WHID 2009-26: F-Secure Joins The Breached AV Vendors Club

Tagged:  
Updated: 
19 February 2009
Attack Information
WHID ID: 
2009-26
Date Occured: 
11 Feb 2009
Attack Method: 
Attack Method: 
Outcome Information
Target Information
Attacked Entity Field: 
Technology
Attacked Entity Geography: 
Finland
Source Information
Attack Source Geography: 
Romania

It wasn't surprising that after attacking a Kaspereski and a BitDefender web sites, Uno, the Romanian hacker,  would continue to strike anti-virus vendors. This time he found a vulnerability in the web site of Finish AV vendor F-Secure. Somewhat less severe than the others, the vulnerability enabled the hacker only to access virus statistics.

As usual, the marketing department response is amazing, mentioning that "the problem with its site was due to a bug in a Web application and not related to an unpatched system". Does that make it better?

Frankly, I don't envy the marketing department role. The company, any company for that matter, is spending too little on web application security, sites are taken down daily, and the marketing people are send to fend off the public. They must have a thick skin to survive in marketing.