Oct 14, 2018

APT report for 2018-10-13

TRANSNATIONAL / UNKNOWN

Nil

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-13

WINDOWS

  1. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available

LINUX

Nil

UNIX

Nil

ANDROID

  1. GPlayed – New Malware Posed as Google Play App to Spy & Steal Data From Your Entire Android Phone

IOS

Nil

MACOS

Nil

Threat report for 2018-10-13

DATA BREACH & DATA LOSS

  1. Pentagon Defense Department travel records data breach
  2. A combination of #SecurityFlaws and inadequate back-end development of the @Google Firebase database led to #DataLeaks and #SecurityVulnerabilities including HospitalGown.
  3. 'Only' 30 million accounts were compromised in Facebook hack
  4. Researchers @proofpoint have been tracking a downloader dubbed #AdvisorsBot as a first-stage payload in campaigns since May 2018.
  5. Facebook Clarifies Extent of Data Breach
  6. An Assessment of Google's Data Leak
  7. ArangoDB v3.3.18 releases: native multi-model database
  8. Facebook Now Revealed Hackers Stolen 29 Million Facebook Users Personal Data
  9. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available
  10. Breach of Pentagon travel records exposes defense personnel PII

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. Hackers launched @netflix #phishing attacks by obtaining TLS certificates. Learn how hackers mimic popular websites to spoof users and steal
  2. This skyscraper reminds me of those really long ANSI art BBS login screens. Cc: @sixteencolors @blocktronics @velikani

WEB DEFACEMENT

Nil

BOTNET

Nil

RANSOMWARE

  1. [SingCERT] Updated Advisory on Ransomware
  2. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11

CRYPTOMINING & CRYPTOCURRENCIES

  1. Criminals' Cryptocurrency Addiction Continues
  2. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  3. Cryptocurrency Miners trick the user through Fake Flash Updates
  4. Blockchain and Healthcare in Today’s World

MALWARE

  1. GPlayed – New Malware Posed as Google Play App to Spy & Steal Data From Your Entire Android Phone
  2. Researchers @proofpoint have been tracking a downloader dubbed #AdvisorsBot as a first-stage payload in campaigns since May 2018.
  3. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  4. Hackers use Googlebot in mining malware attacks
  5. Researchers at @TrendMicro found a new strain of #malware -- dubbed #FacexWorm -- that targets users through a malicious #ChromeExtension.
  6. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11

EXPLOIT

Nil

VULNERABILITY

  1. Now this might be going out on a limb, but here's how a branch.io bug left '685 million' netizens open to website hacks
  2. Review Shows Glaring Flaws In Xiongmai IoT Devices
  3. Microsoft JET vulnerability still open to attacks, despite recent patch
  4. DOM-based XSS Vulnerability Affected 685 Million Users of Tinder, Shopify, Western Union, and Imgur
  5. A patched #MikroTik router vulnerability amps up severity rating as @TenableSecurity researchers find new potential exploits with more critical consequences.
  6. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available
  7. Vulnerabilities affect Shopify, Tinder and many other sites

Region brief for 2018-10-13

ASIA

  1. Review Shows Glaring Flaws In Xiongmai IoT Devices

OCEANIA

  1. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

NORTH AMERICA

  1. Pentagon Defense Department travel records data breach

SOUTH AMERICA

Nil

EUROPE

  1. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

AFRICA

Nil

Sector brief for 2018-10-13

HEALTHCARE

  1. Blockchain and Healthcare in Today’s World

TRANSPORT

Nil

BANKING & FINANCE

  1. Pentagon Defense Department travel records data breach
  2. Cryptocurrency Miners trick the user through Fake Flash Updates
  3. Hackers use Googlebot in mining malware attacks

INFORMATION & TELECOMMUNICATION

  1. This skyscraper reminds me of those really long ANSI art BBS login screens. Cc: @sixteencolors @blocktronics @velikani
  2. 'Only' 30 million accounts were compromised in Facebook hack
  3. Facebook Clarifies Extent of Data Breach
  4. Facebook Now Revealed Hackers Stolen 29 Million Facebook Users Personal Data

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

Nil

Daily brief for 2018-10-13

ASIA

  1. Review Shows Glaring Flaws In Xiongmai IoT Devices

WORLD

  1. Pentagon Defense Department travel records data breach
  2. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

ATTACKS

  1. Pentagon Defense Department travel records data breach
  2. Hackers launched @netflix #phishing attacks by obtaining TLS certificates. Learn how hackers mimic popular websites to spoof users and steal
  3. This skyscraper reminds me of those really long ANSI art BBS login screens. Cc: @sixteencolors @blocktronics @velikani
  4. A combination of #SecurityFlaws and inadequate back-end development of the @Google Firebase database led to #DataLeaks and #SecurityVulnerabilities including HospitalGown.
  5. 'Only' 30 million accounts were compromised in Facebook hack
  6. Researchers @proofpoint have been tracking a downloader dubbed #AdvisorsBot as a first-stage payload in campaigns since May 2018.
  7. Facebook Clarifies Extent of Data Breach
  8. An Assessment of Google's Data Leak
  9. ArangoDB v3.3.18 releases: native multi-model database
  10. Facebook Now Revealed Hackers Stolen 29 Million Facebook Users Personal Data
  11. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available
  12. Breach of Pentagon travel records exposes defense personnel PII

