Oct 20, 2018

APT report for 2018-10-19

TRANSNATIONAL / UNKNOWN

Nil

CHINA

  1. Secret Comment Crew Code Spotted in New Attack
  2. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  3. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  4. Latest Hacking News Podcast
  5. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  6. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

INDIA

Nil

NORTH KOREA

  1. "World-renowned cybersecurity unit #GroupIB is prepping to release its annual report on trends in hi-tech cybercrime...Group-IB expects the number of

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. GreyEnergy
  2. GreyEnergy threat group detected attacking high-value targets
  3. .@ESET researchers claim the #GreyEnergy group has taken up the mantle of ICS-targeting #BlackEnergy, but @MalwareJake said the evidence wasn't
  4. .@ESET researchers claim a new threat group called #GreyEnergy is the successor to #BlackEnergy, but experts are unsure if the
  5. Week in security with Tony Anscombe

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-19

WINDOWS

  1. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  2. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  3. Inside Safari Extensions | Malware’s Golden Key to User Data

LINUX

  1. VestaCP users warned about possible server compromise

UNIX

Nil

ANDROID

  1. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

IOS

Nil

MACOS

  1. Inside Safari Extensions | Malware’s Golden Key to User Data

Threat report for 2018-10-19

DATA BREACH & DATA LOSS

  1. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  2. Campaign 2018: Artificial intelligence is automating attacks on political campaigns
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  5. Campaign 2018: Artificial Intelligence Is Automating Attacks On Political Campaigns
  6. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  7. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  8. US Voter Leak Hits Tea Party Organization
  9. VestaCP users warned about possible server compromise
  10. jQuery File Upload Plugin Vulnerable for 8 Years and Only Hackers Knew
  11. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  12. Campaign launched to protect ethical hackers in the Americas
  13. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  14. Facepunch 2016 breach exposed 343,000 users
  15. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  16. ADHA's non-process for releasing My Health Record data revealed
  17. MikroTik routers targeted by cryptomining campaign | Avast
  18. Vulnerability in Tumblr could have compromise users’ account data
  19. Poor security practices and access to hacking services are making it easy for #cybercriminals to compromise business email, research reveals:

DENIAL-OF-SERVICE

  1. New DDoS Malware Infects Open-Source Web Hosting Software
  2. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'
  3. DDoS Attack Prevention Method on Your Enterprise’s Systems – A Detailed Report

MALVERTISING

Nil

PHISHING

  1. Password and credit card-stealing Azorult malware adds new tricks
  2. AISA 2018: Hunting for phishing kits
  3. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.

WEB DEFACEMENT

Nil

BOTNET

  1. Ok now, which one of you is running this Twitter botnet of fake infosec professionals?

RANSOMWARE

  1. City Pays $2,000 in Computer Ransomware Attack
  2. Water Utility ONWASA Hit by Ransomware Attack
  3. Madison County Computer Systems Face a Ransomware Attack
  4. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  5. Top 4 tips to avoid getting hit by ransomware
  6. Onslow County Utility Hit with Ransomware Attack

CRYPTOMINING & CRYPTOCURRENCIES

  1. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  2. MikroTik routers targeted by cryptomining campaign | Avast
  3. Fraudster Targets Cryptocurrency Wallets with a Variety of Info Stealers

MALWARE

  1. Small or Big Business, Malware Hits Everyone
  2. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Password and credit card-stealing Azorult malware adds new tricks
  5. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  6. New DDoS Malware Infects Open-Source Web Hosting Software
  7. America’s First: US Leads in Global Malware C2 Distribution
  8. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  9. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  10. The Golden Age of Malware
  11. LuminosityLink RAT author sentenced to 30 years in prison
  12. Inside Safari Extensions | Malware’s Golden Key to User Data
  13. .@TrendMicro researchers discovered a malicious #ChromeExtension spreading #malware. Learn more with expert @lewisnic.
  14. ADHA's non-process for releasing My Health Record data revealed
  15. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  16. Canberra competence shines in day of PM domain lapses and tortured analogies

EXPLOIT

  1. NSA-Linked 'DarkPulsar' Exploit Tool Detailed

VULNERABILITY

  1. libssh Vulnerability: Is WatchGuard Affected?
  2. 0-Day in jQuery Plugin Impacts Thousands of Applications
  3. Fixing a CSRF Vulnerability
  4. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  5. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  6. Drupal dev team fixed Remote Code Execution flaws in the popular CMS
  7. Flaw in Libssh Grants Admin Control to Servers
  8. FreeRTOS Vulnerabilities Expose Many Systems to Attacks
  9. Linksys E Series Vulnerabilities
  10. Google warns Apple: Missing bugs in your security bulletins are 'disincentive to patch'
  11. jQuery Zero-Day Was Exploited For At Least Three Years
  12. A Serious Security Flaw Found in LibSSH
  13. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  14. Splunk addressed several vulnerabilities in Enterprise and Light products
  15. Serious D-Link router security flaws may never be patched
  16. Scams and flaws: Why we get duped
  17. Remote Code Execution Flaws Patched in Drupal
  18. Tumblr bug bounty program detects flaw, no user info lost
  19. .@Google Firebase's lack of #DatabaseSecurity and inadequate #BackendDevelopment led to #DataLeaks and vulnerabilities, including HospitalGown. Learn more about this
  20. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  21. Critical Flaw Found in Streaming Library Used by VLC and Other Media Players
  22. Drupal Remote Code Execution Vulnerability Alert
  23. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  24. Splunk Patches Several Flaws in Enterprise, Light Products
  25. Vulnerability in Tumblr could have compromise users’ account data
  26. Three critical vulnerabilities can be chained to take full control of D-Link routers
  27. Zero-day in popular jQuery plugin actively exploited for at least three years
  28. Tumblr serious vulnerability can reveal everyone information
  29. Critical Flaws Found in Amazon FreeRTOS IoT Operating System

Region brief for 2018-10-19

ASIA

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  2. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. Secret Comment Crew Code Spotted in New Attack
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands

OCEANIA

  1. AISA 2018: Hunting for phishing kits
  2. ADHA's non-process for releasing My Health Record data revealed
  3. Authorities seize properties of creators of “Infamous” cheat code, for GTA V
  4. Canberra competence shines in day of PM domain lapses and tortured analogies

NORTH AMERICA

  1. Small or Big Business, Malware Hits Everyone
  2. America’s First: US Leads in Global Malware C2 Distribution
  3. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  4. US Voter Leak Hits Tea Party Organization
  5. Secret Comment Crew Code Spotted in New Attack
  6. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  7. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  8. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  9. Inside Safari Extensions | Malware’s Golden Key to User Data
  10. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

SOUTH AMERICA

Nil

EUROPE

  1. Small or Big Business, Malware Hits Everyone
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  4. GreyEnergy
  5. Onslow County Utility Hit with Ransomware Attack
  6. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  7. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  8. Three critical vulnerabilities can be chained to take full control of D-Link routers
  9. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

AFRICA

  1. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

Sector brief for 2018-10-19

HEALTHCARE

  1. Small or Big Business, Malware Hits Everyone
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Secret Comment Crew Code Spotted in New Attack

TRANSPORT

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware

BANKING & FINANCE

  1. Small or Big Business, Malware Hits Everyone
  2. City Pays $2,000 in Computer Ransomware Attack
  3. Madison County Computer Systems Face a Ransomware Attack
  4. Password and credit card-stealing Azorult malware adds new tricks
  5. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  6. AISA 2018: Hunting for phishing kits
  7. US Voter Leak Hits Tea Party Organization
  8. Secret Comment Crew Code Spotted in New Attack
  9. Inside Safari Extensions | Malware’s Golden Key to User Data
  10. Critical Flaws Found in Amazon FreeRTOS IoT Operating System

INFORMATION & TELECOMMUNICATION

  1. Fixing a CSRF Vulnerability
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Flaw in Libssh Grants Admin Control to Servers
  4. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  5. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  6. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.
  7. Tumblr bug bounty program detects flaw, no user info lost
  8. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  9. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  10. Ok now, which one of you is running this Twitter botnet of fake infosec professionals?
  11. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  12. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  13. Inside Safari Extensions | Malware’s Golden Key to User Data
  14. Vulnerability in Tumblr could have compromise users’ account data
  15. Tumblr serious vulnerability can reveal everyone information
  16. Poor security practices and access to hacking services are making it easy for #cybercriminals to compromise business email, research reveals:

