Tesla Email Scam

ADWCleaner is not a valid windows32 application; internet blocked and high CPU

AVG Quarantined something, what else do I need to do?

Spambot Contains ‘Mind-Boggling’ Amount of Email, SMTP Credentials

Windows 10 has been infected and i need help, please!

Am I infected with PUP Adware.Heuristic

Windows Server Warning and Zeus Virus??

is my router infected ?

Session Hijacking Bug Exposed GitLab Users Private Tokens

RIG exploit kit distributes Princess Ransomware

We have identified a new drive-by download campaign that distributes the Princess Ransomware, leveraging compromised websites and the RIG exploit kit. This is somewhat of a change for those tracking malvertising campaigns and their payloads. We had analyzed the Princess Ransomware last November and pointed out that despite similarities with Cerber’s onion page, the actual code was much different. A new payment page seemed to have been seen in underground forums and is now being used with attacks in the wild. From hacked site to RIG EK We are not so accustomed to witnessing compromised websites pushing exploit kits these days. Indeed, some campaigns have been replaced with tech support scams instead and overall most drive-by activity comes from legitimate publishers and malvertising. Yet, here we observed an iframe injection which redirected from the hacked site to a temporary gate distinct from the well-known “Seamless gate” which has been dropping copious amounts of the Ramn...

Bugs in Arris Modems Distributed by AT&T Vulnerable to Trivial Attacks

FDA Recalls 465K Pacemakers Tied to MedSec Research

Can't access ONE particular website

Issue with my WebBrowser and unwanted folders are being created

Intel Confirms Its Much-Loathed ME Feature Has A Kill Switch

Turla APT Used WhiteBear Espionage Tools Against Defense Industry, Embassies

Certificate Authority Authorization Checking: What is it, and why should you care?

Impact of CAA on Certificate Issuance Publish to Facebook:  No Certificate Authority Authorization checking: what is it, and why should you care? The Public Key Infrastructure (PKI) ecosystem relies on root certificates issued by various certification authorities (CAs) like Symantec. This is what browsers use to decide which websites can be trusted, and which ones are not trusted. Up to now, any CA can issue a TLS certificate for any domain. That’s how the system works, and it’s good in the sense that it gives website owners and operators options to change CAs at their discretion. The downside to this is that certificate issuance can happen without the knowledge of website operators, either by mistake or intentionally by malicious actors. A number of technologies have been created in an attempt to highlight instances of “unknown” issuance, such as Certificate Transparency . These have been effective in making the internet a safer, more trustworthy place but they are ...

Malware vaccination tricks: blue pills or red pills

First, let me explain what I mean by malware vaccination tricks. Most of you will have heard about some of these. Vaccination tricks are in fact techniques that use safety checks done by malware against that same malware. The malware checks for the presence of certain files or registry keys as a sign that the machine should not be infected. And users make sure those keys or files are present as a security measure. Examples of safety checks A lot of malware contains routines to check whether it is running on a Virtual Machine (VM), sandbox or with a debugger. They do this to avoid being detected by many of the automated systems the AV industry uses to deal with the large numbers of malware that surface every second of the day. Some malware check the default language installed on the affected system or the keyboard language. They do this because they shy away from infecting systems in certain countries, or quite the opposite because they target certain countries . Certain types of...

Ferrandino & Son Secure AWS Assets with Cloud Workload Protection

Achieve Single Console Management with Scalability and Cost Savings Publish to Facebook:  No Boasting a client-supported portfolio of more than 50,000 locations across all 50 states, Ferrandino & Son is the nation’s leading service supply chain management company. Maintaining and administering their far-flung and diverse operations necessitates the collection, processing, and storage of sensitive client and corporate data, including both financial and personally identifiable information (PII). Seeking cost savings, easy scalability, and simplification of their data centers, Ferrandino & Son decided to outsource the majority of their IT infrastructure, including their production database server farm and content delivery servers, to Amazon Web Services (AWS). Officially launching in 2006, AWS now leads the infrastructure-as-a-service (IaaS) marketplace, providing on-demand compute, storage, and networking services to more than one million active customers across 1...

