Nov 10, 2018

APT report for 2018-11-09

TRANSNATIONAL / UNKNOWN

  1. Inception Attackers Target Europe with Year-old Office Vulnerability
  2. Inception hackers target European organisations with old Office flaw
  3. DerpTrolling game server DDoS attacker pleads guilty
  4. Sony DDoS-er 'DerpTrolling' Pleads Guilty
  5. Guy Fawkes Day – LulzSec Italy hit numerous organizations in Italy
  6. Notorious "DerpTrolling" Pleads Guilty to DDoS Attacks on EA & Sony

CHINA

  1. Playbook Fridays: Domain Spinning Workbench Spaces App

INDIA

Nil

NORTH KOREA

  1. Lazarus FASTCash ATM Attack Details Discovered
  2. Lazarus FASTCash ATM attack details discovered
  3. Latest Hacking News Podcast

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Playbook Fridays: Domain Spinning Workbench Spaces App
  2. VirusTotal and USCyberCom Join Forces To Identify Malware

SERBIA

Nil

UKRAINE

  1. Playbook Fridays: Domain Spinning Workbench Spaces App

Platform report for 2018-11-09

WINDOWS

  1. Koadic: Security Defense in the Age of LoL Malware, Part IV
  2. Stealthy Crypto-Mining Malware Evades Detection
  3. This Week in Security News: Fake Apps & Malicious Bots
  4. Inception Attackers Target Europe with Year-old Office Vulnerability
  5. Serious XSS Vulnerability Patched in Evernote
  6. Phishing now possible by exploiting online video function vulnerability in Word
  7. Hackers hide malware in the Windows installation files to mine cryptocurrency

LINUX

  1. Cryptomining Malware Uses Rootkit to Hide on Infected Linux Systems
  2. This Week in Security News: Fake Apps & Malicious Bots
  3. Linux cryptocurrency miners are installing rootkits to hide themselves
  4. Seagate and IBM Work Together to Help Reduce Global Hard Drive Counterfeiting with Blockchain Technology

UNIX

Nil

ANDROID

  1. This Week in Security News: Fake Apps & Malicious Bots

IOS

  1. Bug Bounty Hunter Ran ISP Doxing Service
  2. Phishing Attempts Soar to 137 Million in Q3
  3. Snowden speaks about the role of surveillance firm NSO Group in Khashoggi murder

MACOS

  1. Bug Bounty Hunter Ran ISP Doxing Service
  2. OSX/SurfBuyer: Real malware is in the eye of the device holder

Threat report for 2018-11-09

DATA BREACH & DATA LOSS

  1. Email Stealing Emotet Banking Trojan Resurrected in New Extensive Spam Campaign
  2. Oops: Cisco accidentally leaked in-house Dirty COW exploit code with biz conf call software
  3. Bug Bounty Hunter Ran ISP Doxing Service
  4. DJI drone hack could have exposed sensitive data
  5. Emotet launches major new spam campaign
  6. .@ablaich: “Breaches that include personally identifiable information are always dangerous because they can lead to identity theft... they can also
  7. Canada Post leaks sensitive information of thousands of cannabis buyers
  8. D93 staff accounts compromised through a phishing scam
  9. Drone vulnerability could compromise enterprise data
  10. "If the schemas prove not to be compatible, a backup of the previous version of a database must be used
  11. Exposed data of nearly 700k American Express India customers
  12. Nearly 700,000 Plaintext Records of American Express India Customers Personal Info Exposed Online

DENIAL-OF-SERVICE

  1. 'DerpTroll' derps into plea deal, admits DDoS attacks on EA, Steam, Sony game servers
  2. DerpTrolling game server DDoS attacker pleads guilty
  3. Sony DDoS-er 'DerpTrolling' Pleads Guilty
  4. Notorious "DerpTrolling" Pleads Guilty to DDoS Attacks on EA & Sony

MALVERTISING

Nil

PHISHING

  1. Trickbot Malware Added Password And Browser History Stealing
  2. Man Sent Letter Bomb To Bitcoin Firm Over Password Reset
  3. This banking malware just added password and browser history stealing to its playbook
  4. This banking #malware just added #password and browser history stealing to its playbook https://zd.net/2Pl6v31 via @ZDNet & @dannyjpalmer
  5. Phishing Attempts Soar to 137 Million in Q3
  6. Phishing now possible by exploiting online video function vulnerability in Word
  7. D93 staff accounts compromised through a phishing scam
  8. 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing | Check out the full infographic here:
  9. Criminals are targeting cardless ATMs with the help of SMS text-based phishing (aka smishing) to drain bank accounts using stolen

WEB DEFACEMENT

Nil

BOTNET

  1. Spammer scum hack 100,000 home routers via UPnP vulns to craft email-flinging botnet
  2. This Week in Security News: Fake Apps & Malicious Bots
  3. New spam botnet infects over 100,000 home routers
  4. A new spam #botnet took advantage of a UPnP vulnerability to infect over 100,000 home routers in India, China and
  5. IoT botnet BCMUPnP_Hunter targets routers with vulnerable UPnP feature
  6. BCMPUPnP_Hunter Botnet infected 400k routers to turn them in email spammers

RANSOMWARE

  1. Ransomware Still the Top Malware Threat During 2018 According to Europol
  2. The Week in Ransomware - November 9th 2018 - Mostly Dharma Variants
  3. Kraken Ransomware
  4. Are you prepared for #ransomware? Download this how-to guide to learn how to prepare for and detect an attack before

CRYPTOMINING & CRYPTOCURRENCIES

  1. StatCounter fingers cache-poisoning caper for Bitcoin-slurping JavaScript hijack
  2. Cryptomining Malware Uses Rootkit to Hide on Infected Linux Systems
  3. Stealthy Crypto-Mining Malware Evades Detection
  4. Man Sent Letter Bomb To Bitcoin Firm Over Password Reset
  5. Linux cryptocurrency miners are installing rootkits to hide themselves
  6. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  7. Kraken Ransomware
  8. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  9. No, You Don't Need a Blockchain
  10. Canadian Uni Shutters Network After Cryptomining Attack
  11. Hackers hide malware in the Windows installation files to mine cryptocurrency
  12. Visiting Bitcoin City.
  13. Seagate and IBM Work Together to Help Reduce Global Hard Drive Counterfeiting with Blockchain Technology

MALWARE

  1. Hackers Target Bitcoins and USCYBERCOM Shares Malware | Avast
  2. Koadic: Security Defense in the Age of LoL Malware, Part IV
  3. Email Stealing Emotet Banking Trojan Resurrected in New Extensive Spam Campaign
  4. Ransomware Still the Top Malware Threat During 2018 According to Europol
  5. The Pentagon is Publishing Foreign Nation-State Malware
  6. Cryptomining Malware Uses Rootkit to Hide on Infected Linux Systems
  7. Stealthy Crypto-Mining Malware Evades Detection
  8. Advanced tools: Process Hacker
  9. Trickbot Malware Added Password And Browser History Stealing
  10. This Week in Security News: Fake Apps & Malicious Bots
  11. "Inception Attackers" Combine Old Exploit and New Backdoor
  12. Playbook Fridays: Domain Spinning Workbench Spaces App
  13. This banking malware just added password and browser history stealing to its playbook
  14. South Korean Hackers Arrested for Infecting Cryto Mining Malware
  15. #Cyberespionage hackers have used stolen #DigitalCertificates to steal data. Expert Michael Cobb of @thehairyITdog explains how hackers sign Plead
  16. This banking #malware just added #password and browser history stealing to its playbook https://zd.net/2Pl6v31 via @ZDNet & @dannyjpalmer
  17. The Morris Worm Turns 30
  18. Idaho Falls School District Struck by a Computer Virus Attack
  19. OSX/SurfBuyer: Real malware is in the eye of the device holder
  20. How is Plead malware used for cyberespionage attacks?
  21. VirusTotal and USCyberCom Join Forces To Identify Malware
  22. Hackers hide malware in the Windows installation files to mine cryptocurrency
  23. U.S. Cyber Command #malware samples will be shared to #VirusTotal by the Cyber National Mission Force and one expert said

EXPLOIT

  1. Oops: Cisco accidentally leaked in-house Dirty COW exploit code with biz conf call software
  2. "Inception Attackers" Combine Old Exploit and New Backdoor

VULNERABILITY

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. Recently-Patched Adobe ColdFusion Flaw Exploited By APT
  3. Zero-day in popular WordPress plugin exploited in the wild to take over sites
  4. Bug Bounty Hunter Ran ISP Doxing Service
  5. VMware releases security patches for a critical virtual machine escape flaw
  6. Infosec Problems For 2019 and Beyond: Patching, Bug Bounties and Hype
  7. VMware Patches VM Escape Flaw Disclosed at Chinese Hacking Contest
  8. Inception Attackers Target Europe with Year-old Office Vulnerability
  9. Flaws in Roche Medical Devices Can Put Patients at Risk
  10. Inception hackers target European organisations with old Office flaw
  11. A new spam #botnet took advantage of a UPnP vulnerability to infect over 100,000 home routers in India, China and
  12. Serious XSS Vulnerability Patched in Evernote
  13. Update now! WordPress sites vulnerable to WooCommerce plugin flaw
  14. Phishing now possible by exploiting online video function vulnerability in Word
  15. Vulnerabilities in Our Infrastructure: 5 Ways to Mitigate the Risk
  16. Cisco fixes two critical bugs, recommends workaround for a third
  17. Drone vulnerability could compromise enterprise data
  18. US Air Force invites white hats to find hackable flaws, again
  19. Prioritizing Flaws Based on Severity Increasingly Ineffective: Study
  20. DJI Drone Can be Hacked using New Vulnerability To Steal Drone’s Flight logs, Photos & Videos
  21. Adobe ColdFusion Vulnerability Exploited in the Wild
  22. Combination of bugs in WordPress and WooCommerce allows website hijacking
  23. Hack the Air Force 3.0 – New vulnerability bounty program