FOOD

Nil

WATER

  1. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

ENERGY

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  2. GreyEnergy
  3. Onslow County Utility Hit with Ransomware Attack

GOVERNMENT & PUBLIC SERVICE

  1. Small or Big Business, Malware Hits Everyone
  2. Madison County Computer Systems Face a Ransomware Attack
  3. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  4. US Voter Leak Hits Tea Party Organization
  5. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

Daily brief for 2018-10-19

ASIA

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  2. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. Secret Comment Crew Code Spotted in New Attack
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands

WORLD

  1. Small or Big Business, Malware Hits Everyone
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  4. GreyEnergy
  5. Onslow County Utility Hit with Ransomware Attack
  6. America’s First: US Leads in Global Malware C2 Distribution
  7. AISA 2018: Hunting for phishing kits
  8. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  9. US Voter Leak Hits Tea Party Organization
  10. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  11. Secret Comment Crew Code Spotted in New Attack
  12. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  13. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  14. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  15. Inside Safari Extensions | Malware’s Golden Key to User Data
  16. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  17. ADHA's non-process for releasing My Health Record data revealed
  18. Three critical vulnerabilities can be chained to take full control of D-Link routers
  19. Authorities seize properties of creators of “Infamous” cheat code, for GTA V
  20. Canberra competence shines in day of PM domain lapses and tortured analogies
  21. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

ATTACKS

  1. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  2. Campaign 2018: Artificial intelligence is automating attacks on political campaigns
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  5. Password and credit card-stealing Azorult malware adds new tricks
  6. Campaign 2018: Artificial Intelligence Is Automating Attacks On Political Campaigns
  7. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  8. AISA 2018: Hunting for phishing kits
  9. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  10. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  11. US Voter Leak Hits Tea Party Organization
  12. VestaCP users warned about possible server compromise
  13. jQuery File Upload Plugin Vulnerable for 8 Years and Only Hackers Knew
  14. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  15. Campaign launched to protect ethical hackers in the Americas
  16. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.
  17. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  18. Facepunch 2016 breach exposed 343,000 users
  19. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  20. ADHA's non-process for releasing My Health Record data revealed
  21. MikroTik routers targeted by cryptomining campaign | Avast
  22. Vulnerability in Tumblr could have compromise users’ account data
  23. Poor security practices and access to hacking services are making it easy for #cybercriminals to compromise business email, research reveals:

THREATS

  1. libssh Vulnerability: Is WatchGuard Affected?
  2. 0-Day in jQuery Plugin Impacts Thousands of Applications
  3. Small or Big Business, Malware Hits Everyone
  4. Fixing a CSRF Vulnerability
  5. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  6. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  7. City Pays $2,000 in Computer Ransomware Attack
  8. Drupal dev team fixed Remote Code Execution flaws in the popular CMS
  9. Water Utility ONWASA Hit by Ransomware Attack
  10. Madison County Computer Systems Face a Ransomware Attack
  11. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  12. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  13. Top 4 tips to avoid getting hit by ransomware
  14. Flaw in Libssh Grants Admin Control to Servers
  15. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  16. FreeRTOS Vulnerabilities Expose Many Systems to Attacks
  17. Linksys E Series Vulnerabilities
  18. Password and credit card-stealing Azorult malware adds new tricks
  19. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  20. Google warns Apple: Missing bugs in your security bulletins are 'disincentive to patch'
  21. Onslow County Utility Hit with Ransomware Attack
  22. jQuery Zero-Day Was Exploited For At Least Three Years
  23. New DDoS Malware Infects Open-Source Web Hosting Software
  24. A Serious Security Flaw Found in LibSSH
  25. America’s First: US Leads in Global Malware C2 Distribution
  26. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  27. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  28. Splunk addressed several vulnerabilities in Enterprise and Light products
  29. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  30. Serious D-Link router security flaws may never be patched
  31. Scams and flaws: Why we get duped
  32. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  33. Remote Code Execution Flaws Patched in Drupal
  34. The Golden Age of Malware
  35. Tumblr bug bounty program detects flaw, no user info lost
  36. LuminosityLink RAT author sentenced to 30 years in prison
  37. .@Google Firebase's lack of #DatabaseSecurity and inadequate #BackendDevelopment led to #DataLeaks and vulnerabilities, including HospitalGown. Learn more about this
  38. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  39. Critical Flaw Found in Streaming Library Used by VLC and Other Media Players
  40. Drupal Remote Code Execution Vulnerability Alert
  41. Inside Safari Extensions | Malware’s Golden Key to User Data
  42. .@TrendMicro researchers discovered a malicious #ChromeExtension spreading #malware. Learn more with expert @lewisnic.
  43. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  44. Splunk Patches Several Flaws in Enterprise, Light Products
  45. ADHA's non-process for releasing My Health Record data revealed
  46. MikroTik routers targeted by cryptomining campaign | Avast
  47. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  48. Fraudster Targets Cryptocurrency Wallets with a Variety of Info Stealers
  49. Vulnerability in Tumblr could have compromise users’ account data
  50. Three critical vulnerabilities can be chained to take full control of D-Link routers
  51. Zero-day in popular jQuery plugin actively exploited for at least three years
  52. Tumblr serious vulnerability can reveal everyone information
  53. Critical Flaws Found in Amazon FreeRTOS IoT Operating System
  54. Canberra competence shines in day of PM domain lapses and tortured analogies

