Oct 7, 2018

APT report for 2018-10-06

TRANSNATIONAL / UNKNOWN

  1. Burgerville discloses year-long data breach, courtesy of FIN7 cybergang

CHINA

Nothing to report

INDIA

Nothing to report

NORTH KOREA

  1. News of the Week: October 6, 2018

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. APT28 turns away from election hacking and back to cyberespionage
  2. Dutch and British Governments Slam Russia for Cyberattacks
  3. Feds Indict 7 Russians for Hacking and Disinformation

UKRAINE

Nothing to report

Platform report for 2018-10-06

WINDOWS

Nothing to report

LINUX

  1. GitHub fixes a remote code security vulnerability that affects Linux system

UNIX

Nothing to report

ANDROID

  1. Android SMS Worm, plus setting up a Mac for kids
  2. .@ThreatFabric researchers uncovered a #malware that uses overlay techniques to avoid detection. Learn from @lewisnic how this new #Androidmalware --
  3. Researchers at @Trustlook Labs found an #Android #Trojan that copies and steals data from mobile #messagingapps. Discover how this is

IOS

Nothing to report

MACOS

Nothing to report

Threat report for 2018-10-06

DATA BREACH

  1. SQL Injection Exposed Data From Canadian ISP – Altima Telecom
  2. China’s Alleged Hidden Chip for Espionage Exposed
  3. Washington D.C. Man Faces Up to 20 Years in Jail for US Senators Doxing Charges
  4. $12 Billion Lost Because of E-mail Account Compromise Incidents in Five Years
  5. Democratic congressional intern arrested for doxing GOP senators during Kavanaugh hearing
  6. Project Insecurity (@insecurity) researchers recently found #livechatsoftware leaking personal employee data. Learn what #data was leaked and how attackers can
  7. Burgerville discloses year-long data breach, courtesy of FIN7 cybergang
  8. Hackers Offering Less than $150 to Hack Corporate Email Accounts – 12.5 Million Email Archive Files are Exposed

DENIAL-OF-SERVICE

  1. California bill bans bots during elections

MALVERTISING

Nothing to report

PHISHING

  1. California prohibits use of weak default passwords

WEB DEFACEMENT

Nothing to report

MALWARE

  1. Android SMS Worm, plus setting up a Mac for kids
  2. .@ThreatFabric researchers uncovered a #malware that uses overlay techniques to avoid detection. Learn from @lewisnic how this new #Androidmalware --
  3. At the 2018 @RSAConference, researchers discussed the rise of stegware -- #malware that uses #steganography techniques to avoid detection. Learn
  4. Betabot trojan packed with anti-malware evasion tools
  5. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  6. How a remote access #Trojan checks for
  7. Report: Chinese Spy Chip Backdoored US Defense, Tech Firms
  8. More Than 50 Malicious Apps With Over 350,000 Installs Found On Google Play
  9. Researchers at @Trustlook Labs found an #Android #Trojan that copies and steals data from mobile #messagingapps. Discover how this is
  10. How to protect public SSH servers from
  11. Researchers at @TrendMicro found a new strain of #malware -- dubbed #FacexWorm -- that targets users through a malicious #ChromeExtension.

EXPLOIT

  1. SQL Injection Exposed Data From Canadian ISP – Altima Telecom
  2. Hackers exploit vulnerability in Bitcoin code

VULNERABILITY

  1. Sony Bravia Smart TVs affected by a critical vulnerability
  2. Sony Smart TV Bug Allows Remote Access, Root Privileges
  3. How #Shodan helps identify #ICSsecurity vulnerabilities
  4. Git Project Patches Remote Code Execution Vulnerability in Git
  5. The weekend starts here... right after you've installed these critical Cisco bug patches
  6. GitHub fixes a remote code security vulnerability that affects Linux system
  7. Cisco updates address 36 vulnerabilities, three critical
  8. Hackers exploit vulnerability in Bitcoin code
  9. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  10. TP-Link router vulnerable to remote takeover flaw

Region brief for 2018-10-06

ASIA

  1. China’s Alleged Hidden Chip for Espionage Exposed
  2. Report: Chinese Spy Chip Backdoored US Defense, Tech Firms

OCEANIA

Nothing to report

NORTH AMERICA

  1. SQL Injection Exposed Data From Canadian ISP – Altima Telecom
  2. China’s Alleged Hidden Chip for Espionage Exposed
  3. Washington D.C. Man Faces Up to 20 Years in Jail for US Senators Doxing Charges
  4. Sony Bravia Smart TVs affected by a critical vulnerability
  5. News of the Week: October 6, 2018
  6. Feds Indict 7 Russians for Hacking and Disinformation
  7. Report: Chinese Spy Chip Backdoored US Defense, Tech Firms

