Oct 25, 2018

Threat report for 2018-10-24

DATA BREACH & DATA LOSS

  1. Cathay Pacific breach leaks personal data on 9.4 million people
  2. Cathay Pacific data breach hits 9.4 million people
  3. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  4. Democratic Fundraising Firm Leaks Voter Database, Clients, Fundraisers
  5. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  6. Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee
  7. Information-Stealing Malware Campaign Evades Anti-Virus Detection
  8. Cathay Pacific Suffers Data Breach Impacting 9.4 Million Passengers
  9. Pocket iNet Leaves 73 GB of Sensitive Data Exposed
  10. Yahoo to pay up to $85m to settle data breach lawsuit
  11. Tim Cook Blasts Weaponization Of Personal Data And Praises GDPR
  12. Pocket iNet Left All Of Its Corporate Passwords, Keys, And Data Exposed
  13. Apple's Tim Cook: Our personal data is 'weaponized against us' by you-know-who
  14. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  15. Last year the @USAgov required agencies to implement #DMARC records and policies by October 2018. Learn just how hard DMARC
  16. Discover how #NetSpectre attacks leak data remotely via side-channels with Michael Cobb of @thehairyITdog.
  17. Yahoo Agrees to Pay $50 Million in Damages to Settle Data Breach Lawsuit
  18. Business Email Compromise: Gift Cards
  19. US government medical website was hacked that 75,000 personal data was stolen
  20. Morrisons supermarket: We're taking payroll leak liability fight to UK Supreme Court
  21. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  22. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  23. Yahoo agrees to pay $50 million to settle data breach lawsuit
  24. My Health Record opt-outs now sit at over 1.1 million
  25. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  26. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  27. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  28. Yahoo to pay at least $85m for data breach settlement
  29. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  30. A recent @HealthCareGov #breach exposed unknown types of data on 75,000 people, but a lack of information in the disclosure

DENIAL-OF-SERVICE

  1. This botnet snares your smart devices to perform DDoS attacks with a little help from Mirai

MALVERTISING

Nil

PHISHING

  1. Phishing Attack Tip 1: Beware of Unsettling Content An email containing unsettling, startling, or urgent content that requires immediate action on
  2. The Enduring Password Conundrum
  3. Phishing for knowledge
  4. Phishing attacks: Why is email still such an easy target for hackers?
  5. Office 365 for Business - from May to September - has been Recorded Lowest Phish Miss Rate Versus Rivals
  6. Area 1 Security releases Pay-Per-Phish, the performance-based cybersecurity solution

WEB DEFACEMENT

Nil

BOTNET

  1. Poorly secured SSH servers targeted by Chalubo botnet
  2. This botnet snares your smart devices to perform DDoS attacks with a little help from Mirai
  3. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,
  4. Chalubo, a new IoT botnet emerges in the threat landscape

RANSOMWARE

  1. ThreatList: Ransomware, EKs and Trojans lead the Way in Q3 Malware Trends
  2. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  3. How Microsoft's Controlled Folder Access can help stop ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. ​Australian woman arrested over AU$450,000 Ripple theft
  2. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  3. Meet Cryptojacking, the (not so) new kid on the block
  4. FBI: Call of Duty gamers helped steal $3.3 million in cryptocurrency hacking scheme
  5. Crytojacking 101; why cryptojacking is bad for business
  6. China asks blockchain-based service providers to control user information
  7. A Digital Currency for Everyone: 5 Easy Way Steps to Follow for Buying Bitcoin
  8. Securing Blockchain with Privileged Access Management

MALWARE

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  3. Information-Stealing Malware Campaign Evades Anti-Virus Detection
  4. New Malware Targets Industrial Control Systems
  5. FlawedAmmyy Remote Access Trojan
  6. Meet the malware which turns your smartphone into a mobile proxy
  7. sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
  8. ThreatList: Ransomware, EKs and Trojans lead the Way in Q3 Malware Trends
  9. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  10. Mac malware intercepts encrypted web traffic for ad injection
  11. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  12. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  13. LuminosityLink RAT author sentenced to 2.5 years in jail
  14. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  15. Beyond Your Bank Account: Ten Astounding Finds Uncovered by Financial Malware
  16. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware

EXPLOIT

  1. Exploit for New Windows Zero-Day Published on Twitter
  2. Exploit kits: fall 2018 review
  3. New Windows Zero-Day Bug Helps Delete Any File, Exploit Available
  4. Siemens Siclock: How do threat actors exploit these devices?
  5. Magecart Attackers Exploit Magento Zero-Days
  6. Hacker Discloses New Windows Zero-Day Exploit On Twitter

VULNERABILITY

  1. Windows ‘Deletebug’ Zero-Day Allows Privilege Escalation, Destruction
  2. Vulnerabilities in Linksys Routers May Grant Attackers Full Control
  3. Exploit for New Windows Zero-Day Published on Twitter
  4. Cisco Patches Local WebEx Vulnerability, Remotely Exploitable in AD Deployments
  5. CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
  6. Another Windows 0-day flaw has been published on Twitter
  7. .@Siemens disclosed six SICLOCK flaws that were found within its central plant clocks. Discover why three flaws have been rated
  8. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  9. Pentagon Launches Continuous Bug Bounty Program
  10. [SingCERT] Alert on Drupal Critical Vulnerabilities
  11. A Windows 0day vulnerability was made public on Twitter
  12. Organizations with strong DevSecOps find flaws 11x faster than those without
  13. New Microsoft Windows Zero-Day Dropped on Twitter, Micropatch Available
  14. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  15. Most enterprise vulnerabilities remain unpatched a month after discovery
  16. WizCase Found Critical Firmware Vulnerabilities In Leading NAS Devices
  17. New Windows Zero-Day Bug Helps Delete Any File, Exploit Available
  18. Twitter User Discloses Second Microsoft Zero-Day
  19. Firefox 63 Released with Enhanced Tracking Protection and Fixes 14 Security Vulnerabilities
  20. Most applications 'suffer from information leakage bugs'
  21. DoD bug bounty program to expand to more sensitive systems
  22. 3-year-old jQuery plugin vulnerability finally patched
  23. US Department of Defense Expands Bug Bounty Efforts
  24. The Qihoo @360CoreSec team found a @Microsoft vulnerability -- named Double Kill -- that affects applications through #MicrosoftOffice documents. Learn
  25. Good initiative. Would be even better if you would pay bounties for the bugs, too.
  26. Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
  27. A summer intern took a look at tinc VPN, they found some nice authentication bypass and message tampering flaws
  28. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  29. Marine diesel engines software developed by Auto Maskin has serious vulnerabilities
  30. Drupal Remote Code Execution Vulnerability Threat Alert
  31. Hacker Discloses New Windows Zero-Day Exploit On Twitter

Region brief for 2018-10-24

ASIA

  1. Cathay Pacific breach leaks personal data on 9.4 million people
  2. Democratic Fundraising Firm Leaks Voter Database, Clients, Fundraisers
  3. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  4. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  5. Exploit kits: fall 2018 review
  6. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  7. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  8. Phishing for knowledge
  9. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  10. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  11. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  12. Russian Government-owned research institute linked to Triton attacks
  13. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware
  14. Drupal Remote Code Execution Vulnerability Threat Alert
  15. China asks blockchain-based service providers to control user information

OCEANIA

  1. ​Australian woman arrested over AU$450,000 Ripple theft
  2. Phishing for knowledge

NORTH AMERICA

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  3. Meet Cryptojacking, the (not so) new kid on the block
  4. Exploit kits: fall 2018 review
  5. Pocket iNet Leaves 73 GB of Sensitive Data Exposed
  6. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  7. Yahoo to pay up to $85m to settle data breach lawsuit
  8. Apple's Tim Cook: Our personal data is 'weaponized against us' by you-know-who
  9. US government medical website was hacked that 75,000 personal data was stolen
  10. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  11. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  12. Phishing for knowledge
  13. US Department of Defense Expands Bug Bounty Efforts
  14. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  15. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  16. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  17. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  18. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  19. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  20. China asks blockchain-based service providers to control user information

SOUTH AMERICA

  1. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  2. Phishing for knowledge

EUROPE

  1. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  2. Magecart hackers change tactic and target vulnerable Magento extensions
  3. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  4. Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee
  5. New Malware Targets Industrial Control Systems
  6. Yahoo to pay up to $85m to settle data breach lawsuit
  7. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  8. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  9. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,
  10. Morrisons supermarket: We're taking payroll leak liability fight to UK Supreme Court
  11. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  12. Phishing for knowledge
  13. Magecart Attackers Exploit Magento Zero-Days
  14. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  15. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  16. Russian Government-owned research institute linked to Triton attacks
  17. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware
  18. Marine diesel engines software developed by Auto Maskin has serious vulnerabilities

AFRICA

  1. Phishing for knowledge

Sector brief for 2018-10-24

HEALTHCARE

  1. US government medical website was hacked that 75,000 personal data was stolen
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. Drupal Remote Code Execution Vulnerability Threat Alert

TRANSPORT

  1. CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. Securing Blockchain with Privileged Access Management

BANKING & FINANCE

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Magecart hackers change tactic and target vulnerable Magento extensions
  3. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  4. FlawedAmmyy Remote Access Trojan
  5. Meet Cryptojacking, the (not so) new kid on the block
  6. Magecart Hackers Now Targeting Vulnerable Magento Extensions
  7. sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
  8. Exploit kits: fall 2018 review
  9. Mac malware intercepts encrypted web traffic for ad injection
  10. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  11. Phishing for knowledge
  12. Magecart Attackers Exploit Magento Zero-Days
  13. The risk to OT networks is real, and it’s dangerous for business leaders to ignore
  14. Beyond Your Bank Account: Ten Astounding Finds Uncovered by Financial Malware
  15. Russian Government-owned research institute linked to Triton attacks
  16. Drupal Remote Code Execution Vulnerability Threat Alert
  17. China asks blockchain-based service providers to control user information
  18. A Digital Currency for Everyone: 5 Easy Way Steps to Follow for Buying Bitcoin

INFORMATION & TELECOMMUNICATION

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Exploit for New Windows Zero-Day Published on Twitter
  3. Meet Cryptojacking, the (not so) new kid on the block
  4. Another Windows 0-day flaw has been published on Twitter
  5. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  6. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  7. [SingCERT] Alert on Drupal Critical Vulnerabilities
  8. A Windows 0day vulnerability was made public on Twitter
  9. New Microsoft Windows Zero-Day Dropped on Twitter, Micropatch Available
  10. Twitter User Discloses Second Microsoft Zero-Day
  11. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  12. Need help managing supply chain risks? In this week's ShadowTalk episode, the team breaks it down into hardware, software
  13. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  14. Phishing for knowledge
  15. Magecart Attackers Exploit Magento Zero-Days
  16. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  17. Good initiative. Would be even better if you would pay bounties for the bugs, too.
  18. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  19. Office 365 for Business - from May to September - has been Recorded Lowest Phish Miss Rate Versus Rivals
  20. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  21. China asks blockchain-based service providers to control user information
  22. Hacker Discloses New Windows Zero-Day Exploit On Twitter
  23. NETSCOUT Takes Internet Scale Threat Protection to the Edge

FOOD

Nil

WATER

Nil

ENERGY

  1. New Malware Targets Industrial Control Systems
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  4. Drupal Remote Code Execution Vulnerability Threat Alert

GOVERNMENT & PUBLIC SERVICE

  1. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  2. Federal Legislation Enables Consumers to Obtain Security Freezes on Credit Reports Free of Charge
  3. Yahoo to pay up to $85m to settle data breach lawsuit
  4. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  5. US government medical website was hacked that 75,000 personal data was stolen
  6. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  7. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  8. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  9. Russian Government-owned research institute linked to Triton attacks
  10. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  11. China asks blockchain-based service providers to control user information

Daily brief for 2018-10-24

ASIA

  1. Cathay Pacific breach leaks personal data on 9.4 million people
  2. Democratic Fundraising Firm Leaks Voter Database, Clients, Fundraisers
  3. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  4. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  5. Exploit kits: fall 2018 review
  6. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  7. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  8. Phishing for knowledge
  9. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  10. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  11. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  12. Russian Government-owned research institute linked to Triton attacks
  13. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware
  14. Drupal Remote Code Execution Vulnerability Threat Alert
  15. China asks blockchain-based service providers to control user information

