Oct 19, 2018

Threat report for 2018-10-18

DATA BREACH & DATA LOSS

  1. 35 Million Records Of US Voters Data For Sale On The Dark Web
  2. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  3. Tracking Tick Through Recent Campaigns Targeting East Asia
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  6. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  7. Apple to US users: Here's how you can now see what personal data we hold on you
  8. Open source web hosting software compromised with DDoS malware
  9. Anthem Settles with OCR for $16M for 2015 Data Breach
  10. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  11. Hackers can use legitimate #AdminTools to compromise networks. Learn more about "living off the land" attacks from expert Michael Cobb
  12. Tumblr patches bug that could have exposed user data
  13. 12.5 Million Email Archives Exposed - Why would #cybercriminals go to a #darkweb market and pay for access when they
  14. #NetSpectre exploits leak data remotely via side-channel attacks. Learn how to use #ThreatModeling to stop speculative execution from expert Ed
  15. Tracking Tick Through Recent Campaigns Targeting East Asia
  16. McAfee researchers uncover ‘significant’ espionage campaign
  17. Apple to US users: Here's how you can now see what personal data we hold on you
  18. Tumblr Fixes Security Bug that Leaked Private Account Info
  19. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  20. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  21. VestaCP compromised in a new supply-chain attack
  22. VestaCP compromised in a new supply-chain attack
  23. Anthem to pay record £12M for 2015 data breach
  24. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  25. In the wake of numerous high-profile data breaches and privacy incidents, consumers are more aware and concerned than ever about
  26. Senate inquiry recommends locking down My Health Record by default
  27. Tumblr Vulnerability Exposed User Account Information
  28. The Equifax Hack Uploaded Files the Right Way
  29. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise
  30. SEO pollution campaign affects web searches related to EU midterm elections

DENIAL-OF-SERVICE

  1. Open source web hosting software compromised with DDoS malware
  2. Who and Why Make DDoS Attacks on The Site of Colleges and Universities ?
  3. A10 Networks provides cloud, Internet and gaming providers with 1 RU DDoS defense appliance

MALVERTISING

Nil

PHISHING

  1. The libssh “login with no password” bug – what you need to know [VIDEO]

WEB DEFACEMENT

Nil

BOTNET

  1. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  2. How does the resurgent VPNFilter botnet target victims?

RANSOMWARE

  1. 7 best practices for negotiating ransomware payments

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Adobe Flash update hides cryptocurrency malware
  2. Crooks are attempting to spread their cryptojacking malware to unsuspecting victims by disguising it as an update for Flash. The malicious
  3. Top 10 Blockchain Development Companies
  4. Crypto Mining Malware Runs on iPhone
  5. Cryptocurrency Miners Hiding As Flash Updates
  6. Cryptomining Malware Attacks On iPhones Grew By 400%
  7. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  8. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  9. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  10. LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
  11. Researcher Livestreams 51% Attack on Altcoin Blockchain
  12. Cryptojacking: A hidden cost for your company
  13. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers

MALWARE

  1. Fake Adobe Flash update hides cryptocurrency malware
  2. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  3. Open source web hosting software compromised with DDoS malware
  4. LuminosityLink Spyware Mastermind Gets 30 Months In The Clink
  5. Crooks are attempting to spread their cryptojacking malware to unsuspecting victims by disguising it as an update for Flash. The malicious
  6. Crypto Mining Malware Runs on iPhone
  7. GPlayed Trojan - .Net Playing with Google Market
  8. Cryptomining Malware Attacks On iPhones Grew By 400%
  9. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  10. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  11. LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
  12. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  13. XBash Malware Security Advisory
  14. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  15. Stegware: How is #malware using #steganography techniques to avoid detection?
  16. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  17. In order to distribute the attack payload, the code needs to be downloaded onto the PLCs & safety controllers. This

