Latest News

25th July 2017

FBI: Smart toys could harm children’s privacy and physical safety

The Federal Bureau of Investigation has recently issued a Public Service Announcement (PSA), encouraging consumers—parents, in particular—to think twice before purchasing internet-connected toys. Smart toys and entertainment devices for kids are part of the Internet of Things, and as such, they have built-in Wi-Fi capabilities. This enables them to communicate with the cloud and with each other. Other than that, these are also equipped with sensors, cameras, microphones, and other bits that allow them to not just respond to their child owners but also store data and tag a child’s location for parents/guardians to keep track of them in real time. CloudPets, Hello Barbie, My Friend Cayla, i-Que Robot, and hereO are just some of the smart toys and devices that security researchers have scrutinized for their lack of security and privacy measures. The FBI has highlighted in the PSA what type of information these toys may be able to gather. As most of these are normally “always on”, they c..
25th July 2017

Going dark: encryption and law enforcement

We’re hearing it a lot lately: encryption is an insurmountable roadblock between law enforcement and keeping us safe. They can’t gather intelligence on terrorists because they use encryption. They can’t convict criminals because they won’t hand over encryption keys. They can’t stop bad things from happening because bad guys won’t unlock their phones. Therefore—strictly to keep us safe—the tech industry must provide them with means to weaken, circumvent, or otherwise subvert encryption, all for the public good. No “backdoors”, mind you; they simply want a way for encryption to work for good people, but not bad. This is dangerous nonsense, for a lot of reasons. 1. It’s technically incorrect Encryption sustains its value by providing an end to end protection of data, as well as what we call “data at rest.” Governments have asked for both means of observing data in transit, as well as retrieving data at rest on devices of interest. They also insist that they have no interest in weakening..
28th June 2017

Solution Corner: Malwarebytes Endpoint Protection

Only one thing is certain in the threat landscape: the uncertainty around the attacks, the techniques, the tactics, and the vectors. Exploit kits dominated the landscape a few years ago, but has become quiet. Ransomware tops the list of today, but what’s in the store for the future? The trouble is, we don’t know for sure. The threats that we’re seeing today are almost certainly not the threats that we’ll likely see tomorrow. So what do we do in order to protect ourselves from the unknown? We need to take a holistic approach that allows us to protect against anything that may come our way. Multi-Vector Protection Malwarebytes Endpoint Protection leverages 7 unique layers of detection techniques in what we call Multi-Vector Protection – a multi-vector approach protects against today and tomorrow’s threats. The layers fall into two categories: rules-based and behavior-based. The rules-based layers leverage human-intelligence: the curated work of our talented threat researchers. Contrary ..
22nd June 2017

Solution Corner: Malwarebytes Incident Response

Unless you’ve been stuck at a fiery music festival, I don’t need to tell you the threat landscape is constantly evolving and that threats have become increasingly sophisticated at evading detection. Recent Malwarebytes Labs reports, including the 2017 State of Malware shine a light on just how fast these threats continue to spread around the globe impacting businesses of all sizes. In fact, according to eWeek the latest Ponemon Institute 2017 Cost of Data Breach report came out this week and shows dwell times for malicious attacks now average 214 days. The report also highlights that 1 out of 4 businesses will experience a breach. The cost to businesses and the complexity involved in responding to these types of incidents, including remediating the threats from endpoints, continues to increase as well. Osterman Research uncovered that more than 60 percent of attacks take organizations more than nine hours to remediate. We recently announced Malwarebytes Incident Response, a centraliz..
6th June 2017

HTTPS… Everywhere!

We recently updated our redirections rule in HTTPS-Everywhere, a browser extension that automatically redirects you to the HTTPS version of the website you are trying to visit. Now is a good time for us to give a short overview of how important HTTPS is. We’ll also talk about a few major HTTPS-related events that happened lately. When we browse the web, several third-parties are able to snoop on the connection between the user and the website, including the user’s ISP, law enforcement, the website’s ISP, and other people in between. Who can snoop on your connection without HTTPS, and what can they see? (by The TorProject) These intermediaries are able to obtain and modify on the fly most of the information sent through the connection: the website reached, the web page name and content, the potential username and password, the user’s IP address, and more. It obviously poses a lot of problems, which is why HTTPS is now mandatory for more and more websites (public sector, banks, etc.)...