A Week in Security (Jan 03 – Jan 09)

| January 11, 2016
Detail of a calendar page with dates

Last week, we sent our readers a survey that they may want to check out and answer. We created it in the hopes of improving our PUP Friday posts.

We also spotlighted on a defaced UK site, questioned the veracity of the data behind the Mac OS X being “the most vulnerable of 2015”, and delved into another phishing campaign on Facebook, claiming disabled user accounts.

Senior security researcher Jérôme Segura revealed a clever clickjacking campaign banking on the European Cookie Law, a legislation requiring websites to get consent from visitors to store and/or retrieve data from their systems. The said campaign also used a hidden advert underneath a supposed ad they purport to display.

In another post, Segura focused on the abuse of pop-under ads. Unlucky visitors were directed from malicious adverts to a domain serving the Magnitude and Flash exploit kits. Once flaws are found on visitors’ systems, these are then infected with a CryptoWall ransomware.

Notable news stories and security related happenings:

Safe surfing, everyone!

The Malwarebytes Labs Team

About the author