VB Blog

VB2018 paper: Draw me like one of your French APTs – expanding our descriptive palette for cyber threat actors

Posted by   Martijn Grooten on   Jan 7, 2019

Today, we publish the VB2018 paper by Chronicle researcher Juan Andres Guerrero-Saade, who argues we should change the way we talk about APT actors.

Read more  

Book Review: Cyber Wars

Posted by   Martijn Grooten on   Dec 19, 2018

VB Editor Martijn Grooten reviews Charles Arthur's Cyber Wars, which looks at seven prominent hacks and attacks, and the lessons we can learn from them.

Read more  

VB2018 paper: Office bugs on the rise

Posted by   Martijn Grooten on   Dec 14, 2018

At VB2018 Sophos researcher Gábor Szappanos provided a detailed overview of Office exploit builders, and looked in particular at the widely exploited CVE-2017-0199. Today we publish his paper and release the video of his presentation.

Read more  

VB2018 video: The Big Bang Theory by APT-C-23

Posted by   Martijn Grooten on   Dec 12, 2018

Today, we release the video of the VB2018 presentation by Check Point researcher Aseel Kayal, who connected the various dots relating to campaigns by the APT-C-23 threat group.

Read more  

VB2019 London - join us for the most international threat intelligence conference!

Posted by   Martijn Grooten on   Dec 11, 2018

VB calls on organisations and individuals involved in threat intelligence from around the world to participate in next year's Virus Bulletin conference.

Read more  

VB2018 paper: Tracking Mirai variants

Posted by   Martijn Grooten on   Dec 7, 2018

Today, we publish the VB2018 paper by Qihoo 360 researchers Ya Liu and Hui Wang, on extracting data from variants of the Mirai botnet to classify and track variants.

Read more  

VB2018 paper: Hide'n'Seek: an adaptive peer-to-peer IoT botnet

Posted by   Martijn Grooten on   Dec 6, 2018

2018 has seen an increase in the variety of botnets living on the Internet of Things - such as Hide'N'Seek, which is notable for its use of peer-to-peer for command-and-control communication. Today, we publish the VB2018 paper by Bitdefender researchers Adrian Șendroiu and Vladimir Diaconescu, who studied the Hide'N'Seek IoT botnet. We also release the recording of their presentation.

Read more  

New paper: Botception: botnet distributes script with bot capabilities

Posted by   Martijn Grooten on   Dec 4, 2018

In a new paper, Avast researchers Jan Sirmer and Adolf Streda look at how a spam campaign sent via the Necurs botnet was delivering the Flawed Ammyy RAT. As well as publishing the paper, we have also released the video of the reseachers' VB2018 presentation on the same topic.

Read more  

VB2018 video: Behind the scenes of the SamSam investigation

Posted by   Martijn Grooten on   Nov 29, 2018

Today we have published the video of the VB2018 presentation by Andrew Brandt (Sophos) on the SamSam ransomware, which became hot news following the indictment of its two suspected authors yesterday.

Read more  

VB2018 video: Foreverdays: tracking and mitigating threats targeting civil society orgs

Posted by   Martijn Grooten on   Nov 28, 2018

Today, we publish the video of the VB2018 presentation by CitizenLab researchers Masashi Nishihata and John Scott Railton, on threats faced by civil society.

Read more  

Search blog

Patch Tuesday brings little relief from browser exploits

Six fixes issued, but new IE zero day emerges along with Firefox flaw.
Six fixes issued, but new IE zero day emerges along with Firefox flaw.Microsoft has issued its monthly 'Patch Tuesday' security update, with some serious browser flaws patched, but… https://www.virusbulletin.com/blog/2009/07/patch-tuesday-brings-little-relief-browser-exploits/

Korea DDoS surge mired in hype and confusion

Rows rumble on over sources and targets of botnet attacks.
Rows rumble on over sources and targets of botnet attacks. Last week's gush of denial-of-service attacks has sparked considerable excitement and argument, with rumours of possible… https://www.virusbulletin.com/blog/2009/07/korea-ddos-surge-mired-hype-and-confusion/

URL shorteners experience surge of popularity among spammers

More than 2.2% of spam contains shortened URLs.
More than 2.2% of spam contains shortened URLs. URL shortening services have proven recently to be popular not just among microbloggers in need of shorter URLs, but also among… https://www.virusbulletin.com/blog/2009/07/url-shorteners-experience-surge-popularity-among-spammers/

Serious false positive hits users of old McAfee engines

Batch of system files wrongly flagged as malware, current versions not affected.
Batch of system files wrongly flagged as malware, current versions not affected. An update released by McAfee last week resulted in problems around the world, as some vital system… https://www.virusbulletin.com/blog/2009/07/serious-false-positive-hits-users-old-mcafee-engines/

Another IE zero day exploited

Second DirectShow vulnerability in six weeks labelled 'extremely critical'.
Second DirectShow vulnerability in six weeks labelled 'extremely critical'.Microsoft has issued an advisory on a serious vulnerability in an ActiveX control in its Internet… https://www.virusbulletin.com/blog/2009/07/another-ie-zero-day-exploited/

Keyloggers used to loot US county

$415,000 sneaked from local government funds.
$415,000 sneaked from local government funds. A Kentucky county has suffered losses of $415,000 after keylogging malware infiltrated its computer systems, allowing cybercriminals… https://www.virusbulletin.com/blog/2009/07/keyloggers-used-loot-us-county/

VB announces latest VBSpam certification results

Two products achieve top level VBSpam Platinum award.
Two products achieve top level VBSpam Platinum award. Virus Bulletin has announced the results of its second comparative review of anti-spam products, revealing two top-level… https://www.virusbulletin.com/blog/2009/07/vb-announces-latest-vbspam-certification-results/

July

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2009/07/

July issue of VB published

The July issue of Virus Bulletin is now available for subscribers to download.
The July issue of Virus Bulletin is now available for subscribers to download. The July 2009 issue of Virus Bulletin is now available for subscribers to browse online or download… https://www.virusbulletin.com/blog/2009/07/july-issue-vb-published/

DKIM usage shows significant growth

US banks urged to use authentication method
US banks urged to use authentication method In a report on its website, Internet giant Cisco states it has been seeing almost 700,000 non-spam messages that contain valid DKIM… https://www.virusbulletin.com/blog/2009/06/dkim-usage-shows-significant-growth/

June

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2009/06/

Latest AV-Comparatives results released

Retrospective figures follow up February test.
Retrospective figures follow up February test. Independent testing body AV-Comparatives have issued their latest set of retrospective test figures, completing the round of testing… https://www.virusbulletin.com/blog/2009/05/latest-av-comparatives-results-released/

Cyber-security organisations link up to foster collaboration

ASC, NCSA and StopBadware form 'chain of trust' initiative.
ASC, NCSA and StopBadware form 'chain of trust' initiative. Three major groups focused on issues of cyber security - the Anti-Spyware Coalition (ASC), the US National Cyber… https://www.virusbulletin.com/blog/2009/05/cyber-security-organisations-link-foster-collaboration/

AV protection free for aliens

Klingon language scanner given away.
Klingon language scanner given away. After last summer saw malware making its way into space, it seemed like only a matter of time before alien races would need protection from the… https://www.virusbulletin.com/blog/2009/05/av-protection-free-aliens/

Gumblar compromise growth continues

Dominant web threat infecting still more vulnerable sites.
Dominant web threat infecting still more vulnerable sites. A major web compromise, estimated by some to represent over 40% of infected web pages last week, has continued growing in… https://www.virusbulletin.com/blog/2009/05/gumblar-compromise-growth-continues/

McAfee to acquire Solidcore

Whitelisting firm to be assimilated by security giant.
Whitelisting firm to be assimilated by security giant.McAfee has announced the acquisition of whitelisting firm Solidcore in a deal reported to be worth a base rate of $33 million,… https://www.virusbulletin.com/blog/2009/05/mcafee-acquire-solidcore/

Security experts pool ideas at European conferences

Research and expertise shared at CARO and AMTSO meetings.
Research and expertise shared at CARO and AMTSO meetings. Last week saw two major gatherings of top security and anti-malware experts from across the globe, as the third annual… https://www.virusbulletin.com/blog/2009/05/security-experts-pool-ideas-european-conferences/

Security holes trouble vendors

Vulnerabilities fixed in McAfee website and Google Chrome; patch expected for Adobe Reader.
Vulnerabilities fixed in McAfee website and Google Chrome; patch expected for Adobe Reader. A range of vulnerabilities have been causing headaches recently for companies… https://www.virusbulletin.com/blog/2009/05/security-holes-trouble-vendors/

May

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2009/05/

May issue of VB published

The May issue of Virus Bulletin is now available for subscribers to download.
The May issue of Virus Bulletin is now available for subscribers to download. The May 2009 issue of Virus Bulletin is now available for subscribers to browse online or download… https://www.virusbulletin.com/blog/2009/05/may-issue-vb-published/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.