Oct 26, 2018

Threat report for 2018-10-25

DATA BREACH & DATA LOSS

  1. Cutwail Spam Campaign Uses Steganography to Distribute URLZone
  2. Cathay Pacific hack: Personal data of up to 9.4 million airline passengers laid bare
  3. Another 185K Customers Potentially Affected by the British Airways Data Breach
  4. British Airways: Cyberattack, data theft bigger than we first thought
  5. Cathay Pacific data breach: 9.4 million passenger information at risk
  6. Data Breach Announced by CMS – Approximately 75,000 Individuals’ Files Affected
  7. Abandoned Web Apps Found as a Core Cause Behind High Profile Data Breaches
  8. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  9. Questions Mount Over Delay After Cathay Pacific Admits Huge Data Leak
  10. Multiple Phishing Campaigns Target Universities
  11. 77K Additional Customers Affected by British Airways' MageCart Data Breach
  12. Cathay Pacific data breach exposes PII of 9.4 million customers
  13. Cathay Pacific data breach exposed 9.4m customers’ details
  14. Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
  15. Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
  16. CNI Campaign TRITON Linked to Russian Institute
  17. Chalubo Botnet Compromise Your Server or IoT Device & Use it for DDOS Attack
  18. Cathay Pacific data breach affecting 9.4 million passengers
  19. Data leak at consulting firm handling fundraisers for the Democratic party

DENIAL-OF-SERVICE

  1. New DDoS botnet goes after Hadoop enterprise servers
  2. New Botnet Launches DDoS Attacks on SSH Servers
  3. Chalubo Botnet Compromise Your Server or IoT Device & Use it for DDOS Attack
  4. NETSCOUT’s Arbor Cloud Expands DDoS Protection Across Asia

MALVERTISING

Nil

PHISHING

  1. Multiple Phishing Campaigns Target Universities
  2. Cofense Hunts Phishing Threats Round the Clock with Enhanced 24-hour Global Phishing Defense Services
  3. Learn how hackers used TLS certificates to launch @netflix #phishing attacks from expert Michael Cobb of @thehairyITdog
  4. iOS 12 has completely blocked password cracking tool, GrayKey

WEB DEFACEMENT

Nil

BOTNET

  1. New DDoS botnet goes after Hadoop enterprise servers
  2. Hacker creates seven new variants of the Mirai botnet | Avast
  3. New Botnet Launches DDoS Attacks on SSH Servers
  4. Chalubo Botnet Compromise Your Server or IoT Device & Use it for DDOS Attack

RANSOMWARE

  1. Experts released a free Decryption Tool for GandCrab ransomware
  2. New FilesLocker Ransomware Offered as a Ransomware as a Service
  3. GandCrab ransomware declawed with new decryption tool
  4. Files Encrypted by GandCrab Ransomware Can Now Be Decrypted for Free
  5. Bitdefender releases GandCrab ransomware decryption tool
  6. Free GrandCrab Ransomware Decryption Tool Released by Bitdefender
  7. Free Decrypter Available for the Latest GandCrab Ransomware Versions
  8. ESET releases new decryptor for Syrian victims of GandCrab ransomware
  9. Free decryption tool released for multiple GandCrab ransomware versions
  10. West Haven pays $2k USD because of ransomware attack
  11. GandCrab Ransomware decryption tool

CRYPTOMINING & CRYPTOCURRENCIES

  1. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  2. North Korea blamed for two cryptocurrency scams, five trading platform hacks
  3. Building shared digital identity using blockchain technology

MALWARE

  1. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  2. Malware Distributors Adopt DKIM to Bypass Mail Filters
  3. Cobalt Group tries to slip malicious PDFs past bank employees, researchers say
  4. Another one bites the dust! In 2018 Android malware can bypass defences of billon dollar AV industry and Google Play
  5. 'TimpDoor' Malware Turns Android Devices into Proxies
  6. Bypass an Anti Virus Detection with Encrypted Payloads using VENOM Tool
  7. #DidYouKnow AVG Free Antivirus received the highest rating of Advanced+ in @AV_Comparatives latest Malware Protection Test? Share AVG Free Antivirus with
  8. Malware Distributors Adopt DKIM to Bypass Mail Filters
  9. Mac Malware Injects Ads Into Encrypted Traffic
  10. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  11. FireEye ties Russia to Triton malware attack in Saudi Arabia
  12. Our threat intelligence lead Chris Dawson (@mrdatahs) discussing new @proofpoint Threat Insight #Malware research with @threatpost.
  13. FireEye links Triton Malware to Russian Research Institute
  14. .@FireEye security researchers claimed the Russian government was 'most likely' behind the Triton #malware attack on an industrial control system
  15. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye
  16. What is application security? A process and tools for securing software
  17. [BLOG] When #malware actor realizes that he can make more money by himself and transform his dropper into banking malware,
  18. New Android Malware Turns Your Mobile Devices into Hidden Proxies

