Oct 21, 2018

APT report for 2018-10-20

TRANSNATIONAL / UNKNOWN

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. .@RobertMLee said #GreyEnergy is a threat, but people shouldn't conclude from @ESET research that the group will only target

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-20

WINDOWS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  2. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems

LINUX

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  2. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  3. Xerosploit – Toolkit to Perform MITM, Spoofing, DOS, Images Sniffing/Replacement, WD Attacks

UNIX

Nil

ANDROID

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

IOS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

MACOS

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

Threat report for 2018-10-20

DATA BREACH & DATA LOSS

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. If it's only able to leak data at 15 bits per hour, is #NetSpectre a serious threat? Learn more about
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  5. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel

DENIAL-OF-SERVICE

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

MALVERTISING

Nil

PHISHING

Nil

WEB DEFACEMENT

Nil

BOTNET

  1. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

RANSOMWARE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild

MALWARE

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  3. Here's how the hack works: Temperatures used in the pulp cooking process begin to vary random intervals. The fluctuations in temperature

EXPLOIT

  1. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub

VULNERABILITY

  1. Oracle Critical Patch Update October 2018 Addressed 301 Flaws Including 47 High-Rated Flaws
  2. Two Critical RCE Bugs Patched in Drupal 7 and 8
  3. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
  4. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  5. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  6. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  7. OpenSSH 7.9 released: fixed bugs
  8. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  9. Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players
  10. Vulnerabilities in telepresence robots allow access to image and video
  11. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems

Region brief for 2018-10-20

ASIA

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

OCEANIA

Nil

NORTH AMERICA

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations

SOUTH AMERICA

Nil

EUROPE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

AFRICA

Nil

Sector brief for 2018-10-20

HEALTHCARE

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations
  2. Vulnerabilities in telepresence robots allow access to image and video

TRANSPORT

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

BANKING & FINANCE

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations

INFORMATION & TELECOMMUNICATION

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin

FOOD

Nil

WATER

Nil

ENERGY

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

GOVERNMENT & PUBLIC SERVICE

  1. Anthem to Pay Record $16M as Settlement for Privacy Violations

Daily brief for 2018-10-20

ASIA

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free

WORLD

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. The Russian built #VPNFilter #botnet was previously taken down after 500,000 routers were infected. However, recently it attempted a comeback.

ATTACKS

  1. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. If it's only able to leak data at 15 bits per hour, is #NetSpectre a serious threat? Learn more about
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  5. #TLBleed abuses @Intel's HTT chip feature to leak data and obtain sensitive memory information. Learn more about this new side-channel

THREATS

  1. Oracle Critical Patch Update October 2018 Addressed 301 Flaws Including 47 High-Rated Flaws
  2. Syrian victims of the GandCrab ransomware can decrypt their files for free
  3. Fake Flash Player Installer Embeds Monero Coin Miner, Wreaking Havoc in the Wild
  4. DarkPulsar – A Shadow Brokers Group’s New Hacking Tool Leak To Open Backdoor & Provide Remote Control
  5. Two Critical RCE Bugs Patched in Drupal 7 and 8
  6. Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
  7. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  8. Heads-Up: Patch 'Comically Bad' libSSH Flaw Now
  9. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  10. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin
  11. OpenSSH 7.9 released: fixed bugs
  12. Learn how the #NetSpectre vulnerability affects the #cloud from expert Ed Moyle of @securitycurve.
  13. Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players
  14. Vulnerabilities in telepresence robots allow access to image and video
  15. Java Usage Tracker Critical Flaw Enable Hackers to Inject Arbitrary Files on Windows Systems
  16. Here's how the hack works: Temperatures used in the pulp cooking process begin to vary random intervals. The fluctuations in temperature

CRIME

  1. Syrian victims of the GandCrab ransomware can decrypt their files for free
  2. Anthem to Pay Record $16M as Settlement for Privacy Violations
  3. Man Sentenced to 30 Months in Jail For Creating LuminosityLink RAT
  4. Thousands of applications affected by a zero-day issue in jQuery File Upload plugin

POLITICS

  1. Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds
  2. Vulnerabilities in telepresence robots allow access to image and video

Oct 20, 2018

APT report for 2018-10-19

TRANSNATIONAL / UNKNOWN

Nil

CHINA

  1. Secret Comment Crew Code Spotted in New Attack
  2. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  3. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  4. Latest Hacking News Podcast
  5. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  6. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

INDIA

Nil

NORTH KOREA

  1. "World-renowned cybersecurity unit #GroupIB is prepping to release its annual report on trends in hi-tech cybercrime...Group-IB expects the number of

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. GreyEnergy
  2. GreyEnergy threat group detected attacking high-value targets
  3. .@ESET researchers claim the #GreyEnergy group has taken up the mantle of ICS-targeting #BlackEnergy, but @MalwareJake said the evidence wasn't
  4. .@ESET researchers claim a new threat group called #GreyEnergy is the successor to #BlackEnergy, but experts are unsure if the
  5. Week in security with Tony Anscombe

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-19

WINDOWS

  1. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  2. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  3. Inside Safari Extensions | Malware’s Golden Key to User Data

LINUX

  1. VestaCP users warned about possible server compromise

UNIX

Nil

ANDROID

  1. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

IOS

Nil

MACOS

  1. Inside Safari Extensions | Malware’s Golden Key to User Data

Threat report for 2018-10-19

DATA BREACH & DATA LOSS

  1. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  2. Campaign 2018: Artificial intelligence is automating attacks on political campaigns
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  5. Campaign 2018: Artificial Intelligence Is Automating Attacks On Political Campaigns
  6. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  7. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  8. US Voter Leak Hits Tea Party Organization
  9. VestaCP users warned about possible server compromise
  10. jQuery File Upload Plugin Vulnerable for 8 Years and Only Hackers Knew
  11. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  12. Campaign launched to protect ethical hackers in the Americas
  13. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  14. Facepunch 2016 breach exposed 343,000 users
  15. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  16. ADHA's non-process for releasing My Health Record data revealed
  17. MikroTik routers targeted by cryptomining campaign | Avast
  18. Vulnerability in Tumblr could have compromise users’ account data
  19. Poor security practices and access to hacking services are making it easy for #cybercriminals to compromise business email, research reveals:

DENIAL-OF-SERVICE

  1. New DDoS Malware Infects Open-Source Web Hosting Software
  2. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'
  3. DDoS Attack Prevention Method on Your Enterprise’s Systems – A Detailed Report

MALVERTISING

Nil

PHISHING

  1. Password and credit card-stealing Azorult malware adds new tricks
  2. AISA 2018: Hunting for phishing kits
  3. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.

WEB DEFACEMENT

Nil

BOTNET

  1. Ok now, which one of you is running this Twitter botnet of fake infosec professionals?

RANSOMWARE

  1. City Pays $2,000 in Computer Ransomware Attack
  2. Water Utility ONWASA Hit by Ransomware Attack
  3. Madison County Computer Systems Face a Ransomware Attack
  4. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  5. Top 4 tips to avoid getting hit by ransomware
  6. Onslow County Utility Hit with Ransomware Attack

CRYPTOMINING & CRYPTOCURRENCIES

  1. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  2. MikroTik routers targeted by cryptomining campaign | Avast
  3. Fraudster Targets Cryptocurrency Wallets with a Variety of Info Stealers

MALWARE

  1. Small or Big Business, Malware Hits Everyone
  2. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Password and credit card-stealing Azorult malware adds new tricks
  5. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  6. New DDoS Malware Infects Open-Source Web Hosting Software
  7. America’s First: US Leads in Global Malware C2 Distribution
  8. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  9. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  10. The Golden Age of Malware
  11. LuminosityLink RAT author sentenced to 30 years in prison
  12. Inside Safari Extensions | Malware’s Golden Key to User Data
  13. .@TrendMicro researchers discovered a malicious #ChromeExtension spreading #malware. Learn more with expert @lewisnic.
  14. ADHA's non-process for releasing My Health Record data revealed
  15. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  16. Canberra competence shines in day of PM domain lapses and tortured analogies

