avatarTeri Radichel

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

27121

Abstract

uote id="3919"><p>WeSteal uses a simple but effective way to swipe cryptocurrency-receiving addresses: It rummages through clipboards, searching for strings matching Bitcoin and Ethereum wallet identifiers. When it finds them, WeSteal swaps out the legitimate wallet IDs in the clipboard with its own IDs. When a victim tries to paste the swapped wallet ID for a transaction, the funds get whisked off to the attacker’s wallet.</p></blockquote><div id="1d03" class="link-block"> <a href="https://threatpost.com/westeal-cryptocurrency-stealing-tool/165762/"> <div> <div> <h2>WeSteal: A Cryptocurrency-Stealing Tool That Does Just That | Threatpost</h2> <div><h3>Some cybercriminals try, at least, to cover their dirty work with a threadbare "this will throw off the lawsuits"…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*5MXmXSNzsNgHdaQF)"></div> </div> </div> </a> </div><blockquote id="bc9f"><p>Threat actors are increasingly adopting <a href="https://blog.reversinglabs.com/blog/excel-4.0-macros">Excel 4.0 documents</a> as an initial stage vector to distribute malware such as <a href="https://malpedia.caad.fkie.fraunhofer.de/details/win.zloader">ZLoader</a> and Quakbot, according to new research.</p></blockquote><p id="f3e1">Can you live without the macro?</p><div id="57c8" class="link-block"> <a href="https://thehackernews.com/2021/04/cybercriminals-widely-abusing-excel-40.html"> <div> <div> <h2>Cybercriminals Widely Abusing Excel 4.0 Macro to Distribute Malware</h2> <div><h3>Threat actors are increasingly adopting Excel 4.0 documents as an initial stage vector to distribute malware such as…</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*k2J-zKWBASmEpBqk)"></div> </div> </div> </a> </div><p id="9a83">Law enforcement automatically removing Emotet malware from victim machines.</p><div id="39f4" class="link-block"> <a href="https://blog.malwarebytes.com/threat-analysis/2021/01/cleaning-up-after-emotet-the-law-enforcement-file/"> <div> <div> <h2>Cleaning up after Emotet: the law enforcement file — Malwarebytes Labs</h2> <div><h3>Update 2021–04–25 : This blog post was authored by Hasherezade and Jérôme Segura Emotet has been the most wanted…</h3></div> <div><p>blog.malwarebytes.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*4w5_aXFAcwAi5jiX)"></div> </div> </div> </a> </div><p id="a1a9">Babuk ransomware authors claim they will shut down but will make the code public afterwards.</p><div id="b1c1" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/babuk-ransomware-readies-shut-down-post-plans-to-open-source-malware/"> <div> <div> <h2>Babuk ransomware readies ‘shut down’ post, plans to open source malware</h2> <div><h3>After just a few months of activity, the operators of Babuk ransomware briefly posted a short message about their…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*wL7ruUBViHqNN6zw)"></div> </div> </div> </a> </div><p id="6f80">ToxicEye uses Telegram for command and control.</p><div id="a6e2" class="link-block"> <a href="https://blog.checkpoint.com/2021/04/22/turning-telegram-toxic-new-toxiceye-rat-is-the-latest-to-use-telegram-for-command-control/"> <div> <div> <h2>Turning Telegram toxic: ‘ToxicEye’ RAT is the latest to use Telegram for command & control — Check…</h2> <div><h3>Research by: Omer Hofman Telegram, the cloud-based IM platform has enjoyed a surge in popularity this year because of…</h3></div> <div><p>blog.checkpoint.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Ib3Hq23guAkmarL9)"></div> </div> </div> </a> </div><p id="62ee">RotaJakiro: A long lived secret backdoor with 0 VT detection.</p><p id="65ce"><a href="https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/">https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en</a></p><p id="02cd">PortDoor Espionage Malware Takes Aim at Russian Defense Sector. RTF Document.</p><div id="0935" class="link-block"> <a href="https://threatpost.com/portdoor-espionage-malware-takes-aim-at-russian-defense-sector/165770/"> <div> <div> <h2>PortDoor Espionage Malware Takes Aim at Russian Defense Sector</h2> <div><h3>A previously undocumented backdoor malware, dubbed PortDoor, is being used by a probable Chinese advanced persistent…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*hBcrw5aXsSjrgXu1)"></div> </div> </div> </a> </div><p id="49b4"><b>Threat Reports</b></p><div id="da8f" class="link-block"> <a href="https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research-1h21"> <div> <div> <h2>Unit 42 Cloud Threat Report, 1H 2021</h2> <div><h3>In the early days of the COVID-19 pandemic, there was a rapid uptick in demand for cloud services. Utilizing data…</h3></div> <div><p>www.paloaltonetworks.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*rgnSO4NJEXyJc9ax)"></div> </div> </div> </a> </div><p id="04d7"><b>Breaches and Attacks</b></p><p id="a288">West Nyack man loses $35,000 to scam that stemmed from malware subscription. Gave scammers his bank account to get a refund for a subscription. Never give your bank account. This highlights the fact that wire transfers at banks need an overhaul. So much risk related to that process.</p><p id="f0df"><a href="https://bronx.news12.com/west-nyack-man-loses-35-000-to-scam-that-stemmed-from-malware-subscription">https://bronx.news12.com/west-nyack-man-loses-35-000-to-scam-that-stemmed-from-malware-subscription</a></p><p id="7c49">Experian API Exposed Credit Scores of Most Americans</p><blockquote id="4bf2"><p>Demirkapi found the Experian API could be accessed directly without any sort of authentication, and that entering all zeros in the “date of birth” field let him then pull a person’s credit score. He even built a handy command-line tool to automate the lookups, which he dubbed “Bill’s Cool Credit Score Lookup Utility.”</p></blockquote><div id="c74f" class="link-block"> <a href="https://krebsonsecurity.com/2021/04/experian-api-exposed-credit-scores-of-most-americans/"> <div> <div> <h2>Experian API Exposed Credit Scores of Most Americans</h2> <div><h3>Big-three consumer credit bureau Experian just fixed a weakness with a partner website that let anyone look up the…</h3></div> <div><p>krebsonsecurity.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*F-lUgAAJlUJUNrz_)"></div> </div> </div> </a> </div><p id="99ae">Chinese businessman admits smuggling U.S. marine tech to China.</p><blockquote id="1083"><p>Prosecutors said Northwestern Polytechnical University, a Chinese military research institute, tasked Qin with obtaining items used for anti-submarine warfare and that he obtained hydrophones for it from a U.S. manufacturer.</p></blockquote><div id="5f3b" class="link-block"> <a href="https://www.reuters.com/world/china/chinese-businessman-admits-smuggling-us-marine-tech-china-2021-04-28/"> <div> <div> <h2>Chinese businessman admits smuggling U.S. marine tech to China</h2> <div><h3>A Chinese businessman pleaded guilty on Wednesday to U.S. charges that he smuggled marine technology out of the United…</h3></div> <div><p>www.reuters.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div> </div> </div> </a> </div><p id="addd">Cybersecurity breach closes Centennial schools in Portland, Oregon. Does not say how.</p><div id="513c" class="link-block"> <a href="https://www.koin.com/news/oregon/cybersecurity-breach-closes-centennial-schools/"> <div> <div> <h2>Cybersecurity breach closes Centennial schools</h2> <div><h3>PORTLAND, Ore. (KOIN) -- An additional 794 confirmed/presumptive cases of the coronavirus were logged Saturday…</h3></div> <div><p>www.koin.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*HoFFOP2evpLoHIav)"></div> </div> </div> </a> </div><p id="5a4f">Saskatchewan Blue Cross shut down systems after discovering a breach. The company is still researching the cause.</p><div id="55f3" class="link-block"> <a href="https://saskatoon.ctvnews.ca/we-apologize-for-the-uncertainty-impact-on-customer-data-still-unknown-after-sask-blue-cross-cyber-breach-1.5402575"> <div> <div> <h2>'We apologize for the uncertainty': Impact on customer data still unknown after Sask. Blue Cross…</h2> <div><h3>SASKATOON -- Saskatchewan Blue Cross says it's been the victim of a cyber breach. In a statement on its website, the…</h3></div> <div><p>saskatoon.ctvnews.ca</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*lx5lyz_474M9TM_g)"></div> </div> </div> </a> </div><p id="d6e8">Contact Tracing Data Breach Exposed Personal Data For Over 72K Pennsylvanians.</p><p id="5360">Apparently this was a case of “Here, take my data…” a topic in my upcoming talk at <a href="https://go.cloudhealthtech.com/cloudlive">CloudLive</a>.</p><div id="657d" class="link-block"> <a href="https://wskg.org/news/contact-tracing-data-breach-exposed-personal-data-for-over-72k-pennsylvanians/"> <div> <div> <h2>Contact Tracing Data Breach Exposed Personal Data For Over 72K Pennsylvanians</h2> <div><h3>HARRISBURG, PA (WSKG) - A vendor working with the Pennsylvania Department of Health failed to secure the private…</h3></div> <div><p>wskg.org</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Q2Vz8iLkMFuDjjrF)"></div> </div> </div> </a> </div><p id="2176">Illinois attorney general’s office was warned about weak cybersecurity before ransomware attack.</p><div id="b82a" class="link-block"> <a href="https://www.chicagotribune.com/politics/ct-illinois-attorney-general-ransomware-20210430-cjygigcb6vgxdplge2nmfqkwae-story.html"> <div> <div> <h2>Illinois attorney general's office was warned about weak cybersecurity before ransomware attack</h2> <div><h3>A state audit released earlier this year warned that Illinois Attorney General Kwame Raoul's office had a "weaknesses…</h3></div> <div><p>www.chicagotribune.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*LpBaA70B-Dxt6Q7r)"></div> </div> </div> </a> </div><p id="55b2">Ransomware potentially linked to Russia</p><div id="da78" class="link-block"> <a href="https://www.dailyherald.com/news/20210430/data-breach-was-a-ransomware-attack"> <div> <div> <h2>Data breach was a ransomware attack</h2> <div><h3>A data breach reported by state Attorney General Kwame Raoul's office nearly three weeks ago was a ransomware attack…</h3></div> <div><p>www.dailyherald.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*fq21ah4DS_Slh0qD)"></div> </div> </div> </a> </div><p id="6e54">Digital Ocean billing data breach — does not say what flaw caused the breach or how it was fixed.</p><div id="10a1" class="link-block"> <a href="https://techcrunch.com/2021/04/28/digitalocean-customer-billing-data-breach/"> <div> <div> <h2>DigitalOcean says customer billing data accessed in data breach</h2> <div><h3>DigitalOcean has emailed customers warning of a data breach involving customers' billing data, TechCrunch has learned…</h3></div> <div><p>techcrunch.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*G0_cLh7yrh1E9iSt)"></div> </div> </div> </a> </div><blockquote id="e513"><p>A data breach at the Wyoming Department of Health publicly exposed COVID-19, influenza and blood alcohol test data from more than a quarter of Wyomingites and some out of state residents, the department announced Tuesday.</p></blockquote><blockquote id="1a62"><p>The breach occurred when an employee erroneously uploaded files containing that data to the public code-hosting platform GitHub.</p></blockquote><p id="4d28">Proper network security architecture can help prevent this type of thing.</p><div id="190e" class="link-block"> <a href="https://www.powelltribune.com/stories/health-department-data-breach-exposed-info-of-164000-wyomingites,31132"> <div> <div> <h2>Health Department data breach exposed info of 164,000 Wyomingites</h2> <div><h3>CASPER (WNE) - A data breach at the Wyoming Department of Health publicly exposed COVID-19, influenza and blood alcohol…</h3></div> <div><p>www.powelltribune.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*UrdnhTXR252XyTgo)"></div> </div> </div> </a> </div><p id="5e03">Software companies exposed to a breach of sensitive pitch information in breach related to exposed Azure storage account.</p><div id="7e6c" class="link-block"> <a href="https://www.technologytimes.pk/2021/04/28/software-companies-exposed-to-hacking-in-major-data-breach/"> <div> <div> <h2>Software Companies Exposed to Hacking in Major Data Breach</h2> <div><h3>vpnMentor's research team recently uncovered a data breach exposing sensitive internal data, which may presumably be…</h3></div> <div><p>www.technologytimes.pk</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*7U2y9S0smPkmaIS7)"></div> </div> </div> </a> </div><p id="49fc">Reverb hacked. Didn’t say how.</p><div id="cde5" class="link-block"> <a href="https://portswigger.net/daily-swig/musical-instrument-marketplace-reverb-suffers-data-breach"> <div> <div> <h2>Musical instrument marketplace Reverb suffers data breach</h2> <div><h3>Jessica Haworth 28 April 2021 at 12:30 UTC Updated: 28 April 2021 at 17:06 UTC Chicago-based company confirms security…</h3></div> <div><p>portswigger.net</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*rqSd_aOZm4ReuRkI)"></div> </div> </div> </a> </div><p id="3d66">Gyrodata Employee Data Breach. Doesn’t say how.</p><div id="5807" class="link-block"> <a href="https://www.infosecurity-magazine.com/news/us-drilling-giant-gyrodata/"> <div> <div> <h2>US Drilling Giant Gyrodata Reveals Employee Data Breach</h2> <div><h3>A major oil drilling specialist has admitted it suffered a ransomware attack which may have led to the compromise of…</h3></div> <div><p>www.infosecurity-magazine.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*doXuP8nqyLmbos2X)"></div> </div> </div> </a> </div><p id="d8d4">First Horizon breached. Customer funds stolen. Stolen credentials but doesn’t say how. Access issues also in my upcoming talk.