Infosec News 20200221

  • Publicado: Sex, 21/02/2020 - 13:48

Top News


  • Croatia’s largest petrol station chain INA group hit by ransomware attack

"Some operations at INA Group, Croatia’s biggest oil company, and its largest petrol station chain were disrupted by a cyber attack."

Link

TLP1 : Green

  • Haken Malware Family Infests Google Play Store

"Eight apps – mostly camera utilities and children’s games – were discovered spreading a new malware strain that steals data and signs victims up for expensive premium services."

Link

TLP1 : Green

  • ISS World Hit with Malware Attack that Shuts Down Global Computer Network

"The incident cut off access to e-mail and shared IT services across customer sites of the multinational Denmark-based facility-management firm."

Link

Cybersecurity State: Surveillance, Cyberwarfare, Cybercriminality and Hacktivism


  • GDPR Protection Will Continue After Google’s US Data Move, Says Lawyer

"Google is unlikely to be moving UK users’ data to the US because of Brexit-related uncertainty and GDPR privacy rights will continue to be protected after any such move, according to a leading data protection lawyer."

Link

TLP1 : Green

  • ToTok chat app tells users to ignore Google’s spyware warning

"Video chat app ToTok has been removed from the official Android and iOS app stores by Google and Apple respectively, following growing concerns that it was actually helping the government of the United Arab Emirates spy on users’ conversations and location."

Link

TLP1 : Green

  • Policy vs Technology

"Technologists tend to look at more general use cases, like the overall value of strong encryption to societal security. Policy tends to focus on the past, making existing systems work or correcting wrongs that have happened."

Link

TLP1 : Green

Breaches: Data Breaches and Hacks


  • U.S. Department of Defense Disclosed Data Breach at DISA

"The U.S. Department of Defense (DoD) warned that a data breach at the Defense Information Systems Agency (DISA) might have compromised some individuals’ personal information."

Link

TLP1 : Green

Vulnerabilities: Vulnerability Advisories, Zero-Days,Patches and Exploits


  • Remove Akamaihd Mac virus from Safari, Chrome, Firefox

"The Mac malware landscape is full of inconsistencies and hybrid characteristics blurring the legit and outright shady entities into a vicious, undrainable cocktail."

Link

TLP1 : Green

  • TP-LINK TL-WA850RE 5 /data/syslog.filter.json type memory corruption

"A vulnerability, which was classified as critical, has been found in TP-LINK TL-WA850RE 5 (Router Operating System)."

Link

TLP1 : Green

Incident Response: Infrastructure, Training, SIEM and Incident Handling


  • Adama - Searches For Threat Hunting And Security Analytics

"A collection of known log and / or event data searches for threat hunting and detection. They enumerate sets of searches used across many different data pipelines."

Link

TLP1 : Green

Technical Articles: Forensics, Reverse Engineering, Malware, Phishing, Pentesting, Software Security and Cryptography


  • SUDO_KILLER - A Tool To Identify And Exploit Sudo Rules' Misconfigurations And Vulnerabilities Within Sudo

"SUDO_KILLER is a tool that can be used for privilege escalation on linux environment by abusing SUDO in several ways. The tool helps to identify misconfiguration within sudo rules, vulnerability within the version of sudo being used (CVEs and vulns) and the use of dangerous binary, all of these could be abused to elevate privilege to ROOT."

Link

TLP1 : Green

  • ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

"ATM Penetration testing, Hackers have found different approaches to hack into the ATM machines."

Link

TLP1 : Green

  • ObliqueRAT: New RAT hits victims' endpoints via malicious documents

"Cisco Talos has observed a malware campaign that utilizes malicious Microsoft Office documents (maldocs) to spread a remote access trojan (RAT) we're calling "ObliqueRAT."

Link

TLP1 : Green

  • Devo Rolls Out SIEM Solution with Advanced Analytics, Automation

"With Devo Security Operations, the company looks to fill organizations' need for more automation, orchestration and analytics from their SIEM solution."

Link

TLP1 : Green

1Traffic Light Protocol (TLP) [1] for information sharing:

 

 

  • Red:Not for disclosure, restricted to participants only.
  • Amber: Limited disclosure, restricted to participants organizations.
  • Green: Limited disclosure, restricted to the community.

 


[1]https://www.first.org/tlp