Tag: Malwarebytes Labs

Ransomware attack hits ANOTHER school

Categories: News Categories: Ransomware Tags: Wymondham College Tags: ransomware attack Tags: ransomware Tags: Vice Society Tags: National Cyber Security Centre Tags: NCSC Wymondham College is operating as normal, with a few expected distruptions that may be minimal but lasting. (Read…

Facebook illegally processed user data, says court

Categories: News Categories: Privacy Two European privacy watchdogs have won cases against Meta. The rulings may have serious consequences for European website owners. (Read more…) The post Facebook illegally processed user data, says court appeared first on Malwarebytes Labs. This…

Emotet adopts Microsoft OneNote attachments

Categories: Threat Intelligence Emotet finally got the memo and added Microsoft OneNote lures. (Read more…) The post Emotet adopts Microsoft OneNote attachments appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs Read the original article: Emotet…

Update now! Microsoft fixes two zero-day bugs

Categories: Exploits and vulnerabilities Categories: News Tags: patch Tuesday Tags: March Tags: 2023 Tags: Microsoft Tags: Adobe Tags: Fortinet Tags: Android Tags: SAP Tags: CVE-2023-23397 Tags: CVE-2023-24880 Tags: CVE-2023-26360 Tags: CVE-2022-41328 This Patch Tuesday, Microsoft has released fixes for two…

“Just awful” experiment points suicidal teens at chatbot

Categories: News Categories: Privacy Tags: Koko Tags: Robert Morris Tags: Motherboard Tags: AI ethics Tags: AI Tags: artificial intelligence Startup Koko has been criticized for experimenting with young adults at risk of harming themselves. Worse, the young adults were unaware…

Clop ransomware is victimizing GoAnywhere MFT customers

Categories: Exploits and vulnerabilities Categories: News Categories: Ransomware Tags: Clop Tags: ransomware Tags: GoAnywhere Tags: CVE-2023-0669 The Clop ransomware gang has claimed responsibility for attacking several GoAnywhere MFT customers by exploiting a vulnerability in the managed file transfer software’s administrative…

A week in security (March 6 – 12)

Categories: News The most interesting security related news from the week of March 6 to 12. (Read more…) The post A week in security (March 6 – 12) appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

Breast cancer photos published by ransomware gang

Categories: News Categories: Ransomware Tags: ALPHV Tags: BlackCat Tags: Lehigh Valley Health Network Tags: LVHN Russia-linked ransomware group ALPHV has leaked the data it stole from Lehigh Valley Health Network, including clinical photos of women undergoing breast cancer treatment. (Read…

WhatsApp refuses to weaken encryption, would rather leave UK

Categories: News Categories: Privacy Tags: WhatsApp Tags: Online Safety Bill Tags: encryption Tags: Signal end-to-end encryption Tags: private messaging With the UK’s Online Safety Bill set to become law this year, WhatsApp is standing its ground against weakening encryption. (Read…

TikTok “a loaded gun” says NSA

Categories: News Categories: Privacy Speaking at a US Senate hearing on Wednesday, General Paul Nakasone, Director of the NSA, said one sixth of American youth say they’re constantly on TikTok. That’s a loaded gun. (Read more…) The post TikTok “a…

Malware targeting SonicWall devices could survive firmware updates

Categories: News Researchers at Mandiant have identified a campaign that persisted on SonicWall SMA 100 Series appliances tenaciously. (Read more…) The post Malware targeting SonicWall devices could survive firmware updates appeared first on Malwarebytes Labs. This article has been indexed…

Update Android now! Two critical vulnerabilities patched

Categories: Android Categories: News Tags: Android Tags: 2023-03-05 Tags: RCE Tags: EoP Tags: CVE-2023-20951 Tags: CVE-2023-20954 Tags: CVE-2022-33213 Tags: CVE-2022-33256 Tags: CVE-2021-33655 The March security updates for Android include fixes for two critical remote code execution (RCE) vulnerabilities. Update as…

DoppelPaymer ransomware group disrupted

Categories: News Categories: Ransomware Tags: Europol Tags: FBI Tags: police Tags: arrests Tags: DoppelPaymer Tags: Emotet Tags: Dridex In cooperation with the FBI, European police agencies have made arrests that have disrupted the DoppelPaymer ransomware operation (Read more…) The post…

Ransomware review: March 2023

Categories: Ransomware Categories: Threat Intelligence February 2023 saw a record number of victims for LockBit, a record high ransom demand, and a devastating assault on the City of Oakland. (Read more…) The post Ransomware review: March 2023 appeared first on…

Warning issued over Royal ransomware

Categories: News Categories: Ransomware Tags: CISA Tags: Royal Tags: ransomware Tags: phishing Tags: RDP Tags: public facing applications In a Cybersecurity Advisory, CISA and the FBI have shared information about Royal ransomware, which despite being rather new has made a…

