Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

11/30/2009
04:59 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Bit.ly, Sophos Partner For Malware Protection

Goal is to protect users against visiting Web pages that may contain a malware, spam or phishing threat

BOSTON " November 30, 2009 " IT security and data protection firm Sophos today announced that it has entered into an agreement with bit.ly, the world's most popular utility used to shorten, share, and track links, to assist them in protecting users against visiting webpages that may contain a malware, spam or phishing threat.

According to SophosLabs, 23,500 new infected webpages are discovered every day " four times worse than in 2007. Organizations have become increasingly concerned about the rise in malicious attacks taking place via social networking sites, as well as the risks of users revealing sensitive personal or corporate data online. See recent Sophos survey.

More than a third of social networking users report that they have been spammed via social networking sites, and more than 20 percent report that they have been the target of malware " with cybercriminals often using shortened links to disguise their attacks. View poll graphs.

"bit.ly is committed to protecting its users from spam and malware," says Andrew Cohen, general manager at bit.ly. "Services like Sophos are an important part of building trust."

bit.ly currently filters all links through several independent services to check for spam, suspected phishing scams, malware, and other objectionable content. It also enables users to preview any page by adding a "+" to the end of a bit.ly URL. Given the rapidly growing use of bit.ly on the web, and specifically on micro-blogging sites such as Facebook, Twitter, CNN, twitterfeed, there is a danger that cybercriminals could try to exploit bit.ly links in order to infect users.

bit.ly has partnered with Sophos to provide:

* Unparalleled visibility of infected websites through Sophos's combination of virus/malicious behavior detection, search engine partnerships and anti-spam honeypots, which constantly trawl the web and scan email traffic to find newly infected sites and trace them back to the malicious hosting sites.

* Behavioral scanning of the content of webpages to dynamically identify new malware; keeping Sophos one step ahead of the malware authors and their attempts to get past traditional anti-virus software by constantly modifying their malicious code.

"Web 2.0 sites allow users and communities to share links with each other faster and with greater flexibility than ever before " but hackers can also take advantage of the rapid exchange of information to spread malware and phishing threats," said Rainer Gawlick, Chief Marketing Officer at Sophos. "bit.ly is showing it is a responsible member of the internet community by looking to Sophos and other security specialists to better protect its huge user base."

About bit.ly

bit.ly is one of the largest sharing platforms on the web. bit.ly is an URL shortening, web analytics service that allows users to shorten, share and track links. It can be accessed through the bit.ly website, bookmarklets, or through an open API. By creating unique user-level and aggregate links on bit.ly, users are able to view real-time traffic, analyze location and referrer data, as well as track statistics and trends.

About Sophos

More than 100 million users in 150 countries rely on Sophos as the best protection against complex threats and data loss. Sophos is committed to providing security and data protection solutions that are simple to manage, deploy and use and that deliver the industry's lowest total cost of ownership. Sophos offers award-winning encryption, endpoint security, web, email, and network access control solutions backed by SophosLabs " a global network of threat intelligence centers. With more than two decades of experience, Sophos is regarded as a leader in security and data protection by top analyst firms and has received many industry awards.

Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
More SolarWinds Attack Details Emerge
Kelly Jackson Higgins, Executive Editor at Dark Reading,  1/12/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7343
PUBLISHED: 2021-01-18
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The product would continue to function with out-of-date detection files.
CVE-2020-28476
PUBLISHED: 2021-01-18
All versions of package tornado are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configura...
CVE-2020-28473
PUBLISHED: 2021-01-18
The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with defa...
CVE-2021-25173
PUBLISHED: 2021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).
CVE-2021-25174
PUBLISHED: 2021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart).