VB Blog

VB2016 video: Nymaim: the Untold Story

Posted by   Martijn Grooten on   Feb 8, 2017

Until very recently, the Nymaim banking trojan was a serious problem in Poland. Today, we publish the video of the VB2016 presentation by CERT Polska researchers Jarosław Jedynak and Maciej Kotowicz, in which they analyse this malware-dropper-turned-banking-trojan.

Read more  

The Living Dead Anti-Virus

Posted by   Virus Bulletin on   Feb 2, 2017

Should users uninstall their anti-virus products, as was recently suggested by a security expert in a widely shared article? In a guest post, security consultant Hendrik Pilz explains why he doesn't think this is a good idea.

Read more  

Paper: The journey and evolution of God Mode in 2016: CVE-2016-0189

Posted by   Martijn Grooten on   Jan 31, 2017

In a new paper published by Virus Bulletin, FireEye researchers Ankit Anubhav and Manish Sardiwal analyse the 'God Mode' vulnerability CVE-2016-0189 in Microsoft Internet Explorer.

Read more  

VB2016 video: Neverquest: Crime as a Service and On the Hunt for the Big Bucks

Posted by   Martijn Grooten on   Jan 30, 2017

At VB2016, Peter Kruse gave a presentation detailing the Neverquest trojan, the alleged author of which was arrested in Spain earlier this month. Today, we publish the recording of Peter's presentation.

Read more  

VB2016 paper: Great crypto failures

Posted by   Martijn Grooten on   Jan 24, 2017

Crypto is hard, and malware authors often make mistakes. At VB2016, Check Point researchers Yaniv Balmas and Ben Herzog discussed the whys and hows of some of the crypto blunders made by malware authors. Today, we publish their paper and the recording of their presentation.

Read more  

Call for Papers: VB2017

Posted by   Martijn Grooten on   Jan 19, 2017

We have opened the Call for Papers for VB2017. We are particularly interested in receiving submissions from those working outside the security industry itself.

Read more  

Ransomware not a problem for half of businesses

Posted by   Martijn Grooten on   Jan 11, 2017

According to a report by IBM Security, 70 per cent of businesses that are the victim of a ransomware attack end up paying the ransom. However, the report also suggests that a little over half of businesses manage to avoid getting infected at all, showing they must be doing something right.

Read more  

Ransomware would be much worse if it wasn't for email security solutions

Posted by   Martijn Grooten on   Jan 5, 2017

The latest VBSpam test brings good news: at least 199 out of every 200 emails containing a malicious attachment were blocked by email security solutions. All of the full solutions tested achieved a VBSpam award, with five earning a VBSpam+ award.

Read more  

Throwback Thursday: The malware battle: reflections and forecasts

Posted by   Helen Martin on   Jan 5, 2017

"Another year has come to its end and the malware battle still rages on." In January 2004, Jamz Yaneza reflected on the year just ended and pondered what the coming year would have in store for the AV industry.

Read more  

VB2016 paper: Open Source Malware Lab

Posted by   Martijn Grooten on   Jan 4, 2017

At VB2016, ThreatConnect Director of Research Innovation Robert Simmons presented a paper on setting up an open source malware lab. Today, we share the accompanying paper and video.

Read more  

Search blog

News round-up

October's goings on in the AV industry.
October's goings on in the AV industry. Despite no major malware outbreaks having occurred during last month's VB conference (as has almost seemed a tradition in the past),… https://www.virusbulletin.com/blog/2006/11/news-round/

November

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2006/11/

Spamhaus rests easy

US judge rules against suspending Spamhaus domain.
US judge rules against suspending Spamhaus domain. At the end of a month-long court battle, a US judge has ruled that UK anti-spam advisory organization Spamhaus will not have its… https://www.virusbulletin.com/blog/2006/11/spamhaus-rests-easy/

Sender ID specification released

Microsoft reveals all as part of its Open Specification Promise.
Microsoft reveals all as part of its Open Specification Promise.Microsoft has made its Sender ID Framework specification available as part of its recent Open Specification Promise,… https://www.virusbulletin.com/blog/2006/11/sender-id-specification-released/

New anti-spam group formed

StopSpamAlliance unites international bodies.
StopSpamAlliance unites international bodies. A group of international agencies and organisations have teamed up to launch StopSpamAlliance.org, designed to be a centralised base… https://www.virusbulletin.com/blog/2006/11/new-anti-spam-group-formed/

Phish check interface

Developer interface for checking phishy URLs.
Developer interface for checking phishy URLs. The people behind PhishTank, a collaborative clearing house for data and information about phishing, have revealed a simplified… https://www.virusbulletin.com/blog/2006/11/phish-check-interface/

Sophos engine faults disclosed

iDefense reports file-handling vulnerabilities.
iDefense reports file-handling vulnerabilities. Security researchers at iDefense have released information on four separate bugs in the Sophos anti-virus engine, affecting most… https://www.virusbulletin.com/blog/2006/10/sophos-engine-faults-disclosed/

Two more IE7 bugs downplayed by Microsoft

More phishing issues found, not a big problem says MS.
More phishing issues found, not a big problem says MS. A second bug was spotted late last week in Microsoft's recently-released Internet Explorer 7, which could allow malicious… https://www.virusbulletin.com/blog/2006/10/two-more-ie7-bugs-downplayed-microsoft/

McAfee up, Symantec down in profits

Financial reports differ widely between top security rivals.
Financial reports differ widely between top security rivals. Profits reports for the third quarter of the year show Symantec struggling with disappointing sales in the European… https://www.virusbulletin.com/blog/2006/10/mcafee-symantec-down-profits/

Australian spam firm fined $4.1 million

First case under spam laws brings hefty punishment.
First case under spam laws brings hefty punishment. A company based in Western Australia has been charged A$4.5 million, with another A$1 million levied from its director, after a… https://www.virusbulletin.com/blog/2006/10/australian-spam-firm-fined-4-1-million/

Windows Defender fully released

Microsoft anti-spyware product handed out free.
Microsoft anti-spyware product handed out free. After a lengthy beta period, Microsoft's free anti-spyware product, renamed Windows Defender halfway through its beta cycle, has… https://www.virusbulletin.com/blog/2006/10/windows-defender-fully-released/

Sender ID licence opened up

Microsoft frees up access to anti-spam framework.
Microsoft frees up access to anti-spam framework.Microsoft has put the specifications for the Sender ID and Sender Policy Framework (SPF) email verification system under its 'Open… https://www.virusbulletin.com/blog/2006/10/sender-id-licence-opened/

UK banks failing online users

Report names and shames insecure banking sites - again.
Report names and shames insecure banking sites - again. A report from heise Security, following up on a previous study released a month ago, claims several UK banks are still using… https://www.virusbulletin.com/blog/2006/10/uk-banks-failing-online-users/

Trojan installs Kaspersky AV

Scanner software used to keep out rival malware.
Scanner software used to keep out rival malware. A trojan has been reported in the wild using a genuine AV engine to keep its victims' machines free from other threats. This… https://www.virusbulletin.com/blog/2006/10/trojan-installs-kaspersky-av/

Latest VB100% test announced

Call for products issued for Windows XP x64 test.
Call for products issued for Windows XP x64 test. The latest round of VB 100% certification testing has been announced. The test will be run on the Windows XP Professional x64… https://www.virusbulletin.com/blog/2006/10/latest-test-announced/

Microsoft in multiple security rows

AV firms, Apple and Secunia embroiled in MS spats.
AV firms, Apple and Secunia embroiled in MS spats. Operating system giant Microsoft is engaged on multiple fronts in a series of security-related PR battles. The longest running… https://www.virusbulletin.com/blog/2006/10/microsoft-multiple-security-rows/

IE7 used as phishing lure

Spam campaign tries to hook users with new browser version.
Spam campaign tries to hook users with new browser version. A spam campaign has been spotted using the latest version of Microsoft's web browser, Internet Explorer 7, as bait. The… https://www.virusbulletin.com/blog/2006/10/ie7-used-phishing-lure/

MySpace users targeted by spam campaign

Phishers pose as online contacts to push bogus shopping sites.
Phishers pose as online contacts to push bogus shopping sites. A major spam campaign is bombarding inboxes with mails masquerading as messages from conacts on web social and… https://www.virusbulletin.com/blog/2006/10/myspace-users-targeted-spam-campaign/

MacDonald's serves up spyware

Diners 'rewarded' with infected music players
Diners 'rewarded' with infected music players Japanese customers of global burger giant MacDonald's have been warned that 10,000 MP3 players handed out by the firm as part of a… https://www.virusbulletin.com/blog/2006/10/macdonald-s-serves-spyware/

Another hole found in PowerPoint

Proof-of-concept exploit shows further bug in slideshow software
Proof-of-concept exploit shows further bug in slideshow softwareMicrosoft has issued an alert over a new potential zero-day exploit in its PowerPoint presentation software. The… https://www.virusbulletin.com/blog/2006/10/another-hole-found-powerpoint/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.