Detecting and disrupting a months-long malware campaign on an MSP. This article has been indexed from Malwarebytes Read the original article: Stopping a targeted attack on a Managed Service Provider (MSP) with ThreatDown MDR
Category: Malwarebytes
ALPHV is singling out healthcare sector, say FBI and CISA
CISA, FBI and HHS are warning about the ALPHV/ Blackcat ransomware group targeting the healthcare industry. This article has been indexed from Malwarebytes Read the original article: ALPHV is singling out healthcare sector, say FBI and CISA
One year later, Rhadamanthys is still dropped via malvertising
Infostealers like Rhadamanthys continue to be a favorite among malware distributors who leverage search engine ads to lure victims. This article has been indexed from Malwarebytes Read the original article: One year later, Rhadamanthys is still dropped via malvertising
Change Healthcare outages reportedly caused by ransomware
The cyberattack on Change Healthcare that has been causing a lot of disruptions is likely the work of the BlackCat/ALPHV ransomware gang. This article has been indexed from Malwarebytes Read the original article: Change Healthcare outages reportedly caused by ransomware
Android banking trojans: How they steal passwords and drain bank accounts
Android banking trojans are a serious cyberthreat to everyday users that, through clever trickery, steal passwords and drain bank accounts. This article has been indexed from Malwarebytes Read the original article: Android banking trojans: How they steal passwords and drain…
Identity theft is number one threat for consumers, says report
The German BSI has published its 2023 state of IT security report which names identity theft as the main threat for consumers. This article has been indexed from Malwarebytes Read the original article: Identity theft is number one threat for…
How to make a fake ID online, with Joseph Cox: Lock and Code S05E05
This week on the Lock and Code podcast, we speak with Joseph Cox about how an OnlyFake-generated fake ID fooled a cryptocurrency exchange. This article has been indexed from Malwarebytes Read the original article: How to make a fake ID…
A week in security (February 19 – February 25)
week in security This article has been indexed from Malwarebytes Read the original article: A week in security (February 19 – February 25)
Joomla! patches XSS flaws that could lead to remote code execution
Time to get patching! This article has been indexed from Malwarebytes Read the original article: Joomla! patches XSS flaws that could lead to remote code execution
Update now! ConnectWise ScreenConnect vulnerability needs your attention
ConnectWise customers need to take immediate action to remediate a critical vulnerability. This article has been indexed from Malwarebytes Read the original article: Update now! ConnectWise ScreenConnect vulnerability needs your attention
Why ransomware gangs love using RMM tools—and how to stop them
More and more ransomware gangs are using RMM tools in their attacks. This article has been indexed from Malwarebytes Read the original article: Why ransomware gangs love using RMM tools—and how to stop them
Signal to shield user phone numbers by default
Chat app Signal will shield users’ phone numbers by default from now on. Check whether you need to change your settings to adapt to the new version This article has been indexed from Malwarebytes Read the original article: Signal to…
Vibrator virus steals your personal information
One of our customers found their vibrator was buzzing with a hint of malware. This article has been indexed from Malwarebytes Read the original article: Vibrator virus steals your personal information
A first analysis of the i-Soon data leak
Data from a Chinese cybersecurity vendor that works for the Chinese government exposed a range of hacking tools and services. This article has been indexed from Malwarebytes Read the original article: A first analysis of the i-Soon data leak
ThreatDown EDR update: Streamlined Suspicious Activity investigation
Investigating EDR alerts just got a whole lot easier. This article has been indexed from Malwarebytes Read the original article: ThreatDown EDR update: Streamlined Suspicious Activity investigation
Law enforcement trolls LockBit, reveals massive takedown
Law enforcement has humiliated the humiliators. This article has been indexed from Malwarebytes Read the original article: Law enforcement trolls LockBit, reveals massive takedown
Wyze cameras show the wrong feeds to customers. Again.
