Showing posts with label DailyBrief. Show all posts
Showing posts with label DailyBrief. Show all posts

Nov 30, 2018

Daily brief for 2018-11-29

ASIA

  1. Banking Trojan Made in Brazil? A Brief Look
  2. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  3. Indian Police Break Up International Computer Virus Scam
  4. Iranian duo charged with SamSam ransomware-slinging campaign
  5. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  6. US charges Iranian hackers for SamSam ransomware attacks
  7. US charges Iranian hackers for SamSam ransomware attacks
  8. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  9. US Indicts Two Iranians for SamSam Campaign Blitz
  10. Analysis Report of the XorDDoS Malware Family
  11. Lazarus Targeting Latin America
  12. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe

WORLD

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  3. Rotexy malware morphs into dangerous banking Trojan
  4. Banking Trojan Made in Brazil? A Brief Look
  5. First Annual Cyberwarcon
  6. Brazilian Financial Malware Spreads Beyond National Boundaries
  7. USPS API Security Vulnerabilities Caused by Functional Errors
  8. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  9. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  10. SamSam ransomware actors charged, sanctioned by US government
  11. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  12. US charges Iranian hackers for SamSam ransomware attacks
  13. Pterodo Found On State Authorities' Computers In Ukraine
  14. US charges Iranian hackers for SamSam ransomware attacks
  15. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  16. US indicts two over SamSam ransomware attacks
  17. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  18. XSS Shell- Cross Site Scripting
  19. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  20. GCHQ: We don't tell tech companies about every software flaw
  21. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  22. US Indicts Two Iranians for SamSam Campaign Blitz
  23. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  24. Brazilian-made bank trojan
  25. READ: The threat actor SNAKEMACKEREL (#FancyBear) leveraged current geopolitical events and #Brexit themed lure documents to deliver first-stage malware
  26. London-based Urban Massage app leaks data on 300K customers, including sexual misconduct claims
  27. Records of 114 Million US Citizen and Companies Exposed Online
  28. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  29. McAfee Labs 2019 Threats Predictions Report
  30. Lazarus Targeting Latin America
  31. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  32. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  33. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  34. Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords

ATTACKS

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Users Failing Phishing Simulations? That’s ok
  3. Dell Forces Password Reset for Online Customers Following Data Breach
  4. Dell remains quiet on attempted data breach
  5. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  6. 2.6 Million Atrium Health Patient Records Compromised by Vendor AccuDoc
  7. Iranian duo charged with SamSam ransomware-slinging campaign
  8. Office workers beware: Holiday gift card spear phishing attacks on the rise
  9. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  10. Blazy – Open Source Modern Login Brute-forcer
  11. SKY Brasil Exposes 32 Million Customer Records
  12. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  13. Dunkin' Donuts Serves Up Data Breach Alert
  14. Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
  15. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  16. US Indicts Two Iranians for SamSam Campaign Blitz
  17. London-based Urban Massage app leaks data on 300K customers, including sexual misconduct claims
  18. Database breach affects 2.6 million Atrium Health patients
  19. Dell data breach – Dell forces password reset after the incident
  20. Records of 114 Million US Citizen and Companies Exposed Online
  21. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  22. Threat Spotlight: New spear phishing attack gift card scam
  23. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  24. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  25. Dell Resets User Passwords Following Data Breach
  26. Atrium Health Data Breach Affected More than 2 Million Patients
  27. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  28. Dell Hacked – Data Breach Exposed Names, Email addresses & Hashed Passwords
  29. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

THREATS

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. A free decryption tool is available for Thanatos ransomware victims
  3. Rotexy malware morphs into dangerous banking Trojan
  4. Banking Trojan Made in Brazil? A Brief Look
  5. Critical Zoom Flaw Lets Hackers Hijack Conference Meetings
  6. Overall Volume of Thanksgiving Weekend Malware Attacks Lower This Year
  7. Brazilian Financial Malware Spreads Beyond National Boundaries
  8. USPS API Security Vulnerabilities Caused by Functional Errors
  9. Colorado Agency Targeted in Nationwide Ransomware Scheme
  10. Cisco Patches SQL Injection Flaw in Prime License Manager
  11. SamSam ransomware actors charged, sanctioned by US government
  12. Cisco Patches Critical Bug in License Management Tool
  13. Indian Police Break Up International Computer Virus Scam
  14. Hackers can exploit this bug in surveillance cameras to tamper with footage
  15. Iranian duo charged with SamSam ransomware-slinging campaign
  16. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  17. A security hole in a mail preview program may have made the data of 60 million customers vulnerable.
  18. US charges Iranian hackers for SamSam ransomware attacks
  19. Inside the Google Docs Malicious Network
  20. US charges Iranian hackers for SamSam ransomware attacks
  21. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  22. A security researcher notified the @USPS of an #API vulnerability one year ago. But the #USPS website flaw was only
  23. US indicts two over SamSam ransomware attacks
  24. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  25. AriseBank CEO faces 120 years behind bars over alleged cryptocurrency scam
  26. Beware the Malware-Laden Brexit News
  27. KingMiner malware hijacks the full power of Windows Server CPUs
  28. GCHQ: We don't tell tech companies about every software flaw
  29. Malicious developer creates wormable, fileless variant of njRAT
  30. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  31. Brazilian-made bank trojan
  32. READ: The threat actor SNAKEMACKEREL (#FancyBear) leveraged current geopolitical events and #Brexit themed lure documents to deliver first-stage malware
  33. Proofpoint: Hackers testing new reconnaissance #malware on financial institutions.
  34. Beware the Malware-Laden Brexit News https://ubm.io/2Ql2DyP by @ErickaChick
  35. Analysis Report of the XorDDoS Malware Family
  36. Hacker takes over JavaScript library, injects malware to steal Bitcoin
  37. Widely Used Web Conference Service Zoom Patches Critical Flaw
  38. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  39. Several Malicious Apps on Google Play Posing as Voice Messenger Steal User Personal Information
  40. Mobile Malware Attacks Increase as Holiday Season Nears
  41. Facebook Increases Bug Bounty Payouts to Improve User Security
  42. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  43. A targeted attack attempting to steal #cryptocurrency took advantage of open source software with a compromised #NPM package and experts

CRIME

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Colorado Agency Targeted in Nationwide Ransomware Scheme
  3. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  4. Indian Police Break Up International Computer Virus Scam
  5. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  6. US indicts two over SamSam ransomware attacks
  7. SKY Brasil Exposes 32 Million Customer Records
  8. US Charges Hackers in Multimillion Dollar Ransomware Campaign
  9. AriseBank CEO faces 120 years behind bars over alleged cryptocurrency scam
  10. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  11. US Indicts Two Iranians for SamSam Campaign Blitz
  12. Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
  13. McAfee Labs 2019 Threats Predictions Report
  14. Threat Spotlight: New spear phishing attack gift card scam
  15. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  16. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  17. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach
  18. The Justice Department, FBI and several tech and cybersecurity companies have dismantled the #3ve #botnet, and eight individuals have been

POLITICS

  1. GCHQ: this is how we decide to report a security bug or keep it a secret
  2. First Annual Cyberwarcon
  3. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  4. Pterodo Found On State Authorities' Computers In Ukraine
  5. XSS Shell- Cross Site Scripting
  6. Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
  7. McAfee Labs 2019 Threats Predictions Report
  8. Threat Spotlight: New spear phishing attack gift card scam
  9. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  10. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach

Nov 27, 2018

Daily brief for 2018-11-26

ASIA

  1. Half of all Phishing Sites Now Have the Padlock
  2. Cyberthreats to financial institutions 2019: overview and predictions
  3. Ukrainian Police Nab Suspected RAT-Slinger
  4. Crypto Mining Malware Infects Make-A-Wish-Foundation Website

WORLD

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. Did UK city council over-react to a vulnerability report in its recycling app or not?
  3. Knuddels Flirt App Slapped with Hefty Fine After Data Breach
  4. When Do You Need to Report a Data Breach?
  5. Democrats Introduce Bill for Stopping Automated Grinch Bots from Ruining Xmas
  6. Siemens patches major firewall flaw, other vulnerabilities
  7. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  8. Microsoft PowerPoint as Malware Dropper
  9. Recent Attacks on US Entities Attributed to APT29
  10. U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
  11. Phishing Campaign targeting French Industry
  12. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  13. German Social Media Provider Fined €20K for Data Breach
  14. Cyberthreats to financial institutions 2019: overview and predictions
  15. Ukrainian Police Nab Suspected RAT-Slinger
  16. Crypto Mining Malware Infects Make-A-Wish-Foundation Website
  17. Experts found a new powerful modular Linux cryptominer
  18. HR Software Firm PageUp Finds No Evidence of Data Theft
  19. An ongoing phishing campaign is targeting French industry, @FSLabs finds.
  20. Phishing Campaign targeting French Industry

ATTACKS

  1. Knuddels Flirt App Slapped with Hefty Fine After Data Breach
  2. When Do You Need to Report a Data Breach?
  3. USPS, Amazon Data Leaks Showcase API Weaknesses
  4. Holiday Season: Cybercriminals are Phishing All The Way
  5. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  6. Half of all Phishing Sites Now Have the Padlock
  7. Easy as APT: Spear phishing highlighted as ongoing threat for 2019
  8. Despite growing concerns about cybersecurity and the number of data breach incidents in the news, many employees still have bad
  9. Trivial Spotify Phishing Campaign Targets Users To Steal Login Credentials
  10. Phishing Campaign targeting French Industry
  11. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  12. German Social Media Provider Fined €20K for Data Breach
  13. No need to compromise freedom for security - Europol audience told
  14. 50% use password managers to store login details
  15. HR Software Firm PageUp Finds No Evidence of Data Theft
  16. Internal negligence to blame for most data breaches involving personal health information
  17. Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
  18. An ongoing phishing campaign is targeting French industry, @FSLabs finds.
  19. Phishing Campaign targeting French Industry
  20. Beware!! Cyber Criminals Launching Serious Phishing Attack that Target Spotify Customers
  21. My Health Record opt-out officially extended to January 31

THREATS

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. Did UK city council over-react to a vulnerability report in its recycling app or not?
  3. Ransomware attack disrupted emergency rooms at Ohio Hospital System
  4. Lenovo to Pay $7.3 Million in Settlement for Installing Adware on 800K Notebooks
  5. 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
  6. Hacker backdoors popular JavaScript library to steal Bitcoin funds
  7. What is Data Classification? Guidelines and Process
  8. Linux Kernel is affected by two DoS vulnerabilities still unpatched
  9. Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
  10. Harberger Taxes on Ethereum
  11. DoS Vulnerabilities Impact Linux Kernel
  12. Subscribe to the relaunched Virus Bulletin eNews newsletter
  13. Apache Hadoop Spins Cracking Code Injection Vulnerability YARN
  14. Siemens patches major firewall flaw, other vulnerabilities
  15. Play Store Malware Infects Half a Billion
  16. Microsoft PowerPoint as Malware Dropper
  17. #Bluetooth devices might be at risk after a new Bluetooth vulnerability was found targeting #firmware and #OperatingSystem software drivers. Learn
  18. U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
  19. Ransomware Attack Forced Ohio Hospital System to Divert ER Patients
  20. Positive Technologies researchers recently found two serious vulnerabilities that target NCR's #ATMs. Learn how a "black box attack" was involved
  21. OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic
  22. Cryptocurrency threat predictions for 2019
  23. Ukrainian Police Nab Suspected RAT-Slinger
  24. Crypto Mining Malware Infects Make-A-Wish-Foundation Website
  25. Experts found a new powerful modular Linux cryptominer
  26. A new ransomware -- dubbed #Thanatos #ransomware -- was found encrypting data but not decrypting it despite victims paying the
  27. Discover how a @DLink #router vulnerability targeted a banking site to steal #UserCredentials with expert Judith Myerson.
  28. For recent big data software vulnerabilities, botnets and coin mining are just the beginning
  29. Frost & Sullivan Commends Rapid7 for Capturing Nearly a Quarter Share of the Global Vulnerability Management Market

CRIME

  1. When Do You Need to Report a Data Breach?
  2. Holiday Season: Cybercriminals are Phishing All The Way
  3. Half of all Phishing Sites Now Have the Padlock
  4. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  5. Cryptocurrency threat predictions for 2019
  6. Cyberthreats to financial institutions 2019: overview and predictions
  7. Ukrainian Police Nab Suspected RAT-Slinger
  8. Experts found a new powerful modular Linux cryptominer
  9. HR Software Firm PageUp Finds No Evidence of Data Theft
  10. Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual

POLITICS

  1. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  2. Cryptocurrency threat predictions for 2019
  3. Ukrainian Police Nab Suspected RAT-Slinger

Nov 25, 2018

Daily brief for 2018-11-24

ASIA

  1. North Korea-linked group Lazarus targets Latin American banks

WORLD

  1. Quebec Dubbed As An Embarrassment After Paying $30,000 To Ransomware Authors
  2. Adobe Patched A Critical Flash Player Vulnerability Disclosed Publicly
  3. News of the Week: November 24, 2018
  4. North Korea-linked group Lazarus targets Latin American banks
  5. 42-year-old man Arrested For Hacking More than 2,000 Computers From 50 countries With DarkComet RAT
  6. New Trojan mining on the Linux will steal user passwords & removes anti-viruses

ATTACKS

  1. This week's #RiskAndRepeatPodcast digs into the debate over #WeakPasswords and password reuse, and asks: how much are users responsible for

THREATS

  1. Quebec Dubbed As An Embarrassment After Paying $30,000 To Ransomware Authors
  2. Adobe Patched A Critical Flash Player Vulnerability Disclosed Publicly
  3. MacOS Penetration Test Reveals Three Zero-Day Vulnerabilities
  4. Powerful Mobile Malware Rotexy Launched over 70,000 Attacks with Banking Trojan & Ransomware Modules
  5. .@TalosSecurity recently created a #decryptor that helps files affected by the #ransomware #Thanatos -- typically known to not decrypt files
  6. TA505 Cybercrime Group Experimenting with a New RAT In The Wild
  7. Researchers at @okta found a bypass that allows #ThreatActors to pose files as legitimate @Apple files despite being #malware and
  8. 42-year-old man Arrested For Hacking More than 2,000 Computers From 50 countries With DarkComet RAT
  9. SMBs suffered the brunt of ransomware attacks in 2018
  10. CVE-2018-19406, CVE-2018-19407: Two DoS vulnerabilities on Linux Kernel
  11. New Trojan mining on the Linux will steal user passwords & removes anti-viruses
  12. How has the @DLink #router vulnerability affected your enterprise?
  13. The Week in Ransomware - November 23rd 2018 - STOP, Dharma, and More

CRIME

  1. TA505 Cybercrime Group Experimenting with a New RAT In The Wild
  2. New Trojan mining on the Linux will steal user passwords & removes anti-viruses

POLITICS

  1. Quebec Dubbed As An Embarrassment After Paying $30,000 To Ransomware Authors
  2. North Korea-linked group Lazarus targets Latin American banks

Nov 24, 2018

Daily brief for 2018-11-23

ASIA

  1. US Says China Increased Hacking over Trade Dispute
  2. North Korean Hackers Hit Latin American Banks
  3. VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
  4. Adobe Flash Player Remote Code Execution Vulnerability Threat Alert
  5. VMware Patches Workstation Flaw Disclosed at Hacking Contest

WORLD

  1. NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
  2. Data breach in OSIsoft
  3. New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
  4. Brazil's largest professional association suffers massive data leak
  5. German e-government SDK patched against ID spoofing vulnerability
  6. US Postal Service Plugs API Flaw - One Year Later
  7. US Says China Increased Hacking over Trade Dispute
  8. North Korean Hackers Hit Latin American Banks
  9. VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
  10. Phishing Used to Launch GreyEnergy's ICS Attacks
  11. New Emotet Thanksgiving campaign differs from previous ones
  12. Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
  13. Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
  14. US Postal Service Website Left Data Exposed for Over a Year
  15. German eID vulnerability allows hackers to change identities
  16. Hacker says USPS ignored serious security flaw for over a year
  17. Synthetic identity fraud to drive $48 billion in annual losses by 2023 – Juniper Research
  18. Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits
  19. Southwest Washington Regional Surgery Center suffered a Phishing attack
  20. 60 million users’ data were exposed by the US Postal Service
  21. The team discuss continuing activity by the Magecart group, as well as the ways in which #cybercriminals are gearing up

ATTACKS

  1. NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
  2. Data breach in OSIsoft
  3. 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
  4. Brazil's largest professional association suffers massive data leak
  5. Amazon Snafu Exposed Customers' Names and Email Addresses
  6. New Linux crypto-miner steals your root password and disables your antivirus
  7. Attackers Are Landing Email Inboxes Without the Need to Phish
  8. Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
  9. “Back in Black” – Article 13 has YouTube threatening to pull the plug over upload filter
  10. Phishing Used to Launch GreyEnergy's ICS Attacks
  11. New Emotet Thanksgiving campaign differs from previous ones
  12. US Postal Service Website Left Data Exposed for Over a Year
  13. .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
  14. Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits
  15. Southwest Washington Regional Surgery Center suffered a Phishing attack
  16. A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
  17. Software company OSIsoft has suffered a data breach
  18. SAVE 50% FOR BLACK FRIDAY! Get half off FREEDOME VPN and TOTAL with coupon code BLACKFRIDAY.
  19. DNS Shell – Tool to Compromise and Maintain Control Over Victim Machine
  20. @FSecure fait son #BlackFriday ! Profitez de 50% de remise sur une sélection de produits !
  21. 60 million users’ data were exposed by the US Postal Service

THREATS

  1. 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
  2. New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
  3. DoS Vulnerabilities Found in Linux Kernel, Unpatched
  4. Apache Hadoop spins cracking code injection vulnerability YARN
  5. German e-government SDK patched against ID spoofing vulnerability
  6. Malware scum want to build a Linux botnet using Mirai
  7. US Postal Service Plugs API Flaw - One Year Later
  8. VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
  9. Adobe Flash Player Remote Code Execution Vulnerability Threat Alert
  10. Old Printer Vulnerabilities Die Hard
  11. VMware Patches Workstation Flaw Disclosed at Hacking Contest
  12. Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
  13. Black Friday special by Emotet: Filling inboxes with infected XML macros
  14. Black Friday special by Emotet: Filling inboxes with infected XML macros
  15. Cryptocurrency ‘minting’ flaw could have leached money from exchanges
  16. Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
  17. USPS Bug affects 60 Million Users, Finally Fixed.
  18. German eID vulnerability allows hackers to change identities
  19. VMware patches guest-to-host malware vulnerability
  20. Internet connected devices might be the hot item for Christmas this year, but are they secure?
  21. Hacker says USPS ignored serious security flaw for over a year
  22. #WebCache poisoning poses a serious threat to #BrowserSecurity. Learn how #hackers can use unkeyed inputs for malicious intent from expert
  23. SMBs suffered the brunt of ransomware attacks in 2018
  24. Best way to Remove Malware on Mac, Including Other Unwanted Apps
  25. A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
  26. CVE-2018-6983: integer overflow vulnerability in VMware Workstation and Fusion
  27. The number of ransomware attacks on individuals has come down as it has become harder to get them to pay,
  28. New Crypto Malware Spreading that Infects Linux Machines & Removes Anti-Virus
  29. Over 500k Play Store users have installed 13 games that contain malware

CRIME

  1. Data breach in OSIsoft
  2. US Says China Increased Hacking over Trade Dispute
  3. Synthetic identity fraud to drive $48 billion in annual losses by 2023 – Juniper Research
  4. Software company OSIsoft has suffered a data breach
  5. The team discuss continuing activity by the Magecart group, as well as the ways in which #cybercriminals are gearing up

POLITICS

  1. NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
  2. US Says China Increased Hacking over Trade Dispute
  3. Synthetic identity fraud to drive $48 billion in annual losses by 2023 – Juniper Research
  4. Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits

Nov 23, 2018

Daily brief for 2018-11-22

ASIA

  1. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  2. The Rotexy mobile Trojan – banker and ransomware
  3. North Korea To Host Cryptocurrency and Blockchain Conference

WORLD

  1. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  2. Flaw allowing identity spoofing affects authentication based on German eID cards
  3. USPS finally fixes website flaw that exposed 60 million users' data
  4. The Rotexy mobile Trojan – banker and ransomware
  5. Research reveals that 44% of industrial facilities have USB malware risks
  6. North Korea To Host Cryptocurrency and Blockchain Conference
  7. US Postal Service website vulnerability leaked 60 million user data
  8. Amazon technical failure caused to leaks users’ email addresses
  9. US Postal Service Left 60 Million Users Data Exposed For Over a Year
  10. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack

ATTACKS

  1. Almost 9,5 Million PII Records Leaked by Data Aggregator Adapt
  2. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  3. USPS reportedly fixes website bug that exposed data of 60M users
  4. Facebook 'walking dangerous line' as it appeals record fine
  5. USPS finally fixes website flaw that exposed 60 million users' data
  6. LastPass login problems caused by cascading server failure
  7. Furry erotica site 'High Tail Hall' exposed data of nearly 500K users
  8. The July edition of Beazley Breach Insights found that business email compromise attacks have been rising steadily. Is business email
  9. Come evitare che le tue #password diventino la chiave di accesso ai tuoi account
  10. PSA: Phishing Levels Rise Ahead of Black Friday and Cyber Monday
  11. Phishing Attack Compromises Health First Patients’ Data
  12. US Postal Service website vulnerability leaked 60 million user data
  13. Amazon technical failure caused to leaks users’ email addresses
  14. US Postal Service Left 60 Million Users Data Exposed For Over a Year
  15. Amazon Suffered Data Breach – Customers Name & Email Addresses Exposed
  16. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?
  17. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack
  18. New @awscloud settings will allow users to batch change permissions with the aim of avoiding accidental S3 data leaks, but

THREATS

  1. Silicon Valley Hacker Swipes Millions Worth of Cryptocurrency Using SIM Swapping
  2. Google’s Practical Action Against Malware and Its Authors
  3. USPS reportedly fixes website bug that exposed data of 60M users
  4. [SingCERT] Alert on Adobe Flash Player Vulnerability (CVE-2018-15981)
  5. #Irisscon: Stop Siloing Vulnerability Management to Deal with Old Bugs
  6. Rotexy Mobile Trojan Launches 70k+ Attacks in Three Months
  7. .@radware #cybersecurity researchers found hackers to be targeting bank users via a #router vulnerability. Learn how a fake banking site
  8. Cross-site search attack applied to snoop on Google’s bug tracker
  9. Facebook And Instagram Went Down Due To A Server Bug
  10. SIM swap! Man charged after million dollar cryptocurrency theft
  11. SIM swap! Man charged after million dollar cryptocurrency theft
  12. #DidYouKnow A single subscription of AVG Internet Security covers every PC in your family? It also includes webcam and ransomware protection,
  13. SSL vulnerability scanner – MassBleed
  14. Aurora / Zorro Ransomware Actively Being Distributed
  15. How does @TalosSecurity's discovery change the way you or your enterprise views #ransomware?
  16. Flaw allowing identity spoofing affects authentication based on German eID cards
  17. USPS finally fixes website flaw that exposed 60 million users' data
  18. Update now! Adobe Flash has another critical security vulnerability
  19. How Dropbox's red team discovered an Apple zero-day exploit chain by accident
  20. Found this picture of myself doing an internal briefing on the Nimda worm in 2001. Note the size of the
  21. A bypass was found by @okta researchers that allows #macOS #malware to pose as @Apple files despite needing to be
  22. The Rotexy mobile Trojan – banker and ransomware
  23. Researchers recently discovered a new #MacOS #malware that targets #cryptocurrency investors through chat platforms. Discover how this is possible and
  24. How was a black box attack used to exploit ATM vulnerabilities?
  25. Research reveals that 44% of industrial facilities have USB malware risks
  26. CyberSecurity Asean security alert on Multiple Vulnerabilities in VMware vSphere Data Protection Could Allow for Remote Code Execution
  27. Do you believe that the application #security vetting process would benefit from the addition of an entropy source?
  28. Experts found first Mirai bot targeting Linux servers via Hadoop YARN flaw
  29. VMware Releases Critical Security Updates for Multiple Vulnerabilities
  30. Emotet malware runs on a dual infrastructure to avoid downtime and takedowns
  31. North Korea To Host Cryptocurrency and Blockchain Conference
  32. Hacking Syndicate TA505 Back with Focus on Info-Stealing Trojan
  33. US Postal Service website vulnerability leaked 60 million user data
  34. Facebook Increases Average Bounty rewards for High Impact Vulnerabilities
  35. Facebook raises rewards for a security vulnerabilities to $40,000

CRIME

  1. Silicon Valley Hacker Swipes Millions Worth of Cryptocurrency Using SIM Swapping
  2. China Boosted Technology and Intellectual Property Theft Operations Says USTR
  3. SIM swap! Man charged after million dollar cryptocurrency theft
  4. SIM swap! Man charged after million dollar cryptocurrency theft
  5. The Rotexy mobile Trojan – banker and ransomware
  6. The July edition of Beazley Breach Insights found that business email compromise attacks have been rising steadily. Is business email
  7. Hacking Syndicate TA505 Back with Focus on Info-Stealing Trojan
  8. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?

POLITICS

  1. The Rotexy mobile Trojan – banker and ransomware
  2. North Korea To Host Cryptocurrency and Blockchain Conference
  3. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?
  4. 500K Italian Public Administration Email Accounts Compromised By Targeted Attack

Nov 22, 2018

Daily brief for 2018-11-21

ASIA

  1. City of Valdez, Alaska admits to paying off ransomware infection
  2. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  3. Adobe issues fix for Flash bug allowing remote code execution
  4. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  5. Amazon UK is notifying a data breach to its customers days before Black Friday
  6. New Pterodo Backdoor Malware Detected By Ukraine
  7. Is Magecart Checking Out Your Secure Online Transactions?
  8. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  9. Phishing Scams Serious Problem for Canada’s Global Affairs
  10. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  11. Malaysia’s largest media company becomes victim of a ransomware attack

