Showing posts with label Sector. Show all posts
Showing posts with label Sector. Show all posts

Nov 30, 2018

Sector brief for 2018-11-29

HEALTHCARE

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. 2.6 Million Atrium Health Patient Records Compromised by Vendor AccuDoc
  3. U.S. DoJ charges Iranian duo over SamSam Ransomware activity
  4. US Indicts Two Iranians for SamSam Campaign Blitz
  5. Database breach affects 2.6 million Atrium Health patients
  6. McAfee Labs 2019 Threats Predictions Report
  7. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  8. Atrium Health Data Breach Affected More than 2 Million Patients

TRANSPORT

  1. U.S. DoJ charges Iranian duo over SamSam Ransomware activity

BANKING & FINANCE

  1. Atrium Health’s Databreach: 2.65 Million Patient Records Publicly Revealed
  2. Rotexy malware morphs into dangerous banking Trojan
  3. Banking Trojan Made in Brazil? A Brief Look
  4. Brazilian Financial Malware Spreads Beyond National Boundaries
  5. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  6. Looking Ahead: RiskIQ’s 2019 Cybersecurity Predictions
  7. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  8. US Indicts Two Iranians for SamSam Campaign Blitz
  9. Brazilian-made bank trojan
  10. Proofpoint: Hackers testing new reconnaissance #malware on financial institutions.
  11. Dell data breach – Dell forces password reset after the incident
  12. McAfee Labs 2019 Threats Predictions Report
  13. Threat Spotlight: New spear phishing attack gift card scam
  14. Lazarus Targeting Latin America
  15. AccuDoc Data Breach impacted 2.6 Million Atrium Health patients
  16. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  17. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach

INFORMATION & TELECOMMUNICATION

  1. “And once a device is part of a botnet, it leaves them open for future attacks. So users should avoid
  2. A security hole in a mail preview program may have made the data of 60 million customers vulnerable.
  3. NEW: Russian hackers using Brexit talks to disguise its phishing lures
  4. McAfee Labs 2019 Threats Predictions Report
  5. Facebook Increases Bug Bounty Payouts to Improve User Security
  6. Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
  7. UK and Dutch Regulators Fined Uber for $1.1 Million over 2016 Data Breach

FOOD

Nil

WATER

Nil

ENERGY

  1. Banking Trojan Made in Brazil? A Brief Look

GOVERNMENT & PUBLIC SERVICE

  1. Accenture: Russian hackers using Brexit talks to disguise phishing lures
  2. SamSam ransomware actors charged, sanctioned by US government
  3. Indian Police Break Up International Computer Virus Scam
  4. The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
  5. McAfee Labs 2019 Threats Predictions Report
  6. Lazarus Targeting Latin America

Nov 27, 2018

Sector brief for 2018-11-26

HEALTHCARE

  1. Ransomware attack disrupted emergency rooms at Ohio Hospital System
  2. Ransomware Attack Forced Ohio Hospital System to Divert ER Patients
  3. Internal negligence to blame for most data breaches involving personal health information

TRANSPORT

  1. Holiday Season: Cybercriminals are Phishing All The Way
  2. Phishing Campaign targeting French Industry

BANKING & FINANCE

  1. What is Data Classification? Guidelines and Process
  2. When Do You Need to Report a Data Breach?
  3. Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
  4. Holiday Season: Cybercriminals are Phishing All The Way
  5. Phishing Campaign targeting French Industry
  6. Cryptocurrency threat predictions for 2019
  7. Cyberthreats to financial institutions 2019: overview and predictions
  8. Discover how a @DLink #router vulnerability targeted a banking site to steal #UserCredentials with expert Judith Myerson.

INFORMATION & TELECOMMUNICATION

  1. Microsoft launches review after a trio of Azure bugs locked users out of Office 365
  2. 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
  3. How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
  4. Half of all Phishing Sites Now Have the Padlock
  5. Despite growing concerns about cybersecurity and the number of data breach incidents in the news, many employees still have bad
  6. Phishing Campaign targeting French Industry
  7. Cyberthreats to financial institutions 2019: overview and predictions
  8. Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
  9. An ongoing phishing campaign is targeting French industry, @FSLabs finds.

FOOD

Nil

WATER

Nil

ENERGY

  1. Siemens patches major firewall flaw, other vulnerabilities

GOVERNMENT & PUBLIC SERVICE

  1. Did UK city council over-react to a vulnerability report in its recycling app or not?
  2. When Do You Need to Report a Data Breach?
  3. Recent Attacks on US Entities Attributed to APT29
  4. Russia Plans To tighten Data Protection Owing To Intelligence Leaks
  5. Cyberthreats to financial institutions 2019: overview and predictions
  6. Ukrainian Police Nab Suspected RAT-Slinger
  7. Crypto Mining Malware Infects Make-A-Wish-Foundation Website

Nov 24, 2018

Sector brief for 2018-11-23

HEALTHCARE

  1. US Says China Increased Hacking over Trade Dispute
  2. Southwest Washington Regional Surgery Center suffered a Phishing attack

TRANSPORT

  1. US Says China Increased Hacking over Trade Dispute

BANKING & FINANCE

  1. North Korean Hackers Hit Latin American Banks
  2. New Emotet Thanksgiving campaign differs from previous ones
  3. Synthetic identity fraud to drive $48 billion in annual losses by 2023 – Juniper Research

INFORMATION & TELECOMMUNICATION

  1. New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
  2. Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
  3. “Back in Black” – Article 13 has YouTube threatening to pull the plug over upload filter
  4. Internet connected devices might be the hot item for Christmas this year, but are they secure?
  5. SAVE 50% FOR BLACK FRIDAY! Get half off FREEDOME VPN and TOTAL with coupon code BLACKFRIDAY.
  6. The number of ransomware attacks on individuals has come down as it has become harder to get them to pay,
  7. Over 500k Play Store users have installed 13 games that contain malware

FOOD

Nil

WATER

Nil

ENERGY

  1. US Says China Increased Hacking over Trade Dispute

GOVERNMENT & PUBLIC SERVICE

  1. German e-government SDK patched against ID spoofing vulnerability
  2. US Says China Increased Hacking over Trade Dispute
  3. Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
  4. Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
  5. US Postal Service Website Left Data Exposed for Over a Year
  6. Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits
  7. 60 million users’ data were exposed by the US Postal Service

Nov 23, 2018

Sector brief for 2018-11-22

HEALTHCARE

  1. Phishing Attack Compromises Health First Patients’ Data
  2. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?

TRANSPORT

Nil

BANKING & FINANCE

  1. Rotexy Mobile Trojan Launches 70k+ Attacks in Three Months
  2. .@radware #cybersecurity researchers found hackers to be targeting bank users via a #router vulnerability. Learn how a fake banking site
  3. VB2018 paper: Since the hacking of Sony Pictures
  4. The Rotexy mobile Trojan – banker and ransomware
  5. How was a black box attack used to exploit ATM vulnerabilities?
  6. Hacking Syndicate TA505 Back with Focus on Info-Stealing Trojan
  7. Facebook raises rewards for a security vulnerabilities to $40,000
  8. Data breaches in schools: How should an academic institution report a security incident to comply with the GDPR?

INFORMATION & TELECOMMUNICATION

  1. Facebook And Instagram Went Down Due To A Server Bug
  2. #DidYouKnow A single subscription of AVG Internet Security covers every PC in your family? It also includes webcam and ransomware protection,
  3. Facebook 'walking dangerous line' as it appeals record fine
  4. Emoji Kitten Denial Of Service Attack Continues to Haunt Skype
  5. Found this picture of myself doing an internal briefing on the Nimda worm in 2001. Note the size of the
  6. North Korea To Host Cryptocurrency and Blockchain Conference
  7. Amazon technical failure caused to leaks users’ email addresses
  8. Facebook Increases Average Bounty rewards for High Impact Vulnerabilities
  9. Facebook raises rewards for a security vulnerabilities to $40,000

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Flaw allowing identity spoofing affects authentication based on German eID cards
  2. CyberSecurity Asean security alert on Multiple Vulnerabilities in VMware vSphere Data Protection Could Allow for Remote Code Execution
  3. North Korea To Host Cryptocurrency and Blockchain Conference
  4. US Postal Service Left 60 Million Users Data Exposed For Over a Year

Nov 22, 2018

Sector brief for 2018-11-21

HEALTHCARE

  1. Google Taking Over Health Records Raises Patient Privacy Fears
  2. Conficker: A 10-year retrospective on a legendary worm

TRANSPORT

  1. Sofacy APT unleashes new 'Cannon' trojan
  2. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon

BANKING & FINANCE

  1. Emotet Banking Trojan Uses Stolen Templates to Boost Phishing Campaign Numbers
  2. Lazarus APT Uses Modular Backdoor to Target Financial Institutions
  3. What Is Windows PowerShell (And Could It Be Malicious)?
  4. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  5. USPS Site Exposed Data on 60 Million Users
  6. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit
  7. Black Friday Phishing Dos and Don’ts
  8. Bah HumBUG: 5 Recent Holiday Phishing Samples You Need to Watch Out For
  9. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  10. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  11. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  12. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  13. Magecart Black Hats Battle it Out On Infected Site
  14. Is Magecart Checking Out Your Secure Online Transactions?
  15. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  16. A @DLink #router vulnerability was used to send banking users to a fake site in order to steal #UserCredentials. Learn
  17. Infowars Online Store Got Infected with Card Skimming Malware
  18. Signing and Verifying Ethereum Signatures
  19. Millions Stolen by North Korea-Linked Hacking Group from Atms in Africa and Asia
  20. Malaysia’s largest media company becomes victim of a ransomware attack
  21. US Department of Justice is investigating Tether for manipulation of market prices
  22. MageCart Group Sabotages Rival to Ruin Data and Reputation
  23. Major Flaws Found in IT Pentagon Processes After First Ever Financial Audit

INFORMATION & TELECOMMUNICATION

  1. Facebook increases rewards for its bug bounty program and facilitate bug submission
  2. Inspiring the Next Generation of Tech Talent
  3. Google Taking Over Health Records Raises Patient Privacy Fears
  4. What Is Windows PowerShell (And Could It Be Malicious)?
  5. Spoofed addresses and anonymous sending: new Gmail bugs make for easy pickings
  6. Facebook entices researchers with $40,000 reward for account takeover vulnerabilities
  7. USPS Site Exposed Data on 60 Million Users
  8. Researchers Reveal Identity of Hacker Behind Massive Data Breaches
  9. A hacker known as #Tessa88 offered several compromise databases obtained from LinkedIn, MySpace and other companies. Now Recorded Future believes
  10. Black Friday Phishing Dos and Don’ts
  11. 13 Malware-Laden Fake Apps on Google Play
  12. Facebook Ads Urge Its Staff To Leak Secrets
  13. How Retailers Can Protect Against Magecart This Black Friday and Holiday Season
  14. New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
  15. Amazon UK is notifying a data breach to its customers days before Black Friday
  16. Black Friday & Cyber Monday Deals: Phishing and Site Skimmers
  17. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  18. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  19. Malicious programs disguised as racing games on Google Play
  20. Yikes...#Instagram Accidentally Exposed Some Users' #Passwords In Plaintext
  21. #Gmail Glitch Enables Anonymous Messages in #Phishing Attacks:
  22. Facebook Increases Rewards for Account Hacking Vulnerabilities
  23. Facebook Boosts Bug Bounty Payouts for Account Takeover Flaws
  24. OUR BLACK FRIDAY DEALS ARE LIVE! Get 50% off from FREEDOME VPN and TOTAL subscriptions with coupon code BLACKFRIDAY. Buy now:
  25. "Luiz O Pinto" pushed 500,000+ installs of malware via Google Play, in ~1 week.
  26. How to find, is link malicious/URL or not
  27. Microsoft now lets you log into Outlook, Skype, Xbox Live without a password
  28. Worried about cryptojacking? Check out how SentinelOne Detects and Protects from GhostMiner CryptoMiner

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
  2. New Pterodo Backdoor Malware Detected By Ukraine
  3. New Campaign by APT Group Sofacy Discovered using new Malware Named Cannon
  4. White House admits Ivanka Trump used private email for government business
  5. New OceanLotus watering hole attacks target southeast Asia
  6. Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
  7. Weekly Threat Briefing: Russian APT Comes Back to Life with New US Spear-phishing Campaign
  8. Sofacy APT group used a new tool in latest attacks, the Cannon
  9. Phishing Scams Serious Problem for Canada’s Global Affairs
  10. Russian hackers are conducting more covert attacks on US and European computers
  11. Fancy Bear APT Uses New Cannon Trojan to Target Government Entities
  12. Russia Linked Group Resurfaces With Large-Scale Phishing Campaign

Nov 21, 2018

Sector brief for 2018-11-20

HEALTHCARE

  1. Hackers Linked to Russia Impersonate US Officials
  2. Russian APT activity is resurgent, researchers say
  3. Zscaler ThreatLabZ Phishing Roundup

TRANSPORT

Nil

BANKING & FINANCE

  1. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  2. Emotet Returns with Thanksgiving Theme and Better Phishing Tricks
  3. Web skimmers compete in Umbro Brasil hack
  4. Malvertising in Apple Pay Targets iPhone Users
  5. An Introduction to Magecart
  6. Report: Emotet makes phishing lures more convincing by scraping victims' emails
  7. Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America
  8. Emotet Campaigns Persist, Utilize Updated Tactics and Techniques
  9. For Smbs Ransomware Attacks still the Greatest Online Threat
  10. Zscaler ThreatLabZ Phishing Roundup
  11. Vision Direct 'fesses up to hack that exposed customer names, payment cards
  12. Magecart Spies Payment Cards From Retailer Vision Direct
  13. Kaspersky Security Bulletin: Threat Predictions for 2019
  14. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  15. Can a D-Link router vulnerability threaten bank customers?
  16. Google Account Hacked for Fake Bitcoin Reward
  17. 2019 Security Predictions – Utilities and Industrial Control Systems Targeted with Ransomware
  18. Two TalkTalk hackers jailed for 2015 data breach that cost it £77 million

INFORMATION & TELECOMMUNICATION

  1. Instagram bug exposes user passwords
  2. Gmail Glitch Enables Anonymous Messages in Phishing Attacks
  3. 560,000 Duped Into Installing Android Malware in the Form of Fake Driving Games
  4. Inspiring Gender Diversity at Women of the Channel Leadership Summit
  5. Instagram glitch exposed some user passwords
  6. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  7. Zscaler ThreatLabZ Phishing Roundup
  8. 2018 holiday travel period expected to be the busiest travel season on record
  9. Kaspersky Security Bulletin: Threat Predictions for 2019
  10. Instagram Patched A Data Download Tool Bug That Exposed Users Passwords
  11. Vulnerability Spotlight: Multiple remote code execution vulnerabilities in Atlantis Word Processor
  12. Google Account Hacked for Fake Bitcoin Reward
  13. Google, Target Hit by Twitter Bitcoin Scam Account Hacks

FOOD

Nil

WATER

  1. Tech Docs: Keep Out of the Flood Zone with DoS Protection

ENERGY

  1. Tech Docs: Keep Out of the Flood Zone with DoS Protection
  2. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  3. 2019 Security Predictions – Utilities and Industrial Control Systems Targeted with Ransomware

GOVERNMENT & PUBLIC SERVICE

  1. ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaign
  2. 200K Outlaw Botnet Uses SSH Brute Forcing to Propagate, Monero Mining for Profit
  3. Infamous Russian Hacking Group Used New Trojan in Recent Attacks
  4. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  5. APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign
  6. Russia’s Elite Hackers May Have New Phishing Tricks
  7. Government Agencies and Think Tanks attacked, APT29 suspected
  8. Hackers Linked to Russia Impersonate US Officials
  9. Russian APT activity is resurgent, researchers say
  10. Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
  11. OceanLotus: New watering hole attack in Southeast Asia
  12. OceanLotus: New watering hole attack in Southeast Asia
  13. Kaspersky Security Bulletin: Threat Predictions for 2019
  14. Experts analyzed how Iranian OilRIG hackers tested their weaponized documents
  15. Google, Target Hit by Twitter Bitcoin Scam Account Hacks

Nov 20, 2018

Sector brief for 2018-11-19

HEALTHCARE

  1. Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
  2. SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
  3. Texas hospital becomes victim of Dharma ransomware

TRANSPORT

Nil

BANKING & FINANCE

  1. New Modular tRat Remote Access Trojan Surfaced During September
  2. Tianfu Cup PWN hacking contest – White hat hackers earn $1 Million for Zero-Day exploits
  3. Collective Intelligence Podcast, Vitali Kremez on Magecart
  4. Business email compromise scam costs Pathé $21.5 million
  5. Subject: Invoice. The cause of 6 out of 10 of the most effective phishing campaigns in 2018
  6. Vision Direct reveals customer credit card leak, fake Google script may be to blame
  7. Vision Direct Notifies Customers of Data Compromise
  8. Email campaign spreading new tRAT malware
  9. October 2018’s Most Wanted Malware: For The First Time, Remote Access Trojan Reaches Global Threat Index’s Top 10

INFORMATION & TELECOMMUNICATION

  1. U.S. warns countries not to 'manipulate the extradition process' for cybercriminals
  2. Tianfu Cup PWN hacking contest – White hat hackers earn $1 Million for Zero-Day exploits
  3. Instagram Flaw Exposes User Passwords
  4. Multiple Remote TP-Link TL-R600VPN Router Vulnerabilities Patched
  5. A week in security (November 12 – 18)
  6. Instagram Bug, Now Fixed, Exposed User Passwords
  7. The Most Damaging Election Disinformation Campaign Came From Donald Trump, Not Russia
  8. 2FA Login Failure in Office 365 and Azure
  9. SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
  10. New ShadowTalk update looks at: New nation-state threat actor uses advanced TTPs to target Pakistan Lazarus Group’s FASTCash malware
  11. Cybaze ZLab – Yoroi team analyzed malware used in recent attacks on US entities attributed to APT29
  12. Outlaw Group Distributes Botnet for Cryptocurrency-Mining, Scanning, and Brute-Force
  13. Instagram flaw exposes user passwords
  14. Instagram Privacy Tool Exposed Passwords
  15. Proofpoint #ThreatInsight research: #sLoad and #Ramnit pairing in sustained personalized campaigns against UK and Italy:
  16. Instagram Accidentally Exposed Some User Passwords
  17. How #privacy intersects with #CyberSecurity. “Criminals can craft better phishing emails to scam you when they know what you’re interested in.”
  18. Instagram Critical Bug Leaked User’s Password Via its Data Download Tool
  19. Fun fact: The Morris Worm of 1988 did never spread to Finland, as the outbreak happened two weeks before we
  20. Instagram Accidentally Exposed Some Users' Passwords In Plaintext

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
  2. U.S. warns countries not to 'manipulate the extradition process' for cybercriminals
  3. The Most Damaging Election Disinformation Campaign Came From Donald Trump, Not Russia
  4. Cybaze ZLab – Yoroi team analyzed malware used in recent attacks on US entities attributed to APT29
  5. Russian Cozy Bear APT 29 hackers may be impersonating State Department
  6. Turkish Police Arrested Cryptocurrency Hackers

Nov 17, 2018

Sector brief for 2018-11-16

HEALTHCARE

  1. New HealthEquity Data Breach Exposes PII/PHI of Almost 21,000 Customers
  2. SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
  3. Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert

TRANSPORT

  1. Group-IB presented latest cybercrime and nation-state hacking trends in Asia

BANKING & FINANCE

  1. InfoWars: Magecart Infection Points to 'Industrial Sabotage'
  2. Reappearance of Magecart Malware to Infect Virtual Stores
  3. New HealthEquity Data Breach Exposes PII/PHI of Almost 21,000 Customers
  4. Hacking group returns, switches attacks from ransomware to trojan malware
  5. Details of 170,000 Pakistani debit cards leaked on dark web
  6. Cyber News Rundown: Infowars Hacked by Card Skimmers
  7. .@TalosSecurity recently created a #decryptor that helps files affected by the #ransomware #Thanatos -- typically known to not decrypt files
  8. Russian Banks Hit By Major Phishing Attacks
  9. How to Stay One Step Ahead of Phishing Websites — Literally
  10. Group-IB presented latest cybercrime and nation-state hacking trends in Asia
  11. Russian banks hit by major phishing attacks from two hacker groups
  12. ATM Tests Reveal Surprising Security Flaws
  13. tRat is a new modular RAT used by the threat actor TA505
  14. Malaysia’s Largest Media Company Allegedly Suffers Ransomware Attack
  15. Data Breaches on the Rise in Financial Services
  16. Four More Malicious Cryptocurrency Apps on Google Play
  17. Hackers infect Malaysia’s largest media company with ransomware, then demand $6.45 million
  18. #GroupIB #ThreatIntelligence detected large set of compromised payment cards details that was put on sale on underground card shop on
  19. Two hacker groups attacked Russian banks posing as the Central Bank of Russia
  20. Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert
  21. 5 Top Techniques for Testing Blockchain Apps
  22. Warning Issued by Emirates NBD over VAT Phishing Email Targeting its Customers
  23. Looking Back at LogRhythm Labs' 2018 Predictions for Security - How Did We Do?

INFORMATION & TELECOMMUNICATION

  1. InfoWars: Magecart Infection Points to 'Industrial Sabotage'
  2. Gmail Glitch Offers Stealthy Trick for Phishing Attacks
  3. Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
  4. This Week in Security News: Holiday Cybercriminals & Cryptomining Malware
  5. Cybaze ZLab- Yoroi team spotted a new variant of the APT28 Lojax rootkit
  6. Word of the Day: social engineering
  7. SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.
  8. 2FA codes are great for security, except when 26M of them are leaked
  9. #GroupIB #ThreatIntelligence detected large set of compromised payment cards details that was put on sale on underground card shop on
  10. Google, US and Israeli politician Twitter accounts hijacked to promote 'Elon Musk' Bitcoin scam
  11. Two hacker groups attacked Russian banks posing as the Central Bank of Russia
  12. Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert
  13. French Company Data Breach Causes Sensitive Information Stolen to the Hackers
  14. Magecart become close to a household name with hacks of massive sites like http://Ticketmaster.com , http://Newegg.com and British Airways.
  15. Amid calls for a Windows bug status dashboard, Microsoft belatedly agrees to build one
  16. Looking Back at LogRhythm Labs' 2018 Predictions for Security - How Did We Do?
  17. SentinelOne Detects KeyPass Ransomware! KeyPass is a new ransomware threat that has hit at least 20 countries and appears to be

FOOD

Nil

WATER

Nil

ENERGY

  1. Group-IB presented latest cybercrime and nation-state hacking trends in Asia
  2. Apache Struts2 Commons FileUpload Deserialization Remote Code Execution Vulnerability (CVE-2016-100031)Threat Alert
  3. French Company Data Breach Causes Sensitive Information Stolen to the Hackers

GOVERNMENT & PUBLIC SERVICE

  1. Using Microsoft Powerpoint as Malware Dropper
  2. Operation Shaheen – Pakistan Air Force members targeted by nation-state attackers
  3. Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery
  4. This Week in Security News: Holiday Cybercriminals & Cryptomining Malware
  5. Group-IB presented latest cybercrime and nation-state hacking trends in Asia
  6. Kaspersky Announces the Details of Windows 7 Zero-Day Vulnerability
  7. Looking Back at LogRhythm Labs' 2018 Predictions for Security - How Did We Do?

Nov 16, 2018

Sector brief for 2018-11-15

HEALTHCARE

  1. Phishing Attack Causes Breach at Southwest Washington Regional Surgery Center
  2. WannaCry Still Impacts Thousands of Systems Every Month

TRANSPORT

  1. Compromising vital infrastructure: air traffic control
  2. Bots on a plane? Bad bots cause unique cyber-security issues for airlines

BANKING & FINANCE

  1. Proofpoint: Hackers testing new reconnaissance malware on financial institutions
  2. Survey Says: Bad PR Due to Data Breach News, Very Bad for Businesses
  3. Compromising vital infrastructure: air traffic control
  4. Phishing Attack Causes Breach at Southwest Washington Regional Surgery Center
  5. 20% of MageCart-compromised merchants get reinfected within days
  6. 20% of MageCart-compromised merchants get reinfected within days
  7. RiskIQ’s 2018 Black Friday E-commerce Blacklist: Key Intel for This Year’s Mega Shopping Weekend
  8. Phishing Emails with .COM Extensions Are Hitting Finance Departments
  9. Brazilian Users Under Attack From Metamorfo Banking Trojan
  10. Today #GroupIB detected a massive phishing campaign sent to Russian banks from a fake email address purporting to belong to
  11. Massive Data Leaks Keep Happening Because Big Companies Can Afford to Lose Your Data
  12. 14 Malware Families Targeting E-Commerce Brands Ahead of Black Friday
  13. Phishing fraudsters set their sights on online storage portals
  14. Skimmed BA and Newegg Customer Card Details Up for Sale
  15. InfoWars online store hit by Magecart
  16. Alex Jones's InfoWars online store hit by Magecart
  17. Cryptocurrency fraud is the exception, not the rule
  18. Ransomware Attack Strikes Media Prima
  19. Access Control Acronyms: ACL, RBAC, ABAC, PBAC, RAdAC, and a Dash of CBAC

INFORMATION & TELECOMMUNICATION

  1. Suspected Russian cybercriminal arrested in Bulgaria at U.S. request, lawyer says
  2. Vulnerability: Emojis can kill Skype for Business
  3. 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing [Infographic]:
  4. Massive Data Leaks Keep Happening Because Big Companies Can Afford to Lose Your Data
  5. Official Google Twitter account hacked in Bitcoin scam
  6. Law firm uncovers exposed sensitive details about top attorney online. @mazzazone gives the details:
  7. #ThreatHuntThursday: How to hunt for lateral movement by #PSExec. Check out our new blog post by @sp1nl0ck on how remote
  8. Two whitehats receive $60,000 in rewards for successfully finding iOS 12.1 vulnerabilities
  9. #tRat: New modular #RAT appears in multiple email campaigns: http://ow.ly/1nsX50jHzgd via the Proofpoint @threatinsight research team.
  10. Cryptocurrency fraud is the exception, not the rule
  11. Nordstrom is notifying employees of a data breach that exposed their personal information, including names, Social Security numbers, dates of
  12. Facebook fixed a new security bug
  13. I forgot to follow up on this… According to Apple, the process could take up to 7 days. It

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. My Health Record extension highlights lingering security, privacy concerns
  2. Compromising vital infrastructure: air traffic control
  3. Suspected Russian cybercriminal arrested in Bulgaria at U.S. request, lawyer says
  4. Report: Microsoft’s enterprise products covertly gather personal data on users
  5. Chinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTs
  6. Cryptocurrency fraud is the exception, not the rule
  7. My Health Record remains opt-out as Senate passes privacy amendments
  8. Symantec Honored for its Collaboration With Leading Industry Group to Protect Against Business Email Compromise Scams

Nov 15, 2018

Sector brief for 2018-11-14

HEALTHCARE

  1. CVE-2018-15961: Adobe ColdFusion Flaw exploited in attacks in the wild
  2. Australian Senate extends My Health Record opt-out period
  3. Healthcare.gov Health Data Breach Exposes Personal Data
  4. Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware

TRANSPORT

  1. A 100k routers around the world are on the botnet to conduct emails spam

BANKING & FINANCE

  1. FlawedAmmy, the Only RAT in CheckPoint’s Global Threat Index 2018 List
  2. 1,000 Bitcoins Ransom Asked from Media Prima After Successful Ransomware Attack
  3. Weekly Threat Briefing: Adobe ColdFusion Servers Under Attack from APT Group
  4. Magecart Cybercrime Groups Harvest Payment Card Data
  5. How Threat Intelligence Prioritizes Risk in Vulnerability Management
  6. Monitoring file output for malicious code 'could have stopped BA attack more quickly'
  7. Operation FastCash
  8. Magecart- The Card-Skimming Group and Its Many Faces
  9. Infowars Store Affected by Magecart Credit Card Stealing Hack
  10. Alex Jones’ Infowars store was infected with credit card skimming software
  11. BDO Unibank Warned its Customers to Remain Beware from New Phishing Scheme
  12. Healthcare.gov Health Data Breach Exposes Personal Data
  13. Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware

INFORMATION & TELECOMMUNICATION

  1. Bitcoin Giveaway Scam Balloons, with Google the Latest Victim
  2. 1,000 Bitcoins Ransom Asked from Media Prima After Successful Ransomware Attack
  3. Weekly Threat Briefing: Adobe ColdFusion Servers Under Attack from APT Group
  4. Google services collapsed due to BGP leak
  5. Google services collapsed due to BGP leak
  6. Facebook vulnerability could have leaked your private information – again
  7. How Threat Intelligence Prioritizes Risk in Vulnerability Management
  8. Business Email Compromise - When You Don’t Need to Phish:
  9. Is it time to change your password? Check out this list of the 25 worst passwords for 2018 and make
  10. A Large Retailer Responds to #DDoS Extortion: To Pay or Not to Pay?
  11. Microsoft covertly collects personal data from enterprise Office ProPlus users
  12. Facebook reportedly fixes search bug that could have threatened user privacy
  13. Beers with Talos Ep. #41: Sex, money and malware
  14. A #bug allowing websites to capture private data from Facebook users through Chrome has been discovered:
  15. Cyber security is a process: Prevent, Detect, Respond, Predict. @5ean5ullivan @FSecure @ohjelmisto_ry
  16. Are you safe on social? "Countering the Social Hack" a 5-step process from ZF CEO @FirstNameFoster in @BRINKNewsNow
  17. Facebook flaw could have exposed private info of users and their friends
  18. Bitcoin fraud on the official Twitter account of Google GSuite
  19. Exploits confirmed! Congrats to F-Secure’s @MWRLabs team for another great #Pwn2Own performance. @thezdi
  20. BDO Unibank Warned its Customers to Remain Beware from New Phishing Scheme
  21. New Press Release: Team from @FSecure's @MWRLabs demos exploits for previously undisclosed vulnerabilities at Mobile #Pwn2Own competition -
  22. Facebook Patches Another Vulnerability That Exposed User’s Private Information
  23. A 100k routers around the world are on the botnet to conduct emails spam
  24. Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Did you by chance hack OPM back in 2015? Good news, your password probably still works!
  2. Weekly Threat Briefing: Adobe ColdFusion Servers Under Attack from APT Group
  3. Cyber espionage group used CVE-2018-8589 Windows Zero-Day in Middle East Attacks
  4. CVE-2018-15961: Adobe ColdFusion Flaw exploited in attacks in the wild
  5. CyberSecurity Asean security alert on A Vulnerability in Cisco Unity Express Could Allow for Arbitrary Code Execution
  6. Hunt finally submits to My Health Record arm-twists as opt-out window extended
  7. Healthcare.gov Health Data Breach Exposes Personal Data
  8. Senate votes to extend My Health Record opt-out to January 31

Sector brief for 2018-11-13

HEALTHCARE

  1. Premier Media Conglomerate of Malaysia, Falls for Ransomware Infection
  2. The Cybersecurity Tech Accord endorses the Paris Call
  3. Former Employee Accessed Medical Records For Nearly a Year
  4. Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
  5. What’s on Our Minds for 2019? Key Themes from the RSA Speaker Selection Process

TRANSPORT

  1. Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
  2. What’s on Our Minds for 2019? Key Themes from the RSA Speaker Selection Process

BANKING & FINANCE

  1. Fake Crypto Wallet Apps Discovered in Google Play, Built Using Drag-n-Drop
  2. Premier Media Conglomerate of Malaysia, Falls for Ransomware Infection
  3. The Cybersecurity Tech Accord endorses the Paris Call
  4. Magecart Cybercrime Groups Mass Harvest Payment Card Data
  5. Seven Hacking Groups Operate Under “Magecart” Umbrella, Analysis Shows
  6. That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards
  7. Nordstrom Quick to Tell Employees of a Data Breach
  8. Inside Magecart: RiskIQ and Flashpoint Release Comprehensive Report on the Assault on E-Commerce
  9. ‘Inside Magecart’ Exposes the Operation Behind the Web’s Biggest E-Commerce Scourge
  10. The Tactic Cybercriminals Use to Steal Bitcoin
  11. Beware !! Worlds Most Active Malware Emotet Launching New Campaign With Malicious Word and PDF Attachments
  12. Compromised security in millions of cards in the US

INFORMATION & TELECOMMUNICATION

  1. Fixed Facebook Privacy Bug Could Have Allowed Bad Actors to Steal Personal Info
  2. Facebook flaw opened your profile to data thieves
  3. Facebook Patches Another User Data Harvesting Bug
  4. That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards
  5. Nordstrom Quick to Tell Employees of a Data Breach
  6. Facebook Bug Let Websites Access Private User Data
  7. Target and other high profile Twitter accounts exploited for cryptocurrency scams
  8. The Ontario Cannabis Store has reported a data breach that took place Nov. 1 through the Canada Post and affected
  9. Facebook patches another bug that could have allowed mass-harvesting of user data
  10. Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
  11. It’s Amateur Hour in the World of Spyware and Victims Will Pay the Price
  12. Microsoft Patch Tuesday — November 2018: Vulnerability disclosures and Snort coverage
  13. Another Facebook Bug Could Have Exposed Your Private Information
  14. #Gallmaker eschews custom malware, uses living off the land and publicly available #hack tools. Find out more:
  15. Attacker hijacks Elon Musk Twitter account to implement fake bitcoin fraud
  16. Google Services down due to BGP leak, traffic hijacked through Russia, China, and Nigeria
  17. To help you rule out the worst password ideas, FrontNet has put together a list of the 25 words passwords
  18. WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
  19. WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
  20. Illegal cryptocurrency mining
  21. Leak: Windows 10 October Update will be re-launched tomorrow
  22. Twitter grapples with fake Elon Musk accounts promoting bitcoin scams

FOOD

Nil

WATER

  1. That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards

ENERGY

  1. Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
  2. WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
  3. WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
  4. Illegal cryptocurrency mining

GOVERNMENT & PUBLIC SERVICE

  1. Scare Force: Pakistan military hit by Operation Shaheen malware
  2. Pakistan Military Hit By Operation Shaheen Malware
  3. Sophisticated cyber-espionage campaign targeting Pakistani government and air force
  4. Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
  5. It’s Amateur Hour in the World of Spyware and Victims Will Pay the Price
  6. Using Machine Learning to Cluster Malicious Network Flows From Gh0st RAT Variants
  7. WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency
  8. WebCobra Malware Uses Victims’ Computers to Mine Cryptocurrency