Sep 28, 2018

APT report for 2018-09-27

TRANSNATIONAL / UNKNOWN

  1. Threat-group Magecart - More Victims
  2. Europol Highlights Continued Threats, but Magecart Demands Focus on Web Security

CHINA

  1. APT10 Targeting Japanese Corporations Using Updated TTPs

INDIA

Nothing to report

NORTH KOREA

Nothing to report

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. APT Group Uses Dangerous LoJax Malware That Can Survive After OS Re-installation and Hard Disk Replacement
  2. Russians' stealthy 'LoJax' malware can infect on the firmware level
  3. Seven additional modules make Fancy Bear’s VPNFilter malware even more versatile
  4. Russian Cyberspies Use UEFI Rootkit in Attacks
  5. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  6. LoJax: First-ever UEFI rootkit detected in a cyberattack
  7. Cybersecurity Researchers Spotted First-Ever UEFI Rootkit in the Wild
  8. Fancy Bear LoJax campaign reveals first documented use of UEFI rootkit in the wild
  9. Seven additional modules make Fancy Bear's VPNFilter malware even more versatile
  10. APT28 Uses LoJax, First UEFI Rootkit Seen in the Wild
  11. VPNFilter Router Malware Adds 7 New Network Exploitation Modules
  12. “Disturbing plans” in China revealed by a former Google employee

UKRAINE

Nothing to report

Platform report for 2018-09-27

WINDOWS

  1. The PowerShell Boogeyman: How to Defend Against Malicious PowerShell Attacks
  2. Out of sight but not invisible: Defeating fileless malware with behavior monitoring, AMSI, and next-gen AV
  3. Is There Such a Thing as a Malicious PowerShell Command?

LINUX

  1. Local-Privilege Escalation Flaw in Linux Kernel Allows Root Access
  2. Cisco unearths 13 'High Impact' IOS vulnerabilities you need to patch now
  3. Mutagen Astronomy Linux Kernel vulnerability affects Red Hat, CentOS, and Debian distros

UNIX

Nothing to report

ANDROID

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Android password managers not as secure as desktop counterparts
  3. Hide and seek Iot botnet updates include new Android ADB exploit
  4. Hide and seek Iot botnet updates include new Android ADB exploit

IOS

  1. Cisco unearths 13 'High Impact' IOS vulnerabilities you need to patch now

MACOS

  1. ex-NSA Hacker Discloses macOS Mojave 10.14 Zero-Day Vulnerability

Threat report for 2018-09-27

DATA BREACH

  1. Twitter Bug May Have Exposed Millions of DMs
  2. GDPR: Data Breach Class Action Lawsuits Come to Europe
  3. Fancy Bear LoJax campaign reveals first documented use of UEFI rootkit in the wild
  4. SheIn Data Breach Exposed Personal Details 6.4 Million Customers To Hackers
  5. United Nations data found exposed on web: researcher
  6. New GootKit Campaigns Target European Banks with Reconnaissance Attacks
  7. Uber to Pay $148 Million as a Settlement for Data Breach Cover
  8. Uber fined $148m for data breach cover-up
  9. You should prepare for the next mega data breach
  10. Uber agrees to pay $148 million in massive 2016 data breach settlement
  11. Endace launches petabyte network recording appliance

DENIAL-OF-SERVICE

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Hide and seek Iot botnet updates include new Android ADB exploit
  3. New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai
  4. DDoS attack on education vendor hinders access to districts’ online portals
  5. New Torii Botnet uncovered, more sophisticated than Mirai | Avast
  6. Hide and seek Iot botnet updates include new Android ADB exploit
  7. New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai

MALVERTISING

Nothing to report

PHISHING

  1. Android password managers not as secure as desktop counterparts
  2. Boffins bypass password protection with pilfering by phony programs
  3. Are long passphrases the answer to password problems?
  4. Chrome 70 will resolve cookies and login privacy issues

WEB DEFACEMENT

Nothing to report

MALWARE

  1. APT Group Uses Dangerous LoJax Malware That Can Survive After OS Re-installation and Hard Disk Replacement
  2. Russians' stealthy 'LoJax' malware can infect on the firmware level
  3. CCSP Exam Details and Process
  4. CCSP: Overview of Domains
  5. Ransomware Attack Hits Port of San Diego
  6. The PowerShell Boogeyman: How to Defend Against Malicious PowerShell Attacks
  7. Chronicle Unveils VirusTotal Enterprise
  8. Crooks turn to Delphi packers to evade malware detection
  9. Chronicle announces VirusTotal Enterprise with greater search and analysis capabilities
  10. Out of sight but not invisible: Defeating fileless malware with behavior monitoring, AMSI, and next-gen AV
  11. Alphabet launches VirusTotal Enterprise
  12. Is There Such a Thing as a Malicious PowerShell Command?
  13. New KONNI Malware attacking Eurasia and Southeast Asia
  14. New KONNI Malware attacking Eurasia and Southeast Asia
  15. Pirated Game of Thrones episodes most popular TV bait for malware
  16. Seven additional modules make Fancy Bear’s VPNFilter malware even more versatile
  17. Russian Cyberspies Use UEFI Rootkit in Attacks
  18. Dirhunt – Search and Analyze Target Domain Directories
  19. Port of San Diego Affected by a Ransomware Attack
  20. Phorpiex worm pivots to infect the enterprise with GandCrab ransomware
  21. Crooks turn to Delphi packers to evade malware detection
  22. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  23. LoJax: First-ever UEFI rootkit detected in a cyberattack
  24. DanaBot trojan sets sights on Europe, new features
  25. SC Media September Product Reviews: Threat Intelligence DomainTools Iris Investigation Platform l
  26. #Malware classifcation, which encompasses both the identification and attribution of code, has the power to unlock many clues that aid
  27. New VirusTotal Enterprise Offers Private Graphs, Faster Searches
  28. Alphabet's Chronicle Releases VirusTotal Enterprise
  29. Malware steals personal information from 6.4M SheIn customers
  30. Malware hits fashion giant SHEIN; 6.42 million online shoppers affected
  31. Cybersecurity Researchers Spotted First-Ever UEFI Rootkit in the Wild
  32. Emergence of new ransomware variants feature names of popular politicians
  33. Now that Office 365 has become one of Microsoft's fastest-growing revenue streams, it has become a primary target for #ransomware.
  34. Fancy Bear LoJax campaign reveals first documented use of UEFI rootkit in the wild
  35. Researchers find vulnerability in Apple's MDM DEP process
  36. Seven additional modules make Fancy Bear's VPNFilter malware even more versatile
  37. Cloudflare Becomes a Registrar, Sells Domains At Cost
  38. APT28 Uses LoJax, First UEFI Rootkit Seen in the Wild
  39. Alphabet's Chronicle Security Business Launches VirusTotal Enterprise
  40. VPNFilter Router Malware Adds 7 New Network Exploitation Modules
  41. Malware in the Cloud: What You Need to Know
  42. Discover how Tripwire Malware Detection... - Protects against zero-day exploits and other known threats. - Offers an enterprise view of suspicious malware objects across all monitored systems. - Protects from repeat #malware attacks. Learn more here:
  43. Malware in the Cloud: What You Need to Know

EXPLOIT

  1. Hide and seek Iot botnet updates include new Android ADB exploit
  2. Hide and seek Iot botnet updates include new Android ADB exploit
  3. VPNFilter Router Malware Adds 7 New Network Exploitation Modules
  4. Discover how Tripwire Malware Detection... - Protects against zero-day exploits and other known threats. - Offers an enterprise view of suspicious malware objects across all monitored systems. - Protects from repeat #malware attacks. Learn more here:

VULNERABILITY

  1. Local-Privilege Escalation Flaw in Linux Kernel Allows Root Access
  2. DEF CON report finds decade-old flaw in widely used ballot-counting machine
  3. Twitter fixes API bug that shared data with wrong developers
  4. How to Keep Up Security in a Bug-Infested World
  5. Twitter Bug May Have Exposed Millions of DMs
  6. Developers focus on wrong open source software vulnerabilities, research says
  7. Security Flaw Found in Apple Mobile Device Enrollment Program
  8. Cisco Releases Alerts for 14 High Severity Bugs
  9. Apple DEP vulnerability lets attackers access orgs’ resources, info
  10. Cisco unearths 13 'High Impact' IOS vulnerabilities you need to patch now
  11. How automakers are tackling connected vehicle vulnerability management
  12. Tripwire Patch Priority Index for September 2018
  13. Researchers find vulnerability in Apple's MDM DEP process
  14. GNOME 3.30.1 released: bugfixes
  15. Norwegian state discusses vulnerabilities with IT sector
  16. Mutagen Astronomy Linux Kernel vulnerability affects Red Hat, CentOS, and Debian distros
  17. KDE Plasma 5.12.7 LTS releases: fix bugs
  18. Discover how Tripwire Malware Detection... - Protects against zero-day exploits and other known threats. - Offers an enterprise view of suspicious malware objects across all monitored systems. - Protects from repeat #malware attacks. Learn more here:
  19. ex-NSA Hacker Discloses macOS Mojave 10.14 Zero-Day Vulnerability

Region brief for 2018-09-27

ASIA

  1. APT10 Targeting Japanese Corporations Using Updated TTPs
  2. New Torii Botnet uncovered, more sophisticated than Mirai | Avast
  3. “Disturbing plans” in China revealed by a former Google employee

OCEANIA

Nothing to report

NORTH AMERICA

  1. DEF CON report finds decade-old flaw in widely used ballot-counting machine
  2. GDPR: Data Breach Class Action Lawsuits Come to Europe
  3. SheIn Data Breach Exposed Personal Details 6.4 Million Customers To Hackers
  4. You should prepare for the next mega data breach
  5. Uber agrees to pay $148 million in massive 2016 data breach settlement
  6. “Disturbing plans” in China revealed by a former Google employee

SOUTH AMERICA

Nothing to report

EUROPE

  1. Russians' stealthy 'LoJax' malware can infect on the firmware level
  2. Russian Cyberspies Use UEFI Rootkit in Attacks
  3. Threat-group Magecart - More Victims
  4. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  5. Norwegian state discusses vulnerabilities with IT sector
  6. Seven additional modules make Fancy Bear's VPNFilter malware even more versatile
  7. VPNFilter Router Malware Adds 7 New Network Exploitation Modules

AFRICA

Nothing to report

Sector brief for 2018-09-27

HEALTHCARE

Nothing to report

TRANSPORT

Nothing to report

BANKING & FINANCE

  1. Threat-group Magecart - More Victims
  2. New GootKit Campaigns Target European Banks with Reconnaissance Attacks

INFORMATION & TELECOMMUNICATION

Nothing to report

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

Nothing to report

GOVERNMENT & PUBLIC SERVICE

  1. DEF CON report finds decade-old flaw in widely used ballot-counting machine

Daily brief for 2018-09-27

ASIA

  1. APT10 Targeting Japanese Corporations Using Updated TTPs
  2. New Torii Botnet uncovered, more sophisticated than Mirai | Avast
  3. “Disturbing plans” in China revealed by a former Google employee

WORLD

  1. Russians' stealthy 'LoJax' malware can infect on the firmware level
  2. DEF CON report finds decade-old flaw in widely used ballot-counting machine
  3. Russian Cyberspies Use UEFI Rootkit in Attacks
  4. Threat-group Magecart - More Victims
  5. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  6. GDPR: Data Breach Class Action Lawsuits Come to Europe
  7. SheIn Data Breach Exposed Personal Details 6.4 Million Customers To Hackers
  8. Norwegian state discusses vulnerabilities with IT sector
  9. Seven additional modules make Fancy Bear's VPNFilter malware even more versatile
  10. You should prepare for the next mega data breach
  11. Uber agrees to pay $148 million in massive 2016 data breach settlement
  12. VPNFilter Router Malware Adds 7 New Network Exploitation Modules
  13. “Disturbing plans” in China revealed by a former Google employee

ATTACKS

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Android password managers not as secure as desktop counterparts
  3. Hide and seek Iot botnet updates include new Android ADB exploit
  4. Twitter Bug May Have Exposed Millions of DMs
  5. New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai
  6. DDoS attack on education vendor hinders access to districts’ online portals
  7. Boffins bypass password protection with pilfering by phony programs
  8. GDPR: Data Breach Class Action Lawsuits Come to Europe
  9. Fancy Bear LoJax campaign reveals first documented use of UEFI rootkit in the wild
  10. New Torii Botnet uncovered, more sophisticated than Mirai | Avast
  11. SheIn Data Breach Exposed Personal Details 6.4 Million Customers To Hackers
  12. Hide and seek Iot botnet updates include new Android ADB exploit
  13. United Nations data found exposed on web: researcher
  14. New GootKit Campaigns Target European Banks with Reconnaissance Attacks
  15. Uber to Pay $148 Million as a Settlement for Data Breach Cover
  16. Uber fined $148m for data breach cover-up
  17. New "Torii" Botnet's Sophisticated Techniques Set It Apart From Mirai
  18. You should prepare for the next mega data breach
  19. Uber agrees to pay $148 million in massive 2016 data breach settlement
  20. Are long passphrases the answer to password problems?
  21. Chrome 70 will resolve cookies and login privacy issues
  22. Endace launches petabyte network recording appliance

