Nov 6, 2018

Region brief for 2018-11-05

ASIA

  1. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  2. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem
  3. Persian Stalker pillages Iranian users of Instagram and Telegram
  4. A cybersecurity lesson: educational sites suffer rise in DDoS attacks in Q3

OCEANIA

  1. Week in review: Volume of Australian data breaches continues unabated
  2. Australian shipbuilder Austal hit by data breach
  3. Persian Stalker pillages Iranian users of Instagram and Telegram
  4. A cybersecurity lesson: educational sites suffer rise in DDoS attacks in Q3
  5. "Shipbuilder Austal Ltd said on Thursday its Australian business had detected and responded to a data breach"

NORTH AMERICA

  1. What were the DDoS numbers for Q2 & Q3 2018?
  2. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  3. Your personal data is widely available to hackers
  4. Inside SearchPageInstaller | macOS Malware Deploys a MITM Attack
  5. Magecart Strikes Again, and Kitronik Is Latest Victim
  6. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem
  7. Equifax Set to Share More PII with Experian
  8. #SamSam #ransomware continues to be a thorn in the side of organizations in the U.S. with targeted ransomware campaigns continuing,
  9. Over 80,000 Facebook User Accounts Compromised
  10. Why malware attacks should no longer be a problem for businesses
  11. Critical 'Bleedingbit' flaws found in microcontrollers used by Wi-Fi access points
  12. Persian Stalker pillages Iranian users of Instagram and Telegram
  13. A cybersecurity lesson: educational sites suffer rise in DDoS attacks in Q3
  14. "A lot of people in Congress are concerned that the Facebook influence campaigns are about the midterms, but to me
  15. "Shipbuilder Austal Ltd said on Thursday its Australian business had detected and responded to a data breach"

SOUTH AMERICA

  1. Over 80,000 Facebook User Accounts Compromised

EUROPE

  1. Inception Group Uses POWERSHOWER Backdoor in Two-Stage Spear Phishing Attacks
  2. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  3. Magecart Infiltrates U.K. Online Retailer Kitronik POS
  4. Akado Telecom Accidentally Leaks Customers' Names, Phone Numbers, And Addresses
  5. Magecart Strikes Again, and Kitronik Is Latest Victim
  6. Inception Attackers Target Europe with Year-old Office Vulnerability
  7. Kemp Investigates Dems, Not the Reported Vulnerability
  8. Over 80,000 Facebook User Accounts Compromised
  9. Persian Stalker pillages Iranian users of Instagram and Telegram
  10. Kemp Cites Voter Database Hacking Attempt, Gives No Evidence
  11. A cybersecurity lesson: educational sites suffer rise in DDoS attacks in Q3

AFRICA

  1. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem

Sector brief for 2018-11-05

HEALTHCARE

Nil

TRANSPORT

Nil

BANKING & FINANCE

  1. Original Mirai botnet creator hit with hefty financial sentence
  2. Magecart Strikes Again, and Kitronik Is Latest Victim
  3. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem
  4. Over 80,000 Facebook User Accounts Compromised
  5. Why malware attacks should no longer be a problem for businesses
  6. Cybercriminals Using SMS Phishing Attack to Rob Cardless ATM
  7. Persian Stalker pillages Iranian users of Instagram and Telegram
  8. Phishing attacks up by 297 percent across eCommerce in Q3 2018
  9. A cybersecurity lesson: educational sites suffer rise in DDoS attacks in Q3
  10. Video analysis of Android banking Trojan found on Google Play (Red Alert 2)

INFORMATION & TELECOMMUNICATION

  1. PoC Available for Microsoft Edge Zero-Day RCE, Exploit Under Development
  2. Original Mirai botnet creator hit with hefty financial sentence
  3. Inside SearchPageInstaller | macOS Malware Deploys a MITM Attack
  4. Fake Elon Musk Twitter Bitcoin Scam Earned 180K in One Day
  5. Another wave of Elon Musk bitcoin scams spread by verified Twitter accounts
  6. Inception Attackers Target Europe with Year-old Office Vulnerability
  7. Flaw in Icecast streaming media server allows to take off online Radio Stations
  8. Security firm Armis has discovered two vulnerabilities in Bluetooth Chips from several networking industry leaders.
  9. Over 80,000 Facebook User Accounts Compromised
  10. Persian Stalker pillages Iranian users of Instagram and Telegram
  11. Phishing attacks up by 297 percent across eCommerce in Q3 2018
  12. The Ultimate Guide to Bug Bounty Platforms
  13. Researchers discover new zero-day vulnerability in EDGE browser
  14. Fake malicious @RSAsecurity #SecurID malware in pre-release state on @GooglePlay: - Currently gathering information (profiling) the mobile device it is installed
  15. "A lot of people in Congress are concerned that the Facebook influence campaigns are about the midterms, but to me

FOOD

Nil

WATER

Nil

ENERGY

  1. [SingCERT] Technical Advisory on Vulnerabilities in Bluetooth Low Energy Chips by Texas Instruments (CVE-2018-16986 and CVE-2018-7080)
  2. Critical 'Bleedingbit' flaws found in microcontrollers used by Wi-Fi access points

GOVERNMENT & PUBLIC SERVICE

  1. No, blockchain isn't the answer to our voting system woes
  2. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  3. Akado Telecom Accidentally Leaks Customers' Names, Phone Numbers, And Addresses
  4. Inception Attackers Target Europe with Year-old Office Vulnerability
  5. Kemp Investigates Dems, Not the Reported Vulnerability
  6. Persian Stalker pillages Iranian users of Instagram and Telegram
  7. Phishing attacks up by 297 percent across eCommerce in Q3 2018
  8. Kemp Cites Voter Database Hacking Attempt, Gives No Evidence
  9. "A lot of people in Congress are concerned that the Facebook influence campaigns are about the midterms, but to me

Daily brief for 2018-11-05

ASIA

  1. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  2. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem
  3. Persian Stalker pillages Iranian users of Instagram and Telegram
  4. A cybersecurity lesson: educational sites suffer rise in DDoS attacks in Q3

WORLD

  1. Week in review: Volume of Australian data breaches continues unabated
  2. Inception Group Uses POWERSHOWER Backdoor in Two-Stage Spear Phishing Attacks
  3. What were the DDoS numbers for Q2 & Q3 2018?
  4. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  5. Your personal data is widely available to hackers
  6. Magecart Infiltrates U.K. Online Retailer Kitronik POS
  7. Inside SearchPageInstaller | macOS Malware Deploys a MITM Attack
  8. Akado Telecom Accidentally Leaks Customers' Names, Phone Numbers, And Addresses
  9. Magecart Strikes Again, and Kitronik Is Latest Victim
  10. Inception Attackers Target Europe with Year-old Office Vulnerability
  11. Kemp Investigates Dems, Not the Reported Vulnerability
  12. Australian shipbuilder Austal hit by data breach
  13. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem
  14. Equifax Set to Share More PII with Experian
  15. #SamSam #ransomware continues to be a thorn in the side of organizations in the U.S. with targeted ransomware campaigns continuing,
  16. Over 80,000 Facebook User Accounts Compromised
  17. Why malware attacks should no longer be a problem for businesses
  18. Critical 'Bleedingbit' flaws found in microcontrollers used by Wi-Fi access points
  19. Persian Stalker pillages Iranian users of Instagram and Telegram
  20. Kemp Cites Voter Database Hacking Attempt, Gives No Evidence
  21. A cybersecurity lesson: educational sites suffer rise in DDoS attacks in Q3
  22. "A lot of people in Congress are concerned that the Facebook influence campaigns are about the midterms, but to me
  23. "Shipbuilder Austal Ltd said on Thursday its Australian business had detected and responded to a data breach"

ATTACKS

  1. Week in review: Volume of Australian data breaches continues unabated
  2. Almost 300 Percent Increase in eCommerce Phishing Attacks in Q3 2018
  3. Inception Group Uses POWERSHOWER Backdoor in Two-Stage Spear Phishing Attacks
  4. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  5. Your personal data is widely available to hackers
  6. This Tool Shows Exposed Cameras Around Your Neighborhood
  7. New Side-Channel Vulnerability Leaks Sensitive Data From Intel Chips
  8. How to use Firefox Master Password.
  9. Why you should be using a password manager
  10. Akado Telecom Accidentally Leaks Customers' Names, Phone Numbers, And Addresses
  11. Australian shipbuilder Austal hit by data breach
  12. How did @Google eliminate successful #PhishingAttacks? Learn how employees used U2F authentication and physical #SecurityKeys to defend against phishing from
  13. Password Constraints and Their Unintended Security Consequences
  14. Equifax Set to Share More PII with Experian
  15. #SamSam #ransomware continues to be a thorn in the side of organizations in the U.S. with targeted ransomware campaigns continuing,
  16. National biometric database could be on the way (and in private hands)
  17. Over 80,000 Facebook User Accounts Compromised
  18. Cybercriminals Using SMS Phishing Attack to Rob Cardless ATM
  19. How can U2F authentication end phishing attacks?
  20. Phishing attacks up by 297 percent across eCommerce in Q3 2018
  21. "If an organization created #DMARC records for the first time, it would encounter syntax and content issues -- one of
  22. Kemp Cites Voter Database Hacking Attempt, Gives No Evidence
  23. "A lot of people in Congress are concerned that the Facebook influence campaigns are about the midterms, but to me
  24. "Shipbuilder Austal Ltd said on Thursday its Australian business had detected and responded to a data breach"

THREATS

  1. Apache warns Struts 2.3 is using a library with a two year old critical flaw
  2. Inception Group Uses POWERSHOWER Backdoor in Two-Stage Spear Phishing Attacks
  3. Online Radio Stations at Risk from Icecast Flaw
  4. No, blockchain isn't the answer to our voting system woes
  5. PoC Available for Microsoft Edge Zero-Day RCE, Exploit Under Development
  6. Flaws In Self-Encrypting SSDs Let Attackers Bypass Encryption
  7. New Side-Channel Vulnerability Leaks Sensitive Data From Intel Chips
  8. Inside SearchPageInstaller | macOS Malware Deploys a MITM Attack
  9. Why Are Deserialization Vulnerabilities So Popular?
  10. Fake Elon Musk Twitter Bitcoin Scam Earned 180K in One Day
  11. Another wave of Elon Musk bitcoin scams spread by verified Twitter accounts
  12. Flaws in self-encrypting SSDs let attackers bypass disk encryption
  13. [SingCERT] Technical Advisory on Vulnerabilities in Bluetooth Low Energy Chips by Texas Instruments (CVE-2018-16986 and CVE-2018-7080)
  14. Inception Attackers Target Europe with Year-old Office Vulnerability
  15. Malware of the 1980s: Looking back at the Brain Virus and the Morris Worm
  16. Kemp Investigates Dems, Not the Reported Vulnerability
  17. Flaws in Popular SSD Drives Bypass Hardware Disk Encryption
  18. Flaw in Icecast streaming media server allows to take off online Radio Stations
  19. Security researchers exploit Intel hyperthreading flaw to break encryption
  20. .@ArmisSecurity researchers discovered two chip-level #Bluetooth vulnerabilities -- dubbed #Bleedingbit -- that could allow pseudo #RemoteCodeExecution on wireless access points.
  21. Vulnerabilities’ CVSS scores soon to be assigned by AI
  22. Cisco Products Affected By A Zero-Day SIP Inspection Vulnerability Exploited In The Wild
  23. #SamSam #ransomware continues to be a thorn in the side of organizations in the U.S. with targeted ransomware campaigns continuing,
  24. Researchers found #Kraken #ransomware has become more popular after being packaged in the Fallout #ExploitKit and becoming part of an
  25. High severity XML external entity flaw affects Sauter building automation product
  26. Security firm Armis has discovered two vulnerabilities in Bluetooth Chips from several networking industry leaders.
  27. Blockhead makes blockchain easy for developers
  28. Why malware attacks should no longer be a problem for businesses
  29. Critical 'Bleedingbit' flaws found in microcontrollers used by Wi-Fi access points
  30. Mozilla Patched Multiple Security Vulnerabilities in Thunderbird 60.3
  31. Android Rat – TheFatRat to Hack and Gain access to Targeted Android Phone
  32. Apple Patched Multiple XNU Kernel Vulnerabilities In MacOS And iOS
  33. Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts
  34. The building blocks of blockchain-based digital identity
  35. Companies implementing DevSecOps address vulnerabilities faster than others
  36. How to Get Rid of Cortana Runtime Broker CPU Miner Virus
  37. The Ultimate Guide to Bug Bounty Platforms
  38. PortSmash – A New Side Channel Vulnerability in SMT/Hyper-Threading That Allows Attackers To Steal Sensitive Data
  39. Security Think Tank: Three ways to safeguard against application layer vulnerabilities
  40. Security Bug in Icecast Puts Online Radio Stations At Risk
  41. Researchers discover new zero-day vulnerability in EDGE browser
  42. Fake malicious @RSAsecurity #SecurID malware in pre-release state on @GooglePlay: - Currently gathering information (profiling) the mobile device it is installed
  43. Video analysis of Android banking Trojan found on Google Play (Red Alert 2)
  44. Recently there have been a lot of packed Android malware around, so I decided to write a blog-post on how

CRIME

  1. Week in review: Volume of Australian data breaches continues unabated
  2. Original Mirai botnet creator hit with hefty financial sentence
  3. Fake Elon Musk Twitter Bitcoin Scam Earned 180K in One Day
  4. Australian shipbuilder Austal hit by data breach
  5. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem
  6. Equifax Set to Share More PII with Experian
  7. Over 80,000 Facebook User Accounts Compromised
  8. Cybercriminals Using SMS Phishing Attack to Rob Cardless ATM
  9. Persian Stalker pillages Iranian users of Instagram and Telegram
  10. Phishing attacks up by 297 percent across eCommerce in Q3 2018
  11. The Ultimate Guide to Bug Bounty Platforms

POLITICS

  1. Google dorks were the root cause of a catastrophic compromise of CIA’s communications
  2. Kemp Investigates Dems, Not the Reported Vulnerability
  3. Cyber-Attacks: How to Stop a Multibillion-Dollar Problem
  4. "A lot of people in Congress are concerned that the Facebook influence campaigns are about the midterms, but to me

Nov 5, 2018

APT report for 2018-11-04

TRANSNATIONAL / UNKNOWN

  1. Who’s In Your Online Shopping Cart?
  2. Security Affairs newsletter Round 187 – News of the week

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. WireGuard has not been merged into the Linux kernel mainline

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

Nil

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-04

WINDOWS

  1. Security Affairs newsletter Round 187 – News of the week

LINUX

  1. Security Affairs newsletter Round 187 – News of the week
  2. WireGuard has not been merged into the Linux kernel mainline

UNIX

Nil

ANDROID

Nil

IOS

  1. Security Affairs newsletter Round 187 – News of the week

MACOS

Nil

Threat report for 2018-11-04

DATA BREACH & DATA LOSS

  1. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Beware!! Cyber Criminals Stealing Cash From Cardless ATM Using SMS Phishing Attack

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. Kraken ransomware 2.0 is available through the RaaS model
  2. Targeted SamSam Ransomware Attacks Continues to Breaking & Lock 67 Different Organizations Network

CRYPTOMINING & CRYPTOCURRENCIES

  1. Kraken ransomware 2.0 is available through the RaaS model

MALWARE

  1. Week in review: Bleedingbit, nastiest malware of 2018, Cisco security appliances under attack
  2. Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more
  3. What should you do when you realize you've click on a malicious link?

EXPLOIT

  1. New Microsoft Edge Browser Zero-Day RCE Exploit in the Works

VULNERABILITY

  1. Vulnerability Scanners 101
  2. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  3. New Microsoft Edge Browser Zero-Day RCE Exploit in the Works
  4. Researchers recently found vulnerabilities within the robot controllers from @Universal_Robot. Learn what these #robot controllers are used for and how
  5. Why Vulnerability Management Does Not Work
  6. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products
  7. Intel processors are vulnerable to new PortSmash side-channel vulnerability
  8. New Intel CPU Flaw Exploits Hyper-Threading to Steal Encrypted Data

Region brief for 2018-11-04

ASIA

  1. Security Affairs newsletter Round 187 – News of the week
  2. Kraken ransomware 2.0 is available through the RaaS model
  3. Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more
  4. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products

OCEANIA

  1. Security Affairs newsletter Round 187 – News of the week

NORTH AMERICA

  1. Who’s In Your Online Shopping Cart?
  2. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  3. Security Affairs newsletter Round 187 – News of the week
  4. Targeted SamSam Ransomware Attacks Continues to Breaking & Lock 67 Different Organizations Network
  5. Intel processors are vulnerable to new PortSmash side-channel vulnerability
  6. WireGuard has not been merged into the Linux kernel mainline

SOUTH AMERICA

  1. Kraken ransomware 2.0 is available through the RaaS model

EUROPE

  1. Who’s In Your Online Shopping Cart?
  2. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  3. Security Affairs newsletter Round 187 – News of the week
  4. Kraken ransomware 2.0 is available through the RaaS model
  5. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products
  6. Intel processors are vulnerable to new PortSmash side-channel vulnerability

AFRICA

  1. Who’s In Your Online Shopping Cart?

Sector brief for 2018-11-04

HEALTHCARE

  1. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products

TRANSPORT

  1. Vulnerability Scanners 101
  2. Security Affairs newsletter Round 187 – News of the week

BANKING & FINANCE

  1. Who’s In Your Online Shopping Cart?
  2. Kraken ransomware 2.0 is available through the RaaS model
  3. Beware!! Cyber Criminals Stealing Cash From Cardless ATM Using SMS Phishing Attack

INFORMATION & TELECOMMUNICATION

  1. Who’s In Your Online Shopping Cart?
  2. Security Affairs newsletter Round 187 – News of the week
  3. Kraken ransomware 2.0 is available through the RaaS model

FOOD

Nil

WATER

Nil

ENERGY

  1. Security Affairs newsletter Round 187 – News of the week

GOVERNMENT & PUBLIC SERVICE

  1. Security Affairs newsletter Round 187 – News of the week

Daily brief for 2018-11-04

ASIA

  1. Security Affairs newsletter Round 187 – News of the week
  2. Kraken ransomware 2.0 is available through the RaaS model
  3. Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more
  4. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products

WORLD

  1. Who’s In Your Online Shopping Cart?
  2. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  3. Security Affairs newsletter Round 187 – News of the week
  4. Kraken ransomware 2.0 is available through the RaaS model
  5. Targeted SamSam Ransomware Attacks Continues to Breaking & Lock 67 Different Organizations Network
  6. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products
  7. Intel processors are vulnerable to new PortSmash side-channel vulnerability
  8. WireGuard has not been merged into the Linux kernel mainline

ATTACKS

  1. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  2. Beware!! Cyber Criminals Stealing Cash From Cardless ATM Using SMS Phishing Attack

