Nov 9, 2018

APT report for 2018-11-08

TRANSNATIONAL / UNKNOWN

  1. DerpTrolling game server DoS attacker pleads guilty

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. Symantec Uncovers North Korean Group's ATM Attack Malware
  2. Lazarus Group Targets Bank Networks to Rob ATMs
  3. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  4. Symantec researchers dissect North Korean malware used in ATM attacks
  5. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  6. FASTCash: How the Lazarus Group is Emptying Millions from ATMs

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  3. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-08

WINDOWS

  1. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  2. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  3. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  4. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  5. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  6. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  7. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  8. XSS flaw in Evernote allows attackers to execute commands and steal files

LINUX

Nil

UNIX

  1. Symantec Uncovers North Korean Group's ATM Attack Malware
  2. Lazarus Group Targets Bank Networks to Rob ATMs

ANDROID

  1. Google: Newer Android versions are less affected by malware
  2. Spyware disguised as Spanish banking apps removed from Google Play
  3. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524

IOS

  1. iOS 12.1 Vulnerability

MACOS

Nil

Threat report for 2018-11-08

DATA BREACH & DATA LOSS

  1. California Girl Scouts branch suffers data breach
  2. IT Security Culture Evolution of Businesses Exposed
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. 3.6 Billion Records Exposed in Data Breaches Until the End September 2018
  6. DJI Drone Flight Logs, Photos and Videos Exposed to Unauthorized Access
  7. Canada Post Leaked Personal Data On Cannabis Smokers
  8. Drone Vulnerability Could Compromise Enterprise Data
  9. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  10. Radisson Loyalty Program Compromised
  11. Test Your Employees with Internal Phishing Campaigns
  12. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  13. Business email compromise attacks cost over $676 million in 2017, according to the @FBI's Internet #CrimeReport. Learn how to recognize
  14. According to the 2018 Cost of a Data Breach Study by @PonemonPrivacy & @IBM, the global average cost of a
  15. Canada Post leaked personal data, orders of thousands of cannabis smokers
  16. HSBC Bank Alerts US Customers to Data Breach
  17. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  18. Users Stop Engaging With Brands After Data Breaches, Report Finds
  19. Phishing extortion campaign using new, more effective methods
  20. Gamasutra user privacy fragged following IP leak discovery
  21. HSBC confirms data theft in the United States
  22. Increasing value of personal data a 21st century challenge

DENIAL-OF-SERVICE

  1. Cambodia's ISPs Hit By Massive DDoS Attacks
  2. DerpTroll Admits To DDoS On EA, Steam, Sony Game Servers
  3. 4 Cambodia’s ISPs Attacked by DDoS
  4. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  5. Man Behind DDoS Attacks on Gaming Companies Pleads Guilty
  6. To Pay or Not to Pay: A Large Retailer Responds to #DDoS Extortion Find out what happened here:
  7. Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history
  8. Hacker Behind Series of DoS Attack Targeting Gaming Companies Pleaded Guilty

MALVERTISING

Nil

PHISHING

  1. Test Your Employees with Internal Phishing Campaigns
  2. Most IT Security Pros Underestimate Phishing Risks
  3. Most Enterprises Fail to Implement Proper Protection Against Phishing Attacks
  4. Phishing extortion campaign using new, more effective methods
  5. How many of these bad password habits do you have?
  6. Good article about the password problem and a statistic that shows just how bad a problem it has now become...

WEB DEFACEMENT

Nil

BOTNET

  1. Botnet Infects 100,000 Routers to Send Outlook, Hotmail, and Yahoo Spam
  2. New Spam Botnet Likely Infected 400,000 Devices
  3. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  4. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  5. Spam Botnet of Over 100K Routers Abuses UPnP

RANSOMWARE

  1. Dharma Ransomware Hits Altus Baytown Hospital's Systems

CRYPTOMINING & CRYPTOCURRENCIES

  1. Hackers Charged for Creating 6K Strong Cryptojacking Network
  2. Can Blockchain Solve The Problem of Blood Diamonds?
  3. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  4. Managing the Intersection of Cryptocurrency and Compliance
  5. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  6. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  7. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  8. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  9. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  10. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  11. StatCounter Analytics Code Hijacked to Steal Bitcoins from Cryptocurrency Users

MALWARE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal
  3. Google: Newer Android versions are less affected by malware
  4. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  5. Symantec Uncovers North Korean Group's ATM Attack Malware
  6. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  7. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  8. The Pentagon has suddenly started uploading #malware samples from APTs and other nation-state sources to the website VirusTotal.
  9. Symantec researchers dissect North Korean malware used in ATM attacks
  10. Banking Malware Takes Aim at Brazilians
  11. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  12. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  13. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  14. US Cyber Command starts uploading foreign APT malware to VirusTotal
  15. U.S. Cyber Command malware samples to be logged in VirusTotal
  16. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  17. Spyware disguised as Spanish banking apps removed from Google Play
  18. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  19. Did you miss yesterday's #blog? Catch up on how fileless #malware is changing the way we as organizations are treating
  20. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
  21. U.S. Cyber Command Shares Malware via VirusTotal
  22. US Cyber Command starts uploading foreign APT malware to VirusTotal

EXPLOIT

  1. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  2. Cisco Accidentally Released Dirty Cow Exploit Code in Software
  3. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  4. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online

VULNERABILITY

  1. Companies swamped by critical vulnerabilities – Tenable
  2. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  3. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  4. Steam bug could have given you access to all the CD keys of any game
  5. Drone Vulnerability Could Compromise Enterprise Data
  6. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  7. [SingCERT] Alert on Nginx Vulnerabilities (CVE-2018-16843, CVE-2018-16844, and CVE-2018-16845)
  8. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  9. Several Vulnerabilities Patched in nginx
  10. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  11. WooCommerce Plugin file deletion vulnerability exposes WordPress 'failing open' design flaw
  12. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  13. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  14. DJI Patches Forum Bug That Allowed Drone Account Takeovers
  15. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  16. Ranting researcher publishes VM-busting zero-day without warning
  17. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  18. DJI Drone Vulnerability
  19. iOS 12.1 Vulnerability
  20. Encryption flaws in solid state drives enable unauthorised data access
  21. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  22. Ranting researcher publishes #VM-busting zero-day without warning
  23. We don' need no stinkin' bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
  24. Vulnerabilities In Major Self-Encrypting SSDs Allow Encryption Bypass and Affect Bitlocker
  25. [SingCERT] Alert on Critical Apache Struts 2 Remote Code Execution Vulnerability (CVE-2016-1000031)
  26. XSS flaw in Evernote allows attackers to execute commands and steal files
  27. Critical authentication flaw in DJI drone web app fixed
  28. Commoditization of Computing Hardware and the Bugs It Contains
  29. 4 Million Shops Installed WooCommerce Plugin RCE Flaw Allows Attacker to Gain WordPress Sites Admin Access
  30. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524
  31. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online

Region brief for 2018-11-08

ASIA

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. 689,272 plaintext records of Amex India customers exposed online
  3. Cambodia's ISPs Hit By Massive DDoS Attacks
  4. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  5. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  6. Symantec Uncovers North Korean Group's ATM Attack Malware
  7. Lazarus Group Targets Bank Networks to Rob ATMs
  8. 4 Cambodia’s ISPs Attacked by DDoS
  9. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  10. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  11. Symantec researchers dissect North Korean malware used in ATM attacks
  12. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  13. Spam Botnet of Over 100K Routers Abuses UPnP
  14. Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history
  15. HSBC confirms data theft in the United States
  16. Commoditization of Computing Hardware and the Bugs It Contains

