Sep 27, 2018

Threat report for 2018-09-26

DATA BREACH

  1. Uber Agrees to $148M Settlement With States Over Data Breach
  2. Uber to pay $148 million to states for 2016 data breach
  3. Firefox Notifies Users of Compromised Accounts
  4. Uber to pay $148 million in settlment over 2016 data breach and cover-up
  5. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  6. United Nations data found exposed on web: researcher
  7. United Nations data found exposed on web: researcher
  8. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  9. SHEIN Data Breach Impacts Over 6.4 Million Customers
  10. SMBs face costs of up to $2.5 million after a data breach
  11. United Nations data found exposed on web: researcher
  12. Millions of Twitter DMs may have been exposed by year-long bug
  13. Firefox Monitor tells you whether your email was compromised in a data breach
  14. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  15. United Nations Mistakenly Exposed Sensitive Data to The Public
  16. oPatch community released micro patches for Microsoft JET Database Zero-Day
  17. Malware campaign attacks freelancers

DENIAL-OF-SERVICE

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  3. Bad bots are stealing data and ruining the customer experience
  4. DDoS Attack on German Energy Company RWE
  5. DDoS Attack on German Energy Company RWE
  6. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  7. Vulnerability in Cisco routers could allow DoS attacks
  8. DDoS attack on education vendor hinders access to districts’ online portals
  9. Microsoft Adds New Tools to Azure DDoS Protection
  10. Viro Botnet Ransomware
  11. Infinite Campus DDoS attack impedes access to student data
  12. Hide and Seek Botnet Adds Infection Vector for Android Devices
  13. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  14. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability

MALVERTISING

Nothing to report

PHISHING

  1. Chegg to reset passwords for 40 million users after April 2018 hack
  2. Android password managers can be tricked into believing that evil apps are good
  3. User login notifications
  4. Beware of payroll-themed phishing. Here’s one example.
  5. SHEIN breach exposes emails, encrypted passwords of 6.42M customers
  6. Counter Phishing Attacks with These Five Tricks
  7. Password managers can be tricked into believing that malicious Android apps are legitimate
  8. Cisco patches critical default password vulnerability
  9. 11:30 AM ET today: @AlexanderGTster and @illena_a from @SCmagazine share the scoop on #spearphishing and how you can go beyond the obvious defenses to protect users from email attacks.
  10. Password Tips from a Pen Tester: Are 12-Character Passwords Really Stronger, or Just a Dime a Dozen?
  11. #SecurityNews: Popular news aggregation site #NewsNow has been notifying its users of a potential password #breach after it found evidence of an #intrusion. Read more about this #databreach here:
  12. Looking for a enterprise grade password vault solution but MUST be hosted onsite
  13. #SecurityNews: New #Ofcom rules "could help tackle #vishing" (voice #phishing) scams. They come into force on Oct 1st and will ban phone companies for charging for the Caller ID service that helps users screen their calls. Read more abut this here:
  14. 156 million #phishing emails are sent out every day and email users receive up to 20 phishing emails each month. Learn more about modern phishing techniques and how to address them in the @ironscales #whitepaper.
  15. Microsoft is killing passwords one announcement at a time
  16. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  17. NewsNow Ditches Passwords After Possible Breach
  18. Malware steals passwords from SHEIN, 6.4 million customers impacted
  19. Malware steals passwords from 6.4 million SHEIN customers
  20. Backlash sees change in Chrome login and Google account behaviour
  21. Chrome 70 Lets you Control Automatic Login and Deletes Google Cookies

WEB DEFACEMENT

Nothing to report

MALWARE

  1. Cisco's probe of VPNFilter router malware uncovers several new hacking techniques
  2. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  3. Fraudulent shopping domain certificate issuance outstrips legitimate businesses
  4. Businesses in Arkansas Hit with Ransomware
  5. Malware in the Cloud: What You Need to Know
  6. Businesses in Arkansas Hit with Ransomware
  7. Air Gapped PCs are Still at Risk. The Rise of USB-based Crytojacking Malware
  8. Crooks turn to Delphi packers to evade malware detection
  9. USB malware and cryptominers are threat to emerging markets
  10. DanaBot trojan sets sights on Europe, new features
  11. Trojanized App In Google Play Steals Bank Customers' Euros
  12. Password managers can be tricked into believing that malicious Android apps are legitimate
  13. Crooks turn to Delphi packers to evade malware detection
  14. Viro Botnet Ransomware
  15. Freelancers baited with job offers to download malicious macros
  16. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  17. Domain flub leaves 30 million customers high and dry
  18. USB malware and cryptominers are threat to emerging markets
  19. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  20. Android spyware in development plunders WhatsApp data, private conversations
  21. The MITRE ATT&CK Framework: Exfiltration
  22. Malware steals passwords from SHEIN, 6.4 million customers impacted
  23. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  24. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software
  25. Malware steals passwords from 6.4 million SHEIN customers
  26. Crooks leverages Kodi Media Player add-ons for malware distribution
  27. Malware in the Cloud: What You Need to Know
  28. Cryptocurrency mining malware increases 86%
  29. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script
  30. Malware campaign attacks freelancers
  31. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit

EXPLOIT

  1. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  2. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  3. Rockwell Automation Buffer Overflow Vulnerability
  4. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  5. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit

VULNERABILITY

  1. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  2. Vulnerability in Cisco routers could allow DoS attacks
  3. Cisco patches critical default password vulnerability
  4. New Linux Kernel “Mutagen Astronomy” Flaw Impacts Red Hat, CentOS, Debian Distributions.
  5. Twitter fixes API bug that shared data with wrong developers
  6. Cisco: Linux kernel FragmentSmack bug now affects 88 of our products
  7. Bug? Feature? Power users baffled as BitLocker update switch-off continues
  8. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  9. Linux Kernel Vulnerability Affects Red Hat, CentOS, Debian
  10. Millions of Twitter DMs may have been exposed by year-long bug
  11. Apple pushes out Mojave 10.14, patches numerous vulnerabilities
  12. Variant of patched IE vulnerability spotted in wild
  13. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  14. Rockwell Automation Buffer Overflow Vulnerability
  15. Crowdfense launches Vulnerability Research Hub for top security researchers
  16. oPatch community released micro patches for Microsoft JET Database Zero-Day
  17. New Linux Kernel Bug Affects Red Hat, CentOS, and Debian Distributions
  18. Vulnerability affects Cisco Video Surveillance Manager
  19. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  20. Snyk raises $22 million to address security vulnerabilities in open source code
  21. New security vulnerabilities (CVE-2018-14634) affects CentOS and Red Hat Linux
  22. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability

Region brief for 2018-09-26

ASIA

  1. Source Defense raises $10 million for website supply chain solution
  2. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  3. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  4. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC

OCEANIA

Nothing to report

NORTH AMERICA

  1. Uber to pay $148 million to states for 2016 data breach
  2. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  3. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  4. Viro Botnet Ransomware
  5. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  6. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  7. Rockwell Automation Buffer Overflow Vulnerability
  8. Snyk raises $22 million to address security vulnerabilities in open source code

SOUTH AMERICA

Nothing to report

EUROPE

  1. DDoS Attack on German Energy Company RWE
  2. DDoS Attack on German Energy Company RWE
  3. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  4. Source Defense raises $10 million for website supply chain solution
  5. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  6. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  7. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  8. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  9. Snyk raises $22 million to address security vulnerabilities in open source code

AFRICA

Nothing to report

Sector brief for 2018-09-26

HEALTHCARE

Nothing to report

TRANSPORT

Nothing to report

BANKING & FINANCE

  1. Chegg to reset passwords for 40 million users after April 2018 hack
  2. Beware of payroll-themed phishing. Here’s one example.
  3. Source Defense raises $10 million for website supply chain solution
  4. Trojanized App In Google Play Steals Bank Customers' Euros
  5. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  6. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  7. Magecart Attacks Grow Rampant in September

INFORMATION & TELECOMMUNICATION

Nothing to report

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

  1. DDoS Attack on German Energy Company RWE
  2. DDoS Attack on German Energy Company RWE
  3. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script

GOVERNMENT & PUBLIC SERVICE

  1. Beware of payroll-themed phishing. Here’s one example.

Daily brief for 2018-09-26

ASIA

  1. Source Defense raises $10 million for website supply chain solution
  2. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  3. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  4. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC

WORLD

  1. DDoS Attack on German Energy Company RWE
  2. DDoS Attack on German Energy Company RWE
  3. Uber to pay $148 million to states for 2016 data breach
  4. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  5. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  6. Source Defense raises $10 million for website supply chain solution
  7. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  8. Viro Botnet Ransomware
  9. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  10. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  11. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  12. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  13. Rockwell Automation Buffer Overflow Vulnerability
  14. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  15. Snyk raises $22 million to address security vulnerabilities in open source code

