Sep 22, 2018

Sector brief for 2018-09-21

HEALTHCARE

Nothing to report

TRANSPORT

  1. The Week in Ransomware – September 21st 2018 – Beer, Airports, & Dharma
  2. The Week in Ransomware - September 21st 2018 - Beer, Airports, & Dharma

BANKING & FINANCE

  1. Spam or Phish? How to Tell the Difference Between a Marketing Email and a Malicious Spam Email
  2. Phishing finance apps make way back into Google Play
  3. Newegg leaked credit card information for more than a month
  4. Sealed with an XSS: IT pros urge Lloyds Group to avoid web cross talk
  5. What's that smell? Oh, it's Newegg cracked open by card slurpers
  6. Solid password practice on Capital One's site? Don't bank on it
  7. Card-stealing code that pwned British Airways, Ticketmaster pops up on more sites via hacked JS
  8. Law firm seeking leak victims to launch £500m suit at British Airways
  9. 'Magecart' Card-Sniffing Gang Cracks Newegg
  10. FDIC: Supervisory Approach to Payment Processing Relationships with Merchant Customers
  11. MassMiner Malware Targeting Web Servers
  12. Malware Analysis using Osquery Part 2
  13. Malware Analysis using Osquery Part 1
  14. Malicious Documents from Lazarus Group Targeting South Korea
  15. ICO Slaps Equifax with Maximum Fine for the 2017 Data Breach
  16. MageCart Hacked Customers’ In NewEgg Credit Card Data Breach
  17. £500k fine for Equifax 2017 data breach

INFORMATION & TELECOMMUNICATION

  1. Patch for EE's 4G Wi-Fi mini modem nails local privilege escalation flaw

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

  1. Off-the-shelf RATs Targeting Pakistan

PUBLIC SERVICE

Nothing to report

Daily brief for 2018-09-21

ASIA

  1. Off-the-shelf RATs Targeting Pakistan
  2. Malicious Documents from Lazarus Group Targeting South Korea
  3. GZipDe: An Encrypted Downloader Serving Metasploit
  4. More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
  5. The most dangerous mobile spyware, Pegasus that has infected 45 countries
  6. Singapore to offer bug bounty, set up Asean cybersecurity centre

WORLD

  1. Operator of 'VirusTotal for criminals' gets 14-year prison sentence
  2. Newegg leaked credit card information for more than a month
  3. Fully 61 percent of ASX100 exposed as email fraud gets personal
  4. Virobot Ransomware with Botnet Capability Breaks Through
  5. DMARC Fully Implemented on Two Thirds of U.S. Government Domains
  6. Guilty: The Romanian ransomware mastermind who infected Trump inauguration CCTV cams
  7. What's that smell? Oh, it's Newegg cracked open by card slurpers
  8. Who ate all the PII? Not the blockchain, thankfully
  9. Card-stealing code that pwned British Airways, Ticketmaster pops up on more sites via hacked JS
  10. Law firm seeking leak victims to launch £500m suit at British Airways
  11. 'Magecart' Card-Sniffing Gang Cracks Newegg
  12. MassMiner Malware Targeting Web Servers
  13. Malware Analysis using Osquery Part 1
  14. The most dangerous mobile spyware, Pegasus that has infected 45 countries
  15. #SecurityNews: The Information Commissioner’s Office (ICO) has fined #Equifax £500K after the 2017 #databreach. For the 2nd time the #ICO has issued a max fine after the credit agency exposed data on 15 million UK customers. Read more here:   #
  16. CVE-2018-14829: Rockwell Automation Stack Overflow High Risk Vulnerability
  17. ICO Slaps Equifax with Maximum Fine for the 2017 Data Breach
  18. Magecart’s Next Attack Resulted In ABS-CBN Data Breach
  19. The most used email subjects used in phishing attacks
  20. £500k fine for Equifax 2017 data breach

ATTACKS

  1. What Are Honeywords? Password Protection for Database Breaches
  2. Snap! Microsoft database flaw, internet to split? Plus, asteroid probed
  3. Spam or Phish? How to Tell the Difference Between a Marketing Email and a Malicious Spam Email
  4. Twitter Flaw Exposed Direct Messages To External Developers
  5. Twitter Flaw Exposed Direct Messages To External Developers
  6. Phishing finance apps make way back into Google Play
  7. Twitter API bug leaked private data to other accounts
  8. The @aberdeengroup analyzed the likelihood and business impact of #phishing attacks based on lost productivity of 1,000 users with a confirmed #databreach of between 100k - 1m records, for 10 different industries. Download the @cyreninc #whitepaper here
  9. Independence Blue Cross Breach Exposed 17K Records
  10. Independence Blue Cross Breach Exposed 17K Records  …
  11. New Virobot Ransomware and Botnet Emerges
  12. Newegg leaked credit card information for more than a month
  13. ZDI Shares Details of Microsoft JET Database Zero-Day
  14. New Virobot ransomware will also log keystrokes, add PC to a spam botnet
  15. Fully 61 percent of ASX100 exposed as email fraud gets personal
  16. Pegasus spyware spotted in 45 countries, many with questionable human rights records
  17. ICO to Fine Equifax £500,000 for 2017 Data Breach   via @DMBisson #GDPR #databreach
  18. Adams County clerk resigns over role in data breach
  19. This blog post explores how #malvertising works and identifies key defense strategies for #businesses  … #malware #cyberattacks
  20. SC Media September Product Reviews: Threat Intelligence Recorded Future l
  21. Apache Struts and SonicWall Targeted by Mirai and Gafgyt Botnets
  22. Virobot Ransomware with Botnet Capability Breaks Through
  23. 0Day Windows JET Database Vulnerability disclosed by Zero Day Initiative
  24. Securing industrial IoT passwords: For Pete's sake, engineers, don't all jump in at once
  25. No, the Mirai botnet masters aren't going to jail. Why? 'Cos they help Feds nab cyber-crims
  26. Who ate all the PII? Not the blockchain, thankfully
  27. Tick-tock, tick-tock. Oh, that's just the sound of compromised logins waiting to ruin your day
  28. Equifax IT staff had to rerun hackers' database queries to work out what was nicked – audit
  29. Veeam holds its hands up, admits database leak was plain 'complacency'
  30. Solid password practice on Capital One's site? Don't bank on it
  31. Back up a minute: Veeam database config snafu exposed millions of customer records
  32. When is a patch not a patch? When it's for this McAfee password bug
  33. Law firm seeking leak victims to launch £500m suit at British Airways
  34. ZombieBoy
  35. Warning issued as Netflix subscribers hit by phishing attack
  36. The makers of the Mirai IoT-hijacking botnet are sentenced   via @gcluley #DDoS #FBI
  37. #SecurityNews: The Information Commissioner’s Office (ICO) has fined #Equifax £500K after the 2017 #databreach. For the 2nd time the #ICO has issued a max fine after the credit agency exposed data on 15 million UK customers. Read more here:   #
  38. SingHealth data breach reveals several 'inadequate' security measures
  39. Cisco releases fixes for remote code execution flaws in Webex Network Recording Player
  40. Mirai Botnet Creators To Help Law Enforcement Agencies On Cybercrime Investigations
  41. ICO Slaps Equifax with Maximum Fine for the 2017 Data Breach
  42. Cisco fixes Remote Code Execution flaws in Webex Network Recording Player
  43. MageCart Hacked Customers’ In NewEgg Credit Card Data Breach
  44. ZDI Exposed Unpatched Microsoft RCE Zero-day Flaw in Public After it Crossed the 120 Days Deadline
  45. Security data reveals worldwide malicious login attempts are on the rise
  46. AD FS 2016 Password Change from non workplace joined devices
  47. ICO to Fine Equifax £500,000 for 2017 Data Breach   via @DMBisson #databreach #GDPR
  48. Magecart’s Next Attack Resulted In ABS-CBN Data Breach
  49. The most used email subjects used in phishing attacks
  50. £500k fine for Equifax 2017 data breach
  51. AdGuard resets all user passwords after credential stuffing attack
  52. The makers of the Mirai IoT-hijacking botnet are sentenced   via @gcluley #botnets #Mirai

