Tag: Malwarebytes Labs

A week in security (April 24 -30)

Categories: News Tags: Lockbit Tags: cl0p Tags: papercut Tags: vmware Tags: magecart Tags: fileless Tags: chatgpt Tags: apc Tags: Pupy rat Tags: guloader Tags: black basta Tags: flipper zero Tags: clickjacking The most interesting security related news of the week…

How to protect your small business from social engineering

Categories: Personal Tags: Small Business Week 2023 Tags: Small Business Week Tags: phishing Tags: pretexting Tags: baiting Tags: tailgating Tags: BEC Tags: CEO fraud Tags: business email compromise Tags: O’Neill Bragg & Staffin Tags: 2022 Internet Crime Report Tags: FBI…

ChatGPT writes insecure code

Categories: News Tags: ChatGPT Tags: How Secure is Code Generated by ChatGPT? Tags: Raphaël Khoury Tags: Anderson Avila Tags: Jacob Brunelle Tags: Baba Mamadou Camara Tags: Université du Québec Tags: ChatGPT makes insecure code Researchers have found that ChatGPT, OpenAI’s…

Magecart threat actor rolls out convincing modal forms

Categories: Threat Intelligence Tags: magecart Tags: skimmer Tags: modal Tags: fraud Tags: e-commerce It’s hard to put individuals at fault when the malicious copy is better than the original. This credit card skimmer was built to fool just about anyone.…

Decoy dog toolkit plays the long game with Pupy RAT

Categories: News Tags: Pupy RAT Tags: nation state Tags: russia Tags: decoy dog Tags: toolkit Tags: linux Tags: mobile Tags: windows Tags: malware Tags: DNS Tags: evasive We take a look at the discovery of a long running malware toolkit…

Black Basta ransomware attacks Yellow Pages Canada

Categories: News Categories: Ransomware Tags: Yellow Pages Tags: Canada Tags: Black Basta Tags: ransomware Yellow Pages Canada has suffered a cyberattack by the Black Basta ransomware group. (Read more…) The post Black Basta ransomware attacks Yellow Pages Canada appeared first…

GuLoader returns with a rotten shipment

Categories: News Tags: GuLoader Tags: loader Tags: malware Tags: malspam Tags: email Tags: mail Tags: delivery Tags: collection Tags: scam Tags: infection Tags: Italy We take a look at a GuLoader campaign which comes bundled with an Italian language fake…

A week in security (April 17 – 23)

Categories: News Tags: fake Chrome update Tags: AirBnb scam Tags: fake IRS tax email Tags: Ransomware in Germany report Tags: Living Off The Land Tags: LOTL attack Tags: ALPHV ransomware Tags: ransomware Tags: spring cleaning your browser Tags: lost injured…

Adult content malvertising scheme leads to clickjacking

Categories: News Tags: 18+ Tags: malvertising Tags: Google ads Tags: clickjacking Malwarebytes’ researchers have discovered a malvertising scheme that uses adult lures for clickjacking purposes. (Read more…) The post Adult content malvertising scheme leads to clickjacking appeared first on Malwarebytes…

Update now, there’s a Chrome zero-day in the wild

Categories: News Tags: chrome Tags: browser Tags: update Tags: vulnerability Tags: CVE Tags: exploit Tags: exploitation Tags: zero-day Users of Chrome should ensure they’re running the latest version to patch an integer overflow in the Skia graphics library. (Read more…)…

Spring cleaning tips for your browser

Categories: News Tags: Some tips that can enhance your browser’s speed Tags: so you have more time to enjoy the outdoors Some tips that can enhance your browser’s speed, so you have more time to enjoy the outdoors. (Read more…)…

Avoid this “lost injured dog” Facebook hoax

Categories: News Tags: facebook Tags: scam Tags: spam Tags: hoax Tags: dog Tags: injured Tags: lost Tags: vet Tags: missing We take a look at a Facebook hoax which uses supposedly injured dogs as the lure for a bait and…

LockBit ransomware on Mac: Should we worry?

Categories: News Categories: Ransomware Tags: LockBit Tags: ransomware Tags: Patrick Wardle Tags: macOS ransomware Tags: first Mac ransomware Tags: Azim Khodjibaev Tags: BleepingComputer Tags: Mark Stockley With plans to offer more ransomware, LockBit has just created a variant for macOS.…

Woman tracks down and turns table on Airbnb scammer

Categories: News Categories: Scams Tags: Airbnb Tags: TikTok Tags: @livvoogus Tags: Olivia Tags: Mr. Tyler A superhost scammed a woman out of a thousand dollars. She didn’t take it lying down. (Read more…) The post Woman tracks down and turns…

Update Chrome now! Google patches actively exploited flaw

Categories: Exploits and vulnerabilities Categories: News Tags: Google Tags: Chrome zero-day Tags: CVE-2023-2033 Tags: V8 flaw Tags: V8 Google has released an updated version of Chrome to address a zero-day flaw that is being exploited in the wild. (Read more…)…

Beware: Fake IRS tax email wants your Microsoft account

Categories: News Categories: Scams Tags: IRS tax scam Tags: tax scam Tags: IRS Tags: Jerome Segura Tags: Telegram bot Tags: Emotet Expect more IRS tax-related shenanigans from fraudsters, who are now going for corporate accounts, after some states received deadline…

Ransomware in Germany, April 2022 – March 2023

Categories: News In the last 12 months, Germany was one of the most attacked countries in the world, the most attacked in the EU, and a favourite target of the notorious Black Basta group. (Read more…) The post Ransomware in…

Is AI being used for virtual kidnapping scams?

Categories: News Tags: kidnap Tags: scam Tags: virtual Tags: AI Tags: voice Tags: fake Tags: fraud Tags: hoax Tags: kidnapping We take a look at claims that AI is now being used for a notorious form of kidnapping hoax. (Read…

Ransomware in France, April 2022–March 2023

Categories: Ransomware Categories: Threat Intelligence In the last 12 months France was one of the most attacked countries in the world, and a favourite target of LockBit, the world’s most dangerous ransomware. (Read more…) The post Ransomware in France, April…

Ransomware review: April 2023

Categories: Ransomware Categories: Threat Intelligence Cl0p was the most used ransomware in March 2023, dethroning the usual frontrunner LockBit, after breaching over 104 organizations with a zero-day vulnerability. (Read more…) The post Ransomware review: April 2023 appeared first on Malwarebytes…

Ransomware in the UK: April 2022–March 2023

Categories: Ransomware Categories: Threat Intelligence In the last 12 months, the UK has been second only to the USA in terms of ransomware attacks, and its education sector has been subjected to a feeding frenzy by Vice Society. (Read more…)…

Update now! April’s Patch Tuesday includes a fix for one zero-day

Categories: Exploits and vulnerabilities Categories: News Tags: Microsoft Tags: Apple Tags: Google Tags: Adobe Tags: Cisco Tags: SAP Tags: Mozilla Tags: CVE-2023-28252 Tags: CVE-2023-28231 Tags: CVE-2023-21554 Tags: Word Tags: Publisher Tags: Office One fixed vulnerability is being actively exploited by…

A week in security (April 3 – 9)

Categories: News Tags: TikTok Tags: Super FabriXss Tags: Twitter Tags: macOS malware Tags: ransomware Tags: 2023 State of Malware Tags: Western Digital Tags: Android Tags: endpoint security Tags: ChatGPT Tags: K-12 Tags: IoT Tags: Facebook Tags: targeted advertising Tags: Google…

Visitors of tax return e-file service may have downloaded malware

Categories: News Categories: Scams Tags: tax scams Tags: efile.com Tags: US tax 2023 Tags: backdoor Tags: Trojan Tags: Johannes Ullrich Tags: MalwareHunterTeam Tags: /u/SaltyPotter Tags: fake network error notification Cybercriminals have compromised eFile.com to host malicious code that allows for…

TikTok misused children’s data, faces $15.6M fine

Categories: News Tags: TikTok Tags: Information Commissioner’s Office Tags: ICO Tags: Sonia Livingston Tags: John Edwards TikTok has been fined by a UK data protection watchdog after its investigation shows the company failed to get parental consent. (Read more…) The…

Update Android now! Google patches three important vulnerabilities

Categories: Android Categories: Exploits and vulnerabilities Categories: News Tags: Google Tags: Android Tags: update Tags: CVE-2023-21085 Tags: CVE-2023-21096 Tags: CVE-2022-38181 Tags: Use-after-free Tags: input validation Google has released an Android update that fixes two critical remote code execution (RCE) vulnerabilities,…

Pre-ransomware notifications are paying off right from the bat

Categories: News Categories: Ransomware Tags: pre-ransomware notifications Tags: JCDC Tags: CISA Tags: ransomware Tags: IRS Tags: Emotet Tags: MDR CISA has published the first results of its pre-ransomware notifications that were introduced at the start of 2023. And they appear…

A week in security (March 27 – April 2)

Categories: News Tags: Lock and Code Tags: Anna Pobletts Tags: ChatGPT Tags: World Backup Day Tags: GitHub Tags: accidental breach Tags: DDoS service Tags: Instagram scammer Tags: top cyber threats of 2023 Tags: 3CX Tags: BingBang Tags: Apple Tags: EE…

TikTok: What’s going on and should I be worried?

Categories: News Categories: Privacy Tags: TikTok Tags: social media Tags: data Tags: app Tags: privacy Tags: algorithm TikTok has garnered a ton of media attention about its alleged risks. But is it really that much worse than other social media…

Super FabriXss: an RCE vulnerability in Azure Service Fabric Explorer

Categories: Exploits and vulnerabilities Categories: News Tags: Azure Tags: Microsoft Tags: Super FabriXss Tags: RCE Tags: vulnerability Tags: CVE-2023-23383 Researchers disclosed how they found a remote code execution vulnerability in Azure Service Fabric Explorer. (Read more…) The post Super FabriXss:…

3 tips to raise your backup game

Categories: Personal Because backups are the dental floss of cybersecurity—the thing that everyone knows they should do, that everyone intends to do, that nobody actually does. (Read more…) The post 3 tips to raise your backup game appeared first on…

3CX desktop app used in a supply chain attack

Categories: News Tags: 3CX Tags: supply-chain Tags: sideload Researchers have found that the 3CX desktop app may be compromised and used in supply chain attacks. (Read more…) The post 3CX desktop app used in a supply chain attack appeared first…

Fake DDoS services set up to trap cybercriminals

Categories: News Tags: NCA Tags: national crime agency Tags: DDoS Tags: distributed denial of service Tags: booter Tags: underground The British National Crime Agency has been setting up fake DDoS services to teach people a lesson in what not to…

Food giant Dole reveals more about ransomware attack

Categories: News Categories: Ransomware Tags: Dole Tags: ransomware attack Tags: data breach While Dole hasn’t said a lot about the February ransomware incident, it has revealed threat actors accessed employee data. (Read more…) The post Food giant Dole reveals more…

Bogus Chat GPT extension takes over Facebook accounts

Categories: News Tags: Chat GPT Tags: chrome Tags: extension Tags: rogue Tags: facebook Tags: cookies We look at a bogus Chat GPT Chrome extension which was after Facebook cookies. (Read more…) The post Bogus Chat GPT extension takes over Facebook…

Ransomware gunning for transport sector’s OT systems next

Categories: News Categories: Ransomware Tags: ENISA Tags: operational technology Tags: OT Tags: OT systems Tags: ransomware ENISA released a report tackling the threat landscape of the transportation industry. And it has foreseen the targeting of OT systems in the future.…

GitHub accidentally exposes RSA SSH key

Categories: News Tags: GitHub Tags: RSA Tags: SSH Developer platform GitHub has changed its RSA SSH key after it was accidentally exposed on a public repository. (Read more…) The post GitHub accidentally exposes RSA SSH key appeared first on Malwarebytes…

USB bombs sent to news organizations

Categories: News Tags: usb Tags: bomb Tags: mail Tags: post Tags: letter USB sticks repurposed as explosive devices provide a dramatic reminder of how little you know about unknown USB devices. (Read more…) The post USB bombs sent to news…

ChatGPT leaks bits of users’ chat history

Categories: News Tags: ChatGPT Tags: privacy Tags: chat history ChatGPT suddenly started showing users the titles of other users’ chats. (Read more…) The post ChatGPT leaks bits of users’ chat history appeared first on Malwarebytes Labs. This article has been…

Beware: Fake IRS tax email delivers Emotet malware

Categories: News Tags: emotet Tags: malware Tags: IRS Tags: scam Tags: email Tags: W-9 Tags: word Tags: document Tags: macro Tags: macros We look at a current tax scam in circulation which looks to make an Emotet deposit on your…

Google Pixel: Cropped or edited images can be recovered

Categories: Exploits and vulnerabilities Categories: News Tags: Google Tags: Pixel Tags: Markup Tags: CVE-2023-21036 Tags: recover Tags: PNG Tags: truncated A vulnerability in the Markup tool that comes pre-installed on Pixel phones allows anyone with access to the edited image…

New Kritec Magecart skimmer found on Magento stores

Categories: Threat Intelligence Tags: Magecart Tags: skimmer Tags: Kritect Tags: Magento Compromised online stores have been injected with skimmers hiding around the Google Tag Manager script. We identified a new one that looked similar at first but is part of…

A look at a Magecart skimmer using the Hunter obfuscator

Categories: Threat Intelligence Tags: magecart Tags: skimmer Tags: obfuscation Tags: hunter Tags: credit card Tags: magento The threat actor behind this operation is using an open-source JavaScript obfuscator to hide its code. (Read more…) The post A look at a…

The NBA tells fans about data breach

Categories: News Tags: NBA Tags: data breach Tags: Mailchimp The NBA is warning fans of a data breach at a third-party newsletter service which could result in targeted phishing attempts (Read more…) The post The NBA tells fans about data…

A week in security (March 13 – 19)

Categories: News Tags: Becky Holmes Tags: Lock and Code S04E06 Tags: ransomware Tags: WhatsApp Tags: AI chatbot Tags: investment fraud Tags: Clop Tags: Microsoft zero-day Tags: Microsoft Tags: STALKER 2 Tags: Facebook Tags: Microsoft OneNote Tags: LockBit Tags: Rubrik The…

LockBit ransomware attacks Essendant

Categories: News Categories: Ransomware Tags: lockbit Tags: ransomware Tags: essendant Tags: data Tags: encrypt Tags: ransom Tags: leak Tags: website Tags: outage Tags: network The LockBit ransomware group has attacked Essendant, a US-based distributor of office products, and is threatening…