Update now! WinRAR files can be abused to run malware

Categories: Exploits and vulnerabilities

Categories: News

Tags: WinRAR

Tags: CVE-2023-40477

Tags: RCE

Tags: Windows 11

A new version of WinRAR is available that patches two vulnerabilities attackers could use for remote code execution.

(Read more…)

The post Update now! WinRAR files can be abused to run malware appeared first on Malwarebytes Labs.

Read more

Chrome will soon start removing extensions that may be unsafe

Categories: Personal

Tags: chrome

Tags: browser

Tags: rogue

Tags: malicious

Tags: malware

Tags: extension

Tags: remove

Tags: delete

Tags: uninstall

We take a look at news that Chrome will soon start asking users if they want to remove outdated extensions.

(Read more…)

The post Chrome will soon start removing extensions that may be unsafe appeared first on Malwarebytes Labs.

Read more

QR codes used to phish for Microsoft credentials

Categories: News

Tags: QR codes

Tags: attachment

Tags: phishing

Tags: Bing

Tags: Microsoft

Tags: credentials

Researchers have been monitoring a phishing campaign that uses QR codes and Bing redirects to lead targets to phishing sites.

(Read more…)

The post QR codes used to phish for Microsoft credentials appeared first on Malwarebytes Labs.

Read more

Patch now! Citrix Sharefile joins the list of actively exploited file sharing software

Categories: Exploits and vulnerabilities

Categories: News

Tags: Citrix

Tags: ShareFile

Tags: CVE-2023-24489

Tags: RCE

Tags: unauthenticated

Tags: vulnerability

Tags: PoC

Citrix ShareFile can be exploited remotely by unauthenticated attackers.

(Read more…)

The post Patch now! Citrix Sharefile joins the list of actively exploited file sharing software appeared first on Malwarebytes Labs.

Read more

Exchange Server security updates updated

Categories: Exploits and vulnerabilities

Categories: News

Tags: Exchange

Tags: CVE-2023-21709

Tags: August update

Tags: re-release

Microsoft Exchange Server administrators may have to install a re-released security patch

(Read more…)

The post Exchange Server security updates updated appeared first on Malwarebytes Labs.

Read more

Catching up with WoofLocker, the most elaborate traffic redirection scheme to tech support scams

Categories: Threat Intelligence

Tags: tech support scams

Tags: fingerprinting

Tags: steganography

This tech support scam is one of the most long running and covert ones we have ever seen.

(Read more…)

The post Catching up with WoofLocker, the most elaborate traffic redirection scheme to tech support scams appeared first on Malwarebytes Labs.

Read more