Nov 2, 2018

APT report for 2018-11-01

TRANSNATIONAL / UNKNOWN

  1. 0x20k of Ghost Squad Hackers Releases ODay Exploit Targeting Apache Hadoop
  2. British Airways data breach bigger than originally thought
  3. CBS News: A Look Behind the Magecart Assault on E-commerce

CHINA

  1. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  2. Comodo launches Dome Shield Platinum to secure and control Internet access

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

SERBIA

Nil

UKRAINE

  1. New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed

Platform report for 2018-11-01

WINDOWS

  1. Trickbot Malware Now Also Steals Passwords From Apps, Web Browsers
  2. Emotet Malware, the Most Probable Malware of the Year
  3. More Typo-Squatting Malware Found on PyPI
  4. Windows Defender Bug Needs a Restart, Not Shutdown, To Enable Sandbox
  5. Healthcare Industry Continues To Be the Favourite for Ransomware
  6. Trickbot Shows Off New Trick: Password Grabber Module
  7. SamSam Attackers Have Hit 67 Ransomware Targets
  8. Talos Vulnerability Deep Dive - TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  9. Perl-Based Shellbot Looks to Target Organizations via C&C

LINUX

  1. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  2. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  3. 0x20k of Ghost Squad Hackers Releases ODay Exploit Targeting Apache Hadoop
  4. Perl-Based Shellbot Looks to Target Organizations via C&C

UNIX

Nil

ANDROID

  1. Government employee who used to watch porn at work alleged guilty of infecting with malware a network
  2. Perl-Based Shellbot Looks to Target Organizations via C&C

IOS

Nil

MACOS

Nil

Threat report for 2018-11-01

DATA BREACH & DATA LOSS

  1. Australian defence contractor Austal hit by data breach
  2. Radisson discloses data breach impacting rewards customers
  3. 22,000 Records Exposed by JoomlArt in Jira Ticket
  4. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  5. New Bluetooth Vulnerabilities Exposed in Aruba, Cisco, Meraki Access Points
  6. Customer Information Stolen in Radisson Hotel Group Data Breach
  7. British Airways data breach bigger than originally thought
  8. Where Is the Consumer Outrage about Data Breaches?
  9. Eurostar Resets Passwords of Customers After Data Breach
  10. Radisson Hotel Group suffers data breach, customer info leaked
  11. Radisson Rewards Program Targeted in Data Breach
  12. "If the schemas prove not to be compatible, a backup of the previous version of a database must be used
  13. Emotet Malware – Mass-Harvesting millions of Emails in secret Campaign
  14. Last year the @USAgov required agencies to implement #DMARC records and policies by October 2018. Learn just how hard DMARC
  15. New Ramnit Campaign Spreads Azorult Malware
  16. #NetSpectre leaks data remotely via side-channel attacks. Learn from expert Michael Cobb of @thehairyITdog why data from #microprocessors is not
  17. Phishing Attacks Breach 20,000 Patient Records of Catawba Valley Medical Center
  18. Radisson Hotel Group Data Breach Exposed Customer’s Personal Data
  19. Beware !! Square & PayPal Mobile Point of Sales (POS) Devices Are Extremely Vulnerable to Credit/Debit Card Data Theft

DENIAL-OF-SERVICE

  1. Cisco ups the ante for 400G Ethernet with big-bandwidth data-center switches

MALVERTISING

  1. Bad ads: Publishers look to stop malvertising for good

PHISHING

  1. How phishing is evolving to outpace awareness
  2. Going with what works: The state of phishing
  3. October may be over – but phishing attacks never stop. Here’s how to make security awareness successful all year round.
  4. Trickbot Shows Off New Trick: Password Grabber Module
  5. Expert Insights Names Barracuda’s AI powered Sentinel Top Phishing protection product
  6. Phishing Attacks Breach 20,000 Patient Records of Catawba Valley Medical Center

WEB DEFACEMENT

Nil

BOTNET

  1. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  2. Defending your pumpkin from tracker zombies
  3. Necurs Botnet Distributing Sextortion Email Scams
  4. The Russian built #VPNFilter #botnet was taken down by the @FBI after over 500,000 routers were infected. However, VPNFilter is

RANSOMWARE

  1. Ransomware and Back-Up Plans
  2. Healthcare Industry Continues To Be the Favourite for Ransomware
  3. SamSam Attackers Have Hit 67 Ransomware Targets
  4. Nice work if you can get it: GandCrab ransomware nets millions even though it has been broken
  5. Crypto-Locking Kraken Ransomware Looms Larger

