Skip to main content
Netherlands News in English

Main navigation

  • Top stories
  • Health
  • Crime
  • Politics
  • Business
  • Tech
  • Culture
  • Sports
  • Weird
  • 1-1-2
Crime
Ashkan Soltani
exploit kit
Flash
Fox-it
hackers
Java
JavaScript
malware
Mark Loman
online security
software
Surfright
Monday, 6 January 2014 - 04:33

Share this article:

Dutch online security firms discover malware infection through Yahoo!

Two Netherlands based Internet security firms reported that Yahoo's advertising servers have distributed malware to hundreds of thousands of users over the last few days. It appears Yahoo's advertising network has been attacked by malicious parties who hijacked the network.Fox IT, a Netherlands based security firm, described the problem in their blog post on Friday. 'Clients visiting yahoo.com received advertisements served by ads.yahoo.com. Some of the advertisements are malicious,' the firm reported. The Yahoo servers reportedly sent users an "exploit kit" that "exploits vulnerabilities in Java and installs a host of different malware," instead of serving ordinary ads. Yahoo-logo
Xingenious
Wikimedia commons Oftentimes such attacks are 'the result of the hacking of an existing network,' but it's also possible the malicious software was simply submitted as ordinary ads, bypassing Yahoo's system for filtering out malicious submissions, according to security researcher and Washington Post contributor, Ashkan Soltani, who alerted Fox IT to the issue. Yahoo users have been exposed to the threat since at least December 30th, with a rate of about 300,000 users per hour. An estimated 9 percent of those, 27,000 users per hour, actually get infected. That number decreased since the discovery of the infection, possibly due to efforts of the Yahoo security team. Fox IT suggests that the attack may be financially motivated and that the control over victim's computers may be sold online to other criminals. Mark Loman, another Netherlands based security researcher, has confirmed seeing the malware. His firm, Surfright, makes anti-virus software. Java programming was hailed as a way to make web sites more interactive, but has since been superseded by Flash and JavaScript. The software has become a security threat, since its security flaws have become a popular target for hackers. Security experts recommend disabling Java (not JavaScript, which is a separate program), as a precaution for browsers that still support Java, and some browser vendors are considering blocking the software altogether. 'At Yahoo, we take the safety and privacy of our users seriously,' a Yahoo spokesperson said in an email to the Washington Post, Saturday. 'We recently identified an ad designed to spread malware to some of our users. We immediately removed it and will continue to monitor and block any ads being used for this activity.'

More like this

Image
Bird Logo
Amsterdam-based Bird bids €165.8 mil. to acquire chat, payment service provider CM.com
Image
The Royal Netherlands Army is deploying hackers to the front lines as part of the newly formed 101 CEMA Battalion.
Dutch army to deploy hackers to front lines to gain battlefield advantage
Image
Hacker_-_Hacking_-_Symbol
Pro-Russian hackers disrupt Dutch government websites ahead of NATO summit
Image
Two people shaking hands after reaching a deal
Dutch investor Main Capital makes largest software acquisition in over €200 million deal
Make NL Times your top Google source

Follow us:

Latest stories

  • Heatwave: Defqon.1, TT Assen ready for 38°C days; More events cancelled
  • Hundreds of thousands of Dutch use Ozempic to lose weight; Third without prescription
  • Controversial FVD-affiliated school reopens with state funding confirmed
  • Record variable electricity prices forecast for Wednesday evening in Netherlands
  • Netherlands under code orange as record heat intensity levels recorded in Eindhoven

Top stories

  • Six arrested in electoral fraud investigation; Allegations of forgery, voter coercion
  • Hottest night on Dutch records expected tomorrow; Code Orange takes effect at noon
  • 270 children abducted to or from the Netherlands last year; Increase of over 25%
  • Public transport strike from 4 a.m. to 8 a.m.: No trains, buses, trams, metros running
  • Life sentence sought for Dutch-Rwandan man over massacre of 3,000 Tutsi in 1994 genocide

© 2012-2026, NL Times, All rights reserved.

Footer menu

  • Change Privacy Settings
  • Privacy Policy
  • Contact
  • Partner Content