Nov 23, 2018

APT report for 2018-11-22

TRANSNATIONAL / UNKNOWN

  1. #Irisscon: Stop Siloing Vulnerability Management to Deal with Old Bugs
  2. Podcast: Breaking Down the Magecart Threat (Part One)

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. VB2018 paper: Since the hacking of Sony Pictures

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

Nil

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-22

WINDOWS

  1. Google’s Practical Action Against Malware and Its Authors
  2. [SingCERT] Alert on Adobe Flash Player Vulnerability (CVE-2018-15981)
  3. Update now! Adobe Flash has another critical security vulnerability

LINUX

  1. Mirai DDoS baddies take enterprise Linux servers over consumer routers
  2. [SingCERT] Alert on Adobe Flash Player Vulnerability (CVE-2018-15981)
  3. SSL vulnerability scanner – MassBleed
  4. Update now! Adobe Flash has another critical security vulnerability
  5. Experts found first Mirai bot targeting Linux servers via Hadoop YARN flaw

UNIX

Nil

ANDROID

  1. Google’s Practical Action Against Malware and Its Authors
  2. #DidYouKnow A single subscription of AVG Internet Security covers every PC in your family? It also includes webcam and ransomware protection,
  3. The Rotexy mobile Trojan – banker and ransomware

IOS

  1. Google’s Practical Action Against Malware and Its Authors

MACOS

  1. [SingCERT] Alert on Adobe Flash Player Vulnerability (CVE-2018-15981)
  2. A bypass was found by @okta researchers that allows #macOS #malware to pose as @Apple files despite needing to be
  3. Researchers recently discovered a new #MacOS #malware that targets #cryptocurrency investors through chat platforms. Discover how this is possible and

Threat report for 2018-11-22

DATA BREACH & DATA LOSS

  1. Almost 9,5 Million PII Records Leaked by Data Aggregator Adapt
  2. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  3. USPS reportedly fixes website bug that exposed data of 60M users
  4. Facebook 'walking dangerous line' as it appeals record fine
  5. USPS finally fixes website flaw that exposed 60 million users' data
  6. Furry erotica site 'High Tail Hall' exposed data of nearly 500K users
  7. The July edition of Beazley Breach Insights found that business email compromise attacks have been rising steadily. Is business email
  8. US Postal Service website vulnerability leaked 60 million user data
  9. Amazon technical failure caused to leaks users’ email addresses
  10. US Postal Service Left 60 Million Users Data Exposed For Over a Year
  11. Amazon Suffered Data Breach – Customers Name & Email Addresses Exposed
  12. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?
  13. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack
  14. New @awscloud settings will allow users to batch change permissions with the aim of avoiding accidental S3 data leaks, but

DENIAL-OF-SERVICE

  1. Mirai DDoS baddies take enterprise Linux servers over consumer routers
  2. Emoji Kitten Denial Of Service Attack Continues to Haunt Skype

MALVERTISING

Nil

PHISHING

  1. LastPass login problems caused by cascading server failure
  2. Come evitare che le tue #password diventino la chiave di accesso ai tuoi account
  3. PSA: Phishing Levels Rise Ahead of Black Friday and Cyber Monday
  4. Phishing Attack Compromises Health First Patients’ Data

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. #DidYouKnow A single subscription of AVG Internet Security covers every PC in your family? It also includes webcam and ransomware protection,
  2. Aurora / Zorro Ransomware Actively Being Distributed
  3. How does @TalosSecurity's discovery change the way you or your enterprise views #ransomware?
  4. The Rotexy mobile Trojan – banker and ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. Silicon Valley Hacker Swipes Millions Worth of Cryptocurrency Using SIM Swapping
  2. SIM swap! Man charged after million dollar cryptocurrency theft
  3. SIM swap! Man charged after million dollar cryptocurrency theft
  4. Researchers recently discovered a new #MacOS #malware that targets #cryptocurrency investors through chat platforms. Discover how this is possible and
  5. North Korea To Host Cryptocurrency and Blockchain Conference

MALWARE

  1. Google’s Practical Action Against Malware and Its Authors
  2. Rotexy Mobile Trojan Launches 70k+ Attacks in Three Months
  3. Found this picture of myself doing an internal briefing on the Nimda worm in 2001. Note the size of the
  4. A bypass was found by @okta researchers that allows #macOS #malware to pose as @Apple files despite needing to be
  5. The Rotexy mobile Trojan – banker and ransomware
  6. Researchers recently discovered a new #MacOS #malware that targets #cryptocurrency investors through chat platforms. Discover how this is possible and
  7. Research reveals that 44% of industrial facilities have USB malware risks
  8. Do you believe that the application #security vetting process would benefit from the addition of an entropy source?
  9. Emotet malware runs on a dual infrastructure to avoid downtime and takedowns
  10. Hacking Syndicate TA505 Back with Focus on Info-Stealing Trojan

EXPLOIT

  1. How Dropbox's red team discovered an Apple zero-day exploit chain by accident
  2. How was a black box attack used to exploit ATM vulnerabilities?

VULNERABILITY

  1. USPS reportedly fixes website bug that exposed data of 60M users
  2. [SingCERT] Alert on Adobe Flash Player Vulnerability (CVE-2018-15981)
  3. #Irisscon: Stop Siloing Vulnerability Management to Deal with Old Bugs
  4. .@radware #cybersecurity researchers found hackers to be targeting bank users via a #router vulnerability. Learn how a fake banking site
  5. Cross-site search attack applied to snoop on Google’s bug tracker
  6. Facebook And Instagram Went Down Due To A Server Bug
  7. SSL vulnerability scanner – MassBleed
  8. Flaw allowing identity spoofing affects authentication based on German eID cards
  9. USPS finally fixes website flaw that exposed 60 million users' data
  10. Update now! Adobe Flash has another critical security vulnerability
  11. How Dropbox's red team discovered an Apple zero-day exploit chain by accident
  12. How was a black box attack used to exploit ATM vulnerabilities?
  13. CyberSecurity Asean security alert on Multiple Vulnerabilities in VMware vSphere Data Protection Could Allow for Remote Code Execution
  14. Experts found first Mirai bot targeting Linux servers via Hadoop YARN flaw
  15. VMware Releases Critical Security Updates for Multiple Vulnerabilities
  16. US Postal Service website vulnerability leaked 60 million user data
  17. Facebook Increases Average Bounty rewards for High Impact Vulnerabilities
  18. Facebook raises rewards for a security vulnerabilities to $40,000

Region brief for 2018-11-22

ASIA

  1. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  2. The Rotexy mobile Trojan – banker and ransomware
  3. North Korea To Host Cryptocurrency and Blockchain Conference

OCEANIA

Nil

NORTH AMERICA

  1. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  2. USPS finally fixes website flaw that exposed 60 million users' data
  3. Research reveals that 44% of industrial facilities have USB malware risks
  4. North Korea To Host Cryptocurrency and Blockchain Conference
  5. US Postal Service website vulnerability leaked 60 million user data
  6. Amazon technical failure caused to leaks users’ email addresses
  7. US Postal Service Left 60 Million Users Data Exposed For Over a Year

SOUTH AMERICA

Nil

EUROPE

  1. Flaw allowing identity spoofing affects authentication based on German eID cards
  2. The Rotexy mobile Trojan – banker and ransomware
  3. North Korea To Host Cryptocurrency and Blockchain Conference
  4. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack

AFRICA

Nil

Sector brief for 2018-11-22

HEALTHCARE

  1. Phishing Attack Compromises Health First Patients’ Data
  2. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?

TRANSPORT

Nil

BANKING & FINANCE

  1. Rotexy Mobile Trojan Launches 70k+ Attacks in Three Months
  2. .@radware #cybersecurity researchers found hackers to be targeting bank users via a #router vulnerability. Learn how a fake banking site
  3. VB2018 paper: Since the hacking of Sony Pictures
  4. The Rotexy mobile Trojan – banker and ransomware
  5. How was a black box attack used to exploit ATM vulnerabilities?
  6. Hacking Syndicate TA505 Back with Focus on Info-Stealing Trojan
  7. Facebook raises rewards for a security vulnerabilities to $40,000
  8. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?

INFORMATION & TELECOMMUNICATION

  1. Facebook And Instagram Went Down Due To A Server Bug
  2. #DidYouKnow A single subscription of AVG Internet Security covers every PC in your family? It also includes webcam and ransomware protection,
  3. Facebook 'walking dangerous line' as it appeals record fine
  4. Emoji Kitten Denial Of Service Attack Continues to Haunt Skype
  5. Found this picture of myself doing an internal briefing on the Nimda worm in 2001. Note the size of the
  6. North Korea To Host Cryptocurrency and Blockchain Conference
  7. Amazon technical failure caused to leaks users’ email addresses
  8. Facebook Increases Average Bounty rewards for High Impact Vulnerabilities
  9. Facebook raises rewards for a security vulnerabilities to $40,000

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Flaw allowing identity spoofing affects authentication based on German eID cards
  2. CyberSecurity Asean security alert on Multiple Vulnerabilities in VMware vSphere Data Protection Could Allow for Remote Code Execution
  3. North Korea To Host Cryptocurrency and Blockchain Conference
  4. US Postal Service Left 60 Million Users Data Exposed For Over a Year

Daily brief for 2018-11-22

ASIA

  1. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  2. The Rotexy mobile Trojan – banker and ransomware
  3. North Korea To Host Cryptocurrency and Blockchain Conference

WORLD

  1. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  2. Flaw allowing identity spoofing affects authentication based on German eID cards
  3. USPS finally fixes website flaw that exposed 60 million users' data
  4. The Rotexy mobile Trojan – banker and ransomware
  5. Research reveals that 44% of industrial facilities have USB malware risks
  6. North Korea To Host Cryptocurrency and Blockchain Conference
  7. US Postal Service website vulnerability leaked 60 million user data
  8. Amazon technical failure caused to leaks users’ email addresses
  9. US Postal Service Left 60 Million Users Data Exposed For Over a Year
  10. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack

ATTACKS

  1. Almost 9,5 Million PII Records Leaked by Data Aggregator Adapt
  2. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  3. USPS reportedly fixes website bug that exposed data of 60M users
  4. Facebook 'walking dangerous line' as it appeals record fine
  5. USPS finally fixes website flaw that exposed 60 million users' data
  6. LastPass login problems caused by cascading server failure
  7. Furry erotica site 'High Tail Hall' exposed data of nearly 500K users
  8. The July edition of Beazley Breach Insights found that business email compromise attacks have been rising steadily. Is business email
  9. Come evitare che le tue #password diventino la chiave di accesso ai tuoi account
  10. PSA: Phishing Levels Rise Ahead of Black Friday and Cyber Monday
  11. Phishing Attack Compromises Health First Patients’ Data
  12. US Postal Service website vulnerability leaked 60 million user data
  13. Amazon technical failure caused to leaks users’ email addresses
  14. US Postal Service Left 60 Million Users Data Exposed For Over a Year
  15. Amazon Suffered Data Breach – Customers Name & Email Addresses Exposed
  16. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?
  17. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack
  18. New @awscloud settings will allow users to batch change permissions with the aim of avoiding accidental S3 data leaks, but

THREATS

  1. Silicon Valley Hacker Swipes Millions Worth of Cryptocurrency Using SIM Swapping
  2. Google’s Practical Action Against Malware and Its Authors
  3. USPS reportedly fixes website bug that exposed data of 60M users
  4. [SingCERT] Alert on Adobe Flash Player Vulnerability (CVE-2018-15981)
  5. #Irisscon: Stop Siloing Vulnerability Management to Deal with Old Bugs
  6. Rotexy Mobile Trojan Launches 70k+ Attacks in Three Months
  7. .@radware #cybersecurity researchers found hackers to be targeting bank users via a #router vulnerability. Learn how a fake banking site
  8. Cross-site search attack applied to snoop on Google’s bug tracker
  9. Facebook And Instagram Went Down Due To A Server Bug
  10. SIM swap! Man charged after million dollar cryptocurrency theft
  11. SIM swap! Man charged after million dollar cryptocurrency theft
  12. #DidYouKnow A single subscription of AVG Internet Security covers every PC in your family? It also includes webcam and ransomware protection,
  13. SSL vulnerability scanner – MassBleed
  14. Aurora / Zorro Ransomware Actively Being Distributed
  15. How does @TalosSecurity's discovery change the way you or your enterprise views #ransomware?
  16. Flaw allowing identity spoofing affects authentication based on German eID cards
  17. USPS finally fixes website flaw that exposed 60 million users' data
  18. Update now! Adobe Flash has another critical security vulnerability
  19. How Dropbox's red team discovered an Apple zero-day exploit chain by accident
  20. Found this picture of myself doing an internal briefing on the Nimda worm in 2001. Note the size of the
  21. A bypass was found by @okta researchers that allows #macOS #malware to pose as @Apple files despite needing to be
  22. The Rotexy mobile Trojan – banker and ransomware
  23. Researchers recently discovered a new #MacOS #malware that targets #cryptocurrency investors through chat platforms. Discover how this is possible and
  24. How was a black box attack used to exploit ATM vulnerabilities?
  25. Research reveals that 44% of industrial facilities have USB malware risks
  26. CyberSecurity Asean security alert on Multiple Vulnerabilities in VMware vSphere Data Protection Could Allow for Remote Code Execution
  27. Do you believe that the application #security vetting process would benefit from the addition of an entropy source?
  28. Experts found first Mirai bot targeting Linux servers via Hadoop YARN flaw
  29. VMware Releases Critical Security Updates for Multiple Vulnerabilities
  30. Emotet malware runs on a dual infrastructure to avoid downtime and takedowns
  31. North Korea To Host Cryptocurrency and Blockchain Conference
  32. Hacking Syndicate TA505 Back with Focus on Info-Stealing Trojan
  33. US Postal Service website vulnerability leaked 60 million user data
  34. Facebook Increases Average Bounty rewards for High Impact Vulnerabilities
  35. Facebook raises rewards for a security vulnerabilities to $40,000

CRIME

  1. Silicon Valley Hacker Swipes Millions Worth of Cryptocurrency Using SIM Swapping
  2. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  3. SIM swap! Man charged after million dollar cryptocurrency theft
  4. SIM swap! Man charged after million dollar cryptocurrency theft
  5. The Rotexy mobile Trojan – banker and ransomware
  6. The July edition of Beazley Breach Insights found that business email compromise attacks have been rising steadily. Is business email
  7. Hacking Syndicate TA505 Back with Focus on Info-Stealing Trojan
  8. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?

POLITICS

  1. The Rotexy mobile Trojan – banker and ransomware
  2. North Korea To Host Cryptocurrency and Blockchain Conference
  3. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?
  4. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack