Daily brief for 2018-09-25
ASIA
- Snyk gets $22 million for platform that tracks security flaws in open source projects
- Security Engineer Hacks Hotel WiFi, Fined for Exposing Admin Password
- Off-the-shelf RATs Targeting Pakistan
- Malicious Documents from Lazarus Group Targeting South Korea
- GZipDe: An Encrypted Downloader Serving Metasploit
- More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
- USB threats from malware to miners
WORLD
- Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
- Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
- Snyk gets $22 million for platform that tracks security flaws in open source projects
- Astaroth Trojan Resurges in South America
- BrandPost: Malicious Tactics Have Evolved: Your DNS Needs to, Too
- Security In The Crypto World: Exchanges, Wallets, Personal Data. Kiev To Host The Largest Cybersecurity Forum In Eastern Europe
- #SecurityNews: Scottish #Brewery recovers from #ransomware attack. #Arran Brewery in Scotland, received what they thought was a cover letter as part of a job application, but the email attachment contained malware. Read more here:
https://bit.ly/2PYAR7k
- Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
- Baddies just need one email account with clout to unleash phishing hell
- Malware Analysis using Osquery Part 1
- MassMiner Malware Targeting Web Servers
- 14 years prison for man who helped hackers evade detection by anti-virus software
- SHEIN-Fashion Shopping Site Suffers Data Breach Affecting 6.5 Million Users
- 14 years prison for man who helped hackers evade detection by anti-virus software
- New malware-as-a-service, Black Rose Lucy targets Android devices
ATTACKS
- Firefox Monitor provides password breach alerts, Would it convince you to set up a Firefox Account
- Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
- Malware on SHEIN Servers Compromises Data of 6.4M Customers
- GrrCon Augusta 2018, Rachel Giacobozzi’s ‘The Hybrid Analyst: How Phishing Created A New Type Of Intel Analyst’
- Mozilla Launches Firefox Monitor Data Breach Notification Service
- Tomorrow: Go beyond the usual defenses and *really* protect your email from #spearphishing attacks. Find out how with @AlexanderGTster and @illena_a from @SCmagazine. http://www.workcast.com/register?cpak=2026696370909275&referrer=valimailA …
- Third-Party Patch Available for Microsoft JET Database Zero-Day
- 130 Million Hotel Customers Breached Due to Exposed Database
- State Department data breach exposes employee info (w/ commentary from @TripwireInc’s @craigtweets http://bit.ly/2MTcplE
- DDoS Attack on Infinite Campus Limits Parent Access http://dlvr.it/QlL12Z
- DDoS Attack on Infinite Campus Limits Parent Access https://www.infosecurity-magazine.com/news/ddos-attacks-infinite-campus?utm_source=twitterfeed&utm_medium=twitter …
- New Adwind RAT Campaign Targets Windows, Linux and Mac Users
- Cisco patches critical default password vulnerability
- DDoS attack on education vendor hinders access to districts’ online portals
- Bitcoin Core Team fixes a critical DDoS flaw in wallet software
- Shein Data Breach Exposes Personal Data and Email Address of 6.42 Million Customers
- Security researcher fined for hacking hotel Wi-Fi and putting passwords on the internet
- SHEIN Data breach affected 6.42 million users
- Security In The Crypto World: Exchanges, Wallets, Personal Data. Kiev To Host The Largest Cybersecurity Forum In Eastern Europe
- Users fret over Chrome auto-login change
- Security Engineer Hacks Hotel WiFi, Fined for Exposing Admin Password
- AdGuard adblocker resets passwords after credential-stuffing attack
- Symantec accountancy audit uncovers customer transaction recorded as revenue
- 5 Notable Security Incidents that Recently Affected Federal Entities https://tripwire.me/2xGwKoH
- Anti-Phishing Requires A Three-Pronged Strategy https://www.infosecurity-magazine.com/white-papers/antiphishing-requires-threepronged?utm_source=twitterfeed&utm_medium=twitter …
- Microsoft: Here's why we're declaring end of password era
- Microsoft 'kills' passwords, throws up threat manager, APIs Graph Security
- Baddies just need one email account with clout to unleash phishing hell
- Some credential-stuffing botnets don't care about being noticed any more
- Advanced DDoS Detection and Defense
- Why Was Equifax So Stupid About Passwords?
- ZombieBoy
- NewsNow suffers security breach - passwords should be considered compromised
- Cisco patches critical default password vulnerability
- First known malicious cryptomining campaign targeting Kodi discovered
- SHEIN-Fashion Shopping Site Suffers Data Breach Affecting 6.5 Million Users
- macOS zero-day vulnerability leads to user data leaks
- How Long Does it Take to Find Compromised Data
- Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability
- 5 Notable Security Incidents that Recently Affected Federal Entities https://tripwire.me/2xGwKoH
- DBeaver Community Edition 5.2.1 Releases: Free universal database tool and SQL client
THREATS
- Open-source reuse has left Android’s most-popular apps laced with critical vulnerabilities
- The MITRE ATT&CK Framework: Exfiltration https://tripwire.me/2NDbSJV
- Monero bug could have allowed hackers to steal massive amounts of cryptocurrency
- New Linux 'Mutagen Astronomy' security flaw impacts Red Hat and CentOS distros
- Once Popular Online Ad Format Opens Top Tier Sites to XSS Attacks
- Malware on SHEIN Servers Compromises Data of 6.4M Customers
- Third-Party Patch Available for Microsoft JET Database Zero-Day
- Over 80 Cisco Products Affected by FragmentSmack DoS Bug
- Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
- MacOS Mojave zero-day privacy vulnerability uncovered
- New Adwind RAT Campaign Targets Windows, Linux and Mac Users
- Cryptomining Malware Continues Rapid Growth: Report
- Freelancers baited with job offers to download malicious macros
- Snyk gets $22 million for platform that tracks security flaws in open source projects
- Cisco patches critical default password vulnerability
- Twitter fixes API bug that shared data with wrong developers
- DanaBot trojan sets sights on Europe, new features
- Crooks turn to Delphi packers to evade malware detection
- Mac Mojave Zero-Day Allows Malicious Apps to Access Sensitive Info
- Bitcoin Core Team fixes a critical DDoS flaw in wallet software
- Astaroth Trojan Resurges in South America
- BrandPost: Malicious Tactics Have Evolved: Your DNS Needs to, Too
- Bloodhound – A Tool For Exploring Active Directory Domain Security
- No Takers for Zero-Day Vulnerabilities on the Dark Web
- macOS Mojave Patches Vulnerabilities, But New Flaws Already Emerge
- #SecurityNews: #Cryptocurrency mining soars 459% from 2017 to 2018 with no indication of slowing down. Read more about this story here: https://bit.ly/2PXYSew
- New CVE-2018-8373 Exploit Spotted in the Wild
- #SecurityNews: Scottish #Brewery recovers from #ransomware attack. #Arran Brewery in Scotland, received what they thought was a cover letter as part of a job application, but the email attachment contained malware. Read more here:
https://bit.ly/2PYAR7k
- Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
- Malware Analysis using Osquery Part 2
- Off-the-shelf RATs Targeting Pakistan
- Malware Analysis using Osquery Part 1
- Malicious Documents from Lazarus Group Targeting South Korea
- GZipDe: An Encrypted Downloader Serving Metasploit
- More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
- Satan Ransomware Spawns New Methods to Spread
- MassMiner Malware Targeting Web Servers
- Vulnerability Spotlight: Epee Levin Packet Deserialization Code Execution Vulnerability
- 14 years prison for man who helped hackers evade detection by anti-virus software
- USB threats from malware to miners
- DanaBot trojan sets sights on Europe, new features
- Twitter fixes API bug that shared data with wrong developers
- Stealthy cryptomining apps still on Google Play
- New Version of GandCrab Ransomware Appends 5 Character Extension To Encrypted Files
- Cisco patches critical default password vulnerability
- White hat hacker found a macOS Mojave privacy bypass 0-day flaw on release day
- First known malicious cryptomining campaign targeting Kodi discovered
- 14 years prison for man who helped hackers evade detection by anti-virus software
- macOS zero-day vulnerability leads to user data leaks
- New malware-as-a-service, Black Rose Lucy targets Android devices
- Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability
- Vulnerability in macOS Mojave allows access to protected files
- Firefox bugs can cause browsers and even the entire operating system to crash directly
- Domain registrar oversteps taking down Zoho domain, impacts over 30Mil users
- Why the market for zero-day vulnerabilities on the dark web is vanishing
CRIME
- Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
- Porous portals, Newegg is a broken egg, and Mirai’s creators have new hats
- Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
- Cryptomining Malware Continues Rapid Growth: Report
- Bitcoin Core Team fixes a critical DDoS flaw in wallet software
- SHEIN Data breach affected 6.42 million users
- #SecurityNews: #Cryptocurrency mining soars 459% from 2017 to 2018 with no indication of slowing down. Read more about this story here: https://bit.ly/2PXYSew
- Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
- Microsoft: Here's why we're declaring end of password era
- Malware Analysis using Osquery Part 2
- Malware Analysis using Osquery Part 1
- ZombieBoy
- Malicious Documents from Lazarus Group Targeting South Korea
- MassMiner Malware Targeting Web Servers
- 14 years prison for man who helped hackers evade detection by anti-virus software
- DanaBot trojan sets sights on Europe, new features
- Stealthy cryptomining apps still on Google Play
- First known malicious cryptomining campaign targeting Kodi discovered
- 14 years prison for man who helped hackers evade detection by anti-virus software
- Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability
POLITICS
- Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
- Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
- Vulnerability in macOS Mojave allows access to protected files