Oct 30, 2018

Sector brief for 2018-10-29

HEALTHCARE

  1. Hackers Breach System of Healthcare.Gov Exposing Personal Data of 75,000 Users
  2. Beware! Downloader Malware Disguised as Game Apps Found On Google Play with More Than 51,100 Installations

TRANSPORT

  1. What can we do to tackle today’s phishing epidemic?

BANKING & FINANCE

  1. Future Investment Initiative Conference Website, Defaced, Now Restored
  2. Here's how to defend your enterprise from Magecart
  3. Breaking News: Securonix Threat Research: British Airways Breach
  4. Cathay Pacific Suffers World’s Largest Airline Data Breach
  5. sLoad and Ramnit Campaign Against UK and Italy
  6. Cobalt Gang targets banks and financial service providers by sneaking PDFs past staff
  7. Girl Scouts Alerted to Possible Data Breach
  8. 'Narwhal Spider' group's spam campaign targets Japanese recipients with URLZone malware
  9. What can we do to tackle today’s phishing epidemic?
  10. The Worst Data Breach till Now 2018, and What It Means
  11. Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments
  12. Revolutionary Blockchain 3.0 Under CSE Platform

INFORMATION & TELECOMMUNICATION

  1. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  2. Word documents seemingly carrying videos can deliver malicious code instead
  3. Remote Denial of Service Vulnerability Patched in Squid Proxy Cache Server
  4. This is getting worse and worse. And is going to normalize and lead to much more successful phishing through SMS
  5. Malware That Accompanies Google Chrome Download Detected
  6. Systemd flaw could cause the crash or hijack of vulnerable Linux machines
  7. What can we do to tackle today’s phishing epidemic?
  8. Rise of the Bots
  9. The Worst Data Breach till Now 2018, and What It Means
  10. Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments
  11. Crooks continue to abuse exposed Docker APIs for Cryptojacking
  12. Have you ever wondered why #ransomware attacks happen on the Friday before a long weekend? We've teamed up with @SentinelOne
  13. 33,000 Accounting Inbox Credentials Exposed Online: BEC Made Easy | Read the details here:

FOOD

Nil

WATER

  1. Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments

ENERGY

  1. Revolutionary Blockchain 3.0 Under CSE Platform

GOVERNMENT & PUBLIC SERVICE

  1. Pentagon’s big audit will inspect for cybersecurity flaws, comptroller says
  2. Hackers Breach System of Healthcare.Gov Exposing Personal Data of 75,000 Users

Daily brief for 2018-10-29

ASIA

  1. Future Investment Initiative Conference Website, Defaced, Now Restored
  2. Cathay Pacific Suffers World’s Largest Airline Data Breach
  3. Serious Vulnerability Discovered In X.Org Server Affects Major Linux and BSD Variants
  4. 'Narwhal Spider' group's spam campaign targets Japanese recipients with URLZone malware
  5. Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments
  6. Revolutionary Blockchain 3.0 Under CSE Platform
  7. Leaked: iOS 12.1 will be released on October 30th

WORLD

  1. Phishing spikes as private health continues to be most breached sector in Australia
  2. Future Investment Initiative Conference Website, Defaced, Now Restored
  3. Here's how to defend your enterprise from Magecart
  4. Breaking News: Securonix Threat Research: British Airways Breach
  5. Cathay Pacific Suffers World’s Largest Airline Data Breach
  6. sLoad and Ramnit Campaign Against UK and Italy
  7. Magecart Exploits Zero Day Vulnerabilities
  8. Understanding mass data fragmentation
  9. Secret Service Confirms Focus on Email Compromise Cybercrimes Worth $12 Billion
  10. Man Ordered to Pay $8.6 Million for Launching DDoS Attacks against Rutgers University
  11. Security Vulnerability in Internet-Connected Construction Cranes
  12. Girl Scouts Alerted to Possible Data Breach
  13. What can we do to tackle today’s phishing epidemic?
  14. Privacy concerns cooling #InternetOfThings adoption in US & Europe, with consumers concerned about #DataLeaks, malware and product security (via @FSecure)
  15. Das Geschäft mit gestohlenen Login-Daten von Privatnutzern und Unternehmensanwendern boomt. US-Journalist Brian Krebs beziffert die "Ausbeute" bei mehreren 100.000 US-Dollar
  16. The Worst Data Breach till Now 2018, and What It Means
  17. Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments
  18. Cisco patched a command injection vulnerability in Webex Meetings
  19. Leaked: iOS 12.1 will be released on October 30th

ATTACKS

  1. Phishing spikes as private health continues to be most breached sector in Australia
  2. Girl Scouts Issues Data Breach Warning to 2,800 Members
  3. Nation-State Phishing: A Country-Sized Catch
  4. A new phishing report reveals Microsoft, Paypal, and Netflix are among the top brands impersonated by phishing attacks. Attackers tend to
  5. This is getting worse and worse. And is going to normalize and lead to much more successful phishing through SMS
  6. Cathay Pacific Suffers World’s Largest Airline Data Breach
  7. League of Legends Gamers Targeted by Phishing Scam | Avast
  8. sLoad and Ramnit Campaign Against UK and Italy
  9. Secret Service Confirms Focus on Email Compromise Cybercrimes Worth $12 Billion
  10. Girl Scouts Alerted to Possible Data Breach
  11. 'Narwhal Spider' group's spam campaign targets Japanese recipients with URLZone malware
  12. DDoS and ransomware tools for starter and experienced cybercriminals exposed
  13. Biggest Manufacturing Data Breaches of the 21st Century
  14. What can we do to tackle today’s phishing epidemic?
  15. Das Geschäft mit gestohlenen Login-Daten von Privatnutzern und Unternehmensanwendern boomt. US-Journalist Brian Krebs beziffert die "Ausbeute" bei mehreren 100.000 US-Dollar
  16. The Worst Data Breach till Now 2018, and What It Means
  17. Crooks continue to abuse exposed Docker APIs for Cryptojacking
  18. IoT users uncertain if personal data is shared across multiple devices
  19. 19% still save their password on a piece of paper
  20. Hackers Breach System of Healthcare.Gov Exposing Personal Data of 75,000 Users
  21. Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
  22. Leaked: iOS 12.1 will be released on October 30th
  23. Vulnerability In Microsoft Word Online Video Feature Allows for Phishing
  24. 33,000 Accounting Inbox Credentials Exposed Online: BEC Made Easy | Read the details here:

THREATS

  1. Videos and MS Office documents - ingredients for a malware attack
  2. SandboxEscaper expert is back and disclosed a new Windows Zero-Day
  3. IoT Flaw Allows Hijacking of Connected Construction Cranes
  4. Mac CryptoCurrency Price Tracker Caught Installing Backdoors
  5. Mac cryptocurrency ticker app installs backdoors
  6. Word documents seemingly carrying videos can deliver malicious code instead
  7. Remote Denial of Service Vulnerability Patched in Squid Proxy Cache Server
  8. X.Org Flaw Allows Privilege Escalation in Linux Systems
  9. Downloading Google Chrome via Microsoft Edge Endangered by Malware
  10. The Ransomware Attack on a North Carolina Water Utility May Not Have Been What it Seemed
  11. X.Org Flaw Exposes Unix-Like OSes to Attacks
  12. Windows 10 UWP Bug Could Give Malicious Devs Access To All Your Files
  13. X.org Bug Bites OpenBSD And Other Big Operating Systems
  14. If your company uses Windows 10, watch out: there are new vulnerabilities about
  15. Advanced Malware Protection Affected by Bug That Can Inhibit Intrusion Detection
  16. Logical Bug in Microsoft Word's 'Online Video' Allows Code Execution
  17. Call of Duty players caught up in cryptocurrency theft racket
  18. Ransomware and the enterprise: A new white paper
  19. Windows 10 UWP bug could give malicious devs access to all your files
  20. Windows 10 Bug Allowed UWP Apps Full Access to File System
  21. Magecart Exploits Zero Day Vulnerabilities
  22. Serious Vulnerability Discovered In X.Org Server Affects Major Linux and BSD Variants
  23. Malware That Accompanies Google Chrome Download Detected
  24. Security Vulnerability in Internet-Connected Construction Cranes
  25. 'Narwhal Spider' group's spam campaign targets Japanese recipients with URLZone malware
  26. Cyber-criminals exploit misconfigured container to deliver cryptominer
  27. DDoS and ransomware tools for starter and experienced cybercriminals exposed
  28. Systemd flaw could cause the crash or hijack of vulnerable Linux machines
  29. Pentagon’s big audit will inspect for cybersecurity flaws, comptroller says
  30. Vulnerability found in Sophos anti-malware product
  31. Flaws in brain stimulation tech could let hackers erase or hold memories for ransom
  32. Privacy concerns cooling #InternetOfThings adoption in US & Europe, with consumers concerned about #DataLeaks, malware and product security (via @FSecure)
  33. Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments
  34. Crooks continue to abuse exposed Docker APIs for Cryptojacking
  35. Revolutionary Blockchain 3.0 Under CSE Platform
  36. #Antivirus SW alone can't stop new #malware or #ransomware. by @MariaKorolov -
  37. Beware! Downloader Malware Disguised as Game Apps Found On Google Play with More Than 51,100 Installations
  38. Cisco patched a command injection vulnerability in Webex Meetings
  39. Have you ever wondered why #ransomware attacks happen on the Friday before a long weekend? We've teamed up with @SentinelOne
  40. Microsoft Bing Delivered Dangerous Malware When You Try to Download Google Chrome
  41. Vulnerability In Microsoft Word Online Video Feature Allows for Phishing

CRIME

  1. Future Investment Initiative Conference Website, Defaced, Now Restored
  2. Here's how to defend your enterprise from Magecart
  3. Breaking News: Securonix Threat Research: British Airways Breach
  4. Mirai Botnet Operator Ordered to Pay $8.6 Million
  5. Cathay Pacific Suffers World’s Largest Airline Data Breach
  6. Call of Duty players caught up in cryptocurrency theft racket
  7. League of Legends Gamers Targeted by Phishing Scam | Avast
  8. Malware That Accompanies Google Chrome Download Detected
  9. Secret Service Confirms Focus on Email Compromise Cybercrimes Worth $12 Billion
  10. Man Ordered to Pay $8.6 Million for Launching DDoS Attacks against Rutgers University
  11. Girl Scouts Alerted to Possible Data Breach
  12. Mirai Author Gets House Arrest for DDoS Attacks on University
  13. DDoS and ransomware tools for starter and experienced cybercriminals exposed
  14. What can we do to tackle today’s phishing epidemic?
  15. Revolutionary Blockchain 3.0 Under CSE Platform
  16. 33,000 Accounting Inbox Credentials Exposed Online: BEC Made Easy | Read the details here:

POLITICS

  1. Future Investment Initiative Conference Website, Defaced, Now Restored
  2. Secret Service Confirms Focus on Email Compromise Cybercrimes Worth $12 Billion
  3. What can we do to tackle today’s phishing epidemic?

Oct 29, 2018

APT report for 2018-10-28

TRANSNATIONAL / UNKNOWN

  1. Security Affairs newsletter Round 186 – News of the week

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-28

WINDOWS

  1. Security Affairs newsletter Round 186 – News of the week
  2. How to deliver malware using weaponized Microsoft Office docs embedding YouTube video
  3. Critical Code Execution Vulnerability Found in MKVToolNix Tools that Parses MKV Files

LINUX

  1. Security Affairs newsletter Round 186 – News of the week
  2. Critical Code Execution Vulnerability Found in MKVToolNix Tools that Parses MKV Files

UNIX

Nil

ANDROID

  1. Security Affairs newsletter Round 186 – News of the week

IOS

  1. Apple Made Apology Due to Apple ID Phishing Attacks

MACOS

  1. Apple Made Apology Due to Apple ID Phishing Attacks

Threat report for 2018-10-28

DATA BREACH & DATA LOSS

  1. Consulting Firm Leaked Data Of Democratic Party Fundraisers In Unsecured NAS Device
  2. Yahoo To Pay $50M, Other Costs For Massive Data Breach
  3. A recent @HealthCareGov #breach exposed unknown types of data on 75,000 people, but a lack of information in the disclosure
  4. "If an organization created #DMARC records for the first time, it would encounter syntax and content issues -- one of
  5. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Apple Made Apology Due to Apple ID Phishing Attacks
  2. On Phishing Attacks and the Companies That are Targeted the Most

WEB DEFACEMENT

Nil

BOTNET

  1. Satori botnet author in jail again after breaking pretrial release conditions
  2. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets

RANSOMWARE

  1. New ShadowTalk is out! @TheHVanRiper and Rafael Amado join @mazzazone to discuss #ransomware surges in October, Cathay Pacific Breach, and

CRYPTOMINING & CRYPTOCURRENCIES

  1. Is blockchain a solution to IoT security problems?

MALWARE

  1. 12 Malicious Python Libraries Found And Removed From PyPi
  2. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye
  3. How to deliver malware using weaponized Microsoft Office docs embedding YouTube video
  4. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  5. Bingo. Investigators find the same remote access trojan deployed to several other machines. Now the responders know what to look for.
  6. "My name is Mikko and I've been working with viruses and malware all my freaking life."

EXPLOIT

Nil

VULNERABILITY

  1. Cisco Patched Privilege Escalation Vulnerability In Webex Meetings Desktop App
  2. A flaw in @Cisco Webex -- called WebExec -- can allow #RemoteCodeExecution. And while experts don't agree on how dangerous
  3. .@Siemens central plant clocks were affected by six SICLOCK flaws, three have been rated "critical." Learn what these SICLOCK flaws
  4. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  5. Critical Code Execution Vulnerability Found in MKVToolNix Tools that Parses MKV Files

Region brief for 2018-10-28

ASIA

  1. Apple Made Apology Due to Apple ID Phishing Attacks
  2. Security Affairs newsletter Round 186 – News of the week
  3. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye

OCEANIA

Nil

NORTH AMERICA

  1. Consulting Firm Leaked Data Of Democratic Party Fundraisers In Unsecured NAS Device
  2. On Phishing Attacks and the Companies That are Targeted the Most
  3. New ShadowTalk is out! @TheHVanRiper and Rafael Amado join @mazzazone to discuss #ransomware surges in October, Cathay Pacific Breach, and

SOUTH AMERICA

Nil

EUROPE

  1. Security Affairs newsletter Round 186 – News of the week
  2. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye
  3. New ShadowTalk is out! @TheHVanRiper and Rafael Amado join @mazzazone to discuss #ransomware surges in October, Cathay Pacific Breach, and
  4. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets

AFRICA

Nil

Sector brief for 2018-10-28

HEALTHCARE

  1. Security Affairs newsletter Round 186 – News of the week

TRANSPORT

Nil

BANKING & FINANCE

  1. Apple Made Apology Due to Apple ID Phishing Attacks
  2. On Phishing Attacks and the Companies That are Targeted the Most

INFORMATION & TELECOMMUNICATION

  1. Apple Made Apology Due to Apple ID Phishing Attacks
  2. On Phishing Attacks and the Companies That are Targeted the Most
  3. Security Affairs newsletter Round 186 – News of the week
  4. How to deliver malware using weaponized Microsoft Office docs embedding YouTube video
  5. "My name is Mikko and I've been working with viruses and malware all my freaking life."

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Consulting Firm Leaked Data Of Democratic Party Fundraisers In Unsecured NAS Device
  2. Security Affairs newsletter Round 186 – News of the week
  3. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye

Daily brief for 2018-10-28

ASIA

  1. Apple Made Apology Due to Apple ID Phishing Attacks
  2. Security Affairs newsletter Round 186 – News of the week
  3. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye

WORLD

  1. Consulting Firm Leaked Data Of Democratic Party Fundraisers In Unsecured NAS Device
  2. On Phishing Attacks and the Companies That are Targeted the Most
  3. Security Affairs newsletter Round 186 – News of the week
  4. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye
  5. New ShadowTalk is out! @TheHVanRiper and Rafael Amado join @mazzazone to discuss #ransomware surges in October, Cathay Pacific Breach, and
  6. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets

ATTACKS

  1. Consulting Firm Leaked Data Of Democratic Party Fundraisers In Unsecured NAS Device
  2. Apple Made Apology Due to Apple ID Phishing Attacks
  3. On Phishing Attacks and the Companies That are Targeted the Most
  4. Yahoo To Pay $50M, Other Costs For Massive Data Breach
  5. A recent @HealthCareGov #breach exposed unknown types of data on 75,000 people, but a lack of information in the disclosure
  6. "If an organization created #DMARC records for the first time, it would encounter syntax and content issues -- one of
  7. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains

THREATS

  1. Is blockchain a solution to IoT security problems?
  2. Cisco Patched Privilege Escalation Vulnerability In Webex Meetings Desktop App
  3. A flaw in @Cisco Webex -- called WebExec -- can allow #RemoteCodeExecution. And while experts don't agree on how dangerous
  4. 12 Malicious Python Libraries Found And Removed From PyPi
  5. Russian Research Lab Involved in the Development of TRITON Malware, Says FireEye
  6. .@Siemens central plant clocks were affected by six SICLOCK flaws, three have been rated "critical." Learn what these SICLOCK flaws
  7. How to deliver malware using weaponized Microsoft Office docs embedding YouTube video
  8. New ShadowTalk is out! @TheHVanRiper and Rafael Amado join @mazzazone to discuss #ransomware surges in October, Cathay Pacific Breach, and
  9. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  10. Critical Code Execution Vulnerability Found in MKVToolNix Tools that Parses MKV Files
  11. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  12. Bingo. Investigators find the same remote access trojan deployed to several other machines. Now the responders know what to look for.
  13. "My name is Mikko and I've been working with viruses and malware all my freaking life."

CRIME

  1. Apple Made Apology Due to Apple ID Phishing Attacks
  2. On Phishing Attacks and the Companies That are Targeted the Most
  3. Security Affairs newsletter Round 186 – News of the week

POLITICS

  1. Security Affairs newsletter Round 186 – News of the week

Oct 28, 2018

APT report for 2018-10-27

TRANSNATIONAL / UNKNOWN

Nil

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

Nil

SERBIA

Nil

UKRAINE

  1. News of the Week: October 27, 2018

Platform report for 2018-10-27

WINDOWS

  1. Cisco launches patches for vulnerabilities in WEBEX Meetings app

LINUX

  1. The LibSSH Security Bug in the Nutshell

UNIX

Nil

ANDROID

  1. The LibSSH Security Bug in the Nutshell

IOS

  1. The LibSSH Security Bug in the Nutshell

MACOS

  1. The LibSSH Security Bug in the Nutshell

Threat report for 2018-10-27

DATA BREACH & DATA LOSS

Nil

DENIAL-OF-SERVICE

  1. DDoS and Ransomware Tools Used by Cyber Criminals Discovered
  2. A few dollars to bring down sites with new Bushido-based DDoS-for-hire service
  3. Hackers Offering DDoS-for-Hire Service Powered by Bushido Botnet in Dark Web Markets

