VB Blog

VB2018 paper: Fake News, Inc.

Posted by   Helen Martin on   Apr 25, 2019

A former reporter by profession, Andrew Brandt's curiosity was piqued when he came across what appeared at first glance to be the website of a small-town newspaper based in Illinois, but under scrutiny, things didn’t add up. At VB2018 he presented a paper in which he shared the results of his investigation of the site. Today, we publish his paper and the recording of his presentation.

Read more  

Paper: Alternative communication channel over NTP

Posted by   Martijn Grooten on   Apr 24, 2019

In a new paper published today, independent researcher Nikolaos Tsapakis writes about the possibilities of malware using NTP as a covert communication channel and how to stop this.

Read more  

VB2019 conference programme announced

Posted by   Martijn Grooten on   Apr 5, 2019

VB is excited to reveal the details of an interesting and diverse programme for VB2019, the 29th Virus Bulletin International Conference, which takes place 2-4 October in London, UK.

Read more  

VB2018 paper: Under the hood - the automotive challenge

Posted by   Martijn Grooten on   Mar 27, 2019

Car hacking has become a hot subject in recent years, and at VB2018 in Montreal, Argus Cyber Security's Inbar Raz presented a paper that provides an introduction to the subject, looking at the complex problem, examples of car hacks, and the challenges ahead. Today, we publish both Inbar's paper and the recording of his presentation.

Read more  

VB2018 paper and video: Android app deobfuscation using static-dynamic cooperation

Posted by   Martijn Grooten on   Mar 20, 2019

Static analysis and dynamic analysis each have their shortcomings as methods for analysing potentially malicious files. Today, we publish a VB2018 paper by Check Point researchers Yoni Moses and Yaniv Mordekhay, in which they describe a method that combines static and dynamic analysis to defeat app obfuscation in Android binaries. We also publish the video of their presentation.

Read more  

VB2019 call for papers closes this weekend

Posted by   Martijn Grooten on   Mar 15, 2019

The call for papers for VB2019 closes on 17 March, and while we've already received many great submissions, we still want more!

Read more  

Registration open for VB2019 ─ book your ticket now!

Posted by   Martijn Grooten on   Mar 13, 2019

Registration for VB2019, the 29th Virus Bulletin International Conference, is now open, with an early bird rate available until 1 July.

Read more  

The VB2019 call for papers is about ... papers

Posted by   Martijn Grooten on   Mar 8, 2019

When we are calling for papers for the Virus Bulletin conference as we are doing now, we really mean a written paper. But don't worry if you've never written a paper - we can help!

Read more  

VB2018 video: Adware is just malware with a legal department - how we reverse engineered OSX/Pirrit, received legal threats, and survived

Posted by   Martijn Grooten on   Mar 8, 2019

Amit Serper first analysed the OSX/Pirrit adware in 2016, highlighting some of its malware-like techniques, and soon afterwards started receiving legal threats from the company behind it. At VB2018 Amit gave a presentation in which he discussed both the adware and the legal threats he received for calling it malware. Today, we publish the video of Amit's presentation.

Read more  

VB2018 paper: Anatomy of an attack: detecting and defeating CRASHOVERRIDE

Posted by   Martijn Grooten on   Mar 5, 2019

In December 2016, the CRASHOVERRIDE malware framework was used to cause a blackout in Ukraine. At VB2018 in Montreal, Dragos researcher Joe Slowik presented a detailed paper on the framework, explaining how the malware works and how it targets various protocols used to operate the electric grid. Today we publish both Joe's paper and the recording of his presentation.

Read more  

Search blog

Congressional attack on inboxes

US Congressional representatives send bulk email
US Congressional representatives send bulk email While congratulating themselves for (supposedly) stemming the flow of spam with the passage of the CAN-SPAM anti-spam… https://www.virusbulletin.com/blog/2004/01/congressional-attack-inboxes/

MyDoom, YourDoom, OurDoom

SCO offers a bounty for the arrest of the MyDoom author, Bruce Perens offers a conspiracy theory...
SCO offers a bounty for the arrest of the MyDoom author, Bruce Perens offers a conspiracy theory... SCO is offering a reward for information leading to the arrest of the author… https://www.virusbulletin.com/blog/2004/01/mydoom-yourdoom-ourdoom/

Divine intervention

AV on a spiritual level
AV on a spiritual level We all know how quickly time flies when we're having fun, or when there's a deadline looming, but a recent news report on the Asian news website Channel… https://www.virusbulletin.com/blog/2004/01/divine-intervention/

Waiting, reflecting and removing

Microsoft reports success of Blaster removal tool
Microsoft reports success of Blaster removal tool While young Romanian virus author Dan Dumitru Ciobanu awaited trial by a Romanian court last month for releasing a variant of… https://www.virusbulletin.com/blog/2004/01/waiting-reflecting-and-removing/

News summary...

Blaster (variant) author charged, AhnLab warns against complacency, India launches CERT-In, more on monoculture, and what's new in the spam world...
Blaster (variant) author charged, AhnLab warns against complacency, India launches CERT-In, more on monoculture, and what's new in the spam world... In much the same way that the… https://www.virusbulletin.com/blog/2004/01/news-summary/

Email coaching for marketers

DMA releases quick-glance reference guide for email marketers.
DMA releases quick-glance reference guide for email marketers. The Direct Marketing Association (DMA) has released a quick-glance reference guide for marketers entitled 'The CAN… https://www.virusbulletin.com/blog/2004/01/email-coaching-marketers/

Ahnlab partners with Sina.com

Ahnlab gets major ASP deal in China.
Ahnlab gets major ASP deal in China. Ahnlab has acquired a major stepping-stone into the Chinese domestic market, according to an article published by the Korea Herald, by… https://www.virusbulletin.com/blog/2004/01/ahnlab-partners-sina-com/

Security-conscious processors

AMD and Intel prep technology to prevent buffer overflows at the hardware level.
AMD and Intel prep technology to prevent buffer overflows at the hardware level. IT news site Silicon.com has published an article about hardware security in CPUs to prevent… https://www.virusbulletin.com/blog/2004/01/security-conscious-processors/

Weekend round-up

Narrowband blues, 2004 predictions, VeriSign scuttles Symantec, Dloader/Xombie
Narrowband blues, 2004 predictions, VeriSign scuttles Symantec, Dloader/Xombie It's been a busy few days as 2004 starts to get into full swing. VB has a roundup of the weekend's… https://www.virusbulletin.com/blog/2004/01/weekend-round/

January

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/01/

2004

Latest news from the anti-virus industry provided by independent anti-virus advisors, Virus Bulletin
NewsJanuary issue released The Virus Bulletin January 2005 issue is on its way. 23 December 2004Latest VGrep The latest version of the virus name lookup tool - VGrep, is now… https://www.virusbulletin.com/blog/2004/

US and UK spam legislation in place

Anti-spam legislation in place.
Anti-spam legislation in place. While the 'CAN-SPAM Act' is expected to have been signed into US law by 1 January 2004, December 2003 saw the introduction of anti-spam… https://www.virusbulletin.com/blog/2003/12/us-and-uk-spam-legislation-place/

Number crunching

Calculating the average cost of a virus attack - estimates or guesstimates?
Calculating the average cost of a virus attack - estimates or guesstimates? This month has seen a flurry of the traditional end-of-year predictions for the security challenges in… https://www.virusbulletin.com/blog/2003/12/number-crunching/

SAS - the SysAsmin Service?

Computer security experts prepare to become special constables.
Computer security experts prepare to become special constables. A set of proposals for tackling computer crime has been published by UK Parliamentary lobby group EURIM and the… https://www.virusbulletin.com/blog/2003/12/sas-sysasmin-service/

SpamCop snapped up

IronPort Systems to purchase SpamCop
IronPort Systems to purchase SpamCop According to the IDG News Service, email security hardware manufacturer IronPort Systems Inc. is set to announce its purchase of anti-spam… https://www.virusbulletin.com/blog/2003/12/spamcop-snapped/

Seasonal spamming

Increase in spam in lead up to holiday season.
Increase in spam in lead up to holiday season. A recent study carried out by Corvigo, suggests that the volume of spam in our inboxes showed a marked increase over the lead up to… https://www.virusbulletin.com/blog/2003/12/seasonal-spamming/

December

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2003/12/

VB2004 call for papers

Virus Bulletin calls for all speakers papers.
Virus Bulletin calls for all speakers papers. full article Posted on 05 January 2004 by Virus Bulletin https://www.virusbulletin.com/blog/2003/11/call-papers/

The menace within

Is BitDefender really staffed by Romanian vampire hackers...?
Is BitDefender really staffed by Romanian vampire hackers...? A recent report by the Associated Press claims that 'computer-savvy Romanians are fast emerging as a bold menace in… https://www.virusbulletin.com/blog/2003/11/menace-within/

Unanimous vote for CAN-SPAM Act

US Senate approves federal anti-spam legislation.
US Senate approves federal anti-spam legislation. The US Senate has approved the first federal anti-spam legislation. The 'CAN-SPAM Act' was approved by Senate in a unanimous… https://www.virusbulletin.com/blog/2003/11/unanimous-vote-can-spam-act/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.