Weekly Threat Briefing: Ransomware, IPStorm, APT Group, and More

Weekly Threat Briefing: Ransomware, IPStorm, APT Group, and More

The various threat intelligence stories in this iteration of the Weekly Threat Briefing discuss the following topics: APT, BlackTech, BLINDINGCAN, Linux Malware, Palmerworm, Vulnerabilities, and XDSpy. The IOCs related to these stories are attached to the Weekly Threat Briefing and can be used to check your logs for potential malicious activity. Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.


Trending Cyber News and Threat Intelligence


Grindr Fixed a Bug Allowing Full Takeover of Any User Account


(published: October 3, 2020)


Grindr, an LGBT networking platform, has fixed a vulnerability that could allow any account to be hijacked. The vulnerability was identified by security researcher Wassime Bouimadaghene, finding that the reset token was leaked in the page’s response content. This would enable anyone who knows a users’ email address to generate the reset link that is sent via email. Gaining account access would enable an attacker to obtain sensitive information such as pictures stored on the app (including NSFW), HIV status, location, and messages. Grindr has announced a bug bounty program.Recommendation: If your account has been breached, you can reset the password using the reset link sent to the associated email address.Tags: Browser, Exposed tokens, Grindr, Sensitive Info


XDSpy: Stealing Government Secrets Since 2011


(published: October 2, 2020)


Security researchers from ESET have identified a new Advanced Persistent Threat (APT) group that has been targeting Eastern European governments and businesses for up to nine years. Dubbed “XDSpy,” ESET was unable to identify any code similari ..

Support the originator by clicking the read the rest link below.