THREATS

  1. Brewery breach: Not even beer is safe from ransomware
  2. Western Digital Releases Hotfix for My Cloud Auth Bypass Vulnerability
  3. The Week in Ransomware – September 21st 2018 – Beer, Airports, & Dharma
  4. PMP®️ Domain Information & Overview
  5. Critical Vulnerability Found in Cisco Video Surveillance Manager
  6. Critical Vulnerability Found in Cisco Video Surveillance Manager
  7. Expert disclosed an unpatched zero-day flaw in all supported versions of Microsoft Windows
  8. Gamma, Bkp, & Monro Dharma Ransomware Variants Released in One Week
  9. Snap! Microsoft database flaw, internet to split? Plus, asteroid probed
  10. Bug allowing unlimited spiceups in "Answer Question" section
  11. Optional Cumulative Update KB4457139 for Windows 7 Released With Bug Fixes
  12. Spam or Phish? How to Tell the Difference Between a Marketing Email and a Malicious Spam Email
  13. Romanian Citizen Admits Guilt in Police Department Ransomware Attack   via @DMBisson #police #ransomware
  14. Twitter Flaw Exposed Direct Messages To External Developers
  15. Malware Disguised as Job Offers Distributed on Freelance Sites
  16. Twitter Flaw Exposed Direct Messages To External Developers
  17. Romanian Hacker Pleads Guilty for Role in Inauguration Surveillance Ransomware
  18. Proofpoint: One month out from deadline, half of agency domains are #DMARC compliant   via CyberScoopNews #FinSec
  19. Twitter API bug leaked private data to other accounts
  20. Delphi Packer Looks for Human Behavior Before Deploying Payload
  21. Delphi Packer Looks for Human Behavior Before Deploying Payload
  22. Western Digital Releases Hotfix for My Cloud Auth Bypass Vulnerability
  23. Twitter notifies users about API bug that shared DMs with wrong devs
  24. The Week in Ransomware - September 21st 2018 - Beer, Airports, & Dharma
  25. Operator of 'VirusTotal for criminals' gets 14-year prison sentence
  26. Gamma, Bkp, & Monro Dharma Ransomware Variants Released in One Week
  27. New Virobot Ransomware and Botnet Emerges
  28. Optional Cumulative Update KB4457139 for Windows 7 Released With Bug Fixes
  29. Staying King Krab: GandCrab Malware Keeps a Step Ahead of Network Defenses
  30. Malware Disguised as Job Offers Distributed on Freelance Sites
  31. ZDI Shares Details of Microsoft JET Database Zero-Day
  32. New Virobot ransomware will also log keystrokes, add PC to a spam botnet
  33. Security news: All-in-one malware out, GovPayNow drops the ball on security, and Newegg suffers a crack | Avast
  34. Romanian Hacker Pleads Guilty for Role in Inauguration Surveillance Ransomware
  35. Flaw in Western Digital My Cloud exposes the content to hackers
  36. Twitter Bug May Have Sent your Direct Messages to Twitter Developers As Well
  37. Unpatched Microsoft Zero-Day in JET Allows Remote Code-Execution
  38. Pegasus spyware spotted in 45 countries, many with questionable human rights records
  39. Discover how Tripwire Malware Detection... - Protects against zero-day exploits and other known threats. - Offers an enterprise view of suspicious malware objects across all monitored systems. - Protects from repeat #malware attacks. Learn more here:
  40. Legitimate RATs Pose Serious Risk to Industrial Systems
  41. Crooks turn to Delphi packers to evade malware detection
  42. This blog post explores how #malvertising works and identifies key defense strategies for #businesses  … #malware #cyberattacks
  43. Malware Businesses Blending the Legitimate and the Illegitimate
  44. Bitcoin flaw could have allowed dreaded 51% takeover
  45. Avoidable mistakes lead to iOS cryptomining attacks
  46. Romanian Citizen Admits Guilt in Police Department Ransomware Attack   via @DMBisson #ransomware #police
  47. Thousands of WordPress sites backdoored with malicious code
  48. Virobot Ransomware with Botnet Capability Breaks Through
  49. DMARC Fully Implemented on Two Thirds of U.S. Government Domains
  50. 0Day Windows JET Database Vulnerability disclosed by Zero Day Initiative
  51. Guilty: The Romanian ransomware mastermind who infected Trump inauguration CCTV cams
  52. Microsoft's Jet crash: Zero-day flaw drops after deadline passes
  53. Sealed with an XSS: IT pros urge Lloyds Group to avoid web cross talk
  54. Patch for EE's 4G Wi-Fi mini modem nails local privilege escalation flaw
  55. 'I am admin' bug turns WD's My Cloud boxes into Everyone's Cloud
  56. Docker fave Alpine Linux suffers bug miscreants can exploit to poison containers
  57. When is a patch not a patch? When it's for this McAfee password bug
  58. New Hacker Exploits and How to Fight Them
  59. FDIC: Supervisory Approach to Payment Processing Relationships with Merchant Customers
  60. MassMiner Malware Targeting Web Servers
  61. Malware Analysis using Osquery Part 2
  62. Off-the-shelf RATs Targeting Pakistan
  63. Malware Analysis using Osquery Part 1
  64. Malicious Documents from Lazarus Group Targeting South Korea
  65. GZipDe: An Encrypted Downloader Serving Metasploit
  66. More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
  67. Satan Ransomware Spawns New Methods to Spread
  68. Woman Pleads Guilty to DC CCTV Ransomware Blitz
  69. Woman Pleads Guilty to DC CCTV Ransomware Blitz  …
  70. Report: Cryptomining malware detections up more than 459 percent since 2017
  71. Researcher Discloses New Zero-Day Affecting All Versions of Windows
  72. The most dangerous mobile spyware, Pegasus that has infected 45 countries
  73. Rockwell Automation Patches Severe Flaws in Communications Software
  74. Cisco releases fixes for remote code execution flaws in Webex Network Recording Player
  75. Google Cloud Service launches automatic scanning of container vulnerabilities to enhance cloud environment security
  76. CVE-2018-14829: Rockwell Automation Stack Overflow High Risk Vulnerability
  77. Adobe Addresses a Number of Critical Remote Execution Vulnerabilities
  78. Trend Micro Zero Day team discloses unpatched Microsoft Jet RCE vulnerability
  79. Singapore to offer bug bounty, set up Asean cybersecurity centre
  80. Cisco fixes Remote Code Execution flaws in Webex Network Recording Player
  81. ZDI Exposed Unpatched Microsoft RCE Zero-day Flaw in Public After it Crossed the 120 Days Deadline
  82. Security data reveals worldwide malicious login attempts are on the rise
  83. Why voice fraud rates continue to rise with no signs of slowing down
  84. iOS Webkit flaw found that forces iPhone restart
  85. Flaw in 4GEE WiFi Modem Could Leave Your Computer Vulnerable
  86. Authentication Bypass Vulnerability Disclosed in Western Digital My Cloud NAS Devices

CRIME

  1. Spam or Phish? How to Tell the Difference Between a Marketing Email and a Malicious Spam Email
  2. Romanian Hacker Pleads Guilty for Role in Inauguration Surveillance Ransomware
  3. Operator of 'VirusTotal for criminals' gets 14-year prison sentence
  4. Newegg leaked credit card information for more than a month
  5. Fully 61 percent of ASX100 exposed as email fraud gets personal
  6. Romanian Hacker Pleads Guilty for Role in Inauguration Surveillance Ransomware
  7. Bitcoin flaw could have allowed dreaded 51% takeover
  8. Avoidable mistakes lead to iOS cryptomining attacks
  9. Guilty: The Romanian ransomware mastermind who infected Trump inauguration CCTV cams
  10. Sealed with an XSS: IT pros urge Lloyds Group to avoid web cross talk
  11. What's that smell? Oh, it's Newegg cracked open by card slurpers
  12. Solid password practice on Capital One's site? Don't bank on it
  13. Card-stealing code that pwned British Airways, Ticketmaster pops up on more sites via hacked JS
  14. Law firm seeking leak victims to launch £500m suit at British Airways
  15. 'Magecart' Card-Sniffing Gang Cracks Newegg
  16. FDIC: Supervisory Approach to Payment Processing Relationships with Merchant Customers
  17. MassMiner Malware Targeting Web Servers
  18. Malware Analysis using Osquery Part 2
  19. Malware Analysis using Osquery Part 1
  20. ZombieBoy
  21. Malicious Documents from Lazarus Group Targeting South Korea
  22. Woman Pleads Guilty to DC CCTV Ransomware Blitz
  23. Woman Pleads Guilty to DC CCTV Ransomware Blitz  …
  24. Report: Cryptomining malware detections up more than 459 percent since 2017
  25. The makers of the Mirai IoT-hijacking botnet are sentenced   via @gcluley #DDoS #FBI
  26. Mirai Botnet Creators To Help Law Enforcement Agencies On Cybercrime Investigations
  27. MageCart Hacked Customers’ In NewEgg Credit Card Data Breach
  28. The makers of the Mirai IoT-hijacking botnet are sentenced   via @gcluley #botnets #Mirai

POLITICS

Nothing to report

Sep 21, 2018

Threat report for 2018-09-20

DATA BREACH

  1. 14 million customer records exposed in GovPayNow leak
  2. State Department email breach leaks employee PII
  3. Magecart data breach possibly avoidable -magecart-data-breach-possibly-avoidable/ …
  4. Adams County clerk resigns over role in data breach
  5. ICO to Fine Equifax £500,000 for 2017 Data Breach   via
  6. Pegasus spyware spotted in 45 countries, many with questionable human rights records
  7. State Department: Some Employee Info Possibly Exposed in Security Incident   via
  8. This breach is a great example of how CT logs can be useful as an early indicator of an ongoing attack campaign. Orgs should be monitoring CT for certificates issued to look-alike domains to improve their situational awareness. -magazine.com/news/magecart-skimmed-newegg-cards/ …
  9. Data commissioner fines Equifax £500,000 for US data breach affecting UK customers
  10. Newegg Electronic Retailers Suffered a Data Breach and Hackers Stole Customers Credit Card Data
  11. LG V40 ThinQ Alleged Specifications Sheet Leaked; Reveals 8GB RAM Model With a 6.4-Inch Display, but No Triple-Rear-Camera
  12. ICO to Fine Equifax £500,000 for 2017 Data Breach   via
  13. UK organisations’ email accounts used in mass phishing campaigns
  14. Threat Spotlight: Barracuda study finds account takeover incidents widespread, most commonly used for phishing campaigns
  15. 7GB of Medical Data Publicly Exposed Thanks to Misconfigured AWS S3 Bucket
  16. The public's trust, politics and race, and dignity for the LGBT community: MP Murali Pillai goes On the Record
  17. US State Department confirms data breach to unclassified email system
  18. Researcher discovers buffer overflow vulnerability in Microsoft's JET Database Engine
  19. HMRC Tax Refund Scam via Phishing Campaign
  20. China Arrests Suspect for Customer Data Leak at Accor Partner
  21. State Department Email Breach Exposed Personal Data Of Employees
  22. Equifax fined £500,000 over customer data breach
  23. Privacy advocates have failed to engage on My Health Record
  24. UK Regulator Fines Equifax £500,000 Over 2017 Data Breach
  25. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  26. State Department: Some Employee Info Possibly Exposed in Security Incident   via

DENIAL-OF-SERVICE

  1. Snap! Adobe patches, sneaky Android botnets, Alexa invasion, robot skins
  2. The makers of the Mirai IoT-hijacking botnet are sentenced   via
  3. 3 Drivers Behind the Increasing Frequency of DDoS Attacks
  4. New XBash malware combines features from ransomware, cryptocurrency miners, botnets, and worms
  5. : The 3 people suspected of the have escaped jail after agreeing to provide “substantial assistance” to the in ongoing cases. Read more about this story here:   .twitter.com/Yzb9wM7KzU
  6. 3 Drivers Behind the Increasing Frequency of DDoS Attacks
  7. This Russian botnet mimics your click to prevent Android device factory resets
  8. FBI wants to keep “helpful” Mirai botnet authors around
  9. The makers of the Mirai IoT-hijacking botnet are sentenced   via
  10. Mirai botnet developers collaborate with the FBI
  11. Identifying botnets before an attack: The new DARPA challenge
  12. US Signal partners with Cloudflare to deliver DDoS protection service

