Sep 15, 2018

Daily brief for 2018-09-14

Asia

  1. China-linked APT10 Hackers Update Attack Techniques
  2. Well-known Middle Eastern hacking group keeps updating its arsenal
  3. Iran-Linked OilRig APT group targets high-ranking office in a Middle Eastern nation
  4. Illegal Patch Allows Easier Access to India's Aadhaar Biometric Database
  5. Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents
  6. N. Korea Calls Sony, Wannacry Hack Charges Smear Campaign
  7. North Korean hacker officially charged for the WannaCry attacks

World

  1. Evaluating the Threatscape One Year After NotPetya Ransomware Attack
  2. Security news: More phishing, Canada pays ransom, SMBs are a target | Avast
  3. Well-known Middle Eastern hacking group keeps updating its arsenal
  4. Iran-Linked OilRig APT group targets high-ranking office in a Middle Eastern nation
  5. Military, Government Users Just as Bad About Password Hygiene as Civilians
  6. Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents
  7. N. Korea Calls Sony, Wannacry Hack Charges Smear Campaign
  8. Major US mobile carriers want to be your password
  9. Russian man accused of running Kelihos botnet pleads guilty
  10. North Korean hacker officially charged for the WannaCry attacks
  11. Law firm begins legal action for data theft in British Airways
  12. Malware-as-a-Service – New Black Rose Lucy Malware Targets Android Devices With a Special Logic for Xiaomi Phones

Attacks

  1. Jaxx Cryptocurrency wallet phishing campaign shut down
  2. Cryptojacking campaign targets add-ons for popular streaming app Kodi
  3. How to Protect Against Phishing Attacks that Follow Natural Disasters
  4. Survey: Nearly one-third of breached companies reported job losses after data breach
  5. Survey: Nearly one-third of breached companies reported job losses after data breach
  6. MEGA Chrome extension compromised to steal credentials and cryptocurrency
  7. Security news: More phishing, Canada pays ransom, SMBs are a target | Avast
  8. Russians and Latvians in DOJ crosshairs for cybercrimes, including running the Kelihos botnet
  9. Data breaches affect stock performance in the long run, study finds
  10. Cobalt Gang phishing campaign targets Eastern Europeans with CobInt backdoor-downloader
  11. Military, Government Users Just as Bad About Password Hygiene as Civilians
  12. One-Third of Data Breaches Led to People Losing Jobs: Kaspersky
  13. DDoS attacks: Students blamed for many university cyber attacks
  14. Illegal Patch Allows Easier Access to India's Aadhaar Biometric Database
  15. N. Korea Calls Sony, Wannacry Hack Charges Smear Campaign
  16. Major US mobile carriers want to be your password
  17. Russian man accused of running Kelihos botnet pleads guilty
  18. Veeam Publicly Exposed 445 Million Customers Records Of its Marketing Database
  19. Cold Boot Attacks – Hackers Can Unlock All the Modern Computers and Steal Encryption Keys & Passwords
  20. Law firm begins legal action for data theft in British Airways

Threats

  1. Zerodium announced Tor vulnerability on Twitter -announced-tor-vulnerability-on-twitter/ …
  2. FragmentSmack vulnerability also affects Windows, but Microsoft patched it
  3. Google’s desktop update for Chrome squashes two bugs
  4. The Week in Ransomware - September 14th 2018 - Kraken, Dharma, & Matrix
  5. Evaluating the Threatscape One Year After NotPetya Ransomware Attack
  6. Colorado firm claims ransomware attack behind closure
  7. Uptick in malware designed to size up targets before launching full payload
  8. Fallout Exploit Kit Pushing the SAVEfiles Ransomware
  9. Microsoft Office 365 Customers Get Protection Against Malicious Macros
  10. Canadian town bows to ransomware attack, will pay attackers
  11. From PoC to Pwned: New Exploits Appear in Attacks Just Days After Disclosure
  12. Kraken Cryptor Ransomware Masquerading as SuperAntiSpyware Security Program
  13. Cobalt Gang phishing campaign targets Eastern Europeans with CobInt backdoor-downloader
  14. Honolulu-based Fetal Diagnostic Institute of the Pacific hit with ransomware
  15. Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents
  16. Apple’s Safari and Microsoft’s Edge browsers contain spoofing bug
  17. Malware-as-a-Service – New Black Rose Lucy Malware Targets Android Devices With a Special Logic for Xiaomi Phones

