Oct 18, 2018

Sector brief for 2018-10-17

HEALTHCARE

  1. Who is to blame for the majority of data breaches?
  2. Anthem pays out record $16m over data breach

TRANSPORT

Nil

BANKING & FINANCE

  1. AISA 2018: Japan's journey from a cryptocurrency hack to better regulation
  2. FBI Releases Document with Measures for Defending Against Payroll Phishing Scams
  3. New research highlights Vietnamese group's custom hacking tools
  4. How Blockchain Is Making it Easier for Fintech Companies to Scale Up
  5. 35 million voter records from 19 US states for sale
  6. Alphabet in the soup for keeping quiet about Google+ data leak bug
  7. WTB: MuddyWater Expands Operations
  8. A crippling ransomware attack hit a water utility in the aftermath of Hurricane Florence
  9. Oracle releases Critical Patch Update Advisory – October 2018: fix 301 security bugs
  10. Git RCE Vulnerability (CVE-2018-17456)Security Advisory

INFORMATION & TELECOMMUNICATION

  1. Tumblr Patches Security Issue that Would Leak Emails, Hashed-Salted Passwords
  2. Tumblr discloses vulnerability but says 'no evidence that this bug was abused'
  3. How Office 365 learned to reel in phish
  4. CVE-2018-3211: Java Usage Tracker Local Elevation of Privilege on Windows
  5. A hacker who used fake advertisements placed on local newspaper websites to spread malware has been sentenced to 33 months
  6. Tumblr Patches A Flaw That Could Have Exposed Users’ Account Info
  7. "Attackers have expanded [phishing attacks] significantly into SMS and social media, and are displaying a preference for targeting personal email
  8. Millions of US Voter Records for Sale
  9. How does #FacexWorm #malware use @Facebook Messenger to spread? Learn more about this new malware with expert @lewisnic.
  10. #GroupIB has estimated that cryptocurrency exchanges suffered a total loss of $882 mln due to targeted attacks in 2017 and
  11. Russian Hackers Attack Specialist in Customer Review Tied to Innumerable Websites
  12. A crippling ransomware attack hit a water utility in the aftermath of Hurricane Florence
  13. Sony has solved the crash of PS4 receiving malicious message
  14. Vulnerability in Apple VoiceOver allows hackers access to user photos
  15. Google Chrome 70.0.3538.67 releases: fix multiple high-risk vulnerabilities

FOOD

Nil

WATER

Nil

ENERGY

  1. 3 Years After Attacks on Ukraine Power Grid, BlackEnergy Successor Poses Growing Threat
  2. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid

GOVERNMENT & PUBLIC SERVICE

  1. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  2. 35 Million US Voter Registration Records Found for Sale on Dark Web
  3. New research highlights Vietnamese group's custom hacking tools
  4. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  5. SEO Poisoning Campaign Targeting U.S. Midterm Election Keywords
  6. 35 million voter records from 19 US states for sale
  7. WTB: MuddyWater Expands Operations
  8. Millions of US Voter Records for Sale
  9. 35 Million U.S Voter Records Selling in Popular Dark web Hacking Forum from $150 USD to $12,500 USD
  10. Vulnerability in voting machines has not been corrected after 11 years

Daily brief for 2018-10-17

ASIA

  1. AISA 2018: Japan's journey from a cryptocurrency hack to better regulation
  2. New research highlights Vietnamese group's custom hacking tools
  3. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  4. WhiteSource raises $35 million for open source flaw detection platform
  5. Top 5 Publicly Accessible Hacking Tools You Can Download Today
  6. WTB: MuddyWater Expands Operations
  7. Git RCE Vulnerability (CVE-2018-17456)Security Advisory

WORLD

  1. LuminosityLink RAT Author Sentenced to 30 Months in Prison
  2. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  3. 'GreyEnergy' Cyberspies Target Ukraine, Poland
  4. 3 Years After Attacks on Ukraine Power Grid, BlackEnergy Successor Poses Growing Threat
  5. Information of 396K Users Exposed in Facepunch Data Breach
  6. 35 Million US Voter Registration Records Found for Sale on Dark Web
  7. Podcast: A Utility Ransomware Attack, Post-Hurricane
  8. How Office 365 learned to reel in phish
  9. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  10. 35 million US voter records up for sale on the dark web
  11. Who is to blame for the majority of data breaches?
  12. Attackers identified in the pre-espionage stage of CNI attack
  13. SEO Poisoning Campaign Targeting U.S. Midterm Election Keywords
  14. 35 million voter records from 19 US states for sale
  15. Insult to injury: Malware menace soaks water-logged utility ravaged by Hurricane Florence
  16. WTB: MuddyWater Expands Operations
  17. US Voter Records for Sale on Hacker Forum
  18. GreyEnergy group targeting critical infrastructure with espionage
  19. Brazil expert discovers Oracle flaw that allows massive DDoS attacks
  20. Millions of US Voter Records for Sale
  21. 35 Million U.S Voter Records Selling in Popular Dark web Hacking Forum from $150 USD to $12,500 USD
  22. Russian Hackers Attack Specialist in Customer Review Tied to Innumerable Websites
  23. A crippling ransomware attack hit a water utility in the aftermath of Hurricane Florence
  24. Sony has solved the crash of PS4 receiving malicious message
  25. Vulnerability in voting machines has not been corrected after 11 years

ATTACKS

  1. Tumblr Patches Security Issue that Would Leak Emails, Hashed-Salted Passwords
  2. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  3. Redis 5.0 release, High-performance key-value database
  4. Information of 396K Users Exposed in Facepunch Data Breach
  5. 35 Million US Voter Registration Records Found for Sale on Dark Web
  6. FBI Releases Document with Measures for Defending Against Payroll Phishing Scams
  7. How Office 365 learned to reel in phish
  8. Another Phishing Scam is Appearing in Small Business Inboxes
  9. Phishers target book publishers in new campaign
  10. Pentagon Disclosed Data Breach At Department Of Defense Affecting 30,000 Workers
  11. Is this the simple solution to password re-use?
  12. 35 million US voter records up for sale on the dark web
  13. Who is to blame for the majority of data breaches?
  14. Public Cloud Phishing
  15. Learn how hackers used TLS certificates to launch @netflix #phishing attacks from expert Michael Cobb of @thehairyITdog
  16. GreyEnergy: New malware campaign targets critical infrastructure companies
  17. Tumblr Patches A Flaw That Could Have Exposed Users’ Account Info
  18. Anthem pays out record $16m over data breach
  19. SEO Poisoning Campaign Targeting U.S. Midterm Election Keywords
  20. "Attackers have expanded [phishing attacks] significantly into SMS and social media, and are displaying a preference for targeting personal email
  21. .@Google Firebase #DatabaseSecurity proved insufficient when bypassed by hackers to leak data. Learn more about this #SecurityFlaw from expert Michael
  22. 35 million voter records from 19 US states for sale
  23. Alphabet in the soup for keeping quiet about Google+ data leak bug
  24. Anthem Mega-Breach: Record $16 Million HIPAA Settlement
  25. US Voter Records for Sale on Hacker Forum
  26. Millions of US Voter Records for Sale
  27. 35 Million U.S Voter Records Selling in Popular Dark web Hacking Forum from $150 USD to $12,500 USD
  28. Faculties and Staff of Chapman got Affected by the ‘Critical’ Phishing Attack
  29. LibSSH Flaw Allows Hackers to Take Over Servers Without Password
  30. Travel data for about 30,000 individuals was exposed in a Pentagon #DataBreach and experts expect that the information could be

THREATS

  1. AISA 2018: Japan's journey from a cryptocurrency hack to better regulation
  2. Cisco Patches Remotely Exploitable High Risk Security Bugs in Multiple Products
  3. Libssh Vulnerability Exposes Servers to Attacks
  4. Chrome 70 Updates Sign-In Options, Patches 23 Flaws
  5. VoiceOver iOS 12 Bug Creates Lock Screen Bypass Exposing User Photos
  6. LuminosityLink RAT Author Sentenced to 30 Months in Prison
  7. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  8. Tumblr discloses vulnerability but says 'no evidence that this bug was abused'
  9. Oracle Fixes 301 Flaws in October Critical Patch Update
  10. Podcast: A Utility Ransomware Attack, Post-Hurricane
  11. Serious SSH bug lets crooks log in just by asking nicely
  12. Oracle Patched Over 300 Vulnerabilities in Its Q3 2018 Critical Patch Update
  13. LibSSH Flaw Leaves Thousands Of Servers At Risk Of Hijacking
  14. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  15. CVE-2018-10933: Libssh Server Side Authentication Bypass Vulnerability Alert
  16. Thousands of servers easy to hack due to a LibSSH Flaw
  17. Take a Bite out of the Vulnerability Remediation Backlog with InsightVM
  18. How Blockchain Is Making it Easier for Fintech Companies to Scale Up
  19. WhiteSource raises $35 million for open source flaw detection platform
  20. CVE-2018-3211: Java Usage Tracker Local Elevation of Privilege on Windows
  21. Oracle CPU October 2018: 301 vulnerabilities patched
  22. A hacker who used fake advertisements placed on local newspaper websites to spread malware has been sentenced to 33 months
  23. Thousands Of Servers Vulnerable To Hacking Due To libssh Flaw
  24. Im Interview erläutert Georgeta Toth, Regional Director bei dem Security-Spezialisten #Proofpoint, den Einfluss der Crypto-Mining-#Malware auf Endgeräte in Unternehmen.
  25. GreyEnergy: New malware campaign targets critical infrastructure companies
  26. Critical Vulnerabilities Allow Takeover of D-Link Routers
  27. Tumblr Patches A Flaw That Could Have Exposed Users’ Account Info
  28. Remote Code Implantation Flaw Found in Medtronic Cardiac Programmers
  29. Insult to injury: Malware menace soaks water-logged utility ravaged by Hurricane Florence
  30. Alphabet in the soup for keeping quiet about Google+ data leak bug
  31. Hacker: I'm logged in. New LibSSH Vulnerability: OK! I believe you.
  32. Brazil expert discovers Oracle flaw that allows massive DDoS attacks
  33. Endpoint security solutions challenged by zero-day and fileless attacks
  34. VMware addressed Code Execution Flaw in its ESXi, Workstation, and Fusion products
  35. Flaws in Branch.io Affected Over 685 Million Users
  36. How does #FacexWorm #malware use @Facebook Messenger to spread? Learn more about this new malware with expert @lewisnic.
  37. Ransomware attack hits North Carolina water utility following hurricane
  38. Android Apps claim to mine unminable cryptocurrency, just show ads
  39. #GroupIB has estimated that cryptocurrency exchanges suffered a total loss of $882 mln due to targeted attacks in 2017 and
  40. New GreyEnergy Malware Targets ICS, Tied with BlackEnergy and TeleBots
  41. Security flaw in libssh leaves thousands of servers at risk of hijacking
  42. How does #MassMiner #malware infect systems across the web?
  43. A crippling ransomware attack hit a water utility in the aftermath of Hurricane Florence
  44. Oracle patches 301 vulnerabilities, including 46 with a 9.8+ severity rating
  45. VMware Patches Code Execution Flaw in Virtual Graphics Card
  46. Avast scores high in malware protection | Avast
  47. CVE-2018-3245: Weblogic Remote Code Execution Vulnerability Alert
  48. Oracle releases Critical Patch Update Advisory – October 2018: fix 301 security bugs
  49. Git RCE Vulnerability (CVE-2018-17456)Security Advisory
  50. Sony has solved the crash of PS4 receiving malicious message
  51. LibSSH Flaw Allows Hackers to Take Over Servers Without Password
  52. Abandoned Tweet Counter Hijacked With Malicious Script
  53. 21-year-old Hacker Sentenced to 30 Months Prison for Creating Popular Hacking Tool LumunosityLink RAT
  54. Vulnerability in voting machines has not been corrected after 11 years
  55. Vulnerability in Apple VoiceOver allows hackers access to user photos
  56. Google Chrome 70.0.3538.67 releases: fix multiple high-risk vulnerabilities
  57. The attackers learn that due to the complexity and fluctuations of the pulping process, any changes could take up to
  58. The Qihoo @360CoreSec team found a @Microsoft vulnerability -- named Double Kill -- that affects applications through #MicrosoftOffice documents. Learn

CRIME

  1. LuminosityLink RAT Author Sentenced to 30 Months in Prison
  2. Information of 396K Users Exposed in Facepunch Data Breach
  3. FBI Releases Document with Measures for Defending Against Payroll Phishing Scams
  4. Another Phishing Scam is Appearing in Small Business Inboxes
  5. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  6. Who is to blame for the majority of data breaches?
  7. How Blockchain Is Making it Easier for Fintech Companies to Scale Up
  8. A hacker who used fake advertisements placed on local newspaper websites to spread malware has been sentenced to 33 months
  9. SEO Poisoning Campaign Targeting U.S. Midterm Election Keywords
  10. WTB: MuddyWater Expands Operations
  11. Millions of US Voter Records for Sale
  12. Abandoned Tweet Counter Hijacked With Malicious Script
  13. 21-year-old Hacker Sentenced to 30 Months Prison for Creating Popular Hacking Tool LumunosityLink RAT
  14. Vulnerability in Apple VoiceOver allows hackers access to user photos

POLITICS

  1. Cisco Patches Remotely Exploitable High Risk Security Bugs in Multiple Products
  2. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  3. 'GreyEnergy' Cyberspies Target Ukraine, Poland
  4. New research highlights Vietnamese group's custom hacking tools
  5. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  6. GreyEnergy: New malware campaign targets critical infrastructure companies
  7. Attackers identified in the pre-espionage stage of CNI attack
  8. SEO Poisoning Campaign Targeting U.S. Midterm Election Keywords
  9. GreyEnergy group targeting critical infrastructure with espionage
  10. A crippling ransomware attack hit a water utility in the aftermath of Hurricane Florence
  11. Vulnerability in voting machines has not been corrected after 11 years

Oct 17, 2018

APT report for 2018-10-16

TRANSNATIONAL / UNKNOWN

  1. CVE-2018-8453 Zero-Day Flaw Exploited by FruityArmor APT

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-16

WINDOWS

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. CVE-2018-8453 Zero-Day Flaw Exploited by FruityArmor APT
  3. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine
  4. Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits

LINUX

  1. 7 Useful Android Vulnerability Scanners

UNIX

Nil

ANDROID

  1. Chrome 70 arrives with fingerprint login for websites, extension controls, and 23 security fixes
  2. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  3. 7 Useful Android Vulnerability Scanners
  4. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect

IOS

  1. Bug in New iOS Lets Attacker Access iPhone Pics
  2. Report: near-400% increase in crypto-mining malware attacks against iPhones
  3. Cryptomining attacks against Apple devices increase sharply
  4. Cryptojacking attacks against iPhone devices increase
  5. New iPhone Bug Gives Anyone Access to Your Private Photos

MACOS

  1. Chrome 70 arrives with fingerprint login for websites, extension controls, and 23 security fixes

Threat report for 2018-10-16

DATA BREACH & DATA LOSS

  1. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  2. Pentagon data breach exposed travel data for 30,000 individuals
  3. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  4. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  5. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  6. Anthem Agrees To Pay $16 Million In Data Breach Privacy Settlement
  7. The Donald Daters Trump Dating App Exposed Its Users Data
  8. 2018 US voter records offered for sale on hacking forum
  9. #TLBleed exploits abuse Intel's HTT chip feature to leak data. Find out how hackers could launch side-channel attacks to obtain
  10. 35 million US voter records available for sale in a hacking forum
  11. Anthem agrees to pay $16 million in data breach privacy settlement
  12. Dating App for Trump Supporters Exposed Members’ Information
  13. After originally disclosing its latest data breach last month, Facebook revealed that hackers obtained data from some 30 million users. Here’s
  14. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  15. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  16. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  17. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  18. UK’s MoD Exposed in 37 Security Breaches: Report
  19. 35 million voter records from 19 states for sale on hacking forum
  20. Pentagon data breach puts personal details of 30,000 staff at risk
  21. Facebook says fewer users affected by data breach
  22. Pentagon data breach puts personal details of 30,000 staff at risk
  23. Data breach in Pentagon’s service provider affected 30k people

DENIAL-OF-SERVICE

  1. Importance of DNS in Protecting Your Business from DDoS Attacks

MALVERTISING

Nil

PHISHING

  1. Chrome 70 arrives with fingerprint login for websites, extension controls, and 23 security fixes
  2. Chrome 70 released with revamped Google account login system
  3. Phishing Site Impersonates Financial Services Institution: https://www.digitalshadows.com/blog-and-research/phishing-site-impersonates-financial-services-institution/ … (via @mazzazone)
  4. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  5. Phishing and Facebook – a test of reputation

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. In County Crippled by Hurricane, Water Utility Targeted in Ransomware Attack
  2. Madison County computer system infected with ransomware
  3. NC Water Utility Fights Post-Hurricane Ransomware
  4. A “critical water utility” in a county crippled by Hurricane #Florence was hit by a #ransomware attack. The #cyberattack has
  5. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11

CRYPTOMINING & CRYPTOCURRENCIES

  1. SAP Boosts Blockchain Integration and Customer Flexibility
  2. How to Create Blockchain Applications
  3. Report: near-400% increase in crypto-mining malware attacks against iPhones
  4. Line lists cryptocurrency on Bitbox exchange
  5. You are who you say you are: Establishing digital trust with the blockchain
  6. Cryptomining attacks against Apple devices increase sharply
  7. Cryptojacking attacks against iPhone devices increase

MALWARE

  1. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  2. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  3. Malicious RTF Documents Deliver Information Stealers
  4. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  5. #Stegware: it's #Malware that uses #steganography techniques to avoid detection
  6. Report: near-400% increase in crypto-mining malware attacks against iPhones
  7. Octopus malware wraps tentacles around former Telegram users in Central Asia
  8. Mikko didn't put Brain -- the first PC virus -- on his list but he did track down its authors
  9. Now Surfing about your Favourite Celebrities can make you Vulnerable to Virus Attack
  10. Malware Attack Popular Amongst the Hackers, Even though it Dips in Q2 in 2018
  11. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11
  12. Cybercriminals Advertising Godzilla Loader Malware On Dark Web Forums
  13. Most Important Considerations with Malware Analysis Cheats And Tools list
  14. Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits

EXPLOIT

  1. Sony Fixed PlayStation 4 Message Exploit Leasing to a DoS Condition
  2. Hackers tamper with exploit chain to drop Agent Tesla, circumvent antivirus solutions
  3. Numerous PlayStation 4 users reported that a PlayStation Network message exploit is crashing their consoles, requiring a factory reset in

VULNERABILITY

  1. [SingCERT] Alert on Multiple Vulnerabilities in PHP
  2. Multiple Vulnerabilities Allow Attackers to Take Full Control of Linksys Routers
  3. 7 Useful Android Vulnerability Scanners
  4. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  5. Bug in New iOS Lets Attacker Access iPhone Pics
  6. Info of 685 Million Users at Risk Because of Multiple Branch.io XSS Flaws
  7. CVE-2018-8453 Zero-Day Flaw Exploited by FruityArmor APT
  8. Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
  9. Tinder profiles were 'at risk' due to XSS vulnerability
  10. 685 million users may be affected by the Branch.io service XSS vulnerability
  11. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  12. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  13. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  14. #Shodan, a device search engine, can help identify #ICS security vulnerabilities. Learn more about how Shodan works and how it
  15. "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well
  16. 685 million users may be affected by the Branch.io service XSS vulnerability
  17. Juniper Networks launches multiple solutions for Junos OS vulnerabilities
  18. New iPhone Bug Gives Anyone Access to Your Private Photos
  19. Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits

Region brief for 2018-10-16

ASIA

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  3. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  4. Line lists cryptocurrency on Bitbox exchange

OCEANIA

Nil

NORTH AMERICA

  1. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  2. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  3. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  4. Madison County computer system infected with ransomware
  5. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  6. 2018 US voter records offered for sale on hacking forum
  7. 35 million US voter records available for sale in a hacking forum
  8. Anthem agrees to pay $16 million in data breach privacy settlement
  9. Dating App for Trump Supporters Exposed Members’ Information
  10. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  11. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  12. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  13. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  14. UK’s MoD Exposed in 37 Security Breaches: Report
  15. Report: near-400% increase in crypto-mining malware attacks against iPhones
  16. 35 million voter records from 19 states for sale on hacking forum
  17. Pentagon data breach puts personal details of 30,000 staff at risk
  18. Data breach in Pentagon’s service provider affected 30k people

SOUTH AMERICA

  1. A Russian cyber vigilante is patching outdated MikroTik routers exposed online

EUROPE

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  3. Bug in New iOS Lets Attacker Access iPhone Pics
  4. Sony Fixed PlayStation 4 Message Exploit Leasing to a DoS Condition
  5. 2018 US voter records offered for sale on hacking forum
  6. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  7. 35 million US voter records available for sale in a hacking forum
  8. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  9. UK’s MoD Exposed in 37 Security Breaches: Report
  10. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  11. Octopus malware wraps tentacles around former Telegram users in Central Asia
  12. Phishing and Facebook – a test of reputation
  13. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine
  14. New iPhone Bug Gives Anyone Access to Your Private Photos

AFRICA

Nil

Sector brief for 2018-10-16

HEALTHCARE

Nil

TRANSPORT

Nil

BANKING & FINANCE

  1. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  2. Phishing Site Impersonates Financial Services Institution: https://www.digitalshadows.com/blog-and-research/phishing-site-impersonates-financial-services-institution/ … (via @mazzazone)
  3. 35 million US voter records available for sale in a hacking forum
  4. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  5. UK’s MoD Exposed in 37 Security Breaches: Report
  6. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  7. Pentagon data breach puts personal details of 30,000 staff at risk
  8. Pentagon data breach puts personal details of 30,000 staff at risk
  9. Data breach in Pentagon’s service provider affected 30k people
  10. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine

INFORMATION & TELECOMMUNICATION

  1. Multiple Vulnerabilities Allow Attackers to Take Full Control of Linksys Routers
  2. 7 Useful Android Vulnerability Scanners
  3. Bug in New iOS Lets Attacker Access iPhone Pics
  4. Sony Fixed PlayStation 4 Message Exploit Leasing to a DoS Condition
  5. Phishing Site Impersonates Financial Services Institution: https://www.digitalshadows.com/blog-and-research/phishing-site-impersonates-financial-services-institution/ … (via @mazzazone)
  6. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  7. After originally disclosing its latest data breach last month, Facebook revealed that hackers obtained data from some 30 million users. Here’s
  8. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  9. Numerous PlayStation 4 users reported that a PlayStation Network message exploit is crashing their consoles, requiring a factory reset in
  10. Facebook says fewer users affected by data breach
  11. Phishing and Facebook – a test of reputation
  12. Mikko didn't put Brain -- the first PC virus -- on his list but he did track down its authors
  13. Line lists cryptocurrency on Bitbox exchange

FOOD

Nil

WATER

Nil

ENERGY

  1. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine

GOVERNMENT & PUBLIC SERVICE

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  3. 2018 US voter records offered for sale on hacking forum
  4. 35 million US voter records available for sale in a hacking forum
  5. Anthem agrees to pay $16 million in data breach privacy settlement
  6. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  7. UK’s MoD Exposed in 37 Security Breaches: Report
  8. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  9. 35 million voter records from 19 states for sale on hacking forum
  10. Pentagon data breach puts personal details of 30,000 staff at risk
  11. Pentagon data breach puts personal details of 30,000 staff at risk
  12. Data breach in Pentagon’s service provider affected 30k people
  13. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine

Daily brief for 2018-10-16

ASIA

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  3. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  4. Line lists cryptocurrency on Bitbox exchange

WORLD

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  3. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  4. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  5. Bug in New iOS Lets Attacker Access iPhone Pics
  6. Sony Fixed PlayStation 4 Message Exploit Leasing to a DoS Condition
  7. New ShadowTalk Episode 45 This week, CISO @rickhholland, @drshellface, & Simon Hall join Rafael Amado to cover the
  8. Madison County computer system infected with ransomware
  9. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  10. 2018 US voter records offered for sale on hacking forum
  11. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  12. 35 million US voter records available for sale in a hacking forum
  13. Anthem agrees to pay $16 million in data breach privacy settlement
  14. Dating App for Trump Supporters Exposed Members’ Information
  15. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  16. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  17. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  18. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  19. UK’s MoD Exposed in 37 Security Breaches: Report
  20. Report: near-400% increase in crypto-mining malware attacks against iPhones
  21. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  22. 35 million voter records from 19 states for sale on hacking forum
  23. Octopus malware wraps tentacles around former Telegram users in Central Asia
  24. Phishing and Facebook – a test of reputation
  25. Pentagon data breach puts personal details of 30,000 staff at risk
  26. Data breach in Pentagon’s service provider affected 30k people
  27. NotPetya linked to the Industroyer attack against energy infrastructure in Ukraine
  28. New iPhone Bug Gives Anyone Access to Your Private Photos

ATTACKS

  1. Chrome 70 arrives with fingerprint login for websites, extension controls, and 23 security fixes
  2. Chrome 70 released with revamped Google account login system
  3. Insurer Anthem Will Pay Record $16M for Massive Data Breach
  4. Pentagon data breach exposed travel data for 30,000 individuals
  5. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  6. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  7. Personal Records Of 30,000 US Department Of Defense Workers Swiped By Miscreants
  8. Anthem Agrees To Pay $16 Million In Data Breach Privacy Settlement
  9. The Donald Daters Trump Dating App Exposed Its Users Data
  10. Phishing Site Impersonates Financial Services Institution: https://www.digitalshadows.com/blog-and-research/phishing-site-impersonates-financial-services-institution/ … (via @mazzazone)
  11. 2018 US voter records offered for sale on hacking forum
  12. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  13. #TLBleed exploits abuse Intel's HTT chip feature to leak data. Find out how hackers could launch side-channel attacks to obtain
  14. 35 million US voter records available for sale in a hacking forum
  15. Anthem agrees to pay $16 million in data breach privacy settlement
  16. Dating App for Trump Supporters Exposed Members’ Information
  17. After originally disclosing its latest data breach last month, Facebook revealed that hackers obtained data from some 30 million users. Here’s
  18. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  19. Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants
  20. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  21. Pentagon Travel Provider Data Breach Counts 30,000 Victims
  22. UK’s MoD Exposed in 37 Security Breaches: Report
  23. 35 million voter records from 19 states for sale on hacking forum
  24. Pentagon data breach puts personal details of 30,000 staff at risk
  25. Facebook says fewer users affected by data breach
  26. Phishing and Facebook – a test of reputation
  27. Pentagon data breach puts personal details of 30,000 staff at risk
  28. Data breach in Pentagon’s service provider affected 30k people

THREATS

  1. SAP Boosts Blockchain Integration and Customer Flexibility
  2. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  3. [SingCERT] Alert on Multiple Vulnerabilities in PHP
  4. Multiple Vulnerabilities Allow Attackers to Take Full Control of Linksys Routers
  5. In County Crippled by Hurricane, Water Utility Targeted in Ransomware Attack
  6. 7 Useful Android Vulnerability Scanners
  7. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  8. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  9. Bug in New iOS Lets Attacker Access iPhone Pics
  10. Malicious RTF Documents Deliver Information Stealers
  11. Info of 685 Million Users at Risk Because of Multiple Branch.io XSS Flaws
  12. Madison County computer system infected with ransomware
  13. CVE-2018-8453 Zero-Day Flaw Exploited by FruityArmor APT
  14. How to Create Blockchain Applications
  15. NC Water Utility Fights Post-Hurricane Ransomware
  16. Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
  17. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  18. Tinder profiles were 'at risk' due to XSS vulnerability
  19. 685 million users may be affected by the Branch.io service XSS vulnerability
  20. A “critical water utility” in a county crippled by Hurricane #Florence was hit by a #ransomware attack. The #cyberattack has
  21. #Stegware: it's #Malware that uses #steganography techniques to avoid detection
  22. Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
  23. Report: near-400% increase in crypto-mining malware attacks against iPhones
  24. Hackers can use known security vulnerabilities with new technology to bypass Antivirus Software
  25. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  26. #Shodan, a device search engine, can help identify #ICS security vulnerabilities. Learn more about how Shodan works and how it
  27. Octopus malware wraps tentacles around former Telegram users in Central Asia
  28. Mikko didn't put Brain -- the first PC virus -- on his list but he did track down its authors
  29. Line lists cryptocurrency on Bitbox exchange
  30. "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well
  31. You are who you say you are: Establishing digital trust with the blockchain
  32. Now Surfing about your Favourite Celebrities can make you Vulnerable to Virus Attack
  33. Malware Attack Popular Amongst the Hackers, Even though it Dips in Q2 in 2018
  34. Cryptomining attacks against Apple devices increase sharply
  35. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11
  36. Cybercriminals Advertising Godzilla Loader Malware On Dark Web Forums
  37. 685 million users may be affected by the Branch.io service XSS vulnerability
  38. Cryptojacking attacks against iPhone devices increase
  39. Juniper Networks launches multiple solutions for Junos OS vulnerabilities
  40. Most Important Considerations with Malware Analysis Cheats And Tools list
  41. New iPhone Bug Gives Anyone Access to Your Private Photos
  42. Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits

CRIME

  1. Author of LuminosityLink Remote Access Trojan Gets 30 Months Sentence
  2. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  3. How to Create Blockchain Applications
  4. Recent @Proofpoint research shows that #German-speaking regions are facing targeted #phishing, #malware, and #BEC attacks.
  5. 35 million US voter records available for sale in a hacking forum
  6. Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing
  7. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  8. UK’s MoD Exposed in 37 Security Breaches: Report
  9. Report: near-400% increase in crypto-mining malware attacks against iPhones
  10. Facebook says fewer users affected by data breach
  11. Pentagon data breach puts personal details of 30,000 staff at risk

POLITICS

  1. Russia-linked APT group DustSquad targets diplomatic entities in Central Asia
  2. A Russian cyber vigilante is patching outdated MikroTik routers exposed online
  3. Estimated 35 Million Voter Records For Sale on Popular Hacking Forum
  4. UK’s MoD Exposed in 37 Security Breaches: Report
  5. RiskSense cloud service protects against cyber threats and vulnerabilities ahead of midterm elections
  6. Octopus malware wraps tentacles around former Telegram users in Central Asia
  7. "It is no secret that the #RemoteDesktop Protocol has long been a source of exploitable vulnerabilities, and it is well