EXPLOIT

  1. NSA-Linked 'DarkPulsar' Exploit Tool Detailed

VULNERABILITY

  1. libssh Vulnerability: Is WatchGuard Affected?
  2. 0-Day in jQuery Plugin Impacts Thousands of Applications
  3. Fixing a CSRF Vulnerability
  4. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  5. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  6. Drupal dev team fixed Remote Code Execution flaws in the popular CMS
  7. Flaw in Libssh Grants Admin Control to Servers
  8. FreeRTOS Vulnerabilities Expose Many Systems to Attacks
  9. Linksys E Series Vulnerabilities
  10. Google warns Apple: Missing bugs in your security bulletins are 'disincentive to patch'
  11. jQuery Zero-Day Was Exploited For At Least Three Years
  12. A Serious Security Flaw Found in LibSSH
  13. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  14. Splunk addressed several vulnerabilities in Enterprise and Light products
  15. Serious D-Link router security flaws may never be patched
  16. Scams and flaws: Why we get duped
  17. Remote Code Execution Flaws Patched in Drupal
  18. Tumblr bug bounty program detects flaw, no user info lost
  19. .@Google Firebase's lack of #DatabaseSecurity and inadequate #BackendDevelopment led to #DataLeaks and vulnerabilities, including HospitalGown. Learn more about this
  20. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  21. Critical Flaw Found in Streaming Library Used by VLC and Other Media Players
  22. Drupal Remote Code Execution Vulnerability Alert
  23. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  24. Splunk Patches Several Flaws in Enterprise, Light Products
  25. Vulnerability in Tumblr could have compromise users’ account data
  26. Three critical vulnerabilities can be chained to take full control of D-Link routers
  27. Zero-day in popular jQuery plugin actively exploited for at least three years
  28. Tumblr serious vulnerability can reveal everyone information
  29. Critical Flaws Found in Amazon FreeRTOS IoT Operating System

Region brief for 2018-10-19

ASIA

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  2. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. Secret Comment Crew Code Spotted in New Attack
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands

OCEANIA

  1. AISA 2018: Hunting for phishing kits
  2. ADHA's non-process for releasing My Health Record data revealed
  3. Authorities seize properties of creators of “Infamous” cheat code, for GTA V
  4. Canberra competence shines in day of PM domain lapses and tortured analogies

NORTH AMERICA

  1. Small or Big Business, Malware Hits Everyone
  2. America’s First: US Leads in Global Malware C2 Distribution
  3. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  4. US Voter Leak Hits Tea Party Organization
  5. Secret Comment Crew Code Spotted in New Attack
  6. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  7. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  8. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  9. Inside Safari Extensions | Malware’s Golden Key to User Data
  10. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

SOUTH AMERICA

Nil

EUROPE

  1. Small or Big Business, Malware Hits Everyone
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  4. GreyEnergy
  5. Onslow County Utility Hit with Ransomware Attack
  6. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  7. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  8. Three critical vulnerabilities can be chained to take full control of D-Link routers
  9. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

AFRICA

  1. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

Sector brief for 2018-10-19

HEALTHCARE

  1. Small or Big Business, Malware Hits Everyone
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Secret Comment Crew Code Spotted in New Attack

TRANSPORT

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware

BANKING & FINANCE

  1. Small or Big Business, Malware Hits Everyone
  2. City Pays $2,000 in Computer Ransomware Attack
  3. Madison County Computer Systems Face a Ransomware Attack
  4. Password and credit card-stealing Azorult malware adds new tricks
  5. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  6. AISA 2018: Hunting for phishing kits
  7. US Voter Leak Hits Tea Party Organization
  8. Secret Comment Crew Code Spotted in New Attack
  9. Inside Safari Extensions | Malware’s Golden Key to User Data
  10. Critical Flaws Found in Amazon FreeRTOS IoT Operating System

INFORMATION & TELECOMMUNICATION

  1. Fixing a CSRF Vulnerability
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Flaw in Libssh Grants Admin Control to Servers
  4. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  5. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  6. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.
  7. Tumblr bug bounty program detects flaw, no user info lost
  8. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  9. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  10. Ok now, which one of you is running this Twitter botnet of fake infosec professionals?
  11. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  12. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  13. Inside Safari Extensions | Malware’s Golden Key to User Data
  14. Vulnerability in Tumblr could have compromise users’ account data
  15. Tumblr serious vulnerability can reveal everyone information
  16. Poor security practices and access to hacking services are making it easy for #cybercriminals to compromise business email, research reveals:

FOOD

Nil

WATER

  1. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

ENERGY

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  2. GreyEnergy
  3. Onslow County Utility Hit with Ransomware Attack

GOVERNMENT & PUBLIC SERVICE

  1. Small or Big Business, Malware Hits Everyone
  2. Madison County Computer Systems Face a Ransomware Attack
  3. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  4. US Voter Leak Hits Tea Party Organization
  5. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

Daily brief for 2018-10-19

ASIA

  1. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  2. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  5. Secret Comment Crew Code Spotted in New Attack
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands

WORLD

  1. Small or Big Business, Malware Hits Everyone
  2. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  3. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  4. GreyEnergy
  5. Onslow County Utility Hit with Ransomware Attack
  6. America’s First: US Leads in Global Malware C2 Distribution
  7. AISA 2018: Hunting for phishing kits
  8. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  9. US Voter Leak Hits Tea Party Organization
  10. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  11. Secret Comment Crew Code Spotted in New Attack
  12. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  13. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  14. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  15. Inside Safari Extensions | Malware’s Golden Key to User Data
  16. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  17. ADHA's non-process for releasing My Health Record data revealed
  18. Three critical vulnerabilities can be chained to take full control of D-Link routers
  19. Authorities seize properties of creators of “Infamous” cheat code, for GTA V
  20. Canberra competence shines in day of PM domain lapses and tortured analogies
  21. Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'

ATTACKS

  1. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  2. Campaign 2018: Artificial intelligence is automating attacks on political campaigns
  3. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  4. A Pentagon #DataBreach exposed data on at least 30,000 individuals, but other details about the incident are still scarce. By
  5. Password and credit card-stealing Azorult malware adds new tricks
  6. Campaign 2018: Artificial Intelligence Is Automating Attacks On Political Campaigns
  7. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  8. AISA 2018: Hunting for phishing kits
  9. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  10. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  11. US Voter Leak Hits Tea Party Organization
  12. VestaCP users warned about possible server compromise
  13. jQuery File Upload Plugin Vulnerable for 8 Years and Only Hackers Knew
  14. Recent phishing campaign against the Office of the First Deputy Prime Minister - Kingdom of Bahrain. Targeting Aysha Bukhelli, spoofed
  15. Campaign launched to protect ethical hackers in the Americas
  16. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.
  17. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  18. Facepunch 2016 breach exposed 343,000 users
  19. Today we're explaining #Canada's Data Breach Regulations on the #blog. Jet on over to find out if your organization complies
  20. ADHA's non-process for releasing My Health Record data revealed
  21. MikroTik routers targeted by cryptomining campaign | Avast
  22. Vulnerability in Tumblr could have compromise users’ account data
  23. Poor security practices and access to hacking services are making it easy for #cybercriminals to compromise business email, research reveals:

THREATS

  1. libssh Vulnerability: Is WatchGuard Affected?
  2. 0-Day in jQuery Plugin Impacts Thousands of Applications
  3. Small or Big Business, Malware Hits Everyone
  4. Fixing a CSRF Vulnerability
  5. This Week in Security News: Apex One™ Release and Java Usage Tracker Flaws
  6. AWS FreeRTOS Bugs Allow Compromise of IoT Devices
  7. City Pays $2,000 in Computer Ransomware Attack
  8. Drupal dev team fixed Remote Code Execution flaws in the popular CMS
  9. Water Utility ONWASA Hit by Ransomware Attack
  10. Madison County Computer Systems Face a Ransomware Attack
  11. Kaspersky says it detected infections with DarkPulsar, alleged NSA malware
  12. The Week in Ransomware - October 19th 2018 - GandCrab, Birbware, and More
  13. Top 4 tips to avoid getting hit by ransomware
  14. Flaw in Libssh Grants Admin Control to Servers
  15. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  16. FreeRTOS Vulnerabilities Expose Many Systems to Attacks
  17. Linksys E Series Vulnerabilities
  18. Password and credit card-stealing Azorult malware adds new tricks
  19. SettingContent-ms can be Abused to Drop Complex DeepLink and Icon-based Payload
  20. Google warns Apple: Missing bugs in your security bulletins are 'disincentive to patch'
  21. Onslow County Utility Hit with Ransomware Attack
  22. jQuery Zero-Day Was Exploited For At Least Three Years
  23. New DDoS Malware Infects Open-Source Web Hosting Software
  24. A Serious Security Flaw Found in LibSSH
  25. America’s First: US Leads in Global Malware C2 Distribution
  26. New RTF-based Campaign Distributing Agent Tesla and Loki Malware
  27. In this week's Risk & Repeat podcast, editors discuss the #GAOreport on vulnerabilities and weaknesses in military weapons systems and
  28. Splunk addressed several vulnerabilities in Enterprise and Light products
  29. Hackers launched #phishing attacks against @netflix users via malicious sites with TLS certificates. Learn how hackers mimic popular websites to
  30. Serious D-Link router security flaws may never be patched
  31. Scams and flaws: Why we get duped
  32. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers
  33. Remote Code Execution Flaws Patched in Drupal
  34. The Golden Age of Malware
  35. Tumblr bug bounty program detects flaw, no user info lost
  36. LuminosityLink RAT author sentenced to 30 years in prison
  37. .@Google Firebase's lack of #DatabaseSecurity and inadequate #BackendDevelopment led to #DataLeaks and vulnerabilities, including HospitalGown. Learn more about this
  38. The blogging site Tumblr has disclosed and fixed a security flaw that could have exposed sensitive account information.
  39. Critical Flaw Found in Streaming Library Used by VLC and Other Media Players
  40. Drupal Remote Code Execution Vulnerability Alert
  41. Inside Safari Extensions | Malware’s Golden Key to User Data
  42. .@TrendMicro researchers discovered a malicious #ChromeExtension spreading #malware. Learn more with expert @lewisnic.
  43. Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are
  44. Splunk Patches Several Flaws in Enterprise, Light Products
  45. ADHA's non-process for releasing My Health Record data revealed
  46. MikroTik routers targeted by cryptomining campaign | Avast
  47. APT Group Uses Datper Malware To Launch Cyber Attack on Asia Countries by Executing Shell Commands
  48. Fraudster Targets Cryptocurrency Wallets with a Variety of Info Stealers
  49. Vulnerability in Tumblr could have compromise users’ account data
  50. Three critical vulnerabilities can be chained to take full control of D-Link routers
  51. Zero-day in popular jQuery plugin actively exploited for at least three years
  52. Tumblr serious vulnerability can reveal everyone information
  53. Critical Flaws Found in Amazon FreeRTOS IoT Operating System
  54. Canberra competence shines in day of PM domain lapses and tortured analogies

CRIME

  1. NSA-Linked 'DarkPulsar' Exploit Tool Detailed
  2. Small or Big Business, Malware Hits Everyone
  3. Madison County Computer Systems Face a Ransomware Attack
  4. America’s First: US Leads in Global Malware C2 Distribution
  5. Did you know? Corporate email accounts can be compromised for as little as $150. Read more key findings from our
  6. Scams and flaws: Why we get duped
  7. #HurricaneMichael #phishing schemes leverage Azure blob storage to rake in credentials. http://ow.ly/J6m850js1sk via the @threatinsight research team.
  8. Secret Comment Crew Code Spotted in New Attack
  9. LuminosityLink RAT author sentenced to 30 years in prison
  10. #GroupIB is a platinum sponsor @Gartner_inc Security & Risk Management Summit (Dubai, UAE, 22-23 October 2018) Visit us at Stand
  11. "World-renowned cybersecurity unit #GroupIB is prepping to release its annual report on trends in hi-tech cybercrime...Group-IB expects the number of
  12. Authorities seize properties of creators of “Infamous” cheat code, for GTA V

POLITICS

  1. Chinese Hackers Use 'Datper' Trojan in Recent Campaign
  2. GreyEnergy
  3. US Voter Leak Hits Tea Party Organization
  4. Secret Comment Crew Code Spotted in New Attack
  5. LuminosityLink RAT author sentenced to 30 years in prison
  6. Attackers behind Operation Oceansalt reuse code from Chinese Comment Crew
  7. Latest Hacking News Podcast

Oct 19, 2018

APT report for 2018-10-18

TRANSNATIONAL / UNKNOWN

Nil

CHINA

  1. New APT Could Signal Reemergence of Notorious Comment Crew
  2. Tracking Tick Through Recent Campaigns Targeting East Asia
  3. Cyber Espionage Campaign Reuses Code from China's APT1
  4. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  5. Oceansalt Linked To Defunct Chinese APT Comment Crew
  6. 'Operation Oceansalt' Reuses Code from Chinese Group APT1
  7. Tracking Tick Through Recent Campaigns Targeting East Asia
  8. Operation Oceansalt research reveals cyber-attacks targeting South Korea, USA and Canada
  9. Oceansalt cyberattack wave linked to defunct Chinese APT Comment Crew
  10. ‘Operation Oceansalt’ Delivers Wave After Wave
  11. New Reconnaissance Tool Uses Code from Eight-Year-Old Comment Crew Implant

INDIA

  1. New Pennsylvania Law Imposes Fine for Using Drones to Spy

NORTH KOREA

  1. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million
  2. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  3. Targeted attacks on crypto exchanges resulted in a loss of $882 million

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Threat Report: BlackEnergy APT Group Becomes GreyEnergy
  2. GreyEnergy cyberespionage group targets Poland and Ukraine
  3. GreyEnergy Spy APT Mounts Sophisticated Effort Against Critical Infrastructure
  4. GreyEnergy Potential Successor of BlackEnergy
  5. XBash Malware Security Advisory

SERBIA

Nil

UKRAINE

  1. Group-IB: 14 cyber attacks on crypto exchanges resulted in a loss of $882 million

Platform report for 2018-10-18

WINDOWS

  1. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  2. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  3. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  4. Tracking Tick Through Recent Campaigns Targeting East Asia
  5. Ruby 2.4.5 released: 40 bug fixes
  6. XBash Malware Security Advisory

LINUX

  1. Open source web hosting software compromised with DDoS malware
  2. Ruby 2.4.5 released: 40 bug fixes
  3. XBash Malware Security Advisory
  4. VestaCP compromised in a new supply-chain attack
  5. VestaCP compromised in a new supply-chain attack

