Oct 17, 2018

Daily brief for 2018-10-16

ASIA

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  3. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  4. Line lists cryptocurrency on Bitbox exchange

WORLD

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  3. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  4. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  5. Bug in New iOS Lets Attacker Access iPhone Pics
  6. Sony Fixed PlayStation 4 Message Exploit Leasing to a DoS Condition
  7. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  8. Madison County computer system infected with ransomware
  9. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  10. 2018 US voter records offered for sale on hacking forum
  11. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  12. 35 million US voter records available for sale in a hacking forum
  13. Anthem agrees to pay $16 million in data breach privacy settlement
  14. Dating App for Trump Supporters Exposed Members’ Information
  15. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  16. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  17. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  18. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  19. UK’s MoD Exposed in 37 Security Breaches: Report
  20. Report: near-400% increase in crypto-mining malware attacks against iPhones
  21. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  22. 35 million voter records from 19 states for sale on hacking forum
  23. Octopus malware wraps tentacles around former Telegram users in Central Asia
  24. Phishing and Facebook – a test of reputation
  25. Pentagon data breach puts personal details of 30,000 staff at risk
  26. Data breach in Pentagon’s service provider affected 30k people
  27. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine
  28. New iPhone Bug Gives Anyone Access to Your Private Photos

ATTACKS

  1. Chrome 70 arrives with fingerprint login for websites, extension controls, and 23 security fixes
  2. Chrome 70 released with revamped Google account login system
  3. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  4. Pentagon data breach exposed travel data for 30,000 individuals
  5. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  6. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  7. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  8. Anthem Agrees To Pay $16 Million In Data Breach Privacy Settlement
  9. The Donald Daters Trump Dating App Exposed Its Users Data
  10. Phishing Site Impersonates Financial Services Institution: https://www.digitalshadows.com/blog-and-research/phishing-site-impersonates-financial-services-institution/ … (via @mazzazone)
  11. 2018 US voter records offered for sale on hacking forum
  12. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  13. #TLBleed exploits abuse Intel's HTT chip feature to leak data. Find out how hackers could launch side-channel attacks to obtain
  14. 35 million US voter records available for sale in a hacking forum
  15. Anthem agrees to pay $16 million in data breach privacy settlement
  16. Dating App for Trump Supporters Exposed Members’ Information
  17. After originally disclosing its latest data breach last month, Facebook revealed that hackers obtained data from some 30 million users. Here’s
  18. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  19. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  20. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  21. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  22. UK’s MoD Exposed in 37 Security Breaches: Report
  23. 35 million voter records from 19 states for sale on hacking forum
  24. Pentagon data breach puts personal details of 30,000 staff at risk
  25. Facebook says fewer users affected by data breach
  26. Phishing and Facebook – a test of reputation
  27. Pentagon data breach puts personal details of 30,000 staff at risk
  28. Data breach in Pentagon’s service provider affected 30k people

THREATS

  1. SAP Boosts Blockchain Integration and Customer Flexibility
  2. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  3. [SingCERT] Alert on Multiple Vulnerabilities in PHP
  4. Multiple Vulnerabilities Allow Attackers to Take Full Control of Linksys Routers
  5. In County Crippled by Hurricane, Water Utility Targeted in Ransomware Attack
  6. 7 Useful Android Vulnerability Scanners
  7. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  8. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  9. Bug in New iOS Lets Attacker Access iPhone Pics
  10. Malicious RTF Documents Deliver Information Stealers
  11. Info of 685 Million Users at Risk Because of Multiple Branch.io XSS Flaws
  12. Madison County computer system infected with ransomware
  13. CVE-2018-8453 Zero-Day Flaw Exploited by FruityArmor APT
  14. How to Create Blockchain Applications
  15. NC Water Utility Fights Post-Hurricane Ransomware
  16. Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
  17. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  18. Tinder profiles were 'at risk' due to XSS vulnerability
  19. 685 million users may be affected by the Branch.io service XSS vulnerability
  20. A “critical water utility” in a county crippled by Hurricane #Florence was hit by a #ransomware attack. The #cyberattack has
  21. #Stegware: it's #Malware that uses #steganography techniques to avoid detection
  22. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  23. Report: near-400% increase in crypto-mining malware attacks against iPhones
  24. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  25. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  26. #Shodan, a device search engine, can help identify #ICS security vulnerabilities. Learn more about how Shodan works and how it
  27. Octopus malware wraps tentacles around former Telegram users in Central Asia
  28. Mikko didn't put Brain -- the first PC virus -- on his list but he did track down its authors
  29. Line lists cryptocurrency on Bitbox exchange
  30. "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well
  31. You are who you say you are: Establishing digital trust with the blockchain
  32. Now Surfing about your Favourite Celebrities can make you Vulnerable to Virus Attack
  33. Malware Attack Popular Amongst the Hackers, Even though it Dips in Q2 in 2018
  34. Cryptomining attacks against Apple devices increase sharply
  35. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11
  36. Cybercriminals Advertising Godzilla Loader Malware On Dark Web Forums
  37. 685 million users may be affected by the Branch.io service XSS vulnerability
  38. Cryptojacking attacks against iPhone devices increase
  39. Juniper Networks launches multiple solutions for Junos OS vulnerabilities
  40. Most Important Considerations with Malware Analysis Cheats And Tools list
  41. New iPhone Bug Gives Anyone Access to Your Private Photos
  42. Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits

CRIME

  1. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  2. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  3. How to Create Blockchain Applications
  4. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  5. 35 million US voter records available for sale in a hacking forum
  6. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  7. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  8. UK’s MoD Exposed in 37 Security Breaches: Report
  9. Report: near-400% increase in crypto-mining malware attacks against iPhones
  10. Facebook says fewer users affected by data breach
  11. Pentagon data breach puts personal details of 30,000 staff at risk

POLITICS

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  3. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  4. UK’s MoD Exposed in 37 Security Breaches: Report
  5. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  6. Octopus malware wraps tentacles around former Telegram users in Central Asia
  7. "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well