USPS-themed malspam now delivering 1-2-3 knock-out

We’ve detected an uptick in USPS-themed malspam walloping users with a 1-2-3 knock-out of nasty malware designed to infiltrate your system and steal all your most valuable information. This malware-laced email is actively being distributed with various Subject and Body messages containing references to missing and/or late USPS parcels.

Fake pharma sites are getting even more obnoxious

Recently, we have noticed that pharma sites seem to have discovered the use of JavaScript to change the “Stay or Leave” messages that you see, when you try to close or leave their sites.

Advanced phishing tactics used to steal PayPal credentials

A new example was found of a phishing mail trying to get a hold of your PayPal login credentials by using a javascript sending them to a data_receiver_url

Clipboard poisoning attacks on the Mac

Graham Cluley drew my attention the other day to an issue that has apparently been known to some for years, but was new to me: clipboard poisoning, an issue where a website can replace what you think is on your clipboard with something else. Although this seems like an insignificant issue on first glance, it turns out that there are some very serious implications.

App Update Tool Could Endanger iOS Users

Some iOS developers are integrating an update library called JSPatch, used for delivering faster updates to their apps. That’s a great idea, but unfortunately, there are some serious security concerns involved.

