ASIA
- Cyber Security Roundup for September 2018
- GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
- Report Ties North Korean Attacks to New Malware, Linked by Word Macros
- Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- Report Ties North Korean Attacks to New Malware, Linked by Word Macros
- Telegram not really anonymous? Researcher reports bug that leaks IP addresses
- Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
- GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
WORLD
- Cyber Security Roundup for September 2018
- Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
- GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
- A week in security (September 24 – 30)
- 4 Ways to Protect Your Files from a Data Breach
- Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- Facebook: How to minimize the risk of vulnerabilities
- Voice Phishing Scams Are Getting More Clever
- Malwarebytes is a champion of National Cybersecurity Awareness Month
- Formjacking in the Nutshell
- TrickBot Banking Trojan Takes Center Stage in 2018
- Telegram not really anonymous? Researcher reports bug that leaks IP addresses
- Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
- Facebook faces a whopping €1.4 billion penalty under GDPR for Sept. 30 data breach
- UK firms’ password security score ‘average’
- CISO @rickhholland joins @drshellface and @mazzazone to discuss the latest #cybersecurity news: Security Flaws Affect 50 Million Facebook Accounts and
- Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
- New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader
ATTACKS
- 100K Routers Hijacked for Phishing in GhostDNS Campaign
- Picture-in-Picture Phishing Campaign Goes After Steam Credentials
- GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
- Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
- 4 Ways to Protect Your Files from a Data Breach
- Facebook hacked – 50 Million Users’ Data exposed in the security breach
- Instagram Being Used To Sell Botnets And Stolen Fortnite Accounts
- Telegram Patched IP Address Leak Problem In Its Desktop Client
- Weak Passwords Abused for 'FruitFly' Mac Malware Distribution
- Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
- Third-Party Apps Using Facebook Login Also Affected by Latest Hacking Incident
- How to Orchestrate a Smarter Phishing Response
- Voice Phishing Scams Are Getting More Clever
- Why nearly 50% of organizations are failing at password security
- Employees Share Average of 6 Passwords With Co-Workers
- Telegram Leaks User IP Addresses
- Telegram not really anonymous? Researcher reports bug that leaks IP addresses
- Flaws in Tory party conference app leak ministers' personal information
- Facebook faces a whopping €1.4 billion penalty under GDPR for Sept. 30 data breach
- UK firms’ password security score ‘average’
- Torii malware could be gateway to more sophisticated IoT botnet attacks
- Phishing campaign targets developers of Chrome extensions
- Password Security Better, Still Poses Business Risk
- New vicious Torii IoT botnet discovered
- Password Security Better, Still Poses Business Risk
- GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
- 3 GOP senators doxed during Kavanaugh hearing
- Facebook Data Breach Extended to Third-Party Applications
- Following a loud critical backlash to a new #Chrome login feature and cookie retention functionality, @Google will make changes in
- Facebook could face up to $1.6bn fine for data breach
- Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls
- Telegram Calling Feature Leaks Your IP Addresses—Patch Released
- Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
- Torii IoT Botnet Takes Mirai to the Next Level
- High-Profile Instagram Accounts Hacked For Ransom In A Recent Campaign
THREATS
- Adobe Patches 47 Critical Flaws in Acrobat and DC
- Top Cloud Domain Controller for MSPs
- Multiple Code Execution Vulnerabilities Found in Atlantis Word Processor
- CVE-2018-11776 and why you need Black Duck Security Advisories
- GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
- Nine NAS Bugs Open LenovoEMC, Iomega Devices to Attack
- GrandCrab Ransomware Spreads Using Multiple Known Vulnerabilities
- Fileless Malware Attacks on the Rise, Microsoft Says
- 'Short, Brutal Lives': Life Expectancy for Malicious Domains
- Google Bug Breaks Search Results with a Plus Sign On Mac Safari
- Report Ties North Korean Attacks to New Malware, Linked by Word Macros
- Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
- Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
- Google Adds New Rules To End Malicious Chrome Extensions
- Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
- Code Execution Vulnerabilities Uncovered In Atlantis Word Processor
- Deep Dive Into iTranslator - MITM Malware
- LoJax: Fisrt UEFI Rootkit Found In The Wild
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- Telegram Patched IP Address Leak Problem In Its Desktop Client
- Weak Passwords Abused for 'FruitFly' Mac Malware Distribution
- Facebook: How to minimize the risk of vulnerabilities
- Code execution vulnerabilities uncovered in Atlantis Word Processor
- A new Browser Reaper exploit can crash or freeze Mozilla #Firefox, according to a proof of concept published by a
- Malwarebytes is a champion of National Cybersecurity Awareness Month
- Monitor privileged execution to defend against
- Attackers chained three bugs to breach into the Facebook platform
- Telegram Leaks User IP Addresses
- Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
- TrickBot Banking Trojan Takes Center Stage in 2018
- More on the Five Eyes Statement on Encryption and Backdoors
- Monero fixes major ‘burning bug’ flaw, preventing mass devaluation
- Report Ties North Korean Attacks to New Malware, Linked by Word Macros
- Telegram not really anonymous? Researcher reports bug that leaks IP addresses
- Flaws in Tory party conference app leak ministers' personal information
- Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
- Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
- GandCrab ransomware is spreading wildly through several known vulnerabilities
- Python-based attack tools are the most common vector for launching exploit attempts
- Docs reveal how Fruitfly Mac spyware initially spread
- Torii malware could be gateway to more sophisticated IoT botnet attacks
- SamSam ransomware: How is this version different from others?
- Ransomware Casts Anchor at the Port of San Diego
- Hackers Hijacked More Than 100,000 Routers DNS Settings and Redirecting Users to Malicious WebSites
- Ransomware Casts Anchor at the Port of San Diego
- Several Bugs Exploited in Massive Facebook Hack
- Sophos recently discovered a #Samsam extortion code that performs whole-company attacks through a variety of vulnerability exploits. Discover how this
- #VPNFilter #malware: How can users protect themselves?
- Nasty Linux Kernel Vulnerability Discovered, Mandatory Kernel Update Required
- How can attackers exploit a buffer underflow #vulnerability?
- CISO @rickhholland joins @drshellface and @mazzazone to discuss the latest #cybersecurity news: Security Flaws Affect 50 Million Facebook Accounts and
- Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
- Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls
- Telegram Calling Feature Leaks Your IP Addresses—Patch Released
- New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader
CRIME
- Cyber Security Roundup for September 2018
- Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
- GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
- 4 Ways to Protect Your Files from a Data Breach
- Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
- Facebook: How to minimize the risk of vulnerabilities
- Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
- How to Orchestrate a Smarter Phishing Response
- Voice Phishing Scams Are Getting More Clever
- Formjacking in the Nutshell
- Attackers chained three bugs to breach into the Facebook platform
- TrickBot Banking Trojan Takes Center Stage in 2018
- Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
- Hackers Hijacked More Than 100,000 Routers DNS Settings and Redirecting Users to Malicious WebSites
- Sophos recently discovered a #Samsam extortion code that performs whole-company attacks through a variety of vulnerability exploits. Discover how this
- GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
- New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader
POLITICS
- Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
- Report Ties North Korean Attacks to New Malware, Linked by Word Macros
- A week in security (September 24 – 30)
- Facebook: How to minimize the risk of vulnerabilities
- Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
- Malwarebytes is a champion of National Cybersecurity Awareness Month
- Report Ties North Korean Attacks to New Malware, Linked by Word Macros
- Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
TRANSNATIONAL / UNKNOWN
- The British Airways #databreach may be the handiwork of hacking group #Magecart, according to researchers. By @MaddieBacon11
CHINA
Nothing to report
INDIA
Nothing to report
NORTH KOREA
- A security researcher developed a proof-of-concept attack on #Firefox called Browser Reaper that can crash or freeze the browser, but
PAKISTAN
Nothing to report
VIETNAM
Nothing to report
IRAN
Nothing to report
LEBANON
Nothing to report
PALESTINE
Nothing to report
SAUDI ARABIA
Nothing to report
UNITED ARAB EMIRATES
Nothing to report
RUSSIA
- Security Affairs newsletter Round 182 – News of the week
UKRAINE
Nothing to report
DATA BREACH
- Experts comment on Facebook’s 50 million user credential leak
- 40 million more likely affected by massive Facebook data leak - Bitdefender
- Project Insecurity (@insecurity) researchers discovered certain #livechatsoftware that were leaking personal details of employee at several high-profile sites. Discover how
- Telegram Leaks Public & Private IP Address While Making Calls
- The United Nations (@UN) accidentally exposed sensitive information on public @trello boards, in the Jira app, and in #GoogleDocs and
- 3 GOP senators doxed during Kavanaugh hearing
- Uber has agreed to pay more than $140 Million for a data breach settlement
DENIAL-OF-SERVICE
Nothing to report
MALVERTISING
Nothing to report
PHISHING
- Chegg forces password reset on 40 million users
- Hackers are Selling Social Media Logins & Financial Details On Dark Web starting from £2
- USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing
WEB DEFACEMENT
Nothing to report
MALWARE
- GANDCRAB 5.0.1 Ransom Virus – How to Remove It and Restore Data
- Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
- Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
- Telegram Leaks Public & Private IP Address While Making Calls
- #Android #Trojan: How is data being stolen from #messagingapps?
