Cryptolocker: How to avoid getting infected and what to do if you are

Friday, October 25th, 2013

There's a big threat wiling around on the Internet right now: A particularly nasty piece of ransomware called Cryptolocker. Many, many organizations are being infected with this malware, but fortunately, there are surefire ways to avoid it and also ways to mitigate the damage without letting the lowlifes win. What is ...

Microsoft releases Sigcheck 2.0

Friday, October 25th, 2013

Sigcheck is a command-line utility that shows file version number, timestamp information, and digital signature details, including certificate chains. Version 2.0 adds integration with the VirusTotal antivirus scanner aggregation service. Sigcheck can now check the status of a file against over 40 antivirus engines and launch the associated online VirusTotal report, and ...

PHP.net compromised to serve malware

Friday, October 25th, 2013

On Thursday, Google's Safe Browsing service began warning visitors to php.net that the website was discovered serving malware. Initially, most people and PHP maintainers thought that it was a false positive, but subsequent investigation confirmed that some of the project's servers did get compromised. The hackers succeeded in injecting malicious JavaScript code (userprefs.js) ...

LastPass and the NSA Controversy

Tuesday, September 10th, 2013

With news that the United States National Security Agency has deliberately inserted weaknesses into security products and attempted to modify NIST standards, questions have been raised about how these actions affect LastPass and our customers. We want to directly address whether LastPass has been or could be weakened, and whether our users’ ...

Hackers Target Java 6 With Security Exploits

Tuesday, August 27th, 2013

Warning to anyone still using Java 6: Upgrade now to Java 7 to avoid being compromised by active attacks. That alert came via F-Secure anti-malware analyst Timo Hirvonen, who reported finding an in-the-wild exploit actively targeting an unpatched vulnerability in Java 6 following the recent publication of related proof-of-concept (POC) attack ...