Skip to content

Risk

Security and Technology news from various third party sources. All attribution remains the property of the original authors

203 Topics 203 Posts
  • 0 Votes
    1 Posts
    98 Views
    CerberusC

    Analysis of Latest Health Data Breaches on the HHS OCR ‘Wall of Shame’
    Ransomware incidents are becoming a major cause of health data breaches affecting millions of individuals that have been reported so far in 2021, according to the latest additions to the federal tally. What else is topping the list?

    https://www.inforisktoday.co.uk/ransomware-incidents-among-largest-breaches-on-federal-tally-a-17846

  • 0 Votes
    1 Posts
    87 Views
    CerberusC

    Bad Actors Learn Victim Firms’ Public, Nonpublic Data Before Attack to Increase Impact
    The Federal Bureau of Investigation has issued a notification warning to private sector companies, especially those listed or in the process of being listed on stock exchanges, to be aware of ransomware actors using their undisclosed merger and acquisition data for extortion.

    https://www.inforisktoday.co.uk/fbi-warns-ransomware-actors-leveraging-ma-data-a-17847

  • 0 Votes
    1 Posts
    90 Views
    CerberusC

    Criminal Group Announced News on Russian Site, Says Malware Research Organization vx-underground
    Ransomware-as-a-service provider BlackMatter has ceased operations due to pressure from local authorities, malware research organization vx-underground says, citing an announcement made by the gang on a Russian underground site.

    https://www.inforisktoday.co.uk/blackmatter-claims-to-shut-ops-experts-suspect-rebranding-a-17848

  • 0 Votes
    1 Posts
    79 Views
    CerberusC

    BOD 22-01 Imposes Strict Deadlines for Remediation of Publicly Known Exploits
    The U.S. Cybersecurity and Infrastructure Security Agency on Wednesday issued a new directive - BOD 22-01 - requiring federal civilian agencies to patch vulnerabilities known to be actively exploited in the wild.

    https://www.inforisktoday.co.uk/cisa-directs-federal-agencies-to-patch-known-vulnerabilities-a-17845

  • 0 Votes
    1 Posts
    71 Views
    CerberusC

    Facebook Will Delete More Than a Billion Facial Profiles
    Facebook plans to shut down its facial recognition system, saying the regulatory landscape is unclear and citing ongoing concerns about the effects on society of using such systems. The company plans to delete more than one billion facial profiles.

    https://www.inforisktoday.co.uk/facebook-shuts-down-facial-recognition-feature-a-17842

  • 0 Votes
    1 Posts
    68 Views
    CerberusC

    Report Calls for Congressional Action to Address Risks With Fiat-Backed Tokens
    A new report from the U.S. Treasury Department urges Congress to “act promptly” to issue legislation that brings additional oversight to stablecoins, or crypto tokens pegged to fiat currencies. Federal officials say regulation should match that of traditional financial institutions - as a way to mitigate investor, market and cybersecurity risks, among others.

    https://www.inforisktoday.co.uk/us-treasury-department-says-stablecoins-must-be-regulated-a-17840

  • 0 Votes
    1 Posts
    64 Views
    CerberusC

    New Players and Rebranding Remain Constant, as Does Challenge of Operating Anonymously
    While ransomware remains many criminals’ weapon of choice for reliably shaking down victims, the ransomware-attacker landscape itself continues to evolve in numerous ways, with a constant influx of fresh players, regular rebranding, as well as the challenge of cashing in cryptocurrency while staying anonymous.

    https://www.inforisktoday.co.uk/7-trends-how-ransomware-operations-continue-to-evolve-a-17841

  • 0 Votes
    1 Posts
    70 Views
    CerberusC

    A Nevada Cancer Center Is Also Dealing With the Aftermath of an Attack
    A recent cyberattack on Community Medical Centers in Northern California has potentially compromised the information of more than 656,000 individuals. Meanwhile, Las Vegas Cancer Center reportedly fell victim to a ransomware attack during Labor Day weekend.

    https://www.inforisktoday.co.uk/california-clinic-network-cyber-incident-affects-656000-a-17839

  • 0 Votes
    1 Posts
    64 Views
    CerberusC

    European Commission: Guidelines Aim to Protect Wireless Privacy, Prevent Fraud
    Wireless device makers in the European Union market will soon have to adhere to a new set of cybersecurity guidelines at the design and production stages of manufacturing, according to the European Commission. The guidelines target devices such as mobile phones, tablets and other products.

    https://www.inforisktoday.co.uk/new-cybersecurity-norms-for-wireless-device-makers-in-eu-a-17837

  • 0 Votes
    1 Posts
    66 Views
    CerberusC

    This Flaw Could Lead to an Attack Like SolarWinds
    Two researchers from the University of Cambridge have discovered a vulnerability that affects most computer code compilers and many software development environments, according to a new research paper. The bug could cause a SolarWinds-like open-source supply chain attack scenario, they say.

    https://www.inforisktoday.co.uk/trojan-source-invisible-vulnerabilities-in-most-code-a-17833

  • 0 Votes
    1 Posts
    69 Views
    CerberusC

    Agency’s Jen Easterly, Rep. John Katko Discuss Protection of U.S. Networks
    CISA Director Jen Easterly and congressional leader John Katko, R-N.Y., agree that officials must take precautionary steps to identify “systemically important critical infrastructure” to reduce risks of pervasive supply chain cyberattacks.

    https://www.inforisktoday.co.uk/cisa-begins-program-to-identify-critical-infrastructure-a-17835

  • 0 Votes
    1 Posts
    66 Views
    CerberusC

    Lt. Gen. Pant: Why India Needs a Cybersecurity Strategy; What It Plans to Accomplish
    India is in the last stage of rolling out a national cybersecurity strategy that aims to address challenges and appoint an apex body to regulate various government agencies, including CERT-In, the Cyber Crime Coordination Center and the National Critical Information Infrastructure Protection Center.

    https://www.inforisktoday.co.uk/indias-national-cybersecurity-strategy-awaiting-approval-a-17829

  • 0 Votes
    1 Posts
    71 Views
    CerberusC

    London-Based Graff Jeweller’s Clients Include High-Profile Celebs
    The Conti cybercrime gang, known for ransomware attacks, has reportedly leaked details of world leaders, actors and business tycoons after a strike at jeweler Graff. The organization is working with law enforcement and has informed the U.K.'s Information Commissioner’s Office about the incident.

    https://www.inforisktoday.co.uk/celebrities-data-dumped-on-darknet-site-after-hack-a-17830

  • 0 Votes
    1 Posts
    62 Views
    CerberusC

    Operators Left Exposed After Overreaching, Says McAfee Enterprise’s John Fokker
    How is the ransomware ecosystem set to evolve? Since some operations overreached - notably with DarkSide’s hit on Colonial Pipeline - “what we’re seeing … is that there is going to be a power balance shift,” says McAfee’s John Fokker, with more affiliates, not gang leaders, calling the shots.

    https://www.inforisktoday.co.uk/ransomware-evolves-affiliates-set-to-wield-greater-power-a-17832

  • 0 Votes
    1 Posts
    62 Views
    CerberusC

    HHS OCR: If Old Gear Cannot Be Replaced, Take Other Steps to Protect PHI
    Federal regulators are reminding healthcare organizations about the critical importance of addressing security risks involving legacy systems and devices - including specialty software and gear - that are often difficult for entities to replace. What steps should entities take?

    https://www.inforisktoday.co.uk/reduce-security-risk-healthcare-legacy-systems-devices-a-17834

  • 0 Votes
    1 Posts
    73 Views
    CerberusC

    Threat Actors Believed Responsible For More Than 1,800 Ransomware Attacks
    The suspected cyber actors behind deployment of ransomware strains such as LockerGoga, MegaCortex and Dharma, among others, are under arrest, after a joint operation involving law enforcement and judiciary from eight countries. They are believed to have affected more than 1,800 victims.

    https://www.inforisktoday.co.uk/multinational-police-force-arrests-12-suspected-hackers-a-17828

  • 0 Votes
    1 Posts
    78 Views
    CerberusC

    Director Chris Inglis Also Outlines Vision for NCD Office, Level of Accountability
    National Cyber Director Chris Inglis on Thursday announced that Federal CISO Chris DeRusha will concurrently serve as his deputy at the newly created office. Inglis, a Senate-confirmed top adviser to the president, also released a “statement of strategic intent” outlining his own official duties.

    https://www.inforisktoday.co.uk/federal-ciso-derusha-named-deputy-national-cyber-director-a-17827

  • 0 Votes
    1 Posts
    71 Views
    CerberusC

    Exploitation May Have Exposed REST-API Endpoints on Sites, Researchers Say
    OptinMonster, a WordPress plug-in used in more than 1 million websites for sales campaign creation, was vulnerable to high-severity bugs, according to Wordfence researchers. An updated version of the plug-in has patched the flaws.

    https://www.inforisktoday.co.uk/wordpress-plug-in-bugs-put-1-million-plus-sites-at-risk-a-17822

  • 0 Votes
    1 Posts
    69 Views
    CerberusC

    After Consulting With VTC Providers, Authorities Recommend End-to-End Encryption
    Six national data protection and privacy authorities – from Australia, Canada, Gibraltar, Hong Kong SAR, China and Switzerland - have joined with the U.K. information Commissioner’s Office to issue guidance to video teleconferencing companies on privacy, calling for end-to-end encryption.

    https://www.inforisktoday.co.uk/countries-team-up-to-issue-video-teleconference-guidance-a-17823

  • 0 Votes
    1 Posts
    77 Views
    CerberusC

    Academic Medical Center Says Access to Email Accounts Lasted Months
    Massachusetts-based UMass Memorial Health is the latest large healthcare network to report an email phishing incident that potentially compromised hundreds of thousands of individuals’ protected health information. The unauthorized email access lasted about seven months.

    https://www.inforisktoday.co.uk/healthcare-system-phishing-breach-affects-209000-a-17824

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    VMware’s Tom Kellermann on Defending Against Ransomware Attacks
    In ransomware attacks, cybercriminals attack through the backups because they know that security practitioners rely on backups to save themselves after a ransomware attack. Therefore, it is essential to have multiple backups, says Tom Kellermann, head of cybersecurity strategy at VMware.

    https://www.inforisktoday.co.uk/enterprise-backups-are-becoming-targets-for-cybercriminals-a-17820

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    Also: Increasing Diversity and Inclusion in Cybersecurity
    Four ISMG editors discuss important cybersecurity issues, including law enforcement authorities’ disruption of ransomware gang REvil’s operations, how to collaborate as an industry to fight the surge in ransomware attacks hitting businesses, and increasing diversity and inclusion in the workplace.

    https://www.inforisktoday.co.uk/ismg-editors-solving-ransomware-problem-together-a-17818

  • 0 Votes
    1 Posts
    31 Views
    CerberusC

    Company Aims to Fill 250,000-Worker Shortfall in Cybersecurity
    Microsoft launched a four-year campaign on Thursday with community colleges in the U.S. aimed at recruiting hundreds of thousands of people into the field of cybersecurity. The goal is to fill an expected shortfall of 250,000 workers in cybersecurity, which Microsoft says means rising risk.

    https://www.inforisktoday.co.uk/microsoft-launches-cybersecurity-recruitment-campaign-a-17816

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    Security Experts: ‘Grief’ Ransomware Gang Leaks Alleged NRA Data on Darknet
    The National Rifle Association has reportedly fallen victim to a ransomware attack at the hands of a Russian cybercriminal gang known as Grief. The group has reportedly posted 13 files to its website after claiming to have hacked the gun rights advocacy group.

    https://www.inforisktoday.co.uk/nra-reportedly-hit-by-russia-linked-ransomware-attack-a-17815

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    Incident Is Among Latest Involving Healthcare Supply Chain Vendors
    A ransomware attack on a medical practice management services firm that included the theft of files containing patient information is among the latest security incidents involving similar third-party vendors.

    https://www.inforisktoday.co.uk/phi-stolen-in-practice-management-firms-ransomware-attack-a-17813

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    Group Uses MATA Framework to Target Defense Orgs, Researchers Say
    North Korean advanced persistent threat group Lazarus - aka Hidden Cobra - is developing supply chain attack capabilities using its multiplatform malware framework, MATA, for cyberespionage goals, according to researchers from Kaspersky.

    https://www.inforisktoday.co.uk/lazarus-adds-supply-chain-attack-to-list-capabilities-a-17811

  • 0 Votes
    1 Posts
    31 Views
    CerberusC

    Kim Wyman Enters Biden Administration as Key Election Security Leader
    CISA announced that Washington Secretary of State Kim Wyman will be the agency’s senior election security lead. She will become a top security official within the Biden administration, inheriting a role that has garnered public attention following interference in 2016 and fraud claims in 2020.

    https://www.inforisktoday.co.uk/washington-secretary-state-to-head-election-security-a-17812

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Desorden Group Attacks Thailand’s Central Group of Companies
    The Desorden hacker group, previously known for its exploits against computer giant Acer and a Singaporean employment agency, has now targeted Thai luxury hotel chain Centara Hotels & Resorts. The group claims to have stolen 400GB of data from the hotel chain’s network.

    https://www.inforisktoday.co.uk/hackers-claim-400gb-data-stolen-from-thai-hotel-chain-a-17814

  • 0 Votes
    1 Posts
    31 Views
    CerberusC

    Severe ‘Extortion-Based’ Attack From Foreign Entities, Firm Tweets
    Telecom company Voipfone has come under a severe “extortion-based” DDoS attack from foreign entities, according to a tweet by the U.K.-based company. The attack is likely a continuation of the one observed on Thursday, although the company stated that all its systems remained operational.

    https://www.inforisktoday.co.uk/voipfone-ddos-attacks-raise-specter-protection-racket-a-17805

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    4th Major Singapore Data Breach This Year Due to Third-Party Vendors
    Singapore healthcare firm Fullerton Health confirms that a data breach in the server of its vendor partner Agape Connecting People was responsible for the leak of 400,000 user accounts. The incident marks the fourth major data breach incident involving third-party vendors in Singapore this year.

    https://www.inforisktoday.co.uk/vendor-partner-responsible-for-fullerton-health-data-breach-a-17806

  • 0 Votes
    1 Posts
    40 Views
    CerberusC

    Bureau of Cyberspace and Digital Policy to Include Ambassador, Special Envoy
    The U.S. Department of State will create a Bureau of Cyberspace and Digital Policy, led by a Senate-confirmed ambassador-at-large, to advance its cybersecurity diplomacy efforts, according to Secretary of State Antony Blinken. The move is a response to a challenging global threat landscape.

    https://www.inforisktoday.co.uk/us-state-department-to-create-dedicated-cyber-office-a-17807

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    Iranian Government Blames Unnamed Foreign Country
    An attack on systems that govern fuel subsidies in Iran reportedly hit all fuel stations and left many of the country’s citizens without gas for hours. Islamic Republic of Iran Broadcasting says that a cyberattack caused widespread disruption to the country’s fuel distribution network.

    https://www.inforisktoday.co.uk/cyberattack-reportedly-cripples-iran-gas-stations-a-17803

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Rebranding Remains Easy for Ransomware Groups, While Affiliates Already Come and Go
    Will the notorious ransomware operation known as REvil, aka Sodinokibi, reboot yet again after someone apparently messed with its infrastructure? Experts suggest that the operation’s brand is burned, and administrators will launch a new group. Many affiliates, meanwhile, already work with multiple groups.

    https://www.inforisktoday.co.uk/revils-cybercrime-reputation-in-tatters-will-reboot-a-17802

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    ‘Operation DarkHunTOR’ Seizes Millions in Cash & Crypto, Plus Drugs, Guns
    International law enforcement officials on Tuesday announced that some 150 suspects have been arrested globally for buying or selling illegal goods, following a 10-month sting operation, code name “Operation DarkHunTOR,” targeting the dark web.

    https://www.inforisktoday.co.uk/us-doj-global-darknet-sting-nabs-150-suspects-a-17799

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Ron Ross of NIST Discusses Moving Away From Stovepipe Thinking
    In preparation for the relaunch of ISMG’s education platform, CyberEd.io, Ron Ross of the National Institute of Standards and Technology and Brian Barnier, who is designing a course on critical thinking and design thinking, discuss the need for reorienting toward systems thinking in cybersecurity.

    https://www.inforisktoday.co.uk/need-for-systems-thinking-in-cybersecurity-a-17798

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Steve King of CyberTheory on Getting Serious With Our Defense Strategy
    Findings from CyberTheory’s 2021 Third Quarter Review indicate that criminals are exploiting the open-source supply chain, and those exploits are proving much more difficult to identify, defend and stop in terms of complexity and depth than we’ve seen before, says CyberTheory’s director, Steve King.

    https://www.inforisktoday.co.uk/defending-against-open-source-supply-chain-attacks-a-17797

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    Retailer Says an Attempt Was Made to Interfere With Its Systems
    Grocery retailer Tesco said it faced a service disruption on its app and website. The company told ISMG that the outage was likely due to an attempt to interfere with its systems. On Monday, a company spokesperson said that both the website and app were now “back up and running.”

    https://www.inforisktoday.co.uk/uks-tesco-supermarket-app-website-disrupted-a-17792

  • 0 Votes
    1 Posts
    40 Views
    CerberusC

    Microsoft Says Nobelium APT Is Eyeing Resellers, Tech Service Providers
    The actor behind the cyberattack targeting SolarWinds customers - Nobelium - is continuing its campaign to target the global IT supply chain, according to a new advisory from Microsoft, which says 140 resellers and tech service providers have been notified that they have been targeted by the group.

    https://www.inforisktoday.co.uk/report-solarwinds-hackers-targeting-supply-chain-a-17793

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Move by Colonial Pipeline Attackers Follows Law Enforcement Action Against REvil
    Following an outage of the REvil - aka Sodinokibi - ransomware operation due to coordinated law enforcement efforts involving the U.S. and foreign partners, the operators behind DarkSide ransomware have moved Bitcoin worth almost $7 million to multiple new wallets, making it more difficult to track.

    https://www.inforisktoday.co.uk/darkside-transfers-7-million-worth-bitcoin-a-17787

  • 0 Votes
    1 Posts
    31 Views
    CerberusC

    Email Addresses Correlate With Accounts on Crypo Price Tracking Service
    CoinMarketCap says it has found no evidence of a data beach despite the circulation of a list of 3.1 million email addresses that correlates with accounts on its service. Regardless of the source, the list would be useful for attackers to launch phishing attacks against those interested in cryptocurrency.

    https://www.inforisktoday.co.uk/coinmarketcap-no-breach-despite-31m-email-address-leak-a-17789

  • 0 Votes
    1 Posts
    52 Views
    CerberusC

    The Cybercrime Group Posted Job Advertisements on Russian Job Portals
    Threat group FIN7 has set up a website posing as a security company to recruit talent, according to fraud intelligence company Gemini Advisory. The aim of the scam was to lure security researchers who could help the group with penetration testing-related activities to enable ransomware attacks.

    https://www.inforisktoday.co.uk/fin7-sets-up-fake-pentesting-company-site-to-recruit-talent-a-17783

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    Co-Sponsor of Bipartisan Proposal Calls Bill ‘Common-Sense Legislation’
    Two Senate leaders on Thursday introduced legislation that would form a working group charged with monitoring the security of AI data obtained by federal contractors. This body would also ensure that the data adequately protects national security and recognizes privacy rights, the lawmakers say.

    https://www.inforisktoday.co.uk/new-bill-would-secure-government-contractors-use-ai-a-17786

  • 0 Votes
    1 Posts
    32 Views
    CerberusC

    Sonatype: Cryptominers Launched in Windows, macOS, Linux Devices
    Researchers at open-source software firm Sonatype have uncovered multiple malicious packages that disguise themselves as legitimate JavaScript libraries on npm registries to launch cryptominers on Windows, macOS and Linux machines.

    https://www.inforisktoday.co.uk/malicious-packages-disguised-as-javascript-libraries-found-a-17782

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Forrester Analyst Allie Mellen on Navigating the XDR Market
    The current state of the XDR market is a “chaotic jumble of different features,” according to Forrester analyst Allie Mellon, who has authored a new study to identify the top XDR providers in the industry: The Forrester New Wave: Extended Detection And Response (XDR) Providers, Q4 2021.

    https://www.inforisktoday.co.uk/forrester-report-key-questions-to-ask-xdr-vendors-a-17781

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    FBI, US Secret Service and US Cyber Command Target Ransomware Gangs, Reuters Reports
    The outages of the notorious REvil - aka Sodinokibi - ransomware operation have been due to a coordinated law enforcement effort involving the U.S. and foreign partners, aimed at disrupting the group’s attack capabilities, Reuters reports.

    https://www.inforisktoday.co.uk/revil-revelations-law-enforcement-behind-disruptions-a-17779

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    Discussion Also Addresses the Return to In-Person Events
    In the latest weekly update, four ISMG editors discuss: a federal judge imposing the maximum sentences on a hacker who pleaded guilty to conspiracy and aggravated identity theft, regulators getting tougher on cryptocurrency lending platforms and the return to in-person roundtables.

    https://www.inforisktoday.co.uk/ismg-editors-panel-regulators-get-tough-on-crypto-firms-a-17780

  • 0 Votes
    1 Posts
    59 Views
    CerberusC

    Multiple Breach Reports for Phishing Incident Reflect Notification Complexities
    The Professional Dental Alliance is notifying more than 170,000 individuals in about a dozen states of a phishing breach involving an affiliated vendor that provides nonclinical management services to dental practices owned by PDA. Why is breach notification so complicated?

    https://www.inforisktoday.co.uk/dental-alliance-reports-vendor-breach-affecting-170000-a-17775

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    Tools Used for Personal Surveillance, Malicious Activities Must Be Licensed
    The U.S. Bureau of Industry and Security has issued an interim final rule to curb and control the export, reexport, or in-country transfer of certain offensive cyber tools that are used in surveillance of private citizens and other malicious activities that undermine the nation’s security.

    https://www.inforisktoday.co.uk/us-cracks-down-on-sale-offensive-cybersecurity-tools-a-17776

  • 0 Votes
    1 Posts
    33 Views
    CerberusC

    Legislation Targets DHS SBOM, Further Chinese Telecom Restrictions
    In a busy congressional day for cybersecurity legislation, the U.S. House of Representatives passed several bills on Wednesday, targeting both software supply chain and telecommunication system security. One observer describes them as “a win-win for the government and U.S. citizens.”

    https://www.inforisktoday.co.uk/house-passes-bills-on-both-supply-chain-telecom-security-a-17777

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    The Group Updated Its Malware Arsenal With New Capabilities
    Researchers at Kaspersky report that Lyceum group, known for targeting organizations in the energy and telecommunications sectors across the Middle East, has attacked two entities in Tunisia with an updated malware arsenal.

    https://www.inforisktoday.co.uk/lyceum-group-targets-two-tunisia-based-entities-a-17774

