Story image

Malwarebytes CEO 'heartbroken' after botched program updates cause RAM spikes

01 Feb 2018

Malwarebytes has urged its customers to update their software after a botched update last Saturday caused massive memory spikes and computer crashes.

The update affects both enterprise and consumer versions of popular Malwarebytes solutions including:

Malwarebytes for Windows Premium; Malwarebytes for Windows Premium Trial; Malwarebytes Endpoint Security (MBES); and Malwarebytes Endpoint Protection (Cloud Console).

According to the team, the following products are not affected: Malwarebytes for Windows in Free Mode; Malwarebytes for Mac; Malwarebytes for Android; ADWCleaner; Malwarebytes Incident Response standalone (MBBR); and Malwarebytes Incident Response (Cloud Console) for Windows or Mac.

So what happened? On the weekend of January 27 the company released protection update v1.03798 for all Windows machines – but it came with an unexpected side effect.

Some customers started reporting internet block notifications and spikes in RAM as high as 12,930MB according to an official forum.

An official root cause analysis from Malwarebytes’ Engineering and Research team says that the root cause was a product improvement that backfired.

“A review of recent updates found that we had included in the Web Filtering Block List a detection with a syntactical error that resulted in the Web Filtering System to block a large range of IPs,” the analysis says.

“This broken detection was present in the update version v1.0.3798 thru v1.0.3802. (v2018.01.27.03 - v2018.01.27.11 for MBES customers). It was removed in v1.0.3803 (v2018.01.27.12 for MBES customers).”

The analysis explains further:

“There are detection syntax controls in place to prevent such events as the one experienced in this incident. Recently we have been improving our products so that we can show the reason for a block, i.e. the detection "category" for the web protection blocks.”

“In order to support this new feature, we added enhanced detection syntaxes to include the block category in the definitions. The unfortunate oversight was that one of the syntax controls was not implemented in the new detection syntax, which cause the malformed detection to be pushed into production.”

As soon as reports of the errors came in, the company says it turned off updates to all customers to limit the damage.

“The root cause of the issue was a malformed protection update that the client couldn't process correctly. We have pushed upwards of 20,000 of these protection updates routinely. We test every single one before it goes out. We pride ourselves on the safety and accuracy of our detection engines. To say I am heartbroken is an understatement,” comments Malwarebytes CEO Marcin Kleczynski in a forum post.

Malwarebytes says it will take a number of corrective actions including wider and stronger syntax checking of Web Filtering heuristics; faster rollback for problematic detections; and adding more machines to its testing cluster.

Malwarebytes says that any affected customers should install the latest protection update that should fix the issue.

“If the update does not resolve the issue automatically for you, please shut down web protection, check for protection updates, and restart your computer,” Kleczynski says.

 “We are working hard to not only triage your issues and get your computer or business back up and running but to also rebuild your trust. We are going to overhaul how we publish these protection updates so that this never happens again,” Kleczynski concludes.

Microsoft urges organisations to tackle data blindspots
Despite significant focus placed on CX transformation, over a third of Australian organisations claimed that more than one in five of their projects failed.
Raising the stakes: McAfee’s predictions for cybersecurity
Security teams and solutions will have to contend with synergistic threats, increasingly backed by artificial intelligence to avoid detection.
Renesas develops 28nm MCU with virtualisation-assisted functions
The MCU features four 600 megahertz CPUs with a lock-step mechanism and a large 16 MB flash memory capacity.
DOCOMO ranked world's top mobile operator in 5G SEP applications
NTT DOCOMO has been ranked the world's leading mobile operator in terms of applications for candidate standard-essential patents.
Exclusive: Ping Identity on security risk mitigation
“Effective security controls are measured and defined by the direct mitigation of inherent and residual risk.”
CylancePROTECT now available on AWS Marketplace
Customers now have access to CylancePROTECT for AI-driven protection across all Windows, Mac, and Linux (including Amazon Linux) instances.
Gartner’s top 10 data and analytics trends for 2019
Data is the fuel for the modern world, and analytics the engine. Gartner has compiled the top 10 trends to watch this year.
How CIOs can work with colleagues to drive new competitive advantages
"If recent history has taught us anything, it’s that the role of the CIO is always changing, and that it won’t stop changing anytime soon."