EXPLOIT

  1. Researchers recently found vulnerabilities in #robot controllers from @Universal_Robot. Learn what these robot controllers do and how #ThreatActors exploit these

VULNERABILITY

  1. New security flaw impacts most Linux and BSD distros
  2. Multiple Vulnerabilities Patched in ASRock Drivers
  3. Unusual Remote Execution Bug in Cisco WebEx Discovered by Researchers
  4. WINDOWS ZERO-DAY BY SANDBOXESCAPER
  5. Sophos Patches RCE and Memory Disclosure Vulnerabilities in
  6. Vulnerability Spotlight: TALOS-2018-0635/0636 – Sophos HitmanPro.Alert memory disclosure and code execution vulnerabilities
  7. Pentagon Expands Bug-Bounty Program to Include Physical Systems
  8. Researchers Find Command Injection Flaw in Cisco WebEx
  9. Researchers recently found vulnerabilities in #robot controllers from @Universal_Robot. Learn what these robot controllers do and how #ThreatActors exploit these
  10. Microsoft Acknowledges Zip File Overwrite Bug - Fix Coming in November
  11. Cisco releases fix for privilege escalation bug in Webex Meetings app
  12. Amazon IoT operating system FreeRTOS has serious vulnerabilities
  13. Experts discovered a severe command injection flaw in Cisco Webex Meetings Desktop
  14. You patch my back(up) and I'll patch yours... Arcserve bugs burrow remotely exploited holes in UDP storage systems
  15. Signal Desktop App Vulnerability Exposes Message Decryption Key To The Users
  16. Vulnerability Spotlight: TALOS-2018-0635/0636 - Sophos HitmanPro.Alert memory disclosure and code execution vulnerabilities
  17. Windows 10 Update Fixed File Deletion Flaw But Not ZIP File Overwrite Bug
  18. Google Chrome 70.0.3538.77 released: Bugs fix
  19. Win10 1803 big bug bash KB 4462933 joins earlier versions, a week late to the party
  20. FreeRTOS Multiple Remote Code Execution Vulnerabilities Threat Alert
  21. Java Usage Tracker Vulnerability
  22. Windows 10 bug overwrites files without confirmation
  23. Unusual Remote Execution Bug in Cisco WebEx Discovered by Researchers

Region brief for 2018-10-25

ASIA

  1. Experts released a free Decryption Tool for GandCrab ransomware
  2. Cutwail Spam Campaign Uses Steganography to Distribute URLZone
  3. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  4. New FilesLocker Ransomware Offered as a Ransomware as a Service
  5. Cathay Pacific data breach: 9.4 million passenger information at risk
  6. Questions Mount Over Delay After Cathay Pacific Admits Huge Data Leak
  7. North Korea blamed for two cryptocurrency scams, five trading platform hacks
  8. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  9. FireEye ties Russia to Triton malware attack in Saudi Arabia
  10. Cathay Pacific data breach exposed 9.4m customers’ details
  11. CNI Campaign TRITON Linked to Russian Institute
  12. ESET releases new decryptor for Syrian victims of GandCrab ransomware
  13. Cathay Pacific data breach affecting 9.4 million passengers
  14. .@FireEye security researchers claimed the Russian government was 'most likely' behind the Triton #malware attack on an industrial control system
  15. FreeRTOS Multiple Remote Code Execution Vulnerabilities Threat Alert
  16. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye
  17. NETSCOUT’s Arbor Cloud Expands DDoS Protection Across Asia

OCEANIA

  1. NETSCOUT’s Arbor Cloud Expands DDoS Protection Across Asia

NORTH AMERICA

  1. Cutwail Spam Campaign Uses Steganography to Distribute URLZone
  2. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  3. Malware Distributors Adopt DKIM to Bypass Mail Filters
  4. Data Breach Announced by CMS – Approximately 75,000 Individuals’ Files Affected
  5. Abandoned Web Apps Found as a Core Cause Behind High Profile Data Breaches
  6. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  7. Multiple Phishing Campaigns Target Universities
  8. New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed
  9. 5 Common Visibility Gaps Your Enterprise Security Plan Can’t Afford
  10. Malware Distributors Adopt DKIM to Bypass Mail Filters
  11. West Haven pays $2k USD because of ransomware attack
  12. GandCrab Ransomware decryption tool

SOUTH AMERICA

Nil

EUROPE

  1. Experts released a free Decryption Tool for GandCrab ransomware
  2. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  3. British Airways has some good news and bad news about its payment breach
  4. Another 185K Customers Potentially Affected by the British Airways Data Breach
  5. British Airways: Cyberattack, data theft bigger than we first thought
  6. Cobalt Group tries to slip malicious PDFs past bank employees, researchers say
  7. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  8. Multiple Phishing Campaigns Target Universities
  9. 77K Additional Customers Affected by British Airways' MageCart Data Breach
  10. New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed
  11. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  12. Bitdefender releases GandCrab ransomware decryption tool
  13. FireEye ties Russia to Triton malware attack in Saudi Arabia
  14. FireEye links Triton Malware to Russian Research Institute
  15. CNI Campaign TRITON Linked to Russian Institute
  16. Free GrandCrab Ransomware Decryption Tool Released by Bitdefender
  17. Cathay Pacific data breach affecting 9.4 million passengers
  18. .@FireEye security researchers claimed the Russian government was 'most likely' behind the Triton #malware attack on an industrial control system
  19. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye

AFRICA

Nil

Sector brief for 2018-10-25

HEALTHCARE

  1. Data Breach Announced by CMS – Approximately 75,000 Individuals’ Files Affected
  2. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  3. Amazon IoT operating system FreeRTOS has serious vulnerabilities

TRANSPORT

  1. Cobalt Group tries to slip malicious PDFs past bank employees, researchers say
  2. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  3. New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed
  4. Amazon IoT operating system FreeRTOS has serious vulnerabilities

BANKING & FINANCE

  1. British Airways has some good news and bad news about its payment breach
  2. Malware Distributors Adopt DKIM to Bypass Mail Filters
  3. Another 185K Customers Potentially Affected by the British Airways Data Breach
  4. British Airways: Cyberattack, data theft bigger than we first thought
  5. Cobalt Group tries to slip malicious PDFs past bank employees, researchers say
  6. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  7. Questions Mount Over Delay After Cathay Pacific Admits Huge Data Leak
  8. New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed
  9. 5 Common Visibility Gaps Your Enterprise Security Plan Can’t Afford
  10. Cathay Pacific data breach exposes PII of 9.4 million customers
  11. Cathay Pacific data breach affecting 9.4 million passengers
  12. West Haven pays $2k USD because of ransomware attack
  13. [BLOG] When #malware actor realizes that he can make more money by himself and transform his dropper into banking malware,

INFORMATION & TELECOMMUNICATION

  1. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  2. Cobalt Group tries to slip malicious PDFs past bank employees, researchers say
  3. Another one bites the dust! In 2018 Android malware can bypass defences of billon dollar AV industry and Google Play
  4. #DidYouKnow AVG Free Antivirus received the highest rating of Advanced+ in @AV_Comparatives latest Malware Protection Test? Share AVG Free Antivirus with
  5. Hacker creates seven new variants of the Mirai botnet | Avast
  6. iOS 12 has completely blocked password cracking tool, GrayKey

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Experts released a free Decryption Tool for GandCrab ransomware
  2. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  3. 5 Common Visibility Gaps Your Enterprise Security Plan Can’t Afford
  4. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  5. Bitdefender releases GandCrab ransomware decryption tool
  6. FireEye links Triton Malware to Russian Research Institute
  7. CNI Campaign TRITON Linked to Russian Institute
  8. Free GrandCrab Ransomware Decryption Tool Released by Bitdefender
  9. .@FireEye security researchers claimed the Russian government was 'most likely' behind the Triton #malware attack on an industrial control system
  10. Building shared digital identity using blockchain technology
  11. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye
  12. West Haven pays $2k USD because of ransomware attack

