Sector brief for 2018-11-19
HEALTHCARE
- Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
- SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
- Texas hospital becomes victim of Dharma ransomware
TRANSPORT
Nil
BANKING & FINANCE
- New Modular tRat Remote Access Trojan Surfaced During September
- Tianfu Cup PWN hacking contest – White hat hackers earn $1 Million for Zero-Day exploits
- Collective Intelligence Podcast, Vitali Kremez on Magecart
- Business email compromise scam costs Pathé $21.5 million
- Subject: Invoice. The cause of 6 out of 10 of the most effective phishing campaigns in 2018
- Vision Direct reveals customer credit card leak, fake Google script may be to blame
- Vision Direct Notifies Customers of Data Compromise
- Email campaign spreading new tRAT malware
- October 2018’s Most Wanted Malware: For The First Time, Remote Access Trojan Reaches Global Threat Index’s Top 10
INFORMATION & TELECOMMUNICATION
- U.S. warns countries not to 'manipulate the extradition process' for cybercriminals
- Tianfu Cup PWN hacking contest – White hat hackers earn $1 Million for Zero-Day exploits
- Instagram Flaw Exposes User Passwords
- Multiple Remote TP-Link TL-R600VPN Router Vulnerabilities Patched
- A week in security (November 12 – 18)
- Instagram Bug, Now Fixed, Exposed User Passwords
- The Most Damaging Election Disinformation Campaign Came From Donald Trump, Not Russia
- 2FA Login Failure in Office 365 and Azure
- SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
- New ShadowTalk update looks at:
New nation-state threat actor uses advanced TTPs to target Pakistan
Lazarus Group’s FASTCash malware
- Cybaze ZLab – Yoroi team analyzed malware used in recent attacks on US entities attributed to APT29
- Outlaw Group Distributes Botnet for Cryptocurrency-Mining, Scanning, and Brute-Force
- Instagram flaw exposes user passwords
- Instagram Privacy Tool Exposed Passwords
- Proofpoint #ThreatInsight research: #sLoad and #Ramnit pairing in sustained personalized campaigns against UK and Italy:
- Instagram Accidentally Exposed Some User Passwords
- How #privacy intersects with #CyberSecurity.
“Criminals can craft better phishing emails to scam you when they know what you’re interested in.”
- Instagram Critical Bug Leaked User’s Password Via its Data Download Tool
- Fun fact: The Morris Worm of 1988 did never spread to Finland, as the outbreak happened two weeks before we
- Instagram Accidentally Exposed Some Users' Passwords In Plaintext
FOOD
Nil
WATER
Nil
ENERGY
Nil
GOVERNMENT & PUBLIC SERVICE
- Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
- U.S. warns countries not to 'manipulate the extradition process' for cybercriminals
- The Most Damaging Election Disinformation Campaign Came From Donald Trump, Not Russia
- Cybaze ZLab – Yoroi team analyzed malware used in recent attacks on US entities attributed to APT29
- Russian Cozy Bear APT 29 hackers may be impersonating State Department
- Turkish Police Arrested Cryptocurrency Hackers