THREATS

  1. Week in review: Bleedingbit, nastiest malware of 2018, Cisco security appliances under attack
  2. Vulnerability Scanners 101
  3. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  4. New Microsoft Edge Browser Zero-Day RCE Exploit in the Works
  5. Kraken ransomware 2.0 is available through the RaaS model
  6. Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more
  7. Targeted SamSam Ransomware Attacks Continues to Breaking & Lock 67 Different Organizations Network
  8. What should you do when you realize you've click on a malicious link?
  9. Researchers recently found vulnerabilities within the robot controllers from @Universal_Robot. Learn what these #robot controllers are used for and how
  10. Why Vulnerability Management Does Not Work
  11. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products
  12. Intel processors are vulnerable to new PortSmash side-channel vulnerability
  13. New Intel CPU Flaw Exploits Hyper-Threading to Steal Encrypted Data

CRIME

  1. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  2. Security Affairs newsletter Round 187 – News of the week
  3. Kraken ransomware 2.0 is available through the RaaS model

POLITICS

  1. PortSmash flaw in Hyper-Threading CPU could allow sensitive data theft
  2. Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more
  3. Bluetooth chip has serious security vulnerabilities that widely affect smart electronic products

Nov 4, 2018

APT report for 2018-11-03

TRANSNATIONAL / UNKNOWN

  1. BBC micro:bit vendor Kitronik says customers' deets nicked, fingers Magecart malware

CHINA

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-03

WINDOWS

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. New Trickbot Malware Steal Password & Other Sensitive Data From Microsoft Outlook,Chrome,Firefox, IE, Edge

LINUX

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

UNIX

Nil

ANDROID

  1. Android Devices Remain Unsecured, While Two Botnets Fight For Dominance

IOS

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

MACOS

Nil

Threat report for 2018-11-03

DATA BREACH & DATA LOSS

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Business Email Compromise: Must-Have Defenses
  3. Radisson Suffers Global Loyalty Program Data Breach
  4. Android Devices Remain Unsecured, While Two Botnets Fight For Dominance
  5. Discover how #NetSpectre attacks leak data remotely via side-channels with Michael Cobb of @thehairyITdog.

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. New Trickbot Malware Steal Password & Other Sensitive Data From Microsoft Outlook,Chrome,Firefox, IE, Edge

WEB DEFACEMENT

Nil

BOTNET

  1. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,

RANSOMWARE

  1. SamSam ransomware continues to make damages. Call it targeted Ransomware
  2. #SamSam #ransomware targeted 67 organizations in 2018, according to @symantec research. By @MaddieBacon11
  3. #Kraken #ransomware as a service is getting more popular after being bundled into the Fallout #ExploitKit and getting more update
  4. The Week in Ransomware - November 2nd 2018 - RaaS, DiskCryptor, & More

CRYPTOMINING & CRYPTOCURRENCIES

  1. Blockchain as a Tool for Cybersecurity
  2. #Kraken #ransomware as a service is getting more popular after being bundled into the Fallout #ExploitKit and getting more update

MALWARE

  1. Web domain owners paid EasyDNS to cloak their contact info from sight. It was blabbed via public Whois anyway
  2. BBC micro:bit vendor Kitronik says customers' deets nicked, fingers Magecart malware
  3. Gotta love how Robert Tappan Morris describes his Morris worm background in his bio: ”In 1988 his discovery of buffer
  4. New Trickbot Malware Steal Password & Other Sensitive Data From Microsoft Outlook,Chrome,Firefox, IE, Edge

EXPLOIT

  1. Intel CPUs Fall To New Hyperthreading Exploit That Pilfers Keys

VULNERABILITY

  1. The Responsible Disclosure of Software Vulnerabilities in the Nutshell
  2. .@Siemens central plant clocks were affected by six SICLOCK flaws, three have been rated "critical." Learn what these SICLOCK flaws
  3. Six flaws were recently found in @Siemens SICLOCK central plant clocks. Learn what these clocks do, which clocks were infected
  4. Researchers say #Bleedingbit vulnerabilities could allow #RemoteCodeExecution on wireless access points, medical devices and any other products using the affected

Region brief for 2018-11-03

ASIA

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. SamSam ransomware continues to make damages. Call it targeted Ransomware

OCEANIA

  1. SamSam ransomware continues to make damages. Call it targeted Ransomware

NORTH AMERICA

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. SamSam ransomware continues to make damages. Call it targeted Ransomware

SOUTH AMERICA

Nil

EUROPE

  1. BBC micro:bit vendor Kitronik says customers' deets nicked, fingers Magecart malware
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. SamSam ransomware continues to make damages. Call it targeted Ransomware
  4. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,

AFRICA

Nil

Sector brief for 2018-11-03

HEALTHCARE

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. SamSam ransomware continues to make damages. Call it targeted Ransomware
  3. Researchers say #Bleedingbit vulnerabilities could allow #RemoteCodeExecution on wireless access points, medical devices and any other products using the affected

TRANSPORT

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

BANKING & FINANCE

Nil

INFORMATION & TELECOMMUNICATION

  1. The Responsible Disclosure of Software Vulnerabilities in the Nutshell

FOOD

Nil

WATER

Nil

ENERGY

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

GOVERNMENT & PUBLIC SERVICE

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records

Daily brief for 2018-11-03

ASIA

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. SamSam ransomware continues to make damages. Call it targeted Ransomware

