On CBS MoneyWatch: Why Gift Cards Are Lousy Gifts
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matt Hines
Posted on ZDNet News: Apr 25, 2005 4:06:00 PM

Unpatched computers continue to represent the IT world's biggest security problem, keeping threats that target software vulnerabilities at the top of McAfee's latest industry analysis.

In its report covering security threats during the first quarter, McAfee's Anti-virus and Vulnerability Emergency Response Team (AVERT) said Monday that more than 1,000 new attacks aimed at software vulnerabilities emerged in the first three months of this year. The total amounts to a roughly 6 percent increase, compared with the same period last year. McAfee also noted that it received word of more than 200,000 vulnerability-oriented attacks during the first quarter.

McAfee said that while software makers have improved their ability to respond to vulnerabilities as the flaws are discovered, it found that at least 50 percent of computers connected to the Internet remain improperly protected by product updates or patches.

Vincent Gullotto, vice president of AVERT, said that malicious-code writers are finding ways to make a buck off unprotected PCs, which is driving greater numbers of vulnerability-based attacks.

"At least three of the eight-to-10 most malicious pieces of code out there were vulnerability-related with some form of (user) redirect going on, which is getting big because of that sort of attack's ability to make money," Gullotto said. "People are finding a way to gain access to control a machine, or group of machines, through a variety of ways, and to then use those computers to spam or steal."

And in addition to more traditional vulnerability hacks, through which people might try to steal items like valuable corporate data, McAfee said that criminals are getting more sophisticated with the sort of schemes they devise. In one trend particularly popular in Brazil, criminals have taken to stealing data to create fraudulent ATM cards and helping themselves to people's bank accounts.

Gullotto said the high incidence of attacks aimed at directly generating money also indicates a greater likelihood that organized crime has begun to influence the hacking community. But even script kiddies--or people simply looking to wreak havoc on the Internet--may be helping to power these attacks, he said.

"We believe the (professional hackers and script kiddies) are split even farther apart than before, but some of the really high-level people creating complicated malware code to make money may also pass or sell it to the script kiddies," Gullotto said. "We've seen that kind of thing for a time, but the money element is involved, which could help this whole process better sustain itself."

While the volume of mass-mailing viruses actively tracked by McAfee continued to decline in the first quarter, as they have over the last year, AVERT said the Bagle, Netsky and MyDoom threats were the most popular attacks reported during the first three months of 2005.

Security reports regarding adware applications also grew during the first quarter, according to the report. Of the 5 million customers using McAfee's software products, AVERT found that 1.5 million of them reported adware present on their systems, with each machine harboring an average of three different kinds of the hidden programs.

Phishing attacks, a form of online threat aimed at stealing personal data for criminal use or identity theft, continued to increase rapidly during the first quarter, the report said. According to AVERT's research, the frequency of phishing attacks is growing by 25 percent per month--evidence of a higher level of sophistication.

Reports of viruses crafted to attack mobile devices have also increased dramatically, according to AVERT. While such attacks are not yet a major threat to end users, the researchers tracked a jump in the number of malicious programs targeting smart phones and mobile phones during the first quarter, specifically those running on the Symbian operating system. In the fourth quarter of 2004, AVERT was following only five different strains of Symbian-related viruses, whereas now it is reporting on 50 versions of the threat.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 116 Talkback(s)
What do you expect?
Look at the User forums of PC sellers such as Packard Bell... There you will find hundreds, nay thousands of users asking 'Why does my computer start crashing when I upgrade to SP-II, or when I conne... (Read the rest)
Posted by: Elihion Posted on: 05/03/05 You are currently: a Guest | | Terms of Use
Of course things will improve a TON when...  BitTwiddler | 04/25/05
Things would improve even more if...  Taz_z | 04/25/05
More of the same  bill_christy@... | 04/25/05
You've got to be kidding  Taz_z | 04/25/05
Why?  Anton Philidor | 04/25/05
Well excuse me  Taz_z | 04/25/05
Alternate browser?  Anton Philidor | 04/25/05
Also, alternate firewall?  Anton Philidor | 04/25/05
Suit yourself  Taz_z | 04/25/05
Good thought  Anton Philidor | 04/25/05
I'm sorry, I didn't make myself clear ...  Taz_z | 04/25/05
you mean the link...  linuxoverwindows | 04/26/05
social engineering... and some pr0n sites  linuxoverwindows | 04/26/05
That will work perfectly for you  vandamme | 04/25/05
stop breeding...  linuxoverwindows | 04/26/05
IT ignorance  bill_christy@... | 04/25/05
edjikashun ignorance  linuxoverwindows | 04/26/05
I'm using some free protection...  artplus@... | 04/25/05
You forgot one.  jpfitz@... | 04/25/05
free products  ifrancis@... | 04/25/05
and dont forget:  linuxoverwindows | 04/26/05
xTerminator looks, nice, but . . .  CobraA1 | 04/25/05
when you say dnsbl etc...  linuxoverwindows | 04/26/05
Price gouging doesn't help!  litzton@... | 04/25/05
Free anti-virus works.  Anton Philidor | 04/25/05
Indeed  zomalaja | 04/25/05
Message has been deleted.  Jeff Spicoli | 04/25/05
Huh?  zomalaja | 04/25/05
Thought he meant the registration number.  Anton Philidor | 04/25/05
Link in an E-mail  Grook | 04/25/05
Message has been deleted.  Jeff Spicoli | 04/25/05
Ya lost me Anton  Jeff Spicoli | 04/25/05
Just stay where you are. I'll find you.  Anton Philidor | 04/25/05
Things change I suppose  Jeff Spicoli | 04/25/05
That's assuming the address given on the site...  Anton Philidor | 04/25/05
Just stay where you are. I'll find you.  j.dupont | 04/25/05
Smooth way to get along with people.  Anton Philidor | 04/25/05
or at least...  linuxoverwindows | 04/26/05
McAfee is Inaccurate  kchahal | 04/25/05
McAfee Is Inaccurate?  LCoolidge | 04/25/05
What's Spybot Immunize for?  TrustMe_z | 04/26/05
spybot  linuxoverwindows | 04/26/05
PC Vulnerabilities  jerryr_z | 04/25/05
Its the users  zomalaja | 04/25/05
RE: PC Vulnerabilities  nightshade0143 | 04/25/05
i cant think of...  linuxoverwindows | 04/26/05
I agree  zomalaja | 04/25/05
Agree  jmbiii@... | 04/25/05
Half of PC's or half of Windows PC's?  davidr69 | 04/25/05
Not Linux vs. Windows again.....  steve@... | 04/25/05
Not Linux vs. Windows  davidr69 | 04/25/05
RE: Not Linux vs. Windows again.....  nightshade0143 | 04/25/05
actually...  linuxoverwindows | 04/26/05
linux out of the box  linuxoverwindows | 04/26/05
Have you ever helped a Windows user?  Grook | 04/25/05
i have to agree with your post  Monkey_MCSE | 04/25/05
4-year-old uses Linux  davidr69 | 04/25/05
I definitely agree  Taz_z | 04/25/05
Did anybody read the "OpenBSD" part?  davidr69 | 04/25/05
Illiterate??  Grook | 04/25/05
Ford Explorer  davidr69 | 04/25/05
RE: Have you ever helped a Windows user?  nightshade0143 | 04/25/05
I Agree With Grook  phi_alpha_nu@... | 04/25/05
It's the user, not the O/S?  davidr69 | 04/25/05
Smokin' Crack?  phi_alpha_nu@... | 04/25/05
Bad analogy  davidr69 | 04/25/05
So You Do Smoke Crack  phi_alpha_nu@... | 04/25/05
dont start me up...  linuxoverwindows | 04/26/05
Just for the record  lengua99 | 04/26/05
in todays society... yes  linuxoverwindows | 04/26/05
well, users are still...  linuxoverwindows | 04/26/05
SO HELP!  s_gamgee | 04/25/05
rtfm  linuxoverwindows | 04/26/05
Have you ever helped a Windows user?  j.dupont | 04/25/05
i do both  linuxoverwindows | 04/26/05
i usually recommend people not switch to linux...  linuxoverwindows | 04/26/05
linsucks  Tommy Gun | 04/25/05
It's official: Windows users are illiterate  davidr69 | 04/25/05
LOL.. priceless..  Xunil_Sierutuf | 04/25/05
ROFLMAO!  Linux User 147560 | 04/25/05
wah...  linuxoverwindows | 04/26/05
I disagree completely  Grook | 04/25/05
RE: linsucks  nightshade0143 | 04/25/05
its a faerietale  linuxoverwindows | 04/26/05
Yep  sp1k3 | 04/25/05
Win v Lin  clockmendergb@... | 04/25/05
93% of all computers INFECTED!  Reverend MacFellow | 04/25/05
im waiting for an a/v scanner which will detect windows as a virus.  linuxoverwindows | 04/26/05
Shocker! Security company finds threats!  Chad_z | 04/25/05
9.5 Chad + Two More for the FB Ref. (nt)  tbbrickster_z | 04/25/05
In other news, burger managers extol the virtues of outsourcing  Jeff Spicoli | 04/25/05
Yes, and Microsoft wants to make it harder to get patches????  DonnieBoy | 04/25/05
DOH!!! So When Do We Get REAL News??? (nt)  tbbrickster_z | 04/25/05
Let the Unix/Linux/Apple sermons begin...  pdking77 | 04/25/05
Re: Let the Unix/Linux/Apple sermons begin...  nightshade0143 | 04/25/05
No "superiority"  davidr69 | 04/25/05
posts with no real value?  linuxoverwindows | 04/26/05
Lack of Broadband Availability a Major Factor  lcarliner@... | 04/25/05
Yes but these Companies also make a buck!  soulcircus | 04/25/05
Who's to blame  LCoolidge | 04/25/05
*yawn*  linuxoverwindows | 04/26/05
I use windows  s_gamgee | 04/25/05
Re: I use windows  nightshade0143 | 04/25/05
what do you need to compile?  linuxoverwindows | 04/26/05
Misrepresentations about products  jlw@... | 04/25/05
so do some scumware.  linuxoverwindows | 04/26/05
Vulnerability  bachware | 04/25/05
well, depends on the broadband...  linuxoverwindows | 04/26/05
Forget all those-  coffeegurrl | 04/25/05
some things arent necessarily a bad guy at the door...  linuxoverwindows | 04/26/05
Maybe Microsoft should write a Virus  Mr_Dave | 04/25/05
lol, remember blaster?  linuxoverwindows | 04/26/05
If I was an ISP  pbiss | 04/25/05
Not that easy  Bertavenger | 04/26/05
so far we have been successful  linuxoverwindows | 04/26/05
What do you expect?  Elihion | 05/03/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here