THREATS

  1. GPlayed – New Malware Posed as Google Play App to Spy & Steal Data From Your Entire Android Phone
  2. [SingCERT] Updated Advisory on Ransomware
  3. Researchers @proofpoint have been tracking a downloader dubbed #AdvisorsBot as a first-stage payload in campaigns since May 2018.
  4. Now this might be going out on a limb, but here's how a branch.io bug left '685 million' netizens open to website hacks
  5. Review Shows Glaring Flaws In Xiongmai IoT Devices
  6. Criminals' Cryptocurrency Addiction Continues
  7. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  8. Cryptocurrency Miners trick the user through Fake Flash Updates
  9. Microsoft JET vulnerability still open to attacks, despite recent patch
  10. DOM-based XSS Vulnerability Affected 685 Million Users of Tinder, Shopify, Western Union, and Imgur
  11. A patched #MikroTik router vulnerability amps up severity rating as @TenableSecurity researchers find new potential exploits with more critical consequences.
  12. Blockchain and Healthcare in Today’s World
  13. Microsoft Fix for Windows JET Database Bug Not Perfect, Micropatch Available
  14. Hackers use Googlebot in mining malware attacks
  15. Vulnerabilities affect Shopify, Tinder and many other sites
  16. Researchers at @TrendMicro found a new strain of #malware -- dubbed #FacexWorm -- that targets users through a malicious #ChromeExtension.
  17. APT group called #TeleBots linked to #Industroyer #malware and #NotPetya #ransomware, according to @ESET researchers. By @MaddieBacon11

CRIME

  1. ArangoDB v3.3.18 releases: native multi-model database
  2. Facebook Now Revealed Hackers Stolen 29 Million Facebook Users Personal Data

POLITICS

  1. Pentagon Defense Department travel records data breach
  2. GPlayed – New Malware Posed as Google Play App to Spy & Steal Data From Your Entire Android Phone
  3. Security researchers found that Industroyer and NotPetya belong to the Russian hacker group

Oct 13, 2018

APT report for 2018-10-12

TRANSNATIONAL / UNKNOWN

  1. Cyber News Rundown: Windows 10 Update Deletes Files
  2. No Cookies for CartThief, a New Magecart Variant
  3. Payment skimmers sneaking on to websites via third party code
  4. Gallmaker Hacking Group Attack Government, Military, and Defense Sectors Using Publicly Available Hacking Tools

CHINA

  1. Five Eyes Intelligence agencies warn of popular hacking tools

INDIA

Nil

NORTH KOREA

  1. Threat Brief: FASTCash ATM Cash Out Tactics

PAKISTAN

Nil

VIETNAM

Nil

IRAN

  1. MuddyWater APT Latest Activity

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

Nil

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-12

WINDOWS

  1. Windows 10 October 2018 Update: Release – Halt – Bug Identified – Fix!
  2. Cyber News Rundown: Windows 10 Update Deletes Files
  3. Five Eyes Intelligence agencies warn of popular hacking tools
  4. PoC exploit for Windows Shell RCE released
  5. Call of Duty: Black Ops 4 welcomes launch with new Blackout and Zombies trailers
  6. Cryptomining software is hidden as Flash update

LINUX

  1. Five Eyes Intelligence agencies warn of popular hacking tools

UNIX

Nil

ANDROID

  1. Five Eyes Intelligence agencies warn of popular hacking tools
  2. .@ThreatFabric researchers uncovered an #Android malware, #MysteryBot, which uses overlay attacks to avoid detection. Learn how this #malware affects @Google's
  3. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million
  4. This Trojan masquerades as Google Play to hide on your phone in plain sight
  5. Fortnite for Android Released, But Make Sure You Don't Download Malware

IOS

Nil

MACOS

  1. Five Eyes Intelligence agencies warn of popular hacking tools
  2. Vulnerability allows hijacking of software installed in macOS