Wyze cameras allowed users access to other users’ feeds once again. An estimated 13,000 people got a peek at thumbnails from another user’s home. This article has been indexed from Malwarebytes Read the original article: Wyze cameras show the wrong…
Raccoon Infostealer operator extradited to the United States
A Ukrainian national that is being accused of operating the Raccoon Infostealer in a Malware-as-a-Service has been extradited to the US. This article has been indexed from Malwarebytes Read the original article: Raccoon Infostealer operator extradited to the United States
Malvertising: This cyberthreat isn’t on the dark web, it’s on Google
Malvertising made a resurgence in 2023, with cybercriminals creating malicious ads and websites imitating Amazon, TradingView, and Rufus. This article has been indexed from Malwarebytes Read the original article: Malvertising: This cyberthreat isn’t on the dark web, it’s on Google
LockBit, the world’s worst ransomware, is down
LockBit’s position as ransomware’s biggest beast is suddenly in doubt. This article has been indexed from Malwarebytes Read the original article: LockBit, the world’s worst ransomware, is down
Why keeping track of user accounts is important
CISA (the Cybersecurity & Infrastructure Security Agency) has issued a cybersecurity advisory after the discovery of documents containing host and user… This article has been indexed from Malwarebytes Read the original article: Why keeping track of user accounts is important
A week in security (February 12 – February 18)
A list of topics we covered in the week of February 12 to February 18 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (February 12 – February 18)
GoldPickaxe Trojan steals your face!
A group of cybercriminals is committing bank fraud by convincing victims to scan their IDs and faces. This article has been indexed from Malwarebytes Read the original article: GoldPickaxe Trojan steals your face!
Microsoft Exchange vulnerability actively exploited
One of Microsoft’s Patch Tuesday fixes has flipped from “Likely to be Exploited” to “Exploitation Detected”. This article has been indexed from Malwarebytes Read the original article: Microsoft Exchange vulnerability actively exploited
Massive utility scam campaign spreads via online ads
Malwarebytes researchers have discovered a prolific campaign of fraudulent energy ads shown to users via Google searches. This article has been indexed from Malwarebytes Read the original article: Massive utility scam campaign spreads via online ads
Facebook Marketplace users’ stolen data offered for sale
Personal data belonging to 200,000 Facebook Marketplace users has been published online, including email addresses and phone numbers. This article has been indexed from Malwarebytes Read the original article: Facebook Marketplace users’ stolen data offered for sale
How ransomware changed in 2023
In 2023, the CL0P ransomware gang broke the scalability barrier and shook the security world with a series of short, automated campaigns. This article has been indexed from Malwarebytes Read the original article: How ransomware changed in 2023
Malwarebytes crushes malware all the time
The PC Security Channel tested Malwarebytes against 2015 files. Here’s how we did. This article has been indexed from Malwarebytes Read the original article: Malwarebytes crushes malware all the time
Update now! Microsoft fixes two zero-days on February Patch Tuesday
Microsoft has issued patches for 73 security vulnerabilities in its February 2024 Patch Tuesday. This article has been indexed from Malwarebytes Read the original article: Update now! Microsoft fixes two zero-days on February Patch Tuesday
Remote Monitoring & Management software used in phishing attacks
Threat actors are abusing commercial remote software like AnyDesk to phish users and defraud them. This article has been indexed from Malwarebytes Read the original article: Remote Monitoring & Management software used in phishing attacks
TheTruthSpy stalkerware, still insecure, still leaking data
Stalkerware app TheTruthSpy has been hacked for the fourth time, once again leaking the sensitive data it captures. This article has been indexed from Malwarebytes Read the original article: TheTruthSpy stalkerware, still insecure, still leaking data
Patch now! Roundcube mail servers are being actively exploited
A vulnerability in Roundcube webmail is being actively exploited and CISA is urging users to install an updated version. This article has been indexed from Malwarebytes Read the original article: Patch now! Roundcube mail servers are being actively exploited
Warzone RAT infrastructure seized
