Cyware Weekly Threat Intelligence, November 11 - 15, 2019

Weekly Threat Briefing • November 15, 2019
Weekly Threat Briefing • November 15, 2019
The Good
Another week has almost come to an end, and it was quite a busy one in cyberspace. Let’s review the cybersecurity highlights of this week, starting with the positive developments. The U.S. Internal Revenue Service plans to launch a cyber safety campaign called ‘National Tax Security Awareness Week 2019’ that coincides with the year’s busiest online shopping period. The U.S. Air Force plans to launch a cybersecurity program called ‘Infrastructure Asset Pre-Assessment program’ to rate the cybersecurity of commercial satellite communication companies. Meanwhile, MITRE has launched a tech foundation called ‘Engenuity’ that will focus on cyber defense research and development.
The Bad
Several cyberattacks and breaches were reported this week. Two DDoS attacks within a span of 24 hours hit the U.K. Labour Party. Around 93,000 patient files belonging to three facilities managed by Sunshine Behavioral Health were exposed by an unsecured database. Meanwhile, hosting provider SmartASP suffered a ransomware attack that encrypted all customer data.
New Threats
This week witnessed the emergence of multiple vulnerabilities and malware strains. ZombieLoad v2, a new version of the side-channel attack impacting Intel processors was reported. A new phishing campaign involving fake sexual harassment complaints was spotted delivering the TrickBot Trojan. In other news, the Australian Cyber Security Centre (ACSC) has warned businesses and netizens against a new wave of Emotet and BlueKeep attacks.