Detect DLL Hijacks on Windows

Thursday, March 26th, 2015

DLL hijacking is an attack that makes applications load malicious dynamic link libraries instead of the intended -- clean and legit -- library on a Windows system. Programs that don't specify paths to libraries are vulnerable to DLL hijacking as Windows uses a priority based search order in this case to ...

Serious bug in fully patched Internet Explorer puts user credentials at risk

Wednesday, February 4th, 2015

A vulnerability in fully patched versions of Internet Explorer allows attackers to steal login credentials and inject malicious content into users' browsing sessions. Microsoft officials said they're working on a fix for the bug, which works successfully on IE 11 running on both Windows 7 and 8.1. The vulnerability is known ...

New version of Autoruns integrates with VirusTotal

Sunday, February 1st, 2015

The new version of Microsoft's Autoruns (version 13 - released last week) integrates the VirusTotal API for quick analysis and verification of unknown and questionable processes.  After running the program, just right-click on any entry and select Check VirusTotal: You will need to accept VirusTotal's Terms of Service by clicking Yes: Once ...

New “Skeleton Key” malware allows bypassing of passwords

Tuesday, January 13th, 2015

Remember when we discussed how passwords were dead? If you needed more proof that this is true, the bad guys have you covered with a new piece of malware that turned up in the wild. SecureWorks, the security arm of Dell, has discovered the new piece of malware dubbed "Skeleton Key." ...

Here’s What Happens When You Install the Top 10 Download.com Apps

Sunday, January 11th, 2015

We installed the top 10 apps from Download.com, and you’ll never believe what happened! Well… I guess maybe you might have a good guess. Awful things. Awful things are what happens. Join us for the fun! We’ve been railing against freeware download recommendations for years, and recently we taught you how ...