Oct 23, 2018

Threat report for 2018-10-22

DATA BREACH & DATA LOSS

  1. CMS portal breach exposes 75,000 individuals' records
  2. New Ethics Guidance for Lawyers from the American Bar Association (ABA) Regarding Data Breach and Cyber-attack
  3. According to the report, researchers detected 33,568 email addresses of finance departments that had been exposed by third parties. Can
  4. #NetSpectre leaks data remotely via side-channel attacks. Learn from expert Michael Cobb of @thehairyITdog why data from #microprocessors is not
  5. Criminals Hijacked Records of 75 000 Users from
  6. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  7. Enigmatic cyber espionage campaign revives source code from old foe APT1
  8. 75,000 HealthCare.gov Users Exposed, Personal Information Stolen
  9. US Indicts Another Russian for Role in Info Warfare Campaign
  10. What are DMARC records and can they improve email security?
  11. Anthem in Record $16m HIPAA Settlement
  12. The Hunt - Our new data breach detection video looks like a Mission Impossible trailer. However, the threats are for
  13. #NetSpectre exploits speculative execution to leak data remotely via side-channel attacks. Learn how this #SecurityVulnerability affects the #cloud from expert
  14. The most interesting Internet-connected vehicle hacks on record
  15. Web Hosting Software VestaCP Server Compromised With DDoS Malware
  16. Find out how #TLBleed abuses @Intel's HTT chip feature to leak data via TLB
  17. Are you aware of #Canada's data breach regulations? Get up to speed on the #blog:

DENIAL-OF-SERVICE

  1. NSA Hacking Tools Used Against Nuke, Aerospace Worlds
  2. Web Hosting Software VestaCP Server Compromised With DDoS Malware

MALVERTISING

Nil

PHISHING

  1. Phishing Scheme Leverages Azure Blob Storage and Hurricane Michael
  2. Strict password policy could prevent credential reuse, paper suggests
  3. Natural Disaster Related Phishing Scam Abusing Microsoft Azure to Steal login Credentials & Credit Card Numbers

WEB DEFACEMENT

  1. Saudi Future Investment Initiative website defaced by the hackers
  2. Hackers Deface Website of Saudi Investment Forum

BOTNET

  1. The Russian built #VPNFilter #botnet was taken down by the @FBI after over 500,000 routers were infected. However, VPNFilter is

RANSOMWARE

  1. Gamma ransomware compromises data on 16,000 patients at California hernia institute
  2. Ransomware: A cheat sheet for professionals
  3. The latest variant of Satan ransomware is spreading in the wild

CRYPTOMINING & CRYPTOCURRENCIES

  1. Blockchain Security and Privacy
  2. Rambus Vaultify Trade: Secure transaction and storage of crypto assets on blockchain
  3. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  4. iCloud Hacker Wants $175,000 Ransom to Be Paid In Bitcoin (BTC)
  5. Trade.io loses $7.5Mil worth of cryptocurrency in mysterious cold wallet hack
  6. Introducing Infura: Connecting DApps With Ethereum Without Setting up Ethereum Nodes
  7. Business-minded hackers are testing blockchain technologies to secure their illegal operations. Here's what enterprises can learn from them:
  8. India’s First Cryptocurrency ATM To Buy and Sell Cryptocurrencies

MALWARE

  1. How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
  2. US Tops Global Malware C2 Distribution
  3. Signal Upgrade Process Leaves Unencrypted Messages on Disk
  4. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  5. The boom of fileless malware attacks: How can we fight it?
  6. Octopus Malware
  7. Maker of LuminosityLink RAT gets 30 months in the clink
  8. Web Hosting Software VestaCP Server Compromised With DDoS Malware
  9. Adding the EICAR string to your name as part of the visitor self-registration process is a bit of a faux

