• Articles
    • Editorial Articles
    • Research Articles
    • WatchGuard Articles
  • The 443 Podcast
  • Threat Landscape
  • About
    • About Us
    • Contact Us
    • Contribute to Secplicity

Secplicity - Security Simplified

Powered by WatchGuard Technologies

Shady Chrome Font – Daily Security Byte

February 22, 2017 By Corey Nachreiner

Cyber criminals are always trying to find new ways to lure users into doing dumb things. For instance, you’ve probably heard about the old trick where hackers rig malicious web sites to deliver pop-ups telling you to download a video codec in order to see a video. Of course, in most cases the fake codec is malware that the attacker hopes to socially engineer you into installing yourself.

Hopefully, you know enough not to fall for the fake video codec lure, but now attackers have a new trick up their sleeves. According to a Neosmart blog post, hackers are now using fake font pop-ups to deliver malware. However, they’ve upped their game by modifying the web page so that it really looks like you might need a font update. Watch today’s video to learn more about this new trick, and what you can do to avoid it.

Episode Runtime: 2:54

Direct YouTube Link: https://www.youtube.com/watch?v=-wTDdsgAxOk

EPISODE REFERENCES:

  • Researcher’s post on Chrome font hack – Neosmart
  • Beware Chrome asking to download missing fonts – The Next Web

— Corey Nachreiner, CISSP (@SecAdept)

Share This:

Related

Filed Under: Security Bytes Tagged With: Hacking

Comments

  1. Shalin Kowalke says

    February 23, 2017 at 1:13 pm

    Visitors to our site have experienced this very infrequently. Our website developer says it’s not the site, that it’s the users computer that are infected. I’ve scanned our site using online tools and they say it’s clean. How do I prove to the developer that it’s the site?

    Reply
  2. John says

    March 1, 2017 at 3:56 pm

    Wireshark?

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The 443 Podcast

A weekly podcast featuring the leading white-hat hackers and security researchers. Listen Now
the 443 podcast

Threat Landscape

Filter and view Firebox Feed data by type of attack, region, country, and date range. View Now
threat landscape

Top Posts

  • US National Cybersecurity Strategy
  • Cybersecurity’s Toll on Mental Health
  • Cybersecurity News: Free Cybersecurity Training, TrickBot Group Exposed, Major GoDaddy Breach, and Russia to Legalize cybercrime?!
  • Here Come The Regulations

Email Newsletter

Sign up to get the latest security news and threat analysis delivered straight to your inbox

By signing up you agree to our Privacy Policy.


The views and opinions expressed on this website are those of the authors and do not necessarily reflect the policy or position of WatchGuard Technologies.

Stay in Touch

Recent Posts

  • Here Come The Regulations
  • US National Cybersecurity Strategy
  • Cybersecurity News: Free Cybersecurity Training, TrickBot Group Exposed, Major GoDaddy Breach, and Russia to Legalize cybercrime?!
  • Cybersecurity’s Toll on Mental Health
  • Successfully Prosecuting a Russian Hacker
View All

Search

Archives

Copyright © 2023 WatchGuard Technologies · Cookie Policy · Privacy Policy · Terms of Use