Nov 21, 2018

Daily brief for 2018-11-20

ASIA

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  3. Malvertising in Apple Pay Targets iPhone Users
  4. Kaspersky Security Bulletin: Threat Predictions for 2019
  5. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents

WORLD

  1. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  2. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  3. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  4. Voxox leak: Millions of SMS messages exposed
  5. Russia’s Elite Hackers May Have New Phishing Tricks
  6. Web skimmers compete in Umbro Brasil hack
  7. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  8. Government Agencies and Think Tanks attacked, APT29 suspected
  9. An Introduction to Magecart
  10. Hackers Linked to Russia Impersonate US Officials
  11. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  12. Russian hackers are trying out this new malware against US and European targets
  13. TEMP.Periscope Spearphishing
  14. Russian hackers are trying out this new malware against US and European targets
  15. Russian APT activity is resurgent, researchers say
  16. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  17. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  18. Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America
  19. Zscaler ThreatLabZ Phishing Roundup
  20. Dutch audit finds Microsoft Office leaks confidential data
  21. Kaspersky Security Bulletin: Threat Predictions for 2019
  22. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group
  23. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  24. Confiant spots major malvertising attack
  25. Google, Target Hit by Twitter Bitcoin Scam Account Hacks
  26. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

ATTACKS

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. Gmail Glitch Enables Anonymous Messages in Phishing Attacks
  3. jQuery File Upload Disclosure Due Diligence
  4. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  5. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  6. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  7. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  8. Voxox leak: Millions of SMS messages exposed
  9. Russia’s Elite Hackers May Have New Phishing Tricks
  10. Second WordPress hacking campaign underway, this one targeting AMP for WP plugin
  11. Vision Direct Reveals Data Breach
  12. Malvertising in Apple Pay Targets iPhone Users
  13. Instagram glitch exposed some user passwords
  14. OSIsoft Warns Employees, Contractors of Data Breach
  15. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  16. TEMP.Periscope Spearphishing
  17. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  18. OceanLotus: New watering hole attack in Southeast Asia
  19. OceanLotus: New watering hole attack in Southeast Asia
  20. tRat: New Modular RAT Appears in Multiple Email Campaigns
  21. Emotet Campaigns Persist, Utilize Updated Tactics and Techniques
  22. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  23. AWS moves to curb S3 data leaks, but Chris Vickery is doubtful
  24. TalkTalk hackers jailed for role in £77m data breach
  25. CarBlues – Bluetooth Vehicle Hack Exploit Affects Millions Of Vehicles Exposing Users PII
  26. Zscaler ThreatLabZ Phishing Roundup
  27. 2018 holiday travel period expected to be the busiest travel season on record
  28. Vision Direct 'fesses up to hack that exposed customer names, payment cards
  29. A little phishing knowledge may be a dangerous thing
  30. Dutch audit finds Microsoft Office leaks confidential data
  31. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group
  32. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  33. Confiant spots major malvertising attack
  34. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

THREATS

  1. Instagram bug exposes user passwords
  2. Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS
  3. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  4. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  5. Flash Player Type Confusion Critical Vulnerability, Another Reason Not to Use It
  6. Down But Not Out, WannaCry Malware Continues to Infect Unpatched Windows PCs
  7. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  8. 560,000 Duped Into Installing Android Malware in the Form of Fake Driving Games
  9. Flash Player Update Patches Disclosed Code Execution Flaw
  10. Attackers Target Drupal Web Servers with Chained Vulnerabilities
  11. DirtyCOW Is Back In Backdoor Attack Targeting Drupal Web Servers
  12. Inserted Malicious URLs within Office Documents’ Embedded Videos
  13. Russian hackers are trying out this new malware against US and European targets
  14. Russian hackers are trying out this new malware against US and European targets
  15. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  16. WordPress GDPR Plug-in Contains Privilege Escalation Flaw
  17. tRat: New Modular RAT Appears in Multiple Email Campaigns
  18. Dharma Ransomware Variant Discovered
  19. Hackers Exploit Vulnerability in WP GDPR Compliance Plugin – Update Now
  20. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  21. For Smbs Ransomware Attacks still the Greatest Online Threat
  22. Almost 50 Percent of 2018 Vulnerabilities Can Be Exploited Remotely
  23. Targeted ransomware attacks on the rise in 2018, NCSC warns
  24. TP-Link fixes 2 Remote Code Execution flaws in TL-R600VPN SOHO Router and other issues
  25. Raft of flaws discovered in MiSafes child-monitoring devices
  26. Scumbags cram Make-A-Wish website with coin-mining malware
  27. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  28. Microsoft Releases Azure Blockchain Development Kit
  29. DirtyCOW is back in backdoor attack targeting Drupal Web Servers
  30. Can a D-Link router vulnerability threaten bank customers?
  31. 3 New Code Execution Flaws Discovered in Atlantis Word Processor
  32. Vulnerability Spotlight: Multiple remote code execution vulnerabilities in Atlantis Word Processor
  33. Google Account Hacked for Fake Bitcoin Reward
  34. 2019 Security Predictions – Utilities and Industrial Control Systems Targeted with Ransomware
  35. Google, Target Hit by Twitter Bitcoin Scam Account Hacks
  36. The wiper #malware that briefly disrupted the Winter #Olympics earlier this year appears to be back - now with a
  37. 13 Malicious Apps in Google Play With More than 560,000+ Installs
  38. Apache OpenOffice 4.1.6 release: important bug fixes and security fixes
  39. Almost 50 Percent of 2018 Vulnerabilities Can Be Exploited Remotely
  40. #BluetoothDevices might be at risk after a new #Bluetooth vulnerability was found targeting #firmware or operating system software drivers. Learn

CRIME

  1. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  2. An Introduction to Magecart
  3. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  4. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  5. Zscaler ThreatLabZ Phishing Roundup
  6. Magecart Spies Payment Cards From Retailer Vision Direct
  7. Kaspersky Security Bulletin: Threat Predictions for 2019
  8. Google, Target Hit by Twitter Bitcoin Scam Account Hacks
  9. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

POLITICS

  1. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  2. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  3. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  4. Russia’s Elite Hackers May Have New Phishing Tricks
  5. Web skimmers compete in Umbro Brasil hack
  6. TEMP.Periscope Spearphishing
  7. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  8. Magecart Spies Payment Cards From Retailer Vision Direct
  9. Dutch audit finds Microsoft Office leaks confidential data
  10. Kaspersky Security Bulletin: Threat Predictions for 2019
  11. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents

Sector brief for 2018-11-20

HEALTHCARE

  1. Hackers Linked to Russia Impersonate US Officials
  2. Russian APT activity is resurgent, researchers say
  3. Zscaler ThreatLabZ Phishing Roundup

TRANSPORT

Nil

BANKING & FINANCE

  1. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  2. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  3. Web skimmers compete in Umbro Brasil hack
  4. Malvertising in Apple Pay Targets iPhone Users
  5. An Introduction to Magecart
  6. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  7. Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America
  8. Emotet Campaigns Persist, Utilize Updated Tactics and Techniques
  9. For Smbs Ransomware Attacks still the Greatest Online Threat
  10. Zscaler ThreatLabZ Phishing Roundup
  11. Vision Direct 'fesses up to hack that exposed customer names, payment cards
  12. Magecart Spies Payment Cards From Retailer Vision Direct
  13. Kaspersky Security Bulletin: Threat Predictions for 2019
  14. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  15. Can a D-Link router vulnerability threaten bank customers?
  16. Google Account Hacked for Fake Bitcoin Reward
  17. 2019 Security Predictions – Utilities and Industrial Control Systems Targeted with Ransomware
  18. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

INFORMATION & TELECOMMUNICATION

  1. Instagram bug exposes user passwords
  2. Gmail Glitch Enables Anonymous Messages in Phishing Attacks
  3. 560,000 Duped Into Installing Android Malware in the Form of Fake Driving Games
  4. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  5. Instagram glitch exposed some user passwords
  6. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  7. Zscaler ThreatLabZ Phishing Roundup
  8. 2018 holiday travel period expected to be the busiest travel season on record
  9. Kaspersky Security Bulletin: Threat Predictions for 2019
  10. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  11. Vulnerability Spotlight: Multiple remote code execution vulnerabilities in Atlantis Word Processor
  12. Google Account Hacked for Fake Bitcoin Reward
  13. Google, Target Hit by Twitter Bitcoin Scam Account Hacks

FOOD

Nil

WATER

  1. Tech Docs: Keep Out of the Flood Zone with DoS Protection

ENERGY

  1. Tech Docs: Keep Out of the Flood Zone with DoS Protection
  2. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  3. 2019 Security Predictions – Utilities and Industrial Control Systems Targeted with Ransomware

GOVERNMENT & PUBLIC SERVICE

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  3. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  4. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  5. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  6. Russia’s Elite Hackers May Have New Phishing Tricks
  7. Government Agencies and Think Tanks attacked, APT29 suspected
  8. Hackers Linked to Russia Impersonate US Officials
  9. Russian APT activity is resurgent, researchers say
  10. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  11. OceanLotus: New watering hole attack in Southeast Asia
  12. OceanLotus: New watering hole attack in Southeast Asia
  13. Kaspersky Security Bulletin: Threat Predictions for 2019
  14. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  15. Google, Target Hit by Twitter Bitcoin Scam Account Hacks

Region brief for 2018-11-20

ASIA

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  3. Malvertising in Apple Pay Targets iPhone Users
  4. Kaspersky Security Bulletin: Threat Predictions for 2019
  5. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents

OCEANIA

  1. Zscaler ThreatLabZ Phishing Roundup

NORTH AMERICA

  1. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  2. Russia’s Elite Hackers May Have New Phishing Tricks
  3. Web skimmers compete in Umbro Brasil hack
  4. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  5. Hackers Linked to Russia Impersonate US Officials
  6. Russian hackers are trying out this new malware against US and European targets
  7. Russian hackers are trying out this new malware against US and European targets
  8. Russian APT activity is resurgent, researchers say
  9. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  10. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  11. Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America
  12. Zscaler ThreatLabZ Phishing Roundup
  13. Kaspersky Security Bulletin: Threat Predictions for 2019
  14. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  15. Confiant spots major malvertising attack
  16. Google, Target Hit by Twitter Bitcoin Scam Account Hacks

SOUTH AMERICA

Nil

EUROPE

  1. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  2. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  3. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  4. Voxox leak: Millions of SMS messages exposed
  5. Russia’s Elite Hackers May Have New Phishing Tricks
  6. Government Agencies and Think Tanks attacked, APT29 suspected
  7. An Introduction to Magecart
  8. Hackers Linked to Russia Impersonate US Officials
  9. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  10. Russian hackers are trying out this new malware against US and European targets
  11. TEMP.Periscope Spearphishing
  12. Russian hackers are trying out this new malware against US and European targets
  13. Russian APT activity is resurgent, researchers say
  14. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  15. Dutch audit finds Microsoft Office leaks confidential data
  16. Kaspersky Security Bulletin: Threat Predictions for 2019
  17. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group
  18. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

AFRICA

Nil

Threat report for 2018-11-20

DATA BREACH & DATA LOSS

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. jQuery File Upload Disclosure Due Diligence
  3. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  4. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  5. Voxox leak: Millions of SMS messages exposed
  6. Second WordPress hacking campaign underway, this one targeting AMP for WP plugin
  7. Vision Direct Reveals Data Breach
  8. Instagram glitch exposed some user passwords
  9. OSIsoft Warns Employees, Contractors of Data Breach
  10. Two Young Men Jailed for Involvement in TalkTalk Data Breach
  11. tRat: New Modular RAT Appears in Multiple Email Campaigns
  12. Emotet Campaigns Persist, Utilize Updated Tactics and Techniques
  13. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  14. AWS moves to curb S3 data leaks, but Chris Vickery is doubtful
  15. TalkTalk hackers jailed for role in £77m data breach
  16. CarBlues – Bluetooth Vehicle Hack Exploit Affects Millions Of Vehicles Exposing Users PII
  17. 2018 holiday travel period expected to be the busiest travel season on record
  18. Vision Direct 'fesses up to hack that exposed customer names, payment cards
  19. Dutch audit finds Microsoft Office leaks confidential data
  20. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group
  21. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  22. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

DENIAL-OF-SERVICE

  1. Tech Docs: Keep Out of the Flood Zone with DoS Protection

MALVERTISING

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. Malvertising in Apple Pay Targets iPhone Users
  3. OceanLotus: New watering hole attack in Southeast Asia
  4. OceanLotus: New watering hole attack in Southeast Asia
  5. Confiant spots major malvertising attack

PHISHING

  1. Gmail Glitch Enables Anonymous Messages in Phishing Attacks
  2. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  3. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  4. Russia’s Elite Hackers May Have New Phishing Tricks
  5. TEMP.Periscope Spearphishing
  6. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  7. Zscaler ThreatLabZ Phishing Roundup
  8. A little phishing knowledge may be a dangerous thing
  9. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group

WEB DEFACEMENT

Nil

BOTNET

  1. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit

RANSOMWARE

  1. Dharma Ransomware Variant Discovered
  2. For Smbs Ransomware Attacks still the Greatest Online Threat
  3. Targeted ransomware attacks on the rise in 2018, NCSC warns
  4. 2019 Security Predictions – Utilities and Industrial Control Systems Targeted with Ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  2. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  3. Microsoft Releases Azure Blockchain Development Kit
  4. Google Account Hacked for Fake Bitcoin Reward
  5. Google, Target Hit by Twitter Bitcoin Scam Account Hacks

MALWARE

  1. Down But Not Out, WannaCry Malware Continues to Infect Unpatched Windows PCs
  2. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  3. 560,000 Duped Into Installing Android Malware in the Form of Fake Driving Games
  4. DirtyCOW Is Back In Backdoor Attack Targeting Drupal Web Servers
  5. Inserted Malicious URLs within Office Documents’ Embedded Videos
  6. Russian hackers are trying out this new malware against US and European targets
  7. Russian hackers are trying out this new malware against US and European targets
  8. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  9. tRat: New Modular RAT Appears in Multiple Email Campaigns
  10. Scumbags cram Make-A-Wish website with coin-mining malware
  11. DirtyCOW is back in backdoor attack targeting Drupal Web Servers
  12. The wiper #malware that briefly disrupted the Winter #Olympics earlier this year appears to be back - now with a
  13. 13 Malicious Apps in Google Play With More than 560,000+ Installs

EXPLOIT

  1. Hackers Exploit Vulnerability in WP GDPR Compliance Plugin – Update Now
  2. CarBlues – Bluetooth Vehicle Hack Exploit Affects Millions Of Vehicles Exposing Users PII

VULNERABILITY

  1. Instagram bug exposes user passwords
  2. Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS
  3. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  4. Flash Player Type Confusion Critical Vulnerability, Another Reason Not to Use It
  5. Flash Player Update Patches Disclosed Code Execution Flaw
  6. Attackers Target Drupal Web Servers with Chained Vulnerabilities
  7. WordPress GDPR Plug-in Contains Privilege Escalation Flaw
  8. Hackers Exploit Vulnerability in WP GDPR Compliance Plugin – Update Now
  9. Almost 50 Percent of 2018 Vulnerabilities Can Be Exploited Remotely
  10. TP-Link fixes 2 Remote Code Execution flaws in TL-R600VPN SOHO Router and other issues
  11. Raft of flaws discovered in MiSafes child-monitoring devices
  12. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  13. Can a D-Link router vulnerability threaten bank customers?
  14. 3 New Code Execution Flaws Discovered in Atlantis Word Processor
  15. Vulnerability Spotlight: Multiple remote code execution vulnerabilities in Atlantis Word Processor
  16. Apache OpenOffice 4.1.6 release: important bug fixes and security fixes
  17. Almost 50 Percent of 2018 Vulnerabilities Can Be Exploited Remotely
  18. #BluetoothDevices might be at risk after a new #Bluetooth vulnerability was found targeting #firmware or operating system software drivers. Learn

Platform report for 2018-11-20

WINDOWS

  1. Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS
  2. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  3. Flash Player Type Confusion Critical Vulnerability, Another Reason Not to Use It
  4. Down But Not Out, WannaCry Malware Continues to Infect Unpatched Windows PCs
  5. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  6. Malvertising in Apple Pay Targets iPhone Users
  7. Hackers Linked to Russia Impersonate US Officials
  8. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  9. Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America
  10. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign
  11. Kaspersky Security Bulletin: Threat Predictions for 2019
  12. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  13. Apache OpenOffice 4.1.6 release: important bug fixes and security fixes

LINUX

  1. Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS
  2. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  3. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  4. Flash Player Type Confusion Critical Vulnerability, Another Reason Not to Use It
  5. Malvertising in Apple Pay Targets iPhone Users
  6. Attackers Target Drupal Web Servers with Chained Vulnerabilities

UNIX

Nil

ANDROID

  1. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  2. 560,000 Duped Into Installing Android Malware in the Form of Fake Driving Games
  3. Web skimmers compete in Umbro Brasil hack
  4. Malvertising in Apple Pay Targets iPhone Users
  5. Kaspersky Security Bulletin: Threat Predictions for 2019
  6. 13 Malicious Apps in Google Play With More than 560,000+ Installs

IOS

  1. Malvertising in Apple Pay Targets iPhone Users
  2. Kaspersky Security Bulletin: Threat Predictions for 2019

MACOS

  1. Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS
  2. Flash Player Type Confusion Critical Vulnerability, Another Reason Not to Use It
  3. Mac users using Exodus cryptocurrency wallet targeted by a small spam campaign

APT report for 2018-11-20

TRANSNATIONAL / UNKNOWN

  1. Magecart group hilariously sabotages competitor
  2. Web skimmers compete in Umbro Brasil hack
  3. An Introduction to Magecart
  4. Magecart Spies Payment Cards From Retailer Vision Direct

CHINA

  1. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  2. TEMP.Periscope Spearphishing

INDIA

Nil

NORTH KOREA

  1. Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America

PAKISTAN

Nil

VIETNAM

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign

IRAN

  1. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  2. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  3. Russia’s Elite Hackers May Have New Phishing Tricks
  4. Sednit: What’s going on with Zebrocy?
  5. Sednit: What’s going on with Zebrocy?
  6. Government Agencies and Think Tanks attacked, APT29 suspected
  7. Hackers Linked to Russia Impersonate US Officials
  8. Russian APT activity is resurgent, researchers say
  9. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  10. Kaspersky Security Bulletin: Threat Predictions for 2019
  11. Cozy Bear tracks: Phishing campaign looks like work of Russian APT group

SERBIA

Nil

UKRAINE

Nil