Threat report for 2018-10-12

DATA BREACH & DATA LOSS

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users
  2. Pentagon Reveals Cyber Breach of Travel Records
  3. NEW BETABOT CAMPAIGN UNDER THE MICROSCOPE
  4. Detecting Malicious Campaigns with Machine Learning
  5. Fitmetrix fitness software company may have exposed millions of customer records
  6. Fake browser update seeks to compromise more MikroTik routers
  7. Phishing Campaign uses Hijacked Emails to Deliver URSNIF by Replying to Ongoing Threads
  8. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel
  9. Mindbody’s FitMetrix leaked millions of Users’ Personal Details
  10. Is Google Sync a Vector for Data Breaches?
  11. Facebook Revises Data Breach Impact Downward, Provides New Details
  12. How #livechatsoftware leak personal #employeedata?
  13. ​Labor seeks updated My Health Record legislation to prevent privatisation

DENIAL-OF-SERVICE

  1. 'The Nuke Loop' is Fallout 76's endgame, lead designer explains
  2. UK's NCSC to monitor internet routing to stop DDoS and hijacks

MALVERTISING

Nil

PHISHING

  1. Threat Announcement: Phishing Sites Detected on Emoji Domains
  2. Phishing Campaign uses Hijacked Emails to Deliver URSNIF by Replying to Ongoing Threads
  3. An Examination of a Phishing Kit Dubbed Luis
  4. Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
  5. Largest Cyber Attack Against Iceland Driven by Complex Phishing Scheme
  6. Spring Security With Radius Login

WEB DEFACEMENT

Nil

BOTNET

  1. Call of Duty: Black Ops 4 welcomes launch with new Blackout and Zombies trailers

RANSOMWARE

  1. The Week in Ransomware - October 12th 2018 - NotPetya, GandCrab, and More
  2. New @ESET research finds APT group dubbed #TeleBots was behind #Industroyer #malware attacks, #NotPetya #ransomware outbreaks, and a recent Exaramel
  3. GandCrab ransomware operators team up with crypter service
  4. GandCrab Ransomware Partners With Crypter Service
  5. This is how much the WannaCry ransomware attack cost the NHS

CRYPTOMINING & CRYPTOCURRENCIES

  1. Almost 12K MikroTik Routers Are Hunting Around for Cryptojacking Opportunities
  2. Three Industries That Blockchain Will Impact the Most
  3. Obfuscated JavaScript Cryptominer
  4. In 2008, @nokia dominated the mobile phone universe. Four years later, the company was on the verge of extinction. Discover
  5. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million
  6. Cryptomining software is hidden as Flash update

MALWARE

  1. Detecting Malicious Campaigns with Machine Learning
  2. Fake Adobe Flash Updates Hide Malicious Crypto Miners
  3. .@ThreatFabric researchers uncovered an #Android malware, #MysteryBot, which uses overlay attacks to avoid detection. Learn how this #malware affects @Google's
  4. New @ESET research finds APT group dubbed #TeleBots was behind #Industroyer #malware attacks, #NotPetya #ransomware outbreaks, and a recent Exaramel
  5. Researchers at the 2018 @RSAConference discussed #stegware: @malware that uses #steganography. Discover how this works with expert @lewisnic.
  6. Hackers targeting Drupal vulnerabilities to install the Shellbot Backdoor
  7. Researchers at Cisco Talos (@TalosSecurity) recently discovered #GravityRAT, a remote access #Trojan. Discover how this RAT can check for
  8. GPlayed trojan seeks to play users out of their data
  9. This Trojan masquerades as Google Play to hide on your phone in plain sight
  10. Marion County Jail’s Reporting System Fall Prey to Virus Attack
  11. Some 10% of user-reported emails malicious
  12. ThreatFabric on stage @bsidesdelft talking about the evolution of
  13. Fortnite for Android Released, But Make Sure You Don't Download Malware

EXPLOIT

  1. PoC exploit for Windows Shell RCE released

VULNERABILITY

  1. Windows 10 October 2018 Update: Release – Halt – Bug Identified – Fix!
  2. FDA Issues Warning about Security Vulnerabilities in Pacemaker Programmers
  3. Microsoft Zero-Day Patch for JET Bug Incomplete, Claims Firm
  4. Proof-of-Concept Available for Edge Remote Code Execution Vulnerability
  5. Facebook States 30 Million People Affected by Last Month's "View As" Bug
  6. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  7. What's keeping the #CISO up at night? The vulnerabilities caused by third-party vendors, finds @forrester research. 65% of organizations say
  8. Micropatch Released to Correct Partially Fixed JET DB Engine RCE Vulnerability
  9. FDA warns users of cyber vulnerability in pacemaker programmers
  10. Ryan Kalember, Senior VP of #Cybersecurity Strategy at Proofpoint, discussing why humans are a company’s biggest cybersecurity vulnerability.
  11. Sony Patched Three Critical Vulnerabilities In Smart TV Bravia
  12. Hackers targeting Drupal vulnerabilities to install the Shellbot Backdoor
  13. Now, watch this... Network time protocol bugs sting Juniper operating system
  14. DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More
  15. Facebook's WhatsApp says it has fixed a video call security bug that let hackers hijack accounts.
  16. Vulnerability allows hijacking of software installed in macOS
  17. Senator asked Google to explain why the revealing of the Google+ vulnerability was postponed
  18. Proof-of-concept code published for Microsoft Edge remote code execution bug

Region brief for 2018-10-12

ASIA

  1. Cyber News Rundown: Windows 10 Update Deletes Files
  2. Threat Brief: FASTCash ATM Cash Out Tactics
  3. Five Eyes Intelligence agencies warn of popular hacking tools
  4. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million

OCEANIA

  1. Five Eyes Intelligence agencies warn of popular hacking tools
  2. ​Labor seeks updated My Health Record legislation to prevent privatisation

NORTH AMERICA

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users
  2. Pentagon Reveals Cyber Breach of Travel Records
  3. FDA Issues Warning about Security Vulnerabilities in Pacemaker Programmers
  4. Detecting Malicious Campaigns with Machine Learning
  5. Fake browser update seeks to compromise more MikroTik routers
  6. Five Eyes Intelligence agencies warn of popular hacking tools
  7. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million
  8. DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More
  9. Senator asked Google to explain why the revealing of the Google+ vulnerability was postponed

SOUTH AMERICA

Nil

EUROPE

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users
  2. Almost 12K MikroTik Routers Are Hunting Around for Cryptojacking Opportunities
  3. Cyber News Rundown: Windows 10 Update Deletes Files
  4. Fake browser update seeks to compromise more MikroTik routers
  5. An Examination of a Phishing Kit Dubbed Luis
  6. Five Eyes Intelligence agencies warn of popular hacking tools
  7. UK's NCSC to monitor internet routing to stop DDoS and hijacks
  8. Largest Cyber Attack Against Iceland Driven by Complex Phishing Scheme

AFRICA

Nil

Sector brief for 2018-10-12

HEALTHCARE

  1. FDA warns users of cyber vulnerability in pacemaker programmers

TRANSPORT

  1. Five Eyes Intelligence agencies warn of popular hacking tools

BANKING & FINANCE

  1. Pentagon Reveals Cyber Breach of Travel Records
  2. No Cookies for CartThief, a New Magecart Variant
  3. An Examination of a Phishing Kit Dubbed Luis
  4. Mindbody’s FitMetrix leaked millions of Users’ Personal Details
  5. Threat Brief: FASTCash ATM Cash Out Tactics
  6. Five Eyes Intelligence agencies warn of popular hacking tools
  7. Payment skimmers sneaking on to websites via third party code
  8. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million
  9. This is how much the WannaCry ransomware attack cost the NHS
  10. ThreatFabric on stage @bsidesdelft talking about the evolution of

INFORMATION & TELECOMMUNICATION

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users
  2. Detecting Malicious Campaigns with Machine Learning
  3. Almost 12K MikroTik Routers Are Hunting Around for Cryptojacking Opportunities
  4. Cyber News Rundown: Windows 10 Update Deletes Files
  5. Facebook States 30 Million People Affected by Last Month's "View As" Bug
  6. Fake browser update seeks to compromise more MikroTik routers
  7. An Examination of a Phishing Kit Dubbed Luis
  8. Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
  9. Facebook Revises Data Breach Impact Downward, Provides New Details
  10. Facebook's WhatsApp says it has fixed a video call security bug that let hackers hijack accounts.
  11. ThreatFabric on stage @bsidesdelft talking about the evolution of

FOOD

Nil

WATER

Nil

ENERGY

Nil

GOVERNMENT & PUBLIC SERVICE

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users

Daily brief for 2018-10-12

ASIA

  1. Cyber News Rundown: Windows 10 Update Deletes Files
  2. Threat Brief: FASTCash ATM Cash Out Tactics
  3. Five Eyes Intelligence agencies warn of popular hacking tools
  4. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million

WORLD

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users
  2. Pentagon Reveals Cyber Breach of Travel Records
  3. FDA Issues Warning about Security Vulnerabilities in Pacemaker Programmers
  4. Detecting Malicious Campaigns with Machine Learning
  5. Almost 12K MikroTik Routers Are Hunting Around for Cryptojacking Opportunities
  6. Cyber News Rundown: Windows 10 Update Deletes Files
  7. Fake browser update seeks to compromise more MikroTik routers
  8. An Examination of a Phishing Kit Dubbed Luis
  9. Five Eyes Intelligence agencies warn of popular hacking tools
  10. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million
  11. DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More
  12. UK's NCSC to monitor internet routing to stop DDoS and hijacks
  13. Largest Cyber Attack Against Iceland Driven by Complex Phishing Scheme
  14. ​Labor seeks updated My Health Record legislation to prevent privatisation
  15. Senator asked Google to explain why the revealing of the Google+ vulnerability was postponed

ATTACKS

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users
  2. Pentagon Reveals Cyber Breach of Travel Records
  3. NEW BETABOT CAMPAIGN UNDER THE MICROSCOPE
  4. Detecting Malicious Campaigns with Machine Learning
  5. Fitmetrix fitness software company may have exposed millions of customer records
  6. Fake browser update seeks to compromise more MikroTik routers
  7. Threat Announcement: Phishing Sites Detected on Emoji Domains
  8. Phishing Campaign uses Hijacked Emails to Deliver URSNIF by Replying to Ongoing Threads
  9. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel
  10. An Examination of a Phishing Kit Dubbed Luis
  11. Mindbody’s FitMetrix leaked millions of Users’ Personal Details
  12. Is Google Sync a Vector for Data Breaches?
  13. Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
  14. Facebook Revises Data Breach Impact Downward, Provides New Details
  15. How #livechatsoftware leak personal #employeedata?
  16. Largest Cyber Attack Against Iceland Driven by Complex Phishing Scheme
  17. Spring Security With Radius Login
  18. ​Labor seeks updated My Health Record legislation to prevent privatisation

THREATS

  1. Windows 10 October 2018 Update: Release – Halt – Bug Identified – Fix!
  2. FDA Issues Warning about Security Vulnerabilities in Pacemaker Programmers
  3. Detecting Malicious Campaigns with Machine Learning
  4. Almost 12K MikroTik Routers Are Hunting Around for Cryptojacking Opportunities
  5. The Week in Ransomware - October 12th 2018 - NotPetya, GandCrab, and More
  6. Microsoft Zero-Day Patch for JET Bug Incomplete, Claims Firm
  7. Three Industries That Blockchain Will Impact the Most
  8. Proof-of-Concept Available for Edge Remote Code Execution Vulnerability
  9. Facebook States 30 Million People Affected by Last Month's "View As" Bug
  10. Fake Adobe Flash Updates Hide Malicious Crypto Miners
  11. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  12. What's keeping the #CISO up at night? The vulnerabilities caused by third-party vendors, finds @forrester research. 65% of organizations say
  13. Micropatch Released to Correct Partially Fixed JET DB Engine RCE Vulnerability
  14. Obfuscated JavaScript Cryptominer
  15. FDA warns users of cyber vulnerability in pacemaker programmers
  16. In 2008, @nokia dominated the mobile phone universe. Four years later, the company was on the verge of extinction. Discover
  17. .@ThreatFabric researchers uncovered an #Android malware, #MysteryBot, which uses overlay attacks to avoid detection. Learn how this #malware affects @Google's
  18. New @ESET research finds APT group dubbed #TeleBots was behind #Industroyer #malware attacks, #NotPetya #ransomware outbreaks, and a recent Exaramel
  19. Ryan Kalember, Senior VP of #Cybersecurity Strategy at Proofpoint, discussing why humans are a company’s biggest cybersecurity vulnerability.
  20. Researchers at the 2018 @RSAConference discussed #stegware: @malware that uses #steganography. Discover how this works with expert @lewisnic.
  21. Sony Patched Three Critical Vulnerabilities In Smart TV Bravia
  22. Hackers targeting Drupal vulnerabilities to install the Shellbot Backdoor
  23. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million
  24. GandCrab ransomware operators team up with crypter service
  25. Now, watch this... Network time protocol bugs sting Juniper operating system
  26. GandCrab Ransomware Partners With Crypter Service
  27. This is how much the WannaCry ransomware attack cost the NHS
  28. Researchers at Cisco Talos (@TalosSecurity) recently discovered #GravityRAT, a remote access #Trojan. Discover how this RAT can check for
  29. GPlayed trojan seeks to play users out of their data
  30. This Trojan masquerades as Google Play to hide on your phone in plain sight
  31. DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More
  32. Facebook's WhatsApp says it has fixed a video call security bug that let hackers hijack accounts.
  33. Marion County Jail’s Reporting System Fall Prey to Virus Attack
  34. Some 10% of user-reported emails malicious
  35. Cryptomining software is hidden as Flash update
  36. ThreatFabric on stage @bsidesdelft talking about the evolution of
  37. Vulnerability allows hijacking of software installed in macOS
  38. Fortnite for Android Released, But Make Sure You Don't Download Malware
  39. Senator asked Google to explain why the revealing of the Google+ vulnerability was postponed
  40. Proof-of-concept code published for Microsoft Edge remote code execution bug

CRIME

  1. Facebook Data Breach Update: attackers accessed data of 29 Million users
  2. Facebook States 30 Million People Affected by Last Month's "View As" Bug
  3. Fake browser update seeks to compromise more MikroTik routers
  4. Threat Brief: FASTCash ATM Cash Out Tactics
  5. Hackers targeting Drupal vulnerabilities to install the Shellbot Backdoor
  6. 360 Total Security has intercepted more than 50,000 Clipboard Wallet Hijacker attacks, helping users recover over 40 million
  7. PoC exploit for Windows Shell RCE released
  8. DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More
  9. UK's NCSC to monitor internet routing to stop DDoS and hijacks
  10. Largest Cyber Attack Against Iceland Driven by Complex Phishing Scheme

POLITICS

Nil

Oct 12, 2018

APT report for 2018-10-11

TRANSNATIONAL / UNKNOWN

  1. Magecart Card-Stealing Gang Hits 'Shopper Approved' Plug-In
  2. Microsoft October Patch Tuesday fixed Win32k privilege vulnerability that used in targeted attacks
  3. New Gallmaker APT group eschews malware in cyber espionage campaigns

CHINA

  1. Cybersecurity Authorities Issue Alert About Publicly Available Hacking Tools
  2. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  3. Threats in the Netherlands

INDIA

  1. The Reality of Self-Driving Cars and the Regulatory Hurdles

NORTH KOREA

  1. Reaper Group Uses New Malware to Deploy RAT
  2. Threats in the Netherlands

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

  1. Threats in the Netherlands

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Exaramel Malware Links Industroyer ICS malware and NotPetya wiper
  2. Researchers link tools used in NotPetya and Ukraine grid hacks
  3. What would happen if an attack interrupted a country’s power supply?
  4. Threats in the Netherlands

SERBIA

Nil

UKRAINE

  1. Threats in the Netherlands

Platform report for 2018-10-11

WINDOWS

  1. Exaramel Malware Links Industroyer ICS malware and NotPetya wiper
  2. Cybersecurity Authorities Issue Alert About Publicly Available Hacking Tools
  3. PoC Code Available for Microsoft Edge Remote Code Execution Bug
  4. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  5. Researchers link tools used in NotPetya and Ukraine grid hacks
  6. Fake Flash Updaters Push Cryptocurrency Miners
  7. Adobe patches critical flaws in many of its software offerings
  8. Qihoo 360’s precise analysis of ransomware for September
  9. Microsoft October Patch Tuesday fixed Win32k privilege vulnerability that used in targeted attacks
  10. New Gallmaker APT group eschews malware in cyber espionage campaigns
  11. GPlayed Trojan - .Net playing with Google Market
  12. Avast 2019: Extends Artificial Intelligence Technology to Block Advanced Phishing Attacks for Enhanced Consumer Security
  13. JSRAT – Secret Command and Control Channel Backdoor to Control Victims Machine Using JavaScript

LINUX

  1. Exaramel Malware Links Industroyer ICS malware and NotPetya wiper
  2. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  3. Adobe patches critical flaws in many of its software offerings
  4. JSRAT – Secret Command and Control Channel Backdoor to Control Victims Machine Using JavaScript

UNIX

Nil

ANDROID

  1. GPlayed Android Trojan Can Wipe Your Device, Steal Data, Make Calls, Send SMS
  2. Adaptable, All-in-One Android Trojan Shows the Future of Malware
  3. Talos: Android trojan resembling Play Store installs sophisticated spyware
  4. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  5. GPlayed trojan – .Net playing with Google Market
  6. New Android Trojan Gplayed Adapts to Attacker's Needs
  7. All WhatsApp Users Must Update: Zero Day Bug Found in WhatsApp
  8. GPlayed Trojan - .Net playing with Google Market
  9. A simple videocall could compromise your WhatsApp account

IOS

  1. Talos: Android trojan resembling Play Store installs sophisticated spyware
  2. All WhatsApp Users Must Update: Zero Day Bug Found in WhatsApp
  3. A simple videocall could compromise your WhatsApp account

MACOS

  1. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  2. Adobe patches critical flaws in many of its software offerings

Threat report for 2018-10-11

DATA BREACH & DATA LOSS

  1. The BEC List: Helping Thwart Business Email Compromise through Collaboration
  2. Personal data for coffee. What’s the risk? | Avast
  3. The EU and the US have investigated on data breaches on the Google+
  4. FitMetrix user data exposed via passwordless ElasticSearch server cluster
  5. Apple has formed a partnership with lyrics database provider Genius
  6. Defending Against Business Email Compromise Attacks
  7. Heathrow Airport, the busiest airport in the United Kingdom, has been fined £120,000 (about $158,173) following a data breach caused
  8. Palo Alto Networks Uncovers Flash Updater Cryptojacking Campaign
  9. Gemalto reports that 4.6 billion record leaked in the first half of 2018
  10. A new database with information on every shooting at a school in the last 50 years is now available publicly
  11. New Gallmaker APT group eschews malware in cyber espionage campaigns
  12. Ghostdns Attack Compromised Over 100K Routers
  13. A simple videocall could compromise your WhatsApp account
  14. Mingis on Tech: Data breaches and the rise of 'surveillance capitalism'
  15. Mingis on Tech: Data breaches in a world of 'surveillance capitalism'