WORLD

  1. BBC micro:bit vendor Kitronik says customers' deets nicked, fingers Magecart malware
  2. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  3. SamSam ransomware continues to make damages. Call it targeted Ransomware
  4. "The resurgence of #VPNFilter #botnet appears to be limited to the Ukraine, but given the ease of infecting targeted systems,

ATTACKS

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Business Email Compromise: Must-Have Defenses
  3. Radisson Suffers Global Loyalty Program Data Breach
  4. Android Devices Remain Unsecured, While Two Botnets Fight For Dominance
  5. Discover how #NetSpectre attacks leak data remotely via side-channels with Michael Cobb of @thehairyITdog.
  6. New Trickbot Malware Steal Password & Other Sensitive Data From Microsoft Outlook,Chrome,Firefox, IE, Edge

THREATS

  1. The Responsible Disclosure of Software Vulnerabilities in the Nutshell
  2. Web domain owners paid EasyDNS to cloak their contact info from sight. It was blabbed via public Whois anyway
  3. BBC micro:bit vendor Kitronik says customers' deets nicked, fingers Magecart malware
  4. Blockchain as a Tool for Cybersecurity
  5. .@Siemens central plant clocks were affected by six SICLOCK flaws, three have been rated "critical." Learn what these SICLOCK flaws
  6. Six flaws were recently found in @Siemens SICLOCK central plant clocks. Learn what these clocks do, which clocks were infected
  7. SamSam ransomware continues to make damages. Call it targeted Ransomware
  8. Gotta love how Robert Tappan Morris describes his Morris worm background in his bio: ”In 1988 his discovery of buffer
  9. New Trickbot Malware Steal Password & Other Sensitive Data From Microsoft Outlook,Chrome,Firefox, IE, Edge
  10. Researchers say #Bleedingbit vulnerabilities could allow #RemoteCodeExecution on wireless access points, medical devices and any other products using the affected
  11. #SamSam #ransomware targeted 67 organizations in 2018, according to @symantec research. By @MaddieBacon11
  12. #Kraken #ransomware as a service is getting more popular after being bundled into the Fallout #ExploitKit and getting more update
  13. The Week in Ransomware - November 2nd 2018 - RaaS, DiskCryptor, & More

CRIME

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Business Email Compromise: Must-Have Defenses
  3. Radisson Suffers Global Loyalty Program Data Breach

POLITICS

  1. Weekly Threat Briefing: HealthCare.gov Suffered Data Breach As Hackers Stole 75,000 Records
  2. Android Devices Remain Unsecured, While Two Botnets Fight For Dominance
  3. SamSam ransomware continues to make damages. Call it targeted Ransomware

Nov 3, 2018

APT report for 2018-11-02

TRANSNATIONAL / UNKNOWN

  1. Magecart cybergang targeting e-commerce credit card data
  2. Magecart claims fresh victim in electronics kit seller Kitronik

CHINA

  1. Beware this malware: it can even survive operating systems being reinstalled

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. New Data Affirms Cyber Threat for Industrial Control Systems
  2. Beware this malware: it can even survive operating systems being reinstalled

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-02

WINDOWS

  1. Shellbot Variant Used in New Botnet, Spreads Using IoT and Linux Vulnerabilities
  2. Spam campaign targets Exodus Mac Users
  3. New Data Affirms Cyber Threat for Industrial Control Systems
  4. This Week in Security News: Spam Campaigns and Vulnerable Infrastructures
  5. How to password protect a folder or file in Windows | Avast
  6. Beware this malware: it can even survive operating systems being reinstalled
  7. Search for “Installing Chrome” on Bing can lead to malicious content

LINUX

  1. Shellbot Variant Used in New Botnet, Spreads Using IoT and Linux Vulnerabilities
  2. Outlaw Hacking Group Using Command Injection Flow To Attack Organizations Network using Botnet via C&C Server
  3. Systemd Vulnerability In Linux Could Trigger Remote Attacks And System Crashes

UNIX

Nil

ANDROID

  1. Two botnets are fighting over control of thousands of unsecured Android devices
  2. Shellbot Variant Used in New Botnet, Spreads Using IoT and Linux Vulnerabilities

IOS

Nil

MACOS

  1. Spam campaign targets Exodus Mac Users
  2. This Week in Security News: Spam Campaigns and Vulnerable Infrastructures

Threat report for 2018-11-02

DATA BREACH & DATA LOSS

  1. Two botnets are fighting over control of thousands of unsecured Android devices
  2. Joshua Adam Schulte, ex CIA employee, accused of continuing leaks from prison
  3. Spam campaign targets Exodus Mac Users
  4. 120 Million Facebook Accounts Compromised, Private Messages of 81,000 for Sale
  5. #SamSam #ransomware continues to be a thorn in the side of organizations in the U.S. with targeted ransomware campaigns continuing,
  6. 85 Millions of voter records available for sale ahead of the 2018 US Midterm Elections
  7. ePHI of 8,000 Patients Exposed in Health Plan Breach
  8. Facebook has experienced a number of security-related issues lately, but it doesn't appear to be at fault for the leak
  9. This Week in Security News: Spam Campaigns and Vulnerable Infrastructures
  10. Russian hackers compromise 120 million Facebook accounts; private messages on sale online
  11. SamSam ransomware campaigns continue to target U.S. in 2018
  12. Feds Accuse Ex-CIA Employee of Continuing Leaks From Prison
  13. Radisson Hotel Group Hit by Data Breach
  14. Spam campaign targets Exodus Mac Users
  15. Shipbuilder, defense contractor Austal reveals data breach
  16. Data theft at Radisson Hotel Group
  17. 85 million voter records on sale
  18. Iran has become victim of a cyberattack campaign
  19. Apache HBase 2.1.1 release, distributed database
  20. FIFA admits hack and braces for new leaks

DENIAL-OF-SERVICE

  1. ThreatList: Fewer Big DDoS Attacks in Q3, Overall Rate Holds Steady
  2. Bushido Botnet and DDoS-for-Hire

MALVERTISING

Nil

PHISHING

  1. SMS Phishing + Cardless ATM = Profit
  2. "While most phishing attacks on desktop and laptop computers come via email... a mobile device attack vector can be in
  3. #Phishing targets data that lives outside your enterprise perimeter—putting your entire enterprise at risk. Learn how post-perimeter security enables you
  4. How to password protect a folder or file in Windows | Avast
  5. Just half of Fortune 500 companies have installed DMARC, a tool that guards against email phishing scams, according to new
  6. Multiple #phishing pages on multiple domains targeting Canadian citizens posing as Canadian Revenue Agency, Interac, and others 192.99.86.132 (@OVH) cc: @cybercentre_ca
  7. YAPBS – Yet Another Password Breach Scam

WEB DEFACEMENT

Nil

BOTNET

  1. Shellbot Variant Used in New Botnet, Spreads Using IoT and Linux Vulnerabilities
  2. Bushido Botnet and DDoS-for-Hire
  3. Outlaw Hacking Group Using Command Injection Flow To Attack Organizations Network using Botnet via C&C Server
  4. BCMUPnP_Hunter: 100,000-node botnet is abusing routers for spam
  5. 'Outlaw' threat actor uses Shellbot variant to form new botnet

RANSOMWARE

  1. New Ransomware using DiskCryptor With Custom Ransom Message
  2. #SamSam #ransomware continues to be a thorn in the side of organizations in the U.S. with targeted ransomware campaigns continuing,
  3. Researchers found #Kraken #ransomware has become more popular after being packaged in the Fallout #ExploitKit and becoming part of an
  4. SamSam ransomware campaigns continue to target U.S. in 2018
  5. Kraken ransomware gets packaged into Fallout EK
  6. Giant ransomware bundle threatens to make malware attacks easier for crooks

CRYPTOMINING & CRYPTOCURRENCIES

  1. Researchers found #Kraken #ransomware has become more popular after being packaged in the Fallout #ExploitKit and becoming part of an
  2. Kraken ransomware gets packaged into Fallout EK
  3. Blockwatch: The aeternity Blockchain
  4. Trading with cryptocurrencies without losing self control
  5. EY launches the world's first secure private transactions over the Ethereum public blockchain
  6. Another packed room for .@idefense analyst Mei Nelson discussing China and cryptocurrency. #codeblue_jp @AccentureSecure @AccentureJPNews

MALWARE

  1. Facebook Blames Malicious Extensions in Breach of 81K Private Messages
  2. ​The day computer security turned real: The Morris Worm turns 30
  3. Worst Malware and Threat Actors of 2018
  4. Adversaries Distribute Malware Via Rarely Used Extensions
  5. Can you spot a malicious email? Take the quiz at
  6. Antimalware Day: The evolution of malicious code
  7. Outlaw Hacking Group Using Command Injection Flow To Attack Organizations Network using Botnet via C&C Server
  8. Beware this malware: it can even survive operating systems being reinstalled
  9. Emotet Trojan Changes Tactics…Again
  10. Giant ransomware bundle threatens to make malware attacks easier for crooks
  11. If you think you have been hacked or got #malware installed, disconnect the internet, leave your device running and connected
  12. U.S. Geological Survey Network got Infected with Malware
  13. Search for “Installing Chrome” on Bing can lead to malicious content
  14. Previous malware attacks: When more than 7,5000 of the #Mikrotik routes were reportedly being spied on by attackers

EXPLOIT

  1. Kraken ransomware gets packaged into Fallout EK
  2. How to Perform Manual SQL Injection With Double quotes Error Based String Method
  3. Researchers recently found vulnerabilities in #robot controllers from @Universal_Robot. Learn what these robot controllers do and how #ThreatActors exploit these