THREATS

  1. APT Group Uses Dangerous LoJax Malware That Can Survive After OS Re-installation and Hard Disk Replacement
  2. Russians' stealthy 'LoJax' malware can infect on the firmware level
  3. CCSP Exam Details and Process
  4. CCSP: Overview of Domains
  5. Ransomware Attack Hits Port of San Diego
  6. The PowerShell Boogeyman: How to Defend Against Malicious PowerShell Attacks
  7. Chronicle Unveils VirusTotal Enterprise
  8. Crooks turn to Delphi packers to evade malware detection
  9. Chronicle announces VirusTotal Enterprise with greater search and analysis capabilities
  10. Out of sight but not invisible: Defeating fileless malware with behavior monitoring, AMSI, and next-gen AV
  11. Local-Privilege Escalation Flaw in Linux Kernel Allows Root Access
  12. Alphabet launches VirusTotal Enterprise
  13. DEF CON report finds decade-old flaw in widely used ballot-counting machine
  14. Twitter fixes API bug that shared data with wrong developers
  15. Is There Such a Thing as a Malicious PowerShell Command?
  16. New KONNI Malware attacking Eurasia and Southeast Asia
  17. New KONNI Malware attacking Eurasia and Southeast Asia
  18. How to Keep Up Security in a Bug-Infested World
  19. Pirated Game of Thrones episodes most popular TV bait for malware
  20. Seven additional modules make Fancy Bear’s VPNFilter malware even more versatile
  21. Hide and seek Iot botnet updates include new Android ADB exploit
  22. Twitter Bug May Have Exposed Millions of DMs
  23. Russian Cyberspies Use UEFI Rootkit in Attacks
  24. Dirhunt – Search and Analyze Target Domain Directories
  25. Port of San Diego Affected by a Ransomware Attack
  26. Developers focus on wrong open source software vulnerabilities, research says
  27. Phorpiex worm pivots to infect the enterprise with GandCrab ransomware
  28. Security Flaw Found in Apple Mobile Device Enrollment Program
  29. Crooks turn to Delphi packers to evade malware detection
  30. Russian Sednit APT used the first UEFI rootkit of ever in attacks in the wild
  31. LoJax: First-ever UEFI rootkit detected in a cyberattack
  32. DanaBot trojan sets sights on Europe, new features
  33. SC Media September Product Reviews: Threat Intelligence DomainTools Iris Investigation Platform l
  34. #Malware classifcation, which encompasses both the identification and attribution of code, has the power to unlock many clues that aid
  35. New VirusTotal Enterprise Offers Private Graphs, Faster Searches
  36. Alphabet's Chronicle Releases VirusTotal Enterprise
  37. Cisco Releases Alerts for 14 High Severity Bugs
  38. Apple DEP vulnerability lets attackers access orgs’ resources, info
  39. Cisco unearths 13 'High Impact' IOS vulnerabilities you need to patch now
  40. Malware steals personal information from 6.4M SheIn customers
  41. How automakers are tackling connected vehicle vulnerability management
  42. Malware hits fashion giant SHEIN; 6.42 million online shoppers affected
  43. Cybersecurity Researchers Spotted First-Ever UEFI Rootkit in the Wild
  44. Emergence of new ransomware variants feature names of popular politicians
  45. Now that Office 365 has become one of Microsoft's fastest-growing revenue streams, it has become a primary target for #ransomware.
  46. Fancy Bear LoJax campaign reveals first documented use of UEFI rootkit in the wild
  47. Tripwire Patch Priority Index for September 2018
  48. Researchers find vulnerability in Apple's MDM DEP process
  49. GNOME 3.30.1 released: bugfixes
  50. Norwegian state discusses vulnerabilities with IT sector
  51. Seven additional modules make Fancy Bear's VPNFilter malware even more versatile
  52. Hide and seek Iot botnet updates include new Android ADB exploit
  53. Cloudflare Becomes a Registrar, Sells Domains At Cost
  54. APT28 Uses LoJax, First UEFI Rootkit Seen in the Wild
  55. Mutagen Astronomy Linux Kernel vulnerability affects Red Hat, CentOS, and Debian distros
  56. Alphabet's Chronicle Security Business Launches VirusTotal Enterprise
  57. VPNFilter Router Malware Adds 7 New Network Exploitation Modules
  58. Malware in the Cloud: What You Need to Know
  59. KDE Plasma 5.12.7 LTS releases: fix bugs
  60. Discover how Tripwire Malware Detection... - Protects against zero-day exploits and other known threats. - Offers an enterprise view of suspicious malware objects across all monitored systems. - Protects from repeat #malware attacks. Learn more here:
  61. Malware in the Cloud: What You Need to Know
  62. ex-NSA Hacker Discloses macOS Mojave 10.14 Zero-Day Vulnerability

CRIME

  1. Russians' stealthy 'LoJax' malware can infect on the firmware level
  2. Threat-group Magecart - More Victims
  3. New GootKit Campaigns Target European Banks with Reconnaissance Attacks

POLITICS

  1. DEF CON report finds decade-old flaw in widely used ballot-counting machine
  2. Russian Cyberspies Use UEFI Rootkit in Attacks
  3. APT10 Targeting Japanese Corporations Using Updated TTPs
  4. APT28 Uses LoJax, First UEFI Rootkit Seen in the Wild

Sep 27, 2018

APT report for 2018-09-26

TRANSNATIONAL / UNKNOWN

  1. Source Defense raises $10 million for website supply chain solution
  2. Malware steals passwords from 6.4 million SHEIN customers
  3. Magecart Attacks Grow Rampant in September

CHINA

Nothing to report

INDIA

Nothing to report

NORTH KOREA

Nothing to report

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Windows 10 October 2018 Update is RTM: Clues Leads to Final Build 17763
  2. Will Microsoft release Windows 10 October Update on October 2?