SOUTH AMERICA

Nothing to report

EUROPE

  1. News of the Week: October 6, 2018
  2. Dutch and British Governments Slam Russia for Cyberattacks
  3. Feds Indict 7 Russians for Hacking and Disinformation

AFRICA

Nothing to report

Sector brief for 2018-10-06

HEALTHCARE

Nothing to report

TRANSPORT

Nothing to report

BANKING & FINANCE

  1. China’s Alleged Hidden Chip for Espionage Exposed
  2. Washington D.C. Man Faces Up to 20 Years in Jail for US Senators Doxing Charges
  3. $12 Billion Lost Because of E-mail Account Compromise Incidents in Five Years
  4. GitHub fixes a remote code security vulnerability that affects Linux system
  5. Hackers Offering Less than $150 to Hack Corporate Email Accounts – 12.5 Million Email Archive Files are Exposed
  6. Hackers exploit vulnerability in Bitcoin code

INFORMATION & TELECOMMUNICATION

  1. SQL Injection Exposed Data From Canadian ISP – Altima Telecom
  2. China’s Alleged Hidden Chip for Espionage Exposed
  3. .@ThreatFabric researchers uncovered a #malware that uses overlay techniques to avoid detection. Learn from @lewisnic how this new #Androidmalware --
  4. Git Project Patches Remote Code Execution Vulnerability in Git
  5. GitHub fixes a remote code security vulnerability that affects Linux system
  6. More Than 50 Malicious Apps With Over 350,000 Installs Found On Google Play
  7. California prohibits use of weak default passwords

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

Nothing to report

GOVERNMENT & PUBLIC SERVICE

  1. APT28 turns away from election hacking and back to cyberespionage

Daily brief for 2018-10-06

ASIA

  1. China’s Alleged Hidden Chip for Espionage Exposed
  2. Report: Chinese Spy Chip Backdoored US Defense, Tech Firms

WORLD

  1. SQL Injection Exposed Data From Canadian ISP – Altima Telecom
  2. China’s Alleged Hidden Chip for Espionage Exposed
  3. Washington D.C. Man Faces Up to 20 Years in Jail for US Senators Doxing Charges
  4. Sony Bravia Smart TVs affected by a critical vulnerability
  5. News of the Week: October 6, 2018
  6. Dutch and British Governments Slam Russia for Cyberattacks
  7. Feds Indict 7 Russians for Hacking and Disinformation
  8. Report: Chinese Spy Chip Backdoored US Defense, Tech Firms

ATTACKS

  1. SQL Injection Exposed Data From Canadian ISP – Altima Telecom
  2. China’s Alleged Hidden Chip for Espionage Exposed
  3. Washington D.C. Man Faces Up to 20 Years in Jail for US Senators Doxing Charges
  4. $12 Billion Lost Because of E-mail Account Compromise Incidents in Five Years
  5. Democratic congressional intern arrested for doxing GOP senators during Kavanaugh hearing
  6. California bill bans bots during elections
  7. Project Insecurity (@insecurity) researchers recently found #livechatsoftware leaking personal employee data. Learn what #data was leaked and how attackers can
  8. Burgerville discloses year-long data breach, courtesy of FIN7 cybergang
  9. Hackers Offering Less than $150 to Hack Corporate Email Accounts – 12.5 Million Email Archive Files are Exposed
  10. California prohibits use of weak default passwords

THREATS

  1. SQL Injection Exposed Data From Canadian ISP – Altima Telecom
  2. Sony Bravia Smart TVs affected by a critical vulnerability
  3. Android SMS Worm, plus setting up a Mac for kids
  4. .@ThreatFabric researchers uncovered a #malware that uses overlay techniques to avoid detection. Learn from @lewisnic how this new #Androidmalware --
  5. At the 2018 @RSAConference, researchers discussed the rise of stegware -- #malware that uses #steganography techniques to avoid detection. Learn
  6. Sony Smart TV Bug Allows Remote Access, Root Privileges
  7. How #Shodan helps identify #ICSsecurity vulnerabilities
  8. Git Project Patches Remote Code Execution Vulnerability in Git
  9. Betabot trojan packed with anti-malware evasion tools
  10. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  11. How a remote access #Trojan checks for
  12. The weekend starts here... right after you've installed these critical Cisco bug patches
  13. Report: Chinese Spy Chip Backdoored US Defense, Tech Firms
  14. GitHub fixes a remote code security vulnerability that affects Linux system
  15. More Than 50 Malicious Apps With Over 350,000 Installs Found On Google Play
  16. Researchers at @Trustlook Labs found an #Android #Trojan that copies and steals data from mobile #messagingapps. Discover how this is
  17. How to protect public SSH servers from
  18. Cisco updates address 36 vulnerabilities, three critical
  19. Hackers exploit vulnerability in Bitcoin code
  20. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  21. TP-Link router vulnerable to remote takeover flaw
  22. Researchers at @TrendMicro found a new strain of #malware -- dubbed #FacexWorm -- that targets users through a malicious #ChromeExtension.

CRIME

  1. China’s Alleged Hidden Chip for Espionage Exposed
  2. Washington D.C. Man Faces Up to 20 Years in Jail for US Senators Doxing Charges
  3. $12 Billion Lost Because of E-mail Account Compromise Incidents in Five Years
  4. Feds Indict 7 Russians for Hacking and Disinformation
  5. Hackers Offering Less than $150 to Hack Corporate Email Accounts – 12.5 Million Email Archive Files are Exposed
  6. Hackers exploit vulnerability in Bitcoin code

POLITICS

  1. China’s Alleged Hidden Chip for Espionage Exposed
  2. APT28 turns away from election hacking and back to cyberespionage
  3. Feds Indict 7 Russians for Hacking and Disinformation
  4. Report: Chinese Spy Chip Backdoored US Defense, Tech Firms

Oct 6, 2018

APT report for 2018-10-05

TRANSNATIONAL / UNKNOWN

  1. Fin7 Hackers Breached US Chain Burgerville
  2. Fin7 Hackers Breached US Chain Burgerville

CHINA

  1. DHS issued an alert on attacks aimed at Managed Service Providers

INDIA

Nothing to report

NORTH KOREA

  1. Detecting Credit Card Skimmers
  2. North Korean hacking operation behind SWIFT attacks

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  2. Uncle Sam Charges Seven Russians With Fancy Bear Hack Sprees
  3. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  4. VP Mike Pence slams Google over Chinese search engine project
  5. Russia's elite hacking unit has been silent, but busy
  6. Lojax, the new threat developed by Fancy Bear

UKRAINE

Nothing to report

Platform report for 2018-10-05

WINDOWS

  1. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  2. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  3. Missing Files, Bugs Reported After Windows 10 October 2018 Update
  4. DanaBot Banking Trojan’s Journey to North America
  5. Lojax, the new threat developed by Fancy Bear
  6. CMake 3.12.3 releases: managing the build process of software

LINUX

  1. DanaBot Banking Trojan’s Journey to North America
  2. Lojax, the new threat developed by Fancy Bear

UNIX

Nothing to report

ANDROID

  1. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  2. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  3. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  4. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System

IOS

  1. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  2. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System

MACOS

  1. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  2. DanaBot Banking Trojan’s Journey to North America
  3. Lojax, the new threat developed by Fancy Bear

Threat report for 2018-10-05

DATA BREACH

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Fortnite gamers targeted by data theft malware
  3. Apollo hackers steal info from database of 200M contact
  4. Security researchers @proofpoint recently uncovered new #DanaBot campaigns.
  5. GhostDNS hijacking campaign steps up attacks on Brazilians; 100K+ devices compromised
  6. Smart TV kit featuring Google Home Mini and third-gen Chromecast leaks
  7. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  8. Experts warns of a new extortion campaign based on the Breach Compilation archive
  9. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  10. Intel, AMD both claim server speed records
  11. Samsung predicts a return to record profits in Q3
  12. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to

DENIAL-OF-SERVICE

  1. Hacked #Fortnite accounts and rent-a-botnet being pushed on Instagram

MALVERTISING

Nothing to report

PHISHING

  1. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  2. Remove Ursnif Trojan (Purolator Phishing) Scam
  3. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  4. Report: The bigger the company, the messier the password practices
  5. The most commonly used passwords in the world are... 1. 123456 2. password 3. 123456789 4. 12345678 5. 12345 6. qwerty
  6. Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
  7. Weak Passwords Banned In California From 2020
  8. New IoT legislation bans shared default passwords
  9. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  10. Credential-Phishing Attempts Highest on Tuesdays
  11. Credential-Phishing Attempts Highest on Tuesdays
  12. If you're thinking passwords, check out #CyberSauna episode #13: A Hacker's Take on Cracking & Protecting Your Creds
  13. FYI: "password" is the 2nd most popular password in the world. Can you guess the first?
  14. Facebook Logins Available on the Dark Web for $2.60
  15. Passware Kit: Forensic software recovers passwords for Bitcoin wallets

