Threat report for 2018-11-23
DATA BREACH & DATA LOSS
- NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
- Data breach in OSIsoft
- Brazil's largest professional association suffers massive data leak
- Amazon Snafu Exposed Customers' Names and Email Addresses
- “Back in Black” – Article 13 has YouTube threatening to pull the plug over upload filter
- New Emotet Thanksgiving campaign differs from previous ones
- US Postal Service Website Left Data Exposed for Over a Year
- .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
- Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
- Software company OSIsoft has suffered a data breach
- SAVE 50% FOR BLACK FRIDAY!
Get half off FREEDOME VPN and TOTAL with coupon code BLACKFRIDAY.
- DNS Shell – Tool to Compromise and Maintain Control Over Victim Machine
- @FSecure fait son #BlackFriday ! Profitez de 50% de remise sur une sélection de produits !
- 60 million users’ data were exposed by the US Postal Service
DENIAL-OF-SERVICE
- Why e-commerce needs DDoS protection for Cyber Monday
MALVERTISING
Nil
PHISHING
- 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
- New Linux crypto-miner steals your root password and disables your antivirus
- Attackers Are Landing Email Inboxes Without the Need to Phish
- Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
- Phishing Used to Launch GreyEnergy's ICS Attacks
- Southwest Washington Regional Surgery Center suffered a Phishing attack
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
WEB DEFACEMENT
Nil
BOTNET
- Malware scum want to build a Linux botnet using Mirai
- Deep Instinct recently blogged about a new #botnet -- dubbed #Mylobot -- that has shown new, complex tools and techniques.
RANSOMWARE
- SMBs suffered the brunt of ransomware attacks in 2018
- The number of ransomware attacks on individuals has come down as it has become harder to get them to pay,
CRYPTOMINING & CRYPTOCURRENCIES
- Cryptocurrency ‘minting’ flaw could have leached money from exchanges
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
MALWARE
- 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
- New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
- Malware scum want to build a Linux botnet using Mirai
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- Black Friday special by Emotet: Filling inboxes with infected XML macros
- Black Friday special by Emotet: Filling inboxes with infected XML macros
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- VMware patches guest-to-host malware vulnerability
- #WebCache poisoning poses a serious threat to #BrowserSecurity. Learn how #hackers can use unkeyed inputs for malicious intent from expert
- Best way to Remove Malware on Mac, Including Other Unwanted Apps
- New Crypto Malware Spreading that Infects Linux Machines & Removes Anti-Virus
- Over 500k Play Store users have installed 13 games that contain malware
EXPLOIT
Nil
VULNERABILITY
- DoS Vulnerabilities Found in Linux Kernel, Unpatched
- Apache Hadoop spins cracking code injection vulnerability YARN
- German e-government SDK patched against ID spoofing vulnerability
- US Postal Service Plugs API Flaw - One Year Later
- VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
- Adobe Flash Player Remote Code Execution Vulnerability Threat Alert
- Old Printer Vulnerabilities Die Hard
- VMware Patches Workstation Flaw Disclosed at Hacking Contest
- Cryptocurrency ‘minting’ flaw could have leached money from exchanges
- USPS Bug affects 60 Million Users, Finally Fixed.
- German eID vulnerability allows hackers to change identities
- VMware patches guest-to-host malware vulnerability
- Internet connected devices might be the hot item for Christmas this year, but are they secure?
- Hacker says USPS ignored serious security flaw for over a year
- CVE-2018-6983: integer overflow vulnerability in VMware Workstation and Fusion