💣🐛
Malwarebytes Security Incident
Q4 2023
884 days ago
Resolved
Incident Overview
Situation Description
Online stores are experiencing a rise in credit card skimming and malvertising during the holiday shopping season, with Malwarebytes tracking significant increases in these threats.
Event Types
Malware / Destructive Attack
Software Vulnerability Exploitation
Industry Sector
EnergyGeographic Scope
National (Other)Impact Analysis
Event Types (2 identified)
Malware / Destructive Attack
Software Vulnerability Exploitation
Financial Impact
$0 USDRecords Affected
0Data Types Compromised
Operational / System Data
Credentials
Primary Impacts
Operational Disruption
Data Exposure
Key Decisions Made
Malwarebytes researchers tracked a 50% increase month-over-month in the US since September in newly registered domains attributed to Kritec.; Malwarebytes has tracked a 42% increase month-over-month in malvertising incidents in the US over the past two months.; Jrme Segura warns shoppers to safeguard their digital gifts and be aware of cybercriminals exploiting the holiday season.
Technical Analysis
Attack Method
Unpatched Vulnerability
Threat Actor Attribution
Kritec
Vulnerability / Tool
CVE-2023-28771
Zyxel firewalls
Additional Information
Quick Facts
- Company:
- Malwarebytes
- Date:
- Q4 2023
- Status:
- Resolved
- Decision Maker:
- Jrme Segura
- Position:
- senior director of threat research
- Published:
- 23/11/2023
Source Information
Original Query
what security architecture changes do companies make after ransomwareTimeline
Information Published
23/11/2023
Incident Occurred
Q4 2023 (884 days ago)
Status: Resolved
Estimated resolution based on age