Sector brief for 2018-10-24
HEALTHCARE
- US government medical website was hacked that 75,000 personal data was stolen
- Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
- Drupal Remote Code Execution Vulnerability Threat Alert
TRANSPORT
- CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
- Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
- Securing Blockchain with Privileged Access Management
BANKING & FINANCE
- Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
- Magecart hackers change tactic and target vulnerable Magento extensions
- Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
- FlawedAmmyy Remote Access Trojan
- Meet Cryptojacking, the (not so) new kid on the block
- Magecart Hackers Now Targeting Vulnerable Magento Extensions
- sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
- Exploit kits: fall 2018 review
- Mac malware intercepts encrypted web traffic for ad injection
- Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
- Phishing for knowledge
- Magecart Attackers Exploit Magento Zero-Days
- The risk to OT networks is real, and it’s dangerous for business leaders to ignore
- Beyond Your Bank Account: Ten Astounding Finds Uncovered by Financial Malware
- Russian Government-owned research institute linked to Triton attacks
- Drupal Remote Code Execution Vulnerability Threat Alert
- China asks blockchain-based service providers to control user information
- A Digital Currency for Everyone: 5 Easy Way Steps to Follow for Buying Bitcoin
INFORMATION & TELECOMMUNICATION
- Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
- Exploit for New Windows Zero-Day Published on Twitter
- Meet Cryptojacking, the (not so) new kid on the block
- Another Windows 0-day flaw has been published on Twitter
- Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
- SandboxEscaper expert is back and disclosed a new Windows Zero-Day
- [SingCERT] Alert on Drupal Critical Vulnerabilities
- A Windows 0day vulnerability was made public on Twitter
- New Microsoft Windows Zero-Day Dropped on Twitter, Micropatch Available
- Twitter User Discloses Second Microsoft Zero-Day
- Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
- Need help managing supply chain risks?
In this week's ShadowTalk episode, the team breaks it down into hardware, software
- Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
- Phishing for knowledge
- Magecart Attackers Exploit Magento Zero-Days
- Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
- Good initiative. Would be even better if you would pay bounties for the bugs, too.
- ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
- Office 365 for Business - from May to September - has been Recorded Lowest Phish Miss Rate Versus Rivals
- Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
- China asks blockchain-based service providers to control user information
- Hacker Discloses New Windows Zero-Day Exploit On Twitter
- NETSCOUT Takes Internet Scale Threat Protection to the Edge
FOOD
Nil
WATER
Nil
ENERGY
- New Malware Targets Industrial Control Systems
- Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
- Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
- Drupal Remote Code Execution Vulnerability Threat Alert
GOVERNMENT & PUBLIC SERVICE
- Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
- Federal Legislation Enables Consumers to Obtain Security Freezes on Credit Reports Free of Charge
- Yahoo to pay up to $85m to settle data breach lawsuit
- Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
- US government medical website was hacked that 75,000 personal data was stolen
- Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
- Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
- Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
- Russian Government-owned research institute linked to Triton attacks
- Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
- China asks blockchain-based service providers to control user information