Threat report for 2018-11-13
DATA BREACH & DATA LOSS
- Cathay Pacific In Hot Water: Data Breach Started March 2018, Not October 2018
- Cathay Says 'Most Intense' Period of Data Breach Lasted Months
- Nordstrom Reveals Data Breach, Sensitive Employee Information Exposed
- Nordstrom Data Breach Exposes Employee Information
- Nordstrom Quick to Tell Employees of a Data Breach
- Former Employee Accessed Medical Records For Nearly a Year
- Sophisticated cyber-espionage campaign targeting Pakistani government and air force
- Dropbox Account Phishing Campaign
- The Ontario Cannabis Store has reported a data breach that took place Nov. 1 through the Canada Post and affected
- Another Facebook Bug Could Have Exposed Your Private Information
- Google Services down due to BGP leak, traffic hijacked through Russia, China, and Nigeria
- Sophisticated Campaign Targets Pakistan's Air Force
- Google Services Inaccessible Due to BGP Leak
- Beware !! Worlds Most Active Malware Emotet Launching New Campaign With Malicious Word and PDF Attachments
- Compromised security in millions of cards in the US
- Leak: Windows 10 October Update will be re-launched tomorrow
DENIAL-OF-SERVICE
Nil
MALVERTISING
- Malvertising is what happens when attackers buy ad space in popular, legit websites and load them with ads infected by
PHISHING
- Why Gen Z has the most dangerous password practices
- Dropbox Account Phishing Campaign
- Password manager: 85% want their password to be protected against hackers
- How did @Google eliminate successful #PhishingAttacks? Learn how employees used U2F authentication and physical #SecurityKeys to defend against phishing from
- To help you rule out the worst password ideas, FrontNet has put together a list of the 25 words passwords
WEB DEFACEMENT
Nil
BOTNET
- Security cameras – a latent botnet network?
- A new #botnet -- #Mylobot -- has shown new, complex levels of tools and techniques that are subsequently altering botnet
- New #spam #botnet infected over 100,000 home routers through a UPnP vulnerability, according to researchers at @360Netlab. By @MaddieBacon11
- How does the Mylobot botnet differ from a typical botnet?
RANSOMWARE
- What MSPs can learn from Datto’s Channel Ransomware Report
- Premier Media Conglomerate of Malaysia, Falls for Ransomware Infection
- Why WannaCry ransomware is still a threat to your PC
- Ransomware no. 1 cyberthreat to SMBs, and the average attack costs $47K
- Ransomware Attack on City of Muscatine Shutdown Several Servers
CRYPTOMINING & CRYPTOCURRENCIES
- Fake Crypto Wallet Apps Discovered in Google Play, Built Using Drag-n-Drop
- Target and other high profile Twitter accounts exploited for cryptocurrency scams
- Cryptocurrency Mining Malware uses Various Evasion Techniques.
- The Tactic Cybercriminals Use to Steal Bitcoin
- Attacker hijacks Elon Musk Twitter account to implement fake bitcoin fraud
- Data61 and CBA demonstrate blockchain welfare payments
- WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
- WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
- Illegal cryptocurrency mining
- Twitter grapples with fake Elon Musk accounts promoting bitcoin scams
MALWARE
- Triton ICS Malware
- Scare Force: Pakistan military hit by Operation Shaheen malware
- Pakistan Military Hit By Operation Shaheen Malware
- That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards
- What’s on Our Minds for 2019? Key Themes from the RSA Speaker Selection Process
- It’s Amateur Hour in the World of Spyware and Victims Will Pay the Price
- Cryptocurrency Mining Malware uses Various Evasion Techniques.
- Call Recorder App on Google Play with Over 5,000 Installs Contains Hidden Malware Dropper
- #Gallmaker eschews custom malware, uses living off the land and publicly available #hack tools. Find out more:
- Using Machine Learning to Cluster Malicious Network Flows From Gh0st RAT Variants
- How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
- U.S. Cyber Command #malware samples will be shared to #VirusTotal by the Cyber National Mission Force and one expert said
- Beware !! Worlds Most Active Malware Emotet Launching New Campaign With Malicious Word and PDF Attachments
- WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
- WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
- 12 Warning Signs That Help Identify Malware Infection
EXPLOIT
- Attackers exploit flaw in GDPR-themed WordPress plugin to hijack websites
- Ruby taken off the rails by deserialization exploit
- Attackers exploit GDPR compliance plug-in for WordPress
VULNERABILITY
- Microsoft’s Patch Tuesday updates for November 2018 fix actively exploited Windows flaw
- Microsoft Patches Zero-Day Bug in Win7, Server 2008 and 2008 R2
- Microsoft Patches Actively Exploited Windows Vulnerability
- Fixed Facebook Privacy Bug Could Have Allowed Bad Actors to Steal Personal Info
- Microsoft patches Windows zero-day used by multiple cyber-espionage groups
- Adobe Patches Disclosed Acrobat Vulnerability
- SAP Patches Critical Vulnerability in HANA Streaming Analytics
- Facebook flaw opened your profile to data thieves
- Adobe Releases Security Update for Acrobat Vulnerability with Public PoC
- Unpatched Android OS Flaw Allows Adversaries to Track User Location
- Microsoft Patch Tuesday Recap: 12 Critical Bugs Fixed
- Adobe Fixes Acrobat and Reader Flaw With Publicly-Available PoC
- Facebook Patches Another User Data Harvesting Bug
- XSS Vulnerability in Evernote Allows Local File Execution
- Vulnerabilities in Solid-State Drives Can Be Exploited to Decrypt Data
- Side-Channel Vulnerability Could Be Exploited to Steal Data
- Zero-Day Vulnerability in Cisco Products Could Cause DoS Condition
- Attackers exploit flaw in GDPR-themed WordPress plugin to hijack websites
- Facebook Bug Let Websites Access Private User Data
- Microsoft November 2018 Patch Tuesday Fixes 12 Critical Vulnerabilities
- Facebook patches another bug that could have allowed mass-harvesting of user data
- Microsoft Patch Tuesday — November 2018: Vulnerability disclosures and Snort coverage
- Another Facebook Bug Could Have Exposed Your Private Information
- New #spam #botnet infected over 100,000 home routers through a UPnP vulnerability, according to researchers at @360Netlab. By @MaddieBacon11
- Microsoft Word Doc bug using online video feature found in wild
- Check Point Researchers Reported Vulnerabilities in Market-Leading Drone Platform, Enabling Manufacturer to Bolster Security
- Zero Day vulnerability in VirtualBox is disclosed