UNIX

Nil

ANDROID

  1. GPlayed Trojan - .Net Playing with Google Market

IOS

  1. Crypto Mining Malware Runs on iPhone
  2. Cryptomining Malware Attacks On iPhones Grew By 400%

MACOS

  1. Ruby 2.4.5 released: 40 bug fixes
  2. XBash Malware Security Advisory

Threat report for 2018-10-18

DATA BREACH & DATA LOSS

  1. 35 Million Records Of US Voters Data For Sale On The Dark Web
  2. Thousands of Neoflam Clients Had Their Data Leaked After Buying Frying Pans
  3. Tracking Tick Through Recent Campaigns Targeting East Asia
  4. Cyber Espionage Campaign Reuses Code from China's APT1
  5. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  6. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  7. Apple to US users: Here's how you can now see what personal data we hold on you
  8. Open source web hosting software compromised with DDoS malware
  9. Anthem Settles with OCR for $16M for 2015 Data Breach
  10. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  11. Hackers can use legitimate #AdminTools to compromise networks. Learn more about "living off the land" attacks from expert Michael Cobb
  12. Tumblr patches bug that could have exposed user data
  13. 12.5 Million Email Archives Exposed - Why would #cybercriminals go to a #darkweb market and pay for access when they
  14. #NetSpectre exploits leak data remotely via side-channel attacks. Learn how to use #ThreatModeling to stop speculative execution from expert Ed
  15. Tracking Tick Through Recent Campaigns Targeting East Asia
  16. McAfee researchers uncover ‘significant’ espionage campaign
  17. Apple to US users: Here's how you can now see what personal data we hold on you
  18. Tumblr Fixes Security Bug that Leaked Private Account Info
  19. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  20. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  21. VestaCP compromised in a new supply-chain attack
  22. VestaCP compromised in a new supply-chain attack
  23. Anthem to pay record £12M for 2015 data breach
  24. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  25. In the wake of numerous high-profile data breaches and privacy incidents, consumers are more aware and concerned than ever about
  26. Senate inquiry recommends locking down My Health Record by default
  27. Tumblr Vulnerability Exposed User Account Information
  28. The Equifax Hack Uploaded Files the Right Way
  29. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise
  30. SEO pollution campaign affects web searches related to EU midterm elections

DENIAL-OF-SERVICE

  1. Open source web hosting software compromised with DDoS malware
  2. Who and Why Make DDoS Attacks on The Site of Colleges and Universities ?
  3. A10 Networks provides cloud, Internet and gaming providers with 1 RU DDoS defense appliance

MALVERTISING

Nil

PHISHING

  1. The libssh “login with no password” bug – what you need to know [VIDEO]

WEB DEFACEMENT

Nil

BOTNET

  1. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  2. How does the resurgent VPNFilter botnet target victims?

RANSOMWARE

  1. 7 best practices for negotiating ransomware payments

CRYPTOMINING & CRYPTOCURRENCIES

  1. Fake Adobe Flash update hides cryptocurrency malware
  2. Crooks are attempting to spread their cryptojacking malware to unsuspecting victims by disguising it as an update for Flash. The malicious
  3. Top 10 Blockchain Development Companies
  4. Crypto Mining Malware Runs on iPhone
  5. Cryptocurrency Miners Hiding As Flash Updates
  6. Cryptomining Malware Attacks On iPhones Grew By 400%
  7. Hacking Attacks On Cryptocurrency Exchanges Resulted in a Loss of $882 Million
  8. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  9. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  10. LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
  11. Researcher Livestreams 51% Attack on Altcoin Blockchain
  12. Cryptojacking: A hidden cost for your company
  13. Report: Cryptocurrency Exchanges Lost $882 Million to Hackers

