Nov 9, 2018

APT report for 2018-11-08

TRANSNATIONAL / UNKNOWN

  1. DerpTrolling game server DoS attacker pleads guilty

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. Symantec Uncovers North Korean Group's ATM Attack Malware
  2. Lazarus Group Targets Bank Networks to Rob ATMs
  3. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  4. Symantec researchers dissect North Korean malware used in ATM attacks
  5. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  6. FASTCash: How the Lazarus Group is Emptying Millions from ATMs

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  3. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-08

WINDOWS

  1. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  2. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  3. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  4. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  5. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  6. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  7. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  8. XSS flaw in Evernote allows attackers to execute commands and steal files

LINUX

Nil

UNIX

  1. Symantec Uncovers North Korean Group's ATM Attack Malware
  2. Lazarus Group Targets Bank Networks to Rob ATMs

ANDROID

  1. Google: Newer Android versions are less affected by malware
  2. Spyware disguised as Spanish banking apps removed from Google Play
  3. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524

IOS

  1. iOS 12.1 Vulnerability

MACOS

Nil

Threat report for 2018-11-08

DATA BREACH & DATA LOSS

  1. California Girl Scouts branch suffers data breach
  2. IT Security Culture Evolution of Businesses Exposed
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. 3.6 Billion Records Exposed in Data Breaches Until the End September 2018
  6. DJI Drone Flight Logs, Photos and Videos Exposed to Unauthorized Access
  7. Canada Post Leaked Personal Data On Cannabis Smokers
  8. Drone Vulnerability Could Compromise Enterprise Data
  9. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  10. Radisson Loyalty Program Compromised
  11. Test Your Employees with Internal Phishing Campaigns
  12. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  13. Business email compromise attacks cost over $676 million in 2017, according to the @FBI's Internet #CrimeReport. Learn how to recognize
  14. According to the 2018 Cost of a Data Breach Study by @PonemonPrivacy & @IBM, the global average cost of a
  15. Canada Post leaked personal data, orders of thousands of cannabis smokers
  16. HSBC Bank Alerts US Customers to Data Breach
  17. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  18. Users Stop Engaging With Brands After Data Breaches, Report Finds
  19. Phishing extortion campaign using new, more effective methods
  20. Gamasutra user privacy fragged following IP leak discovery
  21. HSBC confirms data theft in the United States
  22. Increasing value of personal data a 21st century challenge

DENIAL-OF-SERVICE

  1. Cambodia's ISPs Hit By Massive DDoS Attacks
  2. DerpTroll Admits To DDoS On EA, Steam, Sony Game Servers
  3. 4 Cambodia’s ISPs Attacked by DDoS
  4. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  5. Man Behind DDoS Attacks on Gaming Companies Pleads Guilty
  6. To Pay or Not to Pay: A Large Retailer Responds to #DDoS Extortion Find out what happened here:
  7. Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history
  8. Hacker Behind Series of DoS Attack Targeting Gaming Companies Pleaded Guilty

MALVERTISING

Nil

PHISHING

  1. Test Your Employees with Internal Phishing Campaigns
  2. Most IT Security Pros Underestimate Phishing Risks
  3. Most Enterprises Fail to Implement Proper Protection Against Phishing Attacks
  4. Phishing extortion campaign using new, more effective methods
  5. How many of these bad password habits do you have?
  6. Good article about the password problem and a statistic that shows just how bad a problem it has now become...

WEB DEFACEMENT

Nil

BOTNET

  1. Botnet Infects 100,000 Routers to Send Outlook, Hotmail, and Yahoo Spam
  2. New Spam Botnet Likely Infected 400,000 Devices
  3. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  4. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  5. Spam Botnet of Over 100K Routers Abuses UPnP

RANSOMWARE

  1. Dharma Ransomware Hits Altus Baytown Hospital's Systems

CRYPTOMINING & CRYPTOCURRENCIES

  1. Hackers Charged for Creating 6K Strong Cryptojacking Network
  2. Can Blockchain Solve The Problem of Blood Diamonds?
  3. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  4. Managing the Intersection of Cryptocurrency and Compliance
  5. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  6. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  7. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  8. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  9. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  10. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  11. StatCounter Analytics Code Hijacked to Steal Bitcoins from Cryptocurrency Users

MALWARE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal
  3. Google: Newer Android versions are less affected by malware
  4. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  5. Symantec Uncovers North Korean Group's ATM Attack Malware
  6. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  7. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  8. The Pentagon has suddenly started uploading #malware samples from APTs and other nation-state sources to the website VirusTotal.
  9. Symantec researchers dissect North Korean malware used in ATM attacks
  10. Banking Malware Takes Aim at Brazilians
  11. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  12. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  13. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  14. US Cyber Command starts uploading foreign APT malware to VirusTotal
  15. U.S. Cyber Command malware samples to be logged in VirusTotal
  16. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  17. Spyware disguised as Spanish banking apps removed from Google Play
  18. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  19. Did you miss yesterday's #blog? Catch up on how fileless #malware is changing the way we as organizations are treating
  20. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
  21. U.S. Cyber Command Shares Malware via VirusTotal
  22. US Cyber Command starts uploading foreign APT malware to VirusTotal

EXPLOIT

  1. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  2. Cisco Accidentally Released Dirty Cow Exploit Code in Software
  3. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  4. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online

VULNERABILITY

  1. Companies swamped by critical vulnerabilities – Tenable
  2. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  3. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  4. Steam bug could have given you access to all the CD keys of any game
  5. Drone Vulnerability Could Compromise Enterprise Data
  6. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  7. [SingCERT] Alert on Nginx Vulnerabilities (CVE-2018-16843, CVE-2018-16844, and CVE-2018-16845)
  8. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  9. Several Vulnerabilities Patched in nginx
  10. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  11. WooCommerce Plugin file deletion vulnerability exposes WordPress 'failing open' design flaw
  12. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  13. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  14. DJI Patches Forum Bug That Allowed Drone Account Takeovers
  15. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  16. Ranting researcher publishes VM-busting zero-day without warning
  17. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  18. DJI Drone Vulnerability
  19. iOS 12.1 Vulnerability
  20. Encryption flaws in solid state drives enable unauthorised data access
  21. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  22. Ranting researcher publishes #VM-busting zero-day without warning
  23. We don' need no stinkin' bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
  24. Vulnerabilities In Major Self-Encrypting SSDs Allow Encryption Bypass and Affect Bitlocker
  25. [SingCERT] Alert on Critical Apache Struts 2 Remote Code Execution Vulnerability (CVE-2016-1000031)
  26. XSS flaw in Evernote allows attackers to execute commands and steal files
  27. Critical authentication flaw in DJI drone web app fixed
  28. Commoditization of Computing Hardware and the Bugs It Contains
  29. 4 Million Shops Installed WooCommerce Plugin RCE Flaw Allows Attacker to Gain WordPress Sites Admin Access
  30. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524
  31. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online

Region brief for 2018-11-08

ASIA

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. 689,272 plaintext records of Amex India customers exposed online
  3. Cambodia's ISPs Hit By Massive DDoS Attacks
  4. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  5. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  6. Symantec Uncovers North Korean Group's ATM Attack Malware
  7. Lazarus Group Targets Bank Networks to Rob ATMs
  8. 4 Cambodia’s ISPs Attacked by DDoS
  9. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  10. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  11. Symantec researchers dissect North Korean malware used in ATM attacks
  12. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  13. Spam Botnet of Over 100K Routers Abuses UPnP
  14. Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history
  15. HSBC confirms data theft in the United States
  16. Commoditization of Computing Hardware and the Bugs It Contains