International law enforcements agencies have disruped the infrastructure behind the Warzone RAT. This article has been indexed from Malwarebytes Read the original article: Warzone RAT infrastructure seized
Ransomware review: February 2024
In January, we recorded a total of 261 ransomware victims. This article has been indexed from Malwarebytes Read the original article: Ransomware review: February 2024
If only you had to worry about malware, with Jason Haddix: Lock and Code S05E04
This week on the Lock and Code podcast, we speak with Jason Haddix about how businesses can protect against modern cyberthreats. This article has been indexed from Malwarebytes Read the original article: If only you had to worry about malware,…
AI-generated voices in robocalls are illegal, rules FCC
The FCC has ruled that the use of AI generated voices in robocalls is illegal, by considering them as artificial under the Telephone Consumer Protection Act. This article has been indexed from Malwarebytes Read the original article: AI-generated voices in…
A week in security (February 5 – February 11)
A list of topics we covered in the week of February 5 to February 11 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (February 5 – February 11)
Ivanti urges customers to patch yet another critical vulnerability
Ivanti has found yet another vulnerability in versions of Connect Secure, Policy Secure, and ZTA gateways. This article has been indexed from Malwarebytes Read the original article: Ivanti urges customers to patch yet another critical vulnerability
Ivanti urges customer to patch yet another critical vulnerability
Ivanti has found yet another vulnerability in versions of Connect Secure, Policy Secure, and ZTA gateways. This article has been indexed from Malwarebytes Read the original article: Ivanti urges customer to patch yet another critical vulnerability
Ransomware in 2023 recap: 5 key takeaways
2023 saw a 70% increase in ransomware attacks from 2022. This article has been indexed from Malwarebytes Read the original article: Ransomware in 2023 recap: 5 key takeaways
FBI and CISA publish guide to Living off the Land techniques
FBI and CISA have produced guidance about Chinese APT group Volt Typhoon and other groups that use Living off the Land (LOTL) techniques. This article has been indexed from Malwarebytes Read the original article: FBI and CISA publish guide to…
Warning from LastPass as fake app found on Apple App Store
LastPass has warned about a fake app called LassPass, available in the Apple App Store. This article has been indexed from Malwarebytes Read the original article: Warning from LastPass as fake app found on Apple App Store
2 million job seekers targeted by data thieves
A criminal group called ResumeLooters has stolen the personal information of over two million job seekers from at least 65 different websites. This article has been indexed from Malwarebytes Read the original article: 2 million job seekers targeted by data…
How to tell if your toothbrush is being used in a DDoS attack
Your essential guide to toothbrush security. This article has been indexed from Malwarebytes Read the original article: How to tell if your toothbrush is being used in a DDoS attack
Facebook fatal accident scam still rages on
We look at a scam campaign on Facebook that continues to do the rounds, and how you can recover your compromised account. This article has been indexed from Malwarebytes Read the original article: Facebook fatal accident scam still rages on
State of Malware 2024: What consumers need to know
The State of Malware 2024 report covers some topics that are of special interest to home users: privacy, passwords, malvertising, banking Trojans, and Mac malware. This article has been indexed from Malwarebytes Read the original article: State of Malware 2024:…
Known ransomware attacks up 68% in 2023
Big Game ransomware is just one of six threats resource-constrained IT teams need to pay attention to in 2024. This article has been indexed from Malwarebytes Read the original article: Known ransomware attacks up 68% in 2023
Safer Internet Day, or why Brad Pitt needed an internet bodyguard
Safer Internet Day is all about raising awareness about a safer and better internet for all, and especially for children and young people. This article has been indexed from Malwarebytes Read the original article: Safer Internet Day, or why Brad…
Clorox counts the cost of cyberattack
Clorox has reported losses of $49 million following a cyberattack in mid-2023. This article has been indexed from Malwarebytes Read the original article: Clorox counts the cost of cyberattack
A week in security (January 29 – February 4)
A list of topics we covered in the week of January 29 to February 4 of 2024 This article has been indexed from Malwarebytes Read the original article: A week in security (January 29 – February 4)
Mother of all Breaches may contain NEW breach data
The MOAB may not be just recycled data after all. This article has been indexed from Malwarebytes Read the original article: Mother of all Breaches may contain NEW breach data
Tax season is here, so are scammers
Watch out for malicious ads tricking you as you prepare to file your taxes. This article has been indexed from Malwarebytes Read the original article: Tax season is here, so are scammers
“You have blood on your hands.” Senate Committee calls for action by social media giants to protect children online
In a hearing with the CEOs of the five most used social media platforms the Senate Judiciary Committee found common ground for the need to protect children online This article has been indexed from Malwarebytes Read the original article: “You…
FBI removes malware from hundreds of routers across the US
The FBI has removed malware from hundreds of routers in an effort to disrupt threat actors linked to the Chinese government. This article has been indexed from Malwarebytes Read the original article: FBI removes malware from hundreds of routers across…
CISA: Disconnect vulnerable Ivanti products TODAY
CISA has ordered all FCEB agencies to disconnect all instances of Ivanti Connect Secure and Ivanti Policy Secure solution products. This article has been indexed from Malwarebytes Read the original article: CISA: Disconnect vulnerable Ivanti products TODAY
Ransomware review: December 2023
In November, ransomware gangs attacked at least 457 victims—the highest monthly count in 2023, after May’s record numbers. This article has been indexed from Malwarebytes Read the original article: Ransomware review: December 2023
Microsoft patches 34 vulnerabilities, including one zero-day
Microsoft and other vendors have released their rounds of December updates on or before patch Tuesday. Update now! This article has been indexed from Malwarebytes Read the original article: Microsoft patches 34 vulnerabilities, including one zero-day
Malvertisers zoom in on cryptocurrencies and initial access
Threat actors are increasingly placing malicious ads for Zoom within Google searches. This article has been indexed from Malwarebytes Read the original article: Malvertisers zoom in on cryptocurrencies and initial access
How to choose a free vulnerability scanner: Insights from an industry veteran
How to choose a free vulnerability scanner? Industry expert Robert Elworthy has the answers. This article has been indexed from Malwarebytes Read the original article: How to choose a free vulnerability scanner: Insights from an industry veteran
Update now! Apple issues patches for older iPhones and other devices
Apple has issued emergency updates that include patches for older iOS devices concerning two actively used zero-days that were patched for iOS 17 last week This article has been indexed from Malwarebytes Read the original article: Update now! Apple issues…
Healthcare giant Norton breach leads to theft of millions of patient records
Ransomware operator ALPHV/Blackcat reportedly stole 2.5 million records from non-profit healthcare system Norton Healthcare This article has been indexed from Malwarebytes Read the original article: Healthcare giant Norton breach leads to theft of millions of patient records
The sound of you typing on your keyboard could reveal your password
Researchers have found a way to guess passwords from keyboard sounds recorded by a smartphone with 95% accuracy. This article has been indexed from Malwarebytes Read the original article: The sound of you typing on your keyboard could reveal your…
“Amazon got hacked” messages are a false alarm
A message about extra delivery addresses getting added to Amazon accounts has gone wild on social media. Luckily, it’s nothing to worry about. This article has been indexed from Malwarebytes Read the original article: “Amazon got hacked” messages are a…
Insights into your unpatched vulnerabilities
Malwarebytes is offering customers its ThreatDown Vulnerability Assessment solution without extra costs to help reduce attack surfaces and improve their security posture This article has been indexed from Malwarebytes Read the original article: Insights into your unpatched vulnerabilities
A week in security (December 4 – December 10)
A list of topics we covered in the week of December 4 to December 10 of 2023 This article has been indexed from Malwarebytes Read the original article: A week in security (December 4 – December 10)
Meta’s Purple Llama wants to test safety risks in AI models
Meta’s Project Llama aims to help developers filter out specific items that might cause their AI model to produce inappropriate content. This article has been indexed from Malwarebytes Read the original article: Meta’s Purple Llama wants to test safety risks…
US government is snooping on people via phone push notifications, says senator
Government agencies have been asking Apple and Google for metadata related to push notifications, but the companies aren’t allowed to tell users about it. This article has been indexed from Malwarebytes Read the original article: US government is snooping on…
Android phones can be taken over remotely – update when you can
Android phones are vulnerable to attacks that allow a remote execution of malicious code and it requires no user interaction. This article has been indexed from Malwarebytes Read the original article: Android phones can be taken over remotely – update…
How IT teams can conduct a vulnerability assessment for third-party applications
A quick IT guide for conducting a vulnerability assessment. This article has been indexed from Malwarebytes Read the original article: How IT teams can conduct a vulnerability assessment for third-party applications
Windows 10 gets its own extended security updates program
Microsoft announced it will offer a similar extended security updates program for Windows 10 as it did for Windows 7 This article has been indexed from Malwarebytes Read the original article: Windows 10 gets its own extended security updates program
Adobe Coldfusion vulnerability used in attacks on government servers
CISA has published an advisory about a vulnerability in Adobe Coldfusion used in two attacks against federal agencies. This article has been indexed from Malwarebytes Read the original article: Adobe Coldfusion vulnerability used in attacks on government servers
Roblox and Twitch provider Tipalti breached by ransomware [updated]
Accounting software provider Tivalti is investigating ALPHV/BlackCat claims it was breached. In a typical supply-chain attack ALPHV is threatening some of their customers like Roblox and Twitch This article has been indexed from Malwarebytes Read the original article: Roblox and…
Roblox and Twitch provider Tipalti breached by ransomware
Accounting software provider Tivalti is investigating ALPHV/BlackCat claims it was breached. In a typical supply-chain attack ALPHV is threatening some of their customers like Roblox and Twitch This article has been indexed from Malwarebytes Read the original article: Roblox and…
23andMe says, er, actually some genetic and health data might have been accessed in recent breach
23andMe has released new details about the credential stuffing attack that took place in October. This article has been indexed from Malwarebytes Read the original article: 23andMe says, er, actually some genetic and health data might have been accessed in…
Why a ransomware gang tattled on its victim, with Allan Liska: Lock and Code S04E24
This week on the Lock and Code podcast, we speak with Allan Liska about why a ransomware group tattled on its own victim, and what to expect next year. This article has been indexed from Malwarebytes Read the original article:…
Update your iPhones! Apple fixes two zero-days in iOS
Apple has released an emergency security update for two zero-day vulnerabilities which may have already been exploited. This article has been indexed from Malwarebytes Read the original article: Update your iPhones! Apple fixes two zero-days in iOS
Social media giants to testify over failing to protect kids
US senators issued subpoenas for the CEO’s of five social media giants to testify about their “failure to protect children online”. This article has been indexed from Malwarebytes Read the original article: Social media giants to testify over failing to…
A week in security (November 27 – December 3)
A list of topics we covered in the week of November 27 to December 3 of 2023 This article has been indexed from Malwarebytes Read the original article: A week in security (November 27 – December 3)
Explained: Domain fronting
Domain fronting is a technique to hide the true origin of HTTPS requests by hiding the real domain name encrypted inside a legitimate TLS request. This article has been indexed from Malwarebytes Read the original article: Explained: Domain fronting
Will ChatGPT write ransomware? Yes.
ChatGPT 4.0 can write basic working ransomware in minutes. This article has been indexed from Malwarebytes Read the original article: Will ChatGPT write ransomware? Yes.
