<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" xml:lang="en" xml:base="http://blog.commtouch.com/cafe/wp-atom.php">
	<title type="text">Commtouch Café</title>
	<subtitle type="text">Email &amp; Web Security &amp; Other Stuff</subtitle>

	<updated>2010-09-01T21:06:43Z</updated>
	<generator uri="http://wordpress.org/" version="2.9.2">WordPress</generator>

	<link rel="alternate" type="text/html" href="http://blog.commtouch.com/cafe" />
	<id>http://blog.commtouch.com/cafe/feed/atom/</id>
	

			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/CommtouchCafe" /><feedburner:info uri="commtouchcafe" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[Please wait while we infect your computer – more malicious HTML attachments]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/BTXhSDrfMOI/" />
		<id>http://blog.commtouch.com/cafe/?p=1600</id>
		<updated>2010-09-01T21:06:43Z</updated>
		<published>2010-08-30T14:01:30Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Email Security" /><category scheme="http://blog.commtouch.com/cafe" term="Bell" /><category scheme="http://blog.commtouch.com/cafe" term="Craigslist" /><category scheme="http://blog.commtouch.com/cafe" term="HTML" /><category scheme="http://blog.commtouch.com/cafe" term="malware" /><category scheme="http://blog.commtouch.com/cafe" term="NewEgg" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/email-security-news/please-wait-while-we-infect-your-computer-%e2%80%93-more-malicious-html-attachments/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/email-security-news/please-wait-while-we-infect-your-computer-%e2%80%93-more-malicious-html-attachments/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">Commtouch labs have detected large volumes of emails with malicious HTML attachments.  The emails purport to come from a range of legitimate sites including:

Bell Canada
Craigslist
NewEgg


So let’s say you read our previous blog about the rise of the malicious HTML attachments.  You open the attached HTML file in a text reader to find the malicious links [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=BTXhSDrfMOI:X9da4vf2VyI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=BTXhSDrfMOI:X9da4vf2VyI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=BTXhSDrfMOI:X9da4vf2VyI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=BTXhSDrfMOI:X9da4vf2VyI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=BTXhSDrfMOI:X9da4vf2VyI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=BTXhSDrfMOI:X9da4vf2VyI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=BTXhSDrfMOI:X9da4vf2VyI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=BTXhSDrfMOI:X9da4vf2VyI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/BTXhSDrfMOI" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/email-security-news/please-wait-while-we-infect-your-computer-%e2%80%93-more-malicious-html-attachments/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[Spammers Almost Take Our Advice about LinkedIn]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/lyMdmT6h3aw/" />
		<id>http://blog.commtouch.com/cafe/?p=1596</id>
		<updated>2010-08-24T13:51:24Z</updated>
		<published>2010-08-24T13:50:26Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Email Security" /><category scheme="http://blog.commtouch.com/cafe" term="linkedin" /><category scheme="http://blog.commtouch.com/cafe" term="spam" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/email-security-news/spammers-almost-take-our-advice-about-linkedin/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/email-security-news/spammers-almost-take-our-advice-about-linkedin/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">In February, we &amp;#8220;recommended&amp;#8221; that cybercriminals save time and money by using LinkedIn as a way to harvest email addresses and details about corporate employees. Instead, they have added LinkedIn to the pantheon of trusted brands being used to scam unaware recipients.
Thanks to the simplicity of the LinkedIn design, spammers have had an easy time [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=lyMdmT6h3aw:WeuyEHRx7mo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=lyMdmT6h3aw:WeuyEHRx7mo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=lyMdmT6h3aw:WeuyEHRx7mo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=lyMdmT6h3aw:WeuyEHRx7mo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=lyMdmT6h3aw:WeuyEHRx7mo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=lyMdmT6h3aw:WeuyEHRx7mo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=lyMdmT6h3aw:WeuyEHRx7mo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=lyMdmT6h3aw:WeuyEHRx7mo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/lyMdmT6h3aw" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/email-security-news/spammers-almost-take-our-advice-about-linkedin/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[Amazon phishing – when username and password is just not enough]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/JqKRfQasErk/" />
		<id>http://blog.commtouch.com/cafe/?p=1586</id>
		<updated>2010-08-17T17:27:04Z</updated>
		<published>2010-08-17T17:27:04Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="phishing" /><category scheme="http://blog.commtouch.com/cafe" term="Amazon" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/phishing/amazon-phishing-%e2%80%93-when-username-and-password-is-just-not-enough/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/phishing/amazon-phishing-%e2%80%93-when-username-and-password-is-just-not-enough/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">In the grand phishing universe, it’s clear that Amazon would be a target.  This particular phishing outbreak caught our eye though.  It starts with a typical “account verification” email.   Recipients must submit the required information or they will suffer the dreaded “locked account”.

Opening the attached HTML file reveals phishing for more than just a username [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=JqKRfQasErk:2pwuAdZr-_E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=JqKRfQasErk:2pwuAdZr-_E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=JqKRfQasErk:2pwuAdZr-_E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=JqKRfQasErk:2pwuAdZr-_E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=JqKRfQasErk:2pwuAdZr-_E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=JqKRfQasErk:2pwuAdZr-_E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=JqKRfQasErk:2pwuAdZr-_E:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=JqKRfQasErk:2pwuAdZr-_E:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/JqKRfQasErk" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/phishing/amazon-phishing-%e2%80%93-when-username-and-password-is-just-not-enough/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[Even Wikipedia and WordPress used for pharmacy spam]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/wdVe7sUZ7P0/" />
		<id>http://blog.commtouch.com/cafe/?p=1582</id>
		<updated>2010-08-05T14:50:56Z</updated>
		<published>2010-08-10T14:45:24Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Email Security" /><category scheme="http://blog.commtouch.com/cafe" term="spam" /><category scheme="http://blog.commtouch.com/cafe" term="Wikipedia" /><category scheme="http://blog.commtouch.com/cafe" term="Wordpress" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/email-security-news/even-wikipedia-and-wordpress-used-for-pharmacy-spam/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/email-security-news/even-wikipedia-and-wordpress-used-for-pharmacy-spam/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">Perhaps you’ve gotten used to phishing, spam and scams supposedly coming from Facebook, Apple and Google.  Now, though, even trusted brands that we thought were safe are being used in an attempt to get recipients to click the embedded URLs.  Check out the emails below, both related to “recent account opening activity”.

Wikipedia and WordPress, whose [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wdVe7sUZ7P0:w6e5VRPYemo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wdVe7sUZ7P0:w6e5VRPYemo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=wdVe7sUZ7P0:w6e5VRPYemo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wdVe7sUZ7P0:w6e5VRPYemo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=wdVe7sUZ7P0:w6e5VRPYemo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wdVe7sUZ7P0:w6e5VRPYemo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wdVe7sUZ7P0:w6e5VRPYemo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=wdVe7sUZ7P0:w6e5VRPYemo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/wdVe7sUZ7P0" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/email-security-news/even-wikipedia-and-wordpress-used-for-pharmacy-spam/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[Silly 419]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/UXV4cqQNsz8/" />
		<id>http://blog.commtouch.com/cafe/?p=1567</id>
		<updated>2010-08-04T13:48:23Z</updated>
		<published>2010-08-05T14:00:17Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Spam Favorites" /><category scheme="http://blog.commtouch.com/cafe" term="#sillyspam" /><category scheme="http://blog.commtouch.com/cafe" term="419" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/spam-favorites/silly-419/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/spam-favorites/silly-419/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">One of the advantages of following us on Twitter is that you get our #Sillyspam posts.  In their efforts to confound mail filters, spammers often need to perform all sorts of language acrobatics.  We usually feel compelled to add a comment to these amusing bits of email – and we summarize our favorites every 3 [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=UXV4cqQNsz8:k2_swwaVDmQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=UXV4cqQNsz8:k2_swwaVDmQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=UXV4cqQNsz8:k2_swwaVDmQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=UXV4cqQNsz8:k2_swwaVDmQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=UXV4cqQNsz8:k2_swwaVDmQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=UXV4cqQNsz8:k2_swwaVDmQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=UXV4cqQNsz8:k2_swwaVDmQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=UXV4cqQNsz8:k2_swwaVDmQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/UXV4cqQNsz8" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/spam-favorites/silly-419/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[Email-malware senders guide – Chapter 1]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/82eLbU-4PMo/" />
		<id>http://blog.commtouch.com/cafe/?p=1554</id>
		<updated>2010-07-26T12:07:35Z</updated>
		<published>2010-07-26T15:07:45Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Email Security" /><category scheme="http://blog.commtouch.com/cafe" term="malware" /><category scheme="http://blog.commtouch.com/cafe" term="zero-hour virus outbreak protection" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/email-security-news/email-malware-senders-guide-%e2%80%93-chapter-1/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/email-security-news/email-malware-senders-guide-%e2%80%93-chapter-1/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">Last week we saw an interesting series of emails which seemed to indicate a mid-outbreak change of tactic.  The initial series of emails all had banking and account related themes.  The emails indicated that it was necessary to open an attached document file.  The attachments were actually zipped executable Trojan downloaders.

A Virus-Total (www.virustotal.com) scan showed [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=82eLbU-4PMo:5iMxYnu2lE8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=82eLbU-4PMo:5iMxYnu2lE8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=82eLbU-4PMo:5iMxYnu2lE8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=82eLbU-4PMo:5iMxYnu2lE8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=82eLbU-4PMo:5iMxYnu2lE8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=82eLbU-4PMo:5iMxYnu2lE8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=82eLbU-4PMo:5iMxYnu2lE8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=82eLbU-4PMo:5iMxYnu2lE8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/82eLbU-4PMo" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/email-security-news/email-malware-senders-guide-%e2%80%93-chapter-1/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[Widespread fake Amazon orders lead to PDF malware]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/nYahDhzm1ac/" />
		<id>http://blog.commtouch.com/cafe/?p=1546</id>
		<updated>2010-07-22T11:15:58Z</updated>
		<published>2010-07-22T16:04:24Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Email Security" /><category scheme="http://blog.commtouch.com/cafe" term="Web Security" /><category scheme="http://blog.commtouch.com/cafe" term="Amazon" /><category scheme="http://blog.commtouch.com/cafe" term="malware" /><category scheme="http://blog.commtouch.com/cafe" term="PDF" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/email-security-news/widespread-fake-amazon-orders-lead-to-pdf-malware/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/email-security-news/widespread-fake-amazon-orders-lead-to-pdf-malware/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">Well-crafted emails mimicking Amazon order confirmations have been detected in large quantities in the past week.  The Amazon logo and “your account” button actually take image files from the Amazon website.  The email includes twelve links designed to motivate recipients to click:

More information about an Amazon Visa card
The ordered items are not shown and are [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=nYahDhzm1ac:L--kpJPZpLQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=nYahDhzm1ac:L--kpJPZpLQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=nYahDhzm1ac:L--kpJPZpLQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=nYahDhzm1ac:L--kpJPZpLQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=nYahDhzm1ac:L--kpJPZpLQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=nYahDhzm1ac:L--kpJPZpLQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=nYahDhzm1ac:L--kpJPZpLQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=nYahDhzm1ac:L--kpJPZpLQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/nYahDhzm1ac" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/email-security-news/widespread-fake-amazon-orders-lead-to-pdf-malware/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Avi Turiel</name>
					</author>
		<title type="html"><![CDATA[HTML attachments – now with malware!]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/x8T6ASc5l_o/" />
		<id>http://blog.commtouch.com/cafe/?p=1537</id>
		<updated>2010-07-20T13:42:28Z</updated>
		<published>2010-07-21T10:40:18Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Email Security" /><category scheme="http://blog.commtouch.com/cafe" term="malware" /><category scheme="http://blog.commtouch.com/cafe" term="HTML" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/email-security-news/html-attachments-%e2%80%93-now-with-malware/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/email-security-news/html-attachments-%e2%80%93-now-with-malware/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">In the last few weeks we have detected increasing usage of HTML attachments in a variety of message types – all of them attempting to install malware.  These sorts of attachments are generally not blocked by message scanning systems.  In addition they may arouse less suspicion in users than zipped attachments.
In the examples below, the [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=x8T6ASc5l_o:C3-t4ejd708:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=x8T6ASc5l_o:C3-t4ejd708:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=x8T6ASc5l_o:C3-t4ejd708:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=x8T6ASc5l_o:C3-t4ejd708:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=x8T6ASc5l_o:C3-t4ejd708:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=x8T6ASc5l_o:C3-t4ejd708:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=x8T6ASc5l_o:C3-t4ejd708:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=x8T6ASc5l_o:C3-t4ejd708:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/x8T6ASc5l_o" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/email-security-news/html-attachments-%e2%80%93-now-with-malware/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Eyal Orgil</name>
						<uri>http://www.commtouch.com</uri>
					</author>
		<title type="html"><![CDATA[Outbound spam? Survey says – Service Providers are looking for a solution]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/SOCezbNePSQ/" />
		<id>http://blog.commtouch.com/cafe/?p=1518</id>
		<updated>2010-07-07T14:37:01Z</updated>
		<published>2010-07-09T06:54:59Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Data &amp; Research" /><category scheme="http://blog.commtouch.com/cafe" term="Outbound Spam" /><category scheme="http://blog.commtouch.com/cafe" term="Research" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/data-and-research/outbound-spam-survey-says-%e2%80%93-service-providers-are-looking-for-a-solution/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/data-and-research/outbound-spam-survey-says-%e2%80%93-service-providers-are-looking-for-a-solution/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">Recently, our service provider customers have become increasingly vocal about the problem of outbound spam, the spam generated within their own networks. We recently sponsored a survey with Osterman Research asking Web hosting companies, ISPs, and email managed service providers how they manage outbound spam.
As you can see from our beautiful chart – service providers [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=SOCezbNePSQ:xNtte1BpmFU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=SOCezbNePSQ:xNtte1BpmFU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=SOCezbNePSQ:xNtte1BpmFU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=SOCezbNePSQ:xNtte1BpmFU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=SOCezbNePSQ:xNtte1BpmFU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=SOCezbNePSQ:xNtte1BpmFU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=SOCezbNePSQ:xNtte1BpmFU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=SOCezbNePSQ:xNtte1BpmFU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/SOCezbNePSQ" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/data-and-research/outbound-spam-survey-says-%e2%80%93-service-providers-are-looking-for-a-solution/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Eyal Orgil</name>
						<uri>http://www.commtouch.com</uri>
					</author>
		<title type="html"><![CDATA[Survey Says &#8211; Outbound Spam IS Your Problem]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CommtouchCafe/~3/wX4otvuzNIQ/" />
		<id>http://blog.commtouch.com/cafe/?p=1512</id>
		<updated>2010-07-07T14:35:53Z</updated>
		<published>2010-07-07T14:50:33Z</published>
		<category scheme="http://blog.commtouch.com/cafe" term="Data &amp; Research" /><category scheme="http://blog.commtouch.com/cafe" term="Outbound Spam" /><category scheme="http://blog.commtouch.com/cafe" term="Research" />		
		<link rel="replies" type="text/html" href="http://blog.commtouch.com/cafe/data-and-research/survey-says-outbound-spam-is-your-problem/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://blog.commtouch.com/cafe/data-and-research/survey-says-outbound-spam-is-your-problem/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<content type="html">Zombies, compromised accounts, and malicious users are just some of the friendly neighborhood spammers on service providers’ networks. Every piece of spam going in AND getting out is your problem, long before it becomes someone else’s.  Commtouch recently commissioned a survey by Osterman Research to determine the state of the industry with regard to outbound [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wX4otvuzNIQ:zi-ed-Y1wLM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wX4otvuzNIQ:zi-ed-Y1wLM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=wX4otvuzNIQ:zi-ed-Y1wLM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wX4otvuzNIQ:zi-ed-Y1wLM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=wX4otvuzNIQ:zi-ed-Y1wLM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wX4otvuzNIQ:zi-ed-Y1wLM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CommtouchCafe?a=wX4otvuzNIQ:zi-ed-Y1wLM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CommtouchCafe?i=wX4otvuzNIQ:zi-ed-Y1wLM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CommtouchCafe/~4/wX4otvuzNIQ" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.commtouch.com/cafe/data-and-research/survey-says-outbound-spam-is-your-problem/</feedburner:origLink></entry>
	</feed>