WORLD

  1. ​Australian woman arrested over AU$450,000 Ripple theft
  2. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  3. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  4. Magecart hackers change tactic and target vulnerable Magento extensions
  5. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  6. Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee
  7. New Malware Targets Industrial Control Systems
  8. Meet Cryptojacking, the (not so) new kid on the block
  9. Exploit kits: fall 2018 review
  10. Pocket iNet Leaves 73 GB of Sensitive Data Exposed
  11. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  12. Yahoo to pay up to $85m to settle data breach lawsuit
  13. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  14. Apple's Tim Cook: Our personal data is 'weaponized against us' by you-know-who
  15. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  16. US government medical website was hacked that 75,000 personal data was stolen
  17. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,
  18. Morrisons supermarket: We're taking payroll leak liability fight to UK Supreme Court
  19. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  20. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  21. Phishing for knowledge
  22. US Department of Defense Expands Bug Bounty Efforts
  23. Magecart Attackers Exploit Magento Zero-Days
  24. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  25. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  26. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  27. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  28. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  29. Russian Government-owned research institute linked to Triton attacks
  30. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware
  31. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  32. Marine diesel engines software developed by Auto Maskin has serious vulnerabilities
  33. China asks blockchain-based service providers to control user information

ATTACKS

  1. Cathay Pacific breach leaks personal data on 9.4 million people
  2. Cathay Pacific data breach hits 9.4 million people
  3. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  4. Democratic Fundraising Firm Leaks Voter Database, Clients, Fundraisers
  5. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  6. Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee
  7. Information-Stealing Malware Campaign Evades Anti-Virus Detection
  8. Cathay Pacific Suffers Data Breach Impacting 9.4 Million Passengers
  9. Pocket iNet Leaves 73 GB of Sensitive Data Exposed
  10. Yahoo to pay up to $85m to settle data breach lawsuit
  11. Tim Cook Blasts Weaponization Of Personal Data And Praises GDPR
  12. Pocket iNet Left All Of Its Corporate Passwords, Keys, And Data Exposed
  13. Apple's Tim Cook: Our personal data is 'weaponized against us' by you-know-who
  14. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  15. Phishing Attack Tip 1: Beware of Unsettling Content An email containing unsettling, startling, or urgent content that requires immediate action on
  16. Last year the @USAgov required agencies to implement #DMARC records and policies by October 2018. Learn just how hard DMARC
  17. Discover how #NetSpectre attacks leak data remotely via side-channels with Michael Cobb of @thehairyITdog.
  18. Yahoo Agrees to Pay $50 Million in Damages to Settle Data Breach Lawsuit
  19. Business Email Compromise: Gift Cards
  20. The Enduring Password Conundrum
  21. US government medical website was hacked that 75,000 personal data was stolen
  22. Morrisons supermarket: We're taking payroll leak liability fight to UK Supreme Court
  23. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  24. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  25. Phishing for knowledge
  26. Phishing attacks: Why is email still such an easy target for hackers?
  27. Yahoo agrees to pay $50 million to settle data breach lawsuit
  28. My Health Record opt-outs now sit at over 1.1 million
  29. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  30. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  31. Office 365 for Business - from May to September - has been Recorded Lowest Phish Miss Rate Versus Rivals
  32. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  33. Yahoo to pay at least $85m for data breach settlement
  34. Area 1 Security releases Pay-Per-Phish, the performance-based cybersecurity solution
  35. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  36. A recent @HealthCareGov #breach exposed unknown types of data on 75,000 people, but a lack of information in the disclosure

THREATS

  1. ​Australian woman arrested over AU$450,000 Ripple theft
  2. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  3. Windows ‘Deletebug’ Zero-Day Allows Privilege Escalation, Destruction
  4. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  5. Vulnerabilities in Linksys Routers May Grant Attackers Full Control
  6. Information-Stealing Malware Campaign Evades Anti-Virus Detection
  7. New Malware Targets Industrial Control Systems
  8. FlawedAmmyy Remote Access Trojan
  9. Exploit for New Windows Zero-Day Published on Twitter
  10. Cisco Patches Local WebEx Vulnerability, Remotely Exploitable in AD Deployments
  11. Meet the malware which turns your smartphone into a mobile proxy
  12. CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
  13. Meet Cryptojacking, the (not so) new kid on the block
  14. sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
  15. ThreatList: Ransomware, EKs and Trojans lead the Way in Q3 Malware Trends
  16. Another Windows 0-day flaw has been published on Twitter
  17. .@Siemens disclosed six SICLOCK flaws that were found within its central plant clocks. Discover why three flaws have been rated
  18. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  19. Mac malware intercepts encrypted web traffic for ad injection
  20. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  21. Pentagon Launches Continuous Bug Bounty Program
  22. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  23. [SingCERT] Alert on Drupal Critical Vulnerabilities
  24. A Windows 0day vulnerability was made public on Twitter
  25. Organizations with strong DevSecOps find flaws 11x faster than those without
  26. New Microsoft Windows Zero-Day Dropped on Twitter, Micropatch Available
  27. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  28. Most enterprise vulnerabilities remain unpatched a month after discovery
  29. WizCase Found Critical Firmware Vulnerabilities In Leading NAS Devices
  30. New Windows Zero-Day Bug Helps Delete Any File, Exploit Available
  31. Twitter User Discloses Second Microsoft Zero-Day
  32. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  33. Firefox 63 Released with Enhanced Tracking Protection and Fixes 14 Security Vulnerabilities
  34. Most applications 'suffer from information leakage bugs'
  35. DoD bug bounty program to expand to more sensitive systems
  36. LuminosityLink RAT author sentenced to 2.5 years in jail
  37. 3-year-old jQuery plugin vulnerability finally patched
  38. US Department of Defense Expands Bug Bounty Efforts
  39. The Qihoo @360CoreSec team found a @Microsoft vulnerability -- named Double Kill -- that affects applications through #MicrosoftOffice documents. Learn
  40. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  41. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  42. FBI: Call of Duty gamers helped steal $3.3 million in cryptocurrency hacking scheme
  43. Good initiative. Would be even better if you would pay bounties for the bugs, too.
  44. Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
  45. Crytojacking 101; why cryptojacking is bad for business
  46. A summer intern took a look at tinc VPN, they found some nice authentication bypass and message tampering flaws
  47. Beyond Your Bank Account: Ten Astounding Finds Uncovered by Financial Malware
  48. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware
  49. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  50. How Microsoft's Controlled Folder Access can help stop ransomware
  51. Marine diesel engines software developed by Auto Maskin has serious vulnerabilities
  52. Drupal Remote Code Execution Vulnerability Threat Alert
  53. China asks blockchain-based service providers to control user information
  54. A Digital Currency for Everyone: 5 Easy Way Steps to Follow for Buying Bitcoin
  55. Hacker Discloses New Windows Zero-Day Exploit On Twitter
  56. Securing Blockchain with Privileged Access Management

CRIME

  1. ​Australian woman arrested over AU$450,000 Ripple theft
  2. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  3. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  4. Magecart hackers change tactic and target vulnerable Magento extensions
  5. Federal Legislation Enables Consumers to Obtain Security Freezes on Credit Reports Free of Charge
  6. Yahoo to pay up to $85m to settle data breach lawsuit
  7. Business Email Compromise: Gift Cards
  8. US government medical website was hacked that 75,000 personal data was stolen
  9. Morrisons supermarket: We're taking payroll leak liability fight to UK Supreme Court
  10. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  11. LuminosityLink RAT author sentenced to 2.5 years in jail
  12. Phishing for knowledge
  13. FBI: Call of Duty gamers helped steal $3.3 million in cryptocurrency hacking scheme
  14. Beyond Your Bank Account: Ten Astounding Finds Uncovered by Financial Malware
  15. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  16. China asks blockchain-based service providers to control user information
  17. Securing Blockchain with Privileged Access Management

POLITICS

  1. New Malware Targets Industrial Control Systems
  2. Meet Cryptojacking, the (not so) new kid on the block
  3. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  4. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  5. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  6. Phishing for knowledge
  7. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  8. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  9. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  10. Russian Government-owned research institute linked to Triton attacks

Oct 24, 2018

APT report for 2018-10-23

TRANSNATIONAL / UNKNOWN

  1. Magecart group leverages zero-days in 20 Magento extensions
  2. NSA Tools Used to Attack Nuclear Energy Firms
  3. Hacking operations with DarkPulsar and other tools developed by the NSA

CHINA

  1. Chinese Cyber Espionage Group using Datper Trojan

INDIA

Nil

NORTH KOREA

  1. North Korean Hackers Stole $571 Million Worth of CryptoCoins in Less Than 24 Months

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Experts advocate for 'ATT&CK' as go-to framework to share threat intel
  2. FireEye links Russia-owned lab to Trisis developers

