DATA BREACH & DATA LOSS
- Knuddels Flirt App Slapped with Hefty Fine After Data Breach
- When Do You Need to Report a Data Breach?
- USPS, Amazon Data Leaks Showcase API Weaknesses
- How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
- Despite growing concerns about cybersecurity and the number of data breach incidents in the news, many employees still have bad
- Trivial Spotify Phishing Campaign Targets Users To Steal Login Credentials
- Phishing Campaign targeting French Industry
- Russia Plans To tighten Data Protection Owing To Intelligence Leaks
- German Social Media Provider Fined €20K for Data Breach
- No need to compromise freedom for security - Europol audience told
- HR Software Firm PageUp Finds No Evidence of Data Theft
- Internal negligence to blame for most data breaches involving personal health information
- Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
- An ongoing phishing campaign is targeting French industry, @FSLabs finds.
- Phishing Campaign targeting French Industry
- My Health Record opt-out officially extended to January 31
DENIAL-OF-SERVICE
Nil
MALVERTISING
Nil
PHISHING
- Holiday Season: Cybercriminals are Phishing All The Way
- Half of all Phishing Sites Now Have the Padlock
- Easy as APT: Spear phishing highlighted as ongoing threat for 2019
- Trivial Spotify Phishing Campaign Targets Users To Steal Login Credentials
- Phishing Campaign targeting French Industry
- 50% use password managers to store login details
- An ongoing phishing campaign is targeting French industry, @FSLabs finds.
- Phishing Campaign targeting French Industry
- Beware!! Cyber Criminals Launching Serious Phishing Attack that Target Spotify Customers
WEB DEFACEMENT
Nil
BOTNET
- Democrats Introduce Bill for Stopping Automated Grinch Bots from Ruining Xmas
RANSOMWARE
- Ransomware attack disrupted emergency rooms at Ohio Hospital System
- Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
- Ransomware Attack Forced Ohio Hospital System to Divert ER Patients
- A new ransomware -- dubbed #Thanatos #ransomware -- was found encrypting data but not decrypting it despite victims paying the
CRYPTOMINING & CRYPTOCURRENCIES
- Hacker backdoors popular JavaScript library to steal Bitcoin funds
- Harberger Taxes on Ethereum
- OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic
- Cryptocurrency threat predictions for 2019
- Crypto Mining Malware Infects Make-A-Wish-Foundation Website
- Experts found a new powerful modular Linux cryptominer
MALWARE
- Lenovo to Pay $7.3 Million in Settlement for Installing Adware on 800K Notebooks
- 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
- What is Data Classification? Guidelines and Process
- Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
- Subscribe to the relaunched Virus Bulletin eNews newsletter
- Play Store Malware Infects Half a Billion
- Microsoft PowerPoint as Malware Dropper
- OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic
- Ukrainian Police Nab Suspected RAT-Slinger
- Crypto Mining Malware Infects Make-A-Wish-Foundation Website
EXPLOIT
Nil
VULNERABILITY
- Microsoft launches review after a trio of Azure bugs locked users out of Office 365
- Did UK city council over-react to a vulnerability report in its recycling app or not?
- Linux Kernel is affected by two DoS vulnerabilities still unpatched
- DoS Vulnerabilities Impact Linux Kernel
- Apache Hadoop Spins Cracking Code Injection Vulnerability YARN
- Siemens patches major firewall flaw, other vulnerabilities
- #Bluetooth devices might be at risk after a new Bluetooth vulnerability was found targeting #firmware and #OperatingSystem software drivers. Learn
- U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
- Positive Technologies researchers recently found two serious vulnerabilities that target NCR's #ATMs. Learn how a "black box attack" was involved
- Discover how a @DLink #router vulnerability targeted a banking site to steal #UserCredentials with expert Judith Myerson.
- For recent big data software vulnerabilities, botnets and coin mining are just the beginning
- Frost & Sullivan Commends Rapid7 for Capturing Nearly a Quarter Share of the Global Vulnerability Management Market
ASIA
- Half of all Phishing Sites Now Have the Padlock
- Cyberthreats to financial institutions 2019: overview and predictions
- Ukrainian Police Nab Suspected RAT-Slinger
- Crypto Mining Malware Infects Make-A-Wish-Foundation Website
WORLD
- Microsoft launches review after a trio of Azure bugs locked users out of Office 365
- Did UK city council over-react to a vulnerability report in its recycling app or not?
