{"id":1599,"date":"2018-05-26T22:34:10","date_gmt":"2018-05-26T22:34:10","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/"},"modified":"2018-05-26T22:34:10","modified_gmt":"2018-05-26T22:34:10","slug":"starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/","title":{"rendered":"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2016\/05\/26\/coffee.jpg?x=1200&amp;y=794\" class=\"ff-og-image-inserted\"\/><\/div>\n<p><strong class=\"trailer\">Roundup<\/strong> While this week was dominated by news of a <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/05\/21\/spectre_meltdown_v4_microsoft_google\/\">new Spectre variant<\/a>, the <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/05\/23\/vpnfilter_malware_menacing_routers_worldwide\/\">VPNFilter botnet<\/a>, and TalkTalk&#8217;s <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/05\/22\/talktalk_routers_cracked_by_four_year_old_bug\/\">badbad routersrouters<\/a>, plenty of other stories popped up.<\/p>\n<p>Here are a handful of security happenings that you may have missed.<\/p>\n<h3 class=\"crosshead\"><span>Wireless Z-Wave smart-locks, home IoT devices menaced<\/span><\/h3>\n<p>Wireless gadgets, such as home smart locks, using Z-Wave to communicate via radio can be potentially hijacked over the air by nearby miscreants, <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.pentestpartners.com\/security-blog\/z-shave-exploiting-z-wave-downgrade-attacks\/\">according to<\/a> infosec biz Pen Test Partners.<\/p>\n<p>Once upon a time, Z-Wave had a pairing mode called S0 that was used to connect a device, such as a lightbulb or lock, to a controller, such as a home IoT hub. In 2013, that <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/sensepost.com\/cms\/resources\/conferences\/2013\/bh_zwave\/Security%20Evaluation%20of%20Z-Wave_WP.pdf\">mode<\/a> was <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2013\/08\/13\/wave_goodbye_to_security_with_zwave\/\">found to be insecure<\/a>, so today Z-Wave-compatible devices use a stronger pairing method called S2.<\/p>\n<p>However, Pen Test Partners said this week it has found a way to downgrade communications between gizmos to S0 mode from S2 during pairing, thus opening up more than 100 million Z-Wave-compatible things to potential attack. If you can get near a gizmo while it is in pairing mode, such as during its initial setup, you can potentially push it down to S0 and attempt to commandeer it.<\/p>\n<p>Here&#8217;s a video demonstrating the flaw:<\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=kw3Ypoi4kIY\" data-media=\"x-videoplayer\">Youtube Video<\/a><\/p>\n<p>Z-Wave overseers Silicon Labs <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.silabs.com\/community\/blog.entry.html\/2018\/05\/23\/tl_dr_your_door_is-g1zC\">said<\/a> devices already paired cannot be forced down to S0 from S2, adding: &#8220;We are updating the specification to ensure that any user will not only get a warning during a downgrade to S0 but will have to acknowledge the warning and accept it to continue inclusion.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>Starbucks brews double-whip grande mocha pwnage<\/span><\/h3>\n<p>Researcher Martin Bajanik discovered a <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/hackerone.com\/reports\/227486\">cross site scripting bug<\/a> that was present on the Starbucks UK website. The now-patched bug would have allowed an attacker to inject malicious JavaScript into the browsers of people visiting the cafe chain&#8217;s online store, though Bajanik says an actual exploit would have been hard to pull off.<\/p>\n<p>&#8220;The underlying issue was a simple HTML injection with extremely low, even none, security impact. Due to existing code, however, I was able to achieve arbitrary JavaScript execution under certain, fairly obscure, circumstances,&#8221; Bajanik told <em>The Register<\/em>.<\/p>\n<p>&#8220;Exploitation would have been rather unlikely as the attack could only work if the potential victims would had followed a malicious link created by the attacker (it was reflected XSS).&#8221;<\/p>\n<p>Speaking of bug bounties, researcher Ryan Stevenson banked $1,000 after <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.zdnet.com\/article\/tmobile-bug-let-anyone-see-any-customers-account-details\/\">discovering<\/a> in April a T-Mobile US server used by staff to look up customers&#8217; names, addresses and account numbers using their cellphone numbers, which was not secured and open to all who could find it. It&#8217;s since been fixed.<\/p>\n<p>If you&#8217;ve found any security vulnerabilities, and want to share details, <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/Author\/Email\/Shaun-Nichols\">please do let us know<\/a> or chat to us anonymously on <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/ricochet.im\/\">Ricochet<\/a> at <code>ricochet:qk724lftsymjcwlq<\/code><\/p>\n<div class=\"boxout\">\n<h3 class=\"crosshead\"><span>Quick links<\/span><\/h3>\n<ul>\n<li>A remote code execution vulnerability found in a Google App Engine system <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/sites.google.com\/site\/testsitehacking\/-36k-google-app-engine-rce\">earned<\/a> an 18-year-old whizkid a $36,000 reward.<\/li>\n<li>Avast has <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/blog.avast.com\/android-devices-ship-with-pre-installed-malware\">found ad-slinging malware<\/a> dubbed Cosiloon shipping in more than 140 models of <strong>cheap Android devices<\/strong> \u2013 a list of allegedly affected models is <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/docs.google.com\/spreadsheets\/d\/1RXkReFfgyBhri-B5ZFsTPk8asRLi_MKtFQnbDYhpf50\/edit#gid=0\">here<\/a>.<\/li>\n<li>SecureList has published <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/securelist.com\/vpnfilter-exif-to-c2-mechanism-analysed\/85721\/\">details<\/a> of the EXIF-based command-and-control mechanisms used by the <strong>VPNFilter<\/strong> <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/05\/24\/fbi_vpnfilter_botnet\/\">home router malware<\/a>.<\/li>\n<li>Dmitry Bogatov, 26, has been <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/themoscowtimes.com\/news\/russias-tor-node-administrator-acquitted-terrorism-charges-61490\">cleared of wrongdoing<\/a> in Russia after the <strong>Tor exit node<\/strong> he administrated was used by someone else to incite terrorism online.<\/li>\n<li>Mobile app <strong>TeenSafe<\/strong>, installed by parents on their kids&#8217; phones to monitor their messages and keep tabs on them, was <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.zdnet.com\/article\/teen-phone-monitoring-app-leaks-thousands-of-users-data\/\">found leaking<\/a> data \u2013 such as the children&#8217;s Apple ID email addresses and plaintext passwords \u2013 in a poorly secured Amazon AWS S3 storage silo. The two databases, one containing test data, the other what appeared to be a few thousand real records, have been pulled offline.<\/li>\n<\/ul>\n<\/div>\n<h3 class=\"crosshead\"><span>IRS warns beancounters over phishing scams<\/span><\/h3>\n<p>US tax officials are sounding an alert over a wave of <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.irs.gov\/newsroom\/irs-warns-tax-pros-of-new-scam-posing-as-professional-associations\">spear phishing attacks<\/a> targeting professional accountants.<\/p>\n<p>The campaigns go after the high-value target in tax scams: the pros who would handle dozens of personal and corporate tax filings.<\/p>\n<p>&#8220;Cybercriminals specifically targeted tax professionals in Iowa, Illinois, New Jersey and North Carolina. The IRS also received reports about a Canadian accounting association,&#8221; the IRS explained<\/p>\n<p>&#8220;The awkwardly worded phishing email states: &#8216;We kindly request that you follow this link HERE and sign in with your email to view this information from (name of accounting association) to all active members. This announcement has been updated for your kind information through our secure information sharing portal which is linked to your email server&#8217;.&#8221;<\/p>\n<p>Needless to say, accountants and the IT staff and admins who work with them should be on the lookout for this scam.<\/p>\n<h3 class=\"crosshead\"><span>Comcast site spaffs Wi-Fi keys<\/span><\/h3>\n<p>US cable giant Comcast has confirmed <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.zdnet.com\/article\/comcast-bug-leaks-xfinity-home-addresses-wireless-passwords\/\">reports<\/a> that its Xfinity home site was leaking some customer information including Wi-Fi passwords. The bug, spotted in the customer portal, would have allowed an attacker with an account number to obtain the person&#8217;s home address, Wi-Fi network name, and password.<\/p>\n<p>&#8220;There\u2019s nothing more important than our customers\u2019 security. Within hours of learning of this issue, we shut it down. At no time did this site enable anyone to access customers\u2019 personal usernames and passwords and we have no reason to believe that any account information was accessed,&#8221; Comcast told <em>The Register<\/em>.<\/p>\n<p>&#8220;We are conducting a thorough investigation and will take all necessary steps to ensure that this doesn\u2019t happen again.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>I wish I knew how to quit you Eugene<\/span><\/h3>\n<p>Weeks after supposedly banning all Kaspersky Lab software from government sysytem, the US Department of Homeland Security is said to still be running the security vendor&#8217;s code on many of its computers. The problem is that a number of routers, firewalls, and other equipment rely on Kaspersky products for their security, we&#8217;re told.<\/p>\n<p>&#8220;It\u2019s messy, and it\u2019s going to take way longer than a year,&#8221; one official <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.thedailybeast.com\/exclusive-us-government-cant-get-controversial-kaspersky-lab-software-off-its-networks\">was quoted<\/a> as saying. &#8220;Congress didn\u2019t give anyone money to replace these devices, and the budget had no wiggle-room to begin with.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>D-Link routers leave the back door open<\/span><\/h3>\n<p>Stop us if you&#8217;ve heard this one before: a home router vendor has left serious security vulnerabilities wide open in its devices.<\/p>\n<p>This time, <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/securelist.com\/backdoors-in-d-links-backyard\/85530\/\">it&#8217;s D-Link<\/a> who have messed up by using a bug-riddled firmware that contains no fewer than four serious remotely exploitable vulnerabilities, including data disclosure and remote code execution.<\/p>\n<p>According to Kaspersky Lab, the routers are largely concentrated to a few ISPs in Russia, but may also be in use by customers in other parts of the world.<\/p>\n<p>&#8220;The latest versions of the firmware have hardcoded default credentials that can be exploited by an unauthenticated attacker to gain privileged access to the firmware and to extract sensitive data, e.g., configuration files with plain-text passwords,&#8221; says the security vendor.<\/p>\n<p>&#8220;The vulnerable web interface allows an unauthenticated attacker to run arbitrary JavaScript code in the user environment and run arbitrary commands in the router\u2019s operating system (OS).&#8221;<\/p>\n<h3 class=\"crosshead\"><span>Mac Monero malware menaces millions<\/span><\/h3>\n<p>Lest you thought rogue coin creators were only a problem for the Windows world (and we have no idea why you would think that), here is a new piece of Mac malware that turns your beloved iThing into a coin-generating machine for hackers.<\/p>\n<p>Malwarebytes has <a target=\"_blank\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/mac-threat-analysis\/2018\/05\/new-mac-cryptominer-uses-xmrig\/\">an analysis<\/a> of a piece of malware spotted by a number of Mac users that hijacks CPU time to run XMRig, a Monero-mining tool. They&#8217;re not sure how the malware is being installed, but it&#8217;s likely not anything more sophisticated than a dodgy download site.<\/p>\n<p>Fortunately, all this malware seems to do is waste your CPU cycles.<\/p>\n<p>&#8220;This malware is not particularly dangerous, unless your Mac has a problem like damaged fans or dust-clogged vents that could cause overheating,&#8221; Malwarebytes explains.<\/p>\n<h3 class=\"crosshead\"><span>Russia breaks up malware bank heist<\/span><\/h3>\n<p>Earlier this week, members of Russia&#8217;s Group-IB announced the arrest of a 32-year-old man they believe to be behind a massive malware operation.<\/p>\n<p>According to the group&#8217;s release, the unnamed man had used a set of Android malware packages to lift the bank account credentials of people in Russia and send them to a command server. From there, withdrawals were made from the accounts, with the same malware infections intercepting SMS notifications on the victims&#8217; phones.<\/p>\n<p>The Group-IB statement indicates the man had been acting as part of a larger operation.<\/p>\n<p>&#8220;The investigation by authorities identified a member of the criminal group, who was responsible for transferring money from user accounts to attacker\u2019s cards, a 32 year old unemployed Russian national who had previous convictions connected to arms trafficking,&#8221; Group-IB said.<\/p>\n<p>&#8220;During the suspects arrest in May 2018, authorities identified SIM cards and fraudulent bank cards to which stolen funds were transferred. The suspect has confessed to his actions and the investigation\/prosecution continues.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>What time is it? Xenotime<\/span><\/h3>\n<p>Security company Dragos says it has found what it thinks is &#8220;easily the most dangerous threat activity publicly known&#8221; in a piece of industrial malware it has dubbed <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/dragos.com\/blog\/20180524Xenotime.html\">&#8220;Xenotime&#8221;.<\/a><\/p>\n<p>The malware, according to Dragos, is highly sophisticated and it spreads through both industrial controllers and Windows systems alike. The ultimate target of the worm appears to be safety control systems. Were it to live, Dragos warns, the malware could cause serious physical danger.<\/p>\n<p>Fortunately, it looks like at least one major attack from the malware&#8217;s controllers has already failed.<\/p>\n<p>&#8220;The group created a custom malware framework and tailormade credential gathering tools, but an apparent misconfiguration prevented the attack from executing properly,&#8221; Dragos said.<\/p>\n<p>&#8220;As Xenotime matures, it is less likely that the group will make this mistake in the future.&#8221;<\/p>\n<p>Now there&#8217;s happy note to enjoy the long weekend on. Stay safe people. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1759\/shttp:\/\/www.mcubed.london\/\">Minds Mastering Machines &#8211; Call for papers now open<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2018\/05\/26\/info_security_roundup\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some security bites for the long weekend Roundup\u00a0 While this week was dominated by news of a new Spectre variant, the VPNFilter botnet, and TalkTalk&#8217;s badbad routersrouters, plenty of other stories popped up.\u2026  READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":1600,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-1599","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-26T22:34:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"794\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more\",\"datePublished\":\"2018-05-26T22:34:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/\"},\"wordCount\":1624,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/\",\"name\":\"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg\",\"datePublished\":\"2018-05-26T22:34:10+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg\",\"width\":1200,\"height\":794},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/","og_locale":"en_US","og_type":"article","og_title":"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-05-26T22:34:10+00:00","og_image":[{"width":1200,"height":794,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more","datePublished":"2018-05-26T22:34:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/"},"wordCount":1624,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/","url":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/","name":"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg","datePublished":"2018-05-26T22:34:10+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more.jpg","width":1200,"height":794},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/starbucks-site-slurped-z-wave-locks-clocked-mad-mac-monero-mining-malware-and-much-more\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/1599","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=1599"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/1599\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/1600"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=1599"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=1599"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=1599"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}