EXPLOIT

  1. Apple Voiceover Exploit Allows Attackers Access to Ios Devices

VULNERABILITY

  1. Cisco, F5 Networks Investigate libssh Vulnerability Impact
  2. How to detect hardware-based server bugs
  3. Flaw in Media Library Impacts VLC, Other Software
  4. Libssh CVE-2018-10933 Scanners & Exploits Released - Apply Updates Now
  5. Recent Branch.io Patch Creates New XSS Flaw
  6. Critical Bug Impacts Live555 Media Streaming Libraries
  7. A newly disclosed #libSSH vulnerability could allow an attacker #AdminAccess to a server with little effort. By @MT_Heller
  8. Zero-day jQuery plugin vulnerability exploited for 3 years
  9. CVE-2018-4013: LIVE555 streaming media RTSP Server Remote Code Execution Vulnerability
  10. Popular website plugin harboured a serious 0-day for years
  11. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  12. It's OK, I'm verified - Libssh flaw allows attackers to bypass server authentication
  13. Repairnator bot finds software bugs, successfully submits patches
  14. Drupal Patched Critical RCE Vulnerabilities In Drupal 7 and 8
  15. FreeRTOS flaws expose millions of IoT devices to cyber attacks
  16. The .@iDefense Vulnerability Contributor Program (VCP) bug-bounty initiative continues to attract top contributors. Join them by submitting your 0-day for
  17. Critical vulnerabilities on FreeRTOS expose many systems to attacks
  18. WebLogic Remote Code Execution Vulnerability(CVE-2018-3245) Threat Alert
  19. MPlayer and VLC media player affected by critical flaw CVE-2018-4013
  20. Remote Code Execution Flaws Found in FreeRTOS - Popular OS for Embedded Systems
  21. Why does Windows 10 have many bugs?

Region brief for 2018-10-22

ASIA

  1. Saudi Future Investment Initiative website defaced by the hackers
  2. Hackers Deface Website of Saudi Investment Forum
  3. How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
  4. Rambus Vaultify Trade: Secure transaction and storage of crypto assets on blockchain
  5. A week in security (October 15 – 21)
  6. Oceansalt Attacks Infrastructure, Finance, Universities and Telecommunications
  7. Enigmatic cyber espionage campaign revives source code from old foe APT1
  8. WebLogic Remote Code Execution Vulnerability(CVE-2018-3245) Threat Alert
  9. India’s First Cryptocurrency ATM To Buy and Sell Cryptocurrencies

OCEANIA

Nil

NORTH AMERICA

  1. How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
  2. US Tops Global Malware C2 Distribution
  3. A week in security (October 15 – 21)
  4. Oceansalt Attacks Infrastructure, Finance, Universities and Telecommunications
  5. Safeguarding the Nation’s Critical Infrastructure
  6. New Ethics Guidance for Lawyers from the American Bar Association (ABA) Regarding Data Breach and Cyber-attack
  7. The boom of fileless malware attacks: How can we fight it?
  8. Criminals Hijacked Records of 75 000 Users from
  9. Enigmatic cyber espionage campaign revives source code from old foe APT1
  10. 75,000 HealthCare.gov Users Exposed, Personal Information Stolen
  11. US Indicts Another Russian for Role in Info Warfare Campaign
  12. Anthem in Record $16m HIPAA Settlement
  13. Are you aware of #Canada's data breach regulations? Get up to speed on the #blog:

SOUTH AMERICA

Nil

EUROPE

  1. A week in security (October 15 – 21)
  2. The Russian built #VPNFilter #botnet was taken down by the @FBI after over 500,000 routers were infected. However, VPNFilter is
  3. iCloud Hacker Wants $175,000 Ransom to Be Paid In Bitcoin (BTC)
  4. Repairnator bot finds software bugs, successfully submits patches
  5. New APT GreyEnergy Found to Target EU Critical Systems, Linked to BlackEnergy
  6. US Indicts Another Russian for Role in Info Warfare Campaign

AFRICA

Nil

Sector brief for 2018-10-22

HEALTHCARE

  1. CMS portal breach exposes 75,000 individuals' records
  2. Oceansalt Attacks Infrastructure, Finance, Universities and Telecommunications
  3. Gamma ransomware compromises data on 16,000 patients at California hernia institute
  4. Safeguarding the Nation’s Critical Infrastructure
  5. Criminals Hijacked Records of 75 000 Users from
  6. 75,000 HealthCare.gov Users Exposed, Personal Information Stolen
  7. Critical vulnerabilities on FreeRTOS expose many systems to attacks
  8. Anthem in Record $16m HIPAA Settlement

TRANSPORT

  1. NSA Hacking Tools Used Against Nuke, Aerospace Worlds
  2. Critical vulnerabilities on FreeRTOS expose many systems to attacks

BANKING & FINANCE

  1. Rambus Vaultify Trade: Secure transaction and storage of crypto assets on blockchain
  2. Oceansalt Attacks Infrastructure, Finance, Universities and Telecommunications
  3. According to the report, researchers detected 33,568 email addresses of finance departments that had been exposed by third parties. Can
  4. Phishing Scheme Leverages Azure Blob Storage and Hurricane Michael
  5. FreeRTOS flaws expose millions of IoT devices to cyber attacks
  6. Critical vulnerabilities on FreeRTOS expose many systems to attacks
  7. Natural Disaster Related Phishing Scam Abusing Microsoft Azure to Steal login Credentials & Credit Card Numbers
  8. India’s First Cryptocurrency ATM To Buy and Sell Cryptocurrencies

INFORMATION & TELECOMMUNICATION

  1. Saudi Future Investment Initiative website defaced by the hackers
  2. Blockchain Security and Privacy
  3. A week in security (October 15 – 21)
  4. Popular website plugin harboured a serious 0-day for years
  5. The latest variant of Satan ransomware is spreading in the wild

FOOD

Nil

WATER

Nil

ENERGY

  1. Safeguarding the Nation’s Critical Infrastructure
  2. New APT GreyEnergy Found to Target EU Critical Systems, Linked to BlackEnergy

GOVERNMENT & PUBLIC SERVICE

  1. Saudi Future Investment Initiative website defaced by the hackers
  2. How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
  3. CMS portal breach exposes 75,000 individuals' records
  4. Safeguarding the Nation’s Critical Infrastructure
  5. Criminals Hijacked Records of 75 000 Users from
  6. US Indicts Another Russian for Role in Info Warfare Campaign
  7. Anthem in Record $16m HIPAA Settlement

Daily brief for 2018-10-22

ASIA

  1. Saudi Future Investment Initiative website defaced by the hackers
  2. Hackers Deface Website of Saudi Investment Forum
  3. How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
  4. Rambus Vaultify Trade: Secure transaction and storage of crypto assets on blockchain
  5. A week in security (October 15 – 21)
  6. Oceansalt Attacks Infrastructure, Finance, Universities and Telecommunications
  7. Enigmatic cyber espionage campaign revives source code from old foe APT1
  8. WebLogic Remote Code Execution Vulnerability(CVE-2018-3245) Threat Alert
  9. India’s First Cryptocurrency ATM To Buy and Sell Cryptocurrencies

WORLD

  1. How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
  2. US Tops Global Malware C2 Distribution
  3. A week in security (October 15 – 21)
  4. Oceansalt Attacks Infrastructure, Finance, Universities and Telecommunications
  5. Safeguarding the Nation’s Critical Infrastructure
  6. New Ethics Guidance for Lawyers from the American Bar Association (ABA) Regarding Data Breach and Cyber-attack
  7. The boom of fileless malware attacks: How can we fight it?
  8. Criminals Hijacked Records of 75 000 Users from
  9. The Russian built #VPNFilter #botnet was taken down by the @FBI after over 500,000 routers were infected. However, VPNFilter is
  10. Enigmatic cyber espionage campaign revives source code from old foe APT1
  11. iCloud Hacker Wants $175,000 Ransom to Be Paid In Bitcoin (BTC)
  12. Repairnator bot finds software bugs, successfully submits patches
  13. 75,000 HealthCare.gov Users Exposed, Personal Information Stolen
  14. New APT GreyEnergy Found to Target EU Critical Systems, Linked to BlackEnergy
  15. US Indicts Another Russian for Role in Info Warfare Campaign
  16. Anthem in Record $16m HIPAA Settlement
  17. Are you aware of #Canada's data breach regulations? Get up to speed on the #blog:

ATTACKS

  1. CMS portal breach exposes 75,000 individuals' records
  2. New Ethics Guidance for Lawyers from the American Bar Association (ABA) Regarding Data Breach and Cyber-attack
  3. According to the report, researchers detected 33,568 email addresses of finance departments that had been exposed by third parties. Can
  4. #NetSpectre leaks data remotely via side-channel attacks. Learn from expert Michael Cobb of @thehairyITdog why data from #microprocessors is not
  5. Phishing Scheme Leverages Azure Blob Storage and Hurricane Michael
  6. Criminals Hijacked Records of 75 000 Users from
  7. Strict password policy could prevent credential reuse, paper suggests
  8. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  9. Enigmatic cyber espionage campaign revives source code from old foe APT1
  10. 75,000 HealthCare.gov Users Exposed, Personal Information Stolen
  11. US Indicts Another Russian for Role in Info Warfare Campaign
  12. What are DMARC records and can they improve email security?
  13. Anthem in Record $16m HIPAA Settlement
  14. The Hunt - Our new data breach detection video looks like a Mission Impossible trailer. However, the threats are for
  15. #NetSpectre exploits speculative execution to leak data remotely via side-channel attacks. Learn how this #SecurityVulnerability affects the #cloud from expert
  16. The most interesting Internet-connected vehicle hacks on record
  17. Web Hosting Software VestaCP Server Compromised With DDoS Malware
  18. Find out how #TLBleed abuses @Intel's HTT chip feature to leak data via TLB
  19. Natural Disaster Related Phishing Scam Abusing Microsoft Azure to Steal login Credentials & Credit Card Numbers
  20. Are you aware of #Canada's data breach regulations? Get up to speed on the #blog:

THREATS

  1. Cisco, F5 Networks Investigate libssh Vulnerability Impact
  2. How to detect hardware-based server bugs
  3. Flaw in Media Library Impacts VLC, Other Software
  4. Libssh CVE-2018-10933 Scanners & Exploits Released - Apply Updates Now
  5. How a Canadian permanent resident and Saudi Arabian dissident was targeted with powerful spyware on Canadian soil
  6. Blockchain Security and Privacy
  7. Recent Branch.io Patch Creates New XSS Flaw
  8. Rambus Vaultify Trade: Secure transaction and storage of crypto assets on blockchain
  9. US Tops Global Malware C2 Distribution
  10. Signal Upgrade Process Leaves Unencrypted Messages on Disk
  11. Gamma ransomware compromises data on 16,000 patients at California hernia institute
  12. Critical Bug Impacts Live555 Media Streaming Libraries
  13. A newly disclosed #libSSH vulnerability could allow an attacker #AdminAccess to a server with little effort. By @MT_Heller
  14. Zero-day jQuery plugin vulnerability exploited for 3 years
  15. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  16. CVE-2018-4013: LIVE555 streaming media RTSP Server Remote Code Execution Vulnerability
  17. The boom of fileless malware attacks: How can we fight it?
  18. Ransomware: A cheat sheet for professionals
  19. Popular website plugin harboured a serious 0-day for years
  20. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  21. It's OK, I'm verified - Libssh flaw allows attackers to bypass server authentication
  22. Octopus Malware
  23. iCloud Hacker Wants $175,000 Ransom to Be Paid In Bitcoin (BTC)
  24. Repairnator bot finds software bugs, successfully submits patches
  25. Drupal Patched Critical RCE Vulnerabilities In Drupal 7 and 8
  26. Trade.io loses $7.5Mil worth of cryptocurrency in mysterious cold wallet hack
  27. FreeRTOS flaws expose millions of IoT devices to cyber attacks
  28. The latest variant of Satan ransomware is spreading in the wild
  29. The .@iDefense Vulnerability Contributor Program (VCP) bug-bounty initiative continues to attract top contributors. Join them by submitting your 0-day for
  30. Maker of LuminosityLink RAT gets 30 months in the clink
  31. Introducing Infura: Connecting DApps With Ethereum Without Setting up Ethereum Nodes
  32. Critical vulnerabilities on FreeRTOS expose many systems to attacks
  33. WebLogic Remote Code Execution Vulnerability(CVE-2018-3245) Threat Alert
  34. MPlayer and VLC media player affected by critical flaw CVE-2018-4013
  35. Web Hosting Software VestaCP Server Compromised With DDoS Malware
  36. Adding the EICAR string to your name as part of the visitor self-registration process is a bit of a faux
  37. Business-minded hackers are testing blockchain technologies to secure their illegal operations. Here's what enterprises can learn from them:
  38. Remote Code Execution Flaws Found in FreeRTOS - Popular OS for Embedded Systems
  39. India’s First Cryptocurrency ATM To Buy and Sell Cryptocurrencies
  40. Why does Windows 10 have many bugs?

CRIME

  1. Blockchain Security and Privacy
  2. Rambus Vaultify Trade: Secure transaction and storage of crypto assets on blockchain
  3. A week in security (October 15 – 21)
  4. Oceansalt Attacks Infrastructure, Finance, Universities and Telecommunications
  5. The boom of fileless malware attacks: How can we fight it?
  6. Phishing Scheme Leverages Azure Blob Storage and Hurricane Michael
  7. iCloud Hacker Wants $175,000 Ransom to Be Paid In Bitcoin (BTC)
  8. 75,000 HealthCare.gov Users Exposed, Personal Information Stolen
  9. The latest variant of Satan ransomware is spreading in the wild
  10. US Indicts Another Russian for Role in Info Warfare Campaign
  11. Natural Disaster Related Phishing Scam Abusing Microsoft Azure to Steal login Credentials & Credit Card Numbers

POLITICS

  1. Saudi Future Investment Initiative website defaced by the hackers
  2. New Ethics Guidance for Lawyers from the American Bar Association (ABA) Regarding Data Breach and Cyber-attack
  3. Enigmatic cyber espionage campaign revives source code from old foe APT1
  4. Octopus Malware
  5. New APT GreyEnergy Found to Target EU Critical Systems, Linked to BlackEnergy
  6. US Indicts Another Russian for Role in Info Warfare Campaign

Oct 22, 2018

APT report for 2018-10-21

TRANSNATIONAL / UNKNOWN

  1. DarkPulsar and other NSA hacking tools used in hacking operations in the wild

CHINA

  1. Security Affairs newsletter Round 185 – News of the week

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. GreyEnergy Malware Targets Energy and Transport Providers
  2. Security Affairs newsletter Round 185 – News of the week

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-21

WINDOWS

  1. DarkPulsar and other NSA hacking tools used in hacking operations in the wild

LINUX

Nil

UNIX

Nil

ANDROID

Nil

IOS

  1. Security Affairs newsletter Round 185 – News of the week

MACOS

Nil

Threat report for 2018-10-21

DATA BREACH & DATA LOSS

  1. HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Week in review: Pentagon data breach, cybersecurity workforce gap, who gets spear phished?
  3. Another US Voters Data Leak Via Tea Party PAC Misconfigured S3 Bucket
  4. Travel data for about 30,000 individuals was exposed in a Pentagon #DataBreach and experts expect that the information could be
  5. A combination of #SecurityFlaws and inadequate back-end development of the @Google Firebase database led to #DataLeaks and #SecurityVulnerabilities including HospitalGown.
  6. Hackers Breach HealthCare.gov System and Steals Sensitive Personal Data of 75,000 Customers

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Hackers launched @netflix #phishing attacks by obtaining TLS certificates. Learn how hackers mimic popular websites to spoof users and steal

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. Kraken Cryptor Ransomware Connecting to BleepingComputer During Encryption
  2. Banking trojans, not #ransomware, are the biggest threat to the enterprise now.

CRYPTOMINING & CRYPTOCURRENCIES

  1. Kraken Cryptor Ransomware Connecting to BleepingComputer During Encryption

MALWARE

  1. GreyEnergy Malware Targets Energy and Transport Providers
  2. Then a vendor calls. A quality control system is running a hidden process. That shouldn’t be happening. The vendor rep

EXPLOIT

Nil

VULNERABILITY

  1. Multiple Vulnerabilities In Telepresence Robots Patched
  2. Tumblr Patched Privacy Bug That Could Expose Sensitive Account Details
  3. WizCase Report: Vulnerabilities found in WD My Book, NetGear Stora, SeaGate Home, Medion LifeCloud NAS
  4. 2 Million Network Storage Devices From WD, SeaGate, NetGear Affected by Unpatched Zero-Day Vulnerabilities

Region brief for 2018-10-21

ASIA

  1. DarkPulsar and other NSA hacking tools used in hacking operations in the wild
  2. Security Affairs newsletter Round 185 – News of the week

OCEANIA

Nil

NORTH AMERICA

  1. HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Another US Voters Data Leak Via Tea Party PAC Misconfigured S3 Bucket
  3. Security Affairs newsletter Round 185 – News of the week
  4. WizCase Report: Vulnerabilities found in WD My Book, NetGear Stora, SeaGate Home, Medion LifeCloud NAS

SOUTH AMERICA

  1. Security Affairs newsletter Round 185 – News of the week

EUROPE

  1. DarkPulsar and other NSA hacking tools used in hacking operations in the wild
  2. GreyEnergy Malware Targets Energy and Transport Providers
  3. Security Affairs newsletter Round 185 – News of the week

AFRICA

Nil

Sector brief for 2018-10-21

HEALTHCARE

  1. HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Hackers Breach HealthCare.gov System and Steals Sensitive Personal Data of 75,000 Customers

TRANSPORT

  1. DarkPulsar and other NSA hacking tools used in hacking operations in the wild
  2. GreyEnergy Malware Targets Energy and Transport Providers

BANKING & FINANCE

  1. Another US Voters Data Leak Via Tea Party PAC Misconfigured S3 Bucket
  2. Banking trojans, not #ransomware, are the biggest threat to the enterprise now.

INFORMATION & TELECOMMUNICATION

  1. Tumblr Patched Privacy Bug That Could Expose Sensitive Account Details
  2. WizCase Report: Vulnerabilities found in WD My Book, NetGear Stora, SeaGate Home, Medion LifeCloud NAS

FOOD

Nil

WATER

Nil

ENERGY

  1. DarkPulsar and other NSA hacking tools used in hacking operations in the wild
  2. GreyEnergy Malware Targets Energy and Transport Providers

GOVERNMENT & PUBLIC SERVICE

  1. HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Another US Voters Data Leak Via Tea Party PAC Misconfigured S3 Bucket

Daily brief for 2018-10-21

ASIA

  1. DarkPulsar and other NSA hacking tools used in hacking operations in the wild
  2. Security Affairs newsletter Round 185 – News of the week

WORLD

  1. HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. DarkPulsar and other NSA hacking tools used in hacking operations in the wild
  3. Another US Voters Data Leak Via Tea Party PAC Misconfigured S3 Bucket
  4. GreyEnergy Malware Targets Energy and Transport Providers
  5. Security Affairs newsletter Round 185 – News of the week
  6. WizCase Report: Vulnerabilities found in WD My Book, NetGear Stora, SeaGate Home, Medion LifeCloud NAS

ATTACKS

  1. HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Week in review: Pentagon data breach, cybersecurity workforce gap, who gets spear phished?
  3. Another US Voters Data Leak Via Tea Party PAC Misconfigured S3 Bucket
  4. Travel data for about 30,000 individuals was exposed in a Pentagon #DataBreach and experts expect that the information could be
  5. Hackers launched @netflix #phishing attacks by obtaining TLS certificates. Learn how hackers mimic popular websites to spoof users and steal
  6. A combination of #SecurityFlaws and inadequate back-end development of the @Google Firebase database led to #DataLeaks and #SecurityVulnerabilities including HospitalGown.
  7. Hackers Breach HealthCare.gov System and Steals Sensitive Personal Data of 75,000 Customers

THREATS

  1. Multiple Vulnerabilities In Telepresence Robots Patched
  2. Tumblr Patched Privacy Bug That Could Expose Sensitive Account Details
  3. GreyEnergy Malware Targets Energy and Transport Providers
  4. Kraken Cryptor Ransomware Connecting to BleepingComputer During Encryption
  5. Banking trojans, not #ransomware, are the biggest threat to the enterprise now.
  6. Then a vendor calls. A quality control system is running a hidden process. That shouldn’t be happening. The vendor rep
  7. WizCase Report: Vulnerabilities found in WD My Book, NetGear Stora, SeaGate Home, Medion LifeCloud NAS
  8. 2 Million Network Storage Devices From WD, SeaGate, NetGear Affected by Unpatched Zero-Day Vulnerabilities

CRIME

  1. Security Affairs newsletter Round 185 – News of the week

POLITICS

  1. Security Affairs newsletter Round 185 – News of the week

Oct 21, 2018

APT report for 2018-10-20

TRANSNATIONAL / UNKNOWN

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. .@RobertMLee said #GreyEnergy is a threat, but people shouldn't conclude from @ESET research that the group will only target

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-20

WINDOWS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  2. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems

LINUX

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  2. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  3. Xerosploit – Toolkit to Perform MITM, Spoofing, DOS, Images Sniffing/Replacement, WD Attacks

UNIX

Nil

ANDROID

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

IOS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

MACOS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

Threat report for 2018-10-20

DATA BREACH & DATA LOSS

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. If it's only able to leak data at 15 bits per hour, is #NetSpectre a serious threat? Learn more about
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  5. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel

DENIAL-OF-SERVICE

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

MALVERTISING

Nil

PHISHING

Nil

WEB DEFACEMENT

Nil

BOTNET

  1. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

RANSOMWARE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

MALWARE

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  3. Here's how the hack works: Temperatures used in the pulp cooking process begin to vary random intervals. The fluctuations in temperature

EXPLOIT

  1. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub

VULNERABILITY

  1. Oracle Critical Patch Update October 2018 Addressed 301 Flaws Including 47 High-Rated Flaws
  2. Two Critical RCE Bugs Patched in Drupal 7 and 8
  3. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
  4. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  5. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  6. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  7. OpenSSH 7.9 released: fixed bugs
  8. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  9. Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players
  10. Vulnerabilities in telepresence robots allow access to image and video
  11. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems

Region brief for 2018-10-20

ASIA

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

OCEANIA

Nil

NORTH AMERICA

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations

SOUTH AMERICA

Nil

EUROPE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

AFRICA

Nil

Sector brief for 2018-10-20

HEALTHCARE

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations
  2. Vulnerabilities in telepresence robots allow access to image and video

TRANSPORT

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

BANKING & FINANCE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations

INFORMATION & TELECOMMUNICATION

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin

FOOD

Nil

WATER

Nil

ENERGY

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

GOVERNMENT & PUBLIC SERVICE

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations

Daily brief for 2018-10-20

ASIA

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

WORLD

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

ATTACKS

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. If it's only able to leak data at 15 bits per hour, is #NetSpectre a serious threat? Learn more about
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  5. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel

THREATS

  1. Oracle Critical Patch Update October 2018 Addressed 301 Flaws Including 47 High-Rated Flaws
  2. Syrian victims of the GandCrab ransomware can decrypt their files for free
  3. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  4. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  5. Two Critical RCE Bugs Patched in Drupal 7 and 8
  6. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
  7. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  8. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  9. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  10. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  11. OpenSSH 7.9 released: fixed bugs
  12. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  13. Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players
  14. Vulnerabilities in telepresence robots allow access to image and video
  15. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems
  16. Here's how the hack works: Temperatures used in the pulp cooking process begin to vary random intervals. The fluctuations in temperature

CRIME

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin

POLITICS

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds
  2. Vulnerabilities in telepresence robots allow access to image and video

Oct 20, 2018

APT report for 2018-10-19

TRANSNATIONAL / UNKNOWN

Nil

CHINA

  1. Secret Comment Crew Code Spotted in New Attack
  2. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  3. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  4. Latest Hacking News Podcast
  5. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  6. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

INDIA

Nil

NORTH KOREA

  1. "World-renowned cybersecurity unit #GroupIB is prepping to release its annual report on trends in hi-tech cybercrime...Group-IB expects the number of

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. GreyEnergy
  2. GreyEnergy threat group detected attacking high-value targets
  3. .@ESET researchers claim the #GreyEnergy group has taken up the mantle of ICS-targeting #BlackEnergy, but @MalwareJake said the evidence wasn't
  4. .@ESET researchers claim a new threat group called #GreyEnergy is the successor to #BlackEnergy, but experts are unsure if the
  5. Week in security with Tony Anscombe

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-19

WINDOWS

  1. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  2. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  3. Inside Safari Extensions | Malware’s Golden Key to User Data

LINUX

  1. VestaCP users warned about possible server compromise

UNIX

Nil

ANDROID

  1. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

IOS

Nil

MACOS

  1. Inside Safari Extensions | Malware’s Golden Key to User Data

Threat report for 2018-10-19

DATA BREACH & DATA LOSS

  1. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  2. Campaign 2018: Artificial intelligence is automating attacks on political campaigns
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  5. Campaign 2018: Artificial Intelligence Is Automating Attacks On Political Campaigns
  6. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  7. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  8. US Voter Leak Hits Tea Party Organization
  9. VestaCP users warned about possible server compromise
  10. jQuery File Upload Plugin Vulnerable for 8 Years and Only Hackers Knew
  11. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  12. Campaign launched to protect ethical hackers in the Americas
  13. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  14. Facepunch 2016 breach exposed 343,000 users
  15. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  16. ADHA's non-process for releasing My Health Record data revealed
  17. MikroTik routers targeted by cryptomining campaign | Avast
  18. Vulnerability in Tumblr could have compromise users’ account data
  19. Poor security practices and access to hacking services are making it easy for #cybercriminals to compromise business email, research reveals:

DENIAL-OF-SERVICE

  1. New DDoS Malware Infects Open-Source Web Hosting Software
  2. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'
  3. DDoS Attack Prevention Method on Your Enterprise’s Systems – A Detailed Report

MALVERTISING

Nil

PHISHING

  1. Password and credit card-stealing Azorult malware adds new tricks
  2. AISA 2018: Hunting for phishing kits
  3. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.

WEB DEFACEMENT

Nil

BOTNET

  1. Ok now, which one of you is running this Twitter botnet of fake infosec professionals?

RANSOMWARE

  1. City Pays $2,000 in Computer Ransomware Attack
  2. Water Utility ONWASA Hit by Ransomware Attack
  3. Madison County Computer Systems Face a Ransomware Attack
  4. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  5. Top 4 tips to avoid getting hit by ransomware
  6. Onslow County Utility Hit with Ransomware Attack

CRYPTOMINING & CRYPTOCURRENCIES

  1. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  2. MikroTik routers targeted by cryptomining campaign | Avast
  3. Fraudster Targets Cryptocurrency Wallets with a Variety of Info Stealers

MALWARE

  1. Small or Big Business, Malware Hits Everyone
  2. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Password and credit card-stealing Azorult malware adds new tricks
  5. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  6. New DDoS Malware Infects Open-Source Web Hosting Software
  7. America’s First: US Leads in Global Malware C2 Distribution
  8. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  9. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  10. The Golden Age of Malware
  11. LuminosityLink RAT author sentenced to 30 years in prison
  12. Inside Safari Extensions | Malware’s Golden Key to User Data
  13. .@TrendMicro researchers discovered a malicious #ChromeExtension spreading #malware. Learn more with expert @lewisnic.
  14. ADHA's non-process for releasing My Health Record data revealed
  15. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  16. Canberra competence shines in day of PM domain lapses and tortured analogies

EXPLOIT

  1. NSA-Linked 'DarkPulsar' Exploit Tool Detailed

VULNERABILITY

  1. libssh Vulnerability: Is WatchGuard Affected?
  2. 0-Day in jQuery Plugin Impacts Thousands of Applications
  3. Fixing a CSRF Vulnerability
  4. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  5. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  6. Drupal dev team fixed Remote Code Execution flaws in the popular CMS
  7. Flaw in Libssh Grants Admin Control to Servers
  8. FreeRTOS Vulnerabilities Expose Many Systems to Attacks
  9. Linksys E Series Vulnerabilities
  10. Google warns Apple: Missing bugs in your security bulletins are 'disincentive to patch'
  11. jQuery Zero-Day Was Exploited For At Least Three Years
  12. A Serious Security Flaw Found in LibSSH
  13. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  14. Splunk addressed several vulnerabilities in Enterprise and Light products
  15. Serious D-Link router security flaws may never be patched
  16. Scams and flaws: Why we get duped
  17. Remote Code Execution Flaws Patched in Drupal
  18. Tumblr bug bounty program detects flaw, no user info lost
  19. .@Google Firebase's lack of #DatabaseSecurity and inadequate #BackendDevelopment led to #DataLeaks and vulnerabilities, including HospitalGown. Learn more about this
  20. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  21. Critical Flaw Found in Streaming Library Used by VLC and Other Media Players
  22. Drupal Remote Code Execution Vulnerability Alert
  23. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  24. Splunk Patches Several Flaws in Enterprise, Light Products
  25. Vulnerability in Tumblr could have compromise users’ account data
  26. Three critical vulnerabilities can be chained to take full control of D-Link routers
  27. Zero-day in popular jQuery plugin actively exploited for at least three years
  28. Tumblr serious vulnerability can reveal everyone information
  29. Critical Flaws Found in Amazon FreeRTOS IoT Operating System

Region brief for 2018-10-19

ASIA

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  2. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. Secret Comment Crew Code Spotted in New Attack
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands

OCEANIA

  1. AISA 2018: Hunting for phishing kits
  2. ADHA's non-process for releasing My Health Record data revealed
  3. Authorities seize properties of creators of “Infamous” cheat code, for GTA V
  4. Canberra competence shines in day of PM domain lapses and tortured analogies

NORTH AMERICA

  1. Small or Big Business, Malware Hits Everyone
  2. America’s First: US Leads in Global Malware C2 Distribution
  3. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  4. US Voter Leak Hits Tea Party Organization
  5. Secret Comment Crew Code Spotted in New Attack
  6. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  7. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  8. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  9. Inside Safari Extensions | Malware’s Golden Key to User Data
  10. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

SOUTH AMERICA

Nil

EUROPE

  1. Small or Big Business, Malware Hits Everyone
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  4. GreyEnergy
  5. Onslow County Utility Hit with Ransomware Attack
  6. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  7. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  8. Three critical vulnerabilities can be chained to take full control of D-Link routers
  9. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

AFRICA

  1. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'