Oct 3, 2018

Daily brief for 2018-10-02

ASIA

  1. Case involving 'AlfabetoVirtual' website defacements ends in guilty plea
  2. Researchers Link New NOKKI Malware to North Korean Actor
  3. TA18-275A: HIDDEN COBRA – FASTCash Campaign
  4. Nielsen warns of Chinese influence campaign, but not with midterms
  5. Report: Zoho's domain regularly exploited to move keylogger data
  6. A Staggering Amount of Stolen Data is Heading to Zoho Domains
  7. Hackers use malicious content delivery system to target iOS device

WORLD

  1. Case involving 'AlfabetoVirtual' website defacements ends in guilty plea
  2. Canadian restaurant chain suffers country-wide outage after malware outbreak
  3. Torii botnet, probably the most sophisticated IoT botnet of ever
  4. DanaBot Observed in Large Campaign Targeting U.S. Organizations
  5. California Governor Signs Bill Requiring Bots to Disclose Their True Identity
  6. AR18-275A: MAR-10201537 – HIDDEN COBRA FASTCash-Related Malware
  7. Ignite 2018 highlights: passwordless sign-in, confidential computing, new threat protection, and more
  8. TA18-275A: HIDDEN COBRA – FASTCash Campaign
  9. Danabot Banking Malware Now Targeting Banks in the U.S.
  10. Ransomware attacks via RDP on the rise | Avast
  11. World Cup may have distracted malware hackers
  12. Microsoft Detection Tools Sniff Out Fileless Malware
  13. Gwinnett Medical Center investigating possible data breach
  14. Rep. Speier: Congress needs a hack demo to understand election vulnerabilities
  15. Fortnite gamers targeted by data theft malware
  16. Nielsen warns of Chinese influence campaign, but not with midterms
  17. DanaBot Observed in Large Campaign Targeting U.S. Organizations
  18. Cyber Threat Landscape: How it’s Evolving & How to Respond
  19. UK Conservative Party Conference dedicated app leaks attendee data
  20. New Type of Malware Developed by Russian Hackers Eludes Discovery
  21. #DanaBot Gains Popularity and Targets US Organizations in Large Campaigns. http://ow.ly/mJza50jiHdI via the Threat Insight research
  22. Sites that use Facebook login could be affected by hack
  23. Facebook may be fined up to $1.63 billion due to data breach

ATTACKS

  1. Cyber criminals using lookalike online shopping domains to phish buyers
  2. Nearly 50% of businesses have yet to take control of password security - report
  3. Case involving 'AlfabetoVirtual' website defacements ends in guilty plea
  4. Sophisticated Voice Phishing Scams
  5. Torii botnet, probably the most sophisticated IoT botnet of ever
  6. DanaBot Observed in Large Campaign Targeting U.S. Organizations
  7. California Governor Signs Bill Requiring Bots to Disclose Their True Identity
  8. Financial Sector Data Breaches Soar Despite Heavy Security Spending
  9. WifiPhisher – WiFi Crack and Phishing Framework
  10. Ignite 2018 highlights: passwordless sign-in, confidential computing, new threat protection, and more
  11. Hackers can use Microsoft Sway to carry out phishing attacks 'without fear of detection'
  12. TA18-275A: HIDDEN COBRA – FASTCash Campaign
  13. Hacker 'AlfabetoVirtual' Pleads Guilty to NYC Comptroller, West Point Website Defacements
  14. Gwinnett Medical Center investigating possible data breach
  15. Fortnite gamers targeted by data theft malware
  16. Nielsen warns of Chinese influence campaign, but not with midterms
  17. Apollo Data Breach Leads To More Than 200 Million Contact Records Stolen
  18. ThreatList: Password Hygiene Remains Lackluster in Global Businesses
  19. The @UN accidentally exposed credentials on public @trello boards. Plus, #Uber is set to pay $148 million settlement following its
  20. Boffins Tricks Password Protection Using Imposter Apps
  21. DanaBot Observed in Large Campaign Targeting U.S. Organizations
  22. Strengthen your security with Avast password generator | Avast
  23. UK Conservative Party Conference dedicated app leaks attendee data
  24. Researchers use Android password managers to make phishing attacks more practical
  25. Breaking bank security: Record theft rises to new heights
  26. Facebook could face $1.63bn fine under GDPR over latest data breach
  27. How #livechatsoftware leaked
  28. UN Sensitive Information Exposed Publicly Due to Neglected Security Settings
  29. #DanaBot Gains Popularity and Targets US Organizations in Large Campaigns. http://ow.ly/mJza50jiHdI via the Threat Insight research
  30. Vulnerable Android password managers make phishing attacks easier
  31. Facebook Hacked: 50 Million Users' Data Exposed
  32. True password behaviors in the workplace revealed
  33. Rarely a week goes by without reports of a large and damaging #DDoS attack against a major business. Techniques are
  34. #SecurityNews: #Tory App Snafu exposes Ministers’ personal info including phone numbers and other personal details of Cabinet ministers, as the
  35. Torii Botnet – A New Sophisticated IoT Botnet Attack in Wide – More Powerful Than Mirai
  36. Telegram vulnerability causes IP address leaking
  37. Sites that use Facebook login could be affected by hack
  38. Facebook may be fined up to $1.63 billion due to data breach
  39. Wait, this isn't The Onion... "FBI fitness app asks users to agree to 'all of their activities monitored and recorded'"
  40. ​NZ customs can now demand phone or laptop passwords
  41. Stop DDoS Attacks In 10 Seconds – Organization’s Most Important Consideration for DDOS Attack Mitigation
  42. When you need to make a new #Password, what do you do? The easiest and most secure way is to
  43. #Video: Bringing all of your #data together under a single management portfolio, under a single #database, allows your organization to
  44. At #MSIgnite, @Microsoft declared "an end to era of passwords" with an update to its Authenticator app, which will allow
  45. Torii malware could be gateway to more sophisticated IoT botnet attacks

THREATS

  1. Cyber criminals using lookalike online shopping domains to phish buyers
  2. PDF patch time: fixes land for over 100 flaws in Adobe's and Foxit's PDF software
  3. Canadian restaurant chain suffers country-wide outage after malware outbreak
  4. Foxit PDF Reader Fixes High-Severity Remote Code Execution Flaws
  5. Foxit Reader 9.3 addresses 118 Vulnerabilities, 18 of them rated as critical
  6. Researchers Link New NOKKI Malware to North Korean Actor
  7. NOKKI Malware Sports Mysterious Link to Reaper APT Group
  8. Malware 101: The Malware Tools That Attackers Use
  9. Following a Trail of Confusion: PowerShell in Malicious Office Documents
  10. Google taking new steps to prevent malicious Chrome extensions
  11. Google Patches Critical Vulnerabilities in Android OS
  12. AR18-275A: MAR-10201537 – HIDDEN COBRA FASTCash-Related Malware
  13. Vulnerability Spotlight: Adobe Acrobat Reader DC Collab reviewServer Remote Code Execution Vulnerability
  14. Enabling Enterprise-Grade Hybrid Cloud Data Processing with SAP and Cisco – Part 2
  15. Foxit Reader Update Patches Over 100 Vulnerabilities
  16. A remote access #Trojan -- dubbed #GravityRAT -- was discovered by Cisco Talos (@TalosSecurity) to be checking for #antimalware sandboxes.
  17. Danabot Banking Malware Now Targeting Banks in the U.S.
  18. Dogcall Rat links NOKKI malware with Reaper group - indicators provided
  19. The MITRE ATT&CK Framework: Command and Control
  20. Ransomware attacks via RDP on the rise | Avast
  21. Use Windows, macOS? Don’t be hacked by PDF, patch these critical Adobe flaws now
  22. Keyloggers Turn to Zoho Office Suite in Droves for Data Exfiltration
  23. Keyloggers Turn to Zoho Office Suite in Droves for Data Exfiltration
  24. World Cup may have distracted malware hackers
  25. New study finds 5 of every 6 routers are inadequately updated for security flaws
  26. Microsoft Detection Tools Sniff Out Fileless Malware
  27. .@FBI, @DHSgov call on users to mitigate #RemoteDesktop Protocol vulnerabilities and handle RDP exploits on their own, even as the
  28. Adobe Releases Updates For 85 PDF Related CVEs
  29. Nine NAS Bugs Open LenovoEMC, Iomega Devices To Attack
  30. Rep. Speier: Congress needs a hack demo to understand election vulnerabilities
  31. Google Cracks Down on Malicious Chrome Extensions in Major Update
  32. Cisco Talos discloses serious vulnerabilities in Foxit PDF Reader
  33. Fortnite gamers targeted by data theft malware
  34. Windows Defender exclusions reek of malware
  35. DanaBot Observed in Large Campaign Targeting U.S. Organizations
  36. Report: Zoho's domain regularly exploited to move keylogger data
  37. A Staggering Amount of Stolen Data is Heading to Zoho Domains
  38. AV-TEST Rates Check Point’s SandBlast Agent as a Top Product in Corporate Endpoint Protection
  39. Adobe fixes 47 critical flaws in Acrobat and Reader
  40. 86 Vulnerabilities Fixed with Adobe Security Updates for Adobe Acrobat and Reader
  41. Malware Less Common in Q2, Still Top Attack Method
  42. Malware Less Common in Q2, Still Top Attack Method
  43. Alphabet's @chroniclesec unveiled #VirusTotal Enterprise, a new version of the file scanning service designed specifically for enterprise customers. By @RobWright22
  44. Fruitfly Mac malware creator used it to spy on minors; FBI discloses technique
  45. Use Windows, macOS? Don't be hacked by PDF, patch these critical Adobe flaws now
  46. CVE-2018-8373: Hackers’ best partner to spread Trojans
  47. Man-in-the-middle attacks allow hackers to intercept, send and receive data to and from your device undetected until the transaction is
  48. Desktop Telegram users showing off not only their silly selfies but also their IP addresses
  49. Facebook Breach: Attackers Exploited Privacy Feature
  50. New Type of Malware Developed by Russian Hackers Eludes Discovery
  51. The Army is working toward a cyber domain doctrine
  52. Vulnerability Spotlight: Adobe Acrobat Reader DC Collab reviewServer Remote Code Execution Vulnerability
  53. The MITRE ATT&CK Framework: Command and Control
  54. SQL injection explained: How these attacks work and how to prevent them
  55. Improving #mobilesecurity programs to detect
  56. Adobe Patches 86 Vulnerabilities in Acrobat Products
  57. Adobe security updates for Acrobat fix 86 Vulnerabilities, 46 rated as critical
  58. A group of #malware was discovered targeting public SSH servers. However, certain #IPaddresses are avoided. Discover how this is possible
  59. Telegram vulnerability causes IP address leaking
  60. Security Update for Foxit PDF Reader Fixes 118 Vulnerabilities
  61. Hackers use malicious content delivery system to target iOS device
  62. Adobe Releases Security Updates for Acrobat that Fix 86 Vulnerabilities
  63. Torii malware could be gateway to more sophisticated IoT botnet attacks

CRIME

  1. Case involving 'AlfabetoVirtual' website defacements ends in guilty plea
  2. DanaBot Observed in Large Campaign Targeting U.S. Organizations
  3. Google taking new steps to prevent malicious Chrome extensions
  4. TA18-275A: HIDDEN COBRA – FASTCash Campaign
  5. Danabot Banking Malware Now Targeting Banks in the U.S.
  6. Hacker 'AlfabetoVirtual' Pleads Guilty to NYC Comptroller, West Point Website Defacements
  7. World Cup may have distracted malware hackers
  8. Fortnite gamers targeted by data theft malware
  9. DanaBot Observed in Large Campaign Targeting U.S. Organizations
  10. Cyber Threat Landscape: How it’s Evolving & How to Respond
  11. Strengthen your security with Avast password generator | Avast
  12. Report: Zoho's domain regularly exploited to move keylogger data
  13. A Staggering Amount of Stolen Data is Heading to Zoho Domains
  14. Breaking bank security: Record theft rises to new heights
  15. Fruitfly Mac malware creator used it to spy on minors; FBI discloses technique

POLITICS

  1. Case involving 'AlfabetoVirtual' website defacements ends in guilty plea
  2. Ignite 2018 highlights: passwordless sign-in, confidential computing, new threat protection, and more
  3. Rep. Speier: Congress needs a hack demo to understand election vulnerabilities
  4. Fruitfly Mac malware creator used it to spy on minors; FBI discloses technique
  5. UN Sensitive Information Exposed Publicly Due to Neglected Security Settings

Oct 2, 2018

APT report for 2018-10-01

TRANSNATIONAL / UNKNOWN

  1. A week in security (September 24 – 30)
  2. Formjacking in the Nutshell

CHINA

  1. Cyber Security Roundup for September 2018

INDIA

Nothing to report

NORTH KOREA

  1. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  2. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  3. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  4. A new Browser Reaper exploit can crash or freeze Mozilla #Firefox, according to a proof of concept published by a
  5. Report Ties North Korean Attacks to New Malware, Linked by Word Macros

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  2. A week in security (September 24 – 30)
  3. LoJax: Fisrt UEFI Rootkit Found In The Wild

UKRAINE

Nothing to report

Platform report for 2018-10-01

WINDOWS

  1. Cyber Security Roundup for September 2018
  2. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  3. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  4. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  5. GandCrab ransomware is spreading wildly through several known vulnerabilities
  6. Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
  7. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls

LINUX

  1. A week in security (September 24 – 30)
  2. Nasty Linux Kernel Vulnerability Discovered, Mandatory Kernel Update Required
  3. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls

UNIX

Nothing to report

ANDROID

  1. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  2. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  3. Malwarebytes is a champion of National Cybersecurity Awareness Month
  4. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  5. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  6. Nasty Linux Kernel Vulnerability Discovered, Mandatory Kernel Update Required
  7. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls

IOS

  1. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  2. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  3. A week in security (September 24 – 30)
  4. Voice Phishing Scams Are Getting More Clever
  5. Malwarebytes is a champion of National Cybersecurity Awareness Month
  6. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system

MACOS

  1. Google Bug Breaks Search Results with a Plus Sign On Mac Safari
  2. A week in security (September 24 – 30)

Threat report for 2018-10-01

DATA BREACH

  1. 100K Routers Hijacked for Phishing in GhostDNS Campaign
  2. Picture-in-Picture Phishing Campaign Goes After Steam Credentials
  3. 4 Ways to Protect Your Files from a Data Breach
  4. Facebook hacked – 50 Million Users’ Data exposed in the security breach
  5. Telegram Patched IP Address Leak Problem In Its Desktop Client
  6. Telegram Leaks User IP Addresses
  7. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  8. Flaws in Tory party conference app leak ministers' personal information
  9. Facebook faces a whopping €1.4 billion penalty under GDPR for Sept. 30 data breach
  10. Phishing campaign targets developers of Chrome extensions
  11. 3 GOP senators doxed during Kavanaugh hearing
  12. Facebook Data Breach Extended to Third-Party Applications
  13. Facebook could face up to $1.6bn fine for data breach
  14. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls
  15. Telegram Calling Feature Leaks Your IP Addresses—Patch Released
  16. High-Profile Instagram Accounts Hacked For Ransom In A Recent Campaign

DENIAL-OF-SERVICE

  1. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  2. Instagram Being Used To Sell Botnets And Stolen Fortnite Accounts
  3. Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
  4. Torii malware could be gateway to more sophisticated IoT botnet attacks
  5. New vicious Torii IoT botnet discovered
  6. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  7. Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
  8. Torii IoT Botnet Takes Mirai to the Next Level

MALVERTISING

Nothing to report

PHISHING

  1. 100K Routers Hijacked for Phishing in GhostDNS Campaign
  2. Picture-in-Picture Phishing Campaign Goes After Steam Credentials
  3. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  4. Weak Passwords Abused for 'FruitFly' Mac Malware Distribution
  5. Third-Party Apps Using Facebook Login Also Affected by Latest Hacking Incident
  6. How to Orchestrate a Smarter Phishing Response
  7. Voice Phishing Scams Are Getting More Clever
  8. Why nearly 50% of organizations are failing at password security
  9. Employees Share Average of 6 Passwords With Co-Workers
  10. UK firms’ password security score ‘average’
  11. Phishing campaign targets developers of Chrome extensions
  12. Password Security Better, Still Poses Business Risk
  13. Password Security Better, Still Poses Business Risk
  14. Following a loud critical backlash to a new #Chrome login feature and cookie retention functionality, @Google will make changes in

WEB DEFACEMENT

Nothing to report

MALWARE

  1. Top Cloud Domain Controller for MSPs
  2. Multiple Code Execution Vulnerabilities Found in Atlantis Word Processor
  3. GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
  4. GrandCrab Ransomware Spreads Using Multiple Known Vulnerabilities
  5. Fileless Malware Attacks on the Rise, Microsoft Says
  6. 'Short, Brutal Lives': Life Expectancy for Malicious Domains
  7. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  8. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  9. Google Adds New Rules To End Malicious Chrome Extensions
  10. Code Execution Vulnerabilities Uncovered In Atlantis Word Processor
  11. Deep Dive Into iTranslator - MITM Malware
  12. LoJax: Fisrt UEFI Rootkit Found In The Wild
  13. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  14. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  15. Telegram Patched IP Address Leak Problem In Its Desktop Client
  16. Weak Passwords Abused for 'FruitFly' Mac Malware Distribution
  17. Code execution vulnerabilities uncovered in Atlantis Word Processor
  18. Malwarebytes is a champion of National Cybersecurity Awareness Month
  19. Monitor privileged execution to defend against
  20. Telegram Leaks User IP Addresses
  21. Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
  22. TrickBot Banking Trojan Takes Center Stage in 2018
  23. More on the Five Eyes Statement on Encryption and Backdoors
  24. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  25. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  26. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  27. GandCrab ransomware is spreading wildly through several known vulnerabilities
  28. Docs reveal how Fruitfly Mac spyware initially spread
  29. Torii malware could be gateway to more sophisticated IoT botnet attacks
  30. SamSam ransomware: How is this version different from others?
  31. Ransomware Casts Anchor at the Port of San Diego
  32. Hackers Hijacked More Than 100,000 Routers DNS Settings and Redirecting Users to Malicious WebSites
  33. Ransomware Casts Anchor at the Port of San Diego
  34. #VPNFilter #malware: How can users protect themselves?
  35. Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
  36. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls
  37. Telegram Calling Feature Leaks Your IP Addresses—Patch Released
  38. New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

EXPLOIT

  1. A new Browser Reaper exploit can crash or freeze Mozilla #Firefox, according to a proof of concept published by a
  2. Python-based attack tools are the most common vector for launching exploit attempts
  3. Several Bugs Exploited in Massive Facebook Hack
  4. Sophos recently discovered a #Samsam extortion code that performs whole-company attacks through a variety of vulnerability exploits. Discover how this
  5. How can attackers exploit a buffer underflow #vulnerability?
  6. New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

VULNERABILITY

  1. Adobe Patches 47 Critical Flaws in Acrobat and DC
  2. Multiple Code Execution Vulnerabilities Found in Atlantis Word Processor
  3. CVE-2018-11776 and why you need Black Duck Security Advisories
  4. Nine NAS Bugs Open LenovoEMC, Iomega Devices to Attack
  5. GrandCrab Ransomware Spreads Using Multiple Known Vulnerabilities
  6. Google Bug Breaks Search Results with a Plus Sign On Mac Safari
  7. Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
  8. Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
  9. Code Execution Vulnerabilities Uncovered In Atlantis Word Processor
  10. Facebook: How to minimize the risk of vulnerabilities
  11. Code execution vulnerabilities uncovered in Atlantis Word Processor
  12. Attackers chained three bugs to breach into the Facebook platform
  13. Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
  14. Monero fixes major ‘burning bug’ flaw, preventing mass devaluation
  15. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  16. Flaws in Tory party conference app leak ministers' personal information
  17. Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
  18. GandCrab ransomware is spreading wildly through several known vulnerabilities
  19. Several Bugs Exploited in Massive Facebook Hack
  20. Sophos recently discovered a #Samsam extortion code that performs whole-company attacks through a variety of vulnerability exploits. Discover how this
  21. Nasty Linux Kernel Vulnerability Discovered, Mandatory Kernel Update Required
  22. How can attackers exploit a buffer underflow #vulnerability?
  23. CISO @rickhholland joins @drshellface and @mazzazone to discuss the latest #cybersecurity news: Security Flaws Affect 50 Million Facebook Accounts and
  24. Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
  25. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls

Region brief for 2018-10-01

ASIA

  1. Cyber Security Roundup for September 2018
  2. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  3. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  4. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  5. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  6. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  7. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  8. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  9. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  10. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers

OCEANIA

  1. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  2. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

NORTH AMERICA

  1. Cyber Security Roundup for September 2018
  2. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  3. GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
  4. A week in security (September 24 – 30)
  5. 4 Ways to Protect Your Files from a Data Breach
  6. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  7. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  8. Voice Phishing Scams Are Getting More Clever
  9. Malwarebytes is a champion of National Cybersecurity Awareness Month
  10. Formjacking in the Nutshell
  11. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  12. CISO @rickhholland joins @drshellface and @mazzazone to discuss the latest #cybersecurity news: Security Flaws Affect 50 Million Facebook Accounts and

SOUTH AMERICA

  1. GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
  2. 4 Ways to Protect Your Files from a Data Breach
  3. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  4. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  5. Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
  6. New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

EUROPE

  1. Cyber Security Roundup for September 2018
  2. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  3. Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
  4. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  5. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  6. Facebook: How to minimize the risk of vulnerabilities
  7. Voice Phishing Scams Are Getting More Clever
  8. Formjacking in the Nutshell
  9. TrickBot Banking Trojan Takes Center Stage in 2018
  10. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  11. Facebook faces a whopping €1.4 billion penalty under GDPR for Sept. 30 data breach
  12. UK firms’ password security score ‘average’

AFRICA

  1. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  2. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

Sector brief for 2018-10-01

HEALTHCARE

  1. Malwarebytes is a champion of National Cybersecurity Awareness Month

TRANSPORT

  1. Cyber Security Roundup for September 2018
  2. A week in security (September 24 – 30)
  3. Ransomware Casts Anchor at the Port of San Diego
  4. Ransomware Casts Anchor at the Port of San Diego

BANKING & FINANCE

  1. Cyber Security Roundup for September 2018
  2. GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
  3. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  4. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  5. A week in security (September 24 – 30)
  6. 4 Ways to Protect Your Files from a Data Breach
  7. Facebook: How to minimize the risk of vulnerabilities
  8. Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
  9. Voice Phishing Scams Are Getting More Clever
  10. Malwarebytes is a champion of National Cybersecurity Awareness Month
  11. Formjacking in the Nutshell
  12. Attackers chained three bugs to breach into the Facebook platform
  13. TrickBot Banking Trojan Takes Center Stage in 2018
  14. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  15. Hackers Hijacked More Than 100,000 Routers DNS Settings and Redirecting Users to Malicious WebSites
  16. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  17. Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
  18. New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

INFORMATION & TELECOMMUNICATION

  1. Cyber Security Roundup for September 2018
  2. Top Cloud Domain Controller for MSPs
  3. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  4. GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
  5. Fileless Malware Attacks on the Rise, Microsoft Says
  6. Google Bug Breaks Search Results with a Plus Sign On Mac Safari
  7. A week in security (September 24 – 30)
  8. Google Adds New Rules To End Malicious Chrome Extensions
  9. Facebook hacked – 50 Million Users’ Data exposed in the security breach
  10. Instagram Being Used To Sell Botnets And Stolen Fortnite Accounts
  11. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  12. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  13. Facebook: How to minimize the risk of vulnerabilities
  14. Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
  15. Third-Party Apps Using Facebook Login Also Affected by Latest Hacking Incident
  16. Voice Phishing Scams Are Getting More Clever
  17. Attackers chained three bugs to breach into the Facebook platform
  18. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  19. Facebook faces a whopping €1.4 billion penalty under GDPR for Sept. 30 data breach
  20. Ransomware Casts Anchor at the Port of San Diego
  21. Ransomware Casts Anchor at the Port of San Diego
  22. Password Security Better, Still Poses Business Risk
  23. Several Bugs Exploited in Massive Facebook Hack
  24. Password Security Better, Still Poses Business Risk
  25. Facebook Data Breach Extended to Third-Party Applications
  26. Nasty Linux Kernel Vulnerability Discovered, Mandatory Kernel Update Required
  27. CISO @rickhholland joins @drshellface and @mazzazone to discuss the latest #cybersecurity news: Security Flaws Affect 50 Million Facebook Accounts and
  28. Following a loud critical backlash to a new #Chrome login feature and cookie retention functionality, @Google will make changes in
  29. Facebook could face up to $1.6bn fine for data breach
  30. Torii IoT Botnet Takes Mirai to the Next Level

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

  1. GrandCrab Ransomware Spreads Using Multiple Known Vulnerabilities
  2. Malwarebytes is a champion of National Cybersecurity Awareness Month

GOVERNMENT & PUBLIC SERVICE

  1. Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
  2. Malwarebytes is a champion of National Cybersecurity Awareness Month

Daily brief for 2018-10-01

ASIA

  1. Cyber Security Roundup for September 2018
  2. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  3. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  4. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  5. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  6. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  7. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  8. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  9. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  10. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers

WORLD

  1. Cyber Security Roundup for September 2018
  2. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  3. GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
  4. A week in security (September 24 – 30)
  5. 4 Ways to Protect Your Files from a Data Breach
  6. Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
  7. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  8. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  9. Facebook: How to minimize the risk of vulnerabilities
  10. Voice Phishing Scams Are Getting More Clever
  11. Malwarebytes is a champion of National Cybersecurity Awareness Month
  12. Formjacking in the Nutshell
  13. TrickBot Banking Trojan Takes Center Stage in 2018
  14. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  15. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  16. Facebook faces a whopping €1.4 billion penalty under GDPR for Sept. 30 data breach
  17. UK firms’ password security score ‘average’
  18. CISO @rickhholland joins @drshellface and @mazzazone to discuss the latest #cybersecurity news: Security Flaws Affect 50 Million Facebook Accounts and
  19. Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
  20. New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

ATTACKS

  1. 100K Routers Hijacked for Phishing in GhostDNS Campaign
  2. Picture-in-Picture Phishing Campaign Goes After Steam Credentials
  3. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  4. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  5. 4 Ways to Protect Your Files from a Data Breach
  6. Facebook hacked – 50 Million Users’ Data exposed in the security breach
  7. Instagram Being Used To Sell Botnets And Stolen Fortnite Accounts
  8. Telegram Patched IP Address Leak Problem In Its Desktop Client
  9. Weak Passwords Abused for 'FruitFly' Mac Malware Distribution
  10. Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
  11. Third-Party Apps Using Facebook Login Also Affected by Latest Hacking Incident
  12. How to Orchestrate a Smarter Phishing Response
  13. Voice Phishing Scams Are Getting More Clever
  14. Why nearly 50% of organizations are failing at password security
  15. Employees Share Average of 6 Passwords With Co-Workers
  16. Telegram Leaks User IP Addresses
  17. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  18. Flaws in Tory party conference app leak ministers' personal information
  19. Facebook faces a whopping €1.4 billion penalty under GDPR for Sept. 30 data breach
  20. UK firms’ password security score ‘average’
  21. Torii malware could be gateway to more sophisticated IoT botnet attacks
  22. Phishing campaign targets developers of Chrome extensions
  23. Password Security Better, Still Poses Business Risk
  24. New vicious Torii IoT botnet discovered
  25. Password Security Better, Still Poses Business Risk
  26. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  27. 3 GOP senators doxed during Kavanaugh hearing
  28. Facebook Data Breach Extended to Third-Party Applications
  29. Following a loud critical backlash to a new #Chrome login feature and cookie retention functionality, @Google will make changes in
  30. Facebook could face up to $1.6bn fine for data breach
  31. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls
  32. Telegram Calling Feature Leaks Your IP Addresses—Patch Released
  33. Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks
  34. Torii IoT Botnet Takes Mirai to the Next Level
  35. High-Profile Instagram Accounts Hacked For Ransom In A Recent Campaign

THREATS

  1. Adobe Patches 47 Critical Flaws in Acrobat and DC
  2. Top Cloud Domain Controller for MSPs
  3. Multiple Code Execution Vulnerabilities Found in Atlantis Word Processor
  4. CVE-2018-11776 and why you need Black Duck Security Advisories
  5. GhostDNS malware already infected over 100K+ devices and targets 70+ different types of home routers
  6. Nine NAS Bugs Open LenovoEMC, Iomega Devices to Attack
  7. GrandCrab Ransomware Spreads Using Multiple Known Vulnerabilities
  8. Fileless Malware Attacks on the Rise, Microsoft Says
  9. 'Short, Brutal Lives': Life Expectancy for Malicious Domains
  10. Google Bug Breaks Search Results with a Plus Sign On Mac Safari
  11. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  12. Roaming Mantis Group Adds Phishing and Web Crypto Mining for iOS Devices
  13. Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
  14. Google Adds New Rules To End Malicious Chrome Extensions
  15. Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
  16. Code Execution Vulnerabilities Uncovered In Atlantis Word Processor
  17. Deep Dive Into iTranslator - MITM Malware
  18. LoJax: Fisrt UEFI Rootkit Found In The Wild
  19. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  20. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  21. Telegram Patched IP Address Leak Problem In Its Desktop Client
  22. Weak Passwords Abused for 'FruitFly' Mac Malware Distribution
  23. Facebook: How to minimize the risk of vulnerabilities
  24. Code execution vulnerabilities uncovered in Atlantis Word Processor
  25. A new Browser Reaper exploit can crash or freeze Mozilla #Firefox, according to a proof of concept published by a
  26. Malwarebytes is a champion of National Cybersecurity Awareness Month
  27. Monitor privileged execution to defend against
  28. Attackers chained three bugs to breach into the Facebook platform
  29. Telegram Leaks User IP Addresses
  30. Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
  31. TrickBot Banking Trojan Takes Center Stage in 2018
  32. More on the Five Eyes Statement on Encryption and Backdoors
  33. Monero fixes major ‘burning bug’ flaw, preventing mass devaluation
  34. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  35. Telegram not really anonymous? Researcher reports bug that leaks IP addresses
  36. Flaws in Tory party conference app leak ministers' personal information
  37. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  38. Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
  39. GandCrab ransomware is spreading wildly through several known vulnerabilities
  40. Python-based attack tools are the most common vector for launching exploit attempts
  41. Docs reveal how Fruitfly Mac spyware initially spread
  42. Torii malware could be gateway to more sophisticated IoT botnet attacks
  43. SamSam ransomware: How is this version different from others?
  44. Ransomware Casts Anchor at the Port of San Diego
  45. Hackers Hijacked More Than 100,000 Routers DNS Settings and Redirecting Users to Malicious WebSites
  46. Ransomware Casts Anchor at the Port of San Diego
  47. Several Bugs Exploited in Massive Facebook Hack
  48. Sophos recently discovered a #Samsam extortion code that performs whole-company attacks through a variety of vulnerability exploits. Discover how this
  49. #VPNFilter #malware: How can users protect themselves?
  50. Nasty Linux Kernel Vulnerability Discovered, Mandatory Kernel Update Required
  51. How can attackers exploit a buffer underflow #vulnerability?
  52. CISO @rickhholland joins @drshellface and @mazzazone to discuss the latest #cybersecurity news: Security Flaws Affect 50 Million Facebook Accounts and
  53. Vulnerability Spotlight: Multiple vulnerabilities in Atlantis Word Processor
  54. Telegram CVE-2018-17780 flaw causes the leak of IP addresses when initiating calls
  55. Telegram Calling Feature Leaks Your IP Addresses—Patch Released
  56. New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

CRIME

  1. Cyber Security Roundup for September 2018
  2. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  3. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  4. 4 Ways to Protect Your Files from a Data Breach
  5. Gemalto ID Card Provider Sued for €152 Million in eID Vulnerability Case
  6. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  7. NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
  8. Facebook: How to minimize the risk of vulnerabilities
  9. Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
  10. How to Orchestrate a Smarter Phishing Response
  11. Voice Phishing Scams Are Getting More Clever
  12. Formjacking in the Nutshell
  13. Attackers chained three bugs to breach into the Facebook platform
  14. TrickBot Banking Trojan Takes Center Stage in 2018
  15. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system
  16. Hackers Hijacked More Than 100,000 Routers DNS Settings and Redirecting Users to Malicious WebSites
  17. Sophos recently discovered a #Samsam extortion code that performs whole-company attacks through a variety of vulnerability exploits. Discover how this
  18. GhostDNS: New DNS Changer Botnet Hijacked Over 100,000 Routers
  19. New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

POLITICS

  1. Hacking Week Call for Pitches: Who Is the Weakest Link In Cybersecurity?
  2. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  3. A week in security (September 24 – 30)
  4. Facebook: How to minimize the risk of vulnerabilities
  5. Hackers Are Selling Botnets and Stolen ‘Fortnite’ Accounts Over Instagram
  6. Malwarebytes is a champion of National Cybersecurity Awareness Month
  7. Report Ties North Korean Attacks to New Malware, Linked by Word Macros
  8. Roaming Mantis part III: iOS crypto-mining and spreading via malicious content delivery system

Oct 1, 2018

APT report for 2018-09-30

TRANSNATIONAL / UNKNOWN

  1. The British Airways #databreach may be the handiwork of hacking group #Magecart, according to researchers. By @MaddieBacon11

CHINA

Nothing to report

INDIA

Nothing to report

NORTH KOREA

  1. A security researcher developed a proof-of-concept attack on #Firefox called Browser Reaper that can crash or freeze the browser, but

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Security Affairs newsletter Round 182 – News of the week

UKRAINE

Nothing to report

Platform report for 2018-09-30

WINDOWS

  1. Telegram Leaks Public & Private IP Address While Making Calls
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. Telegram exposes the IP address during a user call by default
  5. Xbash Malware Combines Many Malicious Functions in Worm
  6. Cisco Multiple Security Vulnerabilities Alert
  7. USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing

LINUX

  1. Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
  2. Security Affairs newsletter Round 182 – News of the week
  3. Telegram exposes the IP address during a user call by default
  4. Xbash Malware Combines Many Malicious Functions in Worm

UNIX

Nothing to report

ANDROID

  1. #Android #Trojan: How is data being stolen from #messagingapps?
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. Telegram exposes the IP address during a user call by default

IOS

  1. Security Affairs newsletter Round 182 – News of the week
  2. Telegram exposes the IP address during a user call by default
  3. Cisco Multiple Security Vulnerabilities Alert

MACOS

  1. Security Affairs newsletter Round 182 – News of the week
  2. Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
  3. Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files

Threat report for 2018-09-30

DATA BREACH

  1. Experts comment on Facebook’s 50 million user credential leak
  2. 40 million more likely affected by massive Facebook data leak - Bitdefender
  3. Project Insecurity (@insecurity) researchers discovered certain #livechatsoftware that were leaking personal details of employee at several high-profile sites. Discover how
  4. Telegram Leaks Public & Private IP Address While Making Calls
  5. The United Nations (@UN) accidentally exposed sensitive information on public @trello boards, in the Jira app, and in #GoogleDocs and
  6. 3 GOP senators doxed during Kavanaugh hearing
  7. Uber has agreed to pay more than $140 Million for a data breach settlement

DENIAL-OF-SERVICE

Nothing to report

MALVERTISING

Nothing to report

PHISHING

  1. Chegg forces password reset on 40 million users
  2. Hackers are Selling Social Media Logins & Financial Details On Dark Web starting from £2
  3. USBStealer – Password Hacking Tool For Windows Machine Applications to Perform Windows Penetration Testing

WEB DEFACEMENT

Nothing to report

MALWARE

  1. GANDCRAB 5.0.1 Ransom Virus – How to Remove It and Restore Data
  2. Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
  3. Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
  4. Telegram Leaks Public & Private IP Address While Making Calls
  5. #Android #Trojan: How is data being stolen from #messagingapps?
  6. Docs reveal how Fruitfly Mac spyware initially spread
  7. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  8. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
  9. Security roundup: Facebook, ransomware, UEFI rootkit, Berners-Lee’s plan for new internet
  10. Telegram exposes the IP address during a user call by default
  11. #GoScanSSH: How does this #malware work and differ from others?
  12. Xbash Malware Combines Many Malicious Functions in Worm
  13. Discover how the #VPNFilter #malware works and affects users
  14. Alphabet's Chronicle has given #VirusTotal a makeover. Find out what's in the new VirusTotal Enterprise offering. By @RobWright22
  15. Improving core processes with next-generation mobile productivity solutions can bring power and cost efficiency gains. However, we must not lose
  16. Malware in the Cloud: What You Need to Know
  17. Beware !! USB Devices & Removable Media are Used to Inject Cryptocurrency Mining Malware

EXPLOIT

  1. Facebook Ad Targeting Exploits Users’ 2FA Phone Numbers
  2. FBI IC3 warns of cyber attacks exploiting Remote Desktop Protocol (RDP)

VULNERABILITY

  1. Mutagen Astronomy – Linux Vulnerability Hits CentOS, Debian, and Red Hat Distros
  2. Facebook Says Three Different Bugs Are Responsible For The Massive Account Hacks
  3. Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
  4. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  5. Apple DEP Authentication Flaw Leaves Devices Vulnerable To Malicious MDM Enrolling
  6. #Cisco patches yet another hardcoded credentials flaw, this time in its video surveillance manager appliance; the latest vulnerability is at
  7. Mojave Flaws Allow An Attacker To Bypass Full Disk Access Requirement
  8. Election equipment vendors come under fire for #votingmachine security in the latest #DEFCON report, which details flaws -- one from
  9. Cisco Multiple Security Vulnerabilities Alert
  10. Zero-Day MacOS Mojave Privacy Bypass Bug Exposes Protected Files
  11. A Top Facebook Bug Bounty Hunter Shares Their Insights on the Facebook Breach

Region brief for 2018-09-30

ASIA

  1. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  2. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats

OCEANIA

Nothing to report

NORTH AMERICA

  1. Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
  2. Telegram exposes the IP address during a user call by default

SOUTH AMERICA

Nothing to report

EUROPE

  1. Estonia sues Gemalto for 152M euros over flaws in citizen ID cards issued by the company
  2. Cryptomining Malware Grows by 86% in Q2: McAfee Report
  3. Security Affairs newsletter Round 182 – News of the week
  4. The British Airways #databreach may be the handiwork of hacking group #Magecart, according to researchers. By @MaddieBacon11

AFRICA

Nothing to report