EXPLOIT

Nil

VULNERABILITY

  1. GitHub now warns devs about bugs that led to Equifax breach
  2. Flaws in telepresence robots allow hackers access to pictures, video feeds
  3. Branch.io Flaws may have affected as many as 685 million individuals
  4. Critical Remote Code Execution Vulnerabilities Patched by Drupal
  5. Code Execution Vulnerability Patched in Library Used by VLC, Other Media Players
  6. Flaws Open Telepresence Robots to Prying Eyes
  7. [SingCERT] Alert on Multiple Security Vulnerabilities in Oracle's Enterprise Products
  8. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  9. A newly disclosed #libSSH vulnerability could allow an attacker #AdminAccess to a server with little effort. By @MT_Heller
  10. Drupal addresses multiple critical flaws with latest release
  11. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  12. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  13. Wapiti – The Black Box Vulnerability Scanner for Web Applications
  14. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  15. The libssh “login with no password” bug – what you need to know [VIDEO]
  16. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  17. How Shodan helps identify ICS cybersecurity vulnerabilities
  18. Oracle extends its thanks to Qihoo 360 for fixing the vulnerabilities of Weblogic
  19. Tumblr patches bug that could have exposed user data
  20. [SingCERT] Alert on Linksys E Series Routers Vulnerabilities (CVE-2018-3953, CVE-2018-3954, and CVE-2018-3955)
  21. Apache Access Vulnerability Could Affect Thousands of Applications
  22. Last year, D-Link flubbed a router bug-fix, so it's back with total pwnage
  23. Party like it's 1989... SVGA code bug haunts VMware's house, lets guests flee to host OS
  24. Oracle Patches 301 Vulnerabilities in October Update
  25. Tumblr Fixes Security Bug that Leaked Private Account Info
  26. Ruby 2.4.5 released: 40 bug fixes
  27. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  28. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  29. New libSSH vulnerability gives root access to servers
  30. A 4-year-old #libSSH vulnerability can allow attackers to easily log in to servers with full administrative control, but it is
  31. The implications of the NetSpectre vulnerability
  32. #Shodan can be a helpful tool for security professionals to locate #ICSsecurity vulnerabilities. Expert Ernie Hayden explains how Shodan works
  33. Oracle security updates contains 45 critical-rated vulnerability
  34. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  35. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  36. Chaining three critical vulnerabilities allows takeover of D-Link routers
  37. Tumblr Fixes Critical Security Bug That Exposes User Account Details
  38. Tumblr Vulnerability Exposed User Account Information
  39. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise

Region brief for 2018-10-18

ASIA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. Tracking Tick Through Recent Campaigns Targeting East Asia
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  6. Oceansalt Linked To Defunct Chinese APT Comment Crew
  7. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million
  8. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  9. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  10. Oracle extends its thanks to Qihoo 360 for fixing the vulnerabilities of Weblogic
  11. Tracking Tick Through Recent Campaigns Targeting East Asia
  12. XBash Malware Security Advisory
  13. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  14. Targeted attacks on crypto exchanges resulted in a loss of $882 million
  15. The Equifax Hack Uploaded Files the Right Way
  16. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  17. ‘Operation Oceansalt’ Delivers Wave After Wave
  18. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

OCEANIA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  3. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  4. Senate inquiry recommends locking down My Health Record by default

NORTH AMERICA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. Branch.io Flaws may have affected as many as 685 million individuals
  3. 35 Million Records Of US Voters Data For Sale On The Dark Web
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. Apple to US users: Here's how you can now see what personal data we hold on you
  6. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  7. New Pennsylvania Law Imposes Fine for Using Drones to Spy
  8. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  9. Crypto Mining Malware Runs on iPhone
  10. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  11. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  12. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  13. Apple to US users: Here's how you can now see what personal data we hold on you
  14. XBash Malware Security Advisory
  15. Anthem to pay record £12M for 2015 data breach
  16. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  17. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  18. ‘Operation Oceansalt’ Delivers Wave After Wave
  19. SEO pollution campaign affects web searches related to EU midterm elections
  20. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

SOUTH AMERICA

Nil

EUROPE

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  4. GreyEnergy Potential Successor of BlackEnergy
  5. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  6. Chaining three critical vulnerabilities allows takeover of D-Link routers

AFRICA

  1. The author of the LuminosityLink RAT sentenced to 30 Months in Prison

Sector brief for 2018-10-18

HEALTHCARE

  1. Anthem to pay record £12M for 2015 data breach

TRANSPORT

Nil

BANKING & FINANCE

  1. Anthem Settles with OCR for $16M for 2015 Data Breach
  2. Top 10 Blockchain Development Companies
  3. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million

INFORMATION & TELECOMMUNICATION

  1. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  2. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  3. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million
  4. Tumblr patches bug that could have exposed user data
  5. [SingCERT] Alert on Linksys E Series Routers Vulnerabilities (CVE-2018-3953, CVE-2018-3954, and CVE-2018-3955)
  6. 12.5 Million Email Archives Exposed - Why would #cybercriminals go to a #darkweb market and pay for access when they
  7. Tumblr Fixes Security Bug that Leaked Private Account Info
  8. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  9. In the wake of numerous high-profile data breaches and privacy incidents, consumers are more aware and concerned than ever about
  10. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  11. Tumblr Fixes Critical Security Bug That Exposes User Account Details
  12. Tumblr Vulnerability Exposed User Account Information
  13. Who and Why Make DDoS Attacks on The Site of Colleges and Universities ?