</p><div id="61a6" class="link-block"> <a href="https://siliconangle.com/2021/04/28/financial-services-firm-first-horizon-suffers-data-breach-customer-funds-stolen/"> <div> <div> <h2>Financial services firm First Horizon suffers data breach with customer funds stolen - SiliconANGLE</h2> <div><h3>Financial services company First Horizon Corp. has suffered a data breach that saw customer accounts accessed and funds…</h3></div> <div><p>siliconangle.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*EQw8XykP88EAAYQ8)"></div> </div> </div> </a> </div><p id="b88d">Disclosed breach after stolen database discovered.</p><div id="c651" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/mangadex-discloses-data-breach-after-stolen-database-shared-online/"> <div> <div> <h2>MangaDex discloses data breach after stolen database shared online</h2> <div><h3>Manga scanlation site MangaDex disclosed a data breach last week after learning that the site's user database was…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*-8hSsHNk3h_tEtty)"></div> </div> </div> </a> </div><p id="ea05">Catholic Charities North Dakota target of a data breach. Suspicious activity related to email accounts. Not specific as to what the activity was or how the organization’s systems were compromised.</p><div id="cb5b" class="link-block"> <a href="https://www.inforum.com/news/crime-and-courts/7007484-Catholic-Charities-North-Dakota-target-of-data-breach"> <div> <div> <h2>Catholic Charities North Dakota target of data breach | INFORUM</h2> <div><h3>FARGO - A law firm representing Catholic Charities North Dakota said Thursday, April 29, the nonprofit's email system…</h3></div> <div><p>www.inforum.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*50EufVs3pEgd0yiF)"></div> </div> </div> </a> </div><p id="cedf">More suspicious email activity. Maryland Ortho Practice breach affects 125,000 people. Doesn’t provide specifics.</p><div id="7826" class="link-block"> <a href="https://ryortho.com/breaking/maryland-ortho-practice-data-breach-exposes-over-125000-people/"> <div> <div> <h2>Maryland Ortho Practice Data Breach Exposes Over 125,000 People</h2> <div><h3>Bethesda, Maryland-based The Centers for Advanced Orthopaedics (CAO) has notified 125,291 patients and CAO health plan…</h3></div> <div><p>ryortho.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VNOlxrSKB41IIHn2)"></div> </div> </div> </a> </div><p id="7631">Personal information of 20 million BigBasket users is now available online for anyone to download and use from a breach that occurred on October 30, 2020.</p><div id="fcb0" class="link-block"> <a href="https://www.moneycontrol.com/news/technology/details-of-20-million-bigbasket-users-leaked-online-after-data-breach-last-year-6817061.html"> <div> <div> <h2>BigBasket Data Breach | Hackers Leak Sensitive Information Of More Than 20 Million Users Online</h2> <div><h3>April 26, 2021 / 03:43 PM IST A well-known illicit forum is now hosting personal details of 20 million BigBasket users…</h3></div> <div><p>www.moneycontrol.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*_z7KTlooZnrctXjs)"></div> </div> </div> </a> </div><p id="8b40">Amazon warned this customer they had an open S3 bucket.</p><div id="c681" class="link-block"> <a href="https://www.zdnet.com/article/paleohacks-data-leak-exposes-customer-records-password-reset-tokens/"> <div> <div> <h2>Paleohacks data leak exposes customer records, password reset tokens | ZDNet</h2> <div><h3>A popular online resource for paleo recipes and tips was the source of a data leak impacting roughly 70,000 users. On…</h3></div> <div><p>www.zdnet.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*g0Y9OD_Cyzwbyk0G)"></div> </div> </div> </a> </div><p id="e627">Suspicious email activity. Does not say how the attackers got in.</p><div id="0942" class="link-block"> <a href="https://www.erienewsnow.com/story/43797546/personal-data-exposed-in-achievement-center-data-breach"> <div> <div> <h2>Personal Data Exposed in Achievement Center Data Breach</h2> <div><h3>Potential data obtained from the email accounts includes demographic data, including name, address, date of birth…</h3></div> <div><p>www.erienewsnow.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*4R91JT_5sZCYR4og)"></div> </div> </div> </a> </div><p id="5fc9">Human error causes a data breach at the Vermont Department of Labor. Report finds controls were adequate to find the error.</p><div id="846a" class="link-block"> <a href="https://www.wcax.com/2021/04/27/audit-finds-human-error-likely-cause-of-vt-data-breach/"> <div> <div> <h2>Audit finds human error likely cause of Vt. data breach</h2> <div><h3>An investigation has determined that a single human error was the likely cause of the Vermont Department of Labor…</h3></div> <div><p>www.wcax.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*0uFssb6j_3Wn7BP4)"></div> </div> </div> </a> </div><p id="afb7">Ransomware group threatens DC police force with informant leak. This will likely put people’s health and lives at risk. Ransomware criminals have no concern whatsoever for the people they affect.</p><p id="8611"><a href="https://www.infosecurity-magazine.com/news/ransomware-group-dc-cops-informant/">https://www.infosecurity-magazine.com/news/ransomware-group-dc-cops-informant/</a></p><p id="f742">Dutch government pauses coronavirus app over data leak fears.</p><blockquote id="61d2"><p>The Dutch app uses “exposure notification” technology developed by <a href="https://telecom.economictimes.indiatimes.com/tag/google">Google</a> and <a href="https://telecom.economictimes.indiatimes.com/tag/apple">Apple</a> that generates random codes that can be exchanged by phones whose users are close to one another for long enough to possibly transmit the virus.</p></blockquote><blockquote id="1336"><p>According to the ministry, Google informed the government Wednesday it has fixed the issue. The Dutch government halted messages from the app for 48 hours to check if the leak has been fixed.</p></blockquote><p id="d833">To research further:</p><blockquote id="f8f9"><p>Google said that random Bluetooth identifiers “on their own have no practical value to bad actors, and it is extremely unlikely that developers of pre-installed apps were aware of the inadvertent availability of those identifiers.”</p></blockquote><div id="6d2b" class="link-block"> <a href="https://telecom.economictimes.indiatimes.com/news/dutch-government-pauses-coronavirus-app-over-data-leak-fears/82309650"> <div> <div> <h2>Dutch government pauses coronavirus app over data leak fears - ET Telecom</h2> <div><h3>Health Minister Hugo de Jonge announced late Wednesday that the CoronaMelder app will stop sending warnings for 48…</h3></div> <div><p>telecom.economictimes.indiatimes.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*6CCLMW4VEid3

