-274333.html?source=NWWNLE_nlt_afterdark_2013-09-30

Android malware utilising Google Cloud Messaging service

Summary: 
Kaspersky Lab claims it has found Android malware making use of an Android app messaging service.

Once you have a piece of malware sitting in the Google Play store, it would be remiss not to use the services available in the Android ecosystem to aid your nefarious activities.

http://www.zdnet.com/android-malware-utilising-google-cloud-messaging-service-7000019427/

Fake Verizon Wireless “Data Usage Overage Alert” Emails Lead to Malware

Verizon Wireless customers are advised to be cautious in case they come across an email titled “Data Usage Overage Alert” in their inbox.

The notifications appear to come from the telecoms company, but in reality they’re part of a cybercriminal scheme designed to distribute malware.

http://news.softpedia.com/news/Fake-Verizon-Wireless-Data-Usage-Overage-Alert-Emails-Lead-to-Malware-369674.shtml

Unusual file-infecting malware steals FTP credentials

About 70% of computers infected with this threat are in the US, according to antivirus firm Trend Micro.

IDG News Service – A new version of a file-infecting malware program that’s being distributed through drive-by download attacks is also capable of stealing FTP (File Transfer Protocol) credentials, according to security researchers from antivirus firm Trend Micro.

http://www.computerworld.com/s/article/9240795/Unusual_file_infecting_malware_steals_FTP_credentials

Pope sued over sexual abuse and not wearing seatbelt? Fake CNN and BBC news alerts spread malware

Don’t believe everything you read – because if you do, cybercriminals are going to take advantage of your gullibility and infect your computer with a Trojan horse.

Malware campaigns spammed out in the last 24 hours have pretended to be breaking news stories from the likes of CNN and the BBC.

Here are some examples, claiming to be a breaking news alert from CNN, which have focused on arresting news stories around the new Pope.

http://nakedsecurity.sophos.com/2013/03/19/breaking-news-pope-malware/

Microsoft warns about fake Java updates that force you to download malicious software

Microsoft would like to remind users about cyber criminals who attempt to take advantage of users who are aware of Java security alerts by creating fake virus alerts that force you to download malicious software, including malicious anti-virus software.

"In the case of the fake Java updates, cyber criminals are taking advantage of news about security vulnerabilities in Java and recommendations to update Java immediately. We agree that if you use Java on your device you should update it directly from the Oracle website," Microsoft warns users. There has been several reports about security alerts for Java in the recent months. Since Java is commonly used, cyber criminals often target users by claiming that their computer or device is at risk, forcing users to click a link to download malicious software. Microsoft recommends that Java users get their Java updates directly from Oracle or simply turn on automatic updates for Java, to avoid any problems.

http://www.winbeta.org/news/microsoft-warns-about-fake-java-updates-force-you-download-malicious-software

Nearly Half Of Mobile Apps Contain Pop-Up Ad Malware

SEATTLE — Remember when pop-up advertisements inundated your PC browser? It’s beginning to happen again, this time on smartphones and touch tablets.

 

Adware for mobile devices — referred to as madware — caught fire in 2012 and is expected to continue escalating this year.

http://www.businessinsider.com/half-of-mobile-apps-contain-pop-up-ad-malware-2013-1

US Homeland Security Continues Warning After Oracle Patches Java

Oracle Corp.has issued a patch for vulnerabilities to its Java software that were exposed last week, but federal security watchdogs continue to advise users to disable Java in Web browsers.

The U.S. Department of Homeland Security issued an alert last week when hackers began putting to use a package of malware that included a new way to avoid Java security and infect personal computers. Once inside, hackers could exploit the machine to run malicious software undetected, including snitching personal information and employing the machine in attacks on websites. 
 
http://www.4-traders.com/ORACLE-CORPORATION-4892/news/US-Homeland-Security-Continues-Warning-After-Oracle-Patches-Java-15825006/