Sep 29, 2018

Daily brief for 2018-09-28

ASIA

  1. No Patches for Critical Flaws in Fuji Electric Servo System, Drives
  2. Google first confirmed the existence of the Dragonfly program for returning to China

WORLD

  1. Facebook leaks data (including private conversations) from 50 million accounts
  2. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  3. Aspire Health, Another Healthcare Firm as a Phishing Victim
  4. 7 new modules for VPNFilter malware, Hide & Seek botnet targets Android, and house oversight takes on AI | Avast
  5. New Phishing Campaign Targets US Employees' Online Payrolls
  6. IC3 Alerts of Increasing Danger of RDP Exploitation Attacks
  7. QRecorder app in the Play Store was hiding a Banking Trojan that targets European banks
  8. Magecart campaign remains active
  9. Researchers: 11-Year-Old Flaw in Vote Scanner Still Unfixed
  10. Who’s behind DDoS attacks at UK universities?
  11. Fancy Bear Attacks Governments Using LoJax UEFI Rootkit
  12. Resident evil: Inside a UEFI rootkit used to spy on govts, made by you-know-who (hi, Russia)
  13. Vulnerabilities and architectural considerations in industrial control systems

ATTACKS

  1. Facebook leaks data (including private conversations) from 50 million accounts
  2. Facebook leaks data (including private conversations) from 50 million accounts
  3. Facebook hacked – 50 Million Users’ Data exposed in the security breach
  4. Big Facebook data breach: 50 million accounts affected
  5. Facebook Data Breach Impacts Almost 50 Million Accounts
  6. Vulnerabilities in PureVPN Client Leak User Credentials
  7. Aspire Health, Another Healthcare Firm as a Phishing Victim
  8. 7 new modules for VPNFilter malware, Hide & Seek botnet targets Android, and house oversight takes on AI | Avast
  9. New Phishing Campaign Targets US Employees' Online Payrolls
  10. Learn how our @PhishingAI successfully detected a custom #phishing kit targeted at the DNC last month:
  11. 3 GOP senators doxed during Kavanaugh hearing
  12. Chegg forces password reset on 40 million users
  13. Torii malware could be gateway to more sophisticated IoT botnet attacks
  14. SHEIN breach exposes emails, encrypted passwords of 6.42M customers
  15. Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
  16. Android App Verification Issues Pave Way For Phishing Attacks
  17. Facebook Resets 90 Million User Passwords as Flaw is Discovered
  18. Facebook Resets 90 Million User Passwords as Flaw is Discovered
  19. Meet Torii, a Stealthy, Versatile and Highly Persistent IoT Botnet
  20. Chegg Resets Passwords After Data Breach That Affected 40 Million Users
  21. Facebook Discloses Data Breach, 50 Million User Accounts Affected
  22. United Nations data found exposed on web: researcher
  23. Hide 'N Seek IoT Botnet Now Targets Android Devices
  24. Magecart campaign remains active
  25. Android password managers vulnerable to phishing apps
  26. “Firefox Monitor” will allow users to check whether their personal information and passwords have been part of a data breach
  27. Bupa fined £175,000 for 2017 data breach affecting 547,000 customers
  28. The @ironscales #whitepaper explores how modern #phishing techniques, such as business email compromise (#BEC), #ransomware, spear-phishing and advanced persistent threats
  29. Power to the people! Google backtracks (a bit) on forced Chrome logins
  30. Who’s behind DDoS attacks at UK universities?
  31. Microsoft is trying to kill passwords in Azure AD application
  32. Android password managers not as secure as desktop counterparts
  33. Stealthy and Persistent Torii IoT Botnet Infects Devices via Telnet
  34. United Nations data found exposed on web: researcher
  35. Meet Torii, a new IoT botnet far more sophisticated than Mirai variants
  36. How can live chat widgets leak personal employee data?
  37. Chegg Data Breach Affects 40 Million Customers
  38. 7 Most Prevalent Phishing Subject Lines
  39. New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai
  40. Phorpiex bots target remote access servers to deliver ransomware
  41. New Iot Botnet Torii Uses Six Methods for Persistence, Has No Clear Purpose
  42. New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai

THREATS

  1. CVE-2018-11776 RCE Flaw in Apache Struts Could Be Root Cause of Clamorous Hacks
  2. Port of San Diego suffers ransomware attack | Avast
  3. Port of San Diego suffers ransomware attack | Avast
  4. Critical Security Vulnerability in Facebook Affects 50 million Users!
  5. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  6. Facebook Security Bug Affects 90M Users
  7. Zoho Was Blacklisted by Domain Registrar TierraNet
  8. [SingCERT] Alert on 14 High-Severity Vulnerabilities in Cisco Products
  9. Another Linux Kernel Bug Surfaces, Allowing Root Access
  10. Vulnerabilities in PureVPN Client Leak User Credentials
  11. The Week in Ransomware - September 28th 2018 - RDP and gandCrab
  12. 7 new modules for VPNFilter malware, Hide & Seek botnet targets Android, and house oversight takes on AI | Avast
  13. 'Torii' Breaks New Ground For IoT Malware
  14. FBI IC3 Warns of RDP Vulnerability
  15. Tripwire Patch Priority Index for September 2018
  16. Port of San Diego, The Newest Victim of Ransomware Attack
  17. Powerful Ransomware Attack Hit on Port of San Diego
  18. IC3 Alerts of Increasing Danger of RDP Exploitation Attacks
  19. Torii malware could be gateway to more sophisticated IoT botnet attacks
  20. Docs reveal how Fruitfly Mac spyware initially spread
  21. Facebook Vulnerability Affecting 50 Million Users Allowed Account Takeover
  22. Fancy Bear’s Lojax is First UEFI Rootkit in the Wild
  23. FBI solves mystery surrounding 15-year-old Fruitfly Mac malware
  24. USB malware and cryptominers are threat to emerging markets
  25. Facebook Resets 90 Million User Passwords as Flaw is Discovered
  26. Potential Misuse of Legitimate Websites to Avoid Malware Detection
  27. Facebook Resets 90 Million User Passwords as Flaw is Discovered
  28. Port of San Diego Suffers Ransomware Attack
  29. Delphi Packer Increasingly Used to Evade Malware Classification
  30. QRecorder app in the Play Store was hiding a Banking Trojan that targets European banks
  31. Hackers Stole 50 Million Facebook Users' Access Tokens Using Zero-Day Flaw
  32. The @ironscales #whitepaper explores how modern #phishing techniques, such as business email compromise (#BEC), #ransomware, spear-phishing and advanced persistent threats
  33. Researchers: 11-Year-Old Flaw in Vote Scanner Still Unfixed
  34. Port of San Diego Hit by Ransomware
  35. Facebook: 50 million accounts impacted by security flaw
  36. Fancy Bear Attacks Governments Using LoJax UEFI Rootkit
  37. Windows 10 security: Here's how we're hitting back at fileless malware, says Microsoft
  38. Resident evil: Inside a UEFI rootkit used to spy on govts, made by you-know-who (hi, Russia)
  39. Sunny Cali goes ballistic, this ransomware is atrocious. Even our IT bill will be something quite ferocious
  40. Fancy Bear still Putin out new modules for VPNFilter malware
  41. 'Mutagen Astronomy' Linux kernel vulnerability sighted
  42. How Data Security Improves When You Engage Employees in the Process
  43. SECURITY UPDATE: Facebook said a breach affected 50 million people on the social network. The vulnerability stemmed from Facebook's "View As"
  44. Connected car cyber-security getting better, fewer critical vulnerabilities found
  45. Users Clicking Through Warnings, Leading to RAT Infections
  46. No Patches for Critical Flaws in Fuji Electric Servo System, Drives
  47. CVE-2018-1718 -Google Project Zero reports a new Linux Kernel flaw
  48. Google Play Store Swarmed with Malware
  49. Phorpiex bots target remote access servers to deliver ransomware
  50. Vulnerabilities and architectural considerations in industrial control systems
  51. Google Project Zero Discloses New Linux Kernel Flaw
  52. Port of San Diego Suffers Ransomware Attack
  53. ICS Cybersecurity: Visibility, Protective Controls & Continuous Monitoring
  54. Google Hacker Discloses New Linux Kernel Vulnerability and PoC Exploit
  55. Tripwire Patch Priority Index for September 2018
  56. ICS Cybersecurity: Visibility, Protective Controls & Continuous Monitoring

CRIME

  1. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  2. Aspire Health, Another Healthcare Firm as a Phishing Victim
  3. New Phishing Campaign Targets US Employees' Online Payrolls
  4. IC3 Alerts of Increasing Danger of RDP Exploitation Attacks
  5. Potential Misuse of Legitimate Websites to Avoid Malware Detection
  6. QRecorder app in the Play Store was hiding a Banking Trojan that targets European banks
  7. Magecart campaign remains active
  8. The @ironscales #whitepaper explores how modern #phishing techniques, such as business email compromise (#BEC), #ransomware, spear-phishing and advanced persistent threats
  9. Stealthy and Persistent Torii IoT Botnet Infects Devices via Telnet

POLITICS

  1. Facebook leaks data (including private conversations) from 50 million accounts
  2. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  3. Aspire Health, Another Healthcare Firm as a Phishing Victim
  4. Hackers Stole 50 Million Facebook Users' Access Tokens Using Zero-Day Flaw
  5. Resident evil: Inside a UEFI rootkit used to spy on govts, made by you-know-who (hi, Russia)