VULNERABILITY

  1. Shellbot Variant Used in New Botnet, Spreads Using IoT and Linux Vulnerabilities
  2. Cisco Security Appliance Zero-Day Found Actively Exploited in the Wild
  3. BLEEDINGBIT – Two Zero Day Vulnerabilities Affecting Wireless Access Point Bluetooth Chips
  4. Hackers actively exploiting vulnerabilities in Cisco security appliances
  5. Cisco fixed the high-risk security vulnerabilities in variant products
  6. Bluetooth Bugs Speak to Lack of Security in DevOps
  7. Sauter Quickly Patches Flaw in Building Automation Software
  8. Bleedingbit vulnerabilities put Wi-Fi access points at risk
  9. Test IO introduces Bug Fix Confirmation, leveraging network of software testers to verify bug fixes
  10. Flaw in Sophos HitmanPro.Alert could enable hackers to gain privileges over systems
  11. Intel CPUs impacted by new PortSmash side-channel vulnerability
  12. CISCO warn of a zero-day DoS flaw that is being actively exploited in attacks
  13. Systemd Vulnerability In Linux Could Trigger Remote Attacks And System Crashes
  14. .@ArmisSecurity researchers discovered two chip-level #Bluetooth vulnerabilities -- dubbed #Bleedingbit -- that could allow pseudo #RemoteCodeExecution on wireless access points.
  15. Cisco Reports SIP Inspection Vulnerability
  16. Mozilla exorcises five bugs on Halloween
  17. Researchers recently found vulnerabilities in #robot controllers from @Universal_Robot. Learn what these robot controllers do and how #ThreatActors exploit these
  18. BLEEDINGBIT – Two Bluetooth Chip-level Vulnerabilities Affected Millions of Enterprise Wi-Fi Access Point Devices
  19. GNOME 3.30.2 released: bugs fix
  20. Attackers Use Zero-Day That Can Restart Cisco Security Appliances

Region brief for 2018-11-02

ASIA

  1. Shellbot Variant Used in New Botnet, Spreads Using IoT and Linux Vulnerabilities
  2. Stuxnet Returns, Striking Iran with New Variant
  3. This Week in Security News: Spam Campaigns and Vulnerable Infrastructures
  4. Outlaw Hacking Group Using Command Injection Flow To Attack Organizations Network using Botnet via C&C Server
  5. BCMUPnP_Hunter: 100,000-node botnet is abusing routers for spam
  6. Iran has become victim of a cyberattack campaign
  7. Another packed room for .@idefense analyst Mei Nelson discussing China and cryptocurrency. #codeblue_jp @AccentureSecure @AccentureJPNews

OCEANIA

Nil

NORTH AMERICA

  1. Joshua Adam Schulte, ex CIA employee, accused of continuing leaks from prison
  2. New Data Affirms Cyber Threat for Industrial Control Systems
  3. #SamSam #ransomware continues to be a thorn in the side of organizations in the U.S. with targeted ransomware campaigns continuing,
  4. 85 Millions of voter records available for sale ahead of the 2018 US Midterm Elections
  5. SMS Phishing + Cardless ATM = Profit
  6. Stuxnet Returns, Striking Iran with New Variant
  7. Bluetooth Bugs Speak to Lack of Security in DevOps
  8. This Week in Security News: Spam Campaigns and Vulnerable Infrastructures
  9. Russian hackers compromise 120 million Facebook accounts; private messages on sale online
  10. SamSam ransomware campaigns continue to target U.S. in 2018
  11. BCMUPnP_Hunter: 100,000-node botnet is abusing routers for spam
  12. Multiple #phishing pages on multiple domains targeting Canadian citizens posing as Canadian Revenue Agency, Interac, and others 192.99.86.132 (@OVH) cc: @cybercentre_ca
  13. U.S. Geological Survey Network got Infected with Malware
  14. 85 million voter records on sale
  15. Iran has become victim of a cyberattack campaign
  16. EY launches the world's first secure private transactions over the Ethereum public blockchain

SOUTH AMERICA

  1. Russian hackers compromise 120 million Facebook accounts; private messages on sale online

EUROPE

  1. Shellbot Variant Used in New Botnet, Spreads Using IoT and Linux Vulnerabilities
  2. Magecart cybergang targeting e-commerce credit card data
  3. 120 Million Facebook Accounts Compromised, Private Messages of 81,000 for Sale
  4. Stuxnet Returns, Striking Iran with New Variant
  5. Sauter Quickly Patches Flaw in Building Automation Software
  6. This Week in Security News: Spam Campaigns and Vulnerable Infrastructures
  7. Russian hackers compromise 120 million Facebook accounts; private messages on sale online
  8. Beware this malware: it can even survive operating systems being reinstalled
  9. Magecart claims fresh victim in electronics kit seller Kitronik
  10. Iran has become victim of a cyberattack campaign
  11. EY launches the world's first secure private transactions over the Ethereum public blockchain

AFRICA

Nil