Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

9th April 2018

A week in security (April 02 – April 08)

Last week, we took a look at fake Whatsapp antics, dubious gaming extensions, and a huge Panera bread breach. There was also LockCrypt ransomware to contend with, we had a poke around Linkedin, and we published another Physician, protect thyself blog. Other news Compromised cash register systems (source: Fin7) Drone buyer data leaked (source: The Register) Data scraping problems for Facebook (source: Help Net Security) Office 365 and ransomware protection (source: Microsoft) Charities potentially vulnerable to CEO fraud (source: gov.uk) Mirai financial sector attack detailed (source: SCMag) Erroneous Equifax breach letters (source: CNBC) Chat system hacked (source: The Register) Fighting back against mobile phish attacks (source: CSO magazine) 3 million scam letters caught in 18 months (source: Which? magazine) Stay safe, everyone! The post A week in security (April 02 – April 08) appeared first on Malwarebytes Labs.
2nd April 2018

A week in security (March 26 – April 01)

Last week, we looked at the thought process behind creating a ransomware decryptor, the inner workings of QuantLoader, the ways one can protect their Android devices, the exploit kits we have encountered this winter, the now-known epidemic of data breaches, the coming of TLS 1.3, and the ways one can protect their P2P payment apps. Other news “Lone wolf” sextortionists pose as hot women behind fake Facebook profiles. (Source: Sophos’s Naked Security Blog) Sad fact: Willing victims of romance scams actually do exist. Not only do they send money to “their partner” whom they haven’t met yet but they also knowingly act as mules. (Source: Security Week) While a majority of IT pros recognize that IoTs are so insecure, not that many are actually doing anything about it. (Source: ZDNet) What happens when you send an application into the background? This SANS diary attempts to answer that. (Source: SANS ISC InfoSec Forums) Well, will you look at that—Monero isn’t that untraceable after all. (S..
26th March 2018

A week in security (March 19 – March 25)

Last week, we looked at the growing problem of smartphone addiction, how link rot is continually slicing down portions of the web, and the theft of our intellectual property. We also explored the landscape of DDoS problems, and tackled a Stephen Hawking 419 scam. Other news What can only really be described as “Scamception” (source: The Register) Mozilla calls time on Facebook advertising (source: Mozilla) City of Atlanta hit by Ransomware (source: 11Alive) Time for some Netflix and bug bounty (source: Netflix) Did someone forget to switch on their VPN? They most certainly did (source: Daily Beast) Hackers ‘led warplanes to Syrian hospital‘ (source: The Telegraph) Dropbox offer a helping hand to security researchers (source: Dropbox) Orbitz hit by data breach (source: SC Magazine) Top exfiltration and evasion techniques (source: Help Net Security) Tax software and phishing attacks (source: CNBC news) When China hoards its hackers everyone loses. (Source: Engadget) A 15-year-old securi..
19th March 2018

A week in security (March 12 – March 18)

Last week on Malwarebytes Labs, we took a look at the inner workings of a fileless attack, explored what happened in a zero day ransomware attack aimed at South Koreans, gave you hints and tips for avoiding cold calls, and took a deep dive into the secretive world of GrayKey. Other news The Equifax story just keep rumbling on. (Source: The Guardian) Some Meltdown and Spectre updates. (Source: The Register) VPN tests give some concerning results. (Source: vpn Mentor) The rich world of money laundering. (Source: Help Net Security) Critical vulnerabilities found in SecurEnvoy SecurMail. (Source: SEC Consult) An incredible story looking at Cambridge Analytica. (Source: The Guardian) Cybercrime as a service. (Source: ZDNet) Geopolitical events contributing to malware spikes. (Source: Enterprise Times) Preinstalled malware on 5 million Android devices? Whoops (Source: The Inquirer) Backdoored BitTorrent client causes malware attack on 400k PCs. (Source: Ars Technica) Stay safe, everyone! T..
12th March 2018

A week in security (March 05 – March 11)

Last week on Malwarebytes Labs, we paid homage to several women in tech, including some of our very own, on International Women’s Day and shared their stories. We also looked into an adware posing as an Android app that claims to live stream the 2018 Winter Olympics, exposed scammers that go by the name GeeksHelp, who were caught red-handed (again) after their first unmasking two years before, and gave you the steps on how to break encryption. Lastly, we spotlighted the impact of artificial intelligence (AI) and machine learning (ML) in cybersecurity, the importance of having a solid and tested incident response framework, and the reality that Mac malware does exist and that they have evolved. Other news Avid Twitter, Facebook, and Instagram user? Be wary of clicking links in your feed, as phishing campaigns are seen on the rise in social media platforms. (Source: Security Brief) Inexpensive Android smartphone models were pre-installed with the Triada Trojan, one of several advanced..