Region brief for 2018-11-09

ASIA

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. VMware releases security patches for a critical virtual machine escape flaw
  3. VMware Patches VM Escape Flaw Disclosed at Chinese Hacking Contest
  4. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  5. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  6. Playbook Fridays: Domain Spinning Workbench Spaces App
  7. A new spam #botnet took advantage of a UPnP vulnerability to infect over 100,000 home routers in India, China and
  8. South Korean Hackers Arrested for Infecting Cryto Mining Malware
  9. Phishing Attempts Soar to 137 Million in Q3
  10. Phishing now possible by exploiting online video function vulnerability in Word
  11. Snowden speaks about the role of surveillance firm NSO Group in Khashoggi murder
  12. BCMPUPnP_Hunter Botnet infected 400k routers to turn them in email spammers
  13. Exposed data of nearly 700k American Express India customers
  14. Hack the Air Force 3.0 – New vulnerability bounty program
  15. Nearly 700,000 Plaintext Records of American Express India Customers Personal Info Exposed Online

OCEANIA

Nil

NORTH AMERICA

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. Koadic: Security Defense in the Age of LoL Malware, Part IV
  3. 'DerpTroll' derps into plea deal, admits DDoS attacks on EA, Steam, Sony game servers
  4. Bug Bounty Hunter Ran ISP Doxing Service
  5. VMware releases security patches for a critical virtual machine escape flaw
  6. The Pentagon is Publishing Foreign Nation-State Malware
  7. Advanced tools: Process Hacker
  8. This Week in Security News: Fake Apps & Malicious Bots
  9. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  10. Playbook Fridays: Domain Spinning Workbench Spaces App
  11. A new spam #botnet took advantage of a UPnP vulnerability to infect over 100,000 home routers in India, China and
  12. Canada Post leaks sensitive information of thousands of cannabis buyers
  13. Phishing Attempts Soar to 137 Million in Q3
  14. Sony DDoS-er 'DerpTrolling' Pleads Guilty
  15. D93 staff accounts compromised through a phishing scam
  16. Snowden speaks about the role of surveillance firm NSO Group in Khashoggi murder
  17. Canadian Uni Shutters Network After Cryptomining Attack
  18. US Air Force invites white hats to find hackable flaws, again
  19. BCMPUPnP_Hunter Botnet infected 400k routers to turn them in email spammers
  20. VirusTotal and USCyberCom Join Forces To Identify Malware
  21. Exposed data of nearly 700k American Express India customers
  22. Hack the Air Force 3.0 – New vulnerability bounty program
  23. Nearly 700,000 Plaintext Records of American Express India Customers Personal Info Exposed Online
  24. U.S. Cyber Command #malware samples will be shared to #VirusTotal by the Cyber National Mission Force and one expert said

SOUTH AMERICA

Nil

EUROPE

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. Stealthy Crypto-Mining Malware Evades Detection
  3. Infosec Problems For 2019 and Beyond: Patching, Bug Bounties and Hype
  4. Inception Attackers Target Europe with Year-old Office Vulnerability
  5. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  6. Playbook Fridays: Domain Spinning Workbench Spaces App
  7. Flaws in Roche Medical Devices Can Put Patients at Risk
  8. Phishing Attempts Soar to 137 Million in Q3
  9. Guy Fawkes Day – LulzSec Italy hit numerous organizations in Italy
  10. Hack the Air Force 3.0 – New vulnerability bounty program
  11. Hackers hide malware in the Windows installation files to mine cryptocurrency

