Nov 1, 2018

Threat report for 2018-10-31

DATA BREACH & DATA LOSS

  1. 85 Millions of voter records available for sale ahead of the 2018 US Midterm Elections
  2. More Information about July 2018’s Singapore SingHealth Data Breach Revealed
  3. Software bugs could compromise midterm votes in Texas
  4. Eurostar Resets Users' Passwords After Potential Data Breach
  5. Why data security is a priority for political campaigns
  6. The Radisson Hotel Group has suffered a data breach
  7. Social Security Numbers, PII Stolen in NorthBay Healthcare Data Breach
  8. Healthcare.gov website suffers data breach affecting 75,000 enrollees
  9. Tomorrowland festival goers affected by data breach
  10. Chinese Intel Agents Indicted for 5-Year IP Theft Campaign
  11. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  12. Nigerian Airline Arik Air May Have Leaked Customer Data
  13. Cyber Attacks Up Prior To Midterms, 81.5 Million Voter Records Threatened
  14. Average data breach fines have doubled as ICO hints at higher fines
  15. Australian companies failing to slow the tide of data breaches: OAIC
  16. Assault and battery: Malvertising campaign checks user device' charge as anti-detection technique
  17. Live Webinar | Identity Proofing in the Era of Data Breaches and Social Networking
  18. Come fermare i data breach con i servizi di Detection&Response #MDR: il caso di un'importante media company finlandese
  19. Fresh SamSam Ransomware Campaign Across the U.S
  20. Nigerian airline Arik Air may have leaked customer data
  21. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  22. SamSam Ransomware Campaigns Highly Active in 2018 and Heavily Targets Organizations
  23. A Report on Data Breaches in Australia
  24. A DHCPv6 package could compromise a vulnerable Linux system
  25. OIG’s Take On Healthcare.gov Patient Record Breach
  26. Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign

DENIAL-OF-SERVICE

  1. DDoS Attacks in Q3 2018

MALVERTISING

  1. Assault and battery: Malvertising campaign checks user device' charge as anti-detection technique

PHISHING

  1. Re: The Zombie Phish
  2. Ramped-up phishing attacks target universities around the world
  3. “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
  4. [Infographic] 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing:

WEB DEFACEMENT

Nil

BOTNET

  1. Re: The Zombie Phish
  2. Google aims to stop the tide of bots with reCAPTCHA v3
  3. Pervasive Emotet Botnet Now Steals Emails
  4. NTT Security targets botnet infrastructure
  5. Satori Botnet's Alleged Developer Rearrested
  6. #Mirai author fined $8.6million, gets 6 months house arrest

RANSOMWARE

  1. SamSam Ransomware Goes on a Tear
  2. 2018’s Most Prevalent Ransomware – We Took it for a Ride
  3. Kraken Ransomware Upgrades Distribution with RaaS Model
  4. GandCrab ransomware crew loses $1M after Bitdefender releases free decrypter
  5. Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
  6. Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
  7. Fresh SamSam Ransomware Campaign Across the U.S
  8. SamSam Ransomware Campaigns Highly Active in 2018 and Heavily Targets Organizations

CRYPTOMINING & CRYPTOCURRENCIES

  1. Kraken Ransomware Upgrades Distribution with RaaS Model
  2. Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
  3. Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
  4. It's a front? Mac cryptocurrency ticker actually installs backdoors
  5. All You Need to Know About Blockchain Testing

MALWARE

  1. Was the Triton Malware Attack Russian in Origin?
  2. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  3. Promethium/StrongPity Malware
  4. “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
  5. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
  6. Double-Gun Trojan which uses game plug-in to spread, is updated to V4.0 and looking for trouble
  7. Emotet Trojan Begins Stealing Victim's Email Using New Module
  8. Emotet trojan starts stealing full emails from infected machines
  9. Recently found GPlayed trojan spinoff analysed
  10. Federal employee infects gov't network with Russian malware through adult video websites
  11. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  12. What do you think the combination of the #TrickBot banking Trojan to #IcedID means for the future of banking #Trojans?
  13. 12 malicious libraries found in Python PyPI
  14. 5 Types of Malware Currently Affecting macOS
  15. Webroot Unveils Nastiest Malware of 2018
  16. Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign

EXPLOIT

  1. Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
  2. Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
  3. Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign

VULNERABILITY

  1. Software bugs could compromise midterm votes in Texas
  2. Yi Technology Home Cameras Exploitable Using Multiple Vulnerabilities
  3. Prioritizing the fundamentals of coordinated vulnerability disclosure
  4. Vulnerability Spotlight: Multiple Vulnerabilities in Yi Technology Home Camera
  5. Apple Patches Multiple Major Security Flaws
  6. Actively Exploited High Impact DoS Vulnerability Found in Cisco ASA and FTD
  7. Apple Fixes Multiple macOS, iOS Bugs Including a Quirky FaceTime Vulnerability
  8. Many States Reject DHS Offer to Check Election Systems for Flaws, Saying They’re Safe from Hackers
  9. Security Code AutoFill Flaw Exposes iOS, macOS Users to Banking Fraud Attacks
  10. Whiteboard Wednesday: Common Vulnerabilities as Personified by Halloween Costumes
  11. Vulnerability Spotlight: Multiple Vulnerabilities in Yi Technology Home Camera
  12. Several vulnerabilities were found in controllers made by @Universal_Robot. Discover what these #robot controllers are used for and how
  13. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
  14. Apple Patches Passcode Bypass, FaceTime Flaws in iOS
  15. Businesses unprepared for Windows 10 migration, fear vulnerability to cyber threats
  16. Apple Patches Critical Flaws in iOS 12.1, macOS 10.14.1 Updates
  17. Canonical Releases Ubuntu 16.04 LTS Kernel Patch, Fixed 4 Security Vulnerabilities
  18. CVE-2018-18649: Gitlab Wiki API Remote Code Execution Vulnerability Alert
  19. Apple Released Security Updates for iOS, watchOS, Safari , tvOS, iTunes & Fixed Several Vulnerabilities
  20. Windows 10 Universal Windows Platform Vulnerability
  21. Microsoft continues to push the KB4464455 patch for fixing ZIP bug