Skip to main content

Cybersecurity Update

Bill Gates, Barack Obama, Jeff Bezos, Joe Biden, Kanye West, Elon Musk and
many other high profile people had their Twitter accounts hacked.
o All their followers received a tweet trying to convince users to send in $1000 in bitcoin

- The US National Security Agency is warning hospitals, universities and
pharmaceutical companies that Russian hackers are attempting to steal COVID-19 research using email phishing and malware attacks.


- Wells Fargo ordered all of its employees to remove the TikTok app from their
smartphones, due to security issues discovered with the app made by ByteDance in China.


- MGM Resorts International, headquartered in Las Vegas, NV, now believes that a breach it suffered in 2019, originally advertised as affecting 10.6 million customers, actually has impacted 142 million customers, and that their info apparently is now for sale on the Dark Web.


- Forbes magazine is reporting that unfilled cybersecurity jobs are expected to reach 1.8 million by 2022.


- BitSight published report on the security vulnerabilities for work from home/remote
employees:
o 3-5 times more likely to have at least one family malware already infecting
devices
o 7.5 times more likely to have at least 5 distinct families of malware
o 25% or more of devices used are exposed on the Internet
o One in seven have exposed cable modem control interface
- COVID-19 pandemic making hospitals highly attractive targets for hackers, according to report published by Health Exec magazine
o PHI from infants are especially prized as they can be resold on Dark Web to
those who wish to use their identities
 “You have a free run for 18 years to utilize these personas.”; stated Gary
Gooden, CISO of Seattle Children’s Hospital

- Benefit Recovery Specialists, headquartered in Houston, TX, notified 274,000 patients that their PHI was exposed after hacker obtained employee credentials to deploy malware.


- Mount Auburn Hospital of Cambridge, MA, reported that it was hit by ransomware, but claims no PHI was exposed.

- Stradis Healthcare of Atlanta, GA reported that a former employee, Christopher Dobbins, was charged by the U.S. Department of Justice after he deleted and modified tens of thousands of records from his former employer’s systems.


- Yevgeniy Nikulin of Russia, was arrested while on vacation in Prague (Czech
Republic), then extradited to the U.S. where a jury found him guilty for hacking into LinkedIn and DropBox, and then profiting from the information he stole.
o Sentencing scheduled for 9/29/2020


- Night Lion Security announced that a hacker accessed servers in its DataViper
division, and valuable info was stolen.
o Hacker claims to have info from 8,200 databases.


- Citrix is warning its customers about potential security vulnerabilities in its ADC,  Gateway and SD-WAN WANOP networking products.


- Juniper Networks announced to its customers that it now offers patches to fix
vulnerabilities found in its Secure Analytics, Junos Space and Junos Space Security Director products.


- The United States Secret Service announced it has formed the Cyber Fraud Task Force (CFTF)
o Aimed at improving data sharing, interoperability and development of
investigative skills
o Also prevention, detection and mitigations of cyberattacks.
- Blackbaud, headquartered in Charleston, South Carolina, a provider of software and hosting solutions, said it stopped a ransomware attack from encrypting files but still had to pay a ransom demand anyway
o hackers stole data from the company's network and threatened to publish it
online

- Quantum Imaging announced that the Fairview Township Police of Pennsylvania are investing an employee who allegedly shared an x-ray image of a man's genitalia on a Facebook group.


- IBM research reports states:
o 80% of medical practices have been victim of cyberattack
o 51% reported patient safety concerns from hacks
o 20% said business was interrupted for more than 5 hours
o 75% increase in cyberattacks during pandemic
 6000% increase in spam attacks

- IBM reported that hackers in Iran have posted training videos online to train new recruits.
o The hacking group involved is known as ITG18, aka Charming Kitten,
Phosphorous and APT35.

- BlackRock is new malware discovered that can infect an Android-based device and steal passwords and card data from 337 apps, according to ZDNet.
- Heartland Counseling Services, headquartered in Sioux City, IA, notified more than 500 patients that their PHI may have been compromised after email phishing attack.
- Delaware Division of Developmental Disabilities Services notified 350 patients that their PHI was exposed after email incident.
- Central California Alliance For Health, headquartered in Scotts Valley, CA, notified an unknown number of patients that their PHI may have been exposed after email phishing attack.


- MyCastingFile, headquartered in New Orleans, LA, notified 260,000 actors and
actresses that their personal info was exposed after database error.


- Sarrell Regional Dental Center for Public Health Inc. of Alabama reported that it suffered from a ransomware attack.


- Columbia College of Chicago, IL reported that it has become the victim of a
ransomware attack which may have affected its students.

If you like something I've posted please feel free to click the "like" button!

Original Post

Add Reply

Post
×
×
×
×
Link copied to your clipboard.
×
×