Nov 30, 2018

APT report for 2018-11-29

TRANSNATIONAL / UNKNOWN

  1. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions

CHINA

  1. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia

INDIA

Nil

NORTH KOREA

  1. McAfee Labs 2019 Threats Predictions Report
  2. Lazarus Targeting Latin America

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. WannaCry: One year later, is the world ready for another major attack?
  2. First Annual Cyberwarcon
  3. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  4. Pterodo Found On State Authorities' Computers In Ukraine
  5. Beware the Malware-Laden Brexit News
  6. McAfee Labs 2019 Threats Predictions Report

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-29

WINDOWS

  1. Banking Trojan Made in Brazil? A Brief Look
  2. Inside the Google Docs Malicious Network
  3. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  4. XSS Shell- Cross Site Scripting
  5. KingMiner malware hijacks the full power of Windows Server CPUs
  6. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe

LINUX

  1. XSS Shell- Cross Site Scripting

UNIX

Nil

ANDROID

  1. Inside the Google Docs Malicious Network
  2. McAfee Labs 2019 Threats Predictions Report
  3. Several Malicious Apps on Google Play Posing as Voice Messenger Steal User Personal Information
  4. Threat Spotlight: New spear phishing attack gift card scam

IOS

Nil

MACOS

  1. Inside the Google Docs Malicious Network

Threat report for 2018-11-29

DATA BREACH & DATA LOSS

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Dell Forces Password Reset for Online Customers Following Data Breach
  3. Dell remains quiet on attempted data breach
  4. 2.6 Million Atrium Health Patient Records Compromised by Vendor AccuDoc
  5. Iranian duo charged with SamSam ransomware-slinging campaign
  6. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  7. SKY Brasil Exposes 32 Million Customer Records
  8. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  9. Dunkin' Donuts Serves Up Data Breach Alert
  10. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  11. US Indicts Two Iranians for SamSam Campaign Blitz
  12. London-based Urban Massage app leaks data on 300K customers, including sexual misconduct claims
  13. Database breach affects 2.6 million Atrium Health patients
  14. Dell data breach – Dell forces password reset after the incident
  15. Records of 114 Million US Citizen and Companies Exposed Online
  16. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  17. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  18. Dell Resets User Passwords Following Data Breach
  19. Atrium Health Data Breach Affected More than 2 Million Patients
  20. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  21. Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords
  22. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Users Failing Phishing Simulations? That’s ok
  2. Dell Forces Password Reset for Online Customers Following Data Breach
  3. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  4. Office workers beware: Holiday gift card spear phishing attacks on the rise
  5. Blazy – Open Source Modern Login Brute-forcer
  6. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  7. Dell data breach – Dell forces password reset after the incident
  8. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  9. Threat Spotlight: New spear phishing attack gift card scam
  10. How have #phishing campaigns threatened your #EnterpriseSecurity system?

WEB DEFACEMENT

Nil

BOTNET

  1. Anti-Botnet Guide Aims to Tackle Automated Threats
  2. “And once a device is part of a botnet, it leaves them open for future attacks. So users should avoid
  3. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  4. The Justice Department, FBI and several tech and cybersecurity companies have dismantled the #3ve #botnet, and eight individuals have been

RANSOMWARE

  1. A free decryption tool is available for Thanatos ransomware victims
  2. Colorado Agency Targeted in Nationwide Ransomware Scheme
  3. SamSam ransomware actors charged, sanctioned by US government
  4. Iranian duo charged with SamSam ransomware-slinging campaign
  5. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  6. US charges Iranian hackers for SamSam ransomware attacks
  7. US charges Iranian hackers for SamSam ransomware attacks
  8. US indicts two over SamSam ransomware attacks
  9. US Charges Hackers in Multimillion Dollar Ransomware Campaign

CRYPTOMINING & CRYPTOCURRENCIES

  1. AriseBank CEO faces 120 years behind bars over alleged cryptocurrency scam
  2. Hacker takes over JavaScript library, injects malware to steal Bitcoin
  3. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

MALWARE

  1. Rotexy malware morphs into dangerous banking Trojan
  2. Banking Trojan Made in Brazil? A Brief Look
  3. Overall Volume of Thanksgiving Weekend Malware Attacks Lower This Year
  4. Brazilian Financial Malware Spreads Beyond National Boundaries
  5. Indian Police Break Up International Computer Virus Scam
  6. Inside the Google Docs Malicious Network
  7. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  8. Beware the Malware-Laden Brexit News
  9. KingMiner malware hijacks the full power of Windows Server CPUs
  10. Malicious developer creates wormable, fileless variant of njRAT
  11. Brazilian-made bank trojan
  12. READ: The threat actor SNAKEMACKEREL (#FancyBear) leveraged current geopolitical events and #Brexit themed lure documents to deliver first-stage malware
  13. Proofpoint: Hackers testing new reconnaissance #malware on financial institutions.
  14. Beware the Malware-Laden Brexit News https://ubm.io/2Ql2DyP by @ErickaChick
  15. Analysis Report of the XorDDoS Malware Family
  16. Hacker takes over JavaScript library, injects malware to steal Bitcoin
  17. Several Malicious Apps on Google Play Posing as Voice Messenger Steal User Personal Information
  18. Mobile Malware Attacks Increase as Holiday Season Nears
  19. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe

EXPLOIT

  1. Cisco Patches SQL Injection Flaw in Prime License Manager
  2. Hackers can exploit this bug in surveillance cameras to tamper with footage

VULNERABILITY

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. Critical Zoom Flaw Lets Hackers Hijack Conference Meetings
  3. USPS API Security Vulnerabilities Caused by Functional Errors
  4. Cisco Patches SQL Injection Flaw in Prime License Manager
  5. Cisco Patches Critical Bug in License Management Tool
  6. Hackers can exploit this bug in surveillance cameras to tamper with footage
  7. A security hole in a mail preview program may have made the data of 60 million customers vulnerable.
  8. A security researcher notified the @USPS of an #API vulnerability one year ago. But the #USPS website flaw was only
  9. GCHQ: We don't tell tech companies about every software flaw
  10. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  11. Widely Used Web Conference Service Zoom Patches Critical Flaw
  12. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  13. Facebook Increases Bug Bounty Payouts to Improve User Security

Region brief for 2018-11-29

ASIA

  1. Banking Trojan Made in Brazil? A Brief Look
  2. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  3. Indian Police Break Up International Computer Virus Scam
  4. Iranian duo charged with SamSam ransomware-slinging campaign
  5. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  6. US charges Iranian hackers for SamSam ransomware attacks
  7. US charges Iranian hackers for SamSam ransomware attacks
  8. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  9. US Indicts Two Iranians for SamSam Campaign Blitz
  10. Analysis Report of the XorDDoS Malware Family
  11. Lazarus Targeting Latin America
  12. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe

OCEANIA

Nil

NORTH AMERICA

  1. Banking Trojan Made in Brazil? A Brief Look
  2. First Annual Cyberwarcon
  3. Brazilian Financial Malware Spreads Beyond National Boundaries
  4. USPS API Security Vulnerabilities Caused by Functional Errors
  5. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  6. SamSam ransomware actors charged, sanctioned by US government
  7. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  8. US charges Iranian hackers for SamSam ransomware attacks
  9. US charges Iranian hackers for SamSam ransomware attacks
  10. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  11. US indicts two over SamSam ransomware attacks
  12. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  13. XSS Shell- Cross Site Scripting
  14. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  15. US Indicts Two Iranians for SamSam Campaign Blitz
  16. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  17. READ: The threat actor SNAKEMACKEREL (#FancyBear) leveraged current geopolitical events and #Brexit themed lure documents to deliver first-stage malware
  18. Records of 114 Million US Citizen and Companies Exposed Online
  19. McAfee Labs 2019 Threats Predictions Report
  20. Lazarus Targeting Latin America
  21. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  22. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  23. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  24. Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords

SOUTH AMERICA

  1. Banking Trojan Made in Brazil? A Brief Look
  2. Brazilian Financial Malware Spreads Beyond National Boundaries
  3. Brazilian-made bank trojan
  4. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe

EUROPE

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  3. Rotexy malware morphs into dangerous banking Trojan
  4. Banking Trojan Made in Brazil? A Brief Look
  5. First Annual Cyberwarcon
  6. Brazilian Financial Malware Spreads Beyond National Boundaries
  7. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  8. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  9. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  10. Pterodo Found On State Authorities' Computers In Ukraine
  11. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  12. XSS Shell- Cross Site Scripting
  13. GCHQ: We don't tell tech companies about every software flaw
  14. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  15. London-based Urban Massage app leaks data on 300K customers, including sexual misconduct claims
  16. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  17. McAfee Labs 2019 Threats Predictions Report
  18. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  19. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  20. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach

AFRICA

Nil

Sector brief for 2018-11-29

HEALTHCARE

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. 2.6 Million Atrium Health Patient Records Compromised by Vendor AccuDoc
  3. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  4. US Indicts Two Iranians for SamSam Campaign Blitz
  5. Database breach affects 2.6 million Atrium Health patients
  6. McAfee Labs 2019 Threats Predictions Report
  7. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  8. Atrium Health Data Breach Affected More than 2 Million Patients

TRANSPORT

  1. U.S. DoJ charges Iranian duo over SamSam Ransomware activity

BANKING & FINANCE

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Rotexy malware morphs into dangerous banking Trojan
  3. Banking Trojan Made in Brazil? A Brief Look
  4. Brazilian Financial Malware Spreads Beyond National Boundaries
  5. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  6. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  7. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  8. US Indicts Two Iranians for SamSam Campaign Blitz
  9. Brazilian-made bank trojan
  10. Proofpoint: Hackers testing new reconnaissance #malware on financial institutions.
  11. Dell data breach – Dell forces password reset after the incident
  12. McAfee Labs 2019 Threats Predictions Report
  13. Threat Spotlight: New spear phishing attack gift card scam
  14. Lazarus Targeting Latin America
  15. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  16. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  17. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach

INFORMATION & TELECOMMUNICATION

  1. “And once a device is part of a botnet, it leaves them open for future attacks. So users should avoid
  2. A security hole in a mail preview program may have made the data of 60 million customers vulnerable.
  3. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  4. McAfee Labs 2019 Threats Predictions Report
  5. Facebook Increases Bug Bounty Payouts to Improve User Security
  6. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  7. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach

FOOD

Nil

WATER

Nil

ENERGY

  1. Banking Trojan Made in Brazil? A Brief Look

GOVERNMENT & PUBLIC SERVICE

  1. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  2. SamSam ransomware actors charged, sanctioned by US government
  3. Indian Police Break Up International Computer Virus Scam
  4. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  5. McAfee Labs 2019 Threats Predictions Report
  6. Lazarus Targeting Latin America

Daily brief for 2018-11-29

ASIA

  1. Banking Trojan Made in Brazil? A Brief Look
  2. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  3. Indian Police Break Up International Computer Virus Scam
  4. Iranian duo charged with SamSam ransomware-slinging campaign
  5. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  6. US charges Iranian hackers for SamSam ransomware attacks
  7. US charges Iranian hackers for SamSam ransomware attacks
  8. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  9. US Indicts Two Iranians for SamSam Campaign Blitz
  10. Analysis Report of the XorDDoS Malware Family
  11. Lazarus Targeting Latin America
  12. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe

WORLD

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  3. Rotexy malware morphs into dangerous banking Trojan
  4. Banking Trojan Made in Brazil? A Brief Look
  5. First Annual Cyberwarcon
  6. Brazilian Financial Malware Spreads Beyond National Boundaries
  7. USPS API Security Vulnerabilities Caused by Functional Errors
  8. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  9. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  10. SamSam ransomware actors charged, sanctioned by US government
  11. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  12. US charges Iranian hackers for SamSam ransomware attacks
  13. Pterodo Found On State Authorities' Computers In Ukraine
  14. US charges Iranian hackers for SamSam ransomware attacks
  15. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  16. US indicts two over SamSam ransomware attacks
  17. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  18. XSS Shell- Cross Site Scripting
  19. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  20. GCHQ: We don't tell tech companies about every software flaw
  21. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  22. US Indicts Two Iranians for SamSam Campaign Blitz
  23. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  24. Brazilian-made bank trojan
  25. READ: The threat actor SNAKEMACKEREL (#FancyBear) leveraged current geopolitical events and #Brexit themed lure documents to deliver first-stage malware
  26. London-based Urban Massage app leaks data on 300K customers, including sexual misconduct claims
  27. Records of 114 Million US Citizen and Companies Exposed Online
  28. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  29. McAfee Labs 2019 Threats Predictions Report
  30. Lazarus Targeting Latin America
  31. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  32. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  33. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  34. Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords

ATTACKS

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Users Failing Phishing Simulations? That’s ok
  3. Dell Forces Password Reset for Online Customers Following Data Breach
  4. Dell remains quiet on attempted data breach
  5. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  6. 2.6 Million Atrium Health Patient Records Compromised by Vendor AccuDoc
  7. Iranian duo charged with SamSam ransomware-slinging campaign
  8. Office workers beware: Holiday gift card spear phishing attacks on the rise
  9. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  10. Blazy – Open Source Modern Login Brute-forcer
  11. SKY Brasil Exposes 32 Million Customer Records
  12. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  13. Dunkin' Donuts Serves Up Data Breach Alert
  14. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  15. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  16. US Indicts Two Iranians for SamSam Campaign Blitz
  17. London-based Urban Massage app leaks data on 300K customers, including sexual misconduct claims
  18. Database breach affects 2.6 million Atrium Health patients
  19. Dell data breach – Dell forces password reset after the incident
  20. Records of 114 Million US Citizen and Companies Exposed Online
  21. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  22. Threat Spotlight: New spear phishing attack gift card scam
  23. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  24. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  25. Dell Resets User Passwords Following Data Breach
  26. Atrium Health Data Breach Affected More than 2 Million Patients
  27. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  28. Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords
  29. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

THREATS

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. A free decryption tool is available for Thanatos ransomware victims
  3. Rotexy malware morphs into dangerous banking Trojan
  4. Banking Trojan Made in Brazil? A Brief Look
  5. Critical Zoom Flaw Lets Hackers Hijack Conference Meetings
  6. Overall Volume of Thanksgiving Weekend Malware Attacks Lower This Year
  7. Brazilian Financial Malware Spreads Beyond National Boundaries
  8. USPS API Security Vulnerabilities Caused by Functional Errors
  9. Colorado Agency Targeted in Nationwide Ransomware Scheme
  10. Cisco Patches SQL Injection Flaw in Prime License Manager
  11. SamSam ransomware actors charged, sanctioned by US government
  12. Cisco Patches Critical Bug in License Management Tool
  13. Indian Police Break Up International Computer Virus Scam
  14. Hackers can exploit this bug in surveillance cameras to tamper with footage
  15. Iranian duo charged with SamSam ransomware-slinging campaign
  16. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  17. A security hole in a mail preview program may have made the data of 60 million customers vulnerable.
  18. US charges Iranian hackers for SamSam ransomware attacks
  19. Inside the Google Docs Malicious Network
  20. US charges Iranian hackers for SamSam ransomware attacks
  21. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  22. A security researcher notified the @USPS of an #API vulnerability one year ago. But the #USPS website flaw was only
  23. US indicts two over SamSam ransomware attacks
  24. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  25. AriseBank CEO faces 120 years behind bars over alleged cryptocurrency scam
  26. Beware the Malware-Laden Brexit News
  27. KingMiner malware hijacks the full power of Windows Server CPUs
  28. GCHQ: We don't tell tech companies about every software flaw
  29. Malicious developer creates wormable, fileless variant of njRAT
  30. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  31. Brazilian-made bank trojan
  32. READ: The threat actor SNAKEMACKEREL (#FancyBear) leveraged current geopolitical events and #Brexit themed lure documents to deliver first-stage malware
  33. Proofpoint: Hackers testing new reconnaissance #malware on financial institutions.
  34. Beware the Malware-Laden Brexit News https://ubm.io/2Ql2DyP by @ErickaChick
  35. Analysis Report of the XorDDoS Malware Family
  36. Hacker takes over JavaScript library, injects malware to steal Bitcoin
  37. Widely Used Web Conference Service Zoom Patches Critical Flaw
  38. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  39. Several Malicious Apps on Google Play Posing as Voice Messenger Steal User Personal Information
  40. Mobile Malware Attacks Increase as Holiday Season Nears
  41. Facebook Increases Bug Bounty Payouts to Improve User Security
  42. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  43. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

CRIME

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Colorado Agency Targeted in Nationwide Ransomware Scheme
  3. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  4. Indian Police Break Up International Computer Virus Scam
  5. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  6. US indicts two over SamSam ransomware attacks
  7. SKY Brasil Exposes 32 Million Customer Records
  8. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  9. AriseBank CEO faces 120 years behind bars over alleged cryptocurrency scam
  10. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  11. US Indicts Two Iranians for SamSam Campaign Blitz
  12. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  13. McAfee Labs 2019 Threats Predictions Report
  14. Threat Spotlight: New spear phishing attack gift card scam
  15. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  16. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  17. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  18. The Justice Department, FBI and several tech and cybersecurity companies have dismantled the #3ve #botnet, and eight individuals have been

POLITICS

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. First Annual Cyberwarcon
  3. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  4. Pterodo Found On State Authorities' Computers In Ukraine
  5. XSS Shell- Cross Site Scripting
  6. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  7. McAfee Labs 2019 Threats Predictions Report
  8. Threat Spotlight: New spear phishing attack gift card scam
  9. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  10. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach

Nov 27, 2018

APT report for 2018-11-26

TRANSNATIONAL / UNKNOWN

  1. Cyberthreats to financial institutions 2019: overview and predictions

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. Cyberthreats to financial institutions 2019: overview and predictions

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. APT28 Is Using New Variant of Lojax
  2. Recent Attacks on US Entities Attributed to APT29

SERBIA

Nil

UKRAINE

  1. Cyberthreats to financial institutions 2019: overview and predictions

Platform report for 2018-11-26

WINDOWS

  1. Half of all Phishing Sites Now Have the Padlock
  2. Phishing Campaign targeting French Industry

LINUX

  1. Linux Kernel is affected by two DoS vulnerabilities still unpatched
  2. DoS Vulnerabilities Impact Linux Kernel
  3. Experts found a new powerful modular Linux cryptominer

UNIX

Nil

ANDROID

  1. 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
  2. Bypassing and Disabling SSL Pinning on Android to Perform Man-in-the-Middle Attack
  3. Play Store Malware Infects Half a Billion

IOS

  1. 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store

MACOS

  1. OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic

Threat report for 2018-11-26

DATA BREACH & DATA LOSS

  1. Knuddels Flirt App Slapped with Hefty Fine After Data Breach
  2. When Do You Need to Report a Data Breach?
  3. USPS, Amazon Data Leaks Showcase API Weaknesses
  4. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  5. Despite growing concerns about cybersecurity and the number of data breach incidents in the news, many employees still have bad
  6. Trivial Spotify Phishing Campaign Targets Users To Steal Login Credentials
  7. Phishing Campaign targeting French Industry
  8. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  9. German Social Media Provider Fined €20K for Data Breach
  10. No need to compromise freedom for security - Europol audience told
  11. HR Software Firm PageUp Finds No Evidence of Data Theft
  12. Internal negligence to blame for most data breaches involving personal health information
  13. Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
  14. An ongoing phishing campaign is targeting French industry, @FSLabs finds.
  15. Phishing Campaign targeting French Industry
  16. My Health Record opt-out officially extended to January 31

