Nov 21, 2018

Daily brief for 2018-11-20

ASIA

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  3. Malvertising in Apple Pay Targets iPhone Users
  4. Kaspersky Security Bulletin: Threat Predictions for 2019
  5. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents

WORLD

  1. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  2. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  3. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  4. Voxox leak: Millions of SMS messages exposed
  5. Russia’s Elite Hackers May Have New Phishing Tricks
  6. Web skimmers compete in Umbro Brasil hack
  7. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  8. Government Agencies and Think Tanks attacked, APT29 suspected
  9. An Introduction to Magecart
  10. Hackers Linked to Russia Impersonate US Officials
  11. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  12. Russian hackers are trying out this new malware against US and European targets
  13. TEMP.Periscope Spearphishing
  14. Russian hackers are trying out this new malware against US and European targets
  15. Russian APT activity is resurgent, researchers say
  16. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  17. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  18. Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America
  19. Zscaler ThreatLabZ Phishing Roundup
  20. Dutch audit finds Microsoft Office leaks confidential data
  21. Kaspersky Security Bulletin: Threat Predictions for 2019
  22. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group
  23. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  24. Confiant spots major malvertising attack
  25. Google, Target Hit by Twitter Bitcoin Scam Account Hacks
  26. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

ATTACKS

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. Gmail Glitch Enables Anonymous Messages in Phishing Attacks
  3. jQuery File Upload Disclosure Due Diligence
  4. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  5. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  6. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  7. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  8. Voxox leak: Millions of SMS messages exposed
  9. Russia’s Elite Hackers May Have New Phishing Tricks
  10. Second WordPress hacking campaign underway, this one targeting AMP for WP plugin
  11. Vision Direct Reveals Data Breach
  12. Malvertising in Apple Pay Targets iPhone Users
  13. Instagram glitch exposed some user passwords
  14. OSIsoft Warns Employees, Contractors of Data Breach
  15. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  16. TEMP.Periscope Spearphishing
  17. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  18. OceanLotus: New watering hole attack in Southeast Asia
  19. OceanLotus: New watering hole attack in Southeast Asia
  20. tRat: New Modular RAT Appears in Multiple Email Campaigns
  21. Emotet Campaigns Persist, Utilize Updated Tactics and Techniques
  22. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  23. AWS moves to curb S3 data leaks, but Chris Vickery is doubtful
  24. TalkTalk hackers jailed for role in £77m data breach
  25. CarBlues – Bluetooth Vehicle Hack Exploit Affects Millions Of Vehicles Exposing Users PII
  26. Zscaler ThreatLabZ Phishing Roundup
  27. 2018 holiday travel period expected to be the busiest travel season on record
  28. Vision Direct 'fesses up to hack that exposed customer names, payment cards
  29. A little phishing knowledge may be a dangerous thing
  30. Dutch audit finds Microsoft Office leaks confidential data
  31. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group
  32. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  33. Confiant spots major malvertising attack
  34. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

THREATS

  1. Instagram bug exposes user passwords
  2. Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS
  3. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  4. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  5. Flash Player Type Confusion Critical Vulnerability, Another Reason Not to Use It
  6. Down But Not Out, WannaCry Malware Continues to Infect Unpatched Windows PCs
  7. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  8. 560,000 Duped Into Installing Android Malware in the Form of Fake Driving Games
  9. Flash Player Update Patches Disclosed Code Execution Flaw
  10. Attackers Target Drupal Web Servers with Chained Vulnerabilities
  11. DirtyCOW Is Back In Backdoor Attack Targeting Drupal Web Servers
  12. Inserted Malicious URLs within Office Documents’ Embedded Videos
  13. Russian hackers are trying out this new malware against US and European targets
  14. Russian hackers are trying out this new malware against US and European targets
  15. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  16. WordPress GDPR Plug-in Contains Privilege Escalation Flaw
  17. tRat: New Modular RAT Appears in Multiple Email Campaigns
  18. Dharma Ransomware Variant Discovered
  19. Hackers Exploit Vulnerability in WP GDPR Compliance Plugin – Update Now
  20. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  21. For Smbs Ransomware Attacks still the Greatest Online Threat
  22. Almost 50 Percent of 2018 Vulnerabilities Can Be Exploited Remotely
  23. Targeted ransomware attacks on the rise in 2018, NCSC warns
  24. TP-Link fixes 2 Remote Code Execution flaws in TL-R600VPN SOHO Router and other issues
  25. Raft of flaws discovered in MiSafes child-monitoring devices
  26. Scumbags cram Make-A-Wish website with coin-mining malware
  27. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  28. Microsoft Releases Azure Blockchain Development Kit
  29. DirtyCOW is back in backdoor attack targeting Drupal Web Servers
  30. Can a D-Link router vulnerability threaten bank customers?
  31. 3 New Code Execution Flaws Discovered in Atlantis Word Processor
  32. Vulnerability Spotlight: Multiple remote code execution vulnerabilities in Atlantis Word Processor
  33. Google Account Hacked for Fake Bitcoin Reward
  34. 2019 Security Predictions – Utilities and Industrial Control Systems Targeted with Ransomware
  35. Google, Target Hit by Twitter Bitcoin Scam Account Hacks
  36. The wiper #malware that briefly disrupted the Winter #Olympics earlier this year appears to be back - now with a
  37. 13 Malicious Apps in Google Play With More than 560,000+ Installs
  38. Apache OpenOffice 4.1.6 release: important bug fixes and security fixes
  39. Almost 50 Percent of 2018 Vulnerabilities Can Be Exploited Remotely
  40. #BluetoothDevices might be at risk after a new #Bluetooth vulnerability was found targeting #firmware or operating system software drivers. Learn

CRIME

  1. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  2. An Introduction to Magecart
  3. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  4. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  5. Zscaler ThreatLabZ Phishing Roundup
  6. Magecart Spies Payment Cards From Retailer Vision Direct
  7. Kaspersky Security Bulletin: Threat Predictions for 2019
  8. Google, Target Hit by Twitter Bitcoin Scam Account Hacks
  9. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

POLITICS

  1. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  2. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  3. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  4. Russia’s Elite Hackers May Have New Phishing Tricks
  5. Web skimmers compete in Umbro Brasil hack
  6. TEMP.Periscope Spearphishing
  7. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  8. Magecart Spies Payment Cards From Retailer Vision Direct
  9. Dutch audit finds Microsoft Office leaks confidential data
  10. Kaspersky Security Bulletin: Threat Predictions for 2019
  11. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents