News archive
30th Semi-annual report of MELANI about problems of personal data on the internet
30.04.2020 - The 30th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyberincidents of the second half of 2019 both in Switzerland and abroad. The latest report focuses on handling personal data on the internet and the problems involved.
MELANI semi-annual report: cybersecurity situation during the coronavirus
29.10.2020 - The 31st semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyberincidents of the first half of 2020 both in Switzerland and abroad. The current report focuses on the coronavirus pandemic.
Encryption Trojans still on the rise
29.10.2019 - The 29th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyberincidents of the first half of 2019 both in Switzerland and abroad. The main focus of the current report is cyberattacks with encryption Trojans, which caused considerable damage worldwide during the first half of the year.
Data leaks, crimeware and attacks on industrial control systems – topics in the MELANI semi-annual report
26.04.18 - The 26th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI), published on 26 April 2018, addresses the most important cyber incidents of the second half of 2017 both in Switzerland and abroad. Among other things, the focus is on the widespread use of crimeware and attacks on industrial control systems in the medical technology sector. The spate of data leaks and their repercussions are examined in the main topic.
For secure dealings with the internet of things
20.04.2017 - The 24th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI), published on 20 April, addresses the most important cyber incidents of the second half of 2016 both in Switzerland and abroad. The focal point of the report is the internet of things, which is becoming increasingly significant.
Handling security bugs, vulnerable infrastructure and a range of DDoS attacks: 22nd MELANI semi-annual report
28.04.2016 - In the second half of 2015, there were once again some spectacular cyber-related incidents worldwide. These were primarily DDoS attacks, phishing attacks and attacks on industrial control systems. Published today, the 22nd MELANI semi-annual report features handling security vulnerabilities as its key topic.
Warning against false emails purporting to be from the FOPH
14.03.2020 - Since Friday lunchtime (13 March 2020), cybercriminals have been exploiting public anxiety related to the coronavirus. They are attempting to spread malware using emails purporting to be from the FOPH. The Reporting and Analysis Centre for Information Assurance MELANI is therefore warning the public. Delete such emails immediately.
Microsoft discontinues support for older products: danger looming
Encryption trojans increasingly target corporate networks
09.05.2019 - Since the beginning of 2019, there is an increase of reports from SMEs and larger companies in Switzerland and abroad which have been attacked by ransomware. In some cases the attackers were able to encrypt the backup as well.
Cyberextortion: key topic in MELANI semi-annual report
The 23rd semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI), published today, highlights the main national and international cyber incidents of the first half of 2016. In its key topic, the report analyses the increased numbers of attacks using cyberextortion. The report also focuses on various data leaks.
Technical Report about the Malware used in the Cyberespionage against RUAG
23.05.16 - The Reporting and Analysis Center for Information Assurance (MELANI) was tasked by the Federal Council to produce a report about the technical findings concerning the RUAG Incident. It is targeted towards network security professionals and is meant to support those responsible for security identifying risks within their own networks, as well as implementing additional security measures.
Swiss Ransomware Awareness Day
19.05.16 - Together with partners, the Reporting and Analysis Centre for Information Assurance MELANI is organising an awareness day for ransomware today. The participants include organisations from various sectors, software manufacturers, federal offices and a range of Swiss associations and consumer protection organisations.
Beware: Ransomware continues to pose a significant security risk for SMEs
19.02.2020 - In recent weeks, MELANI / GovCERT has dealt with more than a dozen ransomware cases in which unknown perpetrators encrypted the systems of Swiss SMEs and large companies and rendered them unusable. The attackers made ransom demands of several tens of thousands of Swiss francs, in some cases even millions.
Why the internet of things (IoT) could cause a power cut
IoT devices can be misused to a large extent for cyber attacks, successful blackmail attempts (e.g. fake sextortion) as well as money transfer fraud with Office 365 access data and the main topic "Dealing with purchased risks in hardware and software". The 28th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) published on 30 April 2019 deals with the most important cyber incidents of the second half of 2018 in Switzerland and abroad.
