Mozilla released an update of Firefox to fix two critical security vulnerabilities that together allowed an attacker to escape the sandbox. This article has been indexed from Malwarebytes Read the original article: Patch now: Mozilla patches two critical vulnerabilities in…
Category: Malwarebytes
YouTube ordered to reveal the identities of video viewers
Federal authorities have asked Google to reveal the identities of people that watched certain videos in at least two investigations. This article has been indexed from Malwarebytes Read the original article: YouTube ordered to reveal the identities of video viewers
Vans warns customers of data breach
Vans warns its customers about phishing and other fraud attacks in the aftermath of a ransomware attack in December This article has been indexed from Malwarebytes Read the original article: Vans warns customers of data breach
Securing your home network is long, tiresome, and entirely worth it, with Carey Parker: Lock and Code S05E07
This week on the Lock and Code podcast, we speak with Carey Parker about the importance and the process of securing your home network. This article has been indexed from Malwarebytes Read the original article: Securing your home network is…
3 important lessons from a devastating ransomware attack
Three things you could learn from the cyber incident review produced by the British Library following its October ransomware attack. This article has been indexed from Malwarebytes Read the original article: 3 important lessons from a devastating ransomware attack
A week in security (March 18 – March 24)
A list of topics we covered in the week of March 18 to March 24 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (March 18 – March 24)
New Go loader pushes Rhadamanthys stealer
A malicious ad for the popular admin tool PuTTY leads victims to a fake site that downloads malware. This article has been indexed from Malwarebytes Read the original article: New Go loader pushes Rhadamanthys stealer
Canada revisits decision to ban Flipper Zero
Since the main reason for the ban was to prevent car thefts that didn’t happen, we’re happy to see the change of heart. This article has been indexed from Malwarebytes Read the original article: Canada revisits decision to ban Flipper…
Patch Ivanti Standalone Sentry and Ivanti Neurons for ITSM now
Ivanti has issued patches for two new vulnerabilities with a high CVSS score. Neither is known to have been explioted in the wild. Yet. This article has been indexed from Malwarebytes Read the original article: Patch Ivanti Standalone Sentry and…
19 million plaintext passwords exposed by incorrectly configured Firebase instances
Researchers scanned the internet for incorrectly configured Firebase instances and what they found was frightening. This article has been indexed from Malwarebytes Read the original article: 19 million plaintext passwords exposed by incorrectly configured Firebase instances
Apex Legends Global Series plagued by hackers
The North American finals of the Apex Legends Global have been postponed after at least two hacking incidents. This article has been indexed from Malwarebytes Read the original article: Apex Legends Global Series plagued by hackers
Tax scammer goes after small business owners and self-employed people
We found a tax scammer that set up a fake website where targets could apply for an Employer Identification Number. This article has been indexed from Malwarebytes Read the original article: Tax scammer goes after small business owners and self-employed…
The ‘AT&T breach’—what you need to know
Data on over 70 million people that came from an alleged breach at AT&T has been posted online. Here’s what you need to know. This article has been indexed from Malwarebytes Read the original article: The ‘AT&T breach’—what you need…
Upcoming webinar: How a leading architecture firm approaches cybersecurity
Learn how top-tier cybersecurity tactics are applied in real-world scenarios. This article has been indexed from Malwarebytes Read the original article: Upcoming webinar: How a leading architecture firm approaches cybersecurity
Social media influencers targeted by identity thieves
Social media influencers are attractive targets for identity thefs. Not just for their bank accounts but also to influence their followers This article has been indexed from Malwarebytes Read the original article: Social media influencers targeted by identity thieves
Store manager admits SIM swapping his customers
A manager at an unnamed telecommunications company has admitted to SIM swapping his customers. This article has been indexed from Malwarebytes Read the original article: Store manager admits SIM swapping his customers
A week in security (March 11 – March 17)
A list of topics we covered in the week of March 11 to March 17 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (March 11 – March 17)
Ransomware’s appetite for US healthcare sees known attacks double in a year
