Organic SEO Blog

231-922-9460 • Contact UsFree SEO Site Audit
Showing posts with label Cyber Attack. Show all posts
Showing posts with label Cyber Attack. Show all posts

Monday, December 01, 2014

SONY MOVIES LEAK ONLINE AS COMPUTER SYSTEMS REMAIN DARK

Original Story: latimes.com

If Sony Pictures employees return to work Monday after the Thanksgiving weekend without computer or email access, it will mark the beginning of the second week of blackout for the Culver City movie studio after a widespread hack.

And Sony's headaches do not appear to have lessened. Pirated copies of some Sony movies have begun to appear online on file sharing websites in the days after the attack. It is not known whether the two problems are related.

Among the titles that have popped up are the Brad Pitt World War II drama "Fury," the musical remake "Annie" and the upcoming film "Still Alice." Copies of "Mr. Turner" and "To Write Love on Her Arms" have also surfaced.

"The theft of Sony Pictures Entertainment content is a criminal matter, and we are working closely with law enforcement to address it," Sony said in a statement.

Of the Sony movies that have leaked online, "Annie" is the biggest that has not yet been released, but according to the website TorrentFreak, "Fury" (still in theaters) is by far the most popular among file-sharers.

This comes just days after the arrest in Britain of two people suspected of stealing and leaking a DVD-quality copy of Lionsgate's "The Expendables 3" before is domestic debut.

On Nov. 24, Sony Pictures workers who turned on their computers were met by an ominous message from a group calling itself GOP, or Guardians of Peace, which threatened to release "internal data" and "secrets" if its unspecified demands were not met.

Sony has declined to comment on its progress in investigating the attack since it released a statement on Nov. 25, saying, "Sony Pictures Entertainment experienced a system disruption, which we are working diligently to resolve."

Employees have been unable to use their devices and have resorted to pens, paper and fax machines to do their jobs. The company has set up Gmail addresses to use instead of its regular employee emails.

As Sony tries to get itself back online, speculation has swirled over how the attack could have happened and who is responsible.

On Friday, the website Re/code said Sony was investigating the possibility that hackers working on behalf of North Korea could be responsible.

Re/code speculated that the attack may have been in response to Sony's upcoming comedy "The Interview." Seth Rogen and James Franco play a pair behind a TV tabloid show who become part of a plot to assassinate Kim Jong-un. The movie hits theaters on Dec. 25 and is not among those that have popped up on file-sharing sites.

On Tuesday, the tech blog The Verge said it received a message from an email associated with last week's attack that claimed the group had help from Sony employees. The email could not be verified.

A thread on the website Reddit has been full of speculation, trying to piece together what happened.

According to the thread, the hacker group claimed to get ahold of troves of sensitive data, including copies of actors' passports and contract documents. However, none of that information appears to have been released, despite the group's threat to unleash data.

A person close to Sony, who asked not to be identified because of the sensitivity of the situation, said that the scale of the breach was likely limited to internal passwords, which have been changed, and general financial projections. This person also said the North Korea connection was far-fetched.

The issues at Sony could encourage companies to ramp up online security efforts, said Adam Levin, chairman of the identity management company IDT911.

"This is not an isolated incident where there was a fire in one building," Levin said. "This apparently affected their entire system. It shows how companies have to step up even more, whatever their efforts are."

Sunday, September 07, 2014

NEW CYBERATTACK ON BANKS 'VERY SOPHISTICATED'

Original Story: USAToday.com

The cyberattacks on JPMorgan Chase and at least four other institutions were "very sophisticated" and were likely state-sponsored, the chairman of the House Intelligence Committee said Thursday.

The nation's largest bank said earlier in the day that it was working with the FBI and other authorities to determine the scope of a hacking attack that hit financial institutions. It said it is not seeing unusual fraud activity. An Atlanta IP Lawyer is reviewing this case.

The other firms involved have not been identified.

