VB Blog

Facebook helps you determine whether emails really came from its servers

Posted by   Martijn Grooten on   Dec 21, 2017

On its website, Facebook now shows which emails it has sent you recently, thus helping you to determine which emails are real, and which should be discarded as phishing.

Read more  

Vulnerability disclosure and botnet takedown not to be hindered by Wassenaar Arrangement

Posted by   Martijn Grooten on   Dec 19, 2017

Clarification in the language of the Wassenaar Arrangement, a multilateral export control regime for conventional arms and dual-use goods and technologies, means those involved in vulnerability disclosure or botnet takedown won't have to worry about acquiring an export licence.

Read more  

VB2017 paper: Nine circles of Cerber

Posted by   Martijn Grooten on   Dec 15, 2017

Cerber is one of the major names in the world of ransomware, and last year, Check Point released a decryption service for the malware. Today, we publish a VB2017 paper by Check Point's Stanislav Skuratovich describing how the Cerber decryption tool worked; we have also uploaded the video of the presentation of this paper, by Or Eshed and Yaniv Balmas.

Read more  

Attack on Fox-IT shows how a DNS hijack can break multiple layers of security

Posted by   Martijn Grooten on   Dec 14, 2017

Dutch security firm Fox-IT deserves praise for being open about an attack on its client network. There are some important lessons to be learned about DNS security from its post-mortem.

Read more  

Throwback Thursday: BGP - from route hijacking to RPKI: how vulnerable is the Internet?

Posted by   Martijn Grooten on   Dec 14, 2017

For this week's Throwback Thursday, we look back at the video of a talk Level 3's Mike Benjamin gave at VB2016 in Denver, on BGP and BGP hijacks.

Read more  

Security Planner gives security advice based on your threat model

Posted by   Martijn Grooten on   Dec 13, 2017

Citizen Lab's Security Planner helps you improve your online safety, based on the specific threats you are facing.

Read more  

VB2017 video: Spora: the saga continues a.k.a. how to ruin your research in a week

Posted by   Martijn Grooten on   Dec 11, 2017

Today, we publish the video of the VB2017 presentation by Avast researcher Jakub Kroustek and his former colleague Előd Kironský, now at ESET, who told the story of Spora, one of of the most prominent ransomware families of 2017.

Read more  

VB2017 paper: Modern reconnaissance phase on APT – protection layer

Posted by   Martijn Grooten on   Dec 7, 2017

During recent research, Cisco Talos researchers observed the ways in which APT actors are evolving and how a reconnaissance phase is included in the infection vector in order to protect valuable zero-day exploits or malware frameworks. At VB2017 in Madrid, two of those researchers, Paul Rascagneres and Warren Mercer, presented a paper detailing five case studies that demonstrate how the infection vector is evolving. Today we publish both Paul and Warren's paper and the recording of their presentation.

Read more  

VB2017 paper: Peering into spam botnets

Posted by   Martijn Grooten on   Dec 1, 2017

At VB2017 in Madrid, CERT Poland researchers Maciej Kotowicz and Jarosław Jedynak presented a paper detailing their low-level analysis of five spam botnets. Today we publish their full paper.

Read more  

Throwback Thursday: Anti-malware testing undercover

Posted by   Martijn Grooten on   Nov 30, 2017

We look back at the VB2016 presentation by Righard Zwienenberg (ESET) and Luis Corrons (Panda Security), in which they discussed various issues relating to anti-malware testing.

Read more  

Search blog

Mobile-to-human virus scare hits Asian nations

Rumours of killer mobile malware travel from Pakistan to Afghanistan.
Rumours of killer mobile malware travel from Pakistan to Afghanistan. The effects of a possible prank which sparked considerable public panic in one country have travelled to a… https://www.virusbulletin.com/blog/2007/04/mobile-human-virus-scare-hits-asian-nations/

Worms exploiting Windows DNS flaw

Zero-day vulnerability quickly used to transmit attacks.
Zero-day vulnerability quickly used to transmit attacks. The zero-day vulnerability in Microsoft's DNS server service, reported last week just after the release of the monthly… https://www.virusbulletin.com/blog/2007/04/worms-exploiting-windows-dns-flaw/

Dr.Web Linux VB100 update

Dr.Web test results recalculated.
Dr.Web test results recalculated. Upon closer analysis of the latest set of VB100 test results VB has regrettably discovered some errors in the detection figures shown for Doctor… https://www.virusbulletin.com/blog/2007/04/dr-web-linux-update/

Sexy pics push Skype malware

Messaging attack hides behind photo of girl in stilettos.
Messaging attack hides behind photo of girl in stilettos. More malware has been reported spreading through the Skype API, sending links to itself to addresses gathered from… https://www.virusbulletin.com/blog/2007/04/sexy-pics-push-skype-malware/

Spam-fighters coalition formed

ICSA announces cooperative forum of anti-spam developers.
ICSA announces cooperative forum of anti-spam developers.CyberTrust-owned ICSA Labs has announced the formation of the Anti-Spam Product Developers' Consortium, a grouping of… https://www.virusbulletin.com/blog/2007/04/spam-fighters-coalition-formed/

US lengthens lead as top spammer

Rivals improve record to leave US spamming rate a standout.
Rivals improve record to leave US spamming rate a standout. The US remains the world's leading source of spam, easily beating off competition from rivals China and several European… https://www.virusbulletin.com/blog/2007/04/us-lengthens-lead-top-spammer/

New exploits emerge in wake of Patch Tuesday

Security update release cycle leads to attack release cycle.
Security update release cycle leads to attack release cycle. With the monthly 'Patch Tuesday' issue of security updates over, the now customary revelations of further… https://www.virusbulletin.com/blog/2007/04/new-exploits-emerge-wake-patch-tuesday/

Major seeding of Storm trojans seen

Latest wave of variants followed up by further fake warnings.
Latest wave of variants followed up by further fake warnings. Yet another wave of malware has been widely spammed out, using similar tactics to previous attacks evolving from the… https://www.virusbulletin.com/blog/2007/04/major-seeding-storm-trojans-seen/

Microsoft reveals more issues on Patch Tuesday

Fix for earlier .ani patch and another Vista issue included in batch.
Fix for earlier .ani patch and another Vista issue included in batch. Five out of six vulnerabilities patched by Microsoft yesterday, in April's 'Patch Tuesday' monthly security… https://www.virusbulletin.com/blog/2007/04/microsoft-reveals-more-issues-patch-tuesday/

Linux/iPod proof-of-concept sighted

New minority platform joins infectable list.
New minority platform joins infectable list. Virus analysts have reported receiving samples of a proof-of-concept virus for the iPodLinux operating system, a port of the… https://www.virusbulletin.com/blog/2007/04/linux-ipod-proof-concept-sighted/

Kaspersky patches series of vulnerabilities

ActiveX and overflow issues allowed remote data theft, local system attacks.
ActiveX and overflow issues allowed remote data theft, local system attacks. Several vulnerabilities have been revealed in many Kaspersky security products, including ActiveX flaws… https://www.virusbulletin.com/blog/2007/04/kaspersky-patches-series-vulnerabilities/

UK ISP association issues spam guidelines

ISPA best practices document advises providers on spam control.
ISPA best practices document advises providers on spam control. The UK Internet Services Providers' Association (ISPA), a voluntary grouping of service providers and other Internet… https://www.virusbulletin.com/blog/2007/04/uk-isp-association-issues-spam-guidelines/

NASA hacker loses case against extradition

UK man should face trial in States despite threats, say judges.
UK man should face trial in States despite threats, say judges. Greg McKinnon, the British hacker accused of breaking into NASA and US military networks while apparently… https://www.virusbulletin.com/blog/2007/04/nasa-hacker-loses-case-against-extradition/

Animated cursor flaw patched out of cycle

Microsoft reacts fast to widespread zero-day exploitation.
Microsoft reacts fast to widespread zero-day exploitation.Microsoft have once again broken their monthly patching cycle to release a fix for a vulnerability which has been the… https://www.virusbulletin.com/blog/2007/04/animated-cursor-flaw-patched-out-cycle/

Swiss spam law to enforce user security

New law may penalise careless zombie hosts.
New law may penalise careless zombie hosts. New anti-spam laws come into effect in Switzerland on Sunday, imposing strict curbs on spamming and strong punishment for perpetrators.… https://www.virusbulletin.com/blog/2007/04/swiss-spam-law-enforce-user-security/

Spam costing US companies over $70 billion per year

Survey finds junk email costs $713 per head in loss of productivity.
Survey finds junk email costs $713 per head in loss of productivity. A study into the impact of spam on US businesses has produced some startling figures for the financial impact… https://www.virusbulletin.com/blog/2007/04/spam-costing-us-companies-over-70-billion-year/

Third round for US anti-spyware bill

Anti-spyware legislation presented in US House of Representatives for third time.
Anti-spyware legislation presented in US House of Representatives for third time. Anti-spyware legislation was presented for the third time in the US House of Representatives last… https://www.virusbulletin.com/blog/2007/04/third-round-us-anti-spyware-bill/

April

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2007/04/

April issue of VB published

The April issue of Virus Bulletin is now available for subscribers to download.
The April issue of Virus Bulletin is now available for subscribers to download. The April 2007 issue of Virus Bulletin is now available for subscribers to browse online or… https://www.virusbulletin.com/blog/2007/04/april-issue-vb-published/

VB2007 conference programme revealed

VB has revealed the conference programme for VB2007, Vienna.
VB has revealed the conference programme for VB2007, Vienna. VB has revealed the conference programme for VB2007, Vienna. Once again, the three-day conference programme boasts… https://www.virusbulletin.com/blog/2007/04/conference-programme-revealed/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.