Category: Malwarebytes Labs

Arris router vulnerability could lead to complete takeover

Categories: Exploits and vulnerabilities Categories: News Tags: Yerodin Richards Tags: Arris Tags: routre Tags: CVE-2022-45701 Tags: default credentials A security researcher found an authenticated remote code execution vulnerability in very wide-spread Arris router models. (Read more…) The post Arris router…

Ransomware pushes City of Oakland into state of emergency

Categories: News Categories: Ransomware Tags: Oakland Tags: ransomware Tags: state of emergency The Interim City Administrator of the City of Oakland declared a state of emergency.after a ransomware attack crippled the city’s services a week ago (Read more…) The post…

Update now! Apple patches vulnerabilities in MacOS and iOS

Categories: Apple Categories: Exploits and vulnerabilities Tags: Apple Tags: macOS Ventura Tags: 13.2.1 Tags: iOS Tags: iPadOS Tags: 16.3.1 Tags: CVE-2023-23514 Tags: CVE-2023-23522 Tags: CVE-2023-23529 Tags: use after free Tags: type confusion Apple has released patches for macOS Ventura, iPadOs,…

Update now! February’s Patch Tuesday tackles three zero-days

Categories: Exploits and vulnerabilities Categories: News Tags: patch Tuesday Tags: Microsoft Tags: Apple Tags: Adobe Tags: SAP Tags: Citrix Tags: Cisco Tags: Atlassian Tags: Google Tags: Mozilla Tags: Forta Tags: OpenSSH Tags: CVE-2023-21823 Tags: CVE-2023-21715 Tags: OneNote Tags: CVE-2023-23376 Tags:…

Should you share passwords with your partner?

Categories: Personal Tags: love and passwords Tags: password sharing with partner Tags: privacy This Valentine’s Day, we ask the inevitable password question: is it okay to share passwords with your partner? (Read more…) The post Should you share passwords with…

One in nine online stores are leaking your data, says study

Categories: News Categories: Privacy Tags: Sansec Tags: leaky data Tags: online store leaks Tags: web skimming A recent study reveals that while users are comfortable shopping online, a number of online stores are accidentally leaking shoppers’ highly sensitive data. (Read…

Malwarebytes recognized as endpoint security leader by G2

Categories: Business G2 has released their Winter 2023 reports, ranking Malwarebytes as the leader across a number of endpoint protection categories based on customer reviews. (Read more…) The post Malwarebytes recognized as endpoint security leader by G2 appeared first on…

A week in security (February 6 – 12)

Categories: News Tags: VMware ESXi Tags: Safer Internet Day Tags: Malwarebytes Mobile Security Tags: ION Tags: LockBit ransomware Tags: ransomware Tags: GoAnywhere Tags: Ryuk Tags: Malwarebytes Application Block Tags: BEC Tags: business email compromise Tags: fake Facebook Tags: Facebook Tags:…

Reddit breached, here’s what you need to know

Categories: News Tags: reddit Tags: compromise Tags: phish Tags: phishing Tags: users Tags: data Tags: 2FA In an admirably transparent notification, Reddit announced that one of its employees was phished. (Read more…) The post Reddit breached, here’s what you need…

KillNet hits healthcare sector with DDoS attacks

Categories: Cybercrime Categories: News Tags: KillNet Tags: CISA Tags: DDoS Tags: HC3 According to CISA, the pro-Russian KillNet group is actively targeting the US and European healthcare sectors with DDoS attacks. (Read more…) The post KillNet hits healthcare sector with…

Ryuk ransomware laundering leads to guilty plea

Categories: News Tags: ryuk Tags: ransomware Tags: guilty Tags: encrypt Tags: ransom Tags: cryptocurrency Tags: bitcoin We take a look at a guilty plea made in relation to Ryuk ransomware proceeds, and how you can best protect yourself from the…

Update now! GoAnywhere MFT zero-day patched

Categories: News Tags: GoAnywhere MFT Tags: managed file transfer Tags: Kevin Beaumont Tags: Brian Krebs Tags: emergency patch 7.1.2 Tags: Fortra Tags: Cobalt Strike Tags: Florian Hauser Tags: Code White A bug in GoAnywhere, a B2B management file transfer software,…

Ransomware review: February 2023

Categories: Ransomware Categories: Threat Intelligence Our Threat Intelligence team looks at known ransomware attacks by gang, country, and industry sector in January 2023, and looks at LockBit’s newest encryptor. (Read more…) The post Ransomware review: February 2023 appeared first on…

A week in security (January 30 – February 5)

Categories: News Tags: week in security Tags: blog roundup Tags: Roomba Tags: Facebook Tags: Eileen Gun Tags: Lock and Code Tags: data wiper Tags: LearnPress Tags: Riot Games Tags: League of Legends Tags: malvertising Tags: dark patterns Tags: supply chain…

The rise of multi-threat ransomware

Categories: News Tags: ransomware Tags: malwarebytes Tags: youtube Tags: video Tags: multi-threat Tags: single threat Tags: double threat Tags: triple threat Tags: encrypt Tags: extortion Take a look at our ten minute video walkthrough of ransomware issues and concerns. (Read…

How to protect your business from supply chain attacks

Categories: Business Categories: News Many have been calling attention to supply chain attacks for years. Is your business ready to listen? (Read more…) The post How to protect your business from supply chain attacks appeared first on Malwarebytes Labs. This…

Ransomware in December 2022

Categories: Threat Intelligence Our Threat Intelligence team looks at known ransomware attacks by gang, country, and industry sector in December 2022, and looks at why LockBit had to make a public apology (Read more…) The post Ransomware in December 2022…

How to protect your business from supply chain attacks

Categories: Business Categories: News Many have been calling attention to supply chain attacks for years. Is your business ready to listen? (Read more…) The post How to protect your business from supply chain attacks appeared first on Malwarebytes Labs. This…

New data wipers deployed against Ukraine

Categories: News Tags: Data wipers Tags: Sandworm Tags: Ukraine Tags: Ukrinform CERT-UA says the Russian Sandworm group deployed data wipers against Ukrinform, Ukraine’s national news agency. (Read more…) The post New data wipers deployed against Ukraine appeared first on Malwarebytes…

Update your LearnPress plugins now!

Categories: News Tags: wordpress Tags: learnpress Tags: vulnerability Tags: SQL Tags: injection Tags: update Tags: fix Tags: plugin Tags: patch We take a look at reports of a WordPress plugin issue. It’s been fixed, but you may need to update!…

Hive! Hive! Hive! Ransomware site submerged by FBI

Categories: News Categories: Ransomware Tags: DoJ Tags: FBI Tags: Europol Tags: HIve Tags: ransomware Tags: RDP Tags: Patch management Tags: Vulnerability Tags: phishing The DoJ, FBI, and Europol have released details about a months-long international disruption campaign against the Hive…

What happened in privacy in 2022

In 2022, privacy was upended for millions of people. Here are the biggest stories from last year. (Read more…) The post What happened in privacy in 2022 appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs…

WhatsApp hijackers take over your account while you sleep

Categories: News Tags: WhatsApp Tags: Zuk Tags: @ihackbanme Tags: voicemail attack Tags: WhatsApp hack There’s an easy way to protect yourself. Here’s how. (Read more…) The post WhatsApp hijackers take over your account while you sleep appeared first on Malwarebytes…

CISA releases advice on how to safeguard K–12 organizations

Categories: Business Categories: News Tags: K-12 Tags: CISA Tags: NIST Tags: CSF Tags: CPG CISA’s released a report with recommendations on how to safeguard K–12 organizations from cybersecurity threats. (Read more…) The post CISA releases advice on how to safeguard…

Consumer privacy and social media

Categories: News Categories: Privacy Tags: Social media Tags: privacy Tags: policies Tags: fines Tags: legislation Tags: scraping Tags: advertising Social media platforms are making a lot of money with targeted advertising. To improve the targeting, they want us much of…

Riot Games compromised, new releases and patches halted

Categories: News Tags: Riot Games Tags: valorant Tags: league of legends Tags: compromise Tags: development Tags: patch Tags: patching Tags: update Riot Games has revealed that it has been compromised after a social engineering attack. (Read more…) The post Riot…

What privacy can get you

Categories: News Categories: Privacy For this year’s Data Privacy Day (and Data Privacy Week), we’re offering the most convenient advantages and benefits of privacy. (Read more…) The post What privacy can get you appeared first on Malwarebytes Labs. This article…

A week in security (January 16—22)

Categories: News Tags: Google Tags: Rust Tags: Chromium Tags: Mailchimp Tags: SweepWizard Tags: bossware Tags: TikTok Tags: surveillance firm Tags: Voyager Labs Tags: TracketPacer Tags: Facebook Tags: Instagram Tags: Vice Society Tags: Liquor Control Board of Ontario Tags: Zoho ManageEngine…

Ransomware revenue significantly down over 2022

Categories: News Categories: Ransomware Tags: ransomware Tags: revenue Tags: attacks Tags: negotiators Tags: back-ups Tags: restore Tags: Continental According to blockchain data platform Chainanalysis, ransomware revenue plummeted significantly in 2022 due to a growing unwillingness to pay. (Read more…) The…

4 ways to protect your privacy while scrolling

Categories: News Categories: Privacy Tags: Privacy Tags: browser Tags: VPN Tags: BrowserGuard For every level of privacy awareness, there are layers you can use to protect yourself. Here are four suggestions. (Read more…) The post 4 ways to protect your…

Ransomware money laundering operation disrupted, founder arrested

Categories: News Categories: Ransomware Tags: Cryptocurrency exchange Tags: Bitzlato Tags: Conti Tags: ransomware Tags: Hydra Tags: dark web marketplace The China-based cryptocurrency exchange Bitzlato is accused of processing over $700 million of illicit funds. (Read more…) The post Ransomware money…

Mailchimp breach feels like deja vu

Categories: News Tags: Mailchimp Tags: social engineering Tags: targete attack Email marketing provider Mailchimp has been breached again, nine months after it was compromised last year. (Read more…) The post Mailchimp breach feels like deja vu appeared first on Malwarebytes…

Google sponsored ads lead to rogue imitation sites

Categories: News Tags: google Tags: ads Tags: advert Tags: paid Tags: sponsored Tags: result Tags: listing Tags: rogue Tags: malware Tags: NFT Tags: phish Tags: phishing Tags: data theft Tags: infostealer We take a look at a flurry of reports…

LastPass users should move their crypto funds, experts warn

Categories: News Tags: LastPass Tags: breach Tags: cryptocurrency Tags: unencrypted data Tags: vault Tags: secret key Tags: lawsuit Experts are warning LastPass users to move their crypto funds since there are plenty of indications that the breach is actively being…

Update now! Two critical flaws in Git’s code found, patched

CVE-2022-23521 and CVE-2022-41903 are critical flaws present in Git’s code. Thankfully, they’ve been addressed in its latest version. (Read more…) The post Update now! Two critical flaws in Git’s code found, patched appeared first on Malwarebytes Labs. This article has…

A week in security (January 9—15)

Categories: News Tags: AWIS Tags: weekly blog roundup Tags: week in security Tags: Slack Tags: GitHub Tags: Magecart Tags: Microsoft Tags: Pokemon NFT Tags: Facebook Tags: Instagram Tags: Snapchat Tags: TikTok Tags: YouTube Tags: Google Tags: Meta Tags: identity theft…

Google to support the use of Rust in Chromium

Categories: News Tags: Google Tags: Chromium Tags: Rust Tags: memory safety Tags: rule of two Google has announced that it will support the use of third-party Rust libraries in Chromium which is a step forward in memory safety for the…

Law enforcement app SweepWizard leaks data on crime suspects

Categories: News Tags: Erik McCauley Tags: SweetWizard Tags: law enforcement app Tags: ODIN Intelligence Tags: Wired SweepWizard, an app designed to assist law enforcement is causing a bit of trouble, was found inadvertently leaking sweeping data for years. (Read more…)…

TikTok dances to the tune of $5.4m cookie fine

Categories: News Tags: tiktok Tags: fine Tags: cookie Tags: consent Tags: opt out Tags: France Tags: CNIL We take a look at the latest fine hitting a social media network, this time over the issue of cookie consent. (Read more…)…

Multiple schools hit by Vice Society ransomware attack

Categories: News Tags: ransomware Tags: high society Tags: compromise Tags: school Tags: schools Tags: learning Tags: documents Tags: data Tags: leak We take a look at reports of 14 schools being compromised by ransomware group Vice Society. (Read more…) The…

Timely patching is good, but sometimes it’s not enough

Categories: News Categories: Ransomware Tags: Lorenz Tags: ransomware Tags: CVE-2022-29499 Tags: Mitel Tags: backdoor Tags: web shell A recent case-study showed once again that timely patching is important, but it’s not a silver bullet for stopping ransomware. (Read more…) The…

5 must-haves for K-12 cybersecurity

Categories: Business Over the years, cyberattacks on K-12 schools and districts have steadily increased and in 2022 that trend only continued. In this post, we’ll look at the 5 must-haves for K-12 cybersecurity. (Read more…) The post 5 must-haves for…