VB Blog

Subtle change could see a reduction in installation of malicious Chrome extensions

Posted by   Martijn Grooten on   Jun 13, 2018

Google has made a subtle change to its Chrome browser, banning the inline installation of new extensions, thus making it harder for malware authors to trick users into unwittingly installing malicious extensions.

Read more  

Paper: EternalBlue: a prominent threat actor of 2017–2018

Posted by   Martijn Grooten on   Jun 11, 2018

We publish a paper by researchers from Quick Heal Security Labs in India, who study the EternalBlue and DoublePulsar exploits in full detail.

Read more  

'North Korea' a hot subject among VB2018 talks

Posted by   Virus Bulletin on   Jun 1, 2018

Several VB2018 papers deal explicitly or implicitly with threats that have been attributed to North Korean actors.

Read more  

Expired domain led to SpamCannibal's blacklist eating the whole world

Posted by   Martijn Grooten on   May 31, 2018

The domain of the little-used SpamCannibal DNS blacklist had expired, resulting in it effectively listing every single IP address.

Read more  

MnuBot banking trojan communicates via SQL server

Posted by   Martijn Grooten on   May 30, 2018

Researchers at IBM X-Force have discovered MnuBot, a banking trojan targeting users in Brazil, which is noteworthy for using SQL Server for command and control communication.

Read more  

Throwback Thursday: Giving the EICAR test file some teeth

Posted by   Martijn Grooten on   May 24, 2018

The 68-byte EICAR test file plays as important a role today as it did 19 years ago. In this week's Throwback Thursday we look back at a VB99 conference paper in which Randy Abrams described how this 'miracle tool' worked and how it could be used.

Read more  

XMRig used in new macOS cryptominer

Posted by   Martijn Grooten on   May 23, 2018

A new piece of cryptocurrency-mining malware on macOS has been found to use the popular XMRig miner.

Read more  

Tendency for DDoS attacks to become less volumetric fits in a wider trend

Posted by   Martijn Grooten on   May 22, 2018

CDN provider Cloudflare reports an increase in DDoS attacks targeting layer 7 and focusing on exhausting server resources rather than sending large volumes of data. This fits in a wider trend.

Read more  

Turkish Twitter users targeted with mobile FinFisher spyware

Posted by   Martijn Grooten on   May 15, 2018

Through fake social media accounts, users were tricked into installing an Android application that was actually a mobile version of the FinFisher spyware.

Read more  

Hide'n'Seek IoT botnet adds persistence

Posted by   Martijn Grooten on   May 9, 2018

The Hide'n'Seek IoT botnet has received an update to make its infection persist on infected devices beyond a restart.

Read more  

Search blog

Sender ID specification released

Microsoft reveals all as part of its Open Specification Promise.
Microsoft reveals all as part of its Open Specification Promise.Microsoft has made its Sender ID Framework specification available as part of its recent Open Specification Promise,… https://www.virusbulletin.com/blog/2006/11/sender-id-specification-released/

New anti-spam group formed

StopSpamAlliance unites international bodies.
StopSpamAlliance unites international bodies. A group of international agencies and organisations have teamed up to launch StopSpamAlliance.org, designed to be a centralised base… https://www.virusbulletin.com/blog/2006/11/new-anti-spam-group-formed/

Phish check interface

Developer interface for checking phishy URLs.
Developer interface for checking phishy URLs. The people behind PhishTank, a collaborative clearing house for data and information about phishing, have revealed a simplified… https://www.virusbulletin.com/blog/2006/11/phish-check-interface/

Spam hits record levels in October

Image-based pump-and-dumps add to inbox bloat.
Image-based pump-and-dumps add to inbox bloat. Spam levels have continued to rise, defying general trends that would suggest a decreasing post-summer ratio, as more people at work… https://www.virusbulletin.com/blog/2006/11/spam-hits-record-levels-october/

November issue of VB published

The November issue of Virus Bulletin is now available for subscribers to download.
The November issue of Virus Bulletin is now available for subscribers to download. The November 2006 issue of Virus Bulletin is now available for subscribers to browse online or… https://www.virusbulletin.com/blog/2006/11/november-issue-vb-published/

News round-up

October's goings on in the AV industry.
October's goings on in the AV industry. Despite no major malware outbreaks having occurred during last month's VB conference (as has almost seemed a tradition in the past),… https://www.virusbulletin.com/blog/2006/11/news-round/

