4th September 2017

A week in security (August 28 – September 3)

Last week, we looked at what actions Kronos can perform in the final installment of a 2-part post. We also dived into Locky, again, a ransomware that just made a comeback, and found that its latest variant (as of this writing) has anti-sandboxing capabilities. This means that once Locky has determined that it’s residing in a virtual machine, it will not perform to its full functionality. Our researchers also talked about a new 419 spam, malware vaccination tricks, malvertising, and insider threats. Lastly, Senior Security Researcher Jérôme Segura uncovered a new RIG exploit kit campaign that drops the PrincessLocker ransomware via drive-by download. Mobile Menace Monday: Implications of Google Play Protect Below are notable news stories and security-related happenings from last week: Latest updates for Consumers Scammers Already Taking Advantage Of Hurricane Harvey, Registering Domains. “The Better Business Bureau said it has already seen sketchy crowdfunding efforts and expects t..
28th August 2017

A week in security (August 21 – August 27)

In our blog posts, we announced the introduction of, and explained the necessity for, real-time protection for our Mac and Android users. Also explaining what you can expect them to do for you and answering the questions that we expect to be frequently asked. We looked at 4 key steps you can take within your business to help gain trust with your employees while educating them to make more secure decisions. And in our “Explained” series we talked about user agent strings and digital forensics. Below are notable news stories and security-related happenings from last week: Latest updates for Consumers Facebook makes Safety Check a permanent feature. Facebook is acting on its promise to make Safety Check a permanent feature by rolling out a dedicated Safety Check hub that helps you find any ongoing crisis without first being prompted to declare yourself as safe. Android spyware linked to Chinese SDK forces Google to boot 500 apps. More than 500 Android mobile apps have been removed from..
21st August 2017

A week in security (August 14 – August 20)

Last week, we gave some security tips for parents and kids aimed at the new school term. We also took a peek at the inside of the Kronos malware, focusing on how it works and protects itself. And, once again, we spotted a return of Locky ransomware with two new flavors at once, diablo6 and Lukitus. Below are notable news stories and security-related happenings from last week: Latest updates for Consumers The US government is seeking to unmask every person who visited an anti-Trump website in what privacy advocates say is an unconstitutional “fishing expedition” for political dissidents. A search warrant was issued to Dreamhost, a company hosting a website that was used to coordinate protest against the US president’s inauguration. Hackers hit Scottish Parliament with brute force cyber-attack. Staff at the Scottish parliament have been advised to change passwords as a result of the attack, performed by a yet unknown external source. An ex-Secret Service agent who stole Bitcoins from t..
14th August 2017

Week in Security (August 7 – August 13)

Last week, we explained how security certificates work and how malware authors have used them to block security software from being downloaded and executed. We also showed how the Magnitude exploit kit is spreading a Cerber ransomware variant that uses binary padding in an attempt to get skipped, because of its file size, during antivirus scans. Latest updates for Businesses Password rules have been way too complicated says the man that invented those rules and regrets it. These rules have now been updated. Locky made another comeback (maybe we should call it Rocky), this time using the diablo6 extension. And another ransomware that came back is the disk-encrypting Mamba. Microsoft and Kaspersky seem to get closer to burying the hatchet concerning the claim by the Russian anti-virus company that the US software giant was unfairly promoting the use of Windows Defender over third-party security products. Salesforce fired two of its senior security engineers after their talk at DEF CON. ..
7th August 2017

A week in security (July 31 – August 6)

Last week we explored some basic PowerShell commands, dived into the new methods used by TrickBot, and wrote at length about the Magnitude exploit kit redirection chain. Our teams were busy at both BlackHat and DefCon, and outside of those famous hallways, we also took time to fire up some basic PowerShell programs. Naturally the two big security events have consumed most of the column inches this past week, but even so there’s still a couple of notable security stories floating around. Latest updates for Consumers WannaCrypt victims paid out over $140k in Bitcoin to get files unscrambled: Victims of Ransomware continue to pay the price (source: The Register) Web Developer for Chrome compromised: A timeline of how a Chrome extension was taken over by bad actors (source: Blog on Chris Pederick) iOS users beware: You’re the biggest target for mobile phishing attacks: Keep a close eye on your trusty Apple devices (source: TechRepublic) Nigerian man charged in US phishing scam: Contra..