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Holiday Season: Cybercriminals are Phishing All The Way
  2. Half of all Phishing Sites Now Have the Padlock
  3. Easy as APT: Spear phishing highlighted as ongoing threat for 2019
  4. Trivial Spotify Phishing Campaign Targets Users To Steal Login Credentials
  5. Phishing Campaign targeting French Industry
  6. 50% use password managers to store login details
  7. An ongoing phishing campaign is targeting French industry, @FSLabs finds.
  8. Phishing Campaign targeting French Industry
  9. Beware!! Cyber Criminals Launching Serious Phishing Attack that Target Spotify Customers

WEB DEFACEMENT

Nil

BOTNET

  1. Democrats Introduce Bill for Stopping Automated Grinch Bots from Ruining Xmas

RANSOMWARE

  1. Ransomware attack disrupted emergency rooms at Ohio Hospital System
  2. Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
  3. Ransomware Attack Forced Ohio Hospital System to Divert ER Patients
  4. A new ransomware -- dubbed #Thanatos #ransomware -- was found encrypting data but not decrypting it despite victims paying the

CRYPTOMINING & CRYPTOCURRENCIES

  1. Hacker backdoors popular JavaScript library to steal Bitcoin funds
  2. Harberger Taxes on Ethereum
  3. OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic
  4. Cryptocurrency threat predictions for 2019
  5. Crypto Mining Malware Infects Make-A-Wish-Foundation Website
  6. Experts found a new powerful modular Linux cryptominer

MALWARE

  1. Lenovo to Pay $7.3 Million in Settlement for Installing Adware on 800K Notebooks
  2. 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
  3. What is Data Classification? Guidelines and Process
  4. Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
  5. Subscribe to the relaunched Virus Bulletin eNews newsletter
  6. Play Store Malware Infects Half a Billion
  7. Microsoft PowerPoint as Malware Dropper
  8. OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic
  9. Ukrainian Police Nab Suspected RAT-Slinger
  10. Crypto Mining Malware Infects Make-A-Wish-Foundation Website

EXPLOIT

Nil

VULNERABILITY

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. Did UK city council over-react to a vulnerability report in its recycling app or not?
  3. Linux Kernel is affected by two DoS vulnerabilities still unpatched
  4. DoS Vulnerabilities Impact Linux Kernel
  5. Apache Hadoop Spins Cracking Code Injection Vulnerability YARN
  6. Siemens patches major firewall flaw, other vulnerabilities
  7. #Bluetooth devices might be at risk after a new Bluetooth vulnerability was found targeting #firmware and #OperatingSystem software drivers. Learn
  8. U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
  9. Positive Technologies researchers recently found two serious vulnerabilities that target NCR's #ATMs. Learn how a "black box attack" was involved
  10. Discover how a @DLink #router vulnerability targeted a banking site to steal #UserCredentials with expert Judith Myerson.
  11. For recent big data software vulnerabilities, botnets and coin mining are just the beginning
  12. Frost & Sullivan Commends Rapid7 for Capturing Nearly a Quarter Share of the Global Vulnerability Management Market

Region brief for 2018-11-26

ASIA

  1. Half of all Phishing Sites Now Have the Padlock
  2. Cyberthreats to financial institutions 2019: overview and predictions
  3. Ukrainian Police Nab Suspected RAT-Slinger
  4. Crypto Mining Malware Infects Make-A-Wish-Foundation Website

OCEANIA

  1. When Do You Need to Report a Data Breach?
  2. HR Software Firm PageUp Finds No Evidence of Data Theft

NORTH AMERICA

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. When Do You Need to Report a Data Breach?
  3. Democrats Introduce Bill for Stopping Automated Grinch Bots from Ruining Xmas
  4. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  5. Microsoft PowerPoint as Malware Dropper
  6. Recent Attacks on US Entities Attributed to APT29
  7. U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
  8. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  9. Cyberthreats to financial institutions 2019: overview and predictions

SOUTH AMERICA

  1. Crypto Mining Malware Infects Make-A-Wish-Foundation Website

EUROPE

  1. Did UK city council over-react to a vulnerability report in its recycling app or not?
  2. Knuddels Flirt App Slapped with Hefty Fine After Data Breach
  3. Siemens patches major firewall flaw, other vulnerabilities
  4. Recent Attacks on US Entities Attributed to APT29
  5. Phishing Campaign targeting French Industry
  6. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  7. German Social Media Provider Fined €20K for Data Breach
  8. Cyberthreats to financial institutions 2019: overview and predictions
  9. Ukrainian Police Nab Suspected RAT-Slinger
  10. Crypto Mining Malware Infects Make-A-Wish-Foundation Website
  11. Experts found a new powerful modular Linux cryptominer
  12. An ongoing phishing campaign is targeting French industry, @FSLabs finds.
  13. Phishing Campaign targeting French Industry

AFRICA

Nil

Sector brief for 2018-11-26

HEALTHCARE

  1. Ransomware attack disrupted emergency rooms at Ohio Hospital System
  2. Ransomware Attack Forced Ohio Hospital System to Divert ER Patients
  3. Internal negligence to blame for most data breaches involving personal health information

TRANSPORT

  1. Holiday Season: Cybercriminals are Phishing All The Way
  2. Phishing Campaign targeting French Industry

BANKING & FINANCE

  1. What is Data Classification? Guidelines and Process
  2. When Do You Need to Report a Data Breach?
  3. Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
  4. Holiday Season: Cybercriminals are Phishing All The Way
  5. Phishing Campaign targeting French Industry
  6. Cryptocurrency threat predictions for 2019
  7. Cyberthreats to financial institutions 2019: overview and predictions
  8. Discover how a @DLink #router vulnerability targeted a banking site to steal #UserCredentials with expert Judith Myerson.

INFORMATION & TELECOMMUNICATION

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
  3. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  4. Half of all Phishing Sites Now Have the Padlock
  5. Despite growing concerns about cybersecurity and the number of data breach incidents in the news, many employees still have bad
  6. Phishing Campaign targeting French Industry
  7. Cyberthreats to financial institutions 2019: overview and predictions
  8. Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
  9. An ongoing phishing campaign is targeting French industry, @FSLabs finds.

FOOD

Nil

WATER

Nil

ENERGY

  1. Siemens patches major firewall flaw, other vulnerabilities

GOVERNMENT & PUBLIC SERVICE

  1. Did UK city council over-react to a vulnerability report in its recycling app or not?
  2. When Do You Need to Report a Data Breach?
  3. Recent Attacks on US Entities Attributed to APT29
  4. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  5. Cyberthreats to financial institutions 2019: overview and predictions
  6. Ukrainian Police Nab Suspected RAT-Slinger
  7. Crypto Mining Malware Infects Make-A-Wish-Foundation Website

Daily brief for 2018-11-26

ASIA

  1. Half of all Phishing Sites Now Have the Padlock
  2. Cyberthreats to financial institutions 2019: overview and predictions
  3. Ukrainian Police Nab Suspected RAT-Slinger
  4. Crypto Mining Malware Infects Make-A-Wish-Foundation Website

WORLD

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. Did UK city council over-react to a vulnerability report in its recycling app or not?
  3. Knuddels Flirt App Slapped with Hefty Fine After Data Breach
  4. When Do You Need to Report a Data Breach?
  5. Democrats Introduce Bill for Stopping Automated Grinch Bots from Ruining Xmas
  6. Siemens patches major firewall flaw, other vulnerabilities
  7. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  8. Microsoft PowerPoint as Malware Dropper
  9. Recent Attacks on US Entities Attributed to APT29
  10. U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
  11. Phishing Campaign targeting French Industry
  12. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  13. German Social Media Provider Fined €20K for Data Breach
  14. Cyberthreats to financial institutions 2019: overview and predictions
  15. Ukrainian Police Nab Suspected RAT-Slinger
  16. Crypto Mining Malware Infects Make-A-Wish-Foundation Website
  17. Experts found a new powerful modular Linux cryptominer
  18. HR Software Firm PageUp Finds No Evidence of Data Theft
  19. An ongoing phishing campaign is targeting French industry, @FSLabs finds.
  20. Phishing Campaign targeting French Industry

ATTACKS

  1. Knuddels Flirt App Slapped with Hefty Fine After Data Breach
  2. When Do You Need to Report a Data Breach?
  3. USPS, Amazon Data Leaks Showcase API Weaknesses
  4. Holiday Season: Cybercriminals are Phishing All The Way
  5. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  6. Half of all Phishing Sites Now Have the Padlock
  7. Easy as APT: Spear phishing highlighted as ongoing threat for 2019
  8. Despite growing concerns about cybersecurity and the number of data breach incidents in the news, many employees still have bad
  9. Trivial Spotify Phishing Campaign Targets Users To Steal Login Credentials
  10. Phishing Campaign targeting French Industry
  11. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  12. German Social Media Provider Fined €20K for Data Breach
  13. No need to compromise freedom for security - Europol audience told
  14. 50% use password managers to store login details
  15. HR Software Firm PageUp Finds No Evidence of Data Theft
  16. Internal negligence to blame for most data breaches involving personal health information
  17. Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
  18. An ongoing phishing campaign is targeting French industry, @FSLabs finds.
  19. Phishing Campaign targeting French Industry
  20. Beware!! Cyber Criminals Launching Serious Phishing Attack that Target Spotify Customers
  21. My Health Record opt-out officially extended to January 31

THREATS

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. Did UK city council over-react to a vulnerability report in its recycling app or not?
  3. Ransomware attack disrupted emergency rooms at Ohio Hospital System
  4. Lenovo to Pay $7.3 Million in Settlement for Installing Adware on 800K Notebooks
  5. 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
  6. Hacker backdoors popular JavaScript library to steal Bitcoin funds
  7. What is Data Classification? Guidelines and Process
  8. Linux Kernel is affected by two DoS vulnerabilities still unpatched
  9. Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
  10. Harberger Taxes on Ethereum
  11. DoS Vulnerabilities Impact Linux Kernel
  12. Subscribe to the relaunched Virus Bulletin eNews newsletter
  13. Apache Hadoop Spins Cracking Code Injection Vulnerability YARN
  14. Siemens patches major firewall flaw, other vulnerabilities
  15. Play Store Malware Infects Half a Billion
  16. Microsoft PowerPoint as Malware Dropper
  17. #Bluetooth devices might be at risk after a new Bluetooth vulnerability was found targeting #firmware and #OperatingSystem software drivers. Learn
  18. U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
  19. Ransomware Attack Forced Ohio Hospital System to Divert ER Patients
  20. Positive Technologies researchers recently found two serious vulnerabilities that target NCR's #ATMs. Learn how a "black box attack" was involved
  21. OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic
  22. Cryptocurrency threat predictions for 2019
  23. Ukrainian Police Nab Suspected RAT-Slinger
  24. Crypto Mining Malware Infects Make-A-Wish-Foundation Website
  25. Experts found a new powerful modular Linux cryptominer
  26. A new ransomware -- dubbed #Thanatos #ransomware -- was found encrypting data but not decrypting it despite victims paying the
  27. Discover how a @DLink #router vulnerability targeted a banking site to steal #UserCredentials with expert Judith Myerson.
  28. For recent big data software vulnerabilities, botnets and coin mining are just the beginning
  29. Frost & Sullivan Commends Rapid7 for Capturing Nearly a Quarter Share of the Global Vulnerability Management Market

CRIME

  1. When Do You Need to Report a Data Breach?
  2. Holiday Season: Cybercriminals are Phishing All The Way
  3. Half of all Phishing Sites Now Have the Padlock
  4. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  5. Cryptocurrency threat predictions for 2019
  6. Cyberthreats to financial institutions 2019: overview and predictions
  7. Ukrainian Police Nab Suspected RAT-Slinger
  8. Experts found a new powerful modular Linux cryptominer
  9. HR Software Firm PageUp Finds No Evidence of Data Theft
  10. Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual

POLITICS

  1. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  2. Cryptocurrency threat predictions for 2019
  3. Ukrainian Police Nab Suspected RAT-Slinger