UKRAINE

Nothing to report

Platform report for 2018-09-26

WINDOWS

  1. New Linux Kernel “Mutagen Astronomy” Flaw Impacts Red Hat, CentOS, Debian Distributions.
  2. Windows 10 October 2018 Update is RTM: Clues Leads to Final Build 17763
  3. Microsoft is killing passwords one announcement at a time
  4. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  5. Variant of patched IE vulnerability spotted in wild
  6. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  7. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software
  8. Crooks leverages Kodi Media Player add-ons for malware distribution
  9. Will Microsoft release Windows 10 October Update on October 2?

LINUX

  1. Vulnerability in Cisco routers could allow DoS attacks
  2. New Linux Kernel “Mutagen Astronomy” Flaw Impacts Red Hat, CentOS, Debian Distributions.
  3. Cisco: Linux kernel FragmentSmack bug now affects 88 of our products
  4. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  5. Linux Kernel Vulnerability Affects Red Hat, CentOS, Debian
  6. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software
  7. Crooks leverages Kodi Media Player add-ons for malware distribution
  8. New Linux Kernel Bug Affects Red Hat, CentOS, and Debian Distributions
  9. New security vulnerabilities (CVE-2018-14634) affects CentOS and Red Hat Linux

UNIX

Nothing to report

ANDROID

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Android password managers can be tricked into believing that evil apps are good
  3. Trojanized App In Google Play Steals Bank Customers' Euros
  4. Password managers can be tricked into believing that malicious Android apps are legitimate
  5. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  6. Android spyware in development plunders WhatsApp data, private conversations
  7. Hide and Seek Botnet Adds Infection Vector for Android Devices
  8. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  9. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script

IOS

  1. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability

MACOS

  1. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  2. Apple pushes out Mojave 10.14, patches numerous vulnerabilities
  3. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software

Threat report for 2018-09-26

DATA BREACH

  1. Uber Agrees to $148M Settlement With States Over Data Breach
  2. Uber to pay $148 million to states for 2016 data breach
  3. Firefox Notifies Users of Compromised Accounts
  4. Uber to pay $148 million in settlment over 2016 data breach and cover-up
  5. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  6. United Nations data found exposed on web: researcher
  7. United Nations data found exposed on web: researcher
  8. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  9. SHEIN Data Breach Impacts Over 6.4 Million Customers
  10. SMBs face costs of up to $2.5 million after a data breach
  11. United Nations data found exposed on web: researcher
  12. Millions of Twitter DMs may have been exposed by year-long bug
  13. Firefox Monitor tells you whether your email was compromised in a data breach
  14. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  15. United Nations Mistakenly Exposed Sensitive Data to The Public
  16. oPatch community released micro patches for Microsoft JET Database Zero-Day
  17. Malware campaign attacks freelancers

DENIAL-OF-SERVICE

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  3. Bad bots are stealing data and ruining the customer experience
  4. DDoS Attack on German Energy Company RWE
  5. DDoS Attack on German Energy Company RWE
  6. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  7. Vulnerability in Cisco routers could allow DoS attacks
  8. DDoS attack on education vendor hinders access to districts’ online portals
  9. Microsoft Adds New Tools to Azure DDoS Protection
  10. Viro Botnet Ransomware
  11. Infinite Campus DDoS attack impedes access to student data
  12. Hide and Seek Botnet Adds Infection Vector for Android Devices
  13. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  14. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability

MALVERTISING

Nothing to report

PHISHING

  1. Chegg to reset passwords for 40 million users after April 2018 hack
  2. Android password managers can be tricked into believing that evil apps are good
  3. User login notifications
  4. Beware of payroll-themed phishing. Here’s one example.
  5. SHEIN breach exposes emails, encrypted passwords of 6.42M customers
  6. Counter Phishing Attacks with These Five Tricks
  7. Password managers can be tricked into believing that malicious Android apps are legitimate
  8. Cisco patches critical default password vulnerability
  9. 11:30 AM ET today: @AlexanderGTster and @illena_a from @SCmagazine share the scoop on #spearphishing and how you can go beyond the obvious defenses to protect users from email attacks.
  10. Password Tips from a Pen Tester: Are 12-Character Passwords Really Stronger, or Just a Dime a Dozen?
  11. #SecurityNews: Popular news aggregation site #NewsNow has been notifying its users of a potential password #breach after it found evidence of an #intrusion. Read more about this #databreach here:
  12. Looking for a enterprise grade password vault solution but MUST be hosted onsite
  13. #SecurityNews: New #Ofcom rules "could help tackle #vishing" (voice #phishing) scams. They come into force on Oct 1st and will ban phone companies for charging for the Caller ID service that helps users screen their calls. Read more abut this here:
  14. 156 million #phishing emails are sent out every day and email users receive up to 20 phishing emails each month. Learn more about modern phishing techniques and how to address them in the @ironscales #whitepaper.
  15. Microsoft is killing passwords one announcement at a time
  16. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  17. NewsNow Ditches Passwords After Possible Breach
  18. Malware steals passwords from SHEIN, 6.4 million customers impacted
  19. Malware steals passwords from 6.4 million SHEIN customers
  20. Backlash sees change in Chrome login and Google account behaviour
  21. Chrome 70 Lets you Control Automatic Login and Deletes Google Cookies

WEB DEFACEMENT

Nothing to report

MALWARE

  1. Cisco's probe of VPNFilter router malware uncovers several new hacking techniques
  2. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  3. Fraudulent shopping domain certificate issuance outstrips legitimate businesses
  4. Businesses in Arkansas Hit with Ransomware
  5. Malware in the Cloud: What You Need to Know
  6. Businesses in Arkansas Hit with Ransomware
  7. Air Gapped PCs are Still at Risk. The Rise of USB-based Crytojacking Malware
  8. Crooks turn to Delphi packers to evade malware detection
  9. USB malware and cryptominers are threat to emerging markets
  10. DanaBot trojan sets sights on Europe, new features
  11. Trojanized App In Google Play Steals Bank Customers' Euros
  12. Password managers can be tricked into believing that malicious Android apps are legitimate
  13. Crooks turn to Delphi packers to evade malware detection
  14. Viro Botnet Ransomware
  15. Freelancers baited with job offers to download malicious macros
  16. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  17. Domain flub leaves 30 million customers high and dry
  18. USB malware and cryptominers are threat to emerging markets
  19. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  20. Android spyware in development plunders WhatsApp data, private conversations
  21. The MITRE ATT&CK Framework: Exfiltration
  22. Malware steals passwords from SHEIN, 6.4 million customers impacted
  23. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  24. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software
  25. Malware steals passwords from 6.4 million SHEIN customers
  26. Crooks leverages Kodi Media Player add-ons for malware distribution
  27. Malware in the Cloud: What You Need to Know
  28. Cryptocurrency mining malware increases 86%
  29. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script
  30. Malware campaign attacks freelancers
  31. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit

EXPLOIT

  1. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  2. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  3. Rockwell Automation Buffer Overflow Vulnerability
  4. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  5. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit

VULNERABILITY

  1. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  2. Vulnerability in Cisco routers could allow DoS attacks
  3. Cisco patches critical default password vulnerability
  4. New Linux Kernel “Mutagen Astronomy” Flaw Impacts Red Hat, CentOS, Debian Distributions.
  5. Twitter fixes API bug that shared data with wrong developers
  6. Cisco: Linux kernel FragmentSmack bug now affects 88 of our products
  7. Bug? Feature? Power users baffled as BitLocker update switch-off continues
  8. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  9. Linux Kernel Vulnerability Affects Red Hat, CentOS, Debian
  10. Millions of Twitter DMs may have been exposed by year-long bug
  11. Apple pushes out Mojave 10.14, patches numerous vulnerabilities
  12. Variant of patched IE vulnerability spotted in wild
  13. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  14. Rockwell Automation Buffer Overflow Vulnerability
  15. Crowdfense launches Vulnerability Research Hub for top security researchers
  16. oPatch community released micro patches for Microsoft JET Database Zero-Day
  17. New Linux Kernel Bug Affects Red Hat, CentOS, and Debian Distributions
  18. Vulnerability affects Cisco Video Surveillance Manager
  19. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  20. Snyk raises $22 million to address security vulnerabilities in open source code
  21. New security vulnerabilities (CVE-2018-14634) affects CentOS and Red Hat Linux
  22. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability

Region brief for 2018-09-26

ASIA

  1. Source Defense raises $10 million for website supply chain solution
  2. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  3. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  4. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC

OCEANIA

Nothing to report

NORTH AMERICA

  1. Uber to pay $148 million to states for 2016 data breach
  2. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  3. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  4. Viro Botnet Ransomware
  5. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  6. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  7. Rockwell Automation Buffer Overflow Vulnerability
  8. Snyk raises $22 million to address security vulnerabilities in open source code

SOUTH AMERICA

Nothing to report

EUROPE

  1. DDoS Attack on German Energy Company RWE
  2. DDoS Attack on German Energy Company RWE
  3. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  4. Source Defense raises $10 million for website supply chain solution
  5. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  6. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  7. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  8. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  9. Snyk raises $22 million to address security vulnerabilities in open source code

AFRICA

Nothing to report

Sector brief for 2018-09-26

HEALTHCARE

Nothing to report

TRANSPORT

Nothing to report

BANKING & FINANCE

  1. Chegg to reset passwords for 40 million users after April 2018 hack
  2. Beware of payroll-themed phishing. Here’s one example.
  3. Source Defense raises $10 million for website supply chain solution
  4. Trojanized App In Google Play Steals Bank Customers' Euros
  5. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  6. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  7. Magecart Attacks Grow Rampant in September

INFORMATION & TELECOMMUNICATION

Nothing to report

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

  1. DDoS Attack on German Energy Company RWE
  2. DDoS Attack on German Energy Company RWE
  3. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script

GOVERNMENT & PUBLIC SERVICE

  1. Beware of payroll-themed phishing. Here’s one example.

Daily brief for 2018-09-26

ASIA

  1. Source Defense raises $10 million for website supply chain solution
  2. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  3. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  4. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC

WORLD

  1. DDoS Attack on German Energy Company RWE
  2. DDoS Attack on German Energy Company RWE
  3. Uber to pay $148 million to states for 2016 data breach
  4. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  5. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  6. Source Defense raises $10 million for website supply chain solution
  7. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  8. Viro Botnet Ransomware
  9. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  10. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  11. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  12. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  13. Rockwell Automation Buffer Overflow Vulnerability
  14. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  15. Snyk raises $22 million to address security vulnerabilities in open source code

ATTACKS

  1. Hide and Seek (HNS) IoT Botnet targets Android devices with ADB option enabled
  2. Uber Agrees to $148M Settlement With States Over Data Breach
  3. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  4. Chegg to reset passwords for 40 million users after April 2018 hack
  5. Bad bots are stealing data and ruining the customer experience
  6. DDoS Attack on German Energy Company RWE
  7. DDoS Attack on German Energy Company RWE
  8. Uber to pay $148 million to states for 2016 data breach
  9. Android password managers can be tricked into believing that evil apps are good
  10. User login notifications
  11. Firefox Notifies Users of Compromised Accounts
  12. Uber to pay $148 million in settlment over 2016 data breach and cover-up
  13. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  14. Beware of payroll-themed phishing. Here’s one example.
  15. Bots at the Gate: A Human Rights Analysis of Automated Decision Making in Canada’s Immigration and Refugee System
  16. United Nations data found exposed on web: researcher
  17. SHEIN breach exposes emails, encrypted passwords of 6.42M customers
  18. United Nations data found exposed on web: researcher
  19. Counter Phishing Attacks with These Five Tricks
  20. Vulnerability in Cisco routers could allow DoS attacks
  21. Password managers can be tricked into believing that malicious Android apps are legitimate
  22. Cisco patches critical default password vulnerability
  23. 11:30 AM ET today: @AlexanderGTster and @illena_a from @SCmagazine share the scoop on #spearphishing and how you can go beyond the obvious defenses to protect users from email attacks.
  24. DDoS attack on education vendor hinders access to districts’ online portals
  25. Microsoft Adds New Tools to Azure DDoS Protection
  26. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  27. Password Tips from a Pen Tester: Are 12-Character Passwords Really Stronger, or Just a Dime a Dozen?
  28. #SecurityNews: Popular news aggregation site #NewsNow has been notifying its users of a potential password #breach after it found evidence of an #intrusion. Read more about this #databreach here:
  29. SHEIN Data Breach Impacts Over 6.4 Million Customers
  30. Viro Botnet Ransomware
  31. Looking for a enterprise grade password vault solution but MUST be hosted onsite
  32. #SecurityNews: New #Ofcom rules "could help tackle #vishing" (voice #phishing) scams. They come into force on Oct 1st and will ban phone companies for charging for the Caller ID service that helps users screen their calls. Read more abut this here:
  33. SMBs face costs of up to $2.5 million after a data breach
  34. 156 million #phishing emails are sent out every day and email users receive up to 20 phishing emails each month. Learn more about modern phishing techniques and how to address them in the @ironscales #whitepaper.
  35. Microsoft is killing passwords one announcement at a time
  36. United Nations data found exposed on web: researcher
  37. Aggregate this: NewsNow has spilt a bunch of 'encrypted' passwords
  38. Millions of Twitter DMs may have been exposed by year-long bug
  39. NewsNow Ditches Passwords After Possible Breach
  40. Firefox Monitor tells you whether your email was compromised in a data breach
  41. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  42. Malware steals passwords from SHEIN, 6.4 million customers impacted
  43. Infinite Campus DDoS attack impedes access to student data
  44. Hide and Seek Botnet Adds Infection Vector for Android Devices
  45. United Nations Mistakenly Exposed Sensitive Data to The Public
  46. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  47. Malware steals passwords from 6.4 million SHEIN customers
  48. Backlash sees change in Chrome login and Google account behaviour
  49. oPatch community released micro patches for Microsoft JET Database Zero-Day
  50. Malware campaign attacks freelancers
  51. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  52. Chrome 70 Lets you Control Automatic Login and Deletes Google Cookies