OCEANIA

Nil

NORTH AMERICA

  1. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  2. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. Canada Post Leaked Personal Data On Cannabis Smokers
  6. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  7. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  8. Lazarus Group Targets Bank Networks to Rob ATMs
  9. Most IT Security Pros Underestimate Phishing Risks
  10. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  11. Symantec researchers dissect North Korean malware used in ATM attacks
  12. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  13. Spam Botnet of Over 100K Routers Abuses UPnP
  14. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  15. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  16. Canada Post leaked personal data, orders of thousands of cannabis smokers
  17. HSBC Bank Alerts US Customers to Data Breach
  18. US Cyber Command starts uploading foreign APT malware to VirusTotal
  19. U.S. Cyber Command malware samples to be logged in VirusTotal
  20. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  21. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  22. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  23. U.S. Cyber Command Shares Malware via VirusTotal
  24. HSBC confirms data theft in the United States
  25. US Cyber Command starts uploading foreign APT malware to VirusTotal

SOUTH AMERICA

  1. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  2. Banking Malware Takes Aim at Brazilians
  3. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  4. HSBC confirms data theft in the United States

EUROPE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  3. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  4. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  5. iOS 12.1 Vulnerability
  6. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  7. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  8. Encryption flaws in solid state drives enable unauthorised data access
  9. Spyware disguised as Spanish banking apps removed from Google Play
  10. HSBC confirms data theft in the United States

AFRICA

Nil

Sector brief for 2018-11-08

HEALTHCARE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Dharma Ransomware Hits Altus Baytown Hospital's Systems
  3. Top 5 Threats Healthcare Organizations Face and How to Combat Them

TRANSPORT

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems

BANKING & FINANCE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. California Girl Scouts branch suffers data breach
  3. Dharma Ransomware Hits Altus Baytown Hospital's Systems
  4. Can Blockchain Solve The Problem of Blood Diamonds?
  5. Symantec Uncovers North Korean Group's ATM Attack Malware
  6. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  7. Test Your Employees with Internal Phishing Campaigns
  8. Lazarus Group Targets Bank Networks to Rob ATMs
  9. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  10. Symantec researchers dissect North Korean malware used in ATM attacks
  11. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  12. Banking Malware Takes Aim at Brazilians
  13. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  14. FASTCash: How the Lazarus Group is Emptying Millions from ATMs
  15. HSBC Bank Alerts US Customers to Data Breach
  16. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  17. Spyware disguised as Spanish banking apps removed from Google Play
  18. HSBC confirms data theft in the United States

INFORMATION & TELECOMMUNICATION

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Botnet Infects 100,000 Routers to Send Outlook, Hotmail, and Yahoo Spam
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  6. 4 Cambodia’s ISPs Attacked by DDoS
  7. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  8. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  9. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  10. Spam Botnet of Over 100K Routers Abuses UPnP
  11. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  12. US Cyber Command starts uploading foreign APT malware to VirusTotal
  13. To Pay or Not to Pay: A Large Retailer Responds to #DDoS Extortion Find out what happened here:
  14. How many of these bad password habits do you have?
  15. Did you miss yesterday's #blog? Catch up on how fileless #malware is changing the way we as organizations are treating
  16. Commoditization of Computing Hardware and the Bugs It Contains
  17. Good article about the password problem and a statistic that shows just how bad a problem it has now become...

FOOD

Nil

WATER

Nil

ENERGY

  1. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  2. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems

GOVERNMENT & PUBLIC SERVICE

  1. Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal
  2. Hackers Charged for Creating 6K Strong Cryptojacking Network
  3. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  4. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  5. Lazarus Group Targets Bank Networks to Rob ATMs
  6. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  7. Symantec researchers dissect North Korean malware used in ATM attacks
  8. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  9. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --

Daily brief for 2018-11-08

ASIA

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. 689,272 plaintext records of Amex India customers exposed online
  3. Cambodia's ISPs Hit By Massive DDoS Attacks
  4. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  5. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  6. Symantec Uncovers North Korean Group's ATM Attack Malware
  7. Lazarus Group Targets Bank Networks to Rob ATMs
  8. 4 Cambodia’s ISPs Attacked by DDoS
  9. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  10. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  11. Symantec researchers dissect North Korean malware used in ATM attacks
  12. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  13. Spam Botnet of Over 100K Routers Abuses UPnP
  14. Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history
  15. HSBC confirms data theft in the United States
  16. Commoditization of Computing Hardware and the Bugs It Contains

WORLD

  1. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  2. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. Canada Post Leaked Personal Data On Cannabis Smokers
  6. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  7. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  8. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  9. Lazarus Group Targets Bank Networks to Rob ATMs
  10. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  11. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  12. Most IT Security Pros Underestimate Phishing Risks
  13. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  14. Symantec researchers dissect North Korean malware used in ATM attacks
  15. Banking Malware Takes Aim at Brazilians
  16. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  17. iOS 12.1 Vulnerability
  18. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  19. Spam Botnet of Over 100K Routers Abuses UPnP
  20. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  21. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  22. Encryption flaws in solid state drives enable unauthorised data access
  23. Canada Post leaked personal data, orders of thousands of cannabis smokers
  24. HSBC Bank Alerts US Customers to Data Breach
  25. US Cyber Command starts uploading foreign APT malware to VirusTotal
  26. U.S. Cyber Command malware samples to be logged in VirusTotal
  27. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  28. Spyware disguised as Spanish banking apps removed from Google Play
  29. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  30. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  31. U.S. Cyber Command Shares Malware via VirusTotal
  32. HSBC confirms data theft in the United States
  33. US Cyber Command starts uploading foreign APT malware to VirusTotal

ATTACKS

  1. California Girl Scouts branch suffers data breach
  2. IT Security Culture Evolution of Businesses Exposed
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. 3.6 Billion Records Exposed in Data Breaches Until the End September 2018
  6. DJI Drone Flight Logs, Photos and Videos Exposed to Unauthorized Access
  7. Canada Post Leaked Personal Data On Cannabis Smokers
  8. Drone Vulnerability Could Compromise Enterprise Data
  9. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  10. Radisson Loyalty Program Compromised
  11. Test Your Employees with Internal Phishing Campaigns
  12. Most IT Security Pros Underestimate Phishing Risks
  13. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  14. Business email compromise attacks cost over $676 million in 2017, according to the @FBI's Internet #CrimeReport. Learn how to recognize
  15. Most Enterprises Fail to Implement Proper Protection Against Phishing Attacks
  16. According to the 2018 Cost of a Data Breach Study by @PonemonPrivacy & @IBM, the global average cost of a
  17. Canada Post leaked personal data, orders of thousands of cannabis smokers
  18. HSBC Bank Alerts US Customers to Data Breach
  19. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  20. Users Stop Engaging With Brands After Data Breaches, Report Finds
  21. Phishing extortion campaign using new, more effective methods
  22. Gamasutra user privacy fragged following IP leak discovery
  23. How many of these bad password habits do you have?
  24. HSBC confirms data theft in the United States
  25. Increasing value of personal data a 21st century challenge
  26. Good article about the password problem and a statistic that shows just how bad a problem it has now become...

