Nov 15, 2018

Threat report for 2018-11-14

DATA BREACH & DATA LOSS

  1. 21K Donors Had Their Personal Info Leaked Following Kars4Kids Data Breach
  2. Google services collapsed due to BGP leak
  3. Google services collapsed due to BGP leak
  4. Facebook vulnerability could have leaked your private information – again
  5. Cathay Apologizes Over Data Breach but Denies Cover-up
  6. Business Email Compromise - When You Don’t Need to Phish:
  7. Australian Senate extends My Health Record opt-out period
  8. The July edition of Beazley Breach Insights found that business email compromise attacks have been rising steadily. Is business email
  9. Microsoft covertly collects personal data from enterprise Office ProPlus users
  10. Facebook flaw could have exposed private info of users and their friends
  11. Hunt finally submits to My Health Record arm-twists as opt-out window extended
  12. This year’s success adds to @MWRLabs’ #Pwn2Own existing track record, which includes demo attacks against Chrome.
  13. The @mwrlabs research team used zero-day vulnerabilities to compromise smart phones from Xiaomi and Samsung.
  14. Healthcare.gov Health Data Breach Exposes Personal Data
  15. Facebook Patches Another Vulnerability That Exposed User’s Private Information
  16. Senate votes to extend My Health Record opt-out to January 31

DENIAL-OF-SERVICE

  1. Just because you're paranoid doesn't mean hackers won't nuke your employer into the ground tomorrow
  2. A Large Retailer Responds to #DDoS Extortion: To Pay or Not to Pay?

MALVERTISING

Nil

PHISHING

  1. Did you by chance hack OPM back in 2015? Good news, your password probably still works!
  2. Business Email Compromise - When You Don’t Need to Phish:
  3. Is it time to change your password? Check out this list of the 25 worst passwords for 2018 and make
  4. Support wouldn’t change his password, so he mailed them a bomb
  5. Public get Warning from Scotts Bluff County Sheriff’s Office about a Phishing Email Scam
  6. BDO Unibank Warned its Customers to Remain Beware from New Phishing Scheme

WEB DEFACEMENT

Nil

BOTNET

  1. 'Mylobot' botnet now downloading second-stage malware meant to siphon data
  2. Airlines Have a Big Problem with Bad Bots
  3. A 100k routers around the world are on the botnet to conduct emails spam

RANSOMWARE

  1. 1,000 Bitcoins Ransom Asked from Media Prima After Successful Ransomware Attack
  2. Targeted ransomware attacks – SophosLabs 2019 Threat Report
  3. Ransomware is the leading cyber threat experienced by SMBs
  4. Key takeaways from Datto’s State of the Channel Ransomware Report 2018
  5. Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. Bitcoin Giveaway Scam Balloons, with Google the Latest Victim
  2. French Data Protection Authority Issues Guidance on Interaction of Blockchain Technology with GDPR
  3. Cryptojacking, Mobile Malware Growing Threats to the Enterprise
  4. Why cryptojacking malware is a bigger threat to your PC than you realise
  5. Don’t fall for fake NEO, Tether and MetaMask cryptocurrency wallets on Google Play
  6. Researchers recently discovered a new #MacOS #malware that targets #cryptocurrency investors through chat platforms. Discover how this is possible and
  7. Bitcoin fraud on the official Twitter account of Google GSuite

MALWARE

  1. 'Mylobot' botnet now downloading second-stage malware meant to siphon data
  2. FlawedAmmy, the Only RAT in CheckPoint’s Global Threat Index 2018 List
  3. Ad-Injecting Mac Malware Rediscovered
  4. Monitoring file output for malicious code 'could have stopped BA attack more quickly'
  5. It's Amateur Hour In The World Of Spyware And Victims Will Pay The Price
  6. Cryptojacking, Mobile Malware Growing Threats to the Enterprise
  7. A bypass was found by @okta researchers that allows #macOS #malware to pose as @Apple files despite needing to be
  8. Why cryptojacking malware is a bigger threat to your PC than you realise
  9. Researchers recently discovered a new #MacOS #malware that targets #cryptocurrency investors through chat platforms. Discover how this is possible and
  10. Holiday Shopping Tip 1: Inoculate Your Computer You need to protect against malware with regular updates to your anti-virus program and
  11. Researchers demo how machine learning can be used to track Gh0st RAT variants
  12. This remote access trojan just popped up on malware's most wanted list
  13. Do you believe that the application #security vetting process would benefit from the addition of an entropy source?
  14. How does signed software help mitigate malware?
  15. Beers with Talos Ep. #41: Sex, money and malware
  16. Cyber security is a process: Prevent, Detect, Respond, Predict. @5ean5ullivan @FSecure @ohjelmisto_ry
  17. Are you safe on social? "Countering the Social Hack" a 5-step process from ZF CEO @FirstNameFoster in @BRINKNewsNow
  18. FlawedAmmy: Dangerous RAT enteres most wanted malware list
  19. Card skimming malware removed from Infowars online store

