Sep 27, 2018

Threat report for 2018-09-26

DATA BREACH

  1. Uber Agrees to $148M Settlement With States Over Data Breach
  2. Uber to pay $148 million to states for 2016 data breach
  3. Firefox Notifies Users of Compromised Accounts
  4. Uber to pay $148 million in settlment over 2016 data breach and cover-up
  5. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  6. United Nations data found exposed on web: researcher
  7. United Nations data found exposed on web: researcher
  8. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  9. SHEIN Data Breach Impacts Over 6.4 Million Customers
  10. SMBs face costs of up to $2.5 million after a data breach
  11. United Nations data found exposed on web: researcher
  12. Millions of Twitter DMs may have been exposed by year-long bug
  13. Firefox Monitor tells you whether your email was compromised in a data breach
  14. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  15. United Nations Mistakenly Exposed Sensitive Data to The Public
  16. oPatch community released micro patches for Microsoft JET Database Zero-Day
  17. Malware campaign attacks freelancers

DENIAL-OF-SERVICE

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  3. Bad bots are stealing data and ruining the customer experience
  4. DDoS Attack on German Energy Company RWE
  5. DDoS Attack on German Energy Company RWE
  6. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  7. Vulnerability in Cisco routers could allow DoS attacks
  8. DDoS attack on education vendor hinders access to districts’ online portals
  9. Microsoft Adds New Tools to Azure DDoS Protection
  10. Viro Botnet Ransomware
  11. Infinite Campus DDoS attack impedes access to student data
  12. Hide and Seek Botnet Adds Infection Vector for Android Devices
  13. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  14. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability

MALVERTISING

Nothing to report

PHISHING

  1. Chegg to reset passwords for 40 million users after April 2018 hack
  2. Android password managers can be tricked into believing that evil apps are good
  3. User login notifications
  4. Beware of payroll-themed phishing. Here’s one example.
  5. SHEIN breach exposes emails, encrypted passwords of 6.42M customers
  6. Counter Phishing Attacks with These Five Tricks
  7. Password managers can be tricked into believing that malicious Android apps are legitimate
  8. Cisco patches critical default password vulnerability
  9. 11:30 AM ET today: @AlexanderGTster and @illena_a from @SCmagazine share the scoop on #spearphishing and how you can go beyond the obvious defenses to protect users from email attacks.
  10. Password Tips from a Pen Tester: Are 12-Character Passwords Really Stronger, or Just a Dime a Dozen?
  11. #SecurityNews: Popular news aggregation site #NewsNow has been notifying its users of a potential password #breach after it found evidence of an #intrusion. Read more about this #databreach here:
  12. Looking for a enterprise grade password vault solution but MUST be hosted onsite
  13. #SecurityNews: New #Ofcom rules "could help tackle #vishing" (voice #phishing) scams. They come into force on Oct 1st and will ban phone companies for charging for the Caller ID service that helps users screen their calls. Read more abut this here:
  14. 156 million #phishing emails are sent out every day and email users receive up to 20 phishing emails each month. Learn more about modern phishing techniques and how to address them in the @ironscales #whitepaper.
  15. Microsoft is killing passwords one announcement at a time
  16. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  17. NewsNow Ditches Passwords After Possible Breach
  18. Malware steals passwords from SHEIN, 6.4 million customers impacted
  19. Malware steals passwords from 6.4 million SHEIN customers
  20. Backlash sees change in Chrome login and Google account behaviour
  21. Chrome 70 Lets you Control Automatic Login and Deletes Google Cookies

WEB DEFACEMENT

Nothing to report

MALWARE

  1. Cisco's probe of VPNFilter router malware uncovers several new hacking techniques
  2. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  3. Fraudulent shopping domain certificate issuance outstrips legitimate businesses
  4. Businesses in Arkansas Hit with Ransomware
  5. Malware in the Cloud: What You Need to Know
  6. Businesses in Arkansas Hit with Ransomware
  7. Air Gapped PCs are Still at Risk. The Rise of USB-based Crytojacking Malware
  8. Crooks turn to Delphi packers to evade malware detection
  9. USB malware and cryptominers are threat to emerging markets
  10. DanaBot trojan sets sights on Europe, new features
  11. Trojanized App In Google Play Steals Bank Customers' Euros
  12. Password managers can be tricked into believing that malicious Android apps are legitimate
  13. Crooks turn to Delphi packers to evade malware detection
  14. Viro Botnet Ransomware
  15. Freelancers baited with job offers to download malicious macros
  16. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  17. Domain flub leaves 30 million customers high and dry
  18. USB malware and cryptominers are threat to emerging markets
  19. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  20. Android spyware in development plunders WhatsApp data, private conversations
  21. The MITRE ATT&CK Framework: Exfiltration
  22. Malware steals passwords from SHEIN, 6.4 million customers impacted
  23. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  24. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software
  25. Malware steals passwords from 6.4 million SHEIN customers
  26. Crooks leverages Kodi Media Player add-ons for malware distribution
  27. Malware in the Cloud: What You Need to Know
  28. Cryptocurrency mining malware increases 86%
  29. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script
  30. Malware campaign attacks freelancers
  31. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit

EXPLOIT

  1. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  2. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  3. Rockwell Automation Buffer Overflow Vulnerability
  4. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  5. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit

VULNERABILITY

  1. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  2. Vulnerability in Cisco routers could allow DoS attacks
  3. Cisco patches critical default password vulnerability
  4. New Linux Kernel “Mutagen Astronomy” Flaw Impacts Red Hat, CentOS, Debian Distributions.
  5. Twitter fixes API bug that shared data with wrong developers
  6. Cisco: Linux kernel FragmentSmack bug now affects 88 of our products
  7. Bug? Feature? Power users baffled as BitLocker update switch-off continues
  8. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  9. Linux Kernel Vulnerability Affects Red Hat, CentOS, Debian
  10. Millions of Twitter DMs may have been exposed by year-long bug
  11. Apple pushes out Mojave 10.14, patches numerous vulnerabilities
  12. Variant of patched IE vulnerability spotted in wild
  13. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  14. Rockwell Automation Buffer Overflow Vulnerability
  15. Crowdfense launches Vulnerability Research Hub for top security researchers
  16. oPatch community released micro patches for Microsoft JET Database Zero-Day
  17. New Linux Kernel Bug Affects Red Hat, CentOS, and Debian Distributions
  18. Vulnerability affects Cisco Video Surveillance Manager
  19. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  20. Snyk raises $22 million to address security vulnerabilities in open source code
  21. New security vulnerabilities (CVE-2018-14634) affects CentOS and Red Hat Linux
  22. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability