Nov 30, 2018

Threat report for 2018-11-29

DATA BREACH & DATA LOSS

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Dell Forces Password Reset for Online Customers Following Data Breach
  3. Dell remains quiet on attempted data breach
  4. 2.6 Million Atrium Health Patient Records Compromised by Vendor AccuDoc
  5. Iranian duo charged with SamSam ransomware-slinging campaign
  6. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  7. SKY Brasil Exposes 32 Million Customer Records
  8. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  9. Dunkin' Donuts Serves Up Data Breach Alert
  10. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  11. US Indicts Two Iranians for SamSam Campaign Blitz
  12. London-based Urban Massage app leaks data on 300K customers, including sexual misconduct claims
  13. Database breach affects 2.6 million Atrium Health patients
  14. Dell data breach – Dell forces password reset after the incident
  15. Records of 114 Million US Citizen and Companies Exposed Online
  16. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  17. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  18. Dell Resets User Passwords Following Data Breach
  19. Atrium Health Data Breach Affected More than 2 Million Patients
  20. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  21. Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords
  22. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Users Failing Phishing Simulations? That’s ok
  2. Dell Forces Password Reset for Online Customers Following Data Breach
  3. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  4. Office workers beware: Holiday gift card spear phishing attacks on the rise
  5. Blazy – Open Source Modern Login Brute-forcer
  6. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  7. Dell data breach – Dell forces password reset after the incident
  8. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  9. Threat Spotlight: New spear phishing attack gift card scam
  10. How have #phishing campaigns threatened your #EnterpriseSecurity system?

WEB DEFACEMENT

Nil

BOTNET

  1. Anti-Botnet Guide Aims to Tackle Automated Threats
  2. “And once a device is part of a botnet, it leaves them open for future attacks. So users should avoid
  3. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  4. The Justice Department, FBI and several tech and cybersecurity companies have dismantled the #3ve #botnet, and eight individuals have been

RANSOMWARE

  1. A free decryption tool is available for Thanatos ransomware victims
  2. Colorado Agency Targeted in Nationwide Ransomware Scheme
  3. SamSam ransomware actors charged, sanctioned by US government
  4. Iranian duo charged with SamSam ransomware-slinging campaign
  5. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  6. US charges Iranian hackers for SamSam ransomware attacks
  7. US charges Iranian hackers for SamSam ransomware attacks
  8. US indicts two over SamSam ransomware attacks
  9. US Charges Hackers in Multimillion Dollar Ransomware Campaign

CRYPTOMINING & CRYPTOCURRENCIES

  1. AriseBank CEO faces 120 years behind bars over alleged cryptocurrency scam
  2. Hacker takes over JavaScript library, injects malware to steal Bitcoin
  3. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

MALWARE

  1. Rotexy malware morphs into dangerous banking Trojan
  2. Banking Trojan Made in Brazil? A Brief Look
  3. Overall Volume of Thanksgiving Weekend Malware Attacks Lower This Year
  4. Brazilian Financial Malware Spreads Beyond National Boundaries
  5. Indian Police Break Up International Computer Virus Scam
  6. Inside the Google Docs Malicious Network
  7. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  8. Beware the Malware-Laden Brexit News
  9. KingMiner malware hijacks the full power of Windows Server CPUs
  10. Malicious developer creates wormable, fileless variant of njRAT
  11. Brazilian-made bank trojan
  12. READ: The threat actor SNAKEMACKEREL (#FancyBear) leveraged current geopolitical events and #Brexit themed lure documents to deliver first-stage malware
  13. Proofpoint: Hackers testing new reconnaissance #malware on financial institutions.
  14. Beware the Malware-Laden Brexit News https://ubm.io/2Ql2DyP by @ErickaChick
  15. Analysis Report of the XorDDoS Malware Family
  16. Hacker takes over JavaScript library, injects malware to steal Bitcoin
  17. Several Malicious Apps on Google Play Posing as Voice Messenger Steal User Personal Information
  18. Mobile Malware Attacks Increase as Holiday Season Nears
  19. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe

EXPLOIT

  1. Cisco Patches SQL Injection Flaw in Prime License Manager
  2. Hackers can exploit this bug in surveillance cameras to tamper with footage

VULNERABILITY

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. Critical Zoom Flaw Lets Hackers Hijack Conference Meetings
  3. USPS API Security Vulnerabilities Caused by Functional Errors
  4. Cisco Patches SQL Injection Flaw in Prime License Manager
  5. Cisco Patches Critical Bug in License Management Tool
  6. Hackers can exploit this bug in surveillance cameras to tamper with footage
  7. A security hole in a mail preview program may have made the data of 60 million customers vulnerable.
  8. A security researcher notified the @USPS of an #API vulnerability one year ago. But the #USPS website flaw was only
  9. GCHQ: We don't tell tech companies about every software flaw
  10. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  11. Widely Used Web Conference Service Zoom Patches Critical Flaw
  12. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  13. Facebook Increases Bug Bounty Payouts to Improve User Security