BlackMailware Found On Porn Site Threatens to Report Users are Spreading Child Porn
https://www.bleepingcomputer.com/news/security/blackmailware-found-on-porn-site-threatens-to-report-users-are-spreading-child-porn/
Blackmailware and Scare Tactics may be more efficient than Ransomware

Adware malvertising, the big threat of 2017 and still going strong:

Read: https://blog.trendmicro.com/trendlabs-security-intelligence/malvertising-campaign-abuses-googles-doubleclick-to-deliver-cryptocurrency-miners/

Mining a reason to keep your adblocker visors high inside your browser of choice!
One copuld also use an additional anti-miner extension.

polonus

Mozilla’s apologies for errors made: https://blog.mozilla.org/firefox/retrospective-looking-glass/

polonus

It’s always easy to realize that after you’ve gotten a black eye, that maybe you should have ducked. :slight_smile:

Security Advisory for Flash Player | APSA18-01
https://helpx.adobe.com/security/products/flash-player/apsa18-01.html

WannaMine – new cryptocurrency malware exposes failings of traditional anti-virus tools
https://www.pandasecurity.com/mediacenter/mobile-news/wannamine-cryptomining-malware/

Malvertizing leads 500k victims to 90 bad Chrome Web Store extensions
https://www.cso.com.au/article/632897/

https://blog.trendmicro.com/trendlabs-security-intelligence/malicious-chrome-extensions-found-chrome-web-store-form-droidclub-botnet/

System Cryptomix Ransomware Variant Released
https://www.bleepingcomputer.com/news/security/system-cryptomix-ransomware-variant-released/

With this version, when a file is encrypted by the ransomware, it will modify the filename and then append the .SYSTEM extension to encrypted file’s name.

New JenX IoT DDoS Botnet Offered Part of Gaming Server Rental Scheme
https://www.bleepingcomputer.com/news/security/new-jenx-iot-ddos-botnet-offered-part-of-gaming-server-rental-scheme/

Word Press update will break automatic update.:
https://wordpress.org/news/2018/02/wordpress-4-9-4-maintenance-release/

Installs now should be performed manually. Note that nearly 30% of websites run the Word Press CMS:
https://w3techs.com/technologies/history_overview/content_management

polonus (volunteer website security analyst and website error-hunter)

Open tab phishing patched by DuckDuckGo, but Google will not patch it (because it supports Google’s core business):
Read: https://sites.google.com/site/bughunteruniversity/nonvuln/phishing-with-window-opener

On that vulnerability: https://www.chaoswebs.net/blog/exploiting-window.opener.html (source credits: Kevin Forman)

polonus (volunteer website security analyst and website error-hunter)

Black Ruby Ransomware

https://www.bleepingcomputer.com/news/security/black-ruby-ransomware-skips-victims-in-iran-and-adds-a-miner-for-good-measure/

Be warned, new TCP DOS vector disclosed, called TCP Starvation:
https://github.com/Eplox/TCP-Starvation (source: 9bd6ea1)

polonus

This critical flaw of TCP has been known since 2008, and more secure protocols, like RDP, were not much used

Olympic Destroyer, malware that was directed at the critical systems of the Olypic Wintergames,
now being analyzed:

http://blog.talosintelligence.com/2018/02/olympic-destroyer.html

polonus

Rapid Ransomware Being Spread Using Fake IRS Malspam
https://www.bleepingcomputer.com/news/security/rapid-ransomware-being-spread-using-fake-irs-malspam/

JavaScript Cryptomining Scripts Discovered in 19 Google Play Apps
https://www.bleepingcomputer.com/news/security/javascript-cryptomining-scripts-discovered-in-19-google-play-apps/

Telegram 0-Day Used to Spread Monero and Zcash Mining Malware
https://www.bleepingcomputer.com/news/security/telegram-0-day-used-to-spread-monero-and-zcash-mining-malware/

A mitigation with policy editor of an attack recently directed at Telegram users:
https://www.ipa.go.jp/security/english/virus/press/201110/E_PR201110.html

About the attack: https://securelist.com/zero-day-vulnerability-in-telegram/83800/

polonus

Bingo, Amigo! Jackpotting: ATM malware from Latin America to the World
https://securelist.com/atm-malware-from-latin-america-to-the-world/83836/

February Patch Tuesday Is a Bouquet of Fixes for Privilege Escalation Vulnerabilities
https://blog.trendmicro.com/trendlabs-security-intelligence/february-patch-tuesday-bouquet-fixes-privilege-escalation-vulnerabilities/