26th October 2017

Please don’t buy this: smart locks

We all like buying the latest and greatest tech toy. It’s fun to get new and novel features on a product that used to be boring and predictable; a draw of the original BeBox (amongst many) was a layer of “das blinkenlights” across the front. But sometimes, the latest feature is not always the greatest feature. And sometimes, some things should not be on the Internet at all. For readers concerned with privacy, or who simply do not want to introduce additional hassle into their tech maintenance routine, we introduce the first entry in our series called “Please don’t buy this.” Today’s feature: smart locks. The cool new thing Recently, Amazon announced a new service combining a selection of smart locks, a web-connected security camera, and a network of home service providers that work in concert to allow remote access to your home. Ignoring the question of allowing third-party contractors vetted by an unpublished standard unsupervised access, lets take a look at why smart locks might not..
23rd October 2017

A week in security (October 16 – October 22)

Last week was an eventful one in security, keeping our research and intel teams on their toes. Multiple security researchers homed in on suspicious and malicious apps on Google Play, affecting thousands of Android users. A new variant of Mac malware Proton was also found in the wild, this time hijacking the Elmedia Player to create a Trojanized copy of the app on its official website. If you’re a Mac user and suspect that you might be infected, our Director of Mac and Mobile, Thomas Reed, provided helpful tips to clean up your computer. We touched on how a business can create and foster an intentional culture of security, addressed why we need such a thing, and debunked some misconceptions surrounding it. We also looked into the Bring Your Own Device (BYOD) policy, the risks associated with it, and some mitigating factors to consider. Independent security researcher Hasherezade analyzed the Magniber ransomware, which targets systems only in South Korea. She noted that this type of hi..
16th October 2017

A week in security (October 9 – October 15)

Last week on the Labs blog, we talked about GDPR as part of our series in the National Cyber Security Awareness Month (NCSAM). We also discussed a new method for phishing Apple ID passwords and the possible ramifications. We analyzed the malvertising chain due to a script that was found on popular websites like those of Equifax (!) and TransUnion. And we explained how decoy Word documents are used to deliver malware using the hyperlink feature in the OpenXML format. Malwarebytes news It was a great week for Malwarebytes since we won three awards at the 2017 Computing Security Awards: Security Company of the Year, Editors Choice, and Malware Solution of the Year. And we were chosen as the winner in the “Rising Star: Cybersecurity Solution” category of NetworkWorld Asia 2017 Readers’ Choice Awards. Our CEO, Marcin Kleczynski, was interviewed by the Huffington Post on the subject 5 things I wish someone told me before I became CEO. And the Malwarebytes Labs team presented you with the q..
9th October 2017

A week in security (October 02 – October 08)

Last week, we gave you some tips for National Cybersecurity Awareness Month, walked through an exploration of a small adware file, and explored the complicated world of the Homograph attack. Here’s what else happened in security. VB2017 Many of our team members attended VB2017 in Madrid, one of the premier yearly security conferences that brings together researchers, companies, law enforcement, and more in an effort to explore the latest security research. Here’s a collection of articles from The Register’s John Leyden, who was in attendance: Bulletproof hosts stay online by operating out of disputed backwaters: A look at how dubious hosts are retreating to places where they can continue to offer dubious services. Spy vs. spy vs. hacker vs… who is THAT? Everyone’s hacking each other: The problem of Intel gathering when everyone is muddying the waters. Hey, IoT vendors. When a paediatric nurse tells you to fix security, you definitely screwed up: The alarming world of IoT medical devi..
2nd October 2017

A week in security (September 25 – October 01)

Recently, we talked about the hacking incident at Deloitte, one of the ‘big four’ global accounting firms. It was reported that client email addresses, usernames, and passwords were exposed. This also brought to light weaknesses in their policies and lack of threat intelligence to recover leaked data. We advised Deloitte clients the following: do an inventory of email addresses used to correspond with the company, review network outbound traffic, determine what possible information might have leaked from the hack, and (more importantly) maintain security best practices to avoid repeating hacks like this from happening. Patrick Wardle, an acclaimed security researcher, found a keychain vulnerability flaw in High Sierra, Apple’s new macOS operating system. This revelation, unfortunately, spurned a lot of articles that one may deem bordering FUD (fear, uncertainty, doubt). So our resident Mac expert, Thomas Reed, set some records straight. Senior Malware Analyst Nathan Collier likened B..