Category: Malwarebytes Labs

3 reasons why your endpoint security is not enough

Categories: Business Join our upcoming webinar and learn about weaknesses in your current endpoint security setup and how to address them. (Read more…) The post 3 reasons why your endpoint security is not enough appeared first on Malwarebytes Labs. This…

Meal delivery service PurFoods announces major data breach

Categories: Business Tags: purfoods Tags: breach Tags: ransomware Tags: data Tags: information We take a look at a breach notice from food delivery service PurFoods. (Read more…) The post Meal delivery service PurFoods announces major data breach appeared first on…

Cisco VPNs without MFA are under attack by ransomware operator

Categories: Business Categories: News Tags: Cisco Tags: VPN Tags: Akira Tags: ransomware Tags: brute-force Tags: credential stuffing Tags: password spraying Several researchers are seeing ransomware attacks targetting Cisco VPNs without MFA (Read more…) The post Cisco VPNs without MFA are…

A week in security (August 21 – August 27)

Categories: News Tags: week Tags: security Tags: august Tags: 2023 Tags: trusted advisor Tags: cyrus Tags: A list of topics we covered in the week of August 21 to August 27 of 2023 (Read more…) The post A week in…

2.6 million DuoLingo users have scraped data released

Categories: News Tags: DuoLingo Tags: data breach Tags: email adress Tags: username Tags: real name Using an openly available API, cybercrimnals were able to scrape the data of 2.6 million DuoLingo users. (Read more…) The post 2.6 million DuoLingo users…

Google strengthens its Workplace suite protection

Categories: Business Tags: google Tags: gmail Tags: workplace Tags: protection Tags: sensitive Tags: trigger Tags: business We take a look at how Google is strengthening protections across its Workplace products, and Gmail in particular. (Read more…) The post Google strengthens…

Update now! Google Chrome’s first weekly update has arrived

Categories: Exploits and vulnerabilities Tags: stable channel Tags: weekly updates Tags: CVE-2023-4427 Tags: CVE-2023-4428 Tags: CVE-2023-4429 Tags: CVE-2023-4430 Tags: CVE-2023-4431 Tags: use after free Tags: out of bounds Tags: heap corruption The first of Chrome’s now weekly security updates fixes…

Teenage members of Lapsus$ ransomware gang convicted

Categories: Business Tags: business Tags: hack Tags: hacked Tags: compromise Tags: lapsus$ Tags: convicted Tags: crime Tags: ransomware Tags: leak Tags: breach A wave of video game developer compromises has come to a court-based conclusion. (Read more…) The post Teenage…

Malwarebytes acquires Cyrus Security

Categories: Personal Cybersecurity isn’t limited to defending against malware anymore; it’s about ensuring your entire digital identity remains unscathed and your private details remain private. (Read more…) The post Malwarebytes acquires Cyrus Security appeared first on Malwarebytes Labs. This article…

Adobe ColdFusion vulnerability exploited in the wild

Categories: Exploits and vulnerabilities Categories: News Tags: Adobe Tags: ColdFusion Tags: CVE-2023-26359 Tags: CVE-2023-26360 Tags: critical Tags: known exploited Tags: deserialization A second Adobe ColdFusion vulnerability that was patched in April has been added to CISA’s known exploited vulnerabilities catalog.…

DarkGate reloaded via malvertising and SEO poisoning campaigns

Categories: Threat Intelligence Tags: darkgate Tags: autoit Tags: malvertising Tags: seo poisoning The new version of the DarkGate malware is currently actively being distributed via malspam, malicious ads and SEO poisoning. (Read more…) The post DarkGate reloaded via malvertising and…

Update now! WinRAR files can be abused to run malware

Categories: Exploits and vulnerabilities Categories: News Tags: WinRAR Tags: CVE-2023-40477 Tags: RCE Tags: Windows 11 A new version of WinRAR is available that patches two vulnerabilities attackers could use for remote code execution. (Read more…) The post Update now! WinRAR…

Alert Prioritization and Guided Remediation: The future of EDR

Categories: Business Defeat alert fatigue using specialized threat intelligence. (Read more…) The post Alert Prioritization and Guided Remediation: The future of EDR appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article: Alert…

A week in security (August 14 – August 20)

