Threat report for 2018-10-22
DATA BREACH & DATA LOSS
- CMS portal breach exposes 75,000 individuals' records
- New Ethics Guidance for Lawyers from the American Bar Association (ABA) Regarding Data Breach and Cyber-attack
- According to the report, researchers detected 33,568 email addresses of finance departments that had been exposed by third parties. Can
- #NetSpectre leaks data remotely via side-channel attacks. Learn from expert Michael Cobb of @thehairyITdog why data from #microprocessors is not
- Criminals Hijacked Records of 75 000 Users from
- A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
- Enigmatic cyber espionage campaign revives source code from old foe APT1
- 75,000 HealthCare.gov Users Exposed, Personal Information Stolen
- US Indicts Another Russian for Role in Info Warfare Campaign
- What are DMARC records and can they improve email security?
- Anthem in Record $16m HIPAA Settlement
- The Hunt - Our new data breach detection video looks like a Mission Impossible trailer. However, the threats are for
- #NetSpectre exploits speculative execution to leak data remotely via side-channel attacks. Learn how this #SecurityVulnerability affects the #cloud from expert
- The most interesting Internet-connected vehicle hacks on record
- Web Hosting Software VestaCP Server Compromised With DDoS Malware
- Find out how #TLBleed abuses @Intel's HTT chip feature to leak data via TLB
- Are you aware of #Canada's data breach regulations? Get up to speed on the #blog:
DENIAL-OF-SERVICE
- NSA Hacking Tools Used Against Nuke, Aerospace Worlds
- Web Hosting Software VestaCP Server Compromised With DDoS Malware
MALVERTISING
Nil
PHISHING
- Phishing Scheme Leverages Azure Blob Storage and Hurricane Michael
- Strict password policy could prevent credential reuse, paper suggests
- Natural Disaster Related Phishing Scam Abusing Microsoft Azure to Steal login Credentials & Credit Card Numbers
WEB DEFACEMENT
- Saudi Future Investment Initiative website defaced by the hackers
- Hackers Deface Website of Saudi Investment Forum
BOTNET
- The Russian built #VPNFilter #botnet was taken down by the @FBI after over 500,000 routers were infected. However, VPNFilter is
RANSOMWARE
- Gamma ransomware compromises data on 16,000 patients at California hernia institute
- Ransomware: A cheat sheet for professionals
- The latest variant of Satan ransomware is spreading in the wild
CRYPTOMINING & CRYPTOCURRENCIES
- Blockchain Security and Privacy
- Rambus Vaultify Trade: Secure transaction and storage of crypto assets on blockchain
- .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
- iCloud Hacker Wants $175,000 Ransom to Be Paid In Bitcoin (BTC)
- Trade.io loses $7.5Mil worth of cryptocurrency in mysterious cold wallet hack
- Introducing Infura: Connecting DApps With Ethereum Without Setting up Ethereum Nodes
- Business-minded hackers are testing blockchain technologies to secure their illegal operations. Here's what enterprises can learn from them:
- India’s First Cryptocurrency ATM To Buy and Sell Cryptocurrencies
MALWARE
- How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
- US Tops Global Malware C2 Distribution
- Signal Upgrade Process Leaves Unencrypted Messages on Disk
- .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
- The boom of fileless malware attacks: How can we fight it?
- Octopus Malware
- Maker of LuminosityLink RAT gets 30 months in the clink
- Web Hosting Software VestaCP Server Compromised With DDoS Malware
- Adding the EICAR string to your name as part of the visitor self-registration process is a bit of a faux
EXPLOIT
- Apple Voiceover Exploit Allows Attackers Access to Ios Devices
VULNERABILITY
- Cisco, F5 Networks Investigate libssh Vulnerability Impact
- How to detect hardware-based server bugs
- Flaw in Media Library Impacts VLC, Other Software
- Libssh CVE-2018-10933 Scanners & Exploits Released - Apply Updates Now
- Recent Branch.io Patch Creates New XSS Flaw
- Critical Bug Impacts Live555 Media Streaming Libraries
- A newly disclosed #libSSH vulnerability could allow an attacker #AdminAccess to a server with little effort. By @MT_Heller
- Zero-day jQuery plugin vulnerability exploited for 3 years
- CVE-2018-4013: LIVE555 streaming media RTSP Server Remote Code Execution Vulnerability
- Popular website plugin harboured a serious 0-day for years
- A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
- It's OK, I'm verified - Libssh flaw allows attackers to bypass server authentication
- Repairnator bot finds software bugs, successfully submits patches
- Drupal Patched Critical RCE Vulnerabilities In Drupal 7 and 8
- FreeRTOS flaws expose millions of IoT devices to cyber attacks
- The .@iDefense Vulnerability Contributor Program (VCP) bug-bounty initiative continues to attract top contributors. Join them by submitting your 0-day for
- Critical vulnerabilities on FreeRTOS expose many systems to attacks
- WebLogic Remote Code Execution Vulnerability(CVE-2018-3245) Threat Alert
- MPlayer and VLC media player affected by critical flaw CVE-2018-4013
- Remote Code Execution Flaws Found in FreeRTOS - Popular OS for Embedded Systems
- Why does Windows 10 have many bugs?