OCEANIA

Nil

NORTH AMERICA

  1. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  2. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. Canada Post Leaked Personal Data On Cannabis Smokers
  6. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  7. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  8. Lazarus Group Targets Bank Networks to Rob ATMs
  9. Most IT Security Pros Underestimate Phishing Risks
  10. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  11. Symantec researchers dissect North Korean malware used in ATM attacks
  12. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  13. Spam Botnet of Over 100K Routers Abuses UPnP
  14. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  15. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  16. Canada Post leaked personal data, orders of thousands of cannabis smokers
  17. HSBC Bank Alerts US Customers to Data Breach
  18. US Cyber Command starts uploading foreign APT malware to VirusTotal
  19. U.S. Cyber Command malware samples to be logged in VirusTotal
  20. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  21. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  22. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  23. U.S. Cyber Command Shares Malware via VirusTotal
  24. HSBC confirms data theft in the United States
  25. US Cyber Command starts uploading foreign APT malware to VirusTotal

SOUTH AMERICA

  1. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  2. Banking Malware Takes Aim at Brazilians
  3. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  4. HSBC confirms data theft in the United States

EUROPE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  3. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  4. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  5. iOS 12.1 Vulnerability
  6. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  7. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  8. Encryption flaws in solid state drives enable unauthorised data access
  9. Spyware disguised as Spanish banking apps removed from Google Play
  10. HSBC confirms data theft in the United States

AFRICA

Nil

Sector brief for 2018-11-08

HEALTHCARE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Dharma Ransomware Hits Altus Baytown Hospital's Systems
  3. Top 5 Threats Healthcare Organizations Face and How to Combat Them

TRANSPORT

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems

BANKING & FINANCE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. California Girl Scouts branch suffers data breach
  3. Dharma Ransomware Hits Altus Baytown Hospital's Systems
  4. Can Blockchain Solve The Problem of Blood Diamonds?
  5. Symantec Uncovers North Korean Group's ATM Attack Malware
  6. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  7. Test Your Employees with Internal Phishing Campaigns
  8. Lazarus Group Targets Bank Networks to Rob ATMs
  9. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  10. Symantec researchers dissect North Korean malware used in ATM attacks
  11. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  12. Banking Malware Takes Aim at Brazilians
  13. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  14. FASTCash: How the Lazarus Group is Emptying Millions from ATMs
  15. HSBC Bank Alerts US Customers to Data Breach
  16. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  17. Spyware disguised as Spanish banking apps removed from Google Play
  18. HSBC confirms data theft in the United States

INFORMATION & TELECOMMUNICATION

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Botnet Infects 100,000 Routers to Send Outlook, Hotmail, and Yahoo Spam
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  6. 4 Cambodia’s ISPs Attacked by DDoS
  7. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  8. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  9. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  10. Spam Botnet of Over 100K Routers Abuses UPnP
  11. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  12. US Cyber Command starts uploading foreign APT malware to VirusTotal
  13. To Pay or Not to Pay: A Large Retailer Responds to #DDoS Extortion Find out what happened here:
  14. How many of these bad password habits do you have?
  15. Did you miss yesterday's #blog? Catch up on how fileless #malware is changing the way we as organizations are treating
  16. Commoditization of Computing Hardware and the Bugs It Contains
  17. Good article about the password problem and a statistic that shows just how bad a problem it has now become...

