avatarTeri Radichel

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

50406

Abstract

es serious SSRF flaw that exposed orgs' internal servers</h2> <div><h3>John Leyden 17 June 2021 at 15:03 UTC Updated: 17 June 2021 at 15:06 UTC DevSecOops Programming code-share platform…</h3></div> <div><p>portswigger.net</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Do4V9UTPY4QTb0-X)"></div> </div> </div> </a> </div><p id="c2a1"><b>Cisco Talos recently discovered an exploitable information disclosure vulnerability in EIP Stack Group OpENer’s Ethernet/IP UDP handler.</b></p><p id="0f9c">OpENer is an Ethernet/IP stack for I/O adapter devices that includes objects and services for making Ethernet/IP-compliant products, as defined in the ODVA specification.</p><div id="2842" class="link-block"> <a href="https://blog.talosintelligence.com/2021/06/vulnerability-spotlight-eip-stack-group.html"> <div> <div> <h2>Vulnerability Spotlight: EIP Stack Group OpENer information disclosure vulnerability</h2> <div><h3>Martin Zeiser of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw. Cisco Talos recently discovered an…</h3></div> <div><p>blog.talosintelligence.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*uNhfKphVhCUnQo-i)"></div> </div> </div> </a> </div><p id="43ca"><b>Update‌ ‌Your Chrome Browser to Patch Yet Another 0-Day Exploit‌ed ‌in‌-the‌-Wild</b></p><div id="4deb" class="link-block"> <a href="https://thehackernews.com/2021/06/update-your-chrome-browser-to-patch-yet.html"> <div> <div> <h2>Update‌ ‌Your Chrome Browser to Patch Yet Another 0-Day Exploit‌ed ‌in‌-the‌-Wild</h2> <div><h3>A new Chrome update has been released by Google to patch another zero-day flaw in the wild.</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*f5201-ybS-eVCeb_)"></div> </div> </div> </a> </div><p id="18ea"><b>Apple fixes ninth zero-day bug exploited in the wild this year</b></p><div id="e589" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/apple-fixes-ninth-zero-day-bug-exploited-in-the-wild-this-year/"> <div> <div> <h2>Apple fixes ninth zero-day bug exploited in the wild this year</h2> <div><h3>Apple has fixed two iOS zero-day vulnerabilities that "may have been actively exploited" to hack into older iPhone…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*ab3W7rxmp4UJDtnW)"></div> </div> </div> </a> </div><p id="4ab8"><b>Instagram‌ ‌Bug Allowed Anyone to View Private Accounts Without Following Them</b></p><div id="317f" class="link-block"> <a href="https://thehackernews.com/2021/06/instagram-bug-allowed-anyone-to-view.html"> <div> <div> <h2>Instagram‌ ‌Bug Allowed Anyone to View Private Accounts Without Following Them</h2> <div><h3>Instagram patched a new flaw that allowed anyone to see content posted by private accounts without following them.</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*-_sTPuGBiG9RJpuL)"></div> </div> </div> </a> </div><p id="3a56"><b>Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild</b></p><div id="3af0" class="link-block"> <a href="https://thehackernews.com/2021/06/apple-issues-urgent-patches-for-2-zero.html"> <div> <div> <h2>Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild</h2> <div><h3>Apple‌ ‌releases emergency patches for two zero-day vulnerabilities found in the wild</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*TtY_2mLi_l8SJnBQ)"></div> </div> </div> </a> </div><p id="6a4d"><b>Security researcher turns Apache Airflow into bug bounty cash cow</b></p><div id="bd2c" class="link-block"> <a href="https://portswigger.net/daily-swig/security-researcher-turns-apache-airflow-into-bug-bounty-cash-cow"> <div> <div> <h2>Security researcher turns Apache Airflow into bug bounty cash cow</h2> <div><h3>John Leyden 14 June 2021 at 15:55 UTC Updated: 14 June 2021 at 20:18 UTC 13,000 banked through scan and exploit attack…</h3></div> <div><p>portswigger.net</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*b7mndcLqkKVdiOrn)"></div> </div> </div> </a> </div><p id="7ce7"><b>Android screen lock protection thwarted by Facebook Messenger Rooms exploit</b></p><p id="6f7c">And people make fun of me because I refuse to use Facebook Messenger. As if they don’t have enough other ways to contact me.</p><div id="dd1a" class="link-block"> <a href="https://portswigger.net/daily-swig/android-screen-lock-protection-thwarted-by-facebook-messenger-rooms-exploit"> <div> <div> <h2>Android screen lock protection thwarted by Facebook Messenger Rooms exploit</h2> <div><h3>Adam Bannister 14 June 2021 at 12:40 UTC Updated: 14 June 2021 at 13:27 UTC Researcher earns 3,000 bug bounty after…</h3></div> <div><p>portswigger.net</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*AaA0UpcsFHxF6OZp)"></div> </div> </div> </a> </div><h1 id="1747">Malware</h1><p id="d8f4"></p><p id="191b"><b>Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise</b></p><div id="ec92" class="link-block"> <a href="https://www.fireeye.com/blog/threat-research/2021/06/darkside-affiliate-supply-chain-software-compromise.html"> <div> <div> <h2>Smoking Out a DARKSIDE Affiliate's Supply Chain Software Compromise</h2> <div><h3>Mandiant observed DARKSIDE affiliate UNC2465 accessing at least one victim through a Trojanized software installer…</h3></div> <div><p>www.fireeye.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*JI44C5ky0_t6bVIT)"></div> </div> </div> </a> </div><blockquote id="bd9e"><p>According to an incident response report published today, Mandiant said the malware was hidden inside a customized version of the <a href="https://us.dahuasecurity.com/?product=smartpss">Dahua SmartPSS</a> Windows app that the unnamed CCTV vendor was providing to its customers.</p></blockquote><blockquote id="e0c6"><p>If customers downloaded and installed the trojanized application, it would infect a company’s systems with a version of the <a href="https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html">SMOKEDHAM backdoor</a>.</p></blockquote><div id="0d3e" class="link-block"> <a href="https://therecord.media/darkside-operator-involved-in-supply-chain-attack-via-cctv-vendors-website/"> <div> <div> <h2>Darkside operator involved in supply chain attack via CCTV vendor’s website — The Record by…</h2> <div><h3>A cybercrime group that used to cooperate with the Darkside ransomware gang has breached the website of a CCTV camera…</h3></div> <div><p>therecord.media</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*4j_HmeSkQd---mI8)"></div> </div> </div> </a> </div><div id="dfea" class="link-block"> <a href="https://threatpost.com/millions-connected-cameras-eavesdropping/166950/"> <div> <div> <h2>Millions of Connected Cameras Open to Eavesdropping</h2> <div><h3>A supply-chain component lays open camera feeds to remote attackers thanks to a critical security vulnerability…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*OznPSDmJfyr7J6Gm)"></div> </div> </div> </a> </div><div id="4adf" class="link-block"> <a href="https://thehackernews.com/2021/06/critical-throughtek-flaw-opens-millions.html"> <div> <div> <h2>Critical ThroughTek Flaw Opens Millions of Connected Cameras to Eavesdropping</h2> <div><h3>Millions of connected cameras are exposed to eavesdropping by a ThroughTek vulnerability</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*wGAwH7U0siKRpfr-)"></div> </div> </div> </a> </div><p id="4c4c"><b>‘Oddball’ Malware Blocks Access to Pirated Software</b></p><p id="a960">Rather than steal credentials or hold data for ransom, a recent campaign observed by Sophos prevents people from visiting sites that offer illegal downloads.</p><div id="96a9" class="link-block"> <a href="https://threatpost.com/oddball-malware-blocks-pirated-software/167060/"> <div> <div> <h2>'Oddball' Malware Blocks Access to Pirated Software</h2> <div><h3>Rather than steal credentials or hold data for ransom, a recent campaign observed by Sophos prevents people from…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*gU3cQtn1jaYpKXll)"></div> </div> </div> </a> </div><div id="42d4" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/vigilante-malware-blocks-victims-from-downloading-pirated-software/"> <div> <div> <h2>Vigilante malware blocks victims from downloading pirated software</h2> <div><h3>A vigilante developer turns the tables on software pirates by distributing malware that prevents them from accessing…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*u1Lf7dcpIavkWi4N)"></div> </div> </div> </a> </div><p id="2596"><b>Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions</b></p><blockquote id="f05d"><p>The worm and ransomware scripts also use the API of the messaging application Telegram for command-and-control (C&C) communication.</p></blockquote><div id="47b7" class="link-block"> <a href="https://www.trendmicro.com/en_us/research/21/f/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions.html"> <div> <div> <h2>Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions</h2> <div><h3>We investigate how certain hacking tools are used to move laterally on victims' networks to deploy ransomware. These…</h3></div> <div><p>www.trendmicro.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VtcTZyPQFUCoxsmH)"></div> </div> </div> </a> </div><p id="dc92"><b>Geek Squad Vishing Attack Bypasses Email Security to Hit 25K Mailboxes</b></p><p id="f66d">I mentioned on Twitter this week that parents of a friend of mine were impacted by this spam campaign. They called a number in the email to clear a fraudulent bill. The attacker instructs the victim to visit a website which downloads malware. The victim may then see the attacker taking actions on their computer. Past campaigns looked for stored passwords for banking sites to automatically login to access customer accounts.</p><div id="216f" class="link-block"> <a href="https://threatpost.com/geek-squad-vishing-bypasses-email-security/167014/"> <div> <div> <h2>Geek Squad Vishing Attack Bypasses Email Security to Hit 25K Mailboxes</h2> <div><h3>A pair of billing and tech support "vishing" attacks using Geek Squad and Norton Antivirus as cover managed to hit…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*7SwttlpKOceKw4PF)"></div> </div> </div> </a> </div><p id="9fa6"><b>Threat Actors Use Google Docs to Host Phishing Attacks</b></p><p id="0285">Using Google Drive to host malware is not new. The landing page may be different. The most recent message: “new rules for June 25.”</p><div id="861e" class="link-block"> <a href="https://threatpost.com/google-docs-host-attack/166998/"> <div> <div> <h2>Threat Actors Use Google Docs to Host Phishing Attacks</h2> <div><h3>Exploit in the widely used document service leveraged to send malicious links that appear legitimate but actually steal…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*LJRp5DA4frfHIlAY)"></div> </div> </div> </a> </div><p id="d452">“This Google Docs page may look familiar to those who share Google Docs outside of their organization. This, however, isn’t that page. It’s a custom HTML page made to look like that familiar Google Docs share page,” Avanan explained.</p><div id="b0f4" class="link-block"> <a href="https://www.infosecurity-magazine.com/news/novel-phishing-attack-abuses/"> <div> <div> <h2>Novel Phishing Attack Uses Google Drive and Docs</h2> <div><h3>Enterprising cyber-criminals have found a way to create convincing phishing emails which abuse Google Docs and Drive…</h3></div> <div><p>www.infosecurity-magazine.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VHvmiZTOjZb2OFue)"></div> </div> </div> </a> </div><p id="15a3"><b>Hackers are using search engine optimization (SEO) to get high rankings for pages with malicious PDF files that steal credentials.</b></p><p id="a07f">Google and other search engines should be aware of this and help block this threat at the source.</p><div id="4ab3" class="link-block"> <a href="https://blog.malwarebytes.com/awareness/2021/06/polazert-trojan-using-poisoned-google-search-results-to-spread/"> <div> <div> <h2>Polazert Trojan using poisoned Google Search results to spread - Malwarebytes Labs</h2> <div><h3>Trojan.Polazert aka SolarMarker has gone back and fine-tuned an old tactic known as SEO-poisoning to plant their Remote…</h3></div> <div><p>blog.malwarebytes.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*GRMjxICrSAspgZSE)"></div> </div> </div> </a> </div><div id="98ef" class="link-block"> <a href="https://threatpost.com/rotten-pdfs-flood-web-password-snarfing/166932/"> <div> <div> <h2>Malicious PDFs Flood the Web, Lead to Password-Snarfing</h2> <div><h3>SolarMarker makers are using SEO poisoning, stuffing thousands of PDFs with tens of thousands of pages full of SEO…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*vfgNHQ7z2puwZh3s)"></div> </div> </div> </a> </div><div id="4833" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/microsoft-seo-poisoning-used-to-backdoor-targets-with-malware/"> <div> <div> <h2>Microsoft: SEO poisoning used to backdoor targets with malware</h2> <div><h3>Microsoft is tracking a series of attacks that use SEO poisoning to infect targets with a remote access trojan (RAT)…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*sQC33UiIG8CatL66)"></div> </div> </div> </a> </div><p id="d973"><b>Unique TTPs link Hades ransomware to new threat group</b></p><div id="4c31" class="link-block"> <a href="https://www.csoonline.com/article/3621764/unique-ttps-link-hades-ransomware-to-new-threat-group.html"> <div> <div> <h2>Unique TTPs link Hades ransomware to new threat group</h2> <div><h3>Researchers claim to have discovered the identity of the operators of Hades ransomware, exposing the distinctive…</h3></div> <div><p>www.csoonline.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*qZP6zLdDn4vBOiRG)"></div> </div> </div> </a> </div><div id="1fe8" class="link-block"> <a href="https://thehackernews.com/2021/06/experts-shed-light-on-distinctive.html"> <div> <div> <h2>Experts Shed Light On Distinctive Tactics Used by Hades Ransomware</h2> <div><h3>Experts‌ ‌Provide Insights Into The Distinctive Tactics Used By‌ ‌Hades‌ ‌ Ransomware</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*KWbS3kPUjw9Rh_Lf)"></div> </div> </div> </a> </div><p id="c96c"><b>NoxPlayer Supply-Chain Attack is Likely the Work of Gelsemium Hackers</b></p><div id="9d11" class="link-block"> <a href="https://thehackernews.com/2021/06/noxplayer-supply-chain-attack-is-likely.html"> <div> <div> <h2>NoxPlayer Supply-Chain Attack is Likely the Work of Gelsemium Hackers</h2> <div><h3>Hackers behind the NoxPlayer supply-chain attack are likely to be Gelsemium hackers.</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*9MneBPZkbvYRUhDl)"></div> </div> </div> </a> </div><p id="62c5"><b>A New Spyware is Targeting Telegram and Psiphon VPN Users in Iran</b></p><div id="ed6a" class="link-block"> <a href="https://thehackernews.com/2021/06/a-new-spyware-is-targeting-telegram-and.html"> <div> <div> <h2>A New Spyware is Targeting Telegram and Psiphon VPN Users in Iran</h2> <div><h3>A spyware in a 6-year-old Ferocious Kitten covert surveillance campaign now targets Telegram and Psiphon VPN users in…</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*3lAINrWOl8JJ2jY4)"></div> </div> </div> </a> </div><div id="ed92" class="link-block"> <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/"> <div> <div> <h2>Ferocious Kitten: 6 years of covert surveillance in Iran</h2> <div><h3>Ferocious Kitten is an APT group that since at least 2015 has been targeting Persian-speaking individuals who appear to…</h3></div> <div><p>securelist.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*86eWuPU7X5vUQT9-)"></div> </div> </div> </a> </div><p id="aab4"><b>Researchers Uncover ‘Process Ghosting’ — A New Malware Evasion Technique</b></p><div id="3e02" class="link-block"> <a href="https://thehackernews.com/2021/06/researchers-uncover-process-ghosting.html"> <div> <div> <h2>Researchers Uncover 'Process Ghosting' - A New Malware Evasion Technique</h2> <div><h3>A new malware evasion technique has been discovered by researchers - 'Process Ghosting'</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*sVKPrIye2IZCYANg)"></div> </div> </div> </a> </div><p id="ebfe"><b>Tinder spam campaign hides “handwritten” links in profile images</b></p><div id="ea3d" class="link-block"> <a href="https://www.bleepingcomputer.com/news/technology/tinder-spam-campaign-hides-handwritten-links-in-profile-images/"> <div> <div> <h2>Tinder spam campaign hides "handwritten" links in profile images</h2> <div><h3>A new trend has emerged on dating apps like Tinder with spammers sneaking in links within profile images. Multiple such…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*2vxx6glKJT8ZCXAn)"></div> </div> </div> </a> </div><h1 id="9a83">Threat Reports</h1><p id="3a85"></p><p id="9d57"><b>Report: Active Directory Certificate Services a big security blindspot on enterprise networks</b></p><p id="fc5e">True. Organizations need to understand <i>all</i> the places where systems or individuals are granted privileges on their network.</p><div id="180a" class="link-block"> <a href="https://www.csoonline.com/article/3622352/report-active-directory-certificate-services-a-big-security-blindspot-on-enterprise-networks.html"> <div> <div> <h2>Active Directory Certificate Services a big security blindspot</h2> <div><h3>As the core of Windows enterprise networks, Active Directory, the service that handles user and computer authentication…</h3></div> <div><p>www.csoonline.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*sC5-wjyxI6fpHyCR)"></div> </div> </div> </a> </div><p id="68ca"><b>Booming Cyber-Underground Market for Initial-Access Brokers</b></p><p id="808e">Ransomware gangs are increasingly buying their way into corporate networks, purchasing access from ‘vendors’ that have previously installed backdoors on targets.</p><div id="9d80" class="link-block"> <a href="https://threatpost.com/booming-cyber-underground-market-initial-access-brokers/166965/"> <div> <div> <h2>Researchers: Booming Cyber-Underground Market for Initial-Access Brokers</h2> <div><h3>It’s well known that email is often the gateway for cybercriminals looking to infiltrate a corporate network. But…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*OM9RT1I3PTKIffwh)"></div> </div> </div> </a> </div><p id="f7bd"><b>80 % of Ransomware Victims don’t pay. 80% of those who do are hit with a second attack.</b></p><div id="98de" class="link-block"> <a href="https://threatpost.com/ransomware-victims-dont-pay-up/166989/"> <div> <div> <h2>Exclusive Ransomware Poll: 80% of Victims Don’t Pay Up | Threatpost</h2> <div><h3>Meanwhile, in a separate survey, 80 percent of organizations that paid the ransom said they were hit by a second…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*aXiLk0rd81pAPxSw)"></div> </div> </div> </a> </div><p id="9f14">An analysis that Kroll conducted of data breach notifications in 2020 showed a sharp increase in attacks against organizations in what it identified as six traditionally “under-attacked” industries — food and beverage, utilities, construction, entertainment, agriculture, and recreation.</p><div id="1058" class="link-block"> <a href="https://www.darkreading.com/attacks-breaches/accidental-insider-leaks-prove-major-source-of-risk/d/d-id/1341343"> <div> <div> <h2>Accidental Insider Leaks Prove Major Source of Risk</h2> <div><h3>While malicious insiders often make headlines, most enterprise data leaks are accidental - caused by end users who fail…</h3></div> <div><p>www.darkreading.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*0Aq-JNpIL1WG1UBQ)"></div> </div> </div> </a> </div><p id="2747"><b>An analysis that Kroll conducted of data breach notifications in 2020 showed a sharp increase in attacks against organizations in what it identified as six traditionally “under-attacked” industries — food and beverage, utilities, construction, entertainment, agriculture, and recreation.</b></p><div id="6a5f" class="link-block"> <a href="https://beta.darkreading.com/attacks-breaches/data-breaches-surge-in-food-beverage-other-industries"> <div> <div> <h2>Dark Reading | Security | Protect The Business</h2> <div><h3>Though no industry is immune from cyberattacks, a few have traditionally been less affected by them than others. A new…</h3></div> <div><p>beta.darkreading.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div> </div> </div> </a> </div><p id="0e56"><b>VPNs and Trust</b></p><p id="2203">Good read and thoughts.</p><div id="8433" class="link-block"> <a href="https://www.schneier.com/blog/archives/2021/06/vpns-and-trust.html"> <div> <div> <h2>Schneier on Security</h2> <div><h3>TorrentFreak surveyed nineteen VPN providers, asking them questions about their privacy practices: what data they keep…</h3></div> <div><p>www.schneier.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Aag1ZevLXikTviSh)"></div> </div> </div> </a> </div><p id="ef71"><b>Thousands of publicly accessible VMware vCenter Servers vulnerable to critical flaws</b></p><div id="a825" class="link-block"> <a href="https://www.csoonline.com/article/3621785/thousands-of-publicly-accessible-vmware-vcenter-servers-vulnerable-to-critical-flaws.html"> <div> <div> <h2>Thousands of publicly accessible VMware vCenter Servers vulnerable to critical flaws</h2> <div><h3>Three weeks after releasing patches for a critical vulnerability in VMware vCenter, thousands of servers that are…</h3></div> <div><p>www.csoonline.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*heSvajj6I6PzNkiN)"></div> </div> </div> </a> </div><p id="1cde"><b>Multi Perimeter Device Exploit Mirai Version Hunting For Sonicwall, DLink, Cisco and more</b></p><div id="d0df" class="link-block"> <a href="https://isc.sans.edu/forums/diary/Multi+Perimeter+Device+Exploit+Mirai+Version+Hunting+For+Sonicwall+DLink+Cisco+and+more/27528/"> <div> <div> <h2>diary</h2> <div><h3>SANS Internet Storm Center - A global cooperative cyber threat / internet security monitor and alert system. Featuring…</h3></div> <div><p>isc.sans.edu</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*bB1JTsCdiOU00PhW)"></div> </div> </div> </a> </div><p id="ef99"><b>Cyber espionage by Chinese hackers in neighbouring nations is on the rise</b></p><p id="7551">Source is a report from Recorded Future.</p><div id="3a6c" class="link-block"> <a href="https://thehackernews.com/2021/06/cyber-espionage-by-chinese-hackers-in.html"> <div> <div> <h2>Cyber espionage by Chinese hackers in neighbouring nations is on the rise</h2> <div><h3>Researchers warn of growing cyber espionage activities by China-backed PLA unit 69010 hackers in neighbouring nations.</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*IugYM3tYYjSFyBmd)"></div> </div> </div> </a> </div><div id="f750" class="link-block"> <a href="https://securityaffairs.co/wordpress/119135/apt/redfoxtrot-operations-linked-to-chinas-pla-unit-69010-due-to-bad-opsec.html"> <div> <div> <h2>RedFoxtrot operations linked to China's PLA Unit 69010 due to bad opsec - Security Affairs</h2> <div><h3>Experts from Recorded Future's Insikt Group linked a series of attacks, part of RedFoxtrot China-linked campaigns, to…</h3></div> <div><p>securityaffairs.co</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*yuZOl-3Od3O75df2)"></div> </div> </div> </a> </div><p id="ce55"><b>CrowdStrike 2021 Global Threat Report</b></p><div id="e8d4" class="link-block"> <a href="https://go.crowdstrike.com/crowdstrike-global-threat-report-2021.html"> <div> <div> <h2>2021 CrowdStrike Global Threat Report</h2> <div><h3>The 2021 CrowdStrike® Global Threat Report is a compressive analysis of the top cyber threats that occurred last year…</h3></div> <div><p>go.crowdstrike.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*eCHO9w2pBLXhe0tx)"></div> </div> </div> </a> </div><p id="2493"><b>Molerats Hackers Return With New Attacks Targeting Middle Eastern Governments</b></p><div id="2e6e" class="link-block"> <a href="https://thehackernews.com/2021/06/molerats-hackers-return-with-new.html"> <div> <div> <h2>Molerats Hackers Return With New Attacks Targeting Middle Eastern Governments</h2> <div><h3>TA402 Molerats hacker group has returned with new attacks that target governments in the Middle East</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*w7FdwKjilKYvMiuq)"></div> </div> </div> </a> </div><h1 id="49b4">Breaches & Attacks</h1><p id="cb2d">_____________________________________________</p><p id="c269"><b>Poland blames Russia for breach, theft of Polish officials’ emails</b></p><div id="0c4b" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/poland-blames-russia-for-breach-theft-of-polish-officials-emails/"> <div> <div> <h2>Poland blames Russia for breach, theft of Polish officials' emails</h2> <div><h3>Poland's deputy prime minister Jarosław Kaczyński says last week's breach of multiple Polish officials' private email…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Y_70_6TV8GQA71Wo)"></div> </div> </div> </a> </div><p id="df50"><b>Chinese Hackers Believed to be Behind Second Cyberattack on Air India</b></p><div id="e5d2" class="link-block"> <a href="https://thehackernews.com/2021/06/chinese-hackers-believed-to-be-behind.html"> <div> <div> <h2>Chinese Hackers Believed to be Behind Second Cyberattack on Air India</h2> <div><h3>Another cyberattack is suspected to have taken place on Air India by Chinese hackers</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VchcTqoq33N-LsPR)"></div> </div> </div> </a> </div><p id="c233"><b>Woman sentenced for embezzling more than half a million dollars from employer</b></p><p id="7388">Make sure your systems and processes are designed to precent insider theft. I talk about the concept of trust in my book and this applies to this particular story. It took too long to uncover this theft.</p><blockquote id="43f3"><p>As described in court documents and testimony, Taylor was employed at an Augusta medical practice from 2006 to 2020 as the office and payroll manager. The year after she was hired, Taylor began stealing from her employer by inflating her own pay and writing unauthorized company checks which she deposited in her own account or used to pay her mortgage.</p></blockquote><div id="659d" class="link-block"> <a href="https://www.justice.gov/usao-sdga/pr/woman-sentenced-embezzling-more-half-million-dollars-employer"> <div> <div> <h2>Woman sentenced for embezzling more than half a million dollars from employer</h2> <div><h3>AUGUSTA, GA: The former office manager for an Augusta medical practice has been sentenced after admitting she stole…</h3></div> <div><p>www.justice.gov</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*-9sxMCwMlboshYCL)"></div> </div> </div> </a> </div><p id="20b2"><b>Critical entities targeted in suspected Chinese cyber spying via Pulse Connect Secure networking devices</b></p><blockquote id="e0d9"><p>The hack of Pulse Connect Secure networking devices <a href="https://apnews.com/article/china-business-government-and-politics-europe-1939a15b8b929d55b77293710d13c6c2">came to light</a> in April, but its scope is only now starting to become clear. The Associated Press has learned that the hackers targeted telecommunications giant Verizon and the country’s largest water agency. News broke earlier this month that the <a href="https://apnews.com/article/hacking-business-technology-df0c04d214044b998b6936c8383e80b9">New York City subway system</a>, the country’s largest, was also breached.</p></blockquote><blockquote id="ced4"><p>In the Pulse campaign, security experts said sophisticated hackers exploited never-before-seen vulnerabilities to break in and were hyper diligent in trying to cover their tracks once inside.</p></blockquote><p id="09a3">If you are using a VPN device on a well-designed network, you’re limiting the potential scope of attack. However, you need to focus a lot of time monitoring and securing your VPN as that will be the primary target of attack (as expected, because it is the only way in if designed correctly).</p><div id="e713" class="link-block"> <a href="https://apnews.com/article/government-and-politics-hacking-technology-business-7350235e07d46ba5afc1238b553ea4b9"> <div> <div> <h2>Critical entities targeted in suspected Chinese cyber spying</h2> <div><h3>RICHMOND, Va. (AP) - A cyberespionage campaign blamed on China was more sweeping than previously known, with suspected…</h3></div> <div><p>apnews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*qV6xeM11CPPEt5Se)"></div> </div> </div> </a> </div><p id="ab44"><b>North Korea Exploited VPN Flaw to Hack South’s Nuclear Research Institute</b></p><p id="01f8">VPN Flaw.</p><div id="aeeb" class="link-block"> <a href="https://thehackernews.com/2021/06/north-korea-exploited-vpn-flaw-to-hack.html"> <div> <div> <h2>North Korea Exploited VPN Flaw to Hack South's Nuclear Research Institute</h2> <div><h3>The South Korean government claims the North hacked its nuclear research institute</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*6kyGNeRI5aezxk7u)"></div> </div> </div> </a> </div><div id="6e0f" class="link-block"> <a href="https://thehackernews.com/2021/06/malware-attack-on-south-korean-entities.html"> <div> <div> <h2>Malware Attack on South Korean Entities Was Work of Andariel Group</h2> <div><h3>Andariel Group of hackers was responsible for the malware attack against South Korean entities</h3></div> <div><p>thehackernews.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*34Ru7kDG4qSFYCRH)"></div> </div> </div> </a> </div><div id="b2d8" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/south-koreas-nuclear-research-agency-hacked-using-vpn-flaw/"> <div> <div> <h2>South Korea's Nuclear Research agency hacked using VPN flaw</h2> <div><h3>South Korea's 'Korea Atomic Energy Research Institute' disclosed yesterday that their internal networks were hacked…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*bgDL3FaiuQ1wrEzc)"></div> </div> </div> </a> </div><p id="90d2"><b>CVS Health Records for 1.1 Billion Customers Exposed</b></p><blockquote id="cdfd"><p>likely because of a cloud-storage misconfiguration</p></blockquote><p id="a974"><a href="https://readmedium.com/cybersecurity-author-teri-radichel-bea5f6c8452f">Please see one of my many cloud security presentations and most appropriately, the last one I did at CloudLive, blog posts, or read my book</a>. I’ve explained how to prevent these issues numerous times.</p><div id="7a36" class="link-block"> <a href="https://threatpost.com/cvs-health-records-billion-customers-exposed/167011/"> <div> <div> <h2>CVS Health Records for 1.1 Billion Customers Exposed</h2> <div><h3>More than 1 billion records for CVS Health customers were left in the database of a third-party, unnamed vendor …</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*UkysjrnggdH4m1Z6)"></div> </div> </div> </a> </div><p id="b175"><b>More cloud data exposed: Cognyte, CVS, Wegmans</b></p><p id="f781">Security researchers and attackers are finding exposed data. Please refer to my comments on the last link and same comment for all cloud-exposed data below.</p><div id="5e81" class="link-block"> <a href="https://beta.darkreading.com/cloud/this-week-in-database-leaks-cognyte-cvs-wegmans"> <div> <div> <h2>Dark Reading | Security | Protect The Business</h2> <div><h3>Unsecured cloud-based databases continue to threaten corporate and consumer data, as indicated by a series of reports…</h3></div> <div><p>beta.darkreading.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div> </div> </div> </a> </div><p id="1c52"><b>Amazon Web Services Misconfiguration Exposes Half a Million Cosmetics Customers</b></p><p id="5cfd">A research team at reviews site WizCase traced the leaky Amazon S3 bucket to popular Turkish beauty products firm <a href="http://www.gercekkozmetik.com.tr/EN/cosmolog-cozmetik">Cosmolog Kozmetik</a>.</p><div id="94b8" class="link-block"> <a href="https://www.infosecurity-magazine.com/news/aws-misconfiguration-exposes/"> <div> <div> <h2>AWS Misconfiguration Exposes Half a Million Cosmetics Customers</h2> <div><h3>Hundreds of thousands of retail customers had their personal data exposed thanks to a misconfigured cloud storage…</h3></div> <div><p>www.infosecurity-magazine.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Jpiq4VwzwMYt3HGd)"></div> </div> </div> </a> </div><p id="3aab"><b>UK legal firm Gateley warns of data breach following cyber-attack</b></p><p id="3031">Not a lot of details as to what attackers did.</p><div id="2ca0" class="link-block"> <a href="https://portswigger.net/daily-swig/uk-legal-firm-gateley-warns-of-data-breach-following-cyber-attack"> <div> <div> <h2>UK legal firm Gateley warns of data breach following cyber-attack</h2> <div><h3>Adam Bannister 17 June 2021 at 10:17 UTC Updated: 17 June 2021 at 11:23 UTC 'Core systems' restored after unauthorized…</h3></div> <div><p>portswigger.net</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VfMUxkep416IDWVc)"></div> </div> </div> </a> </div><p id="a5fe"><b>Carnival Corp., the world’s largest cruise-ship operator, had another breach for the second time in a year</b></p><blockquote id="098d"><p>For the second time in a year, attackers have breached email accounts and accessed personal, financial and health information belonging to guests, employees and crew.</p></blockquote><p id="1312">Compromised email account.</p><div id="0d4b" class="link-block"> <a href="https://threatpost.com/carnival-cruise-cyberattack/167065/"> <div> <div> <h2>Carnival Cruise Cyber-Torpedoed by Cyberattack</h2> <div><h3>Carnival Corp., the world's largest cruise-ship operator, has sprung another leak: For the second time in a year…</h3></div> <div><p>threatpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*JkLndci2rLqMSe1N)"></div> </div> </div> </a> </div><div id="d2bd" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/carnival-cruise-hit-by-data-breach-warns-of-data-misuse-risk/"> <div> <div> <h2>Carnival Cruise hit by data breach, warns of data misuse risk</h2> <div><h3>Carnival Corporation, the world's largest cruise ship operator, has disclosed a data breach after attackers gained…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*gT5xamvKHE1Pc1Dg)"></div> </div> </div> </a> </div><p id="986a"><b>Volkswagen discloses data breach impacting 3.3 million Audi drivers</b></p><div id="94ce" class="link-block"> <a href="https://therecord.media/volkswagen-discloses-data-breach-impacting-3-3-million-audi-drivers/"> <div> <div> <h2>Volkswagen discloses data breach impacting 3.3 million Audi drivers - The Record by Recorded Future</h2> <div><h3>Volkswagen America said that a data breach at a third-party vendor it was using for sales and marketing purposes…</h3></div> <div><p>therecord.media</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*ytely9hfrQ3cMx5N)"></div> </div> </div> </a> </div><p id="3b85">Audi also affected.</p><div id="440d" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/audi-volkswagen-customer-data-being-sold-on-a-hacking-forum/"> <div> <div> <h2>Audi, Volkswagen customer data being sold on a hacking forum</h2> <div><h3>Audi and Volkswagen customer data is being sold on a hacking forum after allegedly being stolen from an exposed Azure…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*HL7dwxZib-skYEoL)"></div> </div> </div> </a> </div><blockquote id="ed7a"><p>The investigation confirmed that the third party obtained limited personal information.</p></blockquote><p id="2b4d">How? How did the information get disclosed? How can it be prevented by other companies? Breach notifications need to provide more information than what is included here.</p><p id="7b91"><a href="https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/06/Delaware-VWGoA-Notice-Letter.pdf">https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/06/Delaware-VWGoA-Notice-Letter.pdf</a></p><p id="6870"><b>Gateley suffers data breach following ‘cyber security incident’</b></p><div id="eaca" class="link-block"> <a href="https://www.globallegalpost.com/big-stories/gateley-suffers-data-breach-following-cyber-security-incident-89304426/"> <div> <div> <h2>Gateley suffers data breach following 'cyber security incident'</h2> <div><h3>16 June 2021 Firm says some client data was exposed but adds that the impact was limited UK listed law firm Gateley…</h3></div> <div><p>www.globallegalpost.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Js2Hh4AJ6W5qUhlZ)"></div>

Options

       </div>
        </div>
      </a>
    </div><p id="7917"><b>Alibaba data breach exposes 1.1 billion pieces of data</b></p><div id="73c5" class="link-block">
      <a href="https://www.itpro.co.uk/security/data-breaches/359897/alibaba-data-breach-exposes-11-billion-pieces-of-data">
        <div>
          <div>
            <h2>Alibaba data breach exposes 1.1 billion pieces of data | IT PRO</h2>
            <div><h3>Alibaba's shopping website Taobao was trawled for 8 months which resulted in over 1.1 billion pieces of user…</h3></div>
            <div><p>www.itpro.co.uk</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*T1dSv1b4apy47LGR)"></div>
          </div>
        </div>
      </a>
    </div><p id="ba00"><b>Elekta’s first-generation cloud-based storage system has experienced a data security incident. 170 customers in North America using the impacted system may be affected.</b></p><div id="44e1" class="link-block">
      <a href="https://www.elekta.com/company/company-update-April-26-2021">
        <div>
          <div>
            <h2>Response to data security incident in the U.S.</h2>
            <div><h3>Elekta's first-generation cloud-based storage system has experienced a data security incident. A subset of customers in…</h3></div>
            <div><p>www.elekta.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*E9Gwsjsrf_AI0WFV)"></div>
          </div>
        </div>
      </a>
    </div><p id="7030">Curious they specify “first-generation.” Sounds like they are using Azure:</p><blockquote id="7bb0"><p>Elekta is in the process of migrating those customers to its new Microsoft Azure cloud and the company is working around the clock to complete that process.</p></blockquote><div id="723b" class="link-block">
      <a href="https://www.hipaajournal.com/healthcare-providers-postpone-radiation-treatments-cyberattack-elekta/">
        <div>
          <div>
            <h2>Radiation Treatments Disrupted After Cyberattack on Software Vendor</h2>
            <div><h3>Share this article on: The Swedish oncology and radiology system provider Elekta is recovering from a cyberattack that…</h3></div>
            <div><p>www.hipaajournal.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*wUSIa7rkvHMScw5z)"></div>
          </div>
        </div>
      </a>
    </div><p id="f758"><b>Repairmen suspected of installing ransomware on customers’ PCs. Arrests in South Korea</b></p><div id="8b86" class="link-block">
      <a href="https://hotforsecurity.bitdefender.com/blog/repairmen-suspected-of-installing-ransomware-on-customers-pcs-arrests-in-south-korea-26006.html">
        <div>
          <div>
            <h2>Repairmen suspected of installing ransomware on customers' PCs...</h2>
            <div><h3>According to a report by Catalin Cimpanu at The Record, authorities in South Korea have filed charges against employees…</h3></div>
            <div><p>hotforsecurity.bitdefender.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*igcJMuveAiV9FxG5)"></div>
          </div>
        </div>
      </a>
    </div><p id="025b"><b>Union Benefits Administrator Says Data Deleted in Hack</b></p><p id="ba56">A Seattle-based benefits administrator for unionized home healthcare and nursing home workers has reported a hacking incident affecting 140,000 individuals that involved deleting certain data.</p><div id="5685" class="link-block">
      <a href="https://www.govinfosecurity.com/union-benefits-administrator-says-data-deleted-in-hack-a-16872">
        <div>
          <div>
            <h2>Union Benefits Administrator Says Data Deleted in Hack</h2>
            <div><h3>Breach Notification , Incident &amp; Breach Response , Security Operations Service Employees International Union 775…</h3></div>
            <div><p>www.govinfosecurity.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*zRDDQBZBTwouS-P6)"></div>
          </div>
        </div>
      </a>
    </div><p id="1a9d"><b>Vaccine registration website for expats back up after data leak</b></p><div id="87d2" class="link-block">
      <a href="https://thethaiger.com/coronavirus/vaccine-registration-website-for-expats-back-up-after-data-leak">
        <div>
          <div>
            <h2>Vaccine registration website for expats back up after data leak | Thaiger</h2>
            <div><h3>The Covid-19 vaccination website for foreign residents is back up after an apparent data leak yesterday where others…</h3></div>
            <div><p>thethaiger.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*ZHJQ2_BTx-kzZP1i)"></div>
          </div>
        </div>
      </a>
    </div><p id="57cb"><b>Bose Added to List of High-Profile Companies Who Have Suffered Ransomware Attack</b></p><div id="170a" class="link-block">
      <a href="https://www.jdsupra.com/legalnews/bose-added-to-list-of-high-profile-2974919/">
        <div>
          <div>
            <h2>Bose Added to List of High-Profile Companies Who Have Suffered Ransomware Attack | JD Supra</h2>
            <div><h3>In late May, Bose announced that it experienced a data breach following a ransomware attack against its systems in…</h3></div>
            <div><p>www.jdsupra.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*4V-BTfXtCLSqJC3M)"></div>
          </div>
        </div>
      </a>
    </div><p id="2eff"><b>Insight Global Asking Employees To Help Locate Documents That May Contain Personal Information</b></p><div id="0a59" class="link-block">
      <a href="https://pittsburgh.cbslocal.com/2021/06/18/insight-global-looking-for-personal-data/">
        <div>
          <div>
            <h2>Insight Global Asking Employees To Help Locate Documents That May Contain Personal Information</h2>
            <div><h3>The company behind a massive data breach of Pennsylvania's COVID-19 contact tracing system is asking employees for help…</h3></div>
            <div><p>pittsburgh.cbslocal.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*-Y2ABc1-7Fm1J_DY)"></div>
          </div>
        </div>
      </a>
    </div><p id="3505"><b>CaptureRx Data Breach Hits MetroHealth System, 16 Others</b></p><p id="2d75"><a href="https://healthitsecurity.com/news/capturerx-data-breach-hits-metrohealth-system-16-others">https://healthitsecurity.com/news/capturerx-data-breach-hits-metrohealth-system-16-others</a></p><div id="7d0f" class="link-block">
      <a href="https://www.beckershospitalreview.com/cybersecurity/3-hospitals-added-to-capturerx-data-breach-victim-toll-17-hospitals-healthcare-organizations-affected.html">
        <div>
          <div>
            <h2>3 hospitals added to CaptureRx data breach victim toll: 17 hospitals, healthcare organizations…</h2>
            <div><h3>Massena Hospital, Jones Memorial Hospital and MetroHealth System have been added to the tally of CaptureRx data breach…</h3></div>
            <div><p>www.beckershospitalreview.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*y-9Y45IoeRSaxx0B)"></div>
          </div>
        </div>
      </a>
    </div><p id="c105"><b>Fake Ledger devices mailed out in attempt to steal from cryptocurrency fans</b></p><div id="26ab" class="link-block">
      <a href="https://hotforsecurity.bitdefender.com/blog/fake-ledger-devices-mailed-out-in-attempt-to-steal-from-cryptocurrency-fans-25991.html">
        <div>
          <div>
            <h2>Fake Ledger devices mailed out in attempt to steal from...</h2>
            <div><h3>In December last year, we reported how the email and mailing addresses of some 270,000 Ledger customers had been…</h3></div>
            <div><p>hotforsecurity.bitdefender.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*NHvvvv7bwz29q5bA)"></div>
          </div>
        </div>
      </a>
    </div><div id="f67d" class="link-block">
      <a href="https://www.bleepingcomputer.com/news/cryptocurrency/criminals-are-mailing-altered-ledger-devices-to-steal-cryptocurrency/">
        <div>
          <div>
            <h2>Criminals are mailing altered Ledger devices to steal cryptocurrency</h2>
            <div><h3>Scammers are sending fake replacement devices to Ledger customers exposed in a recent data breach that are used to…</h3></div>
            <div><p>www.bleepingcomputer.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*L9l4mgEzcGZ4VFXi)"></div>
          </div>
        </div>
      </a>
    </div><p id="4fa9"><b>Largest US propane distributor discloses ‘8-second’ data breach</b></p><div id="be3a" class="link-block">
      <a href="https://www.bleepingcomputer.com/news/security/largest-us-propane-distributor-discloses-8-second-data-breach/">
        <div>
          <div>
            <h2>Largest US propane distributor discloses '8-second' data breach</h2>
            <div><h3>America's largest propane provider, AmeriGas, has disclosed a data breach that lasted ephemerally but impacted 123…</h3></div>
            <div><p>www.bleepingcomputer.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*jpDMSftb-cr94PTg)"></div>
          </div>
        </div>
      </a>
    </div><p id="dbdf"><b>A cyberattack shut down computer systems for hours at St. Joseph’s/Candler in Savannah where I now live this week.</b></p><p id="a21b">The hospital is back to normal now. Imagine if a hospital was out as long as the Colonial Pipeline.</p><div id="fb93" class="link-block">
      <a href="https://www.savannahnow.com/story/news/2021/06/17/cyberattack-hits-computer-systems-st-josephs-candler-hospital-savannah-ga/7734444002/">
        <div>
          <div>
            <h2>Update: Computer systems not yet back to normal after cyberattack at Savannah's largest hospital…</h2>
            <div><h3>A ransomware attack that was first detected Thursday continued to affect computer systems at St. Joseph's/Candler on…</h3></div>
            <div><p>www.savannahnow.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*tukhZ_AmLJ7lzruE)"></div>
          </div>
        </div>
      </a>
    </div><p id="adef"><b>Eggfree Cake Box suffer data breach exposing credit card numbers</b></p><p id="cbbc">Malware on systems.</p><div id="2bee" class="link-block">
      <a href="https://www.bleepingcomputer.com/news/security/eggfree-cake-box-suffer-data-breach-exposing-credit-card-numbers/">
        <div>
          <div>
            <h2>Eggfree Cake Box suffer data breach exposing credit card numbers</h2>
            <div><h3>Eggfree Cake Box has disclosed a data breach after threat actors hacked their website to stole credit card numbers…</h3></div>
            <div><p>www.bleepingcomputer.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*8_4SZcZgXliDoTnn)"></div>
          </div>
        </div>
      </a>
    </div><p id="447a"><b>Graduating students from several universities in the U.S. have been reporting fraudulent transactions after using payment cards at popular cap and gown maker Herff Jones.</b></p><p id="6203">Note that this article came out in May and the breach was just reported to the state of Oregon on 6/16/2021.</p><div id="1e6e" class="link-block">
      <a href="https://www.bleepingcomputer.com/news/security/herff-jones-credit-card-breach-impacts-college-students-across-the-us/">
        <div>
          <div>
            <h2>Herff Jones credit card breach impacts college students across the US</h2>
            <div><h3>Graduating students from several universities in the U.S. have been reporting fraudulent transactions after using…</h3></div>
            <div><p>www.bleepingcomputer.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*S8TszNns4qMXUnMS)"></div>
          </div>
        </div>
      </a>
    </div><p id="3891"><b>Prominence Health Plan just reported a breach to the State of California on 6/18/21 that occurred in November 2020.</b></p><blockquote id="66c9"><p>In a statement, Prominence officials said that a cloud-based data system the company used was accessed by an unauthorized third party.</p></blockquote><p id="18fc">But how did the attacker get the credentials used for the unauthorized access?</p><div id="d311" class="link-block">
      <a href="https://thisisreno.com/2021/06/prominence-health-plan-announces-data-breach/">
        <div>
          <div>
            <h2>Prominence Health Plan announces data breach</h2>
            <div><h3>Prominence Health Plan on Friday announced that personal information for a portion of its plan members was accessed in…</h3></div>
            <div><p>thisisreno.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*6WeOoXu-nTQsO3Jr)"></div>
          </div>
        </div>
      </a>
    </div><p id="4aa2"><b>STG International, Inc. Provides Notice of Data Privacy Incident</b></p><blockquote id="9755"><p>The investigation determined that an email phishing campaign targeted certain employees’ email accounts and resulted in unauthorized person(s) intermittently logging into the accounts between October 22, 2020 and January 12, 2021.</p></blockquote><div id="9b3d" class="link-block">
      <a href="https://www.thecentralvirginian.com/news/state/stg-international-inc-provides-notice-of-data-privacy-incident/article_c360cf30-d551-5c62-831b-ab9cd39f9340.html">
        <div>
          <div>
            <h2>STG International, Inc. Provides Notice of Data Privacy Incident</h2>
            <div><h3>ARLINGTON, Va., June 16, 2021 /PRNewswire/ -- STG International, Inc. ("STGi") is providing notice of a recent event…</h3></div>
            <div><p>www.thecentralvirginian.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div>
          </div>
        </div>
      </a>
    </div><p id="07c3"><b>KENNETH WEISS AND COMPANY PC reports data breach to the state of California that occurred in April</b></p><blockquote id="c503"><p>We recently became aware of a situation where an unauthorized party accessed one of our company’s internal servers and company computers. We discovered this situation on April 27, 2021</p></blockquote><p id="cb7e"><a href="https://oag.ca.gov/system/files/Weiss%20%26%20Company%20notification%20letter%20-%206.12.21%20FINAL.pdf">https://oag.ca.gov/system/files/Weiss%20%26%20Company%20notification%20letter%20-%206.12.21%20FINAL.pdf</a></p><p id="6e44"><b>Archbishop Mitty High School reported a data breach that occurred in May to the state of California on 6/16/2021 ~ related to the BlackBaud breach.</b></p><p id="4b81"><a href="https://oag.ca.gov/system/files/Archbishop%20Mitty-%20Sample%20Notice.pdf">https://oag.ca.gov/system/files/Archbishop%20Mitty-%20Sample%20Notice.pdf</a></p><p id="4b92"><b>Alina Lodge notifies patients of data breach tied to 2020 Blackbaud incident</b></p><div id="3da1" class="link-block">
      <a href="https://www.scmagazine.com/featured/alina-lodge-notifies-patients-of-data-breach-tied-to-2020-blackbaud-incident/">
        <div>
          <div>
            <h2>Alina Lodge notifies patients of data breach tied to 2020 Blackbaud incident</h2>
            <div><h3>The Blackbaud data breach was the largest health care-related incident of 2020, impacting an estimated two dozen…</h3></div>
            <div><p>www.scmagazine.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*K6yoZJI88aWJZalK)"></div>
          </div>
        </div>
      </a>
    </div><p id="ddab"><b>Ally data breach notification on 6/16/2021 for a data breach in February.</b></p><blockquote id="7901"><p>During a routine update to our website, a programming code error occurred that inadvertently resulted in your username and password being exposed to third parties with whom we have business relationships.</p></blockquote><p id="5733"><a href="https://oag.ca.gov/system/files/Notice%20of%20Breach%20CA.pdf">https://oag.ca.gov/system/files/Notice%20of%20Breach%20CA.pdf</a></p><p id="cc30"><b>Holthouse, Carlin &amp; Van Trigt LLP</b></p><blockquote id="c7b3"><p>Unauthorized access to an employee’s email.</p></blockquote><p id="8bcb">Does not say how someone got access to that employee’s email.</p><p id="0c9f"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/4a9aad9c-7835-4ae9-a5e1-60a72eb22d76.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/4a9aad9c-7835-4ae9-a5e1-60a72eb22d76.shtml</a></p><p id="5c1f"><b>Marr and Company PC reported a data breach to the state of Maine this week.</b></p><blockquote id="4506"><p>…the email account that was accessed between June 19, 2020 and June 23, 2020 contained some of your personal information.</p></blockquote><p id="fac6">Does not say how the email was accessed.</p><p id="7022"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/cfc2a8c9-407d-4a7c-b73b-4e4d61efbf31.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/cfc2a8c9-407d-4a7c-b73b-4e4d61efbf31.shtml</a></p><p id="474b"><b>City of Philadelphia reported a data breach this week</b></p><blockquote id="e554"><p>On March 31, 2020, the City became aware of suspicious activity related to an employee’s email account. The City quickly launched an internal investigation to determine the nature and scope of the activity, as well as the extent of potentially affected information. The investigation confirmed that multiple City employees’ email accounts were impacted by a phishing attack, and as a result, were subject to unauthorized access intermittently between March 11, 2020 and January 14, 2021.</p></blockquote><p id="bd4b"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/e359b601-9934-4db0-9993-f259a182e0df.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/e359b601-9934-4db0-9993-f259a182e0df.shtml</a></p><p id="1780"><b>Stride, Inc. reported a breach this week.</b></p><blockquote id="e6ce"><p>On or around November 11, 2020, Stride was the victim of a ransomware attack. Working with third-party forensic investigators, Stride determined that an unknown actor may have gained access to Stride systems from November 4, 2020 to November 19, 2020.</p></blockquote><p id="cc35"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/b44f9c95-853e-4502-84c3-a3885461ebc0.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/b44f9c95-853e-4502-84c3-a3885461ebc0.shtml</a></p><p id="1259"><b>City of Buffalo School District reported a breach this week.</b></p><p id="b198">The Buffalo Public Schools experienced a cybersecurity outage as a result of a ransomware attack on the morning of March 12, 2021.</p><p id="aea2"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/9b698382-9749-44ac-af4e-026f766d0356.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/9b698382-9749-44ac-af4e-026f766d0356.shtml</a></p><p id="da6e"><b>Maximus, Inc. reported a breach this week.</b></p><blockquote id="de24"><p>The investigation determined that the server was impermissibly accessed starting on May 17, 2021.</p></blockquote><p id="5fea"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/4147b711-dc88-4cb4-9561-db9069994341.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/4147b711-dc88-4cb4-9561-db9069994341.shtml</a></p><p id="1707"><b>Lucky Health Group d/b/a LuckyVitamin reported a breach this week</b></p><blockquote id="53da"><p>On March 19, 2021, Lucky discovered that certain computer systems in its environment were inaccessible. The information involved in the incident varied by individual, but includes name and Social Security number.</p></blockquote><p id="f270"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/c6b45a1d-6924-4582-b921-8cb3939c9f43.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/c6b45a1d-6924-4582-b921-8cb3939c9f43.shtml</a></p><p id="96b7"><b>Mevion Medical Systems reported a breach this week</b></p><blockquote id="b279"><p>On April 8, 2021, MMS determined that certain computer systems in its environment were impacted by malware. MMS launched an investigation with the assistance of third-party forensic specialists. The investigation determined that an unknown actor accessed certain MMS files sometime between March 28, 2021 and March 29, 2021.</p></blockquote><p id="914c"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/a599b49a-d267-4aa7-aedc-50ba88a61f7b.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/a599b49a-d267-4aa7-aedc-50ba88a61f7b.shtml</a></p><p id="146e"><b>St. Mark’s School of Texas was impacted by the Blackbaud breach</b></p><p id="2003"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/1b8355a3-f31e-44f4-b107-b21ba954ba19.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/1b8355a3-f31e-44f4-b107-b21ba954ba19.shtml</a></p><p id="024b"><b>Aspiration Financial, LLC reported a breach this week</b></p><blockquote id="96d3"><p>We recently noticed some unusual log-ins on your account that involved possible unauthorized access to your personal and financial information by an attacker from a foreign country using passwords acquired outside of Aspiration.</p></blockquote><p id="538f"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/1b10ead4-d6f7-44c1-adf1-b5a585964e03.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/1b10ead4-d6f7-44c1-adf1-b5a585964e03.shtml</a></p><p id="28e2"><b>Little Hill Foundation for the Rehabilitation of Alcoholics, Inc. d/b/a Alina Lodge reported it was impacted by Blackbaud to the state of Maine this week</b></p><p id="1df8"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/e9106a0a-9588-46ae-855d-eb412968a0f4.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/e9106a0a-9588-46ae-855d-eb412968a0f4.shtml</a></p><p id="bb9c"><b>Lightfoot, Franklin &amp; White LLC reported a breach to the State of Maine this week.</b></p><blockquote id="87f8"><p>On April 17, 2021, we learned of and stopped a ransomware incident that resulted in unlawful access by an unauthorized third party to certain clients’ case files containing personal information for individuals who may have been related to the case, including plaintiffs, defendants, witnesses, and other non-parties.</p></blockquote><p id="1eee"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/9ac44c79-9b35-498b-bed4-84eb5a80ddb7.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/9ac44c79-9b35-498b-bed4-84eb5a80ddb7.shtml</a></p><p id="55b1"><b>Reproductive Biology Associates / My Egg Bank North America reported a data breach this week</b></p><blockquote id="1127"><p>We first became aware of a potential data incident on April 16, 2021 when we discovered that a file server containing embryology data was encrypted and therefore inaccessible. We quickly determined that this was the result of a ransomware attack.</p></blockquote><p id="47f9"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/9a78777d-e1c1-4f83-a462-f704de00bec8.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/9a78777d-e1c1-4f83-a462-f704de00bec8.shtml</a></p><p id="9a50"><b>Spectrum Pharmaceuticals, Inc. reported a data breach this week.</b></p><blockquote id="2835"><p>On April 20, 2021, Spectrum was the target of a ransomware attack on its network, which it detected through its automated threat detection systems.</p></blockquote><p id="3eb1"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/777aabf3-2a29-4afa-951e-34349cfb4d31.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/777aabf3-2a29-4afa-951e-34349cfb4d31.shtml</a></p><p id="f060"><b>Leaders Life Insurance Company reported a breach this week.</b></p><blockquote id="99f6"><p>The investigation confirmed that certain folders on Leaders Life’s systems may have been accessed or removed from its systems without authorization between November 25 and November 27, 2020. The investigation determined that the information that may have been potentially affected includes name, date of birth, Tax ID number, and/or Social Security number.</p></blockquote><p id="a385"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/255c59af-182e-4835-a970-dba92db135d7.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/255c59af-182e-4835-a970-dba92db135d7.shtml</a></p><p id="5253"><b>Nutritional Medicinals, LLC dba Functional Formularies reported a breach this week.</b></p><p id="f310">On May 5, 2021, this investigation determined that malicious code inserted into Nutritional Medicinals’ online store was capable of capturing customer payment card information that was entered between January 18, 2021 and April 14, 2021.</p><p id="8594"><a href="https://apps.web.maine.gov/online/aeviewer/ME/40/9e83b218-dbdd-4980-bde8-3a44a30e43dd.shtml">https://apps.web.maine.gov/online/aeviewer/ME/40/9e83b218-dbdd-4980-bde8-3a44a30e43dd.shtml</a></p><p id="f480"><b>Tax Sheltered Compensation, Inc. reported a breach this week due to a breach of hosting provider NetGain involving rnasomware.</b></p><blockquote id="0c54"><p>On or about January 15, 2021 TSC was informed that Netgain, a cloud hosting company that was used to house data related to TSC’s clients, experienced a ransomware incident.</p></blockquote><h1 id="b6d6">Cost of a Data Breach</h1><p id="bea1">_____________________________________________</p><p id="cc98"><b>First American Financial Pays Farcical $500K Fine</b></p><p id="fa85">Brian Krebs:</p><blockquote id="9c12"><p>In May 2019, KrebsOnSecurity broke the news that the website of mortgage settlement giant <a href="https://en.wikipedia.org/wiki/First_American_Corporation">First American Financial Corp.</a> [<a href="https://www.marketbeat.com/stocks/NYSE/FAF/">NYSE:FAF</a>] was <a href="https://krebsonsecurity.com/2019/05/first-american-financial-corp-leaked-hundreds-of-millions-of-title-insurance-records/">leaking more than 800 million documents</a> — many containing sensitive financial data — related to real estate transactions dating back 16 years. This week, the <b>U.S. Securities and Exchange Commission</b> settled its investigation into the matter after the Fortune 500 company agreed to pay a paltry penalty of less than $500,000.</p></blockquote><div id="47ed" class="link-block">
      <a href="https://krebsonsecurity.com/2021/06/first-american-financial-pays-farcical-500k-fine/">
        <div>
          <div>
            <h2>First American Financial Pays Farcical $500K Fine</h2>
            <div><h3>In May 2019, KrebsOnSecurity broke the news that the website of mortgage settlement giant First American Financial…</h3></div>
            <div><p>krebsonsecurity.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*sH8TS35GRuiiw34r)"></div>
          </div>
        </div>
      </a>
    </div><div id="23a6" class="link-block">
      <a href="https://www.jdsupra.com/legalnews/sec-charges-issuer-with-cybersecurity-5627804/">
        <div>
          <div>
            <h2>SEC Charges Issuer with Cybersecurity Disclosure Controls Failures | JD Supra</h2>
            <div><h3>The SEC announced a settled enforcement action concerning First American Financial Corporation's violations of…</h3></div>
            <div><p>www.jdsupra.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*YZWZUZg-JRDZmxln)"></div>
          </div>
        </div>
      </a>
    </div><p id="5bc2"><b>Jail for consultant who scraped colossal trove of Alibaba customer data</b></p><div id="ad93" class="link-block">
      <a href="https://blog.malwarebytes.com/reports/2021/06/jail-for-consultant-who-scraped-colossal-trove-of-alibaba-customer-data/">
        <div>
          <div>
            <h2>Jail for consultant who scraped colossal trove of Alibaba customer data - Malwarebytes Labs</h2>
            <div><h3>A billion data points, including the usernames and mobile phone numbers of customers have been siphoned off Alibaba…</h3></div>
            <div><p>blog.malwarebytes.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*bCVxoJQdYluOLJjb)"></div>
          </div>
        </div>
      </a>
    </div><p id="6acb"><b>US man accused of 2010 DDoS attack on Santa Cruz government arrested</b></p><div id="db54" class="link-block">
      <a href="https://portswigger.net/daily-swig/us-man-accused-of-2010-ddos-attack-on-santa-cruz-government-arrested">
        <div>
          <div>
            <h2>US man accused of 2010 DDoS attack on Santa Cruz government arrested</h2>
            <div><h3>Emma Woollacott 16 June 2021 at 15:10 UTC Updated: 16 June 2021 at 17:38 UTC Defendant said to have fled following…</h3></div>
            <div><p>portswigger.net</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Voyg1tNmOuExMEM3)"></div>
          </div>
        </div>
      </a>
    </div><p id="c965"><b>IAB Tech Lab sued over its role in ‘world’s largest data breach’</b></p><div id="8cf5" class="link-block">
      <a href="https://www.thedrum.com/news/2021/06/17/iab-tech-lab-sued-over-its-role-world-s-largest-data-breach">
        <div>
          <div>
            <h2>IAB Tech Lab sued over its role in 'world's largest data breach'</h2>
            <div><h3>A branch of the Interactive Advertising Bureau (IAB) and others are being sued by the Irish Council for Civil Liberties…</h3></div>
            <div><p>www.thedrum.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*oSu3jyma1FN8wFbZ)"></div>
          </div>
        </div>
      </a>
    </div><p id="478d"><b>Hackers Behind EA Data Breach Are Selling FIFA 21 Source Code on an Underground Hacking Forum</b></p><p id="a7a7"><a href="https://www.cpomagazine.com/cyber-security/hackers-behind-ea-data-breach-are-selling-fifa-21-source-code-on-an-underground-hacking-forum/">https://www.cpomagazine.com/cyber-security/hackers-behind-ea-data-breach-are-selling-fifa-21-source-code-on-an-underground-hacking-forum/</a></p><p id="c53f"><b>St. Charles patient records released in data breach</b></p><div id="0476" class="link-block">
      <a href="https://www.bendbulletin.com/localstate/st-charles-patient-records-released-in-data-breach/article_21b44910-ce1a-11eb-ac34-73cc98af7b72.html">
        <div>
          <div>
            <h2>St. Charles patient records released in data breach</h2>
            <div><h3>The health records of nearly 5,000 St. Charles Health System cancer patients may have been exposed during a data breach…</h3></div>
            <div><p>www.bendbulletin.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*hX_pfbMCBleEqfC2)"></div>
          </div>
        </div>
      </a>
    </div><p id="f0a9"><b>ParkMobile payment app sued over breach</b></p><div id="9931" class="link-block">
      <a href="https://www.vnews.com/Vermonter-sues-a-leading-parking-app-after-data-breach-40920460">
        <div>
          <div>
            <h2>ParkMobile payment app sued over breach</h2>
            <div><h3>A Vermonter has filed a class-action lawsuit against a popular parking payment app used in Burlington, Montpelier and…</h3></div>
            <div><p>www.vnews.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*WqTxejFVIvxnZE5m)"></div>
          </div>
        </div>
      </a>
    </div><p id="caf6"><b>Emails and passwords of hundreds of Union government officials have been exposed to hackers due to the recent data breaches of Air India, Domino’s and Big Basket, the government has warned officials.</b></p><div id="587c" class="link-block">
      <a href="https://www.thehindu.com/news/national/data-breaches-expose-emails-passwords-of-several-government-officials-to-hackers/article34798982.ece">
        <div>
          <div>
            <h2>Data breaches expose emails, passwords of several government officials to hackers</h2>
            <div><h3>Emails and passwords of hundreds of Union government officials have been exposed to hackers due to the recent data…</h3></div>
            <div><p>www.thehindu.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*-DjLrB-vthJE1jUU)"></div>
          </div>
        </div>
      </a>
    </div><p id="4ee8"><b>2 firms fined S$43,000 in total over personal data breaches affecting Mindef, SAF personnel</b></p><div id="89c5" class="link-block">
      <a href="https://www.todayonline.com/singapore/2-firms-fined-s43000-total-over-personal-data-breaches-affecting-mindef-saf-personnel">
        <div>
          <div>
            <h2>2 firms fined S$43,000 in total over personal data breaches affecting Mindef, SAF personnel</h2>
            <div><h3>SINGAPORE - The HMI Institute of Health Sciences and ST Logistics have been fined S$35,000 and S$8,000 respectively…</h3></div>
            <div><p>www.todayonline.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*I9kyaHkikYvIkGpp)"></div>
          </div>
        </div>
      </a>
    </div><h1 id="391d">Laws &amp; Legal</h1><p id="a8db">_____________________________________________</p><p id="7bc7"><b>Roughly 115 cybersecurity-related bills are working their way through the legislative process, in many cases with bipartisan support.</b></p><div id="04b2" class="link-block">
      <a href="https://www.csoonline.com/article/3621735/us-congress-tees-up-ambitious-cybersecurity-agenda-in-the-wake-of-supply-chain-ransomware-attacks.html">
        <div>
          <div>
            <h2>US Congress tees up ambitious cybersecurity agenda in the wake of supply chain, ransomware attacks</h2>
            <div><h3>The Biden Administration has been thrown into a thicket of cybersecurity troubles in its first six months, forcing the…</h3></div>
            <div><p>www.csoonline.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*f83hhDibipFbBZtK)"></div>
          </div>
        </div>
      </a>
    </div><p id="0ed4"><b>Data breach notification laws by state</b></p><p id="f72c">I ran across this map of US data breach notification laws this week. Seems like it would be very helpful for organizations oper∂ating in different states.</p><div id="1f31" class="link-block">
      <a href="https://www.bakerlaw.com/BreachNotificationLawMap">
        <div>
          <div>
            <h2>Breach Notification Law Interactive Map</h2>
            <div><h3>Baker &amp; Hostetler LLP publications are intended to inform our clients and other friends of the firm about current legal…</h3></div>
            <div><p>www.bakerlaw.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*7f_8sLM4SRj7EMV3)"></div>
          </div>
        </div>
      </a>
    </div><p id="ba67"><b>The U.S. Supreme Court has granted LinkedIn another legal option to try to prevent rival hiQ Labs from scraping public information from its user profiles</b></p><div id="fc5d" class="link-block">
      <a href="https://threatpost.com/court-linkedin-data-scraping/166927/">
        <div>
          <div>
            <h2>Microsoft Gets Second Shot at Banning hiQ from Scraping LinkedIn User Data</h2>
            <div><h3>Decision throws out previous ruling in favor of hiQ Labs that prevented Microsoft's business networking platform to…</h3></div>
            <div><p>threatpost.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*43w9FXZHDgT7DEP4)"></div>
          </div>
        </div>
      </a>
    </div><p id="ac02"><b>New Hampshire Election Audit</b></p><p id="90fc">This two part series may be useful in voting machine challenges.</p><div id="add5" class="link-block">
      <a href="https://freedom-to-tinker.com/2021/06/02/new-hampshire-election-audit-part-1/">
        <div>
          <div>
            <h2>New Hampshire Election Audit, part 1</h2>
            <div><h3>Based on preliminary reports published by the team of experts that New Hampshire engaged to examine an election…</h3></div>
            <div><p>freedom-to-tinker.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div>
          </div>
        </div>
      </a>
    </div><div id="ad45" class="link-block">
      <a href="https://freedom-to-tinker.com/2021/06/07/new-hampshire-election-audit-part-2/">
        <div>
          <div>
            <h2>New Hampshire Election Audit, part 2</h2>
            <div><h3>In my previous post I explained the preliminary conclusions from the three experts engaged by New Hampshire to examine…</h3></div>
            <div><p>freedom-to-tinker.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div>
          </div>
        </div>
      </a>
    </div><p id="4264"><b>US Computer Fraud and Abuse Act: What the ‘landmark’ Van Buren ruling means for security researchers</b></p><div id="b5ae" class="link-block">
      <a href="https://portswigger.net/daily-swig/us-computer-fraud-and-abuse-act-what-the-landmark-van-buren-ruling-means-for-security-researchers">
        <div>
          <div>
            <h2>US Computer Fraud and Abuse Act: What the 'landmark' Van Buren ruling means for security…</h2>
            <div><h3>Industry breathes a sigh of relief as legal threat recedes ANALYSIS Following years of consternation, the US legal…</h3></div>
            <div><p>portswigger.net</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Xl-vjBivAemfY5r3)"></div>
          </div>
        </div>
      </a>
    </div><p id="e109"><b>Senate bill boosts penalties for cyber criminals</b></p><blockquote id="432f"><p><i>The bill permits law enforcement to seize funds generated from the sale of spyware and to take equipment such as illegal intercept devices used in the commission of hacking campaigns, ransomware and other nefarious activity, according to a fact sheet provided by the lawmakers.</i></p></blockquote><div id="4255" class="link-block">
      <a href="https://gcn.com/articles/2021/06/18/senate-cybercrime-penalties.aspx">
        <div>
          <div>
            <h2>Senate bill boosts penalties for cyber criminals -- GCN</h2>
            <div><h3>New legislation aims to create stricter penalties for cyberattacks against critical infrastructure and give the Justice…</h3></div>
            <div><p>gcn.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*7r3cfdoyUHXBPDk-)"></div>
          </div>
        </div>
      </a>
    </div><p id="4a30"><b>Senators Draft a Federal Breach Notification Bill</b></p><div id="935b" class="link-block">
      <a href="https://www.govinfosecurity.com/senators-draft-federal-breach-notification-bill-a-16908">
        <div>
          <div>
            <h2>Senators Draft a Federal Breach Notification Bill</h2>
            <div><h3>Breach Notification , Legislation &amp; Litigation , Security Operations Bipartisan Legislation Would Require Notifying…</h3></div>
            <div><p>www.govinfosecurity.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*XyuUA_Q9SCbnDu9d)"></div>
          </div>
        </div>
      </a>
    </div><p id="2015"><b>Marriott Beats Shareholder’s Data Breach Suit</b></p><div id="1440" class="link-block">
      <a href="https://www.law360.com/articles/1393503/marriott-beats-shareholder-s-data-breach-suit">
        <div>
          <div>
            <h2>Marriott Beats Shareholder's Data Breach Suit - Law360</h2>
            <div><h3>A Maryland federal judge has tossed claims brought against Marriott International Inc. by a shareholder following a…</h3></div>
            <div><p>www.law360.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*JhZKnzmTLVUOR92C)"></div>
          </div>
        </div>
      </a>
    </div><p id="a416"><b>Colorado Passes Comprehensive Data Privacy Law</b></p><div id="00f2" class="link-block">
      <a href="https://www.lexology.com/library/detail.aspx?g=fcbf1131-12e1-4a2e-9b22-f445938cd48f">
        <div>
          <div>
            <h2>Colorado Passes Comprehensive Data Privacy Law | Lexology</h2>
            <div><h3>On June 8, the Colorado legislature passed the Colorado Privacy Act (CPA). Assuming Governor Jared Polis signs the bill…</h3></div>
            <div><p>www.lexology.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*20G9HgF5rrFj_dho)"></div>
          </div>
        </div>
      </a>
    </div><h1 id="781f">Investments</h1><p id="53dd">_____________________________________________</p><p id="c959"><b>Cybersecurity training platform Immersive Labs closes $75M Series C led by Insight Partners</b></p><p id="ab92">What matters is not the platform, but rather the content. I haven’t looked at this particular content or platform so not saying it is good or bad. This is just a note to anyone seeking to invest in cybersecurity training performed by companies like mine. I was formerly a SANS instructor and on the SANS initial board of advisors for cloud security curriculum and helped with their first cloud security class. I went on to write a book on cybersecurity and my own class based on my experience and research in the field. 2nd Sight Lab is not seeking funding because we don’t need it. We teach our classes to select customers. But if you are investing in security training companies, results of the training matters.</p><div id="52de" class="link-block">
      <a href="https://techcrunch.com/2021/06/13/cyber-security-training-platform-immersive-labs-closes-75m-series-c-led-by-insight-partners/">
        <div>
          <div>
            <h2>Cybersecurity training platform Immersive Labs closes $75M Series C led by Insight Partners</h2>
            <div><h3>Immersive Labs, a platform which teaches cybersecurity skills to corporate employees by using real, up-to-date threat…</h3></div>
            <div><p>techcrunch.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*EEMq66RI-3WEZXt_)"></div>
          </div>
        </div>
      </a>
    </div><div id="ceeb" class="link-block">
      <a href="https://siliconangle.com/2021/06/14/immersive-labs-nabs-75m-boost-cybersecurity-teams-threat-response-skills/">
        <div>
          <div>
            <h2>Immersive Labs nabs $75M to boost cybersecurity teams’ threat response skills — SiliconANGLE</h2>
            <div><h3>Immersive Labs Inc., a startup with a platform for training cybersecurity teams to fend off cyberattacks, has raised a…</h3></div>
            <div><p>siliconangle.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*VIkuXptOQZfAna-F)"></div>
          </div>
        </div>
      </a>
    </div><p id="3324"><b>Industrial cybersecurity startup Claroty raises $140M in pre-IPO funding round</b></p><div id="2cba" class="link-block">
      <a href="https://techcrunch.com/2021/06/17/industrial-cybersecurity-startup-claroty-raises-140m-in-pre-ipo-funding-round/">
        <div>
          <div>
            <h2>Industrial cybersecurity startup Claroty raises $140M in pre-IPO funding round</h2>
            <div><h3>Claroty, an industrial cybersecurity company that helps customers protect and manage their Internet of Things (IoT) and…</h3></div>
            <div><p>techcrunch.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*k26V9IFDaq4pVCoj)"></div>
          </div>
        </div>
      </a>
    </div><p id="10a0"><b>Elisity raises $26M Series A to scale its AI cybersecurity platform</b></p><div id="2585" class="link-block">
      <a href="https://techcrunch.com/2021/06/15/elisity-raises-26m-series-a-to-scale-its-ai-cybersecurity-platform/">
        <div>
          <div>
            <h2>Elisity raises $26M Series A to scale its AI cybersecurity platform</h2>
            <div><h3>Elisity, a self-styled innovator that provides behavior-based enterprise cybersecurity, has raised $26 million in…</h3></div>
            <div><p>techcrunch.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*qomwPoHHamxrP8nk)"></div>
          </div>
        </div>
      </a>
    </div><p id="b6c6">Follow for updates.</p><p id="4a3a">Teri Radichel | <i>© <a href="https://2ndsightlab.com/?source=post_page---------------------------">2nd Sight Lab</a> 2021</i></p><div id="8b5f"><pre><span class="hljs-section">About Teri Radichel:
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab</pre></div><div id="caae"><pre><span class="hljs-section">Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</span>
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation</pre></div><div id="3b5e"><pre>Follow <span class="hljs-keyword">for</span> more stories like <span class="hljs-keyword">this</span>:

❤️ Sign Up my Medium Email List ❤️ Twitter: <span class="hljs-meta">@teriradichel</span> ❤️ LinkedIn: https:<span class="hljs-comment">//www.linkedin.com/in/teriradichel</span> ❤️ Mastodon: <span class="hljs-meta">@teriradichel</span><span class="hljs-meta">@infosec</span>.exchange ❤️ Facebook: 2nd Sight Lab ❤️ YouTube: @2ndsightlab</pre></div><figure id="5610"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*H9Ew1KCl-29nZiPR.jpeg"><figcaption></figcaption></figure></article></body>

Cybersecurity News: June 12-18 2021

Highlights: The lag between reporting and occurrence of breaches; More cyber criminals arrested; Savannah hospital shut down by cyberattack

Free Content on Jobs in Cybersecurity | Sign up for the Email List

2nd Sight Lab | Cybersecurity | Vulnerabilities | Malware | Threat Reports | Breaches & Attacks | Cost of a Data Breach | Laws & Legal | Investments

2nd Sight Lab News

Teri Radichel was originally slated to present at AWS re:Inforce in August in Houston. What should be in a cloud penetration test or cloud security assessment? Unfortunately, she will not be attending at this time due to unforeseen circumstances but may give this presentation at another venue in the future so stay tuned.

Have you ever looked at all the traffic your Apple Macintosh computer generates when you start it up? A 2nd Sight Lab blog post takes a look at that this week.

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

If you like this blog, please clap, follow, join, or pass it on. Thanks! 👏

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

Cybersecurity

_____________________________________________

Biden Tells Putin Critical Infrastructure Sectors ‘Off Limits’ to Russian Hacking

Why is attacking anything that harms citizens of another country not off-limits?

G7 leaders ask Russia to hunt down ransomware gangs within its borders

UK National Cyber Security Centre CEO Lindy Cameron issues call to organisations to take the ransomware threat seriously

The Government Accountability Office said it disagrees with the IRS stance that they do not have the authority to improve data security.

Russia bans VyprVPN, Opera VPN services for not complying with blacklist request

On March 28, 2019, the Russian government required VPNs, anonymizers, and search engine operators to ensure that they block sites included on Roskomnadzor’s regularly updated register of banned sites through the Federal State Information System (FSIS).

Senior Nasa Scientist Sentenced To Prison For Making False Statements Related To Chinese Thousand Talents Program Participation And Professorship

Notwithstanding these prohibitions, MEYYAPPAN participated in China’s Thousand Talents Program, a program established by the Chinese government to recruit individuals with access to or knowledge of foreign technology or intellectual property, and held professorships at universities in China, South Korea, and Japan, and failed to disclose these associations and positions to NASA and the U.S. Office of Government Ethics.

Russian National Convicted of Charges Relating to Kelihos Botnet

“By operating a website that was intended to hide malware from antivirus programs, Koshkin provided a critical service that enabled other cyber criminals to infect thousands of computers around the world,” said Acting U.S. Attorney Leonard C Boyle. “We will investigate and prosecute the individuals who aid and abet cyber criminals as vigorously as we do the ones who actually hit the ‘send’ button on viruses and other malicious software.”

Ukrainian police arrest Clop ransomware members, seize server infrastructure

Multiple suspects believed to be linked to the Clop ransomware cartel have been detained in Ukraine this week after a joint operation from law enforcement agencies from Ukraine, South Korea, and the US.

Tim Cook claims sideloading apps would destroy security and privacy of iOS

I have to agree that the closed app store allows for greater security. I hope legislators do not make a mistake here. If the goal is to regulate costs or achieve some other objective, then do that, without destroying the security of the Apple ecosystem.

An Introduction to Google’s SLSA in 5

Google has recently introduced the Supply chain Levels for Software Artifacts or SLSA (pronounced “salsa”) framework. This framework is in its early stages and has been released as part of OpenSSF Foundation.

And Google wants to bring Rust into the Linux Kernel.

Google open-sources tools to bring fully homomorphic encryption into the mainstream

Last time I checked operations were limited to the point this was not a viable for many use cases.

Microsoft takes down large‑scale BEC operation

Microsoft 365 Defender researchers recently uncovered and disrupted a large-scale business email compromise (BEC) infrastructure hosted in multiple web services. Attackers used this cloud-based infrastructure to compromise mailboxes via phishing and add forwarding rules, enabling these attackers to get access to emails about financial transactions.

More data points for upcoming mortgage industry security posts.

National Lab Recommends Energy Department Test Electric Utility Vendors for Cybersecurity

Insurer consortium launches CyberAcuView to improve risk mitigation

https://www.theinsurer.com/news/insurer-consortium-launches-cyberacuview-to-improve-risk-mitigation/16528.article

How Does One Get Hired by a Top Cybercrime Gang?

Last week this news feed included a story about the arrest of a 55 year old Latvian woman involved in a ransomware gang. Brian Krebs takes an interesting look at how someone might get involved in one of these gangs. Back when I had my own hosting business I was skeptical about a few “customers” that tried to hire me. I always wondered if it was all legitimate. If any of them were up to no good and realized I as re-routing suspicious traffic hitting my websites to FBI web sites to bring it to their attention, perhaps they may have left me alone. By the way, I had no idea what I was doing back then, so if anyone noticed this, forgive me for the web spam.

Make sure you’re running the latest version of Microsoft scripts that check for Exchange malware

State Data Breach Notifications

2nd Sight Lab discovered this site which maintains breach reporting lists available from US states. All states should maintain such information. Upon further review many of the links to state breach reporting pages lack sufficient data or are not up to date. A lag in reporting does not help prevent future attacks. The following states seem to have good reporting systems: California, Oregon, and Maine.

Microsoft no longer offers Windows 7 drivers via Windows Update

I wonder where Windows 7 is still running.

NVIDIA is dropping support for Windows 7 and Windows 8 drivers

Missed this one a couple weeks back — Azure Firewall Integration With Sentinel

Google Workspace Now Offers Client-side Encryption For Drive and Docs and Phishing Protection

AWS now offers multi-region encryption keys

Google abandons plans to simplify URLs in Chrome following real-world testing

The browser-maker has been attempting to simplify URLs in the ‘omnibox’ — Chrome’s address bar — for years, starting with the removal of “trivial subdomains” in 2018, although this was rolled back due to developer backlash.

This was followed by an announcement that the ‘www.’, ‘m.’, and ‘https://’ elements would be removed from address bar through an update released in 2019 — a move that also proved controversial.

Thank goodness. Whomever had that idea needs to be sent to security training especially related to tracking down malware and log analysis.

AT&T Cybersecurity Delivers New Managed SASE Solution to Drive Innovation and Transform User Experiences at the Edge

Likely to compete with ZScaler.

Hiccup in Akamai’s DDoS Mitigation Service Triggers Massive String of Outages

See my comments about the Fastly outage in last week’s cybersecurity news.

Microsoft Linux repos suffer day-long outage

HBO Max blames mistaken “Integration Test” email on an intern

Euros-Driven Football Fever Nets Dumb Passwords

Don’t use the password “Football” please.

Protect children online. More arrests by the FBI this week for sex crimes involving children.

Required MFA Is Not Sufficient for Strong Security: Report

Defense in depth is appropriate, but correctly designed and implemented MFA is still one of the most powerful things you can do to prevent data breaches. I explain in my book on cybersecurity for executives some of the caveats related to MFA — when it works and when it doesn’t.

PLC Security Top 20 List

Infosecurity Europe has announced that it is postponing the live event due to run at London Olympia in July, following the government’s delay in lifting the final COVID-19 restrictions.

NSA shares guidance on securing voice, video communications

Privacy

_____________________________________________

IKEA France Fined $1.2M for Elaborate ‘Spying System’

IKEA France’s former chief executive, Jean-Louis Baillot, was also personally fined €50,000 (around $60,200 at press time) for “storing personal data,” according to Deutsche Welle, and given a two-year suspended sentence by the French court.

TikTok can now collect biometrics

Australia — WA Police accessed private G2G pass data for criminal investigations

Vulnerabilities

_____________________________________________

A variant of the Mirai botnet called Moobot saw a big spike in activity recently, with researchers picking up widespread scanning in their telemetry for a known vulnerability in Tenda routers.

Cisco has flagged and patched several high-severity security vulnerabilities in its Cisco Small Business 220 Series Smart Switches that could allow session hijacking, arbitrary code execution, cross-site scripting and HTML injection.

Healthcare vendor Zoll patches high-risk vulnerabilities in defibrillator management software

Vulnerability in Microsoft Teams granted attackers access to emails, messages, and personal files

However, Grant pointed out, the malicious actor would have to be a member of the Microsoft Teams organization that they are attacking, meaning it would only work in the context of an insider threat attack.

Or someone who has the credentials of a valid team member, correct? And we all know that happens. Keep reading.

Peloton Bike+ Bug Gives Hackers Complete Control

XSS flaw in Wire messaging app allowed attackers to ‘fully control’ user accounts

Intentional Flaw in GPRS Encryption Algorithm GEA-1

GEA-1 was designed by the European Telecommunications Standards Institute in 1998. ETSI was — and maybe still is — under the auspices of SOGIS: the Senior Officials Group, Information Systems Security. That’s basically the intelligence agencies of the EU countries.

GitLab fixes serious SSRF flaw that exposed orgs’ internal servers

Cisco Talos recently discovered an exploitable information disclosure vulnerability in EIP Stack Group OpENer’s Ethernet/IP UDP handler.

OpENer is an Ethernet/IP stack for I/O adapter devices that includes objects and services for making Ethernet/IP-compliant products, as defined in the ODVA specification.

Update‌ ‌Your Chrome Browser to Patch Yet Another 0-Day Exploit‌ed ‌in‌-the‌-Wild

Apple fixes ninth zero-day bug exploited in the wild this year

Instagram‌ ‌Bug Allowed Anyone to View Private Accounts Without Following Them

Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild

Security researcher turns Apache Airflow into bug bounty cash cow

Android screen lock protection thwarted by Facebook Messenger Rooms exploit

And people make fun of me because I refuse to use Facebook Messenger. As if they don’t have enough other ways to contact me.

Malware

_____________________________________________

Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise

According to an incident response report published today, Mandiant said the malware was hidden inside a customized version of the Dahua SmartPSS Windows app that the unnamed CCTV vendor was providing to its customers.

If customers downloaded and installed the trojanized application, it would infect a company’s systems with a version of the SMOKEDHAM backdoor.

‘Oddball’ Malware Blocks Access to Pirated Software

Rather than steal credentials or hold data for ransom, a recent campaign observed by Sophos prevents people from visiting sites that offer illegal downloads.

Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions

The worm and ransomware scripts also use the API of the messaging application Telegram for command-and-control (C&C) communication.

Geek Squad Vishing Attack Bypasses Email Security to Hit 25K Mailboxes

I mentioned on Twitter this week that parents of a friend of mine were impacted by this spam campaign. They called a number in the email to clear a fraudulent bill. The attacker instructs the victim to visit a website which downloads malware. The victim may then see the attacker taking actions on their computer. Past campaigns looked for stored passwords for banking sites to automatically login to access customer accounts.

Threat Actors Use Google Docs to Host Phishing Attacks

Using Google Drive to host malware is not new. The landing page may be different. The most recent message: “new rules for June 25.”

“This Google Docs page may look familiar to those who share Google Docs outside of their organization. This, however, isn’t that page. It’s a custom HTML page made to look like that familiar Google Docs share page,” Avanan explained.

Hackers are using search engine optimization (SEO) to get high rankings for pages with malicious PDF files that steal credentials.

Google and other search engines should be aware of this and help block this threat at the source.

Unique TTPs link Hades ransomware to new threat group

NoxPlayer Supply-Chain Attack is Likely the Work of Gelsemium Hackers

A New Spyware is Targeting Telegram and Psiphon VPN Users in Iran

Researchers Uncover ‘Process Ghosting’ — A New Malware Evasion Technique

Tinder spam campaign hides “handwritten” links in profile images

Threat Reports

_____________________________________________

Report: Active Directory Certificate Services a big security blindspot on enterprise networks

True. Organizations need to understand all the places where systems or individuals are granted privileges on their network.

Booming Cyber-Underground Market for Initial-Access Brokers

Ransomware gangs are increasingly buying their way into corporate networks, purchasing access from ‘vendors’ that have previously installed backdoors on targets.

80 % of Ransomware Victims don’t pay. 80% of those who do are hit with a second attack.

An analysis that Kroll conducted of data breach notifications in 2020 showed a sharp increase in attacks against organizations in what it identified as six traditionally “under-attacked” industries — food and beverage, utilities, construction, entertainment, agriculture, and recreation.

An analysis that Kroll conducted of data breach notifications in 2020 showed a sharp increase in attacks against organizations in what it identified as six traditionally “under-attacked” industries — food and beverage, utilities, construction, entertainment, agriculture, and recreation.

VPNs and Trust

Good read and thoughts.

Thousands of publicly accessible VMware vCenter Servers vulnerable to critical flaws

Multi Perimeter Device Exploit Mirai Version Hunting For Sonicwall, DLink, Cisco and more

Cyber espionage by Chinese hackers in neighbouring nations is on the rise

Source is a report from Recorded Future.

CrowdStrike 2021 Global Threat Report

Molerats Hackers Return With New Attacks Targeting Middle Eastern Governments

Breaches & Attacks

_____________________________________________

Poland blames Russia for breach, theft of Polish officials’ emails

Chinese Hackers Believed to be Behind Second Cyberattack on Air India

Woman sentenced for embezzling more than half a million dollars from employer

Make sure your systems and processes are designed to precent insider theft. I talk about the concept of trust in my book and this applies to this particular story. It took too long to uncover this theft.

As described in court documents and testimony, Taylor was employed at an Augusta medical practice from 2006 to 2020 as the office and payroll manager. The year after she was hired, Taylor began stealing from her employer by inflating her own pay and writing unauthorized company checks which she deposited in her own account or used to pay her mortgage.

