Stories by Liam Tung

Researcher finds latest Office zero-day was first used in 2009

By Liam Tung | 18 June, 2013 11:34

Attack Word documents designed to lure victims into opening them were crafted to fetch a PNG image file that contained an exploit for vulnerable versions of Office

Microsoft not sorry for swallowing researchers' work in Citadel takedown

By Liam Tung | 11 June, 2013 10:12

A quarter of the Citadel botnet’s 4,000 command and control domains that Microsoft seized last week in “operation b54” were actually being used by researchers to combat the botnet and others like it, according to a security researcher.

Google outlaws facial recognition apps on Glass for now

By Liam Tung | 03 June, 2013 10:20

Google announced late Friday that it will outlaw facial recognition and other biometric identification apps on Glass, its networked eyewear still in prototype phase that's expected to be commercially released later this year.

Symantec ditches low-cost antivirus from Australia-founded PC Tools

By Liam Tung | 27 May, 2013 11:21

Symantec has killed off its line of low-cost security products from PC Tools, a vendor it acquired in 2008 from Australian entrepreneur Simon Clausen.

Bank trojan targets users of Bitcoin exchange Mt Gox

By Liam Tung | 20 May, 2013 10:35

Brazilian hackers on the hunt for banking credentials are now targeting Bitcoin owners with a trick that sends victims to a phishing page when they enter the correct URL for Mt Gox, the online exchange that claims to account for 80 per cent of all Bitcoin trade.

Malware vendors accept Bitcoin but mules and fake IDs keep it at bay

By Liam Tung | 14 May, 2013 11:15

Malware vendors are warming to bitcoin, but the virtual currency has an unlikely rival in some geographies in the form of fake identity documents and money mules.

Attackers exploit un-patched flaw in IE 8

By Liam Tung | 06 May, 2013 11:04

Microsoft on Friday confirmed a previously unknown vulnerability in Internet Explorer 8 that is believed to have been used to target people from the nuclear energy industry.

Microsoft offers Bing malware site re-evaluation tool

By Liam Tung | 30 April, 2013 09:44

Web masters will now be able to ask Microsoft to re-evaluate sites labeled on its Bing search engine as malware threats, but if malware is found during the re-scan the warning could persist for a long time.

Oracle delays Java 8 to focus on faster security fixes for Java 7

By Liam Tung | 22 April, 2013 09:12

Oracle’s scheduled release for Java 8 this September has been pushed back to March 2014 as engineers focus on speeding up Java security fixes.

ISP fail in Spamhaus DDoS puts ‘open DNS resolvers’ on EU regulator agenda

By Liam Tung | 15 April, 2013 15:05

The cyber-attacks on an anti-spam group that rattled Europe’s internet last month could have been countered by ISPs, according to the EU’s security agency, which is taking new mitigation recommendations to operators and telecoms regulators.

Carder BadB gets 7 years for casher role in $9m RBS WorldPay heist

By Liam Tung | 08 April, 2013 11:45

Vladislav Anatolievich Horohorin, a prominent carder known as ‘BadB’ who also withdrew some of the $9m in the 2008 RBS WorldPay ATM heist, has been sentenced to 88 months prison.

Scribd hacked: as many as 1 million passwords compromised

By Liam Tung | 05 April, 2013 09:15

Hackers broke into the network of popular document sharing service Scribd earlier this week and may have compromised “less than 1 percent” of its users’ passwords, according to the company.

Sophos tells customers to apply security update for Web Protection Appliance

By Liam Tung | 04 April, 2013 14:00

Security vendor Sophos is urging customers to immediately install an update that resolves three security flaws found in its Web Protection Appliance.

North Korea attracts Anonymous threats and leaks

By Liam Tung | 03 April, 2013 16:01

Hackers claiming to be part of ‘Anonymous’ say they have stolen 15,000 passwords from Uriminzokkiri.com, a North Korea run website hosted in China.

Attacks on Spamhaus biggest ‘known’ DDoS at 300Gbps

By Liam Tung | 28 March, 2013 09:42

The ongoing traffic attack on European anti-spam group Spamhaus has escalated from 75 Gbps peak last week to 300Gbps, making it the biggest on public record, according to experts.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Splunk for Security

Use Splunk to search, alert and report in real time on any user, network, system or application activity, configuration changes, and other IT data from one place.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.