Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

16th October 2017

A week in security (October 9 – October 15)

Last week on the Labs blog, we talked about GDPR as part of our series in the National Cyber Security Awareness Month (NCSAM). We also discussed a new method for phishing Apple ID passwords and the possible ramifications. We analyzed the malvertising chain due to a script that was found on popular websites like those of Equifax (!) and TransUnion. And we explained how decoy Word documents are used to deliver malware using the hyperlink feature in the OpenXML format. Malwarebytes news It was a great week for Malwarebytes since we won three awards at the 2017 Computing Security Awards: Security Company of the Year, Editors Choice, and Malware Solution of the Year. And we were chosen as the winner in the “Rising Star: Cybersecurity Solution” category of NetworkWorld Asia 2017 Readers’ Choice Awards. Our CEO, Marcin Kleczynski, was interviewed by the Huffington Post on the subject 5 things I wish someone told me before I became CEO. And the Malwarebytes Labs team presented you with the q..
9th October 2017

A week in security (October 02 – October 08)

Last week, we gave you some tips for National Cybersecurity Awareness Month, walked through an exploration of a small adware file, and explored the complicated world of the Homograph attack. Here’s what else happened in security. VB2017 Many of our team members attended VB2017 in Madrid, one of the premier yearly security conferences that brings together researchers, companies, law enforcement, and more in an effort to explore the latest security research. Here’s a collection of articles from The Register’s John Leyden, who was in attendance: Bulletproof hosts stay online by operating out of disputed backwaters: A look at how dubious hosts are retreating to places where they can continue to offer dubious services. Spy vs. spy vs. hacker vs… who is THAT? Everyone’s hacking each other: The problem of Intel gathering when everyone is muddying the waters. Hey, IoT vendors. When a paediatric nurse tells you to fix security, you definitely screwed up: The alarming world of IoT medical devi..
2nd October 2017

A week in security (September 25 – October 01)

Recently, we talked about the hacking incident at Deloitte, one of the ‘big four’ global accounting firms. It was reported that client email addresses, usernames, and passwords were exposed. This also brought to light weaknesses in their policies and lack of threat intelligence to recover leaked data. We advised Deloitte clients the following: do an inventory of email addresses used to correspond with the company, review network outbound traffic, determine what possible information might have leaked from the hack, and (more importantly) maintain security best practices to avoid repeating hacks like this from happening. Patrick Wardle, an acclaimed security researcher, found a keychain vulnerability flaw in High Sierra, Apple’s new macOS operating system. This revelation, unfortunately, spurned a lot of articles that one may deem bordering FUD (fear, uncertainty, doubt). So our resident Mac expert, Thomas Reed, set some records straight. Senior Malware Analyst Nathan Collier likened B..
25th September 2017

A week in security (September 18 – September 24)

Last week, we kept you updated on our blog about the infected versions of CCleaner that were offered as downloads on the official servers. We also warned you against a fake IRS notice that delivers a customized spying tool, some of the threats currently facing gamers, and a Netflix scam that has been doing the rounds in Europe. Mac users learned how to tell if their Mac is infected and Advanced Tech Support victims learned how to apply for a (partial) refund. Elsewhere: Consumer news The pain caused by the Equifax breach was analyzed in depth by the NY Times. And just as easily Equifax was fooled again. They referred users to a parody site like phishers might have used. Luckily this time it was run by a security researcher. A new twist in ransomware was provided by “nRansomware”, a program that locks up your computer and only releases it after you send in 10 nude pictures. The rise in the number of phishing sites has been huge. Almost 1.5 million new phishing sites pop up every mon..
18th September 2017

A week in security (September 11 – September 17)

Last week, we dug into phishing campaigns done via Linkedin accounts, remediation versus prevention, issues with smart syringe pumps, and advised you to go patch against a Word 0day. We had some tips regarding identity theft protection, explored crowdsourced fraud, and explained YARA rules. Elsewhere: Consumer News Equifax UK admits: 400,000 Brits caught up in mega-breach: The UK gets caught up in the ongoing Equifax saga (Source: The Register) Another month, another malware outbreak in Google’s Play Store: More rogue apps on the Google Play store (Source: The Register) Unsecured Elasticsearch servers turned into PoS malware C&Cs: (Source: Help Net Security) ‘Your Windows Has Been Banned’ malware makes an unwelcome return: There’s always another piece of Ransomware to deal with (source: Betanews) Huge Vevo hack: Another day, another compromise for fans of video uploads everywhere (source: EDM News) Malware blamed for city’s data breach: malware and payment system problems, oh my (sou..