MALVERTISING

Nothing to report

DATA LEAK

  1. Hackers Uploaded Fake Apps into Google Play Store to Steal Credit card details and Login Credentials

PHISHING

  1. Account Takeover Attacks Become a Phishing Fave
  2. Account Takeover Attacks Result in Phishing Scams  pic.twitter.com/hR2kSqlpCN
  3. Malicious Login Attempts Spike in Finance, Retail  pic.twitter.com/OQPWqymDRB
  4. Account Takeover Attacks Result in Phishing Scams -magazine.com/news/account-takeover-attacks-result-in?utm_source=twitterfeed&utm_medium=twitter …
  5. Malicious Login Attempts Spike in Finance, Retail -magazine.com/news/malicious-login-attempts-spike-in?utm_source=twitterfeed&utm_medium=twitter …
  6. Account Takeover Attacks Become a Phishing Fave
  7. : malware detections have soared 273% since 2017 according to new stats from . The most popular way to spread is brute-forcing of passwords, used in 93% of detected attacks. Read more here:   .twitter.com/Ct8Z7qckRC
  8. UK organisations’ email accounts used in mass phishing campaigns
  9. Threat Spotlight: Barracuda study finds account takeover incidents widespread, most commonly used for phishing campaigns
  10. Hackers Uploaded Fake Apps into Google Play Store to Steal Credit card details and Login Credentials
  11. HMRC Tax Refund Scam via Phishing Campaign
  12. Phishing finance apps make way back into Google Play
  13. Manipulation tactics that you fall for in phishing attacks

WEB DEFACEMENT

Nothing to report

MALWARE

  1. US authorities Have Pardoned Authors of Mirai Ransomware in Return For Government “Cooperation”
  2. Domain Joined Outlook 2016 Issues - 0x8004011D
  3. Report: Cryptomining malware detections up more than 459 percent since 2017
  4. Bad actors are sizing up systems via lightweight recon before attack, researchers at Proofpoint said:
  5. The rate at which new threats appear now requires a much greater reliance on threat intelligence. Learn more about its opportunities and challenges in our .  pic.twitter.com/bEh9MKP6nS
  6. Malicious Login Attempts Spike in Finance, Retail  pic.twitter.com/OQPWqymDRB
  7. Malicious Login Attempts Spike in Finance, Retail -magazine.com/news/malicious-login-attempts-spike-in?utm_source=twitterfeed&utm_medium=twitter …
  8. New XBash malware combines features from ransomware, cryptocurrency miners, botnets, and worms
  9. Pegasus spyware spotted in 45 countries, many with questionable human rights records
  10. Book Review: Malware Data Science
  11. Increased Use of a Delphi Packer to Evade Malware Classification
  12. Hundreds of Indian Government Websites Hit with Cryptojacking Malware
  13. This breach is a great example of how CT logs can be useful as an early indicator of an ongoing attack campaign. Orgs should be monitoring CT for certificates issued to look-alike domains to improve their situational awareness. -magazine.com/news/magecart-skimmed-newegg-cards/ …
  14. Mitigate Risk From Malicious and Accidental Insiders
  15. : malware detections have soared 273% since 2017 according to new stats from . The most popular way to spread is brute-forcing of passwords, used in 93% of detected attacks. Read more here:   .twitter.com/Ct8Z7qckRC
  16. Sustes Malware: CPU for Monero
  17. Report: Cryptomining malware detections up more than 459 percent since 2017
  18. Threats posed by using RATs in ICS
  19. Report Reveals Widespread Use of Pegasus Spyware
  20. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  21. Evil Clone Attack – Hackers Injecting Crypto-mining Malware into Legitimate PDF Software
  22. Newegg hacked: The new victim of Magecart malware
  23. How to detect and remove a virus from your Android phone | Avast

EXPLOIT

  1. : Hackers say and have been the easiest attack vectors to exploit this year. 56% of said that social engineering is the fastest account seizing technique to use on them. Read more here:   .twitter.com/e5ogD8VYWT
  2. Researcher discovers buffer overflow vulnerability in Microsoft's JET Database Engine

VULNERABILITY

  1. Android bug bounty tops $3m in third year, but pay flattens out
  2. Facebook Bug Bounty opens to reward access token exposure
  3. Bug hunters fail third year in a row to get top prize in Android hacking program
  4. Cisco Issues New Warning for 6-Month-Old Critical Bug in IOS XE
  5. Guarding the Gate: Cybersecurity De-Mystified
  6. Researcher discovers buffer overflow vulnerability in Microsoft's JET Database Engine
  7. Interview with Daniel Stenberg: His thoughts on the Curl Bug Bounty Program
  8. Western Digital goes quiet on unpatched MyCloud flaw
  9. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability
  10. Adobe releases patch out of schedule to squash critical code execution bug
  11. Cisco IOS XE Software Static Credential Vulnerability
  12. Adobe issued a critical out-of-band patch to address CVE-2018-12848 Acrobat flaw
  13. Ubuntu Released Security Updates & Fixed Multiple Critical Vulnerabilities
  14. Vulnerability in My cloud devices exposes sensitive information
  15. Western Digital My Cloud vulnerability, let’s hacker gives full access
  16. Guarding the Gate: Cybersecurity De-Mystified

Region brief for 2018-09-20

ASIA

  1. Hundreds of Indian Government Websites Hit with Cryptojacking Malware
  2. The public's trust, politics and race, and dignity for the LGBT community: MP Murali Pillai goes On the Record
  3. China Arrests Suspect for Customer Data Leak at Accor Partner

OCEANIA

  1. Privacy advocates have failed to engage on My Health Record

NORTH AMERICA

  1. A worrying future for the next generation?
  2. US authorities Have Pardoned Authors of Mirai Ransomware in Return For Government “Cooperation”
  3. Book Review: Malware Data Science
  4. Wyden: Tech company has told multiple senators of foreign hacking attempts
  5. Data commissioner fines Equifax £500,000 for US data breach affecting UK customers
  6. LG V40 ThinQ Alleged Specifications Sheet Leaked; Reveals 8GB RAM Model With a 6.4-Inch Display, but No Triple-Rear-Camera
  7. 7GB of Medical Data Publicly Exposed Thanks to Misconfigured AWS S3 Bucket
  8. US State Department confirms data breach to unclassified email system
  9. Threats posed by using RATs in ICS
  10. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  11. Card Data-Scraping Magecart Code Found on Newegg
  12. Mirai botnet developers collaborate with the FBI
  13. US Signal partners with Cloudflare to deliver DDoS protection service

SOUTH AMERICA

Nothing to report

EUROPE

  1. New Magecart victims ABS-CBN and Newegg are just the tip of the iceberg
  2. Magecart Strikes Again, Siphoning Payment Info from Newegg
  3. Wyden: Tech company has told multiple senators of foreign hacking attempts
  4. Data commissioner fines Equifax £500,000 for US data breach affecting UK customers
  5. UK organisations’ email accounts used in mass phishing campaigns
  6. Newegg Inc. Suffers Hack, Credit Card Data Stolen
  7. This Russian botnet mimics your click to prevent Android device factory resets
  8. HMRC Tax Refund Scam via Phishing Campaign
  9. NewEgg Network is attacked by hackers
  10. UK Regulator Fines Equifax £500,000 Over 2017 Data Breach
  11. Magecart cybercrime group stole customers’ credit cards from Newegg electronics retailer
  12. Latest Hacking News Podcast
  13. Newegg hacked: The new victim of Magecart malware
  14. Western Digital My Cloud vulnerability, let’s hacker gives full access

AFRICA

Nothing to report

Sector brief for 2018-09-20

HEALTHCARE

  1. 7GB of Medical Data Publicly Exposed Thanks to Misconfigured AWS S3 Bucket

TRANSPORT

  1. US Signal partners with Cloudflare to deliver DDoS protection service

BANKING & FINANCE

  1. Malicious Login Attempts Spike in Finance, Retail  pic.twitter.com/OQPWqymDRB
  2. Malicious Login Attempts Spike in Finance, Retail -magazine.com/news/malicious-login-attempts-spike-in?utm_source=twitterfeed&utm_medium=twitter …
  3. New Magecart victims ABS-CBN and Newegg are just the tip of the iceberg
  4. Magecart Strikes Again, Siphoning Payment Info from Newegg
  5. Newegg Electronic Retailers Suffered a Data Breach and Hackers Stole Customers Credit Card Data
  6. Newegg Inc. Suffers Hack, Credit Card Data Stolen
  7. Hackers Uploaded Fake Apps into Google Play Store to Steal Credit card details and Login Credentials
  8. HMRC Tax Refund Scam via Phishing Campaign
  9. Phishing finance apps make way back into Google Play
  10. NewEgg Network is attacked by hackers
  11. UK Regulator Fines Equifax £500,000 Over 2017 Data Breach
  12. Magecart cybercrime group stole customers’ credit cards from Newegg electronics retailer
  13. Manipulation tactics that you fall for in phishing attacks
  14. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  15. Card Data-Scraping Magecart Code Found on Newegg

INFORMATION & TELECOMMUNICATION

Nothing to report

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

Nothing to report

PUBLIC SERVICE

  1. Wyden: Tech company has told multiple senators of foreign hacking attempts

Daily brief for 2018-09-20

ASIA

  1. Hundreds of Indian Government Websites Hit with Cryptojacking Malware
  2. The public's trust, politics and race, and dignity for the LGBT community: MP Murali Pillai goes On the Record
  3. China Arrests Suspect for Customer Data Leak at Accor Partner

WORLD

  1. A worrying future for the next generation?
  2. US authorities Have Pardoned Authors of Mirai Ransomware in Return For Government “Cooperation”
  3. Book Review: Malware Data Science
  4. New Magecart victims ABS-CBN and Newegg are just the tip of the iceberg
  5. Magecart Strikes Again, Siphoning Payment Info from Newegg
  6. Wyden: Tech company has told multiple senators of foreign hacking attempts
  7. Data commissioner fines Equifax £500,000 for US data breach affecting UK customers
  8. LG V40 ThinQ Alleged Specifications Sheet Leaked; Reveals 8GB RAM Model With a 6.4-Inch Display, but No Triple-Rear-Camera
  9. UK organisations’ email accounts used in mass phishing campaigns
  10. Newegg Inc. Suffers Hack, Credit Card Data Stolen
  11. This Russian botnet mimics your click to prevent Android device factory resets
  12. 7GB of Medical Data Publicly Exposed Thanks to Misconfigured AWS S3 Bucket
  13. US State Department confirms data breach to unclassified email system
  14. HMRC Tax Refund Scam via Phishing Campaign
  15. Threats posed by using RATs in ICS
  16. NewEgg Network is attacked by hackers
  17. Privacy advocates have failed to engage on My Health Record
  18. UK Regulator Fines Equifax £500,000 Over 2017 Data Breach
  19. Magecart cybercrime group stole customers’ credit cards from Newegg electronics retailer
  20. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  21. Latest Hacking News Podcast
  22. Card Data-Scraping Magecart Code Found on Newegg
  23. Newegg hacked: The new victim of Magecart malware
  24. Mirai botnet developers collaborate with the FBI
  25. Western Digital My Cloud vulnerability, let’s hacker gives full access
  26. US Signal partners with Cloudflare to deliver DDoS protection service

