Feeds

Patch often: Cyber-crim toolkits love stinky old gaping holes

Updating software is better than relying on AV - shock finding

Secure remote control for conventional and virtual desktops

More than two in three exploits kits that attempt to inject malware into web surfers' computers were developed in Russia - and at least one in two exploit rather old vulnerabilities.

Blackhole 2.0 is the most often used hacking toolkit - installed on websites to attack and take over visitors' computers - but it targets fewer software security holes than rival cybercrime kits. That's according to a fresh report by managed security biz Solutionary.

Contrary to hype that exploit kits target unpatched flaws in products, Solutionary found the majority (58 per cent) of exploited vulnerabilities were more than two years old.

The company reviewed 26 commonly used kits and discovered code abusing security bugs dating as far back as 2004, evidence that old vulnerabilities continue to be mined for profit for cybercrooks. Criminal hackers typically compromise otherwise legitimate websites to plant hacking toolkits and distribute fake antivirus software, banking Trojans and other nasties.

Researchers at the security firm concluded that antivirus products cannot detect 67 per cent of malware being distributed, a finding that is likely to be controversial. The practical upshot is that surfers would be wise to regularly update applications - especially Adobe Flash, web browsers and the Java runtime - rather than rely on security scanners to block any attacks that come their way.

"Exploit kits largely focus on targeting end-user applications,” said Rob Kraus, a director of security research at Solutionary. “As a result, it is vital that organisations pay close attention to patch management and endpoint security controls in order to significantly decrease the likelihood of compromise."

A complete copy of Solutionary's Q4 2012 threat report can be found here (registration required). ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Managing SSL certificates with ease
The lack of operational efficiencies and compliance pitfalls associated with poor SSL certificate management, and how the right SSL certificate management tool can help.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.