Threat report for 2018-10-31
DATA BREACH & DATA LOSS
- 85 Millions of voter records available for sale ahead of the 2018 US Midterm Elections
- More Information about July 2018’s Singapore SingHealth Data Breach Revealed
- Software bugs could compromise midterm votes in Texas
- Eurostar Resets Users' Passwords After Potential Data Breach
- Why data security is a priority for political campaigns
- The Radisson Hotel Group has suffered a data breach
- Social Security Numbers, PII Stolen in NorthBay Healthcare Data Breach
- Healthcare.gov website suffers data breach affecting 75,000 enrollees
- Tomorrowland festival goers affected by data breach
- Chinese Intel Agents Indicted for 5-Year IP Theft Campaign
- Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
- Nigerian Airline Arik Air May Have Leaked Customer Data
- Cyber Attacks Up Prior To Midterms, 81.5 Million Voter Records Threatened
- Average data breach fines have doubled as ICO hints at higher fines
- Australian companies failing to slow the tide of data breaches: OAIC
- Assault and battery: Malvertising campaign checks user device' charge as anti-detection technique
- Live Webinar | Identity Proofing in the Era of Data Breaches and Social Networking
- Come fermare i data breach con i servizi di Detection&Response #MDR: il caso di un'importante media company finlandese
- Fresh SamSam Ransomware Campaign Across the U.S
- Nigerian airline Arik Air may have leaked customer data
- Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
- SamSam Ransomware Campaigns Highly Active in 2018 and Heavily Targets Organizations
- A Report on Data Breaches in Australia
- A DHCPv6 package could compromise a vulnerable Linux system
- OIG’s Take On Healthcare.gov Patient Record Breach
- Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign
DENIAL-OF-SERVICE
- DDoS Attacks in Q3 2018
MALVERTISING
- Assault and battery: Malvertising campaign checks user device' charge as anti-detection technique
PHISHING
- Re: The Zombie Phish
- Ramped-up phishing attacks target universities around the world
- “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
- [Infographic] 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing:
WEB DEFACEMENT
Nil
BOTNET
- Re: The Zombie Phish
- Google aims to stop the tide of bots with reCAPTCHA v3
- Pervasive Emotet Botnet Now Steals Emails
- NTT Security targets botnet infrastructure
- Satori Botnet's Alleged Developer Rearrested
- #Mirai author fined $8.6million, gets 6 months house arrest
RANSOMWARE
- SamSam Ransomware Goes on a Tear
- 2018’s Most Prevalent Ransomware – We Took it for a Ride
- Kraken Ransomware Upgrades Distribution with RaaS Model
- GandCrab ransomware crew loses $1M after Bitdefender releases free decrypter
- Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
- Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
- Fresh SamSam Ransomware Campaign Across the U.S
- SamSam Ransomware Campaigns Highly Active in 2018 and Heavily Targets Organizations
CRYPTOMINING & CRYPTOCURRENCIES
- Kraken Ransomware Upgrades Distribution with RaaS Model
- Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
- Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
- It's a front? Mac cryptocurrency ticker actually installs backdoors
- All You Need to Know About Blockchain Testing
MALWARE
- Was the Triton Malware Attack Russian in Origin?
- Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
- Promethium/StrongPity Malware
- “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
- "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
- Double-Gun Trojan which uses game plug-in to spread, is updated to V4.0 and looking for trouble
- Emotet Trojan Begins Stealing Victim's Email Using New Module
- Emotet trojan starts stealing full emails from infected machines
- Recently found GPlayed trojan spinoff analysed
- Federal employee infects gov't network with Russian malware through adult video websites
- Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
- What do you think the combination of the #TrickBot banking Trojan to #IcedID means for the future of banking #Trojans?
- 12 malicious libraries found in Python PyPI
- 5 Types of Malware Currently Affecting macOS
- Webroot Unveils Nastiest Malware of 2018
- Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign
EXPLOIT
- Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
- Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
- Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign
VULNERABILITY
- Software bugs could compromise midterm votes in Texas
- Yi Technology Home Cameras Exploitable Using Multiple Vulnerabilities
- Prioritizing the fundamentals of coordinated vulnerability disclosure
- Vulnerability Spotlight: Multiple Vulnerabilities in Yi Technology Home Camera
- Apple Patches Multiple Major Security Flaws
- Actively Exploited High Impact DoS Vulnerability Found in Cisco ASA and FTD
- Apple Fixes Multiple macOS, iOS Bugs Including a Quirky FaceTime Vulnerability
- Many States Reject DHS Offer to Check Election Systems for Flaws, Saying They’re Safe from Hackers
- Security Code AutoFill Flaw Exposes iOS, macOS Users to Banking Fraud Attacks
- Whiteboard Wednesday: Common Vulnerabilities as Personified by Halloween Costumes
- Vulnerability Spotlight: Multiple Vulnerabilities in Yi Technology Home Camera
- Several vulnerabilities were found in controllers made by @Universal_Robot. Discover what these #robot controllers are used for and how
- Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
- Apple Patches Passcode Bypass, FaceTime Flaws in iOS
- Businesses unprepared for Windows 10 migration, fear vulnerability to cyber threats
- Apple Patches Critical Flaws in iOS 12.1, macOS 10.14.1 Updates
- Canonical Releases Ubuntu 16.04 LTS Kernel Patch, Fixed 4 Security Vulnerabilities
- CVE-2018-18649: Gitlab Wiki API Remote Code Execution Vulnerability Alert
- Apple Released Security Updates for iOS, watchOS, Safari , tvOS, iTunes & Fixed Several Vulnerabilities
- Windows 10 Universal Windows Platform Vulnerability
- Microsoft continues to push the KB4464455 patch for fixing ZIP bug