  • 0 Votes
    1 Posts
    45 Views
    CerberusC

    Big Game Hunting Is Out and ‘Mid Game Hunting’ Is In, Coveware Warns
    When a business, government agency or other organization hit by ransomware opted to pay a ransom to its attacker in Q3, the average payment was $140,000, reports ransomware incident response firm Coveware. It says the attack landscape has seen some notable shifts since the Colonial Pipeline attack.

    https://www.inforisktoday.co.uk/ransomware-average-ransom-payment-stays-steady-at-140000-a-17773

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    Multiple Breach Reports for Phishing Incident Reflect Notification Complexities
    The Professional Dental Alliance is notifying more than 170,000 individuals in about a dozen states of a phishing breach involving an affiliated vendor that provides nonclinical management services to dental practices owned by PDA. Why is breach notification so complicated?

    https://www.inforisktoday.co.uk/dental-alliance-reports-vendor-breach-affecting-170k-a-17775

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    (ISC)2 Report: Fixing Underrepresentation of People of Color and Women in Cyber
    In a report published earlier this week, (ISC)² - the international non-profit association that certifies cybersecurity professionals - says minority security practitioners, including people of color and women, are underrepresented in the field and offers practical steps to address the issues.

    https://www.inforisktoday.co.uk/diversity-equity-inclusion-challenges-in-cybersecurity-a-17771

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Bulletproof Hosting Service Supported Zeus, SpyEye and Citadel Malware, Says FBI
    Four extradited Eastern European men have pleaded guilty in U.S. court to one count of conspiring to serve as administrators of a bulletproof hosting service that facilitated online attacks using the Zeus, SpyEye and Citadel Trojans and the Blackhole exploit kit, says the U.S. Department of Justice.

    https://www.inforisktoday.co.uk/4-bulletproof-hosting-provider-admins-getting-sentenced-a-17772

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Threat Actors Use Scanning Tools for Malicious Activities
    Researchers at Uptycs Threat Research have uncovered a campaign in which the cloud-focused cryptojacking group TeamTNT is deploying malicious container images hosted on Docker Hub with an embedded script to download testing tools used for banner grabbing and port scanning.

    https://www.inforisktoday.co.uk/teamtnt-deploys-malicious-docker-image-on-docker-hub-a-17766

  • 0 Votes
    1 Posts
    44 Views
    CerberusC

    @AnibalLeaks Says Entire Database for Sale on Hacking Forum
    A cybercriminal known as cfk on popular hacking forums and @AnibalLeaks on Twitter claims to have stolen a database consisting of 45 million records of Argentina’s National Registry of Persons, or ReNaPer. The government denies that there has been unauthorized entry into its systems.

    https://www.inforisktoday.co.uk/hacker-claims-details-45-million-argentinians-stolen-a-17769

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Federal Judge Imposes 7-Year Prison Time in Human Resources Database Hack Case
    A federal judge has imposed the maximum sentences - a total of seven years in prison - on a hacker who earlier pleaded guilty in a conspiracy case involving the hacking of University of Pittsburgh Medical Center human resources databases and the theft of personal information of 65,000 employees - some which was sold on the dark web and used for federal tax fraud.

    https://www.inforisktoday.co.uk/hacker-in-upmc-data-theft-fraud-case-gets-maximum-sentences-a-17770

  • 0 Votes
    1 Posts
    49 Views
    CerberusC

    Executive Director Wales Cites Colonial Pipeline’s Rapid Notification to Customers
    A top leader of the U.S. Cybersecurity and Infrastructure Security Agency has voiced support for a 24-hour timeline for cyber incident reporting involving critical infrastructure, signaling a push by the Biden administration to implement a rapid mechanism for federal response.

    https://www.inforisktoday.co.uk/cisa-leader-backs-24-hour-timeline-for-incident-reporting-a-17767

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Attorney General Tells 3 Others to Provide Information in Latest Enforcement Effort
    New York State AG Letitia James served cease and desist letters to two cryptocurrency lending platforms that her office says engage in “unregistered and unlawful activities.” Three other platforms were told by the OAG to “immediately provide information about their activities and products.”

    https://www.inforisktoday.co.uk/new-york-tells-2-cryptocurrency-firms-to-cease-desist-a-17764

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    System Infection Can be Prevented Using Flaws in Malware
    Researchers at Zscaler say that malware is often prone to bugs and coding errors which can cause it to crash or serve as a backdoor for defenders to undo the damage it might have caused. They suggest defenders proactively use malware bugs to stop them from spreading and infecting the system.

    https://www.inforisktoday.co.uk/bugs-in-malware-serve-as-backdoor-to-undo-damage-a-17763

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    Trend Micro: Operators Rebrand “Supplier” Ransomware Before Deployment
    Researchers at cybersecurity firm Trend Micro have observed the adoption of a new franchise-based business model by ransomware operators that moves away from the traditional ransomware-as-a-service model. Operators now rebrand a “supplier” ransomware before deployment.

    https://www.inforisktoday.co.uk/new-business-model-white-labeling-ransomware-a-17761

  • 0 Votes
    1 Posts
    59 Views
    CerberusC

    Tells 3 Others to Provide Information in Latest Crypto Enforcement Effort
    New York State AG Letitia James served cease and desist letters to two cryptocurrency lending platforms that her office says engage in “unregistered and unlawful activities.” Three other platforms were told by the OAG to “immediately provide information about their activities and products.”

    https://www.inforisktoday.co.uk/nyag-issues-cease-desist-letters-to-2-crypto-platforms-a-17764

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    Officials: Threats to Sector Rising In Wake of Recent Hospital Ransomware Attack
    Israeli officials say they have fended off a wave of attempted cyberattacks on several hospitals and healthcare entities in recent days, as Hillel Yaffe Medical Center continues to recover from a ransomware attack last week that authorities reportedly suspect was carried out by Chinese hackers.

    https://www.inforisktoday.co.uk/more-attempted-cyberattacks-on-israeli-healthcare-entities-a-17762

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Lisa Plaggemier of NCSA and Oz Alashe of CybSafe on influencing behavior
    To mark Cybersecurity Awareness Month, the National Cyber Security Alliance and U.K. based behavioral science and data analytics company, CybSafe, have released their Annual Cybersecurity Attitudes and Behaviors Report 2021, which uncovers key trends, behaviors and habits among tech users.

    https://www.inforisktoday.co.uk/positive-security-inspiring-behavioral-change-at-workplace-a-17759

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    Matthew Trump of The University of London on Building Effective Response Plans
    A spate of ransomware incidents affecting the education sector has led to the loss of student coursework, financial records and data relating to COVID-19 testing. Matthew Trump, senior IT security officer for the University of London, U.K., outlines incident response strategies.

    https://www.inforisktoday.co.uk/preparing-for-ransomware-attacks-in-education-sector-a-17760

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    HHS Says Several Factors Making Healthcare a Favorite Target in U.S., Globally
    Ransomware attacks are continuing to threaten the U.S. and global healthcare sectors, in part due to many organizations’ high dependency on legacy systems and lack of security resources, says new analysis by federal officials, which also identified the top ransomware gangs hitting the sector.

    https://www.inforisktoday.co.uk/analysis-top-ransomware-gangs-targeting-healthcare-sector-a-17755

  • 0 Votes
    1 Posts
    40 Views
    CerberusC

    Google TAG: Threat Group DPRK Targeted Security Researchers
    Social media platform Twitter has suspended two accounts that were being used by members of the DPRK, a North Korean government-backed threat group, according to Adam Weidemann, an analyst with the Google Threat Analysis Group. The accounts allegedly targeted security researchers around the globe.

    https://www.inforisktoday.co.uk/twitter-suspends-north-korean-threat-actor-accounts-a-17750

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    PC and Device Maker Appears to Have Been Targeted by DESORDEN
    After being targeted by a ransomware attack in March 2021, Acer, one of the world’s largest PC and device makers, has now suffered two further cyberattacks within a week. DESORDEN threat actors are reported to have claimed responsibility for the attacks.

    https://www.inforisktoday.co.uk/acer-taiwan-india-hit-in-2nd-3rd-attacks-2021-a-17754

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    Media Giant Reports Broadcast Outages Nationwide; Investigation is Ongoing
    Sinclair Broadcast Group, Inc., which owns or operates 186 television stations across 87 U.S. markets, has been hit with a ransomware attack that has disrupted operations. The company says the attack has impacted its ability to deliver advertisements and certain programming.

    https://www.inforisktoday.co.uk/sinclair-tv-stations-targeted-in-weekend-ransomware-attack-a-17753

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    Consultancy Discloses Data Leak Tied to Attack For Which LockBit 2.0 Claimed Credit
    Accenture says an online attack against it that it first disclosed in August resulted in “the extraction of proprietary information by a third party, some of which was made available to the public by the third party.” The LockBit 2.0 ransomware operation has taken credit for the attack and dumping data.

    https://www.inforisktoday.co.uk/accenture-ransomware-attack-breached-proprietary-data-a-17751

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    Exposed OAuth Tokens Have Since Been Revoked, Mitigating Takeover Threat
    A data breach affecting MakerBot’s Thingiverse 3D printing repository website is far bigger than what the company has acknowledged, a former employee claims. Upwards of 2 million users may have been affected by the breach, which left their 3D printers at risk of being hijacked.

    https://www.inforisktoday.co.uk/thingiverse-breach-50000-3d-printers-faced-hijacking-risk-a-17749

  • 0 Votes
    1 Posts
    45 Views
    CerberusC

    OAuth Tokens Exposed But Now Have Been Revoked
    A former employee of MakerBot says a data breach affecting that company’s Thingiverse 3D printing repository website is far more expansive than what the company is acknowledging. Upwards of two million users may be affected, and 3D printers could have been hijacked.

    https://www.inforisktoday.co.uk/thingiverse-breach-50000-3d-printers-could-have-been-hijacked-a-17749

  • 0 Votes
    1 Posts
    51 Views
    CerberusC

    OAuth Tokens Exposed But Now Have Been Revoked
    A former employee of MakerBot says a data breach affecting that company’s Thingiverse 3D printing repository website is far more expansive than what the company is acknowledging. Upwards of two million users may be affected, and 3D printers could have been hijacked.

    https://www.inforisktoday.co.uk/thingiverse-breach-50000-printers-could-have-been-hijacked-a-17749

  • 0 Votes
    1 Posts
    33 Views
    CerberusC

    New Crypto-Based Guidelines Target Anonymous Money Laundering Activity
    The U.S. Department of the Treasury unveiled additional steps to curb the illicit use of cryptocurrencies on Friday, warning enterprises not to engage with sanctioned entities exploiting the financial system - particularly to launder ransomware proceeds.

    https://www.inforisktoday.co.uk/treasury-dept-to-crypto-companies-comply-sanctions-a-17744

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    TA505 APT Group delivers phishing email containing malicious links
    Researchers at Morphisec Labs have published fresh details about a new MirrorBlast campaign that they say is run by a Russia-based threat group TA505, targeting financial services organizations. The campaign delivers MirrorBlast via a phishing email that contains malicious links.

    https://www.inforisktoday.co.uk/mirrorblast-campaign-targets-finance-sector-using-macros-a-17745

  • 0 Votes
    1 Posts
    33 Views
    CerberusC

    FBI, CISA, EPA & NSA Advisory Says Threats to Critical Infrastructure Rising
    U.S. federal agencies issued a joint advisory around potential cyber threats to the nation’s water facilities. They cite “ongoing malicious cyber activity - by both known and unknown actors - targeting the IT and OT technology networks, systems and devices” of U.S. water and wastewater systems.

    https://www.inforisktoday.co.uk/us-agencies-to-water-facilities-you-may-be-next-target-a-17741

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    Government Authorities Issue Advisories Following Hospital Attack
    Government authorities in Israel are warning healthcare sector entities in the country of potential cyberattacks after a ransomware attack this week on Hillel Yaffe Medical Center in the city of Hadera. The hospital said it is “using alternative systems” to care for its patients.

    https://www.inforisktoday.co.uk/ransomware-attack-on-israeli-medical-center-raises-alarm-a-17740

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Discussion Also Addresses the Ransom-Paying Dilemma Faced by Cyber Extortion Victims
    In this update, four editors discuss key cybersecurity issues, including addressing the complexity of security, the rising number of victims targeted by double extortion ransomware and the Information Commissioner’s Office’s recent consultation on creating an international data transfer agreement.

    https://www.inforisktoday.co.uk/ismg-editors-panel-are-our-systems-too-complex-to-secure-a-17739

  • 0 Votes
    1 Posts
    49 Views
    CerberusC

    Gov. Michael L. Parson Alleges Newspaper Reporter Improperly Accessed Data
    A newspaper reporter in Missouri who responsibly reported the exposure of Social Security numbers on a state government website has been accused of malicious hacking by the state’s governor. The governor alleged the publication of the vulnerability after it was fixed was part of a “political vendetta.”

    https://www.inforisktoday.co.uk/missouri-refers-coordinated-bug-disclosure-to-prosecutors-a-17737

  • 0 Votes
    1 Posts
    44 Views
    CerberusC

    But Name-and-Shame Attackers Likely Retooling After Spotting Encryption Problems
    A free decryptor for BlackByte ransomware has been released by security researchers at Trustwave who cracked the crypto-locking malware’s encryption. But they say that unfortunately, the underlying encryption problem is likely in the process of already being fixed by the malware’s developer.

    https://www.inforisktoday.co.uk/blackbyte-free-decryptor-released-for-ransomware-strain-a-17738

  • 0 Votes
    1 Posts
    49 Views
    CerberusC

    Gov. Michael L. Parson Alleges Newspaper Reporter Improperly Accessed Data
    A newspaper reporter in Missouri who responsibly reported the exposure of Social Security numbers on a state government website has been accused of malicious hacking by the state’s governor. The governor alleged the publication of the vulnerability after it was fixed was part of a “political vendetta.”

    https://www.inforisktoday.co.uk/missouri-refers-responsibly-reported-bug-to-prosecutors-a-17737

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    Gov. Michael L. Parson Alleges Newspaper Employee Improperly Accessed Data
    A newspaper employee in Missouri who responsibly reported the exposure of Social Security numbers on a state government website has been accused of malicious hacking by the state’s governor. The governor alleged the publication of the vulnerability after it was fixed was part of a “political vendetta.”

    https://www.inforisktoday.co.uk/missouri-refers-responsible-bug-report-to-prosecutors-a-17737

  • 0 Votes
    1 Posts
    44 Views
    CerberusC

    Bill Would Remove Some Third-Party Content ‘Immunity’ Held by Social Platforms
    Democratic lawmakers on the House Committee on Energy and Commerce announced legislation that would rein in tech algorithms on platforms exceeding 5 million monthly viewers. This follows a high-profile whistleblower case heard before Congress on Facebook’s allegedly questionable data policies.

    https://www.inforisktoday.co.uk/house-lawmakers-announce-bill-targeting-tech-algorithms-a-17736

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    Focus is on Critical Infrastructure Threats and Clinical Data
    MITRE, the not-for-profit organization that works across governmental and federal agencies, as well as various industrial verticals and academia, has set up The Cyber Infrastructure Protection Innovation Center and The Clinical Insights Innovation Cell to protect healthcare.

    https://www.inforisktoday.co.uk/mitre-launches-centers-to-protect-infrastructure-health-a-17734

  • 0 Votes
    1 Posts
    49 Views
    CerberusC

    Attackers Can Push Code To A Protected Branch
    Researchers at Cider Security have uncovered a security loophole in GitHub Actions that allows adversaries to bypass the required reviews mechanism and push unreviewed code to a protected branch, allowing it into the pipeline to production.

    https://www.inforisktoday.co.uk/flaws-in-github-actions-bypass-code-review-mechanism-a-17733

  • 0 Votes
    1 Posts
    59 Views
    CerberusC

    PII of Nearly 28,000 Members Exfiltrated in June 2020 Hacking Incident
    The American Osteopathic Association has just begun notifying nearly 28,000 individuals about a June 2020 data exfiltration incident involving their personal information. The medical professional organization says workforce challenges during the pandemic led to the notification delay.

    https://www.inforisktoday.co.uk/osteopathic-professional-group-reports-year-old-breach-a-17735

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    The Data Dump Is Being Broadly Circulated on a Popular Hacking Forum
    Thingiverse, a popular website dedicated to sharing user-created digital design files, has reportedly leaked a 36GB backup file that contains 2.5 million unique email addresses and other personally identifiable information.

    https://www.inforisktoday.co.uk/thingiverse-data-leak-affects-228000-subscribers-a-17729

  • 0 Votes
    1 Posts
    57 Views
    CerberusC

    The Data Dump Is Being Broadly Circulated on a Popular Hacking Forum
    Thingiverse, a popular website dedicated to sharing user-created digital design files, has reportedly leaked a 36GB backup file that contains 2.5 million unique email addresses and other personally identifiable information.

    https://www.inforisktoday.co.uk/thingiverse-data-leak-affects-25-million-subscribers-a-17729

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    New Criminal Penalties, Assistance to Victims in the Ransomware Action Plan
    Australia plans to require businesses with more than $10 million in revenue to report ransomware attacks to the government, part of a comprehensive strategy to fight the attacks that also includes new criminal penalties and assistance to victims. The plan would need to be passed by Parliament.

    https://www.inforisktoday.co.uk/australia-plans-ransomware-attack-reporting-requirement-a-17731

  • 0 Votes
    1 Posts
    59 Views
    CerberusC

    China, Russia Both Absent from 30-Nation Gathering on the Threat of Ransomware
    The White House National Security Council this week kicked off its international counter-ransomware event with participation from more than 30 nations. This gathering aims to elevate both law enforcement collaboration and diplomatic efforts. Noticeably absent from the summit: Russia.

    https://www.inforisktoday.co.uk/us-convenes-global-ransomware-summit-without-russia-a-17730

  • 0 Votes
    1 Posts
    51 Views
    CerberusC

    Also, NJ AG Smacks Fertility Clinic With Big Fine in Hacking Incident
    A flurry of hacking incidents and other recent breach developments highlight the cyberthreats and risks facing fertility healthcare and other related specialty providers that handle sensitive patient information.

    https://www.inforisktoday.co.uk/fertility-testing-lab-says-ransomware-breach-affects-350000-a-17728

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    How Many Strikes Should Cybercrime-as-a-Service Customers Get Before Getting Busted?
    Dutch cybercrime police have a message for almost 30 users of an on-demand distributed-denial-of-service site: We see what you’re doing, now cut it out or we’re going to arrest you. Not for the first time, the move shows police in Europe also emphasizing ethical hacking pursuits instead for young adults.

    https://www.inforisktoday.co.uk/dutch-cyber-cops-tell-stresserbooter-customers-cut-out-a-17727

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    2.4 Tbps Attack Was 140% Higher Than All Recorded Attacks
    Microsoft disclosed that it mitigated a 2.4 Tbps DDoS attack, which was 140% higher in scale than any previously recorded network volumetric event on Azure. The firm and some security experts say that attacks of this magnitude could wreak havoc on targeted companies and are difficult to mitigate.

    https://www.inforisktoday.co.uk/microsoft-says-mitigated-largest-ever-ddos-attack-a-17725

  • 0 Votes
    1 Posts
    57 Views
    CerberusC

    1 Alleged Co-Conspirator Was Employed by Bank of America, TD Bank
    The U.S. Attorney’s Office for the Eastern District of Virginia last week indicted three men - including an ex-employee of Bank of America and TD Bank - with money laundering and aggravated identity theft after the men allegedly conducted an extensive business email compromise scheme.

    https://www.inforisktoday.co.uk/3-men-charged-by-us-doj-laundering-bec-proceeds-a-17726

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    OMB Memo: Agencies Have 90 Days to Allow CISA to Begin Reviewing EDR Status
    In an effort to bolster endpoint protection within the U.S. government, the White House is ordering federal agencies to allow CISA to access existing deployments. It is also setting timelines for improving the protection of workstations, mobile phones and servers.

    https://www.inforisktoday.co.uk/cisa-to-access-agencies-endpoints-help-enhance-security-a-17723

  • 0 Votes
    1 Posts
    50 Views
    CerberusC

    Accountable Care Organization Says It’s Investigating 2020 Incident
    A compromise of sensitive health information affecting nearly 38,000 individuals discovered nearly a year after a terminated company executive accessed the data spotlights some of the top security and privacy challenges covered entities and business associates face with insiders.

    https://www.inforisktoday.co.uk/former-executive-accessed-phi-nearly-38000-individuals-a-17724

  • 0 Votes
    1 Posts
    66 Views
    CerberusC

    Also, Bitdefender Report Reinforces Need for Cyber Hygiene When Using BYOD
    The UK’s NCSC has published an updated guidance for employees using their personal devices for work. The agency offers technical controls for different types of bring-your-own-device, or BYOD, deployments. And a Bitdefender report stresses the need for good cyber hygiene when using BYOD.

    https://www.inforisktoday.co.uk/uk-cybersecurity-agency-releases-new-byod-guidance-a-17722

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    Count of Victims - Listed on Leak Sites or Not - Appears To Be Holding Steady
    One measure of the damage being done by ransomware groups continues to be how many victims get listed on ransomware operators’ dedicated data-leak sites, as part of their so-called double extortion tactics. Unfortunately, the number of victims doesn’t appear to be declining.

    https://www.inforisktoday.co.uk/ransomware-no-decline-in-victims-posted-to-data-leak-sites-a-17719

  • 0 Votes
    1 Posts
    54 Views
    CerberusC

    Letter to 4 Departments Asserts that Cryptocurrency Is Enabling These Attacks
    A congressional letter sent to the heads of four federal agencies expressed an urgent need for the Biden administration to continue combating ransomware. This includes a particular focus on the cryptocurrency infrastructure that is enabling these cyberattacks, four Democratic lawmakers say.

    https://www.inforisktoday.co.uk/democratic-lawmakers-urge-agencies-to-act-on-ransomware-a-17716

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    Mandiant Report Says Threat Actors Deploy Ryuk, Leverage Initial Access Brokers
    A Russian-speaking threat actor group that deploys the Ryuk variant ransomware, leverages initial access brokers, and generally skips double-extortion attempts in favor of fast and higher payout ransoms has been predominately targeting the healthcare sector, warns security firm Mandiant.

    https://www.inforisktoday.co.uk/fin12-ransomware-attacks-aggressively-targeting-healthcare-a-17717

  • 0 Votes
    1 Posts
    51 Views
    CerberusC

    Code Deployed Prevents Detection and Kills Competition
    Researchers at Trend Micro have discovered threat actors deploying malicious code that targets Huawei Cloud and removes defensive applications and services. The malicious codes, they say, disable the hostguard service that detects security issues, protects the system and monitors the agent.

    https://www.inforisktoday.co.uk/trend-micro-linux-malware-targets-huawei-cloud-a-17714

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    Profit Projections Down £25 Million, Revenue Deferrals Put At £50 Million
    A ransomware attack on Scottish multinational engineering firm Weir Group led to several ongoing but temporary disruptions including engineering, manufacturing and shipment rephrasing, hitting profits despite no ransom being paid.

    https://www.inforisktoday.co.uk/ransomware-attack-hits-engineering-giant-weir-group-a-17710

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    Company Outlines Added Security for High-Profile Users, Announces 2FA Enrollment
    Some 14,000 Google users were warned of being suspected targets of Russian government-backed threat actors on Thursday. The next day, the tech giant announced cybersecurity updates - particularly for email accounts of high-profile users, including politicians and journalists.

    https://www.inforisktoday.co.uk/google-says-russian-apt-targeting-journalists-politicians-a-17708

  • Nobelium Makes Russia Leader in Cyberattacks

    1
    0 Votes
    1 Posts
    48 Views
    CerberusC

    Microsoft: 58% of Attacks Reported Worldwide Originated From Russia
    Microsoft, in its annual threat review report, Digital Defense, says 58% of cyberattacks worldwide over the past year originated in Russia. And 92% of the Russia-based threat activity came from the nation-state threat group Nobelium.

    https://www.inforisktoday.co.uk/nobelium-makes-russia-leader-in-cyberattacks-a-17705

  • 0 Votes
    1 Posts
    51 Views
    CerberusC

    Officials and Experts Debate Legality, Diplomatic Ramifications of the Statement
    The Dutch government says it may use intelligence agencies or military services to counter cyberattacks - including ransomware attacks - that threaten the country’s national security. This comes in a letter from Dutch Minister of Foreign Affairs Ben Knapen in response to a parliamentary inquiry.

    https://www.inforisktoday.co.uk/netherlands-says-armed-forces-may-combat-ransomware-attacks-a-17703

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Erik Decker, CISO of Intermountain Health, on Ways to Bolster Security Posture
    A federal law signed earlier this year amending the HITECH Act could help incentivize many healthcare sector entities to bolster their cybersecurity programs, says federal adviser Erik Decker, CISO of Intermountain Health, who suggest other incentives, as well.

    https://www.inforisktoday.co.uk/efforts-to-incentivize-healthcare-sector-cyber-investments-a-17704

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    US Breach Notification Transparency Declining, Identity Theft Resource Center Warns
    The number of breach reports filed by U.S. organizations looks set to break records, as breaches tied to phishing, ransomware and supply chain attacks keep surging, the Identity Theft Resource Center warns. It says that there’s also been a rise in tardy breach notifications containing little detail.

    https://www.inforisktoday.co.uk/data-breach-reports-rise-as-supply-chain-attacks-surge-a-17701

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Discussion Also Addresses the Importance of Product Security
    In the latest weekly update, four editors at Information Security Media Group discuss important cybersecurity issues, including the importance of product security, the impact of ransomware on healthcare sector entities during the pandemic and thinking about cybersecurity awareness creatively.

    https://www.inforisktoday.co.uk/ismg-editors-panel-first-fatality-linked-to-ransomware-a-17698

  • 0 Votes
    1 Posts
    52 Views
    CerberusC

    Martin Cook, Sr. Solutions Engineer, Reliaquest Discusses How to Streamline Your Time to Response
    In this exclusive interview, Martin Cook, Senior Solutions Engineer with ReliaQuest, discusses how to reduce complexity, increase visibility and tap into new resources to enhance your own abilities to detect, investigate and respond to attacks.

    https://www.inforisktoday.co.uk/analyzing-results-2021-cybersecurity-complexity-study-eu-uk-a-17700

  • 0 Votes
    1 Posts
    45 Views
    CerberusC

    110,000 Servers Exposed to Active Attacks; US Government Urges Immediate Patching
    Apache HTTP Server users are being warned to install yet another patch, as a fix released Wednesday was incomplete and introduced a new flaw. The U.S. Cybersecurity and Infrastructure Security Agency has urged all users to update immediately, citing in-the-wild attacks exploiting Apache’s software.

    https://www.inforisktoday.co.uk/apache-issues-another-emergency-patch-for-exploited-flaws-a-17697

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    Plug and Play Ventures Left an Amazon S3 Bucket Open to the Internet
    A Silicon Valley venture capital firm that runs a matchmaker service linking investors with startups exposed 6GB of data, including deal flow information pertaining to investors and startups. The exposure has been closed, but it’s unclear if the company will notify regulators.

    https://www.inforisktoday.co.uk/silicon-valley-vc-firm-leaked-deal-flow-data-a-17696

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    DOJ Also Announces Formation of National Cryptocurrency Enforcement Team
    The U.S. Department of Justice said this week it will pursue government contractors that fail to report cybersecurity incidents. The department also announced the formation of a Cryptocurrency Enforcement Team to prosecute the misuse of virtual currencies.

    https://www.inforisktoday.co.uk/us-doj-to-fine-contractors-for-failure-to-report-incidents-a-17695

  • 0 Votes
    1 Posts
    45 Views
    CerberusC

    Ransomware Variant Updated; Group Claimed Credit for Accenture Attack
    Federal regulators are warning healthcare and public health sector organizations of potential attacks by the ransomware group LockBit 2.0 and its affiliates. The group claimed credit for the August attack on consultancy firm Accenture. What preventative steps should healthcare sector entities take?

    https://www.inforisktoday.co.uk/hhs-warns-healthcare-sector-about-lockbit-20-threats-a-17694

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    5-Year Intrusion Is the Latest Incident Involving Lesser-Known - Yet Key - Provider
    Who had heard of Syniverse before it recently disclosed a five-year breach, potentially exposing call-routing data and text messages for hundreds of mobile phone networks? The incident is just the latest supply chain attack to hit a lesser-known but nevertheless critical service provider.

    https://www.inforisktoday.co.uk/breach-syniverse-reveals-yet-another-supply-chain-attack-a-17692

  • 0 Votes
    1 Posts
    58 Views
    CerberusC

    Exploits Use Ethernet Cables, Can Leak Data to Location Several Meters Away
    Researchers at Ben-Gurion University of the Negev, Israel, have uncovered a new type of electromagnetic attack, dubbed LANtenna, that exfiltrates sensitive data from an isolated, air-gapped computer using Ethernet cables as transmitting antennas.

    https://www.inforisktoday.co.uk/lantenna-attacks-exploit-air-gapped-networks-via-ethernet-a-17688

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    Legislation Would Also Direct US DHS to Study Ransomware, Cryptocurrencies
    U.S. lawmakers have introduced legislation that would require the reporting of ransom payments within 48 hours of the transaction. The bill would also require DHS to create a voluntary website to log ransom payments and task the department with studying ransomware and cryptocurrencies.

    https://www.inforisktoday.co.uk/new-bill-would-require-ransom-disclosure-within-48-hours-a-17689

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    Recent Cyber-Related Incidents Spotlight the Serious Potential Risks Facing Patients
    The expanded recall of insulin pump devices due to vulnerabilities that pose the risk of injury or death to patients and a recent malpractice lawsuit alleging that the effects of a ransomware attack led to a baby’s death are the latest warnings of dangers posed by security issues in medical gear.

    https://www.inforisktoday.co.uk/patient-safety-concerns-grow-over-medical-gear-security-a-17687

  • 0 Votes
    1 Posts
    32 Views
    CerberusC

    Reports: Platform’s Entire Source Code Compromised in 125GB Leak
    Amazon-owned video streaming service Twitch, which focuses on video games and e-sports broadcasts, reportedly suffered a massive data breach, which the company vaguely confirmed via Twitter. A post on the anonymous online forum 4chan reportedly indicates that the entire platform was compromised.

    https://www.inforisktoday.co.uk/video-game-streamer-twitch-confirms-massive-data-breach-a-17686

  • 0 Votes
    1 Posts
    60 Views
    CerberusC

    Shodan Search Shows 112,000 HTTP Servers Running Vulnerable Version
    Apache, a popular open-source web server software for Unix and Windows, says it has fixed a zero-day vulnerability in its HTTP server that it says has been exploited in the wild. The path traversal and file disclosure vulnerability only affects Apache HTTP servers upgraded to version 2.4.49.

    https://www.inforisktoday.co.uk/apache-fixes-zero-day-flaw-exploited-in-wild-a-17685

  • Understanding the Real Threat of Ransomware

    1
    0 Votes
    1 Posts
    41 Views
    CerberusC

    Cybersecurity Specialist John Walker on How Attackers Work
    Cyber extortion through digital means is nothing new, says U.K.-based cybersecurity expert John Walker, but the concerning aspect of today’s ransomware attacks is that they are “low-cost in the macro sense and so easy to achieve.”

    https://www.inforisktoday.co.uk/understanding-real-threat-ransomware-a-17684

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    Syniverse Routes Over 1 Trillion Messages Annually for AT&T, Verizon, Others
    Telecommunications service provider Syniverse, which routes 1 trillion messages annually for many of the world’s mobile phone carriers, has disclosed a five-year breach of its systems, which handle call metadata and text messages. Experts say the exposed data poses serious criminal and espionage risks.

    https://www.inforisktoday.co.uk/text-messaging-routing-firm-syniverse-reveals-5-year-breach-a-17682

  • Anonymous Leaks Data from Texas GOP

    1
    0 Votes
    1 Posts
    55 Views
    CerberusC

    This Is the 3rd Attack Involving the US Web Hosting Service Epik
    Hacktivist collective Anonymous has for the third time carried out an attack involving Washington-based domain name registrar and web hosting service Epik, according to independent Texas journalist Steven Monacelli. This time around, the group leaked data belonging to the Republican Party of Texas.

    https://www.inforisktoday.co.uk/anonymous-leaks-data-from-texas-gop-a-17679

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    FDA Warns Exploitation of Security Flaw Could Cause Death
    The Food and Drug Administration on Tuesday issued a warning notifying patients that medical device maker Medtronic has expanded a recall of remote controllers for certain wireless insulin pumps that were part of an earlier recall. The FDA has classified the recall as the most serious type due to issues that could result in serious injury or death.

    https://www.inforisktoday.co.uk/medtronic-insulin-pump-devices-recalled-due-to-serious-risks-a-17680

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    Agency Issues Best Practices for Communicating Device Vulnerabilities
    The Food and Drug Administration has issued a new best practices document for healthcare industry stakeholders and government agencies to use when communicating medical device vulnerabilities to patients and caregivers.

    https://www.inforisktoday.co.uk/fda-how-to-inform-patients-about-medical-device-cyber-flaws-a-17677

  • 0 Votes
    1 Posts
    55 Views
    CerberusC

    Head of NSA, Cyber Command Says US Will Continue to Battle Ransomware for Years
    Some of the highest-ranking cybersecurity officials in the U.S. government discussed the pervasive threat of ransomware on Tuesday, likening it to a clear issue of national security with the ability to inflict measurable damage on major world powers.

    https://www.inforisktoday.co.uk/top-us-cyber-officials-say-ransomware-here-to-stay-a-17678

  • 0 Votes
    1 Posts
    40 Views
    CerberusC

    BlackMatter, HelloKitty and REvil Among Groups Targeting VMware’s ESXi Hypervisor
    Hypervisors under fire: BlackMatter, HelloKitty and REvil are among the ransomware groups targeting instances of VMware’s ESXi. In one case investigated by security firm Sophos, after first accessing a TeamViewer account, attackers left an organization’s ESXi environment crypto-locked just three hours later.

    https://www.inforisktoday.co.uk/how-ransomware-attackers-hit-virtual-machine-hypervisors-a-17675

  • 0 Votes
    1 Posts
    85 Views
    CerberusC

    Social Media Giant Confirms Incident via Twitter; Analysis Suggests DNS Issue
    Social media giant Facebook experienced a global outage on Monday that also involved its properties - including Instagram, Messenger and WhatsApp. According to Cisco’s internet analysis division, ThousandEyes, the tech giant experienced a DNS issue that hindered access to Facebook’s tools and apps.