Options

wJ-o)"></div> </div> </div> </a> </div><p id="379a">Large data dump of billions of passwords and emails.</p><div id="9052" class="link-block"> <a href="https://thehackernews.com/2021/04/32-billion-leaked-passwords-contain-15.html"> <div> <div> <h2>3.2 Billion Leaked Passwords Contain 1.5 Million Records with Government Emails</h2> <div><h3>A staggering number of 3.28 billion passwords linked to 2.18 billion unique email addresses were exposed in what’s one…</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*SUdHdlZKpz80sT7r)"></div> </div> </div> </a> </div><blockquote id="4961"><p>Hundreds of furious Football Index investors have their identities revealed by DCMS data breach after email in response to complaints about collapsed gambling platform was sent out with recipients’ names not hidden.</p></blockquote><p id="04ed">Not a good way to send out a breach notification, if that wasn’t clear.</p><div id="fdff" class="link-block"> <a href="https://www.dailymail.co.uk/sport/sportsnews/article-9507053/Hundreds-furious-Football-Index-investors-affected-DCMS-data-breach.html"> <div> <div> <h2>Furious Football Index investors affected by DCMS data breach</h2> <div><h3>Football Index customers have been affected by a data breach by the DCMS An email sent by the department forgot to use…</h3></div> <div><p>www.dailymail.co.uk</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*kL3ZTkUpB1JU7NkU)"></div> </div> </div> </a> </div><p id="efac">Human error leads to private information about a crime sent to the wrong person. I’m a fan of making people log into systems to get their data instead of emailing sensitive information around. I’ll be writing about that in a future post.</p><div id="529c" class="link-block"> <a href="https://www.itv.com/news/meridian/2021-04-29/serious-data-breach-after-man-receives-police-email-with-sensitive-information-on-pupils"> <div> <div> <h2>'Serious data breach' after man receives police email with information on pupils | ITV News</h2> <div><h3>Dorset police are investigating a serious data breach involving pupils from two schools in Christchurch. Information…</h3></div> <div><p>www.itv.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Yj1P0znqoUr3v4Yt)"></div> </div> </div> </a> </div><p id="b6d6"><b>Cost of a Data Breach</b></p><p id="614e">In early March, the New York State Department of Financial Services (“DFS”) entered into a consent order requiring Residential Mortgage Company to pay 1.5 million for failing to comply with Cybersecurity Regulation, Part 500 of Title 23 of the New York Code.</p><div id="b8d1" class="link-block"> <a href="https://www.mondaq.com/unitedstates/data-protection/1063046/dfs-enters-into-15-million-consent-order-with-residential-mortgage-company-in-wake-of-data-breach"> <div> <div> <h2>DFS Enters Into 1.5 Million Consent Order With Residential Mortgage Company In Wake Of Data Breach…</h2> <div><h3>United States: DFS Enters Into 1.5 Million Consent Order With Residential Mortgage Company In Wake Of Data Breach…</h3></div> <div><p>www.mondaq.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*7A3CNqgzfRaLM_iH)"></div> </div> </div> </a> </div><p id="59b9">The <a href="https://autoriteitpersoonsgegevens.nl/en">Dutch Data Protection Authority</a> recently imposed <a href="https://autoriteitpersoonsgegevens.nl/nl/nieuws/boete-bookingcom-voor-te-laat-melden-datalek">a €475,000 fine</a> (558,000) against the hotel website Booking.com for waiting longer than 72 hours to report a data breach.</p><div id="46fa" class="link-block"> <a href="https://www.natlawreview.com/article/bookingcom-fined-dutch-dpa-breach-notice-delay"> <div> <div> <h2>Booking.com Fined By Dutch DPA For Breach Notice Delay</h2> <div><h3>The Dutch Data Protection Authority recently imposed a €475,000 fine (558,000) against the hotel website Booking.com…</h3></div> <div><p>www.natlawreview.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*jg1iJ_sQYGF43kRd)"></div> </div> </div> </a> </div><p id="996c">Singapore. Organization that oversees Tafep fined 29,000 over data breach.</p><div id="98c3" class="link-block"> <a href="https://www.straitstimes.com/tech/tech-news/organisation-that-oversees-tafep-fined-29000-over-data-breach"> <div> <div> <h2>Organisation that oversees Tafep fined 29,000 over data breach</h2> <div><h3>The Tripartite Alliance Limited (TAL) has been fined 29,000 after the data of about 20,000 people was accessed by…</h3></div> <div><p>www.straitstimes.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*tHiJ9t6DCkRYKAc1)"></div> </div> </div> </a> </div><p id="9c12">Google case accusing the company of illegally tracking millions of iPhone users is going to the US Supreme Court.</p><div id="a948" class="link-block"> <a href="https://www.bbc.com/news/technology-56901364"> <div> <div> <h2>Google data case to be heard in Supreme Court</h2> <div><h3>By Jane Wakefield Technology reporter A landmark case alleging Google illegally tracked millions of iPhone users is set…</h3></div> <div><p>www.bbc.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VIvFqiOtda7aSfKf)"></div> </div> </div> </a> </div><p id="f437">Geico sued over breach.</p><div id="7b8d" class="link-block"> <a href="https://www.law360.com/articles/1378510/geico-hit-with-consumer-suit-over-data-breach"> <div> <div> <h2>Geico Hit With Consumer Suit Over Data Breach - Law360</h2> <div><h3>Law360 (April 26, 2021, 4:40 PM EDT) -- A California couple has hit Geico with a proposed class action in federal court…</h3></div> <div><p>www.law360.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*ifMPUOsyBXvYMVqK)"></div> </div> </div> </a> </div><p id="0387">Police Sue Pension Unit Of Equiniti For £1M Over Data Breach</p><div id="5705" class="link-block"> <a href="https://www.law360.com/articles/1379019/police-sue-pension-unit-of-equiniti-for-1m-over-data-breach"> <div> <div> <h2>Police Sue Pension Unit Of Equiniti For £1M Over Data Breach - Law360</h2> <div><h3>More than 470 police officers have sued the pensions unit of Equiniti Group PLC for more than £1 million (1.4 million)…</h3></div> <div><p>www.law360.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*zr5gO05yoJEhYXH6)"></div> </div> </div> </a> </div><p id="66f9">Patient represented by Philadelphia law firm sues Einstein over 2020 data breach.</p><div id="2ec4" class="link-block"> <a href="https://www.bizjournals.com/philadelphia/news/2021/04/28/einstein-healthcare-network-data-breach-lawsuit.html"> <div> <div> <h2>Einstein Healthcare Network sued following 2020 data breach incident - Philadelphia Business…</h2> <div><h3>A former Einstein Healthcare Network patient has initiated a class action lawsuit against the Philadelphia-based health…</h3></div> <div><p>www.bizjournals.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*UnXVGptWVR34BzQx)"></div> </div> </div> </a> </div><p id="0e11">Class action lawsuit over Einstein breach.</p><div id="3f51" class="link-block"> <a href="https://healthitsecurity.com/news/breach-victims-file-class-action-lawsuit-against-einstein-healthcare"> <div> <div> <h2>Breach Victims File Class Action Lawsuit Against Einstein Healthcare</h2> <div><h3>Einstein Healthcare Network is facing a class-action lawsuit, following the August 2020 hack of several employee email…</h3></div> <div><p>healthitsecurity.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*ieM2bPQbJuoPp88h)"></div> </div> </div> </a> </div><p id="391d"><b>Laws &amp; Legal</b></p><p id="ae97">Justice Department to undertake 120 day review of cybersecurity challenges</p><div id="a8db" class="link-block"> <a href="https://thehill.com/policy/cybersecurity/551195-justice-department-to-undertake-120-day-review-of-cybersecurity"> <div> <div> <h2>Justice Department to undertake 120 day review of cybersecurity challenges</h2> <div><h3>Newly confirmed Deputy Attorney General Lisa Monaco announced the review during virtual remarks at the Munich Cyber…</h3></div> <div><p>thehill.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*qqT3f22dUhhPpuk0)"></div> </div> </div> </a> </div><p id="fe25">Senators from both sides of the political aisle introduced several bills late last week aimed at strengthening the government’s cybersecurity readiness and response efforts.</p><div id="6364" class="link-block"> <a href="https://www.nextgov.com/cybersecurity/2021/04/senators-introduce-fresh-slate-cybersecurity-centered-bills/173613/"> <div> <div> <h2>Senators Introduce Fresh Slate of Cybersecurity-Centered Bills</h2> <div><h3>Senators from both sides of the political aisle introduced several bills late last week aimed at strengthening the…</h3></div> <div><p>www.nextgov.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*bqRO7nbUPQgX1Ss-)"></div> </div> </div> </a> </div><p id="ad18">State Department Gets Dedicated Cybersecurity Bureau in Proposed Bill</p><div id="d218" class="link-block"> <a href="https://www.msspalert.com/cybersecurity-markets/americas/us-department-of-state-legislation/"> <div> <div> <h2>State Dept Gets Dedicated Cybersecurity Bureau in Newly Proposed Bill - MSSP Alert</h2> <div><h3>A bipartisan measure that would give U.S. cybersecurity a more prominent presence within the State Department and on…</h3></div> <div><p>www.msspalert.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*WMPGX_UF5P4ef8NY)"></div> </div> </div> </a> </div><p id="ceb0">New Georgia Bills Will Affect Public’s Access To Cybersecurity Details:</p><blockquote id="e58d"><p><a href="https://gov.georgia.gov/document/2021-signed-legislation/hb-156/download">Georgia House Bill 156,</a> signed by Gov. Brian Kemp in late March, “increases data sharing between different parts of government about data breaches and cyber-attacks,” according to Sarah Brewerton-Palmer, chair of the Georgia First Amendment Foundation’s Legislative Committee.</p></blockquote><blockquote id="2f4a"><p>However, Brewerton-Palmer is concerned the bill could exempt an entire report about cybersecurity breaches from the Open Records Act depending on the interpretation of the law.</p></blockquote><p id="5625">One concern about not understanding how systems are breached could relate to breaches of voting systems to change the outcome of elections. If the people in power control access to the information about data breaches of election systems, no one will be able to prove they hacked the systems to keep themselves in power. I’m not saying in any way this is happening, but it is a potential problem.</p><div id="7fad" class="link-block"> <a href="https://gradynewsource.uga.edu/new-georgia-bills-will-affect-publics-access-to-cybersecurity-details/"> <div> <div> <h2>New Georgia Bills Will Affect Public's Access to Cybersecurity Details</h2> <div><h3>Georgia House Bill 156, signed by Gov. Brian Kemp in late March, "increases data sharing between different parts of…</h3></div> <div><p>gradynewsource.uga.edu</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*-Meoe1fZVxE05N-0)"></div> </div> </div> </a> </div><p id="e78e">Debate continues over the ability to initiate a lawsuit based on potential identity theft in the future leveraging the stolen data. Given the number of ways stolen data is used to try to break into other systems and instantiate many types of fraud, monetary, and data loss including the recent barrage of fraud related to unemployment benefits, it is not clear why this is in question. It will be nearly impossible to link future harm to a specific breach because there are so many — but companies who blatantly disregard best security practices still need to be held accountable.</p><div id="fe7d" class="link-block"> <a href="https://www.reuters.com/article/us-otc-databreach/in-major-ruling-2nd-circuit-says-no-circuit-split-on-data-breaches-and-standing-idUSKBN2CD2I4"> <div> <div> <h2>In major ruling, 2nd Circuit says no circuit split on data breaches and standing</h2> <div><h3>For years, I've been writing about a split among the federal circuits on whether data breach victims can establish a…</h3></div> <div><p>www.reuters.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*ivDIWwBhmxc9Oo9s)"></div> </div> </div> </a> </div><div id="f183" class="link-block"> <a href="https://www.natlawreview.com/article/wait-what-ninth-circuit-affirms-dismissal-data-breach-litigation-deficient-damages"> <div> <div> <h2>Wait, What?! Ninth Circuit Affirms Dismissal of Data Breach Litigation for Deficient Damages…</h2> <div><h3>in a break with a recent streak of plaintiff-friendly rulings, the Ninth Circuit recently sided with a defendant in…</h3></div> <div><p>www.natlawreview.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*w7LfpWjQ_PIGm10b)"></div> </div> </div> </a> </div><div id="d7be" class="link-block"> <a href="https://www.natlawreview.com/article/district-court-third-circuit-confirms-when-it-comes-to-data-breaches-actual-misuse"> <div> <div> <h2>District Court in Third Circuit Confirms That, When it Comes to Data Breaches, Actual Misuse Must…</h2> <div><h3>Every federal lawsuit requires standing for the court to have subject matter jurisdiction to hear the case, and…</h3></div> <div><p>www.natlawreview.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*LdhFJ3mBcLiQiKF9)"></div> </div> </div> </a> </div><p id="5603">Senate Intelligence Panel working on data breach notification law.</p><div id="aa84" class="link-block"> <a href="https://thehill.com/policy/cybersecurity/550543-senate-intelligence-panel-working-on-legislation-around-mandatory-cyber"> <div> <div> <h2>Senate Intelligence panel working on legislation around mandatory cyber breach notification</h2> <div><h3>The Senate Intelligence Committee is working on a bill to create some form of limited data breach mandatory reporting…</h3></div> <div><p>thehill.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*de-IOKhUwvpkz24t)"></div> </div> </div> </a> </div><p id="7d85">When data breaches and laws impact freedom of the press.</p><div id="0c4a" class="link-block"> <a href="https://www.voanews.com/press-freedom/election-data-breach-story-renews-press-freedom-debate-albania"> <div> <div> <h2>Election Data Breach Story Renews Press Freedom Debate in Albania</h2> <div><h3>TIRANA, ALBANIA - First came the news that the personal data of over 900,000 Albanians might be in the hands of party…</h3></div> <div><p>www.voanews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*lGPt2AUYMuc81Yer)"></div> </div> </div> </a> </div><p id="c203">The National Association of Insurance Commissioner (NAIC)’s model data security law (“Model Law”) was recently adopted by Maine and North Dakota.</p><div id="d278" class="link-block"> <a href="https://www.mondaq.com/unitedstates/security/1061668/two-more-states-adopt-naic-model-data-security-law"> <div> <div> <h2>Two More States Adopt NAIC Model Data Security Law - Technology - United States</h2> <div><h3>United States: Two More States Adopt NAIC Model Data Security Law The National Association of Insurance Commissioner…</h3></div> <div><p>www.mondaq.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*mzuq_kKk79FhEV4u)"></div> </div> </div> </a> </div><p id="781f"><b>Investments</b></p><div id="4012" class="link-block"> <a href="https://www.cnbc.com/2021/04/26/thoma-bravo-purchase-of-proofpoint-marks-top-private-equity-cloud-deal.html"> <div> <div> <h2>Thoma Bravo's 12.3 billion purchase of Proofpoint is the largest private equity cloud deal</h2> <div><h3>Even with private equity firms spending record amounts of cash for software in recent years, Thoma Bravo just trumped…</h3></div> <div><p>www.cnbc.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*StrEMU5qz20HTSM_)"></div> </div> </div> </a> </div><p id="0b78">Be careful with buzzwords.</p><div id="e345" class="link-block"> <a href="https://venturebeat.com/2021/04/28/viso-trust-assesses-third-party-cybersecurity-risk-with-ai-raises-3m/"> <div> <div> <h2>Viso Trust assesses third-party cybersecurity risk with AI, raises 3M</h2> <div><h3>Viso Trust, a platform that uses AI to perform cyber risk assessments, today announced it has raised 3 million. The…</h3></div> <div><p>venturebeat.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*p1-0Ex0hDqSiPTHF)"></div> </div> </div> </a> </div><div id="acca" class="link-block"> <a href="https://venturebeat.com/2021/04/29/ai-powered-cybersecurity-platform-vectra-ai-raises-130m/"> <div> <div> <h2>AI-powered cybersecurity platform Vectra AI raises 130M</h2> <div><h3>San Jose, California-based cybersecurity startup Vectra AI today announced it has raised 130 million in a funding…</h3></div> <div><p>venturebeat.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*wlnDR-SPYMXIllY_)"></div> </div> </div> </a> </div><div id="c959" class="link-block"> <a href="https://www.zdnet.com/article/accenture-acquires-french-cybersecurity-firm-openminded/"> <div> <div> <h2>Accenture acquires French cybersecurity firm Openminded | ZDNet</h2> <div><h3>Accenture has announced its intention to acquire French cybersecurity firm Openminded. Announced on Thursday, the…</h3></div> <div><p>www.zdnet.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VUi_piN9LlH-jWQs)"></div> </div> </div> </a> </div><blockquote id="62be"><p>Mexico City, Mexico — Banco Santander México has announced an investment of 500 million USD in the country to improve infrastructure and service to customers. In a press conference, the bank said the money will be invested in its infrastructure, systems and cybersecurity to improve its customer experience.</p></blockquote><p id="7b55">Personal note: The last time I tried to send money to Mexico, which I admit was years ago so I hope it improved, I was informed not to do a bank transfer because you could kiss the money goodbye. Additionally, you could only use one of the Western Union options. I picked the correct option and despite that, the money was sent the wrong way, and 900 was “lost”. I argued with someone in Texas incessantly until I got it back. There likely is more to this problem than “infrastructure.”</p><div id="01d7" class="link-block"> <a href="https://www.riviera-maya-news.com/banco-santander-mexico-to-invest-500-million-in-infrastructure-cybersecurity/2021.html"> <div> <div> <h2>Banco Santander México to invest 500 million in infrastructure, cybersecurity - Riviera Maya News</h2> <div><h3>Mexico City, Mexico - Banco Santander México has announced an investment of 500 million USD in the country to improve…</h3></div> <div><p>www.riviera-maya-news.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*KWvm0iyCH8QIP8eg)"></div> </div> </div> </a> </div><p id="728b">Big cybersecurity startups like Tanium, Netskope, and SentinelOne are dragging their heels ongoing public because they don’t need the money or the trouble.</p><div id="b91f" class="link-block"> <a href="https://www.businessinsider.com/cybersecurity-startups-ipo-tanium-netskope-sentinelone-2021-4"> <div> <div> <h2>Big cybersecurity startups like Tanium, Netskope, and SentinelOne are dragging their heels on going…</h2> <div><h3>Cybersecurity startups like Netskope, Tanium, and SentinelOne are taking longer to go public. Cybersecurity - a $148…</h3></div> <div><p>www.businessinsider.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*NjanmpLuaAmtMSsM)"></div> </div> </div> </a> </div><p id="b6c6">Follow for updates.</p><p id="4a3a">Teri Radichel | <i>© <a href="https://2ndsightlab.com/?source=post_page---------------------------">2nd Sight Lab</a> 2021</i></p><div id="8b5f"><pre><span class="hljs-section">About Teri Radichel:

⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab</pre></div><div id="caae"><pre><span class="hljs-section">Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</span>
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation</pre></div><div id="3b5e"><pre>Follow <span class="hljs-keyword">for</span> more stories like <span class="hljs-keyword">this</span>:

❤️ Sign Up my Medium Email List ❤️ Twitter: <span class="hljs-meta">@teriradichel</span> ❤️ LinkedIn: https:<span class="hljs-comment">//www.linkedin.com/in/teriradichel</span> ❤️ Mastodon: <span class="hljs-meta">@teriradichel</span><span class="hljs-meta">@infosec</span>.exchange ❤️ Facebook: 2nd Sight Lab ❤️ YouTube: @2ndsightlab</pre></div><figure id="5610"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*H9Ew1KCl-29nZiPR.jpeg"><figcaption></figcaption></figure></article></body>

Cybersecurity News: April 24 –April 30, 2021

2nd Sight Lab cloud security news and notable cyber security industry information for the week of April 24 — April 30, 2021

2nd Sight Lab | Cybersecurity | Vulnerabilities | Malware | Threat Reports | Breaches and Attacks | Cost of a Data Breach | Laws & Legal | Investments

Free Content on Jobs in Cybersecurity | Sign up for the Email List

2nd Sight Lab News

Teri Radichel, CEO of 2nd Sight Lab, will be presenting at CloudLIVE 2021 ~ a cloud security conference from CloudHealth by VMWare. This presentation will cover five top threats to your cloud and how to defend against them. Find out why breaches are occurring and more effective risk management strategies to defend against them. Register today!

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

If you like this blog, please clap, follow, join, or pass it on. Thanks! 👏

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

Cybersecurity

A group prepared a report with strategies for combatting ransomware. It has some interesting ideas which can be pursued to help reduce the impact of this problem. However, it doesn’t provide a solution to a critical element of the problem: Organizations need to better secure their systems.

Much of the report seems to recommend more committees and slips in a recommendation that sounds like a proposal to provide funds to organizations that have been attacked by ransomware. If that is the correct interpretation that action will, ironically, reduce the urgency for organizations to improve system security because if they get attacked, they know they will get money to deal with it.

Governments should establish Cyber Response and Recovery Funds to support ransomware response and other cybersecurity activities;

Taxpayers may not want to pay to bail out organizations that have not properly invested in effective cybersecurity solutions after they are attacked by ransomware. A proactive strategy is better than a reactive strategy as explained in this post: Defensive cybersecurity strategies -> Don’t let the attacker get the ball.

Perhaps funds should be provided in advance to organizations that cannot afford to prepare for ransomware such as schools and underfunded medical facilities. The funds could go towards training to help companies understand cybersecurity fundamentals construct proper networks and implement secure systems — not for buying cyber insurance, paying ransoms, and purchasing ineffective products. The money could also go to research and development to come up with new provable security solutions and effective risk management, topics in this book on cybersecurity for executives.

Although I’m supportive of taking down criminals and networks carrying out these attacks, complications exist when it comes to taking down networks and prosecuting hackers in foreign countries. The effectiveness may also be short-lived as soon as one attacker network gets shut down, another will spring up. The attackers are largely outside the jurisdiction of US law enforcement. Indictments will have little effect in some cases. Efforts in this area will help but not completely solve the problem.

Until companies address ineffective strategies used for cybersecurity, ransomware attacks will continue to harm organizations, national security, jobs, healthcare patients, and the economy. Executives need to take greater responsibility to maintain secure systems.

The NSA has released a cybersecurity advisory with some tangible steps organizations can take to reduce cyber risk:

Stop Malicious Cyber Activity Against Connected Operational Technology

Biden administration is preparing an order to improve cybersecurity in response to the SolarWinds attack.

Among other things, the draft order includes something similar to the National Transportation Safety Board, or NTSB, for cyber. Just as the NTSB inspects the wreckage of a plane and recovers black boxes to see if the crash requires a systematic fix, a cyber NTSB would potentially paw through code and data logs to discover the root causes that permitted a successful cyberattack.

We need to know what is causing the breaches to solve the root problems. That is also a topic of my talk at CloudLive. How can you defend against what you don’t understand? Notice how many cybersecurity reports in this news feed do not specify how the systems were breached.

Ransomware gangs are going to start informing companies of customers of data breaches if they don’t pay fast enough. This could lead to more data breach disclosures or at least faster disclosures or payments.

Engineers of physical infrastructure need to understand cybersecurity since much infrastructure involves systems connected to the Internet.

Good strategy though of course, the devil is in the details.

This 100-Day Plan, when viewed along with with the Federal Energy Regulatory Commission’s (FERC) December 17, 2020 Notice of Proposed Rulemaking (NOPR) to establish an incentive-based framework for utilities that voluntarily make cybersecurity investments that exceed the current mandatory Critical Infrastructure Protection (CIP) Reliability Standards, and the forthcoming Department of Homeland Security’s “60-day sprint” initiative focused on industrial control systems, signify a new and welcome trend in government support for critical infrastructure.

A student steals a teacher’s password, logs in, and changes grades. In response, UK is providing free cybersecurity training to teachers. Brilliant!

The agency responsible for developing and fielding defense systems for ballistic missiles — and recently hypersonic missiles — has failed to complete assessments since 2017 to identify cyber vulnerabilities and possible attack routes, the nonpartisan Government Accountability Office noted.

More of this, but suggest background checks.

The San Diego Workforce Partnership Thursday announced a two-year, $1.5 million grant from the James Irvine Foundation to fund CyberHire San Diego, a movement aimed at increasing the number of unemployed, underemployed and low-wage workers in quality cybersecurity careers.

Massachusetts expands K-12 cybersecurity training.

The University of New Hampshire is offering a free cybersecurity camp for high school students this summer.

In Wake of Recent Breaches, FAA Wants to Up Cybersecurity of National Airspace System

Is this supposed to say “vetted” instead of “vested?” Vetted by whom? Additional research is required before forming an opinion.

Creating safer cloud journeys with new security features and guidance for Google Cloud and Workspace

FBI-DHS-CISA Joint Advisory on Russian Foreign Intelligence Service Cyber Operations

Vulnerabilities

New Spectre-style hardware vulnerability discovered at University of Viginia.

Hackers exploiting Mac bug. Patch. Patrick Wardle of Jamf to the rescue again.

Malware

Cool. FBI teams up with ‘Have I Been Pwned’ by Troy Hunt to alert Emotet victims.

Cyberspies target military organizations with new Nebulae backdoor

Please don’t download “WhatsApp Pink.”

GitHub Explores New Anti-Malware Policy but the Community Expresses Concerns.

2nd Sight Lab leverages the ability to find tools on GitHub to perform assessments for customers more quickly. Some of these same tools get incorporated into systems that companies buy to perform security assessments. It’s hard to draw a line here. On the one hand it helps companies provide a service that helps other companies secure their systems by understanding the attacks. On the other hand, the code is out there for malicious actors as well. With bug bounties and more security research going on we’re probably better off with the code out in the open to inspect to understand how they work and create defenses based on indicators of compromise. Additionally, there’s a fine line between what is an offensive or defensive tool. Some can be used both ways to find flaws in systems — for good or for evil purposes.

WeSteal blatantly posting and selling malware. Here’s how it works:

WeSteal uses a simple but effective way to swipe cryptocurrency-receiving addresses: It rummages through clipboards, searching for strings matching Bitcoin and Ethereum wallet identifiers. When it finds them, WeSteal swaps out the legitimate wallet IDs in the clipboard with its own IDs. When a victim tries to paste the swapped wallet ID for a transaction, the funds get whisked off to the attacker’s wallet.

Threat actors are increasingly adopting Excel 4.0 documents as an initial stage vector to distribute malware such as ZLoader and Quakbot, according to new research.

Can you live without the macro?

Law enforcement automatically removing Emotet malware from victim machines.

Babuk ransomware authors claim they will shut down but will make the code public afterwards.

ToxicEye uses Telegram for command and control.

RotaJakiro: A long lived secret backdoor with 0 VT detection.

https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en

PortDoor Espionage Malware Takes Aim at Russian Defense Sector. RTF Document.

Threat Reports

Breaches and Attacks

West Nyack man loses $35,000 to scam that stemmed from malware subscription. Gave scammers his bank account to get a refund for a subscription. Never give your bank account. This highlights the fact that wire transfers at banks need an overhaul. So much risk related to that process.

https://bronx.news12.com/west-nyack-man-loses-35-000-to-scam-that-stemmed-from-malware-subscription

Experian API Exposed Credit Scores of Most Americans

Demirkapi found the Experian API could be accessed directly without any sort of authentication, and that entering all zeros in the “date of birth” field let him then pull a person’s credit score. He even built a handy command-line tool to automate the lookups, which he dubbed “Bill’s Cool Credit Score Lookup Utility.”