THREATS

  1. Companies swamped by critical vulnerabilities – Tenable
  2. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  3. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  4. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  5. Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal
  6. Google: Newer Android versions are less affected by malware
  7. Hackers Charged for Creating 6K Strong Cryptojacking Network
  8. Dharma Ransomware Hits Altus Baytown Hospital's Systems
  9. Steam bug could have given you access to all the CD keys of any game
  10. Drone Vulnerability Could Compromise Enterprise Data
  11. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  12. [SingCERT] Alert on Nginx Vulnerabilities (CVE-2018-16843, CVE-2018-16844, and CVE-2018-16845)
  13. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  14. Can Blockchain Solve The Problem of Blood Diamonds?
  15. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  16. Symantec Uncovers North Korean Group's ATM Attack Malware
  17. Several Vulnerabilities Patched in nginx
  18. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  19. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  20. The Pentagon has suddenly started uploading #malware samples from APTs and other nation-state sources to the website VirusTotal.
  21. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  22. WooCommerce Plugin file deletion vulnerability exposes WordPress 'failing open' design flaw
  23. Managing the Intersection of Cryptocurrency and Compliance
  24. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  25. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  26. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  27. DJI Patches Forum Bug That Allowed Drone Account Takeovers
  28. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  29. Symantec researchers dissect North Korean malware used in ATM attacks
  30. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  31. Ranting researcher publishes VM-busting zero-day without warning
  32. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  33. Banking Malware Takes Aim at Brazilians
  34. DJI Drone Vulnerability
  35. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  36. iOS 12.1 Vulnerability
  37. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  38. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  39. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  40. Encryption flaws in solid state drives enable unauthorised data access
  41. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  42. Ranting researcher publishes #VM-busting zero-day without warning
  43. We don' need no stinkin' bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
  44. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  45. Vulnerabilities In Major Self-Encrypting SSDs Allow Encryption Bypass and Affect Bitlocker
  46. [SingCERT] Alert on Critical Apache Struts 2 Remote Code Execution Vulnerability (CVE-2016-1000031)
  47. US Cyber Command starts uploading foreign APT malware to VirusTotal
  48. U.S. Cyber Command malware samples to be logged in VirusTotal
  49. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  50. Spyware disguised as Spanish banking apps removed from Google Play
  51. XSS flaw in Evernote allows attackers to execute commands and steal files
  52. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  53. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  54. Did you miss yesterday's #blog? Catch up on how fileless #malware is changing the way we as organizations are treating
  55. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
  56. U.S. Cyber Command Shares Malware via VirusTotal
  57. Critical authentication flaw in DJI drone web app fixed
  58. Commoditization of Computing Hardware and the Bugs It Contains
  59. 4 Million Shops Installed WooCommerce Plugin RCE Flaw Allows Attacker to Gain WordPress Sites Admin Access
  60. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524
  61. StatCounter Analytics Code Hijacked to Steal Bitcoins from Cryptocurrency Users
  62. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online
  63. US Cyber Command starts uploading foreign APT malware to VirusTotal

CRIME

  1. California Girl Scouts branch suffers data breach
  2. 3.6 Billion Records Exposed in Data Breaches Until the End September 2018
  3. Can Blockchain Solve The Problem of Blood Diamonds?
  4. Radisson Loyalty Program Compromised
  5. Test Your Employees with Internal Phishing Campaigns
  6. Lazarus Group Targets Bank Networks to Rob ATMs
  7. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  8. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  9. Business email compromise attacks cost over $676 million in 2017, according to the @FBI's Internet #CrimeReport. Learn how to recognize
  10. Symantec researchers dissect North Korean malware used in ATM attacks
  11. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  12. Man Behind DDoS Attacks on Gaming Companies Pleads Guilty
  13. DerpTrolling game server DoS attacker pleads guilty
  14. HSBC Bank Alerts US Customers to Data Breach
  15. Phishing extortion campaign using new, more effective methods
  16. To Pay or Not to Pay: A Large Retailer Responds to #DDoS Extortion Find out what happened here:
  17. Spyware disguised as Spanish banking apps removed from Google Play
  18. Hacker Behind Series of DoS Attack Targeting Gaming Companies Pleaded Guilty
  19. HSBC confirms data theft in the United States

POLITICS

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  3. Lazarus Group Targets Bank Networks to Rob ATMs
  4. 4 Cambodia’s ISPs Attacked by DDoS
  5. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  6. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  7. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --

Nov 8, 2018

APT report for 2018-11-07

TRANSNATIONAL / UNKNOWN

  1. Feds get guilty plea in 'DerpTrolling' attacks on video game sites
  2. Goblin Panda
  3. Weekly Threat Briefing: Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts

CHINA

Nil

INDIA

Nil

NORTH KOREA

Nil

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

Nil

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-07

WINDOWS

  1. Evernote Flaw Allows Hackers to Steal Files, Execute Commands
  2. Security Alert: New Dharma Ransomware Strains Alarmingly Go Undetected By Antivirus Engines
  3. Erratic Windows 10 Bug Breaks Changing of Default File Associations
  4. Researcher discloses VirtualBox Zero-Day without reporting it to Oracle
  5. Serious XSS flaw discovered in Evernote for Windows, update now!
  6. Weekly Threat Briefing: Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts
  7. Linux servers and IoT devices, main targets of Shellbot botnet
  8. Vulnerabilities in self encrypted SSD allow attackers to bypass disk encryption

LINUX

  1. Researcher discloses VirtualBox Zero-Day without reporting it to Oracle
  2. Weekly Threat Briefing: Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts
  3. Linux servers and IoT devices, main targets of Shellbot botnet

UNIX

Nil

ANDROID

  1. 3,2 Million New Android Malicious Apps Detected Until the End of Q3 2018
  2. Security Alert: New Dharma Ransomware Strains Alarmingly Go Undetected By Antivirus Engines
  3. Not sure how to tell if your Android phone has a virus? Android malware comes in many forms, ranging from spyware
  4. Weekly Threat Briefing: Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts
  5. November Android Security Update Fixes Critical Bugs, Drops Media Library
  6. We recently detected an Android banking malware campaign (Anubis) actively targeting the Dutch market by #abusing the @PostNL brand. After
  7. Linux servers and IoT devices, main targets of Shellbot botnet

IOS

  1. Weekly Threat Briefing: Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts

MACOS

  1. Weekly Threat Briefing: Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts

Threat report for 2018-11-07

DATA BREACH & DATA LOSS

  1. New Jersey AG Announces $200,000 Settlement with Business Associate and Permanent Ban for BA’s Owner due to 2016 Data Breach Affecting Over 1,650 Patients
  2. Half a Million People Potentially Affected by Data Breach at Bankers Life
  3. Data Of Nearly 700,000 Amex India Customers Exposed Via Unsecured MongoDB Server
  4. HSBC Bank Suffers Data Breach
  5. Amex India accounts exposed by misconfigured MongoDB installation
  6. Data of nearly 700,000 Amex India customers exposed via unsecured MongoDB server
  7. Hacker Leaked Unpatched Virtual Box Zero-day Vulnerability and its Exploit Online
  8. HSBC Bank Data Breach Exposed Customer’s Account Details and More
  9. HSBC US Customers Hit by Data Breach
  10. What do you think is the average cost of a data breach?
  11. HSBC now stands for Hapless Security, Became Compromised: Thousands of customer files snatched by crims
  12. ICO poised to fine Leave campaign and Arron Banks’ insurance biz £135,000
  13. HSBC suffers data breach, customer banking info exposed
  14. We recently detected an Android banking malware campaign (Anubis) actively targeting the Dutch market by #abusing the @PostNL brand. After
  15. New dropper campaign with at least 8 droppers in #GooglePlay (30k+ installs total), found with the help of @avast_antivirus @apklabio.
  16. How voting history data benefits political campaigns
  17. HSBC Bank Data Breach Exposed Account Numbers, Balances, Transaction History and Other Details
  18. Personal data of police and ministries employees leaked by Anonymous Italy
  19. Five Guys suffers employees’ data theft
  20. Rushed My Health Record changes still missing the point
  21. What businesses can learn from political campaigns about using big data

DENIAL-OF-SERVICE

Nil

MALVERTISING

Nil

PHISHING

  1. A Phishing Incident is Being Investigated by the Carthage Police
  2. Why you should use a password manager
  3. They stopped a phishing attack in 10 minutes. It used to take days.
  4. Password Grabber Module Added to Trickbot
  5. Why Password Management and Security Strategies Fall Short
  6. Learn About Phishing Incident Response on Nov 15
  7. Learn why @Google chose U2F authentication over OTP to eliminate #PhishingEmails from expert Michael Cobb of @thehairyITdog.
  8. A poor password is a key for the wrong person to get in.