- Knuddels Flirt App Slapped with Hefty Fine After Data Breach
- When Do You Need to Report a Data Breach?
- Democrats Introduce Bill for Stopping Automated Grinch Bots from Ruining Xmas
- Siemens patches major firewall flaw, other vulnerabilities
- How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
- Microsoft PowerPoint as Malware Dropper
- Recent Attacks on US Entities Attributed to APT29
- U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
- Phishing Campaign targeting French Industry
- Russia Plans To tighten Data Protection Owing To Intelligence Leaks
- German Social Media Provider Fined €20K for Data Breach
- Cyberthreats to financial institutions 2019: overview and predictions
- Ukrainian Police Nab Suspected RAT-Slinger
- Crypto Mining Malware Infects Make-A-Wish-Foundation Website
- Experts found a new powerful modular Linux cryptominer
- HR Software Firm PageUp Finds No Evidence of Data Theft
- An ongoing phishing campaign is targeting French industry, @FSLabs finds.
- Phishing Campaign targeting French Industry
ATTACKS
- Knuddels Flirt App Slapped with Hefty Fine After Data Breach
- When Do You Need to Report a Data Breach?
- USPS, Amazon Data Leaks Showcase API Weaknesses
- Holiday Season: Cybercriminals are Phishing All The Way
- How Pirated Versions of ‘Super Smash Bros. Ultimate’ Leaked Weeks Before Release
- Half of all Phishing Sites Now Have the Padlock
- Easy as APT: Spear phishing highlighted as ongoing threat for 2019
- Despite growing concerns about cybersecurity and the number of data breach incidents in the news, many employees still have bad
- Trivial Spotify Phishing Campaign Targets Users To Steal Login Credentials
- Phishing Campaign targeting French Industry
- Russia Plans To tighten Data Protection Owing To Intelligence Leaks
- German Social Media Provider Fined €20K for Data Breach
- No need to compromise freedom for security - Europol audience told
- 50% use password managers to store login details
- HR Software Firm PageUp Finds No Evidence of Data Theft
- Internal negligence to blame for most data breaches involving personal health information
- Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
- An ongoing phishing campaign is targeting French industry, @FSLabs finds.
- Phishing Campaign targeting French Industry
- Beware!! Cyber Criminals Launching Serious Phishing Attack that Target Spotify Customers
- My Health Record opt-out officially extended to January 31
THREATS
- Microsoft launches review after a trio of Azure bugs locked users out of Office 365
- Did UK city council over-react to a vulnerability report in its recycling app or not?
- Ransomware attack disrupted emergency rooms at Ohio Hospital System
- Lenovo to Pay $7.3 Million in Settlement for Installing Adware on 800K Notebooks
- 13 Newly Discovered Malicious Apps, Deleted By Google From the Play Store
- Hacker backdoors popular JavaScript library to steal Bitcoin funds
- What is Data Classification? Guidelines and Process
- Linux Kernel is affected by two DoS vulnerabilities still unpatched
- Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
- Harberger Taxes on Ethereum
- DoS Vulnerabilities Impact Linux Kernel
- Subscribe to the relaunched Virus Bulletin eNews newsletter
- Apache Hadoop Spins Cracking Code Injection Vulnerability YARN
- Siemens patches major firewall flaw, other vulnerabilities
- Play Store Malware Infects Half a Billion
- Microsoft PowerPoint as Malware Dropper
- #Bluetooth devices might be at risk after a new Bluetooth vulnerability was found targeting #firmware and #OperatingSystem software drivers. Learn
- U.S. Postal Service API Flaw Exposes Data of 60 Million Customers
- Ransomware Attack Forced Ohio Hospital System to Divert ER Patients
- Positive Technologies researchers recently found two serious vulnerabilities that target NCR's #ATMs. Learn how a "black box attack" was involved
- OSX.Dummy #malware has been discovered to use chat platforms in order to target #cryptocurrency investors. Learn more with expert @lewisnic
- Cryptocurrency threat predictions for 2019
- Ukrainian Police Nab Suspected RAT-Slinger
- Crypto Mining Malware Infects Make-A-Wish-Foundation Website
- Experts found a new powerful modular Linux cryptominer
- A new ransomware -- dubbed #Thanatos #ransomware -- was found encrypting data but not decrypting it despite victims paying the
- Discover how a @DLink #router vulnerability targeted a banking site to steal #UserCredentials with expert Judith Myerson.