SERBIA

Nil

UKRAINE

  1. TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers

Platform report for 2018-10-23

WINDOWS

  1. Microsoft Windows zero-day disclosed on Twitter, again
  2. When Ransomware Stopped Working Harder and Started Working Smarter
  3. Chalubo DDoS Botnet Compromises Linux SSH Servers Using Brute-Force Attacks
  4. Bots Targeting SSH Servers and Brute-Forcing Entry
  5. TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers
  6. NSA Tools Used to Attack Nuclear Energy Firms
  7. Hacking operations with DarkPulsar and other tools developed by the NSA
  8. Windows 10 1809 Zip Extraction Bug Overwrites Files without Confirmation

LINUX

  1. Chalubo DDoS Botnet Compromises Linux SSH Servers Using Brute-Force Attacks
  2. Bots Targeting SSH Servers and Brute-Forcing Entry

UNIX

Nil

ANDROID

Nil

IOS

  1. The fix for the DOM-based XSS in Branch.io introduced a new XSS flaw
  2. Apple has launched its university ID Cards feature in Wallet. Students at three universities can now access their student ID

MACOS

  1. Inside Safari Extensions | Malicious Plugins Remain on Mojave
  2. The fix for the DOM-based XSS in Branch.io introduced a new XSS flaw

Threat report for 2018-10-23

DATA BREACH & DATA LOSS

  1. Case Study: Protecting PII
  2. An ISP Left Corporate Passwords, Keys, and All its Data Exposed on the Internet
  3. Top 10 security steps in Microsoft 365 that political campaigns can take today
  4. Critical vulnerabilities in FreeRTOS allowed for IoT device compromise
  5. Thousands of applications affected by a zero-day issue injQuery File Upload plugin
  6. Malicious actors attacked a back-end insurance system and the resulting @HealthCareGov #breach exposed an unknown amount of data on 75,000
  7. Identify when your data is exposed, your brand is abused, or your company is mentioned on the dark web. Test
  8. Thousands of Applications Vulnerable to RCE via jQuery File Upload
  9. Facebook has seen several data breaches in the last few months, leading the company to look into acquiring a
  10. Police have issued a fresh warning concerning Fortnite and players giving out their personal details online. Cheshire Police posted on Facebook,
  11. Adult websites shuttered after 1.2 million user details exposed
  12. #sLoad and #Ramnit pairing in sustained personalized campaigns against UK and Italy
  13. jQuery? More like preyQuery: File upload tool can be exploited to hijack at-risk websites
  14. "Advanced attacks, spear-phishing and data breaches are the norm, instead of the exception. We need to address these issues with
  15. “We’re less likely to be caught up in a massive breach of highly available PII or financial data that gets
  16. A flaw in @Google Firebase #DatabaseSecurity allowed hackers to bypass security and leak data. Learn more about this #SecurityFlaw and
  17. Morrisons loses appeal over data breach
  18. Morrisons loses appeal against data breach liability ruling
  19. A #ZeroDay in the popular #jQuery File Upload plugin could affect thousands of projects and the jQuery #plugin vulnerability may

DENIAL-OF-SERVICE

  1. DDoS-Capable IoT Botnet 'Chalubo' Rises
  2. Chalubo DDoS Botnet Compromises Linux SSH Servers Using Brute-Force Attacks
  3. Netscout Launches Arbor Edge Defense for Enterprise DDoS Security
  4. Oracle Doubles Down on Cloud Security With CASB, WAF, DDoS Protection

MALVERTISING

Nil

PHISHING

  1. Phishing is still the most commonly used attack on organizations, survey says
  2. New Phishing Attack That Uses Multiple Replica Sign-In Pages
  3. How sophisticated phishing grants attackers total control of your computer
  4. How sophisticated phishing grants attackers total control of your computer
  5. 5 Ways #Cybercriminals Can Access Your Emails Without Phishing [Infographic]:
  6. Phishing attacks becoming more targeted, phishers love Microsoft the most
  7. Learn how hackers launched #phishing attacks against @netflix users with expert Michael Cobb of @thehairyITdog
  8. "Advanced attacks, spear-phishing and data breaches are the norm, instead of the exception. We need to address these issues with
  9. Phishing Report Shows Microsoft, Paypal, & Netflix as Top Targets
  10. 4 suggerimenti per utilizzare al meglio il vostro #password manager e generare password davvero efficaci. Ebbene sì, repetita juvant :)

WEB DEFACEMENT

  1. Hackers Defaced Davos In The Desert To Show Image Of Murdered Journalist
  2. Saudi Investment Site Defaced After Journalist’s Murder

BOTNET

  1. DDoS-Capable IoT Botnet 'Chalubo' Rises
  2. Chalubo DDoS Botnet Compromises Linux SSH Servers Using Brute-Force Attacks
  3. Battling Bots: How to Find Fake Twitter Followers
  4. Bots Targeting SSH Servers and Brute-Forcing Entry

RANSOMWARE

  1. When Ransomware Stopped Working Harder and Started Working Smarter
  2. City Pays $2K in Ransomware, Stirs ‘Never Pay’ Debate
  3. Case Study: Ransomware
  4. Indiana National Guard Suffers Ransomware Attack
  5. Indiana National Guard hit by ransomware
  6. Have you ever wondered why #ransomware attacks happen on the Friday before a long weekend? We've teamed up with @SentinelOne

CRYPTOMINING & CRYPTOCURRENCIES

  1. Why the blockchain is not secure
  2. Trade.io Cold Wallet Hacked Losing 50 Million TIO Tokens – TIO Coin To Be Forked
  3. Why is Elon Musk promoting this Bitcoin scam? (He’s not)
  4. Report: Cryptocurrency hackers earned $20M with 51-percent attacks in 2018
  5. Apple has launched its university ID Cards feature in Wallet. Students at three universities can now access their student ID
  6. Can Cybercriminals Hack Blockchain?
  7. A Beginner’s Guide to Bitcoin Mining (Bitcoin Mining 101)

MALWARE

  1. Burned malware returns, according to Cylance: is Hacking Team responsible?
  2. Status of Today’s Email as a Malware Vector
  3. Case Study: Destructive Malware
  4. Banking Trojan Infections Persist Throughout the State
  5. Triton Malware Linked to Russian Government Research Institute
  6. FireEye links Russian research lab to Triton ICS malware attacks
  7. Securing Government Operations with Cloud-based Malware Analysis
  8. How RATs infect computers with malicious software
  9. This is how government spyware StrongPity uses security researchers' work against them
  10. Russian Malware Was Apparently Used in an Attempt to Sabotage a Saudi Petrol Plant
  11. Inside Safari Extensions | Malicious Plugins Remain on Mojave
  12. Malicious actors attacked a back-end insurance system and the resulting @HealthCareGov #breach exposed an unknown amount of data on 75,000
  13. H-Worm and jRAT Malware: Two RATs are Better than One
  14. How RATs infect computers with malicious software
  15. What do you think the combination of the #TrickBot banking Trojan to #IcedID means for the future of banking #Trojans?
  16. Updated Azorult malware for sale on the Dark Web
  17. UK and US sign military Cyber Accord to dominate cyber domain - with help from business
  18. Chinese Cyber Espionage Group using Datper Trojan
  19. Burned malware returns, says Cylance report: Is Hacking Team responsible?

EXPLOIT

Nil

VULNERABILITY

  1. DHS warns of another dangerous flaw in Advantech WebAccess SCADA software
  2. Microsoft Windows zero-day disclosed on Twitter, again
  3. AWS FreeRTOS Riddled with Security Vulnerabilities | Avast
  4. Critical vulnerabilities in FreeRTOS allowed for IoT device compromise
  5. Thousands of applications affected by a zero-day issue injQuery File Upload plugin
  6. Grave TCP/IP Flaws In FreeRTOS Leave IoT Gear Open To Mass Hijacking
  7. Patch now! Multiple serious flaws found in Drupal
  8. Quantifying Vulnerability Risk: How to Quickly Calculate and Prioritize Risk
  9. Amazon Patched Multiple IoT Vulnerabilities Affecting Its Smart Devices
  10. Amazon patches IoT and critical infrastructure security flaws
  11. Patch me, if you can: Grave TCP/IP flaws in FreeRTOS leave IoT gear open to mass hijacking
  12. Several vulnerabilities were found in controllers made by @Universal_Robot. Discover what these #robot controllers are used for and how
  13. How do newly found flaws affect robot controllers?
  14. Firmware zero-day leaves 2m storage devices open to RCE
  15. A flaw in @Google Firebase #DatabaseSecurity allowed hackers to bypass security and leak data. Learn more about this #SecurityFlaw and
  16. CyberSecurity Asean security alert on Multiple Vulnerabilities in Cisco WebEx Network Recording Player for Advanced Recording Format Files Could Allow for Arbitrary Code Execution
  17. Bug Spells Doom for Nearly-Vacant Google+ Network
  18. The fix for the DOM-based XSS in Branch.io introduced a new XSS flaw
  19. libssh Server-Side Identity Authentication Bypass Vulnerability (CVE-2018-10933)Threat Alert
  20. WebLogic Remote Code Execution Vulnerability(CVE-2018-3191)Threat Alert
  21. Different Vendors Confirm The Impact Of LibSSH Flaw On Their Products
  22. FreeRTOS IoT OS Critical Vulnerabilities Affected Million of Smart Home & Critical Infrastructure Based IoT Devices
  23. LIVE555 Streaming library affected by remote code execution vulnerability
  24. Windows 10 1809 Zip Extraction Bug Overwrites Files without Confirmation
  25. A #ZeroDay in the popular #jQuery File Upload plugin could affect thousands of projects and the jQuery #plugin vulnerability may

Region brief for 2018-10-23

ASIA

  1. FireEye links Russia-owned lab to Trisis developers
  2. Russian Malware Was Apparently Used in an Attempt to Sabotage a Saudi Petrol Plant
  3. Chinese Cyber Espionage Group using Datper Trojan
  4. Saudi Investment Site Defaced After Journalist’s Murder
  5. NSA Tools Used to Attack Nuclear Energy Firms
  6. Burned malware returns, says Cylance report: Is Hacking Team responsible?
  7. libssh Server-Side Identity Authentication Bypass Vulnerability (CVE-2018-10933)Threat Alert
  8. WebLogic Remote Code Execution Vulnerability(CVE-2018-3191)Threat Alert
  9. North Korean Hackers Stole $571 Million Worth of CryptoCoins in Less Than 24 Months
  10. Hacking operations with DarkPulsar and other tools developed by the NSA
  11. Can Cybercriminals Hack Blockchain?

OCEANIA

Nil

NORTH AMERICA

  1. When Ransomware Stopped Working Harder and Started Working Smarter
  2. FireEye links Russia-owned lab to Trisis developers
  3. An ISP Left Corporate Passwords, Keys, and All its Data Exposed on the Internet
  4. Securing Government Operations with Cloud-based Malware Analysis
  5. Inside Safari Extensions | Malicious Plugins Remain on Mojave
  6. Quantifying Vulnerability Risk: How to Quickly Calculate and Prioritize Risk
  7. Phishing attacks becoming more targeted, phishers love Microsoft the most
  8. Indiana National Guard hit by ransomware
  9. UK and US sign military Cyber Accord to dominate cyber domain - with help from business
  10. Saudi Investment Site Defaced After Journalist’s Murder
  11. NSA Tools Used to Attack Nuclear Energy Firms
  12. Burned malware returns, says Cylance report: Is Hacking Team responsible?
  13. The fix for the DOM-based XSS in Branch.io introduced a new XSS flaw
  14. Can Cybercriminals Hack Blockchain?

SOUTH AMERICA

Nil

EUROPE

  1. Experts advocate for 'ATT&CK' as go-to framework to share threat intel
  2. FireEye links Russia-owned lab to Trisis developers
  3. Triton Malware Linked to Russian Government Research Institute
  4. FireEye links Russian research lab to Triton ICS malware attacks
  5. Russian Malware Was Apparently Used in an Attempt to Sabotage a Saudi Petrol Plant
  6. TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers
  7. #sLoad and #Ramnit pairing in sustained personalized campaigns against UK and Italy
  8. UK and US sign military Cyber Accord to dominate cyber domain - with help from business
  9. NSA Tools Used to Attack Nuclear Energy Firms
  10. “We’re less likely to be caught up in a massive breach of highly available PII or financial data that gets
  11. Morrisons loses appeal over data breach
  12. Hacking operations with DarkPulsar and other tools developed by the NSA

AFRICA

Nil