VB Blog

Tizi Android malware highlights the importance of security patches for high-risk users

Posted by   Martijn Grooten on   Nov 28, 2017

Researchers from Google have taken down 'Tizi', an Android malware family, that used nine already patched vulnerabilities to obtain root on infected devices.

Read more  

Virus Bulletin to attend AMTSO, AVAR and Botconf

Posted by   Martijn Grooten on   Nov 27, 2017

Next week, Virus Bulletin researchers will be attending the AMTSO meeting and AVAR conference in Beijing, China, as well as the 5th edition of the Botconf conference in Montpellier, France.

Read more  

VB2017 video: FinFisher: New techniques and infection vectors revealed

Posted by   Martijn Grooten on   Nov 24, 2017

Today, we publish the video of the VB2017 presentation by ESET researcher Filip Kafka, who looked at recent changes in the FinFisher government malware, including its infection vectors.

Read more  

Throwback Thursday: The beginning of the end(point): where we are now and where we'll be in five years

Posted by   Martijn Grooten on   Nov 23, 2017

We look back at the VB2016 presentation by Adrian Sanabria on the state of endpoint security, both now and in the future.

Read more  

VB2017 paper: Beyond lexical and PDNS: using signals on graphs to uncover online threats at scale

Posted by   Martijn Grooten on   Nov 22, 2017

At VB2017 in Madrid, Cisco Umbrella (OpenDNS) researchers Dhia Mahjoub and David Rodriguez presented a new approach to detecting infected machines using graphs to detect botnet traffic at scale. Today we publish both Dhia and David's paper and the recording of their presentation.

Read more  

Firefox 59 to make it a lot harder to use data URIs in phishing attacks

Posted by   Martijn Grooten on   Nov 21, 2017

Firefox developer Mozilla has announced that, as of version 59 of the browser, many kinds of data URIs, which provide a way to create "domainless web content", will not be rendered in the browser, thus making this trick - used in various phishing campaigns - a lot less attractive.

Read more  

Standalone product test: FireEye Endpoint

Posted by   Martijn Grooten on   Nov 16, 2017

Virus Bulletin ran a standalone test on FireEye's Endpoint Security solution.

Read more  

VB2017 video: Consequences of bad security in health care

Posted by   Martijn Grooten on   Nov 13, 2017

Jelena Milosevic, a nurse with a passion for IT security, is uniquely placed to witness poor security practices in the health care sector, and to fully understand the consequences. Today, we publish the recording of a presentation given by Jelena at VB2017 in Madrid, in which she shared her inside view of security in hospitals.

Read more  

Vulnerabilities play only a tiny role in the security risks that come with mobile phones

Posted by   Martijn Grooten on   Nov 9, 2017

Both bad news (all devices were pwnd) and good news (pwning is increasingly difficult) came from the most recent mobile Pwn2Own competition. But the practical security risks that come with using mobile phones have little to do with vulnerabilities.

Read more  

VB2017 paper: The (testing) world turned upside down

Posted by   Martijn Grooten on   Nov 8, 2017

At VB2017 in Madrid, industry veteran and ESET Senior Research Fellow David Harley presented a paper on the state of security software testing. Today we publish David's paper in both HTML and PDF format.

Read more  

Search blog

Corporate mail spam drops Haxdoor

Business-related message carries trojan.
Business-related message carries trojan. A vaguely official-sounding email is being widely spammed, claiming to relate to some nebulous business activity between the sender and… https://www.virusbulletin.com/blog/2006/08/corporate-mail-spam-drops-haxdoor/

Phone companies' security shaken

As T-Mobile hacker is convicted, AT&T reveals break-in.
As T-Mobile hacker is convicted, AT&T reveals break-in. A 23-year-old Oregon resident has been sentenced to a year of 'home detention', after being convicted of hacking into the… https://www.virusbulletin.com/blog/2006/08/phone-companies-security-shaken/

BitDefender to join mobile market

AV firm releases phone security beta.
AV firm releases phone security beta.BitDefender has become the latest AV company to make a move into the mobile device market. It has released a beta of its mobile AV software,… https://www.virusbulletin.com/blog/2006/08/bitdefender-join-mobile-market/

AOL 9.0 slated for suspect tactics

More badware accusations levelled at web giant.
More badware accusations levelled at web giant.StopBadware.org, the international anti-malware coalition backed by Google and Sun among others, has labelled AOL's current free… https://www.virusbulletin.com/blog/2006/08/aol-9-0-slated-suspect-tactics/

More ConsumerReports complaints

Testing organisation's methodology slammed again.
Testing organisation's methodology slammed again.ConsumerReports.org, the online wing of American consumers association Consumers Union, is once again taking flak for its testing… https://www.virusbulletin.com/blog/2006/08/more-consumerreports-complaints/

iPod spam carries trojan

Fake sales invoice includes downloader.
Fake sales invoice includes downloader. A new spam campaign claiming to be information on an order for a new iPod is accompanied by a trojan which, when run, attempts to download… https://www.virusbulletin.com/blog/2006/08/ipod-spam-carries-trojan/

IBM invests in security, others may follow

Big Blue purchase sparks rumours of more mergers.
Big Blue purchase sparks rumours of more mergers. When massive cross-sector IT giant IBM bought Internet Security Systems for a rumoured $1.3 billion last week, it joined the list… https://www.virusbulletin.com/blog/2006/08/ibm-invests-security-others-may-follow/

Share dealers robbed, phishing suspected

Canadian stock-trading association warns of security breaches.
Canadian stock-trading association warns of security breaches. The Investment Dealers Association of Canada (IDA), a national regulatory organisation, has released an urgent press… https://www.virusbulletin.com/blog/2006/08/share-dealers-robbed-phishing-suspected/

Malware mostly crime-related, says Panda

Security firm reports 88% of new malware linked to cyber crime.
Security firm reports 88% of new malware linked to cyber crime. The labs of Spanish firm Panda Software have released a quarterly report, stating that criminal activity is behind… https://www.virusbulletin.com/blog/2006/08/malware-mostly-crime-related-says-panda/

Three years for botnet master

Zombie herder sentenced to 37 months behind bars.
Zombie herder sentenced to 37 months behind bars. A Californian 21-year-old has been sent to a federal prison in the US, after being convicted of computer fraud and computer damage… https://www.virusbulletin.com/blog/2006/08/three-years-botnet-master/

Rooting out malware

Sophos joins anti-rootkit market, others expected to follow soon.
Sophos joins anti-rootkit market, others expected to follow soon.Sophos has released a free anti-rootkit tool, available for download from its website. The UK-based company joins… https://www.virusbulletin.com/blog/2006/08/rooting-out-malware/

Child porn blackmail spam carries trojan

Spoof mail claims to come from anti-child porn site.
Spoof mail claims to come from anti-child porn site. A spam campaign claiming to come from child porn activists ASACP accuses recipients of visiting child porn sites, suggesting a… https://www.virusbulletin.com/blog/2006/08/child-porn-blackmail-spam-carries-trojan/

Phishing help for Yahoo! users

As phishing nets spread wider, Yahoo! announces defensive 'seal'.
As phishing nets spread wider, Yahoo! announces defensive 'seal'. Web giant Yahoo! has announced plans to introduce a new anti-phishing system to help protect its customers. The… https://www.virusbulletin.com/blog/2006/08/phishing-help-yahoo-users/

Trend and Microsoft deny vulnerability

PowerPoint zero-day hype just hype after all.
PowerPoint zero-day hype just hype after all. After an announcement from Trend Micro sparked numerous reports of a zero-day PowerPoint exploit, taking advantage of an… https://www.virusbulletin.com/blog/2006/08/trend-and-microsoft-deny-vulnerability/

Stock scam spam duo sued

Pump-and-dump couple face fines, as do many others worldwide.
Pump-and-dump couple face fines, as do many others worldwide. A Connecticut couple have been indicted over claims they used a spam campaign to artificially inflate stock prices. In… https://www.virusbulletin.com/blog/2006/08/stock-scam-spam-duo-sued/

AOL AV in adware alarm

Free product offered by AOL accused of potentially unwanted tactics.
Free product offered by AOL accused of potentially unwanted tactics. Recently released Active Virus Shield, the Kaspersky-based anti-virus product from web giant AOL, is coming… https://www.virusbulletin.com/blog/2006/08/aol-av-adware-alarm/

McAfee faces legal and financial woes

With books under scrutiny, McAfee is sued over property rights.
With books under scrutiny, McAfee is sued over property rights. As McAfee faces up to the likelihood of its financial results for the last five years being overturned following… https://www.virusbulletin.com/blog/2006/08/mcafee-faces-legal-and-financial-woes/

Phishers target more charities

Christian Aid warns supporters of bogus emails, while Katrina phishmaster is indicted.
Christian Aid warns supporters of bogus emails, while Katrina phishmaster is indicted. Church charity organisation Christian Aid has released a statement warning supporters to be… https://www.virusbulletin.com/blog/2006/08/phishers-target-more-charities/

Movie firm harasses users with spyware

Film download service accused of using spyware strongarm tactics.
Film download service accused of using spyware strongarm tactics. Washington state has brought an action against a firm called Movieland.com, after complaints that the company's… https://www.virusbulletin.com/blog/2006/08/movie-firm-harasses-users-spyware/

AOL digging for spammer's treasure

Web giant plans hunt for hidden spam gold.
Web giant plans hunt for hidden spam gold. ISP mammoth AOL has obtained a court judgement allowing it to dig up the land of a convicted spammer's family, in a search for a stash… https://www.virusbulletin.com/blog/2006/08/aol-digging-spammer-s-treasure/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.