Categories: Exploits and vulnerabilities Categories: News Tags: Oracle Tags: WebLogic Tags: CVE-2023-21839 Tags: CVE-2023-1389 Tags: CVE-2021-45046 Tags: CISA Tags: reverse shell An easy to exploit vulnerability in Oracle WebLogic Server has been added to the CISA list of things you…
Tag: Malwarebytes Labs
How to keep your ChatGPT conversations out of its training data
Categories: News Tags: ChatGPT Tags: AI training Tags: ChatGPT Business OpenAI has introduced a feature that lets you opt your conversations out of ChatGPT’s training data, but you have to switch it on. (Read more…) The post How to keep…
Is it OK to train an AI on your images, without permission?
Categories: News Tags: AI Tags: bot Tags: tool Tags: scrape Tags: scraper Tags: website. image Tags: images Tags: art Tags: artist Tags: consent A tool that’s harvesting pictures to train image-generating AIs has caused some measure of chaos among webmasters…
A week in security (April 24 -30)
Categories: News Tags: Lockbit Tags: cl0p Tags: papercut Tags: vmware Tags: magecart Tags: fileless Tags: chatgpt Tags: apc Tags: Pupy rat Tags: guloader Tags: black basta Tags: flipper zero Tags: clickjacking The most interesting security related news of the week…
How to protect your small business from social engineering
Categories: Personal Tags: Small Business Week 2023 Tags: Small Business Week Tags: phishing Tags: pretexting Tags: baiting Tags: tailgating Tags: BEC Tags: CEO fraud Tags: business email compromise Tags: O’Neill Bragg & Staffin Tags: 2022 Internet Crime Report Tags: FBI…
Microsoft: You’re already using the last version of Windows 10
Categories: News Tags: Windows 10 Tags: Windows 11 Tags: Windows 10 end of support The current version of Windows 10, version 22H2, will be the last edition of the operating system (OS). (Read more…) The post Microsoft: You’re already using…
Update now: Critical flaw in VMWare Fusion and VMWare Workstation
Categories: News Tags: VMware Tags: workstation Tags: fusion Tags: virtual machine Tags: SCSI Tags: DVD Tags: CD Tags: virtualisation Tags: exploit Tags: vulnerability Tags: flaw Tags: CVE VMWare has released fixes and mitigations for three Important and one Critical vulnerability…
LockBit and Cl0p ransomware gangs actively exploiting Papercut vulnerabilities
Categories: News Categories: Ransomware Tags: PaperCut Tags: Cl0p Tags: LockBit Vulnerabilities in PaperCut printing management are being used in ransomware attacks. (Read more…) The post LockBit and Cl0p ransomware gangs actively exploiting Papercut vulnerabilities appeared first on Malwarebytes Labs. This…
ChatGPT writes insecure code
Categories: News Tags: ChatGPT Tags: How Secure is Code Generated by ChatGPT? Tags: Raphaël Khoury Tags: Anderson Avila Tags: Jacob Brunelle Tags: Baba Mamadou Camara Tags: Université du Québec Tags: ChatGPT makes insecure code Researchers have found that ChatGPT, OpenAI’s…
Fileless attacks: How attackers evade traditional AV and how to stop them
Categories: Business Find threats camouflaging themselves in RAM. (Read more…) The post Fileless attacks: How attackers evade traditional AV and how to stop them appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original…
Magecart threat actor rolls out convincing modal forms
Categories: Threat Intelligence Tags: magecart Tags: skimmer Tags: modal Tags: fraud Tags: e-commerce It’s hard to put individuals at fault when the malicious copy is better than the original. This credit card skimmer was built to fool just about anyone.…
Decoy dog toolkit plays the long game with Pupy RAT
Categories: News Tags: Pupy RAT Tags: nation state Tags: russia Tags: decoy dog Tags: toolkit Tags: linux Tags: mobile Tags: windows Tags: malware Tags: DNS Tags: evasive We take a look at the discovery of a long running malware toolkit…
APC warns about critical vulnerabilities in online UPS monitoring software
Categories: Exploits and vulnerabilities Categories: News Tags: APC Tags: UPS Tags: Schneider Electric Tags: CVE-2023-29411 Tags: CVE-2023-29412 Tags: CVE-2023-29413 In a security notification, APC has warned home and corporate users about critical vulnerabilities in the software used to monitor and…
Update your PaperCut application servers now: Exploits in the wild
Categories: News Tags: PaperCut Tags: server Tags: exploit Tags: attack Tags: authentication Tags: update Tags: patch We take a look at urgent updates needed for users of PaperCut, after two exploits were found in the wild. (Read more…) The post…
Black Basta ransomware attacks Yellow Pages Canada
Categories: News Categories: Ransomware Tags: Yellow Pages Tags: Canada Tags: Black Basta Tags: ransomware Yellow Pages Canada has suffered a cyberattack by the Black Basta ransomware group. (Read more…) The post Black Basta ransomware attacks Yellow Pages Canada appeared first…
GuLoader returns with a rotten shipment
Categories: News Tags: GuLoader Tags: loader Tags: malware Tags: malspam Tags: email Tags: mail Tags: delivery Tags: collection Tags: scam Tags: infection Tags: Italy We take a look at a GuLoader campaign which comes bundled with an Italian language fake…
A week in security (April 17 – 23)
Categories: News Tags: fake Chrome update Tags: AirBnb scam Tags: fake IRS tax email Tags: Ransomware in Germany report Tags: Living Off The Land Tags: LOTL attack Tags: ALPHV ransomware Tags: ransomware Tags: spring cleaning your browser Tags: lost injured…
Adult content malvertising scheme leads to clickjacking
Categories: News Tags: 18+ Tags: malvertising Tags: Google ads Tags: clickjacking Malwarebytes’ researchers have discovered a malvertising scheme that uses adult lures for clickjacking purposes. (Read more…) The post Adult content malvertising scheme leads to clickjacking appeared first on Malwarebytes…
Removing the human: When should AI be used in emotional crisis? Lock and Code S03E09
Categories: Podcast This week on Lock and Code, we speak with Courtney Brown about a mental health nonprofit’s use of AI to speak to people suffering emotional distress. (Read more…) The post Removing the human: When should AI be used…
Update now, there’s a Chrome zero-day in the wild
Categories: News Tags: chrome Tags: browser Tags: update Tags: vulnerability Tags: CVE Tags: exploit Tags: exploitation Tags: zero-day Users of Chrome should ensure they’re running the latest version to patch an integer overflow in the Skia graphics library. (Read more…)…
Would-be hitman busted after being fooled by parody website
Categories: News Tags: Josiah Ernesto Garcia Tags: Air National Guard Tags: Air Guard Tags: Pentagon leak Tags: murder-for-hire Tags: hired gun Instead of using his time and military training for good, 21-year-old Josiah Garcia decided to become a hired gun—and…
US Facebook users can now claim Cambridge Analytica settlement cash
Categories: News Tags: Facebook Tags: class action lawsuit settlement Tags: Cambridge Analytica Tags: Lauren Price Tags: Meta In December, Facebook decided to pay $725 million to settle a class action lawsuit. Facebook users in the US can now claim their…
Fancy Bear known to be exploiting vulnerability in Cisco routers
Categories: Exploits and vulnerabilities Categories: News Tags: APT28 Tags: Sofacy Tags: Fancy Bear Tags: GRU Tags: Cisco Tags: CVE–2017-6742 Tags: SNMP Tags: Jaguar Tooth A joint advisory about a Cisco vulnerability by several US and UK agencies gives us a…
FTC tackles tech support scams by chasing payment processor firms
Categories: News Tags: ftc Tags: tech support scam Tags: scammers Tags: payment processor Tags: fine Tags: visa Tags: chargeback We take a look at a story involving the FTC going head to head with a payment processor caught up in…
QBot changes tactic, remains a menace to business networks
Categories: News Tags: QBot Tags: Trojan dropper QBot has resurfaced with a new tactic involving a reply-chain phishing email, a fake PDF, and the likely promise of a ransomware infection. (Read more…) The post QBot changes tactic, remains a menace…
What your peers said: G2 comparison of top Endpoint Security vendors
Categories: Business #1 in Endpoint Protection, #1 ROI for EDR, #1 for EDR implementation. (Read more…) The post What your peers said: G2 comparison of top Endpoint Security vendors appeared first on Malwarebytes Labs. This article has been indexed from…
Instagram scam promises money in exchange for your image
Categories: News Tags: fake Tags: muse Tags: art Tags: artist Tags: instagram Tags: check Tags: payment Tags: fraud Tags: wire Tags: bank Tags: banking Tags: drawing Tags: painting We take a look at a fake check scam which plugs into…
Malware authors join forces and target organisations with Domino Backdoor
Categories: News Tags: domino Tags: loader Tags: backdoor Tags: malware Tags: ransomware Tags: emotet Tags: network Tags: corporate Tags: business Tags: organisation Tags: data Tags: theft Tags: steal Tags: banking Tags: trojan We take a look at a malware collective…
Introducing the Malwarebytes Admin app: Endpoint security at your fingertips
Categories: Business IT security on the go. (Read more…) The post Introducing the Malwarebytes Admin app: Endpoint security at your fingertips appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article: Introducing the…
Payment giant’s point-of-sale outage caused by ALPHV ransomware
Categories: News Categories: Ransomware Tags: NCR Tags: Aloha Tags: ALPHV Tags: BalckCat Tags: ransomware An issue with the NCR Aloha point-of-sale system turned out to be a ransomware attack claimed by the ALPHV group (Read more…) The post Payment giant’s…
Spring cleaning tips for your browser
Categories: News Tags: Some tips that can enhance your browser’s speed Tags: so you have more time to enjoy the outdoors Some tips that can enhance your browser’s speed, so you have more time to enjoy the outdoors. (Read more…)…
Avoid this “lost injured dog” Facebook hoax
Categories: News Tags: facebook Tags: scam Tags: spam Tags: hoax Tags: dog Tags: injured Tags: lost Tags: vet Tags: missing We take a look at a Facebook hoax which uses supposedly injured dogs as the lure for a bait and…
Swatting-as-a-Service is a growing and complicated problem to solve
Categories: News Tags: swatting Tags: caller ID spoofing Tags: telegram Tags: cryptocurrency Tags: AI generated voice Using a false call to deploy emergency services to the address of a victim or a school has been turned into Swatting-as-a-Service (Read more…)…
LockBit ransomware on Mac: Should we worry?
Categories: News Categories: Ransomware Tags: LockBit Tags: ransomware Tags: Patrick Wardle Tags: macOS ransomware Tags: first Mac ransomware Tags: Azim Khodjibaev Tags: BleepingComputer Tags: Mark Stockley With plans to offer more ransomware, LockBit has just created a variant for macOS.…
Woman tracks down and turns table on Airbnb scammer
Categories: News Categories: Scams Tags: Airbnb Tags: TikTok Tags: @livvoogus Tags: Olivia Tags: Mr. Tyler A superhost scammed a woman out of a thousand dollars. She didn’t take it lying down. (Read more…) The post Woman tracks down and turns…
Update Chrome now! Google patches actively exploited flaw
Categories: Exploits and vulnerabilities Categories: News Tags: Google Tags: Chrome zero-day Tags: CVE-2023-2033 Tags: V8 flaw Tags: V8 Google has released an updated version of Chrome to address a zero-day flaw that is being exploited in the wild. (Read more…)…
Beware: Fake IRS tax email wants your Microsoft account
Categories: News Categories: Scams Tags: IRS tax scam Tags: tax scam Tags: IRS Tags: Jerome Segura Tags: Telegram bot Tags: Emotet Expect more IRS tax-related shenanigans from fraudsters, who are now going for corporate accounts, after some states received deadline…
Ransomware in Germany, April 2022 – March 2023
Categories: News In the last 12 months, Germany was one of the most attacked countries in the world, the most attacked in the EU, and a favourite target of the notorious Black Basta group. (Read more…) The post Ransomware in…
Living Off the Land (LOTL) attacks: Detecting ransomware gangs hiding in plain sight
Categories: Business Good tools gone bad. (Read more…) The post Living Off the Land (LOTL) attacks: Detecting ransomware gangs hiding in plain sight appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article:…
Massive malvertising campaign targets seniors via fake Weebly sites
Categories: Threat Intelligence Tags: malvertising Tags: weebly Tags: google Tags: ads Tags: seniors Tags: recipe Tags: tech support Tags: scam Scammers are buying ads on for the most common Google searches made by seniors and defrauding them with tech support…
Is AI being used for virtual kidnapping scams?
Categories: News Tags: kidnap Tags: scam Tags: virtual Tags: AI Tags: voice Tags: fake Tags: fraud Tags: hoax Tags: kidnapping We take a look at claims that AI is now being used for a notorious form of kidnapping hoax. (Read…
Port scan attacks: Protecting your business from RDP attacks and Mirai botnets
Categories: Business Prevent port scanning attacks with Malwarebytes for Business. (Read more…) The post Port scan attacks: Protecting your business from RDP attacks and Mirai botnets appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read…
Google Pay accidentally handed out free money, bug now fixed
Categories: News Tags: Google Pay Tags: Google Pay bug Tags: free money All good things must end, they say, including generous offers of rewards caused by a short-lived glitch in Google Pay. (Read more…) The post Google Pay accidentally handed…
Sextortion “assistance” scammers con victims further
Categories: News Tags: FBI Tags: extortion Tags: sextortion Tags: crime Tags: criminal Tags: nude Tags: nudes Tags: photographs Tags: images Tags: video Tags: photo Tags: scam Tags: payment Tags: profit Tags: assistance Tags: help We take a look at an…
Ransomware in France, April 2022–March 2023
Categories: Ransomware Categories: Threat Intelligence In the last 12 months France was one of the most attacked countries in the world, and a favourite target of LockBit, the world’s most dangerous ransomware. (Read more…) The post Ransomware in France, April…
Ransomware review: April 2023
Categories: Ransomware Categories: Threat Intelligence Cl0p was the most used ransomware in March 2023, dethroning the usual frontrunner LockBit, after breaching over 104 organizations with a zero-day vulnerability. (Read more…) The post Ransomware review: April 2023 appeared first on Malwarebytes…
Don’t plug your phone into a free charging station, warns FBI
Categories: Awareness Categories: News Tags: FBI Tags: juice jacking Tags: public chargers The FBI warned consumers against using free public charging stations, stating that criminals have managed to hijack public chargers to infect devices with malware. (Read more…) The post…
KFC, Pizza Hut owner employee data stolen in ransomware attack
Categories: News Categories: Ransomware Tags: The Habit Burger Grill Tags: KFC Tags: Pizza Hut Tags: Yum! Brands Tags: ransomware Yum! Brands, owner of KFC, Pizza Hut, and other fast food chains, was breached in January. It recently found employee data…
Ransomware in the UK: April 2022–March 2023
Categories: Ransomware Categories: Threat Intelligence In the last 12 months, the UK has been second only to the USA in terms of ransomware attacks, and its education sector has been subjected to a feeding frenzy by Vice Society. (Read more…)…
Update now! April’s Patch Tuesday includes a fix for one zero-day
Categories: Exploits and vulnerabilities Categories: News Tags: Microsoft Tags: Apple Tags: Google Tags: Adobe Tags: Cisco Tags: SAP Tags: Mozilla Tags: CVE-2023-28252 Tags: CVE-2023-28231 Tags: CVE-2023-21554 Tags: Word Tags: Publisher Tags: Office One fixed vulnerability is being actively exploited by…
A week in security (April 3 – 9)
Categories: News Tags: TikTok Tags: Super FabriXss Tags: Twitter Tags: macOS malware Tags: ransomware Tags: 2023 State of Malware Tags: Western Digital Tags: Android Tags: endpoint security Tags: ChatGPT Tags: K-12 Tags: IoT Tags: Facebook Tags: targeted advertising Tags: Google…
Apple releases emergency updates for two known-to-be-exploited vulnerabilities
Categories: Apple Categories: Exploits and vulnerabilities Categories: News Tags: iOS 16.4.1 Tags: iPadOS 16.4.1 Tags: macOS 13.3.1 Tags: CVE-2023-28206 Tags: CVE-2023-28205 Tags: use-after-free Tags: out-of-bounds write Tags: IOSurfaceAccelerator Apple has released iOS 16.4.1, iPadOS 16.4.1, and macOS 13.3.1 for the…
How the cops buy a “God view” of your location data, with Bennett Cyphers: Lock and Code S04E09
Categories: Podcast This week on Lock and Code, we speak with Bennett Cyphers about one largely unknown company’s efforts to package and sell Americans’ location data almost exclusively to cops. (Read more…) The post How the cops buy a “God…
IoT garage door exploit allows for remote opening attack
Categories: News Tags: IoT Tags: garage Tags: door Tags: remote Tags: open Tags: app Tags: switch Tags: alarm Tags: Nexx Multiple exploits are impacting a line of smart products for the home. (Read more…) The post IoT garage door exploit…
New tool allows you to opt out of Facebook’s targeted advertising
Categories: News Categories: Privacy Privacy watchdog noyb has built a tool for EU users to make it easier to opt out of Meta’s targeted advertising. (Read more…) The post New tool allows you to opt out of Facebook’s targeted advertising…
Google aims to reduce data theft with app data and account deletions
Categories: News Tags: android Tags: mobile Tags: play Tags: app store Tags: app Tags: application Tags: data Tags: collection Tags: account Tags: user Tags: delete Tags: deletion We take a look at proposals from Google to make it easier for…
Visitors of tax return e-file service may have downloaded malware
Categories: News Categories: Scams Tags: tax scams Tags: efile.com Tags: US tax 2023 Tags: backdoor Tags: Trojan Tags: Johannes Ullrich Tags: MalwareHunterTeam Tags: /u/SaltyPotter Tags: fake network error notification Cybercriminals have compromised eFile.com to host malicious code that allows for…
Uber data theft: Driver info stolen after law firm breached
Categories: News Tags: Uber breach Tags: Genova Burns Tags: The Register For the third time in the last six months, internal Uber data has been compromised. This latest incident is the result of a supply chain attack. (Read more…) The…
Fake ransomware demands payment without actually encrypting files
Categories: News Tags: ransomware Tags: fake Tags: faker Tags: fraud Tags: scam Tags: bogus Tags: midnight We take a look at a ransomware group that doesn’t produce any ransomware, only threats. (Read more…) The post Fake ransomware demands payment without…
Western Digital confirms breach, affects My Cloud and SanDisk users
Categories: News Tags: Western Digital Tags: WD Tags: data breach Tags: My Cloud Tags: SanDisk The company behind My Cloud and SanDisk says it has experienced a security incident. Little is still known about what happened and who attacked it.…
TikTok misused children’s data, faces $15.6M fine
Categories: News Tags: TikTok Tags: Information Commissioner’s Office Tags: ICO Tags: Sonia Livingston Tags: John Edwards TikTok has been fined by a UK data protection watchdog after its investigation shows the company failed to get parental consent. (Read more…) The…
Update Android now! Google patches three important vulnerabilities
Categories: Android Categories: Exploits and vulnerabilities Categories: News Tags: Google Tags: Android Tags: update Tags: CVE-2023-21085 Tags: CVE-2023-21096 Tags: CVE-2022-38181 Tags: Use-after-free Tags: input validation Google has released an Android update that fixes two critical remote code execution (RCE) vulnerabilities,…
9 vital criteria for effective endpoint security: Insights from the ‘Endpoint Security Evaluation Guide’ eBook
Categories: Business Our Endpoint Security Evaluation Guide eBook helps you choose the right endpoint security solution. (Read more…) The post 9 vital criteria for effective endpoint security: Insights from the ‘Endpoint Security Evaluation Guide’ eBook appeared first on Malwarebytes Labs.…
Pre-ransomware notifications are paying off right from the bat
Categories: News Categories: Ransomware Tags: pre-ransomware notifications Tags: JCDC Tags: CISA Tags: ransomware Tags: IRS Tags: Emotet Tags: MDR CISA has published the first results of its pre-ransomware notifications that were introduced at the start of 2023. And they appear…
2023 State of Malware Report: What the channel needs to know to stay ahead of threats
Categories: Business There are 5 cyberthreats for channel partners to focus on in 2023. (Read more…) The post 2023 State of Malware Report: What the channel needs to know to stay ahead of threats appeared first on Malwarebytes Labs. This…
A week in security (March 27 – April 2)
Categories: News Tags: Lock and Code Tags: Anna Pobletts Tags: ChatGPT Tags: World Backup Day Tags: GitHub Tags: accidental breach Tags: DDoS service Tags: Instagram scammer Tags: top cyber threats of 2023 Tags: 3CX Tags: BingBang Tags: Apple Tags: EE…
TikTok: What’s going on and should I be worried?
Categories: News Categories: Privacy Tags: TikTok Tags: social media Tags: data Tags: app Tags: privacy Tags: algorithm TikTok has garnered a ton of media attention about its alleged risks. But is it really that much worse than other social media…
Super FabriXss: an RCE vulnerability in Azure Service Fabric Explorer
Categories: Exploits and vulnerabilities Categories: News Tags: Azure Tags: Microsoft Tags: Super FabriXss Tags: RCE Tags: vulnerability Tags: CVE-2023-23383 Researchers disclosed how they found a remote code execution vulnerability in Azure Service Fabric Explorer. (Read more…) The post Super FabriXss:…
Big changes to Twitter verification: How to spot a verified account
Categories: News Tags: twitter Tags: blue Tags: verified Tags: verification Tags: fake Tags: fraud Tags: phish Tags: phishing Tags: scam Tags: imposter Significant changes to Twitter’s verification identifiers mean new rules for ensuring whether an account is real. (Read more…)…
New macOS malware steals sensitive info, including a user’s entire Keychain database
Categories: Apple Categories: News Tags: MacStealer Tags: mac infostealer Tags: information stealer Tags: Apple Tags: Thomas Reed Tags: iCloud Keychain MacStealer could be an infamous stealer in the making, but right now, it needs improvement, according to Malwarebytes expert. (Read…
Steer clear of this EE phish that wants your card details
Categories: News Tags: EE Tags: phish Tags: phishing Tags: scam Tags: fake Tags: mail Tags: email Tags: fraud Tags: bank details We take a look at a phish targeting users of the EE mobile network. (Read more…) The post Steer…
3 tips to raise your backup game
Categories: Personal Because backups are the dental floss of cybersecurity—the thing that everyone knows they should do, that everyone intends to do, that nobody actually does. (Read more…) The post 3 tips to raise your backup game appeared first on…
3 tips for creating backups your organization can rely on when ransomware strikes
Categories: News Categories: Ransomware Tags: World Backup Day Backups are your last line of defense against ransomware, if they work. (Read more…) The post 3 tips for creating backups your organization can rely on when ransomware strikes appeared first on…
Smart home assistants at risk from “NUIT” ultrasound attack
Categories: News Tags: ultrasound Tags: NUIT Tags: speakers Tags: microphone Tags: device Tags: IoT Tags: assistant Tags: alexa Tags: siri Tags: google Tags: silent We take a look at research for an IoT attack called NUIT, capable of hijacking voice…
3CX desktop app used in a supply chain attack
Categories: News Tags: 3CX Tags: supply-chain Tags: sideload Researchers have found that the 3CX desktop app may be compromised and used in supply chain attacks. (Read more…) The post 3CX desktop app used in a supply chain attack appeared first…
“BingBang” flaw enabled altering of Bing search results, account takeover
Categories: News Tags: bing Tags: microsoft Tags: azure Tags: takeover Tags: search Tags: results Tags: access We take a look at the BingBang flaw which allowed for search engine manipulation in Bing. (Read more…) The post “BingBang” flaw enabled altering…
Update now! Apple fixes actively exploited vulnerability and introduces new features
Categories: Apple Categories: Exploits and vulnerabilities Categories: News Tags: macOS Tags: iOS Tags: iPadOS Tags: watchOS Tags: tvOS Tags: Studio Display Tags: CVE-2023-23529 Tags: type confusion Tags: emoji Apple has released security updates and new features for several of its…
ChatGPT happy to write ransomware, just really bad at it
We asked ChatGPT to help us write some ransomware. It threw aside its safeguards and wrote some terrible code. (Read more…) The post ChatGPT happy to write ransomware, just really bad at it appeared first on Malwarebytes Labs. This article…
“Log-out king” Instagram scammer gets accounts taken down, then charges to reinstate them
Categories: News Tags: Instagram scam Tags: Instascammer Tags: ban-as-a-service Tags: BaaS Tags: takedown-for-hire Tags: OBN Brandon Tags: obnbrandon Tags: OBN A fraudster going by OBN Brandon has been defrauding Instagram influencers and entertainment figures out of hundreds of thousands of…
ChatGPT helps both criminals and law enforcement, says Europol report
Categories: News Tags: ChatGPT Tags: large language models Tags: LLMs Tags: jailbreak Tags: restrictions Tags: impersonating Tags: misinformation Subject matter experts at Europol were asked to explore how criminals can abuse LLMs such as ChatGPT, as well as how they…
Fake DDoS services set up to trap cybercriminals
Categories: News Tags: NCA Tags: national crime agency Tags: DDoS Tags: distributed denial of service Tags: booter Tags: underground The British National Crime Agency has been setting up fake DDoS services to teach people a lesson in what not to…
Food giant Dole reveals more about ransomware attack
Categories: News Categories: Ransomware Tags: Dole Tags: ransomware attack Tags: data breach While Dole hasn’t said a lot about the February ransomware incident, it has revealed threat actors accessed employee data. (Read more…) The post Food giant Dole reveals more…
Bogus Chat GPT extension takes over Facebook accounts
Categories: News Tags: Chat GPT Tags: chrome Tags: extension Tags: rogue Tags: facebook Tags: cookies We look at a bogus Chat GPT Chrome extension which was after Facebook cookies. (Read more…) The post Bogus Chat GPT extension takes over Facebook…
Ransomware gunning for transport sector’s OT systems next
Categories: News Categories: Ransomware Tags: ENISA Tags: operational technology Tags: OT Tags: OT systems Tags: ransomware ENISA released a report tackling the threat landscape of the transportation industry. And it has foreseen the targeting of OT systems in the future.…
GitHub accidentally exposes RSA SSH key
Categories: News Tags: GitHub Tags: RSA Tags: SSH Developer platform GitHub has changed its RSA SSH key after it was accidentally exposed on a public repository. (Read more…) The post GitHub accidentally exposes RSA SSH key appeared first on Malwarebytes…
Solving the password’s hardest problem with passkeys, featuring Anna Pobletts
Categories: Podcast This week on Lock and Code, we speak with Anna Pobletts about the death of passwords, and how passkeys can become the non-compromising fix to authentication’s biggest problems. (Read more…) The post Solving the password’s hardest problem with…
USB bombs sent to news organizations
Categories: News Tags: usb Tags: bomb Tags: mail Tags: post Tags: letter USB sticks repurposed as explosive devices provide a dramatic reminder of how little you know about unknown USB devices. (Read more…) The post USB bombs sent to news…
ChatGPT leaks bits of users’ chat history
Categories: News Tags: ChatGPT Tags: privacy Tags: chat history ChatGPT suddenly started showing users the titles of other users’ chats. (Read more…) The post ChatGPT leaks bits of users’ chat history appeared first on Malwarebytes Labs. This article has been…
Beware: Fake IRS tax email delivers Emotet malware
Categories: News Tags: emotet Tags: malware Tags: IRS Tags: scam Tags: email Tags: W-9 Tags: word Tags: document Tags: macro Tags: macros We look at a current tax scam in circulation which looks to make an Emotet deposit on your…
BreachForums to be shut down after all for fear of law enforcement infiltration
Categories: News Tags: BreachForums Tags: Pompompurin Tags: FBI Tags: Dark Web Tags: data breaches After the arrest of the administrator of the Dark Web site BreachForums there was talk about keeping it alive, but now the forums will be shut…
Google Pixel: Cropped or edited images can be recovered
Categories: Exploits and vulnerabilities Categories: News Tags: Google Tags: Pixel Tags: Markup Tags: CVE-2023-21036 Tags: recover Tags: PNG Tags: truncated A vulnerability in the Markup tool that comes pre-installed on Pixel phones allows anyone with access to the edited image…
New Kritec Magecart skimmer found on Magento stores
Categories: Threat Intelligence Tags: Magecart Tags: skimmer Tags: Kritect Tags: Magento Compromised online stores have been injected with skimmers hiding around the Google Tag Manager script. We identified a new one that looked similar at first but is part of…
A look at a Magecart skimmer using the Hunter obfuscator
Categories: Threat Intelligence Tags: magecart Tags: skimmer Tags: obfuscation Tags: hunter Tags: credit card Tags: magento The threat actor behind this operation is using an open-source JavaScript obfuscator to hide its code. (Read more…) The post A look at a…
The NBA tells fans about data breach
Categories: News Tags: NBA Tags: data breach Tags: Mailchimp The NBA is warning fans of a data breach at a third-party newsletter service which could result in targeted phishing attempts (Read more…) The post The NBA tells fans about data…
Malware creator who compromised 10,000 computers arrested
Categories: News Tags: RAT Tags: ukraine Tags: trojan Tags: arrest Tags: game Tags: application Tags: fake We take a look at news of an arrest in Ukraine regarding the creator of a remote access trojan. (Read more…) The post Malware…
A week in security (March 13 – 19)
Categories: News Tags: Becky Holmes Tags: Lock and Code S04E06 Tags: ransomware Tags: WhatsApp Tags: AI chatbot Tags: investment fraud Tags: Clop Tags: Microsoft zero-day Tags: Microsoft Tags: STALKER 2 Tags: Facebook Tags: Microsoft OneNote Tags: LockBit Tags: Rubrik The…
“ViLE” members posed as police officers and extorted victims
Categories: News Tags: Doxxers Tags: doxxing Tags: police Tags: social media Tags: extortion Tags: data breach Two individuals have been charged with being members of ViLE, a group of doxxers that even impersonated police officers to obtain personal information about…
Google reveals 18 chip vulnerabilities threatening mobile, wearables, vehicles
Categories: News Tags: android Tags: google Tags: samsung Tags: chip Tags: VoLTE Tags: modem Tags: chipset Tags: vulnerability Tags: pixel Tags: CVE-2023-24033 We take a look at multiple vulnerabilities highlighted by Google’s Project Zero team, and what you can do…
LockBit ransomware attacks Essendant
Categories: News Categories: Ransomware Tags: lockbit Tags: ransomware Tags: essendant Tags: data Tags: encrypt Tags: ransom Tags: leak Tags: website Tags: outage Tags: network The LockBit ransomware group has attacked Essendant, a US-based distributor of office products, and is threatening…
Rubrik is latest victim of the Clop ransomware zero-day campaign
Categories: News Categories: Ransomware Tags: Rubrik Tags: GoAnywhere MFT Tags: Fortra Tags: Clop ransomware Tags: Clop Tags: ransomware Tags: CVE-2023-0669 Tags: zero-day Rubrik, a cloud data management company, has revealed that Clop made use of an infamous GoAnywhere flaw. (Read…