18th June 2018

Don’t forget to reboot your router | Avast

UPDATE June 18th: US consumers who practice poor router security are at high risk from cyberattacks designed to take over their connected devices, steal passwords and gather other sensitive personal information. Half of people surveyed (51%) in the US by Avast, the global leader in digital security, have never even logged into their router’s web administration interface to change the factory login credentials. And, 72% have never updated their firmware. Given the vulnerabilities users face with VPNFilter, it is highly recommended to update your router firmware and change your router admin password. See the article below for the full story. UPDATE June 6th: Many more devices are affected by VPNFilter than originally thought. Ars Technica estimates that over 200,000 additional models may be affected. Click here for the full list of routers. The FBI recently issued an immediate call-to-action for every small office and homeowner out there: power cycle (reboot) your router ASAP. The malw..
18th June 2018

A week in security (June 11 – June 17)

Last week on Malwarebytes Labs, we discussed how to protect the online privacy of children, we gave you a spring 2018 overview of exploit kits, rounded up the ongoing discussions about the VPNFilter malware, and discussed the struggles of (UK) law enforcement with modern-day cybercrime. Other news Terros Health data breach: 1,600 patients potentially impacted. (Source; ABC 15) A critical server for popular weight-loss service Weight Watchers was left unprotected. (Source: ThreatPost) Net Neutrality has officially been repealed by the Federal Communications Commission. (Source: The New York Times) Here’s the content of the Microsoft June 2018 Patch Tuesday. (Source: SANS ISC ) Microsoft reveals which Windows bugs it might decide not to fix. (Source: The Register) Bitcoin priceplosion may have been market manipulation. (Source: NakedSecurity) Brutal cryptocurrency mining malware crashes your PC when discovered. (Source: ZDNet) Cryptojacking malware proves a big winner for web crooks. (S..
15th June 2018

Major Microsoft fixes and risky Android devices | Avast

Microsoft fixes 50 flaws for Windows, Adobe, Spectre, and more Microsoft packed a lot into its Patch Tuesday updates this week, providing 50 fixes for vulnerabilities covering everything from the Windows OS, Internet Explorer, and Microsoft Office to Microsoft Edge and ChakraCore JavaScript. The full list of patches includes fixes for eight recently-discovered Spectre flaws, which allow for Speculative Store Bypass, a trick thieves can use to steal info through websites. Also included in the massive patch is a Flash Player update that fixes an Adobe zero-day vulnerability patched out-of-band last week, as well as three other Adobe bugs.
14th June 2018

How to fight sophisticated cybercrime | Avast

As all the pieces of our cyberworld — personal laptops, business desktops, smartphones, digital assistants, TVs, appliances — grow more connected, they also make us more vulnerable to cyberattacks. Both on the individual and corporate levels, cyberattacks have become big business, which in turn has made cybersecurity big business as well. The research firm Gartner estimates that $96 billion will be spent on global information security in 2018, an 8% increase from 2017.
14th June 2018

What does ‘consent to tracking’ really mean?

Thanks to Jerome Boursier for contributions. Post GDPR, many social media platforms will ask end users to consent to some form of tracking as a condition of using the service. It’s easy to make assumptions as to what that means, especially when the actual terms of service or data policy for the service in question is tough to find, full of legal jargon, or just long and boring. Part of the shock of recent Facebook stories was in discovering just how expansive their consent to tracking really was. Let’s take a look at what can happen after you hit OK on a new site’s Terms of Service. What we think they’re doing Most commonly, users think that social media sites limit their tracking to actual interactions with the site while logged in. This includes likes, follows, favorites, and general use of the site as intended. Those interactions are then analyzed to determine a user’s rough interests, and serve them corresponding ads. We asked some non-technical Malwarebytes staffers what they t..