AFRICA

Nil

Sector brief for 2018-11-09

HEALTHCARE

  1. Playbook Fridays: Domain Spinning Workbench Spaces App
  2. Flaws in Roche Medical Devices Can Put Patients at Risk

TRANSPORT

Nil

BANKING & FINANCE

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. Email Stealing Emotet Banking Trojan Resurrected in New Extensive Spam Campaign
  3. Bug Bounty Hunter Ran ISP Doxing Service
  4. Stealthy Crypto-Mining Malware Evades Detection
  5. Lazarus FASTCash ATM Attack Details Discovered
  6. This Week in Security News: Fake Apps & Malicious Bots
  7. Playbook Fridays: Domain Spinning Workbench Spaces App
  8. This banking malware just added password and browser history stealing to its playbook
  9. Canada Post leaks sensitive information of thousands of cannabis buyers
  10. This banking #malware just added #password and browser history stealing to its playbook https://zd.net/2Pl6v31 via @ZDNet & @dannyjpalmer
  11. Phishing Attempts Soar to 137 Million in Q3
  12. Sony DDoS-er 'DerpTrolling' Pleads Guilty
  13. Lazarus FASTCash ATM attack details discovered
  14. Criminals are targeting cardless ATMs with the help of SMS text-based phishing (aka smishing) to drain bank accounts using stolen
  15. Exposed data of nearly 700k American Express India customers
  16. Hack the Air Force 3.0 – New vulnerability bounty program

INFORMATION & TELECOMMUNICATION

  1. Bug Bounty Hunter Ran ISP Doxing Service
  2. VMware releases security patches for a critical virtual machine escape flaw
  3. Advanced tools: Process Hacker
  4. This Week in Security News: Fake Apps & Malicious Bots
  5. Playbook Fridays: Domain Spinning Workbench Spaces App
  6. .@ablaich: “Breaches that include personally identifiable information are always dangerous because they can lead to identity theft... they can also
  7. Canada Post leaks sensitive information of thousands of cannabis buyers
  8. Are you prepared for #ransomware? Download this how-to guide to learn how to prepare for and detect an attack before
  9. Phishing now possible by exploiting online video function vulnerability in Word
  10. BCMPUPnP_Hunter Botnet infected 400k routers to turn them in email spammers
  11. 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing | Check out the full infographic here:
  12. Visiting Bitcoin City.

FOOD

Nil

WATER

Nil

ENERGY

  1. Chinese headmaster fired after setting up his own secret cryptomining rig at school

GOVERNMENT & PUBLIC SERVICE

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. Bug Bounty Hunter Ran ISP Doxing Service
  3. The Pentagon is Publishing Foreign Nation-State Malware
  4. This Week in Security News: Fake Apps & Malicious Bots
  5. Playbook Fridays: Domain Spinning Workbench Spaces App
  6. South Korean Hackers Arrested for Infecting Cryto Mining Malware
  7. Guy Fawkes Day – LulzSec Italy hit numerous organizations in Italy
  8. VirusTotal and USCyberCom Join Forces To Identify Malware
  9. Hack the Air Force 3.0 – New vulnerability bounty program

Daily brief for 2018-11-09

ASIA

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. VMware releases security patches for a critical virtual machine escape flaw
  3. VMware Patches VM Escape Flaw Disclosed at Chinese Hacking Contest
  4. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  5. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  6. Playbook Fridays: Domain Spinning Workbench Spaces App
  7. A new spam #botnet took advantage of a UPnP vulnerability to infect over 100,000 home routers in India, China and
  8. South Korean Hackers Arrested for Infecting Cryto Mining Malware
  9. Phishing Attempts Soar to 137 Million in Q3
  10. Phishing now possible by exploiting online video function vulnerability in Word
  11. Snowden speaks about the role of surveillance firm NSO Group in Khashoggi murder
  12. BCMPUPnP_Hunter Botnet infected 400k routers to turn them in email spammers
  13. Exposed data of nearly 700k American Express India customers
  14. Hack the Air Force 3.0 – New vulnerability bounty program
  15. Nearly 700,000 Plaintext Records of American Express India Customers Personal Info Exposed Online

WORLD

  1. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  2. Koadic: Security Defense in the Age of LoL Malware, Part IV
  3. 'DerpTroll' derps into plea deal, admits DDoS attacks on EA, Steam, Sony game servers
  4. Bug Bounty Hunter Ran ISP Doxing Service
  5. VMware releases security patches for a critical virtual machine escape flaw
  6. The Pentagon is Publishing Foreign Nation-State Malware
  7. Stealthy Crypto-Mining Malware Evades Detection
  8. Infosec Problems For 2019 and Beyond: Patching, Bug Bounties and Hype
  9. Advanced tools: Process Hacker
  10. This Week in Security News: Fake Apps & Malicious Bots
  11. Inception Attackers Target Europe with Year-old Office Vulnerability
  12. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  13. Playbook Fridays: Domain Spinning Workbench Spaces App
  14. Flaws in Roche Medical Devices Can Put Patients at Risk
  15. A new spam #botnet took advantage of a UPnP vulnerability to infect over 100,000 home routers in India, China and
  16. Canada Post leaks sensitive information of thousands of cannabis buyers
  17. Phishing Attempts Soar to 137 Million in Q3
  18. Sony DDoS-er 'DerpTrolling' Pleads Guilty
  19. D93 staff accounts compromised through a phishing scam
  20. Snowden speaks about the role of surveillance firm NSO Group in Khashoggi murder
  21. Canadian Uni Shutters Network After Cryptomining Attack
  22. US Air Force invites white hats to find hackable flaws, again
  23. Guy Fawkes Day – LulzSec Italy hit numerous organizations in Italy
  24. BCMPUPnP_Hunter Botnet infected 400k routers to turn them in email spammers
  25. VirusTotal and USCyberCom Join Forces To Identify Malware
  26. Exposed data of nearly 700k American Express India customers
  27. Hack the Air Force 3.0 – New vulnerability bounty program
  28. Hackers hide malware in the Windows installation files to mine cryptocurrency
  29. Nearly 700,000 Plaintext Records of American Express India Customers Personal Info Exposed Online
  30. U.S. Cyber Command #malware samples will be shared to #VirusTotal by the Cyber National Mission Force and one expert said

