Friday, September 16, 2022
Saturday, October 3, 2020
Security: This malware is one more reason to dread PowerPoint presentations
Security: This malware is one more reason to dread PowerPoint presentations
Saturday, September 12, 2020
Linux users beware - you'll be facing more cyber threats than ever before
Linux users beware - you'll be facing more cyber threats than ever before
Linux users are warned to up their security protection following new research which found the system might be facing a big rise in cyber threats.
a
Researchers at Kaspersky have discovered an increase within the number of criminals targeting Linux, which is usually thought to be safer and safer than other operating systems.
But the corporate discovered an increase in attacks designed to specifically damage Linux systems as criminals follow bigger and bolder gains.
- We've put together an inventory of the simplest Linux laptops on the market
- These are the simplest Linux distros for privacy and security
- Also, inspect the simplest Linux web hosting services
Linux security
Kaspersky says the trend in attacks is especially worrying as more organizations choose Linux for strategically important servers and systems over Windows.
However the corporate found Linux systems could potentially be in danger from advanced persistent threats (APTs) and targeted attacks from hackers that have created specifically Linux-focused tools.
Kaspersky says that over a dozen APT actors, including dangerous threat groups like Lazarus, are observed to use Linux malware or some Linux-based modules in recent years, diversifying their attacks across multiple operating systems during a bid to maximize returns.
The company notes that there's a myth that Linux, being a less popular OS, is unlikely to be targeted by malware. However, this is often not the case, with smaller, more targeted attacks becoming the norm, especially in systems using multiple operating systems, where access to an infected device could allow hackers into endpoints running Windows or macOS.
In the example of Lazarus, which is reportedly based in North Korea, the group used Linux malware to hold out widespread attacks and attempts to focus on multiple organizations within the US and Europe.
“The trend of enhancing APT toolsets was identified by our experts repeatedly within the past, and Linux-focused tools are not any exception," noted Yury Namestnikov, head of Kaspersky’s Global Research and Analysis Team (GReAT) in Russia.
"Aiming to secure their systems, IT and security departments are using Linux more often than before. Threat actors are responding to the present with the creation of sophisticated tools that are ready to penetrate such systems. We advise cybersecurity experts to require this trend under consideration and implement additional measures to guard their servers and workstations."
In order to remain safe, Kaspersky recommends maintaining an inventory of trusted software sources and avoid using unencrypted update channels, and not running binaries and scripts from untrusted sources.
Thursday, August 13, 2020
New Update: Qualcomm Snapdragon bugs leave almost half all smartphones hospitable attack
Security flaws could allow hackers to tack control of devices, spy on users and make un-removable malware
(Image credit: Qualcomm)
New research from Check Point has discovered over 400 vulnerabilities in Qualcomm's Snapdragon Digital Signal Processor (DSP) chip that if exploited, could allow hackers to require control of over 40 percent of all smartphones.
A DSP may be a system on a chip that's used for the audio signal and digital image processing during a number of consumer devices including TVs and smartphones. While DSP chips bring a variety of latest features and capabilities to the devices they're utilized in, they also introduce new weak points and expand a device's attack surface.
Read Also: Qualcomm new ultrasonic fingerprint sensor may accompany a bigger scanning area
The vulnerabilities discovered by Check Point have serious implications as Qualcomm's chips are found in nearly every Android smartphone including flagship phones from Google, Samsung, LG, Xiaomi, OnePlus, and other hardware makers.
We've put together an inventory of the simplest malware removal software
Protect your privacy on mobile with one among the simplest Android VPNs
These are the simplest privacy apps for Android
By exploiting the vulnerabilities in Qualcomm's DSP chip, an attacker can spy on users via their smartphones, render a user's mobile constantly unresponsive and make un-removable malware capable of evading detection.
DSP chip vulnerabilities
Check Point responsibly disclosed its findings to Qualcomm and therefore the chip maker acknowledges the vulnerabilities, notified device vendors and assigned six of the issues with CVE listings.
Qualcomm has already patched the six security flaws affecting its Snapdragon DSP chip but smartphone makers still need to implement and deliver fixes to their users' devices which suggests that a lot of smartphones within the wild are still susceptible to potential attacks.
In a blog post, Check Point provided further insight on how it discovered the vulnerabilities within the company's DSP chips, saying:
“Due to the “Black Box” nature of the DSP chips, it's very challenging for the mobile vendors to repair these issues, as they have to be first addressed by the chip manufacturer. Using our research methodologies and state-of-the-art fuzz testing technologies, we were ready to overcome these issues – gaining us with a rare insight into the internals of the tested DSP chip. This allowed us to effectively review the chip’s security controls and identify its weak points.”
