Security

MalwareBytesSecurity

A week in security (April 3 – 9)

Categories: News

Tags: TikTok

Tags: Super FabriXss

Tags: Twitter

Tags: macOS malware

Tags: ransomware

Tags: 2023 State of Malware

Tags: Western Digital

Tags: Android

Tags: endpoint security

Tags: ChatGPT

Tags: K-12

Tags: IoT

Tags: Facebook

Tags: targeted advertising

Tags: Google

Tags: data theft

Tags: e-file

Tags: tax

Tags: Uber breach

The most interesting security related news from the week of April 3 – 9.

(Read more…)

The post A week in security (April 3 – 9) appeared first on Malwarebytes Labs.

Read More
MicrosoftSecurity

Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign

Credit to Author: Microsoft Security Threat Intelligence – Editor| Date: Tue, 11 Apr 2023 17:00:00 +0000

This guide provides steps that organizations can take to assess whether users have been targeted or compromised by threat actors exploiting CVE-2022-21894 via a Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus.

The post Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign appeared first on Microsoft Security Blog.

Read More
MicrosoftSecurity

DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia

Credit to Author: Microsoft Security Threat Intelligence| Date: Tue, 11 Apr 2023 16:00:00 +0000

Microsoft analyzes a threat group tracked as DEV-0196, the actor’s iOS malware “KingsPawn”, and their link to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infrastructure called REIGN, that’s designed to exfiltrate data from mobile devices.

The post DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia appeared first on Microsoft Security Blog.

Read More
MalwareBytesSecurity

How the cops buy a “God view” of your location data, with Bennett Cyphers: Lock and Code S04E09

Categories: Podcast

This week on Lock and Code, we speak with Bennett Cyphers about one largely unknown company’s efforts to package and sell Americans’ location data almost exclusively to cops.

(Read more…)

The post How the cops buy a “God view” of your location data, with Bennett Cyphers: Lock and Code S04E09 appeared first on Malwarebytes Labs.

Read More