Oct 1, 2018

APT report for 2018-09-30

TRANSNATIONAL / UNKNOWN

  1. The British Airways #databreach may be the handiwork of hacking group #Magecart, according to researchers. By @MaddieBacon11

CHINA

Nothing to report

INDIA

Nothing to report

NORTH KOREA

  1. A security researcher developed a proof-of-concept attack on #Firefox called Browser Reaper that can crash or freeze the browser, but

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Security Affairs newsletter Round 182 – News of the week

UKRAINE

Nothing to report

Platform report for 2018-09-30

WINDOWS

  1. Telegram Leaks Public & Private IP Address While Making Calls
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. Telegram exposes the IP address during a user call by default
  5. Xbash Malware Combines Many Malicious Functions in Worm
  6. Cisco Multiple Security Vulnerabilities Alert
  7. USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing

LINUX

  1. Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
  2. Security Affairs newsletter Round 182 – News of the week
  3. Telegram exposes the IP address during a user call by default
  4. Xbash Malware Combines Many Malicious Functions in Worm

UNIX

Nothing to report

ANDROID

  1. #Android #Trojan: How is data being stolen from #messagingapps?
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. Telegram exposes the IP address during a user call by default

IOS

  1. Security Affairs newsletter Round 182 – News of the week
  2. Telegram exposes the IP address during a user call by default
  3. Cisco Multiple Security Vulnerabilities Alert

MACOS

  1. Security Affairs newsletter Round 182 – News of the week
  2. Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
  3. Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files

Threat report for 2018-09-30

DATA BREACH

  1. Experts comment on Facebook’s 50 million user credential leak
  2. 40 million more likely affected by massive Facebook data leak - Bitdefender
  3. Project Insecurity (@insecurity) researchers discovered certain #livechatsoftware that were leaking personal details of employee at several high-profile sites. Discover how
  4. Telegram Leaks Public & Private IP Address While Making Calls
  5. The United Nations (@UN) accidentally exposed sensitive information on public @trello boards, in the Jira app, and in #GoogleDocs and
  6. 3 GOP senators doxed during Kavanaugh hearing
  7. Uber has agreed to pay more than $140 Million for a data breach settlement

DENIAL-OF-SERVICE

Nothing to report

MALVERTISING

Nothing to report

PHISHING

  1. Chegg forces password reset on 40 million users
  2. Hackers are Selling Social Media Logins & Financial Details On Dark Web starting from £2
  3. USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing

WEB DEFACEMENT

Nothing to report

MALWARE

  1. GANDCRAB 5.0.1 Ransom Virus – How to Remove It and Restore Data
  2. Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
  3. Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
  4. Telegram Leaks Public & Private IP Address While Making Calls
  5. #Android #Trojan: How is data being stolen from #messagingapps?
  6. Docs reveal how Fruitfly Mac spyware initially spread
  7. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  8. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
  9. Security roundup: Facebook, ransomware, UEFI rootkit, Berners-Lee’s plan for new internet
  10. Telegram exposes the IP address during a user call by default
  11. #GoScanSSH: How does this #malware work and differ from others?
  12. Xbash Malware Combines Many Malicious Functions in Worm
  13. Discover how the #VPNFilter #malware works and affects users
  14. Alphabet's Chronicle has given #VirusTotal a makeover. Find out what's in the new VirusTotal Enterprise offering. By @RobWright22
  15. Improving core processes with next-generation mobile productivity solutions can bring power and cost efficiency gains. However, we must not lose
  16. Malware in the Cloud: What You Need to Know
  17. Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware

EXPLOIT

  1. Facebook Ad Targeting Exploits Users’ 2FA Phone Numbers
  2. FBI IC3 warns of cyber attacks exploiting Remote Desktop Protocol (RDP)

VULNERABILITY

  1. Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
  2. Facebook Says Three Different Bugs Are Responsible For The Massive Account Hacks
  3. Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
  4. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  5. Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
  6. #Cisco patches yet another hardcoded credentials flaw, this time in its video surveillance manager appliance; the latest vulnerability is at
  7. Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
  8. Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from
  9. Cisco Multiple Security Vulnerabilities Alert
  10. Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files
  11. A Top Facebook Bug Bounty Hunter Shares Their Insights on the Facebook Breach

