Categories: Exploits and vulnerabilities Categories: News Tags: Yerodin Richards Tags: Arris Tags: routre Tags: CVE-2022-45701 Tags: default credentials A security researcher found an authenticated remote code execution vulnerability in very wide-spread Arris router models. (Read more…) The post Arris router…
Category: Malwarebytes Labs
Ransomware pushes City of Oakland into state of emergency
Categories: News Categories: Ransomware Tags: Oakland Tags: ransomware Tags: state of emergency The Interim City Administrator of the City of Oakland declared a state of emergency.after a ransomware attack crippled the city’s services a week ago (Read more…) The post…
TrickBot gang members sanctioned after pandemic ransomware attacks
Categories: News Tags: Conti Tags: ransomware Tags: TrickBot Tags: sanction The US, in partnership with the UK, named individuals tied to TrickBot and shamed them with a sanction. (Read more…) The post TrickBot gang members sanctioned after pandemic ransomware attacks…
Update now! Apple patches vulnerabilities in MacOS and iOS
Categories: Apple Categories: Exploits and vulnerabilities Tags: Apple Tags: macOS Ventura Tags: 13.2.1 Tags: iOS Tags: iPadOS Tags: 16.3.1 Tags: CVE-2023-23514 Tags: CVE-2023-23522 Tags: CVE-2023-23529 Tags: use after free Tags: type confusion Apple has released patches for macOS Ventura, iPadOs,…
Update now! February’s Patch Tuesday tackles three zero-days
Categories: Exploits and vulnerabilities Categories: News Tags: patch Tuesday Tags: Microsoft Tags: Apple Tags: Adobe Tags: SAP Tags: Citrix Tags: Cisco Tags: Atlassian Tags: Google Tags: Mozilla Tags: Forta Tags: OpenSSH Tags: CVE-2023-21823 Tags: CVE-2023-21715 Tags: OneNote Tags: CVE-2023-23376 Tags:…
Should you share passwords with your partner?
Categories: Personal Tags: love and passwords Tags: password sharing with partner Tags: privacy This Valentine’s Day, we ask the inevitable password question: is it okay to share passwords with your partner? (Read more…) The post Should you share passwords with…
Android 14 developer preview highlights multiple security improvements
Categories: News Tags: android 14 Tags: developer preview Tags: apps Tags: malware Tags: download We take a look at what the Android 14 developer preview means for Android security moving forward. (Read more…) The post Android 14 developer preview highlights…
One in nine online stores are leaking your data, says study
Categories: News Categories: Privacy Tags: Sansec Tags: leaky data Tags: online store leaks Tags: web skimming A recent study reveals that while users are comfortable shopping online, a number of online stores are accidentally leaking shoppers’ highly sensitive data. (Read…
New ESXiArgs encryption routine outmaneuvers recovery methods
Categories: News Categories: Ransomware Tags: ESXi Tags: ESXiArgs Tags: encryption routine The ransomware group behind the massive attack on ESXi Virtual Machines has come up with a new variant that can no longer be decrypted with the existing recovery script…
Malwarebytes recognized as endpoint security leader by G2
Categories: Business G2 has released their Winter 2023 reports, ranking Malwarebytes as the leader across a number of endpoint protection categories based on customer reviews. (Read more…) The post Malwarebytes recognized as endpoint security leader by G2 appeared first on…
A week in security (February 6 – 12)
Categories: News Tags: VMware ESXi Tags: Safer Internet Day Tags: Malwarebytes Mobile Security Tags: ION Tags: LockBit ransomware Tags: ransomware Tags: GoAnywhere Tags: Ryuk Tags: Malwarebytes Application Block Tags: BEC Tags: business email compromise Tags: fake Facebook Tags: Facebook Tags:…
What is AI good at (and what the heck is it, actually), with Josh Saxe: Lock and Code S04E04
Categories: Podcast This week on Lock and Code, we speak with Josh Saxe about artificial intelligence, machine learning, security, and where the three intersect. (Read more…) The post What is AI good at (and what the heck is it, actually),…
Jailbreaking ChatGPT and other large language models while we can
Categories: News Tags: ChatGPT Tags: DAN Tags: Bing Chat Tags: Chinese Tags: large language model Tags: jailbreak Large language models like ChatGPT are now being tested by the public and, no surprise here, researchers are finding ways to jailbreak the…
CISA issues alert with South Korean government about DPRK’s ransomware antics
Categories: News Categories: Ransomware Tags: CISA Tags: ransomware Tags: Democratic People’s Republic of Korea Tags: DPRK Tags: North Korea Tags: WannaCry Tags: EternalBlue Tags: Lazarus Group Tags: APT Tags: Magniber Tags: Magnitude exploit kit Tags: exploit kit Tags: EK Tags:…
