Oct 1, 2018

Threat report for 2018-09-30

DATA BREACH

  1. Experts comment on Facebook’s 50 million user credential leak
  2. 40 million more likely affected by massive Facebook data leak - Bitdefender
  3. Project Insecurity (@insecurity) researchers discovered certain #livechatsoftware that were leaking personal details of employee at several high-profile sites. Discover how
  4. Telegram Leaks Public & Private IP Address While Making Calls
  5. The United Nations (@UN) accidentally exposed sensitive information on public @trello boards, in the Jira app, and in #GoogleDocs and
  6. 3 GOP senators doxed during Kavanaugh hearing
  7. Uber has agreed to pay more than $140 Million for a data breach settlement

DENIAL-OF-SERVICE

Nothing to report

MALVERTISING

Nothing to report

PHISHING

  1. Chegg forces password reset on 40 million users
  2. Hackers are Selling Social Media Logins & Financial Details On Dark Web starting from £2
  3. USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing

WEB DEFACEMENT

Nothing to report

MALWARE

  1. GANDCRAB 5.0.1 Ransom Virus – How to Remove It and Restore Data
  2. Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
  3. Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
  4. Telegram Leaks Public & Private IP Address While Making Calls
  5. #Android #Trojan: How is data being stolen from #messagingapps?
  6. Docs reveal how Fruitfly Mac spyware initially spread
  7. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  8. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
  9. Security roundup: Facebook, ransomware, UEFI rootkit, Berners-Lee’s plan for new internet
  10. Telegram exposes the IP address during a user call by default
  11. #GoScanSSH: How does this #malware work and differ from others?
  12. Xbash Malware Combines Many Malicious Functions in Worm
  13. Discover how the #VPNFilter #malware works and affects users
  14. Alphabet's Chronicle has given #VirusTotal a makeover. Find out what's in the new VirusTotal Enterprise offering. By @RobWright22
  15. Improving core processes with next-generation mobile productivity solutions can bring power and cost efficiency gains. However, we must not lose
  16. Malware in the Cloud: What You Need to Know
  17. Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware

EXPLOIT

  1. Facebook Ad Targeting Exploits Users’ 2FA Phone Numbers
  2. FBI IC3 warns of cyber attacks exploiting Remote Desktop Protocol (RDP)

VULNERABILITY

  1. Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
  2. Facebook Says Three Different Bugs Are Responsible For The Massive Account Hacks
  3. Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
  4. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  5. Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
  6. #Cisco patches yet another hardcoded credentials flaw, this time in its video surveillance manager appliance; the latest vulnerability is at
  7. Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
  8. Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from
  9. Cisco Multiple Security Vulnerabilities Alert
  10. Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files
  11. A Top Facebook Bug Bounty Hunter Shares Their Insights on the Facebook Breach