Region brief for 2018-09-30

ASIA

  1. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  2. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats

OCEANIA

Nothing to report

NORTH AMERICA

  1. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
  2. Telegram exposes the IP address during a user call by default

SOUTH AMERICA

Nothing to report

EUROPE

  1. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. The British Airways #databreach may be the handiwork of hacking group #Magecart, according to researchers. By @MaddieBacon11

AFRICA

Nothing to report

Sector brief for 2018-09-30

HEALTHCARE

Nothing to report

TRANSPORT

  1. Security Affairs newsletter Round 182 – News of the week

BANKING & FINANCE

  1. Security Affairs newsletter Round 182 – News of the week
  2. Hackers are Selling Social Media Logins & Financial Details On Dark Web starting from £2

INFORMATION & TELECOMMUNICATION

Nothing to report

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

Nothing to report

GOVERNMENT & PUBLIC SERVICE

  1. Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from

Daily brief for 2018-09-30

ASIA

  1. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  2. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats

WORLD

  1. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. The British Airways #databreach may be the handiwork of hacking group #Magecart, according to researchers. By @MaddieBacon11
  5. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
  6. Telegram exposes the IP address during a user call by default

ATTACKS

  1. Experts comment on Facebook’s 50 million user credential leak
  2. 40 million more likely affected by massive Facebook data leak - Bitdefender
  3. Project Insecurity (@insecurity) researchers discovered certain #livechatsoftware that were leaking personal details of employee at several high-profile sites. Discover how
  4. Telegram Leaks Public & Private IP Address While Making Calls
  5. The United Nations (@UN) accidentally exposed sensitive information on public @trello boards, in the Jira app, and in #GoogleDocs and
  6. Chegg forces password reset on 40 million users
  7. Hackers are Selling Social Media Logins & Financial Details On Dark Web starting from £2
  8. 3 GOP senators doxed during Kavanaugh hearing
  9. Uber has agreed to pay more than $140 Million for a data breach settlement
  10. USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing

THREATS

  1. Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
  2. GANDCRAB 5.0.1 Ransom Virus – How to Remove It and Restore Data
  3. Facebook Says Three Different Bugs Are Responsible For The Massive Account Hacks
  4. Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
  5. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  6. Facebook Ad Targeting Exploits Users’ 2FA Phone Numbers
  7. Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
  8. Telegram Leaks Public & Private IP Address While Making Calls
  9. #Android #Trojan: How is data being stolen from #messagingapps?
  10. Docs reveal how Fruitfly Mac spyware initially spread
  11. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  12. #Cisco patches yet another hardcoded credentials flaw, this time in its video surveillance manager appliance; the latest vulnerability is at
  13. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
  14. Security roundup: Facebook, ransomware, UEFI rootkit, Berners-Lee’s plan for new internet
  15. Telegram exposes the IP address during a user call by default
  16. #GoScanSSH: How does this #malware work and differ from others?
  17. Xbash Malware Combines Many Malicious Functions in Worm
  18. Discover how the #VPNFilter #malware works and affects users
  19. Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
  20. FBI IC3 warns of cyber attacks exploiting Remote Desktop Protocol (RDP)
  21. Alphabet's Chronicle has given #VirusTotal a makeover. Find out what's in the new VirusTotal Enterprise offering. By @RobWright22
  22. Improving core processes with next-generation mobile productivity solutions can bring power and cost efficiency gains. However, we must not lose
  23. Malware in the Cloud: What You Need to Know
  24. Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware
  25. Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from
  26. Cisco Multiple Security Vulnerabilities Alert
  27. Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files
  28. A Top Facebook Bug Bounty Hunter Shares Their Insights on the Facebook Breach

CRIME

  1. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. Xbash Malware Combines Many Malicious Functions in Worm
  5. Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware

POLITICS

  1. Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from