CRIME

  1. NSA-Linked 'DarkPulsar' Exploit Tool Detailed
  2. Small or Big Business, Malware Hits Everyone
  3. Madison County Computer Systems Face a Ransomware Attack
  4. America’s First: US Leads in Global Malware C2 Distribution
  5. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  6. Scams and flaws: Why we get duped
  7. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.
  8. Secret Comment Crew Code Spotted in New Attack
  9. LuminosityLink RAT author sentenced to 30 years in prison
  10. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  11. "World-renowned cybersecurity unit #GroupIB is prepping to release its annual report on trends in hi-tech cybercrime...Group-IB expects the number of
  12. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

POLITICS

  1. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  2. GreyEnergy
  3. US Voter Leak Hits Tea Party Organization
  4. Secret Comment Crew Code Spotted in New Attack
  5. LuminosityLink RAT author sentenced to 30 years in prison
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. Latest Hacking News Podcast

Oct 19, 2018

APT report for 2018-10-18

TRANSNATIONAL / UNKNOWN

Nil

CHINA

  1. New APT Could Signal Reemergence of Notorious Comment Crew
  2. Tracking Tick Through Recent Campaigns Targeting East Asia
  3. Cyber Espionage Campaign Reuses Code from China's APT1
  4. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  5. Oceansalt Linked To Defunct Chinese APT Comment Crew
  6. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  7. Tracking Tick Through Recent Campaigns Targeting East Asia
  8. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  9. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  10. ‘Operation Oceansalt’ Delivers Wave After Wave
  11. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

INDIA

  1. New Pennsylvania Law Imposes Fine for Using Drones to Spy

NORTH KOREA

  1. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million
  2. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  3. Targeted attacks on crypto exchanges resulted in a loss of $882 million

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. GreyEnergy Spy APT Mounts Sophisticated Effort Against Critical Infrastructure
  4. GreyEnergy Potential Successor of BlackEnergy
  5. XBash Malware Security Advisory

SERBIA

Nil

UKRAINE

  1. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million

Platform report for 2018-10-18

WINDOWS

  1. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  2. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  3. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  4. Tracking Tick Through Recent Campaigns Targeting East Asia
  5. Ruby 2.4.5 released: 40 bug fixes
  6. XBash Malware Security Advisory

LINUX

  1. Open source web hosting software compromised with DDoS malware
  2. Ruby 2.4.5 released: 40 bug fixes
  3. XBash Malware Security Advisory
  4. VestaCP compromised in a new supply-chain attack
  5. VestaCP compromised in a new supply-chain attack