Crime

  1. Cryptojacking campaign targets add-ons for popular streaming app Kodi
  2. How to Protect Against Phishing Attacks that Follow Natural Disasters
  3. Russian man accused of running Kelihos botnet pleads guilty
  4. Law firm begins legal action for data theft in British Airways

Politics

  1. Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents

Sep 14, 2018

Daily brief for 2018-09-13

Asia

  1. OilRig APT Continues Its Ongoing Malware Evolution
  2. APT10 Targeting Japanese Corporations Using Updated TTPs

World

  1. Russian man extradited to U.S. for ‘massive’ financial hacking campaign
  2. Bacloud: Russia’s New Misinformation Safe Haven
  3. Kelihos Botnet Operator Pleads Guilty in Federal Court
  4. Scareware scheme operator thrown behind bars for targeting US media
  5. Cobalt crime gang is using again CobInt malware in attacks on former soviet states
  6. Russian Hacker Pleads Guilty to Operating Kelihos Botnet
  7. Kelihos Botnet Author Pleads Guilty in U.S. Court
  8. New PyLocky Ransomware Attack on Various Organization that Encrypt More than 100 File Extensions
  9. Smashing Security : British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked

Attacks

  1. Russian man extradited to U.S. for ‘massive’ financial hacking campaign
  2. Sly malware author hides cryptomining botnet behind ever-shifting proxy service
  3. Park by Phone data breach affects 5000 customers
  4. Cobalt Gang phishing campaign targets Eastern Europeans with CobInt backdoor-downloader
  5. Cold-Boot Attack Steals Passwords In Under Two Minutes
  6. Security flaw can leak Intel ME encryption keys
  7. New Necurs Spam Campaign Targets Banks with Malicious .Wiz Files
  8. Veeam leaves MongoDB database wide open, exposes 445m records
  9. Kelihos Botnet Operator Pleads Guilty in Federal Court
  10. Kodi add-ons launch cryptomining campaign
  11. Jaxx wallet phishing campaign aimed to steal user cryptocurrency
  12. Kelihos botnet operator jailed for account theft, ID trading in the Dark Web
  13. Files With 42 Million Emails and Passwords Found On Free Hosting Service
  14. Raise of IoT Botnets Responsible for Massive DDoS Attacks – Q2 2018 Threat Report
  15. Russian Hacker Pleads Guilty to Operating Kelihos Botnet
  16. Kelihos Botnet Author Pleads Guilty in U.S. Court
  17. Mongo Lock: The attack that deletes MongoDB databases
  18. Mongo Lock: The attack that deletes MongoDB databases
  19. Smashing Security : British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked

Threats

  1. Domestic Kitten spyware targets ISIS supporters
  2. September Patch Tuesday: Adobe patches seven critical vulnerabilities
  3. Sly malware author hides cryptomining botnet behind ever-shifting proxy service
  4. Apple store apps are not all safe: Malwarebytes, Tripwire
  5. Uptick in malware designed to size up targets before launching full payload
  6. Honolulu-based Fetal Diagnostic Institute of the Pacific hit with ransomware
  7. Cobalt Gang phishing campaign targets Eastern Europeans with CobInt backdoor-downloader
  8. Apple’s Safari and Microsoft’s Edge browsers contain spoofing bug
  9. OilRig APT Continues Its Ongoing Malware Evolution
  10. Apache Struts exploit found in Mirai variant may signify shift in attack strategy
  11. Flaws in firmware expose almost any modern PC to Cold Boot Attacks
  12. ThreatList: Microsoft Macros Remain Top Vector for Malware Delivery
  13. Security flaw can leak Intel ME encryption keys
  14. How to Perform Manual SQL Injection With Integer Based Method
  15. [SingCERT] Alert on Critical Microsoft Vulnerabilities CVE-2018-8440, CVE-2018-8475, CVE-2018-0965, CVE-2018-8439 & CVE-2018-8449
  16. 2 Billion Bluetooth Devices Remain Exposed to Airborne Attack Vulnerabilities
  17. Really old computer viruses are still infecting new machines
  18. New Necurs Spam Campaign Targets Banks with Malicious .Wiz Files
  19. ICS CERT warns of several flaws in Fuji Electric V-Server
  20. Two billion devices still vulnerable to Blueborne flaws a year after discovery
  21. Prison for man who assisted scareware scheme that targeted newspaper website
  22. Microsoft Office Macros: Still Your Leader in Malware Delivery
  23. Windows and Linux Kodi users infected with cryptomining malware
  24. Kodi add-ons launch cryptomining campaign
  25. Ransomware attack shuts down small Canadian town; officials pay ransom
  26. New Firmware Flaws Resurrect Cold Boot Attacks
  27. New Gartner Report Recommends a Vulnerability Management Process Based on Weaponization and Asset Value
  28. Kernel exploit discovered in macOS Webroot SecureAnywhere antivirus software
  29. Malicious Kodi Add-ons Install Windows & Linux Coin Mining Trojans
  30. Scareware scheme operator thrown behind bars for targeting US media
  31. Cobalt crime gang is using again CobInt malware in attacks on former soviet states
  32. New PyLocky Ransomware stands out for anti-machine learning capability
  33. New PyLocky Ransomware Attack on Various Organization that Encrypt More than 100 File Extensions
  34. Smashing Security : British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked

Crime

  1. Sly malware author hides cryptomining botnet behind ever-shifting proxy service
  2. Prison for man who assisted scareware scheme that targeted newspaper website
  3. Bacloud: Russia’s New Misinformation Safe Haven
  4. Windows and Linux Kodi users infected with cryptomining malware
  5. Kelihos Botnet Operator Pleads Guilty in Federal Court
  6. Kodi add-ons launch cryptomining campaign
  7. Ransomware attack shuts down small Canadian town; officials pay ransom
  8. New Gartner Report Recommends a Vulnerability Management Process Based on Weaponization and Asset Value
  9. Kelihos botnet operator jailed for account theft, ID trading in the Dark Web
  10. Files With 42 Million Emails and Passwords Found On Free Hosting Service
  11. Scareware scheme operator thrown behind bars for targeting US media
  12. Cobalt crime gang is using again CobInt malware in attacks on former soviet states
  13. Russian Hacker Pleads Guilty to Operating Kelihos Botnet
  14. Kelihos Botnet Author Pleads Guilty in U.S. Court

Politics

  1. APT10 Targeting Japanese Corporations Using Updated TTPs
  2. Bacloud: Russia’s New Misinformation Safe Haven

Sep 13, 2018

Daily brief for 2018-09-12

Asia

  1. WTB: Apple Removes Top Security Tool for Secretly Stealing Data

World

  1. Multi-Stage Malware Heavily Used in Recent Cobalt Attacks
  2. Latvian hacker sentenced to 33 months in prison for scareware scheme
  3. Russian hacker pleads guilty for role in massive botnet schemes
  4. Modular Malware Brings Stealthy Attacks to Former Soviet States
  5. Data breach — 380,000 British Airways transactions compromised | Avast
  6. Researchers implicate online card-skimming group in British Airways hack
  7. British Airways reveals details about data breach

