您现在的位置: 方向标英语网 >> 英语学习方法 >> 英语阅读 >> 文章正文
英语搜索:
 
 最新英语            more>>
 推荐英语            more>>
 热门英语            more>>

World Cup 2010:the unforeseen security risks

作者:stephen    文章来源:fsteurope    点击数:    更新时间:2010-6-13 【我来说两句

1.jpg

Huge unanticipated security risks are posed to companies by cyber criminals who have taken full advantage of the upcoming World Cup, via targeted malicious PDFs/malware serving campaigns, blackhat SEO and fraudulent propositions, as well as fake lottery winning notifications and letters of claim-themed scams, and these security risks are likely to increase once the event gets underway.

According to Dancho Danchev, an independent security consultant and cyber threats analyst, Symantec researchers have discovered a continuing targeted malware campaign which is using the World Cup as a smokescreen in order to persuade end users to open malicious PDF files. The campaign is capitalising on a patched flaw within Adobe Flash Player; a vulnerability which was found last week.

A spokesperson for Adobe said: "We are in the process of finalising a fix for the issue" but the company admitted that "the vulnerability is being actively exploited in the wild."

"It doesn't really get any worse than a 'zero-day' vulnerability like this," said Graham Cluley, senior technology consultant at Sophos, a security software company.

Targeted malicious attacks are, arguably, the most damaging type of Internet threat and, according to Dan Bleaken, the Malware Data Analyst for Symantec, these attacks "are designed to target a specific individual or organisation."

Attackers have used the appeal of the World Cup in order to entice people working within companies and, if an employer/employee opens the PDF, the resulting security risks can be endless. It has also been noted that two thirds of the attacks are being directed at the highest levels of corporations and the government, due to the fact that those in the most senior positions have access to the most valuable and sensitive data.

"The aim" said Mr. Bleaken "is to extract sensitive or valuable information, which could then be used to gain competitive advantage, blackmail, harm reputation, gather intelligence, spy, steal secrets/designs/ideas, and so on."

Fraudulent World Cup emails

The World Cup has provided attackers with newsworthy and exciting bait and they have been tailoring emails and attachments to sound official. By placing certain legitimate details within the emails, the attackers make it more likely for people within an organisation to open the documents and, as a consequence have their network compromised.

An example of one such cyber crime that revealed the potentially enormous security risks that can be posed by cyber attacks was seen in the form of fraudulent emails and documents being sent under the banner of Greenlife Africa, a safari company based in South Africa.

Cyber criminals downloaded a PDF document from Greenlife concerning details of World Cup safaris and altered it by including malicious code into its content. The fraudulent PDF was sent to numerous targets across the globe, including "a user in a major international organisation that brings together governments from all over the world" claimed Symantec.

 

[1] [2] 下一页

已有很多网友发表了看法,点击参与讨论】【对英语不懂,点击提问】【英语论坛】【返回首页

  • 上一篇文章:
  • 下一篇文章:
  •  英语图片文章                                          more>>