2nd December 2014

SSLPersonas, making the padlock obvious.

This blog post will showcase a Firefox Add-on that illustrates the SSL status of a web page in a more visually striking manner than the traditional method. A web server that uses an SSL (Secure Socket Layer) certificate will show a little padlock in the URL field on the browser visiting web pages. This padlock is the visual cue that the browser provides its users, to indicate that the website visited has an SSL certificate. This SSL certificate is used to confirm that you are visiting the actual website, and not an impostor. SSL certificates also help you avoid becoming a victim of a “Man-in-the-middle” attack. Clicking on the padlock also provides the user with additional information about the site. This information comes from a trusted 3rd party called a CA (Certificate Authority) Cindy Cohn and Trevor Timm of the EFF explain how vitally important this kind of encryption is: “Every casual Internet user, whether they know it or not, uses encryption daily. It’s the “s” in https and..
1st December 2014

The New Malwarebytes Anti-Exploit 1.05

While we’re still riding high on Malwarebytes Anti-Exploit winning the V3 Security Innovation of the year award, we are also happy to announce the general availability of the new Malwarebytes Anti-Exploit 1.05.1.1014. While with 0.10 beta we did a complete re-write of the underlying service architecture, this build is a complete re-write or refactor of the protection DLL. This refactoring greatly improves the overall stability and reduces most known conflicts with third-party applications as detailed in the Known Issues list. In addition we’ve added a whole new protection layer. The new Layer0 called “Application Hardening” now includes protections such as DEP Enforcement, Anti-HeapSpraying and BottomUp ASLR Enforcement. The other protection layers have also been improved by including ROP protection and StackPivoting 64bit mitigations in Layer1, 64bit caller mitigations for Layer2 and new application behavior mitigations for Layer3. As an example of Layer3, we’ve added a mitigation f..
10th November 2014

BrowserStack: “We did get hacked.”

BrowserStack, the cross-browser testing tool website, has not had a very good weekend. There was a compromise and a rather odd email was sent to customers. The email made a number of worrying claims regarding security, and – just to add that little extra dash of panic – was titled “BrowserStack is shutting down”: Just got this email. Someone at @browserstack is having a very bad day (and prob looking for a new job) pic.twitter.com/uL7o3WS6jy — Tom Johns (@johnsee) November 10, 2014 Things you don’t want to be Tweeting on a Monday morning: The hacker’s access was restricted solely to a list of email addresses. We’ll be back up in a few hours. Sincere apologies. — BrowserStack (@browserstack) November 10, 2014 Ouch. BrowserStack are currently investigating what happened, and we’ll have to play a waiting game to see if anything else was impacted outside of email addresses. Christopher Boyd The post BrowserStack: “We did get hacked.” appeared first on Malwarebytes Labs.
12th June 2014

Introducing Malwarebytes Anti-Exploit

I’m delighted to announce the launch of Malwarebytes Anti-Exploit, following a year of beta. We have spent the last year developing and testing the product, and I believe it is a great example of how we are always coming up with new ways to beat the bad guys. For home users, a 3MB download provides quick and easy protection against exploits and runs quietly in the background. It’s available either as a Free version, which protects against browser and Java exploits, or a Premium version, which adds protection for PDF readers, Microsoft Office, media players and also allows people to create custom shields. Malwarebytes Anti-Exploit For Business is designed to protect companies of every size, with full visibility of all endpoints through a central console which can be remotely managed. For those of you who are unfamiliar with exploits, we put together the video below. Basically, these threats abuse vulnerabilities in everyday software applications such as browsers, office documents and..
5th March 2014

New Malwarebytes Anti-Malware Mobile update

The lean, mean mobile malware eating machine you’ve all known and love is now adding PUPs to its detection. Malwarebytes Anti-Malware Mobile version 1.03 will be crushing pesky Potentially Unwanted Programs (PUPs) on your Android devices. In addition to detecting and removing malware, a scan on Malwarebytes Anti-Malware Mobile will detect PUPs so you can remove programs (including adware) that degrade or do not enhance your mobile experience. Malwarebytes Anti-Malware Mobile guards your identity and personal data on-the-go. So you and your Android smartphone or tablet are safe from malware, infected applications, and unauthorized surveillance. Wherever you are. Whenever you go. Download this new version from Google Play at http://mwb.to/MMobile and on Amazon App store here. Read a SC Magazine article about Aggressive adware and PUPs ‘increase vulnerability to malware’ on Android. The post New Malwarebytes Anti-Malware Mobile update appeared first on Malwarebytes Labs.