25th September 2017

A week in security (September 18 – September 24)

Last week, we kept you updated on our blog about the infected versions of CCleaner that were offered as downloads on the official servers. We also warned you against a fake IRS notice that delivers a customized spying tool, some of the threats currently facing gamers, and a Netflix scam that has been doing the rounds in Europe. Mac users learned how to tell if their Mac is infected and Advanced Tech Support victims learned how to apply for a (partial) refund. Elsewhere: Consumer news The pain caused by the Equifax breach was analyzed in depth by the NY Times. And just as easily Equifax was fooled again. They referred users to a parody site like phishers might have used. Luckily this time it was run by a security researcher. A new twist in ransomware was provided by “nRansomware”, a program that locks up your computer and only releases it after you send in 10 nude pictures. The rise in the number of phishing sites has been huge. Almost 1.5 million new phishing sites pop up every mon..
18th September 2017

A week in security (September 11 – September 17)

Last week, we dug into phishing campaigns done via Linkedin accounts, remediation versus prevention, issues with smart syringe pumps, and advised you to go patch against a Word 0day. We had some tips regarding identity theft protection, explored crowdsourced fraud, and explained YARA rules. Elsewhere: Consumer News Equifax UK admits: 400,000 Brits caught up in mega-breach: The UK gets caught up in the ongoing Equifax saga (Source: The Register) Another month, another malware outbreak in Google’s Play Store: More rogue apps on the Google Play store (Source: The Register) Unsecured Elasticsearch servers turned into PoS malware C&Cs: (Source: Help Net Security) ‘Your Windows Has Been Banned’ malware makes an unwelcome return: There’s always another piece of Ransomware to deal with (source: Betanews) Huge Vevo hack: Another day, another compromise for fans of video uploads everywhere (source: EDM News) Malware blamed for city’s data breach: malware and payment system problems, oh my (sou..
11th September 2017

A week in security (September 4 – September 10)

Last week, we looked into expired domain names being used for malvertising, delved into dubious Facebook apps, and checked out Chinese seminar scams. We also explained the whys and wherefores of false positives, explained what Google is doing with HTTPs, warned you away from a fake DHS email, and outlined some early information about the Equifax breach. Elsewhere: Consumer News Equifax mega-leak: The biggest story around, with updates on the initial breach coming thick and fast (Source: The Register) IoT hackers shift to the dark side: A tangled tale of hacking, and personal information scattering (Source: NewSky Security) Patch your Android device to foil Toast Overlay attacks: Overlay attacks are nothing new for Android users, and Palo Alto Networks Unit 42 researchers have found yet another way for attackers to perpetrate them. (Source: Help Net Security) How hackers could send secret commands to speech recognition systems with ultrasound: Chinese security researchers have discove..
4th September 2017

A week in security (August 28 – September 3)

Last week, we looked at what actions Kronos can perform in the final installment of a 2-part post. We also dived into Locky, again, a ransomware that just made a comeback, and found that its latest variant (as of this writing) has anti-sandboxing capabilities. This means that once Locky has determined that it’s residing in a virtual machine, it will not perform to its full functionality. Our researchers also talked about a new 419 spam, malware vaccination tricks, malvertising, and insider threats. Lastly, Senior Security Researcher Jérôme Segura uncovered a new RIG exploit kit campaign that drops the PrincessLocker ransomware via drive-by download. Mobile Menace Monday: Implications of Google Play Protect Below are notable news stories and security-related happenings from last week: Latest updates for Consumers Scammers Already Taking Advantage Of Hurricane Harvey, Registering Domains. “The Better Business Bureau said it has already seen sketchy crowdfunding efforts and expects t..
28th August 2017

A week in security (August 21 – August 27)

In our blog posts, we announced the introduction of, and explained the necessity for, real-time protection for our Mac and Android users. Also explaining what you can expect them to do for you and answering the questions that we expect to be frequently asked. We looked at 4 key steps you can take within your business to help gain trust with your employees while educating them to make more secure decisions. And in our “Explained” series we talked about user agent strings and digital forensics. Below are notable news stories and security-related happenings from last week: Latest updates for Consumers Facebook makes Safety Check a permanent feature. Facebook is acting on its promise to make Safety Check a permanent feature by rolling out a dedicated Safety Check hub that helps you find any ongoing crisis without first being prompted to declare yourself as safe. Android spyware linked to Chinese SDK forces Google to boot 500 apps. More than 500 Android mobile apps have been removed from..