Malwarebytes Experiences Major Security Flaws
Google’s research team recently uncovered a huge security hole in a free security software program that you have probably heard of, Malwarebytes. Reasearcher, Travis Ormandy took note of the program getting its virus definition updates over an unencrypted Internet connection. So what does this mean? Essentially, hackers can trick the program into ignoring certain malicious files, or could secretly place their code into the program.
Malwarebytes is currently addressing the issue; however they did report it will take three to four weeks to fully resolve the problem. Until the issue is fully resolved, it is encourage users implement the “self-protection” setting. With the news of these security flaws, Malwarebytes is creating an internal “bug bounty” program. This program is designed to help identify security issues, in hopes to address any flaws in a more timely manner.
Sources:
http://www.komando.com/happening-now/346105/this-one-security-program-has-serious-unfixed-bugs
https://blog.malwarebytes.org/news/2016/02/malwarebytes-anti-malware-vulnerability-disclosure/