Taken from https://blog.avast.com/topic/security-news/rss.xml

15th June 2018

Major Microsoft fixes and risky Android devices | Avast

Microsoft fixes 50 flaws for Windows, Adobe, Spectre, and more Microsoft packed a lot into its Patch Tuesday updates this week, providing 50 fixes for vulnerabilities covering everything from the Windows OS, Internet Explorer, and Microsoft Office to Microsoft Edge and ChakraCore JavaScript. The full list of patches includes fixes for eight recently-discovered Spectre flaws, which allow for Speculative Store Bypass, a trick thieves can use to steal info through websites. Also included in the massive patch is a Flash Player update that fixes an Adobe zero-day vulnerability patched out-of-band last week, as well as three other Adobe bugs.
14th June 2018

How to fight sophisticated cybercrime | Avast

As all the pieces of our cyberworld — personal laptops, business desktops, smartphones, digital assistants, TVs, appliances — grow more connected, they also make us more vulnerable to cyberattacks. Both on the individual and corporate levels, cyberattacks have become big business, which in turn has made cybersecurity big business as well. The research firm Gartner estimates that $96 billion will be spent on global information security in 2018, an 8% increase from 2017.
8th June 2018

Travel site phishing scam and genealogy site data breach | Avast

Booking.com users get phished Some unfortunate travelers had their thirst for adventure rewarded with a steaming mug of scam. Users of the popular travel-booking site booking.com received bogus texts directing them to change their passwords “due to a security breach.” A malicious link in the text, if clicked, gave the phishers access to that user’s bookings. A second text then capitalized on the booking data by demanding bank info to “process payment” for the user’s specific trip. Booking.com is part of the hospitality magnate that includes priceline.com, kayak.com, and opentable.com. A spokesperson for the site states their system was not compromised, pointing to select hotel partners as the attack victims. The company claims all impacted guests have been notified and that any damages will be compensated.
1st June 2018

Routers at risk, Canadian chaos, and a Hidden Cobra | Avast

FBI advises Americans to reset their routers Last week, we reported how the FBI had seized a key domain to the botnet VPNFilter. That story continued yesterday when the Bureau publicly asked all US residents to reboot their routers. The advice comes with the knowledge that while VPNFilter can take control of a router, part of the malware can be easily kicked off the system with a simple reboot — turning the device off for a moment. This renders the malicious program harmless, though the router can be reinfected. To prevent that, users are also advised to make sure the router’s security is fully up to date and the password has been changed from the default to a suitably complex one. The malware attacks many kinds of routers, most notably Linksys, MikroTik, Netgear, and TP-Link. Each of those companies have posted further detailed instructions to combat VPNFilter on their websites.
25th May 2018

5 malware attacks making the news | Avast

BMWs at risk of hacking BMW is in the process of issuing security patches to drivers of its 2017 i3, 2016 X1 and 525Li, and 2012 730Li. The patches will cover fourteen newly-discovered vulnerabilities, four of which can be triggered only through physical connection to the car computer systems, while another four require USB connection to the car. The remaining six vulnerabilities can be exploited remotely. A diligent cybercriminal can gain access to the cars’ infotainment systems, T-Box components, and UDS communication. In light of the findings, BMW has embraced the value of third-party cybersecurity research, and they are working on fixes.