- For recent big data software vulnerabilities, botnets and coin mining are just the beginning
- Frost & Sullivan Commends Rapid7 for Capturing Nearly a Quarter Share of the Global Vulnerability Management Market
CRIME
- When Do You Need to Report a Data Breach?
- Holiday Season: Cybercriminals are Phishing All The Way
- Half of all Phishing Sites Now Have the Padlock
- Russia Plans To tighten Data Protection Owing To Intelligence Leaks
- Cryptocurrency threat predictions for 2019
- Cyberthreats to financial institutions 2019: overview and predictions
- Ukrainian Police Nab Suspected RAT-Slinger
- Experts found a new powerful modular Linux cryptominer
- HR Software Firm PageUp Finds No Evidence of Data Theft
- Sextortion 2.0: We have continued to monitor the campaigns and have seen a recent change in tactics, with some unusual
POLITICS
- Russia Plans To tighten Data Protection Owing To Intelligence Leaks
- Cryptocurrency threat predictions for 2019
- Ukrainian Police Nab Suspected RAT-Slinger
TRANSNATIONAL / UNKNOWN
Nil
CHINA
Nil
INDIA
Nil
NORTH KOREA
- North Korea-linked group Lazarus targets Latin American banks
PAKISTAN
Nil
VIETNAM
Nil
IRAN
Nil
IRAQ
Nil
LEBANON
Nil
PALESTINE
Nil
SAUDI ARABIA
Nil
SYRIA
Nil
TURKEY
Nil
UNITED ARAB EMIRATES
Nil
YEMEN
Nil
RUSSIA
- News of the Week: November 24, 2018
SERBIA
Nil
UKRAINE
Nil
ASIA
- North Korea-linked group Lazarus targets Latin American banks
WORLD
- Quebec Dubbed As An Embarrassment After Paying $30,000 To Ransomware Authors
- Adobe Patched A Critical Flash Player Vulnerability Disclosed Publicly
- News of the Week: November 24, 2018
- North Korea-linked group Lazarus targets Latin American banks
- 42-year-old man Arrested For Hacking More than 2,000 Computers From 50 countries With DarkComet RAT
- New Trojan mining on the Linux will steal user passwords & removes anti-viruses
ATTACKS
- This week's #RiskAndRepeatPodcast digs into the debate over #WeakPasswords and password reuse, and asks: how much are users responsible for
THREATS
- Quebec Dubbed As An Embarrassment After Paying $30,000 To Ransomware Authors
- Adobe Patched A Critical Flash Player Vulnerability Disclosed Publicly
- MacOS Penetration Test Reveals Three Zero-Day Vulnerabilities
- Powerful Mobile Malware Rotexy Launched over 70,000 Attacks with Banking Trojan & Ransomware Modules
- .@TalosSecurity recently created a #decryptor that helps files affected by the #ransomware #Thanatos -- typically known to not decrypt files
- TA505 Cybercrime Group Experimenting with a New RAT In The Wild
- Researchers at @okta found a bypass that allows #ThreatActors to pose files as legitimate @Apple files despite being #malware and
- 42-year-old man Arrested For Hacking More than 2,000 Computers From 50 countries With DarkComet RAT
- SMBs suffered the brunt of ransomware attacks in 2018
- CVE-2018-19406, CVE-2018-19407: Two DoS vulnerabilities on Linux Kernel
- New Trojan mining on the Linux will steal user passwords & removes anti-viruses
- How has the @DLink #router vulnerability affected your enterprise?
- The Week in Ransomware - November 23rd 2018 - STOP, Dharma, and More
CRIME
- TA505 Cybercrime Group Experimenting with a New RAT In The Wild
- New Trojan mining on the Linux will steal user passwords & removes anti-viruses
POLITICS
- Quebec Dubbed As An Embarrassment After Paying $30,000 To Ransomware Authors
- North Korea-linked group Lazarus targets Latin American banks
DATA BREACH & DATA LOSS
- NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
- Data breach in OSIsoft
- Brazil's largest professional association suffers massive data leak
- Amazon Snafu Exposed Customers' Names and Email Addresses
- “Back in Black” – Article 13 has YouTube threatening to pull the plug over upload filter
- New Emotet Thanksgiving campaign differs from previous ones
- US Postal Service Website Left Data Exposed for Over a Year
- .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
- Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
- Software company OSIsoft has suffered a data breach
- SAVE 50% FOR BLACK FRIDAY!
Get half off FREEDOME VPN and TOTAL with coupon code BLACKFRIDAY.
- DNS Shell – Tool to Compromise and Maintain Control Over Victim Machine
- @FSecure fait son #BlackFriday ! Profitez de 50% de remise sur une sélection de produits !
- 60 million users’ data were exposed by the US Postal Service
DENIAL-OF-SERVICE
- Why e-commerce needs DDoS protection for Cyber Monday
MALVERTISING
Nil
PHISHING
- 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
- New Linux crypto-miner steals your root password and disables your antivirus
- Attackers Are Landing Email Inboxes Without the Need to Phish
- Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
- Phishing Used to Launch GreyEnergy's ICS Attacks
- Southwest Washington Regional Surgery Center suffered a Phishing attack
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
WEB DEFACEMENT
Nil
BOTNET
- Malware scum want to build a Linux botnet using Mirai
- Deep Instinct recently blogged about a new #botnet -- dubbed #Mylobot -- that has shown new, complex tools and techniques.
RANSOMWARE
- SMBs suffered the brunt of ransomware attacks in 2018
- The number of ransomware attacks on individuals has come down as it has become harder to get them to pay,
CRYPTOMINING & CRYPTOCURRENCIES
- Cryptocurrency ‘minting’ flaw could have leached money from exchanges
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
MALWARE
- 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
- New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
- Malware scum want to build a Linux botnet using Mirai
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- Black Friday special by Emotet: Filling inboxes with infected XML macros
- Black Friday special by Emotet: Filling inboxes with infected XML macros
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- VMware patches guest-to-host malware vulnerability
- #WebCache poisoning poses a serious threat to #BrowserSecurity. Learn how #hackers can use unkeyed inputs for malicious intent from expert
- Best way to Remove Malware on Mac, Including Other Unwanted Apps
- New Crypto Malware Spreading that Infects Linux Machines & Removes Anti-Virus
- Over 500k Play Store users have installed 13 games that contain malware
EXPLOIT
Nil
VULNERABILITY
- DoS Vulnerabilities Found in Linux Kernel, Unpatched
- Apache Hadoop spins cracking code injection vulnerability YARN
- German e-government SDK patched against ID spoofing vulnerability
- US Postal Service Plugs API Flaw - One Year Later
- VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
- Adobe Flash Player Remote Code Execution Vulnerability Threat Alert
- Old Printer Vulnerabilities Die Hard
- VMware Patches Workstation Flaw Disclosed at Hacking Contest
- Cryptocurrency ‘minting’ flaw could have leached money from exchanges
- USPS Bug affects 60 Million Users, Finally Fixed.
- German eID vulnerability allows hackers to change identities
- VMware patches guest-to-host malware vulnerability
- Internet connected devices might be the hot item for Christmas this year, but are they secure?