Given the severity of the vulnerabilities in Qualcomm's DSP chips, its recommended that users install any potential patches or fixes as soon as they become available.
A spokesperson from Qualcomm reached out TechRadar Pro and provided the subsequent statement on the matter:
Source URL Techradar
Friday, December 21, 2018
Malware threats continue to rise and target IoT
IoT malware and ransomware still on the rise, McAfee Labs report finds.
The number of new malware threats grew significantly during the last few months of 2018 as criminals upped their hacking game, according to research from McAfee Labs.
The firm reported finding 480 new variants every minute during the three months of Q3 2018, and new malware samples growing by 53 percent, showing the scale of security threats targeting consumers and businesses alike.
The company reported new IoT malware strains growing 73 percent during the three-month period, as the total amount of IoT malware was up 203 percent over the previous four quarters.
Ransomware threat
Among the other findings in the report were new ransomware strains increasing by 10 percent, illustrating the popularity of such malware strains, however, McAfee says that the number of unique ransomware families continued to decline.
“Cybercriminals are eager to weaponize vulnerabilities both new and old, and the number of services now available on underground markets has dramatically increased their effectiveness,” said Christiaan Beek, lead scientist at McAfee.
SOURCE:
Tuesday, September 25, 2018
Cryptocurrency Mining Malware is only going to get worse according to McAfee Report
And some of this crypto-mining malware is retooled ransomware
McAfee has published its latest threat report which highlights a big spike in cryptocurrency-related malware.
The McAfee Labs Threat Report for September found that malware which engages in cryptocurrency mining – using your PC’s resources behind your back to mine coins for someone else – nearly doubled in the second quarter of this year, with an 85% increase. In total, 2.5 million new samples were found, and McAfee discovered what appeared to be older strains of malware, like ransomware, retooled to target cryptocurrency.
That isn’t surprising given the amount of news we’ve seen coming through of these various crypto-mining exploits popping up all over the place, for example, in games on Steam or Kodi add-ons.
McAfee also found that malware which is designed to exploit software vulnerabilities shot up by 151% during Q2, much of it being repurposed spins on WannaCry and NotPetya.
Christiaan Beek, Lead Scientist and Senior Principal Engineer at McAfee, commented: “WannaCry and NotPetya provided cybercriminals compelling examples of how malware could use vulnerability exploits to gain a foothold on systems and then quickly propagate across networks.
“It’s still surprising to see numerous vulnerabilities from as far back as 2014 used successfully to spearhead attacks, even when there have been patches available for months and years to deflect exploits.”
Cortana capers
On the voice assistant front, McAfee reminded us of a flaw in Microsoft’s Cortana which allowed for bypassing the Windows 10 lock screen, found back in June, and patched by Microsoft at that time.
Concerning the Internet of Things and smart home gadgets, McAfee also highlighted a security hole in Belkin’s Wemo smart plug, which the security firm discovered last month. An attacker could potentially use this to remotely open a backdoor on a network, and subsequently, meddle with any connected smart home devices (for example, turning your smart TV on or off).
There are likely to be more vulnerabilities which can be leveraged via digital assistants discovered in the near future – McAfee has said it’s already looking more deeply into finding further examples of these – and there will certainly be more holes in IoT gadgets cropping up than you can shake a ‘smart stick’ at.
We’ve picked out the best antivirus software of 2018.
SOURCE TechRadar:
Monday, June 11, 2018
Malware hits HR programming firm PageUp with conceivable information bargain
The organization said the malware assault has conceivably uncovered the names and contact points of interest of its customers, for example, Telstra.
Tuesday, June 28, 2016
Malware Museum's main 10 oldies but goodies
From CoffeeShop to Mars Land to LSD, here are the historical center's most downloaded infections.
Huge hits
Since the Malware Museum opened its virtual entryways in February, its accumulation of de-fanged DOS-based malware from the 80s and 90s has pulled in about 1 million perspectives. (Perused the full story.) Here are the historical center's most downloaded infections.
Yankee Doodle
Initially found in 1989 and composed by a Bulgarian programmer, this is a memory-inhabitant DOS infection contaminating .com and .exe records. It's best known for the music that gave it its name. Once in memory, it plays - you got it - "Yankee Doodle" each day at 4:00 p.m. What's more, that wouldn't get irritating by any means, OK?
Mars Land
What emerges about this MS-DOS infection, which spread in newsgroups in 1997, is the cool, if primitive, geographical guide of Mars (thus the name) it seems to make. Mars Land is only one variation of the Spanska infection.
Song
Here's a case of how infection essayists used to get their deferred chuckles: Once this DOS-based malware was downloaded, it hid until the month and date related (April 4, for instance, or May 5), and would then junk data in the C: circle boot part. And afterward it would compound an already painful situation by playing the national song of devotion of what was, in 1990 when Hymn was made, the USSR. In the same way as other early infections, Hymn had teeth; it could render a defrauded PC unbootable without uncommon utilities.
More from the exhibition hall: Don't touch the malware at this historical center
LSD
This dreadful bit of work has certain control advance, showing as a Woodstock-period awesome medication trip video (nothing unexpected there, given the name). The inconvenience was that while casualties were laughing at the far-out video, the non-memory-occupant parasitic infection was overwriting all documents in their catalog. It then showed the triumphant message, "Coded By Death Dealer 4/29/94."
Club
This fiendishly cunning infection has been refered to by Mikko Hypponen, the adoptive parent of the Malware Museum, as a most loved outdated illustration. Casualties experienced the message, "I have recently DESTROYED the FAT [File Allocation Tables] on your plate!! Be that as it may, I have a duplicate in RAM, and I'm giving you a last opportunity to reestablish your valuable information." Hapless casualties then played five rounds of Jackpot, purportedly to spare their records. Be that as it may, whether they won or lost, most variations of Casino close down their PC, driving them to reinstall their working framework.
Walker
This DOS infection, however most variations open with an obscene picture, was moderately innocuous. Once the dreadful picture vanished, Walker showed as a man just strolling right to left over the client's screen like clockwork or something like that. (The man was a character from a long-overlooked PC amusement called Bad Street Brawler, on the off chance that you're following along.) Users were not able info information amid the irritating walks, yet that was the degree of the harm.
Crash
Moderately little is thought about this DOS infection, however it taints almost every .com document on contaminated machines. Its ubiquity at the exhibition hall, both Hypponen and Scott, is likely because of its awesome indication. Crash fills the screen with test-design hues and drivel characters, blazing alarmingly at the hapless client. "This is one reason individuals really recollect these [old DOS viruses] affectionately," Scott says. "They'll do a little move for you." You could stop the move by squeezing CTR-ALT-DEL - just to discover that your records had been wiped out.
Skynet
This unpleasant piece of malware was, obviously, propelled by The Terminator - the 1984 Arnold Schwarzenegger blockbuster. It contaminates all .exe records, moderating the PC significantly. Before long, the screen turns red and an odd, ungrammatical message (obviously, English was not the primary dialect of this current malware's creator) reports that it's an "exceptionally kind infection." That it might be - Skynet was not a corruptor of records - but rather it slowed a ton of PCs and bother a great deal of clients.
CoffeeShop
Initially found in 1992 and thought to begin in Sweden, this is a for the most part unremarkable DOS infection that embeds the content string "CoffeeShop" in tainted documents. It doesn't do much other than duplicate, so why is this such a prevalent Malware Museum download? It's about the visual: CoffeeShop shows on casualties' screens as a major green pot leaf, above which is composed, in red, white, and blue, no less: "Authorize CANNABIS." Apparently, today's gallery guests still discover the message laugh commendable.
A&A
No. 1 on the hit parade, A&A taints .com documents, changing the date and time stamps of contaminated projects to those of the disease. Outwardly, it clears and reprints pieces of the screen in a really mind-desensitizing design. Starting in Russia, A&A was initially seen in 1993. The Malware Museum is unable to say why this is the most as often as possible downloaded case. Wistfulness? Then again is the clarification something as basic as in sequential order request?
Wednesday, June 15, 2016
Piece malware,ransomware, and phishing with 5 layers
There's no silver slug to keeping interlopers and programmers out, yet you can minimize the danger by joining approaches.
They truly are after you.
I spent a week ago in London at the InfoSec gathering, where it wasn't just the sellers talking up security alarms, however the participants I talked with in the paths and meeting rooms. All of them had some individual involvement with lance phishing or a ransomware assault.
At InfoSec a lot of arrangements were proffered to limit such assaults, from point items to suites. It turned out to be clear that there are five key layers expected to safeguard your organization from such assaults.
1. Email security passage
Clearly the larger part of breaks nowadays start with an email. The email may contain a connection to some sort of data fraud site, guidelines for a wire exchange, or a weaponized connection. Lance phishing, whaling, ransomware, spam, and malware are all genuine dangers and aggravations that your association faces.
You ought to have some kind of email passage, be it a product in light of premises or a cloud-based apparatus or, then again, a machine. It's ideal on the off chance that you utilize a layered methodology where you upgrade what you as of now have, for example, inside Exchange or Exchange Online.
2. DNS security
The utilization of a DNS insurance apparatus like OpenDNS is an oft-overlooked choice for battling against assaults. Since each connection a client clicks must contact a DNS server for determination before the client can really open the connection, having a device that can gain from every one of those snaps can give a shield.
3. Endpoint security
From a specialized viewpoint, endpoint (customer) insurance is your last purpose of security against assaults. Endpoint assurance apparatuses range from antimalware programming to multifaceted validations VPNs, and you'll require more than one.
4. Client conduct examination
Client conduct examination apparatuses look for patterns in your client base with the goal that you can see when warnings come up, similar to a client who regularly downloads 10 reports a day beginning to download 1,000. There is no denying that Big Brother viewing your association is a key methodology going ahead in reality as we know it where more of the general population assaulting you are now within and trusted to a certain extent.
5. Phishing testing and preparing
Bringing issues to light and expanding the instruction level of the client (your weakest connection in security) is key. Not amazing, there are instruments to offer assistance. With such an apparatus, you can test your clients all the time to perceive how they respond to true assaults, then require they take extra preparing (over and over). It's the main way you can persuade them to be so jumpy about hurtful connections that they reconsider before clicking.
At last, a focused on assault may at present traverse all these layers. Be that as it may, by actualizing each of the five layers, you minimize the odds of being a casualty of such an assault.
Tuesday, April 7, 2015
Fast and effective malware detection -- for free
Everyone discovers computer code on the net that appears just like the right tool for a selected job. however is it safe? The Malwr malware detection website will tell you.
Ever discover a website or a service that is spic-and-span and funky, solely to find out it’s been around for years? No, I’m not talking concerning cat videos. i am relating the awful, free malware analysis website Malwr.
It’s been around since January 2011 and is predicated on the popular open supply analysis computer code Cuckoo. Malwr takes Cuckoo’s sandbox, throws a forepart thereon, and adds different connected options. I’m undecided if the malware analysis groups at the leading antivirus corporations use it (my guess is that they have additional subtle, dear analysis tools at their disposal), however Malwr is nice enough for any disassembling amateur. Claudio Guarnieri and Alessandro Tanasi -- severally, chairman and director of the Netherlands-based Cuckoo Foundation -- created and operate Malwr.
I detected that Malwr got overpowered a jiffy agone, running out of resources thanks to Associate in Nursing abundance of users. currently it runs on systems provided by the long-trusted Shadowserver Foundation.
To use it, move to malwr.com and opt for the Submit possibility from the highest of the page. Then browse to your malware sample, transfer it for examination, kind within the mathematical answer to a mathematician check, and click on on Analyze.
You can then pore through the results. The analysis includes:
- Hash process results
- Submission to Virustotal.com
- Screenshots of the program throughout execution and installation
- Static analysis
- Dynamic analysis
- Behaviors
- Domains contacted
- Hosts contacted
- whether or not the program makes itself autorun on Window systems
- written record keys created
- Files born
- Mutexes created
- Files and written record keys queried, failures, and successes
- Network activity
- HTTPS packets generated
There's a mess additional. i used to be delighted to envision the extent of knowledge delivered. It’s positively enough to work out if the program in question is doing one thing shady or sudden. It’s not good -- and malware is commonly written specifically to cover unhealthy behaviors from tools like Malwr -- however it’s a hundred times quicker than attempting to try to to the analysis on your own.
I downloaded a suspicious “registry cleaner” to research. Here square measure some screenshots from the results:
Malwr malware detection one
Malwr malware detection a pair of
Malwr malware detection five
It was nice that I didn’t need to run the malware sample on my very own desktop, though I may have done therefore safely in a very new created VM and put in extra watching tools -- or maybe used Cuckoo. Instead, I designated the file, uploaded to Malwr, and waited one or 2 minutes whereas it did all the diligence -- no setup or configuration, no sweat, and no mussy cleanup, one and done. I love it.
Though I’m late to the invention, i do know needless to say that Malwr are one in all my go-to tools -- beside Sysinternals Processor individual and Virustotal.com -- for a protracted time.










