Sector brief for 2018-11-16
HEALTHCARE
- New HealthEquity Data Breach Exposes PII/PHI of Almost 21,000 Customers
- SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
- Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert
TRANSPORT
- Group-IB presented latest cybercrime and nation-state hacking trends in Asia
BANKING & FINANCE
- InfoWars: Magecart Infection Points to 'Industrial Sabotage'
- Reappearance of Magecart Malware to Infect Virtual Stores
- New HealthEquity Data Breach Exposes PII/PHI of Almost 21,000 Customers
- Hacking group returns, switches attacks from ransomware to trojan malware
- Details of 170,000 Pakistani debit cards leaked on dark web
- Cyber News Rundown: Infowars Hacked by Card Skimmers
- .@TalosSecurity recently created a #decryptor that helps files affected by the #ransomware #Thanatos -- typically known to not decrypt files
- Russian Banks Hit By Major Phishing Attacks
- How to Stay One Step Ahead of Phishing Websites — Literally
- Group-IB presented latest cybercrime and nation-state hacking trends in Asia
- Russian banks hit by major phishing attacks from two hacker groups
- ATM Tests Reveal Surprising Security Flaws
- tRat is a new modular RAT used by the threat actor TA505
- Malaysia’s Largest Media Company Allegedly Suffers Ransomware Attack
- Data Breaches on the Rise in Financial Services
- Four More Malicious Cryptocurrency Apps on Google Play
- Hackers infect Malaysia’s largest media company with ransomware, then demand $6.45 million
- #GroupIB #ThreatIntelligence detected large set of compromised payment cards details that was put on sale on underground card shop on
- Two hacker groups attacked Russian banks posing as the Central Bank of Russia
- Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert
- 5 Top Techniques for Testing Blockchain Apps
- Warning Issued by Emirates NBD over VAT Phishing Email Targeting its Customers
- Looking Back at LogRhythm Labs' 2018 Predictions for Security - How Did We Do?
INFORMATION & TELECOMMUNICATION
- InfoWars: Magecart Infection Points to 'Industrial Sabotage'
- Gmail Glitch Offers Stealthy Trick for Phishing Attacks
- Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
- This Week in Security News: Holiday Cybercriminals & Cryptomining Malware
- Cybaze ZLab- Yoroi team spotted a new variant of the APT28 Lojax rootkit
- Word of the Day: social engineering
- SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
- 2FA codes are great for security, except when 26M of them are leaked
- #GroupIB #ThreatIntelligence detected large set of compromised payment cards details that was put on sale on underground card shop on
- Google, US and Israeli politician Twitter accounts hijacked to promote 'Elon Musk' Bitcoin scam
- Two hacker groups attacked Russian banks posing as the Central Bank of Russia
- Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert
- French Company Data Breach Causes Sensitive Information Stolen to the Hackers
- Magecart become close to a household name with hacks of massive sites like http://Ticketmaster.com , http://Newegg.com and British Airways.
- Amid calls for a Windows bug status dashboard, Microsoft belatedly agrees to build one
- Looking Back at LogRhythm Labs' 2018 Predictions for Security - How Did We Do?
- SentinelOne Detects KeyPass Ransomware!
KeyPass is a new ransomware threat that has hit at least 20 countries and appears to be
FOOD
Nil
WATER
Nil
ENERGY
- Group-IB presented latest cybercrime and nation-state hacking trends in Asia
- Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert
- French Company Data Breach Causes Sensitive Information Stolen to the Hackers
GOVERNMENT & PUBLIC SERVICE
- Using Microsoft Powerpoint as Malware Dropper
- Operation Shaheen – Pakistan Air Force members targeted by nation-state attackers
- Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
- This Week in Security News: Holiday Cybercriminals & Cryptomining Malware
- Group-IB presented latest cybercrime and nation-state hacking trends in Asia
- Kaspersky Announces the Details of Windows 7 Zero-Day Vulnerability
- Looking Back at LogRhythm Labs' 2018 Predictions for Security - How Did We Do?