ATTACKS

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Uber Agrees to $148M Settlement With States Over Data Breach
  3. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  4. Chegg to reset passwords for 40 million users after April 2018 hack
  5. Bad bots are stealing data and ruining the customer experience
  6. DDoS Attack on German Energy Company RWE
  7. DDoS Attack on German Energy Company RWE
  8. Uber to pay $148 million to states for 2016 data breach
  9. Android password managers can be tricked into believing that evil apps are good
  10. User login notifications
  11. Firefox Notifies Users of Compromised Accounts
  12. Uber to pay $148 million in settlment over 2016 data breach and cover-up
  13. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  14. Beware of payroll-themed phishing. Here’s one example.
  15. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  16. United Nations data found exposed on web: researcher
  17. SHEIN breach exposes emails, encrypted passwords of 6.42M customers
  18. United Nations data found exposed on web: researcher
  19. Counter Phishing Attacks with These Five Tricks
  20. Vulnerability in Cisco routers could allow DoS attacks
  21. Password managers can be tricked into believing that malicious Android apps are legitimate
  22. Cisco patches critical default password vulnerability
  23. 11:30 AM ET today: @AlexanderGTster and @illena_a from @SCmagazine share the scoop on #spearphishing and how you can go beyond the obvious defenses to protect users from email attacks.
  24. DDoS attack on education vendor hinders access to districts’ online portals
  25. Microsoft Adds New Tools to Azure DDoS Protection
  26. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  27. Password Tips from a Pen Tester: Are 12-Character Passwords Really Stronger, or Just a Dime a Dozen?
  28. #SecurityNews: Popular news aggregation site #NewsNow has been notifying its users of a potential password #breach after it found evidence of an #intrusion. Read more about this #databreach here:
  29. SHEIN Data Breach Impacts Over 6.4 Million Customers
  30. Viro Botnet Ransomware
  31. Looking for a enterprise grade password vault solution but MUST be hosted onsite
  32. #SecurityNews: New #Ofcom rules "could help tackle #vishing" (voice #phishing) scams. They come into force on Oct 1st and will ban phone companies for charging for the Caller ID service that helps users screen their calls. Read more abut this here:
  33. SMBs face costs of up to $2.5 million after a data breach
  34. 156 million #phishing emails are sent out every day and email users receive up to 20 phishing emails each month. Learn more about modern phishing techniques and how to address them in the @ironscales #whitepaper.
  35. Microsoft is killing passwords one announcement at a time
  36. United Nations data found exposed on web: researcher
  37. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  38. Millions of Twitter DMs may have been exposed by year-long bug
  39. NewsNow Ditches Passwords After Possible Breach
  40. Firefox Monitor tells you whether your email was compromised in a data breach
  41. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  42. Malware steals passwords from SHEIN, 6.4 million customers impacted
  43. Infinite Campus DDoS attack impedes access to student data
  44. Hide and Seek Botnet Adds Infection Vector for Android Devices
  45. United Nations Mistakenly Exposed Sensitive Data to The Public
  46. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  47. Malware steals passwords from 6.4 million SHEIN customers
  48. Backlash sees change in Chrome login and Google account behaviour
  49. oPatch community released micro patches for Microsoft JET Database Zero-Day
  50. Malware campaign attacks freelancers
  51. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  52. Chrome 70 Lets you Control Automatic Login and Deletes Google Cookies

THREATS

  1. Cisco's probe of VPNFilter router malware uncovers several new hacking techniques
  2. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  3. Fraudulent shopping domain certificate issuance outstrips legitimate businesses
  4. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  5. Businesses in Arkansas Hit with Ransomware
  6. Malware in the Cloud: What You Need to Know
  7. Businesses in Arkansas Hit with Ransomware
  8. Air Gapped PCs are Still at Risk. The Rise of USB-based Crytojacking Malware
  9. Crooks turn to Delphi packers to evade malware detection
  10. USB malware and cryptominers are threat to emerging markets
  11. DanaBot trojan sets sights on Europe, new features
  12. Trojanized App In Google Play Steals Bank Customers' Euros
  13. Vulnerability in Cisco routers could allow DoS attacks
  14. Password managers can be tricked into believing that malicious Android apps are legitimate
  15. Cisco patches critical default password vulnerability
  16. New Linux Kernel “Mutagen Astronomy” Flaw Impacts Red Hat, CentOS, Debian Distributions.
  17. Crooks turn to Delphi packers to evade malware detection
  18. Twitter fixes API bug that shared data with wrong developers
  19. Viro Botnet Ransomware
  20. Freelancers baited with job offers to download malicious macros
  21. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  22. Domain flub leaves 30 million customers high and dry
  23. Cisco: Linux kernel FragmentSmack bug now affects 88 of our products
  24. USB malware and cryptominers are threat to emerging markets
  25. Bug? Feature? Power users baffled as BitLocker update switch-off continues
  26. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  27. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  28. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  29. Linux Kernel Vulnerability Affects Red Hat, CentOS, Debian
  30. Millions of Twitter DMs may have been exposed by year-long bug
  31. Apple pushes out Mojave 10.14, patches numerous vulnerabilities
  32. Android spyware in development plunders WhatsApp data, private conversations
  33. Variant of patched IE vulnerability spotted in wild
  34. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  35. The MITRE ATT&CK Framework: Exfiltration
  36. Malware steals passwords from SHEIN, 6.4 million customers impacted
  37. Rockwell Automation Buffer Overflow Vulnerability
  38. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  39. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  40. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software
  41. Malware steals passwords from 6.4 million SHEIN customers
  42. Crooks leverages Kodi Media Player add-ons for malware distribution
  43. Malware in the Cloud: What You Need to Know
  44. Crowdfense launches Vulnerability Research Hub for top security researchers
  45. oPatch community released micro patches for Microsoft JET Database Zero-Day
  46. Cryptocurrency mining malware increases 86%
  47. New Linux Kernel Bug Affects Red Hat, CentOS, and Debian Distributions
  48. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script
  49. Vulnerability affects Cisco Video Surveillance Manager
  50. Malware campaign attacks freelancers
  51. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit
  52. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  53. Snyk raises $22 million to address security vulnerabilities in open source code
  54. New security vulnerabilities (CVE-2018-14634) affects CentOS and Red Hat Linux
  55. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability

CRIME

  1. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  2. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  3. Source Defense raises $10 million for website supply chain solution
  4. Trojanized App In Google Play Steals Bank Customers' Euros
  5. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  6. SHEIN Data Breach Impacts Over 6.4 Million Customers
  7. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  8. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  9. Crooks leverages Kodi Media Player add-ons for malware distribution
  10. Cryptocurrency mining malware increases 86%
  11. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script
  12. Malware campaign attacks freelancers
  13. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  14. Magecart Attacks Grow Rampant in September

POLITICS

  1. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  2. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  3. United Nations Mistakenly Exposed Sensitive Data to The Public

Sep 26, 2018

Threat report for 2018-09-25

DATA BREACH

  1. Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
  2. Malware on SHEIN Servers Compromises Data of 6.4M Customers
  3. Mozilla Launches Firefox Monitor Data Breach Notification Service
  4. Third-Party Patch Available for Microsoft JET Database Zero-Day
  5. 130 Million Hotel Customers Breached Due to Exposed Database
  6. State Department data breach exposes employee info (w/ commentary from @TripwireInc’s @craigtweets http://bit.ly/2MTcplE
  7. New Adwind RAT Campaign Targets Windows, Linux and Mac Users
  8. Shein Data Breach Exposes Personal Data and Email Address of 6.42 Million Customers
  9. SHEIN Data breach affected 6.42 million users
  10. Security In The Crypto World: Exchanges, Wallets, Personal Data. Kiev To Host The Largest Cybersecurity Forum In Eastern Europe
  11. Symantec accountancy audit uncovers customer transaction recorded as revenue
  12. NewsNow suffers security breach - passwords should be considered compromised
  13. First known malicious cryptomining campaign targeting Kodi discovered
  14. SHEIN-Fashion Shopping Site Suffers Data Breach Affecting 6.5 Million Users
  15. macOS zero-day vulnerability leads to user data leaks
  16. How Long Does it Take to Find Compromised Data
  17. DBeaver Community Edition 5.2.1 Releases: Free universal database tool and SQL client

DENIAL-OF-SERVICE

  1. DDoS Attack on Infinite Campus Limits Parent Access http://dlvr.it/QlL12Z
  2. DDoS Attack on Infinite Campus Limits Parent Access https://www.infosecurity-magazine.com/news/ddos-attacks-infinite-campus?utm_source=twitterfeed&utm_medium=twitter …
  3. DDoS attack on education vendor hinders access to districts’ online portals
  4. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  5. Some credential-stuffing botnets don't care about being noticed any more
  6. Advanced DDoS Detection and Defense
  7. ZombieBoy
  8. Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability

MALVERTISING

Nothing to report

PHISHING

  1. Firefox Monitor provides password breach alerts, Would it convince you to set up a Firefox Account
  2. GrrCon Augusta 2018, Rachel Giacobozzi’s ‘The Hybrid Analyst: How Phishing Created A New Type Of Intel Analyst’
  3. Tomorrow: Go beyond the usual defenses and *really* protect your email from #spearphishing attacks. Find out how with @AlexanderGTster and @illena_a from @SCmagazine. http://www.workcast.com/register?cpak=2026696370909275&referrer=valimailA …
  4. Cisco patches critical default password vulnerability
  5. Security researcher fined for hacking hotel Wi-Fi and putting passwords on the internet
  6. Users fret over Chrome auto-login change
  7. Security Engineer Hacks Hotel WiFi, Fined for Exposing Admin Password
  8. AdGuard adblocker resets passwords after credential-stuffing attack
  9. 5 Notable Security Incidents that Recently Affected Federal Entities https://tripwire.me/2xGwKoH
  10. Anti-Phishing Requires A Three-Pronged Strategy https://www.infosecurity-magazine.com/white-papers/antiphishing-requires-threepronged?utm_source=twitterfeed&utm_medium=twitter …
  11. Microsoft: Here's why we're declaring end of password era
  12. Microsoft 'kills' passwords, throws up threat manager, APIs Graph Security
  13. Baddies just need one email account with clout to unleash phishing hell
  14. Why Was Equifax So Stupid About Passwords?
  15. NewsNow suffers security breach - passwords should be considered compromised
  16. Cisco patches critical default password vulnerability
  17. 5 Notable Security Incidents that Recently Affected Federal Entities https://tripwire.me/2xGwKoH

WEB DEFACEMENT

Nothing to report

MALWARE

  1. The MITRE ATT&CK Framework: Exfiltration https://tripwire.me/2NDbSJV
  2. Malware on SHEIN Servers Compromises Data of 6.4M Customers
  3. Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
  4. New Adwind RAT Campaign Targets Windows, Linux and Mac Users
  5. Cryptomining Malware Continues Rapid Growth: Report
  6. Freelancers baited with job offers to download malicious macros
  7. DanaBot trojan sets sights on Europe, new features
  8. Crooks turn to Delphi packers to evade malware detection
  9. Mac Mojave Zero-Day Allows Malicious Apps to Access Sensitive Info
  10. Astaroth Trojan Resurges in South America
  11. BrandPost: Malicious Tactics Have Evolved: Your DNS Needs to, Too
  12. Bloodhound – A Tool For Exploring Active Directory Domain Security
  13. #SecurityNews: #Cryptocurrency mining soars 459% from 2017 to 2018 with no indication of slowing down. Read more about this story here: https://bit.ly/2PXYSew
  14. #SecurityNews: Scottish #Brewery recovers from #ransomware attack. #Arran Brewery in Scotland, received what they thought was a cover letter as part of a job application, but the email attachment contained malware. Read more here: https://bit.ly/2PYAR7k
  15. Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
  16. Malware Analysis using Osquery Part 2
  17. Off-the-shelf RATs Targeting Pakistan
  18. Malware Analysis using Osquery Part 1
  19. Malicious Documents from Lazarus Group Targeting South Korea
  20. GZipDe: An Encrypted Downloader Serving Metasploit
  21. Satan Ransomware Spawns New Methods to Spread
  22. MassMiner Malware Targeting Web Servers
  23. 14 years prison for man who helped hackers evade detection by anti-virus software
  24. USB threats from malware to miners
  25. DanaBot trojan sets sights on Europe, new features
  26. Stealthy cryptomining apps still on Google Play
  27. New Version of GandCrab Ransomware Appends 5 Character Extension To Encrypted Files
  28. First known malicious cryptomining campaign targeting Kodi discovered
  29. 14 years prison for man who helped hackers evade detection by anti-virus software
  30. New malware-as-a-service, Black Rose Lucy targets Android devices
  31. Domain registrar oversteps taking down Zoho domain, impacts over 30Mil users

EXPLOIT

  1. New CVE-2018-8373 Exploit Spotted in the Wild

VULNERABILITY

  1. Open-source reuse has left Android’s most-popular apps laced with critical vulnerabilities
  2. Monero bug could have allowed hackers to steal massive amounts of cryptocurrency
  3. New Linux 'Mutagen Astronomy' security flaw impacts Red Hat and CentOS distros
  4. Third-Party Patch Available for Microsoft JET Database Zero-Day
  5. Over 80 Cisco Products Affected by FragmentSmack DoS Bug
  6. MacOS Mojave zero-day privacy vulnerability uncovered
  7. Snyk gets $22 million for platform that tracks security flaws in open source projects
  8. Cisco patches critical default password vulnerability
  9. Twitter fixes API bug that shared data with wrong developers
  10. Mac Mojave Zero-Day Allows Malicious Apps to Access Sensitive Info
  11. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  12. No Takers for Zero-Day Vulnerabilities on the Dark Web
  13. macOS Mojave Patches Vulnerabilities, But New Flaws Already Emerge
  14. New CVE-2018-8373 Exploit Spotted in the Wild
  15. More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
  16. Vulnerability Spotlight: Epee Levin Packet Deserialization Code Execution Vulnerability
  17. Twitter fixes API bug that shared data with wrong developers
  18. Cisco patches critical default password vulnerability
  19. White hat hacker found a macOS Mojave privacy bypass 0-day flaw on release day
  20. macOS zero-day vulnerability leads to user data leaks
  21. Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability
  22. Vulnerability in macOS Mojave allows access to protected files
  23. Firefox bugs can cause browsers and even the entire operating system to crash directly
  24. Why the market for zero-day vulnerabilities on the dark web is vanishing

Region brief for 2018-09-25

ASIA

  1. Snyk gets $22 million for platform that tracks security flaws in open source projects
  2. Security Engineer Hacks Hotel WiFi, Fined for Exposing Admin Password
  3. Off-the-shelf RATs Targeting Pakistan
  4. Malicious Documents from Lazarus Group Targeting South Korea
  5. GZipDe: An Encrypted Downloader Serving Metasploit
  6. More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
  7. USB threats from malware to miners

OCEANIA

Nothing to report

NORTH AMERICA

  1. Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
  2. Astaroth Trojan Resurges in South America
  3. Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
  4. Malware Analysis using Osquery Part 1
  5. MassMiner Malware Targeting Web Servers
  6. 14 years prison for man who helped hackers evade detection by anti-virus software
  7. SHEIN-Fashion Shopping Site Suffers Data Breach Affecting 6.5 Million Users
  8. 14 years prison for man who helped hackers evade detection by anti-virus software

SOUTH AMERICA

Nothing to report

EUROPE

  1. Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
  2. Snyk gets $22 million for platform that tracks security flaws in open source projects
  3. Security In The Crypto World: Exchanges, Wallets, Personal Data. Kiev To Host The Largest Cybersecurity Forum In Eastern Europe
  4. #SecurityNews: Scottish #Brewery recovers from #ransomware attack. #Arran Brewery in Scotland, received what they thought was a cover letter as part of a job application, but the email attachment contained malware. Read more here: https://bit.ly/2PYAR7k
  5. Baddies just need one email account with clout to unleash phishing hell
  6. 14 years prison for man who helped hackers evade detection by anti-virus software
  7. New malware-as-a-service, Black Rose Lucy targets Android devices

AFRICA

  1. BrandPost: Malicious Tactics Have Evolved: Your DNS Needs to, Too

Sector brief for 2018-09-25

HEALTHCARE

  1. macOS zero-day vulnerability leads to user data leaks

TRANSPORT

Nothing to report

BANKING & FINANCE

  1. Porous portals, Newegg is a broken egg, and Mirai’s creators have new hats
  2. Symantec accountancy audit uncovers customer transaction recorded as revenue
  3. Malware Analysis using Osquery Part 2
  4. Malware Analysis using Osquery Part 1
  5. Malicious Documents from Lazarus Group Targeting South Korea
  6. MassMiner Malware Targeting Web Servers
  7. DanaBot trojan sets sights on Europe, new features

INFORMATION & TELECOMMUNICATION

Nothing to report

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

  1. Off-the-shelf RATs Targeting Pakistan
  2. USB threats from malware to miners
  3. Stealthy cryptomining apps still on Google Play

GOVERNMENT & PUBLIC SERVICE

Nothing to report

Daily brief for 2018-09-25

ASIA

  1. Snyk gets $22 million for platform that tracks security flaws in open source projects
  2. Security Engineer Hacks Hotel WiFi, Fined for Exposing Admin Password
  3. Off-the-shelf RATs Targeting Pakistan
  4. Malicious Documents from Lazarus Group Targeting South Korea
  5. GZipDe: An Encrypted Downloader Serving Metasploit
  6. More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
  7. USB threats from malware to miners

WORLD

  1. Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
  2. Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
  3. Snyk gets $22 million for platform that tracks security flaws in open source projects
  4. Astaroth Trojan Resurges in South America
  5. BrandPost: Malicious Tactics Have Evolved: Your DNS Needs to, Too
  6. Security In The Crypto World: Exchanges, Wallets, Personal Data. Kiev To Host The Largest Cybersecurity Forum In Eastern Europe
  7. #SecurityNews: Scottish #Brewery recovers from #ransomware attack. #Arran Brewery in Scotland, received what they thought was a cover letter as part of a job application, but the email attachment contained malware. Read more here: https://bit.ly/2PYAR7k
  8. Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
  9. Baddies just need one email account with clout to unleash phishing hell
  10. Malware Analysis using Osquery Part 1
  11. MassMiner Malware Targeting Web Servers
  12. 14 years prison for man who helped hackers evade detection by anti-virus software
  13. SHEIN-Fashion Shopping Site Suffers Data Breach Affecting 6.5 Million Users
  14. 14 years prison for man who helped hackers evade detection by anti-virus software
  15. New malware-as-a-service, Black Rose Lucy targets Android devices

ATTACKS

  1. Firefox Monitor provides password breach alerts, Would it convince you to set up a Firefox Account
  2. Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
  3. Malware on SHEIN Servers Compromises Data of 6.4M Customers
  4. GrrCon Augusta 2018, Rachel Giacobozzi’s ‘The Hybrid Analyst: How Phishing Created A New Type Of Intel Analyst’
  5. Mozilla Launches Firefox Monitor Data Breach Notification Service
  6. Tomorrow: Go beyond the usual defenses and *really* protect your email from #spearphishing attacks. Find out how with @AlexanderGTster and @illena_a from @SCmagazine. http://www.workcast.com/register?cpak=2026696370909275&referrer=valimailA …
  7. Third-Party Patch Available for Microsoft JET Database Zero-Day
  8. 130 Million Hotel Customers Breached Due to Exposed Database
  9. State Department data breach exposes employee info (w/ commentary from @TripwireInc’s @craigtweets http://bit.ly/2MTcplE
  10. DDoS Attack on Infinite Campus Limits Parent Access http://dlvr.it/QlL12Z
  11. DDoS Attack on Infinite Campus Limits Parent Access https://www.infosecurity-magazine.com/news/ddos-attacks-infinite-campus?utm_source=twitterfeed&utm_medium=twitter …
  12. New Adwind RAT Campaign Targets Windows, Linux and Mac Users
  13. Cisco patches critical default password vulnerability
  14. DDoS attack on education vendor hinders access to districts’ online portals
  15. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  16. Shein Data Breach Exposes Personal Data and Email Address of 6.42 Million Customers
  17. Security researcher fined for hacking hotel Wi-Fi and putting passwords on the internet
  18. SHEIN Data breach affected 6.42 million users
  19. Security In The Crypto World: Exchanges, Wallets, Personal Data. Kiev To Host The Largest Cybersecurity Forum In Eastern Europe
  20. Users fret over Chrome auto-login change
  21. Security Engineer Hacks Hotel WiFi, Fined for Exposing Admin Password
  22. AdGuard adblocker resets passwords after credential-stuffing attack
  23. Symantec accountancy audit uncovers customer transaction recorded as revenue
  24. 5 Notable Security Incidents that Recently Affected Federal Entities https://tripwire.me/2xGwKoH
  25. Anti-Phishing Requires A Three-Pronged Strategy https://www.infosecurity-magazine.com/white-papers/antiphishing-requires-threepronged?utm_source=twitterfeed&utm_medium=twitter …
  26. Microsoft: Here's why we're declaring end of password era
  27. Microsoft 'kills' passwords, throws up threat manager, APIs Graph Security
  28. Baddies just need one email account with clout to unleash phishing hell
  29. Some credential-stuffing botnets don't care about being noticed any more
  30. Advanced DDoS Detection and Defense
  31. Why Was Equifax So Stupid About Passwords?
  32. ZombieBoy
  33. NewsNow suffers security breach - passwords should be considered compromised
  34. Cisco patches critical default password vulnerability
  35. First known malicious cryptomining campaign targeting Kodi discovered
  36. SHEIN-Fashion Shopping Site Suffers Data Breach Affecting 6.5 Million Users
  37. macOS zero-day vulnerability leads to user data leaks
  38. How Long Does it Take to Find Compromised Data
  39. Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability
  40. 5 Notable Security Incidents that Recently Affected Federal Entities https://tripwire.me/2xGwKoH
  41. DBeaver Community Edition 5.2.1 Releases: Free universal database tool and SQL client

THREATS

  1. Open-source reuse has left Android’s most-popular apps laced with critical vulnerabilities
  2. The MITRE ATT&CK Framework: Exfiltration https://tripwire.me/2NDbSJV
  3. Monero bug could have allowed hackers to steal massive amounts of cryptocurrency
  4. New Linux 'Mutagen Astronomy' security flaw impacts Red Hat and CentOS distros
  5. Once Popular Online Ad Format Opens Top Tier Sites to XSS Attacks
  6. Malware on SHEIN Servers Compromises Data of 6.4M Customers
  7. Third-Party Patch Available for Microsoft JET Database Zero-Day
  8. Over 80 Cisco Products Affected by FragmentSmack DoS Bug
  9. Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
  10. MacOS Mojave zero-day privacy vulnerability uncovered
  11. New Adwind RAT Campaign Targets Windows, Linux and Mac Users
  12. Cryptomining Malware Continues Rapid Growth: Report
  13. Freelancers baited with job offers to download malicious macros
  14. Snyk gets $22 million for platform that tracks security flaws in open source projects
  15. Cisco patches critical default password vulnerability
  16. Twitter fixes API bug that shared data with wrong developers
  17. DanaBot trojan sets sights on Europe, new features
  18. Crooks turn to Delphi packers to evade malware detection
  19. Mac Mojave Zero-Day Allows Malicious Apps to Access Sensitive Info
  20. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  21. Astaroth Trojan Resurges in South America
  22. BrandPost: Malicious Tactics Have Evolved: Your DNS Needs to, Too
  23. Bloodhound – A Tool For Exploring Active Directory Domain Security
  24. No Takers for Zero-Day Vulnerabilities on the Dark Web
  25. macOS Mojave Patches Vulnerabilities, But New Flaws Already Emerge
  26. #SecurityNews: #Cryptocurrency mining soars 459% from 2017 to 2018 with no indication of slowing down. Read more about this story here: https://bit.ly/2PXYSew
  27. New CVE-2018-8373 Exploit Spotted in the Wild
  28. #SecurityNews: Scottish #Brewery recovers from #ransomware attack. #Arran Brewery in Scotland, received what they thought was a cover letter as part of a job application, but the email attachment contained malware. Read more here: https://bit.ly/2PYAR7k
  29. Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
  30. Malware Analysis using Osquery Part 2
  31. Off-the-shelf RATs Targeting Pakistan
  32. Malware Analysis using Osquery Part 1
  33. Malicious Documents from Lazarus Group Targeting South Korea
  34. GZipDe: An Encrypted Downloader Serving Metasploit
  35. More Details on an ActiveX Vulnerability Recently Used to Target Users in South Korea
  36. Satan Ransomware Spawns New Methods to Spread
  37. MassMiner Malware Targeting Web Servers
  38. Vulnerability Spotlight: Epee Levin Packet Deserialization Code Execution Vulnerability
  39. 14 years prison for man who helped hackers evade detection by anti-virus software
  40. USB threats from malware to miners
  41. DanaBot trojan sets sights on Europe, new features
  42. Twitter fixes API bug that shared data with wrong developers
  43. Stealthy cryptomining apps still on Google Play
  44. New Version of GandCrab Ransomware Appends 5 Character Extension To Encrypted Files
  45. Cisco patches critical default password vulnerability
  46. White hat hacker found a macOS Mojave privacy bypass 0-day flaw on release day
  47. First known malicious cryptomining campaign targeting Kodi discovered
  48. 14 years prison for man who helped hackers evade detection by anti-virus software
  49. macOS zero-day vulnerability leads to user data leaks
  50. New malware-as-a-service, Black Rose Lucy targets Android devices
  51. Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability
  52. Vulnerability in macOS Mojave allows access to protected files
  53. Firefox bugs can cause browsers and even the entire operating system to crash directly
  54. Domain registrar oversteps taking down Zoho domain, impacts over 30Mil users
  55. Why the market for zero-day vulnerabilities on the dark web is vanishing

CRIME

  1. Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
  2. Porous portals, Newegg is a broken egg, and Mirai’s creators have new hats
  3. Operator of Scan4You Malware-Scanning sentenced to 14 Years in prison
  4. Cryptomining Malware Continues Rapid Growth: Report
  5. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  6. SHEIN Data breach affected 6.42 million users
  7. #SecurityNews: #Cryptocurrency mining soars 459% from 2017 to 2018 with no indication of slowing down. Read more about this story here: https://bit.ly/2PXYSew
  8. Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
  9. Microsoft: Here's why we're declaring end of password era
  10. Malware Analysis using Osquery Part 2
  11. Malware Analysis using Osquery Part 1
  12. ZombieBoy
  13. Malicious Documents from Lazarus Group Targeting South Korea
  14. MassMiner Malware Targeting Web Servers
  15. 14 years prison for man who helped hackers evade detection by anti-virus software
  16. DanaBot trojan sets sights on Europe, new features
  17. Stealthy cryptomining apps still on Google Play
  18. First known malicious cryptomining campaign targeting Kodi discovered
  19. 14 years prison for man who helped hackers evade detection by anti-virus software
  20. Bitcoin Core Software Patches a Critical DDoS Attack Vulnerability

POLITICS

  1. Ex-NSA Hacker Sentenced to Jail Over Kaspersky Leak
  2. Man gets two years in prison for sabotaging US Army servers with 'logic bomb'
  3. Vulnerability in macOS Mojave allows access to protected files