Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

7th May 2018

Week in security (April 30 – May 6)

Last week on Labs, we examined the Spartacus ransomware, reported about a new tactic used by the Necurs malspam campaign, informed you about the recommended Twitter password change, and discussed engaging students to start considering careers in cybersecurity. Other news NTML credentials can be stolen via malicious Portable Document Format (PDF) files without any user interaction. (Source: SecurityWeek) Twitter sold data access to a Cambridge Analytica-linked researcher. (Source: Bloomberg) FacexWorm targets cryptocurrency users by spreading through Facebook Messenger. (Source: Security Affairs) New DNS encryption tools accelerate privacy online. (Source: HelpNetSecurity) IoT security: Is cryptocurrency-mining malware your next big headache? (Source: ZDNet) Companies from across the tech spectrum are lining up to protest the measure that would allow them to “hack back” with offensive initiatives in the face of a cyberattack. (Source: ThreatPost) Drive-by Rowhammer attack uses GPU to c..
7th May 2018

A week in security (April 30 – May 6)

Last week on Labs, we examined the Spartacus ransomware, reported about a new tactic used by the Necurs malspam campaign, informed you about the recommended Twitter password change, and discussed engaging students to start considering careers in cybersecurity. Other news NTML credentials can be stolen via malicious Portable Document Format (PDF) files without any user interaction. (Source: SecurityWeek) Twitter sold data access to a Cambridge Analytica-linked researcher. (Source: Bloomberg) FacexWorm targets cryptocurrency users by spreading through Facebook Messenger. (Source: Security Affairs) New DNS encryption tools accelerate privacy online. (Source: HelpNetSecurity) IoT security: Is cryptocurrency-mining malware your next big headache? (Source: ZDNet) Companies from across the tech spectrum are lining up to protest the measure that would allow them to “hack back” with offensive initiatives in the face of a cyberattack. (Source: ThreatPost) Drive-by Rowhammer attack uses GPU to c..
23rd April 2018

A week in security (April 16 – April 22)

Last week, we took a stroll down memory lane talking about Facebook and MySpace, noticed a change in the Magnitude exploit kit—wherein it started adopting the GandCrab ransomware, took a good look at a new form of adware that is based on Python, chatted a bit about Russian hacking with a journalist, encouraged retailers to ask the right questions to protect their business, and weighed in on a way to speed up Internet bandwidth and increase privacy via Cloudflare’s new DNS service. Other news Cryptocurrency is all the rave these days—and so are cryptominers. Security researchers recently discovered one that doesn’t rely on an open browser session. (Source: HackRead) Tax fraud is no longer for the clueless, it seems. Experts noticed that scammers are also targeting tax professionals—those filing taxes on behalf of their clients. (Source: CNBC) To date, adware, spyware, and malware have lurked inside the Google Play Store. But surveillanceware? That’s definitely something new. (Source: L..
16th April 2018

Week in security (April 09 – April 15)

Last week, we took a look at a malware-campaign called FakeUpdates, methods to use secure instant messaging, the inner workings of a decryption tool, and some Facebook spam campaigns. We also published our first quarterly Malwarebytes Labs CTNT report of 2018. Other news A security researcher discovered a flaw in P.F.Changs Rewards website. (Source: [email protected]) Security Consultant Xavier Mertens described a suspicious use of certutil.exe. (Source: InfoSec Handlers Diary Blog) A significant number of Cisco devices belonging to organizations in Russia and Iran were hacked by a group calling itself JHT. (Source: The Hacker News) Facebook CEO Mark Zuckerberg spoke at a joint hearing of the US Senate judiciary and commerce committees in Washington, DC. (Source: siliconrepublic) A vulnerability in Microsoft Outlook allowed hackers to steal a user’s Windows password. (Source: ThreatPost) A malware gang is going for identity theft and phony tax refunds by targeting CPAs. (Sour..
16th April 2018

A week in security (April 09 – April 15)

Last week, we took a look at a malware-campaign called FakeUpdates, methods to use secure instant messaging, the inner workings of a decryption tool, and some Facebook spam campaigns. We also published our first quarterly Malwarebytes Labs CTNT report of 2018. Other news A security researcher discovered a flaw in P.F.Changs Rewards website. (Source: [email protected]) Security Consultant Xavier Mertens described a suspicious use of certutil.exe. (Source: InfoSec Handlers Diary Blog) A significant number of Cisco devices belonging to organizations in Russia and Iran were hacked by a group calling itself JHT. (Source: The Hacker News) Facebook CEO Mark Zuckerberg spoke at a joint hearing of the US Senate judiciary and commerce committees in Washington, DC. (Source: siliconrepublic) A vulnerability in Microsoft Outlook allowed hackers to steal a user’s Windows password. (Source: ThreatPost) A malware gang is going for identity theft and phony tax refunds by targeting CPAs. (Sour..