Whoever uses the same password more than once, helps attackers
08.11.2018 - The 27th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI), published on 8 November 2018, addresses the most important cyber incidents of the first half of 2018 both in Switzerland and abroad. The key topic is dedicated to the vulnerabilities in hardware. The focus is also on targeted malware attacks, for which the name of the Spiez Laboratory was misused, as well as various data leaks and the problem of multiple use of a password.
Update Ransomware: New Procedure
30.07.2019 – During the last few weeks, Swiss companies have been targeted by a new kind of cyber-attack where the attackers were able to infiltrate the company’s network and encrypt all data with a crypto Trojan. Several well-known Swiss companies have been affected by this kind of attack.
Encryption Trojans and malicious emails in name of authorities on the rise
02.11.2017 - The 25th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI), published on 2 November 2017, addresses the most important cyber incidents of the first half of 2017 both in Switzerland and abroad. The encryption Trojans Wanna Cry and NotPetya, which made the headlines worldwide in spring 2017, are the focal point of the report.
Ransom payments finance and strengthen DDoS attack infrastructure
19.11.2015 - Extortion is currently a popular method used by cybercriminals seeking rapid financial gain. Different types of attack are used as leverage to extract money from a victim, including DDoS attacks, which disrupt the availability of websites and online services. MELANI has reported several times this year on such attacks and the associated extortion by the Armada Collective and DD4BC groups, which attracted media attention in Switzerland. MELANI strongly advises against agreeing to the blackmailers' demands.
21st MELANI semi-annual report covers key topic of website security
29.10.2015 - The 21st MELANI semi-annual report is dedicated to incidents such as espionage attacks, including those which affected Switzerland, the ever-present phishing attacks and the key topic of website security. The key topic is one of several innovations which the semi-annual report underwent.
Ten years of MELANI: a review and look at current cyber threats in 20th semi-annual report
30.04.2015 - The Reporting and Analysis Centre for Information Assurance MELANI has celebrated its tenth anniversary. Therefore, the 20th semi-annual report does not merely focus on the main events of the second half of 2014, which concerned primarily incidents of blackmail and attacks on poorly protected systems. The report published today also takes a look at the development of cybercrime over the past decade.
Sophisticated social engineering and phishing attacks tailored to Switzerland – 19th MELANI semi-annual report
23.10.2014 - In the first half of 2014, the main focus was on sophisticated attacks on companies using social engineering, phishing attacks tailored to Switzerland and the Heartbleed security vulnerability in encryption software. Published today, the 19th semi-annual report by the Reporting and Analysis Centre for Information Assurance MELANI highlights these and other incidents.
Joining forces for greater online security
11.09.2014 - Joining forces to confront cybercrime. With this in mind, Internet providers, banks and other partners have founded the Swiss Internet Security Alliance (SISA). SISA has launched a security check which allows users to verify and optimize their devices.
Blackmail using Malware is on the rise – 18th Semi Annual Report MELANI
15.04.2014 - Blackmail using malware is not only on the rise, but is becoming extremely malicious. In September 2013 the malware «Cryptolocker» was detected for the first time. It encrypts all data stored on the computer and thereby blackmails its victims to make payments. This, as well as other common incidents of customer and credit card data theft, the newest revelations surrounding the NSA, Bitcoin and tampering with industrial control systems, are the main focus of today’s publication of the MELANI Report for the second half of 2013.
DDoS attacks – massive increase in Switzerland too – 17th MELANI semi-annual report
29.10.2013 - The biggest DDoS attack in the history of the Internet, e-banking attacks using smartphone trojans and numerous targeted espionage attacks all constitute the focus of the 17th semi-annual report published today by the Reporting and Analysis Centre for Information Assurance (MELANI). MELANI also published today security recommendations for industrial control systems and content management systems.
Phishing attacks on the rise – 16th MELANI semi-annual report
02.05.2013 - Increasingly sophisticated methods of phishing to attack e-banking accounts; massive DDoS attacks on US banks; the latest on cyber conflict in the Middle East; and the information we do not know we are revealing while surfing the net: these are the focus areas of the second semi-annual report for 2012 from the Reporting and Analysis Centre for Information Assurance (MELANI), published today.
