Alleged “Likejackers” agree to root out Facebook spam

Adscend Media LLC also pays $100,000 in attorneys’ fees to state

SEATTLE – The owners of a California-based online marketing company have agreed to stop spamming Facebook users. The details were revealed today in a settlement – a consent decree – between Adscend Media LLC and the Washington State Attorney General’s Office.

“Today’s settlement puts a stop to Adscend’s ‘likejacking’ and other misleading tactics that led Facebook users to fork over personal information or buy subscription services from sites that appeared to be recommended by friends,” said Washington State Attorney General Rob McKenna.

In January, McKenna’s office and Facebook sued Jeremy Bash and Fehzan Ali, the owners of Adscend Media LLC for initiating posts to Facebook pages that appeared to offer visitors an opportunity to view scandalous or provocative content. However, before being able to view the content, a series of required steps lured Facebook users into eventually visiting commercial websites. Other tactics included “likejacking,” in which Facebook users were tricked into clicking the “like” button, inadvertently spreading the sales pitches to friends.

Adscend, hired to promote products, in turn does business with “affiliates” who create attention-getting marketing messages. Too often, according to the Attorney General’s Office, those messages amounted to social media spam.

http://www.atg.wa.gov/pressrelease.aspx?&id=29716

http://nakedsecurity.sophos.com/2012/05/08/facebook-clickjacking/

Tags: -

{ 0 comments }

The Microsoft Security Response Center (MSRC)

Today we’re releasing our advance notification for the May security bulletin release, which is scheduled for Tuesday, May 8. This month’s release includes 7 bulletins addressing 23 vulnerabilities in Microsoft Windows, Office, Silverlight, and .NET Framework. All 7 bulletins will be released on Tuesday, May 8 at approximately 10 a.m. PDT. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.

As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.

http://technet.microsoft.com/en-us/security/bulletin/ms12-may

Tags:

{ 0 comments }

Thunderbird 12.0.1 released

by certifiedbug on May 2, 2012

in Software

Fix various issues relating to new mail notifications and filtering on POP3 based accounts
Fixes an occasional startup crash seen in TB 12.0
Fixes an issue with corrrupted message bodies when using movemail

http://www.mozilla.org/en-US/thunderbird/12.0.1/releasenotes/

If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu.

Or download: http://www.mozilla.org/en-US/thunderbird/all.html

Tags:

{ 0 comments }

Firefox ShowIP add-on privacy concerns

by certifiedbug on May 1, 2012

in Internet Security

Sophos

A popular Firefox add-on appears to have started leaking private information about every website that users visit to a third-party server, including sensitive data which could identify individuals or reduce their security.

Naked Security reader Rob Sanders alerted us to the activities of the recently updated ShowIP add-on for the Firefox browser.

Currently over 170,000 people are said to be using ShowIP.

What the add-on’s description doesn’t say is that since version 1.3 (released on April 19th 2012) it has also sent – unencrypted – the full URL of sites visited using HTTPS, and sites viewed in Private Browsing mode, to a site called ip2info.org.

The user never realises that the data has been shared with a third-party, unless they use special tools to monitor what data is being sent from their computer.

http://nakedsecurity.sophos.com/2012/05/01/privacy-concern-showip-firefox-add-on/

Tags: --

{ 0 comments }

Microsoft Security Intelligence Report Volume 12 Released

April 25, 2012

Microsoft Security Blog Today we released the latest volume of the Microsoft Security Intelligence Report (SIR) containing a large body of new data and analysis on the threat landscape. This volume of the SIR includes:Latest industry vulnerability disclosure trends and analysis Latest industry vulnerability disclosure trends and analysis Latest data and analysis of global vulnerability [...]

Read the full article →

Firefox 12.0 released

April 25, 2012

Fixed in Firefox version 12. MFSA 2012-33 Potential site identity spoofing when loading RSS and Atom feeds MFSA 2012-32 HTTP Redirections and remote content can be read by javascript errors MFSA 2012-31 Off-by-one error in OpenType Sanitizer MFSA 2012-30 Crash with WebGL content using textImage2D MFSA 2012-29 Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues MFSA 2012-28 [...]

Read the full article →

Sabpab Mac OS X backdoor Trojan

April 13, 2012

Graham Cluley Sophos “The Sabpab Trojan horse exploits the same drive-by Java vulnerability used to create the Flashback botnet.” http://nakedsecurity.sophos.com/2012/04/13/sabpab-new-mac-os-x-backdoor-trojan-horse-discovered/ http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx Tags: Apple-Botnet-Malware-Trojan

Read the full article →

Researchers Estimate 600,000 Macs infected by Flashback Trojan

April 10, 2012

Apple 8 views… http://support.apple.com/kb/HT5244 Forbes 4/06/2012 For anyone who doubted that Apple’s long grace period with cybercriminals is over, doubt no more: On Friday, researchers at Russian antivirus firm Kaspersky confirmed findings from another security firm earlier this week that more than 600,000 computers running Mac’s OSX are infected with the Flashback botnet, and half [...]

Read the full article →

Microsoft Security Bulletin Summary for April 2012

April 5, 2012

The Microsoft Security Response Center (MSRC) Today we’re releasing our advance notification for the April security bulletin release, which is scheduled for Tuesday, April 10. This month’s release includes 6 bulletins addressing 11 vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Forefront UAG, and .NET Framework. All 6 bulletins will be released on Tuesday, April [...]

Read the full article →

MasterCard and VISA Warn of Processor Breach

March 30, 2012

Krebs on Security VISA and MasterCard are alerting banks across the country about a recent major breach at a U.S.-based credit card processor. Sources in the financial sector are calling the breach “massive,” and say it may involve more than 10 million compromised card numbers. http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/ Tags: CreditCard-Fraud

Read the full article →