Threat report for 2018-10-03
DATA BREACH
- FakeSpy Is Back as Part of New SmiShing Campaign, Adds New Features
- The ultimate fallout from the Facebook data breach could be massive
- Gwinnett Medical Center Investigates Possible Data Breach
- Gwinnett Medical Center investigates possible data breach
- GhostDNS hijacking campaign steps up attacks on Brazilians; 100K+ devices compromised
- #DanaBot Observed in Large Campaign Targeting U.S. Organizations
- Ransomware operators breach 40.000+ records from Fetal Diagnostic Institute of the Pacific
- Facebook Reveals That Trio of Bugs Led to Data Breach
- Vietnam-Born Worker in U.S Intelligence Ordered Prison over Data Theft and Leakage
- New Danabot Banking Malware campaign now targets banks in the U.S.
- Zoho domains central to keylogger, data theft campaigns worldwide
- 100,000-Plus Home Routers Hijacked in Campaign to Steal Banking Credentials
- .@Lookout’s @VijayaKaza is at @FedNewsRadio’s studio recording with @gschumm!
- How Ashley Madison Recovered From Its Massive Data Breach
- An extremely high number of keylogger #phishing campaigns have been seen tied to the Zoho online office suite software:
- New Betabot campaign under the microscope
- CyberSecurity Asean security alert on A Vulnerability in Microsoft Windows JET Database Engine Could Allow for Remote Code Execution
- Facebook faces legal actions after data breach
- Norton by Symantec Urges Consumers to Help Protect Their Personal Data
- DanaBot Observed in Large Campaign Targeting U.S. Organizations
DENIAL-OF-SERVICE
- Torii Botnet - Definitely Not a Mirai Wannabe
- Instagram Used as Marketplace to Sell Stolen Fortnite Accounts and Botnets
- Hacked Fortnite accounts and rent-a-botnet being pushed on Instagram
- Hackers Use Instagram For Selling Stolen ‘Fortnite’ Accounts And Botnets
- Enormous botnet used to hijack traffic destined for Brazilian banks
- BYOB – Build Your Own Botnet
- The @activereach guide to #DDoS, is aimed at technically aware business people who do not necessarily have a background in
MALVERTISING
Nothing to report
PHISHING
- Phishing 101: Protection for Everyone
- How to use the Firefox Master Password
- Phishing gets more complex as decoy PDF pops up with Microsoft-issued SSL certificate
- LastPass study shines new light on global password security practices
- Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
- Phishing Attack Impersonates Law Firm
- Phishing Attack Uses Azure Blob Storage to Impersonate Microsoft
- Phishing Attack Impersonates Law Firm
- Password-sharing is still prevalent in the workplace – although 45 percent of businesses do now use multifactor authentication:
- GhostDNS hijacked 100,000 router traffic directed to phishing sites
- Dark Web Malware Builder Allow Attackers To Create Malware That Steals Passwords & Credit Card Data
- An extremely high number of keylogger #phishing campaigns have been seen tied to the Zoho online office suite software:
- What is the future of authentication? Hint: It’s not passwords, passphrases or MFA
- 100,000 routers hijacked by GhostDNS, traffic directed to phishing sites
WEB DEFACEMENT
- Hacker Faces Jail Time After Defacing West Point, NYC Sites
- Hacker Defacing 11,000 US Websites Faces 10 Years behind Bars
- Hacktivist pleads guilty to defacing websites for NYC comptroller, Combating Terrorism Center
- Hacker faces jail time after defacing US military academy, NYC sites
MALWARE
- Windows 10 October 2018 Update refines ransomware protection
- Virus Bulletin 2018: macOS Flaw Allows Attackers to Hijack Installed Apps
- Virus Bulletin 2018: Microsoft’s Lambert on How Cloud is Changing Security
- Malware Outbreak Causes Disruptions, Closures at Canadian Restaurant Chain
- Betabot - An Example of Cheap Modern Malware Sophistication
- Instagram accounts frozen with ransomware | Avast
- Instagram accounts frozen with ransomware | Avast
- Did you know that 1 in 131 emails contains malware? In honor of #NCSAM, secure your spot for #RiskSec, expand
- New KONNI Malware Attacking Eurasia and Southeast Asia
- Google Taking New Steps To Prevent Malicious Chrome Extensions
- 3 types of attacks with ransomware: Cyber-theft, extortion, and sabotage
- Network Outage at Some Recipe Unlimited Locations Caused by Malware
- Labeless Part 6: How to Resolve Obfuscated API Calls in the Ngioweb Proxy Malware
- Banking trojans, not #ransomware, are the biggest threat to the enterprise now.