French law to report cyberincidents within 3 days to become effective soon
Categories: News Tags: France Tags: law Tags: 72 hours Tags: cyberincident Tags: insurance A French law has been announced that requires victims of a cyberincident to report within 72 hours after discovery. We have heard similar proposals that may come…
Consent to gather data is a “misguided” solution, study reveals
Categories: News Categories: Privacy Tags: Annenberg School for Communication Tags: University of Pennsylvania Tags: informed consent Tags: digital consent Tags: Americans Can’t Consent to Companies’ Use of Their Data Tags: Lina M. Khan Tags: Federal Trade Commission Tags: Paul Schwartz…
$800,000 recovered from Business Email Compromise attack
Categories: News Tags: business email compromise Tags: wire transfer Tags: fraud Tags: scam Tags: BEC Tags: phish Tags: phishing Tags: malware We take a look at a business email compromise attack which nearly resulted in a very costly loss for…
Beware fake Facebook emails saying “your page has been disabled”
Categories: News Categories: Scams Tags: phish Tags: phishing Tags: facebook Tags: urgent Tags: disabled Tags: BBB Facebook users need to be on their guard for bogus emails claiming they’ve breached Facebook Community Standards. (Read more…) The post Beware fake Facebook…
Reddit breached, here’s what you need to know
Categories: News Tags: reddit Tags: compromise Tags: phish Tags: phishing Tags: users Tags: data Tags: 2FA In an admirably transparent notification, Reddit announced that one of its employees was phished. (Read more…) The post Reddit breached, here’s what you need…
KillNet hits healthcare sector with DDoS attacks
Categories: Cybercrime Categories: News Tags: KillNet Tags: CISA Tags: DDoS Tags: HC3 According to CISA, the pro-Russian KillNet group is actively targeting the US and European healthcare sectors with DDoS attacks. (Read more…) The post KillNet hits healthcare sector with…
Ryuk ransomware laundering leads to guilty plea
Categories: News Tags: ryuk Tags: ransomware Tags: guilty Tags: encrypt Tags: ransom Tags: cryptocurrency Tags: bitcoin We take a look at a guilty plea made in relation to Ryuk ransomware proceeds, and how you can best protect yourself from the…
Introducing Malwarebytes Application Block: How to block unauthorized software from executing on Windows endpoints
Categories: Business Application Block helps organizations easily thwart unwanted applications from launching on Windows endpoints. (Read more…) The post Introducing Malwarebytes Application Block: How to block unauthorized software from executing on Windows endpoints appeared first on Malwarebytes Labs. This article…
ION starts bringing customers back online after LockBit ransomware attack
Categories: News Categories: Ransomware Tags: LockBit Tags: ransomware Tags: LockBit ransomware group Tags: FBI Tags: Todd Conklin Tags: Financial Conduct Authority Tags: FCA Tags: Tags: Prudential Regulation Authority Tags: PRA Tags: Tom Kellermann Tags: Joseph Schifano Pernicious ransomware group, LockBit,…
Stalkerware-type app developers fined by NY Attorney General
Categories: News Tags: stalkerware Tags: mobile Tags: device Tags: NYAG Tags: monitoring Tags: New York Tags: app Tags: developer We take a look at news that the NYAG has penalised developers of stalkerware-type apps, and the ramifications for those developers…
Encrypted messaging service eavesdropped on by police, users arrested
Categories: News Tags: Exclu Tags: end-to-end encryption Tags: messaging Tags: encrypted Law enforcement eavesdropped on encrypted messaging service Exclu for five months before pulling the plug on it. (Read more…) The post Encrypted messaging service eavesdropped on by police, users…
Update now! GoAnywhere MFT zero-day patched
Categories: News Tags: GoAnywhere MFT Tags: managed file transfer Tags: Kevin Beaumont Tags: Brian Krebs Tags: emergency patch 7.1.2 Tags: Fortra Tags: Cobalt Strike Tags: Florian Hauser Tags: Code White A bug in GoAnywhere, a B2B management file transfer software,…
Ransomware review: February 2023
Categories: Ransomware Categories: Threat Intelligence Our Threat Intelligence team looks at known ransomware attacks by gang, country, and industry sector in January 2023, and looks at LockBit’s newest encryptor. (Read more…) The post Ransomware review: February 2023 appeared first on…
On the 20th Safer Internet Day, what was security like back in 2004?