WEB DEFACEMENT

Nothing to report

MALWARE

  1. Ransomware Recovery at the Taxpayers’ Expense
  2. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  3. Fortnite gamers targeted by data theft malware
  4. Remove Ursnif Trojan (Purolator Phishing) Scam
  5. Trojans go after MS Office vulnerabilities and China hacks US hardware
  6. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  7. Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
  8. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  9. Danabot Banking Malware Targets U.S. Organizations
  10. The Virus Bulletin conference returns home: VB2019 to take place in London
  11. Fileless malware: part deux
  12. Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
  13. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  14. DanaBot Banking Trojan’s Journey to North America
  15. Virus Bulletin 2018: Supply chain hacking grows up
  16. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  17. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  18. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  19. How does FacexWorm malware use Facebook Messenger to spread?
  20. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  21. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  22. .@FireEye researches discovered that the group behind #Sanny #malware attacks has made delivery method changes that put users at risk.
  23. Fake News Domains Spoof UK News Sites
  24. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  25. Top 5 Viruses of All Time by Security Expert Mikko Hyppönen
  26. CMake 3.12.3 releases: managing the build process of software

EXPLOIT

  1. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  2. Advanced Persistent Threat Activity Exploiting Managed Service Providers

VULNERABILITY

  1. Adobe October Patch Update Fixed 86 Different Security Vulnerabilities
  2. Sony Smart TV Bug Allows Remote Access, Root Privileges
  3. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  4. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  5. D-Link Patches RCE Bugs in Wireless Access Point Gear
  6. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  7. 150 Bugs Found in the Hack the Marine Corps Challenge
  8. Trojans go after MS Office vulnerabilities and China hacks US hardware
  9. 150 Bugs Found in the Hack the Marine Corps Challenge
  10. Most Home Routers Are Full of Vulnerabilities
  11. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  12. Adobe update cleans up 86 bugs in Acrobat and Reader, many critical
  13. Missing Files, Bugs Reported After Windows 10 October 2018 Update
  14. Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
  15. Mozilla Resolves Critical Code Execution Flaw In Thunderbird
  16. Cisco patches critical flaws in DNA Center and Prime Infrastructure
  17. Marine Corps bug bounty program finds 150 vulnerabilities
  18. Mozilla resolves critical code execution flaw in Thunderbird email client
  19. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  20. D-Link Patches Code Execution, XSS Flaws in Management Tool
  21. Cisco updates address 36 vulnerabilities, three critical
  22. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  23. #PulseNet: How does an improper #authentication flaw affect it?
  24. Cisco Released Security Updates & Fixed 37 Vulnerabilities that Affected Cisco Products
  25. Mozilla Patches Critical Vulnerability in Thunderbird 60.2.1

Region brief for 2018-10-05

ASIA

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  4. DHS issued an alert on attacks aimed at Managed Service Providers
  5. VP Mike Pence slams Google over Chinese search engine project
  6. North Korean hacking operation behind SWIFT attacks

OCEANIA

  1. Trojans go after MS Office vulnerabilities and China hacks US hardware
  2. Danabot Banking Malware Targets U.S. Organizations
  3. DanaBot Banking Trojan’s Journey to North America

NORTH AMERICA

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  4. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  5. Danabot Banking Malware Targets U.S. Organizations
  6. Uncle Sam Charges Seven Russians With Fancy Bear Hack Sprees
  7. DanaBot Banking Trojan’s Journey to North America
  8. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  9. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  10. DHS issued an alert on attacks aimed at Managed Service Providers
  11. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  12. Fin7 Hackers Breached US Chain Burgerville
  13. Fin7 Hackers Breached US Chain Burgerville

SOUTH AMERICA

Nothing to report

EUROPE

  1. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  2. Danabot Banking Malware Targets U.S. Organizations
  3. The Virus Bulletin conference returns home: VB2019 to take place in London
  4. DanaBot Banking Trojan’s Journey to North America
  5. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  6. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  7. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  8. Experts warns of a new extortion campaign based on the Breach Compilation archive
  9. Facebook Logins Available on the Dark Web for $2.60
  10. DHS issued an alert on attacks aimed at Managed Service Providers
  11. Fake News Domains Spoof UK News Sites
  12. Russia's elite hacking unit has been silent, but busy

AFRICA

Nothing to report

Sector brief for 2018-10-05

HEALTHCARE

  1. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  2. DHS issued an alert on attacks aimed at Managed Service Providers

TRANSPORT

Nothing to report

BANKING & FINANCE

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Remove Ursnif Trojan (Purolator Phishing) Scam
  3. Trojans go after MS Office vulnerabilities and China hacks US hardware
  4. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  5. Danabot Banking Malware Targets U.S. Organizations
  6. Report: The bigger the company, the messier the password practices
  7. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  8. DanaBot Banking Trojan’s Journey to North America
  9. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  10. Detecting Credit Card Skimmers
  11. Experts warns of a new extortion campaign based on the Breach Compilation archive
  12. Facebook Logins Available on the Dark Web for $2.60
  13. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  14. Passware Kit: Forensic software recovers passwords for Bitcoin wallets
  15. North Korean hacking operation behind SWIFT attacks

INFORMATION & TELECOMMUNICATION

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  3. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  4. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  5. 150 Bugs Found in the Hack the Marine Corps Challenge
  6. 150 Bugs Found in the Hack the Marine Corps Challenge
  7. Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
  8. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  9. Fileless malware: part deux
  10. Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
  11. Smart TV kit featuring Google Home Mini and third-gen Chromecast leaks
  12. Hacked #Fortnite accounts and rent-a-botnet being pushed on Instagram
  13. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  14. Credential-Phishing Attempts Highest on Tuesdays
  15. Credential-Phishing Attempts Highest on Tuesdays
  16. If you're thinking passwords, check out #CyberSauna episode #13: A Hacker's Take on Cracking & Protecting Your Creds
  17. How does FacexWorm malware use Facebook Messenger to spread?
  18. FYI: "password" is the 2nd most popular password in the world. Can you guess the first?
  19. Facebook Logins Available on the Dark Web for $2.60
  20. VP Mike Pence slams Google over Chinese search engine project
  21. Fake News Domains Spoof UK News Sites
  22. Fin7 Hackers Breached US Chain Burgerville
  23. Fin7 Hackers Breached US Chain Burgerville
  24. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  25. CMake 3.12.3 releases: managing the build process of software

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

  1. DHS issued an alert on attacks aimed at Managed Service Providers

GOVERNMENT & PUBLIC SERVICE

Nothing to report

Daily brief for 2018-10-05

ASIA

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  4. DHS issued an alert on attacks aimed at Managed Service Providers
  5. VP Mike Pence slams Google over Chinese search engine project
  6. North Korean hacking operation behind SWIFT attacks

WORLD

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  4. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  5. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  6. Danabot Banking Malware Targets U.S. Organizations
  7. The Virus Bulletin conference returns home: VB2019 to take place in London
  8. Uncle Sam Charges Seven Russians With Fancy Bear Hack Sprees
  9. DanaBot Banking Trojan’s Journey to North America
  10. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  11. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  12. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  13. Experts warns of a new extortion campaign based on the Breach Compilation archive
  14. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  15. Facebook Logins Available on the Dark Web for $2.60
  16. DHS issued an alert on attacks aimed at Managed Service Providers
  17. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  18. Fake News Domains Spoof UK News Sites
  19. Russia's elite hacking unit has been silent, but busy
  20. Fin7 Hackers Breached US Chain Burgerville
  21. Fin7 Hackers Breached US Chain Burgerville

ATTACKS

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  3. Fortnite gamers targeted by data theft malware
  4. Remove Ursnif Trojan (Purolator Phishing) Scam
  5. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  6. Report: The bigger the company, the messier the password practices
  7. The most commonly used passwords in the world are... 1. 123456 2. password 3. 123456789 4. 12345678 5. 12345 6. qwerty
  8. Apollo hackers steal info from database of 200M contact
  9. Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
  10. Security researchers @proofpoint recently uncovered new #DanaBot campaigns.
  11. Weak Passwords Banned In California From 2020
  12. New IoT legislation bans shared default passwords
  13. GhostDNS hijacking campaign steps up attacks on Brazilians; 100K+ devices compromised
  14. Smart TV kit featuring Google Home Mini and third-gen Chromecast leaks
  15. Hacked #Fortnite accounts and rent-a-botnet being pushed on Instagram
  16. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  17. Experts warns of a new extortion campaign based on the Breach Compilation archive
  18. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  19. Credential-Phishing Attempts Highest on Tuesdays
  20. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  21. Credential-Phishing Attempts Highest on Tuesdays
  22. If you're thinking passwords, check out #CyberSauna episode #13: A Hacker's Take on Cracking & Protecting Your Creds
  23. Intel, AMD both claim server speed records
  24. FYI: "password" is the 2nd most popular password in the world. Can you guess the first?
  25. Facebook Logins Available on the Dark Web for $2.60
  26. Samsung predicts a return to record profits in Q3
  27. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  28. Passware Kit: Forensic software recovers passwords for Bitcoin wallets

THREATS

  1. Adobe October Patch Update Fixed 86 Different Security Vulnerabilities
  2. Ransomware Recovery at the Taxpayers’ Expense
  3. Sony Smart TV Bug Allows Remote Access, Root Privileges
  4. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  5. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  6. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  7. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  8. Fortnite gamers targeted by data theft malware
  9. D-Link Patches RCE Bugs in Wireless Access Point Gear
  10. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  11. Remove Ursnif Trojan (Purolator Phishing) Scam
  12. 150 Bugs Found in the Hack the Marine Corps Challenge
  13. Trojans go after MS Office vulnerabilities and China hacks US hardware
  14. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  15. 150 Bugs Found in the Hack the Marine Corps Challenge
  16. Most Home Routers Are Full of Vulnerabilities
  17. Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
  18. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  19. Danabot Banking Malware Targets U.S. Organizations
  20. The Virus Bulletin conference returns home: VB2019 to take place in London
  21. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  22. Fileless malware: part deux
  23. Adobe update cleans up 86 bugs in Acrobat and Reader, many critical
  24. Missing Files, Bugs Reported After Windows 10 October 2018 Update
  25. Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
  26. Advanced Persistent Threat Activity Exploiting Managed Service Providers
  27. Mozilla Resolves Critical Code Execution Flaw In Thunderbird
  28. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  29. DanaBot Banking Trojan’s Journey to North America
  30. Cisco patches critical flaws in DNA Center and Prime Infrastructure
  31. Virus Bulletin 2018: Supply chain hacking grows up
  32. Marine Corps bug bounty program finds 150 vulnerabilities
  33. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  34. Mozilla resolves critical code execution flaw in Thunderbird email client
  35. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  36. D-Link Patches Code Execution, XSS Flaws in Management Tool
  37. Cisco updates address 36 vulnerabilities, three critical
  38. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  39. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  40. How does FacexWorm malware use Facebook Messenger to spread?
  41. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  42. #PulseNet: How does an improper #authentication flaw affect it?
  43. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  44. .@FireEye researches discovered that the group behind #Sanny #malware attacks has made delivery method changes that put users at risk.
  45. Cisco Released Security Updates & Fixed 37 Vulnerabilities that Affected Cisco Products
  46. Fake News Domains Spoof UK News Sites
  47. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  48. Top 5 Viruses of All Time by Security Expert Mikko Hyppönen
  49. CMake 3.12.3 releases: managing the build process of software
  50. Mozilla Patches Critical Vulnerability in Thunderbird 60.2.1

CRIME

  1. Fortnite gamers targeted by data theft malware
  2. Remove Ursnif Trojan (Purolator Phishing) Scam
  3. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  4. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  5. Danabot Banking Malware Targets U.S. Organizations
  6. Report: The bigger the company, the messier the password practices
  7. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  8. DanaBot Banking Trojan’s Journey to North America
  9. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  10. Detecting Credit Card Skimmers
  11. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  12. Experts warns of a new extortion campaign based on the Breach Compilation archive
  13. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  14. Facebook Logins Available on the Dark Web for $2.60
  15. DHS issued an alert on attacks aimed at Managed Service Providers
  16. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  17. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  18. Passware Kit: Forensic software recovers passwords for Bitcoin wallets
  19. North Korean hacking operation behind SWIFT attacks
  20. Lojax, the new threat developed by Fancy Bear

POLITICS

  1. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  2. Advanced Persistent Threat Activity Exploiting Managed Service Providers
  3. DHS issued an alert on attacks aimed at Managed Service Providers

Oct 5, 2018

APT report for 2018-10-04

TRANSNATIONAL / UNKNOWN

  1. Formjacking attacks spike as Magecart sets sites on ecommerce
  2. Pacific Northwest burger chain hit by FIN7
  3. Burgerville customer credit card info stolen in data breach laid at Fin7's feet

CHINA

Nothing to report

INDIA

Nothing to report

NORTH KOREA

  1. HIDDEN COBRA – FASTCash Campaign
  2. APT38 is behind financially motivated attacks carried out by North Korea

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Virus Bulletin 2018: Turla APT Changes Shape with New Code and Targets
  2. Should You Worry About Software Supply Chain Attacks?
  3. Shedding Skin – Turla’s Fresh Faces
  4. LoJack for computers used to attack European government bodies
  5. Justice Department charges 7 Russian intelligence officers
  6. APT28 turns away from election hacking and back to cyberespionage
  7. Russian Fancy Bear APT Linked To Earworm Hacking Group
  8. Russian Fancy Bear APT linked to Earworm hacking group
  9. LoJax: First UEFI Malware seen in the Wild

UKRAINE

Nothing to report

Platform report for 2018-10-04

WINDOWS

  1. Shedding Skin – Turla’s Fresh Faces
  2. LoJack for computers used to attack European government bodies
  3. CVE-2018-8373 Exploit Spotted
  4. LoJax: First UEFI Malware seen in the Wild
  5. Foxit PDF Reader fixes serious remote code execution vulnerability

LINUX

  1. LoJack for computers used to attack European government bodies

UNIX

Nothing to report

ANDROID

  1. .@ThreatFabric researchers uncovered an #Android malware, #MysteryBot, which uses overlay attacks to avoid detection. Learn how this #malware affects @Google's
  2. How is Android Accessibility Service affected by a banking Trojan?
  3. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  4. Researchers found that cheap Android devices were shipped pre-installed backdoors

IOS

  1. A Remote iOS Bug

MACOS

  1. Google Project Zero drops macOS exploit, calls out Apple for silent patching
  2. CVE-2018-4251 – Apple did not disable Intel Manufacturing Mode in its laptops
  3. macOS Flaw Allows Attackers To Hijack Installed Apps
  4. Tearing Apart the Undetected (OSX)Coldroot RAT
  5. An Unpatched Kernel Bug
  6. OSX/MacRansom; analyzing the latest ransomware to target macs
  7. Two Bugs, One Func(), part three
  8. Two Bugs, One Func(), part two
  9. Two Bugs, One Func(), part one
  10. Analysis of an Intrusive Cross-Platform Adware; OSX/Pirrit
  11. More on, "Adware for OS X Distributes Trojans"
  12. A Google bug breaks the search results in Safari

Threat report for 2018-10-04

DATA BREACH

  1. UK pins ‘reckless campaign of cyber attacks’ on Russian military intelligence
  2. .@FireEye researchers tracked an aggressive #cybertheft campaign -- attributed to North Korean #APT38 -- in which threat actors attempted to
  3. Campaign 2018: Cyberattacks on infrastructure could suppress voter turnout
  4. Sony accidentally leaked November's PS Plus free games
  5. US charges Russian military officers over international hacking and disinformation campaigns
  6. Burgerville Customer Credit Card Info Stolen In Data Breach
  7. HIDDEN COBRA – FASTCash Campaign
  8. Database of 200 Million Records Stolen from Apollo in Data Breach
  9. Irish Data Regulator Likely to Fine Facebook for Data Breach
  10. 5,000 UK firms' financial details exposed in data breaches, finds @digitalshadows
  11. The @UN accidentally exposed credentials on public @trello boards. Plus, #Uber is set to pay $148 million settlement following its
  12. Burgerville customer credit card info stolen in data breach laid at Fin7's feet
  13. How #livechatsoftware leak personal #employeedata?
  14. Democratic congressional intern arrested for doxing GOP senators during Kavanaugh hearing
  15. Business Email Compromise: When You Don’t Need to Phish.
  16. Business email compromise made easy for cyber criminals
  17. In manufacturing, almost half – 47 percent – of breaches involve the theft of intellectual property to gain competitive advantage.
  18. Security Investigator who Compromised Hotel Wi-Fi, Shared Pass-Codes Online, is Fined
  19. UK and allies accuse Russia of cyber attack campaign
  20. Business email compromise made easy for #cybercriminals as 12.5 million company email boxes and 33,000 finance department credentials found openly
  21. U.S. Capitol Police Arrest Suspect for Doxing U.S. Senators
  22. DanaBot Observed in Large Campaign Targeting U.S. Organizations

DENIAL-OF-SERVICE

  1. California bill bans bots during elections
  2. Why It’s Time to Nuke the Password
  3. Why It’s Time to Nuke the Password

MALVERTISING

Nothing to report

PHISHING

  1. Exclusive: Moving away from passwords to two-factor authentication
  2. Block Blocking Login Items
  3. Business Email Compromise: When You Don’t Need to Phish.
  4. Hackers Selling Facebook Account Logins Details On Dark Web For $3
  5. Experts recommend avoiding single step logins
  6. Phishing Attacks Distributed Through CloudFlare's IPFS Gateway
  7. Why It’s Time to Nuke the Password
  8. Why It’s Time to Nuke the Password
  9. DanaBot Observed in Large Campaign Targeting U.S. Organizations

WEB DEFACEMENT

  1. Hacker Pleads Guilty of Defacing 11,000 Websites, Could Get up to 20 Years
  2. Hacktivist pleads guilty to defacing websites for NYC comptroller, Combating Terrorism Center

MALWARE

  1. Virus Bulletin 2018: Turla APT Changes Shape with New Code and Targets
  2. .@ThreatFabric researchers uncovered an #Android malware, #MysteryBot, which uses overlay attacks to avoid detection. Learn how this #malware affects @Google's
  3. China allegedly infiltrated US companies through implanted hardware backdoors
  4. Researchers at the 2018 @RSAConference discussed #stegware: @malware that uses #steganography. Discover how this works with expert @lewisnic.
  5. Report: In Huge Hack, Chinese Manufacturer Sneaks Backdoors Onto Motherboards
  6. Avast AV reclassifies cryptominers | Avast
  7. Researchers at Cisco Talos (@TalosSecurity) recently discovered #GravityRAT, a remote access #Trojan. Discover how this RAT can check for
  8. This is also a good time to remind that bugdoors are far more scary than backdoors.
  9. Fallout Exploit Kit Now Installing the Kraken Cryptor Ransomware
  10. Apple, Amazon deny claims Chinese spies implanted backdoor chips in company hardware: report
  11. Researchers from @proofpoint have announced the discovery of a remote access trojan, and an upgraded version of an old banking
  12. Canadian restaurant chain Recipe suffered a network outage, is it a ransomware attack?
  13. Tearing Apart the Undetected (OSX)Coldroot RAT
  14. Mac Malware of 2017
  15. WTF is Mughthesec!? poking on a piece of undetected adware
  16. OSX/MacRansom; analyzing the latest ransomware to target macs
  17. Mac Malware of 2016
  18. Towards Generic Ransomware Detection
  19. Analysis of an Intrusive Cross-Platform Adware; OSX/Pirrit
  20. Analyzing the Anti-Analysis Logic of an Adware Installer
  21. Monitoring Process Creation via the Kernel (Part III)
  22. Monitoring Process Creation via the Kernel (Part II)
  23. Monitoring Process Creation via the Kernel (Part I)
  24. More on, "Adware for OS X Distributes Trojans"
  25. LoJax: First UEFI Malware seen in the Wild
  26. Virus Bulletin 2018: Attack velocity ramps up
  27. More than 4,000 ransomware attacks occur every day. Secure your company & build your network at #RiskSec with promo code
  28. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  29. Betabot trojan packed with anti-malware evasion tools
  30. How is Android Accessibility Service affected by a banking Trojan?
  31. How does stegware malware exploit steganography techniques?
  32. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  33. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  34. A new group of #malware -- dubbed #GoScanSSH -- was recently discovered by researchers. Learn how this malware works and
  35. Seriously if I could make evil semiconductors I would just replace one which is already present rather than adding it. Show
  36. WATCH: Top 5 Viruses of All Time by Security Expert @mikko Hyppönen
  37. New DanaBot Banking Malware Attack in Various Countries with Stealer and Remote Access Futures
  38. Researchers found that cheap Android devices were shipped pre-installed backdoors
  39. Google opened the .page domain
  40. Most Advanced Backdoor Obfuscation and Evasion Technique That used by Hackers
  41. Zoho Heavily Used by Keyloggers to Transmit Stolen Data
  42. Network Outage at Some Recipe Unlimited Locations Caused by Malware
  43. DanaBot Observed in Large Campaign Targeting U.S. Organizations

EXPLOIT

  1. Google Project Zero drops macOS exploit, calls out Apple for silent patching
  2. CVE-2018-8373 Exploit Spotted
  3. Fallout Exploit Kit Now Installing the Kraken Cryptor Ransomware
  4. Remote Mac Exploitation Via Custom URL Schemes
  5. How does stegware malware exploit steganography techniques?
  6. Secure encrypted #virtualization: How is this technology exploited?

VULNERABILITY

  1. Bug bounty scheme uncovers 150 vulnerabilities in US Marine Corps websites
  2. CVE-2018-4251 – Apple did not disable Intel Manufacturing Mode in its laptops
  3. macOS Flaw Allows Attackers To Hijack Installed Apps
  4. ICYMI - CISO @rickhholland joins @drshellface and @mazzazone in this week's ShadowTalk episode: Security Flaws Affect 50 Million Facebook Accounts
  5. CVE-2018-8373 Exploit Spotted
  6. Vulnerability Scanning vs. Penetration Testing by @TripwireInc
  7. This is also a good time to remind that bugdoors are far more scary than backdoors.
  8. A Remote iOS Bug
  9. An Unpatched Kernel Bug
  10. From the Top to the Bottom; Tracking down CVE-2017-7149
  11. Two Bugs, One Func(), part three
  12. Two Bugs, One Func(), part two
  13. Two Bugs, One Func(), part one
  14. CVE-2015-3673: Goodbye Rootpipe...(for now?)
  15. Cisco: Two critical bugs in DNA network software need these urgent patches
  16. Paper over the Kracks: New techniques can bypass WPA2 flaw mitigations
  17. Hackers Earn $150,000 in Marine Corps Bug Bounty Program
  18. Cisco plugs critical flaws in DNA Center and Prime Infrastructure
  19. Marine Corps bug bounty program finds 150 vulnerabilities
  20. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  21. Foxit PDF Reader fixes serious remote code execution vulnerability
  22. A Google bug breaks the search results in Safari
  23. Hacking for good uncovers over 150 Marine Corps web vulnerabilities