Sep 20, 2018

Threat report for 2018-09-19

DATA BREACH

  1. Survey: Nearly one-third of breached companies reported job losses after data breach
  2. Access to over 3,000 compromised sites sold on Russian black marketplace MagBo
  3. NSA Leak Fuels Rise in Hacking for Crypto Mining: Report
  4. Magecart claims another victim in Newegg merchant data theft
  5. Here we Mongo again! Millions of records exposed by insecure database
  6. How Facebook wants to protect political campaigners from hacking
  7. Yahoo settles for $47 million in litigation following data breach of 3 billion accounts
  8. State Department reveals data breach, employee information exposed
  9. Vulnerabilities Discovered in NUUO Network Video Recorder
  10. Veeam gets hacked: Data management enterprise exposes database with more than 400 million emails
  11. New ransomware campaign encrypts files even if the ransom is paid

DENIAL-OF-SERVICE

  1. A Hybrid Solution to Taming SOC Alert Overload
  2. The makers of the Mirai IoT-hijacking botnet are sentenced
  3. Mirai botnet authors avoid prison after "substantial assistance" to the FBI
  4. New Malware Combines Ransomware, Coin Mining and Botnet Features in One
  5. Mirai Botnet Creators Helping FBI Fight Cybercrime to Stay Out of Jail

MALVERTISING

  1. Nothing to report

DATA LEAK

  1. Nothing to report

PHISHING

  1. Phishing finance apps make way back into Google Play
  2. Hackers Constantly Carrying out Password Stealing Attacks Targeting Financial Services Industry
  3. FBI: Phishing Attacks Aim to Swap Payroll Information
  4. Credential Stuffing Attacks Generate Billions of Login Attempts
  5. This Windows file may be secretly hoarding your passwords and emails
  6. Your business should be more afraid of phishing than malware

WEB DEFACEMENT

  1. Nothing to report

MALWARE

  1. VAI MALANDRA: A LOOK INTO THE LIFECYCLE OF BRAZILIAN FINANCIAL MALWARE
  2. WANNAMINE CRYPTOMINER THAT USES ETERNALBLUE STILL ACTIVE
  3. Colorado firm claims ransomware attack behind closure
  4. Access to over 3,000 backdoored sites sold on Russian hacking forum
  5. NSA Leak Fuels Rise in Hacking for Crypto Mining: Report
  6. Researchers find new financial malware targeting banking customers in Brazil
  7. XBash Malware Packs Double Punch: Destroys Data and Mines for Crypto Coins
  8. The Past, the Present, and the Future of Illicit Cryptomining: Cyber Threat Alliance Publishes Landmark White Paper
  9. New Malware Combines Ransomware, Coin Mining and Botnet Features in One
  10. Your business should be more afraid of phishing than malware
  11. Cyber Threat Alliance Releases Cryptomining Whitepaper
  12. Hackers using Android & iOS Spyware “Pegasus” to Conducting Massive Surveillance Operations in 45 Countries
  13. New ransomware campaign encrypts files even if the ransom is paid

EXPLOIT

  1. Nothing to report

VULNERABILITY

  1. Adobe Patches Code Execution, Other Flaws in Acrobat and Reader
  2. Bug in Bitcoin code also opens smaller cryptocurrencies to attacks
  3. Rapid7 Threat Intelligence Book Club: ‘Countdown to Zero Day’ Recap
  4. ‘Peekaboo’ zero-day lets hackers view and alter surveillance camera footage
  5. WTB: Windows Systems Vulnerable To FragmentSmack, 90s-Like DoS Bug
  6. Flaw in Western Digital My Cloud exposes the content to hackers
  7. Vulnerabilities Discovered in NUUO Network Video Recorder
  8. Zero Day vulnerability allows access to CCTV cameras
  9. Windows 10 Build 18242 (19H1) Released With Bug Fixes