Category: Malwarebytes Labs

Webinar recap: EDR vs MDR for business success

Categories: Business Learn more about EDR and MDR and which is right for your business. (Read more…) The post Webinar recap: EDR vs MDR for business success appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs…

KeePass vulnerability allows attackers to access the master password

Categories: Exploits and vulnerabilities Categories: News Categories: Personal Tags: KeePass Tags: memory dump Tags: CVE-2023-32784 There is a Proof-of-Concept available for an unpatched vulnerability in KeePass that allows attackers to dump the master password. (Read more…) The post KeePass vulnerability…

Child safety app riddled with vulnerabilities: Update now!

Categories: Personal Tags: Parental control kids place Tags: child Tags: safety Tags: controls Tags: restrict. block Tags: limit Tags: vulnerability Tags: exploit Tags: password Tags: upload Tags: dashboard Child safety app Parental Control – Kids Place has been found to…

Zip domains, a bad idea nobody asked for

Categories: News Just, why? (Read more…) The post Zip domains, a bad idea nobody asked for appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article: Zip domains, a bad idea nobody asked…

PharMerica breach impacts almost 6 million people

Categories: News Categories: Ransomware Tags: PharMerica Tags: Money Message Tags: ransomware Tags: PII Tags: SSN US pharmacy giant PharMerica has reported a cybersecurity incident that affects over 5.8 million people. The data theft has been claimed by ransomware group Money…

Leaked Babuk ransomware builder code lives on as RA Group

Categories: News Tags: ransomware Tags: RA Group Tags: babuk Tags: code Tags: leaked Tags: encrypted Tags: stolen Tags: exfiltrated Tags: ransom Tags: hijack Tags: blackmail Tags: double extortion Tags: leak Tags: sell We take a look at yet another ransomware…

3 reasons to use a VPN

Categories: Personal Categories: Privacy Tags: VPN Tags: Privacy Tags: always on Tags: location Tags: sensitive information Most VPN users can be put in one of three categories. It all depends on your needs and your threat model. (Read more…) The…

A week in security (May 8-14)

Categories: News Tags: YouTube Tags: ad block Tags: sponsored tweets Tags: Twitter Tags: fake BBC News Tags: AVLab assessment Tags: Google Tags: Google Passkey Tags: MSP Tags: Patch Tuesday Tags: Discord Tags: RedStinger Tags: tech support scam Tags: Aurora stealer…

Why we should be more open about ransomware attacks

Categories: News Categories: Ransomware Tags: ransomware Tags: data breach Tags: dark web Tags: share information Paying the ransom and not saying a word about what happened is what cybercriminals would like us all to do. (Read more…) The post Why…

Windows 11 is showing its first signs of Rust

Categories: News Tags: Windows 11 Tags: OS Tags: operating system Tags: programming language Tags: rust Tags: C Tags: C++ Tags: kernel Tags: buffer overflow We take a look at the slow introduction of programming language Rust into the Windows 11…

YouTube is testing ad blocker detection

Categories: News Categories: Personal Tags: youtube Tags: ad Tags: advert Tags: network Tags: ad industry Tags: block Tags: blocker Tags: adblock Tags: malware Tags: malvertising Tags: intrusive Tags: popup Tags: affiliate We take a look at YouTube’s testing of ad…

Google Passkeys: How to create one and when you shouldn’t

Categories: News Tags: Google passkey Tags: passkey Tags: passwordless future Tags: passwordless Tags: phishing Google is offering users the best option to date to securing their accounts from phishing. (Hint: It’s not passwords.) (Read more…) The post Google Passkeys: How…

How to spot and avoid a tech support scam

Categories: Awareness Categories: Personal Categories: Scams Tags: Tech Support Scams Tags: Malwarebytes Tags: impersonating Tags: screen lockers Tags: fake warnings Tags: remote access Tech support scams are an ongoing nuisance. Knowing how they operate helps you to recognize them. (Read…

New Discord username policy raises user privacy fears

Categories: News Tags: Discord Tags: privacy Tags: username Tags: discriminator Tags: DM Tags: bot Tags: chat Tags: change Tags: changing Tags: server Tags: hijack phish Tags: private We take a look at the reaction to Discord’s proposed changes to how…

Update now! May 2023 Patch Tuesday tackles three zero-days

Categories: Exploits and vulnerabilities Categories: News Tags: Microsoft Tags: CVE-2023-29336 Tags: CVE-2023-24932 Tags: bootkit Tags: CVE-2023-29325 Tags: Outlook Tags: preview Tags: CVE-2023-24941 Tags: Apple Tags: Cisco Tags: Google Tags: Android Tags: VMWare Tags: SAP Tags: Mozilla Microsoft’s Patch Tuesday round…

Brightline breach hits at least 964,000 people, US records show

Categories: News Categories: Ransomware Tags: Brightlight Tags: GoAnywhere MFT Tags: data breach Tags: Cl0p Following the Cl0p ransomware gang’s attacks that leveraged Fortra’s GoAnywhereMFT software tool, behavioral health provider Brightline informed customers about a data breach related to the attacks.…

