Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

16th July 2018

A week in security (July 9 – July 15)

Last week, we talked about domestic abuse fuelled by IoT, doing threat intel programs right, blocking ICO fraud, and man-in-the-middle attacks. We also explained why we block shady ad blockers and provided tips to online shoppers for Prime Day. Other news: Reports revealed that low-end Android devices sold in Egypt, Brazil, South Africa, Myanmar, and other developing markets contain pre-installed malware. (Source: Help Net Security) The breach in Ticketmaster was found to be part of a larger card fraud campaign. (Source: Dark Reading) Significant increases in Microsoft and virtualization software bugs seen. (Source: CSO Online) Two new Spectre-style CPU attacks uncovered by researchers. (Source: ZDNet) Sextortion is in the news once again, and scammers behind it get the attention of their targets by revealing old passwords tied to their account. (Source: KrebsOnSecurity) Almost half of organizations worldwide were hit by crypto mining attacks, report says. (Source: Help Net Security) ..
9th July 2018

A week in security (July 2 – July 8)

Last week, we tracked back a large mining operation from their Coinhive shortlink, we took a look at online project management tools, we described a new macro-less technique to distribute malware, and talked about a Mac malware that targets crypto-mining users. Other news: Huawei enterprise comms kit has a TLS crypto bug. (Source: The Register) The Pentagon is building a dream team of tech-savvy soldiers. (Source: Wired) Some computer science academics ran an experiment to find out whether your phone is secretly listening to you. (Source: Gizmodo) Chrome and Firefox pull stylish add-on after a report it logged browser history. (Source: Bleeping Computer) A downloader that decides how to infect the victim: with a cryptor or with a miner. (Source: SecureList) Macro-based malware campaign replaces desktop and Quick Launch shortcuts to install backdoor. (Source: SCMagazine) Homeland Security subpoenas Twitter for data breach finder’s account. (Source: ZDNet) Ex-NSO employee caught selling..
2nd July 2018

A week in security (June 25 – July 1)

Last week on Labs, we looked at comment moderation duties, Viagra spam on a news-making restaurant’s website, and how to manage your child’s online presence for Internet safety month. We also looked at a set of big breaches and leaks, as well as malware threats with a World Cup vibe. Other news Homeland Security subpoenas “Flash Gordon” (Source: ZDNet) Looking into the world of digtal ad fraud (Source: The Register) Cryptominers dial it down to avoid detection (Source: SANS) EU “cyber force” on the way (Source: Ministry of National Defence Lithuania) GDPR and dark patterns [PDF] (Source: Forbruker Radet) A reminder to not give out your personal information (Source: BBC) Monitoring in the workplace (Source: Help Net Security) New Brave update includes TOR (Source: Brave) Phishing is top SMB attack threat (Source: Infosec Magazine) Spearphishing campaign attacks South Korea (Source: Dark Reading) Stay safe, everyone! The post A week in security (June 25 – July 1) appeared first on Ma..
25th June 2018

A week in security (June 18 – June 24)

Last week, we took a deep dive into SamSam ransomware, looked at ways how to identify and delete malicious emails, recognized that there are now risks affecting job recruitment portals, analyzed a malicious Android app banking on the popularity of Fortnite, and identified causes and solutions for the skills shortage in cybersecurity. Other news Security researchers pointed a finger at China for a sophisticated hacking campaign that breached satellite operators, telco companies, and defense contractors. (Source: Reuters) Latest Netflix phishing campaign started using valid TLS certificates. Typical. (Source: SANS InfoSec Forum) Two studies reveal that most websites and web apps are poorly secured. (Source: Dark Reading) An artist-cum-programmer realized that streaming devices are vulnerable to DNS rebinding, a weakness that has been known within the security industry for years. (Source: Wired) An information stealer malware on Android is found to particularly fond of Japanese- and Kor..
18th June 2018

A week in security (June 11 – June 17)

Last week on Malwarebytes Labs, we discussed how to protect the online privacy of children, we gave you a spring 2018 overview of exploit kits, rounded up the ongoing discussions about the VPNFilter malware, and discussed the struggles of (UK) law enforcement with modern-day cybercrime. Other news Terros Health data breach: 1,600 patients potentially impacted. (Source; ABC 15) A critical server for popular weight-loss service Weight Watchers was left unprotected. (Source: ThreatPost) Net Neutrality has officially been repealed by the Federal Communications Commission. (Source: The New York Times) Here’s the content of the Microsoft June 2018 Patch Tuesday. (Source: SANS ISC ) Microsoft reveals which Windows bugs it might decide not to fix. (Source: The Register) Bitcoin priceplosion may have been market manipulation. (Source: NakedSecurity) Brutal cryptocurrency mining malware crashes your PC when discovered. (Source: ZDNet) Cryptojacking malware proves a big winner for web crooks. (S..