Ransomware for macOS shows the importance of using independently tested Mac antivirus software. EvilQuest / ThiefQuest ransomware is now blocked by all the Mac AV products certified by AV-Comparatives in 2020: Avast, AVG, Avira, Bitdefender, CrowdStrike, FireEye, Kaspersky, and Trend Micro.
Spotlight on security: Why independent testing of anti-virus software is important
If you’ve ever considered doing your own tests of antivirus programs, you might be surprised to find that it’s much, much more difficult than you think. Here’s why:
Spotlight on security: The Curse of the False Positive
By David Harley
When is a false positive (FP) really a false positive? How much care should security vendors take to avoid or at worst fix them: do they really matter at all?
AV-Comparatives found a flaw in a macOS security feature that allowed unidentified apps to run (bypassing Gatekeeper checks)
In spring of 2019, AV-Comparatives ran a team-building event, in which their research team was asked to find security bugs on macOS. This was actually planned as a nice event with co-operative activities, but it happened that they found a security flaw on macOS Mojave 10.14.4 and earlier versions. The issue allows Gatekeeper to be bypassed, and unsigned apps from outside the App Store to be executed. The method used does not require any specialist knowledge or programming ability. Anyone who can create, copy and rename folders in Finder could do it, with a few very simple instructions.
Spotlight on security: Antivirus programs and System Performance
A common complaint about antivirus software is that it reduces system performance, making everyday use of the computer frustratingly slow. For this reason, AV-Comparatives includes a Performance Test in both its Consumer and Enterprise Main-Test Series. This lets users compare the effect that the tested programs have on a computer’s operating speed.
Spotlight on security: the inconvenient truth about CEO-impersonation fraud
Reported incidents of CEO-fraud or business email compromise (BEC) scams are so bizarre that most people think they are urban myths, told by security specialists to spice up their business and catch the attention of board-level executives. Sadly, these “April Fools’ Day” story lines have the opposite effect on C-level management. Let’s take a look at a recent € 19.2 million CEO-fraud case and put BEC-scams in a cyber-crime perspective to see whether you still think “it won’t happen to me”.
Spotlight on Security: why the claims of Google Play Protect are misleading
In October, Google announced two contract changes for European Android device vendors. One concerned a minimum security-patch requirement, and the other involved charging a fee for Google services (e.g. Google Play Store). These announcements indicate that many Android smartphones suffer from significant security weaknesses. Let us explain (and prove) why Google’s claims about the effectiveness of their Play Protect service are misleading, to say the least.
Spotlight on security: Politics and cyber security, a troubled relationship
The relationships between various countries in the world are worsening, not only with regard to economic and political issues, but also in the field of cybersecurity. The recent bans on Chinese (such as Huawei) and Russian security products (such as Kaspersky Lab) are examples of the troubled relations between politics and cyber security.
Malware in the media – why healthcare systems are under attack
Also this summer incidents were reported in general news media involving cyber- and ransomware-attacks on healthcare organizations. Cyber-attacks on healthcare organizations are not uncommon. According to CSO-online “the healthcare experiences twice the number of cyber-attacks as other Industries”. Why are health care systems so often attacked?
Spotlight on security: The problem with false alarms
False Positives (FPs, also known as False Alarms) are harmless and legitimate programs that are incorrectly identified as malicious by an antivirus program. A false positive can have very serious consequences. In some cases, it will not be possible to run a legitimate program if it is blocked by the security software.