Weekly Threat Briefing: Ensiko Ransomware, Lazarus, Vulnerabilities and More

The various threat intelligence stories in this iteration of the Weekly Threat Briefing discuss the following topics: APT, Data breach, Data leak, Malware, Nemty, Ransomware, Twitter Hack, and Vulnerabilities. The IOCs related to these stories are attached to the Weekly Threat Briefing and can be used to check your logs for potential malicious activity.



Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.



Trending Cyber News and Threat Intelligence



Havenly Discloses Data Breach After 1.3M Accounts Leaked Online



(published: August 2, 2020)



Interior design website Havenly has been breached, exposing 1.3 million user records. The database has been posted on a hacking forum for free, following the leak of 386 million user records from 18 companies. The Havenly breach includes email addresses, names, phone numbers, zip code and MD5 hashed passwords. Havenly claim they do not store full credit card numbers, and that only the last four digits could be exposed.Recommendation: Havenly have implemented a mandatory password change, make sure to use a strong and unique password for all accounts. Threat actors may try to use cracked passwords for other sites which users may have an account with the same login details.Tags: Data breach, Leaked Database, PII



US Government Sites Abused to Redirect Users to Porn Sites



(published: July 31, 2020)



In an ongoing Search Engine Optimization (SEO) campaign, blackhat scammers are using open redirects found on US government websites to create links that redirect users to porn sites while ..

Support the originator by clicking the read the rest link below.