CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

Survey finds Trojan-based attacks biggest threat to online banking

A survey released this week found that more than 50% of financial services professionals consider banking Trojans such as Zeus to be the greatest threat to online banking today. Typically aimed at stripping business accounts of assets, the malware attacks steal from legitimate accounts and transfer funds to fraudsters’ own accounts or money mules.

69% of respondents said their organizations have seen an increase in Zeus-style attacks against customer accounts over the past year. The report noted that these types of attacks hit online banking services that 1-in-3 respondents said are either “extremely” or “very” vulnerable to attacks — online Automated Clearing House (ACH) and wire transfers. ( Read More… )

Please use the comment form and leave your thoughts!

Top Endpoint Security Stories for November 2010 — If malware is a top security concern, then why does it take so long to fix known vulnerabilities?

In a world where cyber criminals are working around the clock, it’s interesting how long it can take publicly known vulnerabilities to get fixed. That question was (sort of) answered in November. Other industry surveys in November brought to light the impact identity theft is having on healthcare organizations, and the biggest IT security concerns for small businesses. Here are some of the top endpoint stories for November 2010. ( Read More… )

Please use the comment form and leave your thoughts!

A clean sweep: Bouncer helps defeat all of SC Magazine’s “Top 5 Threats” of 2010

December is a time for lists. There’s holiday wish lists, year-in-review lists, and so on.

This week, SC Magazine published its list of top security topics and stories for 2010. Among the various lists the staff compiled for the article, “IT security: The year in lists,” was the year’s “Top Five Threats”. What’s interesting is that this particular list is a mirror-image of what we’ve been blogging about all year — and that all five are threats that CoreTrace’s Bouncer application whitelisting solution help thwart.

Starting in January, we’ve written specific blogs on four of the top five threats mentioned. And the one that we haven’t blogged on, we know Bouncer can help defeat. Here is the recap:

Please use the comment form and leave your thoughts!

Godzilla versus King Kong, bot style? Zeus versus Ares… (and why neither wants to face Bouncer)

Over the past few years, the Zeus virus has infected millions of financial systems worldwide, capturing account credentials that cybercriminals use to gain access to corporate networks and steal sensitive data. While there have been competitive programs designed to dethrone Zeus and remove the widespread malware from infected systems, a newly announced malicious software is threatening to one-up the infamous do-it-yourself banking Trojan. ( Read More… )

Most recent comment:   A clean sweep: Bouncer helps defeat all of SC Magazine’s “Top 5 Threats” of 2010

[...] modus operandi to amass a mighty botnet. While we haven’t blogged on this specifically, much like Zeus and the ...

Once again, we agree with McAfee… to a point

I recently came across an interesting article that struck a cord with me on many different levels. In the story, “McAfee CEO stresses mobility at T.O. event,” I once again agree with a number of points Dave DeWalt made at a partner summit in Toronto, with one big exception.

First, I couldn’t agree more with his general outlook:

  • Mobile devices are the wave of the future
  • Microsoft is not going to be the end-all, be-all dominant player in the corporate environment
  • Whitelisting and blacklisting in combination is the way the security world is going
  • Blacklisting is moving to the cloud rather than directly on every single device ( Read More… )

Most recent comment:   Greg Newman

Well of course he has to propogate myth. The idea of whitelisting products that actually work in a Windows environment ...