MALWARE

  1. Fake Adobe Flash update hides cryptocurrency malware
  2. After an attempted comeback by the Russian built #VPNFilter #botnet, home #networkdevices are at risk. Learn how this #malware targets
  3. Open source web hosting software compromised with DDoS malware
  4. LuminosityLink Spyware Mastermind Gets 30 Months In The Clink
  5. Crooks are attempting to spread their cryptojacking malware to unsuspecting victims by disguising it as an update for Flash. The malicious
  6. Crypto Mining Malware Runs on iPhone
  7. GPlayed Trojan - .Net Playing with Google Market
  8. Cryptomining Malware Attacks On iPhones Grew By 400%
  9. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  10. RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
  11. LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
  12. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  13. XBash Malware Security Advisory
  14. The author of the LuminosityLink RAT sentenced to 30 Months in Prison
  15. Stegware: How is #malware using #steganography techniques to avoid detection?
  16. Around 600 Computers of Anne Arundel County Public Library have been Exposed to Emotet Virus
  17. In order to distribute the attack payload, the code needs to be downloaded onto the PLCs & safety controllers. This

EXPLOIT

Nil

VULNERABILITY

  1. GitHub now warns devs about bugs that led to Equifax breach
  2. Flaws in telepresence robots allow hackers access to pictures, video feeds
  3. Branch.io Flaws may have affected as many as 685 million individuals
  4. Critical Remote Code Execution Vulnerabilities Patched by Drupal
  5. Code Execution Vulnerability Patched in Library Used by VLC, Other Media Players
  6. Flaws Open Telepresence Robots to Prying Eyes
  7. [SingCERT] Alert on Multiple Security Vulnerabilities in Oracle's Enterprise Products
  8. The #NetSpectre vulnerability could enable a slow leak of data remotely via side channels. Expert Michael Cobb of @thehairyITdog explains
  9. A newly disclosed #libSSH vulnerability could allow an attacker #AdminAccess to a server with little effort. By @MT_Heller
  10. Drupal addresses multiple critical flaws with latest release
  11. Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
  12. CVE-2018-8460: Exposing a Double Free in Internet Explorer for Code Execution
  13. Wapiti – The Black Box Vulnerability Scanner for Web Applications
  14. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  15. The libssh “login with no password” bug – what you need to know [VIDEO]
  16. Card Factory Exposed Customers Photos Publicly Due To A Website Flaw
  17. How Shodan helps identify ICS cybersecurity vulnerabilities
  18. Oracle extends its thanks to Qihoo 360 for fixing the vulnerabilities of Weblogic
  19. Tumblr patches bug that could have exposed user data
  20. [SingCERT] Alert on Linksys E Series Routers Vulnerabilities (CVE-2018-3953, CVE-2018-3954, and CVE-2018-3955)
  21. Apache Access Vulnerability Could Affect Thousands of Applications
  22. Last year, D-Link flubbed a router bug-fix, so it's back with total pwnage
  23. Party like it's 1989... SVGA code bug haunts VMware's house, lets guests flee to host OS
  24. Oracle Patches 301 Vulnerabilities in October Update
  25. Tumblr Fixes Security Bug that Leaked Private Account Info
  26. Ruby 2.4.5 released: 40 bug fixes
  27. Tumblr fixed a #vulnerability that could have exposed sensitive account #data, including usernames/passwords and individual IP addresses. But the company
  28. The #TLBleed vulnerability uses @Intel's HTT chip feature to leak data. Learn about how hackers could use #malware to launch
  29. New libSSH vulnerability gives root access to servers
  30. A 4-year-old #libSSH vulnerability can allow attackers to easily log in to servers with full administrative control, but it is
  31. The implications of the NetSpectre vulnerability
  32. #Shodan can be a helpful tool for security professionals to locate #ICSsecurity vulnerabilities. Expert Ernie Hayden explains how Shodan works
  33. Oracle security updates contains 45 critical-rated vulnerability
  34. A #libSSH vulnerability that went undisclosed for almost five years could allow an attacker easy #AdminAccess to servers, @0xAmit said
  35. Vulnerability Spotlight: Live Networks LIVE555 streaming media RTSPServer code execution vulnerability
  36. Chaining three critical vulnerabilities allows takeover of D-Link routers
  37. Tumblr Fixes Critical Security Bug That Exposes User Account Details
  38. Tumblr Vulnerability Exposed User Account Information
  39. Bug Trio Affecting Eight D-Link Models Leads to Full Compromise