VB Blog

VB2018 paper: Fake News, Inc.

Posted by   Helen Martin on   Apr 25, 2019

A former reporter by profession, Andrew Brandt's curiosity was piqued when he came across what appeared at first glance to be the website of a small-town newspaper based in Illinois, but under scrutiny, things didn’t add up. At VB2018 he presented a paper in which he shared the results of his investigation of the site. Today, we publish his paper and the recording of his presentation.

Read more  

Paper: Alternative communication channel over NTP

Posted by   Martijn Grooten on   Apr 24, 2019

In a new paper published today, independent researcher Nikolaos Tsapakis writes about the possibilities of malware using NTP as a covert communication channel and how to stop this.

Read more  

VB2019 conference programme announced

Posted by   Martijn Grooten on   Apr 5, 2019

VB is excited to reveal the details of an interesting and diverse programme for VB2019, the 29th Virus Bulletin International Conference, which takes place 2-4 October in London, UK.

Read more  

VB2018 paper: Under the hood - the automotive challenge

Posted by   Martijn Grooten on   Mar 27, 2019

Car hacking has become a hot subject in recent years, and at VB2018 in Montreal, Argus Cyber Security's Inbar Raz presented a paper that provides an introduction to the subject, looking at the complex problem, examples of car hacks, and the challenges ahead. Today, we publish both Inbar's paper and the recording of his presentation.

Read more  

VB2018 paper and video: Android app deobfuscation using static-dynamic cooperation

Posted by   Martijn Grooten on   Mar 20, 2019

Static analysis and dynamic analysis each have their shortcomings as methods for analysing potentially malicious files. Today, we publish a VB2018 paper by Check Point researchers Yoni Moses and Yaniv Mordekhay, in which they describe a method that combines static and dynamic analysis to defeat app obfuscation in Android binaries. We also publish the video of their presentation.

Read more  

VB2019 call for papers closes this weekend

Posted by   Martijn Grooten on   Mar 15, 2019

The call for papers for VB2019 closes on 17 March, and while we've already received many great submissions, we still want more!

Read more  

Registration open for VB2019 ─ book your ticket now!

Posted by   Martijn Grooten on   Mar 13, 2019

Registration for VB2019, the 29th Virus Bulletin International Conference, is now open, with an early bird rate available until 1 July.

Read more  

The VB2019 call for papers is about ... papers

Posted by   Martijn Grooten on   Mar 8, 2019

When we are calling for papers for the Virus Bulletin conference as we are doing now, we really mean a written paper. But don't worry if you've never written a paper - we can help!

Read more  

VB2018 video: Adware is just malware with a legal department - how we reverse engineered OSX/Pirrit, received legal threats, and survived

Posted by   Martijn Grooten on   Mar 8, 2019

Amit Serper first analysed the OSX/Pirrit adware in 2016, highlighting some of its malware-like techniques, and soon afterwards started receiving legal threats from the company behind it. At VB2018 Amit gave a presentation in which he discussed both the adware and the legal threats he received for calling it malware. Today, we publish the video of Amit's presentation.

Read more  

VB2018 paper: Anatomy of an attack: detecting and defeating CRASHOVERRIDE

Posted by   Martijn Grooten on   Mar 5, 2019

In December 2016, the CRASHOVERRIDE malware framework was used to cause a blackout in Ukraine. At VB2018 in Montreal, Dragos researcher Joe Slowik presented a detailed paper on the framework, explaining how the malware works and how it targets various protocols used to operate the electric grid. Today we publish both Joe's paper and the recording of his presentation.

Read more  

Search blog

Extra-large crop of updates for Patch Tuesday

Fourteen security alerts from Microsoft join two from Adobe.
Fourteen security alerts from Microsoft join two from Adobe.Microsoft's monthly Patch Tuesday security bulletins came out this week, featuring a chunky 14 separate alerts with many… https://www.virusbulletin.com/blog/2010/08/extra-large-crop-updates-patch-tuesday/

Firefox 4 crack spreads trojan

'Cracked' versions of free software used to spread malware
'Cracked' versions of free software used to spread malware In a new malware campaign, users are told they can download a free crack of the Firefox 4 browser, only to find… https://www.virusbulletin.com/blog/2010/08/firefox-4-crack-spreads-trojan/

August

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2010/08/

August issue of VB published

The August issue of Virus Bulletin is now available for subscribers to download.
The August issue of Virus Bulletin is now available for subscribers to download. The August 2010 issue of Virus Bulletin is now available for subscribers to browse online or… https://www.virusbulletin.com/blog/2010/08/august-issue-vb-published/

July

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2010/07/

July issue of VB published

The July issue of Virus Bulletin is now available for subscribers to download.
The July issue of Virus Bulletin is now available for subscribers to download. The July 2010 issue of Virus Bulletin is now available for subscribers to browse online or download… https://www.virusbulletin.com/blog/2010/07/july-issue-vb-published/

Microsoft sues alleged spammer for gaming Hotmail's spam filter

Messages marked as 'not spam' from phony web mail accounts.
Messages marked as 'not spam' from phony web mail accounts. Connecticut spammer Boris Mizhen and several companies controlled by him have been sued by Microsoft for sending… https://www.virusbulletin.com/blog/2010/06/microsoft-sues-alleged-spammer-gaming-hotmail-s-spam-filter/

Latest VB100 announced

Solutions for Windows Vista to be put through their paces.
Solutions for Windows Vista to be put through their paces. The latest round of VB100 testing has been announced, with a comparative to be run on Microsoft's Windows Vista in July.… https://www.virusbulletin.com/blog/2010/06/latest-announced/

Patches come thick and fast in major update spree

Monthly and out-of-band issues flood admins' to-do lists.
Monthly and out-of-band issues flood admins' to-do lists. The release of this month's Patch Tuesday security bulletins from Microsoft, with a fairly average 10 alerts covering 34… https://www.virusbulletin.com/blog/2010/06/patches-come-thick-and-fast-major-update-spree/

June issue of VB published

The June issue of Virus Bulletin is now available for subscribers to download.
The June issue of Virus Bulletin is now available for subscribers to download. The June 2010 issue of Virus Bulletin is now available for subscribers to browse online or download… https://www.virusbulletin.com/blog/2010/06/june-issue-vb-published/

June

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2010/06/

ESET buys COMDOM

Security vendor strengthens anti-spam capabilities.
Security vendor strengthens anti-spam capabilities. Slovakian security vendor ESET has announced the acquisition of Slovakian anti-spam firm COMDOM Software. The anti-spam firm's… https://www.virusbulletin.com/blog/2010/05/eset-buys-comdom/

Symantec to acquire VeriSign business

Vendor splashes out more cash on authentication.
Vendor splashes out more cash on authentication.Symantec, the AV vendor with a reputation for snapping up other companies, has announced its purchase of VeriSign's authentication… https://www.virusbulletin.com/blog/2010/05/symantec-acquire-verisign-business/

Contract spam serving malware

Recipients made to believe they have been sent emails accidentally.
Recipients made to believe they have been sent emails accidentally. In a new campaign, spammers are sending out emails that have appear to have contracts attached to them, but… https://www.virusbulletin.com/blog/2010/05/contract-spam-serving-malware/

Mariposa bot herders apply for job with security firm

Applicants weren't successful, but may not see prison either.
Applicants weren't successful, but may not see prison either.Panda Labs' Luis Corrons believed he was the victim if a practical joke when two people who had been involved in the… https://www.virusbulletin.com/blog/2010/05/mariposa-bot-herders-apply-job-security-firm/

Symantec buys key pair of encryption firms

PGP and GuardianEdge snapped up in surprise dual acquisition.
PGP and GuardianEdge snapped up in surprise dual acquisition.Symantec has announced the acquisition of two separate firms specialising in encryption and email security. The deals… https://www.virusbulletin.com/blog/2010/05/symantec-buys-key-pair-encryption-firms/

McAfee offers payments to cover FP cleanup costs

Compensation for faulty update victims could set precedent.
Compensation for faulty update victims could set precedent. Victims of the erroneous McAfee DAT update last month are being offered cash payments to cover costs incurred in fixing… https://www.virusbulletin.com/blog/2010/05/mcafee-offers-payments-cover-fp-cleanup-costs/

Sophos bought up by investment firm

APAX Partners acquires major stake in $830 million company.
APAX Partners acquires major stake in $830 million company.Sophos has announced that a majority share of the company will be sold to major private investment firm APAX Partners, in… https://www.virusbulletin.com/blog/2010/05/sophos-bought-investment-firm/

May

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2010/05/

May issue of VB published

The May issue of Virus Bulletin is now available for subscribers to download.
The May issue of Virus Bulletin is now available for subscribers to download. The May 2010 issue of Virus Bulletin is now available for subscribers to browse online or download… https://www.virusbulletin.com/blog/2010/05/may-issue-vb-published/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.