ATTACKS

  1. Email Stealing Emotet Banking Trojan Resurrected in New Extensive Spam Campaign
  2. Oops: Cisco accidentally leaked in-house Dirty COW exploit code with biz conf call software
  3. Bug Bounty Hunter Ran ISP Doxing Service
  4. DJI drone hack could have exposed sensitive data
  5. Trickbot Malware Added Password And Browser History Stealing
  6. Man Sent Letter Bomb To Bitcoin Firm Over Password Reset
  7. Emotet launches major new spam campaign
  8. .@ablaich: “Breaches that include personally identifiable information are always dangerous because they can lead to identity theft... they can also
  9. This banking malware just added password and browser history stealing to its playbook
  10. Canada Post leaks sensitive information of thousands of cannabis buyers
  11. This banking #malware just added #password and browser history stealing to its playbook https://zd.net/2Pl6v31 via @ZDNet & @dannyjpalmer
  12. Phishing Attempts Soar to 137 Million in Q3
  13. Phishing now possible by exploiting online video function vulnerability in Word
  14. D93 staff accounts compromised through a phishing scam
  15. Drone vulnerability could compromise enterprise data
  16. "If the schemas prove not to be compatible, a backup of the previous version of a database must be used
  17. 5 Ways #Cybercriminals Can Access Your Emails Without #Phishing | Check out the full infographic here:
  18. Criminals are targeting cardless ATMs with the help of SMS text-based phishing (aka smishing) to drain bank accounts using stolen
  19. Exposed data of nearly 700k American Express India customers
  20. Nearly 700,000 Plaintext Records of American Express India Customers Personal Info Exposed Online

