Tag: Malwarebytes Labs

Baby monitor safety: What you need to know

Categories: Personal Tags: baby Tags: monitor Tags: wi-fi Tags: wireless Tags: cam Tags: webcam Tags: camera Tags: DECT Tags: FHSS Tags: cloud Tags: storage Tags: secure Tags: safety Tags: password We take a look at some of the options available…

Update now! ASUS fixes nine security flaws

Categories: Exploits and vulnerabilities Categories: News Tags: ASUS Tags: router Tags: models Tags: CVE-2022-26376 Tags: CVE-2018-1160 Tags: Netatalk Tags: disable WAN ASUS has released firmware updates for several router models fixing two critical and several other security issues. (Read more…)…

A week in security (June 12 – 18)

Categories: News Tags: week Tags: security Tags: june 2023 A list of topics we covered in the week of June 12 to June 18 of 2023 (Read more…) The post A week in security (June 12 – 18) appeared first…

Phishing scam takes $950k from DoorDash drivers

Categories: Business Tags: door dash Tags: delivery Tags: phish Tags: phishing Tags: scam Tags: fake Tags: fraud Tags: theft Tags: call Tags: support Tags: phone We take a look at a phishing scam that cost 700 DoorDash drivers a combined…

Fake security researchers push malware files on GitHub

Categories: News Tags: GitHub Tags: malware Tags: repository Tags: security researcher Tags: fake Tags: download Tags: scam Tags: twitter Tags: social We take a look at reports of fake security researchers offering up malware downloads via GitHub repositories. (Read more…)…

MOVEit discloses THIRD critical vulnerability

Categories: Exploits and vulnerabilities Categories: News Categories: Ransomware Tags: Progress Tags: Moveit Tags: CVE-2023-34362 Tags: CVE-2023-35036 Tags: Cl0p Progress has released an advisory about yet another MOVEit Transfer vulnerability while new victims of the first one keep emerging. (Read more…)…

Ticket scammers target Taylor Swift tour

Categories: Personal Tags: Taylor Tags: swift Tags: eras Tags: music Tags: gig Tags: concert Tags: tour Tags: scam Tags: ticket Tags: reseller Tags: fraud Tags: fake We take a look at multiple reports of ticket reseller fraud aimed at fans…

Microsoft fixes six critical vulnerabilities in June Patch Tuesday

Categories: Exploits and vulnerabilities Categories: News Tags: Microsoft Tags: patch Tuesday Tags: CVE-2023-29357 Tags: CVE-2023-29363 Tags: CVE-2023-32014 Tags: CVE-2023-32015 Tags: CVE-2023-32013 Tags: CVE-2023-24897 Tags: CVE-2023-32031 Tags: SharePoint Tags: PGM Tags: Exchange Tags: Hyper-V Patch Tuesday of June 2023 is relatively…

Edge browser feature sends images you view back to Microsoft

Categories: News Tags: Edge Tags: Enhance images Tags: super resolution Tags: content creators A new Edge feature labelled ‘Enhance images in Microsoft Edge’ has raised some privacy concerns because it sends information to Microsoft. (Read more…) The post Edge browser…

A week in security (June 5 – 11)

Categories: News Tags: week in security A list of topics we covered in the week of June 5 to June 11 of 2023 (Read more…) The post A week in security (June 5 – 11) appeared first on Malwarebytes Labs.…

Public and free WiFi: Can I safely use it?

Categories: News Categories: Personal Tags: Free Tags: public Tags: WiFi Tags: HTTPS Tags: TLS Tags: VPN The Internet has changed. A lot. Does that make it safer to use public, free WiFi? (Read more…) The post Public and free WiFi:…

Strava heatmap loophole may reveal users’ home addresses

Categories: Personal Tags: strava Tags: fitness Tags: health Tags: run Tags: running Tags: jog Tags: jogging Tags: jogger Tags: cycling Tags: bike Tags: race Tags: data Tags: anonymous Tags: anonymise Tags: location Tags: map Tags: heatmap Anonymous data on fitness…