Attacks on SMEs in the spotlight – the 15th MELANI semi-annual report
18.10.2012 - The Reporting and Analysis Centre for Information Assurance (MELANI) published today its report for the first half of 2012. The main topics covered include the multiplication of data theft incidents affecting SMEs, the hampering of client communication by phishing attacks, the cyber conflict during the Arab Spring and the plans for cooperation on information security at national and international level.
MELANI newsletter – new subscription required
06.07.2012 - Dear newsletter subscriber, Thank you for your interest in the MELANI newsletter. Due to a technical change on our website, we will henceforth offer the MELANI newsletter via the central news portal of the Federal Administration (www.news.admin.ch). It is unfortunately not possible to transfer the e-mail addresses of persons who previously subscribed to the MELANI newsletter. If you continue to be interested in the MELANI newsletter, we ask you to please subscribe again on the news portal of the Federal Administration. This also gives you the opportunity to subscribe to the newsletters of other federal authorities free of charge. We apologise for the inconvenience. Instructions on how to subscribe to the new news service can be found in a detailed notice on our website www.melani.admin.ch.
Phishing e-mail in circulation – alleged tax refund from the Federal Tax Administration
04.06.2012 - The attention of the Reporting and Analysis Centre for Information Assurance (MELANI) has been drawn to the fact that phishing e-mails that are apparently from the Federal Tax Administration have been circulated since Monday, 4 June 2012. In the e-mail, recipients are given the prospect of a tax refund. Personal details and credit card information are then requested in the attached HTML form. The HTML page is based locally on the recipient's computer and does not redirect the user to a website. If the form is filled out, the data is sent to a server on which there is a PHP script – probably a mailer – that then forwards the data to the attacker.
Phishing, fraud and ransomware on the rise – 14th MELANI semi-annual report
04.05.2012 - In the second half of 2011, the Reporting and Analysis Centre for Information Assurance (MELANI) observed an increase in phishing attacks, attempted fraud and ransomware. This and other information is included in the semi-annual report published today.
Publication technical report - Attacks against certification service providers and their ramifications
01.05.2012 - The Reporting and Analysis Centre for Information Assurance MELANI publishes technical reports in the area of Information Assurance at irregular intervals. The reports will deepen actual topics related to incidents and ocurrences in the information and communication technologies (ICT) and will address the corresponding set of problems and put them in a major context. The second publication brings up the attacks against certification service providers.
Publication technical report - Current Threats on the Internet: Perpetrators, Tools, Prosecution and Incident Response
19.01.2012 - From now on the Reporting and Analysis Centre for Information Assurance MELANI will publish technical reports in the area of Information Assurance at irregular intervals. The reports will deepen actual topics related to incidents and ocurrences in the information and communication technologies (ICT) and will address the corresponding set of problems and put them in a major context.
UPDATE] Schadsoftware im Umlauf
Espionage attacks on companies are now commonplace – Thirteenth MELANI semi-annual report
31.10.2011 - In the first half of 2011, the Reporting and Analysis Centre for Information Assurance (MELANI) detected higher numbers of espionage attacks on the most diverse range of companies worldwide. The number of hacker attacks aimed at accessing sensitive data also increased. There was a massive increase in skimming cases in Switzerland. These are some of the focus areas of the latest semi-annual report, which was published today.
Increase of cyber attacks on the availability of websites and with the goal of damaging service providers - 12th MELANI semi-annual report
19.04.2011 - The primary goal of cyber attacks continues to be to deny the availability of websites or to infect them with malware. In terms of motivation, a shift from pure acts of vandalism toward acts of revenge, damage to competitors, or political goals has been noted. The computer worm Stuxnet also shows that practically any system can be attacked. These are some of the focus areas of the 12th semi-annual report of MELANI.
"Stories from the internet" for greater security in the information society
16.11.2010 - Agencies of the Confederation and cantons have published a joint publication entitled "Stories from the internet - that no-one would like to live". The comic strips illustrate dangerous situations on the web and how they can be detected and avoided. The objective is to strengthen population's security and confidence in using information and communication technologies (ICT).
Increase in espionage and data theft - Eleventh report of the Reporting and Analysis Centre for Information Assurance
02.11.2010 - In the first half of 2010, the number of cases of espionage and stolen data rose worldwide. Websites and networks were often hacked for this purpose. Hacking is also used to distribute malicious software or to pursue politically motivated goals. To find Swiss websites harmed in this way, the Reporting and Analysis Centre for Information Assurance (MELANI) has been employing a new tool since this year. MELANI can now also request the blocking of .ch domains for the purpose of combating misuse of Internet addresses.
Malware e-mails with regard to the soccer world championship expected
08.06.2010 - The full text of this message is available in German, French, and Italian.
Information theft and politically-motivated hacking in focus: Tenth report of the Reporting and Analysis Centre for Information Assurance
29.04.2010 - In its latest report, the Reporting and Analysis Centre for Information Assurance (MELANI) examines cybercriminal activities in the second half of 2009. The focus is on global information theft, politically-motivated hacking and blackmailing through the use of DDoS attacks.
Critical update for Internet Explorer
31.03.2010 - Microsoft has released an out-of-band security-update for Internet Explorer on March 30th.
UPDATE of the information: Temporary higher risk for Internet Explorer users – patch available
22.01.2010 - Microsoft has made a Patch available, which fixes a critical vulnerability recently found in Microsoft Internet Explorer. We are sorry to offer the full text in German, French, and Italian only!
Temporary higher risk for Internet Explorer users
18.01.2010 - A vulnerability in Microsoft's Internet Explorer allows an attacker to execute malicious code on a system by the visit of a bogus website alone. We are sorry to offer the full text in German, French, and Italian only!
Supervisory control and data acquisition systems increasingly in the focus of cybercriminals: ninth report of the Reporting and Analysis Centre for Information Assurance
29.10.2009 - Supervisory control and data acquisition systems for industrial facilities and utilities are increasingly being targeted by cybercriminals. Also apparent is a shift away from attacks by way of e-mail with attachments or links toward attacks by way of "drive-by" infections of websites. These are two of the main topics of the ninth semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the first half of 2009.
E-mail wave with fake virus warning in circulation
05.08.2009 - At the moment e-mails with a fake virus-warning are in circulation. These e-mails ask to download an antivirus programm from a special site. Usually this antivirus-software is free, but in this case you are only able to download the software after a subcription which requires a fee. The full text of this message is available in German, French, and Italian.
E-banking increasingly targeted by cyber criminals: eighth report of the Reporting and Analysis Centre for Information Assurance
04.05.2009 - The spread of malicious software directed at e-banking applications and phishing attacks directed at Swiss Internet service providers continue to be a huge problem in the second half of 2008. Even the use of USB sticks as a means for possible attacks and dealing with waste data which is continually growing are topics of the eighth semi-annual report 2008 of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the second half of 2008.
Update of the information: Email wave target Swiss computers with malware
30.01.2009 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
Information: Email wave target Swiss computers with malware
26.01.2009 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
Mass hacking of websites: more than 700 cases in Switzerland
24.12.2008 - The full text of this warning in German, French, and Italian only.
Information: Email wave target Swiss computers with malware
10.12.2008 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian
Information: Emails looking for financial agents for money laundering are in circulation
26.11.2008 - At the moment e-mails are in circulation with job offers enlisting the support of unknowing citizens to move assets stemming from illegal business dealings. The full text of this warning in German, French, and Italian only.
Increases in malicious code in personal computers after visiting allegedly clean internet sites: seventh report of the Reporting and Analysis Centre for Information Assurance
17.10.2008 - The increase in mass hacking of websites, developments in the area of politically-motivated hacking, the risks posed by open wireless networks and the dangers involved in using social network sites: these are the topics of the seventh semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the first half-year of 2008.
9th update of the following warning: several email waves target Swiss computers with malware
28.08.2008 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian
Fake email with death threat in circulation
05.08.2008 - A fake email with a death threat in the name of a Swiss citizien is in circulation. The email is fake, the threat is not real. The full text of this message is available in German, French, and Italian
8th update of the following warning: several email waves target Swiss computers with malware
30.07.2008 - A new wave of spam emails - this time written in french - is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian
7th update of the following warning: several email waves target Swiss computers with malware
24.07.2008 - A new wave of spam emails - this time in the name of paypal - is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
6th update of the following warning: several email waves target Swiss computers with malware
09.07.2008 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients.
5th update of the following warning: several email waves target Swiss computers with malware
02.06.2008 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
Information: Financial agents are being recruited once again for money laundering
30.05.2008 - At the moment e-mails are in circulation with job offers enlisting the support of unknowing citizens to move assets stemming from illegal business dealings. The full text of this warning in German, French, and Italian only.
4th update of the following warning: several email waves target Swiss computers with malware
22.05.2008 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
Sixth report on the current information assurance situation by the Reporting and Analysis Centre for Information Assurance
09.05.2008 - The human-computer interface as a point of attack, developments in espionage and data theft, and the threats emanating from botnets and distributed denial of service (DDoS) attacks: These are the topics discussed in the sixth semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the second half of 2007.
3rd update of the following warning: several email waves target Swiss computers with malware
11.04.2008 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
2nd update of the following warning: several email waves target Swiss computers with malware
04.04.2008 - A new wave of spam emails is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
Update of the following warning: several email waves target Swiss computers with malware
27.03.2008 - A new wave of spam emails that uses social engineering by proposing a collapse of Swiss financial institutions is a further attempt by criminals to install malware on the computers of the recipients. The full text of this message is available in German, French, and Italian.
Several Email Waves Target Swiss Computers with Malware and Recruit Mules
17.03.2008 - Since the beginning of 2008 several waves of emails have targetted Switzerland with the goal of infecting the recipients' computers with malware and recruiting intermediaries ("money mules") for illegal financial transactions. The full text of this message is available in German, French, and Italian.
About the situation in information assurance. Fifth Report of the Reporting and Analysis Centre for Information Assurance
25.10.2007 - The attacks on Swiss financial institutes with the aim of unjustified enrichment and the threat of the targeted industrial espionage via the internet are the main topics of the fifth semi-annual report of the Reporting and Analysis Centre for Information Assurance. The report assesses the situation of the first half of the year 2007 in Switzerland and is now available. We regret that we can only offer the full text in German, French, and Italian. However, the report itself is available in English.
Update of the following warning: E-Mails pretending to stem from a Swiss lawyer's office at law contain malware directed at e-banking
17.07.2007 - E-mails containing malware in the attachment masked as a bill are circulating again. Most often the spoofed sender is the Swiss law firm mentioned already in the MELANI Newsletter of July 4th 2007. The malware aims at e-banking customers. Furthermore, the malware is being sent in new versions which can not yet be recognized by all antivirus applications. We are sorry to offer the full text of this message in German, French, and Italian only.
E-Mails pretending to stem from a Swiss lawyer's office at law contain malware directed at e-banking
04.07.2007 - The e-mails circulating since Monday, allegedly sent by a lawyer in Berne, contain malware in the attachment masked as a bill. This malware is pointed at e-banking-customers. If you should have opened the attachment make sure to remove the malware completely before using e-banking again. We are sorry to offer the full text of this message in German, French, and Italian only.
Information: E-Mails with dubious job offers in circulation
08.06.2007 - During the last couple of days e-mails have occured, which promote a known mule recruiting company. These offers are posted by criminal organizations, which look for the support of unknowing citizens, to move assets stemming from illegal business dealings. People who apply and follow through such activities and offers commit a crime. We are sorry to offer the full text of this warning in German, French, and Italian only.
Electronic payment transactions in Switzerland: Hacker attacks on the increase
23.05.2007 - Targeted attacks by hackers on the accounts of private individuals and institutions who carry out their payment transactions online via PC are on the increase in Switzerland. The harmful functions also include amongst other things undesired access to e-banking accounts. This is why surfing habits are becoming increasingly important.
Information: Fourth Report of the Reporting and Analysis Centre for Information Assurance about the situation in Switzerland
30.04.2007 - Increased and more sophisticated Social Engineering, the increase in identity- and data-thefts and the newest methods of attack: These are the most important topics of the fourth semi-annual report of the Reporting and Analysis Center for Information Assurance (MELANI). The report assesses the situation of the second half of the year 2006 in Switzerland and is now available. We regret that we can only offer the full text in German, French, and Italian. However, the report itself is available in English.
Information: Reorientation of the MELANI Newsletter
05.04.2007 - Here you will be receiving in the future information on the development of information assurance as well as analyses regarding its situation in Switzerland. On the other hand, announcements concerning security vulnerabilities - the way they are already being published by various other providers - will be suspended. We regret that we can only offer the full text in German, French, and Italian.
Information: New types of money laundering for assets stemming from phishing
05.04.2007 - During the last couple of months joboffers promising easy and fast money were observed. Many of these offers are posted by criminal organizations, which look for the support of unknowing citizens, to move assets stemming from fraudulent phishing cases. Now there is an increase in new variants of this form of money laundering. These new types are more difficult to identify and could also concern small and medium-sized enterprises. We are sorry to offer the full text of this warning in German, French, and Italian only.
Information: Third MELANI semi-annual report available
16.11.2006 - The recruitment of Swiss citizens for the assistance in phishing, the targeted industrial espionage against national companies and the terror discussion in the field of the internet: That are the most important topics of the third semi-annual report of the "Reporting and Analysis Centre for Information Assurance" (MELANI). We regret that we can only offer the full text in German, French, and Italian. However, the report itself is available in English.
Information: First study on information security in swiss companies
08.11.2006 - There is hardly a company in Switzerland that has not experienced incidents related to its information or communications infrastructure. In the first study on this subject, conducted by the Center for Security Studies at ETH Zurich, 72% of the participating companies stated they had experienced at least one incident in 2005. Nevertheless, most companies have only allocated very limited financial and personal resources at their disposal for information security. We regret that we can only offer the full text in German, French, and Italian. However, the study itself is available in English.
UPDATE of the warning: Vulnerability in Microsoft Powerpoint – patch available
11.10.2006 - Microsoft has made a Patch available, which fixes the critical vulnerability recently found in Microsoft Powerpoint. We are sorry to offer the full text of this warning in German, French, and Italian only.
Warning: Temporary higher risk for Microsoft Powerpoint users
28.09.2006 - A critical vulnerability in Microsoft Powerpoint allows an attacker to execute malicious code on a computer-system. For that purpose, the attacker has to get the user to open a specially crafted Powerpoint-document. So far, Microsoft has not issued any patch. We are sorry to offer the full text of this warning in German, French, and Italian only.
Warning: Temporary higher risk for Microsoft Word users
07.09.2006 - The rumors about a critical vulnerability in the word processor Microsoft Word have been confirmed by Microsoft. It allows an attacker to execute malicious code on a computer-system. For that purpose, the attacker has to get the user to open a specially crafted Word-document. First attacks have already been watched. So far, Microsft has not issued any patch. We are sorry to offer the full text in German, French, and Italian only.
Information: Instructions on the topic of "Unintentional disclosure of sensitive data"
24.07.2006 - The unintentional disclosure of sensitive information can have serious consequences for companies, administrations and individuals as well. MELANI identifies the rules to be taken into account and provides a checklist and a practice-oriented guidance. These publications are also available in English.
UPDATE of the warning: Temporary higher risk for Microsoft Excel users – patch available
12.07.2006 - Microsoft has made a Patch available, which fixes the critical vulnerability recently found in Microsoft Excel. We are sorry to offer the full text of this warning in German, French, and Italian only.
Information: Take caution of being recruited for money laundering for assets stemming from phishing cases
30.06.2006 - During the last days and weeks job-offers promising easy and fast money have increased. Many of these offers are posted by criminal organizations, which look for the support of unknowing citizens, to move assets stemming from fraudulent phishing cases. People which apply and follow through such activities and offers commit a crime. We are sorry to offer the full text of this warning in German, French, and Italian only.
UPDATE of the warning: Temporary higher risk for Microsoft Excel users - Microsoft Security Advisory released
20.06.2006 - A critical vulnerability in Microsoft Excel allows an attacker to execute malicious code on a computer-system. For that purpose, the attacker has to get the user to open a specially crafted Excel-document. So far, Microsoft has not issued any patch. We are sorry to offer the full text of this warning in German, French, and Italian only.
Update of the warning: Temporary higher risk for Microsoft Word users - patch available
14.06.2006 - Microsoft has made a Patch available, which fixes the critical vulnerability recently found in the word processor Microsoft Word.
Information: demonstration and learning software about security settings in Internet Explorer
31.05.2006 - Using demonstration and learning software, MELANI comprehensibly explains security settings in Internet Explorer.
Warning: Temporary higher risk for Microsoft Word users
23.05.2006 - A critical vulnerability in the word processor Microsoft Word allows an attacker to execute malicious code on a computer-system. For that purpose, the attacker has to get the user to open a specially crafted Word-document. First attacks have already been watched. So far, Microsoft has not issued any patch. We are sorry to offer the full text of this warning in German, French, and Italian only.
Information: Second MELANI semi-annual report available
04.04.2006 - Targeted espionage attacks originating in China, phishing and pharming, and an extended assessment of cyberterrorism: These are the main topics of the second semi-annual report of the "Reporting and Analysis Centre for Information Assurance" (MELANI).
Information: Care should be taken when using Bluetooth
11.08.2005 - An increasing number of mobile phones and Personal Digital Assistants (PDAs) have the Bluetooth function which enables wireless communication with other appliances. However, Bluetooth can involve risks if it is not properly configured and applied.
Warning: Trojan horse spies on username and passwords - Swiss online services affected as well
18.03.2005 - A newly appeared Trojan horse spies on usernames and passwords. This variant affects Swiss online services as well. During the log-in process, keyboard strokes are being logged and transmitted to an attacker. We are sorry to offer the full text in German, French, and Italian only!
Information: Measures against Browser Hijacking
07.03.2005 - If the browser doesn't start with the expected site or if the browser opens a strange website while typing an incorrect internet address, it's probably the matter of Browser Hijacking. We are sorry to offer the full text in German, French, and Italian only!
UPDATE of the warning: New phishing-trick using Internationalized Domain Names (IDN) - Browser Update for Firefox available
25.02.2005 - A new technique of phishing - that is the gathering of login-data like user name and password - allows scammers to fake even encrypted homepages. Users knowing the risk are able to recognize the scam, though. We are sorry to offer the full text in German, French, and Italian only!
Information: Caution with the web-content of E-Mail messages
31.01.2005 - The downloading of web-contents in E-Mail messages is a possibility for spammers to verify E-Mail addresses. Hence, it is advantageous to block web-contents in E-Mails or firstly to download the headers of your E-Mail messages only and to decide afterwards which messages one wants to open or to delete immediately. We are sorry to offer the full text in German, French, and Italian only!
UPDATE of the warning: risk from unpatched security holes in Internet Explorer - patch available
12.01.2005 - Multiple known unpatched holes in Internet Explorer can cause security problems. An example exploit has shown that it is possible to save any file on a user's system. We are sorry to offer the full text in German, French, and Italian only.
Information: A router-device lowers the risk of a networking-attack
27.12.2004 - A router-device with or without firewall functionality and the possibility to assign private IP-addresses is an affordable and efficient solution for a better protection from networking attacks (worms, Trojans). We are sorry to offer the full text in German, French, and Italian only.
Information: "Google Desktop Search" may jeopardize e-banking and VPN-login security
15.12.2004 - "Google Desktop Search" and similar tools may jeopardize the security of e-banking or of logins in Virtual Private Networks (VPN) from abroad. We are sorry to offer the full text in German, French, and Italian only.
Warning: IFrame vulnerability in Internet Explorer
02.12.2004 - Today Microsoft has provided an update to remove the IFrame vulnerability in Internet Explorer 6. MELANI recommends to update your computer as soon as possible.
Information: New Phishing Technique
01.12.2004 - E-mails have appeared which on opening manipulate your computer to reveal information about, say, your bank account.