| Cyware Weekly Cyber Threat Intelligence | March 12 - 16, 2018

Weekly Threat Briefing • Mar 16, 2018
This website uses cookies and similar technologies to provide essential functionality and improve your experience. Some features, such as demo scheduling and chat support, require marketing cookies to function. By clicking "Accept All", you consent to all cookies. Alternatively, you can customize your preferences, but note that declining marketing cookies will limit certain website features.
Weekly Threat Briefing • Mar 16, 2018
Good news is a bit meek this week! Researchers have released a kill switch, called Memfixed, to fix the infamous memcached DDoS attacks. A new quantum computing chip with 72 quantum bits has been unveiled by Google. Researchers have also made progress in AI, which is being leveraged to provide enhanced security to consumer’s credit card data.
Google has unveiled Bristlecone, a new quantum computing chip with 72 quantum bits much above the previous record holder of IBM with a mere 50-qubit processor. As per team Google, although few more tests are required but its expected that the chip will be available this year. Google has pinned high hopes on this chip that would help them achieve “quantum supremacy”, a point at which a quantum computer can do calculations beyond the reach of today’s fastest supercomputers.
Artificial Intelligence is now being leveraged by banks to provide enhanced security to consumer’s credit card data. Capital One has come out with a virtual credit card number for its customers to make online purchases. The technology behind the card is a browser extension that runs in the background of the cardholder’s computer automatically detecting when the person finishes off the shopping. Once the customer reaches a checkout page a virtual credit card number covering that person’s transactions with that specific retailer is generated and all payment fields on the site are filled. That way, if a retailer were to be hacked, or if the customer identified a fraudulent charge on their bill, Capital One could simply deactivate the compromised credit card alias, instead of replacing the card itself.
Researchers released a “kill switch” that effectively counters the memcached vulnerability bringing a downfall in the frequency of massive DDoS attacks being carried out by the hackers. The tool suppresses a memcached DDoS attack while leaving the compromised servers online. It makes use of ‘flush_all’ command to defeat the DDoS exploit.
This week, unfortunately, registered a number of breaches and data leaks. German security researchers revealed that a data breach in Limoges Jewelry owner MBM Company impacted over 1.3 million people. Two healthcare facilities, BJC HealthCare and St. Peter’s Surgery & Endoscopy Center, resulting in loss of patient records of 33,420 people and 135,000 patients respectively.
Researchers from a German security firm have revealed that the Chicago based famous jewelry brand Limoges Jewelry owner MBM Company has suffered a data breach impacting over 1.3 million people. As per report, the company was allegedly handling customer details improperly over an unsecured Amazon S3 storage bucket. The leaked information includes addresses, zip-codes, e-mail addresses, IP addresses and even plain text passwords.
St. Louis healthcare facility, BJC HealthCare, disclosed that a data storage error had potentially compromised patient records impact 33,420 people. As per the disclosure made, the data was publicly available for nine months due to a misconfigured server that was left without a security protocol in place allowing someone to view scanned documents containing patient's driver's licenses, insurance cards and treatment-related documents from 2003 to 2009.
Another healthcare facility made announcement of a breach that might have impacted medical records of about 135,000 patients. St. Peter’s Surgery & Endoscopy Center revealed that it had unearthed a breach that occurred on 8th January 2018 with an unauthorized party gaining access to its servers. As per the healthcare facility, despite no evidence of hackers gaining access to patient data being found, it could not be conclusively ruled out that hackers did not access personal and medical information of patients including their names, date of birth, addresses, diagnosis codes, insurance information, and Medicare details.
Researchers, this week, have unveiled a new malspam campaign, a backdoor, critical flaws and new tweaks in an old malware. Qrypter remote access Trojan (RAT), an old malware, has been found propagating through malicious emails. A new malspam campaign was spotted distributing the Sigma ransomware, and a new backdoor deployed by OceanLotus is targeting Southeast Asian countries. Researchers also found new critical flaws in AMD chips.