Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Malvertising on Spin Cycle: What the Industry Should Know
Articles

Malvertising on Spin Cycle: What the Industry Should Know

Kowsik GuruswamyBy Kowsik GuruswamySeptember 4, 2015Updated:April 30, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Malvertising attacks are surging beyond levels the industry has ever seen before. A recent study today found that instances of malware served by ad networks more than tripled between June 2014 and February 2015. Just this week, a malvertising attack impacted millions of users of the Plenty of Fish (pof.com) online dating site – a seemingly trusted site, but deemed vulnerable by an exploit kits. According to Malwarebytes, one of the ad networks that used pof.com was exploited as a key link in the attack chain that ultimately infected visitors’ devices with the Tinba banking Trojan.

Similarly, a recent breach of Yahoo’s networks highlighted the scale and affect of malvertising. Yahoo’s properties, which see nearly 7 billion visits per month, were redirecting users through ads to sites that have been compromised and set up to serve malware.

The attacks exposed millions, if not billions of users, and their private data. Yet, there wasn’t anything especially interesting or sophisticated about the attacks, nor was there anything novel in the recommendations being made in their wake – patch your systems, keep your antivirus (AV) updated, etc.  Of course, if everyone actually did keep their systems patched and their AV updated we might see far fewer of these types of attacks because they wouldn’t yield much for attackers. But that’s clearly not the case, so the economics of such attacks still favor the bad guys. Even worse, keeping systems patched and AV updated don’t protect against zero-day attacks. Given the rate at which new zero-days are being introduced, it would seem that creating and using them is a very good business indeed.

There’s an often-used quote defining insanity as doing the same thing over and over again and expecting different results. The quote seems apt as a comment on the current approach to preventing malware attacks. We can’t find vulnerabilities, patch systems and identify new attacks faster than attackers. Businesses spent more than $70 billion on cyber security tools in 2014, and collectively lost nearly $400 billion as a result of cyber crime.

And yet we continue to try, as if there’s nothing else we can do – except, perhaps, disconnect from the Internet.

Even the most trusted websites could be compromised, delivering zero-day malware to unsuspecting users. With breakthroughs in virtualization, cloud and remote rendering technologies, there is a way to eliminate the threat of Web-borne malware attacks. Isolation security operates on the simple premise that attacks are undetectable, and therefore no content from the Web should ever reach a user’s device. It doesn’t rely on the ability to detect attacks – zero-day or otherwise, and it doesn’t require that users’ operating systems and browsers remain patched and up-to-date.

Any attempt to categorize a website as good or bad, with respect to malware or malvertising, is a false notion. We are fooling ourselves into thinking that this is even possible. With billions of dollars being spent on enterprise security, we are nowhere closer to securing our users or making the Internet a safe place to be. As an industry, we need to step back and think about definitive ways to eliminate attacks, not just detect or react to them after the damage is already done.[su_box title=”Abou Kowsik Guruswamy” style=”noise” box_color=”#336588″]Kowsik Guruswamy CTO menlosecurityKowsik Guruswamy is CTO of Menlo Security. Previously, he was co-­founder and CTO at Mu Dynamics, which pioneered a new way to analyze networked products for security vulnerabilities. Prior to Mu, he was a distinguished engineer at Juniper Networks. Kowsik joined Juniper via the NetScreen/OneSecure acquisition where he designed and implemented the industry’s first IPS. He has more than 15+ years of experience in diverse technologies like security, cloud, data visualization, and computer graphics. Kowsik has 18 issued patents and holds an MSCS from University of Louisiana.[/su_box]

Kowsik Guruswamy

Chief Technology Officer

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

    May 20, 20265 Mins Read

    Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

    May 6, 20265 Mins Read

    Why OSINT deserves the same status as other intelligence disciplines

    March 17, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}