Rep. Mike Rogers, R-Mich., the Intelligence Committee chairman who has been briefed on the attacks, described the intrusions on "multiple" financial institutions as "very sophisticated.''

The level of sophistication "takes a very special skill set," he said, and indicates that "clearly, either they were aided by or conducted by a state sponsor."

However, a federal law enforcement official, not authorized to comment publicly, told USA TODAY that at least four banks were hacked recently in a series of coordinated attacks that law enforcement officials believe were carried out by Russian hackers. It's unknown whether the Russian government played a role. An Atlanta data privacy lawyer is skilled in data privacy compliance issues.

"This is a very real and dangerous threat and it's only going to get worse,'' Rogers said. "We've been admiring the advanced sophistication of these actions long enough. Now, it's time to do something about it."

The Financial Times reported on its website Thursday that it interviewed people familiar with the matter who say the attacks were focused on commercial banks. Wall Street investment banks including Goldman Sachs, which have been the targets of previous attempts to steal data or disrupt services, were unaffected, the FT's story said.

However, some sensitive data was lost in the attack, Bloomberg.com said, citing unnamed security experts.

Sophisticated cyberattacks against financial institutions have become "an everyday occurrence" and are just another part of the cost of doing business today, said Alexander Southwell, a former computer crime prosecutor who is now co-chair of the information technology group at Gibson Dunn & Crutcher, a Los Angeles-based law firm.

As a result, most banks are well-prepared. "The work of cybersecurity is often like 'Whac-A-Mole,' with new threats regularly emerging, followed by efforts to stop those threats, which then leads to threats emerging in different ways," Southwell said. "This attack may simply be another round in that 'game.' "

JPMorgan suggests that customers contact the bank if they detect any suspicious activity on their accounts. All of the bank's cards have full liability protection for consumers against fraud. "As we learn more, we will contact anyone we determine may have been impacted by this," bank spokesman Michael Fusco said.

It remains unknown whether the digital intruders were financially motivated or part of an espionage campaign.

JPMorgan Chase CEO Jamie Dimon said in the firm's 2013 annual report to shareholders that it has bolstered its cyberdefenses. This year, JPMorgan Chase will spend more than $250 million and devote about 1,000 people to cybersecurity, he said. The company is also building three regional state-of-the-art cybersecurity operations centers.

"We're making good progress on these and other efforts, but cyberattacks are growing every day in strength and velocity across the globe," Dimon said. "It is going to be a continual and likely never-ending battle to stay ahead of it — and, unfortunately, not every battle will be won."

The Sunnyvale, Calif.-based data security firm reported multiple examples of a credential phishing campaign in which authentic-looking e-mails encouraged users to click a link to see a secure message from JPMorgan.

When they did, they were asked to enter their credentials. The Web page was hosted on a server in Moscow and installed a so-called Trojan-program onto their computer, allowing the attackers to compromise the user's computer.

Proofpoint identified several other active campaigns that appeared to be run by the same attackers, each of which attempted to install the same Trojan software.

Wednesday, May 28, 2014

HACKER HELPED DISRUPT 300 WEB ATTACKS, PROSECUTORS SAY

Original Story:  NYTimes.com

A prominent hacker set to be sentenced in federal court this week for breaking into numerous computer systems worldwide has provided a trove of information to the authorities, allowing them to disrupt at least 300 cyberattacks on targets that included the United States military, Congress, the federal courts, NASA and private companies, according to a newly filed government court document.

The hacker, Hector Xavier Monsegur, also helped the authorities dismantle a particularly aggressive cell of the hacking collective Anonymous, leading to the arrest of eight of its members in Europe and the United States, including Jeremy Hammond, who the Federal Bureau of Investigation said was its top “cybercriminal target,” the document said. Mr. Hammond is serving a 10-year prison term.

The court document was prepared by prosecutors who are asking a judge, Loretta A. Preska, for leniency for Mr. Monsegur because of his “extraordinary cooperation.” He is set to be sentenced on Tuesday in Federal District Court in Manhattan on hacking conspiracy and other charges that could result in a long prison term.

It has been known since 2012 that Mr. Monsegur, who was arrested in 2011, was acting as a government mole in the shadowy world of computer hacking, but the memorandum submitted to Judge Preska late on Friday reveals for the first time the extent of his assistance and what the government perceives of its value. It also offers the government’s first explanation of Mr. Monsegur’s involvement in a series of coordinated attacks on foreign websites in early 2012, though his precise role is in dispute.

The whereabouts of Mr. Monsegur have been shrouded in mystery. Since his cooperation with the authorities became known, he has been vilified online by supporters of Anonymous, of which he was a member. The memo, meanwhile, said the government became so concerned about his safety that it relocated him and some members of his family.

“Monsegur repeatedly was approached on the street and threatened or menaced about his cooperation once it became publicly known,” said the memo, which was filed by the office of Preet Bharara, the United States attorney in Manhattan.

Born in 1983, Mr. Monsegur moved to the Jacob Riis housing project on the Lower East Side of Manhattan at a young age, where he lived with his grandmother after his father and aunt were arrested for selling heroin. He became involved with hacking groups in the late 1990s, drawn, he has indicated, to the groups’ anti-government philosophies.

Mr. Monsegur’s role emerged in March 2012 when the authorities announced charges against Mr. Hammond and others. A few months later, Mr. Monsegur’s bail was revoked after he made “unauthorized online postings,” the document said without elaboration. He was jailed for about seven months, then released on bail in December 2012, and has made no further postings, it said.



The memo said that when Mr. Monsegur (who used the Internet alias Sabu) was first approached by F.B.I. agents in June 2011 and questioned about his online activities, he admitted to criminal conduct and immediately agreed to cooperate with law enforcement.

That night, he reviewed his computer files with the agents, and throughout the summer, he daily “provided, in real time, information” that allowed the government to disrupt attacks and identify “vulnerabilities in significant computer systems,” the memo said.

“Working sometimes literally around the clock,” it added, “at the direction of law enforcement, Monsegur engaged his co-conspirators in online chats that were critical to confirming their identities and whereabouts.”

His primary assistance was his cooperation against Anonymous and its splinter groups Internet Feds and LulzSec.

“He provided detailed historical information about the activities of Anonymous, contributing greatly to law enforcement’s understanding of how Anonymous operates,” the memo said.

Neither Mr. Bharara’s office nor a lawyer for Mr. Monsegur would comment about the memo.

Mr. Monsegur provided an extraordinary window on the activities of LulzSec, which he and five other members of Anonymous had created. The memo describes LulzSec as a “tightly knit group of hackers” who worked as a team with “complementary, specialized skills that enabled them to gain unauthorized access to computer systems, damage and exploit those systems, and publicize their hacking activities.”

The memo said that LulzSec had developed an “action plan to destroy evidence and disband if the group determined that any of its members had been arrested, or were out of touch,” and it credits Mr. Monsegur for agreeing so quickly to cooperate after being confronted by the bureau. Had he delayed his decision and remained offline for an extended period, the document said, “it is likely that much of the evidence regarding LulzSec’s activities would have been destroyed.”

After his arrest, Mr. Monsegur provided information that helped repair a hack of PBS’s website in which he had been a “direct participant,” and helped patch a vulnerability in the Senate’s website. He also provided information about “vulnerabilities in critical infrastructure, including at a water utility for an American city, and a foreign energy company,” the document said.

The coordinated attacks on foreign government websites in 2012 exploited a vulnerability in a popular web hosting software. The targets included Iran, Pakistan, Turkey and Brazil, according to court documents in Mr. Hammond’s case. The memo said that “at law enforcement direction,” Mr. Monsegur tried to obtain details about the software vulnerability but was unsuccessful.

“At the same time, Monsegur was able to learn of many hacks, including hacks of foreign government computer servers, committed by these targets and other hackers, enabling the government to notify the victims, wherever feasible,” the memo said.

The memo does not specify which of the foreign governments the United States alerted about the vulnerabilities.

But according to a recent prison interview with Mr. Hammond as well as logs of Internet chats between him and Mr. Monsegur, which were submitted to the court in Mr. Hammond’s case, Mr. Monsegur seemed to have played a more active role in directing some of the attacks. In the chat logs, Mr. Monsegur directed Mr. Hammond to hack numerous foreign websites, and closely monitored whether Mr. Hammond had success in gaining access to the sites.

Sarah Kunstler, a lawyer for Mr. Hammond, said on Saturday: “The government’s characterization of Sabu’s role is false. Far from protecting foreign governments, Sabu identified targets and actively facilitated the hacks of their computer systems.”

At his sentencing in November, Mr. Hammond was prohibited by Judge Preska from naming the foreign governments that Mr. Monsegur had asked him to hack. But, according to an uncensored version of a court statement by Mr. Hammond that appeared online that day, the target list included more than 2,000 Internet domains in numerous countries.

Mr. Hammond’s sentencing statement also said that Mr. Monsegur encouraged other hackers to give him data from Syrian government websites, including those of banks and ministries associated with the leadership of President Bashar al-Assad.

Tuesday, June 12, 2012

Flame Virus Scares Microsoft

Story first appeared on CNBC.

Discovery of the Flame virus that mainly affected computers in the Middle East, has prompted Microsoft Corp to strengthen the security of a Windows program that helps customers secure their PCs and update software.

The senior director of the Microsoft Security Response Center said in a blog post that the world's biggest software maker plans to boost security measures on the Windows Update software that is included with the operating system that runs the majority of the world's PCs.

Microsoft disclosed over the weekend that the hackers who built Flame exploited a flaw in Windows that allowed them to trick PCs into believing it was a legitimate piece of software from Microsoft. The software was then downloaded onto computers using the Microsoft Update feature.

News of the Flame virus surfaced a week ago when cyber security experts described it as one of the most sophisticated pieces of malicious software discovered to date. They are still investigating the virus, which they believe was released specifically to target computers in Iran and across the Middle East, similar to the Stuxnet worm that attacked Iran's nuclear program in 2010.

The security experts said Flame likely only infected several thousand computers and was targeted at entities that would be of interest to nations involved in espionage.

Microsoft said on its website on Sunday that it was releasing software to fix the bug using its Windows Update system. But security experts said machines infected with some advanced viruses may not benefit from that update because those viruses had disabled the Windows Update software.

That is partially what prompted the need to further boost the security of the Windows Update feature, they said.

If Microsoft is going to 'harden' the update feature, they must also prevent writers of malicious software from disabling the updating process on local computers.

Microsoft disclosed the plan to boost security of Windows Update late Monday on a Microsoft Security Response Center blog: http://blogs.technet.com/b/msrc/

Windows has said that it was taking the flaw in Windows seriously because the bug could be exploited by developers of less sophisticated viruses to launch more widespread attacks.


For information on website optimization or for the latest SEO News, visit the SEO Done Right blog.
For more national and worldwide Business News, visit the Peak News Room blog.
For more local and state of Michigan Business News, visit the Michigan Business News blog.
For more Health News, visit the Healthcare and Medical News blog.
For more Electronics News, visit the Electronics America blog.
For more Real Estate News, visit the Commercial and Residential Real Estate blog.
For more Law News, visit the Nation of Law blog.
For more Advertising News, visit the Advertising, Marketing and Media blog.
For more Environmental News, visit the Environmental Responsibility News blog.

LinkedIn Stocks Seem Immune to Danger

Story first appeared on CNBC.

After a day of rumors and investigations, LinkedIn has formally acknowledged that some of its users passwords have been compromised.

This is the worst privacy and security news to slam the business networking service yet.

The company apologized and encouraged “best practices” to update passwords.

This is no small deal: by some reports it impacted over six million passwords, about 4 percent of LinkedIn’s users. But still, LinkedIn’s stock has been remarkably robust. At one point today it sank about 1.2 percent, but it closed the day up 9 cents, and it’s up nearly 50 percent year-to-date. Today not a single analyst issued a note in response to the news or changed a rating or stock target.

So why is the stock immune to a hack attack?

LinkedIn’s built a strong reputation on these matters. The great efforts LinkedIn has made to stay out of the spotlight on security and privacy concerns seems to have paid off. The company hasn’t drawn the outrage and concerns that Facebook has when it comes to privacy issues. This is partly due to LinkedIn’s focus on business, rather than the personal photos and details people share on Facebook. By its very nature of enabling people to share their professional profiles, there is simply less risk.

A number of Wall Street analysts say that they do not expect this news to at all impact LinkedIn usage. Why? These hack attacks and the need to change passwords are perceived as a cost of doing business in today’s digital world. As long as no one gets hurt, as one analyst put it, it’s not a big deal.

Perhaps most interesting, today’s hacking news follows media storm over LinkedIn’s mobile app violating personal privacy by improperly downloading and sharing personal details from users calendars, including conference call dial-ins and private notes. Users complained about the mobile app, and LinkedIn responded by changing its policy—it no longer downloads or shares the notes section of appointment reminders. When this news came out, the stock barely moved—ending the day less than a percentage point.

The company plans to update its privacy policy to give users more control sometime in the next few days.  We’ll hear when LinkedIn does its next quarterly report if there’s been any impact on LinkedIn traffic. But Wall Street certainly thinks that users will take today’s news in stride; they’ll change their password and perhaps click on through to connect with the service.


For information on website optimization or for the latest SEO News, visit the SEO Done Right blog.
For more national and worldwide Business News, visit the Peak News Room blog.
For more local and state of Michigan Business News, visit the Michigan Business News blog.
For more Health News, visit the Healthcare and Medical News blog.
For more Electronics News, visit the Electronics America blog.
For more Real Estate News, visit the Commercial and Residential Real Estate blog.
For more Law News, visit the Nation of Law blog.
For more Advertising News, visit the Advertising, Marketing and Media blog.
For more Environmental News, visit the Environmental Responsibility News blog.

Thursday, June 07, 2012

LinkedIn Website Hacked

Story first appeared in USA Today.
In the latest blow to online confidence, the accounts of some users of business-networking site LinkedIn and dating site eHarmony were compromised after users' encrypted passwords were posted on the Internet.

Many of LinkedIn's 161 million members worldwide, who use the site to form professional connections, were also bombarded Wednesday by e-mail from unfamiliar parties urging them to click on links to verify e-mail addresses. LinkedIn and eHarmony join the list of several major websites, including retailer Zappos.com, that were hacked in recent months.

Wednesday's cyberattack on LinkedIn, which affects as many as 6.5 million users, came on the heels of a discovery that LinkedIn's mobile app on Apple devices tracked users' calendar events and synched them to its server without users' knowledge, a practice that could violate Apple's privacy regulations.

The encrypted password hash codes, which can be deciphered to uncover users' passwords, could give the hacker access to users' accounts once the codes are cracked, according to an IDC tech industry analyst.

Some of the passwords that were compromised correspond to LinkedIn accounts, the company confirmed in a blog post on its site Wednesday. In another post, LinkedIn urged users never change your password by following a link in an e-mail, since those links might be compromised and redirect you to the wrong place. The company also said it would send users of the affected accounts instructions on how to reset their passwords and that these instructions would be devoid of any links.

