Nov 15, 2018

Sector brief for 2018-11-14

HEALTHCARE

  1. CVE-2018-15961: Adobe ColdFusion Flaw exploited in attacks in the wild
  2. Australian Senate extends My Health Record opt-out period
  3. Healthcare.gov Health Data Breach Exposes Personal Data
  4. Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware

TRANSPORT

  1. A 100k routers around the world are on the botnet to conduct emails spam

BANKING & FINANCE

  1. FlawedAmmy, the Only RAT in CheckPoint’s Global Threat Index 2018 List
  2. 1,000 Bitcoins Ransom Asked from Media Prima After Successful Ransomware Attack
  3. Weekly Threat Briefing: Adobe ColdFusion Servers Under Attack from APT Group
  4. Magecart Cybercrime Groups Harvest Payment Card Data
  5. How Threat Intelligence Prioritizes Risk in Vulnerability Management
  6. Monitoring file output for malicious code 'could have stopped BA attack more quickly'
  7. Operation FastCash
  8. Magecart- The Card-Skimming Group and Its Many Faces
  9. Infowars Store Affected by Magecart Credit Card Stealing Hack
  10. Alex Jones’ Infowars store was infected with credit card skimming software
  11. BDO Unibank Warned its Customers to Remain Beware from New Phishing Scheme
  12. Healthcare.gov Health Data Breach Exposes Personal Data
  13. Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware

INFORMATION & TELECOMMUNICATION

  1. Bitcoin Giveaway Scam Balloons, with Google the Latest Victim
  2. 1,000 Bitcoins Ransom Asked from Media Prima After Successful Ransomware Attack
  3. Weekly Threat Briefing: Adobe ColdFusion Servers Under Attack from APT Group
  4. Google services collapsed due to BGP leak
  5. Google services collapsed due to BGP leak
  6. Facebook vulnerability could have leaked your private information – again
  7. How Threat Intelligence Prioritizes Risk in Vulnerability Management
  8. Business Email Compromise - When You Don’t Need to Phish:
  9. Is it time to change your password? Check out this list of the 25 worst passwords for 2018 and make
  10. A Large Retailer Responds to #DDoS Extortion: To Pay or Not to Pay?
  11. Microsoft covertly collects personal data from enterprise Office ProPlus users
  12. Facebook reportedly fixes search bug that could have threatened user privacy
  13. Beers with Talos Ep. #41: Sex, money and malware
  14. A #bug allowing websites to capture private data from Facebook users through Chrome has been discovered:
  15. Cyber security is a process: Prevent, Detect, Respond, Predict. @5ean5ullivan @FSecure @ohjelmisto_ry
  16. Are you safe on social? "Countering the Social Hack" a 5-step process from ZF CEO @FirstNameFoster in @BRINKNewsNow
  17. Facebook flaw could have exposed private info of users and their friends
  18. Bitcoin fraud on the official Twitter account of Google GSuite
  19. Exploits confirmed! Congrats to F-Secure’s @MWRLabs team for another great #Pwn2Own performance. @thezdi
  20. BDO Unibank Warned its Customers to Remain Beware from New Phishing Scheme
  21. New Press Release: Team from @FSecure's @MWRLabs demos exploits for previously undisclosed vulnerabilities at Mobile #Pwn2Own competition -
  22. Facebook Patches Another Vulnerability That Exposed User’s Private Information
  23. A 100k routers around the world are on the botnet to conduct emails spam
  24. Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Did you by chance hack OPM back in 2015? Good news, your password probably still works!
  2. Weekly Threat Briefing: Adobe ColdFusion Servers Under Attack from APT Group
  3. Cyber espionage group used CVE-2018-8589 Windows Zero-Day in Middle East Attacks
  4. CVE-2018-15961: Adobe ColdFusion Flaw exploited in attacks in the wild
  5. CyberSecurity Asean security alert on A Vulnerability in Cisco Unity Express Could Allow for Arbitrary Code Execution
  6. Hunt finally submits to My Health Record arm-twists as opt-out window extended
  7. Healthcare.gov Health Data Breach Exposes Personal Data
  8. Senate votes to extend My Health Record opt-out to January 31