 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Security Detail &#187; MacDefender</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/security-detail/tag/macdefender/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/security-detail</link>
	<description>Tony Bradley's take on the latest vital IT security news.</description>
	<lastBuildDate>Mon, 29 Apr 2013 17:39:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Mac OS Update Takes Care of Mac Malware</title>
		<link>http://itknowledgeexchange.techtarget.com/security-detail/mac-os-update-takes-care-of-mac-malware/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-detail/mac-os-update-takes-care-of-mac-malware/#comments</comments>
		<pubDate>Tue, 31 May 2011 22:20:25 +0000</pubDate>
		<dc:creator>Tony Bradley</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Mac malware]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[MacDefender]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-detail/mac-os-update-takes-care-of-mac-malware/</guid>
		<description><![CDATA[Apple has released an update for Mac OS X that addresses the recent scourge of Mac malware. The plague of rogue AV scareware apps has been a source of controversy and heated debate over the past few weeks. Mac users are trained to believe the OS is impervious, making them easier targets for social engineering [...]]]></description>
				<content:encoded><![CDATA[<p>Apple has released an <a href="http://support.apple.com/kb/HT4657" target="_blank">update for Mac OS X</a> that addresses the recent scourge of Mac malware.</p>
<p>The <a href="http://www.pcworld.com/businesscenter/article/228832/is_macdefender_malware_a_sign_of_the_macpocalypse.html" target="_blank">plague of rogue AV scareware apps </a>has been a source of controversy and heated debate over the past few weeks. Mac users are trained to believe the OS is impervious, making them easier targets for social engineering attacks like MacDefender.</p>
<p>Apple initially stayed out of the fray, and directed support techs not to get involved with eradicating the malware from Mac systems, but eventually Apple acknowledged the threat and <a href="http://www.computerworld.com/s/article/9217163/Mac_OS_update_detects_deletes_MacDefender_scareware_?taxonomyId=89" target="_blank">developed this update </a>to address the problem.</p>
<p>Mac users should download and apply the update immediately.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-detail/mac-os-update-takes-care-of-mac-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Recognize a Social Engineering Attack</title>
		<link>http://itknowledgeexchange.techtarget.com/security-detail/how-to-recognize-a-social-engineering-attack/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-detail/how-to-recognize-a-social-engineering-attack/#comments</comments>
		<pubDate>Mon, 30 May 2011 13:16:21 +0000</pubDate>
		<dc:creator>Tony Bradley</dc:creator>
				<category><![CDATA[cookiejacking]]></category>
		<category><![CDATA[Mac malware]]></category>
		<category><![CDATA[MacDefender]]></category>
		<category><![CDATA[rogue AV]]></category>
		<category><![CDATA[scarewar]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-detail/how-to-recognize-a-social-engineering-attack/</guid>
		<description><![CDATA[The rogue AV scareware attacks against Mac OS X, and the disclosure of a &#8216;cookiejacking&#8217; attack that could compromised sensitive account credentials both have one thing in common&#8211;social engineering. These attacks generally have a technical element as well. The latest variants of the Mac scareware take advantage of a setting in Safari to automatically open [...]]]></description>
				<content:encoded><![CDATA[<p>The rogue AV scareware <a href="http://www.pcworld.com/businesscenter/article/228832/is_macdefender_malware_a_sign_of_the_macpocalypse.html" target="_blank">attacks against Mac OS X</a>, and the disclosure of a <a href="http://www.pcworld.com/article/228917/dangers_of_ie_cookiejacking_what_you_need_to_know.html" target="_blank">&#8216;cookiejacking&#8217; attack </a>that could compromised sensitive account credentials both have one thing in common&#8211;social engineering.</p>