Daily brief for 2018-10-25

ASIA

  1. Experts released a free Decryption Tool for GandCrab ransomware
  2. Cutwail Spam Campaign Uses Steganography to Distribute URLZone
  3. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  4. New FilesLocker Ransomware Offered as a Ransomware as a Service
  5. Cathay Pacific data breach: 9.4 million passenger information at risk
  6. Questions Mount Over Delay After Cathay Pacific Admits Huge Data Leak
  7. North Korea blamed for two cryptocurrency scams, five trading platform hacks
  8. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  9. FireEye ties Russia to Triton malware attack in Saudi Arabia
  10. Cathay Pacific data breach exposed 9.4m customers’ details
  11. CNI Campaign TRITON Linked to Russian Institute
  12. ESET releases new decryptor for Syrian victims of GandCrab ransomware
  13. Cathay Pacific data breach affecting 9.4 million passengers
  14. .@FireEye security researchers claimed the Russian government was 'most likely' behind the Triton #malware attack on an industrial control system
  15. FreeRTOS Multiple Remote Code Execution Vulnerabilities Threat Alert
  16. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye
  17. NETSCOUT’s Arbor Cloud Expands DDoS Protection Across Asia

WORLD

  1. Experts released a free Decryption Tool for GandCrab ransomware
  2. Cutwail Spam Campaign Uses Steganography to Distribute URLZone
  3. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  4. British Airways has some good news and bad news about its payment breach
  5. Malware Distributors Adopt DKIM to Bypass Mail Filters
  6. Another 185K Customers Potentially Affected by the British Airways Data Breach
  7. British Airways: Cyberattack, data theft bigger than we first thought
  8. Cobalt Group tries to slip malicious PDFs past bank employees, researchers say
  9. Data Breach Announced by CMS – Approximately 75,000 Individuals’ Files Affected
  10. Abandoned Web Apps Found as a Core Cause Behind High Profile Data Breaches
  11. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  12. Multiple Phishing Campaigns Target Universities
  13. 77K Additional Customers Affected by British Airways' MageCart Data Breach
  14. New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed
  15. 5 Common Visibility Gaps Your Enterprise Security Plan Can’t Afford
  16. Malware Distributors Adopt DKIM to Bypass Mail Filters
  17. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  18. Bitdefender releases GandCrab ransomware decryption tool
  19. FireEye ties Russia to Triton malware attack in Saudi Arabia
  20. FireEye links Triton Malware to Russian Research Institute
  21. CNI Campaign TRITON Linked to Russian Institute
  22. Free GrandCrab Ransomware Decryption Tool Released by Bitdefender
  23. Cathay Pacific data breach affecting 9.4 million passengers
  24. .@FireEye security researchers claimed the Russian government was 'most likely' behind the Triton #malware attack on an industrial control system
  25. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye
  26. West Haven pays $2k USD because of ransomware attack
  27. NETSCOUT’s Arbor Cloud Expands DDoS Protection Across Asia
  28. GandCrab Ransomware decryption tool

ATTACKS

  1. Cutwail Spam Campaign Uses Steganography to Distribute URLZone
  2. Cathay Pacific hack: Personal data of up to 9.4 million airline passengers laid bare
  3. Another 185K Customers Potentially Affected by the British Airways Data Breach
  4. British Airways: Cyberattack, data theft bigger than we first thought
  5. Cathay Pacific data breach: 9.4 million passenger information at risk
  6. Data Breach Announced by CMS – Approximately 75,000 Individuals’ Files Affected
  7. Abandoned Web Apps Found as a Core Cause Behind High Profile Data Breaches
  8. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  9. Questions Mount Over Delay After Cathay Pacific Admits Huge Data Leak
  10. Multiple Phishing Campaigns Target Universities
  11. 77K Additional Customers Affected by British Airways' MageCart Data Breach
  12. Cofense Hunts Phishing Threats Round the Clock with Enhanced 24-hour Global Phishing Defense Services
  13. Cathay Pacific data breach exposes PII of 9.4 million customers
  14. Cathay Pacific data breach exposed 9.4m customers’ details
  15. Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
  16. Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
  17. CNI Campaign TRITON Linked to Russian Institute
  18. Chalubo Botnet Compromise Your Server or IoT Device & Use it for DDOS Attack
  19. Cathay Pacific data breach affecting 9.4 million passengers
  20. Learn how hackers used TLS certificates to launch @netflix #phishing attacks from expert Michael Cobb of @thehairyITdog
  21. iOS 12 has completely blocked password cracking tool, GrayKey
  22. Data leak at consulting firm handling fundraisers for the Democratic party

THREATS

  1. New security flaw impacts most Linux and BSD distros
  2. Experts released a free Decryption Tool for GandCrab ransomware
  3. Misconfigured Container Abused to Deliver Cryptocurrency-mining Malware
  4. Malware Distributors Adopt DKIM to Bypass Mail Filters
  5. Multiple Vulnerabilities Patched in ASRock Drivers
  6. Unusual Remote Execution Bug in Cisco WebEx Discovered by Researchers
  7. Cobalt Group tries to slip malicious PDFs past bank employees, researchers say
  8. WINDOWS ZERO-DAY BY SANDBOXESCAPER
  9. New FilesLocker Ransomware Offered as a Ransomware as a Service
  10. Another one bites the dust! In 2018 Android malware can bypass defences of billon dollar AV industry and Google Play
  11. Sophos Patches RCE and Memory Disclosure Vulnerabilities in
  12. Vulnerability Spotlight: TALOS-2018-0635/0636 – Sophos HitmanPro.Alert memory disclosure and code execution vulnerabilities
  13. Pentagon Expands Bug-Bounty Program to Include Physical Systems
  14. GandCrab ransomware declawed with new decryption tool
  15. Researchers Find Command Injection Flaw in Cisco WebEx
  16. Files Encrypted by GandCrab Ransomware Can Now Be Decrypted for Free
  17. 'TimpDoor' Malware Turns Android Devices into Proxies
  18. North Korea blamed for two cryptocurrency scams, five trading platform hacks
  19. Bypass an Anti Virus Detection with Encrypted Payloads using VENOM Tool
  20. #DidYouKnow AVG Free Antivirus received the highest rating of Advanced+ in @AV_Comparatives latest Malware Protection Test? Share AVG Free Antivirus with
  21. Researchers recently found vulnerabilities in #robot controllers from @Universal_Robot. Learn what these robot controllers do and how #ThreatActors exploit these
  22. Microsoft Acknowledges Zip File Overwrite Bug - Fix Coming in November
  23. Malware Distributors Adopt DKIM to Bypass Mail Filters
  24. Mac Malware Injects Ads Into Encrypted Traffic
  25. Cisco releases fix for privilege escalation bug in Webex Meetings app
  26. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  27. Bitdefender releases GandCrab ransomware decryption tool
  28. Amazon IoT operating system FreeRTOS has serious vulnerabilities
  29. FireEye ties Russia to Triton malware attack in Saudi Arabia
  30. Our threat intelligence lead Chris Dawson (@mrdatahs) discussing new @proofpoint Threat Insight #Malware research with @threatpost.
  31. FireEye links Triton Malware to Russian Research Institute
  32. Experts discovered a severe command injection flaw in Cisco Webex Meetings Desktop
  33. You patch my back(up) and I'll patch yours... Arcserve bugs burrow remotely exploited holes in UDP storage systems
  34. Free GrandCrab Ransomware Decryption Tool Released by Bitdefender
  35. Free Decrypter Available for the Latest GandCrab Ransomware Versions
  36. Signal Desktop App Vulnerability Exposes Message Decryption Key To The Users
  37. ESET releases new decryptor for Syrian victims of GandCrab ransomware
  38. Vulnerability Spotlight: TALOS-2018-0635/0636 - Sophos HitmanPro.Alert memory disclosure and code execution vulnerabilities
  39. Free decryption tool released for multiple GandCrab ransomware versions
  40. .@FireEye security researchers claimed the Russian government was 'most likely' behind the Triton #malware attack on an industrial control system
  41. Windows 10 Update Fixed File Deletion Flaw But Not ZIP File Overwrite Bug
  42. Google Chrome 70.0.3538.77 released: Bugs fix
  43. Win10 1803 big bug bash KB 4462933 joins earlier versions, a week late to the party
  44. Building shared digital identity using blockchain technology
  45. FreeRTOS Multiple Remote Code Execution Vulnerabilities Threat Alert
  46. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye
  47. Java Usage Tracker Vulnerability
  48. Windows 10 bug overwrites files without confirmation
  49. West Haven pays $2k USD because of ransomware attack
  50. Unusual Remote Execution Bug in Cisco WebEx Discovered by Researchers
  51. What is application security? A process and tools for securing software
  52. [BLOG] When #malware actor realizes that he can make more money by himself and transform his dropper into banking malware,
  53. New Android Malware Turns Your Mobile Devices into Hidden Proxies
  54. GandCrab Ransomware decryption tool

CRIME

  1. Another 185K Customers Potentially Affected by the British Airways Data Breach
  2. British Airways: Cyberattack, data theft bigger than we first thought
  3. Aftermath of the Data Breach: Cathay Pacific Customers Losing Confidence
  4. Multiple Phishing Campaigns Target Universities
  5. 5 Common Visibility Gaps Your Enterprise Security Plan Can’t Afford
  6. Cofense Hunts Phishing Threats Round the Clock with Enhanced 24-hour Global Phishing Defense Services
  7. Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
  8. Cathay Pacific data breach affecting 9.4 million passengers

POLITICS

  1. Russian-Made Malware Used to Attack Saudi Petrol Plant, Claims FireEye

Oct 25, 2018

APT report for 2018-10-24

TRANSNATIONAL / UNKNOWN

  1. Magecart hackers change tactic and target vulnerable Magento extensions
  2. Magecart Cybergang Targets 0days in Third-Party Magento Extensions
  3. Magecart Hackers Now Targeting Vulnerable Magento Extensions
  4. Magecart Attackers Exploit Magento Zero-Days

CHINA

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign

INDIA

  1. Federal Legislation Enables Consumers to Obtain Security Freezes on Credit Reports Free of Charge

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. New Malware Targets Industrial Control Systems
  2. Need help managing supply chain risks? In this week's ShadowTalk episode, the team breaks it down into hardware, software
  3. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  4. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  5. The risk to OT networks is real, and it’s dangerous for business leaders to ignore
  6. Russian Government-owned research institute linked to Triton attacks
  7. NETSCOUT Takes Internet Scale Threat Protection to the Edge
  8. .@RobertMLee said #GreyEnergy is a threat, but people shouldn't conclude from @ESET research that the group will only target

SERBIA

Nil

UKRAINE

  1. Russian Government-owned research institute linked to Triton attacks

Platform report for 2018-10-24

WINDOWS

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Windows ‘Deletebug’ Zero-Day Allows Privilege Escalation, Destruction
  3. Exploit for New Windows Zero-Day Published on Twitter
  4. Cisco Patches Local WebEx Vulnerability, Remotely Exploitable in AD Deployments
  5. CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
  6. Meet Cryptojacking, the (not so) new kid on the block
  7. Exploit kits: fall 2018 review
  8. Another Windows 0-day flaw has been published on Twitter
  9. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  10. A Windows 0day vulnerability was made public on Twitter
  11. New Microsoft Windows Zero-Day Dropped on Twitter, Micropatch Available
  12. New Windows Zero-Day Bug Helps Delete Any File, Exploit Available
  13. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  14. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  15. The risk to OT networks is real, and it’s dangerous for business leaders to ignore
  16. Russian Government-owned research institute linked to Triton attacks
  17. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  18. How Microsoft's Controlled Folder Access can help stop ransomware
  19. Hacker Discloses New Windows Zero-Day Exploit On Twitter

LINUX

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Meet Cryptojacking, the (not so) new kid on the block
  3. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  4. Chalubo, a new IoT botnet emerges in the threat landscape

UNIX

Nil

ANDROID

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  3. Marine diesel engines software developed by Auto Maskin has serious vulnerabilities

IOS

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

MACOS

  1. CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
  2. Meet Cryptojacking, the (not so) new kid on the block
  3. Mac malware intercepts encrypted web traffic for ad injection

Threat report for 2018-10-24

DATA BREACH & DATA LOSS

  1. Cathay Pacific breach leaks personal data on 9.4 million people
  2. Cathay Pacific data breach hits 9.4 million people
  3. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  4. Democratic Fundraising Firm Leaks Voter Database, Clients, Fundraisers
  5. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  6. Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee
  7. Information-Stealing Malware Campaign Evades Anti-Virus Detection
  8. Cathay Pacific Suffers Data Breach Impacting 9.4 Million Passengers
  9. Pocket iNet Leaves 73 GB of Sensitive Data Exposed
  10. Yahoo to pay up to $85m to settle data breach lawsuit
  11. Tim Cook Blasts Weaponization Of Personal Data And Praises GDPR
  12. Pocket iNet Left All Of Its Corporate Passwords, Keys, And Data Exposed
  13. Apple's Tim Cook: Our personal data is 'weaponized against us' by you-know-who
  14. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  15. Last year the @USAgov required agencies to implement #DMARC records and policies by October 2018. Learn just how hard DMARC
  16. Discover how #NetSpectre attacks leak data remotely via side-channels with Michael Cobb of @thehairyITdog.
  17. Yahoo Agrees to Pay $50 Million in Damages to Settle Data Breach Lawsuit
  18. Business Email Compromise: Gift Cards
  19. US government medical website was hacked that 75,000 personal data was stolen
  20. Morrisons supermarket: We're taking payroll leak liability fight to UK Supreme Court
  21. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  22. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  23. Yahoo agrees to pay $50 million to settle data breach lawsuit
  24. My Health Record opt-outs now sit at over 1.1 million
  25. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  26. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  27. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  28. Yahoo to pay at least $85m for data breach settlement
  29. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  30. A recent @HealthCareGov #breach exposed unknown types of data on 75,000 people, but a lack of information in the disclosure

