VB Blog

A Christmas present for the security community

Posted by   Martijn Grooten on   Dec 24, 2016

As a Christmas present for the security community, we have uploaded most of the papers and videos from the VB2015 conference which took place in Prague almost 15 months ago. The Virus Bulletin crew wishes you all the best for 2017!

Read more  

Paper: Spreading techniques used by malware

Posted by   Martijn Grooten on   Dec 21, 2016

In a new paper published by Virus Bulletin, Acalvio researcher Abhishek Singh discusses some of the techniques used by malware to increase its impact by spreading further.

Read more  

VB2016 video: On the StrongPity waterhole attacks targeting Italian and Belgian encryption users

Posted by   Martijn Grooten on   Dec 20, 2016

At VB2016, Kaspersky Lab researcher Kurt Baumgartner delivered a presentation on the StrongPity watering hole attacks that targeted users of encryption technologies, and which were recently featured in a report by Microsoft. Today, we share the video of Kurt's presentation.

Read more  

Conference review: Botconf 2016

Posted by   Martijn Grooten on   Dec 20, 2016

Three members of the Virus Bulletin team attended the Botconf 2016 conference in Lyon, France last month, enjoying talks on subjects that ranged from state-sponsored attacks to exploit kits, and from banking trojans to cyber insurance.

Read more  

Throwback Thursday: Adjust Your Attitude!

Posted by   Helen Martin on   Dec 15, 2016

"Most of you reading this article have the technical skill but do you have the people skills?" In 2000, James Wolfe urged security experts to sell themselves and their services.

Read more  

VB2016 paper: Modern attacks on Russian financial institutions

Posted by   Martijn Grooten on   Dec 12, 2016

Today, we publish the VB2016 paper and presentation (recording) by ESET researchers Jean-Ian Boutin and Anton Cherepanov, in which they look at sophisticated attacks against Russian financial institutions.

Read more  

More on the Moose botnet at Botconf

Posted by   Martijn Grooten on   Dec 2, 2016

At Botconf 2016 this week, GoSecure researchers Masarah Paquet-Clouston and Olivier Bilodeau presented their research on the Moose botnet - something Olivier Bilodeau previously spoke about at VB2015.

Read more  

VB2016 paper: Defeating sandbox evasion: how to increase successful emulation rate in your virtualized environment

Posted by   Martijn Grooten on   Dec 2, 2016

Today, we publish the VB2016 paper and presentation (recording) by Check Point Software researchers Alexander Chailytko and Stanislav Skuratovich, which focuses on the techniques used by malware to detect virtual environments, and provides detailed technical descriptions of what can be done to defeat them.

Read more  

VB2016 paper: Mobile applications: a backdoor into the Internet of Things?

Posted by   Martijn Grooten on   Nov 29, 2016

While the Internet of Things blossoms with newly connected objects every day, the security and privacy of these objects is often overlooked, making the IoT a major security concern. Unfortunately, reverse-engineering so-called smart devices is not an easy task. In her VB2016 paper, Axelle Apvrille presented a novel way of analysing smart devices: by looking at the accompanying mobile app. Today, we publish both Axelle’s paper and the video recording of her VB2016 presentation.

Read more  

VB2016 paper: Wave your false flags! Deception tactics muddying attribution in targeted attacks

Posted by   Martijn Grooten on   Nov 21, 2016

Today, we publish the VB2016 paper and presentation (recording) by Kaspersky Lab researchers Juan Andrés Guerrero-Saade and Brian Bartholomew, in which they look at some of the deception tactics used in targeted attacks.

Read more  

Search blog

News round-up

October's goings on in the AV industry.
October's goings on in the AV industry. Despite no major malware outbreaks having occurred during last month's VB conference (as has almost seemed a tradition in the past),… https://www.virusbulletin.com/blog/2006/11/news-round/

November

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2006/11/

Spamhaus rests easy

US judge rules against suspending Spamhaus domain.
US judge rules against suspending Spamhaus domain. At the end of a month-long court battle, a US judge has ruled that UK anti-spam advisory organization Spamhaus will not have its… https://www.virusbulletin.com/blog/2006/11/spamhaus-rests-easy/

Sender ID specification released

Microsoft reveals all as part of its Open Specification Promise.
Microsoft reveals all as part of its Open Specification Promise.Microsoft has made its Sender ID Framework specification available as part of its recent Open Specification Promise,… https://www.virusbulletin.com/blog/2006/11/sender-id-specification-released/

New anti-spam group formed

StopSpamAlliance unites international bodies.
StopSpamAlliance unites international bodies. A group of international agencies and organisations have teamed up to launch StopSpamAlliance.org, designed to be a centralised base… https://www.virusbulletin.com/blog/2006/11/new-anti-spam-group-formed/

Phish check interface

Developer interface for checking phishy URLs.
Developer interface for checking phishy URLs. The people behind PhishTank, a collaborative clearing house for data and information about phishing, have revealed a simplified… https://www.virusbulletin.com/blog/2006/11/phish-check-interface/

Sophos engine faults disclosed

iDefense reports file-handling vulnerabilities.
iDefense reports file-handling vulnerabilities. Security researchers at iDefense have released information on four separate bugs in the Sophos anti-virus engine, affecting most… https://www.virusbulletin.com/blog/2006/10/sophos-engine-faults-disclosed/

Two more IE7 bugs downplayed by Microsoft

More phishing issues found, not a big problem says MS.
More phishing issues found, not a big problem says MS. A second bug was spotted late last week in Microsoft's recently-released Internet Explorer 7, which could allow malicious… https://www.virusbulletin.com/blog/2006/10/two-more-ie7-bugs-downplayed-microsoft/

McAfee up, Symantec down in profits

Financial reports differ widely between top security rivals.
Financial reports differ widely between top security rivals. Profits reports for the third quarter of the year show Symantec struggling with disappointing sales in the European… https://www.virusbulletin.com/blog/2006/10/mcafee-symantec-down-profits/

Australian spam firm fined $4.1 million

First case under spam laws brings hefty punishment.
First case under spam laws brings hefty punishment. A company based in Western Australia has been charged A$4.5 million, with another A$1 million levied from its director, after a… https://www.virusbulletin.com/blog/2006/10/australian-spam-firm-fined-4-1-million/

Windows Defender fully released

Microsoft anti-spyware product handed out free.
Microsoft anti-spyware product handed out free. After a lengthy beta period, Microsoft's free anti-spyware product, renamed Windows Defender halfway through its beta cycle, has… https://www.virusbulletin.com/blog/2006/10/windows-defender-fully-released/

Sender ID licence opened up

Microsoft frees up access to anti-spam framework.
Microsoft frees up access to anti-spam framework.Microsoft has put the specifications for the Sender ID and Sender Policy Framework (SPF) email verification system under its 'Open… https://www.virusbulletin.com/blog/2006/10/sender-id-licence-opened/

UK banks failing online users

Report names and shames insecure banking sites - again.
Report names and shames insecure banking sites - again. A report from heise Security, following up on a previous study released a month ago, claims several UK banks are still using… https://www.virusbulletin.com/blog/2006/10/uk-banks-failing-online-users/

Trojan installs Kaspersky AV

Scanner software used to keep out rival malware.
Scanner software used to keep out rival malware. A trojan has been reported in the wild using a genuine AV engine to keep its victims' machines free from other threats. This… https://www.virusbulletin.com/blog/2006/10/trojan-installs-kaspersky-av/

Latest VB100% test announced

Call for products issued for Windows XP x64 test.
Call for products issued for Windows XP x64 test. The latest round of VB 100% certification testing has been announced. The test will be run on the Windows XP Professional x64… https://www.virusbulletin.com/blog/2006/10/latest-test-announced/

Microsoft in multiple security rows

AV firms, Apple and Secunia embroiled in MS spats.
AV firms, Apple and Secunia embroiled in MS spats. Operating system giant Microsoft is engaged on multiple fronts in a series of security-related PR battles. The longest running… https://www.virusbulletin.com/blog/2006/10/microsoft-multiple-security-rows/

IE7 used as phishing lure

Spam campaign tries to hook users with new browser version.
Spam campaign tries to hook users with new browser version. A spam campaign has been spotted using the latest version of Microsoft's web browser, Internet Explorer 7, as bait. The… https://www.virusbulletin.com/blog/2006/10/ie7-used-phishing-lure/

MySpace users targeted by spam campaign

Phishers pose as online contacts to push bogus shopping sites.
Phishers pose as online contacts to push bogus shopping sites. A major spam campaign is bombarding inboxes with mails masquerading as messages from conacts on web social and… https://www.virusbulletin.com/blog/2006/10/myspace-users-targeted-spam-campaign/

MacDonald's serves up spyware

Diners 'rewarded' with infected music players
Diners 'rewarded' with infected music players Japanese customers of global burger giant MacDonald's have been warned that 10,000 MP3 players handed out by the firm as part of a… https://www.virusbulletin.com/blog/2006/10/macdonald-s-serves-spyware/

Another hole found in PowerPoint

Proof-of-concept exploit shows further bug in slideshow software
Proof-of-concept exploit shows further bug in slideshow softwareMicrosoft has issued an alert over a new potential zero-day exploit in its PowerPoint presentation software. The… https://www.virusbulletin.com/blog/2006/10/another-hole-found-powerpoint/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.