WEB DEFACEMENT

Nil

BOTNET

  1. IoT Botnet Infects 100,000 Routers To Send Spam
  2. Rapidly Growing Router Botnet Takes Advantage of 5-Year-Old Flaw
  3. IoT botnet infects 100,000 routers to send Hotmail, Outlook, and Yahoo spam
  4. A fresh #botnet is rapidly growing by targeting a five-year-old #vulnerability. So far, @360Netlab said hundreds of thousands of bot
  5. Linux servers and IoT devices, main targets of Shellbot botnet

RANSOMWARE

  1. Healthcare Targeted by 37 Percent of All Ransomware Attacks in Q3 2018
  2. Security Alert: New Dharma Ransomware Strains Alarmingly Go Undetected By Antivirus Engines
  3. #SamSam #ransomware targeted 67 organizations in 2018, according to @symantec research. By @MaddieBacon11
  4. How to Remove NOBAD Ransomware
  5. #Kraken #ransomware as a service is getting more popular after being bundled into the Fallout #ExploitKit and getting more update
  6. Managing Third-Party Risk in the Age of Ransomware

CRYPTOMINING & CRYPTOCURRENCIES

  1. Uni cans crypto-mining CPU raid by switching off whole IT network
  2. Salesforce Aims to Curb Spam With Blockchain
  3. Using Blockchain Technology to Solve Global Problems
  4. JavaScript attack aimed to reroute bitcoin transactions
  5. University shuts down network to thwart Bitcoin cryptojacking scheme
  6. Attackers breached Statcounter to steal cryptocurrency from gate.io users
  7. Elon Musk Bitcoin Scammers Hijack Verified Status Accounts
  8. #Kraken #ransomware as a service is getting more popular after being bundled into the Fallout #ExploitKit and getting more update
  9. Hackers seed StatCounter with nasty JavaScript in elaborate Bitcoin theft scheme
  10. Blockchain: The Good, the Bad and the Legal
  11. New cryptocurrencies offer better anonymity, new security challenges, from @CSOonline http://0fox.co/sSmx30i8vm4 ZeroFOX CTO weighs in on the #infosec challenges
  12. Bitcoin Cryptojacking Attack Forces University to Disable Entire Network
  13. Researchers rank cryptocurrency exchanges by how secure they are

MALWARE

  1. Cisco removed its seventh backdoor account this year, and that's a good thing
  2. 3,2 Million New Android Malicious Apps Detected Until the End of Q3 2018
  3. Not sure how to tell if your Android phone has a virus? Android malware comes in many forms, ranging from spyware
  4. Weekly Threat Briefing: Scammers Ride on Popular Vote411 Voter Info Site to Push Scareware Alerts
  5. On the #blog today, we talk about how fileless malware is changing the way we as organizations treats #cyberthreats.
  6. We recently detected an Android banking malware campaign (Anubis) actively targeting the Dutch market by #abusing the @PostNL brand. After
  7. New dropper campaign with at least 8 droppers in #GooglePlay (30k+ installs total), found with the help of @avast_antivirus @apklabio.
  8. Coupa Simplifies Fragmented B2B Payments Process
  9. Turning Malware Trends into Proactive Behaviors
  10. DHS on Election Day: No malicious cyber-activity observed
  11. AMD and TSMC outline 7nm process products to be listed next year

EXPLOIT

  1. Hacker Leaked Unpatched Virtual Box Zero-day Vulnerability and its Exploit Online
  2. VirtualBox Guest-to-Host escape 0day and exploit released online
  3. According to @digitalshadows, attackers used a browser exploit to steal the private #Facebook messages of at least 81,000 people. Read
  4. #Virtualbox hat eine #Zeroday Sicherheitslücke. Tipp: Ändern Sie Ihren virtuellen Netzwerkadapter auf etwas anderes als Intel PRO/1000.
  5. VirtualBox Zero-Day Vulnerability Details and Exploit Are Publicly Available

VULNERABILITY

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. Security Flaws Found in Widely Used Data Storage Devices | Avast
  3. A flaw in WooCommerce WordPress Plugin could be exploited to take over e-stores
  4. Flaw in Icecast streaming media server allows to take off online Radio Stations
  5. VirtualBox zero-day dumped on GitHub
  6. Security Researcher Drops VirtualBox Guest-to-Host Escape Zero-Day on GitHub
  7. WordPress Flaw Opens Millions of WooCommerce Shops to Takeover
  8. Rapidly Growing Router Botnet Takes Advantage of 5-Year-Old Flaw
  9. Flaw Leads to RCE in WordPress Plugins, WooCommerce
  10. Hacker education, inclusivity, and shifting perceptions of bug bounties
  11. Apache alerts developers of remote code execution flaw
  12. Evernote Flaw Allows Hackers to Steal Files, Execute Commands
  13. Top 20 application vulnerabilities in the enterprise are dominated by Adobe and Microsoft
  14. Equifax nemesis Apache Struts found vulnerable to 2-year old unpatched flaw; workaround available
  15. Rapid7 Wins Frost & Sullivan 2018 Global Vulnerability Management Market Leadership Award
  16. Hacker Leaked Unpatched Virtual Box Zero-day Vulnerability and its Exploit Online
  17. Zero-day flaw in VirtualBox details go public
  18. Erratic Windows 10 Bug Breaks Changing of Default File Associations
  19. Researcher discloses VirtualBox Zero-Day without reporting it to Oracle
  20. Serious XSS flaw discovered in Evernote for Windows, update now!
  21. Researchers say #Bleedingbit vulnerabilities could allow #RemoteCodeExecution on wireless access points, medical devices and any other products using the affected
  22. Enterprises Sinking Under 100+ Critical Flaws Per Day
  23. WordPress, WooCommerce flaws combine to allow website hijacking
  24. Apache Struts vulnerability would allow system take over
  25. Up to 4 million online merchants who use the popular @WooCommerce #WordPress plugin are vulnerable to a file deletion flaw.
  26. Researcher Drops Oracle VirtualBox Zero-Day
  27. Stop us if you've heard this one: Remote code hijacking flaw in Apache Struts, patch ASAP
  28. Bug bounty: Hack the US Air Force and Get Paid
  29. Microsoft, Google apps feature in the top 20 vulnerabilities in enterprise environments
  30. VirtualBox zero-day published by disgruntled researcher
  31. A fresh #botnet is rapidly growing by targeting a five-year-old #vulnerability. So far, @360Netlab said hundreds of thousands of bot
  32. .@Siemens SICLOCK central plant clocks were recently found to be affected by several vulnerabilities, some of which have been rated
  33. Apache Struts users have to update FileUpload library to fix years-old flaws
  34. Zero-Day #Vulnerability Explained
  35. November Android Security Update Fixes Critical Bugs, Drops Media Library
  36. Researcher publishes new VirtualBox zero-day vulnerability
  37. Vulnerabilities in self encrypted SSD allow attackers to bypass disk encryption
  38. #Virtualbox hat eine #Zeroday Sicherheitslücke. Tipp: Ändern Sie Ihren virtuellen Netzwerkadapter auf etwas anderes als Intel PRO/1000.
  39. Popular WooCommerce WordPress Plugin Patches Critical Vulnerability
  40. Google's automated fuzz bot has found over 9,000 bugs in the past two years
  41. VirtualBox Zero-Day Vulnerability Details and Exploit Are Publicly Available