THREATS

  1. Cisco's probe of VPNFilter router malware uncovers several new hacking techniques
  2. VPNFilter Malware Adds Seven New Tools For Exploiting Network Devices
  3. Fraudulent shopping domain certificate issuance outstrips legitimate businesses
  4. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  5. Businesses in Arkansas Hit with Ransomware
  6. Malware in the Cloud: What You Need to Know
  7. Businesses in Arkansas Hit with Ransomware
  8. Air Gapped PCs are Still at Risk. The Rise of USB-based Crytojacking Malware
  9. Crooks turn to Delphi packers to evade malware detection
  10. USB malware and cryptominers are threat to emerging markets
  11. DanaBot trojan sets sights on Europe, new features
  12. Trojanized App In Google Play Steals Bank Customers' Euros
  13. Vulnerability in Cisco routers could allow DoS attacks
  14. Password managers can be tricked into believing that malicious Android apps are legitimate
  15. Cisco patches critical default password vulnerability
  16. New Linux Kernel “Mutagen Astronomy” Flaw Impacts Red Hat, CentOS, Debian Distributions.
  17. Crooks turn to Delphi packers to evade malware detection
  18. Twitter fixes API bug that shared data with wrong developers
  19. Viro Botnet Ransomware
  20. Freelancers baited with job offers to download malicious macros
  21. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  22. Domain flub leaves 30 million customers high and dry
  23. Cisco: Linux kernel FragmentSmack bug now affects 88 of our products
  24. USB malware and cryptominers are threat to emerging markets
  25. Bug? Feature? Power users baffled as BitLocker update switch-off continues
  26. NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits
  27. Braking bad: Mitsubishi recalls 68k SUVs over buggy software
  28. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  29. Linux Kernel Vulnerability Affects Red Hat, CentOS, Debian
  30. Millions of Twitter DMs may have been exposed by year-long bug
  31. Apple pushes out Mojave 10.14, patches numerous vulnerabilities
  32. Android spyware in development plunders WhatsApp data, private conversations
  33. Variant of patched IE vulnerability spotted in wild
  34. Alert: A remote code execution vulnerability is discovered in Microsoft Windows Jet database engine
  35. The MITRE ATT&CK Framework: Exfiltration
  36. Malware steals passwords from SHEIN, 6.4 million customers impacted
  37. Rockwell Automation Buffer Overflow Vulnerability
  38. Hide and Seek IoT Botnet Learns New Tricks: Uses ADB over Internet to Exploit Thousands of Android Devices
  39. VPNFilter III: More Tools for the Swiss Army Knife of Malware
  40. New Adwind RAT Attack Linux, Windows and Mac via DDE Code Injection Technique by Evading Antivirus Software
  41. Malware steals passwords from 6.4 million SHEIN customers
  42. Crooks leverages Kodi Media Player add-ons for malware distribution
  43. Malware in the Cloud: What You Need to Know
  44. Crowdfense launches Vulnerability Research Hub for top security researchers
  45. oPatch community released micro patches for Microsoft JET Database Zero-Day
  46. Cryptocurrency mining malware increases 86%
  47. New Linux Kernel Bug Affects Red Hat, CentOS, and Debian Distributions
  48. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script
  49. Vulnerability affects Cisco Video Surveillance Manager
  50. Malware campaign attacks freelancers
  51. GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit
  52. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  53. Snyk raises $22 million to address security vulnerabilities in open source code
  54. New security vulnerabilities (CVE-2018-14634) affects CentOS and Red Hat Linux
  55. CVE-2018-0150: Cisco IOS XE Software Static Credential Vulnerability

CRIME

  1. Bitcoin Core Team fixes a critical DDoS flaw in wallet software
  2. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  3. Source Defense raises $10 million for website supply chain solution
  4. Trojanized App In Google Play Steals Bank Customers' Euros
  5. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  6. SHEIN Data Breach Impacts Over 6.4 Million Customers
  7. Android Banking Trojan Found On Google Play with 10,000 Installs Steals User’s Banking Credentials
  8. WTB: Adwind Trojan Circumvents Antivirus Software To Infect Your PC
  9. Crooks leverages Kodi Media Player add-ons for malware distribution
  10. Cryptocurrency mining malware increases 86%
  11. 25 Malicious apps that Downloaded More Than 120,000 Times Contains Hidden Cryptomining Script
  12. Malware campaign attacks freelancers
  13. Bitcoin Core Team Releases Critical Security Update to Fix DDoS Attack Vulnerability
  14. Magecart Attacks Grow Rampant in September

POLITICS

  1. Ex-NSA employee sentenced to 5.5 years in prison for leaking confidential data
  2. Former NSA TAO hacker sentenced to 66 months in prison over Kaspersky Leak
  3. United Nations Mistakenly Exposed Sensitive Data to The Public