Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

11th June 2018

A week in security (June 4 – June 10)

Last week on Labs, we took a look at hidden mobile ads, the perils of social media spam, and how to shore up your landline defenses. We also took a deep dive into Emotet malware analysis, and gave you some summertime safety tips. Other news Update your Adobe Flash player if you haven’t already. (source: Adobe) Be careful with your World Cup Wi-Fi. (Source: Securelist) Wannacry ransomware slayer faces new problems. (Source: The Register) Retiree’s personal info swiped. (Source: CA.gov) Weak credentials leads to IoT botnet takeover. (Source: Newsky Security) Ex TalkTalk CEO talks about the mega breach. (Source: The Register) Private posts accidentally go public. (Source: Facebook) What would you do if your data was abused? (Source: Help Net Security) Subdomain flaws and phishing attacks. (Source: Imperva) Russian APT attacks strike out at government targets. (Source: SCMagazine) Stay safe, everyone! The post A week in security (June 4 – June 10) appeared first on Malwarebytes Labs.
4th June 2018

A week in security (May 28 – June 3)

Last week on Labs, we talked about the significance of SEO poisoning in the world of search marketing, blackmail attempts against financial institutions in Canada, voice command flaws in smart assistants, survey and potential phishing scams on Instagram, and the latest changes in Office 365. We also shared our latest intel about America Geeks, a band of tech scammers that we profiled in 2015 and 2016. Other news Theoretically, millions of smart devices are at risk of compromise if the Z-Shave attack is done in the wild. (Source: Bleeping Computer) First, SunTrust. Now, Coca-Cola. (Source: Bleeping Computer) I think we saw this coming: robots are extremely insecure and can be used as “cyber weapons.” (Source: Internet of Business) When it comes to securing IoTs, multi-modal biometrics user authentication could become the norm. (Source: ABI Research) Users in India warned of new malware dubbed “virtual girlfriend” and “panda banker” that are capable of stealing money and user data. (So..
28th May 2018

A week in security (May 21 – May 27)

Last week we told you about a Mac cryptominer using XMRig, an overview of Dreamcast related scams, part 1 of decoding Emotet, and what to do about bad coding habits that die hard. We also published the results of our second CrackMe contest. Other news How a pioneer of machine learning became one of its sharpest critics. (Source: The Atlantic) The man who cracked the lottery. Spoiler: it was an inside job. (Source: The New York Times Magazine) New Spectre (variant 4) CPU flaw discovered —Intel, ARM, AMD affected (Source: The Hacker News) Amazon urged not to sell facial recognition tool to police. (Source: ABC News) Does the Facebook app even spy on those who don’t have an account? (Source: The Register) FBI stats: email fraud still #1 cybercrime. (Source: MailGuard Blog ) Brain Food spam botnet malware found on thousands of websites. (Source: SCMagazine) Amazon Alexa Security – How to stop hacks on voice assistants. (Source: Forbes) Necurs delivering flawed Ammy RAT via IQY Excel Web ..
21st May 2018

A week in security (May 14 – May 20)

Last week, we looked at the deluge of incoming policies caused by GDPR, tackled Adobe Reader zero days, and ran through some iPhone security tips. We also caught some helpline scammers in the act, explored advergaming, got our Senate Bill game face on, and deep dived into Drupal vulnerabilities. Other news Mining apps in Snaps store controversy (Source: The Register) Man identified in spy tools leak (Source: Washington Post) Facial recognition technology under fire (Source: Big Brother Watch) Phishers increasingly targeting SaaS/cloud storage (Source: Help Net Security) Yet another Facebook leak (Source: New Scientist) Signal caught by HTML tag injection (Source: Ivan Barerra Oro Blog) iOS has a ZipperDown problem (Source: Zipperdown(dot)org) Avoid this ICO scam (Source: Naked Security) Avoiding phishing with machine learning (Source: Business dot com) There’s always time for some more Mac malware (Source: LifeHacker) Stay safe, everyone! The post A week in security (May 14 – May 20)..
14th May 2018

A week in security (May 7 – May 13)

Last week on Labs, we looked at the case of a fake Android AV, an annoying adware that goes by the name of Kuik, the return of threat actors behind the Shopper Stop tech scam, a new Netflix phishing scam, the recent zero-day vulnerability in Internet Explorer, and the insufficiency of merely relying on the presence of the green padlock. Also, in a brief blog post, we talked about why we removed the blacklist of tech support scammers we have been dutifully maintaining for years. Other news Security researchers found a worm lurking in Facebook’s Messenger, and it steals account credentials from cryptocurrency platforms. (Source: InfoSec Institute) DDoS attacks are on the cusp of evolution. It would be foolish to expect it to die any time soon. (Source: Dark Reading) Oh no, they didn’t. OH. NO. THEY. DIDN’T! (Source: Graham Cluley’s blog) Speaking of Microsoft, hackers have found a way to bypass Safe Links, a feature in MS Office 365 that keeps malware and phishing attacks at bay. (Sourc..