VMware patches critical vulnerabilities in Aria Operations for Networks

Categories: Exploits and vulnerabilities Categories: News Tags: cve-2023-20887 Tags: cve-2023-20888 Tags: cve-2023-20889 Tags: vmware Tags: Aria Operations for Networks Tags: RCE Tags: information disclosure Tags: deserialization Tags: command injection VMware has released security updates to fix a trio of flaws…

Ransomware review: June 2023

Categories: Ransomware Categories: Threat Intelligence May saw a record number of 556 reported ransomware victims, the unusual emergence of Italy and Russia as major targets, and a significant rise in attacks on the education sector. (Read more…) The post Ransomware…

Facebook clickbait leads to money scam for users

Categories: Threat Intelligence Tags: facebook Tags: posts Tags: google Tags: cloud run Clickbait posts on Facebook can lead to malicious websites. In this campaign, crooks are redirecting Facebook victims to scam pages hosted on Google’s infrastructure. (Read more…) The post…

5 unusual cybersecurity tips that actually work

Categories: Personal It’s time to shake off that special feeling, start lying, forget everything you’ve been told about passwords, spin up a million email addresses, and start throwing away computers for fun. (Read more…) The post 5 unusual cybersecurity tips…

Update now! MOVEit Transfer vulnerability actively exploited

Categories: Exploits and vulnerabilities Categories: News Tags: Progress Tags: MOVEit Tags: vulnerability Tags: human2.aspx A critical vulnerability in Progress MOVEit Transfer is being used to steal large amounts of data (Read more…) The post Update now! MOVEit Transfer vulnerability actively…

Amazon’s Ring cameras were used to spy on customers

Categories: News Categories: Personal It’s what we all feared, but hoped wouldn’t be the case. (Read more…) The post Amazon’s Ring cameras were used to spy on customers appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

US hospital forced to divert ambulances after cyberattack

Categories: News Categories: Ransomware Tags: Idaho Tags: hospital Tags: cyberattack Tags: virus Tags: ransomware The Idaho Falls Community Hospital fell victim to a cyberattack on Monday and had to divert ambulances to nearby hospitals and close some of its clinics.…

Microsoft gives Apple a migraine

Categories: Exploits and vulnerabilities Categories: News Tags: Apple Tags: macOS Tags: Ventura 13.4 Tags: Monterey 12.6.6 Tags: Big Sur 11.7.7 Tags: libxpc Tags: SIP Tags: XPC Tags: NVRAM Tags: CVE-2023-32369 Tags: Migraine Microsoft has released details about a vulnerability that…

A week in security (May 22-28)

Categories: News Tags: Cisco Tags: Zyxel Tags: ChatGPT Tags: Malvertising Tags: Apple Tags: Google Tags: insider threat Tags: Pentagon explosion Tags: CISA Tags: ransomware guide Tags: Rheinmetall Tags: BlackBasta Tags: WordPress A list of topics we covered in the week…

Zyxel patches two critical vulnerabilities

Categories: Exploits and vulnerabilities Categories: News Zyxel has released a security advisory about two critical vulnerabilities that could allow an unauthorized, remote attacker to take control of its firewall devices. (Read more…) The post Zyxel patches two critical vulnerabilities appeared…

CISA updates ransomware guidance

Categories: News Categories: Ransomware Tags: CISA Tags: StopRansomware Tags: guide Tags: ZTA Tags: compromised Tags: cloud Tags: MDR CISA has updated its #StopRansomware guide to account for changes in ransomware tactics and techniques. (Read more…) The post CISA updates ransomware…

Rheinmetall attacked by BlackBasta ransomware

Categories: News Categories: Ransomware Tags: Rheinmetall Tags: BlackBasta Tags: ransomware A cyberattack on arms manufacturer Rheinmetall has been claimed by the BlackBasta ransomware group on its leak site. (Read more…) The post Rheinmetall attacked by BlackBasta ransomware appeared first on…

Malvertising via brand impersonation is back again

Categories: Threat Intelligence Tags: malvertising Tags: google Tags: ads Tags: amazon Tags: cloaking Ads containing the official website of an impersonated brand are running again, allowing fraudsters to scam users. (Read more…) The post Malvertising via brand impersonation is back…

Update now! Apple issues patches for three actively used zero-days

Categories: Exploits and vulnerabilities Categories: News Tags: Apple Tags: RSR Tags: CVE-2023-32409 Tags: CVE-2023-28204 Tags: CVE-2023-32373 Tags: out of bounds Tags: use after free Apple issued information about patches against three actively exploited zero-days in WebKit. One vulnerability is new,…

A week in security (May 15-21)

Categories: News Tags: Week in security Tags: May 2023 The most interesting security-related news of the week from May 15-21. (Read more…) The post A week in security (May 15-21) appeared first on Malwarebytes Labs. This article has been indexed…

ChatGPT: Cybersecurity friend or foe?

Categories: Business There are a lot of benefits to ChatGPT, but many in the security community have concerns about it. Malwarebytes’ CEO Marcin Kleczynski takes a deep dive into the topic. (Read more…) The post ChatGPT: Cybersecurity friend or foe?…

Webinar recap: EDR vs MDR for business success

Categories: Business Learn more about EDR and MDR and which is right for your business. (Read more…) The post Webinar recap: EDR vs MDR for business success appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs…

KeePass vulnerability allows attackers to access the master password

Categories: Exploits and vulnerabilities Categories: News Categories: Personal Tags: KeePass Tags: memory dump Tags: CVE-2023-32784 There is a Proof-of-Concept available for an unpatched vulnerability in KeePass that allows attackers to dump the master password. (Read more…) The post KeePass vulnerability…

Child safety app riddled with vulnerabilities: Update now!

Categories: Personal Tags: Parental control kids place Tags: child Tags: safety Tags: controls Tags: restrict. block Tags: limit Tags: vulnerability Tags: exploit Tags: password Tags: upload Tags: dashboard Child safety app Parental Control – Kids Place has been found to…

Zip domains, a bad idea nobody asked for

Categories: News Just, why? (Read more…) The post Zip domains, a bad idea nobody asked for appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article: Zip domains, a bad idea nobody asked…

PharMerica breach impacts almost 6 million people

Categories: News Categories: Ransomware Tags: PharMerica Tags: Money Message Tags: ransomware Tags: PII Tags: SSN US pharmacy giant PharMerica has reported a cybersecurity incident that affects over 5.8 million people. The data theft has been claimed by ransomware group Money…

Leaked Babuk ransomware builder code lives on as RA Group

Categories: News Tags: ransomware Tags: RA Group Tags: babuk Tags: code Tags: leaked Tags: encrypted Tags: stolen Tags: exfiltrated Tags: ransom Tags: hijack Tags: blackmail Tags: double extortion Tags: leak Tags: sell We take a look at yet another ransomware…

3 reasons to use a VPN

Categories: Personal Categories: Privacy Tags: VPN Tags: Privacy Tags: always on Tags: location Tags: sensitive information Most VPN users can be put in one of three categories. It all depends on your needs and your threat model. (Read more…) The…

A week in security (May 8-14)

Categories: News Tags: YouTube Tags: ad block Tags: sponsored tweets Tags: Twitter Tags: fake BBC News Tags: AVLab assessment Tags: Google Tags: Google Passkey Tags: MSP Tags: Patch Tuesday Tags: Discord Tags: RedStinger Tags: tech support scam Tags: Aurora stealer…

Why we should be more open about ransomware attacks

Categories: News Categories: Ransomware Tags: ransomware Tags: data breach Tags: dark web Tags: share information Paying the ransom and not saying a word about what happened is what cybercriminals would like us all to do. (Read more…) The post Why…

Windows 11 is showing its first signs of Rust

Categories: News Tags: Windows 11 Tags: OS Tags: operating system Tags: programming language Tags: rust Tags: C Tags: C++ Tags: kernel Tags: buffer overflow We take a look at the slow introduction of programming language Rust into the Windows 11…

YouTube is testing ad blocker detection

Categories: News Categories: Personal Tags: youtube Tags: ad Tags: advert Tags: network Tags: ad industry Tags: block Tags: blocker Tags: adblock Tags: malware Tags: malvertising Tags: intrusive Tags: popup Tags: affiliate We take a look at YouTube’s testing of ad…

Google Passkeys: How to create one and when you shouldn’t

Categories: News Tags: Google passkey Tags: passkey Tags: passwordless future Tags: passwordless Tags: phishing Google is offering users the best option to date to securing their accounts from phishing. (Hint: It’s not passwords.) (Read more…) The post Google Passkeys: How…

How to spot and avoid a tech support scam

Categories: Awareness Categories: Personal Categories: Scams Tags: Tech Support Scams Tags: Malwarebytes Tags: impersonating Tags: screen lockers Tags: fake warnings Tags: remote access Tech support scams are an ongoing nuisance. Knowing how they operate helps you to recognize them. (Read…

New Discord username policy raises user privacy fears

Categories: News Tags: Discord Tags: privacy Tags: username Tags: discriminator Tags: DM Tags: bot Tags: chat Tags: change Tags: changing Tags: server Tags: hijack phish Tags: private We take a look at the reaction to Discord’s proposed changes to how…

Update now! May 2023 Patch Tuesday tackles three zero-days

Categories: Exploits and vulnerabilities Categories: News Tags: Microsoft Tags: CVE-2023-29336 Tags: CVE-2023-24932 Tags: bootkit Tags: CVE-2023-29325 Tags: Outlook Tags: preview Tags: CVE-2023-24941 Tags: Apple Tags: Cisco Tags: Google Tags: Android Tags: VMWare Tags: SAP Tags: Mozilla Microsoft’s Patch Tuesday round…

Brightline breach hits at least 964,000 people, US records show

Categories: News Categories: Ransomware Tags: Brightlight Tags: GoAnywhere MFT Tags: data breach Tags: Cl0p Following the Cl0p ransomware gang’s attacks that leveraged Fortra’s GoAnywhereMFT software tool, behavioral health provider Brightline informed customers about a data breach related to the attacks.…

A week in security (May 1 – 7)

Categories: News The most interesting security related news of the week from May 1 till 7 (Read more…) The post A week in security (May 1 – 7) appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

Ransomware review: May 2023

LockBit maintained its position as the top ransomware attacker and was also observed expanding into the Mac space. (Read more…) The post Ransomware review: May 2023 appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read…

Google and Apple cooperate to address unwanted tracking

Categories: News Categories: Privacy Tags: Google Tags: Apple Tags: AirTag Tags: Tile Tags: Samsung Tags: Bluetooth Tags: trackers Tags: stalking Tags: car thieves Google and Apple want to create a specification for tech that alerts users when they’re being tracked…

World Password Day must die

Categories: News Critical technology should not require an annual pep talk to function correctly. (Read more…) The post World Password Day must die appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article:…

The one and only password tip you need

Categories: News I was asked to write a list of password tips. It’s a short list. (Read more…) The post The one and only password tip you need appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

How small businesses can secure employees’ mobile devices

Categories: Business Categories: News Tags: Small Business Week Tags: mobile security policy Tags: A third of organizations aren’t protecting their mobile devices at all. Don’t be one of them. (Read more…) The post How small businesses can secure employees’ mobile…

Google Authenticator WILL get end-to-end encryption. Eventually.

Categories: News Google has promised to add end-to-end encryption to Google Authenticator backups after users were warned against turning on the new feature. (Read more…) The post Google Authenticator WILL get end-to-end encryption. Eventually. appeared first on Malwarebytes Labs. This…

Google takes CryptBot to the wood shed

Categories: News Tags: CryptBot Tags: malware Tags: chrome Tags: download Tags: package Tags: packages Tags: google Tags: legal Tags: court order Tags: RICO Tags: Pakistan We take a look at Google’s efforts to shut down a particularly nasty set of…