MALVERTISING

Nil

PHISHING

Nil

WEB DEFACEMENT

Nil

BOTNET

  1. Hackers Offering DDoS-for-Hire Service Powered by Bushido Botnet in Dark Web Markets

RANSOMWARE

  1. DDoS and Ransomware Tools Used by Cyber Criminals Discovered
  2. Decrypt files attacked with the latest versions of GandCrab ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. Sorry friends, I'm afraid I just can't quite afford the Bitcoin to stop that vid from leaking everywhere
  2. Australian Cryptocurrency Theft Highlights Security Mistakes

MALWARE

  1. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  2. Bankbot/Anubis downloader hits #1 trending at finance @ThreatFabric @
  3. Twelve malicious Python libraries found and removed from PyPI
  4. The forensics analysts log the adversaries’ actions and every network packet the hackers send. The adversaries use a process running
  5. Executable Formats and How To Exploit Them
  6. Unpatched Critical Bug in Microsoft Word Online Video Feature Allow Attacker to Deliver Powerful Malware
  7. New malware attacks targeting voters in key states in the 2018 US midterm elections
  8. Two hours after the deadline, the forensics team notices someone accessing the MES system server using domain administrator credentials through

EXPLOIT

  1. Executable Formats and How To Exploit Them

VULNERABILITY

  1. Researchers recently found vulnerabilities within the robot controllers from @Universal_Robot. Learn what these #robot controllers are used for and how
  2. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  3. The LibSSH Security Bug in the Nutshell
  4. The Pentagon expands the scope of its vulnerability bounty program
  5. Unpatched Critical Bug in Microsoft Word Online Video Feature Allow Attacker to Deliver Powerful Malware
  6. Cisco launches patches for vulnerabilities in WEBEX Meetings app
  7. A #RemoteCodeExecution flaw in @Cisco Webex -- called WebExec -- could be an easy vector for insider attacks, and the

Region brief for 2018-10-27

ASIA

  1. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia

OCEANIA

  1. Australian Cryptocurrency Theft Highlights Security Mistakes

NORTH AMERICA

  1. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  2. Australian Cryptocurrency Theft Highlights Security Mistakes
  3. The Pentagon expands the scope of its vulnerability bounty program
  4. Decrypt files attacked with the latest versions of GandCrab ransomware
  5. New malware attacks targeting voters in key states in the 2018 US midterm elections

SOUTH AMERICA

Nil

EUROPE

  1. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  2. Decrypt files attacked with the latest versions of GandCrab ransomware
  3. New malware attacks targeting voters in key states in the 2018 US midterm elections

AFRICA

Nil

Sector brief for 2018-10-27

HEALTHCARE

Nil

TRANSPORT

  1. A few dollars to bring down sites with new Bushido-based DDoS-for-hire service

BANKING & FINANCE

  1. News of the Week: October 27, 2018
  2. Australian Cryptocurrency Theft Highlights Security Mistakes
  3. Bankbot/Anubis downloader hits #1 trending at finance @ThreatFabric @
  4. The Pentagon expands the scope of its vulnerability bounty program

INFORMATION & TELECOMMUNICATION

  1. A few dollars to bring down sites with new Bushido-based DDoS-for-hire service
  2. Bankbot/Anubis downloader hits #1 trending at finance @ThreatFabric @
  3. The LibSSH Security Bug in the Nutshell

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  2. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  3. Australian Cryptocurrency Theft Highlights Security Mistakes
  4. The Pentagon expands the scope of its vulnerability bounty program
  5. Decrypt files attacked with the latest versions of GandCrab ransomware
  6. New malware attacks targeting voters in key states in the 2018 US midterm elections

Daily brief for 2018-10-27

ASIA

  1. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia

WORLD

  1. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  2. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  3. Australian Cryptocurrency Theft Highlights Security Mistakes
  4. The Pentagon expands the scope of its vulnerability bounty program
  5. Decrypt files attacked with the latest versions of GandCrab ransomware
  6. New malware attacks targeting voters in key states in the 2018 US midterm elections

ATTACKS

Nil

THREATS

  1. .@FireEye researchers have attributed the #Triton #malware -- used in an attack on an industrial control system in Saudi Arabia
  2. DDoS and Ransomware Tools Used by Cyber Criminals Discovered
  3. Researchers recently found vulnerabilities within the robot controllers from @Universal_Robot. Learn what these #robot controllers are used for and how
  4. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  5. Sorry friends, I'm afraid I just can't quite afford the Bitcoin to stop that vid from leaking everywhere
  6. Australian Cryptocurrency Theft Highlights Security Mistakes
  7. Bankbot/Anubis downloader hits #1 trending at finance @ThreatFabric @
  8. Twelve malicious Python libraries found and removed from PyPI
  9. The forensics analysts log the adversaries’ actions and every network packet the hackers send. The adversaries use a process running
  10. The LibSSH Security Bug in the Nutshell
  11. Executable Formats and How To Exploit Them
  12. The Pentagon expands the scope of its vulnerability bounty program
  13. Decrypt files attacked with the latest versions of GandCrab ransomware
  14. Unpatched Critical Bug in Microsoft Word Online Video Feature Allow Attacker to Deliver Powerful Malware
  15. Cisco launches patches for vulnerabilities in WEBEX Meetings app
  16. New malware attacks targeting voters in key states in the 2018 US midterm elections
  17. Two hours after the deadline, the forensics team notices someone accessing the MES system server using domain administrator credentials through
  18. A #RemoteCodeExecution flaw in @Cisco Webex -- called WebExec -- could be an easy vector for insider attacks, and the

CRIME

  1. DDoS and Ransomware Tools Used by Cyber Criminals Discovered
  2. Australian Cryptocurrency Theft Highlights Security Mistakes
  3. Hackers Offering DDoS-for-Hire Service Powered by Bushido Botnet in Dark Web Markets

POLITICS

Nil

Oct 27, 2018

APT report for 2018-10-26

TRANSNATIONAL / UNKNOWN

  1. British Airways: additional 185,000 passengers may have been affected
  2. BA Website Hijacked by Magecart. Again. | Avast
  3. US Counters Russian Influence & Magecart Hacks Magento | Avast
  4. BA website and data breach by Magecart deeper than first thought
  5. BA Breach: An Extra 185K Customers Notified
  6. Hackers attack Cathay Pacific
  7. Second attack against British Airways is disclosed

CHINA

  1. Tracking Tick Through Recent Campaigns Targeting East Asia
  2. Operation Oceansalt

INDIA

Nil

NORTH KOREA

  1. North Korea Backed Two Cryptocurrency Scams This Year, Says Report

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. GreyEnergy cyberespionage group targets Poland and Ukraine
  2. Russian sabotage in Saudi petrochemicals

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-26

WINDOWS

  1. CVE-2018-14665 privilege escalation flaw affects popular Linux distros
  2. Code Execution Vulnerability Patched in Cross-Platform MKVToolNix Toolset
  3. ICMP Shell- Secret Command and Control Channel to Control Victims Machine Using Ping
  4. Cisco patches command injection bug in Webex Meetings Desktop App for Windows
  5. Vulnerability Spotlight: Talos-2018-0694 - MKVToolNix mkvinfo read_one_element Code Execution Vulnerability
  6. New Malware Abusing Two Legitimate Windows Files to Steal Victims Personal Data
  7. Zero-day vulnerability in Windows allows privileges escalation

LINUX

  1. CVE-2018-14665 privilege escalation flaw affects popular Linux distros
  2. Code Execution Vulnerability Patched in Cross-Platform MKVToolNix Toolset
  3. ICMP Shell- Secret Command and Control Channel to Control Victims Machine Using Ping
  4. Trivial Bug in X.Org Gives Root Permission on Linux and BSD Systems
  5. Chalubo Botnet
  6. CVE-2018-14665: Xorg X Server privilege escalation vulnerabilities
  7. This two-year-old X.org give-me-root hole is so trivial to exploit, you can fit it in a single tweet
  8. Vulnerability Spotlight: Talos-2018-0694 - MKVToolNix mkvinfo read_one_element Code Execution Vulnerability
  9. New Privilege Escalation Flaw Affects Most Linux Distributions

UNIX

  1. CVE-2018-14665 privilege escalation flaw affects popular Linux distros
  2. CVE-2018-14665: Xorg X Server privilege escalation vulnerabilities
  3. New Privilege Escalation Flaw Affects Most Linux Distributions