- Hacker says USPS ignored serious security flaw for over a year
- CVE-2018-6983: integer overflow vulnerability in VMware Workstation and Fusion
ASIA
- US Says China Increased Hacking over Trade Dispute
- North Korean Hackers Hit Latin American Banks
- VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
- Adobe Flash Player Remote Code Execution Vulnerability Threat Alert
- VMware Patches Workstation Flaw Disclosed at Hacking Contest
WORLD
- NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
- Data breach in OSIsoft
- New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
- Brazil's largest professional association suffers massive data leak
- German e-government SDK patched against ID spoofing vulnerability
- US Postal Service Plugs API Flaw - One Year Later
- US Says China Increased Hacking over Trade Dispute
- North Korean Hackers Hit Latin American Banks
- VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
- Phishing Used to Launch GreyEnergy's ICS Attacks
- New Emotet Thanksgiving campaign differs from previous ones
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- US Postal Service Website Left Data Exposed for Over a Year
- German eID vulnerability allows hackers to change identities
- Hacker says USPS ignored serious security flaw for over a year
- Synthetic identity fraud to drive $48 billion in annual losses by 2023 – Juniper Research
- Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits
- Southwest Washington Regional Surgery Center suffered a Phishing attack
- 60 million users’ data were exposed by the US Postal Service
- The team discuss continuing activity by the Magecart group, as well as the ways in which #cybercriminals are gearing up
ATTACKS
- NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
- Data breach in OSIsoft
- 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
- Brazil's largest professional association suffers massive data leak
- Amazon Snafu Exposed Customers' Names and Email Addresses
- New Linux crypto-miner steals your root password and disables your antivirus
- Attackers Are Landing Email Inboxes Without the Need to Phish
- Do you know the top myths and facts of #mobile #phishing? If not, don't worry, we've compiled a list of
- “Back in Black” – Article 13 has YouTube threatening to pull the plug over upload filter
- Phishing Used to Launch GreyEnergy's ICS Attacks
- New Emotet Thanksgiving campaign differs from previous ones
- US Postal Service Website Left Data Exposed for Over a Year
- .@Amazon unveils new settings to help users avoid S3 data leaks, but UpGuard's Chris Vickery, who uncovered most #AWS exposures,
- Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits
- Southwest Washington Regional Surgery Center suffered a Phishing attack
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
- Software company OSIsoft has suffered a data breach
- SAVE 50% FOR BLACK FRIDAY!
Get half off FREEDOME VPN and TOTAL with coupon code BLACKFRIDAY.
- DNS Shell – Tool to Compromise and Maintain Control Over Victim Machine
- @FSecure fait son #BlackFriday ! Profitez de 50% de remise sur une sélection de produits !
- 60 million users’ data were exposed by the US Postal Service
THREATS
- 8 tips for avoiding phishing, malware, scams, and hacks while holiday shopping online
- New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
- DoS Vulnerabilities Found in Linux Kernel, Unpatched
- Apache Hadoop spins cracking code injection vulnerability YARN
- German e-government SDK patched against ID spoofing vulnerability
- Malware scum want to build a Linux botnet using Mirai
- US Postal Service Plugs API Flaw - One Year Later
- VMware fixed Workstation flaw disclosed at the Tianfu Cup PWN competition
- Adobe Flash Player Remote Code Execution Vulnerability Threat Alert
- Old Printer Vulnerabilities Die Hard
- VMware Patches Workstation Flaw Disclosed at Hacking Contest
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- Black Friday special by Emotet: Filling inboxes with infected XML macros
- Black Friday special by Emotet: Filling inboxes with infected XML macros
- Cryptocurrency ‘minting’ flaw could have leached money from exchanges
- Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
- USPS Bug affects 60 Million Users, Finally Fixed.
- German eID vulnerability allows hackers to change identities
- VMware patches guest-to-host malware vulnerability
- Internet connected devices might be the hot item for Christmas this year, but are they secure?
- Hacker says USPS ignored serious security flaw for over a year
- #WebCache poisoning poses a serious threat to #BrowserSecurity. Learn how #hackers can use unkeyed inputs for malicious intent from expert
- SMBs suffered the brunt of ransomware attacks in 2018
- Best way to Remove Malware on Mac, Including Other Unwanted Apps
- A #phishing campaign was recently found to be hijacking the traffic of @Trezor user #cryptocurrency wallets. Learn how such an
- CVE-2018-6983: integer overflow vulnerability in VMware Workstation and Fusion
- The number of ransomware attacks on individuals has come down as it has become harder to get them to pay,
- New Crypto Malware Spreading that Infects Linux Machines & Removes Anti-Virus
- Over 500k Play Store users have installed 13 games that contain malware
CRIME
- Data breach in OSIsoft
- US Says China Increased Hacking over Trade Dispute
- Synthetic identity fraud to drive $48 billion in annual losses by 2023 – Juniper Research
- Software company OSIsoft has suffered a data breach
- The team discuss continuing activity by the Magecart group, as well as the ways in which #cybercriminals are gearing up
POLITICS
- NUI Galway’s Problem: Misplaced USB Flash Drive Containing Unencrypted Student Records
- US Says China Increased Hacking over Trade Dispute
- Synthetic identity fraud to drive $48 billion in annual losses by 2023 – Juniper Research
- Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits