Nov 22, 2018

APT report for 2018-11-21

TRANSNATIONAL / UNKNOWN

  1. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  2. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  3. Magecart Black Hats Battle it Out On Infected Site
  4. Exploit Windows Remote PC with EternalBlue & DoublePulsar Exploit through Metasploit
  5. Is Magecart Checking Out Your Secure Online Transactions?
  6. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  7. Infowars Online Store Got Infected with Card Skimming Malware
  8. MageCart Group Sabotages Rival to Ruin Data and Reputation

CHINA

  1. Inspiring the Next Generation of Tech Talent
  2. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign

INDIA

Nil

NORTH KOREA

  1. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  2. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia

PAKISTAN

Nil

VIETNAM

Nil

IRAN

  1. Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  2. Sofacy APT unleashes new 'Cannon' trojan
  3. New Pterodo Backdoor Malware Detected By Ukraine
  4. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  5. Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
  6. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  7. Latest Hacking News Podcast
  8. Sofacy APT group used a new tool in latest attacks, the Cannon
  9. Russian hackers are conducting more covert attacks on US and European computers
  10. Fancy Bear APT Uses New Cannon Trojan to Target Government Entities
  11. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  12. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-21

WINDOWS

  1. What Is Windows PowerShell (And Could It Be Malicious)?
  2. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  3. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  4. New Pterodo Backdoor Malware Detected By Ukraine
  5. Exploit Windows Remote PC with EternalBlue & DoublePulsar Exploit through Metasploit
  6. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  7. Adobe plugs critical RCE Flash Player flaw, update ASAP! Exploitation may be imminent
  8. CVE-2018-15981: Adobe Flash Player Arbitrary Code Execution Vulnerability
  9. How to find, is link malicious/URL or not

LINUX

  1. What Is Windows PowerShell (And Could It Be Malicious)?
  2. Mirai Used as Payload in Hadoop YARN Vulnerability
  3. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  4. Adobe plugs critical RCE Flash Player flaw, update ASAP! Exploitation may be imminent
  5. CVE-2018-15981: Adobe Flash Player Arbitrary Code Execution Vulnerability
  6. Uncover virtual hosts of domain with Fierce
  7. How to find, is link malicious/URL or not

UNIX

Nil

ANDROID

  1. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  2. 500K Android users hit with malware, and what to do if you're infected
  3. 13 Malware-Laden Fake Apps on Google Play
  4. Malicious programs disguised as racing games on Google Play
  5. "Luiz O Pinto" pushed 500,000+ installs of malware via Google Play, in ~1 week.

IOS

  1. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  2. 13 Malware-Laden Fake Apps on Google Play
  3. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit

MACOS

  1. Pen-test at Dropbox turns up three Apple 0-day bugs
  2. What Is Windows PowerShell (And Could It Be Malicious)?
  3. Adobe plugs critical RCE Flash Player flaw, update ASAP! Exploitation may be imminent
  4. CVE-2018-15981: Adobe Flash Player Arbitrary Code Execution Vulnerability

Threat report for 2018-11-21

DATA BREACH & DATA LOSS

  1. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  2. A flaw in US Postal Service website exposed data on 60 Million Users
  3. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  4. Amazon Customer Email Addresses Leaked Because of 'Technical Error'
  5. Google Taking Over Health Records Raises Patient Privacy Fears
  6. Amazon tech error leaks customers’ email addresses
  7. USPS Site Exposed Data on 60 Million Users
  8. Vision Direct Deals With Customer Data Leak
  9. Amazon suffers data breach days before Black Friday
  10. Emotet’s Thanksgiving Campaign Delivers New Recipes for Compromise
  11. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  12. Record Retention
  13. A hacker known as #Tessa88 offered several compromise databases obtained from LinkedIn, MySpace and other companies. Now Recorded Future believes
  14. The promised integration with #HaveIBeenPwned is expanding in #FirefoxMonitor with new breach alerts when a user visits a recently compromised
  15. Amazon warns customers it leaked their names and email addresses
  16. Amazon leaks users' email addresses due to 'technical error'
  17. High Tail Hall data breach exposes over 400,000 furry fans
  18. Facebook Ads Urge Its Staff To Leak Secrets
  19. Amazon Suffers Data Breach Days Before Black Friday
  20. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  21. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  22. Amazon UK is notifying a data breach to its customers days before Black Friday
  23. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  24. White House admits Ivanka Trump used private email for government business
  25. .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
  26. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  27. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  28. Amazon Data Leak Exposes Email Addresses Right Before Black Friday
  29. Yikes...#Instagram Accidentally Exposed Some Users' #Passwords In Plaintext
  30. APAC consumers want IoT devices, but fear data leaks
  31. OUR BLACK FRIDAY DEALS ARE LIVE! Get 50% off from FREEDOME VPN and TOTAL subscriptions with coupon code BLACKFRIDAY. Buy now:
  32. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

DENIAL-OF-SERVICE

Nil

MALVERTISING

  1. New OceanLotus watering hole attacks target southeast Asia

PHISHING

  1. Phishing: It's all too easy on mobile devices
  2. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  3. Black Friday Phishing Dos and Don’ts
  4. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  5. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  6. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  7. #CyberMonday Tip 1: Be careful of phishing scams claiming to be from a package-delivery company with links to tracking information. AVG
  8. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  9. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  10. Yikes...#Instagram Accidentally Exposed Some Users' #Passwords In Plaintext
  11. #Gmail Glitch Enables Anonymous Messages in #Phishing Attacks:
  12. Phishing Scams Serious Problem for Canada’s Global Affairs
  13. Microsoft now lets you log into Outlook, Skype, Xbox Live without a password
  14. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

WEB DEFACEMENT

Nil

BOTNET

  1. Outlaw Group Botnet Enhanced
  2. A new #botnet -- #Mylobot -- has shown new, complex levels of tools and techniques that are subsequently altering botnet
  3. New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform Cryptocurrency-Mining & Brute-Force Attack

RANSOMWARE

  1. City of Valdez, Alaska admits to paying off ransomware infection
  2. Malaysia’s largest media company becomes victim of a ransomware attack

CRYPTOMINING & CRYPTOCURRENCIES

  1. Malware Moves: Attackers Retool for Cryptocurrency Theft
  2. New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform Cryptocurrency-Mining & Brute-Force Attack
  3. Signing and Verifying Ethereum Signatures
  4. US Department of Justice is investigating Tether for manipulation of market prices
  5. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

MALWARE

  1. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  2. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  3. What Is Windows PowerShell (And Could It Be Malicious)?
  4. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  5. Mirai Used as Payload in Hadoop YARN Vulnerability
  6. 500K Android users hit with malware, and what to do if you're infected
  7. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  8. 13 Malware-Laden Fake Apps on Google Play
  9. Italian Naval Industry Attacked By MartyMcFly Malware
  10. Sofacy APT unleashes new 'Cannon' trojan
  11. New Pterodo Backdoor Malware Detected By Ukraine
  12. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  13. Malicious programs disguised as racing games on Google Play
  14. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  15. Conficker: A 10-year retrospective on a legendary worm
  16. Malware Moves: Attackers Retool for Cryptocurrency Theft
  17. Infowars Online Store Got Infected with Card Skimming Malware
  18. Awake Security uncovers malicious intent across on-premise, IoT and cloud infrastructure
  19. Centreon releases Remote Server functionality for cross-domain monitoring of multi-site IT operations
  20. Fancy Bear APT Uses New Cannon Trojan to Target Government Entities
  21. "Luiz O Pinto" pushed 500,000+ installs of malware via Google Play, in ~1 week.
  22. Uncover virtual hosts of domain with Fierce
  23. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  24. How to find, is link malicious/URL or not
  25. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

EXPLOIT

  1. Attackers Exploit Recently Patched Popular WordPress Plugin
  2. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  3. Exploit Windows Remote PC with EternalBlue & DoublePulsar Exploit through Metasploit
  4. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

VULNERABILITY

  1. Pen-test at Dropbox turns up three Apple 0-day bugs
  2. A flaw in US Postal Service website exposed data on 60 Million Users
  3. Facebook increases rewards for its bug bounty program and facilitate bug submission
  4. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  5. Mirai Used as Payload in Hadoop YARN Vulnerability
  6. Facebook entices researchers with $40,000 reward for account takeover vulnerabilities
  7. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  8. How a Security Test for DropBox Revealed 3 Apple Zero Day Vulnerabilities
  9. Adobe issues fix for Flash bug allowing remote code execution
  10. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  11. German eID Authentication Flaw Lets You Change Identity
  12. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  13. New vulnerabilities are coming faster than you can fix them
  14. Red Hawk – Open Source Information Gathering and Vulnerability Scanning Tool
  15. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  16. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  17. Experts found flaws in Dell EMC and VMware Products. Patch them now!
  18. From directory traversal to direct travesty: Crash, hijack, siphon off this TP-Link VPN box via classic exploitable bugs
  19. A @DLink #router vulnerability was used to send banking users to a fake site in order to steal #UserCredentials. Learn
  20. Adobe plugs critical RCE Flash Player flaw, update ASAP! Exploitation may be imminent
  21. Patches Released for Flaws Affecting Dell EMC, VMware Products
  22. Adobe Fixes Critical Flash Vulnerability with
  23. Facebook Increases Rewards for Account Hacking Vulnerabilities
  24. Adobe Flash Player Update Released for Remote Code Execution Vulnerability
  25. Facebook Boosts Bug Bounty Payouts for Account Takeover Flaws
  26. Hacker got Rewarded for Discovering a Critical Steam Bug
  27. CVE-2018-15981: Adobe Flash Player Arbitrary Code Execution Vulnerability
  28. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit

Region brief for 2018-11-21

ASIA

  1. City of Valdez, Alaska admits to paying off ransomware infection
  2. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  3. Adobe issues fix for Flash bug allowing remote code execution
  4. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  5. Amazon UK is notifying a data breach to its customers days before Black Friday
  6. New Pterodo Backdoor Malware Detected By Ukraine
  7. Is Magecart Checking Out Your Secure Online Transactions?
  8. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  9. Phishing Scams Serious Problem for Canada’s Global Affairs
  10. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  11. Malaysia’s largest media company becomes victim of a ransomware attack

OCEANIA

  1. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign

NORTH AMERICA

  1. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  2. A flaw in US Postal Service website exposed data on 60 Million Users
  3. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  4. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  5. Facebook increases rewards for its bug bounty program and facilitate bug submission
  6. Inspiring the Next Generation of Tech Talent
  7. What Is Windows PowerShell (And Could It Be Malicious)?
  8. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  9. Amazon tech error leaks customers’ email addresses
  10. USPS Site Exposed Data on 60 Million Users
  11. Amazon suffers data breach days before Black Friday
  12. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  13. Black Friday Phishing Dos and Don’ts
  14. Amazon warns customers it leaked their names and email addresses
  15. Amazon UK is notifying a data breach to its customers days before Black Friday
  16. New Pterodo Backdoor Malware Detected By Ukraine
  17. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  18. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  19. White House admits Ivanka Trump used private email for government business
  20. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  21. Sofacy APT group used a new tool in latest attacks, the Cannon
  22. Phishing Scams Serious Problem for Canada’s Global Affairs
  23. Malaysia’s largest media company becomes victim of a ransomware attack
  24. Russian hackers are conducting more covert attacks on US and European computers
  25. US Department of Justice is investigating Tether for manipulation of market prices
  26. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  27. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

SOUTH AMERICA

  1. Magecart Black Hats Battle it Out On Infected Site
  2. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign

EUROPE

  1. Google Taking Over Health Records Raises Patient Privacy Fears
  2. Vision Direct Deals With Customer Data Leak
  3. Amazon suffers data breach days before Black Friday
  4. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  5. German eID Authentication Flaw Lets You Change Identity
  6. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  7. Amazon UK is notifying a data breach to its customers days before Black Friday
  8. Italian Naval Industry Attacked By MartyMcFly Malware
  9. Sofacy APT unleashes new 'Cannon' trojan
  10. New Pterodo Backdoor Malware Detected By Ukraine
  11. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  12. Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
  13. Is Magecart Checking Out Your Secure Online Transactions?
  14. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  15. Infowars Online Store Got Infected with Card Skimming Malware
  16. Sofacy APT group used a new tool in latest attacks, the Cannon
  17. Phishing Scams Serious Problem for Canada’s Global Affairs
  18. Russian hackers are conducting more covert attacks on US and European computers
  19. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  20. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

AFRICA

  1. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign

Sector brief for 2018-11-21

HEALTHCARE

  1. Google Taking Over Health Records Raises Patient Privacy Fears
  2. Conficker: A 10-year retrospective on a legendary worm

TRANSPORT

  1. Sofacy APT unleashes new 'Cannon' trojan
  2. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon

BANKING & FINANCE

  1. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  2. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  3. What Is Windows PowerShell (And Could It Be Malicious)?
  4. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  5. USPS Site Exposed Data on 60 Million Users
  6. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  7. Black Friday Phishing Dos and Don’ts
  8. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  9. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  10. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  11. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  12. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  13. Magecart Black Hats Battle it Out On Infected Site
  14. Is Magecart Checking Out Your Secure Online Transactions?
  15. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  16. A @DLink #router vulnerability was used to send banking users to a fake site in order to steal #UserCredentials. Learn
  17. Infowars Online Store Got Infected with Card Skimming Malware
  18. Signing and Verifying Ethereum Signatures
  19. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  20. Malaysia’s largest media company becomes victim of a ransomware attack
  21. US Department of Justice is investigating Tether for manipulation of market prices
  22. MageCart Group Sabotages Rival to Ruin Data and Reputation
  23. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit

INFORMATION & TELECOMMUNICATION

  1. Facebook increases rewards for its bug bounty program and facilitate bug submission
  2. Inspiring the Next Generation of Tech Talent
  3. Google Taking Over Health Records Raises Patient Privacy Fears
  4. What Is Windows PowerShell (And Could It Be Malicious)?
  5. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  6. Facebook entices researchers with $40,000 reward for account takeover vulnerabilities
  7. USPS Site Exposed Data on 60 Million Users
  8. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  9. A hacker known as #Tessa88 offered several compromise databases obtained from LinkedIn, MySpace and other companies. Now Recorded Future believes
  10. Black Friday Phishing Dos and Don’ts
  11. 13 Malware-Laden Fake Apps on Google Play
  12. Facebook Ads Urge Its Staff To Leak Secrets
  13. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  14. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  15. Amazon UK is notifying a data breach to its customers days before Black Friday
  16. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  17. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  18. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  19. Malicious programs disguised as racing games on Google Play
  20. Yikes...#Instagram Accidentally Exposed Some Users' #Passwords In Plaintext
  21. #Gmail Glitch Enables Anonymous Messages in #Phishing Attacks:
  22. Facebook Increases Rewards for Account Hacking Vulnerabilities
  23. Facebook Boosts Bug Bounty Payouts for Account Takeover Flaws
  24. OUR BLACK FRIDAY DEALS ARE LIVE! Get 50% off from FREEDOME VPN and TOTAL subscriptions with coupon code BLACKFRIDAY. Buy now:
  25. "Luiz O Pinto" pushed 500,000+ installs of malware via Google Play, in ~1 week.
  26. How to find, is link malicious/URL or not
  27. Microsoft now lets you log into Outlook, Skype, Xbox Live without a password
  28. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
  2. New Pterodo Backdoor Malware Detected By Ukraine
  3. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  4. White House admits Ivanka Trump used private email for government business
  5. New OceanLotus watering hole attacks target southeast Asia
  6. Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
  7. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  8. Sofacy APT group used a new tool in latest attacks, the Cannon
  9. Phishing Scams Serious Problem for Canada’s Global Affairs
  10. Russian hackers are conducting more covert attacks on US and European computers
  11. Fancy Bear APT Uses New Cannon Trojan to Target Government Entities
  12. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

Daily brief for 2018-11-21

ASIA

  1. City of Valdez, Alaska admits to paying off ransomware infection
  2. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  3. Adobe issues fix for Flash bug allowing remote code execution
  4. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  5. Amazon UK is notifying a data breach to its customers days before Black Friday
  6. New Pterodo Backdoor Malware Detected By Ukraine
  7. Is Magecart Checking Out Your Secure Online Transactions?
  8. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  9. Phishing Scams Serious Problem for Canada’s Global Affairs
  10. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  11. Malaysia’s largest media company becomes victim of a ransomware attack

WORLD

  1. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  2. A flaw in US Postal Service website exposed data on 60 Million Users
  3. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  4. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  5. Facebook increases rewards for its bug bounty program and facilitate bug submission
  6. Inspiring the Next Generation of Tech Talent
  7. Google Taking Over Health Records Raises Patient Privacy Fears
  8. What Is Windows PowerShell (And Could It Be Malicious)?
  9. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  10. Amazon tech error leaks customers’ email addresses
  11. USPS Site Exposed Data on 60 Million Users
  12. Vision Direct Deals With Customer Data Leak
  13. Amazon suffers data breach days before Black Friday
  14. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  15. Black Friday Phishing Dos and Don’ts
  16. Amazon warns customers it leaked their names and email addresses
  17. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  18. German eID Authentication Flaw Lets You Change Identity
  19. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  20. Amazon UK is notifying a data breach to its customers days before Black Friday
  21. Italian Naval Industry Attacked By MartyMcFly Malware
  22. Sofacy APT unleashes new 'Cannon' trojan
  23. New Pterodo Backdoor Malware Detected By Ukraine
  24. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  25. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  26. White House admits Ivanka Trump used private email for government business
  27. Magecart Black Hats Battle it Out On Infected Site
  28. Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
  29. Is Magecart Checking Out Your Secure Online Transactions?
  30. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  31. Infowars Online Store Got Infected with Card Skimming Malware
  32. Sofacy APT group used a new tool in latest attacks, the Cannon
  33. Phishing Scams Serious Problem for Canada’s Global Affairs
  34. Malaysia’s largest media company becomes victim of a ransomware attack
  35. Russian hackers are conducting more covert attacks on US and European computers
  36. US Department of Justice is investigating Tether for manipulation of market prices
  37. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  38. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  39. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

ATTACKS

  1. Phishing: It's all too easy on mobile devices
  2. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  3. A flaw in US Postal Service website exposed data on 60 Million Users
  4. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  5. Amazon Customer Email Addresses Leaked Because of 'Technical Error'
  6. Google Taking Over Health Records Raises Patient Privacy Fears
  7. Amazon tech error leaks customers’ email addresses
  8. USPS Site Exposed Data on 60 Million Users
  9. Vision Direct Deals With Customer Data Leak
  10. Amazon suffers data breach days before Black Friday
  11. Emotet’s Thanksgiving Campaign Delivers New Recipes for Compromise
  12. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  13. Record Retention
  14. A hacker known as #Tessa88 offered several compromise databases obtained from LinkedIn, MySpace and other companies. Now Recorded Future believes
  15. Black Friday Phishing Dos and Don’ts
  16. The promised integration with #HaveIBeenPwned is expanding in #FirefoxMonitor with new breach alerts when a user visits a recently compromised
  17. Amazon warns customers it leaked their names and email addresses
  18. Amazon leaks users' email addresses due to 'technical error'
  19. High Tail Hall data breach exposes over 400,000 furry fans
  20. Facebook Ads Urge Its Staff To Leak Secrets
  21. Amazon Suffers Data Breach Days Before Black Friday
  22. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  23. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  24. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  25. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  26. Amazon UK is notifying a data breach to its customers days before Black Friday
  27. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  28. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  29. White House admits Ivanka Trump used private email for government business
  30. New OceanLotus watering hole attacks target southeast Asia
  31. #CyberMonday Tip 1: Be careful of phishing scams claiming to be from a package-delivery company with links to tracking information. AVG
  32. .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
  33. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  34. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  35. Amazon Data Leak Exposes Email Addresses Right Before Black Friday
  36. Yikes...#Instagram Accidentally Exposed Some Users' #Passwords In Plaintext
  37. #Gmail Glitch Enables Anonymous Messages in #Phishing Attacks:
  38. APAC consumers want IoT devices, but fear data leaks
  39. Phishing Scams Serious Problem for Canada’s Global Affairs
  40. OUR BLACK FRIDAY DEALS ARE LIVE! Get 50% off from FREEDOME VPN and TOTAL subscriptions with coupon code BLACKFRIDAY. Buy now:
  41. Microsoft now lets you log into Outlook, Skype, Xbox Live without a password
  42. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

