Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

5th March 2018

Week in security (February 26 – March 4)

Last week on Malwarebytes Labs, we explained how to protect your computer from malicious cryptomining, we gave an encryption 101 lesson using ShiOne ransomware as a case study, and we offered an explanation about SQL injection. We also released a report on the state of malicious cryptomining from its first resurgence in the fall until now. In active malware, we discussed how the RIG malvertising campaign uses cryptocurrency themes as a decoy, how an old virus made its way onto a Chinese DDoS bot, and how a massive DDoS attack washed over GitHub. We also drew your attention to our own Chris Boyd appearing in Jenny Radcliffe’s Human Factor Podcast. Other news Does your endpoint solution stop fileless attacks? They are gaining traction, says a Ponemon Institute study. (Source: Bricata) Feedless is an iOS content blocker that takes the media out of social media. (Source: The Verge) A serious remote code execution vulnerability in both the ‘μTorrent desktop app for Windows and the newly ..
26th February 2018

A week in security (February 19 – February 25)

Last week on Malwarebytes Labs, we gave readers a primer on encryption, took a stab at that Deepfakes tool Internet users seem to be interested in, and started a new series that talks about GDPR. We also looked at a drive-by download campaign that starts in booby-trapped Chinese websites that drop malware via different exploits. This malware is a DDoS bot called Avzhan, which we then studied in detail. Other news Hackers targeted Russian and Indian banks by attempting to abuse the SWIFT global banking network. (Source: Security Week) Are you an independent writer who sells books via Amazon’s Createspace? You may want to check if someone is impersonating you for fraud. (Source: KrebsOnSecurity) Akamai spotted an uptick in credential abuse in the last quarter of 2017. (Source: Computer Weekly) Let’s read about that new Google Chrome “adblocker” that is actually not an adblocker at all. (Source: Sophos’ Naked Security Blog) Should “security” and “social” be in the same sentence together..
19th February 2018

A week in security (February 12 – February 18)

Last week on Malwarebytes Labs, we looked at a huge Android cryptomining campaign, malicious apps on Google Play, and some Apple scams doing the rounds. We also explored the world of healthcare security, and dived into the land of scammy Valentine’s Day tricks and cheats. Other news Thought the Equifax breach couldn’t get any worse? You might want to take a seat. (Source: The Register) Google Chrome is going to start blocking a wide range of ads. (Source: Google) Bitcoin phishing pulls in massive amount of cash. (Source: Coindesk) Two Russian nationals are in a whole lot of trouble. (Source: Justice(dot)gov) Not on Windows 10 but need some ATP support? Microsoft would like a word. (Source: Microsoft) Intel is offering big money for big vulnerabilities. (Source: Help Net Security) Websites are now asking users to sign up for some mining instead of viewing ads. (Source: Mashable) Unfortunately, aliens are going to kill us all with malware. (Source: LadBible) 50k Snapchat users phished. ..
12th February 2018

A week in security (February 5 – February 11)

Last week on Malwarebytes Labs, we featured a new Flash Player zero-day that has been found in recent targeted attacks. And we talked about a new trick to cripple browsers that came out of the hat of tech support scammers. We also covered several methods of stealing cryptocurrencies, including one for the Mac that wasn’t as new as it seemed, one for Android that poses as hack apps, and yet another abusing the fact that Deepfakes content was banned from most major networks. We even threw in an overview of several major cryptocurrency related thefts. For Safer Internet Day 2018, we provided you with some fast and free tools to make your Internet experience safer and more private using ad blockers and anti-trackers. Other news Security researcher Scott Helme reported that thousands of US and UK government sites were running a compromised BrowserAloud plugin, making visitors mine for the Monero cryptocurrency. (Source: Sky News) Lenovo warned customers about two critical Broadcom (Wifi)..
5th February 2018

A week in security (January 29 – February 04)

Last week on Labs, we looked into PUPs stealing and using mainstream logos of security and tech companies to further gain user trust, GandCrab and Scarab ransomware variants in the wild, and a new Mac malware called OSX.CreativeUpdater that can be distributed via MacUpdate. We also profiled robocalling and ransomware, particularly how ransomware was named the “It” malware of early- to mid-2017, and then began to fizzle like a dying firecracker at end of the year onwards. Other news Brian Krebs reminded everyone to file their taxes before threat actors do it for them. (Source: KrebsOnSecurity) Hold on to your digital wallets as attacks against them will likely increase, security experts say. (Source: The Express) Well, would you look at that? Scammers can get scammed, too! (Source: The Register) This low-budget, low technical know-how phishing campaign was able to spy on a community for more than a year. (Source: Dark Reading) With all the hoopla around Meltdown and Spectre, malware au..