THREATS

  1. Hackers Target Bitcoins and USCYBERCOM Shares Malware | Avast
  2. U.S. Air Force announced Hack the Air Force 3.0, the third Bug Bounty Program
  3. Koadic: Security Defense in the Age of LoL Malware, Part IV
  4. Recently-Patched Adobe ColdFusion Flaw Exploited By APT
  5. Email Stealing Emotet Banking Trojan Resurrected in New Extensive Spam Campaign
  6. StatCounter fingers cache-poisoning caper for Bitcoin-slurping JavaScript hijack
  7. Zero-day in popular WordPress plugin exploited in the wild to take over sites
  8. Bug Bounty Hunter Ran ISP Doxing Service
  9. VMware releases security patches for a critical virtual machine escape flaw
  10. Ransomware Still the Top Malware Threat During 2018 According to Europol
  11. The Pentagon is Publishing Foreign Nation-State Malware
  12. Cryptomining Malware Uses Rootkit to Hide on Infected Linux Systems
  13. The Week in Ransomware - November 9th 2018 - Mostly Dharma Variants
  14. Stealthy Crypto-Mining Malware Evades Detection
  15. Infosec Problems For 2019 and Beyond: Patching, Bug Bounties and Hype
  16. Advanced tools: Process Hacker
  17. Trickbot Malware Added Password And Browser History Stealing
  18. Man Sent Letter Bomb To Bitcoin Firm Over Password Reset
  19. This Week in Security News: Fake Apps & Malicious Bots
  20. "Inception Attackers" Combine Old Exploit and New Backdoor
  21. Linux cryptocurrency miners are installing rootkits to hide themselves
  22. VMware Patches VM Escape Flaw Disclosed at Chinese Hacking Contest
  23. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  24. Kraken Ransomware
  25. Inception Attackers Target Europe with Year-old Office Vulnerability
  26. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  27. Playbook Fridays: Domain Spinning Workbench Spaces App
  28. Flaws in Roche Medical Devices Can Put Patients at Risk
  29. This banking malware just added password and browser history stealing to its playbook
  30. Inception hackers target European organisations with old Office flaw
  31. A new spam #botnet took advantage of a UPnP vulnerability to infect over 100,000 home routers in India, China and
  32. South Korean Hackers Arrested for Infecting Cryto Mining Malware
  33. Serious XSS Vulnerability Patched in Evernote
  34. #Cyberespionage hackers have used stolen #DigitalCertificates to steal data. Expert Michael Cobb of @thehairyITdog explains how hackers sign Plead
  35. Update now! WordPress sites vulnerable to WooCommerce plugin flaw
  36. Are you prepared for #ransomware? Download this how-to guide to learn how to prepare for and detect an attack before
  37. This banking #malware just added #password and browser history stealing to its playbook https://zd.net/2Pl6v31 via @ZDNet & @dannyjpalmer
  38. The Morris Worm Turns 30
  39. Phishing now possible by exploiting online video function vulnerability in Word
  40. Idaho Falls School District Struck by a Computer Virus Attack
  41. Vulnerabilities in Our Infrastructure: 5 Ways to Mitigate the Risk
  42. OSX/SurfBuyer: Real malware is in the eye of the device holder
  43. No, You Don't Need a Blockchain
  44. Cisco fixes two critical bugs, recommends workaround for a third
  45. Canadian Uni Shutters Network After Cryptomining Attack
  46. Drone vulnerability could compromise enterprise data
  47. US Air Force invites white hats to find hackable flaws, again
  48. How is Plead malware used for cyberespionage attacks?
  49. Prioritizing Flaws Based on Severity Increasingly Ineffective: Study
  50. DJI Drone Can be Hacked using New Vulnerability To Steal Drone’s Flight logs, Photos & Videos
  51. Adobe ColdFusion Vulnerability Exploited in the Wild
  52. VirusTotal and USCyberCom Join Forces To Identify Malware
  53. Combination of bugs in WordPress and WooCommerce allows website hijacking
  54. Hack the Air Force 3.0 – New vulnerability bounty program
  55. Hackers hide malware in the Windows installation files to mine cryptocurrency
  56. Visiting Bitcoin City.
  57. Seagate and IBM Work Together to Help Reduce Global Hard Drive Counterfeiting with Blockchain Technology
  58. U.S. Cyber Command #malware samples will be shared to #VirusTotal by the Cyber National Mission Force and one expert said

CRIME

  1. Email Stealing Emotet Banking Trojan Resurrected in New Extensive Spam Campaign
  2. 'DerpTroll' derps into plea deal, admits DDoS attacks on EA, Steam, Sony game servers
  3. Bug Bounty Hunter Ran ISP Doxing Service
  4. Ransomware Still the Top Malware Threat During 2018 According to Europol
  5. Advanced tools: Process Hacker
  6. This Week in Security News: Fake Apps & Malicious Bots
  7. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  8. Playbook Fridays: Domain Spinning Workbench Spaces App
  9. .@ablaich: “Breaches that include personally identifiable information are always dangerous because they can lead to identity theft... they can also
  10. South Korean Hackers Arrested for Infecting Cryto Mining Malware
  11. #Cyberespionage hackers have used stolen #DigitalCertificates to steal data. Expert Michael Cobb of @thehairyITdog explains how hackers sign Plead
  12. DerpTrolling game server DDoS attacker pleads guilty
  13. Phishing Attempts Soar to 137 Million in Q3
  14. Sony DDoS-er 'DerpTrolling' Pleads Guilty
  15. D93 staff accounts compromised through a phishing scam
  16. How is Plead malware used for cyberespionage attacks?
  17. Criminals are targeting cardless ATMs with the help of SMS text-based phishing (aka smishing) to drain bank accounts using stolen
  18. Latest Hacking News Podcast
  19. Notorious "DerpTrolling" Pleads Guilty to DDoS Attacks on EA & Sony

POLITICS

  1. This Week in Security News: Fake Apps & Malicious Bots
  2. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  3. Chinese headmaster fired after setting up his own secret cryptomining rig at school
  4. #Cyberespionage hackers have used stolen #DigitalCertificates to steal data. Expert Michael Cobb of @thehairyITdog explains how hackers sign Plead
  5. Phishing Attempts Soar to 137 Million in Q3
  6. Snowden speaks about the role of surveillance firm NSO Group in Khashoggi murder
  7. How is Plead malware used for cyberespionage attacks?
  8. Guy Fawkes Day – LulzSec Italy hit numerous organizations in Italy
  9. Exposed data of nearly 700k American Express India customers