DENIAL-OF-SERVICE

  1. This botnet snares your smart devices to perform DDoS attacks with a little help from Mirai

MALVERTISING

Nil

PHISHING

  1. Phishing Attack Tip 1: Beware of Unsettling Content An email containing unsettling, startling, or urgent content that requires immediate action on
  2. The Enduring Password Conundrum
  3. Phishing for knowledge
  4. Phishing attacks: Why is email still such an easy target for hackers?
  5. Office 365 for Business - from May to September - has been Recorded Lowest Phish Miss Rate Versus Rivals
  6. Area 1 Security releases Pay-Per-Phish, the performance-based cybersecurity solution

WEB DEFACEMENT

Nil

BOTNET

  1. Poorly secured SSH servers targeted by Chalubo botnet
  2. This botnet snares your smart devices to perform DDoS attacks with a little help from Mirai
  3. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,
  4. Chalubo, a new IoT botnet emerges in the threat landscape

RANSOMWARE

  1. ThreatList: Ransomware, EKs and Trojans lead the Way in Q3 Malware Trends
  2. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  3. How Microsoft's Controlled Folder Access can help stop ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. ​Australian woman arrested over AU$450,000 Ripple theft
  2. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  3. Meet Cryptojacking, the (not so) new kid on the block
  4. FBI: Call of Duty gamers helped steal $3.3 million in cryptocurrency hacking scheme
  5. Crytojacking 101; why cryptojacking is bad for business
  6. China asks blockchain-based service providers to control user information
  7. A Digital Currency for Everyone: 5 Easy Way Steps to Follow for Buying Bitcoin
  8. Securing Blockchain with Privileged Access Management

MALWARE

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  3. Information-Stealing Malware Campaign Evades Anti-Virus Detection
  4. New Malware Targets Industrial Control Systems
  5. FlawedAmmyy Remote Access Trojan
  6. Meet the malware which turns your smartphone into a mobile proxy
  7. sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
  8. ThreatList: Ransomware, EKs and Trojans lead the Way in Q3 Malware Trends
  9. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  10. Mac malware intercepts encrypted web traffic for ad injection
  11. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  12. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  13. LuminosityLink RAT author sentenced to 2.5 years in jail
  14. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  15. Beyond Your Bank Account: Ten Astounding Finds Uncovered by Financial Malware
  16. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware

EXPLOIT

  1. Exploit for New Windows Zero-Day Published on Twitter
  2. Exploit kits: fall 2018 review
  3. New Windows Zero-Day Bug Helps Delete Any File, Exploit Available
  4. Siemens Siclock: How do threat actors exploit these devices?
  5. Magecart Attackers Exploit Magento Zero-Days
  6. Hacker Discloses New Windows Zero-Day Exploit On Twitter

VULNERABILITY

  1. Windows ‘Deletebug’ Zero-Day Allows Privilege Escalation, Destruction
  2. Vulnerabilities in Linksys Routers May Grant Attackers Full Control
  3. Exploit for New Windows Zero-Day Published on Twitter
  4. Cisco Patches Local WebEx Vulnerability, Remotely Exploitable in AD Deployments
  5. CVE-2018-4338: Triggering an Information Disclosure on macOS Through a Broadcom AirPort Kext
  6. Another Windows 0-day flaw has been published on Twitter
  7. .@Siemens disclosed six SICLOCK flaws that were found within its central plant clocks. Discover why three flaws have been rated
  8. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  9. Pentagon Launches Continuous Bug Bounty Program
  10. [SingCERT] Alert on Drupal Critical Vulnerabilities
  11. A Windows 0day vulnerability was made public on Twitter
  12. Organizations with strong DevSecOps find flaws 11x faster than those without
  13. New Microsoft Windows Zero-Day Dropped on Twitter, Micropatch Available
  14. A #ZeroDay in #jQuery File Upload could affect thousands of projects because the jQuery #plugin vulnerability has existed for eight
  15. Most enterprise vulnerabilities remain unpatched a month after discovery
  16. WizCase Found Critical Firmware Vulnerabilities In Leading NAS Devices
  17. New Windows Zero-Day Bug Helps Delete Any File, Exploit Available
  18. Twitter User Discloses Second Microsoft Zero-Day
  19. Firefox 63 Released with Enhanced Tracking Protection and Fixes 14 Security Vulnerabilities
  20. Most applications 'suffer from information leakage bugs'
  21. DoD bug bounty program to expand to more sensitive systems
  22. 3-year-old jQuery plugin vulnerability finally patched
  23. US Department of Defense Expands Bug Bounty Efforts
  24. The Qihoo @360CoreSec team found a @Microsoft vulnerability -- named Double Kill -- that affects applications through #MicrosoftOffice documents. Learn
  25. Good initiative. Would be even better if you would pay bounties for the bugs, too.
  26. Learn about the #NetSpectre vulnerability and the benefits of #ThreatModeling for cloud deployments from expert Ed Moyle of @securitycurve.
  27. A summer intern took a look at tinc VPN, they found some nice authentication bypass and message tampering flaws
  28. Again Hacker Exposed New Microsoft Unpatched Zero-day Bug In Twitter With PoC
  29. Marine diesel engines software developed by Auto Maskin has serious vulnerabilities
  30. Drupal Remote Code Execution Vulnerability Threat Alert
  31. Hacker Discloses New Windows Zero-Day Exploit On Twitter