Play ransomware gang leaks City of Oakland data

Categories: News Categories: Ransomware Tags: Play ransomware Tags: ransomware Tags: City of Oakland Tags: Oakland California After claiming responsibility for attacking the City of Oakland, California, the Play ransomware gang has begun leaking the data it stole. (Read more…) The…

A week in security (February 27 – March 5)

Categories: News The most interesting security related news from the week of February 27 to March 5. (Read more…) The post A week in security (February 27 – March 5) appeared first on Malwarebytes Labs. This article has been indexed…

8 cybersecurity tips to keep you safe when travelling

Categories: Awareness Categories: News Tags: travel Tags: safe Tags: devices Tags: VPN Tags: backups Tags: connections Tags: updates Here are some cybersecurity tips to keep you safe while you travel. (Read more…) The post 8 cybersecurity tips to keep you…

National Cybersecurity Strategy Document: What you need to know

Categories: News Tags: whitehouse Tags: biden Tags: national cybersecurity document Tags: federal Tags: government Tags: data Tags: privacy Tags: security The US Government has been working on the National Cybersecurity Strategy Document 2023 for some time now, and it’s finally…

Intel CPU vulnerabilities fixed. But should you update?

Categories: Exploits and vulnerabilities Categories: News Tags: CVE-2022-21123 Tags: CVE-2022-21125 Tags: CVE-2022-21127 Tags: CVE-2022-21166 Tags: Intel Tags: VMs Tags: microcode Microsoft has released out of band updates for information disclosure vulnerabilities in Intel CPUs, but who needs them? (Read more…)…

YouTube under fire for allegedly gathering children’s data

Categories: News Tags: YouTube Tags: ICO Tags: data Tags: children Tags: YouTube Kids Tags: gathering Tags: collecting Tags: safety Tags: privacy The complaint asserts that YouTube collected “the location, viewing habits and preferences” of up to five million children. (Read…

LockBit ransomware demands $2 million for Pierce Transit data

Categories: News Categories: Ransomware Tags: Pierce Transit Tags: Tacoma Tags: Washington Tags: LockBit Tags: ransomware The ransomware group LockBit is offering data stolen from a Washington state public transit operator on the dark web. (Read more…) The post LockBit ransomware…

Ransomware led to multiple DISH Network outages

Categories: News Tags: DISH network Tags: ransomware Tags: SEC Tags: attack Tags: compromise Tags: outage We take a look at a ransomware outbreak impacting multiple DISH Network services. (Read more…) The post Ransomware led to multiple DISH Network outages appeared…

LastPass was undone by an attack on a remote employee

Categories: News Tags: LastPass Tags: remote Tags: work Tags: worker Tags: VPN Tags: media player Tags: compromise Tags: breach Tags: AWS Tags: cloud Tags: storage The attackers responsible for the LastPass breach compromised a remote worker’s computer. (Read more…) The…

AI voice cracks telephone banking voice recognition

Categories: News Tags: AI Tags: voice Tags: generated Tags: synthetic Tags: bank Tags: banking Tags: telephone Tags: login Tags: account Now that we have freely available artificial intelligence happily replicating people’s voices, could it be a security risk? (Read more…)…

iPhone users targeted in phone AND data theft campaign

Categories: News Tags: iPhone theft Tags: passcode theft Tags: iPhone and passcode theft Tags: Apple Tags: shoulder surfing Tags: social engineering When is an iPhone theft not just an iPhone theft? When the user’s Apple ID and more, goes with…

US Marshals Service hit by ransomware and data breach

Categories: News Categories: Ransomware Tags: US Marshalls Tags: WITSEC Tags: usms Tags: ransomware The US Marshals Service has suffered a ransomware attack in which an attacker managed to get hold of sensitive information about staff and fugitives. (Read more…) The…

A week in security (February 20 – 26)

Categories: News The most interesting security related news from the week of February 20 to 26. (Read more…) The post A week in security (February 20 – 26) appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes…

TikTok probed over child privacy practices

Categories: News Categories: Privacy Tags: Canada Tags: TikTok Tags: privacy Tags: young Tags: bans Tags: Netherlands Tags: EU Tags: UK Tags: state employees Canadian privacy protection authorities have announced they will start an investigation into TikTok’s privacy practices, especially in…

How to work from home securely, the NSA way

Categories: News Tags: network Tags: home Tags: secure Tags: router Tags: NSA Tags: social engineering Tags: social network Tags: email Tags: update Tags: hotspot The NSA has some advice about keeping remote workers safe from harm. (Read more…) The post…

Fake Amazon Prime email abuses LinkedIn’s URL shortener

Categories: News Categories: Scams Tags: LinkedIn Tags: Slinks Tags: phish Tags: phishing Tags: email Tags: payment details Tags: amazon Tags: gmail Tags: outlook Tags: hotmail Tags: scam Tags: scammers The email claims if you not update your card information in…