WORLD

  1. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  2. A flaw in US Postal Service website exposed data on 60 Million Users
  3. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  4. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  5. Facebook increases rewards for its bug bounty program and facilitate bug submission
  6. Inspiring the Next Generation of Tech Talent
  7. Google Taking Over Health Records Raises Patient Privacy Fears
  8. What Is Windows PowerShell (And Could It Be Malicious)?
  9. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  10. Amazon tech error leaks customers’ email addresses
  11. USPS Site Exposed Data on 60 Million Users
  12. Vision Direct Deals With Customer Data Leak
  13. Amazon suffers data breach days before Black Friday
  14. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  15. Black Friday Phishing Dos and Don’ts
  16. Amazon warns customers it leaked their names and email addresses
  17. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  18. German eID Authentication Flaw Lets You Change Identity
  19. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  20. Amazon UK is notifying a data breach to its customers days before Black Friday
  21. Italian Naval Industry Attacked By MartyMcFly Malware
  22. Sofacy APT unleashes new 'Cannon' trojan
  23. New Pterodo Backdoor Malware Detected By Ukraine
  24. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  25. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  26. White House admits Ivanka Trump used private email for government business
  27. Magecart Black Hats Battle it Out On Infected Site
  28. Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
  29. Is Magecart Checking Out Your Secure Online Transactions?
  30. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  31. Infowars Online Store Got Infected with Card Skimming Malware
  32. Sofacy APT group used a new tool in latest attacks, the Cannon
  33. Phishing Scams Serious Problem for Canada’s Global Affairs
  34. Malaysia’s largest media company becomes victim of a ransomware attack
  35. Russian hackers are conducting more covert attacks on US and European computers
  36. US Department of Justice is investigating Tether for manipulation of market prices
  37. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  38. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  39. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

ATTACKS

  1. Phishing: It's all too easy on mobile devices
  2. Email Addresses and Phone Numbers of More than 60 Million Users Exposed by USPS
  3. A flaw in US Postal Service website exposed data on 60 Million Users
  4. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  5. Amazon Customer Email Addresses Leaked Because of 'Technical Error'
  6. Google Taking Over Health Records Raises Patient Privacy Fears
  7. Amazon tech error leaks customers’ email addresses
  8. USPS Site Exposed Data on 60 Million Users
  9. Vision Direct Deals With Customer Data Leak
  10. Amazon suffers data breach days before Black Friday
  11. Emotet’s Thanksgiving Campaign Delivers New Recipes for Compromise
  12. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  13. Record Retention
  14. A hacker known as #Tessa88 offered several compromise databases obtained from LinkedIn, MySpace and other companies. Now Recorded Future believes
  15. Black Friday Phishing Dos and Don’ts
  16. The promised integration with #HaveIBeenPwned is expanding in #FirefoxMonitor with new breach alerts when a user visits a recently compromised
  17. Amazon warns customers it leaked their names and email addresses
  18. Amazon leaks users' email addresses due to 'technical error'
  19. High Tail Hall data breach exposes over 400,000 furry fans
  20. Facebook Ads Urge Its Staff To Leak Secrets
  21. Amazon Suffers Data Breach Days Before Black Friday
  22. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  23. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  24. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  25. Despite early speculation, experts concluded the BGP route leak that sent Google traffic through China and Russia was due to
  26. Amazon UK is notifying a data breach to its customers days before Black Friday
  27. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  28. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  29. White House admits Ivanka Trump used private email for government business
  30. New OceanLotus watering hole attacks target southeast Asia
  31. #CyberMonday Tip 1: Be careful of phishing scams claiming to be from a package-delivery company with links to tracking information. AVG
  32. .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
  33. How have #phishing campaigns threatened your #EnterpriseSecurity system?
  34. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  35. Amazon Data Leak Exposes Email Addresses Right Before Black Friday
  36. Yikes...#Instagram Accidentally Exposed Some Users' #Passwords In Plaintext
  37. #Gmail Glitch Enables Anonymous Messages in #Phishing Attacks:
  38. APAC consumers want IoT devices, but fear data leaks
  39. Phishing Scams Serious Problem for Canada’s Global Affairs
  40. OUR BLACK FRIDAY DEALS ARE LIVE! Get 50% off from FREEDOME VPN and TOTAL subscriptions with coupon code BLACKFRIDAY. Buy now:
  41. Microsoft now lets you log into Outlook, Skype, Xbox Live without a password
  42. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

THREATS

  1. Pen-test at Dropbox turns up three Apple 0-day bugs
  2. City of Valdez, Alaska admits to paying off ransomware infection
  3. A flaw in US Postal Service website exposed data on 60 Million Users
  4. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  5. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  6. Facebook increases rewards for its bug bounty program and facilitate bug submission
  7. What Is Windows PowerShell (And Could It Be Malicious)?
  8. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  9. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  10. Mirai Used as Payload in Hadoop YARN Vulnerability
  11. Facebook entices researchers with $40,000 reward for account takeover vulnerabilities
  12. 500K Android users hit with malware, and what to do if you're infected
  13. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  14. Russian Cozy Bear cyberspies awake from hibernation to sling spyware
  15. How a Security Test for DropBox Revealed 3 Apple Zero Day Vulnerabilities
  16. Adobe issues fix for Flash bug allowing remote code execution
  17. 13 Malware-Laden Fake Apps on Google Play
  18. A new vulnerability was discovered to affect #Bluetooth #firmware or operating system software drivers. Learn what this vulnerability is and
  19. German eID Authentication Flaw Lets You Change Identity
  20. Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOW
  21. New vulnerabilities are coming faster than you can fix them
  22. Red Hawk – Open Source Information Gathering and Vulnerability Scanning Tool
  23. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  24. Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
  25. Italian Naval Industry Attacked By MartyMcFly Malware
  26. Sofacy APT unleashes new 'Cannon' trojan
  27. New Pterodo Backdoor Malware Detected By Ukraine
  28. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  29. Experts found flaws in Dell EMC and VMware Products. Patch them now!
  30. From directory traversal to direct travesty: Crash, hijack, siphon off this TP-Link VPN box via classic exploitable bugs
  31. A @DLink #router vulnerability was used to send banking users to a fake site in order to steal #UserCredentials. Learn
  32. Malicious programs disguised as racing games on Google Play
  33. Adobe plugs critical RCE Flash Player flaw, update ASAP! Exploitation may be imminent
  34. Patches Released for Flaws Affecting Dell EMC, VMware Products
  35. Adobe Fixes Critical Flash Vulnerability with
  36. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  37. Conficker: A 10-year retrospective on a legendary worm
  38. Malware Moves: Attackers Retool for Cryptocurrency Theft
  39. Infowars Online Store Got Infected with Card Skimming Malware
  40. Facebook Increases Rewards for Account Hacking Vulnerabilities
  41. Adobe Flash Player Update Released for Remote Code Execution Vulnerability
  42. New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform Cryptocurrency-Mining & Brute-Force Attack
  43. Facebook Boosts Bug Bounty Payouts for Account Takeover Flaws
  44. Signing and Verifying Ethereum Signatures
  45. Hacker got Rewarded for Discovering a Critical Steam Bug
  46. CVE-2018-15981: Adobe Flash Player Arbitrary Code Execution Vulnerability
  47. Malaysia’s largest media company becomes victim of a ransomware attack
  48. US Department of Justice is investigating Tether for manipulation of market prices
  49. Awake Security uncovers malicious intent across on-premise, IoT and cloud infrastructure
  50. Centreon releases Remote Server functionality for cross-domain monitoring of multi-site IT operations
  51. Fancy Bear APT Uses New Cannon Trojan to Target Government Entities
  52. "Luiz O Pinto" pushed 500,000+ installs of malware via Google Play, in ~1 week.
  53. Uncover virtual hosts of domain with Fierce
  54. Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
  55. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  56. How to find, is link malicious/URL or not
  57. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

CRIME

  1. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  2. Facebook increases rewards for its bug bounty program and facilitate bug submission
  3. What Is Windows PowerShell (And Could It Be Malicious)?
  4. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  5. Take a Look at L0rdix, The Super Malware Toolkit of 2018
  6. USPS Site Exposed Data on 60 Million Users
  7. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  8. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  9. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  10. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  11. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  12. Is Magecart Checking Out Your Secure Online Transactions?
  13. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  14. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  15. Signing and Verifying Ethereum Signatures
  16. Phishing Scams Serious Problem for Canada’s Global Affairs
  17. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  18. Malaysia’s largest media company becomes victim of a ransomware attack

POLITICS

  1. What Is Windows PowerShell (And Could It Be Malicious)?
  2. USPS Site Exposed Data on 60 Million Users
  3. New Pterodo Backdoor Malware Detected By Ukraine
  4. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  5. How is Plead #malware used for #cyberespionage attacks? Learn more with Michael Cobb of @thehairyITdog.
  6. Phishing Scams Serious Problem for Canada’s Global Affairs
  7. Russian hackers are conducting more covert attacks on US and European computers
  8. US Department of Justice is investigating Tether for manipulation of market prices
  9. MageCart Group Sabotages Rival to Ruin Data and Reputation