Threat report for 2018-10-05
DATA BREACH
- Sales intel firm Apollo data breach exposed more than 200 million contact records
- Fortnite gamers targeted by data theft malware
- Apollo hackers steal info from database of 200M contact
- Security researchers @proofpoint recently uncovered new #DanaBot campaigns.
- GhostDNS hijacking campaign steps up attacks on Brazilians; 100K+ devices compromised
- Smart TV kit featuring Google Home Mini and third-gen Chromecast leaks
- UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
- Experts warns of a new extortion campaign based on the Breach Compilation archive
- Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
- Intel, AMD both claim server speed records
- Samsung predicts a return to record profits in Q3
- New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well.
The campaign attempts to
DENIAL-OF-SERVICE
- Hacked #Fortnite accounts and rent-a-botnet being pushed on Instagram
MALVERTISING
Nothing to report
PHISHING
- Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
- Remove Ursnif Trojan (Purolator Phishing) Scam
- California Is Making It Illegal for Devices to Have Shitty Default Passwords
- Report: The bigger the company, the messier the password practices
- The most commonly used passwords in the world are...
1. 123456
2. password
3. 123456789
4. 12345678
5. 12345
6. qwerty
- Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
- Weak Passwords Banned In California From 2020
- New IoT legislation bans shared default passwords
- US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
- Credential-Phishing Attempts Highest on Tuesdays
- Credential-Phishing Attempts Highest on Tuesdays
- If you're thinking passwords, check out #CyberSauna episode #13:
A Hacker's Take on Cracking & Protecting Your Creds
- FYI: "password" is the 2nd most popular password in the world.
Can you guess the first?
- Facebook Logins Available on the Dark Web for $2.60
- Passware Kit: Forensic software recovers passwords for Bitcoin wallets
WEB DEFACEMENT
Nothing to report
MALWARE
- Ransomware Recovery at the Taxpayers’ Expense
- Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
- Fortnite gamers targeted by data theft malware
- Remove Ursnif Trojan (Purolator Phishing) Scam
- Trojans go after MS Office vulnerabilities and China hacks US hardware
- .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
- Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
- AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
- Danabot Banking Malware Targets U.S. Organizations
- The Virus Bulletin conference returns home: VB2019 to take place in London
- Fileless malware: part deux
- Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
- Hackers fly under the radar for two years after infecting chiropractic clinic with malware
- DanaBot Banking Trojan’s Journey to North America
- Virus Bulletin 2018: Supply chain hacking grows up
- The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
- Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
- Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
- How does FacexWorm malware use Facebook Messenger to spread?
- Malicious remote admin tool seemingly linked to KONNI malware, North Korea
- New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well.
The campaign attempts to
- .@FireEye researches discovered that the group behind #Sanny #malware attacks has made delivery method changes that put users at risk.
- Fake News Domains Spoof UK News Sites
- Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
- Top 5 Viruses of All Time by Security Expert Mikko Hyppönen
- CMake 3.12.3 releases: managing the build process of software
EXPLOIT
- Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
- Advanced Persistent Threat Activity Exploiting Managed Service Providers
VULNERABILITY
- Adobe October Patch Update Fixed 86 Different Security Vulnerabilities
- Sony Smart TV Bug Allows Remote Access, Root Privileges
- Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
- Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
- D-Link Patches RCE Bugs in Wireless Access Point Gear
- VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
- 150 Bugs Found in the Hack the Marine Corps Challenge
- Trojans go after MS Office vulnerabilities and China hacks US hardware
- 150 Bugs Found in the Hack the Marine Corps Challenge
- Most Home Routers Are Full of Vulnerabilities
- Vulnerability Scanning vs. Penetration Testing: What's the Difference?
- Adobe update cleans up 86 bugs in Acrobat and Reader, many critical
- Missing Files, Bugs Reported After Windows 10 October 2018 Update
- Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
- Mozilla Resolves Critical Code Execution Flaw In Thunderbird
- Cisco patches critical flaws in DNA Center and Prime Infrastructure
- Marine Corps bug bounty program finds 150 vulnerabilities
- Mozilla resolves critical code execution flaw in Thunderbird email client
- Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
- D-Link Patches Code Execution, XSS Flaws in Management Tool
- Cisco updates address 36 vulnerabilities, three critical
- Vulnerability Scanning vs. Penetration Testing: What's the Difference?
- #PulseNet: How does an improper #authentication flaw affect it?
- Cisco Released Security Updates & Fixed 37 Vulnerabilities that Affected Cisco Products
- Mozilla Patches Critical Vulnerability in Thunderbird 60.2.1