Samsung adds Message Guard protection against zero-click exploits

Categories: Android Categories: News Tags: Samsung Tags: message guard Tags: sandbox Tags: zero-click exploit Tags: images Tags: attachments Samsung has announced the introduction of Message Guard protection against zero-click exploits for the Samsung Galaxy S23 series. (Read more…) The post…

DNA testing company fined after customer data theft

Categories: News Tags: DNA Diagnostics Center Tags: DDC Tags: Orchid Cellmark Tags: DNA testing industry Tags: Ohio Attorney General Dave Yost Tags: Acting Attorney General Michelle Henry DNA Diagnostics Center, a leading DNA testing company, failed to protect client data…

BlackCat ransomware targets another healthcare facility

Categories: News Categories: Ransomware Tags: Lehigh Valley Health Network Tags: LVHN Tags: BlackCat Tags: ALPHV Tags: Noberus Tags: ransomware Tags: leak site Tags: DDoS The Lehigh Valley Health Network stated it was the target of a cybersecurity attack by a…

Royal Mail schools LockBit in leaked negotiation

Categories: News The LockBit gang has released a chat history showing its negotiations with Royal Mail. (Read more…) The post Royal Mail schools LockBit in leaked negotiation appeared first on Malwarebytes Labs. This article has been indexed from Malwarebytes Labs…

Twitter and two-factor authentication: What’s changing?

Categories: News Tags: twitter Tags: 2fa Tags: sms Tags: 2 factor authentication Tags: app Tags: authorisation Tags: authentication app Tags: hardware key Tags: login Tags: phish Tags: phishing Tags: verify Tags: mobile Twitter is making radical changes to how two…

A week in security (February 13 – 19)

Categories: News Tags: Josh Saxe Tags: Lock and Code S04E04 Tags: AI Tags: artificial intelligence Tags: endpoint security leader Tags: CISA Tags: DPRK Tags: ChatGPT Tags: informed consent Tags: valentine’s day Tags: password sharing Tags: Android Tags: data leaks Tags:…

GoAnywhere zero-day opened door to Clop ransomware

Categories: News Categories: Ransomware Tags: Clop Tags: Clop ransomware Tags: ransomware Tags: GoAnywhere Tags: managed file transfer Tags: MFT Tags: Fortra Tags: CISA Tags: Known Exploited Vulnerabilities Catalog The Clop ransomware gang has claimed responsibility for a wave of attacks…

Chip company loses $250m after ransomware hits supply chain

Categories: News Categories: Ransomware Tags: Applied materials Tags: MKS Tags: ransomware Tags: semiconductor Applied Materials has said it expects to miss $250 million in second-quarter sales due to a ransomware attack at a supplier. (Read more…) The post Chip company…

TikTok car theft challenge: Hyundai, Kia fix flaw

Categories: News Tags: Hyundai Tags: Kia Tags: car theft hack Tags: Kia Challenge Tags: viral TikTok challenge Tags: TikTok Hyundai and Kia have released a software update to fix a car theft hack that went viral on TikTok, and resulted…

iPhone calendar spam: What it is, and how to remove it

Categories: Awareness Categories: News Categories: Scams Tags: iPhone Tags: calendar Tags: spam Tags: iOS Tags: mobile Tags: device Tags: ad Tags: advert Tags: popup Tags: permission Tags: remove Tags: notification Tags: Apple Is your iPhone claiming that you’ve been hacked,…

WordPress sites backdoored with ad fraud plugin

Categories: Threat Intelligence Tags: ad fraud Tags: popunder Tags: ads Tags: fraud Tags: wordpress Tags: plugins Popunders are the ideal vehicle to serve ad fraud. In this case, we investigate a scheme where a webpage you can’t see is loading…

Fake Hogwarts Legacy cracks lead to adware, scams

Categories: News Categories: Scams Tags: Hogwarts Legacy Tags: video game survey scam Tags: survey scam Tags: Trojan dropper Tags: adware With Hogwarts Legacy becoming the popular game it was expected to be, online criminals have resorted to old tricks to…

Arris router vulnerability could lead to complete takeover

Categories: Exploits and vulnerabilities Categories: News Tags: Yerodin Richards Tags: Arris Tags: routre Tags: CVE-2022-45701 Tags: default credentials A security researcher found an authenticated remote code execution vulnerability in very wide-spread Arris router models. (Read more…) The post Arris router…

Ransomware pushes City of Oakland into state of emergency

Categories: News Categories: Ransomware Tags: Oakland Tags: ransomware Tags: state of emergency The Interim City Administrator of the City of Oakland declared a state of emergency.after a ransomware attack crippled the city’s services a week ago (Read more…) The post…

Update now! Apple patches vulnerabilities in MacOS and iOS

Categories: Apple Categories: Exploits and vulnerabilities Tags: Apple Tags: macOS Ventura Tags: 13.2.1 Tags: iOS Tags: iPadOS Tags: 16.3.1 Tags: CVE-2023-23514 Tags: CVE-2023-23522 Tags: CVE-2023-23529 Tags: use after free Tags: type confusion Apple has released patches for macOS Ventura, iPadOs,…

Update now! February’s Patch Tuesday tackles three zero-days

Categories: Exploits and vulnerabilities Categories: News Tags: patch Tuesday Tags: Microsoft Tags: Apple Tags: Adobe Tags: SAP Tags: Citrix Tags: Cisco Tags: Atlassian Tags: Google Tags: Mozilla Tags: Forta Tags: OpenSSH Tags: CVE-2023-21823 Tags: CVE-2023-21715 Tags: OneNote Tags: CVE-2023-23376 Tags:…

Should you share passwords with your partner?

Categories: Personal Tags: love and passwords Tags: password sharing with partner Tags: privacy This Valentine’s Day, we ask the inevitable password question: is it okay to share passwords with your partner? (Read more…) The post Should you share passwords with…

One in nine online stores are leaking your data, says study

Categories: News Categories: Privacy Tags: Sansec Tags: leaky data Tags: online store leaks Tags: web skimming A recent study reveals that while users are comfortable shopping online, a number of online stores are accidentally leaking shoppers’ highly sensitive data. (Read…

Malwarebytes recognized as endpoint security leader by G2

Categories: Business G2 has released their Winter 2023 reports, ranking Malwarebytes as the leader across a number of endpoint protection categories based on customer reviews. (Read more…) The post Malwarebytes recognized as endpoint security leader by G2 appeared first on…

A week in security (February 6 – 12)

Categories: News Tags: VMware ESXi Tags: Safer Internet Day Tags: Malwarebytes Mobile Security Tags: ION Tags: LockBit ransomware Tags: ransomware Tags: GoAnywhere Tags: Ryuk Tags: Malwarebytes Application Block Tags: BEC Tags: business email compromise Tags: fake Facebook Tags: Facebook Tags:…

Reddit breached, here’s what you need to know

Categories: News Tags: reddit Tags: compromise Tags: phish Tags: phishing Tags: users Tags: data Tags: 2FA In an admirably transparent notification, Reddit announced that one of its employees was phished. (Read more…) The post Reddit breached, here’s what you need…

KillNet hits healthcare sector with DDoS attacks

Categories: Cybercrime Categories: News Tags: KillNet Tags: CISA Tags: DDoS Tags: HC3 According to CISA, the pro-Russian KillNet group is actively targeting the US and European healthcare sectors with DDoS attacks. (Read more…) The post KillNet hits healthcare sector with…

Ryuk ransomware laundering leads to guilty plea

Categories: News Tags: ryuk Tags: ransomware Tags: guilty Tags: encrypt Tags: ransom Tags: cryptocurrency Tags: bitcoin We take a look at a guilty plea made in relation to Ryuk ransomware proceeds, and how you can best protect yourself from the…

Update now! GoAnywhere MFT zero-day patched

Categories: News Tags: GoAnywhere MFT Tags: managed file transfer Tags: Kevin Beaumont Tags: Brian Krebs Tags: emergency patch 7.1.2 Tags: Fortra Tags: Cobalt Strike Tags: Florian Hauser Tags: Code White A bug in GoAnywhere, a B2B management file transfer software,…

Ransomware review: February 2023

Categories: Ransomware Categories: Threat Intelligence Our Threat Intelligence team looks at known ransomware attacks by gang, country, and industry sector in January 2023, and looks at LockBit’s newest encryptor. (Read more…) The post Ransomware review: February 2023 appeared first on…

A week in security (January 30 – February 5)

Categories: News Tags: week in security Tags: blog roundup Tags: Roomba Tags: Facebook Tags: Eileen Gun Tags: Lock and Code Tags: data wiper Tags: LearnPress Tags: Riot Games Tags: League of Legends Tags: malvertising Tags: dark patterns Tags: supply chain…

The rise of multi-threat ransomware

Categories: News Tags: ransomware Tags: malwarebytes Tags: youtube Tags: video Tags: multi-threat Tags: single threat Tags: double threat Tags: triple threat Tags: encrypt Tags: extortion Take a look at our ten minute video walkthrough of ransomware issues and concerns. (Read…

How to protect your business from supply chain attacks

Categories: Business Categories: News Many have been calling attention to supply chain attacks for years. Is your business ready to listen? (Read more…) The post How to protect your business from supply chain attacks appeared first on Malwarebytes Labs. This…