Threat report for 2018-09-18
Data Breach
- US Dept of State says attack on email system exposed employees’ personal data
- State Department email breach leaks employee PII
- 14 million customer records exposed in GovPayNow leak
- Xbash Malware Deletes Databases on Linux, Mines for Coins on Windows
- Survey: Nearly one-third of breached companies reported job losses after data breach
- Insiders Continue to be Data Theft’s Best Friend
- Symantec offers political campaigns service to guard against website spoofing
- Huge E-marketing Database that Contains 11 Million Sensitive Personal Records Exposed Online
- GovPayNow Leak of 14M+ Records Dates Back to 2012
- MongoDB server leaks 11 million user records from e-marketing service
- GovPayNow payment portal may have exposed over 14 million customer records
- Database with 11 Million Email Records Exposed
- UK watchdog has not issued any GDPR data breach-related fines yet
- Political Figures Differ Online: Names of Trump, Obama, Merkel Attached to Ransomware Campaigns
- 900,000 Australians opt out of My Health Record
Denial-of-Service
- Bizarre botnet infects your PC to scrub away cryptocurrency mining malware
- New Xbash Malware Attack on Linux & Windows with Botnet, Ransomware & Coinminer Capabilities
- New XBash malware combines features from ransomware, cryptocurrency miners, botnets, and worms
Malvertising
- Nothing to report
Data Leak
- Nothing to report
Phishing
- Here’s a Free Turnkey Phishing Awareness Program for National Cybersecurity Awareness Month
- Hackers selling research phished from universities on WhatsApp
Web Defacement
- Nothing to report
Malware
- NSO mobile Pegasus Spyware used in operations in 45 countries
- ThreatList: Malware Samples Targeting IoT More Than Double in 2018
- Xbash Malware Deletes Databases on Linux, Mines for Coins on Windows
- Chinese-speaking cybercrime group launches destructive malware family
- Pegasus spyware active in 45 countries, Citizen Lab says
- Destructive Xbash Linux Malware Targets Enterprise Intranets
- Dangerous Pegasus Spyware Has Spread to 45 Countries
- "Lawful intercept" Pegasus spyware found deployed in 45 countries
- Cybercrime: Ransomware remains a 'key' malware threat says Europol
- HIDE AND SEEK: Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries
- Bizarre botnet infects your PC to scrub away cryptocurrency mining malware
- Powerful Android and iOS Spyware Found Deployed in 45 Countries
- New Xbash Malware Attack on Linux & Windows with Botnet, Ransomware & Coinminer Capabilities
- New XBash malware combines features from ransomware, cryptocurrency miners, botnets, and worms
- Political Figures Differ Online: Names of Trump, Obama, Merkel Attached to Ransomware Campaigns
- Ransomware attack causes blackout on screens of Bristol Airport
Exploit
- 91 “child friendly” Android apps accused of exploitation
- Cracked Windows installations are serially infected with EternalBlue exploit code
Vulnerability
- Facebook Bug Bounty opens to reward access token exposure
- iOS Webkit flaw found that forces iPhone restart
- The NUUO Peekaboo vulnerability gives hackers your camera feed | Avast
- Intel releases firmware update for ME flaw
- Critical Vulnerability Impacts Hundreds of Thousands of IoT Cameras
- iOS 12 Brings Patches for 16 Security Vulnerabilities
- A flaw in Alpine Linux could allow executing arbitrary code
- Windows 10 Build 17763 Released As Microsoft Continues to Squash Bugs
- Hackers acknowledge Windows flaws but prefer social engineering tricks
- Critical RCE Peekaboo Bug in NVR Surveillance System, PoC Available
- Facebook Offers Rewards for Access Token Exposure Flaws
- Response Guide of IBM WebSphere Code Execution Vulnerability