EXPLOIT

  1. Chinese APT Group Exploit Fixed Critical Adobe ColdFusion Vulnerability On Unpatched Servers
  2. Zero-day Windows exploit fix stars in November Patch Tuesday
  3. A new exploit for zero-day vulnerability CVE-2018-8589
  4. This year’s success adds to @MWRLabs’ #Pwn2Own existing track record, which includes demo attacks against Chrome.

VULNERABILITY

  1. Microsoft Patches RCE Vulnerabilities in Word, Excel, and Windows Search
  2. Siemens Patches Firewall Flaw That Put Operations at Risk
  3. Chinese APT Group Exploit Fixed Critical Adobe ColdFusion Vulnerability On Unpatched Servers
  4. Facebook vulnerability could have leaked your private information – again
  5. Cyber espionage group used CVE-2018-8589 Windows Zero-Day in Middle East Attacks
  6. CVE-2018-15961: Adobe ColdFusion Flaw exploited in attacks in the wild
  7. How Threat Intelligence Prioritizes Risk in Vulnerability Management
  8. Hackers Taking Over Websites Due to WordPress GDPR Plugin Flaw
  9. November 2018 Patch Tuesday: Microsoft fixes 63 flaws, one actively exploited zero-day
  10. Siemens Releases 7 Advisories for SIMATIC, SCALANCE Vulnerabilities
  11. Adobe Patch Tuesday updates for November 2018 fix known Acrobat flaw
  12. Zero-day Windows exploit fix stars in November Patch Tuesday
  13. Microsoft's Patch Tuesday addresses Zero Day vulnerabilities
  14. Facebook reportedly fixes search bug that could have threatened user privacy
  15. CyberSecurity Asean security alert on A Vulnerability in Cisco Unity Express Could Allow for Arbitrary Code Execution
  16. November Patch Tuesday Fixes Another Zero-Day Win32k Bug, Other Public Vulnerabilities
  17. AVEVA InduSoft Web Studio and InTouch Edge HMI Critical Vulnerabilities Threat Alert
  18. A #bug allowing websites to capture private data from Facebook users through Chrome has been discovered:
  19. Microsoft Patches Windows Zero-Day Exploited in Cyber Attacks
  20. 7 New Meltdown and Spectre-type CPU Flaws Affect Intel, AMD, ARM CPUs
  21. APT Group Uses Windows Zero-Day in Middle East Attacks
  22. Facebook flaw could have exposed private info of users and their friends
  23. A new exploit for zero-day vulnerability CVE-2018-8589
  24. Adobe November Security Update: fixes multiple vulnerabilities in its products
  25. Microsoft Released Security Updates & Fixed More than 60 Vulnerabilities Along with Active Windows Zero day
  26. The @mwrlabs research team used zero-day vulnerabilities to compromise smart phones from Xiaomi and Samsung.
  27. Exploits confirmed! Congrats to F-Secure’s @MWRLabs team for another great #Pwn2Own performance. @thezdi
  28. New Press Release: Team from @FSecure's @MWRLabs demos exploits for previously undisclosed vulnerabilities at Mobile #Pwn2Own competition -
  29. Facebook Patches Another Vulnerability That Exposed User’s Private Information
  30. 63 New Flaws (Including 0-Days) Windows Users Need to Patch Now
  31. Confirmed! The @mwrlabs team used a download bug along with a silent app installation to load their custom app and