Feeds

Tainted ads punt scareware to surfers on LSE and Myvue sites

Autotrader.co.uk, and possibly eBay.co.uk, also hit by malvertising attack

Boost IT visibility and business value

Several highly trafficked UK sites – including the website of the London Stock Exchange – served malware-tainted ads as the result of a breach of security by a third-party firm they shared in common.

Surfers visiting auto-trading site Autotrader.co.uk and the cinema site Myvue.com were also exposed to the attack, which stemmed from a breach at their common ad provider, Unanimis, rather than at any of the three sites themselves. Unconfirmed reports suggest eBay.co.uk was also affected.

The malicious ads made several concealed redirects before dropping surfers on a portal pimping rogue anti-virus (AKA scareware).

Google's malicious website detection tool was among the first security tools to flag up the breach. The security breach at the London Stock Exchange – which was separately be-devilled by system availability problems last week – was brought to wider attention by a blog post by security consultant Paul Mutton on Sunday.

Net security firm Websense confirmed the attack on Monday, saying it had been tracking the progress of the attack over recent days.

"We have been following the exploit domains in this malvertising campaign for quite a while now," said Elad Sharf of Websense Security Labs. "In addition to MyVue.com and Autotrader.com, we've also received reports that ebay.co.uk and londonstockexchange.com were also affected."

By attacking third-party ad networks rather than websites, cybercrooks can increase the potency of attacks, Sharf added. ®

Gartner critical capabilities for enterprise endpoint backup

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?