Attacks

  1. OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government
  2. Russian hacker pleads guilty for role in massive botnet schemes
  3. Jaxx Cryptocurrency wallet phishing campaign shut down
  4. Modular Malware Brings Stealthy Attacks to Former Soviet States
  5. Data breach — 380,000 British Airways transactions compromised | Avast
  6. Veeam Leaks 200 GB Customer Database, Goldmine for Phishers
  7. Park by Phone data breach affects 5000 customers
  8. Feeling the Pulse of Cyber Security in Healthcare
  9. Phishing warning: One in every one hundred emails is now a hacking attempt
  10. Cybercriminals Go Phishing For Jaxx Wallet Users
  11. Dramatic Increase of DDoS Attack Sizes Attributed to IoT Devices
  12. Data management firm Veeam mismanages own data, leaks 445m records
  13. Crooks Combine Phishing and Impersonation For Higher Success Rate
  14. Beware! Unpatched Safari Browser Hack Lets Attackers Spoof URLs
  15. British Airways reveals details about data breach

Threats

  1. Multi-Stage Malware Heavily Used in Recent Cobalt Attacks
  2. OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government
  3. Latvian hacker sentenced to 33 months in prison for scareware scheme
  4. Canadian town bows to ransomware attack, will pay attackers
  5. Russian hacker pleads guilty for role in massive botnet schemes
  6. PowerShell Obfuscation Ups the Ante on Antivirus
  7. New Python-based Ransomware Poses as Locky
  8. Modular Malware Brings Stealthy Attacks to Former Soviet States
  9. Uproar after Adobe winds down Magento rewards-based bug bounty program
  10. Malware Campaign Targeting Jaxx Wallet Holders Shut Down
  11. Osiris Banking Trojan Displays Modern Malware Innovation
  12. September Patch Tuesday: Adobe patches seven critical vulnerabilities
  13. Office VBA + AMSI: Parting the veil on malicious macros
  14. A question of security: What is obfuscation and how does it work?
  15. Feedify becomes latest victim of the Magecart malware campaign
  16. Flaws Found in Fuji Electric Tool That Links Corporate PCs to ICS
  17. Researchers implicate online card-skimming group in British Airways hack
  18. Veeam Leaks 200 GB Customer Database, Goldmine for Phishers
  19. September 2018 Security Notes address a total of 14 flaws in SAP products
  20. Domestic Kitten spyware targets ISIS supporters
  21. Six Critical Vulnerabilities in Adobe ColdFusion Get Patches
  22. Microsoft purges 3,000 tech support scams hiding on TechNet
  23. Faster Prod at the Expense of Security? 2018 ‘Under the Hoodie’ Reveals Gaps in Applications
  24. Feedify Hacked with Magecart Information Stealing Script
  25. Cybercriminals Go Phishing For Jaxx Wallet Users
  26. Adobe patch update tackles six critical vulnerabilities in ColdFusion
  27. Crooks Combine Phishing and Impersonation For Higher Success Rate
  28. Microsoft Patch Tuesday updates for September 2018 also address recently disclosed Windows zero-day
  29. September Patch Tuesday: Windows Fixes ALPC Elevation of Privilege, Remote Code Execution Vulnerabilities
  30. Address Bar Spoofing Flaw Found in Edge, Safari
  31. Beware! Unpatched Safari Browser Hack Lets Attackers Spoof URLs
  32. Microsoft Released Security Updates with the Patch for Recent Windows Zero-day Flow

Crime

  1. Russian hacker pleads guilty for role in massive botnet schemes
  2. Osiris Banking Trojan Displays Modern Malware Innovation
  3. Data breach — 380,000 British Airways transactions compromised | Avast
  4. Researchers implicate online card-skimming group in British Airways hack
  5. Veeam Leaks 200 GB Customer Database, Goldmine for Phishers
  6. Feedify Hacked with Magecart Information Stealing Script
  7. WTB: Apple Removes Top Security Tool for Secretly Stealing Data
  8. British Airways reveals details about data breach

Politics

  1. Nothing to report

Sep 10, 2018

Daily brief for 2018-09-09

Asia

  1. Domestic Kitten – An Iranian surveillance operation under the radar since 2016

World

  1. Nothing to report

Attacks

  1. Nothing to report

Threats

  1. Nothing to report

Crime

  1. Nothing to report

Politics

  1. Nothing to report