Chinese businessman admits smuggling U.S. marine tech to China.

Prosecutors said Northwestern Polytechnical University, a Chinese military research institute, tasked Qin with obtaining items used for anti-submarine warfare and that he obtained hydrophones for it from a U.S. manufacturer.

Cybersecurity breach closes Centennial schools in Portland, Oregon. Does not say how.

Saskatchewan Blue Cross shut down systems after discovering a breach. The company is still researching the cause.

Contact Tracing Data Breach Exposed Personal Data For Over 72K Pennsylvanians.

Apparently this was a case of “Here, take my data…” a topic in my upcoming talk at CloudLive.

Illinois attorney general’s office was warned about weak cybersecurity before ransomware attack.

Ransomware potentially linked to Russia

Digital Ocean billing data breach — does not say what flaw caused the breach or how it was fixed.

A data breach at the Wyoming Department of Health publicly exposed COVID-19, influenza and blood alcohol test data from more than a quarter of Wyomingites and some out of state residents, the department announced Tuesday.

The breach occurred when an employee erroneously uploaded files containing that data to the public code-hosting platform GitHub.

Proper network security architecture can help prevent this type of thing.

Software companies exposed to a breach of sensitive pitch information in breach related to exposed Azure storage account.

Reverb hacked. Didn’t say how.

Gyrodata Employee Data Breach. Doesn’t say how.

First Horizon breached. Customer funds stolen. Stolen credentials but doesn’t say how. Access issues also in my upcoming talk.

Disclosed breach after stolen database discovered.

Catholic Charities North Dakota target of a data breach. Suspicious activity related to email accounts. Not specific as to what the activity was or how the organization’s systems were compromised.

More suspicious email activity. Maryland Ortho Practice breach affects 125,000 people. Doesn’t provide specifics.

Personal information of 20 million BigBasket users is now available online for anyone to download and use from a breach that occurred on October 30, 2020.

Amazon warned this customer they had an open S3 bucket.

Suspicious email activity. Does not say how the attackers got in.

Human error causes a data breach at the Vermont Department of Labor. Report finds controls were adequate to find the error.

Ransomware group threatens DC police force with informant leak. This will likely put people’s health and lives at risk. Ransomware criminals have no concern whatsoever for the people they affect.

https://www.infosecurity-magazine.com/news/ransomware-group-dc-cops-informant/

Dutch government pauses coronavirus app over data leak fears.

The Dutch app uses “exposure notification” technology developed by Google and Apple that generates random codes that can be exchanged by phones whose users are close to one another for long enough to possibly transmit the virus.

According to the ministry, Google informed the government Wednesday it has fixed the issue. The Dutch government halted messages from the app for 48 hours to check if the leak has been fixed.

To research further:

Google said that random Bluetooth identifiers “on their own have no practical value to bad actors, and it is extremely unlikely that developers of pre-installed apps were aware of the inadvertent availability of those identifiers.”

Large data dump of billions of passwords and emails.

Hundreds of furious Football Index investors have their identities revealed by DCMS data breach after email in response to complaints about collapsed gambling platform was sent out with recipients’ names not hidden.

Not a good way to send out a breach notification, if that wasn’t clear.

Human error leads to private information about a crime sent to the wrong person. I’m a fan of making people log into systems to get their data instead of emailing sensitive information around. I’ll be writing about that in a future post.

Cost of a Data Breach

In early March, the New York State Department of Financial Services (“DFS”) entered into a consent order requiring Residential Mortgage Company to pay $1.5 million for failing to comply with Cybersecurity Regulation, Part 500 of Title 23 of the New York Code.

The Dutch Data Protection Authority recently imposed a €475,000 fine ($558,000) against the hotel website Booking.com for waiting longer than 72 hours to report a data breach.

Singapore. Organization that oversees Tafep fined $29,000 over data breach.

Google case accusing the company of illegally tracking millions of iPhone users is going to the US Supreme Court.

Geico sued over breach.

Police Sue Pension Unit Of Equiniti For £1M Over Data Breach

Patient represented by Philadelphia law firm sues Einstein over 2020 data breach.

Class action lawsuit over Einstein breach.

Laws & Legal

Justice Department to undertake 120 day review of cybersecurity challenges

Senators from both sides of the political aisle introduced several bills late last week aimed at strengthening the government’s cybersecurity readiness and response efforts.

State Department Gets Dedicated Cybersecurity Bureau in Proposed Bill

New Georgia Bills Will Affect Public’s Access To Cybersecurity Details:

Georgia House Bill 156, signed by Gov. Brian Kemp in late March, “increases data sharing between different parts of government about data breaches and cyber-attacks,” according to Sarah Brewerton-Palmer, chair of the Georgia First Amendment Foundation’s Legislative Committee.

However, Brewerton-Palmer is concerned the bill could exempt an entire report about cybersecurity breaches from the Open Records Act depending on the interpretation of the law.

One concern about not understanding how systems are breached could relate to breaches of voting systems to change the outcome of elections. If the people in power control access to the information about data breaches of election systems, no one will be able to prove they hacked the systems to keep themselves in power. I’m not saying in any way this is happening, but it is a potential problem.

Debate continues over the ability to initiate a lawsuit based on potential identity theft in the future leveraging the stolen data. Given the number of ways stolen data is used to try to break into other systems and instantiate many types of fraud, monetary, and data loss including the recent barrage of fraud related to unemployment benefits, it is not clear why this is in question. It will be nearly impossible to link future harm to a specific breach because there are so many — but companies who blatantly disregard best security practices still need to be held accountable.

Senate Intelligence Panel working on data breach notification law.

When data breaches and laws impact freedom of the press.

The National Association of Insurance Commissioner (NAIC)’s model data security law (“Model Law”) was recently adopted by Maine and North Dakota.

Investments

Be careful with buzzwords.

Mexico City, Mexico — Banco Santander México has announced an investment of $500 million USD in the country to improve infrastructure and service to customers. In a press conference, the bank said the money will be invested in its infrastructure, systems and cybersecurity to improve its customer experience.

Personal note: The last time I tried to send money to Mexico, which I admit was years ago so I hope it improved, I was informed not to do a bank transfer because you could kiss the money goodbye. Additionally, you could only use one of the Western Union options. I picked the correct option and despite that, the money was sent the wrong way, and $900 was “lost”. I argued with someone in Texas incessantly until I got it back. There likely is more to this problem than “infrastructure.”

Big cybersecurity startups like Tanium, Netskope, and SentinelOne are dragging their heels ongoing public because they don’t need the money or the trouble.

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2021

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab
Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation
Follow for more stories like this:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
❤️ Sign Up my Medium Email List
❤️ Twitter: @teriradichel
❤️ LinkedIn: https://www.linkedin.com/in/teriradichel
❤️ Mastodon: @teriradichel@infosec.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
Cybersecurity News
Cybersecurity
Malware
Cyber Law
Cyber Risk
Recommended from ReadMedium