    https://www.inforisktoday.co.uk/facebook-instagram-whatsapp-suffer-widespread-outage-a-17669

  • 0 Votes
    1 Posts
    32 Views
    CerberusC

    DOJ: Thousands of US Service Members, Veterans Targeted
    A former U.S. Army contractor has been sentenced to 12 years and seven months in prison and ordered to pay $2,331,639.85 in restitution, for conspiring to commit wire fraud and launder money, targeting thousands of military-affiliated individuals, according to a Department of Justice statement.

    https://www.inforisktoday.co.uk/ex-army-contractor-sentenced-to-12-years-for-fraud-a-17670

  • 0 Votes
    1 Posts
    49 Views
    CerberusC

    Some Patients’ Care Previously Postponed Due to COVID-19; What Happens Now?
    Two Indiana hospitals say their IT systems are disabled as they recover from cyberattacks suffered last week. Both hospitals in recent weeks have had to divert patients or postpone elective procedures as COVID-19 cases surged in the state. So what’s the impact of the attacks on patient care?

    https://www.inforisktoday.co.uk/cyberattacks-disable-networks-at-2-indiana-hospitals-a-17671

  • 0 Votes
    1 Posts
    32 Views
    CerberusC

    DSCI: Ransomware Alkhal Likely Spread Via Phishing, Malicious URLs
    The Data Security Council of India has issued an advisory about newly discovered ransomware Alkhal, which uses a strong encryption tool and has no known decryptor to recover lost data. The ransomware was likely discovered on Oct. 1 by security firms Malwarebytes and Cyclonis.

    https://www.inforisktoday.co.uk/new-file-locking-malware-no-known-decryptor-found-a-17673

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    $150 Million in Worldwide Losses Tied to Unnamed Ransomware Operation and Suspects
    Police in Ukraine have arrested two members of a ransomware operation they say has targeted businesses in North American and Europe, leading to victim losses totaling at least $150 million. The operation also involved French cyber police, the FBI and Interpol, backed by Europol’s European Cybercrime Centre.

    https://www.inforisktoday.co.uk/ukraine-busts-2-suspects-tied-to-major-ransomware-group-a-17667

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    Sarwent Malware Can Execute Remote Tasks
    Fraudsters are impersonating Amnesty International by building a fake site to distribute malware purporting to be an anti-virus tool to protect against the NSO Group’s Pegasus tool, according to researchers at Cisco Talos.

    https://www.inforisktoday.co.uk/hackers-impersonate-amnesty-international-to-spread-malware-a-17666

  • President Biden Touts Cybersecurity Efforts

    1
    0 Votes
    1 Posts
    57 Views
    CerberusC

    Cites Need to Secure Privately Owned Critical Infrastructure, Signs Proclamation
    As Cybersecurity Awareness Month kicks off this week, U.S. President Joe Biden has weighed in on his administration’s efforts to curb cyberattacks and bolster the federal government’s security posture.

    https://www.inforisktoday.co.uk/president-biden-touts-cybersecurity-efforts-a-17665

  • 0 Votes
    1 Posts
    91 Views
    CerberusC

    Suit Alleges Inability to Access Critical Fetal Monitoring Data Was Malpractice
    The death of a baby born with complications during a 2019 ransomware attack on an Alabama hospital – one that left clinicians unable to access electronic health records and patient monitoring systems - is intensifying the spotlight on the potentially fatal consequences of such cyber incidents.

    https://www.inforisktoday.co.uk/lawsuit-hospitals-ransomware-attack-led-to-babys-death-a-17663

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    ‘Technology Modernization Fund’ Announces 7 Projects at 4 US Agencies
    Four federal agencies have been awarded $311 million to bolster the U.S. government’s cyber defenses and address IT modernization challenges, according to the interagency board of the Technology Modernization Fund, a federal funding source, which made the announcement Thursday.

    https://www.inforisktoday.co.uk/us-agencies-awarded-311-million-in-cybersecurity-funds-a-17664

  • 0 Votes
    1 Posts
    56 Views
    CerberusC

    Discussion Also Addresses Fraudsters’ Evolving Tactics
    In the latest weekly update, four editors at Information Security Media Group discuss important cybersecurity issues, including why enterprises need a multilayered approach to securing identity, how fraud will evolve in 2022 and the need to secure backdoors to prevent ransomware attacks.

    https://www.inforisktoday.co.uk/ismg-editors-panel-protecting-active-directory-from-ransomware-attacks-a-17660

  • 0 Votes
    1 Posts
    54 Views
    CerberusC

    Exposed Data Includes Login Credentials, Security Questions
    Neiman Marcus Group says it is notifying 4.6 million of its online customers who are affected by a data breach that occurred in May 2020. The data includes personally identifiable data, payment and gift cards, online account credentials and security questions.

    https://www.inforisktoday.co.uk/neiman-marcus-says-46m-affected-by-data-breach-a-17658

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    State’s Renewal of Relaxed Regs Mirrors Handling of Federal HIPAA Waivers
    California is extending a waiver that was set to expire this week. Similar to action taken by federal regulators, the extended California waiver relaxes enforcement of certain privacy and security regulations related to healthcare providers that offer telehealth services.

    https://www.inforisktoday.co.uk/california-extends-telehealth-privacy-security-waivers-a-17656

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    Agency Is Also Keeping Its ‘Rumor Control’ Website Active Ahead of Midterm Elections
    A new self-assessment tool aims to help public and private sector organizations assess their level of vulnerability to insider threats, according to CISA. The agency also indicated this week it will keep its “rumor control” website active ahead of the 2022 midterm elections.

    https://www.inforisktoday.co.uk/cisa-launches-insider-threat-self-assessment-tool-a-17657

  • Anonymous Leaks Epik Data - Again

    1
    0 Votes
    1 Posts
    33 Views
    CerberusC

    Part 2 of ‘Operation Epik Fail’ Leaks 300GB of Data, Researcher Says
    Hacktivist collective Anonymous has, for the second time this month, leaked data belonging to Washington-based domain name registrar and web hosting service Epik. The size of the second set: more than 300GB - double the amount in the first leak.

    https://www.inforisktoday.co.uk/anonymous-leaks-epik-data-again-a-17655

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    Bipartisan Bill Would Require 24-Hour Ransom Notice, 72-Hour Incident Report
    A bipartisan effort to implement cybersecurity incident reporting and the tracking of ransomware payments has been introduced by leaders of the Senate Homeland Security and Governmental Affairs Committee. While it differs from legislation introduced in July, lawmakers hope to reconcile the bills.

    https://www.inforisktoday.co.uk/new-legislation-eyes-both-ransom-incident-reporting-a-17650

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Neither Firm Has Fixed Issue, Researchers Say
    Researchers at the University of Birmingham and University of Surrey say they have uncovered a vulnerability in the Apple Pay-Visa setup that could allow hackers to bypass iPhone’s Apple Pay lock screen, perform contactless payments and skirt transaction limits.

    https://www.inforisktoday.co.uk/apple-pay-visa-vulnerability-may-enable-payment-fraud-a-17648

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    Microsoft Sparred with SecureWorks Over Impact But Relents
    Microsoft has indicated it will make changes to reduce the risk around what a security vendor says is a vulnerability that lets attackers run brute-force credential attacks against Azure Active Directory. The issue was reported to Microsoft in June by SecureWorks’ Counter Threat Unit.

    https://www.inforisktoday.co.uk/microsoft-will-mitigate-brute-force-bug-in-azure-ad-a-17646

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    CISA Warns of ‘Widespread Exploitation’ for 1 Critical Bug
    Cybersecurity vendor VMware has published a security advisory detailing 19 vulnerabilities affecting its vCenter server and Cloud Foundation products and has released fixes for all of them. One of the flaws has a high CVSS of 9.8, and CISA is warning of its “widespread exploitation.”

    https://www.inforisktoday.co.uk/vmware-discloses-releases-fixes-for-19-bugs-in-products-a-17645

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    PII, PHI for 35,000 Individuals Potentially Stolen in Incident
    A Philadelphia-based mental health services provider has begun to notify tens of thousands of individuals that their health and personal information was potentially viewed or stolen by hackers in a data security incident discovered more than six months ago.

    https://www.inforisktoday.co.uk/mental-health-clinic-notifies-patients-6-months-after-hack-a-17642

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    Group-IB’s Ilya Sachkov Arrested on Treason Charges; Cybersecurity Leaders Speak Out
    The founder of Group-IB, one of Russia’s largest cybersecurity companies, has been detained on state treason charges and will be held in custody for two months, with alleged crimes punishable by up to 20 years in prison, according to wire reports.

    https://www.inforisktoday.co.uk/top-russian-cybersecurity-ceo-charged-treason-a-17644

  • NSA, CISA Release VPN Security Guidance

    1
    0 Votes
    1 Posts
    55 Views
    CerberusC

    Agencies Offer Advice on Minimizing Attack Surface
    In a bid to address security risks associated with the use of virtual private network solutions, the National Security Agency and the Cybersecurity and Infrastructure Security Agency on Tuesday offered government leaders guidance on selecting remote access VPNs and strengthening their security.

    https://www.inforisktoday.co.uk/nsa-cisa-release-vpn-security-guidance-a-17640

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Hearing: Researchers Liken Major Platforms to a ‘Disinformation Black Box’
    Cybersecurity and computer science experts testifying before Congress on Tuesday expressed concerns about their inability to access key social media data sets that could allow them to analyze and potentially counter the spread of misinformation.

    https://www.inforisktoday.co.uk/experts-slam-social-media-platforms-data-policies-a-17635

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    Senators Introduce Bill to Task Treasury Department with Mining Assessment
    A bipartisan bill has been introduced in the U.S. Senate which, if passed, would find the Treasury Department actively monitoring cryptocurrency mining abroad, as well as its ultimate impact on U.S. supply chains for critical resources, including semiconductors.

    https://www.inforisktoday.co.uk/bipartisan-us-senate-bill-eyes-cryptomining-oversight-a-17636

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    ShapeShift’s Systems Reduced Privacy for Monero, Researcher Says
    Weaknesses in the systems of ShapeShift, a U.K.-based cryptocurrency exchange, reveal how a North Korean-linked group laundered cryptocurrency that came from the WannaCry 2.0 attack four years ago. The issues undermined some protections in Monero, a cryptocurrency designed to provide a high degree of privacy.

    https://www.inforisktoday.co.uk/crypto-exchange-bug-reveals-north-korean-monero-laundering-a-17629

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    Microsoft: Malware Creates Backdoor to Exfiltrate Sensitive ADFS Server Data
    The Russia-linked cyberespionage group Nobelium, which was responsible for the SolarWinds supply chain attack, has developed and deployed a new malware, dubbed FoggyWeb, according to a Microsoft Threat Intelligence Center security blog. Microsoft says FoggyWeb creates a backdoor to exfiltrate data.

    https://www.inforisktoday.co.uk/russia-linked-nobelium-deploying-new-foggyweb-malware-a-17632

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    Analysis of Latest Major Health Data Breaches Posted to HHS OCR Website
    Hacking incidents - especially those involving ransomware attacks and vendors - continue to rack up some of the largest victim counts in major health data breaches being reported to federal regulators in 2021. Will the trend continue?

    https://www.inforisktoday.co.uk/ransomware-vendor-breaches-spike-on-federal-tally-a-17634

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    Researchers Say Trojan Steals Data from Steam, Epic Games Stores, EA Origin
    Researchers at cybersecurity firm Kaspersky have discovered an advanced Trojan, dubbed BloodyStealer, stealing gamer accounts and data from platforms such as Steam, Epic Games Stores and EA Origin. They say there is a demand for this type of data among cybercriminals.