UNIX

Nil

ANDROID

  1. GPlayed Trojan - .Net Playing with Google Market

IOS

  1. Crypto Mining Malware Runs on iPhone
  2. Cryptomining Malware Attacks On iPhones Grew By 400%

MACOS

  1. Ruby 2.4.5 released: 40 bug fixes
  2. XBash Malware Security Advisory

Threat report for 2018-10-18

DATA BREACH & DATA LOSS

  1. 35 Million Records Of US Voters Data For Sale On The Dark Web
  2. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  3. Tracking Tick Through Recent Campaigns Targeting East Asia
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  6. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  7. Apple to US users: Here's how you can now see what personal data we hold on you
  8. Open source web hosting software compromised with DDoS malware
  9. Anthem Settles with OCR for $16M for 2015 Data Breach
  10. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  11. Hackers can use legitimate #AdminTools to compromise networks. Learn more about "living off the land" attacks from expert Michael Cobb
  12. Tumblr patches bug that could have exposed user data
  13. 12.5 Million Email Archives Exposed - Why would #cybercriminals go to a #darkweb market and pay for access when they
  14. #NetSpectre exploits leak data remotely via side-channel attacks. Learn how to use #ThreatModeling to stop speculative execution from expert Ed
  15. Tracking Tick Through Recent Campaigns Targeting East Asia
  16. McAfee researchers uncover ‘significant’ espionage campaign
  17. Apple to US users: Here's how you can now see what personal data we hold on you
  18. Tumblr Fixes Security Bug that Leaked Private Account Info
  19. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  20. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  21. VestaCP compromised in a new supply-chain attack
  22. VestaCP compromised in a new supply-chain attack
  23. Anthem to pay record £12M for 2015 data breach
  24. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  25. In the wake of numerous high-profile data breaches and privacy incidents, consumers are more aware and concerned than ever about
  26. Senate inquiry recommends locking down My Health Record by default
  27. Tumblr Vulnerability Exposed User Account Information
  28. The Equifax Hack Uploaded Files the Right Way
  29. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise
  30. SEO pollution campaign affects web searches related to EU midterm elections

DENIAL-OF-SERVICE

  1. Open source web hosting software compromised with DDoS malware
  2. Who and Why Make DDoS Attacks on The Site of Colleges and Universities ?
  3. A10 Networks provides cloud, Internet and gaming providers with 1 RU DDoS defense appliance

MALVERTISING

Nil

PHISHING

  1. The libssh “login with no password” bug – what you need to know [VIDEO]

WEB DEFACEMENT

Nil

BOTNET

  1. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  2. How does the resurgent VPNFilter botnet target victims?

RANSOMWARE

  1. 7 best practices for negotiating ransomware payments

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Adobe Flash update hides cryptocurrency malware
  2. Crooks are attempting to spread their cryptojacking malware to unsuspecting victims by disguising it as an update for Flash. The malicious
  3. Top 10 Blockchain Development Companies
  4. Crypto Mining Malware Runs on iPhone
  5. Cryptocurrency Miners Hiding As Flash Updates
  6. Cryptomining Malware Attacks On iPhones Grew By 400%
  7. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  8. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  9. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  10. LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
  11. Researcher Livestreams 51% Attack on Altcoin Blockchain
  12. Cryptojacking: A hidden cost for your company
  13. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers

MALWARE

  1. Fake Adobe Flash update hides cryptocurrency malware
  2. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  3. Open source web hosting software compromised with DDoS malware
  4. LuminosityLink Spyware Mastermind Gets 30 Months In The Clink
  5. Crooks are attempting to spread their cryptojacking malware to unsuspecting victims by disguising it as an update for Flash. The malicious
  6. Crypto Mining Malware Runs on iPhone
  7. GPlayed Trojan - .Net Playing with Google Market
  8. Cryptomining Malware Attacks On iPhones Grew By 400%
  9. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  10. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  11. LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
  12. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  13. XBash Malware Security Advisory
  14. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  15. Stegware: How is #malware using #steganography techniques to avoid detection?
  16. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  17. In order to distribute the attack payload, the code needs to be downloaded onto the PLCs & safety controllers. This

EXPLOIT

Nil

VULNERABILITY

  1. GitHub now warns devs about bugs that led to Equifax breach
  2. Flaws in telepresence robots allow hackers access to pictures, video feeds
  3. Branch.io Flaws may have affected as many as 685 million individuals
  4. Critical Remote Code Execution Vulnerabilities Patched by Drupal
  5. Code Execution Vulnerability Patched in Library Used by VLC, Other Media Players
  6. Flaws Open Telepresence Robots to Prying Eyes
  7. [SingCERT] Alert on Multiple Security Vulnerabilities in Oracle's Enterprise Products
  8. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  9. A newly disclosed #libSSH vulnerability could allow an attacker #AdminAccess to a server with little effort. By @MT_Heller
  10. Drupal addresses multiple critical flaws with latest release
  11. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  12. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  13. Wapiti – The Black Box Vulnerability Scanner for Web Applications
  14. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  15. The libssh “login with no password” bug – what you need to know [VIDEO]
  16. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  17. How Shodan helps identify ICS cybersecurity vulnerabilities
  18. Oracle extends its thanks to Qihoo 360 for fixing the vulnerabilities of Weblogic
  19. Tumblr patches bug that could have exposed user data
  20. [SingCERT] Alert on Linksys E Series Routers Vulnerabilities (CVE-2018-3953, CVE-2018-3954, and CVE-2018-3955)
  21. Apache Access Vulnerability Could Affect Thousands of Applications
  22. Last year, D-Link flubbed a router bug-fix, so it's back with total pwnage
  23. Party like it's 1989... SVGA code bug haunts VMware's house, lets guests flee to host OS
  24. Oracle Patches 301 Vulnerabilities in October Update
  25. Tumblr Fixes Security Bug that Leaked Private Account Info
  26. Ruby 2.4.5 released: 40 bug fixes
  27. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  28. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  29. New libSSH vulnerability gives root access to servers
  30. A 4-year-old #libSSH vulnerability can allow attackers to easily log in to servers with full administrative control, but it is
  31. The implications of the NetSpectre vulnerability
  32. #Shodan can be a helpful tool for security professionals to locate #ICSsecurity vulnerabilities. Expert Ernie Hayden explains how Shodan works
  33. Oracle security updates contains 45 critical-rated vulnerability
  34. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  35. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  36. Chaining three critical vulnerabilities allows takeover of D-Link routers
  37. Tumblr Fixes Critical Security Bug That Exposes User Account Details
  38. Tumblr Vulnerability Exposed User Account Information
  39. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise

Region brief for 2018-10-18

ASIA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. Tracking Tick Through Recent Campaigns Targeting East Asia
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  6. Oceansalt Linked To Defunct Chinese APT Comment Crew
  7. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million
  8. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  9. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  10. Oracle extends its thanks to Qihoo 360 for fixing the vulnerabilities of Weblogic
  11. Tracking Tick Through Recent Campaigns Targeting East Asia
  12. XBash Malware Security Advisory
  13. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  14. Targeted attacks on crypto exchanges resulted in a loss of $882 million
  15. The Equifax Hack Uploaded Files the Right Way
  16. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  17. ‘Operation Oceansalt’ Delivers Wave After Wave
  18. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

OCEANIA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  3. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  4. Senate inquiry recommends locking down My Health Record by default

NORTH AMERICA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. Branch.io Flaws may have affected as many as 685 million individuals
  3. 35 Million Records Of US Voters Data For Sale On The Dark Web
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. Apple to US users: Here's how you can now see what personal data we hold on you
  6. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  7. New Pennsylvania Law Imposes Fine for Using Drones to Spy
  8. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  9. Crypto Mining Malware Runs on iPhone
  10. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  11. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  12. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  13. Apple to US users: Here's how you can now see what personal data we hold on you
  14. XBash Malware Security Advisory
  15. Anthem to pay record £12M for 2015 data breach
  16. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  17. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  18. ‘Operation Oceansalt’ Delivers Wave After Wave
  19. SEO pollution campaign affects web searches related to EU midterm elections
  20. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

SOUTH AMERICA

Nil

EUROPE

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  4. GreyEnergy Potential Successor of BlackEnergy
  5. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  6. Chaining three critical vulnerabilities allows takeover of D-Link routers

AFRICA

  1. The author of the LuminosityLink RAT sentenced to 30 Months in Prison