Categories: News Tags: safer internet day Tags: SID Tags: 2004 Tags: 2005 Tags: 20th anniversary Tags: security Tags: windows Tags: XP Tags: XPSP2 Tags: 20 minutes Come with us on a journey down memory lane. (Read more…) The post On…
Florida hospital takes entire IT systems offline after ‘ransomware attack’
Categories: News Categories: Ransomware Tags: Tallahassee Memorial Tags: TMH Tags: Mark O’Bryant Tags: Max Henderson Tags: Atlantic General Hospital Tags: ransomware Tags: healthcare ransomware attack Tallahassee Memorial in Florida has reportedly been hit by a ransomware attack. (Read more…) The…
Introducing Malwarebytes Mobile Security for Business: How to find malware and stop phishing attacks on smartphones and ChromeOS
Categories: Business See how our new offering Malwarebytes Security for Business helps you crush mobile malware and phishing attacks. (Read more…) The post Introducing Malwarebytes Mobile Security for Business: How to find malware and stop phishing attacks on smartphones and…
A week in security (January 30 – February 5)
Categories: News Tags: week in security Tags: blog roundup Tags: Roomba Tags: Facebook Tags: Eileen Gun Tags: Lock and Code Tags: data wiper Tags: LearnPress Tags: Riot Games Tags: League of Legends Tags: malvertising Tags: dark patterns Tags: supply chain…
Two year old vulnerability used in ransomware attack against VMware ESXi
Categories: Exploits and vulnerabilities Categories: News Categories: Ransomware Tags: VMware Tags: ESXi Tags: Nevada Tags: ransomware Tags: Linux Tags: CVE-2021-21974 Over the weekend, several CERTs warned about ongoing ransomware attacks against unpatched VMware ESXi virtual machines. (Read more…) The post…
The rise of multi-threat ransomware
Categories: News Tags: ransomware Tags: malwarebytes Tags: youtube Tags: video Tags: multi-threat Tags: single threat Tags: double threat Tags: triple threat Tags: encrypt Tags: extortion Take a look at our ten minute video walkthrough of ransomware issues and concerns. (Read…
Cyberthreats facing UK finance sector “a national security threat”
Categories: Business Categories: News Tags: Financials Tags: fraud Tags: cybersecurity Tags: cooperation Tags: NatWest Tags: romance scam Tags: BEC scam Tags: NCP fraud Reports published about the UK financial industry show a growing number of cyberthreats and enormous losses to…
How the CISA catalog of vulnerabilities can help your organization
Categories: Exploits and vulnerabilities Categories: News The CISA catalog of known exploited vulnerabilities is designed for the federal government and useful to everyone. (Read more…) The post How the CISA catalog of vulnerabilities can help your organization appeared first on…
Business Email Compromise attack imitates vendors, targets supply chains
Categories: News Tags: BEC Tags: business email compromise Tags: email Tags: scam Tags: social engineer Tags: supply chain Tags: vendor Tags: accounting Tags: wire transfer We take a look at a smart social engineering ploy being used in Vendor Email…
How to protect your business from supply chain attacks
Categories: Business Categories: News Many have been calling attention to supply chain attacks for years. Is your business ready to listen? (Read more…) The post How to protect your business from supply chain attacks appeared first on Malwarebytes Labs. This…
Up to 10 million people potentially impacted by JD Sports breach
Categories: News Tags: JD Sports Tags: data breach Tags: stolen Tags: unauthorised Tags: access Tags: data Tags: customers Tags: phish Tags: social engineering We take a look at JD Sports revealing a breach which took place between 2018 and 2020,…
GitHub revokes several certificates after unauthorized access