The US healthcare industry suffers more ransomware attacks than most countries. This article has been indexed from Malwarebytes Read the original article: Ransomware’s appetite for US healthcare sees known attacks double in a year
Webinar recap: 6 critical cyberthreats in 2024 and how to counter them
Get expert insights on the six most critical cyberthreats of 2024. This article has been indexed from Malwarebytes Read the original article: Webinar recap: 6 critical cyberthreats in 2024 and how to counter them
TikTok faces ban in US unless it parts ways with Chinese owner ByteDance
A bill that passed the House of Representatives would ban TikTok from the US unless Chinese owner ByteDance gives up its share of the app. This article has been indexed from Malwarebytes Read the original article: TikTok faces ban in…
Malwarebytes Premium blocks 100% of malware during external AVLab test
Malwarebytes Premium for Windows detected and blocked 100% of the malware samples used in AVLab’s January evaluation. This article has been indexed from Malwarebytes Read the original article: Malwarebytes Premium blocks 100% of malware during external AVLab test
ThreatDown achieves perfect score in latest AVLab assessment
ThreatDown has earned a perfect score in the AVLabs test for the eleventh consecutive quarter. This article has been indexed from Malwarebytes Read the original article: ThreatDown achieves perfect score in latest AVLab assessment
How to update outdated software on Mac endpoints: Introducing ThreatDown VPM for Mac
Vulnerability Assessment and Patch Management (VPM) is now available for Mac endpoints. This article has been indexed from Malwarebytes Read the original article: How to update outdated software on Mac endpoints: Introducing ThreatDown VPM for Mac
Microsoft Patch Tuesday March 2024 includes critical Hyper-V flaws
Microsoft patched 61 vulnerabilities in the March 2024 Patch Tuesday round, including two critical flaws in Hyper-V. This article has been indexed from Malwarebytes Read the original article: Microsoft Patch Tuesday March 2024 includes critical Hyper-V flaws
New Facebook photo rule hoax spreads
A hoax telling people to copy and paste a copyright notice on Facebook has been making the rounds since 2012. Can we make it go away? Please! This article has been indexed from Malwarebytes Read the original article: New Facebook…
FakeBat delivered via several active malvertising campaigns
A number of software brands are being impersonated with malicious ads and fake sites to distribute malware. This article has been indexed from Malwarebytes Read the original article: FakeBat delivered via several active malvertising campaigns
Ransomware review: March 2024
February 2024 is likely to be remembered as one of the most turbulent months in ransomware history. This article has been indexed from Malwarebytes Read the original article: Ransomware review: March 2024
Data brokers admit they’re selling information on precise location, kids, and reproductive healthcare
Information newly made available under California law has shed light on data broker practices, including exactly what categories of information they trade in. This article has been indexed from Malwarebytes Read the original article: Data brokers admit they’re selling information…
Going viral shouldn’t lead to bomb threats, with Leigh Honeywell: Lock and Code S05E06
This week on the Lock and Code podcast, we speak with Leigh Honeywell about the cybersecurity defenses to online harassment. This article has been indexed from Malwarebytes Read the original article: Going viral shouldn’t lead to bomb threats, with Leigh…
A week in security (March 4 – March 10)
A list of topics we covered in the week of March 4 to March 10 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (March 4 – March 10)
Patch now! VMWare escape flaws are so serious even end-of-life software gets a fix
The flaws could allow an attacker with privileged access to a guest VM to access the hypervisor on the host. This article has been indexed from Malwarebytes Read the original article: Patch now! VMWare escape flaws are so serious even…
Update now! JetBrains TeamCity vulnerability abused at scale
Users of JetBrains TeamCity on-prmises server need to deal with two serious vulnerabilities. This article has been indexed from Malwarebytes Read the original article: Update now! JetBrains TeamCity vulnerability abused at scale
PetSmart warns customers of credential stuffing attack
Pet retail company PetSmart has emailed customers to alert them to a recent attack that used reused passwords. This article has been indexed from Malwarebytes Read the original article: PetSmart warns customers of credential stuffing attack
Predator spyware vendor banned in US
The US Treasury Department has sanctioned Predator spyware vendor Intellexa Consortium, and banned the company from doing business in the US. This article has been indexed from Malwarebytes Read the original article: Predator spyware vendor banned in US
