VB Blog

WordPress users urged to manually update to fix bug that prevents automatic updating

Posted by   Martijn Grooten on   Feb 8, 2018

Users of the popular WordPress content management system are urged to manually update their installation to version 4.9.4, as a bug in the previous version broke the ability to automatically install updates.

Read more  

New paper: A review of the evolution of Andromeda over the years

Posted by   Martijn Grooten on   Feb 7, 2018

The Andromeda botnet (aka Gamarue or Wauchos) has plagued Internet users for more than half a decade but, following a takedown effort and the arrest of the suspected botnet owner in December 2017, it is likely we have seen the end of it. In a new paper by Fortinet researchers Bahare Sabouri and He Xu, we look back at the evolution of Andromeda from version 2.06 to 2.10 and demonstrate both how it improved its loader to evade automatic analysis/detection and how the payload varied among the different versions.

Read more  

There is no evidence in-the-wild malware is using Meltdown or Spectre

Posted by   Martijn Grooten on   Feb 2, 2018

Reports of malware using the Meltdown or Spectre attacks are likely based on proof-of-concept code rather than files written for a malicious purpose.

Read more  

Throwback Thursday: Malware taking a bit(coin) more than we bargained for

Posted by   Martijn Grooten on   Feb 1, 2018

This Throwback Thursday, we republish the VB2012 paper by Microsoft researcher Amir Fouda, one of the earliest papers to look at malware targeting Bitcoin.

Read more  

First time speaker? Don't be afraid of submitting to the VB2018 CFP

Posted by   Martijn Grooten on   Jan 31, 2018

We especially encourage those less experienced in speaking in public to submit to the call for papers for VB2018, where we aim to provide a friendly and welcoming environment in which people can both present their own research and learn from what others have been working on.

Read more  

VB2017 paper: VirusTotal tips, tricks and myths

Posted by   Martijn Grooten on   Jan 25, 2018

At VB2017 in Madrid, security researcher Randy Abrams presented an overview of the VirusTotal service and then went on to bust several of the persistent myths that surround it. Today we publish both Randy's paper and the recording of his presentation.

Read more  

Healthcare CERTs highlight the need for security guidance for specific sectors

Posted by   Martijn Grooten on   Jan 24, 2018

A new computer emergency response team has been launched in the Netherlands to provide guidance specifically tailored to the healthcare sector. Martijn Grooten welcomes the development.

Read more  

VB2018 call for papers now open!

Posted by   Martijn Grooten on   Jan 23, 2018

Have you analysed a new online threat? Do you know a new way to defend against such threats? Are you tasked with securing systems and fending off attacks? The call for papers for VB2018 is now open and we want to hear from you!

Read more  

Book review: Serious Cryptography

Posted by   Martijn Grooten on   Jan 22, 2018

VB Editor Martijn Grooten recommends Jean-Philippe Aumasson's 'Serious Cryptography' as a very solid but practically focused introduction to cryptography.

Read more  

Necurs pump-and-dump spam campaign pushes obscure cryptocurrency

Posted by   Martijn Grooten on   Jan 16, 2018

A Necurs pump-and-dump spam campaign pushing the lesser known Swisscoin botnet is mostly background noise for the Internet.

Read more  

Search blog

Fake updates and phony postcards carry malware

Microsoft patch and greetings card spams bring more trojans.
Microsoft patch and greetings card spams bring more trojans. Several spam runs posing as vulnerability alerts from Microsoft have been spotted in the last week, with links to… https://www.virusbulletin.com/blog/2007/07/fake-updates-and-phony-postcards-carry-malware/

NOD32 alerts on suspect adverts

False positive reveals sneaky techniques used in ads.
False positive reveals sneaky techniques used in ads.ESET's NOD32 product was updated several times in close succession over the weekend, as false positives were introduced… https://www.virusbulletin.com/blog/2007/07/nod32-alerts-suspect-adverts/

July issue of VB published

The July issue of Virus Bulletin is now available for subscribers to download.
The July issue of Virus Bulletin is now available for subscribers to download. The July 2007 issue of Virus Bulletin is now available for subscribers to browse online or download… https://www.virusbulletin.com/blog/2007/07/july-issue-vb-published/

Spammer offers new service

Spammer turns court order into money-making opportunity.
Spammer turns court order into money-making opportunity. Wily email marketer/spammer (depending on your viewpoint) David Linhardt, famed for suing UK spam-fighting organization… https://www.virusbulletin.com/blog/2007/07/spammer-offers-new-service/

Challenge Blue Pill

Researcher challenged to prove 100% undetectable rootkit claim.
Researcher challenged to prove 100% undetectable rootkit claim. Joanna Rutkowska, the security researcher who last year claimed that she can create 100% undetectable malware, has… https://www.virusbulletin.com/blog/2007/07/challenge-blue-pill/

Pity poor MS Security workers

MS Security rated 6th worst job in science.
MS Security rated 6th worst job in science. Spare a thought this month for the staff of the Microsoft Security Response Center who, according to Popular Science magazine, have the… https://www.virusbulletin.com/blog/2007/07/pity-poor-ms-security-workers/

July

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2007/07/

Advance diary dates: VB2008

VB announces VB2008.
VB announces VB2008. VB is pleased to announce that VB2008 will take place 1-3 October 2008 in Ottawa, Canada. Reserve the dates and start making your travel plans now! If you… https://www.virusbulletin.com/blog/2007/07/advance-diary-dates/

Symantec presenter spotted using KAV

Another update embarrassment as rival software pops up.
Another update embarrassment as rival software pops up. After the recent damaging false positive incident in China, which has led Symantec to offer free software to those hit by… https://www.virusbulletin.com/blog/2007/06/symantec-presenter-spotted-using-kav/

US porn spammers convicted

Two found guilty of CAN-SPAM breaches.
Two found guilty of CAN-SPAM breaches. A federal jury in Phoenix, Arizona, has found two men guilty of two charges of violating the US CAN-SPAM regulations, as well as other… https://www.virusbulletin.com/blog/2007/06/us-porn-spammers-convicted/

Spanish mobile malware suspect arrested

28-year-old charged with Cabir/Commwarrior crimes.
28-year-old charged with Cabir/Commwarrior crimes. An unnamed man has been arrested in Valencia, Spain, on suspicion of creating and spreading 20 variants of the Cabir and… https://www.virusbulletin.com/blog/2007/06/spanish-mobile-malware-suspect-arrested/

UK users ignoring security issues

Surveys find public in the dark and careless about sensitive data.
Surveys find public in the dark and careless about sensitive data. Several surveys out this week have shown the UK public is failing to take basic security precautions to protect… https://www.virusbulletin.com/blog/2007/06/uk-users-ignoring-security-issues/

100,000 new phishing sites set up in 7 days

IBM sees huge rise in kit-build scam sites.
IBM sees huge rise in kit-build scam sites. Phishing watchers at IBM's X-Force research team have recorded an enormous burst of phishing activity in the last seven days, with over… https://www.virusbulletin.com/blog/2007/06/100-000-new-phishing-sites-set-7-days/

Latest VB100 announced

Products for 64-bit Windows Vista to be tested.
Products for 64-bit Windows Vista to be tested. VB has issued a call for submissions for the latest VB100 comparative review, with products for the 64-bit version of Microsoft… https://www.virusbulletin.com/blog/2007/06/latest-announced/

China steps up fight against spammers

Blacklist aims to reduce massive spamming levels.
Blacklist aims to reduce massive spamming levels. Chinese web organisation the Internet Society of China (ISC) has announced the setting up of a central anti-spam blacklist, to… https://www.virusbulletin.com/blog/2007/06/china-steps-fight-against-spammers/

Mpack packs punch in Italy

10,000 sites carrying exploits in large-scale attack.
10,000 sites carrying exploits in large-scale attack. Sophisticated remote-exploit attack kit 'Mpack' has been spotted in use in increasingly large numbers throughout Europe, with… https://www.virusbulletin.com/blog/2007/06/mpack-packs-punch-italy/

FBI serves up Operation Bot Roast

Investigations identify more than 1 million victim IP addresses.
Investigations identify more than 1 million victim IP addresses. The FBI has announced the results of an ongoing initiative, dubbed 'Operation Bot Roast', which is aimed at… https://www.virusbulletin.com/blog/2007/06/fbi-serves-operation-bot-roast/

Phisher gets six years

Californian receives 70-month prison sentence, avoids 101 years behind bars.
Californian receives 70-month prison sentence, avoids 101 years behind bars. A Californian man, found guilty in January this year of operating a phishing scheme aimed at scamming… https://www.virusbulletin.com/blog/2007/06/phisher-gets-six-years/

Bugs found in Apple's new Windows browser within hours of release

Safari not so good-y.
Safari not so good-y. A number of security researchers say they found bugs in Apple's brand new web browser Safari for Windows just hours after its public beta release on 11 June.… https://www.virusbulletin.com/blog/2007/06/bugs-found-apple-s-new-windows-browser-within-hours-release/

4 critical flaws patched this Patch Tuesday

Microsoft's June Security Bulletin covers range of vulnerabilities.
Microsoft's June Security Bulletin covers range of vulnerabilities.Microsoft's latest 'Patch Tuesday' security bulletin, released yesterday, includes fixes for six vulnerabilities,… https://www.virusbulletin.com/blog/2007/06/4-critical-flaws-patched-patch-tuesday/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.