Friday, November 30, 2012

Buy of the Week: Toshiba Excite 10 AT305-T16 Tablet for $353

This offer expired on 12/7/12, please check the top banner ad for active deals.

Toshiba Excite 10The AT300 (Excite 10) tablet delivers more performance, sleek durability and more essential ports and features than the average Android powered tablet, so you - quite simply - can do more.

Until December 7th, 2012, you can order a Toshiba Excite 10 AT305-T16 from Hyphenet for only $353, plus shipping!

Specifications for Toshiba Excite 10 AT305-T16 Tablet





























































MFR# PDA08U-001001
Product TypeTablet
Display10.1" TFT LED backlight Multi-Touch
1280 x 800
ProcessorNVIDIA Tegra 3 (Quad-Core)
Memory1 GB - DDR3L SDRAM
Storage16 GB
Camera5 Megapixel rear,
2 Megapixel front
Networking802.11b/g/n,
Bluetooth 3.0
FeaturesUSB host,
HDMI Port
BatteryLithium polymer (up to 10 hours)
ColorChampagne silver
Weight1.3 lbs
Operating SystemAndroid 4.0
Warranty1-Year Toshiba Warranty

Call (619) 325-0990 to order a Toshiba Excite 10 AT305-T16 Tablet today!


Buy of the Week offer valid through December 7th, 2012.

Note: Shipping and taxes apply.

Looking for something else? Check out our monthly deals or contact us to get a quote on the product you're searching for.
This offer expired on 12/7/12, please check the top banner ad for active deals.

Malicious Browser Add-on Edits Hosts File to Redirect Users to Phishing Websites

Only install add-ons from trusted sourcesIt’s no secret that browser add-ons bring us joy by increasing productivity and enhancing our overall internet experience, but not all add-ons are built with good intentions.

Cybercriminals have been known to push malicious browser add-ons that inject ads into websites or post spam on social network accounts.

More recently, Symantec researchers found that evil-doers have been spreading malicious browser add-ons that will redirect users to phishing websites whenever they type the URL of a legitimate site into their address bar.

These rogue add-ons are served from a phishing website mimicking the look & feel of a popular e-commerce website, complete with a typo-squatted domain and all.

The spoofed e-commerce website detects the user’s browser upon visit and prompts them to install the add-on for their particular browser. If the end-user chooses to install the add-on, it will modify the hosts file located in the Windows System32 directory, assigning the domain names of well-known companies to IP addresses of phishing websites.

For the uninitiated, Symantec explains that “when a user enters a website URL in the browser address bar, it checks the local DNS information, such as the hosts file, before sending a DNS query to the Internet.” That means if you type the web address for a website that’s been re-assigned using the hosts file, you’ll be directed to the phishing website instead of the legitimate one.

Fortunately Symantec says that the phishing site pushing the add-on has been taken offline, but another can easily pop-up elsewhere. Therefore, users are urged to remain vigilant and proceed with caution when installing software on their computer, even browser add-ons.

Browser Add-on Safety Tips



  • Use your browser’s built-in mechanism or visit the official add-on markets for Firefox, IE, Chrome, etc. to browse & install available add-ons.

  • Check the number of downloads, add-on rating, and user reviews for any red flags before downloading.

  • Do not download or install add-ons from unknown or untrusted sources.


[via Symantec]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Thursday, November 29, 2012

Shylock Trojan Detects & Avoids Remote Desktop Connections

Shylock Banking TrojanIf you were hoping to study the latest variant of the Shylock Trojan via remote desktop connection, you’re out of luck.

Trusteer researchers discovered that Shylock is now capable of detecting remote desktop environments, which are commonly used by security researchers to analyze malware samples.

Shylock identifies remote desktop environments by “feeding invalid data into a certain routine and then observing the error code returned.” If the error code doesn't match ones expected from a normal desktop, Shylock won’t install.

Trusteer noted that it is possible to use this method to identify other known or proprietary virtual/sandbox environments.

Shylock’s new evasion technique will make it difficult for security researchers to study the malware and antivirus vendors to update detection signatures.

Of course, it is always better for users to take a proactive approach vs. reactive when it comes to malware, especially if its financial data-stealing malware like Shylock.

Being that Shylock often infects PCs via drive-by-download attacks and phishing emails, users are urged to:

  • Keep their operating system & third-party software patched and up-to-date.

  • Avoid clicking links or downloading files attached to emails from unknown/untrusted sources.

  • Always run antivirus that runs real-time scanning.


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Wednesday, November 28, 2012

Register for the Managing the Unmanageable BYOD Webinar!









Please join the upcoming Managing the Unmanageable BYOD Webinar to learn more about the growing BYOD trend & how to manage personal devices your business.

Date: Thursday, December 13th, 2012
Time: 10:00 AM - 11:00 AM PST
Hosted by: Hyphenet & NetClarity
Cost: FREE!

In this seminar, Jason Orgill, industry expert and Director of Product Management and Business Development at NetClarity, will demonstrate:

  • What is the BYOD trend and should I allow it in my business?

