• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

'FakeUpdates' Campaign Leverages Multiple Website Platforms

rgMekanic

[H]ard|News
2FA
Joined
May 13, 2013
Messages
6,942
Malwarebytes Labs has written a very in depth article on their blog about a malware campaign that they are calling "FakeUpdates." The campaign uses vulnerabilities in multiple website Content Management Systems to inject malicious code that prompt users that a program on their computer is out of date, and starts a download of a malicious file.

Even more nefarious is the fact that these attacks use legitimate file hosting services to spread the malicious files, such as GitHub and DropBox. The article goes deep into the details on how the script is injected on various platforms, but a simple crawler made by Malwarebytes found several hundred compromised WordPress and Joomla websites. Thanks to cageymaru for the story.

This campaign relies on a delivery mechanism that leverages social engineering and abuses a legitimate file hosting service. The ‘bait’ file consists of a script rather than a malicious executable, giving the attackers the flexibility to develop interesting obfuscation and fingerprinting techniques.
 
  • Like
Reactions: WhoMe
like this
What? You didn't update? You're not secure!

What? You did the update? You're not secure!

:goto What?
 
I always have firefox autoupdate turned off. So I have to check for updates. This way I don't get tricked.
Also I think noscript catches these as well.
 
It always amazes me how many of these things push past pop-up blockers on game trainer sites, pRon, pirates, or hell even coupon code sites. I swear their f'ing everywhere over the last 5+ years. If you get a cookie somewhere they follow worse than any case of herpes I've heard about.
 
Back
Top