Categories: News Tags: Augsut 2023 Tags: week in security A list of topics we covered in the week of August 14 to August 20 of 2023 (Read more…) The post A week in security (August 14 – August 20) appeared…

QR codes used to phish for Microsoft credentials

Categories: News Tags: QR codes Tags: attachment Tags: phishing Tags: Bing Tags: Microsoft Tags: credentials Researchers have been monitoring a phishing campaign that uses QR codes and Bing redirects to lead targets to phishing sites. (Read more…) The post QR…

Trusted Advisor puts you in the security driving seat

Categories: Personal Malwarebytes’ new Trusted Advisor makes security easy with a comprehensive, at-a-glance, real-time assessment. (Read more…) The post Trusted Advisor puts you in the security driving seat appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

Exchange Server security updates updated

Categories: Exploits and vulnerabilities Categories: News Tags: Exchange Tags: CVE-2023-21709 Tags: August update Tags: re-release Microsoft Exchange Server administrators may have to install a re-released security patch (Read more…) The post Exchange Server security updates updated appeared first on Malwarebytes…

Attackers demand ransoms for stolen LinkedIn accounts

Categories: News Tags: LinkedIn Tags: rambler.ru Tags: MFA Tags: brute-force Tags: credential stuffing LinkedIn support channels are being swamped by users that have been locked out of their accounts. (Read more…) The post Attackers demand ransoms for stolen LinkedIn accounts…

Malvertisers up their game against researchers

Categories: Threat Intelligence Tags: malvertising Tags: google Tags: ads Tags: malware Tags: fingerprinting Malicious ads via search engine results page are getting harder to identify thanks to advanced fingerprinting techniques (Read more…) The post Malvertisers up their game against researchers…

Discord.io confirms theft of 760,000 members’ data

Categories: News Tags: Discord.io Tags: Discord Tags: data breach Discord.io has confirmed that personally identifiable information of 760,000 members was stolen in a data breach. The third-party Discord service has been shut down for the time being (Read more…) The…

PCMag ranks Malwarebytes #1 cybersecurity vendor

Categories: Business PCMag readers named Malwarebytes the #1 most-recommended security software vendor in its list of Best Tech Brands for 2023.  (Read more…) The post PCMag ranks Malwarebytes #1 cybersecurity vendor appeared first on Malwarebytes Labs. This article has been…

A week in security (August 7 – August 13)

Categories: News Tags: Zoom Tags: YouTube Tags: Chrome Tags: TikTok Tags: ransomware Tags: Cloudflare Tags: robocallers Tags: security advisor A list of topics we covered in the week of August 7 to August 13 of 2023 (Read more…) The post…

Old exploit kits still kicking around in 2023

Categories: Threat Intelligence Tags: exploit kits Tags: eks Tags: rigek Tags: purplefoxek Internet Explorer may be a thing of the past, but there are still users and threat actors trying to deliver drive-by downloads. (Read more…) The post Old exploit…

August Patch Tuesday stops actively exploited attack chain and more

Categories: Exploits and vulnerabilities Categories: News Microsoft has announced patches for 87 vulnerabilities this month, including two that are being actively exploited. (Read more…) The post August Patch Tuesday stops actively exploited attack chain and more appeared first on Malwarebytes…

Ransomware review: August 2023

Categories: Threat Intelligence July saw one of the highest number of ransomware attacks in 2023 at 441. At the forefront of these attacks is, once again, Cl0p. (Read more…) The post Ransomware review: August 2023 appeared first on Malwarebytes Labs.…

Voter data stolen in UK Electoral Commission systems breach

Categories: Personal Tags: electoral commission Tags: election Tags: voting Tags: vote Tags: record Tags: roll Tags: register Tags: breached Tags: compromise Tags: uk Tags: opt-out We take a look at reports that the UK’s electoral commission has been breached, and…

Cloudflare Tunnel increasingly abused by cybercriminals

Categories: News Tags: Cloudflare Tunnel Tags: cloudflared Tags: rdp Tags: https Tags: smb Tags: ssh Researchers have found that cybercriminals are shifting to Cloudflare Tunnel to hide and anonymize their nefarious activities. (Read more…) The post Cloudflare Tunnel increasingly abused…

Digital assets continue to be prime target for malvertisers

Categories: Threat Intelligence Tags: malvertising Tags: nft Tags: crypto Tags: wallet Tags: bing Tags: google NFT enthusiasts are getting their wallets drained after clicking on a malicious ad. (Read more…) The post Digital assets continue to be prime target for…

Server breach could be fatal blow for LetMeSpy

Categories: Personal Tags: letmespy Tags: stalkerware Tags: spy Tags: snoop Tags: install Tags: data Tags: breach Tags: hacked We take a look at reports of an app called LetMeSpy facing an imminent shutdown after a server breach and data deletion…

A week in security (July 31 – August 6)

Categories: News Tags: Ivanti Tags: Meta Tags: Teams Tags: ransomware rollback Tags: AMP Tags: Minecraft Tags: Barracuda A list of topics we covered in the week of July 31 to August 6 of 2023 (Read more…) The post A week…

New Security Advisor amps up security in minutes

Categories: Business The new feature provides comprehensive health score that assesses the quality of your Nebula implementation. (Read more…) The post New Security Advisor amps up security in minutes appeared first on Malwarebytes Labs. This article has been indexed from…

2022’s most routinely exploited vulnerabilities—history repeats

Categories: Exploits and vulnerabilities Categories: News Tags: Zoho ManageEngine Tags: CVE-2021-40539 Tags: Log4Shell Tags: CVE-2021-44228 Tags: CVE-2021-13379 Tags: ProxyShell Tags: CVE-2021-34473 Tags: CVE-2021-31207 Tags: CVE-2021-34523 Tags: CVE-2021-26084 Tags: Atlassian Tags: CVE-2022-22954 Tags: CVE-2022-22960 Tags: CVE-2022-26134 Tags: CVE-2022-1388 Tags: CVE-2022-30190 Tags:…

TikTok facing fines for violating children’s privacy

Categories: News Categories: Privacy Tags: tiktok Tags: privacy Tags: gdpr Tags: children Tags: under 13 TikTok is looking at yet another fine… (Read more…) The post TikTok facing fines for violating children’s privacy appeared first on Malwarebytes Labs. This article…

How to protect your child’s identity

Categories: News Categories: Personal Tags: Children Tags: identity Tags: theft Tags: protection Tags: SSN Tags: COPPA Identity theft is a serious problem, especially when it affects children. (Read more…) The post How to protect your child’s identity appeared first on…

FAQ: How does Malwarebytes ransomware rollback work?

Categories: Business Malwarebytes Ransomware Rollback rescues your data from encryption by effectively “turning back the clock” of a ransomware attack. But how does it work, exactly? (Read more…) The post FAQ: How does Malwarebytes ransomware rollback work? appeared first on…

Film companies lose battle to unmask Reddit users

Categories: Personal Tags: reddit Tags: copyright Tags: piracy Tags: court Tags: case Tags: movie Tags: film Tags: producer Tags: pirate Tags: torrent Tags: steal Tags: theft Tags: download Tags: IP A Judge has thrown out a case where multiple movie…

Ivanti patches second zero-day vulnerability being used in attacks

Categories: Exploits and vulnerabilities Categories: News Tags: Ivanti Tags: EPMM Tags: MobileIron Tags: CVE-2023-35081 Tags: CVE-2023-35078 Tags: tomcat Tags: arbitrary file write Tags: ACL Tags: upgrade Ivanti has issued a patch to address a second critical zero-day vulnerability (Read more…)…

A week in security (July 24 – July 30)

Categories: News Tags: week Tags: security Tags: 2023 Tags: July A list of topics we covered in the week of July 24 to July 30 of 2023 (Read more…) The post A week in security (July 24 – July 30)…

60,000 Androids have stalkerware-type app Spyhide installed

Categories: News Categories: Privacy Tags: stalkerware Tags: carew Tags: spyhide A hacktivist was able to grab all the data from a stalkerware operator and shared the method and the findings. (Read more…) The post 60,000 Androids have stalkerware-type app Spyhide…

How to set up computer security for your parents

Categories: News Categories: Personal Tags: parents Tags: cybersecurity Tags: chromebook Tags: auto updates Tags: urgent notifications Tags: remote desktop Tags: router Tags: block list Tags: encryption Here are some tips that you can use to set up a secure environment…

Update now! Apple fixes several serious vulnerabilities

Categories: Exploits and vulnerabilities Categories: News Tags: Apple Tags: WebKit Tags: CVE-2023-38606 Tags: CVE-2023-32409 Tags: CVE-2023-37450 Tags: CVE-2023-32416 Apple has released security updates for several products to address several serious vulnerabilities including some actively exploited zero-days. (Read more…) The post…

A week in security (July 17 – 23)

Categories: News Tags: week in security Tags: malwarebytes Tags: July Tags: 2023 A list of topics we covered in the week of July 17 to July 23 of 2023 (Read more…) The post A week in security (July 17 –…

Docker Hub images found to expose secrets and private keys

Categories: Awareness Categories: News Tags: Docker Tags: Docker Hub Tags: containerization Tags: secrets Tags: exposed Researchers have found that numerous Docker images shared on Docker Hub expose sensitive data. (Read more…) The post Docker Hub images found to expose secrets…

FakeSG enters the ‘FakeUpdates’ arena to deliver NetSupport RAT

Categories: Threat Intelligence Tags: fakeupdates Tags: socgholish Tags: netsupport Tags: RAT A new campaign leveraging compromised WordPress sites emerges with another fake browser update. (Read more…) The post FakeSG enters the ‘FakeUpdates’ arena to deliver NetSupport RAT appeared first on…

A week in security (July 10 – 16)

Categories: News Tags: week Tags: security Tags: July Tags: 2023 A list of topics we covered in the week of July 10 to July 16 of 2023 (Read more…) The post A week in security (July 10 – 16) appeared…

Act now! In-the-wild Zimbra vulnerability needs a workaround

Categories: Exploits and vulnerabilities Categories: News Tags: Zimbra Tags: MalasLocker Tags: vulnerability Tags: Google Tags: actively exploited Tags: fn:escapeXml Security experts are warning Zimbra users that a vulnerability for which there is no patch is being actively exploited in the…

Tax preparation firms shared sensitive information with Meta

Categories: News Categories: Privacy Tags: tax preparation Tags: Meta Tags: Pixel Tags: Markup Tax preparation firms shared personal and financial information with social media giant Meta (Read more…) The post Tax preparation firms shared sensitive information with Meta appeared first…

Ransomware review: July 2023

Categories: Threat Intelligence Following a three-month lull of activity, Cl0p returned with a vengeance in June and beat out LockBit as the month’s most active ransomware gang. (Read more…) The post Ransomware review: July 2023 appeared first on Malwarebytes Labs.…

From Malvertising to Ransomware: A ThreatDown webinar recap

Categories: Business Get the low-down on our recent webinar From Malvertising to Ransomware. (Read more…) The post From Malvertising to Ransomware: A ThreatDown webinar recap appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the…

Update now! Microsoft patches a whopping 130 vulnerabilities

Categories: Exploits and vulnerabilities Categories: News Tags: Microsoft Tags: Adobe Tags: Apple Tags: Android Tags: Cisco Tags: Fortinet Tags: MOVEit Tags: Mozilla Tags: SAP Tags: VMware Tags: CVE-2023-32049 Tags: CVE-2023-35311 Tags: CVE-2023-32046 Tags: CVE-2023-36874 Tags: CVE-2023-36844 For the July 2023…

How to secure your business before going on vacation

Categories: Business Are you a critical security expert for your organization? Are you also going on vacation? Here’s how to ensure your time away from the office doesn’t get interrupted with a security incident. (Read more…) The post How to…

Threatening rogue finance apps removed from the Apple Store

Categories: Personal Tags: app Tags: finance Tags: india Tags: loan Tags: rogue Tags: Apple Store Tags: play store Tags: google Tags: threaten Tags: blackmail Tags: sextortion Tags: fake Tags: deepfake Tags: deepfakes Tags: morph Multiple finance apps have been removed…

A week in security (July 3 – 9)

Categories: News Tags: week Tags: security Tags: July 2023 A list of topics we covered in the week of July 3 to July 9 of 2023 (Read more…) The post A week in security (July 3 – 9) appeared first…