    https://www.inforisktoday.co.uk/new-malware-bloodystealer-targets-gaming-accounts-a-17631

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Video Security Tech Firm Releases Firmware Update to Fix Vulnerability
    A security researcher who goes by the alias Watchful_IP has discovered a command injection vulnerability that could potentially affect millions of Hikvision’s IoT devices. The video security solutions provider says it has fixed the flaw and rolled out a firmware update for its end users.

    https://www.inforisktoday.co.uk/critical-flaw-may-affect-millions-hikvision-devices-a-17625

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    Trump-Era Mandate Calls for Verifying IDs of Foreign IaaS Account Holders
    The U.S. Department of Commerce is soliciting input on a Trump administration cybersecurity executive order that requires cloud providers to verify the identities of certain users - particularly cyber actors potentially operating abroad and leveraging U.S. cloud technologies.

    https://www.inforisktoday.co.uk/us-commerce-officials-seek-comment-on-iaas-executive-order-a-17626

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    Lisa J. Pino Served at DHS During OPM’s Mega-Breach Mitigation
    The Department of Health and Human Services has named Lisa J. Pino - a former Department of Homeland Security official charged with mitigating the massive 2015 cyberattack on Office of Personnel Management - as the new director of its HIPAA enforcement agency.

    https://www.inforisktoday.co.uk/former-dhs-official-to-lead-hhs-hipaa-enforcement-agency-a-17627

  • 0 Votes
    1 Posts
    40 Views
    CerberusC

    Canal de Isabel II Suspends Its Telephone Services
    GSS, the Spanish and Latin America division of Europe’s largest call center provider Covisian, has informed that it has been subjected to a ransomware attack, which froze its IT systems and crippled call centers across its Spanish-speaking customer base.

    https://www.inforisktoday.co.uk/ransomware-attack-reportedly-cripples-european-call-center-a-17619

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    2 Proposed Class Actions Filed in Incident Affecting Nearly 496,000 Individuals
    Two proposed class action lawsuits filed this week in a California federal court allege negligence and a variety of other claims against UC San Diego Health in the wake of a phishing incident that affected nearly 496,000 individuals.

    https://www.inforisktoday.co.uk/lawsuits-negligence-led-to-uc-san-diego-health-incident-a-17618

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    Discussion Also Tackles Kaseya Ransomware Decryption Key, Raising Enterprise Security Posture
    Four editors at Information Security Media Group discuss important cybersecurity issues, including the rise of quadruple extortion attacks employed by ransomware gangs, the FBI reportedly withholding the Kaseya ransomware decryption key for weeks, and raising security posture during a pandemic.

    https://www.inforisktoday.co.uk/ismg-editors-panel-rise-quadruple-extortion-attacks-a-17612

  • 0 Votes
    1 Posts
    50 Views
    CerberusC

    Jen Easterly Offered Details of Investigation That Led to Joint Security Alert
    During testimony before a U.S. Senate committee hearing Thursday, CISA Director Jen Easterly told lawmakers that a recent joint alert issued by her agency, the FBI and the Coast Guard Cyber Command stemmed from an attempted attack against the Port of Houston in August.

    https://www.inforisktoday.co.uk/cisa-director-attackers-targeted-port-houston-a-17614

  • 0 Votes
    1 Posts
    49 Views
    CerberusC

    The Ad, Now Deleted, Lured Users to a Phishing Website to Harvest Credentials
    Chinese security researcher Zhi has discovered a malware targeting Mac users. The malware, spread via a paid advertisement on search engine Baidu, is intended to harvest user credentials, he says. The advertisement has now been taken down.

    https://www.inforisktoday.co.uk/researcher-finds-malware-targeting-mac-users-via-baidu-ad-a-17616

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    ACSC: Vulnerability in Password Management Platform Had RCE Capability
    The Australian Cyber Security Center has issued a critical vulnerability alert in a Zoho Corp. password management service that could enable a threat actor to take control of the targeted host. The company has issued a security patch.

    https://www.inforisktoday.co.uk/australia-warns-critical-vulnerability-in-zoho-service-a-17617

  • Business Resilience Through ‘Zero Trust’

    1
    0 Votes
    1 Posts
    33 Views
    CerberusC

    CyberEdBoard Executive Member Maria Filomena Gibe Speaks on Panel at ISMG Virtual Cybersecurity Summit Asia: Financial Services
    CyberEdBoard member Maria Filomena Gibe speaks on a panel at ISMG Virtual Cybersecurity Summit Asia: Financial Services. The panel discusses: • How “zero trust” has made security a business enabler; • Building a multifactor authentication model based on zero trust; • Building a zero trust framework aligned with people, process and platforms.

    https://www.inforisktoday.co.uk/business-resilience-through-zero-trust-a-17603

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Jerome Powell Says Discussion Paper Forthcoming as Fed Weighs CBDC
    The U.S. Federal Reserve said Wednesday it is continuing to evaluate the creation of a central bank digital currency, or CBDC, and that it intends to publish research on the subject shortly, according to Chair Jerome Powell.

    https://www.inforisktoday.co.uk/fed-chair-says-central-bank-evaluating-digital-currency-a-17604

  • 0 Votes
    1 Posts
    32 Views
    CerberusC

    CISA’s Jen Easterly and National Cyber Director Chris Inglis Support Updates
    As the Senate Homeland Security Committee considers new cyber rules and regulations for U.S. critical infrastructure, lawmakers heard testimony from CISA’s Jen Easterly and National Cyber Director Chris Inglis on Thursday in support of these measures, which include updates to FISMA.

    https://www.inforisktoday.co.uk/senators-debate-cyber-rules-for-us-critical-infrastructure-a-17605

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    Advisory Urges Multifactor Authentication, Network Segmentation, Patching and More
    The pace of Conti ransomware attacks has been increasing, with more than 400 organizations globally having fallen victim, warns a joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency, FBI and National Security Agency, which details essential defenses.

    https://www.inforisktoday.co.uk/conti-ransomware-attacks-surging-us-government-warns-a-17599

  • Work from Everywhere, Securely

    1
    0 Votes
    1 Posts
    36 Views
    CerberusC

    CyberEdBoard Executive Member, Charmaine Valmonte, guest speaks at ISMG Virtual Cybersecurity Summit Asia: Financial Services
    Volmonte is VP, IT security and IT infrastructure, Aboitiz Group of Companies. She has more than 30 years of experience in the U.S. military and the private sector. Experienced in building cyber risk and IT security programs with highly effective teams focused on reducing the risks of security breaches, minimizing disruptions to preserve brand reputation and build client confidence.

    https://www.inforisktoday.co.uk/work-from-everywhere-securely-a-17601

  • 0 Votes
    1 Posts
    29 Views
    CerberusC

    CyberEdBoard Executive Member, Maria Filomena Gibe, guest speaks on panel at ISMG Virtual Cybersecurity Summit Asia: Financial Services
    The panel discusses: • How ‘zero trust’ has made security as a business enabler • Building a multi-factor authentication model based on ‘zero trust’ • Building ‘zero trust’ framework aligned with people, process and platforms

    https://www.inforisktoday.co.uk/business-resilience-through-zero-trust-navigating-through-people-process-a-17603

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    CyberEdBoard Executive Member, Dr. Deepak Kumar, guest speaks at the keynote session at ISMG Virtual Cybersecurity Summit Asia: Financial Services
    The session addresses how the banking and financial services organizations can take steps to invest for operational speed, drive value from new investments, enhance their training and cybersecurity collaboration, and work to sustain what they have.

    https://www.inforisktoday.co.uk/establishing-cybersecurity-in-era-resilience-a-17600

  • 0 Votes
    1 Posts
    33 Views
    CerberusC

    Researchers Say BulletProofLink Subscription Offers Many Services
    Microsoft Security on Tuesday issued a detailed report on a massive phishing-as-a-service operation named BulletProofLink that offered as a subscription all the tools needed to conduct a campaign. The gang remains operational.

    https://www.inforisktoday.co.uk/microsoft-analyzes-phishing-as-a-service-operation-a-17594

  • 0 Votes
    1 Posts
    57 Views
    CerberusC

    Russia’s Remote Electronic Voting System Fends Off 19 DDoS Attacks
    Russian cybersecurity firm Rostelecom-Solar reports that it prevented what it believes is the Mēris botnet from an attempted takeover of 45,000 new devices. The company’s president says it also stopped 19 distributed denial-of-service attacks targeting Russia’s remote electronic voting system.

    https://www.inforisktoday.co.uk/russians-prevent-meris-botnet-from-hijacking-45000-devices-a-17595

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    DHS’ Alejandro Mayorkas, FBI’s Christopher Wray Discuss Ransomware Surge
    U.S. FBI and Department of Homeland Security leaders fielded several cybersecurity questions from House lawmakers Wednesday, particularly around the surge in ransomware attacks, diplomatic efforts to curb ransomware’s financial model, and the nation-states that harbor cybercriminals.

    https://www.inforisktoday.co.uk/us-dhs-fbi-face-ransomware-questions-from-congress-a-17596

  • 0 Votes
    1 Posts
    31 Views
    CerberusC

    Researcher: Decade-Old Exposure Is a Privacy Concern
    Researcher Bob Diachenko has discovered an unsecured database containing personal information of 106 million foreign nationals who have visited Thailand in the past decade. The 200GB database, which has now been secured, has not been accessed by unauthorized personnel, Thai authorities say.

    https://www.inforisktoday.co.uk/researcher-finds-exposed-data-106-million-thai-visitors-a-17591

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    Cisco Talos: Turla Deploying Malware Against US, German and Afghan Victims
    A Russian-linked group known as Turla has been deploying a secondary backdoor against numerous targets to maintain persistence within compromised devices even after the primary malware has been discovered and removed, Cisco Talos report. Victims include U.S., German and Afghan organizations.

    https://www.inforisktoday.co.uk/russian-linked-group-using-secondary-backdoor-against-targets-a-17592

  • BlackMatter Knocks Marketron Off the Air

    1
    0 Votes
    1 Posts
    39 Views
    CerberusC

    Ransomware Gang’s Second Attack in 3 Days Affects 6,000 Broadcasters
    Marketron Broadcast Solutions was hit over the weekend by a ransomware attack launched by the BlackMatter gang, and the attack has taken down a number of the marketing firm’s products. Marketron is currently in talks with its attacker.

    https://www.inforisktoday.co.uk/blackmatter-knocks-marketron-off-air-a-17588

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    Researchers: Vulnerability Unmasks Users’ VPNs; Virgin Media: Risk Is ‘Very Low’
    Researchers have found a zero-day vulnerability in U.K. broadband and cable TV provider Virgin Media’s Super Hub 3 routers that enables an attacker to unmask IP addresses of VPN users. But A Virgin Media spokesperson says the risk of that happening is “very low.”

    https://www.inforisktoday.co.uk/zero-day-vulnerability-found-in-uk-virgin-media-routers-a-17589

  • 0 Votes
    1 Posts
    45 Views
    CerberusC

    ‘Suex’ Accused of Laundering Tens of Millions of Dollars for Cybercriminals
    The U.S. Department of the Treasury has blacklisted Russia-based cryptocurrency exchange Suex for allegedly laundering tens of millions of dollars for ransomware operators, scammers and darknet markets. It is the first such designation for a virtual currency exchange.

    https://www.inforisktoday.co.uk/us-treasury-blacklists-russia-based-crypto-exchange-a-17590

  • 0 Votes
    1 Posts
    45 Views
    CerberusC

    Christopher Wray Asked About Report That Bureau Held Key for 3 Weeks
    FBI Director Christopher Wray faced questions during a Senate hearing Tuesday concerning a published report that the bureau for almost three weeks withheld a decryption key that agents obtained from the ransomware gang that targeted software firm Kaseya.

    https://www.inforisktoday.co.uk/fbi-director-questioned-over-kaseya-decryption-key-a-17584

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    Put Your Automotive Code to the Test

    With automotive standard ISO 21434 just around the corner, this tutorial focuses on how it will form a key protective component against the cyber threats facing automation software developers.

    https://www.inforisktoday.co.uk/how-to-keep-cybercrimes-foot-off-pedal-isosae-21434-a-17585

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    One Incident Involved Foiled Attempt at Invoice and Wire Transfer Fraud
    Two eye care entities are among the latest healthcare provider organizations recently reporting hacking breaches each affecting tens of thousands of individuals. One of the incidents involved a foiled wire transfer fraud attempt.

    https://www.inforisktoday.co.uk/hacking-incidents-lead-to-2-big-eye-care-provider-breaches-a-17587

  • 0 Votes
    1 Posts
    29 Views
    CerberusC

    Crypto Exchange Also Scraps Plans for Lending Program Amid SEC Pushback
    U.S.-based cryptocurrency exchange Coinbase has contracted with the U.S. Department of Homeland Security to provide its blockchain monitoring software, according to government tracking sites. The U.S.-based exchange also withdrew plans to launch a crypto lending program amid tensions with the SEC.

    https://www.inforisktoday.co.uk/coinbase-contracts-dhs-for-blockchain-analytics-a-17586

  • 0 Votes
    1 Posts
    44 Views
    CerberusC

    Researchers Believe NEW Cooperative Targeted By BlackMatter Gang
    NEW Cooperative, an Iowa-based farm services cooperative, has reportedly been targeted by the BlackMatter ransomware gang, demanding a $5.9 million payment from the organization, according to security researchers and published reports. The cooperative is working with law enforcement.

    https://www.inforisktoday.co.uk/ransomware-reportedly-hits-iowa-farm-services-cooperative-a-17582

  • 0 Votes
    1 Posts
    42 Views
    CerberusC

    Alaska DHSS’ IT Systems Are Still Recovering from Nation-State-Sponsored Attack
    Alaska’s Department of Health and Social Services says it is notifying “all Alaskans” that their personal and protected health information may have been compromised in a nation-state-sponsored cyberattack that was detected in May, from which the department is still recovering.

    https://www.inforisktoday.co.uk/post-attack-health-agency-notifying-all-alaskans-a-17578

  • 0 Votes
    1 Posts
    31 Views
    CerberusC

    Compromised PII Includes Names, Email and Phone Numbers
    The French shipping firm CMA CGM reported on Monday that it had been struck with a data breach almost a year after it was hit with a ransomware attack that knocked its systems offline for several days.

    https://www.inforisktoday.co.uk/shipping-giant-cma-cgm-hit-second-attack-a-17579

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Cross-Chain Protocol pNetwork Offers Hacker ‘Clean’ $1.5 Million Bug Bounty
    In the latest security incident involving a decentralized finance protocol, cross-chain project pNetwork announced Sunday it had been hacked for 277 pBTC, a form of wrapped bitcoin, with losses worth over $12 million at current value.

    https://www.inforisktoday.co.uk/hacker-makes-off-12-million-in-latest-defi-breach-a-17580

  • 0 Votes
    1 Posts
    34 Views
    CerberusC

    Nation-State Chinese Groups APT27, APT41 Likely Candidates
    Earlier this month, McAfee Enterprise’s Advanced Threat Research team, working with McAfee’s Professional Services IR team, reported that an APT campaign dubbed Operation Harvest had been in operation for years. Their analysis provides insight into the group’s tools, tactics and techniques.

    https://www.inforisktoday.co.uk/chinese-apt-data-harvesting-campaign-analyzed-a-17581

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    MicroTik Flaws Still Being Exploited, But There Are Mitigation Steps
    The Mēris botnet, responsible for huge waves of DDoS attacks recorded by cybersecurity firms Qrator Labs and Cloudflare, is still active, using “abandoned” MikroTik routers. The attack signatures saw a spike of 21.8 million requests per second, exploiting a vulnerable version of MikroTik RouterOS.

    https://www.inforisktoday.co.uk/meris-how-to-stop-most-powerful-botnet-on-record-a-17574

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    IG Report on Dams Urges Agency to Make Several Security Improvements
    CISA must update its plans to improve the security - both physical and cyber - within the nation’s critical infrastructure, according to a report that specifically looked at issues related to the country’s dams and levees. Attacks targeting critical infrastructure have raised the issue.

    https://www.inforisktoday.co.uk/cisa-must-update-critical-infrastructure-protection-plans-a-17575

  • No Bounty for Bug Hunters in India

    1
    0 Votes
    1 Posts
    56 Views
    CerberusC

    Experts Discuss Challenges, Solutions for Bounty Hunters
    While there is no dearth of talent among Indian bug bounty hunters, hurdles such as lack of trust, payment disputes, cost, unethical practices and lack of regulatory laws deter the growth of the bug bounty programs in the country, according to some experts.

    https://www.inforisktoday.co.uk/no-bounty-for-bug-hunters-in-india-a-17571

  • 0 Votes
    1 Posts
    44 Views
    CerberusC

    Scraped Whois Information Leaked by Anonymous in Reprisal for Alt-Right Site Hosting
    More than 15 million email addresses and individuals’ personal details have been leaked by Anonymous in reprisal for Texas’ new law restricting abortion. The leaked information allegedly comes from Epik, which has hosted far-right websites, including for the Republican Party of Texas.

    https://www.inforisktoday.co.uk/web-hoster-epiks-breach-exposes-15-million-email-addresses-a-17572

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    Europol: Illegal Operation Connected to Italian Mafia
    The Spanish and Italian national police agencies, in conjunction with Europol, have arrested 106 individuals who allegedly are linked to the Italian mafia on a variety of online fraud charges that authorities say earned the group at least 10 million euros ($11.7 million) in illegal profits.

    https://www.inforisktoday.co.uk/spanish-italian-police-break-up-phishing-gang-a-17576

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    Report: Treasury Department to Announce Sanctions as Early as This Week
    The Biden administration may soon unveil plans to curtail the ransomware attacks that have crippled corporate networks this year. According to a report from The Wall Street Journal, the Treasury Department will announce sanctions and similar guidance designed to disrupt the ransomware model.

    https://www.inforisktoday.co.uk/us-to-unveil-sanctions-on-use-cryptocurrency-for-ransoms-a-17567

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    Matthew Gatrel Offered Subscription-Based Computer Attack Platforms
    An Illinois man has been found guilty of running subscription-based distributed denial of service attacks that enabled customers to launch DDoS strikes of their own. He is now facing a statutory maximum sentence of 35 years in federal prison when sentenced in January 2022.

    https://www.inforisktoday.co.uk/illinois-man-convicted-running-ddos-facilitation-websites-a-17568

  • Mirai Botnet Actively Exploiting OMIGOD Flaw

    1
    0 Votes
    1 Posts
    63 Views
    CerberusC

    Researchers Say OMIGOD Vulnerability Can Give Attackers Root Privileges
    The Mirai botnet is actively exploiting the known vulnerability CVE-2021-38647, which is part of a quarter of vulnerabilities dubbed OMIGOD, in Microsoft’s Azure Linux Open Management Infrastructure framework, according to Kevin Beaumont, head of the security operations center for Arcadia Group.

    https://www.inforisktoday.co.uk/mirai-botnet-actively-exploiting-omigod-flaw-a-17566

  • HHS OCR's Latest HIPAA Enforcement Action

    1
    0 Votes
    1 Posts
    42 Views
    CerberusC

    20th ‘Right of Access’ Settlement, But When Will a New Director Be Named?
    While the wait continues for the Biden administration to name a new leader for the Department of Health and Human Services’ Office for Civil Rights, the HIPAA enforcement agency recently issued its 20th settlement to date in a case involving a patient “right of access” dispute.

    https://www.inforisktoday.co.uk/hhs-ocrs-latest-hipaa-enforcement-action-a-17563

  • 0 Votes
    1 Posts
    33 Views
    CerberusC

    Researchers: Attacker Sold Pilfered Airline Data on the Darknet
    Cisco Talos researchers have connected a previously discovered series of aviation industry attacks stretching back more than three years to a Nigeria-based attacker. The attacker sold the stolen information on the darknet, the researchers say.

    https://www.inforisktoday.co.uk/nigerian-hacker-connected-to-aviation-industry-attacks-a-17564

  • 0 Votes
    1 Posts
    55 Views
    CerberusC

    Man Allegedly Recruited, Trained AT&T Employees to Act as Hackers
    A dual citizen of Pakistan and Grenada has been sentenced to 12 years in prison for orchestrating a seven-year scheme that unlawfully unlocked nearly 2 million AT&T smartphones, which the carrier says amounted to $200 million in subscriber losses, according to the U.S. DOJ.

    https://www.inforisktoday.co.uk/fraudster-gets-12-year-sentence-for-att-unlocking-scheme-a-17565

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    FBI, CISA, Coast Guard Release Joint Warning and Urge Customers to Patch
    CISA, the FBI and the U.S. Coast Guard Cyber Command warn users of Zoho Corp.'s single sign-on and password management tool to patch for a vulnerability that nation-state groups may look to exploit. Attackers could use the bug to compromise credentials and exfiltrate data from Active Directory.

    https://www.inforisktoday.co.uk/us-warns-nation-state-groups-may-exploit-flaw-in-zoho-tool-a-17562

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    Many Files Crypto-Locked Before July 13 Unlockable via Free Bitdefender Decryptor
    Score one for the good guys in the fight against ransomware: Anyone who fell victim to REvil, aka Sodinokibi, crypto-locking malware before July 13 can now decrypt at least some of their files for free, thanks to a decryptor released by security firm Bitdefender.

    https://www.inforisktoday.co.uk/good-news-revil-ransomware-victims-get-free-decryptor-a-17560

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    Breach Notification Report Reveals Some PII Could Have Been Exposed
    The Republican Governors Association was one of several U.S. organizations targeted in March when a nation-state group took advantage of vulnerabilities in Microsoft Exchange email servers, according to a breach notification letter filed with Maine authorities. It appears some PII was exposed.

    https://www.inforisktoday.co.uk/republican-governors-association-targeted-in-exchange-attacks-a-17554

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    But Does the ‘Policy Statement’ Warning Overstep the Intention of the Rule?
    The FTC warns makers of personal health records, mobile health apps, fitness devices and a variety of similar products and services that they will face stiff civil monetary penalties for failure to comply with the commission’s 12-year-old - but never-yet enforced - Health Breach Notification Rule.

    https://www.inforisktoday.co.uk/ftc-health-app-device-makers-must-report-breaches-a-17555

  • 0 Votes
    1 Posts
    47 Views
    CerberusC

    Analysts Say the Gang Is Escalating Rhetoric to Scare Victims
    Regarding the recent tactical innovation by the Grief ransomware gang that is threatening to wipe a victim’s data and decryption key if the victim engages a ransom negotiator, analysts are calling this a desperate ploy to scare a target into paying the ransom demand.

    https://www.inforisktoday.co.uk/griefs-threat-to-wipe-decryption-key-believable-a-17556

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Calls for Global Cryptocurrency Regulation Escalate as US Explores Options
    Amid growing calls for cryptocurrency regulations, the U.S. acting comptroller of the currency has made a definitive statement on safeguarding investors and how cryptocurrency should intersect with traditional financial institutions.

    https://www.inforisktoday.co.uk/occs-hsu-addresses-need-for-cryptocurrency-oversight-a-17557