<p>These attacks generally have a technical element as well. The latest variants of the <a href="http://itknowledgeexchange.techtarget.com/security-detail/mac-scareware-trail-leads-back-to-russian-firm/" target="_blank">Mac scareware </a>take advantage of a setting in Safari to automatically open &#8220;safe&#8221; files, and the &#8216;cookiejacking&#8217; attack uses a weakness in the security zones protection of Internet Explorer. But, technical component aside, these attacks rely on somehow convincing the user to do something through social engineering.</p>
<p>A post on the <a href="http://windowsteamblog.com/windows/b/windowssecurity/archive/2011/05/28/combating-social-engineering-tactics-like-cookiejacking-to-stay-safer-online.aspx" target="_blank">Windows Security Blog </a>focused on the &#8216;cookiejacking&#8217; attack explains, &#8220;This is a form of social engineering attack and these kinds of threats will remain a concern for Internet users on all browsers. Software vulnerabilities are not needed for these kinds of threats to be successful so it is always a good idea to follow best practices – regardless of the browser you are using &#8211; in order to stay safe.&#8221;</p>
<p>The post offers six simple tips you can use to identify social engineering attacks, and avoid becoming a victim.</p>
<ol>
<li>Odd messages from friends on social networking sites to participate in games or offers you must act upon immediately.</li>
<li>Alarmist messages and threats of account closures.</li>
<li>Promises of money for little or no effort.</li>
<li>Deals that sound too good to be true.</li>
<li>Requests to donate to a charitable organization after a disaster that has been in the news.</li>
<li>Bad grammar and misspellings.</li>
</ol>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-detail/how-to-recognize-a-social-engineering-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Scareware Trail Leads Back to Russian Firm</title>
		<link>http://itknowledgeexchange.techtarget.com/security-detail/mac-scareware-trail-leads-back-to-russian-firm/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-detail/mac-scareware-trail-leads-back-to-russian-firm/#comments</comments>
		<pubDate>Mon, 30 May 2011 04:57:06 +0000</pubDate>
		<dc:creator>Tony Bradley</dc:creator>
				<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[ChronoPay]]></category>
		<category><![CDATA[Mac malware]]></category>
		<category><![CDATA[MacDefender]]></category>
		<category><![CDATA[rogue AV]]></category>
		<category><![CDATA[scareware]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-detail/mac-scareware-trail-leads-back-to-russian-firm/</guid>
		<description><![CDATA[Follow the money. If you want to get to the bottom of something&#8211;whether it is a political scandal, a murder mystery, or the source of rogue AV scareware attacks against Mac OS X&#8230;follow the money. Security reporter Brian Krebs did just that and he has connected the dots leading from MacDefender and the sudden plague [...]]]></description>
				<content:encoded><![CDATA[<p>Follow the money.</p>
<p>If you want to get to the bottom of something&#8211;whether it is a political scandal, a murder mystery, or the source of <a href="http://www.pcworld.com/businesscenter/article/228832/is_macdefender_malware_a_sign_of_the_macpocalypse.html" target="_blank">rogue AV scareware attacks against Mac OS X</a>&#8230;follow the money.</p>
<p>Security reporter Brian Krebs did just that and <a href="http://krebsonsecurity.com/2011/05/chronopay-fueling-mac-scareware-scams/" target="_blank">he has connected the dots </a>leading from MacDefender and the sudden plague of Mac malware back to a Russian payment processing company&#8211;ChronoPay.</p>
<p>Observant Mac users reported the domain names that the rogue AV attacks were being directed to for payment. Krebs did some digging into the WhoIs details to try and determine the owner of those domains to follow the money back to the source. It so happens that Krebs is also in possession of tens of thousands of pages of ChronoPay documents leaked in a data breach last year which allowed him to follow the trail back to ChronoPay.</p>
<p>It is unclear how that knowledge can be put to good use. Given the nature of international law enforcement, prosecuting attacks across national borders can be tricky.</p>
<p>In the meantime, Mac users should just be aware of the issue, and follow the <a href="http://support.apple.com/kb/HT4650" target="_blank">guidance from Apple </a>to address the threat pending an update for Mac OS X to guard against it.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-detail/mac-scareware-trail-leads-back-to-russian-firm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