New Locky Variant ‘IKARUSdilapidated’ Strikes Again

Siemens Fixes Session Hijacking Bug in LOGO!, Warns of Man-in-the-Middle Attacks

Businesses most at risk from new breed of ransomware

Avast and AVG score 100% in Real-World Test

AV Randomly turns off

NHS Lanarkshire Apologizes After Malware Attack

Endpoint Protection .Cloud: オンプレミス Active Directory から複数のユーザーを追加

Google Reminding Admins HTTP Pages Will Be Marked ‘Not Secure’ in October

Researchers Figure Out How to Blind ISPs from Smart Home Device Traffic

Revamped Nukebot Malware Changes Targets, Adds Functions

419 spam: 10 million US dollars, courtesy of “Rev. Goodluck Ebola”

I’m not saying an email claiming to be from the “Central Bank of Nigeria” with a contact handler named “Rev. Goodluck Ebola” will raise too many red flags, but… Click to Enlarge CENTRAL BANK OF NIGERIA OFFICE OF THE GOVERNOR Zaria Street, Off Samuel Akintola Street,Garki 11, Garki-Abuja. Our Ref: FGN/CBN/NIG/01/2017. Your Ref…………………………. From The Desk Of Mr. Godwin Emefiele. Governor, Central Bank of Nigeria (CBN) SUBJECT: Dear Valued Customer. Dear Friend, We wish to inform you that your unclaimed payment of USD$10.5 Million in Africa has been released and ready to be paid to you via PREPAID VISA CARD which you will use to withdraw the US$10.5 Million from any ATM Machine in any part of the world. We have mandated UBA financial advicers Ghana, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your US$10.5Million Dollars in any ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is US$20,000.00 Only. You are th...

Telnet Credential Leak Reinforces Bleak State of IoT Security

False positive or not?

DJI Launches Drone Bug Bounty Program

Task Manager says multiple websites in google chrome are in use

"Resource In Use" Rootkit has stronghold Malware/Antivirus

RootKit nightmare - Virus across multiple devices

Fraudulent Donations Lead to Disbanding of Hutchins Legal Defense Fund

CEOs Resign from Trump’s Cybersecurity Commission

Mobile WireX DDoS Botnet ‘Neutralized’ by Collaboration of Competitors

A week in security (August 21 – August 27)

In our blog posts, we announced the introduction of, and explained the necessity for, real-time protection for our Mac and Android users. Also explaining what you can expect them to do for you and answering the questions that we expect to be frequently asked. We looked at 4 key steps you can take within your business to help gain trust with your employees while educating them to make more secure decisions. And in our “Explained” series we talked about user agent strings and digital forensics . Below are notable news stories and security-related happenings from last week: Latest updates for Consumers Facebook makes Safety Check a permanent feature . Facebook is acting on its promise to make Safety Check a permanent feature by rolling out a dedicated Safety Check hub that helps you find any ongoing crisis without first being prompted to declare yourself as safe. Android spyware linked to Chinese SDK forces Google to boot 500 apps . More than 500 Android mobile apps have been re...

Anonymous Messaging App Sarahah to Halt Collection of User Data With Next Update

Mobile Menace Monday: Implications of Google Play Protect

Along with the recent release of Google’s new OS, Android 8.0 Oreo, they also released a new security suite known as Google Play Protect . As blogged about in July in Play Protect: Android’s new security system is now available , this new suite has been available since mid-May. To reiterate As noted in our July blog, the new Find My Phone does exactly what the name implies. You can also lock the phone remotely, display a message on the phone, call the phone through a browser, or even erase all the data on the phone with this feature. I personally hope this will help alleviate the use of shady monitoring apps . There is also Google’s Safe Browsing that stops you before you proceed to an unsafe site via Chrome. This feature has been around for a while. 50 billion apps, oh my! Of most interest is Google’s security suite is its new scanning capabilities. Google boasts it can scan 50 billion apps daily, and uses machine learning to weed out the bad stuff. For quite some time, Google ...

I think I'm bugged!

Announcing Deep Visibility into Advanced Email Attacks

window 10

NHS Lanarkshire Apologizes After Malware Attack

Curious About some Virus Total Scan Results

Chrome has major ads and popups, even on this site

Invincible ataqkjql.sys rootkit

Something is consuming over 150GB of bandwidth a month on my desktop

iSkysoft Helper Compact?

Laptop accessed remotely without my knowledge?

infected with malware from fake KM Spico

Is my internet connection being throttled ?

iexplorer cannot be updated. FRST data posted.

iexplorer cannot be updated and the old version seems to be vulnerable

Can't delete files and ransomware alert

Explained: digital forensics

What is it? Digital forensics is a modern day field of forensic science, which deals with the recovery and investigation of material found in digital devices. When needed, this is often because of a (cyber) crime, whether suspected or established. The most common reasons for performing digital forensics are: attribution identifying a leak within an organization assessing the possible damage that occurred during a breach The field of digital forensics is divided up into several subdivisions, depending on the nature of the digital device that is the subject of the investigation: computer forensics network forensics forensic data analysis mobile device forensics What does it take? Working in this field combines the excitement of solving a puzzle with the data at hand and requires a deep understanding of the software and hardware involved. The most important skill is to be able to find and interpret the data involved in the crime while minimizing the changes made on the inve...


Endpoint Protection .Cloud: オンプレミス Active Directory から複数のユーザーを追加

e-mail malware - bad

"a website is slowing down your browser...