FOOD

Nil

WATER

Nil

ENERGY

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. New Pennsylvania Law Imposes Fine for Using Drones to Spy
  4. GreyEnergy Potential Successor of BlackEnergy

GOVERNMENT & PUBLIC SERVICE

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. 35 Million Records Of US Voters Data For Sale On The Dark Web
  3. Cyber Espionage Campaign Reuses Code from China's APT1
  4. New Pennsylvania Law Imposes Fine for Using Drones to Spy
  5. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  6. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  7. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  8. SEO pollution campaign affects web searches related to EU midterm elections

Daily brief for 2018-10-18

ASIA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. Tracking Tick Through Recent Campaigns Targeting East Asia
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  6. Oceansalt Linked To Defunct Chinese APT Comment Crew
  7. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million
  8. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  9. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  10. Oracle extends its thanks to Qihoo 360 for fixing the vulnerabilities of Weblogic
  11. Tracking Tick Through Recent Campaigns Targeting East Asia
  12. XBash Malware Security Advisory
  13. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  14. Targeted attacks on crypto exchanges resulted in a loss of $882 million
  15. The Equifax Hack Uploaded Files the Right Way
  16. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  17. ‘Operation Oceansalt’ Delivers Wave After Wave
  18. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

WORLD

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. Branch.io Flaws may have affected as many as 685 million individuals
  3. GreyEnergy cyberespionage group targets Poland and Ukraine
  4. 35 Million Records Of US Voters Data For Sale On The Dark Web
  5. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  6. Cyber Espionage Campaign Reuses Code from China's APT1
  7. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  8. Apple to US users: Here's how you can now see what personal data we hold on you
  9. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  10. New Pennsylvania Law Imposes Fine for Using Drones to Spy
  11. GreyEnergy Potential Successor of BlackEnergy
  12. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  13. Crypto Mining Malware Runs on iPhone
  14. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  15. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  16. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  17. Apple to US users: Here's how you can now see what personal data we hold on you
  18. XBash Malware Security Advisory
  19. Anthem to pay record £12M for 2015 data breach
  20. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  21. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  22. Chaining three critical vulnerabilities allows takeover of D-Link routers
  23. Senate inquiry recommends locking down My Health Record by default
  24. ‘Operation Oceansalt’ Delivers Wave After Wave
  25. SEO pollution campaign affects web searches related to EU midterm elections
  26. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

ATTACKS

  1. 35 Million Records Of US Voters Data For Sale On The Dark Web
  2. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  3. Tracking Tick Through Recent Campaigns Targeting East Asia
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  6. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  7. Apple to US users: Here's how you can now see what personal data we hold on you
  8. Open source web hosting software compromised with DDoS malware
  9. Anthem Settles with OCR for $16M for 2015 Data Breach
  10. The libssh “login with no password” bug – what you need to know [VIDEO]
  11. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  12. Hackers can use legitimate #AdminTools to compromise networks. Learn more about "living off the land" attacks from expert Michael Cobb
  13. Tumblr patches bug that could have exposed user data
  14. 12.5 Million Email Archives Exposed - Why would #cybercriminals go to a #darkweb market and pay for access when they
  15. #NetSpectre exploits leak data remotely via side-channel attacks. Learn how to use #ThreatModeling to stop speculative execution from expert Ed
  16. Tracking Tick Through Recent Campaigns Targeting East Asia
  17. McAfee researchers uncover ‘significant’ espionage campaign
  18. Apple to US users: Here's how you can now see what personal data we hold on you
  19. Tumblr Fixes Security Bug that Leaked Private Account Info
  20. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  21. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  22. VestaCP compromised in a new supply-chain attack
  23. VestaCP compromised in a new supply-chain attack
  24. Anthem to pay record £12M for 2015 data breach
  25. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  26. In the wake of numerous high-profile data breaches and privacy incidents, consumers are more aware and concerned than ever about
  27. Senate inquiry recommends locking down My Health Record by default
  28. Tumblr Vulnerability Exposed User Account Information
  29. The Equifax Hack Uploaded Files the Right Way
  30. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise
  31. SEO pollution campaign affects web searches related to EU midterm elections