Nov 9, 2018

APT report for 2018-11-08

TRANSNATIONAL / UNKNOWN

  1. DerpTrolling game server DoS attacker pleads guilty

CHINA

Nil

INDIA

Nil

NORTH KOREA

  1. Symantec Uncovers North Korean Group's ATM Attack Malware
  2. Lazarus Group Targets Bank Networks to Rob ATMs
  3. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  4. Symantec researchers dissect North Korean malware used in ATM attacks
  5. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  6. FASTCash: How the Lazarus Group is Emptying Millions from ATMs

PAKISTAN

Nil

VIETNAM

Nil

IRAN

Nil

IRAQ

Nil

LEBANON

Nil

PALESTINE

Nil

SAUDI ARABIA

Nil

SYRIA

Nil

TURKEY

Nil

UNITED ARAB EMIRATES

Nil

YEMEN

Nil

RUSSIA

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Top 5 Threats Healthcare Organizations Face and How to Combat Them
  3. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal

SERBIA

Nil

UKRAINE

Nil

Platform report for 2018-11-08

WINDOWS

  1. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  2. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  3. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  4. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  5. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  6. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  7. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  8. XSS flaw in Evernote allows attackers to execute commands and steal files

LINUX

Nil

UNIX

  1. Symantec Uncovers North Korean Group's ATM Attack Malware
  2. Lazarus Group Targets Bank Networks to Rob ATMs

ANDROID

  1. Google: Newer Android versions are less affected by malware
  2. Spyware disguised as Spanish banking apps removed from Google Play
  3. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524

IOS

  1. iOS 12.1 Vulnerability

MACOS

Nil

Threat report for 2018-11-08

DATA BREACH & DATA LOSS

  1. California Girl Scouts branch suffers data breach
  2. IT Security Culture Evolution of Businesses Exposed
  3. Canada Post Leaked Personal Data of 4,500 Cannabis Customers
  4. 689,272 plaintext records of Amex India customers exposed online
  5. 3.6 Billion Records Exposed in Data Breaches Until the End September 2018
  6. DJI Drone Flight Logs, Photos and Videos Exposed to Unauthorized Access
  7. Canada Post Leaked Personal Data On Cannabis Smokers
  8. Drone Vulnerability Could Compromise Enterprise Data
  9. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  10. Radisson Loyalty Program Compromised
  11. Test Your Employees with Internal Phishing Campaigns
  12. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  13. Business email compromise attacks cost over $676 million in 2017, according to the @FBI's Internet #CrimeReport. Learn how to recognize
  14. According to the 2018 Cost of a Data Breach Study by @PonemonPrivacy & @IBM, the global average cost of a
  15. Canada Post leaked personal data, orders of thousands of cannabis smokers
  16. HSBC Bank Alerts US Customers to Data Breach
  17. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  18. Users Stop Engaging With Brands After Data Breaches, Report Finds
  19. Phishing extortion campaign using new, more effective methods
  20. Gamasutra user privacy fragged following IP leak discovery
  21. HSBC confirms data theft in the United States
  22. Increasing value of personal data a 21st century challenge

DENIAL-OF-SERVICE

  1. Cambodia's ISPs Hit By Massive DDoS Attacks
  2. DerpTroll Admits To DDoS On EA, Steam, Sony Game Servers
  3. 4 Cambodia’s ISPs Attacked by DDoS
  4. DDoS attack on Cambodia’s top ISPs reached 150Gbps
  5. Man Behind DDoS Attacks on Gaming Companies Pleads Guilty
  6. To Pay or Not to Pay: A Large Retailer Responds to #DDoS Extortion Find out what happened here:
  7. Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history
  8. Hacker Behind Series of DoS Attack Targeting Gaming Companies Pleaded Guilty

MALVERTISING

Nil

PHISHING

  1. Test Your Employees with Internal Phishing Campaigns
  2. Most IT Security Pros Underestimate Phishing Risks
  3. Most Enterprises Fail to Implement Proper Protection Against Phishing Attacks
  4. Phishing extortion campaign using new, more effective methods
  5. How many of these bad password habits do you have?
  6. Good article about the password problem and a statistic that shows just how bad a problem it has now become...

WEB DEFACEMENT

Nil

BOTNET

  1. Botnet Infects 100,000 Routers to Send Outlook, Hotmail, and Yahoo Spam
  2. New Spam Botnet Likely Infected 400,000 Devices
  3. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  4. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  5. Spam Botnet of Over 100K Routers Abuses UPnP

RANSOMWARE

  1. Dharma Ransomware Hits Altus Baytown Hospital's Systems

CRYPTOMINING & CRYPTOCURRENCIES

  1. Hackers Charged for Creating 6K Strong Cryptojacking Network
  2. Can Blockchain Solve The Problem of Blood Diamonds?
  3. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  4. Managing the Intersection of Cryptocurrency and Compliance
  5. Hackers from North Korea still breaking into PCs for mining crypto-currencies
  6. SIM Swapping Hacker Group Who Managed to Steal $80,000 Worth of Cryptocurrency Got Arrested
  7. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  8. Beware of scams! Elon Musk is not giving away bitcoin on Twitter
  9. StatCounter platform compromised to infect gate.io exchange with bitcoin-stealing code
  10. Canadian University Undergoes A Forced Shutdown After Cryptojacking Attack
  11. StatCounter Analytics Code Hijacked to Steal Bitcoins from Cryptocurrency Users

MALWARE

  1. Triton Malware Spearheads Latest Generation of Attacks on Industrial Systems
  2. Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal
  3. Google: Newer Android versions are less affected by malware
  4. Attack uses malicious InPage document and outdated VLC media player to give attackers backdoor access to targets
  5. Symantec Uncovers North Korean Group's ATM Attack Malware
  6. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  7. Hackers Attack Crypto Exchange With Bitcoin-Stealing Malware
  8. The Pentagon has suddenly started uploading #malware samples from APTs and other nation-state sources to the website VirusTotal.
  9. Symantec researchers dissect North Korean malware used in ATM attacks
  10. Banking Malware Takes Aim at Brazilians
  11. Cryptocurrency Mining Malware uses Various Evasion Techniques, Including Windows Installer, as Part of its Routine
  12. The Cyber National Mission Force will share unclassified U.S. Cyber Command #malware samples to #VirusTotal and one expert hopes there
  13. U.S. Cyber Command CNMF Shares unclassified malware samples via VirusTotal
  14. US Cyber Command starts uploading foreign APT malware to VirusTotal
  15. U.S. Cyber Command malware samples to be logged in VirusTotal
  16. Metamorfo Banking Trojan Keeps Its Sights on Brazil
  17. Spyware disguised as Spanish banking apps removed from Google Play
  18. Unclassified #malware samples from U.S. Cyber Command will be shared with @virustotal by the Cyber National Mission Force. @MalwareJake @stephengillett
  19. Did you miss yesterday's #blog? Catch up on how fileless #malware is changing the way we as organizations are treating
  20. "The presence of the insecure remote access software on systems used for election management raised concerns that malicious #ThreatActors --
  21. U.S. Cyber Command Shares Malware via VirusTotal
  22. US Cyber Command starts uploading foreign APT malware to VirusTotal

EXPLOIT

  1. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  2. Cisco Accidentally Released Dirty Cow Exploit Code in Software
  3. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  4. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online

VULNERABILITY

  1. Companies swamped by critical vulnerabilities – Tenable
  2. Cisco hunts for Apache Struts 2 FileUpload bug and finds DIRTY CoW exploit
  3. Bleedingbit Vulnerabilities Could Affect Enterprises Worldwide
  4. Steam bug could have given you access to all the CD keys of any game
  5. Drone Vulnerability Could Compromise Enterprise Data
  6. Oracle's VirtualBox Vulnerability Leaked By Disgruntled Researcher
  7. [SingCERT] Alert on Nginx Vulnerabilities (CVE-2018-16843, CVE-2018-16844, and CVE-2018-16845)
  8. Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)
  9. Several Vulnerabilities Patched in nginx
  10. Flaws in several self-encrypting SSDs allows attackers to decrypt data they contain
  11. WooCommerce Plugin file deletion vulnerability exposes WordPress 'failing open' design flaw
  12. VirtualBox zero-day flaw released on Github; working exploit available but no patch
  13. DJI Drone Vulnerability Exposed Customer Data, Flight Logs, Photos and Videos
  14. DJI Patches Forum Bug That Allowed Drone Account Takeovers
  15. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  16. Ranting researcher publishes VM-busting zero-day without warning
  17. Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
  18. DJI Drone Vulnerability
  19. iOS 12.1 Vulnerability
  20. Encryption flaws in solid state drives enable unauthorised data access
  21. Microsoft Bug is Deactivating Windows 10 Pro Licenses and Downgrading to Home
  22. Ranting researcher publishes #VM-busting zero-day without warning
  23. We don' need no stinkin' bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
  24. Vulnerabilities In Major Self-Encrypting SSDs Allow Encryption Bypass and Affect Bitlocker
  25. [SingCERT] Alert on Critical Apache Struts 2 Remote Code Execution Vulnerability (CVE-2016-1000031)
  26. XSS flaw in Evernote allows attackers to execute commands and steal files
  27. Critical authentication flaw in DJI drone web app fixed
  28. Commoditization of Computing Hardware and the Bugs It Contains
  29. 4 Million Shops Installed WooCommerce Plugin RCE Flaw Allows Attacker to Gain WordPress Sites Admin Access
  30. A year later, @amarekano's Android overlay bug has been included in the AOSP November 2018 patched notes as CVE-2018-9524
  31. Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online