Oct 21, 2018

APT report for 2018-10-20

TRANSNATIONAL / UNKNOWN

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. .@RobertMLee said #GreyEnergy is a threat, but people shouldn't conclude from @ESET research that the group will only target

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-20

WINDOWS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  2. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems

LINUX

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  2. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  3. Xerosploit – Toolkit to Perform MITM, Spoofing, DOS, Images Sniffing/Replacement, WD Attacks

UNIX

Nil

ANDROID

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

IOS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

MACOS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

Threat report for 2018-10-20

DATA BREACH & DATA LOSS

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. If it's only able to leak data at 15 bits per hour, is #NetSpectre a serious threat? Learn more about
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  5. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel

DENIAL-OF-SERVICE

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

MALVERTISING

Nil

PHISHING

Nil

WEB DEFACEMENT

Nil

BOTNET

  1. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

RANSOMWARE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

MALWARE

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  3. Here's how the hack works: Temperatures used in the pulp cooking process begin to vary random intervals. The fluctuations in temperature

EXPLOIT

  1. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub

VULNERABILITY

  1. Oracle Critical Patch Update October 2018 Addressed 301 Flaws Including 47 High-Rated Flaws
  2. Two Critical RCE Bugs Patched in Drupal 7 and 8
  3. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
  4. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  5. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  6. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  7. OpenSSH 7.9 released: fixed bugs
  8. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  9. Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players
  10. Vulnerabilities in telepresence robots allow access to image and video
  11. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems

Region brief for 2018-10-20

ASIA

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

OCEANIA

Nil

NORTH AMERICA

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations

SOUTH AMERICA

Nil

EUROPE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

AFRICA

Nil

Sector brief for 2018-10-20

HEALTHCARE

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations
  2. Vulnerabilities in telepresence robots allow access to image and video

TRANSPORT

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

BANKING & FINANCE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations

INFORMATION & TELECOMMUNICATION

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin

FOOD

Nil

WATER

Nil

ENERGY

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

GOVERNMENT & PUBLIC SERVICE

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations

Daily brief for 2018-10-20

ASIA

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

WORLD

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

ATTACKS

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. If it's only able to leak data at 15 bits per hour, is #NetSpectre a serious threat? Learn more about
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  5. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel

THREATS

  1. Oracle Critical Patch Update October 2018 Addressed 301 Flaws Including 47 High-Rated Flaws
  2. Syrian victims of the GandCrab ransomware can decrypt their files for free
  3. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  4. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  5. Two Critical RCE Bugs Patched in Drupal 7 and 8
  6. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
  7. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  8. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  9. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  10. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  11. OpenSSH 7.9 released: fixed bugs
  12. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  13. Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players
  14. Vulnerabilities in telepresence robots allow access to image and video
  15. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems
  16. Here's how the hack works: Temperatures used in the pulp cooking process begin to vary random intervals. The fluctuations in temperature

CRIME

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin

POLITICS

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds
  2. Vulnerabilities in telepresence robots allow access to image and video