THREATS

  1. GitHub now warns devs about bugs that led to Equifax breach
  2. Flaws in telepresence robots allow hackers access to pictures, video feeds
  3. Fake Adobe Flash update hides cryptocurrency malware
  4. Branch.io Flaws may have affected as many as 685 million individuals
  5. Critical Remote Code Execution Vulnerabilities Patched by Drupal
  6. Code Execution Vulnerability Patched in Library Used by VLC, Other Media Players
  7. Flaws Open Telepresence Robots to Prying Eyes
  8. [SingCERT] Alert on Multiple Security Vulnerabilities in Oracle's Enterprise Products
  9. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  10. A newly disclosed #libSSH vulnerability could allow an attacker #AdminAccess to a server with little effort. By @MT_Heller
  11. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  12. Drupal addresses multiple critical flaws with latest release
  13. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  14. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  15. Open source web hosting software compromised with DDoS malware
  16. Wapiti – The Black Box Vulnerability Scanner for Web Applications
  17. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  18. LuminosityLink Spyware Mastermind Gets 30 Months In The Clink
  19. Crooks are attempting to spread their cryptojacking malware to unsuspecting victims by disguising it as an update for Flash. The malicious
  20. Top 10 Blockchain Development Companies
  21. Crypto Mining Malware Runs on iPhone
  22. The libssh “login with no password” bug – what you need to know [VIDEO]
  23. Cryptocurrency Miners Hiding As Flash Updates
  24. GPlayed Trojan - .Net Playing with Google Market
  25. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  26. How Shodan helps identify ICS cybersecurity vulnerabilities
  27. Cryptomining Malware Attacks On iPhones Grew By 400%
  28. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  29. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  30. Oracle extends its thanks to Qihoo 360 for fixing the vulnerabilities of Weblogic
  31. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  32. Tumblr patches bug that could have exposed user data
  33. [SingCERT] Alert on Linksys E Series Routers Vulnerabilities (CVE-2018-3953, CVE-2018-3954, and CVE-2018-3955)
  34. Apache Access Vulnerability Could Affect Thousands of Applications
  35. LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
  36. Last year, D-Link flubbed a router bug-fix, so it's back with total pwnage
  37. Party like it's 1989... SVGA code bug haunts VMware's house, lets guests flee to host OS
  38. Oracle Patches 301 Vulnerabilities in October Update
  39. Tumblr Fixes Security Bug that Leaked Private Account Info
  40. Ruby 2.4.5 released: 40 bug fixes
  41. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  42. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  43. XBash Malware Security Advisory
  44. New libSSH vulnerability gives root access to servers
  45. A 4-year-old #libSSH vulnerability can allow attackers to easily log in to servers with full administrative control, but it is
  46. The implications of the NetSpectre vulnerability
  47. Researcher Livestreams 51% Attack on Altcoin Blockchain
  48. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  49. #Shodan can be a helpful tool for security professionals to locate #ICSsecurity vulnerabilities. Expert Ernie Hayden explains how Shodan works
  50. Oracle security updates contains 45 critical-rated vulnerability
  51. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  52. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  53. Stegware: How is #malware using #steganography techniques to avoid detection?
  54. Cryptojacking: A hidden cost for your company
  55. Chaining three critical vulnerabilities allows takeover of D-Link routers
  56. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  57. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  58. Tumblr Fixes Critical Security Bug That Exposes User Account Details
  59. In order to distribute the attack payload, the code needs to be downloaded onto the PLCs & safety controllers. This
  60. Tumblr Vulnerability Exposed User Account Information
  61. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise
  62. 7 best practices for negotiating ransomware payments

CRIME

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  4. New Pennsylvania Law Imposes Fine for Using Drones to Spy
  5. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million
  6. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  7. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  8. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  9. Tumblr patches bug that could have exposed user data
  10. 12.5 Million Email Archives Exposed - Why would #cybercriminals go to a #darkweb market and pay for access when they
  11. XBash Malware Security Advisory
  12. VestaCP compromised in a new supply-chain attack
  13. VestaCP compromised in a new supply-chain attack
  14. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  15. Targeted attacks on crypto exchanges resulted in a loss of $882 million
  16. 7 best practices for negotiating ransomware payments

