24 May 2010
Security experts have called on Facebook to set up an early warning system on its network to notify users of any threats as and when they occur, after yet another malware attack hit the site over the weekend.
The attack is the second in successive Saturdays to use a 'sexy video' to lure the recipient into clicking on a fake FLV Player upgrade message which then downloads adware onto the PC.
Both files arrive as a thumbnail video in messages posted to users' walls. Last week's included the message: 'This is without doubt the sexiest video ever!: P :P :P.', while the new scam refers to 'distracting beach babes'.
"Facebook is aware of the problem and is actively removing both the wall posts and the malicious applications," wrote Websense senior research manager Patrik Runald in a blog post.
"We certainly hope that 'a new malware scam on Facebook every Saturday' won't turn into a trend."
However, Graham Cluley, senior technology consultant at Sophos, went further, complaining in a blog post that the dedicated Facebook Security page has still posted no official warnings about either of the attacks.
"Isn't it time that Facebook set up an early warning system through which they can alert their almost 500 million users about breaking threats as they happen?" he wrote.
"Imagine just how many people could have been protected if a simple message had appeared on all users' screens warning them of the outbreak."
Cluley added that the criminals behind the attacks may be launching them at weekends in an attempt to catch anti-virus researchers and Facebook's security team "snoozing".
A Facebook spokesperson responded that it is usually better to educate users with simple rules on how to keep their online accounts secure, rather than point out each individual scam.
“We work quickly to disable any bugs, or applications that contain malware, ensuring that once reported to us they have minimal impact on our users," the spokesperson added.
"We urge people to remember that if someone is posting comments, or links, or sending you messages that look weird, don’t trust it. Delete it immediately and let the person know."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Credit Risk Modeller, SAS, London, £50,000 Title- Credit...
My London client is looking for an experienced Programme...
My leading client is looking for a number of excellent...
My client, a leading international name in Manufacturing...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?