Quantcast
Channel: McAfee Labs, Author at McAfee Blog
Browsing all 203 articles
Browse latest View live

2014 Threats Predictions: HTML5, Exploit Kits, ‘Free’ Software Require Web...

This post is one in a series of articles that expand on the recently released McAfee Labs 2014 Threats Predictions. In this and related posts, McAfee Labs researchers offer their views of new and...

View Article


2014 Threats Predictions: Malware to Take Advantage of Hotspots, Gaming Consoles

This post is the last in a series of articles that expand on the recently released McAfee Labs 2014 Threats Predictions. In this and related posts, McAfee Labs researchers offer their views of new and...

View Article


Image may be NSFW.
Clik here to view.

January 2014 #SecChat Wrap-up — Threat Predictions

Threats seem to be top of mind for the masses of late—with three large-scale attacks on major brands already this year, potentially compromising the financial data and identity of millions. And things...

View Article

It’s ‘Game Over’ for Zeus and CryptoLocker

Under Operation Tovar, global law enforcement—in conjunction with the private sector and McAfee—has launched an action to dismantle the Gameover Zeus and CryptoLocker infrastructure. Disrupting the...

View Article

Image may be NSFW.
Clik here to view.

Detection Effectiveness: the Beat Goes On

In May, we wrote about the breach discovery gap, which is the time it takes IT security practitioners to discover a data breach after their systems have been compromised in a cyberattack. We made this...

View Article


What you need to know about the Bash Bug aka Shellshock

European security researcher Stéphane Chazelashas discovered a critical vulnerability in the command-line shell known as Bash, or GNU Bourne-again Shell, the most widely deployed shell for Unix-based...

View Article

‘Cookiejacking’ Poses Minimal Danger if You Keep Good Habits

“Cookiejacking,” anyone? In the last few days, a new vulnerability in Microsoft Internet Explorer has made its way through the media. Disclosed at the Hack on the Box conference by the independent...

View Article

Image may be NSFW.
Clik here to view.

Guide To Online Banking Safety for Carefree, Confident, and Conservative...

A recent poll revealed that 54% of U.S. consumers said the theft of their personal or financial information worried them more than losing their job or not having healthcare for their family members.[1]...

View Article


Image may be NSFW.
Clik here to view.

Steve Jobs’ Impact on One Fan

Where does one start? I’m not sure if I would consider this a research blog post. In the sea of comments and chatter today, it just feels right to say something. It feels right to “Think Different.”...

View Article


Image may be NSFW.
Clik here to view.

An Update on DNSChanger and Rogue DNS Servers

In late 2011, the FBI released documents and data focusing on “Operation Ghost Click.” This malicious operation, leveraging a variety of DNSChanger-type malware, was defined by the FBI as an...

View Article

Image may be NSFW.
Clik here to view.

RDP+RCE=Bad News (MS12-020)

See March 15 and 16 updates at the end of this blog. —————————————————-   The March Security Bulletin release from Microsoft was relatively light in volume. Out of the six bulletins released, only one...

View Article

Image may be NSFW.
Clik here to view.

Latest Yahoo Data Breach Restates Need for Basic Security

News broke today of a large data breach against Yahoo Voices, resulting in more than 400,000 username/password combinations being posted in clear text. The compromise involved a basic SQL-injection...

View Article

Image may be NSFW.
Clik here to view.

Tool Talk: Cracking the Code on XtremeRAT

Late last week, reports began to surface that the Israeli police (along with other regional law enforcement) were targeted by a malware attack.  The entry vector was described as a phishing campaign...

View Article


Image may be NSFW.
Clik here to view.

Anonymous Releases ‘Warhead’ via #OpLastResort

This post was updated on January 27. See end of file for update.  There has been a great explosion of chatter in the last day around Anonymous’ “Operation Last Resort” (a.k.a. #OpLastResort). The...

View Article

Image may be NSFW.
Clik here to view.

Digging Into the Sandbox-Escape Technique of the Recent PDF Exploit

As promised in our previous blog entry for the recent Adobe Reader PDF zero-day attack, we now offer more technical details on this Reader “sandbox-escape” plan. In order to help readers understand...

View Article


Image may be NSFW.
Clik here to view.

NCCDC 2013 – Red Team Recap

          This past April (4/19 to 4/21) I had the great pleasure and experience of joining the Red Team at 9th NCCDC competition.   It was actually my 2nd year on the Red Team and 4th year to attend...

View Article

Operation Troy: OpenIOC Release

  In conjunction with our investigation into Operation Troy, we will be releasing IOC data in the open and highly flexible OpenIOC Framework format. The McAfee Operation Troy IOC can be downloaded...

View Article


Product Coverage and Mitigation for CVE-2013-3893

Microsoft Security Advisory (2887505) On September 17th, 2013, Microsoft published Security Advisory 2887505, which coverers a remote code execution vulnerability in all supported versions of Microsoft...

View Article

Updates and Mitigation to Microsoft Office Zero-Day Threat (CVE-2013-3906)

On November 5, Microsoft posted Security Advisory 2896666. This vulnerability, discovered by Haifei Li of McAfee Labs, affects multiple versions of Microsoft Office, Windows, and Lync. Successful...

View Article

Product Coverage and Mitigation for CVE-2013-5065

On November 27, Microsoft published Security Advisory 2914486, which covers an elevation of privilege vulnerability in certain versions of Windows XP and Windows Server 2003. The flaw lies in the...

View Article
Browsing all 203 articles
Browse latest View live


Latest Images