ATTACKS

  1. 14 million customer records exposed in GovPayNow leak
  2. State Department email breach leaks employee PII
  3. Magecart data breach possibly avoidable -magecart-data-breach-possibly-avoidable/ …
  4. Adams County clerk resigns over role in data breach
  5. Snap! Adobe patches, sneaky Android botnets, Alexa invasion, robot skins
  6. Account Takeover Attacks Become a Phishing Fave
  7. ICO to Fine Equifax £500,000 for 2017 Data Breach   via
  8. Account Takeover Attacks Result in Phishing Scams  pic.twitter.com/hR2kSqlpCN
  9. Malicious Login Attempts Spike in Finance, Retail  pic.twitter.com/OQPWqymDRB
  10. Account Takeover Attacks Result in Phishing Scams -magazine.com/news/account-takeover-attacks-result-in?utm_source=twitterfeed&utm_medium=twitter …
  11. Malicious Login Attempts Spike in Finance, Retail -magazine.com/news/malicious-login-attempts-spike-in?utm_source=twitterfeed&utm_medium=twitter …
  12. The makers of the Mirai IoT-hijacking botnet are sentenced   via
  13. 3 Drivers Behind the Increasing Frequency of DDoS Attacks
  14. New XBash malware combines features from ransomware, cryptocurrency miners, botnets, and worms
  15. Pegasus spyware spotted in 45 countries, many with questionable human rights records
  16. Account Takeover Attacks Become a Phishing Fave
  17. : The 3 people suspected of the have escaped jail after agreeing to provide “substantial assistance” to the in ongoing cases. Read more about this story here:   .twitter.com/Yzb9wM7KzU
  18. State Department: Some Employee Info Possibly Exposed in Security Incident   via
  19. This breach is a great example of how CT logs can be useful as an early indicator of an ongoing attack campaign. Orgs should be monitoring CT for certificates issued to look-alike domains to improve their situational awareness. -magazine.com/news/magecart-skimmed-newegg-cards/ …
  20. 3 Drivers Behind the Increasing Frequency of DDoS Attacks
  21. Data commissioner fines Equifax £500,000 for US data breach affecting UK customers
  22. Newegg Electronic Retailers Suffered a Data Breach and Hackers Stole Customers Credit Card Data
  23. LG V40 ThinQ Alleged Specifications Sheet Leaked; Reveals 8GB RAM Model With a 6.4-Inch Display, but No Triple-Rear-Camera
  24. : malware detections have soared 273% since 2017 according to new stats from . The most popular way to spread is brute-forcing of passwords, used in 93% of detected attacks. Read more here:   .twitter.com/Ct8Z7qckRC
  25. ICO to Fine Equifax £500,000 for 2017 Data Breach   via
  26. UK organisations’ email accounts used in mass phishing campaigns
  27. Threat Spotlight: Barracuda study finds account takeover incidents widespread, most commonly used for phishing campaigns
  28. Hackers Uploaded Fake Apps into Google Play Store to Steal Credit card details and Login Credentials
  29. This Russian botnet mimics your click to prevent Android device factory resets
  30. 7GB of Medical Data Publicly Exposed Thanks to Misconfigured AWS S3 Bucket
  31. The public's trust, politics and race, and dignity for the LGBT community: MP Murali Pillai goes On the Record
  32. FBI wants to keep “helpful” Mirai botnet authors around
  33. US State Department confirms data breach to unclassified email system
  34. Researcher discovers buffer overflow vulnerability in Microsoft's JET Database Engine
  35. HMRC Tax Refund Scam via Phishing Campaign
  36. China Arrests Suspect for Customer Data Leak at Accor Partner
  37. Phishing finance apps make way back into Google Play
  38. State Department Email Breach Exposed Personal Data Of Employees
  39. Equifax fined £500,000 over customer data breach
  40. The makers of the Mirai IoT-hijacking botnet are sentenced   via
  41. Privacy advocates have failed to engage on My Health Record
  42. UK Regulator Fines Equifax £500,000 Over 2017 Data Breach
  43. Manipulation tactics that you fall for in phishing attacks
  44. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  45. Mirai botnet developers collaborate with the FBI
  46. State Department: Some Employee Info Possibly Exposed in Security Incident   via
  47. Identifying botnets before an attack: The new DARPA challenge
  48. US Signal partners with Cloudflare to deliver DDoS protection service