- Docs reveal how Fruitfly Mac spyware initially spread
- Cryptomining Malware Grows by 86% in Q2: McAfee Report
- Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
- Security roundup: Facebook, ransomware, UEFI rootkit, Berners-Lee’s plan for new internet
- Telegram exposes the IP address during a user call by default
- #GoScanSSH: How does this #malware work and differ from others?
- Xbash Malware Combines Many Malicious Functions in Worm
- Discover how the #VPNFilter #malware works and affects users
- Alphabet's Chronicle has given #VirusTotal a makeover. Find out what's in the new VirusTotal Enterprise offering. By @RobWright22
- Improving core processes with next-generation mobile productivity solutions can bring power and cost efficiency gains. However, we must not lose
- Malware in the Cloud: What You Need to Know
- Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware
EXPLOIT
- Facebook Ad Targeting Exploits Users’ 2FA Phone Numbers
- FBI IC3 warns of cyber attacks exploiting Remote Desktop Protocol (RDP)
VULNERABILITY
- Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
- Facebook Says Three Different Bugs Are Responsible For The Massive Account Hacks
- Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
- Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
- Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
- #Cisco patches yet another hardcoded credentials flaw, this time in its video surveillance manager appliance; the latest vulnerability is at
- Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
- Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from
- Cisco Multiple Security Vulnerabilities Alert
- Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files
- A Top Facebook Bug Bounty Hunter Shares Their Insights on the Facebook Breach
ASIA
- Cryptomining Malware Grows by 86% in Q2: McAfee Report
- Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
WORLD
- Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
- Cryptomining Malware Grows by 86% in Q2: McAfee Report
- Security Affairs newsletter Round 182 – News of the week
- The British Airways #databreach may be the handiwork of hacking group #Magecart, according to researchers. By @MaddieBacon11
- Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
- Telegram exposes the IP address during a user call by default
ATTACKS
- Experts comment on Facebook’s 50 million user credential leak
- 40 million more likely affected by massive Facebook data leak - Bitdefender
- Project Insecurity (@insecurity) researchers discovered certain #livechatsoftware that were leaking personal details of employee at several high-profile sites. Discover how
- Telegram Leaks Public & Private IP Address While Making Calls
- The United Nations (@UN) accidentally exposed sensitive information on public @trello boards, in the Jira app, and in #GoogleDocs and
- Chegg forces password reset on 40 million users
- Hackers are Selling Social Media Logins & Financial Details On Dark Web starting from £2
- 3 GOP senators doxed during Kavanaugh hearing
- Uber has agreed to pay more than $140 Million for a data breach settlement
- USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing
THREATS
- Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
- GANDCRAB 5.0.1 Ransom Virus – How to Remove It and Restore Data
- Facebook Says Three Different Bugs Are Responsible For The Massive Account Hacks
- Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
- Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
- Facebook Ad Targeting Exploits Users’ 2FA Phone Numbers
- Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
- Telegram Leaks Public & Private IP Address While Making Calls
- #Android #Trojan: How is data being stolen from #messagingapps?
- Docs reveal how Fruitfly Mac spyware initially spread
- Cryptomining Malware Grows by 86% in Q2: McAfee Report
- #Cisco patches yet another hardcoded credentials flaw, this time in its video surveillance manager appliance; the latest vulnerability is at
- Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
- Security roundup: Facebook, ransomware, UEFI rootkit, Berners-Lee’s plan for new internet
- Telegram exposes the IP address during a user call by default
- #GoScanSSH: How does this #malware work and differ from others?
- Xbash Malware Combines Many Malicious Functions in Worm
- Discover how the #VPNFilter #malware works and affects users
- Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
- FBI IC3 warns of cyber attacks exploiting Remote Desktop Protocol (RDP)
- Alphabet's Chronicle has given #VirusTotal a makeover. Find out what's in the new VirusTotal Enterprise offering. By @RobWright22
- Improving core processes with next-generation mobile productivity solutions can bring power and cost efficiency gains. However, we must not lose
- Malware in the Cloud: What You Need to Know
- Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware
- Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from
- Cisco Multiple Security Vulnerabilities Alert
- Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files
- A Top Facebook Bug Bounty Hunter Shares Their Insights on the Facebook Breach
CRIME
- Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
- Cryptomining Malware Grows by 86% in Q2: McAfee Report
- Security Affairs newsletter Round 182 – News of the week
- Xbash Malware Combines Many Malicious Functions in Worm
- Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware
POLITICS
- Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from
TRANSNATIONAL / UNKNOWN
Nothing to report
CHINA
- Long Term Security Attitudes and Practices Study
- CLOUDFLARE announces a domain name registration service, Cloudflare Registrar
INDIA
Nothing to report
NORTH KOREA
Nothing to report
PAKISTAN
Nothing to report
VIETNAM
Nothing to report
IRAN
Nothing to report
LEBANON
Nothing to report
PALESTINE
Nothing to report
SAUDI ARABIA
Nothing to report
UNITED ARAB EMIRATES
Nothing to report
RUSSIA
- Seven additional modules make Fancy Bear’s VPNFilter malware even more versatile
UKRAINE
Nothing to report
ASIA
- India’s Banking Cybersecurity Woes
WORLD
- Long Term Security Attitudes and Practices Study
- Torii botnet, probably the most sophisticated IoT botnet of ever
- UK Conservative Party conference app leaks MPs' personal details
- CLOUDFLARE announces a domain name registration service, Cloudflare Registrar
ATTACKS
- Telegram fixes IP address leak in desktop client
- Torii botnet, probably the most sophisticated IoT botnet of ever
- UK Conservative Party conference app leaks MPs' personal details
- Chegg Forces Password Reset On 40 Million Users
- Telegram Leaks IP Addresses by Default When Initiating Calls
- Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
- Trustwave expert found 2 credential leak issues in Windows PureVPN Client
- Torii malware could be gateway to more sophisticated IoT botnet attacks
- Hide and seek Iot botnet updates include new Android ADB exploit
- Android password managers not as secure as desktop counterparts
- Facebook Discloses Data Breach, 50 Million Accounts Affected
- Facebook data breach: 50 million users affected
- The @UN accidentally exposed credentials on public @trello boards. Plus, #Uber is set to pay $148 million settlement following its
- #Facebook Discloses Data Breach, 50 Million User Accounts Affected https://tripwire.me/2NQrPfW via@ritzsanti
THREATS
- Telegram fixes IP address leak in desktop client
- Linux Kernel Bug Surfaces, Allowing Root Access
- Telegram Leaks IP Addresses by Default When Initiating Calls
- Malicious Hackers Increasing the Exploitation of RDP Protocol to Hack the Targeted Victims
- Defeating Polymorphic Malware with Cognitive Intelligence. Part 2: Command Line Argument Clustering
- Pirated Game of Thrones episodes most popular TV bait for malware
- Seven additional modules make Fancy Bear’s VPNFilter malware even more versatile
- Can monitoring help defend against #Sanny #malware update?
- Torii malware could be gateway to more sophisticated IoT botnet attacks
- VirusTotal slips on biz suit, says Google's daddy will help the search for nasties
- Ransomware Crypto-Locks Port of San Diego IT Systems
- Hide and seek Iot botnet updates include new Android ADB exploit
- Google Project Zero Disclosed PoC & Exploit for Serious Linux Kernel Vulnerability
- Port of San Diego Suffers Ransomware Attack
- How a vulnerability in #strongSwan caused a buffer underflow
- Beware!! New Android Malware That Can Read Your WhatsApp Messages & Take Screen Shots
- Malware in the Cloud: What You Need to Know
- Vulnerability discovered in WiFi routers
- Pirated episodes of Game of Thrones, the most popular malware bait
- CLOUDFLARE announces a domain name registration service, Cloudflare Registrar
- Hackers Exploited Facebook Zero-Day Flaw & Stolen 50 Million Accounts Access Tokens
- Tripwire Patch Priority Index for September 2018
- Port of San Diego Suffers Ransomware Attack
- Alphabet's @chroniclesec unveiled #VirusTotal Enterprise, a new version of the file scanning service designed specifically for enterprise customers. By @RobWright22
CRIME
- India’s Banking Cybersecurity Woes
- Ransomware Crypto-Locks Port of San Diego IT Systems
- Vulnerability discovered in WiFi routers
POLITICS
Nothing to report
DATA BREACH
- Facebook leaks data (including private conversations) from 50 million accounts
- Facebook leaks data (including private conversations) from 50 million accounts
- Facebook hacked – 50 Million Users’ Data exposed in the security breach
- Big Facebook data breach: 50 million accounts affected
- Facebook Data Breach Impacts Almost 50 Million Accounts
- Vulnerabilities in PureVPN Client Leak User Credentials
- New Phishing Campaign Targets US Employees' Online Payrolls
- 3 GOP senators doxed during Kavanaugh hearing
- Chegg Resets Passwords After Data Breach That Affected 40 Million Users
- Facebook Discloses Data Breach, 50 Million User Accounts Affected
- United Nations data found exposed on web: researcher
- Magecart campaign remains active
- “Firefox Monitor” will allow users to check whether their personal information and passwords have been part of a data breach
- Bupa fined £175,000 for 2017 data breach affecting 547,000 customers
- The @ironscales #whitepaper explores how modern #phishing techniques, such as business email compromise (#BEC), #ransomware, spear-phishing and advanced persistent threats
- United Nations data found exposed on web: researcher
- How can live chat widgets leak personal employee data?
- Chegg Data Breach Affects 40 Million Customers
DENIAL-OF-SERVICE
- 7 new modules for VPNFilter malware, Hide & Seek botnet targets Android, and house oversight takes on AI | Avast
- Torii malware could be gateway to more sophisticated IoT botnet attacks
- Meet Torii, a Stealthy, Versatile and Highly Persistent IoT Botnet
- Hide 'N Seek IoT Botnet Now Targets Android Devices
- Who’s behind DDoS attacks at UK universities?
- Stealthy and Persistent Torii IoT Botnet Infects Devices via Telnet
- Meet Torii, a new IoT botnet far more sophisticated than Mirai variants
- New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai
- Phorpiex bots target remote access servers to deliver ransomware
- New Iot Botnet Torii Uses Six Methods for Persistence, Has No Clear Purpose
- New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai
MALVERTISING
Nothing to report
PHISHING
- Aspire Health, Another Healthcare Firm as a Phishing Victim
- New Phishing Campaign Targets US Employees' Online Payrolls
- Learn how our @PhishingAI successfully detected a custom #phishing kit targeted at the DNC last month:
- Chegg forces password reset on 40 million users
- SHEIN breach exposes emails, encrypted passwords of 6.42M customers
- Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
- Android App Verification Issues Pave Way For Phishing Attacks
- Facebook Resets 90 Million User Passwords as Flaw is Discovered
- Facebook Resets 90 Million User Passwords as Flaw is Discovered
- Chegg Resets Passwords After Data Breach That Affected 40 Million Users
- Android password managers vulnerable to phishing apps
- “Firefox Monitor” will allow users to check whether their personal information and passwords have been part of a data breach
- The @ironscales #whitepaper explores how modern #phishing techniques, such as business email compromise (#BEC), #ransomware, spear-phishing and advanced persistent threats
- Power to the people! Google backtracks (a bit) on forced Chrome logins
- Microsoft is trying to kill passwords in Azure AD application
- Android password managers not as secure as desktop counterparts
- 7 Most Prevalent Phishing Subject Lines
WEB DEFACEMENT
Nothing to report
MALWARE
- Port of San Diego suffers ransomware attack | Avast
- Port of San Diego suffers ransomware attack | Avast
- Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
- Zoho Was Blacklisted by Domain Registrar TierraNet
- The Week in Ransomware - September 28th 2018 - RDP and gandCrab
- 7 new modules for VPNFilter malware, Hide & Seek botnet targets Android, and house oversight takes on AI | Avast
- 'Torii' Breaks New Ground For IoT Malware
- Port of San Diego, The Newest Victim of Ransomware Attack
- Powerful Ransomware Attack Hit on Port of San Diego
- Torii malware could be gateway to more sophisticated IoT botnet attacks
- Docs reveal how Fruitfly Mac spyware initially spread
- Fancy Bear’s Lojax is First UEFI Rootkit in the Wild
- FBI solves mystery surrounding 15-year-old Fruitfly Mac malware
- USB malware and cryptominers are threat to emerging markets
- Potential Misuse of Legitimate Websites to Avoid Malware Detection
- Port of San Diego Suffers Ransomware Attack
- Delphi Packer Increasingly Used to Evade Malware Classification
- QRecorder app in the Play Store was hiding a Banking Trojan that targets European banks
- The @ironscales #whitepaper explores how modern #phishing techniques, such as business email compromise (#BEC), #ransomware, spear-phishing and advanced persistent threats
- Port of San Diego Hit by Ransomware
- Fancy Bear Attacks Governments Using LoJax UEFI Rootkit
- Windows 10 security: Here's how we're hitting back at fileless malware, says Microsoft
- Resident evil: Inside a UEFI rootkit used to spy on govts, made by you-know-who (hi, Russia)
- Sunny Cali goes ballistic, this ransomware is atrocious. Even our IT bill will be something quite ferocious
- Fancy Bear still Putin out new modules for VPNFilter malware
- How Data Security Improves When You Engage Employees in the Process
- Users Clicking Through Warnings, Leading to RAT Infections
- Google Play Store Swarmed with Malware
- Phorpiex bots target remote access servers to deliver ransomware
- Port of San Diego Suffers Ransomware Attack
- ICS Cybersecurity: Visibility, Protective Controls & Continuous Monitoring
- ICS Cybersecurity: Visibility, Protective Controls & Continuous Monitoring
EXPLOIT
- Tripwire Patch Priority Index for September 2018
- IC3 Alerts of Increasing Danger of RDP Exploitation Attacks
- Google Hacker Discloses New Linux Kernel Vulnerability and PoC Exploit
VULNERABILITY
- CVE-2018-11776 RCE Flaw in Apache Struts Could Be Root Cause of Clamorous Hacks
- Critical Security Vulnerability in Facebook Affects 50 million Users!
- Facebook Security Bug Affects 90M Users
- [SingCERT] Alert on 14 High-Severity Vulnerabilities in Cisco Products
- Another Linux Kernel Bug Surfaces, Allowing Root Access
- Vulnerabilities in PureVPN Client Leak User Credentials
- FBI IC3 Warns of RDP Vulnerability
- Facebook Vulnerability Affecting 50 Million Users Allowed Account Takeover
- Facebook Resets 90 Million User Passwords as Flaw is Discovered
- Facebook Resets 90 Million User Passwords as Flaw is Discovered
- Hackers Stole 50 Million Facebook Users' Access Tokens Using Zero-Day Flaw
- Researchers: 11-Year-Old Flaw in Vote Scanner Still Unfixed
- Facebook: 50 million accounts impacted by security flaw
- 'Mutagen Astronomy' Linux kernel vulnerability sighted
- SECURITY UPDATE: Facebook said a breach affected 50 million people on the social network.
The vulnerability stemmed from Facebook's "View As"
- Connected car cyber-security getting better, fewer critical vulnerabilities found
- No Patches for Critical Flaws in Fuji Electric Servo System, Drives
- CVE-2018-1718 -Google Project Zero reports a new Linux Kernel flaw
- Vulnerabilities and architectural considerations in industrial control systems
- Google Project Zero Discloses New Linux Kernel Flaw
- Google Hacker Discloses New Linux Kernel Vulnerability and PoC Exploit
- Tripwire Patch Priority Index for September 2018