ANDROID

Nil

IOS

Nil

MACOS

  1. Code Execution Vulnerability Patched in Cross-Platform MKVToolNix Toolset

Threat report for 2018-10-26

DATA BREACH & DATA LOSS

  1. ThreatList: 1 Out of 5 Would Ditch a Business After a Data Breach
  2. Facebook removes Iranian influence campaign as midterms near
  3. Bushido-Powered DDoS Service Whipped Up from Leaked Code
  4. British Airways: 185K Affected in Second Data Breach
  5. British Airways Data Breach Takes Off Again with 185K More Victims
  6. Settlement in Yahoo data breach leaves company to pay $50M
  7. Pocket iNET ISP Exposed 73GB of Sensitive Data On Misconfigured S3 Bucket
  8. Campaign 2018: New malware attacks target voters in key battleground states
  9. Cathay Pacific Hacked, Personal Data For 9.4 Million Passengers Compromised
  10. Tracking Tick Through Recent Campaigns Targeting East Asia
  11. Details of 9mil compromised in Cathay Pacific data leak
  12. Cathay Pacific Suffered Data Breach Affecting 9.4 Million Customers
  13. BA website and data breach by Magecart deeper than first thought
  14. Malicious actors attacked a back-end insurance system and the resulting @HealthCareGov #breach exposed an unknown amount of data on 75,000
  15. Cathay Pacific hack: Personal data of up to 9.4 million airline passengers laid bare
  16. Cathay Pacific Says 9.4 Million Affected by Data Breach
  17. A #ZeroDay in the popular #jQuery File Upload plugin could affect thousands of projects and the jQuery #plugin vulnerability may
  18. Airline Discovers Trove of Frequent Flyer Accounts Compromised and Posted for Sale Online:
  19. British Airways data breach worse than thought
  20. Spammers Behind Historic Data Breach Affecting Millions of Facebook Users
  21. Cathay Pacific Airways Confirm Data Breach of its Customers
  22. “Advanced attacks, spear-phishing and data breaches are the norm, instead of the exception. We need to address these issues with
  23. New Malware Abusing Two Legitimate Windows Files to Steal Victims Personal Data

DENIAL-OF-SERVICE

  1. University DDoS attack leads to $8.6 million fine, house arrest for New Jersey man
  2. Bushido-Powered DDoS Service Whipped Up from Leaked Code
  3. 16K Strong DDoS-for-Hire Botnet Provides 420+ GB/s Club to Knock Out Websites
  4. DemonBot Fans DDoS Flames with Hadoop Enslavement
  5. New DemonBot Attack Hadoop Clusters to Performing DDoS Attacks using Powerful Cloud infrastructure servers

MALVERTISING

Nil

PHISHING

  1. Microsoft bug makes phishing easy, says cybersecurity firm
  2. PhishX –Spear Phishing Tool for Capturing Credentials
  3. “Advanced attacks, spear-phishing and data breaches are the norm, instead of the exception. We need to address these issues with

WEB DEFACEMENT

Nil

BOTNET

  1. Exploits Block List Grows 50% Because of Spambot, Avalanche/Gamarue botnet
  2. 16K Strong DDoS-for-Hire Botnet Provides 420+ GB/s Club to Knock Out Websites
  3. Chalubo Botnet
  4. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  5. New DemonBot Botnet Pulls the YARN in Hadoop Servers

RANSOMWARE

  1. The Week in Ransomware - October 26th 2018 - Decryptors, RaaS, and More
  2. 3 Keys to Reducing the Threat of Ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. 23-year-old woman charged with stealing $320,000 worth of cryptocurrency
  2. 23-year-old woman charged with stealing $320,000 worth of cryptocurrency
  3. North Korea regime using and exploiting cryptocurrencies
  4. North Korea Backed Two Cryptocurrency Scams This Year, Says Report
  5. No Place for Security as Cryptocurrency Skills Demand Soars
  6. What Is Gridcoin and How Can It Advance Science?
  7. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  8. China’s Alibaba Cloud Expands Enterprise Blockchain Offering to Global Markets
  9. How to become a Monero million(th)aire in just 20 minutes [PODCAST]

MALWARE

  1. Due to Misconfigured Component: DemonBot Malware Infects Multiple Apache Hadoop Servers
  2. PoC Attack Leverages Microsoft Office and YouTube to Deliver Malware
  3. ICMP Shell- Secret Command and Control Channel to Control Victims Machine Using Ping
  4. Scammers use old browser trick to create fake virus download
  5. Campaign 2018: New malware attacks target voters in key battleground states
  6. DeepPhish: Simulating Malicious AI to Act Like an Adversary
  7. .@FireEye #security researchers claimed the Russian government was 'most likely' behind the #Triton #malware attack on an industrial control system
  8. Malicious actors attacked a back-end insurance system and the resulting @HealthCareGov #breach exposed an unknown amount of data on 75,000
  9. An innovative partnership could help Cyber Command fight malware
  10. New Malware Abusing Two Legitimate Windows Files to Steal Victims Personal Data

EXPLOIT

  1. This two-year-old X.org give-me-root hole is so trivial to exploit, you can fit it in a single tweet

VULNERABILITY

  1. CVE-2018-14665 privilege escalation flaw affects popular Linux distros
  2. Cloudflare WAF Bypass Vulnerability Discovered
  3. Code Execution Vulnerability Patched in Cross-Platform MKVToolNix Toolset
  4. Vulnerability Spotlight: Talos-2018-0694 – MKVToolNix mkvinfo read_one_element Code Execution Vulnerability
  5. Microsoft bug makes phishing easy, says cybersecurity firm
  6. A flaw in @Cisco Webex -- called WebExec -- can allow #RemoteCodeExecution. And while experts don't agree on how dangerous
  7. Pentagon Expands Bug Bounty To Include Physical Systems
  8. WebExec vulnerability leaves Webex open to insider attacks
  9. Trivial Bug in X.Org Gives Root Permission on Linux and BSD Systems
  10. Researchers discovered a vulnerability in Cisco #Webex, called #WebExec, which allows local attackers to issue commands as privileged users. @iagox86
  11. Cisco patches command injection bug in Webex Meetings Desktop App for Windows
  12. CVE-2018-9206 was maliciously exploited that multiple websites were linked to the search page to jump to the betting site
  13. CVE-2018-14665: Xorg X Server privilege escalation vulnerabilities
  14. What a crane in the ass: Bug leaves construction machinery vulnerable to evil command injection
  15. Researchers report vulnerability in Microsoft Word's online video feature
  16. A #ZeroDay in the popular #jQuery File Upload plugin could affect thousands of projects and the jQuery #plugin vulnerability may
  17. Vulnerability Spotlight: Talos-2018-0694 - MKVToolNix mkvinfo read_one_element Code Execution Vulnerability
  18. LIVE NETWORKS LIVE555 Streaming Media RTSP Server Remote Code Execution Vulnerability(CVE-2018-4013) Threat Alert
  19. New Privilege Escalation Flaw Affects Most Linux Distributions
  20. Top 5 Application Vulnerabilities: How to Prevent Risks
  21. 7 places to find threat intel beyond vulnerability databases
  22. Zero-day vulnerability in Windows allows privileges escalation

Region brief for 2018-10-26

ASIA

  1. GreyEnergy cyberespionage group targets Poland and Ukraine
  2. Facebook removes Iranian influence campaign as midterms near
  3. Exploits Block List Grows 50% Because of Spambot, Avalanche/Gamarue botnet
  4. CVE-2018-14665 privilege escalation flaw affects popular Linux distros
  5. 23-year-old woman charged with stealing $320,000 worth of cryptocurrency
  6. Tracking Tick Through Recent Campaigns Targeting East Asia
  7. .@FireEye #security researchers claimed the Russian government was 'most likely' behind the #Triton #malware attack on an industrial control system
  8. North Korea regime using and exploiting cryptocurrencies
  9. North Korea Backed Two Cryptocurrency Scams This Year, Says Report
  10. LIVE NETWORKS LIVE555 Streaming Media RTSP Server Remote Code Execution Vulnerability(CVE-2018-4013) Threat Alert
  11. New Privilege Escalation Flaw Affects Most Linux Distributions
  12. Operation Oceansalt
  13. Hackers attack Cathay Pacific
  14. China’s Alibaba Cloud Expands Enterprise Blockchain Offering to Global Markets
  15. Russian sabotage in Saudi petrochemicals

OCEANIA

  1. 23-year-old woman charged with stealing $320,000 worth of cryptocurrency
  2. 23-year-old woman charged with stealing $320,000 worth of cryptocurrency

NORTH AMERICA

  1. University DDoS attack leads to $8.6 million fine, house arrest for New Jersey man
  2. 23-year-old woman charged with stealing $320,000 worth of cryptocurrency
  3. US Counters Russian Influence & Magecart Hacks Magento | Avast
  4. North Korea Backed Two Cryptocurrency Scams This Year, Says Report
  5. What a crane in the ass: Bug leaves construction machinery vulnerable to evil command injection
  6. China’s Alibaba Cloud Expands Enterprise Blockchain Offering to Global Markets

SOUTH AMERICA

Nil

EUROPE

  1. British Airways: additional 185,000 passengers may have been affected
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. British Airways: 185K Affected in Second Data Breach
  4. BA Website Hijacked by Magecart. Again. | Avast
  5. British Airways Data Breach Takes Off Again with 185K More Victims
  6. 23-year-old woman charged with stealing $320,000 worth of cryptocurrency
  7. US Counters Russian Influence & Magecart Hacks Magento | Avast
  8. .@FireEye #security researchers claimed the Russian government was 'most likely' behind the #Triton #malware attack on an industrial control system
  9. BA website and data breach by Magecart deeper than first thought
  10. No Place for Security as Cryptocurrency Skills Demand Soars
  11. BA Breach: An Extra 185K Customers Notified
  12. British Airways data breach worse than thought
  13. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  14. Hackers attack Cathay Pacific
  15. China’s Alibaba Cloud Expands Enterprise Blockchain Offering to Global Markets
  16. Second attack against British Airways is disclosed
  17. Russian sabotage in Saudi petrochemicals

AFRICA

Nil