Story image

Malwarebytes CEO 'heartbroken' after botched program updates cause RAM spikes

01 Feb 2018

Malwarebytes has urged its customers to update their software after a botched update last Saturday caused massive memory spikes and computer crashes.

The update affects both enterprise and consumer versions of popular Malwarebytes solutions including:

Malwarebytes for Windows Premium; Malwarebytes for Windows Premium Trial; Malwarebytes Endpoint Security (MBES); and Malwarebytes Endpoint Protection (Cloud Console).

According to the team, the following products are not affected: Malwarebytes for Windows in Free Mode; Malwarebytes for Mac; Malwarebytes for Android; ADWCleaner; Malwarebytes Incident Response standalone (MBBR); and Malwarebytes Incident Response (Cloud Console) for Windows or Mac.

So what happened? On the weekend of January 27 the company released protection update v1.03798 for all Windows machines – but it came with an unexpected side effect.

Some customers started reporting internet block notifications and spikes in RAM as high as 12,930MB according to an official forum.

An official root cause analysis from Malwarebytes’ Engineering and Research team says that the root cause was a product improvement that backfired.

“A review of recent updates found that we had included in the Web Filtering Block List a detection with a syntactical error that resulted in the Web Filtering System to block a large range of IPs,” the analysis says.

“This broken detection was present in the update version v1.0.3798 thru v1.0.3802. (v2018.01.27.03 - v2018.01.27.11 for MBES customers). It was removed in v1.0.3803 (v2018.01.27.12 for MBES customers).”

The analysis explains further:

“There are detection syntax controls in place to prevent such events as the one experienced in this incident. Recently we have been improving our products so that we can show the reason for a block, i.e. the detection "category" for the web protection blocks.”

“In order to support this new feature, we added enhanced detection syntaxes to include the block category in the definitions. The unfortunate oversight was that one of the syntax controls was not implemented in the new detection syntax, which cause the malformed detection to be pushed into production.”

As soon as reports of the errors came in, the company says it turned off updates to all customers to limit the damage.

“The root cause of the issue was a malformed protection update that the client couldn't process correctly. We have pushed upwards of 20,000 of these protection updates routinely. We test every single one before it goes out. We pride ourselves on the safety and accuracy of our detection engines. To say I am heartbroken is an understatement,” comments Malwarebytes CEO Marcin Kleczynski in a forum post.

Malwarebytes says it will take a number of corrective actions including wider and stronger syntax checking of Web Filtering heuristics; faster rollback for problematic detections; and adding more machines to its testing cluster.

Malwarebytes says that any affected customers should install the latest protection update that should fix the issue.

“If the update does not resolve the issue automatically for you, please shut down web protection, check for protection updates, and restart your computer,” Kleczynski says.

 “We are working hard to not only triage your issues and get your computer or business back up and running but to also rebuild your trust. We are going to overhaul how we publish these protection updates so that this never happens again,” Kleczynski concludes.

Kiwis know security is important, but they're not doing much about it
Only 49% of respondents use antivirus software and even fewer – just 19% -  change their passwords regularly.
Avi Networks: Using visibility to build trust
Visibility, also referred to as observability, is a core tenet of modern application architectures for basic operation, not just for security.
Privacy: The real cost of “free” mobile apps
Sales of location targeted advertising, based on location data provided by apps, is set to reach $30 billion by 2020.
Myth-busting assumptions about identity governance - SailPoint
The identity governance space has evolved and matured over the past 10 years, changing with the world around it.
Forrester names Crowdstrike leader in incident response
The report provides an in-depth evaluation of the top 15 IR service providers across 11 criteria.
Slack doubles down on enterprise key management
EKM adds an extra layer of protection so customers can share conversations, files, and data while still meeting their own risk mitigation requirements.
Security professionals want to return fire – Venafi
Seventy-two percent of professionals surveyed believe nation-states have the right to ‘hack back’ cybercriminals.
Alcatraz AI to replace corporate badges with AI security
The Palo Alto-based startup supposedly leverages facial recognition, 3D sensing, and machine learning to enable secure access control.