CRYPTOMINING & CRYPTOCURRENCIES

  1. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  2. UK considers banning cryptocurrencies for their lack of “intrinsic value”
  3. Crypto-Locking Kraken Ransomware Looms Larger
  4. Crypto Micropayments: an Exciting Future for Blockchain Transactions

MALWARE

  1. 2018’s worst malware revealed in report
  2. Trickbot Malware Now Also Steals Passwords From Apps, Web Browsers
  3. Emotet Malware, the Most Probable Malware of the Year
  4. USB Drives Deliver Dangerous Malware to Industrial Facilities: Honeywell
  5. More Typo-Squatting Malware Found on PyPI
  6. Employee used US government network for adult websites, infected infrastructure with Russian malware
  7. Government employee who used to watch porn at work alleged guilty of infecting with malware a network
  8. Malware Analysis for Blue Teams
  9. Emotet Malware – Mass-Harvesting millions of Emails in secret Campaign
  10. Hackers Drops New Emotet Malware to Perform Mass Email Exfiltration From Victims Email Client
  11. New Ramnit Campaign Spreads Azorult Malware
  12. Perl-Based Shellbot Looks to Target Organizations via C&C
  13. IKARUS Security Software partners with PolySwarm to advance early malware detection
  14. Pdgmail – Forensic Tool to Analysis Process Memory Dump

EXPLOIT

  1. PoC Exploit Compromises Microsoft Live Accounts via Subdomain Hijacking
  2. 0x20k of Ghost Squad Hackers Releases ODay Exploit Targeting Apache Hadoop
  3. Hackers Exploit Cisco Zero Day Vulnerability in Wild Resulting in DoS Condition

VULNERABILITY

  1. Yi IoT Home Camera Riddled with Code-Execution Vulnerabilities
  2. BLEEDINGBIT Bluetooth flaws in TI chips expose enterprises to remote attacks
  3. New Bluetooth Vulnerabilities Exposed in Aruba, Cisco, Meraki Access Points
  4. Windows Defender Bug Needs a Restart, Not Shutdown, To Enable Sandbox
  5. Bluetooth Chip Flaws Expose Enterprises to Remote Attacks
  6. Two Zero-Day Bugs Open Millions of Wireless Access Points to Attack
  7. Cisco says a flaw in its Adaptive Security Appliance allows remote attacks
  8. Talos Vulnerability Deep Dive – TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  9. Security researchers find flaws in chips used in hospitals, factories and stores
  10. Bleedingbit: Critical vulnerabilities in BLE chips expose millions of access points to attack
  11. Bleedingbit zero-day chip flaws may expose majority of enterprises to remote code execution attacks
  12. Cisco Zero-Day Exploited In The Wild To Crash And Reload Devices
  13. Zero-Day RCE Vulnerabilities Expose Millions of BLE-Enabled Devices to Attacks
  14. Hackers Exploit Cisco Zero Day Vulnerability in Wild Resulting in DoS Condition
  15. New BLEEDINGBIT Vulnerabilities Affect Widely-Used Bluetooth Chips
  16. Two New Bluetooth Chip Flaws Expose Millions of Devices to Remote Attacks
  17. .@Siemens disclosed six SICLOCK flaws that were found within its central plant clocks. Discover why three flaws have been rated
  18. Our fabulous @5ean5ullivan explains to @CyberSauna listeners how the multiple vulnerabilities in the US electoral system may be^H^H^H^H^H^Hare being exploited.
  19. Bleedingbit Bluetooth Vulnerabilities Expose WiFi APs to Risk
  20. Talos Vulnerability Deep Dive - TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  21. Cisco Warns of Zero-Day Vulnerability in Security Appliances
  22. Cisco zero-day exploited in the wild to crash and reload devices

Region brief for 2018-11-01

ASIA

  1. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  2. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  3. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  4. Trickbot Shows Off New Trick: Password Grabber Module
  5. SamSam Attackers Have Hit 67 Ransomware Targets
  6. Perl-Based Shellbot Looks to Target Organizations via C&C
  7. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

OCEANIA

  1. Australian defence contractor Austal hit by data breach
  2. Trickbot Shows Off New Trick: Password Grabber Module
  3. SamSam Attackers Have Hit 67 Ransomware Targets

NORTH AMERICA

  1. Australian defence contractor Austal hit by data breach
  2. BLEEDINGBIT Bluetooth flaws in TI chips expose enterprises to remote attacks
  3. Emotet Malware, the Most Probable Malware of the Year
  4. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  5. New Bluetooth Vulnerabilities Exposed in Aruba, Cisco, Meraki Access Points
  6. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  7. Bleedingbit: Critical vulnerabilities in BLE chips expose millions of access points to attack
  8. Healthcare Industry Continues To Be the Favourite for Ransomware
  9. Employee used US government network for adult websites, infected infrastructure with Russian malware
  10. CBS News: A Look Behind the Magecart Assault on E-commerce
  11. UK considers banning cryptocurrencies for their lack of “intrinsic value”
  12. Government employee who used to watch porn at work alleged guilty of infecting with malware a network
  13. Trickbot Shows Off New Trick: Password Grabber Module
  14. SamSam Attackers Have Hit 67 Ransomware Targets
  15. Our fabulous @5ean5ullivan explains to @CyberSauna listeners how the multiple vulnerabilities in the US electoral system may be^H^H^H^H^H^Hare being exploited.
  16. Hackers Drops New Emotet Malware to Perform Mass Email Exfiltration From Victims Email Client
  17. Talos Vulnerability Deep Dive - TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  18. Perl-Based Shellbot Looks to Target Organizations via C&C
  19. Beware !! Square & PayPal Mobile Point of Sales (POS) Devices Are Extremely Vulnerable to Credit/Debit Card Data Theft

SOUTH AMERICA

  1. Perl-Based Shellbot Looks to Target Organizations via C&C

EUROPE

  1. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  2. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  3. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  4. British Airways data breach bigger than originally thought
  5. Eurostar Resets Passwords of Customers After Data Breach
  6. Employee used US government network for adult websites, infected infrastructure with Russian malware
  7. CBS News: A Look Behind the Magecart Assault on E-commerce
  8. UK considers banning cryptocurrencies for their lack of “intrinsic value”
  9. Trickbot Shows Off New Trick: Password Grabber Module
  10. Radisson Rewards Program Targeted in Data Breach
  11. SamSam Attackers Have Hit 67 Ransomware Targets
  12. Perl-Based Shellbot Looks to Target Organizations via C&C
  13. The Russian built #VPNFilter #botnet was taken down by the @FBI after over 500,000 routers were infected. However, VPNFilter is
  14. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

AFRICA

Nil

Sector brief for 2018-11-01

HEALTHCARE

  1. BLEEDINGBIT Bluetooth flaws in TI chips expose enterprises to remote attacks
  2. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  3. Security researchers find flaws in chips used in hospitals, factories and stores
  4. Healthcare Industry Continues To Be the Favourite for Ransomware
  5. SamSam Attackers Have Hit 67 Ransomware Targets
  6. Phishing Attacks Breach 20,000 Patient Records of Catawba Valley Medical Center

TRANSPORT

  1. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  2. SamSam Attackers Have Hit 67 Ransomware Targets

BANKING & FINANCE

  1. Radisson discloses data breach impacting rewards customers
  2. Trickbot Malware Now Also Steals Passwords From Apps, Web Browsers
  3. Emotet Malware, the Most Probable Malware of the Year
  4. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  5. Customer Information Stolen in Radisson Hotel Group Data Breach
  6. British Airways data breach bigger than originally thought
  7. Healthcare Industry Continues To Be the Favourite for Ransomware
  8. CBS News: A Look Behind the Magecart Assault on E-commerce
  9. UK considers banning cryptocurrencies for their lack of “intrinsic value”
  10. Trickbot Shows Off New Trick: Password Grabber Module
  11. Nice work if you can get it: GandCrab ransomware nets millions even though it has been broken
  12. Crypto Micropayments: an Exciting Future for Blockchain Transactions
  13. Beware !! Square & PayPal Mobile Point of Sales (POS) Devices Are Extremely Vulnerable to Credit/Debit Card Data Theft

INFORMATION & TELECOMMUNICATION

  1. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  2. 0x20k of Ghost Squad Hackers Releases ODay Exploit Targeting Apache Hadoop
  3. Where Is the Consumer Outrage about Data Breaches?
  4. Our fabulous @5ean5ullivan explains to @CyberSauna listeners how the multiple vulnerabilities in the US electoral system may be^H^H^H^H^H^Hare being exploited.
  5. Talos Vulnerability Deep Dive - TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  6. Perl-Based Shellbot Looks to Target Organizations via C&C
  7. Comodo launches Dome Shield Platinum to secure and control Internet access
  8. Pdgmail – Forensic Tool to Analysis Process Memory Dump

FOOD

Nil

WATER

  1. Malware Analysis for Blue Teams

ENERGY

  1. BLEEDINGBIT Bluetooth flaws in TI chips expose enterprises to remote attacks
  2. Bluetooth Chip Flaws Expose Enterprises to Remote Attacks
  3. Bleedingbit: Critical vulnerabilities in BLE chips expose millions of access points to attack
  4. Zero-Day RCE Vulnerabilities Expose Millions of BLE-Enabled Devices to Attacks
  5. Two New Bluetooth Chip Flaws Expose Millions of Devices to Remote Attacks
  6. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

GOVERNMENT & PUBLIC SERVICE

  1. Emotet Malware, the Most Probable Malware of the Year
  2. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  3. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  4. Employee used US government network for adult websites, infected infrastructure with Russian malware
  5. UK considers banning cryptocurrencies for their lack of “intrinsic value”
  6. Government employee who used to watch porn at work alleged guilty of infecting with malware a network
  7. SamSam Attackers Have Hit 67 Ransomware Targets
  8. Our fabulous @5ean5ullivan explains to @CyberSauna listeners how the multiple vulnerabilities in the US electoral system may be^H^H^H^H^H^Hare being exploited.
  9. Perl-Based Shellbot Looks to Target Organizations via C&C
  10. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

Daily brief for 2018-11-01

ASIA

  1. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  2. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  3. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  4. Trickbot Shows Off New Trick: Password Grabber Module
  5. SamSam Attackers Have Hit 67 Ransomware Targets
  6. Perl-Based Shellbot Looks to Target Organizations via C&C
  7. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

WORLD

  1. Australian defence contractor Austal hit by data breach
  2. BLEEDINGBIT Bluetooth flaws in TI chips expose enterprises to remote attacks
  3. Emotet Malware, the Most Probable Malware of the Year
  4. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  5. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  6. New Bluetooth Vulnerabilities Exposed in Aruba, Cisco, Meraki Access Points
  7. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  8. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  9. Bleedingbit: Critical vulnerabilities in BLE chips expose millions of access points to attack
  10. British Airways data breach bigger than originally thought
  11. Eurostar Resets Passwords of Customers After Data Breach
  12. Healthcare Industry Continues To Be the Favourite for Ransomware
  13. Employee used US government network for adult websites, infected infrastructure with Russian malware
  14. CBS News: A Look Behind the Magecart Assault on E-commerce
  15. UK considers banning cryptocurrencies for their lack of “intrinsic value”
  16. Government employee who used to watch porn at work alleged guilty of infecting with malware a network
  17. Trickbot Shows Off New Trick: Password Grabber Module
  18. Radisson Rewards Program Targeted in Data Breach
  19. SamSam Attackers Have Hit 67 Ransomware Targets
  20. Our fabulous @5ean5ullivan explains to @CyberSauna listeners how the multiple vulnerabilities in the US electoral system may be^H^H^H^H^H^Hare being exploited.
  21. Hackers Drops New Emotet Malware to Perform Mass Email Exfiltration From Victims Email Client
  22. Talos Vulnerability Deep Dive - TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  23. Perl-Based Shellbot Looks to Target Organizations via C&C
  24. The Russian built #VPNFilter #botnet was taken down by the @FBI after over 500,000 routers were infected. However, VPNFilter is
  25. Beware !! Square & PayPal Mobile Point of Sales (POS) Devices Are Extremely Vulnerable to Credit/Debit Card Data Theft
  26. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

ATTACKS

  1. Australian defence contractor Austal hit by data breach
  2. Radisson discloses data breach impacting rewards customers
  3. 22,000 Records Exposed by JoomlArt in Jira Ticket
  4. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  5. New Bluetooth Vulnerabilities Exposed in Aruba, Cisco, Meraki Access Points
  6. How phishing is evolving to outpace awareness
  7. Customer Information Stolen in Radisson Hotel Group Data Breach
  8. Going with what works: The state of phishing
  9. British Airways data breach bigger than originally thought
  10. Where Is the Consumer Outrage about Data Breaches?
  11. Eurostar Resets Passwords of Customers After Data Breach
  12. Radisson Hotel Group suffers data breach, customer info leaked
  13. October may be over – but phishing attacks never stop. Here’s how to make security awareness successful all year round.
  14. Trickbot Shows Off New Trick: Password Grabber Module
  15. Radisson Rewards Program Targeted in Data Breach
  16. "If the schemas prove not to be compatible, a backup of the previous version of a database must be used
  17. Bad ads: Publishers look to stop malvertising for good
  18. Emotet Malware – Mass-Harvesting millions of Emails in secret Campaign
  19. Last year the @USAgov required agencies to implement #DMARC records and policies by October 2018. Learn just how hard DMARC
  20. Expert Insights Names Barracuda’s AI powered Sentinel Top Phishing protection product
  21. New Ramnit Campaign Spreads Azorult Malware
  22. #NetSpectre leaks data remotely via side-channel attacks. Learn from expert Michael Cobb of @thehairyITdog why data from #microprocessors is not
  23. Phishing Attacks Breach 20,000 Patient Records of Catawba Valley Medical Center
  24. Radisson Hotel Group Data Breach Exposed Customer’s Personal Data
  25. Beware !! Square & PayPal Mobile Point of Sales (POS) Devices Are Extremely Vulnerable to Credit/Debit Card Data Theft

