Oct 21, 2018

Threat report for 2018-10-20

DATA BREACH & DATA LOSS

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. If it's only able to leak data at 15 bits per hour, is #NetSpectre a serious threat? Learn more about
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  5. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel

DENIAL-OF-SERVICE

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

MALVERTISING

Nil

PHISHING

Nil

WEB DEFACEMENT

Nil

BOTNET

  1. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

RANSOMWARE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

MALWARE

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  3. Here's how the hack works: Temperatures used in the pulp cooking process begin to vary random intervals. The fluctuations in temperature

EXPLOIT

  1. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub

VULNERABILITY

  1. Oracle Critical Patch Update October 2018 Addressed 301 Flaws Including 47 High-Rated Flaws
  2. Two Critical RCE Bugs Patched in Drupal 7 and 8
  3. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
  4. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  5. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  6. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  7. OpenSSH 7.9 released: fixed bugs
  8. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  9. Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players
  10. Vulnerabilities in telepresence robots allow access to image and video
  11. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems