Oct 17, 2018

Daily brief for 2018-10-16

ASIA

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  3. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  4. Line lists cryptocurrency on Bitbox exchange

WORLD

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  3. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  4. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  5. Bug in New iOS Lets Attacker Access iPhone Pics
  6. Sony Fixed PlayStation 4 Message Exploit Leasing to a DoS Condition
  7. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  8. Madison County computer system infected with ransomware
  9. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  10. 2018 US voter records offered for sale on hacking forum
  11. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  12. 35 million US voter records available for sale in a hacking forum
  13. Anthem agrees to pay $16 million in data breach privacy settlement
  14. Dating App for Trump Supporters Exposed Members’ Information
  15. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  16. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  17. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  18. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  19. UK’s MoD Exposed in 37 Security Breaches: Report
  20. Report: near-400% increase in crypto-mining malware attacks against iPhones
  21. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  22. 35 million voter records from 19 states for sale on hacking forum
  23. Octopus malware wraps tentacles around former Telegram users in Central Asia
  24. Phishing and Facebook – a test of reputation
  25. Pentagon data breach puts personal details of 30,000 staff at risk
  26. Data breach in Pentagon’s service provider affected 30k people
  27. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine
  28. New iPhone Bug Gives Anyone Access to Your Private Photos

ATTACKS

  1. Chrome 70 arrives with fingerprint login for websites, extension controls, and 23 security fixes
  2. Chrome 70 released with revamped Google account login system
  3. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  4. Pentagon data breach exposed travel data for 30,000 individuals
  5. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  6. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  7. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  8. Anthem Agrees To Pay $16 Million In Data Breach Privacy Settlement
  9. The Donald Daters Trump Dating App Exposed Its Users Data
  10. Phishing Site Impersonates Financial Services Institution: https://www.digitalshadows.com/blog-and-research/phishing-site-impersonates-financial-services-institution/ … (via @mazzazone)
  11. 2018 US voter records offered for sale on hacking forum
  12. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  13. #TLBleed exploits abuse Intel's HTT chip feature to leak data. Find out how hackers could launch side-channel attacks to obtain
  14. 35 million US voter records available for sale in a hacking forum
  15. Anthem agrees to pay $16 million in data breach privacy settlement
  16. Dating App for Trump Supporters Exposed Members’ Information
  17. After originally disclosing its latest data breach last month, Facebook revealed that hackers obtained data from some 30 million users. Here’s
  18. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  19. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  20. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  21. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  22. UK’s MoD Exposed in 37 Security Breaches: Report
  23. 35 million voter records from 19 states for sale on hacking forum
  24. Pentagon data breach puts personal details of 30,000 staff at risk
  25. Facebook says fewer users affected by data breach
  26. Phishing and Facebook – a test of reputation
  27. Pentagon data breach puts personal details of 30,000 staff at risk
  28. Data breach in Pentagon’s service provider affected 30k people

THREATS

  1. SAP Boosts Blockchain Integration and Customer Flexibility
  2. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  3. [SingCERT] Alert on Multiple Vulnerabilities in PHP
  4. Multiple Vulnerabilities Allow Attackers to Take Full Control of Linksys Routers
  5. In County Crippled by Hurricane, Water Utility Targeted in Ransomware Attack
  6. 7 Useful Android Vulnerability Scanners
  7. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  8. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  9. Bug in New iOS Lets Attacker Access iPhone Pics
  10. Malicious RTF Documents Deliver Information Stealers
  11. Info of 685 Million Users at Risk Because of Multiple Branch.io XSS Flaws
  12. Madison County computer system infected with ransomware
  13. CVE-2018-8453 Zero-Day Flaw Exploited by FruityArmor APT
  14. How to Create Blockchain Applications
  15. NC Water Utility Fights Post-Hurricane Ransomware
  16. Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
  17. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  18. Tinder profiles were 'at risk' due to XSS vulnerability
  19. 685 million users may be affected by the Branch.io service XSS vulnerability
  20. A “critical water utility” in a county crippled by Hurricane #Florence was hit by a #ransomware attack. The #cyberattack has
  21. #Stegware: it's #Malware that uses #steganography techniques to avoid detection
  22. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  23. Report: near-400% increase in crypto-mining malware attacks against iPhones
  24. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  25. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  26. #Shodan, a device search engine, can help identify #ICS security vulnerabilities. Learn more about how Shodan works and how it
  27. Octopus malware wraps tentacles around former Telegram users in Central Asia
  28. Mikko didn't put Brain -- the first PC virus -- on his list but he did track down its authors
  29. Line lists cryptocurrency on Bitbox exchange
  30. "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well
  31. You are who you say you are: Establishing digital trust with the blockchain
  32. Now Surfing about your Favourite Celebrities can make you Vulnerable to Virus Attack
  33. Malware Attack Popular Amongst the Hackers, Even though it Dips in Q2 in 2018
  34. Cryptomining attacks against Apple devices increase sharply
  35. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11
  36. Cybercriminals Advertising Godzilla Loader Malware On Dark Web Forums
  37. 685 million users may be affected by the Branch.io service XSS vulnerability
  38. Cryptojacking attacks against iPhone devices increase
  39. Juniper Networks launches multiple solutions for Junos OS vulnerabilities
  40. Most Important Considerations with Malware Analysis Cheats And Tools list
  41. New iPhone Bug Gives Anyone Access to Your Private Photos
  42. Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits

CRIME

  1. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  2. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  3. How to Create Blockchain Applications
  4. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  5. 35 million US voter records available for sale in a hacking forum
  6. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  7. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  8. UK’s MoD Exposed in 37 Security Breaches: Report
  9. Report: near-400% increase in crypto-mining malware attacks against iPhones
  10. Facebook says fewer users affected by data breach
  11. Pentagon data breach puts personal details of 30,000 staff at risk

POLITICS

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  3. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  4. UK’s MoD Exposed in 37 Security Breaches: Report
  5. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  6. Octopus malware wraps tentacles around former Telegram users in Central Asia
  7. "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well

Oct 16, 2018

APT report for 2018-10-15

TRANSNATIONAL / UNKNOWN

  1. New Gallmaker APT group eschews malware in cyber espionage campaigns
  2. A week in security (October 8 – 14)
  3. Gallmaker - Threat Group Targeting Governments and Militaries
  4. Gallmaker threat group evades detection by living off the land
  5. Stopping Hidden Threats: How to Defend Against Fileless Attacks

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. Nintendo Switch Diablo III bundle launches November 2

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. TeleBots APT Group - Links to Industroyer, NotPetya and BlackEnergy
  2. Russia-linked BlackEnergy backed new cyber attacks on Ukraine’s state bodies
  3. Octopus-infested seas of Central Asia

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-15

WINDOWS

  1. Flash Updater Adds Cryptocurrency Miner
  2. New Gallmaker APT group eschews malware in cyber espionage campaigns
  3. Fake Adobe update really *does* update Flash (while also installing cryptominer)
  4. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  5. Fake Adobe update really *does* update Flash (while also installing cryptominer)
  6. Octopus-infested seas of Central Asia

LINUX

Nil

UNIX

Nil

ANDROID

  1. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  2. Octopus-infested seas of Central Asia
  3. #Nymaim and #BankBot #Anubis PL campaign hxxp://przelewy24[.]ml/ hxxp://faktura24[.]cf/ SHA256: 4cb0b471a2132a747abf78214fbdbf0e8d7f44857996117bdbb266d42a277970 C2: bilagoong[.]tk @ThreatFabric @virqdroid @LukasStefanko
  4. Android Apps Pretend to Mine Unmineable CryptoCurrencies to Just Show Ads
  5. Google to Encrypt Android Cloud Backups With Your Lock Screen Password

IOS

  1. 400 Percent Increase in Cryptocurrency Mining Attacks Against iOS Devices
  2. Apple VoiceOver iOS Vulnerability Permits Hacker Access To User Photos
  3. iPhone a Growing Target of Crypto-Mining Attacks
  4. Apple VoiceOver iOS vulnerability permits hacker access to user photos
  5. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise

MACOS

Nil

Threat report for 2018-10-15

DATA BREACH & DATA LOSS

  1. Facebook Hack Update – 30 Million Affected; More Details Exposed; No ID Protection
  2. Malware Campaign Distributes Data Stealer Trojan/RAT, Circumvents Anti-Malware
  3. Up to 35 Million 2018 Voter Records For Sale on Hacking Forum
  4. US voter records from 19 states sold on hacking forum
  5. Tens of Millions of U.S. Voter Records for Sale
  6. Pentagon Defense Department travel records data breach
  7. Did Jamal Khashoggi’s Apple Watch record his murder at Saudi consulate? Probably not
  8. New Gallmaker APT group eschews malware in cyber espionage campaigns
  9. Microsoft Incompletely Patches JET Database Vulnerability
  10. Old dog, new tricks – Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  11. Millions of Voter Records Found for Sale on the Dark Web
  12. Pentagon reveals cyber breach of travel records
  13. Pentagon Employee Data Breach, An Eye-Opener
  14. Facebook opens up about data breach details
  15. Facebook data breach: Victims will not be offered free identity theft protection
  16. A flaw in @Google Firebase #DatabaseSecurity allowed hackers to bypass security and leak data. Learn more about this #SecurityFlaw and
  17. Iceland hit by Biggest Cyber Attack on Record
  18. Scottish Ambulance Service Exposed Employees’ Data Online
  19. Pentagon Staff Hit by Major Data Breach
  20. FitMetrix data exposed on unprotected Elasticsearch servers
  21. Pentagon Data Breach Exposes up to 30,000 Travel Records
  22. Iceland's largest phishing campaign imitated police
  23. #Nymaim and #BankBot #Anubis PL campaign hxxp://przelewy24[.]ml/ hxxp://faktura24[.]cf/ SHA256: 4cb0b471a2132a747abf78214fbdbf0e8d7f44857996117bdbb266d42a277970 C2: bilagoong[.]tk @ThreatFabric @virqdroid @LukasStefanko
  24. Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  25. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  26. FitMetrix Unprotected Passwordless Database Exposed Millions of User​ Data
  27. Stringent password rules lower risk of personal data breaches
  28. Branch.io Flaws Exposed Tinder, Shopify, Yelp Users to XSS Attacks

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Create an email phishing test to minimize attack vectors
  2. Learn how we are using #MachineLearning to detect mobile #phishing attacks with @thepacketrat and @dyngnosis: https://okt.to/W29vsS @PhishingAi @arstechnica
  3. Learn how hackers launched #phishing attacks against @netflix users with expert Michael Cobb of @thehairyITdog
  4. Hackers could use emoji domains to spread phishing attacks
  5. Iceland's largest phishing campaign imitated police
  6. Stringent password rules lower risk of personal data breaches
  7. According to #GroupIB experts, online market for counterfeit goods in Russia has reached $1,5 billion, while the number of phishing
  8. Google to Encrypt Android Cloud Backups With Your Lock Screen Password

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. Small businesses repeatedly falling victim to ransomware - Kaspersky
  2. Ransomware hits computer networks of North Carolina water utility
  3. Un nouveau rapport montre que les attaques par ransomware ont diminué au premier semestre 2018. Les pirates se tournent vers

CRYPTOMINING & CRYPTOCURRENCIES

  1. 400 Percent Increase in Cryptocurrency Mining Attacks Against iOS Devices
  2. Flash Updater Adds Cryptocurrency Miner
  3. iPhone a Growing Target of Crypto-Mining Attacks
  4. Economist Nouriel Roubini: Blockchain and bitcoin are the world’s biggest scams
  5. Fake Adobe update really *does* update Flash (while also installing cryptominer)
  6. Cryptomining Malware Infects Computers via Fake Adobe Updates
  7. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  8. Fake Adobe update really *does* update Flash (while also installing cryptominer)
  9. 'Flash update' scam serves up legit software, but with a side of cryptominer
  10. How a #cryptocurrency mining #malware infects systems
  11. What are blockchain’s smart contracts? And how to secure them
  12. Android Apps Pretend to Mine Unmineable CryptoCurrencies to Just Show Ads
  13. SpankChain hacker steals the virtual currency and returns stolen ethereum

MALWARE

  1. Malware Campaign Distributes Data Stealer Trojan/RAT, Circumvents Anti-Malware
  2. New Gallmaker APT group eschews malware in cyber espionage campaigns
  3. Octopus Trojan exploits Telegram ban fears to snag diplomatic targets across Asia
  4. At the 2018 @RSAConference, researchers discussed the rise of stegware -- #malware that uses #steganography techniques to avoid detection. Learn
  5. Cryptomining Malware Infects Computers via Fake Adobe Updates
  6. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  7. #Mobile #malware is on the rise. With mobile devices, hackers are able to access data far more sensitive than what
  8. .@TrendMicro researchers discovered #FacexWorm, a #malware that uses a #ChromeExtension and @Facebook Messenger to spread. Learn which users are at
  9. How does the MnuBot banking Trojan use unusual C&C servers?
  10. How a #cryptocurrency mining #malware infects systems
  11. @ThreatFabric Gaetan van Diemen showed us the actual situation and future predictions of Mobile Banking Malware. Thx for that awesome
  12. Godzilla Loader and the Long Tail of Malware
  13. Sony PS4 encounters malicious code attack and receives malicious messages

EXPLOIT

  1. New Technique Recycles Exploit Chain to Keep Antivirus Silent

VULNERABILITY

  1. FDA Warns of Flaws in Medtronic Programmers
  2. Microsoft Incompletely Patches JET Database Vulnerability
  3. Apple VoiceOver iOS Vulnerability Permits Hacker Access To User Photos
  4. .@TenableSecurity research finds new exploits of an already patched #MikroTik router vulnerability that could enable hackers to launch remote code
  5. Sony working on a fix for bug that's crashing PlayStation 4 consoles
  6. Apple VoiceOver iOS vulnerability permits hacker access to user photos
  7. Multiple Vulnerabilities Discovered in PHP Lead to Arbitrary Code Execution, DoS
  8. Details of Vulnerability in Google PDFium’s JBIG2 Revealed
  9. A flaw in @Google Firebase #DatabaseSecurity allowed hackers to bypass security and leak data. Learn more about this #SecurityFlaw and
  10. Branch.io Flaws may have affected as many as 685 million individuals
  11. Branch.io Flaws Exposed Tinder, Shopify, Yelp Users to XSS Attacks

Region brief for 2018-10-15

ASIA

  1. Did Jamal Khashoggi’s Apple Watch record his murder at Saudi consulate? Probably not
  2. Octopus-infested seas of Central Asia

OCEANIA

Nil

NORTH AMERICA

  1. US voter records from 19 states sold on hacking forum
  2. Tens of Millions of U.S. Voter Records for Sale
  3. Pentagon Defense Department travel records data breach
  4. FDA Warns of Flaws in Medtronic Programmers
  5. Millions of Voter Records Found for Sale on the Dark Web
  6. Pentagon Employee Data Breach, An Eye-Opener
  7. Economist Nouriel Roubini: Blockchain and bitcoin are the world’s biggest scams
  8. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  9. Pentagon Staff Hit by Major Data Breach
  10. Pentagon Data Breach Exposes up to 30,000 Travel Records
  11. Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  12. @ThreatFabric Gaetan van Diemen showed us the actual situation and future predictions of Mobile Banking Malware. Thx for that awesome
  13. Branch.io Flaws may have affected as many as 685 million individuals
  14. Stopping Hidden Threats: How to Defend Against Fileless Attacks
  15. SpankChain hacker steals the virtual currency and returns stolen ethereum

SOUTH AMERICA

  1. A Russian cyber vigilante is patching outdated MikroTik routers exposed online

EUROPE

  1. New Gallmaker APT group eschews malware in cyber espionage campaigns
  2. TeleBots APT Group - Links to Industroyer, NotPetya and BlackEnergy
  3. Iceland hit by Biggest Cyber Attack on Record
  4. Scottish Ambulance Service Exposed Employees’ Data Online
  5. Russia-linked BlackEnergy backed new cyber attacks on Ukraine’s state bodies
  6. Un nouveau rapport montre que les attaques par ransomware ont diminué au premier semestre 2018. Les pirates se tournent vers
  7. Octopus-infested seas of Central Asia
  8. Iceland's largest phishing campaign imitated police
  9. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  10. According to #GroupIB experts, online market for counterfeit goods in Russia has reached $1,5 billion, while the number of phishing

AFRICA

Nil

Sector brief for 2018-10-15

HEALTHCARE

  1. A week in security (October 8 – 14)

TRANSPORT

Nil

BANKING & FINANCE

  1. Pentagon Defense Department travel records data breach
  2. A week in security (October 8 – 14)
  3. Pentagon Employee Data Breach, An Eye-Opener
  4. Economist Nouriel Roubini: Blockchain and bitcoin are the world’s biggest scams
  5. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  6. Pentagon Staff Hit by Major Data Breach
  7. FitMetrix data exposed on unprotected Elasticsearch servers
  8. How does the MnuBot banking Trojan use unusual C&C servers?
  9. @ThreatFabric Gaetan van Diemen showed us the actual situation and future predictions of Mobile Banking Malware. Thx for that awesome
  10. Stopping Hidden Threats: How to Defend Against Fileless Attacks
  11. SpankChain hacker steals the virtual currency and returns stolen ethereum

INFORMATION & TELECOMMUNICATION

  1. Ransomware hits computer networks of North Carolina water utility
  2. Facebook Hack Update – 30 Million Affected; More Details Exposed; No ID Protection
  3. A week in security (October 8 – 14)
  4. Learn how we are using #MachineLearning to detect mobile #phishing attacks with @thepacketrat and @dyngnosis: https://okt.to/W29vsS @PhishingAi @arstechnica
  5. Facebook opens up about data breach details
  6. Facebook data breach: Victims will not be offered free identity theft protection
  7. #Mobile #malware is on the rise. With mobile devices, hackers are able to access data far more sensitive than what
  8. Un nouveau rapport montre que les attaques par ransomware ont diminué au premier semestre 2018. Les pirates se tournent vers
  9. .@TrendMicro researchers discovered #FacexWorm, a #malware that uses a #ChromeExtension and @Facebook Messenger to spread. Learn which users are at
  10. @ThreatFabric Gaetan van Diemen showed us the actual situation and future predictions of Mobile Banking Malware. Thx for that awesome
  11. Stringent password rules lower risk of personal data breaches
  12. According to #GroupIB experts, online market for counterfeit goods in Russia has reached $1,5 billion, while the number of phishing

FOOD

Nil

WATER

  1. Ransomware hits computer networks of North Carolina water utility

ENERGY

  1. TeleBots APT Group - Links to Industroyer, NotPetya and BlackEnergy

GOVERNMENT & PUBLIC SERVICE

  1. Tens of Millions of U.S. Voter Records for Sale
  2. A week in security (October 8 – 14)

Daily brief for 2018-10-15

ASIA

  1. Did Jamal Khashoggi’s Apple Watch record his murder at Saudi consulate? Probably not
  2. Octopus-infested seas of Central Asia

WORLD

  1. US voter records from 19 states sold on hacking forum
  2. Tens of Millions of U.S. Voter Records for Sale
  3. Pentagon Defense Department travel records data breach
  4. FDA Warns of Flaws in Medtronic Programmers
  5. New Gallmaker APT group eschews malware in cyber espionage campaigns
  6. Millions of Voter Records Found for Sale on the Dark Web
  7. Pentagon Employee Data Breach, An Eye-Opener
  8. Economist Nouriel Roubini: Blockchain and bitcoin are the world’s biggest scams
  9. TeleBots APT Group - Links to Industroyer, NotPetya and BlackEnergy
  10. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  11. Iceland hit by Biggest Cyber Attack on Record
  12. Scottish Ambulance Service Exposed Employees’ Data Online
  13. Pentagon Staff Hit by Major Data Breach
  14. Russia-linked BlackEnergy backed new cyber attacks on Ukraine’s state bodies
  15. Pentagon Data Breach Exposes up to 30,000 Travel Records
  16. Un nouveau rapport montre que les attaques par ransomware ont diminué au premier semestre 2018. Les pirates se tournent vers
  17. Octopus-infested seas of Central Asia
  18. Iceland's largest phishing campaign imitated police
  19. Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  20. @ThreatFabric Gaetan van Diemen showed us the actual situation and future predictions of Mobile Banking Malware. Thx for that awesome
  21. Branch.io Flaws may have affected as many as 685 million individuals
  22. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  23. According to #GroupIB experts, online market for counterfeit goods in Russia has reached $1,5 billion, while the number of phishing
  24. Stopping Hidden Threats: How to Defend Against Fileless Attacks
  25. SpankChain hacker steals the virtual currency and returns stolen ethereum

ATTACKS

  1. Create an email phishing test to minimize attack vectors
  2. Facebook Hack Update – 30 Million Affected; More Details Exposed; No ID Protection
  3. Malware Campaign Distributes Data Stealer Trojan/RAT, Circumvents Anti-Malware
  4. Up to 35 Million 2018 Voter Records For Sale on Hacking Forum
  5. US voter records from 19 states sold on hacking forum
  6. Tens of Millions of U.S. Voter Records for Sale
  7. Pentagon Defense Department travel records data breach
  8. Did Jamal Khashoggi’s Apple Watch record his murder at Saudi consulate? Probably not
  9. New Gallmaker APT group eschews malware in cyber espionage campaigns
  10. Microsoft Incompletely Patches JET Database Vulnerability
  11. Old dog, new tricks – Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  12. Millions of Voter Records Found for Sale on the Dark Web
  13. Learn how we are using #MachineLearning to detect mobile #phishing attacks with @thepacketrat and @dyngnosis: https://okt.to/W29vsS @PhishingAi @arstechnica
  14. Learn how hackers launched #phishing attacks against @netflix users with expert Michael Cobb of @thehairyITdog
  15. Hackers could use emoji domains to spread phishing attacks
  16. Pentagon reveals cyber breach of travel records
  17. Pentagon Employee Data Breach, An Eye-Opener
  18. Facebook opens up about data breach details
  19. Facebook data breach: Victims will not be offered free identity theft protection
  20. A flaw in @Google Firebase #DatabaseSecurity allowed hackers to bypass security and leak data. Learn more about this #SecurityFlaw and
  21. Iceland hit by Biggest Cyber Attack on Record
  22. Scottish Ambulance Service Exposed Employees’ Data Online
  23. Pentagon Staff Hit by Major Data Breach
  24. FitMetrix data exposed on unprotected Elasticsearch servers
  25. Pentagon Data Breach Exposes up to 30,000 Travel Records
  26. Iceland's largest phishing campaign imitated police
  27. #Nymaim and #BankBot #Anubis PL campaign hxxp://przelewy24[.]ml/ hxxp://faktura24[.]cf/ SHA256: 4cb0b471a2132a747abf78214fbdbf0e8d7f44857996117bdbb266d42a277970 C2: bilagoong[.]tk @ThreatFabric @virqdroid @LukasStefanko
  28. Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  29. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  30. FitMetrix Unprotected Passwordless Database Exposed Millions of User​ Data
  31. Stringent password rules lower risk of personal data breaches
  32. Branch.io Flaws Exposed Tinder, Shopify, Yelp Users to XSS Attacks
  33. According to #GroupIB experts, online market for counterfeit goods in Russia has reached $1,5 billion, while the number of phishing
  34. Google to Encrypt Android Cloud Backups With Your Lock Screen Password

THREATS

  1. Small businesses repeatedly falling victim to ransomware - Kaspersky
  2. 400 Percent Increase in Cryptocurrency Mining Attacks Against iOS Devices
  3. Flash Updater Adds Cryptocurrency Miner
  4. Ransomware hits computer networks of North Carolina water utility
  5. Malware Campaign Distributes Data Stealer Trojan/RAT, Circumvents Anti-Malware
  6. FDA Warns of Flaws in Medtronic Programmers
  7. New Gallmaker APT group eschews malware in cyber espionage campaigns
  8. Microsoft Incompletely Patches JET Database Vulnerability
  9. Apple VoiceOver iOS Vulnerability Permits Hacker Access To User Photos
  10. .@TenableSecurity research finds new exploits of an already patched #MikroTik router vulnerability that could enable hackers to launch remote code
  11. iPhone a Growing Target of Crypto-Mining Attacks
  12. Octopus Trojan exploits Telegram ban fears to snag diplomatic targets across Asia
  13. Sony working on a fix for bug that's crashing PlayStation 4 consoles
  14. Economist Nouriel Roubini: Blockchain and bitcoin are the world’s biggest scams
  15. At the 2018 @RSAConference, researchers discussed the rise of stegware -- #malware that uses #steganography techniques to avoid detection. Learn
  16. Fake Adobe update really *does* update Flash (while also installing cryptominer)
  17. Apple VoiceOver iOS vulnerability permits hacker access to user photos
  18. Cryptomining Malware Infects Computers via Fake Adobe Updates
  19. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  20. Fake Adobe update really *does* update Flash (while also installing cryptominer)
  21. Multiple Vulnerabilities Discovered in PHP Lead to Arbitrary Code Execution, DoS
  22. Details of Vulnerability in Google PDFium’s JBIG2 Revealed
  23. A flaw in @Google Firebase #DatabaseSecurity allowed hackers to bypass security and leak data. Learn more about this #SecurityFlaw and
  24. #Mobile #malware is on the rise. With mobile devices, hackers are able to access data far more sensitive than what
  25. Un nouveau rapport montre que les attaques par ransomware ont diminué au premier semestre 2018. Les pirates se tournent vers
  26. .@TrendMicro researchers discovered #FacexWorm, a #malware that uses a #ChromeExtension and @Facebook Messenger to spread. Learn which users are at
  27. 'Flash update' scam serves up legit software, but with a side of cryptominer
  28. How does the MnuBot banking Trojan use unusual C&C servers?
  29. How a #cryptocurrency mining #malware infects systems
  30. @ThreatFabric Gaetan van Diemen showed us the actual situation and future predictions of Mobile Banking Malware. Thx for that awesome
  31. Branch.io Flaws may have affected as many as 685 million individuals
  32. Godzilla Loader and the Long Tail of Malware
  33. Branch.io Flaws Exposed Tinder, Shopify, Yelp Users to XSS Attacks
  34. What are blockchain’s smart contracts? And how to secure them
  35. Android Apps Pretend to Mine Unmineable CryptoCurrencies to Just Show Ads
  36. SpankChain hacker steals the virtual currency and returns stolen ethereum
  37. Sony PS4 encounters malicious code attack and receives malicious messages

CRIME

  1. Online ads: a potential way in for XSS attacks
  2. Facebook data breach: Victims will not be offered free identity theft protection
  3. September 2018’s Most Wanted Malware: Cryptomining Attacks Against Apple Devices On The Rise
  4. Octopus-infested seas of Central Asia
  5. Iceland's largest phishing campaign imitated police
  6. 'Flash update' scam serves up legit software, but with a side of cryptominer
  7. Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  8. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  9. SpankChain hacker steals the virtual currency and returns stolen ethereum

POLITICS

  1. Pentagon Defense Department travel records data breach
  2. New Gallmaker APT group eschews malware in cyber espionage campaigns
  3. A week in security (October 8 – 14)
  4. Gallmaker - Threat Group Targeting Governments and Militaries
  5. Octopus-infested seas of Central Asia
  6. Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox
  7. A Russian cyber vigilante is patching outdated MikroTik routers exposed online

Oct 15, 2018

APT report for 2018-10-14

TRANSNATIONAL / UNKNOWN

  1. DDoS Attacks Hit Games Like Assassin’s Creed and Final Fantasy XIV
  2. Security Affairs newsletter Round 184 – News of the week

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Security Affairs newsletter Round 184 – News of the week

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-14

WINDOWS

  1. Microsoft fixed the Zero-Day for JET flaw, but the fix is incomplete
  2. Microsoft patch for JET flaw zero-day is ‘incomplete,’ Windows still vulnerable
  3. Expert released PoC Code Microsoft Edge Remote Code Execution flaw
  4. Exploiting Windows Using Microsoft Office DDE Exploit (MACROLESS)

LINUX

Nil

UNIX

Nil

ANDROID

  1. .@ThreatFabric researchers uncovered a #malware that uses overlay techniques to avoid detection. Learn from @lewisnic how this new #Androidmalware --

IOS

Nil

MACOS

Nil

Threat report for 2018-10-14

DATA BREACH & DATA LOSS

  1. My Health Record privacy amendments 'woefully inadequate': Labor
  2. #NetSpectre exploits speculative execution to leak data remotely via side-channel attacks. Learn how this #SecurityVulnerability affects the #cloud from expert
  3. Web Hosting Provider Suffers Data Breach Second Time in a Year
  4. Find out how #TLBleed abuses @Intel's HTT chip feature to leak data via TLB
  5. Microsoft still has not completely solved the Microsoft JET database engine vulnerability
  6. See how SearchLight identifies when your data is exposed, your brand is abused, or your company is mentioned on the
  7. Pentagon Discloses Data Breach, More Than 30,000 Workers Have Affected
  8. A @Google security audit uncovered a glitch in #GooglePlus that exposed data from nearly 500,000 accounts, causing the company to
  9. PHASE 4 – INFORMATION GATHERING AND PLANNING Meet Eric, a control systems engineer working for a third-party integrator. He’s guy who uploaded

DENIAL-OF-SERVICE

  1. DDoS Attacks Hit Games Like Assassin’s Creed and Final Fantasy XIV

MALVERTISING

Nil

PHISHING

Nil

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. New @ESET research finds APT group dubbed #TeleBots was behind #Industroyer #malware attacks, #NotPetya #ransomware outbreaks, and a recent Exaramel

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Flash Updates pushing Malware to Inject XMRig Cryptocurrency Miners

MALWARE

  1. Week in review: Enterprise cybersecurity PKIs, keeping your cloud malware-free
  2. New @ESET research finds APT group dubbed #TeleBots was behind #Industroyer #malware attacks, #NotPetya #ransomware outbreaks, and a recent Exaramel
  3. .@ThreatFabric researchers uncovered a #malware that uses overlay techniques to avoid detection. Learn from @lewisnic how this new #Androidmalware --
  4. At the 2018 @RSAConference, researchers discussed the rise of stegware -- #malware that uses #steganography techniques to avoid detection. Learn
  5. How a remote access #Trojan checks for
  6. Fake Flash Updates pushing Malware to Inject XMRig Cryptocurrency Miners

EXPLOIT

  1. Expert released PoC Code Microsoft Edge Remote Code Execution flaw
  2. Exploiting Windows Using Microsoft Office DDE Exploit (MACROLESS)

VULNERABILITY

  1. Microsoft fixed the Zero-Day for JET flaw, but the fix is incomplete
  2. A2SV – SSL Vulnerability Analysis Tool
  3. Microsoft patch for JET flaw zero-day is ‘incomplete,’ Windows still vulnerable
  4. Microsoft still has not completely solved the Microsoft JET database engine vulnerability
  5. Expert released PoC Code Microsoft Edge Remote Code Execution flaw

Region brief for 2018-10-14

ASIA

Nil

OCEANIA

  1. My Health Record privacy amendments 'woefully inadequate': Labor

NORTH AMERICA

  1. Security Affairs newsletter Round 184 – News of the week
  2. Expert released PoC Code Microsoft Edge Remote Code Execution flaw
  3. Pentagon Discloses Data Breach, More Than 30,000 Workers Have Affected

SOUTH AMERICA

Nil

EUROPE

  1. Week in review: Enterprise cybersecurity PKIs, keeping your cloud malware-free
  2. Web Hosting Provider Suffers Data Breach Second Time in a Year
  3. A @Google security audit uncovered a glitch in #GooglePlus that exposed data from nearly 500,000 accounts, causing the company to

AFRICA

  1. Web Hosting Provider Suffers Data Breach Second Time in a Year

Sector brief for 2018-10-14

HEALTHCARE

Nil

TRANSPORT

Nil

BANKING & FINANCE

  1. Web Hosting Provider Suffers Data Breach Second Time in a Year
  2. Security Affairs newsletter Round 184 – News of the week
  3. Pentagon Discloses Data Breach, More Than 30,000 Workers Have Affected

INFORMATION & TELECOMMUNICATION

  1. Security Affairs newsletter Round 184 – News of the week
  2. Expert released PoC Code Microsoft Edge Remote Code Execution flaw
  3. See how SearchLight identifies when your data is exposed, your brand is abused, or your company is mentioned on the
  4. PHASE 4 – INFORMATION GATHERING AND PLANNING Meet Eric, a control systems engineer working for a third-party integrator. He’s guy who uploaded

FOOD

Nil

WATER

Nil

ENERGY

  1. Week in review: Enterprise cybersecurity PKIs, keeping your cloud malware-free

GOVERNMENT & PUBLIC SERVICE

Nil

Daily brief for 2018-10-14

ASIA

Nil

WORLD

  1. My Health Record privacy amendments 'woefully inadequate': Labor
  2. Week in review: Enterprise cybersecurity PKIs, keeping your cloud malware-free
  3. Web Hosting Provider Suffers Data Breach Second Time in a Year
  4. Security Affairs newsletter Round 184 – News of the week
  5. Expert released PoC Code Microsoft Edge Remote Code Execution flaw
  6. Pentagon Discloses Data Breach, More Than 30,000 Workers Have Affected
  7. A @Google security audit uncovered a glitch in #GooglePlus that exposed data from nearly 500,000 accounts, causing the company to

ATTACKS

  1. My Health Record privacy amendments 'woefully inadequate': Labor
  2. #NetSpectre exploits speculative execution to leak data remotely via side-channel attacks. Learn how this #SecurityVulnerability affects the #cloud from expert
  3. Web Hosting Provider Suffers Data Breach Second Time in a Year
  4. Find out how #TLBleed abuses @Intel's HTT chip feature to leak data via TLB
  5. Microsoft still has not completely solved the Microsoft JET database engine vulnerability
  6. See how SearchLight identifies when your data is exposed, your brand is abused, or your company is mentioned on the
  7. Pentagon Discloses Data Breach, More Than 30,000 Workers Have Affected
  8. A @Google security audit uncovered a glitch in #GooglePlus that exposed data from nearly 500,000 accounts, causing the company to
  9. PHASE 4 – INFORMATION GATHERING AND PLANNING Meet Eric, a control systems engineer working for a third-party integrator. He’s guy who uploaded

THREATS

  1. Microsoft fixed the Zero-Day for JET flaw, but the fix is incomplete
  2. Week in review: Enterprise cybersecurity PKIs, keeping your cloud malware-free
  3. A2SV – SSL Vulnerability Analysis Tool
  4. New @ESET research finds APT group dubbed #TeleBots was behind #Industroyer #malware attacks, #NotPetya #ransomware outbreaks, and a recent Exaramel
  5. .@ThreatFabric researchers uncovered a #malware that uses overlay techniques to avoid detection. Learn from @lewisnic how this new #Androidmalware --
  6. Microsoft patch for JET flaw zero-day is ‘incomplete,’ Windows still vulnerable
  7. At the 2018 @RSAConference, researchers discussed the rise of stegware -- #malware that uses #steganography techniques to avoid detection. Learn
  8. Microsoft still has not completely solved the Microsoft JET database engine vulnerability
  9. Expert released PoC Code Microsoft Edge Remote Code Execution flaw
  10. How a remote access #Trojan checks for
  11. Fake Flash Updates pushing Malware to Inject XMRig Cryptocurrency Miners

CRIME

  1. Security Affairs newsletter Round 184 – News of the week
  2. Expert released PoC Code Microsoft Edge Remote Code Execution flaw

POLITICS

  1. Security Affairs newsletter Round 184 – News of the week
  2. Pentagon Discloses Data Breach, More Than 30,000 Workers Have Affected

Oct 14, 2018

APT report for 2018-10-13

TRANSNATIONAL / UNKNOWN

Nil

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-13

WINDOWS

  1. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available

LINUX

Nil

UNIX

Nil

ANDROID

  1. GPlayed – New Malware Posed as Google Play App to Spy & Steal Data From Your Entire Android Phone

IOS

Nil

MACOS

Nil

Threat report for 2018-10-13

DATA BREACH & DATA LOSS

  1. Pentagon Defense Department travel records data breach
  2. A combination of #SecurityFlaws and inadequate back-end development of the @Google Firebase database led to #DataLeaks and #SecurityVulnerabilities including HospitalGown.
  3. 'Only' 30 million accounts were compromised in Facebook hack
  4. Researchers @proofpoint have been tracking a downloader dubbed #AdvisorsBot as a first-stage payload in campaigns since May 2018.
  5. Facebook Clarifies Extent of Data Breach
  6. An Assessment of Google's Data Leak
  7. ArangoDB v3.3.18 releases: native multi-model database
  8. Facebook Now Revealed Hackers Stolen 29 Million Facebook Users Personal Data
  9. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available
  10. Breach of Pentagon travel records exposes defense personnel PII

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Hackers launched @netflix #phishing attacks by obtaining TLS certificates. Learn how hackers mimic popular websites to spoof users and steal
  2. This skyscraper reminds me of those really long ANSI art BBS login screens. Cc: @sixteencolors @blocktronics @velikani

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. [SingCERT] Updated Advisory on Ransomware
  2. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11

CRYPTOMINING & CRYPTOCURRENCIES

  1. Criminals' Cryptocurrency Addiction Continues
  2. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  3. Cryptocurrency Miners trick the user through Fake Flash Updates
  4. Blockchain and Healthcare in Today’s World

MALWARE

  1. GPlayed – New Malware Posed as Google Play App to Spy & Steal Data From Your Entire Android Phone
  2. Researchers @proofpoint have been tracking a downloader dubbed #AdvisorsBot as a first-stage payload in campaigns since May 2018.
  3. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  4. Hackers use Googlebot in mining malware attacks
  5. Researchers at @TrendMicro found a new strain of #malware -- dubbed #FacexWorm -- that targets users through a malicious #ChromeExtension.
  6. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11

EXPLOIT

Nil

VULNERABILITY

  1. Now this might be going out on a limb, but here's how a branch.io bug left '685 million' netizens open to website hacks
  2. Review Shows Glaring Flaws In Xiongmai IoT Devices
  3. Microsoft JET vulnerability still open to attacks, despite recent patch
  4. DOM-based XSS Vulnerability Affected 685 Million Users of Tinder, Shopify, Western Union, and Imgur
  5. A patched #MikroTik router vulnerability amps up severity rating as @TenableSecurity researchers find new potential exploits with more critical consequences.
  6. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available
  7. Vulnerabilities affect Shopify, Tinder and many other sites

Region brief for 2018-10-13

ASIA

  1. Review Shows Glaring Flaws In Xiongmai IoT Devices

OCEANIA

  1. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

NORTH AMERICA

  1. Pentagon Defense Department travel records data breach

SOUTH AMERICA

Nil

EUROPE

  1. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

AFRICA

Nil