VB Blog

Throwback Thursday: Olympic Games

Posted by   Helen Martin on   Aug 2, 2016

In 1994, along with the Olympic Games came an Olympic virus, from a group of Swedish virus authors calling themselves ‘Immortal Riot’. We look back at Mikko Hyppönen's analysis in the VB archive.

Read more  

VB2016 call for last-minute papers opened, discounts announced

Posted by   Martijn Grooten on   Aug 1, 2016

Announcing the VB2016 call for last-minute papers and a number of discounts on the conference registration rate.

Read more  

Guest Blog: Malicious Scripts Gaining Prevalence in Brazil

Posted by   Virus Bulletin on   Jul 28, 2016

In the run up to VB2016, we invited the conference sponsors to write guest posts for our blog. In the second of this series, ESET's Matías Porolli writes about malicious Visual Basic and JavaScript gaining prevalence in Brazil.

Read more  

Romanian university website compromised to serve Neutrino exploit kit

Posted by   Martijn Grooten on   Jul 28, 2016

The website of the Carol Davila University of Medicine and Pharmacy has been compromised to inject a hidden iframe into the site's source code that serves the Neutrino exploit kit and may infect visitors with ransomware.

Read more  

It's 2016. Can we stop using MD5 in malware analyses?

Posted by   Martijn Grooten on   Jul 26, 2016

While there are no actually risks involved in using MD5s in malware analyses, it reinforces bad habits and we should all start using SHA-256 instead.

Read more  

Throwback Thursday: Holding the Bady

Posted by   Helen Martin on   Jul 21, 2016

In 2001, ‘Code Red’ caused White House administrators to change the IP address of the official White House website, and even penetrated Microsoft’s own IIS servers.

Read more  

Paper: The Journey of Evasion Enters Behavioural Phase

Posted by   Martijn Grooten on   Jul 20, 2016

A new paper by FireEye researcher Ankit Anubhav provides an overview of evasion techniques applied by recently discovered malware.

Read more  

Guest blog: Espionage toolkit uncovered targeting Central and Eastern Europe

Posted by   Virus Bulletin on   Jul 15, 2016

Recently, ESET researchers uncovered a new espionage toolkit targeting targeting Central and Eastern Europe. They provide some details in a guest post.

Read more  

Avast acquires AVG for $1.3bn

Posted by   Martijn Grooten on   Jul 8, 2016

Anti-virus vendor Avast has announced the acquisition of its rival AVG for 1.3 billion US dollars.

Read more  

Throwback Thursday: You Are the Weakest Link, Goodbye!

Posted by   Helen Martin on   Jul 7, 2016

Passwords have long been a weak point in the security chain, despite efforts to encourage users to pick strong ones. 13 years ago, Martin Overton wrote an article highlighting the weakness and explaining why it is the human element that presents the biggest risk to computer security - something that rings as true today as it did 13 years ago.

Read more  

Search blog

Symbian SMS pest highlighted

Mobile exploit attack disables messaging.
Mobile exploit attack disables messaging. A presentation at a popular hacking forum has brought much attention to a flaw in the SMS processing in some versions of the Symbian… https://www.virusbulletin.com/blog/2009/01/symbian-sms-pest-highlighted/

MS to release out-of-band patch for critical IE vulnerability

Users advised to patch ASAP.
Users advised to patch ASAP.Microsoft is set to release an emergency out-of-band patch for the vulnerability in its Internet Explorer browser reported last week. Attacks via the… https://www.virusbulletin.com/blog/2008/12/ms-release-out-band-patch-critical-ie-vulnerability/

IE zero-day danger growing

Large numbers of users vulnerable to unpatched problem.
Large numbers of users vulnerable to unpatched problem. The as-yet unpatched vulnerability in Microsoft's Internet Explorer browser, reported last week and coinciding with the… https://www.virusbulletin.com/blog/2008/12/ie-zero-day-danger-growing/

FTC goes after scareware scammers

Courts crack down on pushers of rogue anti-malware.
Courts crack down on pushers of rogue anti-malware. The US Federal Trade Commission (FTC) has announced a successful move to persuade a US district court to shut down a major… https://www.virusbulletin.com/blog/2008/12/ftc-goes-after-scareware-scammers/

Patch Tuesday released closely followed by emergency update

Bumper crop of patches plus further fix leave known holes open.
Bumper crop of patches plus further fix leave known holes open. This month's 'Patch Tuesday' security bulletin from Microsoft contained eight separate updates, two more than… https://www.virusbulletin.com/blog/2008/12/patch-tuesday-released-closely-followed-emergency-update/

Worm targets MS08-067 vulnerability

Exploit attack patches flaw once system penetrated.
Exploit attack patches flaw once system penetrated. A worm has been seen taking advantage of the vulnerability in Microsoft's Windows Server Service, patched out-of-cycle last… https://www.virusbulletin.com/blog/2008/12/worm-targets-ms08-067-vulnerability/

