Malwarebytes Week in Security

Taken from https://blog.malwarebytes.com/category/security-world/week-in-security/feed/

20th November 2017

A week in security (November 13 – November 19)

Last week, we gave you some tips for the inevitable online chaos that is Cyber Monday, explained how “trusted” root certificates can sometimes be anything but, and explored the strange world of catphishing. We also pulled apart some malware found on Google Play and laid out the specifics of the cloud in simple terms. Other news London Metropolitan Police aren’t massively keen on facial recognition technology. (source: The Register) Fake News is a bigger problem than just in the realm of the political. (source: Digital Shadows) Banking Trojans won’t be going away anytime soon—here’s another one! (source: Security Intelligence) Why do bug bounty hunters, er, hunt bug bounties? Study available here. (source: Help Net Security) That camera in your home may have a vulnerability lurking. (source: Talos Security) A legitimate email appears to be phishy fun with the Punisher. (source: io9) Hide your Facebook and Twitter from this piece of malware. (source: CNet) Stay safe everyone! The post ..
13th November 2017

A week in security (November 6 – November 12)

After coming out victorious in a case against PUPs, Malwarebytes CEO Marcin Kleczynski has this to say: We fought for our users and we won. — Marcin Kleczynski (@mkleczynski) November 9, 2017 And my, do we feel like champions! You can read more about this here. Last week, we looked into the cryptocurrency mining phenomenon, rising digital crimes that target businesses—the final supplement of a two-part series—a bogus WhatsApp app that got through the Google Play store because the actor behind it used Unicode, and puppy scams. We also revealed a Bitcoin multiplier scam that actors behind the Magnitude EK were banking on and the coming back of the Disdain EK, this time delivering a Neutrino bot. Lastly, we put out word about potential fakeries from cybercriminals targeting those shopping on Singles’ Day and a little exercise for the talented guys and gals who like to tinker with code, which we followed with a step-by-step tut on how to solve it. Other news Paradise lost? Breach of..
6th November 2017

A week in security (October 30 – November 5)

Last week on our blog, we told you what to expect at the upcoming Irisscon security conference in Dublin. We gave you a quick introduction into the why and how of analyzing malware based on their API calls. And we issued a warning about some lesser-known cybercrimes. Plus we explained why emerging APAC markets are prime targets for cybercriminals. We also introduced you to some of the scariest malware monsters that could come knocking on your door for more than just candy. And finally, we explained how cryptocurrencies work and why all the cybercriminals love them. Other news More data records were lost or stolen in the first half of 2017 than in all of 2016. In total, 918 data breaches led to 1.9 billion records being compromised worldwide in the first half of 2017. (source: CSO Online) Galleries hit by cybercrime wave. Hackers are using an email scam to intercept payments between galleries, collectors, and others. (source: The Art Newspaper) Investigation: WannaCry cyberattack and ..
30th October 2017

A week in security (October 23 – October 29)

Welcome back to “A week in security.” Last week, we took a look at how deleted files can be recovered, explored the BadRabbit ransomware plague attacking Eastern Europe (including a deep dive into the code), and talked about what it takes to work in security. One of our researchers, who is a PhD candidate in immunobiology at Yale, also discussed digital vs biological security. Finally, we launched a new series called “Please don’t buy this,” and our first edition featured smart locks. In other news around the net: Bad news for Google Play Protect: it might not be the malware-smashing barrier everyone was hoping it’d be. (source: The Register) A Dell customer support domain lapses, with predictable “Oh no, here’s a headache” results. (source: Krebs on Security) Home appliances going rogue? You’d better believe it. (source: Check Point blog) Old, reused passwords are still causing problems—even for coin miners. (source: Help Net Security) Oh look, even more bad apps on Google Play. (so..
23rd October 2017

A week in security (October 16 – October 22)

Last week was an eventful one in security, keeping our research and intel teams on their toes. Multiple security researchers homed in on suspicious and malicious apps on Google Play, affecting thousands of Android users. A new variant of Mac malware Proton was also found in the wild, this time hijacking the Elmedia Player to create a Trojanized copy of the app on its official website. If you’re a Mac user and suspect that you might be infected, our Director of Mac and Mobile, Thomas Reed, provided helpful tips to clean up your computer. We touched on how a business can create and foster an intentional culture of security, addressed why we need such a thing, and debunked some misconceptions surrounding it. We also looked into the Bring Your Own Device (BYOD) policy, the risks associated with it, and some mitigating factors to consider. Independent security researcher Hasherezade analyzed the Magniber ransomware, which targets systems only in South Korea. She noted that this type of hi..