Region brief for 2018-10-24

ASIA

  1. Cathay Pacific breach leaks personal data on 9.4 million people
  2. Democratic Fundraising Firm Leaks Voter Database, Clients, Fundraisers
  3. Cathay Pacific Hit by Data Leak Affecting 9.4M Passengers
  4. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  5. Exploit kits: fall 2018 review
  6. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  7. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  8. Phishing for knowledge
  9. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  10. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  11. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  12. Russian Government-owned research institute linked to Triton attacks
  13. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware
  14. Drupal Remote Code Execution Vulnerability Threat Alert
  15. China asks blockchain-based service providers to control user information

OCEANIA

  1. ​Australian woman arrested over AU$450,000 Ripple theft
  2. Phishing for knowledge

NORTH AMERICA

  1. Warning: More iOS Devices Are Infected by Cryptocurrency Mining Malware
  2. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  3. Meet Cryptojacking, the (not so) new kid on the block
  4. Exploit kits: fall 2018 review
  5. Pocket iNet Leaves 73 GB of Sensitive Data Exposed
  6. Beers with Talos EP40: BWT XL feat. SuperMicro, Giant Patches, and More Mobile Malware
  7. Yahoo to pay up to $85m to settle data breach lawsuit
  8. Apple's Tim Cook: Our personal data is 'weaponized against us' by you-know-who
  9. US government medical website was hacked that 75,000 personal data was stolen
  10. Pocket iNet ISP exposed 73GB of data including secret keys, plain text passwords
  11. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  12. Phishing for knowledge
  13. US Department of Defense Expands Bug Bounty Efforts
  14. Join us, and @SentinelOne Nov 29, as we discuss fast acting #ransomware remediation, threat hunting, and #AI that stops incongruous
  15. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  16. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  17. ISP Provider Exposed 73 Gigabytes of Highly Sensitive Data Including To The Internet
  18. South Korea Seems Chief Target of the ‘Operation Oceansalt’ Campaign
  19. Survey: Nearly Half of U.S. Adults Experienced a Data Breach in the Past Three Years
  20. China asks blockchain-based service providers to control user information

SOUTH AMERICA

  1. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  2. Phishing for knowledge

EUROPE

  1. Hacker Guccifer, who exposed Clinton private email server, ready for US prison sentence
  2. Magecart hackers change tactic and target vulnerable Magento extensions
  3. Russia Behind Triton Malware? A Cybersecurity Consulting Firm Confirms
  4. Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee
  5. New Malware Targets Industrial Control Systems
  6. Yahoo to pay up to $85m to settle data breach lawsuit
  7. Russian Malware Used In An Attempt To Sabotage Saudi Petrol Plant
  8. Malware Targeting Brazil Uses Legitimate Windows Components WMI and CertUtil as Part of its Routine
  9. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,
  10. Morrisons supermarket: We're taking payroll leak liability fight to UK Supreme Court
  11. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  12. Phishing for knowledge
  13. Magecart Attackers Exploit Magento Zero-Days
  14. Deadly Malware That Attacked Saudi Industrial Plant Came From Russia
  15. Researchers: Russia is the initiator of ICS Attack Framework “TRITON” and Trisis
  16. Russian Government-owned research institute linked to Triton attacks
  17. FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware
  18. Marine diesel engines software developed by Auto Maskin has serious vulnerabilities

AFRICA

  1. Phishing for knowledge