Nov 16, 2018

Threat report for 2018-11-15

DATA BREACH & DATA LOSS

  1. My Health Record extension highlights lingering security, privacy concerns
  2. Firefox Now Alerts You of Website Data Breaches While You're Browsing the Web
  3. Survey Says: Bad PR Due to Data Breach News, Very Bad for Businesses
  4. Firefox warns if the website you're visiting suffered a data breach
  5. 20% of MageCart-compromised merchants get reinfected within days
  6. 20% of MageCart-compromised merchants get reinfected within days
  7. Today #GroupIB detected a massive phishing campaign sent to Russian banks from a fake email address purporting to belong to
  8. Report: Microsoft’s enterprise products covertly gather personal data on users
  9. Massive Data Leaks Keep Happening Because Big Companies Can Afford to Lose Your Data
  10. A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
  11. Law firm uncovers exposed sensitive details about top attorney online. @mazzazone gives the details:
  12. #tRat: New modular #RAT appears in multiple email campaigns: http://ow.ly/1nsX50jHzgd via the Proofpoint @threatinsight research team.
  13. Nordstrom is notifying employees of a data breach that exposed their personal information, including names, Social Security numbers, dates of
  14. Data breach at Nordstrom
  15. My Health Record remains opt-out as Senate passes privacy amendments
  16. Symantec Honored for its Collaboration With Leading Industry Group to Protect Against Business Email Compromise Scams

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. G Suite Adds Advanced Password Controls
  2. Man Sends Bomb to Cryptopay for Denying a Password Change Request
  3. Phishing Attack Causes Breach at Southwest Washington Regional Surgery Center
  4. 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing [Infographic]:
  5. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  6. Today #GroupIB detected a massive phishing campaign sent to Russian banks from a fake email address purporting to belong to
  7. A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
  8. Phishing fraudsters set their sights on online storage portals
  9. 'DarkGate' miner, password-stealer could open up world of hurt for Windows users
  10. Learn why @Google chose U2F authentication over OTP to eliminate #PhishingEmails from expert Michael Cobb of @thehairyITdog.
  11. Vade Secure launches IsItPhishing Threat Detection to help SOCs identify phishing URLs
  12. Smashing Security #104: The world’s most evil phishing test, and cyborgs in the workplace

WEB DEFACEMENT

Nil

BOTNET

  1. Deep Instinct recently blogged about a new #botnet -- dubbed #Mylobot -- that has shown new, complex tools and techniques.
  2. Bots on a plane? Bad bots cause unique cyber-security issues for airlines

RANSOMWARE

  1. Should Windows Users Worry About Ransomware in 2019?
  2. 500 Percent Increase in macOS/iOS Ransomware Attacks During 1H 2018
  3. Ransomware Continues to Be Top Threat to Small Companies
  4. Ransomware Attack Strikes Media Prima

CRYPTOMINING & CRYPTOCURRENCIES

  1. Linux Based Crypto-Mining Malware
  2. Official Google Twitter account hacked in Bitcoin scam
  3. A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
  4. How is the Trezor cryptocurrency online wallet under attack?
  5. Cryptocurrency fraud is the exception, not the rule
  6. Fake cryptocurrency Wallets Apps on Google Play Steal User Credentials and Mimic as Legitimate Wallets
  7. Access Control Acronyms: ACL, RBAC, ABAC, PBAC, RAdAC, and a Dash of CBAC
  8. Cryptowerk introduces blockchain-based technology to certify data integrity of digital assets
  9. The ABC of the Hong Kong tech scene: A - AI, B - blockchain, C - cloud

MALWARE

  1. Proofpoint: Hackers testing new reconnaissance malware on financial institutions
  2. A RAT Just Made It in the Global Threat Index’s Top 10
  3. Ahead of Black Friday, Rash of Malware Families Takes Aim at Holiday Shoppers
  4. Cyber Crooks Diversify Business with Multi-Intent Malware
  5. Linux Based Crypto-Mining Malware
  6. Cloud, China, Generic Malware Top Security Concerns for 2019
  7. Brazilian Users Under Attack From Metamorfo Banking Trojan
  8. #WebCache poisoning poses a serious threat to #BrowserSecurity. Learn how #hackers can use unkeyed inputs for malicious intent from expert
  9. 14 Malware Families Targeting E-Commerce Brands Ahead of Black Friday
  10. #tRat: New modular #RAT appears in multiple email campaigns: http://ow.ly/1nsX50jHzgd via the Proofpoint @threatinsight research team.
  11. Carpet (IT) to Concrete (OT) – The Evolution of Internet-Based Malware
  12. Creating and Analyzing a Malicious PDF File with PDF-Parser Tool
  13. I forgot to follow up on this… According to Apple, the process could take up to 7 days. It

EXPLOIT

  1. Fresh exploit takes the shackles off disabled PHP functions
  2. What is the impact of cyber espionage? @MikaSusiEK from Confederation of Finnish Industries EK discusses, how to tackle the growing

VULNERABILITY

  1. Vulnerability: Emojis can kill Skype for Business
  2. IRCTC Free Insurance Bug That Puts Millions of Passenger Data Under Risk
  3. Unpatched Microsoft Word Video Feature Vulnerability is Being Exploited In The Wild
  4. 7 New Meltdown and Spectre Level Vulnerabilities Discovered that Affected ARM, Intel & AMD CPU’s
  5. Two whitehats receive $60,000 in rewards for successfully finding iOS 12.1 vulnerabilities
  6. VMware Virtual Machine Escape Vulnerabilities (CVE-2018-6981 and CVE-2018-6982) Threat Alert
  7. Cisco Stealthwatch Management Console and Unity Express Critical Vulnerabilities Threat Alert
  8. Popular AMP Plugin for WordPress Patches Critical Flaw – Update Now
  9. Is Your Vulnerability Management Program Efficient and Successful?
  10. Find vulnerabilities using nikto
  11. Facebook fixed a new security bug
  12. 63 new vulnerabilities found in Windows