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. California Bill Increases Default Password Security
  2. Cofense Report Reveals 10 Percent of User-Reported Emails Across Key Industries are Malicious, Over Half Tied to Credential Phishing
  3. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  4. Avast 2019: Extends Artificial Intelligence Technology to Block Advanced Phishing Attacks for Enhanced Consumer Security
  5. AVG 2019 now includes enhanced phishing threat detection

WEB DEFACEMENT

  1. Italian Police Finally Identified 25-Year-old Italian Hacker who have Defaced NASA Websites

BOTNET

Nil

RANSOMWARE

  1. Qihoo 360’s precise analysis of ransomware for September
  2. Costly cryptojacking overtakes ransomware in the enterprise threat stakes

CRYPTOMINING & CRYPTOCURRENCIES

  1. XMRig Cryptocurrency Miner Camouflages Itself as a Flash Updater
  2. Cops Arrest Infamous SIM Swapper Who Stole Crypto Currency
  3. Cops Arrest Infamous SIM Swapper Who Allegedly Stole $14 Million in Cryptocurrency
  4. Cryptomining malware discovered masquerading as Flash updates
  5. Fake Flash Updaters Push Cryptocurrency Miners
  6. Hackers Abusing Legitimate Googlebot Services to Inject Cryptomining Malware
  7. Researchers from @alienvault found a new #cryptocurrency mining malware -- dubbed #MassMiner -- that infects systems across the web. Learn
  8. Crypto-mining malware poses as Flash updates
  9. Dublin Information Sec: Protect your firm from 'Gold Rush' #cryptocurrency scammers: https://www.independent.ie/business/dublin-information-sec/dublin-information-sec-protect-your-firm-from-gold-rush-cryptocurrency-scammers-37286913.html … ( via @jimmychappell )

MALWARE

  1. Exaramel Malware Links Industroyer ICS malware and NotPetya wiper
  2. GPlayed Android Trojan Can Wipe Your Device, Steal Data, Make Calls, Send SMS
  3. Hackers Exploit Drupalgeddon2 to Install Backdoor
  4. Adaptable, All-in-One Android Trojan Shows the Future of Malware
  5. Talos: Android trojan resembling Play Store installs sophisticated spyware
  6. Most Malware Arrives Via Email
  7. Fake Adobe Flash Updates Hide Malicious Crypto Miners
  8. .@TrendMicro researchers discovered a malicious #ChromeExtension spreading #malware. Learn more with expert @lewisnic.
  9. GPlayed trojan – .Net playing with Google Market
  10. Cryptomining malware discovered masquerading as Flash updates
  11. This cryptojacking mining malware pretends to be a Flash update
  12. Hackers Abusing Legitimate Googlebot Services to Inject Cryptomining Malware
  13. Reaper Group Uses New Malware to Deploy RAT
  14. Cofense Report Reveals 10 Percent of User-Reported Emails Across Key Industries are Malicious, Over Half Tied to Credential Phishing
  15. Exaramel Malware Reinforces Link Between Industroyer and NotPetya
  16. New TeleBots backdoor: First evidence linking Industroyer to NotPetya
  17. New TeleBots backdoor: First evidence linking Industroyer to NotPetya
  18. New Android Trojan Gplayed Adapts to Attacker's Needs
  19. Researchers from @alienvault found a new #cryptocurrency mining malware -- dubbed #MassMiner -- that infects systems across the web. Learn
  20. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  21. Crypto-mining malware poses as Flash updates
  22. Who needs custom malware? 'Govt-backed' Gallmaker spy crew uses off-the-shelf wares
  23. Worker perks flinger Sodexo pulls Engage website after malware smackdown
  24. New Backdoor Ties NotPetya and Industroyer to TeleBots Group
  25. .@FarsightSecInc's @paulvixie says his company's new research into domain name lifespans and causes of death shows the need for new
  26. "Help! I have a #computer worm..oh wait is it a computer #virus?" These terms are often used interchangeably, but have
  27. The attached file promptly infects Peter’s laptop with the RAT, remote access trojan. It only takes about an hour from
  28. New Gallmaker APT group eschews malware in cyber espionage campaigns
  29. GPlayed Trojan - .Net playing with Google Market
  30. Canada-Based Restaurant Chain Hit with Malware Attack
  31. Hackers Use Hijacked Email Address To Send Malware as a Reply to Existing Email Thread
  32. JSRAT – Secret Command and Control Channel Backdoor to Control Victims Machine Using JavaScript
  33. How to Defeat Malicious Everything as-a-Service

EXPLOIT

  1. Hackers Exploit Drupalgeddon2 to Install Backdoor
  2. PoC Code Available for Microsoft Edge Remote Code Execution Bug

VULNERABILITY

  1. Multiple Vulnerabilities Dicovered In RouterOS That Affected MikroTik Routers
  2. Senate seeks internal memo on Google+ vulnerability
  3. Slow disclosure of Google+ flaw draws attention of senators
  4. PoC Code Available for Microsoft Edge Remote Code Execution Bug
  5. .@Google Firebase's lack of #DatabaseSecurity and inadequate #BackendDevelopment led to #DataLeaks and vulnerabilities, including HospitalGown. Learn more about this
  6. Network Time Protocol Bugs Sting Juniper Operating System
  7. Juniper Networks provides dozens of fix for vulnerabilities in Junos OS
  8. Audit Finds No Critical Flaws in Firefox Update System
  9. [SingCERT] Alert on 12 Critical Microsoft Vulnerabilities for October 2018 Patch Tuesday
  10. A patched #MikroTik router vulnerability amps up severity rating as @TenableSecurity researchers find new potential exploits with more critical consequences.
  11. Juniper fixes 30+ vulnerabilities in its routing, switching devices
  12. Adobe patches critical flaws in many of its software offerings
  13. Update now! Microsoft fixes 49 bugs, 12 are critical
  14. All WhatsApp Users Must Update: Zero Day Bug Found in WhatsApp
  15. VMware issues advisory for a DoS vulnerability
  16. .@TenableSecurity found new exploits of an already patched #MikroTik router vulnerability that could enable hackers to launch #RemoteCode execution attacks.
  17. Juniper Patches Serious Flaws in Junos OS
  18. Microsoft October Patch Tuesday fixed Win32k privilege vulnerability that used in targeted attacks
  19. Four Critical Flaws Patched In Adobe Digital Edition

Region brief for 2018-10-11

ASIA

  1. Cybersecurity Authorities Issue Alert About Publicly Available Hacking Tools
  2. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  3. What would happen if an attack interrupted a country’s power supply?
  4. Reaper Group Uses New Malware to Deploy RAT
  5. Threats in the Netherlands

OCEANIA

  1. Cybersecurity Authorities Issue Alert About Publicly Available Hacking Tools
  2. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide

NORTH AMERICA

  1. Cybersecurity Authorities Issue Alert About Publicly Available Hacking Tools
  2. The Reality of Self-Driving Cars and the Regulatory Hurdles
  3. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  4. The EU and the US have investigated on data breaches on the Google+
  5. Researchers link tools used in NotPetya and Ukraine grid hacks
  6. What would happen if an attack interrupted a country’s power supply?
  7. Cops Arrest Infamous SIM Swapper Who Allegedly Stole $14 Million in Cryptocurrency
  8. Microsoft October Patch Tuesday fixed Win32k privilege vulnerability that used in targeted attacks
  9. Threats in the Netherlands
  10. Italian Police Finally Identified 25-Year-old Italian Hacker who have Defaced NASA Websites
  11. Canada-Based Restaurant Chain Hit with Malware Attack

SOUTH AMERICA

  1. Ghostdns Attack Compromised Over 100K Routers

EUROPE

  1. Exaramel Malware Links Industroyer ICS malware and NotPetya wiper
  2. Cybersecurity Authorities Issue Alert About Publicly Available Hacking Tools
  3. Adaptable, All-in-One Android Trojan Shows the Future of Malware
  4. Talos: Android trojan resembling Play Store installs sophisticated spyware
  5. AA18-284A: Publicly Available Tools Seen in Cyber Incidents Worldwide
  6. Researchers link tools used in NotPetya and Ukraine grid hacks
  7. What would happen if an attack interrupted a country’s power supply?
  8. Reaper Group Uses New Malware to Deploy RAT
  9. Worker perks flinger Sodexo pulls Engage website after malware smackdown
  10. Defending Against Business Email Compromise Attacks
  11. Heathrow Airport, the busiest airport in the United Kingdom, has been fined £120,000 (about $158,173) following a data breach caused
  12. Threats in the Netherlands
  13. New Gallmaker APT group eschews malware in cyber espionage campaigns
  14. Italian Police Finally Identified 25-Year-old Italian Hacker who have Defaced NASA Websites
  15. GPlayed Trojan - .Net playing with Google Market

AFRICA

Nil