Malwarebytes - Experts & Thought Leaders

Latest Malwarebytes news & announcements

Malwarebytes Enhances Privacy With AzireVPN Audit

Malwarebytes, a global pioneer in online protection, announced the completion of its first independent third-party security audit of the AzireVPN infrastructure. Malwarebytes acquired AzireVPN in 2024 to bring its bespoke privacy features to its VPN solution and now leverages the AzireVPN infrastructure. The comprehensive assessment, conducted by renowned security audit provider X41 D-Sec, validates the integrity of Malwarebytes infrastructure and its strict adherence to its no-logs policy. In an industry where trust is often requested but rarely verified, Malwarebytes made the strategic decision to open its entire source code, server configurations, and internal processes to external scrutiny. Highest privacy and security standards “Trust shouldn't be a leap of faith; it should be an informed choice based on evidence,” said Marcin Kleczynski, Founder and CEO, Malwarebytes. “By completing this audit, we are moving beyond promises and providing our users with objective proof that their data is handled with the highest privacy and security standards. If a VPN provider can’t offer that level of transparency through an independent audit, it’s worth questioning whether it should be trusted at all. We hope this helps people make better decisions about who they trust with their internet traffic and activity.” Identifiable user metadata The audit was conducted by X41 D-Sec over a period of two months and employed a white-box penetration testing methodology to review the software and hardware Malwarebytes developed and deployed to operate its VPN service. This provided the auditors with full access to: Core applications: Source code for Windows/macOS/Android/iOS apps. Server infrastructure: A deep dive into the configuration of Malwarebytes’s global VPN node network. Privacy architecture: Verification of the "no-logs" systems to ensure no identifiable user metadata is stored or accessible. Key Findings Zero-logs verification: Auditors confirmed that the technical architecture is consistent with Malwarebytes’s privacy policy, finding no evidence of logging user IP addresses, browsing history, or DNS queries. X41 noted, “During our assessment, we did not observe evidence of user activity logging, and access to systems is tightly controlled, with no unnecessary remote, local, or SSH access exposed.” Good security level: The final report concluded that the Malwarebytes “systems appear to be on a good security level compared to systems of similar size and complexity.” Swift response to findings: Malwarebytes worked with the X41 team to quickly inspect and address findings. X41 shared, “While vulnerabilities were identified; most have already been addressed, including one critical issue, with remaining items in the process of being resolved." “This thorough security audit provides the level of transparency any VPN provider and privacy company should aim for,” said Jérôme Boursier, Principal Research Engineer and privacy advocate at Malwarebytes. “Combining a software audit with hardware penetration testing is invaluable. It gives our users a clear understanding of how we operate and how we stand apart from competitors. These results reinforce our commitment to security and will guide us in setting a higher standard for our users.” Malwarebytes privacy VPN Malwarebytes Privacy VPN is an ultra-fast, ultra-private VPN service designed to protect user privacy and provide secure, unrestricted internet access. With servers worldwide, Privacy VPN lets users access the internet safely and without geographic limits, just as if they were using it in another country. Key features include: RAM-only, diskless servers Independently verified no-logs policy and Blind Operator Mode Full infrastructure control Ongoing transparency reports and Warrant Canary New server locations including Jakarta, Indonesia, and Johannesburg, South Africa Part of holistic dashboard across desktop and mobile

Zimperium Announces Chris White As CRO And Anupam Bandyopadhyay As SVP Of Engineering

Zimperium, the only mobile-first security platform for mobile devices and mobile apps, welcomes Chris White as Chief Revenue Officer and Anupam Bandyopadhyay as Senior Vice President of Engineering. These new executives will accelerate global revenue growth, drive customer acquisition and retention, and advance platform innovation as part of the company’s mission to help organizations protect mobile endpoints and apps from cyber threats. Chris White Chris White joins Zimperium from Druva, a pioneer in cloud data protection, where he was Chief Revenue Officer and serves as an Advisor. Chris is a proven global sales pioneer with a demonstrated history of working in the SaaS, Security, and Infrastructure space. He brings over 30 years of experience driving growth and pioneering strategic sales teams at companies such as A10 Networks, Proofpoint, Hitachi Data Systems, NetApp, Symantec, and ADP. Data protection and cybersecurity solutions “The market for data protection and cybersecurity solutions has evolved considerably over the past year. I believe Zimperium is poised for market dominance and I’m excited to help lead the next chapter of growth for the company,” said Chris White. He adds, “I’ve spent decades pioneering transformational IT and security companies to exceed their growth and revenue goals, and I look forward to helping drive Zimperium forward while exceeding the expectations and needs of our customers and employees.”  Anupam Bandyopadhyay Anupam Bandyopadhyay will lead the engineering team to deliver continued innovation Anupam Bandyopadhyay will lead the engineering team to deliver continued innovation to meet the growing demand for mobile security. Anupam brings with him nearly three decades of engineering expertise building world-class products and services, using various Artificial Intelligence (AI) and Machine Learning (ML) models and cutting-edge technologies. His experience spans notable companies such as JPMorgan Chase, VIPRE Security Group, and IBM. He joins Zimperium from malware protection company, Malwarebytes, where he led a global team of developers that built cybersecurity solutions augmented by ML/DL techniques to protect 40+ million devices globally. Mobile security strategies “As a technologist and visionary pioneer, I aspire to be at the forefront of technological innovation,” said Anupam Bandyopadhyay. He adds, “Zimperium’s mobile security platform truly elevates customers’ mobile security strategies to new heights and it’s an honor to be able to pioneer advanced security solutions in the mobile technology arena.” Mobile-first security platform “Chris and Anupam have the experience needed to scale our sales organization and build the game-changing products required to dominate the mobile security market,” said Shridhar Mittal, Chief Executive Officer at Zimperium. He adds, “As we look to strengthen our already robust mobile-first security platform and accelerate revenue growth, both Chris and Anupam will play critical roles in the next stage of our growth and will be a driving force to ensure Zimperium remains at the forefront in protecting mobile endpoints and applications around the world.”

