Vulnerabilities / Threats
12/3/2008
04:37 PM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

Black Friday Kicks Off Red-Letter Week For Phishers

Number of threats increased by 300 percent over 2007, report says

Holiday shoppers may have been out and about over the Thanksgiving weekend, but phishers apparently were hard at work.

Cyveillance today reported that it recorded some 8,298 phishing threats during Thanksgiving week, a 300 percent increase from last year. In addition, Black Friday saw attacks increase 380 percent year-over-year, while attacks on Cyber Monday rose nearly 400 percent, up from 242 in 2007 to 954 Monday. Cyveillance said it has also observed an increased use of previously unknown malware in these attacks, allowing the criminals to more easily mask their attacks.

The spike in phishing attacks, which also occurred last year, is a result of criminals capitalizing on historically lax security measures taken during long holiday weekends, Cyveillance said. Typical targets include small businesses and credit unions, which may not have around-the-clock security teams to respond to threats that occur during extended weekends. Phishing attacks have reached all-time highs in the past three months, the security company said.

"Online criminals are still targeting unsuspecting Internet users during long holiday weekends, validating a trend we first discovered in 2007," said Panos Anastassiadis, CEO of Cyveillance. "During this down economy, online criminals are undoubtedly trying to take advantage of online shoppers looking for holiday deals. The hectic nature of the holiday season, combined with a lack of structured security set the stage for criminals to take advantage of vulnerable users." Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1032
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party inf...

CVE-2012-1417
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

CVE-2012-1506
Published: 2014-09-17
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from th...

CVE-2012-1507
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index...

CVE-2012-2583
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.

Best of the Web
Dark Reading Radio
Listen Now A Grown-Up Conversation About Passwords
A Grown-Up Conversation About Passwords