FOOD

Nil

WATER

Nil

ENERGY

  1. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  2. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems

GOVERNMENT & PUBLIC SERVICE

  1. Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal
  2. Hackers Charged for Creating 6K Strong Cryptojacking Network
  3. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  4. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  5. Lazarus Group Targets Bank Networks to Rob ATMs
  6. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  7. Symantec researchers dissect North Korean malware used in ATM attacks
  8. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  9. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --

Daily brief for 2018-11-08

ASIA

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. 689,272 plaintext records of Amex India customers exposed online
  3. Cambodia's ISPs Hit By Massive DDoS Attacks
  4. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  5. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  6. Symantec Uncovers North Korean Group's ATM Attack Malware
  7. Lazarus Group Targets Bank Networks to Rob ATMs
  8. 4 Cambodia’s ISPs Attacked by DDoS
  9. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  10. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  11. Symantec researchers dissect North Korean malware used in ATM attacks
  12. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  13. Spam Botnet of Over 100K Routers Abuses UPnP
  14. Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history
  15. HSBC confirms data theft in the United States
  16. Commoditization of Computing Hardware and the Bugs It Contains

WORLD

  1. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  2. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. Canada Post Leaked Personal Data On Cannabis Smokers
  6. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  7. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  8. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  9. Lazarus Group Targets Bank Networks to Rob ATMs
  10. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  11. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  12. Most IT Security Pros Underestimate Phishing Risks
  13. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  14. Symantec researchers dissect North Korean malware used in ATM attacks
  15. Banking Malware Takes Aim at Brazilians
  16. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  17. iOS 12.1 Vulnerability
  18. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  19. Spam Botnet of Over 100K Routers Abuses UPnP
  20. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  21. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  22. Encryption flaws in solid state drives enable unauthorised data access
  23. Canada Post leaked personal data, orders of thousands of cannabis smokers
  24. HSBC Bank Alerts US Customers to Data Breach
  25. US Cyber Command starts uploading foreign APT malware to VirusTotal
  26. U.S. Cyber Command malware samples to be logged in VirusTotal
  27. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  28. Spyware disguised as Spanish banking apps removed from Google Play
  29. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  30. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  31. U.S. Cyber Command Shares Malware via VirusTotal
  32. HSBC confirms data theft in the United States
  33. US Cyber Command starts uploading foreign APT malware to VirusTotal

ATTACKS

  1. California Girl Scouts branch suffers data breach
  2. IT Security Culture Evolution of Businesses Exposed
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. 3.6 Billion Records Exposed in Data Breaches Until the End September 2018
  6. DJI Drone Flight Logs, Photos and Videos Exposed to Unauthorized Access
  7. Canada Post Leaked Personal Data On Cannabis Smokers
  8. Drone Vulnerability Could Compromise Enterprise Data
  9. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  10. Radisson Loyalty Program Compromised
  11. Test Your Employees with Internal Phishing Campaigns
  12. Most IT Security Pros Underestimate Phishing Risks
  13. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  14. Business email compromise attacks cost over $676 million in 2017, according to the @FBI's Internet #CrimeReport. Learn how to recognize
  15. Most Enterprises Fail to Implement Proper Protection Against Phishing Attacks
  16. According to the 2018 Cost of a Data Breach Study by @PonemonPrivacy & @IBM, the global average cost of a
  17. Canada Post leaked personal data, orders of thousands of cannabis smokers
  18. HSBC Bank Alerts US Customers to Data Breach
  19. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  20. Users Stop Engaging With Brands After Data Breaches, Report Finds
  21. Phishing extortion campaign using new, more effective methods
  22. Gamasutra user privacy fragged following IP leak discovery
  23. How many of these bad password habits do you have?
  24. HSBC confirms data theft in the United States
  25. Increasing value of personal data a 21st century challenge
  26. Good article about the password problem and a statistic that shows just how bad a problem it has now become...