Malwarebytes Announces EDR Extra Strength, Setting The New Standard For Endpoint Protection

Malwarebytes, a pioneer in real-time cyber protection, is revolutionizing endpoint protection for IT-constrained businesses with EDR Extra Strength, a new solution that combines the company's deep historical threat intelligence knowledge with endpoint detection and response (EDR) and AI-driven tools for attack surface reduction and accelerated response. Even with standard endpoint security deployments, successful attacks are rampant—83% of organizations have had more than one data breach and 71% of organizations were impacted by ransomware last year. EDR Extra Strength goes beyond traditional detection and response solutions by combining Malwarebytes’ extensive remediation expertise with simple steps anyone can follow to remediate a threat. Eliminating difficult threats Malwarebytes thrives on tackling the most difficult security challenges. Born out of remediation, the company is laser-focused on finding and eliminating the most difficult threats – including the ones that others miss – to best protect customers.  EDR Extra Strength is available as part of Malwarebytes for Business Advanced. For one price, customers receive: Vulnerability Assessment to identify known vulnerabilities Patch Management to automate the remediation of top-level vulnerabilities Endpoint Detection and Response (including Endpoint Protection) Alert prioritization which filters, prioritizes, and categorizes alerts Step-by-step guidance for addressing and resolving critical issues Revolutionizing the EDR field for IT-constrained businesses Good enough has proven not enough to protect organizations from today’s threat landscape" “Good enough has proven not enough to protect organizations from today’s threat landscape which has become so complex that the majority of alerts generated by traditional EDR solutions are ignored,” said Marcin Kleczynski, Co-Founder and CEO, Malwarebytes. He adds, “We’re revolutionizing the EDR field for IT-constrained businesses by combining our remediation roots that focus on all of today’s sophisticated threats – fileless attacks, zero days and ransomware – with AI-driven tools to reduce an organization’s attack surface while guiding and accelerating response.” Benefits Benefits include: Attack Surface Reduction: Neutralises vulnerability risks by identifying weaknesses and deploying the latest patches to harden applications and operating systems. AI-powered Prevention: Uses several AI-powered engines to immediately stop threats at every stage of the attack life cycle. Alert Prioritization and Streamlined Guidance: Uses threat intelligence to enrich data and identify critical alerts that require immediate attention. Notifies customers with guidance for easy remediation. One Agent and One Console: Easy to deploy in minutes for fast protection or to add additional security modules or services, all managed via a single pane of glass. Auto-remediation: Malwarebytes’ proprietary Linking Engine technology detects and removes dynamic and related artifacts, changes and process alterations to ensure thorough eradication of malware (and ransomware) to prevent reinfection. EDR investment While detection is critical, it is incomplete unless there is an equally reliable response mechanism" “In assessing EDR, organizations must avoid the trap of only focusing on detection,” said Michael Suby, Research Vice President, Security & Trust, IDC. He adds, “While detection is critical, it is incomplete unless there is an equally reliable response mechanism that interrupts active threats, fully unwinds the changes threat actors made, and plugs the gaps in security posture and cyber defenses to better deflect future attacks. This new and balanced detection-and-response offering from Malwarebytes will assist under-resourced organizations in realizing a positive return on their EDR investment.” G2 awarded Malwarebytes Real users on G2 awarded Malwarebytes EDR with badges for the Best Support, Easiest Doing Business With, Easiest Admin, Easiest to Use, Most Implementable, and Easiest Set Up.  As Justin N. shared, “The Nebula console is one of the most user-friendly interfaces we've come across. We can't recommend it enough.” David G. continued, “I love that Malwarebytes is easy to install, update, and manage.”