27th November 2017

A week in security (November 20 – November 26)

Last week, we warned you about a new method by which the Mac malware OSX.Proton is being spread, we informed you where all those free Bitcoins you were texted about were being held up, how the EU intends to battle fake news, and how the Terdot Trojan likes social media. We also revealed our 2018 security predictions. Other news Due to zero entropy implementation of Address Space Layout Randomization (ASLR), the Windows 10 defense is ‘worthless’ and this bug dates back to Windows 8. (source: ZDNet) A new tech support scam technique streamlines the entire scam experience, leaving the potential victims only one click or tap away from speaking with a scammer. (Source: Microsoft blog) You have less than 90 days to claim your share of $586 million refund if you were scammed via (not by) Western Union. (Source: Tripwire) Firefox 59 to make it a lot harder to use data URIs in phishing attacks, as it will stop rendering them in certain scenarios. (Source: Virusbulletin blog) An increasing numb..
23rd November 2017

Mr. Robot Review: eps3.6_fredrick+tanya.chk

I don’t know about you guys, but this episode was an emotional one for me. As happy as I was to see Leon back, chatting away about Frasier and Knight Rider, I knew no good could come out of him being back.
22nd November 2017

Mr. Robot Review eps3.5_kill-pr0cess.inc.

A little late, but better than never: Avast’s Mr. Robot Review eps3.5_kill-pr0cess.inc.
20th November 2017

A week in security (November 13 – November 19)

Last week, we gave you some tips for the inevitable online chaos that is Cyber Monday, explained how “trusted” root certificates can sometimes be anything but, and explored the strange world of catphishing. We also pulled apart some malware found on Google Play and laid out the specifics of the cloud in simple terms. Other news London Metropolitan Police aren’t massively keen on facial recognition technology. (source: The Register) Fake News is a bigger problem than just in the realm of the political. (source: Digital Shadows) Banking Trojans won’t be going away anytime soon—here’s another one! (source: Security Intelligence) Why do bug bounty hunters, er, hunt bug bounties? Study available here. (source: Help Net Security) That camera in your home may have a vulnerability lurking. (source: Talos Security) A legitimate email appears to be phishy fun with the Punisher. (source: io9) Hide your Facebook and Twitter from this piece of malware. (source: CNet) Stay safe everyone! The post ..
13th November 2017

A week in security (November 6 – November 12)

After coming out victorious in a case against PUPs, Malwarebytes CEO Marcin Kleczynski has this to say: We fought for our users and we won. — Marcin Kleczynski (@mkleczynski) November 9, 2017 And my, do we feel like champions! You can read more about this here. Last week, we looked into the cryptocurrency mining phenomenon, rising digital crimes that target businesses—the final supplement of a two-part series—a bogus WhatsApp app that got through the Google Play store because the actor behind it used Unicode, and puppy scams. We also revealed a Bitcoin multiplier scam that actors behind the Magnitude EK were banking on and the coming back of the Disdain EK, this time delivering a Neutrino bot. Lastly, we put out word about potential fakeries from cybercriminals targeting those shopping on Singles’ Day and a little exercise for the talented guys and gals who like to tinker with code, which we followed with a step-by-step tut on how to solve it. Other news Paradise lost? Breach of..