Oct 25, 2018

Sector brief for 2018-10-24

HEALTHCARE

  1. US government medical website was hacked that 75,000 personal data was stolen
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. Drupal Remote Code Execution Vulnerability Threat Alert

TRANSPORT

  1. CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. Securing Blockchain with Privileged Access Management

BANKING & FINANCE

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Magecart hackers change tactic and target vulnerable Magento extensions
  3. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  4. FlawedAmmyy Remote Access Trojan
  5. Meet Cryptojacking, the (not so) new kid on the block
  6. Magecart Hackers Now Targeting Vulnerable Magento Extensions
  7. sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
  8. Exploit kits: fall 2018 review
  9. Mac malware intercepts encrypted web traffic for ad injection
  10. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  11. Phishing for knowledge
  12. Magecart Attackers Exploit Magento Zero-Days
  13. The risk to OT networks is real, and it’s dangerous for business leaders to ignore
  14. Beyond Your Bank Account: Ten Astounding Finds Uncovered by Financial Malware
  15. Russian Government-owned research institute linked to Triton attacks
  16. Drupal Remote Code Execution Vulnerability Threat Alert
  17. China asks blockchain-based service providers to control user information
  18. A Digital Currency for Everyone: 5 Easy Way Steps to Follow for Buying Bitcoin

INFORMATION & TELECOMMUNICATION

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Exploit for New Windows Zero-Day Published on Twitter
  3. Meet Cryptojacking, the (not so) new kid on the block
  4. Another Windows 0-day flaw has been published on Twitter
  5. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  6. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  7. [SingCERT] Alert on Drupal Critical Vulnerabilities
  8. A Windows 0day vulnerability was made public on Twitter
  9. New Microsoft Windows Zero-Day Dropped on Twitter, Micropatch Available
  10. Twitter User Discloses Second Microsoft Zero-Day
  11. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  12. Need help managing supply chain risks? In this week's ShadowTalk episode, the team breaks it down into hardware, software
  13. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  14. Phishing for knowledge
  15. Magecart Attackers Exploit Magento Zero-Days
  16. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  17. Good initiative. Would be even better if you would pay bounties for the bugs, too.
  18. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  19. Office 365 for Business - from May to September - has been Recorded Lowest Phish Miss Rate Versus Rivals
  20. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  21. China asks blockchain-based service providers to control user information
  22. Hacker Discloses New Windows Zero-Day Exploit On Twitter
  23. NETSCOUT Takes Internet Scale Threat Protection to the Edge

FOOD

Nil

WATER

Nil

ENERGY

  1. New Malware Targets Industrial Control Systems
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  4. Drupal Remote Code Execution Vulnerability Threat Alert

GOVERNMENT & PUBLIC SERVICE

  1. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  2. Federal Legislation Enables Consumers to Obtain Security Freezes on Credit Reports Free of Charge
  3. Yahoo to pay up to $85m to settle data breach lawsuit
  4. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  5. US government medical website was hacked that 75,000 personal data was stolen
  6. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  7. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  8. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  9. Russian Government-owned research institute linked to Triton attacks
  10. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  11. China asks blockchain-based service providers to control user information