Date: 01-08-2008
Facebook has notified its users that a widget known as Secret Crush that serves up adware from Zango violates its terms of service. The widget, identified by the Fortinet Global Security Research Team, prompts users to check the profile of one of their friends who ''might'' have a crush on them. Curious to know more about this secret admirer, users take a series of steps that ultimately infects them with the Zango adware/spyware, which monitors web browsing and then initiates targeted pop-up windows. However, Zango denied affiliation with the Secret Crush widget. ''A thorough investigation by Zango security personnel reveals no silent or surreptitious installation of any software, much less any ''spyware,'' by or in connection with the Secret Crush widget,'' claimed Zango in its blog. As of the first report, the widget has already been used by 3% of the Facebook community, which accounts to more than 1 million users. Facebook prohibits developers of widgets accessed on their site to include adware or spyware in their products.