Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

11th September 2017

A week in security (September 4 – September 10)

Last week, we looked into expired domain names being used for malvertising, delved into dubious Facebook apps, and checked out Chinese seminar scams. We also explained the whys and wherefores of false positives, explained what Google is doing with HTTPs, warned you away from a fake DHS email, and outlined some early information about the Equifax breach. Elsewhere: Consumer News Equifax mega-leak: The biggest story around, with updates on the initial breach coming thick and fast (Source: The Register) IoT hackers shift to the dark side: A tangled tale of hacking, and personal information scattering (Source: NewSky Security) Patch your Android device to foil Toast Overlay attacks: Overlay attacks are nothing new for Android users, and Palo Alto Networks Unit 42 researchers have found yet another way for attackers to perpetrate them. (Source: Help Net Security) How hackers could send secret commands to speech recognition systems with ultrasound: Chinese security researchers have discove..
4th September 2017

A week in security (August 28 – September 3)

Last week, we looked at what actions Kronos can perform in the final installment of a 2-part post. We also dived into Locky, again, a ransomware that just made a comeback, and found that its latest variant (as of this writing) has anti-sandboxing capabilities. This means that once Locky has determined that it’s residing in a virtual machine, it will not perform to its full functionality. Our researchers also talked about a new 419 spam, malware vaccination tricks, malvertising, and insider threats. Lastly, Senior Security Researcher Jérôme Segura uncovered a new RIG exploit kit campaign that drops the PrincessLocker ransomware via drive-by download. Mobile Menace Monday: Implications of Google Play Protect Below are notable news stories and security-related happenings from last week: Latest updates for Consumers Scammers Already Taking Advantage Of Hurricane Harvey, Registering Domains. “The Better Business Bureau said it has already seen sketchy crowdfunding efforts and expects t..
28th August 2017

A week in security (August 21 – August 27)

In our blog posts, we announced the introduction of, and explained the necessity for, real-time protection for our Mac and Android users. Also explaining what you can expect them to do for you and answering the questions that we expect to be frequently asked. We looked at 4 key steps you can take within your business to help gain trust with your employees while educating them to make more secure decisions. And in our “Explained” series we talked about user agent strings and digital forensics. Below are notable news stories and security-related happenings from last week: Latest updates for Consumers Facebook makes Safety Check a permanent feature. Facebook is acting on its promise to make Safety Check a permanent feature by rolling out a dedicated Safety Check hub that helps you find any ongoing crisis without first being prompted to declare yourself as safe. Android spyware linked to Chinese SDK forces Google to boot 500 apps. More than 500 Android mobile apps have been removed from..
21st August 2017

A week in security (August 14 – August 20)

Last week, we gave some security tips for parents and kids aimed at the new school term. We also took a peek at the inside of the Kronos malware, focusing on how it works and protects itself. And, once again, we spotted a return of Locky ransomware with two new flavors at once, diablo6 and Lukitus. Below are notable news stories and security-related happenings from last week: Latest updates for Consumers The US government is seeking to unmask every person who visited an anti-Trump website in what privacy advocates say is an unconstitutional “fishing expedition” for political dissidents. A search warrant was issued to Dreamhost, a company hosting a website that was used to coordinate protest against the US president’s inauguration. Hackers hit Scottish Parliament with brute force cyber-attack. Staff at the Scottish parliament have been advised to change passwords as a result of the attack, performed by a yet unknown external source. An ex-Secret Service agent who stole Bitcoins from t..
14th August 2017

Week in Security (August 7 – August 13)

Last week, we explained how security certificates work and how malware authors have used them to block security software from being downloaded and executed. We also showed how the Magnitude exploit kit is spreading a Cerber ransomware variant that uses binary padding in an attempt to get skipped, because of its file size, during antivirus scans. Latest updates for Businesses Password rules have been way too complicated says the man that invented those rules and regrets it. These rules have now been updated. Locky made another comeback (maybe we should call it Rocky), this time using the diablo6 extension. And another ransomware that came back is the disk-encrypting Mamba. Microsoft and Kaspersky seem to get closer to burying the hatchet concerning the claim by the Russian anti-virus company that the US software giant was unfairly promoting the use of Windows Defender over third-party security products. Salesforce fired two of its senior security engineers after their talk at DEF CON. ..