- Labeless Part 5: How to Decrypt Strings in Boleto Banking Malware Without Reconstructing Decryption Algorithm.
- Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
- Ransomware operators breach 40.000+ records from Fetal Diagnostic Institute of the Pacific
- New Danabot Banking Malware campaign now targets banks in the U.S.
- Zoho domains central to keylogger, data theft campaigns worldwide
- Recipe Unlimited denies ransomware attack, despite alleged ransom note
- Dark Web Malware Builder Allow Attackers To Create Malware That Steals Passwords & Credit Card Data
- IDG Contributor Network: Will your company be valued by its price-to-data ratio?
- Researchers from @alienvault found a new #cryptocurrency mining malware -- dubbed #MassMiner -- that infects systems across the web. Learn
- Introducing...
THE HUNT: A Cyber Attack in the Process Industry
- Researchers associated the recently discovered NOKKI Malware to North Korean APT
- Changes to #Sanny #malware delivery method attacks were recently discovered by @FireEye researches. Learn who is at risk and how
- Ransomware Hits Port of San Diego
- An extremely high number of keylogger #phishing campaigns have been seen tied to the Zoho online office suite software:
- Z-LAB Report – Analyzing the GandCrab v5 ransomware
- Preventing and Detecting Malicious Insiders
- In 1999, AV-TEST reported that there were 98,428 total unique malware samples.
Today, AV-TEST registers over 350,000 new pieces of
- Cheap Android Phones and Poor Quality Control Leads to Malware Surprise
- DanaBot Observed in Large Campaign Targeting U.S. Organizations
EXPLOIT
- TA18-276B: Advanced Persistent Threat Activity Exploiting Managed Service Providers
- TA18-276A: Using Rigorous Credential Control to Mitigate Trusted Network Exploitation
- Heipparallaa! Uudessa jaksossamme sivuutamme ajankohtaiset aiheet ja keskitymme puhumaan @japi999 ja @ekoivune kanssa tietoturva-asiantuntijuudesta. Bonusvieraana tällä kertaa OpSecin sijaan @Larppa1337!
VULNERABILITY
- Virus Bulletin 2018: macOS Flaw Allows Attackers to Hijack Installed Apps
- [SingCERT] Alert on 47 Critical Vulnerabilities in Adobe Acrobat and Adobe Reader
- Mozilla Firefox Releases 62.0.3 & Security Updates for 2 High Critical Vulnerabilities
- Women in Information Security: Pam Armstrong
- Vulnerability Spotlight: Google PDFium JBIG2 Image ComposeToOpt2WithRect Information Disclosure Vulnerability
- Foxit patches 118 vulnerabilities in popular PDF reader
- Experts found 9 NAS flaws that expose LenovoEMC, Iomega Devices to hack
- The one serious MacBook Pro security flaw that nobody is talking about
- Update now: Adobe fixes 85 serious flaws in Acrobat and Reader
- 18 Vulnerabilities Found in Foxit PDF Reader
- 18 Vulnerabilities Found in Foxit PDF Reader
- Marine Corps bug bounty program finds 150 vulnerabilities
- TP-Link router vulnerable to remote takeover flaw
- Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
- Adobe update cleans up 86 bugs in Acrobat and Reader, many critical
- Facebook Reveals That Trio of Bugs Led to Data Breach
- TP-Link router vulnerable to remote takeover flaw
- Adobe update cleans up 86 bugs in Acrobat and Reader, many critical
- The Intel Management Engine exposes a new vulnerability
- How an improper #authentication flaw affects
- Vulnerability Spotlight: Google PDFium JBIG2 Image ComposeToOpt2WithRect Information Disclosure Vulnerability
- CyberSecurity Asean security alert on A Vulnerability in Microsoft Windows JET Database Engine Could Allow for Remote Code Execution
- Vulnerabilities expose Iomega and LenovoEMC NAS devices to attacks
- Estonia sues Gemalto for €152M for the flaws in the identification cards issued by the company
- Scanning for OWASP Top 10 Vulnerabilities with Metasploit for the Web(w3af)
- Mozilla Firefox 62.0.3 releases: Fixed hangs on macOS Mojave & security bugs
- Apple iOS 12 Texting Bug Sends Messages To Wrong Contacts