Cyware Weekly Threat Intelligence - February 17–21

Weekly Threat Briefing • February 21, 2020
Weekly Threat Briefing • February 21, 2020
The Good
The week started on a good note, with governments focusing on increasing the cybersecurity budget to bolster their countries’ critical infrastructure and IT systems. While the U.S administration has requested a fund of $9.8 billion for the fiscal year 2021 to enhance the cybersecurity posture of DoD, Singapore has set aside a total of $1 billion over the next three years to build the government’s cyber and data security capabilities. Meanwhile, MITRE Engenuity has rolled out its plan to evaluate and validate cybersecurity products based on the threats from the Carbanak gang.
The Bad
Two major data leaks due to misconfigured AWS S3 databases also grabbed the attention of security experts this week. While one belonged to PhotoSquared, the other was related to a medical imaging firm NextMotion. MGM Resorts was also in the news after its 10.6 million guest records were posted on an online hacking forum. The records included data of high-profile celebrities and government officials.
New Threats
Among the new threats observed this week, Adwind returned with a new version 3.0 to target more than 80 Turkish companies. The infamous BlueKeep flaw, for which a patch has been released, continues to affect over 55% of medical imaging devices - including MRIs, X-rays and ultrasound machines. On the other hand, the Fox Kitten cyber espionage campaign, which was active for at least three years, has now evolved to exploit 1-day vulnerabilities in VPN and RDP services.