Late Wednesday, eHarmony said the passwords of a "small fraction" of its users had also been compromised. The site, which says it has more than 20 million registered online users, did not say how many had been affected. But tech news site Ars Technica said it found about 1.5 million passwords leaked online that appeared to be from eHarmony users.

It's unclear who was behind the hacking, but several tech analysts encouraged users to change passwords on the sites and create unique passwords for every social-media account. If you have the same password on multiple accounts, change them right now. If the hackers get one password and all of your passwords are the same, they're going to have access to all your information.

The LinkedIn incident underscores the importance of passing data-protection legislation and that it forecasts a shaky future for online consumerism. How many times is this going to happen before Congress finally wakes up and takes action? More people are becoming antsy about providing their personal information online, and that's not good for the future.

Saturday, October 02, 2010

Accounts Raided in Global Bank Hack

The Wall Street Journal

 
More than 100 people have been arrested or charged in the U.S. and the U.K. as part of an alleged global cybercrime ring using computer viruses to steal bank-account information and loot money from unsuspecting victims.

At least $3 million was stolen from U.S. accounts from about May of last year to this September, federal and state prosecutors said in New York Thursday as they unveiled indictments. The investigation is in its early stages and could result in law-enforcement actions in other countries, authorities said.

In an action American officials say is related, 19 people were arrested Tuesday in London as part of an investigation of a group alleged to have stolen at least £6 million, or $9.5 million, from U.K. bank accounts. Police announced a 20th arrest Thursday. Those arrested in the U.K. included men and women from Ukraine, Latvia, Estonia, Belarus and Georgia.

The U.S. investigation, in progress for over a year, has focused mostly on a network of "mules," or people recruited to open bank accounts using false names and fake passports and transfer stolen funds back to handlers in Eastern Europe, according to prosecutors.

The prosecutors alleged a scheme in which hackers used malicious computer software known as Zeus Trojan, disguised in seemingly benign email. When the email recipient clicks on a link or attachment in the email, the virus monitors the victim's computer activity to grab user names and passwords.

The hackers, according to U.S. prosecutors, would use the stolen data to move money from victims' accounts to accounts held by the mules, who would either wire it overseas or take it out in cash.

The scheme allegedly defrauded five banks and dozens of individuals and corporate defendants. Some banks were victims and some were used by the mules, authorities said.

The banks that were victimized by the scheme included units of J.P. Morgan Chase & Co., Ally Financial Inc. and PNC Financial Services Group Inc. In addition, mules used units of Bank of America Corp. and TD Bank Financial Group to open accounts into which to siphon money, according to federal court documents.

Chase and Ally declined to comment. PNC said it would defer to law enforcement. B of A said it has fully cooperated with the probe. TD Bank said it takes the matter seriously and is working with authorities.

The documents said money was typically withdrawn in amounts of around $10,000, with the mules often keeping about 8% to 10%.

Many of the mules were recruited through ads in a Russian-language newspaper or social-networking site, said Manhattan District Attorney Cyrus Vance Jr. Those charged included citizens of Russia, Moldova, Ukraine, Kazakhstan and Belarus.

"The Internet is the crime scene of the 21st Century," Mr. Vance said.

In all, more than 80 people have been charged in the U.S. by state and federal prosecutors, of whom 10 were arrested Thursday and 29 previously, though officials wouldn't specify when. Four of those charged acted as managers of the mule network, said Preet Bharara, the U.S. Attorney in Manhattan. A number of those charged are at large and believed to have left the U.S.

The federal charges include conspiracy to commit bank and wire fraud, to possess false identification documents, to commit money laundering and false use of a passport. The state charges include grand larceny and identity theft.

U.K. police said they have charged 11 individuals with conspiracy to defraud and money laundering, among other things, while nine other individuals were on bail, pending further inquiries.

The Zeus software program is one antivirus specialists became aware of several years ago. They believe it was developed by an individual or group out of Russia, said Mikko Hypponen, chief research officer at computer-security firm F-Secure Corp.

In its early form, the Zeus code would harvest data such as basic bank log-in information as users of infected computers accessed their financial accounts online, sending the information to criminals who would then either use it or sell it.

Over the past year, the code has become more sophisticated, antivirus experts say, enabling criminals to take over someone's connection with a financial institution to siphon money directly to mule accounts. By piggybacking on the legitimate user's access to an account, the virus bypasses additional password protection financial firms have put in place.

Zeus is so popular that bootleg versions have emerged on the cyber black market from a hacker known by the online handle Bishop. Zeus isn't just used to steal bank data but also log-in information to government and military sites.

There are a handful of large cybercrime operations known for their success with multimillion-dollar heists using Zeus, and the group of people arrested Thursday is part of one of those operations, said Don Jackson, who is director of threat intelligence at the information security firm SecureWorks and has provided information on Zeus operations to federal law enforcement.

"The mules they have arrested in the U.S. are affiliated with one of the largest if not the largest Zeus operations in the world," he said. "This could potentially be a major turning point in Zeus history."

Security firm M86 Security, of Orange, Calif., says that in July it identified Zeus-infected computers of customers of one U.K. bank, where $1 million was stolen. Bradley Anstis, a vice president at the security firm, said it tracked the servers to Estonia, where it found log files showing that details of about 3,000 customers at one bank had been stolen. The data included account numbers, dates of birth and other details.

"The modern high-tech bank heist, does not require a gun," said Mr. Bharara, the Manhattan U.S. attorney. "It requires only the Internet and ingenuity."

Wednesday, May 26, 2010

Nebraska Man Sentenced in Scientology Cyber Attack
Associated Press

 
A Nebraska man has been sentenced to a year in federal prison for his role in a cyber attack on the Church of Scientology's websites two years ago.

Brian Mettenbrink, of Grand Island, Neb., was also ordered Monday to pay $20,000 in restitution and serve a year on supervised release after he gets out of prison.

The cyber attack was orchestrated by an underground group that calls itself "Anonymous" and protests the Church of Scientology, accusing it of Internet censorship.

Mettenbrink admitted being a member and pleaded guilty in February to a misdemeanor charge of unauthorized access of a protected computer.

U.S. District Judge Gary Feess says the cyber attack had "a sense of hate crime."

Wednesday, December 30, 2009

Researcher: Google Wave, iPhone and Android will be Heavily Attacked in 2010
USA Today


 
From the crystal ball of  Roel Schouwenberg: Google Wave, the iPhone and Android mobile phones will come under heavy cyber attacks in 2010.

Schouwenberg, a senior malware researcher at Kaspersky Lab Americas, predicts Google Wave will grab headlines in coming months -- but not necessarily for emerging as the next killer online networking app. Instead, he says, Google Wave is likely to become a top target of cyber criminals.

"Attacks on this new Google service will no doubt follow the usual pattern," Schouwenberg soothsays. "First, the sending of spam, followed by phishing attacks, then the exploiting of vulnerabilities and the spreading of malware."

Schouwenberg also anticipates a sharp rise in attacks on the iPhone and Android mobile platforms, following the successful probe attacks of 2009. "The first malicious programs for these mobile platforms appeared in 2009, a sure sign that they have aroused the interest of cybercriminals," he says.

Android users, in particular, seem ripe for plundering. "The increasing popularity of mobile phones running the Android operating system, combined with a lack of effective checks to ensure third-party software applications are secure, will lead to a number of high-profile malware outbreaks," he says.

Schowenberg's prescient orb also tells him that  the overheated race between Google, Microsoft Bing, and Yahoo Search to incorporate Facebook and Twitter posts in search results -- in real time -- is destined to aid and abet cyber criminals' deployment of phishing scams, banking Trojans and cutting-edge intrusions. "Malware will continue to further its sophistication in 2010," he says.