ALPHV ransomware gang fakes own death, fools no one
The ALPHV gang’s attempt to cover up an exit scam isn’t going well. This article has been indexed from Malwarebytes Read the original article: ALPHV ransomware gang fakes own death, fools no one
Update your iPhones and iPads now: Apple patches security vulnerabilities in iOS and iPadOS
Apple has released a security update for iOS and iPadOS to patch two zero-day vulnerabilities which are reported to already have been exploited. This article has been indexed from Malwarebytes Read the original article: Update your iPhones and iPads now:…
Check your DNS! Abandoned domains used to bypass spam checks
Researchers have uncovered thousands of “subdomailing” campaigns. This article has been indexed from Malwarebytes Read the original article: Check your DNS! Abandoned domains used to bypass spam checks
American Express warns customers about third party data breach
American Express has warned affected customers about a breach at a merchant process that leaked account numbers, names, and card expiration dates. This article has been indexed from Malwarebytes Read the original article: American Express warns customers about third party…
No “Apple magic” as 11% of macOS detections last year came from malware
Last year, 11% of all detections on Macs were caused by malware. The illuminating figure gives a view into the world of Mac cyberthreats. This article has been indexed from Malwarebytes Read the original article: No “Apple magic” as 11%…
Pegasus spyware creator ordered to reveal code used to spy on WhatsApp users
Meta has won a court case against spyware vendor NSO Group to reveal the Pegasus spyware code that allows spying on WhatsApp users. This article has been indexed from Malwarebytes Read the original article: Pegasus spyware creator ordered to reveal…
A week in security (February 26 – March 3)
A list of topics we covered in the week of February 26 to March 3 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (February 26 – March 3)
PikaBot malware on the rise: What organizations need to know
Ransomware gangs are using a powerful new trojan named PikaBot. This article has been indexed from Malwarebytes Read the original article: PikaBot malware on the rise: What organizations need to know
Malicious meeting invite fix targets Mac users
Scammers are attacking Mac users interested in cryptocurrencies using a fake fix for a meeting link that won’t work. This article has been indexed from Malwarebytes Read the original article: Malicious meeting invite fix targets Mac users
Pig butchering scams, how they work and how to avoid them
Pig butchering scams are usually tied to cryptocurrency investments that make for big business with victims on both sides of the line. This article has been indexed from Malwarebytes Read the original article: Pig butchering scams, how they work and…
Airbnb scam sends you to a fake Tripadvisor site, takes your money
One of our researchers was targeted by a scammer advertising on Airbnb and hosting a fake Tripadvisor website. This article has been indexed from Malwarebytes Read the original article: Airbnb scam sends you to a fake Tripadvisor site, takes your…
Facebook bug could have allowed attacker to take over accounts
A vulnerability, now fixed, in Facebook could have allowed an attacker to take over a Facebook account without the victim needing to click on anything at all. This article has been indexed from Malwarebytes Read the original article: Facebook bug…
Stopping a targeted attack on a Managed Service Provider (MSP) with ThreatDown MDR
Detecting and disrupting a months-long malware campaign on an MSP. This article has been indexed from Malwarebytes Read the original article: Stopping a targeted attack on a Managed Service Provider (MSP) with ThreatDown MDR
ALPHV is singling out healthcare sector, say FBI and CISA
CISA, FBI and HHS are warning about the ALPHV/ Blackcat ransomware group targeting the healthcare industry. This article has been indexed from Malwarebytes Read the original article: ALPHV is singling out healthcare sector, say FBI and CISA
One year later, Rhadamanthys is still dropped via malvertising
Infostealers like Rhadamanthys continue to be a favorite among malware distributors who leverage search engine ads to lure victims. This article has been indexed from Malwarebytes Read the original article: One year later, Rhadamanthys is still dropped via malvertising
Change Healthcare outages reportedly caused by ransomware
The cyberattack on Change Healthcare that has been causing a lot of disruptions is likely the work of the BlackCat/ALPHV ransomware gang. This article has been indexed from Malwarebytes Read the original article: Change Healthcare outages reportedly caused by ransomware
Android banking trojans: How they steal passwords and drain bank accounts
