{"id":15440,"date":"2019-05-31T06:00:02","date_gmt":"2019-05-31T14:00:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/05\/31\/news-9189\/"},"modified":"2019-05-31T06:00:02","modified_gmt":"2019-05-31T14:00:02","slug":"news-9189","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/05\/31\/news-9189\/","title":{"rendered":"This Week in Security News: Trickbots and Infected Containers"},"content":{"rendered":"<p><strong>Credit to Author: Jon Clay (Global Threat Communications)| Date: Fri, 31 May 2019 13:05:27 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-300x300.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" link_thumbnail=\"\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-300x300.jpg 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-768x768.jpg 768w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-1024x1024.jpg 1024w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-640x640.jpg 640w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-900x900.jpg 900w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-440x440.jpg 440w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-380x380.jpg 380w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn how a Trickbot attacked a school district\u2019s networks and how infected cryptocurrency-mining containers target docker hosts with exposed APIs.<\/p>\n<p>Read on:<\/p>\n<p><strong><a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/trickbot-attack-forces-ohio-school-district-to-cancel-classes\">Trickbot Attack Forces Ohio School District to Cancel Classes<\/a><\/strong><\/p>\n<p><em>A school district in Ohio suspended classes on Monday, May 20, because of a Trickbot attack on its network and computers.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong><a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/internet-of-things\/the-iot-attack-surface-threats-and-security-solutions\">The IoT Attack Surface: Threats and Security Solutions<\/a><\/strong><\/p>\n<p><em>Part of adopting the IoT is anticipating what else the technology brings to the environments it is being applied to \u2014 not least of which are security concerns that can give rise to successful attacks on IoT systems and devices.<\/em><\/p>\n<p><strong><a href=\"https:\/\/www.scmagazine.com\/home\/security-news\/data-breach\/hacker-has-designs-on-canva-data-steals-info-belonging-to-139m-users\/\">Hacker Has Designs on Canva Data, Steals Info Belonging to 139M Users<\/a><\/strong><\/p>\n<p><em>The graphic design website Canva was hacked in a data theft incident, which exposed usernames, email addresses, encrypted passwords, customer names and more. <\/em><\/p>\n<p><strong><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cve-2019-0725-an-analysis-of-its-exploitability\/\">CVE-2019-0725: An Analysis of Its Exploitability<\/a><\/strong><\/p>\n<p><em>A remote code execution vulnerability from May\u2019s Patch Tuesday is particularly hard to ignore: CVE-2019-0725, an RCE vulnerability in Windows Dynamic Host Configuration Protocol (DHCP) Server<\/em><em>, which <\/em><em>doesn\u2019t require user interaction and affects all versions of Windows Server<\/em><em>.<\/em><\/p>\n<p><strong><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-mirai-variant-uses-multiple-exploits-to-target-routers-and-other-devices\/\">New Mirai Variant Uses Multiple Exploits to Target Routers and Other Devices<\/a><\/strong><\/p>\n<p><em>Trend Micro discovered a new variant of Mirai that uses a total of 13 different exploits in a single campaign &#8211; the first Mirai variant to do so &#8211; and has backdoor and distributed denial-of-service (DDoS) capabilities. <\/em><\/p>\n<p><strong><a href=\"https:\/\/www.forbes.com\/sites\/ajdellinger\/2019\/05\/28\/first-american-hit-with-class-action-lawsuit-over-massive-data-exposure\/#6ae4516159c3\">First American Hit with Class Action Lawsuit Over Massive Data Exposure<\/a><\/strong><\/p>\n<p><em>Insurance giant First American Financial is facing a class action lawsuit for negligence after it left more than 885 million sensitive documents dating as far back as 2003<\/em> <em>exposed online.\u00a0 <\/em><\/p>\n<p><strong><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cve-2019-11815-a-cautionary-tale-about-cvss-scores\/\">CVE-2019-11815: A Cautionary Tale About CVSS Scores<\/a><\/strong><\/p>\n<p><em>At first glance, the details for Linux kernel vulnerability CVE-2019-11815\u2019s score from CVSS seem like a worst-case scenario but assessing a vulnerability\u2019s potential impact goes beyond the attack vector, privileges, and CIA impact of the base score.<\/em><\/p>\n<p><strong><a href=\"https:\/\/www.zdnet.com\/article\/flipboard-says-hackers-stole-user-details\/\">Flipboard Says Hackers Stole User Details<\/a><\/strong><\/p>\n<p><em>Flipboard, a news aggregator service and mobile news app, has started notifying users of a security incident during which hackers had access to internal systems for more than nine months.<\/em><\/p>\n<p><strong><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/infected-cryptocurrency-mining-containers-target-docker-hosts-with-exposed-apis-use-shodan-to-find-additional-victims\/\">Infected Cryptocurrency-Mining Containers Target Docker Hosts With Exposed APIs, Use Shodan to Find Additional Victims<\/a><\/strong><\/p>\n<p><em>By analyzing the logs and traffic data coming to and from a honeypot, Trend Micro found a container that came from a public and accessible Docker Hub repository named zoolu2 that contained images with the binary of a Monero cryptocurrency miner.<\/em><\/p>\n<p><strong><a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/vulnerabilities-and-exploits\/nearly-1-million-systems-affected-by-wormable-bluekeep-vulnerability-cve-2019-0708\">Nearly 1 Million Systems Affected By &#8216;Wormable&#8217; BlueKeep Vulnerability (CVE-2019-0708)<\/a><\/strong><\/p>\n<p><em>Almost a million systems are reportedly vulnerable to BlueKeep, a critical vulnerability in remote desktop services, but Microsoft\u2019s Patch Tuesday for May already rolled out patches for BlueKeep and security advisories were released to help users address the vulnerability. <\/em><\/p>\n<p><strong><a href=\"https:\/\/www.bankinfosecurity.com\/under-gdpr-uk-data-breach-reports-quadruple-a-12530\">Under GDPR, UK Data Breach Reports Quadruple<\/a><\/strong><\/p>\n<p><em>The United Kingdom has seen the number of data breach notifications more than quadruple since Europe&#8217;s GDPR privacy law went into full force a result of\u00a0<a href=\"https:\/\/www.bankinfosecurity.com\/data-breach-reports-in-europe-under-gdpr-exceed-59000-a-12006\">mandatory reporting<\/a>\u00a0driving better visibility<\/em><\/p>\n<p>Where you surprised that a Trickbot attack could cause school districts to cancel classes? Share your thoughts in the comments below or follow me on Twitter to continue the conversation: <a href=\"https:\/\/twitter.com\/jonlclay\">@JonLClay.<\/a><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/this-week-in-security-news-trickbots-and-infected-containers\/\">This Week in Security News: Trickbots and Infected Containers<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com\/this-week-in-security-news-trickbots-and-infected-containers\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jon Clay (Global Threat Communications)| Date: Fri, 31 May 2019 13:05:27 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-300x300.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" link_thumbnail=\"\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-300x300.jpg 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-768x768.jpg 768w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-1024x1024.jpg 1024w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-640x640.jpg 640w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-900x900.jpg 900w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-440x440.jpg 440w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/02\/Week-in-Security-News-Logo_RGB-380x380.jpg 380w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn how a Trickbot attacked a school district\u2019s networks and how infected cryptocurrency-mining containers target docker hosts with exposed APIs. Read on: Trickbot Attack Forces Ohio School&#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/this-week-in-security-news-trickbots-and-infected-containers\/\">This Week in Security News: Trickbots and Infected Containers<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[10422,714],"class_list":["post-15440","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-current-news","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15440"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15440\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15440"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}