  • Several risks that go along with BYOD

  • Educating your employees on BYOD Best Practices

  • BYOD made easy with NetClarity's NACwall appliances


Register for this webinar by filling out the form on the right. You will receive Webex information for the event one day before the event is held.
NetClarityRegister
Seats are limited, so act now!

[contact-form to='sales@hyphenet.com' subject='BYOD Webinar Registration'][contact-field label='Name' type='name' required='1'/][contact-field label='Email' type='email' required='1'/][contact-field label='Phone Number' type='text' required='1'/][contact-field label='Company' type='text' required='1'/][/contact-form]

 

 

Cybercriminals Setup Fake Update Pages for Chrome, Firefox & IE

Firefox - Chrome - IEDo you know how to update your web browser?

One of the nice things about Google Chrome is that it automatically updates whenever a new browser version is detected.

Aside from that, you can manually check for updates by clicking the Menu icon and selecting ‘About Chrome’. If there are any updates found, it will download them automatically and install them whenever you decide to restart your browser.

Firefox is pretty much the same, as well as Opera.

Internet Explorer is a bit different as it usually involves downloading another browser, like Firefox or Chrome. – Just kidding! Internet Explorer 9 updates are provided via Windows Updates.

And yes, knowing how to update your web browser is important.

Aside from running the risk of having a browser vulnerability exploited in a cyber-attack, there’s always the chance of you downloading malware posing as a browser update.

StopMalvertising warns that cybercriminals have launched new phishing schemes using malvertisements and fake browser update webpages in hopes of tricking you into downloading malware onto your computer.

The risk of falling for a phony browser update page is present regardless if you use Firefox, Chrome or Internet Explorer. The pages are set to detect your browser of choice & customize the content just for you:

Firefox, Chrome & IE Update Pages

Screenshot Credit: StopMalvertising


In the event that the script cannot determine which browser you’re using, Mozilla 5.1, GoogleBot 2.1 or unknown unknown.1 Service Packs are offered for download.

A VirusTotal scan of the file served in the attack, index.exe found that it is actually Trojan:Win32/Startpage.UY.

Once it infects your machine, Trojan:Win32/Startpage.UY will change your browser’s homepage. While that may seem harmless, it’s important to note that TrendMicro’s analysis of this attack found that the updated home page may “host other malicious files that can further infect [your] system.”

One of the things that set this particular batch of fake browser update pages apart from the ones we saw back in January is the fact that these new pages pose a threat to mobile users as well.

Although it does not appear that payloads targeting smartphones are served, StopMalvertising noticed JavaScript on the site that will display pop-ups and notifications asking for your mobile phone number. Providing such information to a scammer can be a costly mistake as they won't think twice about signing you up for expensive SMS services, so don't do it!

How to Avoid Falling for Fake Browser Update Phishing Schemes


So now that you know the risks, what can you do to avoid becoming a victim?

  • Always use your web browser’s built-in update mechanism or download updates from a legitimate source (like the vendor’s official website).

  • Always run antivirus software that offers real-time scanning and always scan downloaded files before opening them.

  • Remain vigilant when surfing the web and do your best to avoid suspicious links or website.


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Tuesday, November 27, 2012

Piwik.org Hacked to Serve Trojanized Version of Piwik Software

PiwikAn unknown attacker hacked the Piwik.org website on Monday morning and added a piece of malicious code into the Piwik 1.9.2 Zip file that will reportedly open a backdoor on systems it is installed on.

The Trojanized file remained available for public download for roughly eight hours until the breach was discovered and the file replaced with a clean copy by the Piwik team.

Piwik stated that their website runs on the popular WordPress platform and the hacker was able to gain partial access to the website server by exploiting a vulnerability within an unnamed WordPress plugin.

No personal or sensitive user data was said to be stolen in the breach, and the Piwik team is not aware of any security holes within the actual Piwik software.

Instructions on how to check if you downloaded an infected copy of Piwik along with the necessary steps to remove the malicious code can be found on the Piwik blog.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Monday, November 26, 2012

Malware Waits for Users Looking for Nude Photos of Beyonce

BeyonceWARNING: This threat is still active.

Her name may not have made it on the list of the Most Dangerous Celebrities to Search Online, but looking for Beyonce photos that are NSFW can still lead you to a malware infection.

GFI Labs warns that cybercriminals have setup a trap for anyone that dares to type in “beyonce nude” in Google’s search engine and click the following link:

Flickr Beyonce Nude

The link will take you to a Flickr page containing an image of an embedded video player (clever). Said image will redirect you to a third-party website that will prompt you to download an exe file before viewing the [nonexistent] video.

Nude Beyonce Video Scam PageScreenshot Credit: GFI


Don’t bother downloading whatever “video player” or browser plugin they’re pushing. There’s no video, and you definitely won’t be seeing Beyonce in her birthday suit.

You've been warned!

[via GFI]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+