Categories: News Tags: GitHub Tags: Atom Tags: Desktop for Mac Tags: Apple Developer ID Tags: certificates Tags: Digicert Tags: sunset After an unauthorized access incident, GitHub will revoke three certificates which will affect users of Atom and GitHub Desktop for…
Malwarebytes earns AV-TEST Top Product awards for fifth consecutive quarter
Categories: Business AV-TEST, a leading independent tester of cybersecurity solutions, has just ranked Malwarebytes as a Top Product for consumers and businesses for the fifth quarter in a row. (Read more…) The post Malwarebytes earns AV-TEST Top Product awards for…
Ransomware in December 2022
Categories: Threat Intelligence Our Threat Intelligence team looks at known ransomware attacks by gang, country, and industry sector in December 2022, and looks at why LockBit had to make a public apology (Read more…) The post Ransomware in December 2022…
Cybersecurity and privacy tips you can teach your 5+-year-old
Categories: Personal Tags: cybersecurity 101 Tags: online privacy 101 Are you smarter than a five-year-old? When it comes to online security and privacy, you should be. (Read more…) The post Cybersecurity and privacy tips you can teach your 5+-year-old appeared…
How to protect your business from supply chain attacks
Categories: Business Categories: News Many have been calling attention to supply chain attacks for years. Is your business ready to listen? (Read more…) The post How to protect your business from supply chain attacks appeared first on Malwarebytes Labs. This…
Up to 10 million people potentially impacted by JD Sports breach
Categories: News Tags: JD Sports Tags: data breach Tags: stolen Tags: unauthorised Tags: access Tags: data Tags: customers Tags: phish Tags: social engineering We take a look at JD Sports revealing a breach which took place between 2018 and 2020,…
GitHub revokes several certificates after unauthorized access
Categories: News Tags: GitHub Tags: Atom Tags: Desktop for Mac Tags: Apple Developer ID Tags: certificates Tags: Digicert Tags: sunset After an unauthorized access incident, GitHub will revoke three certificates which will affect users of Atom and GitHub Desktop for…
Malwarebytes earns AV-TEST Top Product awards for fifth consecutive quarter
Categories: Business AV-TEST, a leading independent tester of cybersecurity solutions, has just ranked Malwarebytes as a Top Product for consumers and businesses for the fifth quarter in a row. (Read more…) The post Malwarebytes earns AV-TEST Top Product awards for…
New data wipers deployed against Ukraine
Categories: News Tags: Data wipers Tags: Sandworm Tags: Ukraine Tags: Ukrinform CERT-UA says the Russian Sandworm group deployed data wipers against Ukrinform, Ukraine’s national news agency. (Read more…) The post New data wipers deployed against Ukraine appeared first on Malwarebytes…
Google sponsored ads malvertising targets password manager
Categories: News Tags: sponsored ads Tags: top results Tags: ad rank Tags: password manager Tags: 1password Our reserachers found a more direct way to go after your password by using Google sponsored ads campaigns (Read more…) The post Google sponsored…
40% of online shops tricking users with “dark patterns”
Categories: News Tags: dark patterns Tags: CPC Tags: EC Tags: web shops Tags: countdown timers Tags: hidden information Tags: subscriptions An investigation into 399 web shops by the European Commission and its partners found almost 40% of them using one…
A private moment, caught by a Roomba, ended up on Facebook. Eileen Guo explains how: Lock and Code S04E03
Categories: Podcast This week on Lock and Code, we speak with MIT Technology Review reporter Eileen Guo about how an image of a woman on a toilet—captured by a smart vacuum—ended up on Facebook. (Read more…) The post A private…
Update your LearnPress plugins now!