POLITICS

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. New APT Could Signal Reemergence of Notorious Comment Crew
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. New Pennsylvania Law Imposes Fine for Using Drones to Spy
  6. GreyEnergy Spy APT Mounts Sophisticated Effort Against Critical Infrastructure
  7. GreyEnergy Potential Successor of BlackEnergy
  8. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  9. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  10. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  11. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  12. Tracking Tick Through Recent Campaigns Targeting East Asia
  13. McAfee researchers uncover ‘significant’ espionage campaign
  14. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  15. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

Oct 18, 2018

APT report for 2018-10-17

TRANSNATIONAL / UNKNOWN

  1. WTB: MuddyWater Expands Operations
  2. Russian Hackers Attack Specialist in Customer Review Tied to Innumerable Websites

CHINA

  1. Top 5 Publicly Accessible Hacking Tools You Can Download Today
  2. WTB: MuddyWater Expands Operations

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

  1. New research highlights Vietnamese group's custom hacking tools

IRAN

  1. WTB: MuddyWater Expands Operations

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. 'GreyEnergy' Cyberspies Target Ukraine, Poland
  2. 3 Years After Attacks on Ukraine Power Grid, BlackEnergy Successor Poses Growing Threat
  3. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  4. Attackers identified in the pre-espionage stage of CNI attack
  5. GreyEnergy group targeting critical infrastructure with espionage
  6. GreyEnergy: Updated arsenal of one of the most dangerous threat actors
  7. GreyEnergy: Updated arsenal of one of the most dangerous threat actors
  8. New GreyEnergy Malware Targets ICS, Tied with BlackEnergy and TeleBots

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-17

WINDOWS

  1. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  2. CVE-2018-3211: Java Usage Tracker Local Elevation of Privilege on Windows
  3. Top 5 Publicly Accessible Hacking Tools You Can Download Today
  4. WTB: MuddyWater Expands Operations
  5. VMware addressed Code Execution Flaw in its ESXi, Workstation, and Fusion products
  6. Git RCE Vulnerability (CVE-2018-17456)Security Advisory

LINUX

  1. Git RCE Vulnerability (CVE-2018-17456)Security Advisory

UNIX

Nil

ANDROID

  1. WTB: MuddyWater Expands Operations
  2. VMware addressed Code Execution Flaw in its ESXi, Workstation, and Fusion products
  3. Android Apps claim to mine unminable cryptocurrency, just show ads

IOS

  1. VoiceOver iOS 12 Bug Creates Lock Screen Bypass Exposing User Photos
  2. Vulnerability in Apple VoiceOver allows hackers access to user photos
  3. Google Chrome 70.0.3538.67 releases: fix multiple high-risk vulnerabilities

MACOS

  1. Git RCE Vulnerability (CVE-2018-17456)Security Advisory
  2. Vulnerability in Apple VoiceOver allows hackers access to user photos

Threat report for 2018-10-17

DATA BREACH & DATA LOSS

  1. Tumblr Patches Security Issue that Would Leak Emails, Hashed-Salted Passwords
  2. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  3. Redis 5.0 release, High-performance key-value database
  4. Information of 396K Users Exposed in Facepunch Data Breach
  5. 35 Million US Voter Registration Records Found for Sale on Dark Web
  6. Phishers target book publishers in new campaign
  7. Pentagon Disclosed Data Breach At Department Of Defense Affecting 30,000 Workers
  8. 35 million US voter records up for sale on the dark web
  9. Who is to blame for the majority of data breaches?
  10. GreyEnergy: New malware campaign targets critical infrastructure companies
  11. Tumblr Patches A Flaw That Could Have Exposed Users’ Account Info
  12. Anthem pays out record $16m over data breach
  13. SEO Poisoning Campaign Targeting U.S. Midterm Election Keywords
  14. .@Google Firebase #DatabaseSecurity proved insufficient when bypassed by hackers to leak data. Learn more about this #SecurityFlaw from expert Michael
  15. 35 million voter records from 19 US states for sale
  16. Alphabet in the soup for keeping quiet about Google+ data leak bug
  17. Anthem Mega-Breach: Record $16 Million HIPAA Settlement
  18. US Voter Records for Sale on Hacker Forum
  19. Millions of US Voter Records for Sale
  20. 35 Million U.S Voter Records Selling in Popular Dark web Hacking Forum from $150 USD to $12,500 USD
  21. Travel data for about 30,000 individuals was exposed in a Pentagon #DataBreach and experts expect that the information could be

DENIAL-OF-SERVICE

  1. Brazil expert discovers Oracle flaw that allows massive DDoS attacks

MALVERTISING

Nil

PHISHING

  1. FBI Releases Document with Measures for Defending Against Payroll Phishing Scams
  2. How Office 365 learned to reel in phish
  3. Another Phishing Scam is Appearing in Small Business Inboxes
  4. Is this the simple solution to password re-use?
  5. Public Cloud Phishing
  6. Learn how hackers used TLS certificates to launch @netflix #phishing attacks from expert Michael Cobb of @thehairyITdog
  7. "Attackers have expanded [phishing attacks] significantly into SMS and social media, and are displaying a preference for targeting personal email
  8. Faculties and Staff of Chapman got Affected by the ‘Critical’ Phishing Attack
  9. LibSSH Flaw Allows Hackers to Take Over Servers Without Password

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. Podcast: A Utility Ransomware Attack, Post-Hurricane
  2. Ransomware attack hits North Carolina water utility following hurricane
  3. A crippling ransomware attack hit a water utility in the aftermath of Hurricane Florence

CRYPTOMINING & CRYPTOCURRENCIES

  1. AISA 2018: Japan's journey from a cryptocurrency hack to better regulation
  2. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  3. How Blockchain Is Making it Easier for Fintech Companies to Scale Up
  4. Im Interview erläutert Georgeta Toth, Regional Director bei dem Security-Spezialisten #Proofpoint, den Einfluss der Crypto-Mining-#Malware auf Endgeräte in Unternehmen.
  5. Android Apps claim to mine unminable cryptocurrency, just show ads
  6. #GroupIB has estimated that cryptocurrency exchanges suffered a total loss of $882 mln due to targeted attacks in 2017 and

MALWARE

  1. LuminosityLink RAT Author Sentenced to 30 Months in Prison
  2. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  3. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  4. A hacker who used fake advertisements placed on local newspaper websites to spread malware has been sentenced to 33 months
  5. Im Interview erläutert Georgeta Toth, Regional Director bei dem Security-Spezialisten #Proofpoint, den Einfluss der Crypto-Mining-#Malware auf Endgeräte in Unternehmen.
  6. GreyEnergy: New malware campaign targets critical infrastructure companies
  7. Insult to injury: Malware menace soaks water-logged utility ravaged by Hurricane Florence
  8. How does #FacexWorm #malware use @Facebook Messenger to spread? Learn more about this new malware with expert @lewisnic.
  9. New GreyEnergy Malware Targets ICS, Tied with BlackEnergy and TeleBots
  10. How does #MassMiner #malware infect systems across the web?
  11. Avast scores high in malware protection | Avast
  12. Sony has solved the crash of PS4 receiving malicious message
  13. Abandoned Tweet Counter Hijacked With Malicious Script
  14. 21-year-old Hacker Sentenced to 30 Months Prison for Creating Popular Hacking Tool LumunosityLink RAT
  15. The attackers learn that due to the complexity and fluctuations of the pulping process, any changes could take up to

EXPLOIT

Nil

VULNERABILITY

  1. Cisco Patches Remotely Exploitable High Risk Security Bugs in Multiple Products
  2. Libssh Vulnerability Exposes Servers to Attacks
  3. Chrome 70 Updates Sign-In Options, Patches 23 Flaws
  4. VoiceOver iOS 12 Bug Creates Lock Screen Bypass Exposing User Photos
  5. Tumblr discloses vulnerability but says 'no evidence that this bug was abused'
  6. Oracle Fixes 301 Flaws in October Critical Patch Update
  7. Serious SSH bug lets crooks log in just by asking nicely
  8. Oracle Patched Over 300 Vulnerabilities in Its Q3 2018 Critical Patch Update
  9. LibSSH Flaw Leaves Thousands Of Servers At Risk Of Hijacking
  10. CVE-2018-10933: Libssh Server Side Authentication Bypass Vulnerability Alert
  11. Thousands of servers easy to hack due to a LibSSH Flaw
  12. Take a Bite out of the Vulnerability Remediation Backlog with InsightVM
  13. WhiteSource raises $35 million for open source flaw detection platform
  14. CVE-2018-3211: Java Usage Tracker Local Elevation of Privilege on Windows
  15. Oracle CPU October 2018: 301 vulnerabilities patched
  16. Thousands Of Servers Vulnerable To Hacking Due To libssh Flaw
  17. Critical Vulnerabilities Allow Takeover of D-Link Routers
  18. Tumblr Patches A Flaw That Could Have Exposed Users’ Account Info
  19. Remote Code Implantation Flaw Found in Medtronic Cardiac Programmers
  20. Alphabet in the soup for keeping quiet about Google+ data leak bug
  21. Hacker: I'm logged in. New LibSSH Vulnerability: OK! I believe you.
  22. Brazil expert discovers Oracle flaw that allows massive DDoS attacks
  23. Endpoint security solutions challenged by zero-day and fileless attacks
  24. VMware addressed Code Execution Flaw in its ESXi, Workstation, and Fusion products
  25. Flaws in Branch.io Affected Over 685 Million Users
  26. Security flaw in libssh leaves thousands of servers at risk of hijacking
  27. Oracle patches 301 vulnerabilities, including 46 with a 9.8+ severity rating
  28. VMware Patches Code Execution Flaw in Virtual Graphics Card
  29. CVE-2018-3245: Weblogic Remote Code Execution Vulnerability Alert
  30. Oracle releases Critical Patch Update Advisory – October 2018: fix 301 security bugs
  31. Git RCE Vulnerability (CVE-2018-17456)Security Advisory
  32. LibSSH Flaw Allows Hackers to Take Over Servers Without Password
  33. Vulnerability in voting machines has not been corrected after 11 years
  34. Vulnerability in Apple VoiceOver allows hackers access to user photos
  35. Google Chrome 70.0.3538.67 releases: fix multiple high-risk vulnerabilities
  36. The Qihoo @360CoreSec team found a @Microsoft vulnerability -- named Double Kill -- that affects applications through #MicrosoftOffice documents. Learn

Region brief for 2018-10-17

ASIA

  1. AISA 2018: Japan's journey from a cryptocurrency hack to better regulation
  2. New research highlights Vietnamese group's custom hacking tools
  3. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  4. WhiteSource raises $35 million for open source flaw detection platform
  5. Top 5 Publicly Accessible Hacking Tools You Can Download Today
  6. WTB: MuddyWater Expands Operations
  7. Git RCE Vulnerability (CVE-2018-17456)Security Advisory

OCEANIA

Nil

NORTH AMERICA

  1. LuminosityLink RAT Author Sentenced to 30 Months in Prison
  2. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  3. 35 Million US Voter Registration Records Found for Sale on Dark Web
  4. Podcast: A Utility Ransomware Attack, Post-Hurricane
  5. How Office 365 learned to reel in phish
  6. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  7. 35 million US voter records up for sale on the dark web
  8. SEO Poisoning Campaign Targeting U.S. Midterm Election Keywords
  9. 35 million voter records from 19 US states for sale
  10. Insult to injury: Malware menace soaks water-logged utility ravaged by Hurricane Florence
  11. WTB: MuddyWater Expands Operations
  12. US Voter Records for Sale on Hacker Forum
  13. Brazil expert discovers Oracle flaw that allows massive DDoS attacks
  14. Millions of US Voter Records for Sale
  15. 35 Million U.S Voter Records Selling in Popular Dark web Hacking Forum from $150 USD to $12,500 USD
  16. A crippling ransomware attack hit a water utility in the aftermath of Hurricane Florence
  17. Vulnerability in voting machines has not been corrected after 11 years

SOUTH AMERICA

  1. Brazil expert discovers Oracle flaw that allows massive DDoS attacks

EUROPE

  1. MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval Industry
  2. 'GreyEnergy' Cyberspies Target Ukraine, Poland
  3. 3 Years After Attacks on Ukraine Power Grid, BlackEnergy Successor Poses Growing Threat
  4. Information of 396K Users Exposed in Facepunch Data Breach
  5. Meet GreyEnergy, the newest hacking group hitting Ukraine’s power grid
  6. Who is to blame for the majority of data breaches?
  7. Attackers identified in the pre-espionage stage of CNI attack
  8. WTB: MuddyWater Expands Operations
  9. GreyEnergy group targeting critical infrastructure with espionage
  10. Millions of US Voter Records for Sale
  11. Russian Hackers Attack Specialist in Customer Review Tied to Innumerable Websites
  12. Sony has solved the crash of PS4 receiving malicious message

AFRICA

  1. WTB: MuddyWater Expands Operations