Home Artists Posts Import Register

Content

Vote below for the next topic to be covered on ThreatWire! You have until Monday morning to vote, at which time I'll check the totals and write a news story around that topic.


Thanks for your support!!


BlueKeep Updates / GoldBrute Botnet:

https://www.zdnet.com/video/intense-scanning-activity-detected-for-bluekeep-rdp-flaw/

https://www.zdnet.com/article/even-the-nsa-is-urging-windows-users-to-patch-bluekeep-cve-2019-0708/

https://threatpost.com/bluekeep-mega-worm-looms-as-fresh-poc-shows-full-system-takeover/145368/

https://threatpost.com/forget-bluekeep-beware-goldbrute/145482/

https://thehackernews.com/2019/06/windows-rdp-brute-force.html

https://thehackernews.com/2019/06/rdp-windows-lock-screen.html

238 Google Play apps found with malicious code

https://arstechnica.com/information-technology/2019/06/238-google-play-apps-with-440-million-installs-made-phones-nearly-unusable/

https://threatpost.com/android-completely-obnoxious-pop-ups/145390/

https://www.zdnet.com/article/440-million-android-users-installed-apps-with-an-aggressive-advertising-plugin/

POS Attack Hits Checkers and Rally’s

https://www.cnet.com/news/hackers-steal-credit-card-information-from-checkers-fast-food-chain/

https://www.checkers.com/security-issue/

https://www.cyberscoop.com/checkers-hack-rallys-point-of-sale-payment-cards/

LabCorp hit in same breach as Quest Diagnostics

https://krebsonsecurity.com/2019/06/labcorp-7-7m-consumers-hit-in-collections-firm-breach/

https://www.cnet.com/news/collections-firm-breach-exposes-data-on-7-7m-labcorp-customers/

Comments

Anonymous

The Labcorp/Quest breach is interesting since neither were directly breached. It is a strong statement of how responsible 3rd parties and MSPs are for data that is not their own. It should also be a wake-up call for all covered entities who have BAAs with vendors to ensure those vendors are following and implementing HIPAA standards.

Anonymous

I do believe I just untied (pun intended) BlueKeep and LabCorp. :)

Anonymous

The issue of Checkers/Rally is just how unmonitored these POS system are. This goes back to 2017-16 at some locations. Just like Target’s POS issue in the past, no one is auditing the network. Lapcorp/Quest isn’t something I can control, BlueKeep is targeting mostly old systems and can be patched. Checkers type issues is a reason I pay cash at this type of business.