Categories: News Tags: wordpress Tags: learnpress Tags: vulnerability Tags: SQL Tags: injection Tags: update Tags: fix Tags: plugin Tags: patch We take a look at reports of a WordPress plugin issue. It’s been fixed, but you may need to update!…
Riot Games refuses to pay ransom to avoid League of Legends leak
Categories: News Tags: Riot Games Tags: 2K Games Tags: Rockstar Games Tags: social engineering Tags: phishing The Riot Games breach saga continues. (Read more…) The post Riot Games refuses to pay ransom to avoid League of Legends leak appeared first…
Analyzing and remediating a malware infested T95 TV box from Amazon
Categories: Android Categories: Threat Intelligence Find out why one of our Android experts has been obsessing over a little black box from Amazon. (Read more…) The post Analyzing and remediating a malware infested T95 TV box from Amazon appeared first…
Hive! Hive! Hive! Ransomware site submerged by FBI
Categories: News Categories: Ransomware Tags: DoJ Tags: FBI Tags: Europol Tags: HIve Tags: ransomware Tags: RDP Tags: Patch management Tags: Vulnerability Tags: phishing The DoJ, FBI, and Europol have released details about a months-long international disruption campaign against the Hive…
What happened in privacy in 2022
In 2022, privacy was upended for millions of people. Here are the biggest stories from last year. (Read more…) The post What happened in privacy in 2022 appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs…
“2.6 million DuoLingo account entries” up for sale
Categories: News Tags: duolingo Tags: data Tags: scraped Tags: API Tags: forum Tags: sale Tags: selling Tags: post Tags: user Tags: account Tags: info We take a look at claims of large amounts of DuoLingo user data up for sale,…
3 ways Malwarebytes helps you browse securely and privately online
Categories: Personal The Internet is kind of like the Wild West when it comes to threats to our privacy and security. But Malwarebytes can help you become the sheriff of your own digital frontier. (Read more…) The post 3 ways…
WhatsApp hijackers take over your account while you sleep
Categories: News Tags: WhatsApp Tags: Zuk Tags: @ihackbanme Tags: voicemail attack Tags: WhatsApp hack There’s an easy way to protect yourself. Here’s how. (Read more…) The post WhatsApp hijackers take over your account while you sleep appeared first on Malwarebytes…
CISA releases advice on how to safeguard K–12 organizations
Categories: Business Categories: News Tags: K-12 Tags: CISA Tags: NIST Tags: CSF Tags: CPG CISA’s released a report with recommendations on how to safeguard K–12 organizations from cybersecurity threats. (Read more…) The post CISA releases advice on how to safeguard…
5 facts about Vice Society, the ransomware group wreaking havoc on the education sector
Categories: Business In this article, we’ll arm you with five facts about Vice Society so you can get the upper-hand against this persistent education sector threat. (Read more…) The post 5 facts about Vice Society, the ransomware group wreaking havoc…
Grand Theft Auto 5 exploit allows cheaters to tamper with your data
Categories: News Tags: GTAV Tags: grand theft auto 5 Tags: game Tags: gaming Tags: rockstar Tags: exploit Tags: corruption Tags: profile Tags: data We take a look at reports of players having their GTAV data corrupted by exploiters. (Read more…)…
Consumer privacy and social media
Categories: News Categories: Privacy Tags: Social media Tags: privacy Tags: policies Tags: fines Tags: legislation Tags: scraping Tags: advertising Social media platforms are making a lot of money with targeted advertising. To improve the targeting, they want us much of…
Video game playing FISH live streams credit card ‘theft’
Categories: News Tags: fish Tags: video game Tags: stream Tags: credit card Tags: pokemon We take a look at an incredible tale of a fish who wouldn’t stop until it made a credit card purchase while streaming a video game.…
Key takeaways from Malwarebytes 2023 State of Mobile Cybersecurity
Categories: Business We asked 250 schools and hospitals about their mobile security posture, including Chromebooks. Here’s what we found out. (Read more…) The post Key takeaways from Malwarebytes 2023 State of Mobile Cybersecurity appeared first on Malwarebytes Labs. This article…
Riot Games compromised, new releases and patches halted
Categories: News Tags: Riot Games Tags: valorant Tags: league of legends Tags: compromise Tags: development Tags: patch Tags: patching Tags: update Riot Games has revealed that it has been compromised after a social engineering attack. (Read more…) The post Riot…
What privacy can get you
Categories: News Categories: Privacy For this year’s Data Privacy Day (and Data Privacy Week), we’re offering the most convenient advantages and benefits of privacy. (Read more…) The post What privacy can get you appeared first on Malwarebytes Labs. This article…
VASTFLUX ad fraud massively affected millions of iOS devices, dismantled
Categories: Apple Categories: News Tags: VASTFLUX Tags: HUMAN Tags: fast flux Tags: VAST Tags: Matryoshka Tags: JavaScript Tags: JS Tags: iOS Tags: ad fraud Tags: malvertising Tags: Video Ad Serving Template Tags: VAST Tags: command-and-control Tags: C2 An evasive ad…
Own an older iPhone? Check you’re on the latest version to avoid this bug
Categories: Apple Categories: Exploits and vulnerabilities Categories: News Tags: iOS 12.5.7 Tags: CVE-2022-42856 Tags: type confusion Tags: WebKit Apple has now released security content for iOS 12.5.7 which includes a patch for an actively exploited vulnerability in WebKit and many…
A week in security (January 16—22)
Categories: News Tags: Google Tags: Rust Tags: Chromium Tags: Mailchimp Tags: SweepWizard Tags: bossware Tags: TikTok Tags: surveillance firm Tags: Voyager Labs Tags: TracketPacer Tags: Facebook Tags: Instagram Tags: Vice Society Tags: Liquor Control Board of Ontario Tags: Zoho ManageEngine…
T-Mobile reports data theft of 37 million customers in the US
Categories: News Tags: T-Mobile Tags: 37 million Tags: data breach Tags: k-8 T-Mobile has disclosed that an attacker was able to obtain the information of approximately 37 million US customers. (Read more…) The post T-Mobile reports data theft of 37…
Ransomware revenue significantly down over 2022
Categories: News Categories: Ransomware Tags: ransomware Tags: revenue Tags: attacks Tags: negotiators Tags: back-ups Tags: restore Tags: Continental According to blockchain data platform Chainanalysis, ransomware revenue plummeted significantly in 2022 due to a growing unwillingness to pay. (Read more…) The…
Microsoft to end direct sale of Windows 10 licenses at the end of January
Categories: News Tags: windows 10 Tags: windows 11 Tags: microsoft Tags: license Tags: sale Tags: third party Tags: desktop Tags: upgrade Tags: hardware We take a look at reports that Microsoft will shortly be ending the direct sale of Windows…
TikTok CEO told to “step up efforts to comply” with digital laws
Categories: News Categories: Privacy Tags: TikTok Tags: Shou Zi Chew Tags: Thierry Breton Tags: EU Commissioner Tags: Digital Markets Act Tags: DMA Tags: Digital Services Act Tags: DSA Tags: Vera Jourova Tags: Caroline Greer Tags: GDPR Tags: General Data Protection…
4 ways to protect your privacy while scrolling
Categories: News Categories: Privacy Tags: Privacy Tags: browser Tags: VPN Tags: BrowserGuard For every level of privacy awareness, there are layers you can use to protect yourself. Here are four suggestions. (Read more…) The post 4 ways to protect your…
Ransomware money laundering operation disrupted, founder arrested
Categories: News Categories: Ransomware Tags: Cryptocurrency exchange Tags: Bitzlato Tags: Conti Tags: ransomware Tags: Hydra Tags: dark web marketplace The China-based cryptocurrency exchange Bitzlato is accused of processing over $700 million of illicit funds. (Read more…) The post Ransomware money…
Credit card fraud group member could get up to 30 years in jail
Categories: News Tags: new york Tags: card fraud Tags: credit card Tags: US Tags: credit cards We take a look at a New York based credit card fraud group, and see how the justice system is slowly taking it to…
Mailchimp breach feels like deja vu
Categories: News Tags: Mailchimp Tags: social engineering Tags: targete attack Email marketing provider Mailchimp has been breached again, nine months after it was compromised last year. (Read more…) The post Mailchimp breach feels like deja vu appeared first on Malwarebytes…
Google sponsored ads lead to rogue imitation sites
Categories: News Tags: google Tags: ads Tags: advert Tags: paid Tags: sponsored Tags: result Tags: listing Tags: rogue Tags: malware Tags: NFT Tags: phish Tags: phishing Tags: data theft Tags: infostealer We take a look at a flurry of reports…
LastPass users should move their crypto funds, experts warn
Categories: News Tags: LastPass Tags: breach Tags: cryptocurrency Tags: unencrypted data Tags: vault Tags: secret key Tags: lawsuit Experts are warning LastPass users to move their crypto funds since there are plenty of indications that the breach is actively being…
Update now! Two critical flaws in Git’s code found, patched
CVE-2022-23521 and CVE-2022-41903 are critical flaws present in Git’s code. Thankfully, they’ve been addressed in its latest version. (Read more…) The post Update now! Two critical flaws in Git’s code found, patched appeared first on Malwarebytes Labs. This article has…
A week in security (January 9—15)
Categories: News Tags: AWIS Tags: weekly blog roundup Tags: week in security Tags: Slack Tags: GitHub Tags: Magecart Tags: Microsoft Tags: Pokemon NFT Tags: Facebook Tags: Instagram Tags: Snapchat Tags: TikTok Tags: YouTube Tags: Google Tags: Meta Tags: identity theft…
CircleCI: Malware stole GitHub OAuth keys, bypassing 2FA
CircleCI, a big name in the DevOps space, has released an incident report about a data breach it experienced early this month. (Read more…) The post CircleCI: Malware stole GitHub OAuth keys, bypassing 2FA appeared first on Malwarebytes Labs. This…
Web skimmer found on website of Liquor Control Board of Ontario
LCBO account holders are under advice to schange their passwords and monitor their credit card statements after a web skimmer was found on the webiste (Read more…) The post Web skimmer found on website of Liquor Control Board of Ontario…
University suffers leaks, shutdowns at the hands of Vice Society
Categories: News Tags: vice society Tags: ransomware Tags: university Tags: leak Tags: data Tags: locked Tags: encrypted Tags: We take a look at the devastating impact of a ransomware attack on a University which includes leaks and network destruction. (Read…
Update now! Proof of concept code to be released for Zoho ManageEngine vulnerability
Categories: Exploits and vulnerabilities Categories: News Tags: Zoho Tags: ManageEngine Tags: PoC Tags: RCE Tags: CVE-2022-47966 Tags: CVE-2022-35405 Tags: SAML Tags: Apache Santuario Proof of Concept code is about to be released for a vulnerability in many ManageEngine products which…
Google to support the use of Rust in Chromium
Categories: News Tags: Google Tags: Chromium Tags: Rust Tags: memory safety Tags: rule of two Google has announced that it will support the use of third-party Rust libraries in Chromium which is a step forward in memory safety for the…
Law enforcement app SweepWizard leaks data on crime suspects
Categories: News Tags: Erik McCauley Tags: SweetWizard Tags: law enforcement app Tags: ODIN Intelligence Tags: Wired SweepWizard, an app designed to assist law enforcement is causing a bit of trouble, was found inadvertently leaking sweeping data for years. (Read more…)…
Accountant ordered to pay ex-employer after bossware shows “time theft”
Categories: News Tags: Karlee Besse Tags: Reach CPA Tags: time theft Tags: bossware Tags: TimeCamp Tags: Court Order Interest Act Tags: COIA Tags: Civil Resolution Tribunal Tags: CRT Bossware helped an employer fire an accountant for not working during work…
TikTok dances to the tune of $5.4m cookie fine
Categories: News Tags: tiktok Tags: fine Tags: cookie Tags: consent Tags: opt out Tags: France Tags: CNIL We take a look at the latest fine hitting a social media network, this time over the issue of cookie consent. (Read more…)…
“Untraceable” surveillance firm sued for scraping Facebook and Instagram data
Categories: News Tags: Voyager Labs Tags: Facebook Tags: Instagram Tags: Meta Tags: surveillance tool Tags: data scraping Voyager Labs, a surveillance firm, allegedly created thousands of Facebook and Instagram accounts so it could use its scraping tool to steal data.…
Fighting technology’s gender gap with TracketPacer: Lock and Code S04E02
Categories: Podcast This week on Lock and Code, we speak with Lexie Cooper, the owner behind the TikTok account TrackerPacer, about the vitriol she faced online after talking about the gender gap in technology. (Read more…) The post Fighting technology’s…
Multiple schools hit by Vice Society ransomware attack
Categories: News Tags: ransomware Tags: high society Tags: compromise Tags: school Tags: schools Tags: learning Tags: documents Tags: data Tags: leak We take a look at reports of 14 schools being compromised by ransomware group Vice Society. (Read more…) The…
Timely patching is good, but sometimes it’s not enough
Categories: News Categories: Ransomware Tags: Lorenz Tags: ransomware Tags: CVE-2022-29499 Tags: Mitel Tags: backdoor Tags: web shell A recent case-study showed once again that timely patching is important, but it’s not a silver bullet for stopping ransomware. (Read more…) The…
3 ways Malwarebytes helps you browse securely and privately online
Categories: Personal The Internet is kind of like the Wild West when it comes to threats to our privacy and security. But Malwarebytes can help you become the sheriff of your own digital frontier. (Read more…) The post 3 ways…
US Department of the Interior’s passwords “easily cracked”
Categories: News Tags: US department of the interior Tags: password Tags: hashes Tags: cracking Tags: requirements Tags: MFA A recent audit cracked 21 percent of the department’s passwords. (Read more…) The post US Department of the Interior’s passwords “easily cracked”…
Update now! Patch Tuesday January 2023 includes one actively exploited vulnerability
Categories: Exploits and vulnerabilities Categories: News Tags: patch Tuesday Tags: CVE-2023-21674 Tags: APLC Tags: CVE-2023-21743 Tags: Sharepoint Tags: CVE-2023-21563 Tags: BitLocker The second Tuesday of the year brings us many updates, including one for an actively exploited vulnerability that could…
WhatsApp lawsuit against NSO Group greenlit by Supreme Court
Categories: News Tags: Pegasus Tags: spyware Tags: Pegasus spyware Tags: NSO Group Tags: NSO Tags: Apple Tags: WhatsApp Tags: Meta Tags: Foreign Sovereign Immunity Act The US Supreme Court essentially gave Meta’s WhatsApp the go ahead to pursue their case…
Identity thieves bypass security questions to access Experian credit reports
Categories: News Tags: Experian Tags: credit reports Tags: freeze Identity thieves were aware of a method to access full credit reports at Experian using just your social security number and some basic information. (Read more…) The post Identity thieves bypass…
Maternal & Family Health Services discloses ransomware attack months after discovery
Categories: News Categories: Ransomware Tags: Maternal and Family Health Services Tags: MFHS A US health and human services organization recently revealed it was a victim of a ransomware attack that likely happened between August 2021 and April 2022. (Read more…)…
5 must-haves for K-12 cybersecurity
Categories: Business Over the years, cyberattacks on K-12 schools and districts have steadily increased and in 2022 that trend only continued. In this post, we’ll look at the 5 must-haves for K-12 cybersecurity. (Read more…) The post 5 must-haves for…