Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

29th January 2018

A week in security (January 22 – January 28)

Last week on Labs, we analyzed a rogue app outbreak on Twitter, took a look at how Singapore’s government is faring with network defense, and rolled out our 2017 State of Malware report. We also became visionaries in Gartner’s Magic Quadrant report and explored a VR data mishap. Other news Man jailed for mass email compromise. (source: Justice.gov) You have 10 days to save your company. The clock is ticking. (source: The Register) Ransomware that rewards payments with…more malware. (source: ZDNet) Human trafficking victims forced to take part in web scams. (Help Net Security) Mobile point of sale gets a PCI security standard [PDF]. (source: pcisecuritystandards(dot)org) Coinhive mining in Youtube adverts. (source: The Register) Spyware is up and ransomware is down (courtesy of Labs’ State of Malware report). (source: SC Magazine) New research released on Bitcoins and anonymity. [PDF] (source: arxiv(dot)org) Two factor authentication on Reddit? Yes please. (source: Reddit) Travel and h..
22nd January 2018

A week in security (January 15 – January 21)

Last week on Labs, we gave you some background information about cookies, specifically which ones to worry about and why. We also warned you about scams surrounding the Mega Millions winner, who promised to donate his money to good causes. We analyzed a cryptocurrency miner using a very old technique called Heaven’s Gate to make injections into 64-bit processes from 32-bit loaders. On top of that, we pointed out that there are Chrome and Firefox extensions using “forced installs” that hide from users and hijack browsers. And last but not least, we enticed you to think about some practical New Year’s resolutions related to cybersecurity and privacy. Other news Google acknowledged a known issue where a bug in the Cast software may incorrectly send a large amount of network traffic, which can slow down or temporarily impact Wi-Fi networks. (Source: Google Support) Soon after, Google announced an update Android phones so an interaction with Chromecast video-streaming devices and Google H..
15th January 2018

A week in security (January 8 – January 14)

It’s very early in the year, yet everyone has already had a complete meltdown (pun intended) over a number of serious vulnerabilities found in legacy and modern microprocessors. Last week, rightly so, vendors released patches for hardware and OSes to help mitigate these threats. However, problems in patching persisted. As if this wasn’t challenging enough, some online criminals jumped on the bandwagon to take advantage of the hullabaloo to push out the Smoke Loader malware to inconspicuous user systems. On our blog, we also touched on WPA3, misleading marketing tactics, more 419 scams, and the indictment of alleged Fruitfly creator—a win for the security community. Lastly, in the realm of cryptocurrency, we saw an increase in malware payloads from the RIG exploit kit. Other news The espionage group named Turla came back, but not with a bang [PDF]. (Source: ESET’s We Live Security Blog) Aadhar, the world’s largest biometric database located in India, houses the data of 1.2 billion c..
9th January 2018

A week in security (January 1-8)

New year, new threats, as 2018 gets underway. On our blog, we had dubious searches aplenty for those hunting for Malwarebytes information, and we also covered the huge Meltdown/Spectre bug, affecting hardware going back to 10 years. Other news Coin miners are at it again, with a proof of concept for hacking public Wi-Fi and injecting cryptomining code into browsing sessions. (source: The Register) Around 240k people have been tied up in a “privacy incident” over at the DHS. (source: DHS) Browser makers are looking to mitigate risks from Meltdown and Spectre. (Source: Help Net Security) 36 rogue apps wound up on the Google Play store, reminding us to be extra vigilant even when on an official site. (Source: Trend Micro) Yet another cryptominer doing the rounds, this time dragging Linux machines into a cash spinning botnet. (source: F5) Face recognition: nice idea, but being fooled by photographs is a bit much. (source: Naked Security) A well put together phishing mail is causing heada..
9th January 2018

A week in security (January 1 – January 7)

New year, new threats, as 2018 gets underway. On our blog, we had dubious searches aplenty for those hunting for Malwarebytes information, and we also covered the huge Meltdown/Spectre bug, affecting hardware going back to 10 years. Other news Coin miners are at it again, with a proof of concept for hacking public Wi-Fi and injecting cryptomining code into browsing sessions. (source: The Register) Around 240k people have been tied up in a “privacy incident” over at the DHS. (source: DHS) Browser makers are looking to mitigate risks from Meltdown and Spectre. (Source: Help Net Security) 36 rogue apps wound up on the Google Play store, reminding us to be extra vigilant even when on an official site. (Source: Trend Micro) Yet another cryptominer doing the rounds, this time dragging Linux machines into a cash spinning botnet. (source: F5) Face recognition: nice idea, but being fooled by photographs is a bit much. (source: Naked Security) A well put together phishing mail is causing heada..