A week in security (May 1 – 7)

Categories: News The most interesting security related news of the week from May 1 till 7 (Read more…) The post A week in security (May 1 – 7) appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

Ransomware review: May 2023

LockBit maintained its position as the top ransomware attacker and was also observed expanding into the Mac space. (Read more…) The post Ransomware review: May 2023 appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read…

Google and Apple cooperate to address unwanted tracking

Categories: News Categories: Privacy Tags: Google Tags: Apple Tags: AirTag Tags: Tile Tags: Samsung Tags: Bluetooth Tags: trackers Tags: stalking Tags: car thieves Google and Apple want to create a specification for tech that alerts users when they’re being tracked…

World Password Day must die

Categories: News Critical technology should not require an annual pep talk to function correctly. (Read more…) The post World Password Day must die appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article:…

The one and only password tip you need

Categories: News I was asked to write a list of password tips. It’s a short list. (Read more…) The post The one and only password tip you need appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

How small businesses can secure employees’ mobile devices

Categories: Business Categories: News Tags: Small Business Week Tags: mobile security policy Tags: A third of organizations aren’t protecting their mobile devices at all. Don’t be one of them. (Read more…) The post How small businesses can secure employees’ mobile…

Google Authenticator WILL get end-to-end encryption. Eventually.

Categories: News Google has promised to add end-to-end encryption to Google Authenticator backups after users were warned against turning on the new feature. (Read more…) The post Google Authenticator WILL get end-to-end encryption. Eventually. appeared first on Malwarebytes Labs. This…

Google takes CryptBot to the wood shed

Categories: News Tags: CryptBot Tags: malware Tags: chrome Tags: download Tags: package Tags: packages Tags: google Tags: legal Tags: court order Tags: RICO Tags: Pakistan We take a look at Google’s efforts to shut down a particularly nasty set of…

A week in security (April 24 -30)

Categories: News Tags: Lockbit Tags: cl0p Tags: papercut Tags: vmware Tags: magecart Tags: fileless Tags: chatgpt Tags: apc Tags: Pupy rat Tags: guloader Tags: black basta Tags: flipper zero Tags: clickjacking The most interesting security related news of the week…

How to protect your small business from social engineering

Categories: Personal Tags: Small Business Week 2023 Tags: Small Business Week Tags: phishing Tags: pretexting Tags: baiting Tags: tailgating Tags: BEC Tags: CEO fraud Tags: business email compromise Tags: O’Neill Bragg & Staffin Tags: 2022 Internet Crime Report Tags: FBI…

ChatGPT writes insecure code

Categories: News Tags: ChatGPT Tags: How Secure is Code Generated by ChatGPT? Tags: Raphaël Khoury Tags: Anderson Avila Tags: Jacob Brunelle Tags: Baba Mamadou Camara Tags: Université du Québec Tags: ChatGPT makes insecure code Researchers have found that ChatGPT, OpenAI’s…

Magecart threat actor rolls out convincing modal forms

Categories: Threat Intelligence Tags: magecart Tags: skimmer Tags: modal Tags: fraud Tags: e-commerce It’s hard to put individuals at fault when the malicious copy is better than the original. This credit card skimmer was built to fool just about anyone.…

Decoy dog toolkit plays the long game with Pupy RAT

Categories: News Tags: Pupy RAT Tags: nation state Tags: russia Tags: decoy dog Tags: toolkit Tags: linux Tags: mobile Tags: windows Tags: malware Tags: DNS Tags: evasive We take a look at the discovery of a long running malware toolkit…

Black Basta ransomware attacks Yellow Pages Canada

Categories: News Categories: Ransomware Tags: Yellow Pages Tags: Canada Tags: Black Basta Tags: ransomware Yellow Pages Canada has suffered a cyberattack by the Black Basta ransomware group. (Read more…) The post Black Basta ransomware attacks Yellow Pages Canada appeared first…

GuLoader returns with a rotten shipment

Categories: News Tags: GuLoader Tags: loader Tags: malware Tags: malspam Tags: email Tags: mail Tags: delivery Tags: collection Tags: scam Tags: infection Tags: Italy We take a look at a GuLoader campaign which comes bundled with an Italian language fake…

A week in security (April 17 – 23)

Categories: News Tags: fake Chrome update Tags: AirBnb scam Tags: fake IRS tax email Tags: Ransomware in Germany report Tags: Living Off The Land Tags: LOTL attack Tags: ALPHV ransomware Tags: ransomware Tags: spring cleaning your browser Tags: lost injured…

Adult content malvertising scheme leads to clickjacking

Categories: News Tags: 18+ Tags: malvertising Tags: Google ads Tags: clickjacking Malwarebytes’ researchers have discovered a malvertising scheme that uses adult lures for clickjacking purposes. (Read more…) The post Adult content malvertising scheme leads to clickjacking appeared first on Malwarebytes…

Update now, there’s a Chrome zero-day in the wild

Categories: News Tags: chrome Tags: browser Tags: update Tags: vulnerability Tags: CVE Tags: exploit Tags: exploitation Tags: zero-day Users of Chrome should ensure they’re running the latest version to patch an integer overflow in the Skia graphics library. (Read more…)…

Spring cleaning tips for your browser

Categories: News Tags: Some tips that can enhance your browser’s speed Tags: so you have more time to enjoy the outdoors Some tips that can enhance your browser’s speed, so you have more time to enjoy the outdoors. (Read more…)…

Avoid this “lost injured dog” Facebook hoax

Categories: News Tags: facebook Tags: scam Tags: spam Tags: hoax Tags: dog Tags: injured Tags: lost Tags: vet Tags: missing We take a look at a Facebook hoax which uses supposedly injured dogs as the lure for a bait and…

LockBit ransomware on Mac: Should we worry?

Categories: News Categories: Ransomware Tags: LockBit Tags: ransomware Tags: Patrick Wardle Tags: macOS ransomware Tags: first Mac ransomware Tags: Azim Khodjibaev Tags: BleepingComputer Tags: Mark Stockley With plans to offer more ransomware, LockBit has just created a variant for macOS.…

Woman tracks down and turns table on Airbnb scammer

Categories: News Categories: Scams Tags: Airbnb Tags: TikTok Tags: @livvoogus Tags: Olivia Tags: Mr. Tyler A superhost scammed a woman out of a thousand dollars. She didn’t take it lying down. (Read more…) The post Woman tracks down and turns…

Update Chrome now! Google patches actively exploited flaw

Categories: Exploits and vulnerabilities Categories: News Tags: Google Tags: Chrome zero-day Tags: CVE-2023-2033 Tags: V8 flaw Tags: V8 Google has released an updated version of Chrome to address a zero-day flaw that is being exploited in the wild. (Read more…)…

Beware: Fake IRS tax email wants your Microsoft account

Categories: News Categories: Scams Tags: IRS tax scam Tags: tax scam Tags: IRS Tags: Jerome Segura Tags: Telegram bot Tags: Emotet Expect more IRS tax-related shenanigans from fraudsters, who are now going for corporate accounts, after some states received deadline…

Ransomware in Germany, April 2022 – March 2023

Categories: News In the last 12 months, Germany was one of the most attacked countries in the world, the most attacked in the EU, and a favourite target of the notorious Black Basta group. (Read more…) The post Ransomware in…

Is AI being used for virtual kidnapping scams?

Categories: News Tags: kidnap Tags: scam Tags: virtual Tags: AI Tags: voice Tags: fake Tags: fraud Tags: hoax Tags: kidnapping We take a look at claims that AI is now being used for a notorious form of kidnapping hoax. (Read…

Ransomware in France, April 2022–March 2023

Categories: Ransomware Categories: Threat Intelligence In the last 12 months France was one of the most attacked countries in the world, and a favourite target of LockBit, the world’s most dangerous ransomware. (Read more…) The post Ransomware in France, April…

Ransomware review: April 2023

Categories: Ransomware Categories: Threat Intelligence Cl0p was the most used ransomware in March 2023, dethroning the usual frontrunner LockBit, after breaching over 104 organizations with a zero-day vulnerability. (Read more…) The post Ransomware review: April 2023 appeared first on Malwarebytes…

Ransomware in the UK: April 2022–March 2023

Categories: Ransomware Categories: Threat Intelligence In the last 12 months, the UK has been second only to the USA in terms of ransomware attacks, and its education sector has been subjected to a feeding frenzy by Vice Society. (Read more…)…

Update now! April’s Patch Tuesday includes a fix for one zero-day

Categories: Exploits and vulnerabilities Categories: News Tags: Microsoft Tags: Apple Tags: Google Tags: Adobe Tags: Cisco Tags: SAP Tags: Mozilla Tags: CVE-2023-28252 Tags: CVE-2023-28231 Tags: CVE-2023-21554 Tags: Word Tags: Publisher Tags: Office One fixed vulnerability is being actively exploited by…

A week in security (April 3 – 9)

Categories: News Tags: TikTok Tags: Super FabriXss Tags: Twitter Tags: macOS malware Tags: ransomware Tags: 2023 State of Malware Tags: Western Digital Tags: Android Tags: endpoint security Tags: ChatGPT Tags: K-12 Tags: IoT Tags: Facebook Tags: targeted advertising Tags: Google…

Visitors of tax return e-file service may have downloaded malware

Categories: News Categories: Scams Tags: tax scams Tags: efile.com Tags: US tax 2023 Tags: backdoor Tags: Trojan Tags: Johannes Ullrich Tags: MalwareHunterTeam Tags: /u/SaltyPotter Tags: fake network error notification Cybercriminals have compromised eFile.com to host malicious code that allows for…

TikTok misused children’s data, faces $15.6M fine

Categories: News Tags: TikTok Tags: Information Commissioner’s Office Tags: ICO Tags: Sonia Livingston Tags: John Edwards TikTok has been fined by a UK data protection watchdog after its investigation shows the company failed to get parental consent. (Read more…) The…