Nov 22, 2018

Daily brief for 2018-11-21

ASIA

  1. City of Valdez, Alaska admits to paying off ransomware infection
  2. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  3. Adobe issues fix for Flash bug allowing remote code execution
  4. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  5. Amazon UK is notifying a data breach to its customers days before Black Friday
  6. New Pterodo Backdoor Malware Detected By Ukraine
  7. Is Magecart Checking Out Your Secure Online Transactions?
  8. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  9. Phishing Scams Serious Problem for Canada’s Global Affairs
  10. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  11. Malaysia’s largest media company becomes victim of a ransomware attack

WORLD

  1. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  2. A flaw in US Postal Service website exposed data on 60 Million Users
  3. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  4. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  5. Facebook increases rewards for its bug bounty program and facilitate bug submission
  6. Inspiring the Next Generation of Tech Talent
  7. Google Taking Over Health Records Raises Patient Privacy Fears
  8. What Is Windows PowerShell (And Could It Be Malicious)?
  9. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  10. Amazon tech error leaks customers’ email addresses
  11. USPS Site Exposed Data on 60 Million Users
  12. Vision Direct Deals With Customer Data Leak
  13. Amazon suffers data breach days before Black Friday
  14. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  15. Black Friday Phishing Dos and Don’ts
  16. Amazon warns customers it leaked their names and email addresses
  17. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  18. German eID Authentication Flaw Lets You Change Identity
  19. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  20. Amazon UK is notifying a data breach to its customers days before Black Friday
  21. Italian Naval Industry Attacked By MartyMcFly Malware
  22. Sofacy APT unleashes new 'Cannon' trojan
  23. New Pterodo Backdoor Malware Detected By Ukraine
  24. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  25. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  26. White House admits Ivanka Trump used private email for government business
  27. Magecart Black Hats Battle it Out On Infected Site
  28. Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
  29. Is Magecart Checking Out Your Secure Online Transactions?
  30. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  31. Infowars Online Store Got Infected with Card Skimming Malware
  32. Sofacy APT group used a new tool in latest attacks, the Cannon
  33. Phishing Scams Serious Problem for Canada’s Global Affairs
  34. Malaysia’s largest media company becomes victim of a ransomware attack
  35. Russian hackers are conducting more covert attacks on US and European computers
  36. US Department of Justice is investigating Tether for manipulation of market prices
  37. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  38. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  39. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

ATTACKS

  1. Phishing: It's all too easy on mobile devices
  2. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  3. A flaw in US Postal Service website exposed data on 60 Million Users
  4. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  5. Amazon Customer Email Addresses Leaked Because of 'Technical Error'
  6. Google Taking Over Health Records Raises Patient Privacy Fears
  7. Amazon tech error leaks customers’ email addresses
  8. USPS Site Exposed Data on 60 Million Users
  9. Vision Direct Deals With Customer Data Leak
  10. Amazon suffers data breach days before Black Friday
  11. Emotet’s Thanksgiving Campaign Delivers New Recipes for Compromise
  12. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  13. Record Retention
  14. A hacker known as #Tessa88 offered several compromise databases obtained from LinkedIn, MySpace and other companies. Now Recorded Future believes
  15. Black Friday Phishing Dos and Don’ts
  16. The promised integration with #HaveIBeenPwned is expanding in #FirefoxMonitor with new breach alerts when a user visits a recently compromised
  17. Amazon warns customers it leaked their names and email addresses
  18. Amazon leaks users' email addresses due to 'technical error'
  19. High Tail Hall data breach exposes over 400,000 furry fans
  20. Facebook Ads Urge Its Staff To Leak Secrets
  21. Amazon Suffers Data Breach Days Before Black Friday
  22. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  23. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  24. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  25. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  26. Amazon UK is notifying a data breach to its customers days before Black Friday
  27. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  28. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  29. White House admits Ivanka Trump used private email for government business
  30. New OceanLotus watering hole attacks target southeast Asia
  31. #CyberMonday Tip 1: Be careful of phishing scams claiming to be from a package-delivery company with links to tracking information. AVG
  32. .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
  33. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  34. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  35. Amazon Data Leak Exposes Email Addresses Right Before Black Friday
  36. Yikes...#Instagram Accidentally Exposed Some Users' #Passwords In Plaintext
  37. #Gmail Glitch Enables Anonymous Messages in #Phishing Attacks:
  38. APAC consumers want IoT devices, but fear data leaks
  39. Phishing Scams Serious Problem for Canada’s Global Affairs
  40. OUR BLACK FRIDAY DEALS ARE LIVE! Get 50% off from FREEDOME VPN and TOTAL subscriptions with coupon code BLACKFRIDAY. Buy now:
  41. Microsoft now lets you log into Outlook, Skype, Xbox Live without a password
  42. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

THREATS

  1. Pen-test at Dropbox turns up three Apple 0-day bugs
  2. City of Valdez, Alaska admits to paying off ransomware infection
  3. A flaw in US Postal Service website exposed data on 60 Million Users
  4. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  5. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  6. Facebook increases rewards for its bug bounty program and facilitate bug submission
  7. What Is Windows PowerShell (And Could It Be Malicious)?
  8. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  9. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  10. Mirai Used as Payload in Hadoop YARN Vulnerability
  11. Facebook entices researchers with $40,000 reward for account takeover vulnerabilities
  12. 500K Android users hit with malware, and what to do if you're infected
  13. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  14. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  15. How a Security Test for DropBox Revealed 3 Apple Zero Day Vulnerabilities
  16. Adobe issues fix for Flash bug allowing remote code execution
  17. 13 Malware-Laden Fake Apps on Google Play
  18. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  19. German eID Authentication Flaw Lets You Change Identity
  20. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  21. New vulnerabilities are coming faster than you can fix them
  22. Red Hawk – Open Source Information Gathering and Vulnerability Scanning Tool
  23. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  24. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  25. Italian Naval Industry Attacked By MartyMcFly Malware
  26. Sofacy APT unleashes new 'Cannon' trojan
  27. New Pterodo Backdoor Malware Detected By Ukraine
  28. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  29. Experts found flaws in Dell EMC and VMware Products. Patch them now!
  30. From directory traversal to direct travesty: Crash, hijack, siphon off this TP-Link VPN box via classic exploitable bugs
  31. A @DLink #router vulnerability was used to send banking users to a fake site in order to steal #UserCredentials. Learn
  32. Malicious programs disguised as racing games on Google Play
  33. Adobe plugs critical RCE Flash Player flaw, update ASAP! Exploitation may be imminent
  34. Patches Released for Flaws Affecting Dell EMC, VMware Products
  35. Adobe Fixes Critical Flash Vulnerability with
  36. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  37. Conficker: A 10-year retrospective on a legendary worm
  38. Malware Moves: Attackers Retool for Cryptocurrency Theft
  39. Infowars Online Store Got Infected with Card Skimming Malware
  40. Facebook Increases Rewards for Account Hacking Vulnerabilities
  41. Adobe Flash Player Update Released for Remote Code Execution Vulnerability
  42. New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform Cryptocurrency-Mining & Brute-Force Attack
  43. Facebook Boosts Bug Bounty Payouts for Account Takeover Flaws
  44. Signing and Verifying Ethereum Signatures
  45. Hacker got Rewarded for Discovering a Critical Steam Bug
  46. CVE-2018-15981: Adobe Flash Player Arbitrary Code Execution Vulnerability
  47. Malaysia’s largest media company becomes victim of a ransomware attack
  48. US Department of Justice is investigating Tether for manipulation of market prices
  49. Awake Security uncovers malicious intent across on-premise, IoT and cloud infrastructure
  50. Centreon releases Remote Server functionality for cross-domain monitoring of multi-site IT operations
  51. Fancy Bear APT Uses New Cannon Trojan to Target Government Entities
  52. "Luiz O Pinto" pushed 500,000+ installs of malware via Google Play, in ~1 week.
  53. Uncover virtual hosts of domain with Fierce
  54. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  55. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  56. How to find, is link malicious/URL or not
  57. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

CRIME

  1. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  2. Facebook increases rewards for its bug bounty program and facilitate bug submission
  3. What Is Windows PowerShell (And Could It Be Malicious)?
  4. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  5. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  6. USPS Site Exposed Data on 60 Million Users
  7. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  8. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  9. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  10. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  11. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  12. Is Magecart Checking Out Your Secure Online Transactions?
  13. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  14. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  15. Signing and Verifying Ethereum Signatures
  16. Phishing Scams Serious Problem for Canada’s Global Affairs
  17. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  18. Malaysia’s largest media company becomes victim of a ransomware attack

POLITICS

  1. What Is Windows PowerShell (And Could It Be Malicious)?
  2. USPS Site Exposed Data on 60 Million Users
  3. New Pterodo Backdoor Malware Detected By Ukraine
  4. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  5. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  6. Phishing Scams Serious Problem for Canada’s Global Affairs
  7. Russian hackers are conducting more covert attacks on US and European computers
  8. US Department of Justice is investigating Tether for manipulation of market prices
  9. MageCart Group Sabotages Rival to Ruin Data and Reputation