Two updates in Microsoft's November's patch release

Just two updates released by Microsoft this month: one rated critical, one important.
Just two updates released by Microsoft this month: one rated critical, one important.Microsoft has issued two updates in the November round of its monthly patch release cycle, one… https://www.virusbulletin.com/blog/2008/11/two-updates-microsoft-s-november-s-patch-release/

Microsoft issues emergency patch

Out-of-cycle update fixes serious, wormable flaw.
Out-of-cycle update fixes serious, wormable flaw.Microsoft has issued an emergency update to cover a serious vulnerability in the Windows Server service, breaking its usual monthly… https://www.virusbulletin.com/blog/2008/10/microsoft-issues-emergency-patch/

Vulnerability test raises hackles

Secunia suite trial slates lack of PoC detection, but test methods called into question.
Secunia suite trial slates lack of PoC detection, but test methods called into question. Vulnerability specialist Secunia published the results of a trial of internet security… https://www.virusbulletin.com/blog/2008/10/vulnerability-test-raises-hackles/

Four critical updates this Patch Tuesday

11 updates to be issued by Microsoft in October's monthly patch release: 4 critical.
11 updates to be issued by Microsoft in October's monthly patch release: 4 critical.Microsoft has prepared a total of 11 updates for the October round of its monthly patch release… https://www.virusbulletin.com/blog/2008/10/four-critical-updates-patch-tuesday/

Four critical updates in Patch Tuesday release

Monthly security update small but vital.
Monthly security update small but vital.Microsoft has released its monthly 'Patch Tuesday' batch of security updates, with only four items on the list but all of them marked… https://www.virusbulletin.com/blog/2008/09/four-critical-updates-patch-tuesday-release/

Trend OfficeScan flaws labelled highly critical

Web-delivered products at risk of allowing remote access.
Web-delivered products at risk of allowing remote access. A set of vulnerabilities have been reported in Trend Micro's Officescan product, which have been flagged with the 'Highly… https://www.virusbulletin.com/blog/2008/08/trend-officescan-flaws-labelled-highly-critical/

DNS flaw exploitation danger growing

Slow patchers targeted by sophisticated attacks.
Slow patchers targeted by sophisticated attacks. The serious vulnerability in the implementation of DNS systems has been targeted by malicious attacks, as security watchers have… https://www.virusbulletin.com/blog/2008/08/dns-flaw-exploitation-danger-growing/

Patch Tuesday sees serious DNS flaws fixed

Nothing marked critical, but some very important patches issued.
Nothing marked critical, but some very important patches issued.Microsoft's latest 'Patch Tuesday' round of security updates for once contains no bulletins marked as 'critical',… https://www.virusbulletin.com/blog/2008/07/patch-tuesday-sees-serious-dns-flaws-fixed/

Macs under attack from trojan double whammy

Two new threats in a week spark worries of approaching Mac malware era.
Two new threats in a week spark worries of approaching Mac malware era. Users of Apple Mac systems, who have so far only suffered from minimal attention from malware creators, may… https://www.virusbulletin.com/blog/2008/06/macs-under-attack-trojan-double-whammy/

Microsoft releases latest Patch Tuesday fixes

7 vulnerabilities, 3 critical, addressed in June security update.
7 vulnerabilities, 3 critical, addressed in June security update.Microsoft has issued its monthly 'Patch Tuesday' set of security fixes, with seven separate areas covered of which… https://www.virusbulletin.com/blog/2008/06/microsoft-releases-latest-patch-tuesday-fixes/

Microsoft increases pressure on Apple to fix Safari blended threat

'Carpet bombing' vulnerability more serious than Apple claims, MS warns.
'Carpet bombing' vulnerability more serious than Apple claims, MS warns.Microsoft, whose Internet Explorer has come under frequent criticism for security vulnerabilities, has… https://www.virusbulletin.com/blog/2008/06/microsoft-increases-pressure-apple-fix-safari-blended-threat/

Latest Patch Tuesday update released

Microsoft announces five 'critical' vulnerabilities need fixing.
Microsoft announces five 'critical' vulnerabilities need fixing.Microsoft has issued its monthly 'Patch Tuesday' security bulletin, with five 'critical' and three 'important'… https://www.virusbulletin.com/blog/2008/04/latest-patch-tuesday-update-released/

Latest Patch Tuesday release

March's Patch Tuesday sees four 'critical' updates.
March's Patch Tuesday sees four 'critical' updates.Microsoft has released its monthly 'Patch Tuesday' security bulletin. This month the bulletin features four 'critical' updates,… https://www.virusbulletin.com/blog/2008/03/latest-patch-tuesday-release/

Cisco announces 'Patch Wednesdays'

Cisco set to embark on regular release cycle.
Cisco set to embark on regular release cycle. Following a trend set by Microsoft's monthly 'Patch Tuesdays' and Oracle's quarterly security updates, networking giant Cisco has… https://www.virusbulletin.com/blog/2008/03/cisco-announces-patch-wednesdays/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.