Daily brief for 2018-09-14
Asia
- China-linked APT10 Hackers Update Attack Techniques
- Well-known Middle Eastern hacking group keeps updating its arsenal
- Iran-Linked OilRig APT group targets high-ranking office in a Middle Eastern nation
- Illegal Patch Allows Easier Access to India's Aadhaar Biometric Database
- Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents
- N. Korea Calls Sony, Wannacry Hack Charges Smear Campaign
- North Korean hacker officially charged for the WannaCry attacks
World
- Evaluating the Threatscape One Year After NotPetya Ransomware Attack
- Security news: More phishing, Canada pays ransom, SMBs are a target | Avast
- Well-known Middle Eastern hacking group keeps updating its arsenal
- Iran-Linked OilRig APT group targets high-ranking office in a Middle Eastern nation
- Military, Government Users Just as Bad About Password Hygiene as Civilians
- Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents
- N. Korea Calls Sony, Wannacry Hack Charges Smear Campaign
- Major US mobile carriers want to be your password
- Russian man accused of running Kelihos botnet pleads guilty
- North Korean hacker officially charged for the WannaCry attacks
- Law firm begins legal action for data theft in British Airways
- Malware-as-a-Service – New Black Rose Lucy Malware Targets Android Devices With a Special Logic for Xiaomi Phones
Attacks
- Jaxx Cryptocurrency wallet phishing campaign shut down
- Cryptojacking campaign targets add-ons for popular streaming app Kodi
- How to Protect Against Phishing Attacks that Follow Natural Disasters
- Survey: Nearly one-third of breached companies reported job losses after data breach
- Survey: Nearly one-third of breached companies reported job losses after data breach
- MEGA Chrome extension compromised to steal credentials and cryptocurrency
- Security news: More phishing, Canada pays ransom, SMBs are a target | Avast
- Russians and Latvians in DOJ crosshairs for cybercrimes, including running the Kelihos botnet
- Data breaches affect stock performance in the long run, study finds
- Cobalt Gang phishing campaign targets Eastern Europeans with CobInt backdoor-downloader
- Military, Government Users Just as Bad About Password Hygiene as Civilians
- One-Third of Data Breaches Led to People Losing Jobs: Kaspersky
- DDoS attacks: Students blamed for many university cyber attacks
- Illegal Patch Allows Easier Access to India's Aadhaar Biometric Database
- N. Korea Calls Sony, Wannacry Hack Charges Smear Campaign
- Major US mobile carriers want to be your password
- Russian man accused of running Kelihos botnet pleads guilty
- Veeam Publicly Exposed 445 Million Customers Records Of its Marketing Database
- Cold Boot Attacks – Hackers Can Unlock All the Modern Computers and Steal Encryption Keys & Passwords
- Law firm begins legal action for data theft in British Airways
Threats
- Zerodium announced Tor vulnerability on Twitter -announced-tor-vulnerability-on-twitter/ …
- FragmentSmack vulnerability also affects Windows, but Microsoft patched it
- Google’s desktop update for Chrome squashes two bugs
- The Week in Ransomware - September 14th 2018 - Kraken, Dharma, & Matrix
- Evaluating the Threatscape One Year After NotPetya Ransomware Attack
- Colorado firm claims ransomware attack behind closure
- Uptick in malware designed to size up targets before launching full payload
- Fallout Exploit Kit Pushing the SAVEfiles Ransomware
- Microsoft Office 365 Customers Get Protection Against Malicious Macros
- Canadian town bows to ransomware attack, will pay attackers
- From PoC to Pwned: New Exploits Appear in Attacks Just Days After Disclosure
- Kraken Cryptor Ransomware Masquerading as SuperAntiSpyware Security Program
- Cobalt Gang phishing campaign targets Eastern Europeans with CobInt backdoor-downloader
- Honolulu-based Fetal Diagnostic Institute of the Pacific hit with ransomware
- Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents
- Apple’s Safari and Microsoft’s Edge browsers contain spoofing bug
- Malware-as-a-Service – New Black Rose Lucy Malware Targets Android Devices With a Special Logic for Xiaomi Phones
Crime
- Cryptojacking campaign targets add-ons for popular streaming app Kodi
- How to Protect Against Phishing Attacks that Follow Natural Disasters
- Russian man accused of running Kelihos botnet pleads guilty
- Law firm begins legal action for data theft in British Airways
Politics
- Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents