Daily brief for 2018-11-15
ASIA
- Ransomware Continues to Be Top Threat to Small Companies
- Cloud, China, Generic Malware Top Security Concerns for 2019
- Chinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTs
- Two whitehats receive $60,000 in rewards for successfully finding iOS 12.1 vulnerabilities
- VMware Virtual Machine Escape Vulnerabilities (CVE-2018-6981 and CVE-2018-6982) Threat Alert
- Cisco Stealthwatch Management Console and Unity Express Critical Vulnerabilities Threat Alert
- Ransomware Attack Strikes Media Prima
- WannaCry Still Impacts Thousands of Systems Every Month
- The ABC of the Hong Kong tech scene: A - AI, B - blockchain, C - cloud
WORLD
- Survey Says: Bad PR Due to Data Breach News, Very Bad for Businesses
- Compromising vital infrastructure: air traffic control
- Man Sends Bomb to Cryptopay for Denying a Password Change Request
- Suspected Russian cybercriminal arrested in Bulgaria at U.S. request, lawyer says
- Phishing Attack Causes Breach at Southwest Washington Regional Surgery Center
- RiskIQ’s 2018 Black Friday E-commerce Blacklist: Key Intel for This Year’s Mega Shopping Weekend
- Brazilian Users Under Attack From Metamorfo Banking Trojan
- Today #GroupIB detected a massive phishing campaign sent to Russian banks from a fake email address purporting to belong to
- Report: Microsoft’s enterprise products covertly gather personal data on users
- Massive Data Leaks Keep Happening Because Big Companies Can Afford to Lose Your Data
- Chinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTs
- Skimmed BA and Newegg Customer Card Details Up for Sale
- Two whitehats receive $60,000 in rewards for successfully finding iOS 12.1 vulnerabilities
- InfoWars online store hit by Magecart
- Alex Jones's InfoWars online store hit by Magecart
- Cryptocurrency fraud is the exception, not the rule
- What is the impact of cyber espionage? @MikaSusiEK from Confederation of Finnish Industries EK discusses, how to tackle the growing
- WannaCry Still Impacts Thousands of Systems Every Month
- Data breach at Nordstrom
- 63 new vulnerabilities found in Windows
- My Health Record remains opt-out as Senate passes privacy amendments
ATTACKS
- My Health Record extension highlights lingering security, privacy concerns
- G Suite Adds Advanced Password Controls
- Firefox Now Alerts You of Website Data Breaches While You're Browsing the Web
- Survey Says: Bad PR Due to Data Breach News, Very Bad for Businesses
- Man Sends Bomb to Cryptopay for Denying a Password Change Request
- Firefox warns if the website you're visiting suffered a data breach
- Phishing Attack Causes Breach at Southwest Washington Regional Surgery Center
- 20% of MageCart-compromised merchants get reinfected within days
- 20% of MageCart-compromised merchants get reinfected within days
- 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing [Infographic]:
- Phishing Emails with .COM Extensions Are Hitting Finance Departments
- Today #GroupIB detected a massive phishing campaign sent to Russian banks from a fake email address purporting to belong to
- Report: Microsoft’s enterprise products covertly gather personal data on users
- Massive Data Leaks Keep Happening Because Big Companies Can Afford to Lose Your Data
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
- Phishing fraudsters set their sights on online storage portals
- Law firm uncovers exposed sensitive details about top attorney online. @mazzazone gives the details:
- 'DarkGate' miner, password-stealer could open up world of hurt for Windows users
- #tRat: New modular #RAT appears in multiple email campaigns: http://ow.ly/1nsX50jHzgd via the Proofpoint @threatinsight research team.
- Learn why @Google chose U2F authentication over OTP to eliminate #PhishingEmails from expert Michael Cobb of @thehairyITdog.
- Nordstrom is notifying employees of a data breach that exposed their personal information, including names, Social Security numbers, dates of
- Vade Secure launches IsItPhishing Threat Detection to help SOCs identify phishing URLs
- Data breach at Nordstrom
- My Health Record remains opt-out as Senate passes privacy amendments
- Symantec Honored for its Collaboration With Leading Industry Group to Protect Against Business Email Compromise Scams
- Smashing Security #104: The world’s most evil phishing test, and cyborgs in the workplace
THREATS
- Should Windows Users Worry About Ransomware in 2019?
- Proofpoint: Hackers testing new reconnaissance malware on financial institutions
- A RAT Just Made It in the Global Threat Index’s Top 10
- 500 Percent Increase in macOS/iOS Ransomware Attacks During 1H 2018
- Vulnerability: Emojis can kill Skype for Business
- Ransomware Continues to Be Top Threat to Small Companies
- Ahead of Black Friday, Rash of Malware Families Takes Aim at Holiday Shoppers
- Cyber Crooks Diversify Business with Multi-Intent Malware
- Linux Based Crypto-Mining Malware
- Cloud, China, Generic Malware Top Security Concerns for 2019
- Brazilian Users Under Attack From Metamorfo Banking Trojan
- #WebCache poisoning poses a serious threat to #BrowserSecurity. Learn how #hackers can use unkeyed inputs for malicious intent from expert
- 14 Malware Families Targeting E-Commerce Brands Ahead of Black Friday
- Official Google Twitter account hacked in Bitcoin scam
- IRCTC Free Insurance Bug That Puts Millions of Passenger Data Under Risk
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
- Unpatched Microsoft Word Video Feature Vulnerability is Being Exploited In The Wild
- 7 New Meltdown and Spectre Level Vulnerabilities Discovered that Affected ARM, Intel & AMD CPU’s
- How is the Trezor cryptocurrency online wallet under attack?
- Two whitehats receive $60,000 in rewards for successfully finding iOS 12.1 vulnerabilities
- VMware Virtual Machine Escape Vulnerabilities (CVE-2018-6981 and CVE-2018-6982) Threat Alert
- Cisco Stealthwatch Management Console and Unity Express Critical Vulnerabilities Threat Alert
- #tRat: New modular #RAT appears in multiple email campaigns: http://ow.ly/1nsX50jHzgd via the Proofpoint @threatinsight research team.
- Popular AMP Plugin for WordPress Patches Critical Flaw – Update Now
- Cryptocurrency fraud is the exception, not the rule
- Fake cryptocurrency Wallets Apps on Google Play Steal User Credentials and Mimic as Legitimate Wallets
- Ransomware Attack Strikes Media Prima
- Access Control Acronyms: ACL, RBAC, ABAC, PBAC, RAdAC, and a Dash of CBAC
- Carpet (IT) to Concrete (OT) – The Evolution of Internet-Based Malware
- Is Your Vulnerability Management Program Efficient and Successful?
- Creating and Analyzing a Malicious PDF File with PDF-Parser Tool
- Find vulnerabilities using nikto
- Facebook fixed a new security bug
- 63 new vulnerabilities found in Windows
- I forgot to follow up on this… According to Apple, the process could take up to 7 days. It
- Cryptowerk introduces blockchain-based technology to certify data integrity of digital assets
- The ABC of the Hong Kong tech scene: A - AI, B - blockchain, C - cloud
CRIME
- My Health Record extension highlights lingering security, privacy concerns
- Proofpoint: Hackers testing new reconnaissance malware on financial institutions
- Man Sends Bomb to Cryptopay for Denying a Password Change Request
- Suspected Russian cybercriminal arrested in Bulgaria at U.S. request, lawyer says
- Ransomware Continues to Be Top Threat to Small Companies
- Phishing Attack Causes Breach at Southwest Washington Regional Surgery Center
- RiskIQ’s 2018 Black Friday E-commerce Blacklist: Key Intel for This Year’s Mega Shopping Weekend
- Phishing Emails with .COM Extensions Are Hitting Finance Departments
- Official Google Twitter account hacked in Bitcoin scam
- Chinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTs
- Skimmed BA and Newegg Customer Card Details Up for Sale
- Cryptocurrency fraud is the exception, not the rule
- Symantec Honored for its Collaboration With Leading Industry Group to Protect Against Business Email Compromise Scams
POLITICS
- Compromising vital infrastructure: air traffic control
- Chinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTs
- What is the impact of cyber espionage? @MikaSusiEK from Confederation of Finnish Industries EK discusses, how to tackle the growing
- Facebook fixed a new security bug