Attacks/Breaches
5/30/2012
10:34 AM
Connect Directly
RSS
E-Mail
50%
50%

Flame's Big Question: What Else Is Lurking?

Stealth and scope of Flame intrigues researchers looking for other nation-state sponsored spyware and attacks.

It's big--20 times the size of Stuxnet--and it's stealthy--operating undetected for years--but the newly discovered Flame cyberespionage malware at its core is really just next-generation spyware.

This latest cyberweapon, which has the earmarks of a well-funded nation-state, further confirms suspicions that there are still attacks we can't see out there stealing information in the shadows, security experts say. Flame doesn't use the same codebase as Stuxnet or Duqu, but there are some haunting parallels: its prime target is Iran, its modular design is similar to Duqu's, and it uses the same exploits Stuxnet did. But Flame appears so far to be good old-fashioned espionage: It steals documents, takes screenshots of the victim's machine, records Skype calls, and snoops on email and instant messaging sessions.

Read the rest of this article on Dark Reading.

Hacktivist and cybercriminal threats concern IT teams most, our first Federal Government Cybersecurity Survey reveals. Here's how they're fighting back. Also in the new, all-digital Top Federal IT Threats issue of InformationWeek Government: Why federal efforts to cut IT costs don't go far enough, and how the State Department is enhancing security. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0985
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName parameter.

CVE-2014-0986
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCmd parameter.

CVE-2014-0987
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

CVE-2014-0988
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode parameter.

CVE-2014-0989
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode2 parameter.

Best of the Web
Dark Reading Radio