THREATS

  1. Companies swamped by critical vulnerabilities – Tenable
  2. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  3. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  4. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  5. Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal
  6. Google: Newer Android versions are less affected by malware
  7. Hackers Charged for Creating 6K Strong Cryptojacking Network
  8. Dharma Ransomware Hits Altus Baytown Hospital's Systems
  9. Steam bug could have given you access to all the CD keys of any game
  10. Drone Vulnerability Could Compromise Enterprise Data
  11. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  12. [SingCERT] Alert on Nginx Vulnerabilities (CVE-2018-16843, CVE-2018-16844, and CVE-2018-16845)
  13. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  14. Can Blockchain Solve The Problem of Blood Diamonds?
  15. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  16. Symantec Uncovers North Korean Group's ATM Attack Malware
  17. Several Vulnerabilities Patched in nginx
  18. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  19. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  20. The Pentagon has suddenly started uploading #malware samples from APTs and other nation-state sources to the website VirusTotal.
  21. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  22. WooCommerce Plugin file deletion vulnerability exposes WordPress 'failing open' design flaw
  23. Managing the Intersection of Cryptocurrency and Compliance
  24. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  25. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  26. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  27. DJI Patches Forum Bug That Allowed Drone Account Takeovers
  28. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  29. Symantec researchers dissect North Korean malware used in ATM attacks
  30. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  31. Ranting researcher publishes VM-busting zero-day without warning
  32. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  33. Banking Malware Takes Aim at Brazilians
  34. DJI Drone Vulnerability
  35. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  36. iOS 12.1 Vulnerability
  37. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  38. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  39. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  40. Encryption flaws in solid state drives enable unauthorised data access
  41. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  42. Ranting researcher publishes #VM-busting zero-day without warning
  43. We don' need no stinkin' bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
  44. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  45. Vulnerabilities In Major Self-Encrypting SSDs Allow Encryption Bypass and Affect Bitlocker
  46. [SingCERT] Alert on Critical Apache Struts 2 Remote Code Execution Vulnerability (CVE-2016-1000031)
  47. US Cyber Command starts uploading foreign APT malware to VirusTotal
  48. U.S. Cyber Command malware samples to be logged in VirusTotal
  49. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  50. Spyware disguised as Spanish banking apps removed from Google Play
  51. XSS flaw in Evernote allows attackers to execute commands and steal files
  52. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  53. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  54. Did you miss yesterday's #blog? Catch up on how fileless #malware is changing the way we as organizations are treating
  55. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
  56. U.S. Cyber Command Shares Malware via VirusTotal
  57. Critical authentication flaw in DJI drone web app fixed
  58. Commoditization of Computing Hardware and the Bugs It Contains
  59. 4 Million Shops Installed WooCommerce Plugin RCE Flaw Allows Attacker to Gain WordPress Sites Admin Access
  60. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524
  61. StatCounter Analytics Code Hijacked to Steal Bitcoins from Cryptocurrency Users
  62. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online
  63. US Cyber Command starts uploading foreign APT malware to VirusTotal

CRIME

  1. California Girl Scouts branch suffers data breach
  2. 3.6 Billion Records Exposed in Data Breaches Until the End September 2018
  3. Can Blockchain Solve The Problem of Blood Diamonds?
  4. Radisson Loyalty Program Compromised
  5. Test Your Employees with Internal Phishing Campaigns
  6. Lazarus Group Targets Bank Networks to Rob ATMs
  7. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  8. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  9. Business email compromise attacks cost over $676 million in 2017, according to the @FBI's Internet #CrimeReport. Learn how to recognize
  10. Symantec researchers dissect North Korean malware used in ATM attacks
  11. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  12. Man Behind DDoS Attacks on Gaming Companies Pleads Guilty
  13. DerpTrolling game server DoS attacker pleads guilty
  14. HSBC Bank Alerts US Customers to Data Breach
  15. Phishing extortion campaign using new, more effective methods
  16. To Pay or Not to Pay: A Large Retailer Responds to #DDoS Extortion Find out what happened here:
  17. Spyware disguised as Spanish banking apps removed from Google Play
  18. Hacker Behind Series of DoS Attack Targeting Gaming Companies Pleaded Guilty
  19. HSBC confirms data theft in the United States

POLITICS

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  3. Lazarus Group Targets Bank Networks to Rob ATMs
  4. 4 Cambodia’s ISPs Attacked by DDoS
  5. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  6. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  7. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --