Why Log4Text is not another Log4Shell

Categories: Exploits and vulnerabilities

Categories: News

Tags: Log4Text

Tags: Apache

Tags: Commons Text

Tags: CVE-2022-42889

Tags: Log4j

Tags: Log4Shell

Tags: interpolators

Log4Text is a recently found vulnerability in Apache Commons. Log4Text provoked a knee jerk reaction because it reminds us of Log4Shell. So should we worry?

(Read more…)

The post Why Log4Text is not another Log4Shell appeared first on Malwarebytes Labs.

Read more

DeadBolt ransomware gang tricked into giving victims free decryption keys

Categories: News

Categories: Ransomware

Tags: Dutch

Tags: law enforcement

Tags: DeadBolt

Tags: ransomware

Tags: decryption keys

Tags: responders.nu

With the idea provided by an incident response company, Dutch police used a clever trick to get 150 DeadBolt ransomware decryption keys for free.

(Read more…)

The post DeadBolt ransomware gang tricked into giving victims free decryption keys appeared first on Malwarebytes Labs.

Read more

Warning: “FaceStealer” iOS and Android apps steal your Facebook login

Categories: Awareness

Categories: News

Tags: FaceStealer

Tags: Facebook stealer

Tags: Facebook

Tags: Nathan Collier

Tags: Meta

Tags: fake Android apps

Tags: fake iOS apps

FaceStealer is back. As a seasoned threat to legitimate app stores, expect it to be gone and then back again.

(Read more…)

The post Warning: “FaceStealer” iOS and Android apps steal your Facebook login appeared first on Malwarebytes Labs.

Read more

Fake tractor fraudsters plague online transactions

Categories: News

Tags: Tractors

Tags: Australia

Tags: scam

Tags: fake

Tags: escrow

Tags: advert

Tags: advertising

Tags: advertisement

We take a look at reports of the agriculture sector increasingly running into fake online adverts for tractors, at great cost to unfortunate buyers.

(Read more…)

The post Fake tractor fraudsters plague online transactions appeared first on Malwarebytes Labs.

Read more

Thermal cameras could help reveal your password

Categories: News

Categories: Threats

Tags: ThermoSecure

Tags: University of Glasgow

Tags: Dr. Mohamed Khamis

Tags: Dr. John Williamson

Tags: Norah Alotaibi

Tags: thermal attack

ThermoSecure, a system developed by researchers at the University of Glasgow demonstrated how thermal cameras and AI can steal credentials from, literally, under our noses.

(Read more…)

The post Thermal cameras could help reveal your password appeared first on Malwarebytes Labs.

Read more

A week in security (October 10 – 16)

Categories: News

Tags: a week in security

Tags: week in security

Tags: AI Bill of Rights

Tags: Final Fantasy XIV

Tags: Lock and Code S03E21

Tags: Meta

Tags: WhatsApp

Tags: ransomware

Tags: tax scam

Tags: Chinese APT

Tags: Android

Tags: Chrome

Tags: iOS

Tags: managed detection response

Tags: MDR

Tags: disinformation

Tags: FBI

Tags: CISA

The most important and interesting computer security stories from the last week.

(Read more…)

The post A week in security (October 10 – 16) appeared first on Malwarebytes Labs.

Read more

Winnti APT group docks in Sri Lanka for new campaign

Categories: Threat Intelligence

Tags: Winnti

Tags: APT

Tags: China

Tags: Sri Lanka

Tags: India

Tags: Keyplug

Tags: malware

Tags: dropbox

Tags: C2

Tags: DBoxAgent

In this research paper, we document a new campaign we attribute to the Winnti APT group. The victims are located in Sri Lanka at a point in time where the country is going through economic hardship while China makes headlines for docking on of its special vessels there.

(Read more…)

The post Winnti APT group docks in Sri Lanka for new campaign appeared first on Malwarebytes Labs.

Read more