Cyware Weekly Threat Intelligence - September 09–13

Weekly Threat Briefing • Sep 13, 2019
This website uses cookies and similar technologies to provide essential functionality and improve your experience. Some features, such as demo scheduling and chat support, require marketing cookies to function. By clicking "Accept All", you consent to all cookies. Alternatively, you can customize your preferences, but note that declining marketing cookies will limit certain website features.
Weekly Threat Briefing • Sep 13, 2019
The Good
As we gear up for a new weekend, let’s quickly glance through all that happened in cyberspace over the week. Before delving into the security incidents and new threats, let’s first take a look at all the positive advancements. Hitachi Europe Ltd. has announced ‘Hand gesture biometric authentication’ technology that replaces passwords. Researchers have developed a new hardware wallet to eliminate entire classes of vulnerabilities that impact existing designs. Meanwhile, Microsoft and the Hewlett Foundation are planning to launch the non-profit organization named ‘Cyber Peace Institute’.
Hitachi Europe Ltd. has announced a new biometric technology dubbed ‘Hand gesture biometric authentication’. This technology couples Hitachi's proven secure finger vein technology with any device that has a camera. This authentication system replaces passwords, fingerprint scanning, and facial recognition systems for authorizing transactions.
Researchers from MIT's Computer Science and Artificial Intelligence Laboratory (MIT CSAIL) have developed a new hardware wallet. This new wallet has been designed to eliminate entire classes of vulnerabilities that impact existing designs.
Sophos has announced plans to release its Sandboxie project as an open-source project. Sandboxie enables users to run any application inside a secure sandbox. Sophos will publish the project’s source code under an open-source license in the near future.
Microsoft and the Hewlett Foundation are planning to launch the non-profit organization named ‘Cyber Peace Institute’. This institute is dedicated to expose the details of harmful cyberattacks and provide assistance to cyberattack victims in investigating and assessing the costs of cyberattacks against civilian infrastructure.
The Bad
Several data breaches and security incidents were witnessed in this week. Dealer Leads has exposed almost 198 million records containing information about potential car buyers. In another instance, an unprotected database belonging to a cybercriminal network has exposed almost 17 million email addresses. Last but not least, attackers launched a massive DDoS attack against Wikipedia and took down its website across various countries.
An unprotected Elasticsearch database belonging to Dealer Leads has exposed almost 198 million records containing information about potential car buyers. The exposed data includes names, email addresses, phone, addresses, IP addresses, ports, pathways, storage information, loan and finance inquiries, and details of vehicles that were for sale.
An unprotected database belonging to a cybercriminal network has exposed almost 17 million email addresses. The breach allowed access to the personal details of users purchasing tickets from any website that uses the Neuroticket software. This impacted popular ticket vendors such as Groupon, Ticketmaster, and Tickpick apart from various small independent venues.
Researchers have discovered a phishing campaign launched by an Iran-linked hacker group called Cobalt Dickens that has targeted over 380 Universities across over 30 countries. This campaign has predominantly affected the universities in Canada, Australia, the US, and the UK. The hacker group has targeted universities in order to steal intellectual property that can be used for financial gain.
Attackers launched a massive DDoS attack against Wikipedia and took down its website across various countries. The attack was launched on September 6, 2019 (Friday) and targeted several countries including the U.K., France, Germany, Italy, The Netherlands, Poland and parts of the Middle East.
Toyota Boshoku disclosed that one of its European subsidiaries fell victim to a Business Email Compromise (BEC) scam losing over $37 million. On August 14, 2019, Toyota Boshoku’s European subsidiary made a payment of roughly 4 billion yen (~$37,472,000) to a third party. Later, the car components manufacturer became aware that the payment directions were fraudulent.
The fundraising organization Trail’s End suffered a data breach compromising the personal information of children and parents associated with the Boy Scouts of America. The exposed information includes children’s full names, dates of birth, email addresses, phone numbers, parent names, favorite products, and affiliation.
An unprotected database belonging to the Likud-National Liberal Movement in Israel has exposed the private data of over 4 million Israeli voters. The database was left open to the public for almost five days before it was secured. The exposed data includes names, addresses, phone numbers, ID numbers, Social security numbers, and voting preferences.
The personal information of roughly 50,000 students involved in university societies and clubs around Australia have been exposed online due to a vulnerability in Get app. Upon learning about the incident, Get’s engineering team took immediate steps to address the potential vulnerability by reviewing and tokenizing all API calls.
Job recruitment site Monster has exposed hundreds of resumes, CVs, and other files of job applicants due to a misconfigured server that was owned by one of its recruitment customers. The exposed server contained hundreds of resumes, CVs, and other files from job applicants who applied for jobs between 2014 and 2017. The other files found on the exposed server included immigration documentation for work, which Monster does not collect.
Attackers have stolen $4.2 million in funds from the Oklahoma Law Enforcement Retirement System, a pension system for retired Oklahoma Highway Patrol Troopers and other state law enforcement officers. Attackers hacked the email account of an OLERS employee and then stole funds managed by an investment manager, on the behalf of OLERS.
**New Threats **
This week also witnessed the occurrence of several new malware strains and vulnerabilities. The infamous TrickBot trojan has made a comeback with a massive phishing attack targeting several states in the US. The US Cyber Command has shared 11 malware samples with VirusTotal, which are believed to be linked to the notorious Lazarus Group. Meanwhile, researchers have uncovered a new vulnerability dubbed ‘NetCAT’ in Intel chips that abuses the Data-Direct I/O (DDIO) feature.