Daily brief for 2018-10-16
ASIA
- Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
- New ShadowTalk Episode 45
This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
- Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
- Line lists cryptocurrency on Bitbox exchange
WORLD
- Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
- Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
- Insurer Anthem Will Pay Record $16M for Massive Data Breach
- A Russian cyber vigilante is patching outdated MikroTik routers exposed online
- Bug in New iOS Lets Attacker Access iPhone Pics
- Sony Fixed PlayStation 4 Message Exploit Leasing to a DoS Condition
- New ShadowTalk Episode 45
This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
- Madison County computer system infected with ransomware
- Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
- 2018 US voter records offered for sale on hacking forum
- Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
- 35 million US voter records available for sale in a hacking forum
- Anthem agrees to pay $16 million in data breach privacy settlement
- Dating App for Trump Supporters Exposed Members’ Information
- Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
- Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
- Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
- Pentagon Travel Provider Data Breach Counts 30,000 Victims
- UK’s MoD Exposed in 37 Security Breaches: Report
- Report: near-400% increase in crypto-mining malware attacks against iPhones
- Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
- 35 million voter records from 19 states for sale on hacking forum
- Octopus malware wraps tentacles around former Telegram users in Central Asia
- Phishing and Facebook – a test of reputation
- Pentagon data breach puts personal details of 30,000 staff at risk
- Data breach in Pentagon’s service provider affected 30k people
- NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine
- New iPhone Bug Gives Anyone Access to Your Private Photos
ATTACKS
- Chrome 70 arrives with fingerprint login for websites, extension controls, and 23 security fixes
- Chrome 70 released with revamped Google account login system
- Insurer Anthem Will Pay Record $16M for Massive Data Breach
- Pentagon data breach exposed travel data for 30,000 individuals
- A Russian cyber vigilante is patching outdated MikroTik routers exposed online
- A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
- Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
- Anthem Agrees To Pay $16 Million In Data Breach Privacy Settlement
- The Donald Daters Trump Dating App Exposed Its Users Data
- Phishing Site Impersonates Financial Services Institution: https://www.digitalshadows.com/blog-and-research/phishing-site-impersonates-financial-services-institution/ … (via @mazzazone)
- 2018 US voter records offered for sale on hacking forum
- Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
- #TLBleed exploits abuse Intel's HTT chip feature to leak data. Find out how hackers could launch side-channel attacks to obtain
- 35 million US voter records available for sale in a hacking forum
- Anthem agrees to pay $16 million in data breach privacy settlement
- Dating App for Trump Supporters Exposed Members’ Information
- After originally disclosing its latest data breach last month, Facebook revealed that hackers obtained data from some 30 million users.
Here’s
- Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
- Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
- Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
- Pentagon Travel Provider Data Breach Counts 30,000 Victims
- UK’s MoD Exposed in 37 Security Breaches: Report
- 35 million voter records from 19 states for sale on hacking forum
- Pentagon data breach puts personal details of 30,000 staff at risk
- Facebook says fewer users affected by data breach
- Phishing and Facebook – a test of reputation
- Pentagon data breach puts personal details of 30,000 staff at risk
- Data breach in Pentagon’s service provider affected 30k people
THREATS
- SAP Boosts Blockchain Integration and Customer Flexibility
- Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
- [SingCERT] Alert on Multiple Vulnerabilities in PHP
- Multiple Vulnerabilities Allow Attackers to Take Full Control of Linksys Routers
- In County Crippled by Hurricane, Water Utility Targeted in Ransomware Attack
- 7 Useful Android Vulnerability Scanners
- Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
- .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
- Bug in New iOS Lets Attacker Access iPhone Pics
- Malicious RTF Documents Deliver Information Stealers
- Info of 685 Million Users at Risk Because of Multiple Branch.io XSS Flaws
- Madison County computer system infected with ransomware
- CVE-2018-8453 Zero-Day Flaw Exploited by FruityArmor APT
- How to Create Blockchain Applications
- NC Water Utility Fights Post-Hurricane Ransomware
- Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
- Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
- Tinder profiles were 'at risk' due to XSS vulnerability
- 685 million users may be affected by the Branch.io service XSS vulnerability
- A “critical water utility” in a county crippled by Hurricane #Florence was hit by a #ransomware attack.
The #cyberattack has
- #Stegware: it's #Malware that uses #steganography techniques to avoid detection
- Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
- Report: near-400% increase in crypto-mining malware attacks against iPhones
- Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
- RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
- #Shodan, a device search engine, can help identify #ICS security vulnerabilities. Learn more about how Shodan works and how it
- Octopus malware wraps tentacles around former Telegram users in Central Asia
- Mikko didn't put Brain -- the first PC virus -- on his list but he did track down its authors
- Line lists cryptocurrency on Bitbox exchange
- "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well
- You are who you say you are: Establishing digital trust with the blockchain
- Now Surfing about your Favourite Celebrities can make you Vulnerable to Virus Attack
- Malware Attack Popular Amongst the Hackers, Even though it Dips in Q2 in 2018
- Cryptomining attacks against Apple devices increase sharply
- APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11
- Cybercriminals Advertising Godzilla Loader Malware On Dark Web Forums
- 685 million users may be affected by the Branch.io service XSS vulnerability
- Cryptojacking attacks against iPhone devices increase
- Juniper Networks launches multiple solutions for Junos OS vulnerabilities
- Most Important Considerations with Malware Analysis Cheats And Tools list
- New iPhone Bug Gives Anyone Access to Your Private Photos
- Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits
CRIME
- Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
- A Russian cyber vigilante is patching outdated MikroTik routers exposed online
- How to Create Blockchain Applications
- Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
- 35 million US voter records available for sale in a hacking forum
- Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
- Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
- UK’s MoD Exposed in 37 Security Breaches: Report
- Report: near-400% increase in crypto-mining malware attacks against iPhones
- Facebook says fewer users affected by data breach
- Pentagon data breach puts personal details of 30,000 staff at risk
POLITICS
- Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
- A Russian cyber vigilante is patching outdated MikroTik routers exposed online
- Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
- UK’s MoD Exposed in 37 Security Breaches: Report
- RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
- Octopus malware wraps tentacles around former Telegram users in Central Asia
- "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well