Two more IE7 bugs downplayed by Microsoft

More phishing issues found, not a big problem says MS.
More phishing issues found, not a big problem says MS. A second bug was spotted late last week in Microsoft's recently-released Internet Explorer 7, which could allow malicious… https://www.virusbulletin.com/blog/2006/10/two-more-ie7-bugs-downplayed-microsoft/

Sophos engine faults disclosed

iDefense reports file-handling vulnerabilities.
iDefense reports file-handling vulnerabilities. Security researchers at iDefense have released information on four separate bugs in the Sophos anti-virus engine, affecting most… https://www.virusbulletin.com/blog/2006/10/sophos-engine-faults-disclosed/

Australian spam firm fined $4.1 million

First case under spam laws brings hefty punishment.
First case under spam laws brings hefty punishment. A company based in Western Australia has been charged A$4.5 million, with another A$1 million levied from its director, after a… https://www.virusbulletin.com/blog/2006/10/australian-spam-firm-fined-4-1-million/

McAfee up, Symantec down in profits

Financial reports differ widely between top security rivals.
Financial reports differ widely between top security rivals. Profits reports for the third quarter of the year show Symantec struggling with disappointing sales in the European… https://www.virusbulletin.com/blog/2006/10/mcafee-symantec-down-profits/

Sender ID licence opened up

Microsoft frees up access to anti-spam framework.
Microsoft frees up access to anti-spam framework.Microsoft has put the specifications for the Sender ID and Sender Policy Framework (SPF) email verification system under its 'Open… https://www.virusbulletin.com/blog/2006/10/sender-id-licence-opened/

Windows Defender fully released

Microsoft anti-spyware product handed out free.
Microsoft anti-spyware product handed out free. After a lengthy beta period, Microsoft's free anti-spyware product, renamed Windows Defender halfway through its beta cycle, has… https://www.virusbulletin.com/blog/2006/10/windows-defender-fully-released/

Latest VB100% test announced

Call for products issued for Windows XP x64 test.
Call for products issued for Windows XP x64 test. The latest round of VB 100% certification testing has been announced. The test will be run on the Windows XP Professional x64… https://www.virusbulletin.com/blog/2006/10/latest-test-announced/

Microsoft in multiple security rows

AV firms, Apple and Secunia embroiled in MS spats.
AV firms, Apple and Secunia embroiled in MS spats. Operating system giant Microsoft is engaged on multiple fronts in a series of security-related PR battles. The longest running… https://www.virusbulletin.com/blog/2006/10/microsoft-multiple-security-rows/

UK banks failing online users

Report names and shames insecure banking sites - again.
Report names and shames insecure banking sites - again. A report from heise Security, following up on a previous study released a month ago, claims several UK banks are still using… https://www.virusbulletin.com/blog/2006/10/uk-banks-failing-online-users/

Trojan installs Kaspersky AV

Scanner software used to keep out rival malware.
Scanner software used to keep out rival malware. A trojan has been reported in the wild using a genuine AV engine to keep its victims' machines free from other threats. This… https://www.virusbulletin.com/blog/2006/10/trojan-installs-kaspersky-av/

MacDonald's serves up spyware

Diners 'rewarded' with infected music players
Diners 'rewarded' with infected music players Japanese customers of global burger giant MacDonald's have been warned that 10,000 MP3 players handed out by the firm as part of a… https://www.virusbulletin.com/blog/2006/10/macdonald-s-serves-spyware/

Another hole found in PowerPoint

Proof-of-concept exploit shows further bug in slideshow software
Proof-of-concept exploit shows further bug in slideshow softwareMicrosoft has issued an alert over a new potential zero-day exploit in its PowerPoint presentation software. The… https://www.virusbulletin.com/blog/2006/10/another-hole-found-powerpoint/

IE7 used as phishing lure

Spam campaign tries to hook users with new browser version.
Spam campaign tries to hook users with new browser version. A spam campaign has been spotted using the latest version of Microsoft's web browser, Internet Explorer 7, as bait. The… https://www.virusbulletin.com/blog/2006/10/ie7-used-phishing-lure/

MySpace users targeted by spam campaign

Phishers pose as online contacts to push bogus shopping sites.
Phishers pose as online contacts to push bogus shopping sites. A major spam campaign is bombarding inboxes with mails masquerading as messages from conacts on web social and… https://www.virusbulletin.com/blog/2006/10/myspace-users-targeted-spam-campaign/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.