Latest News

11th June 2018

A week in security (June 4 – June 10)

Last week on Labs, we took a look at hidden mobile ads, the perils of social media spam, and how to shore up your landline defenses. We also took a deep dive into Emotet malware analysis, and gave you some summertime safety tips. Other news Update your Adobe Flash player if you haven’t already. (source: Adobe) Be careful with your World Cup Wi-Fi. (Source: Securelist) Wannacry ransomware slayer faces new problems. (Source: The Register) Retiree’s personal info swiped. (Source: CA.gov) Weak credentials leads to IoT botnet takeover. (Source: Newsky Security) Ex TalkTalk CEO talks about the mega breach. (Source: The Register) Private posts accidentally go public. (Source: Facebook) What would you do if your data was abused? (Source: Help Net Security) Subdomain flaws and phishing attacks. (Source: Imperva) Russian APT attacks strike out at government targets. (Source: SCMagazine) Stay safe, everyone! The post A week in security (June 4 – June 10) appeared first on Malwarebytes Labs.
8th June 2018

Tips for safe summer travels: your cybersecurity checklist

Summer is just around the corner in the Northern Hemisphere, and with it comes vacation plans for many. Those looking to take some time away from work and home are likely making plans to secure their home, have their pets taken care of, and tie up loose ends at work. But how about securing your devices and your data while you’re away? Here are some things to take into consideration if you want to have a trip free of cyber worries. Before you leave Some of the things on your cybersecurity checklist can be taken care of before you leave. They include the following: Make sure the operating systems and software on all the devices you are going to take along with you are up to date. Having to install updates while you are on the road can be a pain due to slow and unstable connections. Use your at-home Wi-Fi, which you know is secured with a password. (Right? If not—do that right away.) You may want to take precautions to secure devices that you’ll be leaving behind in your workplace and h..
8th June 2018

Travel site phishing scam and genealogy site data breach | Avast

Booking.com users get phished Some unfortunate travelers had their thirst for adventure rewarded with a steaming mug of scam. Users of the popular travel-booking site booking.com received bogus texts directing them to change their passwords “due to a security breach.” A malicious link in the text, if clicked, gave the phishers access to that user’s bookings. A second text then capitalized on the booking data by demanding bank info to “process payment” for the user’s specific trip. Booking.com is part of the hospitality magnate that includes priceline.com, kayak.com, and opentable.com. A spokesperson for the site states their system was not compromised, pointing to select hotel partners as the attack victims. The company claims all impacted guests have been notified and that any damages will be compensated.
4th June 2018

A week in security (May 28 – June 3)

Last week on Labs, we talked about the significance of SEO poisoning in the world of search marketing, blackmail attempts against financial institutions in Canada, voice command flaws in smart assistants, survey and potential phishing scams on Instagram, and the latest changes in Office 365. We also shared our latest intel about America Geeks, a band of tech scammers that we profiled in 2015 and 2016. Other news Theoretically, millions of smart devices are at risk of compromise if the Z-Shave attack is done in the wild. (Source: Bleeping Computer) First, SunTrust. Now, Coca-Cola. (Source: Bleeping Computer) I think we saw this coming: robots are extremely insecure and can be used as “cyber weapons.” (Source: Internet of Business) When it comes to securing IoTs, multi-modal biometrics user authentication could become the norm. (Source: ABI Research) Users in India warned of new malware dubbed “virtual girlfriend” and “panda banker” that are capable of stealing money and user data. (So..
1st June 2018

Routers at risk, Canadian chaos, and a Hidden Cobra | Avast

FBI advises Americans to reset their routers Last week, we reported how the FBI had seized a key domain to the botnet VPNFilter. That story continued yesterday when the Bureau publicly asked all US residents to reboot their routers. The advice comes with the knowledge that while VPNFilter can take control of a router, part of the malware can be easily kicked off the system with a simple reboot — turning the device off for a moment. This renders the malicious program harmless, though the router can be reinfected. To prevent that, users are also advised to make sure the router’s security is fully up to date and the password has been changed from the default to a suitably complex one. The malware attacks many kinds of routers, most notably Linksys, MikroTik, Netgear, and TP-Link. Each of those companies have posted further detailed instructions to combat VPNFilter on their websites.