THREATS

  1. Pen-test at Dropbox turns up three Apple 0-day bugs
  2. City of Valdez, Alaska admits to paying off ransomware infection
  3. A flaw in US Postal Service website exposed data on 60 Million Users
  4. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  5. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  6. Facebook increases rewards for its bug bounty program and facilitate bug submission
  7. What Is Windows PowerShell (And Could It Be Malicious)?
  8. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  9. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  10. Mirai Used as Payload in Hadoop YARN Vulnerability
  11. Facebook entices researchers with $40,000 reward for account takeover vulnerabilities
  12. 500K Android users hit with malware, and what to do if you're infected
  13. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  14. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  15. How a Security Test for DropBox Revealed 3 Apple Zero Day Vulnerabilities
  16. Adobe issues fix for Flash bug allowing remote code execution
  17. 13 Malware-Laden Fake Apps on Google Play
  18. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  19. German eID Authentication Flaw Lets You Change Identity
  20. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  21. New vulnerabilities are coming faster than you can fix them
  22. Red Hawk – Open Source Information Gathering and Vulnerability Scanning Tool
  23. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  24. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  25. Italian Naval Industry Attacked By MartyMcFly Malware
  26. Sofacy APT unleashes new 'Cannon' trojan
  27. New Pterodo Backdoor Malware Detected By Ukraine
  28. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  29. Experts found flaws in Dell EMC and VMware Products. Patch them now!
  30. From directory traversal to direct travesty: Crash, hijack, siphon off this TP-Link VPN box via classic exploitable bugs
  31. A @DLink #router vulnerability was used to send banking users to a fake site in order to steal #UserCredentials. Learn
  32. Malicious programs disguised as racing games on Google Play
  33. Adobe plugs critical RCE Flash Player flaw, update ASAP! Exploitation may be imminent
  34. Patches Released for Flaws Affecting Dell EMC, VMware Products
  35. Adobe Fixes Critical Flash Vulnerability with
  36. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  37. Conficker: A 10-year retrospective on a legendary worm
  38. Malware Moves: Attackers Retool for Cryptocurrency Theft
  39. Infowars Online Store Got Infected with Card Skimming Malware
  40. Facebook Increases Rewards for Account Hacking Vulnerabilities
  41. Adobe Flash Player Update Released for Remote Code Execution Vulnerability
  42. New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform Cryptocurrency-Mining & Brute-Force Attack
  43. Facebook Boosts Bug Bounty Payouts for Account Takeover Flaws
  44. Signing and Verifying Ethereum Signatures
  45. Hacker got Rewarded for Discovering a Critical Steam Bug
  46. CVE-2018-15981: Adobe Flash Player Arbitrary Code Execution Vulnerability
  47. Malaysia’s largest media company becomes victim of a ransomware attack
  48. US Department of Justice is investigating Tether for manipulation of market prices
  49. Awake Security uncovers malicious intent across on-premise, IoT and cloud infrastructure
  50. Centreon releases Remote Server functionality for cross-domain monitoring of multi-site IT operations
  51. Fancy Bear APT Uses New Cannon Trojan to Target Government Entities
  52. "Luiz O Pinto" pushed 500,000+ installs of malware via Google Play, in ~1 week.
  53. Uncover virtual hosts of domain with Fierce
  54. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  55. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  56. How to find, is link malicious/URL or not
  57. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

CRIME

  1. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  2. Facebook increases rewards for its bug bounty program and facilitate bug submission
  3. What Is Windows PowerShell (And Could It Be Malicious)?
  4. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  5. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  6. USPS Site Exposed Data on 60 Million Users
  7. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  8. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  9. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  10. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  11. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  12. Is Magecart Checking Out Your Secure Online Transactions?
  13. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  14. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  15. Signing and Verifying Ethereum Signatures
  16. Phishing Scams Serious Problem for Canada’s Global Affairs
  17. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  18. Malaysia’s largest media company becomes victim of a ransomware attack

POLITICS

  1. What Is Windows PowerShell (And Could It Be Malicious)?
  2. USPS Site Exposed Data on 60 Million Users
  3. New Pterodo Backdoor Malware Detected By Ukraine
  4. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  5. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  6. Phishing Scams Serious Problem for Canada’s Global Affairs
  7. Russian hackers are conducting more covert attacks on US and European computers
  8. US Department of Justice is investigating Tether for manipulation of market prices
  9. MageCart Group Sabotages Rival to Ruin Data and Reputation