Android banking trojans are a serious cyberthreat to everyday users that, through clever trickery, steal passwords and drain bank accounts. This article has been indexed from Malwarebytes Read the original article: Android banking trojans: How they steal passwords and drain…
Identity theft is number one threat for consumers, says report
The German BSI has published its 2023 state of IT security report which names identity theft as the main threat for consumers. This article has been indexed from Malwarebytes Read the original article: Identity theft is number one threat for…
How to make a fake ID online, with Joseph Cox: Lock and Code S05E05
This week on the Lock and Code podcast, we speak with Joseph Cox about how an OnlyFake-generated fake ID fooled a cryptocurrency exchange. This article has been indexed from Malwarebytes Read the original article: How to make a fake ID…
A week in security (February 19 – February 25)
week in security This article has been indexed from Malwarebytes Read the original article: A week in security (February 19 – February 25)
Joomla! patches XSS flaws that could lead to remote code execution
Time to get patching! This article has been indexed from Malwarebytes Read the original article: Joomla! patches XSS flaws that could lead to remote code execution
Update now! ConnectWise ScreenConnect vulnerability needs your attention
ConnectWise customers need to take immediate action to remediate a critical vulnerability. This article has been indexed from Malwarebytes Read the original article: Update now! ConnectWise ScreenConnect vulnerability needs your attention
Why ransomware gangs love using RMM tools—and how to stop them
More and more ransomware gangs are using RMM tools in their attacks. This article has been indexed from Malwarebytes Read the original article: Why ransomware gangs love using RMM tools—and how to stop them
Signal to shield user phone numbers by default
Chat app Signal will shield users’ phone numbers by default from now on. Check whether you need to change your settings to adapt to the new version This article has been indexed from Malwarebytes Read the original article: Signal to…
Vibrator virus steals your personal information
One of our customers found their vibrator was buzzing with a hint of malware. This article has been indexed from Malwarebytes Read the original article: Vibrator virus steals your personal information
A first analysis of the i-Soon data leak
Data from a Chinese cybersecurity vendor that works for the Chinese government exposed a range of hacking tools and services. This article has been indexed from Malwarebytes Read the original article: A first analysis of the i-Soon data leak
ThreatDown EDR update: Streamlined Suspicious Activity investigation
Investigating EDR alerts just got a whole lot easier. This article has been indexed from Malwarebytes Read the original article: ThreatDown EDR update: Streamlined Suspicious Activity investigation
Law enforcement trolls LockBit, reveals massive takedown
Law enforcement has humiliated the humiliators. This article has been indexed from Malwarebytes Read the original article: Law enforcement trolls LockBit, reveals massive takedown
Wyze cameras show the wrong feeds to customers. Again.
Wyze cameras allowed users access to other users’ feeds once again. An estimated 13,000 people got a peek at thumbnails from another user’s home. This article has been indexed from Malwarebytes Read the original article: Wyze cameras show the wrong…
Raccoon Infostealer operator extradited to the United States
A Ukrainian national that is being accused of operating the Raccoon Infostealer in a Malware-as-a-Service has been extradited to the US. This article has been indexed from Malwarebytes Read the original article: Raccoon Infostealer operator extradited to the United States
Malvertising: This cyberthreat isn’t on the dark web, it’s on Google
Malvertising made a resurgence in 2023, with cybercriminals creating malicious ads and websites imitating Amazon, TradingView, and Rufus. This article has been indexed from Malwarebytes Read the original article: Malvertising: This cyberthreat isn’t on the dark web, it’s on Google
LockBit, the world’s worst ransomware, is down
LockBit’s position as ransomware’s biggest beast is suddenly in doubt. This article has been indexed from Malwarebytes Read the original article: LockBit, the world’s worst ransomware, is down
Why keeping track of user accounts is important
CISA (the Cybersecurity & Infrastructure Security Agency) has issued a cybersecurity advisory after the discovery of documents containing host and user… This article has been indexed from Malwarebytes Read the original article: Why keeping track of user accounts is important
A week in security (February 12 – February 18)
A list of topics we covered in the week of February 12 to February 18 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (February 12 – February 18)
GoldPickaxe Trojan steals your face!
A group of cybercriminals is committing bank fraud by convincing victims to scan their IDs and faces. This article has been indexed from Malwarebytes Read the original article: GoldPickaxe Trojan steals your face!
Microsoft Exchange vulnerability actively exploited
One of Microsoft’s Patch Tuesday fixes has flipped from “Likely to be Exploited” to “Exploitation Detected”. This article has been indexed from Malwarebytes Read the original article: Microsoft Exchange vulnerability actively exploited
Massive utility scam campaign spreads via online ads
Malwarebytes researchers have discovered a prolific campaign of fraudulent energy ads shown to users via Google searches. This article has been indexed from Malwarebytes Read the original article: Massive utility scam campaign spreads via online ads
Facebook Marketplace users’ stolen data offered for sale
Personal data belonging to 200,000 Facebook Marketplace users has been published online, including email addresses and phone numbers. This article has been indexed from Malwarebytes Read the original article: Facebook Marketplace users’ stolen data offered for sale
How ransomware changed in 2023
In 2023, the CL0P ransomware gang broke the scalability barrier and shook the security world with a series of short, automated campaigns. This article has been indexed from Malwarebytes Read the original article: How ransomware changed in 2023
Malwarebytes crushes malware all the time
The PC Security Channel tested Malwarebytes against 2015 files. Here’s how we did. This article has been indexed from Malwarebytes Read the original article: Malwarebytes crushes malware all the time
Update now! Microsoft fixes two zero-days on February Patch Tuesday
Microsoft has issued patches for 73 security vulnerabilities in its February 2024 Patch Tuesday. This article has been indexed from Malwarebytes Read the original article: Update now! Microsoft fixes two zero-days on February Patch Tuesday
Remote Monitoring & Management software used in phishing attacks
Threat actors are abusing commercial remote software like AnyDesk to phish users and defraud them. This article has been indexed from Malwarebytes Read the original article: Remote Monitoring & Management software used in phishing attacks
TheTruthSpy stalkerware, still insecure, still leaking data
Stalkerware app TheTruthSpy has been hacked for the fourth time, once again leaking the sensitive data it captures. This article has been indexed from Malwarebytes Read the original article: TheTruthSpy stalkerware, still insecure, still leaking data
Patch now! Roundcube mail servers are being actively exploited
A vulnerability in Roundcube webmail is being actively exploited and CISA is urging users to install an updated version. This article has been indexed from Malwarebytes Read the original article: Patch now! Roundcube mail servers are being actively exploited
Warzone RAT infrastructure seized
International law enforcements agencies have disruped the infrastructure behind the Warzone RAT. This article has been indexed from Malwarebytes Read the original article: Warzone RAT infrastructure seized
Ransomware review: February 2024
In January, we recorded a total of 261 ransomware victims. This article has been indexed from Malwarebytes Read the original article: Ransomware review: February 2024
If only you had to worry about malware, with Jason Haddix: Lock and Code S05E04
This week on the Lock and Code podcast, we speak with Jason Haddix about how businesses can protect against modern cyberthreats. This article has been indexed from Malwarebytes Read the original article: If only you had to worry about malware,…
AI-generated voices in robocalls are illegal, rules FCC
The FCC has ruled that the use of AI generated voices in robocalls is illegal, by considering them as artificial under the Telephone Consumer Protection Act. This article has been indexed from Malwarebytes Read the original article: AI-generated voices in…
A week in security (February 5 – February 11)
A list of topics we covered in the week of February 5 to February 11 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (February 5 – February 11)
Ivanti urges customers to patch yet another critical vulnerability
Ivanti has found yet another vulnerability in versions of Connect Secure, Policy Secure, and ZTA gateways. This article has been indexed from Malwarebytes Read the original article: Ivanti urges customers to patch yet another critical vulnerability
Ivanti urges customer to patch yet another critical vulnerability
Ivanti has found yet another vulnerability in versions of Connect Secure, Policy Secure, and ZTA gateways. This article has been indexed from Malwarebytes Read the original article: Ivanti urges customer to patch yet another critical vulnerability
Ransomware in 2023 recap: 5 key takeaways
2023 saw a 70% increase in ransomware attacks from 2022. This article has been indexed from Malwarebytes Read the original article: Ransomware in 2023 recap: 5 key takeaways
FBI and CISA publish guide to Living off the Land techniques
FBI and CISA have produced guidance about Chinese APT group Volt Typhoon and other groups that use Living off the Land (LOTL) techniques. This article has been indexed from Malwarebytes Read the original article: FBI and CISA publish guide to…
Warning from LastPass as fake app found on Apple App Store
LastPass has warned about a fake app called LassPass, available in the Apple App Store. This article has been indexed from Malwarebytes Read the original article: Warning from LastPass as fake app found on Apple App Store
2 million job seekers targeted by data thieves
A criminal group called ResumeLooters has stolen the personal information of over two million job seekers from at least 65 different websites. This article has been indexed from Malwarebytes Read the original article: 2 million job seekers targeted by data…
How to tell if your toothbrush is being used in a DDoS attack
Your essential guide to toothbrush security. This article has been indexed from Malwarebytes Read the original article: How to tell if your toothbrush is being used in a DDoS attack
Facebook fatal accident scam still rages on
We look at a scam campaign on Facebook that continues to do the rounds, and how you can recover your compromised account. This article has been indexed from Malwarebytes Read the original article: Facebook fatal accident scam still rages on
State of Malware 2024: What consumers need to know
The State of Malware 2024 report covers some topics that are of special interest to home users: privacy, passwords, malvertising, banking Trojans, and Mac malware. This article has been indexed from Malwarebytes Read the original article: State of Malware 2024:…
Known ransomware attacks up 68% in 2023
Big Game ransomware is just one of six threats resource-constrained IT teams need to pay attention to in 2024. This article has been indexed from Malwarebytes Read the original article: Known ransomware attacks up 68% in 2023
Safer Internet Day, or why Brad Pitt needed an internet bodyguard
Safer Internet Day is all about raising awareness about a safer and better internet for all, and especially for children and young people. This article has been indexed from Malwarebytes Read the original article: Safer Internet Day, or why Brad…
Clorox counts the cost of cyberattack
Clorox has reported losses of $49 million following a cyberattack in mid-2023. This article has been indexed from Malwarebytes Read the original article: Clorox counts the cost of cyberattack
A week in security (January 29 – February 4)
A list of topics we covered in the week of January 29 to February 4 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (January 29 – February 4)
Mother of all Breaches may contain NEW breach data
The MOAB may not be just recycled data after all. This article has been indexed from Malwarebytes Read the original article: Mother of all Breaches may contain NEW breach data
Tax season is here, so are scammers
Watch out for malicious ads tricking you as you prepare to file your taxes. This article has been indexed from Malwarebytes Read the original article: Tax season is here, so are scammers
“You have blood on your hands.” Senate Committee calls for action by social media giants to protect children online
In a hearing with the CEOs of the five most used social media platforms the Senate Judiciary Committee found common ground for the need to protect children online This article has been indexed from Malwarebytes Read the original article: “You…
FBI removes malware from hundreds of routers across the US
The FBI has removed malware from hundreds of routers in an effort to disrupt threat actors linked to the Chinese government. This article has been indexed from Malwarebytes Read the original article: FBI removes malware from hundreds of routers across…