THREATS

  1. 2018’s worst malware revealed in report
  2. Yi IoT Home Camera Riddled with Code-Execution Vulnerabilities
  3. BLEEDINGBIT Bluetooth flaws in TI chips expose enterprises to remote attacks
  4. Trickbot Malware Now Also Steals Passwords From Apps, Web Browsers
  5. Emotet Malware, the Most Probable Malware of the Year
  6. USB Drives Deliver Dangerous Malware to Industrial Facilities: Honeywell
  7. New Bluetooth Vulnerabilities Exposed in Aruba, Cisco, Meraki Access Points
  8. More Typo-Squatting Malware Found on PyPI
  9. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  10. Ransomware and Back-Up Plans
  11. Windows Defender Bug Needs a Restart, Not Shutdown, To Enable Sandbox
  12. Bluetooth Chip Flaws Expose Enterprises to Remote Attacks
  13. Two Zero-Day Bugs Open Millions of Wireless Access Points to Attack
  14. Cisco says a flaw in its Adaptive Security Appliance allows remote attacks
  15. Talos Vulnerability Deep Dive – TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  16. Security researchers find flaws in chips used in hospitals, factories and stores
  17. Bleedingbit: Critical vulnerabilities in BLE chips expose millions of access points to attack
  18. Bleedingbit zero-day chip flaws may expose majority of enterprises to remote code execution attacks
  19. Cisco Zero-Day Exploited In The Wild To Crash And Reload Devices
  20. Healthcare Industry Continues To Be the Favourite for Ransomware
  21. Employee used US government network for adult websites, infected infrastructure with Russian malware
  22. UK considers banning cryptocurrencies for their lack of “intrinsic value”
  23. Government employee who used to watch porn at work alleged guilty of infecting with malware a network
  24. Zero-Day RCE Vulnerabilities Expose Millions of BLE-Enabled Devices to Attacks
  25. Hackers Exploit Cisco Zero Day Vulnerability in Wild Resulting in DoS Condition
  26. New BLEEDINGBIT Vulnerabilities Affect Widely-Used Bluetooth Chips
  27. Two New Bluetooth Chip Flaws Expose Millions of Devices to Remote Attacks
  28. SamSam Attackers Have Hit 67 Ransomware Targets
  29. .@Siemens disclosed six SICLOCK flaws that were found within its central plant clocks. Discover why three flaws have been rated
  30. Nice work if you can get it: GandCrab ransomware nets millions even though it has been broken
  31. Crypto-Locking Kraken Ransomware Looms Larger
  32. Malware Analysis for Blue Teams
  33. Our fabulous @5ean5ullivan explains to @CyberSauna listeners how the multiple vulnerabilities in the US electoral system may be^H^H^H^H^H^Hare being exploited.
  34. Emotet Malware – Mass-Harvesting millions of Emails in secret Campaign
  35. Crypto Micropayments: an Exciting Future for Blockchain Transactions
  36. Bleedingbit Bluetooth Vulnerabilities Expose WiFi APs to Risk
  37. Hackers Drops New Emotet Malware to Perform Mass Email Exfiltration From Victims Email Client
  38. Talos Vulnerability Deep Dive - TALOS-2018-0636 / CVE-2018-3971 Sophos HitmanPro.Alert vulnerability
  39. New Ramnit Campaign Spreads Azorult Malware
  40. Perl-Based Shellbot Looks to Target Organizations via C&C
  41. Cisco Warns of Zero-Day Vulnerability in Security Appliances
  42. Cisco zero-day exploited in the wild to crash and reload devices
  43. IKARUS Security Software partners with PolySwarm to advance early malware detection
  44. Pdgmail – Forensic Tool to Analysis Process Memory Dump

CRIME

  1. Emotet Malware, the Most Probable Malware of the Year
  2. ‘Aaron Smith’ Sextortion scam campaigns hit tens of thousands of individuals
  3. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  4. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  5. Customer Information Stolen in Radisson Hotel Group Data Breach
  6. British Airways data breach bigger than originally thought
  7. Where Is the Consumer Outrage about Data Breaches?
  8. Radisson Hotel Group suffers data breach, customer info leaked
  9. Healthcare Industry Continues To Be the Favourite for Ransomware
  10. October may be over – but phishing attacks never stop. Here’s how to make security awareness successful all year round.
  11. Government employee who used to watch porn at work alleged guilty of infecting with malware a network
  12. Crypto Micropayments: an Exciting Future for Blockchain Transactions
  13. Expert Insights Names Barracuda’s AI powered Sentinel Top Phishing protection product
  14. Necurs Botnet Distributing Sextortion Email Scams
  15. Beware !! Square & PayPal Mobile Point of Sales (POS) Devices Are Extremely Vulnerable to Credit/Debit Card Data Theft
  16. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

POLITICS

  1. Emotet Malware, the Most Probable Malware of the Year
  2. Open Letter to Francisco Partners: Continued Misuse of NSO Group’s Pegasus Technology
  3. Experts presented BOTCHAIN, the first fully functional Botnet built upon the Bitcoin Protocol
  4. DOJ indictment spotlights China’s civilian intel agency – and its hacker recruits
  5. SamSam Attackers Have Hit 67 Ransomware Targets
  6. Our fabulous @5ean5ullivan explains to @CyberSauna listeners how the multiple vulnerabilities in the US electoral system may be^H^H^H^H^H^Hare being exploited.
  7. Emotet Malware – Mass-Harvesting millions of Emails in secret Campaign
  8. CSM-ACE 2018: FireEye Interview – ASEAN Countries Need to Place Greater Focus on Resourcing Their Cyber Defences

Nov 1, 2018

APT report for 2018-10-31

TRANSNATIONAL / UNKNOWN

  1. URLZone Distributed Via Cutwail Spam Using Steganography
  2. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

  1. Promethium/StrongPity Malware

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-10-31

WINDOWS

  1. 2018’s Most Prevalent Ransomware – We Took it for a Ride
  2. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
  3. Businesses unprepared for Windows 10 migration, fear vulnerability to cyber threats
  4. DDoS Attacks in Q3 2018
  5. Windows 10 Universal Windows Platform Vulnerability
  6. Webroot Unveils Nastiest Malware of 2018
  7. OIG’s Take On Healthcare.gov Patient Record Breach
  8. Microsoft continues to push the KB4464455 patch for fixing ZIP bug

LINUX

  1. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
  2. DDoS Attacks in Q3 2018
  3. Canonical Releases Ubuntu 16.04 LTS Kernel Patch, Fixed 4 Security Vulnerabilities
  4. A DHCPv6 package could compromise a vulnerable Linux system

UNIX

  1. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros

ANDROID

  1. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros

IOS

  1. Apple Fixes Multiple macOS, iOS Bugs Including a Quirky FaceTime Vulnerability
  2. Security Code AutoFill Flaw Exposes iOS, macOS Users to Banking Fraud Attacks
  3. Apple Patches Passcode Bypass, FaceTime Flaws in iOS
  4. Apple Patches Critical Flaws in iOS 12.1, macOS 10.14.1 Updates
  5. Apple Released Security Updates for iOS, watchOS, Safari , tvOS, iTunes & Fixed Several Vulnerabilities

MACOS

  1. Apple Fixes Multiple macOS, iOS Bugs Including a Quirky FaceTime Vulnerability
  2. Security Code AutoFill Flaw Exposes iOS, macOS Users to Banking Fraud Attacks
  3. Apple Patches Passcode Bypass, FaceTime Flaws in iOS
  4. Apple Patches Critical Flaws in iOS 12.1, macOS 10.14.1 Updates
  5. 5 Types of Malware Currently Affecting macOS

Threat report for 2018-10-31

DATA BREACH & DATA LOSS

  1. 85 Millions of voter records available for sale ahead of the 2018 US Midterm Elections
  2. More Information about July 2018’s Singapore SingHealth Data Breach Revealed
  3. Software bugs could compromise midterm votes in Texas
  4. Eurostar Resets Users' Passwords After Potential Data Breach
  5. Why data security is a priority for political campaigns
  6. The Radisson Hotel Group has suffered a data breach
  7. Social Security Numbers, PII Stolen in NorthBay Healthcare Data Breach
  8. Healthcare.gov website suffers data breach affecting 75,000 enrollees
  9. Tomorrowland festival goers affected by data breach
  10. Chinese Intel Agents Indicted for 5-Year IP Theft Campaign
  11. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  12. Nigerian Airline Arik Air May Have Leaked Customer Data
  13. Cyber Attacks Up Prior To Midterms, 81.5 Million Voter Records Threatened
  14. Average data breach fines have doubled as ICO hints at higher fines
  15. Australian companies failing to slow the tide of data breaches: OAIC
  16. Assault and battery: Malvertising campaign checks user device' charge as anti-detection technique
  17. Live Webinar | Identity Proofing in the Era of Data Breaches and Social Networking
  18. Come fermare i data breach con i servizi di Detection&Response #MDR: il caso di un'importante media company finlandese
  19. Fresh SamSam Ransomware Campaign Across the U.S
  20. Nigerian airline Arik Air may have leaked customer data
  21. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  22. SamSam Ransomware Campaigns Highly Active in 2018 and Heavily Targets Organizations
  23. A Report on Data Breaches in Australia
  24. A DHCPv6 package could compromise a vulnerable Linux system
  25. OIG’s Take On Healthcare.gov Patient Record Breach
  26. Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign

DENIAL-OF-SERVICE

  1. DDoS Attacks in Q3 2018

MALVERTISING

  1. Assault and battery: Malvertising campaign checks user device' charge as anti-detection technique

PHISHING

  1. Re: The Zombie Phish
  2. Ramped-up phishing attacks target universities around the world
  3. “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
  4. [Infographic] 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing:

WEB DEFACEMENT

Nil

BOTNET

  1. Re: The Zombie Phish
  2. Google aims to stop the tide of bots with reCAPTCHA v3
  3. Pervasive Emotet Botnet Now Steals Emails
  4. NTT Security targets botnet infrastructure
  5. Satori Botnet's Alleged Developer Rearrested
  6. #Mirai author fined $8.6million, gets 6 months house arrest

RANSOMWARE

  1. SamSam Ransomware Goes on a Tear
  2. 2018’s Most Prevalent Ransomware – We Took it for a Ride
  3. Kraken Ransomware Upgrades Distribution with RaaS Model
  4. GandCrab ransomware crew loses $1M after Bitdefender releases free decrypter
  5. Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
  6. Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
  7. Fresh SamSam Ransomware Campaign Across the U.S
  8. SamSam Ransomware Campaigns Highly Active in 2018 and Heavily Targets Organizations

CRYPTOMINING & CRYPTOCURRENCIES

  1. Kraken Ransomware Upgrades Distribution with RaaS Model
  2. Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
  3. Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
  4. It's a front? Mac cryptocurrency ticker actually installs backdoors
  5. All You Need to Know About Blockchain Testing

MALWARE

  1. Was the Triton Malware Attack Russian in Origin?
  2. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  3. Promethium/StrongPity Malware
  4. “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
  5. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
  6. Double-Gun Trojan which uses game plug-in to spread, is updated to V4.0 and looking for trouble
  7. Emotet Trojan Begins Stealing Victim's Email Using New Module
  8. Emotet trojan starts stealing full emails from infected machines
  9. Recently found GPlayed trojan spinoff analysed
  10. Federal employee infects gov't network with Russian malware through adult video websites
  11. Emotet malware gang is mass-harvesting millions of emails in mysterious campaign
  12. What do you think the combination of the #TrickBot banking Trojan to #IcedID means for the future of banking #Trojans?
  13. 12 malicious libraries found in Python PyPI
  14. 5 Types of Malware Currently Affecting macOS
  15. Webroot Unveils Nastiest Malware of 2018
  16. Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign

EXPLOIT

  1. Kraken Cryptor ransomware merges with Fallout exploit kit, fees slashed to gain followers
  2. Kraken Ransomware Now Being Distributed by Fallout Exploit Kit
  3. Exploit Chain Modified to Slip Antivirus Detection in a New Malware Campaign