Race is On To Notify Owners After Public List of IoT Device Credentials Published

Defray Ransomware Seen Targeting Education, Healthcare Industry

Threatpost News Wrap, August 25, 2017

Cryptocurrency Mining Malware Hosted in Amazon S3 Bucket

Security Lacking in Previous AppleAVEDriver iOS Kernel Extension

Crystal Finance Millennium Used To Spread Malware

Chinese Man Charged Over US Hack Attacks

CIA Created Bogus Software Upgrade To Steal Data From NSA, FBI

Uncle Sam Outlines Evidence Against Hutchins

モバイルマルウェア工場: ランサムウェアを作成できる Android アプリが出現

エンドポイントセキュリティソリューションの選定で、重視したい 5 つの特長

エンドポイントセキュリティへの多層的なアプローチ Cross Post Blogs:  Thought Leadership Background Image on Blogs "Quilted" Page:  Tunnel Data.jpg Publish to Facebook:  No 昨年 1 年間だけでも、マルウェアの新しい亜種は 1 日 100 万種以上も発見され、ランサムウェアのファミリーも 3 倍に増えました( 「2017 年インターネットセキュリティ脅威レポート、ISTR22」 による)。ランサムウェアに伴う支払い金額の平均は昨年比 266% と急増し、1,077 ドルに達しています。こうした厳しいデータを見るだけでも、セキュリティの専門家が毎日のように直面している困難の大きさが察せられます。複雑なネットワークと、変異し続ける無数の外的な脅威から生じるセキュリティ需要に対応するには、適切なエンドポイントセキュリティソリューションの導入が不可欠です。 最近の ブログ で、Gartner の Avivah Litan 氏は、顧客にこう提案しています。「アプリケーションのホワイトリストおよびブラックリストや、たいていの EPP(エンドポイント保護)プラットフォームに組み込まれているコントロールなど、多層的なエンドポイントセキュリティのアプローチを用いるべきである」 まさに、我が意を得たりの提案でした。企業は、急速に変化するセキュリティ環境への対処を前提として、保護・検出・対応までのサイクルを網羅した保護を実現する、万全のエンドポイントセキリティを必要としています。運用する保護の機能に限界があれば、その結果は火を見るより明らかです。 昨今のひときわ深刻な脅威から組織を確実に保護していただくために、万全のエンドポイントセキュリティに欠かせない一連の特長を紹介しましょう。 1. 攻撃チェーンの全体をカバーする総合的なセキュリティ 感染は、ネットワーク侵害につながる大きいチェーンのなかで 1 つのリンクにすぎません。最高のエンドポイントセキュリティシステムは、実績のある技術と新世代の技術を融合して、場所や経緯にかかわらず脅威を防ぎます。これまでより包括的なアプローチをとって初...

Strong Validation for Symantec ATP in Multiple Independent Assessments

Mobile malware factories: Android apps for creating ransomware

Avast is proven to keep phishing scams at bay

Introducing myself - Powermet virus

Virus wont allow me to open Anti Virus

IMAP email hacked?

Avast Arms MSPs For a Security-First Future

Solution Corner: Malwarebytes for Android

People have become increasingly reliant on their mobile devices in recent years. Smartphones and tablets have revolutionized daily life. Unfortunately, such rapid growth has also attracted criminals, bringing Android up to par with Windows in terms of infection rates. Android threat landscape A rapidly increasing group of threats on Android devices are so-called screen lockers, a form of ransomware that attempts to hold your device hostage by locking the screen with a ransom message and making it unusable. Android ransomware rose by nearly 140% globally from Q1 to Q2 of this year alone. Trojan malware is also on the rise, increasing by 10% in that same timeframe, with many of the threats in this category being banking Trojans. Such malware poses a significant risk, allowing attackers to potentially clean out an unfortunate victim’s bank account. Potentially unwanted programs (PUPs) are also a growing threat, accounting for nearly half of all Android threat detections in the first h...

Solution Corner: Malwarebytes for Mac

Mac users have been told for years: Macs don’t get viruses. Even Apple said so , in their famous Get a Mac ads that aired a decade ago. Wow, that’s so cool! It’s good to know we’re all safe. Now, on a different topic, can you tell me why Safari is going to a Russian search engine instead of Google? And I keep getting pop-ups telling me to “clean your Mac from junk!” Mac threat landscape Unfortunately, this old “wisdom” has never been true. There has almost always been malware for the Mac. The first widespread virus was the Elk Cloner virus, which actually infected the Apple II, prior to any PC malware. Some of the earliest malware affected the first Macs in the mid-1980s. The switch to a completely new architecture in Mac OS X, in 2001, killed all the old “Classic” Mac malware, but it didn’t take long for more to start appearing, starting with the MW2004 trojan a few years later. The only reason the myth that Macs can’t get infected with malware has persisted is t...