Associated Press, ESPN, CBS among top sites serving fake virus alerts
A fake antivirus alert may suddenly hijack your screen while browsing. This latest malvertising campaign hit top publishers. This article has been indexed from Malwarebytes Read the original article: Associated Press, ESPN, CBS among top sites serving fake virus alerts
Meta sued over forcing users to pay to stop tracking
Privacy organization nyob has filed a complaint against Meta about their “Pay or Okay” model it has introduced for European users. This article has been indexed from Malwarebytes Read the original article: Meta sued over forcing users to pay to…
Many major websites allow users to have weak passwords
A new study that looked at the password requirements of the most popular websites came to a disappointing but not surprising conclusion. This article has been indexed from Malwarebytes Read the original article: Many major websites allow users to have…
Update now! Chrome fixes actively exploited zero-day vulnerability
Google’s released an update to Chrome which includes seven security fixes. Make sure you’re using the latest version! This article has been indexed from Malwarebytes Read the original article: Update now! Chrome fixes actively exploited zero-day vulnerability
Ransomware gangs and Living Off the Land (LOTL) attacks: A deep dive
Dive deep into into the intersection of two of today’s most dangerous threats. This article has been indexed from Malwarebytes Read the original article: Ransomware gangs and Living Off the Land (LOTL) attacks: A deep dive
ownCloud vulnerability can be used to extract admin passwords
A vulnerability in the ownCloud file sharing app could lead to the exposure of sensitive credentials like admin passwords. This article has been indexed from Malwarebytes Read the original article: ownCloud vulnerability can be used to extract admin passwords
A week in security (November 20 – November 26)
A list of topics we covered in the week of November 20 to November 26 of 2023 This article has been indexed from Malwarebytes Read the original article: A week in security (November 20 – November 26)
Citrix Bleed widely exploitated, warn government agencies
Citrix Bleed is being actively exploited by at least six cybercrime groups. This article has been indexed from Malwarebytes Read the original article: Citrix Bleed widely exploitated, warn government agencies
Windows Hello fingerprint authentication can be bypassed on popular laptops
Researchers have found several weaknesses in the fingerprint authentication for Windows Hello on popular laptops. This article has been indexed from Malwarebytes Read the original article: Windows Hello fingerprint authentication can be bypassed on popular laptops
Chrome pushes forward with plans to limit ad blockers in the future
Google has set a date for the introduction of Manifest V3 which will hurt the capabilities of many ad blockers. This article has been indexed from Malwarebytes Read the original article: Chrome pushes forward with plans to limit ad blockers…
$19 Stanley cup deal is a Black Friday scam
What better way to kick off the holiday scamming season than by offering a Black Friday sale on one of the most popular products around: a Stanley cup. This article has been indexed from Malwarebytes Read the original article: $19…
Malwarebytes consumer product roundup: The latest
Here are the innovations we’ve made in our products recently. Are you making the most of them? This article has been indexed from Malwarebytes Read the original article: Malwarebytes consumer product roundup: The latest
Explained: Privacy washing
Google’s recently been accused of “privacy washing”, despite claiming its a privacy-focused company. But what is privacy washing? This article has been indexed from Malwarebytes Read the original article: Explained: Privacy washing
Nothing Chats pulled from Google Play
Nothing’s new message app Chats has been pulled from Google Play after harsh criticism about security issues. This article has been indexed from Malwarebytes Read the original article: Nothing Chats pulled from Google Play
How to stop fake System notifications on macOS
Browser push notifications are becoming a problem on macOS. Learn how to remove them. This article has been indexed from Malwarebytes Read the original article: How to stop fake System notifications on macOS
Why less is more: 10 steps to secure customer data
The Australian Cyber Security Centre has provided 10 steps for small and medium businesses to store customers’ personal data securely. This article has been indexed from Malwarebytes Read the original article: Why less is more: 10 steps to secure customer…
Atomic Stealer distributed to Mac users via fake browser updates
Compromised websites are being used to redirect to fake browser updates and deliver malware onto Mac users. This article has been indexed from Malwarebytes Read the original article: Atomic Stealer distributed to Mac users via fake browser updates
Scattered Spider ransomware gang falls under government agency scrutiny
Ransomware group Scattered Spider aka Octo Tempest are masters at social engineering tactics like SIM swapping. This article has been indexed from Malwarebytes Read the original article: Scattered Spider ransomware gang falls under government agency scrutiny
Student discount: Get 50% off Malwarebytes
We’ve got good news. Malwarebytes is now offering 50% off our products to students, wherever you are in the world. This article has been indexed from Malwarebytes Read the original article: Student discount: Get 50% off Malwarebytes
A week in security (November 13 – November 19)
A list of topics we covered in the week of November 13 to November 19 of 2023 This article has been indexed from Malwarebytes Read the original article: A week in security (November 13 – November 19)