VULNERABILITY

  1. Software bugs could compromise midterm votes in Texas
  2. Yi Technology Home Cameras Exploitable Using Multiple Vulnerabilities
  3. Prioritizing the fundamentals of coordinated vulnerability disclosure
  4. Vulnerability Spotlight: Multiple Vulnerabilities in Yi Technology Home Camera
  5. Apple Patches Multiple Major Security Flaws
  6. Actively Exploited High Impact DoS Vulnerability Found in Cisco ASA and FTD
  7. Apple Fixes Multiple macOS, iOS Bugs Including a Quirky FaceTime Vulnerability
  8. Many States Reject DHS Offer to Check Election Systems for Flaws, Saying They’re Safe from Hackers
  9. Security Code AutoFill Flaw Exposes iOS, macOS Users to Banking Fraud Attacks
  10. Whiteboard Wednesday: Common Vulnerabilities as Personified by Halloween Costumes
  11. Vulnerability Spotlight: Multiple Vulnerabilities in Yi Technology Home Camera
  12. Several vulnerabilities were found in controllers made by @Universal_Robot. Discover what these #robot controllers are used for and how
  13. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
  14. Apple Patches Passcode Bypass, FaceTime Flaws in iOS
  15. Businesses unprepared for Windows 10 migration, fear vulnerability to cyber threats
  16. Apple Patches Critical Flaws in iOS 12.1, macOS 10.14.1 Updates
  17. Canonical Releases Ubuntu 16.04 LTS Kernel Patch, Fixed 4 Security Vulnerabilities
  18. CVE-2018-18649: Gitlab Wiki API Remote Code Execution Vulnerability Alert
  19. Apple Released Security Updates for iOS, watchOS, Safari , tvOS, iTunes & Fixed Several Vulnerabilities
  20. Windows 10 Universal Windows Platform Vulnerability
  21. Microsoft continues to push the KB4464455 patch for fixing ZIP bug

Region brief for 2018-10-31

ASIA

  1. More Information about July 2018’s Singapore SingHealth Data Breach Revealed
  2. Was the Triton Malware Attack Russian in Origin?
  3. Chinese Intel Agents Indicted for 5-Year IP Theft Campaign
  4. Many States Reject DHS Offer to Check Election Systems for Flaws, Saying They’re Safe from Hackers
  5. Ramped-up phishing attacks target universities around the world
  6. NTT Security targets botnet infrastructure
  7. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
  8. Fresh SamSam Ransomware Campaign Across the U.S
  9. DDoS Attacks in Q3 2018
  10. Microsoft continues to push the KB4464455 patch for fixing ZIP bug

OCEANIA

  1. Ramped-up phishing attacks target universities around the world
  2. Australian companies failing to slow the tide of data breaches: OAIC
  3. Fresh SamSam Ransomware Campaign Across the U.S
  4. DDoS Attacks in Q3 2018
  5. A Report on Data Breaches in Australia

NORTH AMERICA

  1. 85 Millions of voter records available for sale ahead of the 2018 US Midterm Elections
  2. Prioritizing the fundamentals of coordinated vulnerability disclosure
  3. 2018’s Most Prevalent Ransomware – We Took it for a Ride
  4. Many States Reject DHS Offer to Check Election Systems for Flaws, Saying They’re Safe from Hackers
  5. Ramped-up phishing attacks target universities around the world
  6. Whiteboard Wednesday: Common Vulnerabilities as Personified by Halloween Costumes
  7. Vulnerability Spotlight: Multiple Vulnerabilities in Yi Technology Home Camera
  8. “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
  9. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
  10. Fresh SamSam Ransomware Campaign Across the U.S
  11. Federal employee infects gov't network with Russian malware through adult video websites
  12. DDoS Attacks in Q3 2018
  13. OIG’s Take On Healthcare.gov Patient Record Breach

SOUTH AMERICA

  1. Ramped-up phishing attacks target universities around the world
  2. “Brazilian Election” Themed Phish Target Users with South American-Targeted Malware, Astaroth Trojan
  3. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros

EUROPE

  1. Eurostar Resets Users' Passwords After Potential Data Breach
  2. 2018’s Most Prevalent Ransomware – We Took it for a Ride
  3. Was the Triton Malware Attack Russian in Origin?
  4. Many States Reject DHS Offer to Check Election Systems for Flaws, Saying They’re Safe from Hackers
  5. Ramped-up phishing attacks target universities around the world
  6. Weekly Threat Briefing: New Security Flaw Impacts Most Linux And BSD Distros
  7. Recently found GPlayed trojan spinoff analysed
  8. Fresh SamSam Ransomware Campaign Across the U.S
  9. Federal employee infects gov't network with Russian malware through adult video websites
  10. Businesses unprepared for Windows 10 migration, fear vulnerability to cyber threats
  11. DDoS Attacks in Q3 2018
  12. 12 malicious libraries found in Python PyPI

AFRICA

  1. Ramped-up phishing attacks target universities around the world
  2. Nigerian Airline Arik Air May Have Leaked Customer Data
  3. Nigerian airline Arik Air may have leaked customer data
  4. DDoS Attacks in Q3 2018