THREATS

  1. Android bug bounty tops $3m in third year, but pay flattens out
  2. Facebook Bug Bounty opens to reward access token exposure
  3. US authorities Have Pardoned Authors of Mirai Ransomware in Return For Government “Cooperation”
  4. Bug hunters fail third year in a row to get top prize in Android hacking program
  5. Domain Joined Outlook 2016 Issues - 0x8004011D
  6. Report: Cryptomining malware detections up more than 459 percent since 2017
  7. Bad actors are sizing up systems via lightweight recon before attack, researchers at Proofpoint said:
  8. The rate at which new threats appear now requires a much greater reliance on threat intelligence. Learn more about its opportunities and challenges in our .  pic.twitter.com/bEh9MKP6nS
  9. Malicious Login Attempts Spike in Finance, Retail  pic.twitter.com/OQPWqymDRB
  10. Malicious Login Attempts Spike in Finance, Retail -magazine.com/news/malicious-login-attempts-spike-in?utm_source=twitterfeed&utm_medium=twitter …
  11. New XBash malware combines features from ransomware, cryptocurrency miners, botnets, and worms
  12. Pegasus spyware spotted in 45 countries, many with questionable human rights records
  13. Book Review: Malware Data Science
  14. Increased Use of a Delphi Packer to Evade Malware Classification
  15. Cisco Issues New Warning for 6-Month-Old Critical Bug in IOS XE
  16. Hundreds of Indian Government Websites Hit with Cryptojacking Malware
  17. This breach is a great example of how CT logs can be useful as an early indicator of an ongoing attack campaign. Orgs should be monitoring CT for certificates issued to look-alike domains to improve their situational awareness. -magazine.com/news/magecart-skimmed-newegg-cards/ …
  18. Mitigate Risk From Malicious and Accidental Insiders
  19. : malware detections have soared 273% since 2017 according to new stats from . The most popular way to spread is brute-forcing of passwords, used in 93% of detected attacks. Read more here:   .twitter.com/Ct8Z7qckRC
  20. Sustes Malware: CPU for Monero
  21. : Hackers say and have been the easiest attack vectors to exploit this year. 56% of said that social engineering is the fastest account seizing technique to use on them. Read more here:   .twitter.com/e5ogD8VYWT
  22. Guarding the Gate: Cybersecurity De-Mystified
  23. Researcher discovers buffer overflow vulnerability in Microsoft's JET Database Engine
  24. Interview with Daniel Stenberg: His thoughts on the Curl Bug Bounty Program
  25. Report: Cryptomining malware detections up more than 459 percent since 2017
  26. Threats posed by using RATs in ICS
  27. Western Digital goes quiet on unpatched MyCloud flaw
  28. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability
  29. Adobe releases patch out of schedule to squash critical code execution bug
  30. Cisco IOS XE Software Static Credential Vulnerability
  31. Report Reveals Widespread Use of Pegasus Spyware
  32. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  33. Adobe issued a critical out-of-band patch to address CVE-2018-12848 Acrobat flaw
  34. Ubuntu Released Security Updates & Fixed Multiple Critical Vulnerabilities
  35. Evil Clone Attack – Hackers Injecting Crypto-mining Malware into Legitimate PDF Software
  36. Newegg hacked: The new victim of Magecart malware
  37. Vulnerability in My cloud devices exposes sensitive information
  38. Western Digital My Cloud vulnerability, let’s hacker gives full access
  39. Guarding the Gate: Cybersecurity De-Mystified
  40. How to detect and remove a virus from your Android phone | Avast

CRIME

  1. Report: Cryptomining malware detections up more than 459 percent since 2017
  2. The makers of the Mirai IoT-hijacking botnet are sentenced   via
  3. : The 3 people suspected of the have escaped jail after agreeing to provide “substantial assistance” to the in ongoing cases. Read more about this story here:   .twitter.com/Yzb9wM7KzU
  4. New Magecart victims ABS-CBN and Newegg are just the tip of the iceberg
  5. Magecart Strikes Again, Siphoning Payment Info from Newegg
  6. Newegg Electronic Retailers Suffered a Data Breach and Hackers Stole Customers Credit Card Data
  7. Newegg Inc. Suffers Hack, Credit Card Data Stolen
  8. Hackers Uploaded Fake Apps into Google Play Store to Steal Credit card details and Login Credentials
  9. 7GB of Medical Data Publicly Exposed Thanks to Misconfigured AWS S3 Bucket
  10. HMRC Tax Refund Scam via Phishing Campaign
  11. Report: Cryptomining malware detections up more than 459 percent since 2017
  12. NewEgg Network is attacked by hackers
  13. The makers of the Mirai IoT-hijacking botnet are sentenced   via
  14. Magecart cybercrime group stole customers’ credit cards from Newegg electronics retailer
  15. Manipulation tactics that you fall for in phishing attacks
  16. GovPayNow Leak of 14M+ Records The All Time Low in Processing
  17. Card Data-Scraping Magecart Code Found on Newegg
  18. Newegg hacked: The new victim of Magecart malware
  19. Mirai botnet developers collaborate with the FBI

POLITICS

  1. Wyden: Tech company has told multiple senators of foreign hacking attempts
  2. 7GB of Medical Data Publicly Exposed Thanks to Misconfigured AWS S3 Bucket