Cyware Weekly Threat Intelligence, October 05 - 09, 2020

Weekly Threat Briefing • October 9, 2020
Weekly Threat Briefing • October 9, 2020
The Good
With the rise in sophistication of cyberattacks, several government agencies have come up with different cybersecurity strategies to protect organizations and individuals. Acting in this direction, Singapore has decided to form a panel consisting of global experts to tackle cyberattacks against OT systems. On the other hand, DHS’ Science and Technology Directorate (S&T) has invented a new technology called TrustMS to protect apps against manipulation, buffer overflows, and execution of unintended code.
The Bad
Data leak incidents made headlines this week. Some of the victim organizations included Airline International UAE, SEPTA, and Chowbus. In addition to this, threat actors leveraged legacy software—Magento 1.x and PHP version 5.6.40—to compromise online stores in different skimming attacks.
New Threats
Talking about new threats, experts demonstrated a new fileless technique called Kraken that abuses Windows Error Reporting (WER) service as a defense evasion mechanism. Making headway, security researchers developed a new jailbreaking technique by combining checkm8 exploit and Blackbird vulnerability.