Lucian ConstantinRomania Correspondent, IDG News Service

Lucian Constantin writes about information security, privacy, and data protection for the IDG News Service.

PCWorld News

International law enforcement operation disrupts Shylock banking malware

Police in eight countries worked with security vendors to seize domain names and servers used by the Trojan program

PCWorld News

Botnet brute-forces remote access to point-of-sale systems

A new malware threat scans the Internet for POS systems and tries to access them using common usernames and passwords

avg secure search blowup

Vulnerability in AVG security toolbar puts IE users at risk

Bad design decisions could have enabled malware infections, researchers from CERT/CC said.

android malware

Android bug lets apps make rogue phone calls

The flaw affects the majority of Android devices in use and could easily be exploited by malware to make premium-rate calls.

malware 0 100257425 orig

Attack on Dailymotion redirected visitors to exploits

A rogue iframe injected into the site led visitors to exploits that installed a click-fraud Trojan program, researchers from Symantec said

PCWorld News

Ruby on Rails gets patches for SQL injection vulnerabilities

The two vulnerabilities affect Rails applications that use PostgreSQL as a database system

PCWorld News

Hardcoded SSH key gives backdoor access to Cisco communications manager

Cisco released new software versions to fix the issue and patch another serious vulnerability

PCWorld News

Critical vulnerability in popular WordPress newsletter plug-in endangers many blogs

Attackers could exploit a flaw in the MailPoet Newsletters plug-in to take full control of vulnerable blogs, researchers from Sucuri said

PCWorld News

Israeli security startup firm Hexadite automates cyber incident response

The company claims its product reduces cyber incident response times by up to 95 percent

Microsoft resumes emailed security notifications days after announcing its demise

The next security notifications will go out Thursday ahead of monthly security patches

malware 0 100257425 orig 100309194 large

New malware program hooks into networking APIs to steal banking data

The Emotet malware can sniff information even from HTTPS connections, researchers from Trend Micro said.

android devil malware

Rare text message worm targets Android devices

The new Selfmite Android malware spreads by sending text messages with a malicious link to the device owner's contacts

PCWorld News

VMware catches up with some Apache Struts patches

The company updates the version of Struts included in its vCenter Operations Management Suite product.

PCWorld News

Researchers bypass PayPal's two-factor authentication system

An API and mobile app loophole allowed access to 2FA-enabled accounts with only a user name and password, researchers from Duo Security said

PCWorld News

Fewer NTP servers can be abused to amplify DDoS attacks, but threat remains

Despite visible progress 2,000 servers with large amplification factors remain, a security vendor reports