Critical entities targeted in suspected Chinese cyber spying via Pulse Connect Secure networking devices

The hack of Pulse Connect Secure networking devices came to light in April, but its scope is only now starting to become clear. The Associated Press has learned that the hackers targeted telecommunications giant Verizon and the country’s largest water agency. News broke earlier this month that the New York City subway system, the country’s largest, was also breached.

In the Pulse campaign, security experts said sophisticated hackers exploited never-before-seen vulnerabilities to break in and were hyper diligent in trying to cover their tracks once inside.

If you are using a VPN device on a well-designed network, you’re limiting the potential scope of attack. However, you need to focus a lot of time monitoring and securing your VPN as that will be the primary target of attack (as expected, because it is the only way in if designed correctly).

North Korea Exploited VPN Flaw to Hack South’s Nuclear Research Institute

VPN Flaw.

CVS Health Records for 1.1 Billion Customers Exposed

likely because of a cloud-storage misconfiguration

Please see one of my many cloud security presentations and most appropriately, the last one I did at CloudLive, blog posts, or read my book. I’ve explained how to prevent these issues numerous times.

More cloud data exposed: Cognyte, CVS, Wegmans

Security researchers and attackers are finding exposed data. Please refer to my comments on the last link and same comment for all cloud-exposed data below.

Amazon Web Services Misconfiguration Exposes Half a Million Cosmetics Customers

A research team at reviews site WizCase traced the leaky Amazon S3 bucket to popular Turkish beauty products firm Cosmolog Kozmetik.

UK legal firm Gateley warns of data breach following cyber-attack

Not a lot of details as to what attackers did.

Carnival Corp., the world’s largest cruise-ship operator, had another breach for the second time in a year

For the second time in a year, attackers have breached email accounts and accessed personal, financial and health information belonging to guests, employees and crew.

Compromised email account.

Volkswagen discloses data breach impacting 3.3 million Audi drivers

Audi also affected.

The investigation confirmed that the third party obtained limited personal information.

How? How did the information get disclosed? How can it be prevented by other companies? Breach notifications need to provide more information than what is included here.

https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/06/Delaware-VWGoA-Notice-Letter.pdf

Gateley suffers data breach following ‘cyber security incident’

Alibaba data breach exposes 1.1 billion pieces of data

Elekta’s first-generation cloud-based storage system has experienced a data security incident. 170 customers in North America using the impacted system may be affected.

Curious they specify “first-generation.” Sounds like they are using Azure:

Elekta is in the process of migrating those customers to its new Microsoft Azure cloud and the company is working around the clock to complete that process.

Repairmen suspected of installing ransomware on customers’ PCs. Arrests in South Korea

Union Benefits Administrator Says Data Deleted in Hack

A Seattle-based benefits administrator for unionized home healthcare and nursing home workers has reported a hacking incident affecting 140,000 individuals that involved deleting certain data.

Vaccine registration website for expats back up after data leak

Bose Added to List of High-Profile Companies Who Have Suffered Ransomware Attack

Insight Global Asking Employees To Help Locate Documents That May Contain Personal Information

CaptureRx Data Breach Hits MetroHealth System, 16 Others

https://healthitsecurity.com/news/capturerx-data-breach-hits-metrohealth-system-16-others

Fake Ledger devices mailed out in attempt to steal from cryptocurrency fans

Largest US propane distributor discloses ‘8-second’ data breach

A cyberattack shut down computer systems for hours at St. Joseph’s/Candler in Savannah where I now live this week.

The hospital is back to normal now. Imagine if a hospital was out as long as the Colonial Pipeline.

Eggfree Cake Box suffer data breach exposing credit card numbers

Malware on systems.

Graduating students from several universities in the U.S. have been reporting fraudulent transactions after using payment cards at popular cap and gown maker Herff Jones.

Note that this article came out in May and the breach was just reported to the state of Oregon on 6/16/2021.

Prominence Health Plan just reported a breach to the State of California on 6/18/21 that occurred in November 2020.

In a statement, Prominence officials said that a cloud-based data system the company used was accessed by an unauthorized third party.

But how did the attacker get the credentials used for the unauthorized access?

STG International, Inc. Provides Notice of Data Privacy Incident

The investigation determined that an email phishing campaign targeted certain employees’ email accounts and resulted in unauthorized person(s) intermittently logging into the accounts between October 22, 2020 and January 12, 2021.

KENNETH WEISS AND COMPANY PC reports data breach to the state of California that occurred in April

We recently became aware of a situation where an unauthorized party accessed one of our company’s internal servers and company computers. We discovered this situation on April 27, 2021

https://oag.ca.gov/system/files/Weiss%20%26%20Company%20notification%20letter%20-%206.12.21%20FINAL.pdf

Archbishop Mitty High School reported a data breach that occurred in May to the state of California on 6/16/2021 ~ related to the BlackBaud breach.

https://oag.ca.gov/system/files/Archbishop%20Mitty-%20Sample%20Notice.pdf

Alina Lodge notifies patients of data breach tied to 2020 Blackbaud incident

Ally data breach notification on 6/16/2021 for a data breach in February.

During a routine update to our website, a programming code error occurred that inadvertently resulted in your username and password being exposed to third parties with whom we have business relationships.

https://oag.ca.gov/system/files/Notice%20of%20Breach%20CA.pdf

Holthouse, Carlin & Van Trigt LLP

Unauthorized access to an employee’s email.

Does not say how someone got access to that employee’s email.

https://apps.web.maine.gov/online/aeviewer/ME/40/4a9aad9c-7835-4ae9-a5e1-60a72eb22d76.shtml

Marr and Company PC reported a data breach to the state of Maine this week.

…the email account that was accessed between June 19, 2020 and June 23, 2020 contained some of your personal information.

Does not say how the email was accessed.

https://apps.web.maine.gov/online/aeviewer/ME/40/cfc2a8c9-407d-4a7c-b73b-4e4d61efbf31.shtml

City of Philadelphia reported a data breach this week

On March 31, 2020, the City became aware of suspicious activity related to an employee’s email account. The City quickly launched an internal investigation to determine the nature and scope of the activity, as well as the extent of potentially affected information. The investigation confirmed that multiple City employees’ email accounts were impacted by a phishing attack, and as a result, were subject to unauthorized access intermittently between March 11, 2020 and January 14, 2021.

https://apps.web.maine.gov/online/aeviewer/ME/40/e359b601-9934-4db0-9993-f259a182e0df.shtml

Stride, Inc. reported a breach this week.

On or around November 11, 2020, Stride was the victim of a ransomware attack. Working with third-party forensic investigators, Stride determined that an unknown actor may have gained access to Stride systems from November 4, 2020 to November 19, 2020.

https://apps.web.maine.gov/online/aeviewer/ME/40/b44f9c95-853e-4502-84c3-a3885461ebc0.shtml

City of Buffalo School District reported a breach this week.

The Buffalo Public Schools experienced a cybersecurity outage as a result of a ransomware attack on the morning of March 12, 2021.

https://apps.web.maine.gov/online/aeviewer/ME/40/9b698382-9749-44ac-af4e-026f766d0356.shtml

Maximus, Inc. reported a breach this week.

The investigation determined that the server was impermissibly accessed starting on May 17, 2021.

https://apps.web.maine.gov/online/aeviewer/ME/40/4147b711-dc88-4cb4-9561-db9069994341.shtml

Lucky Health Group d/b/a LuckyVitamin reported a breach this week

On March 19, 2021, Lucky discovered that certain computer systems in its environment were inaccessible. The information involved in the incident varied by individual, but includes name and Social Security number.

https://apps.web.maine.gov/online/aeviewer/ME/40/c6b45a1d-6924-4582-b921-8cb3939c9f43.shtml

Mevion Medical Systems reported a breach this week

On April 8, 2021, MMS determined that certain computer systems in its environment were impacted by malware. MMS launched an investigation with the assistance of third-party forensic specialists. The investigation determined that an unknown actor accessed certain MMS files sometime between March 28, 2021 and March 29, 2021.

https://apps.web.maine.gov/online/aeviewer/ME/40/a599b49a-d267-4aa7-aedc-50ba88a61f7b.shtml

St. Mark’s School of Texas was impacted by the Blackbaud breach

https://apps.web.maine.gov/online/aeviewer/ME/40/1b8355a3-f31e-44f4-b107-b21ba954ba19.shtml

Aspiration Financial, LLC reported a breach this week

We recently noticed some unusual log-ins on your account that involved possible unauthorized access to your personal and financial information by an attacker from a foreign country using passwords acquired outside of Aspiration.

https://apps.web.maine.gov/online/aeviewer/ME/40/1b10ead4-d6f7-44c1-adf1-b5a585964e03.shtml

Little Hill Foundation for the Rehabilitation of Alcoholics, Inc. d/b/a Alina Lodge reported it was impacted by Blackbaud to the state of Maine this week

https://apps.web.maine.gov/online/aeviewer/ME/40/e9106a0a-9588-46ae-855d-eb412968a0f4.shtml

Lightfoot, Franklin & White LLC reported a breach to the State of Maine this week.

On April 17, 2021, we learned of and stopped a ransomware incident that resulted in unlawful access by an unauthorized third party to certain clients’ case files containing personal information for individuals who may have been related to the case, including plaintiffs, defendants, witnesses, and other non-parties.

https://apps.web.maine.gov/online/aeviewer/ME/40/9ac44c79-9b35-498b-bed4-84eb5a80ddb7.shtml

Reproductive Biology Associates / My Egg Bank North America reported a data breach this week

We first became aware of a potential data incident on April 16, 2021 when we discovered that a file server containing embryology data was encrypted and therefore inaccessible. We quickly determined that this was the result of a ransomware attack.

https://apps.web.maine.gov/online/aeviewer/ME/40/9a78777d-e1c1-4f83-a462-f704de00bec8.shtml

Spectrum Pharmaceuticals, Inc. reported a data breach this week.

On April 20, 2021, Spectrum was the target of a ransomware attack on its network, which it detected through its automated threat detection systems.

https://apps.web.maine.gov/online/aeviewer/ME/40/777aabf3-2a29-4afa-951e-34349cfb4d31.shtml

Leaders Life Insurance Company reported a breach this week.

The investigation confirmed that certain folders on Leaders Life’s systems may have been accessed or removed from its systems without authorization between November 25 and November 27, 2020. The investigation determined that the information that may have been potentially affected includes name, date of birth, Tax ID number, and/or Social Security number.

https://apps.web.maine.gov/online/aeviewer/ME/40/255c59af-182e-4835-a970-dba92db135d7.shtml

Nutritional Medicinals, LLC dba Functional Formularies reported a breach this week.

On May 5, 2021, this investigation determined that malicious code inserted into Nutritional Medicinals’ online store was capable of capturing customer payment card information that was entered between January 18, 2021 and April 14, 2021.

https://apps.web.maine.gov/online/aeviewer/ME/40/9e83b218-dbdd-4980-bde8-3a44a30e43dd.shtml

Tax Sheltered Compensation, Inc. reported a breach this week due to a breach of hosting provider NetGain involving rnasomware.

On or about January 15, 2021 TSC was informed that Netgain, a cloud hosting company that was used to house data related to TSC’s clients, experienced a ransomware incident.

Cost of a Data Breach

_____________________________________________

First American Financial Pays Farcical $500K Fine

Brian Krebs:

In May 2019, KrebsOnSecurity broke the news that the website of mortgage settlement giant First American Financial Corp. [NYSE:FAF] was leaking more than 800 million documents — many containing sensitive financial data — related to real estate transactions dating back 16 years. This week, the U.S. Securities and Exchange Commission settled its investigation into the matter after the Fortune 500 company agreed to pay a paltry penalty of less than $500,000.

Jail for consultant who scraped colossal trove of Alibaba customer data

US man accused of 2010 DDoS attack on Santa Cruz government arrested

IAB Tech Lab sued over its role in ‘world’s largest data breach’

Hackers Behind EA Data Breach Are Selling FIFA 21 Source Code on an Underground Hacking Forum

https://www.cpomagazine.com/cyber-security/hackers-behind-ea-data-breach-are-selling-fifa-21-source-code-on-an-underground-hacking-forum/

St. Charles patient records released in data breach

ParkMobile payment app sued over breach

Emails and passwords of hundreds of Union government officials have been exposed to hackers due to the recent data breaches of Air India, Domino’s and Big Basket, the government has warned officials.

2 firms fined S$43,000 in total over personal data breaches affecting Mindef, SAF personnel

Laws & Legal

_____________________________________________

Roughly 115 cybersecurity-related bills are working their way through the legislative process, in many cases with bipartisan support.

Data breach notification laws by state

I ran across this map of US data breach notification laws this week. Seems like it would be very helpful for organizations oper∂ating in different states.

The U.S. Supreme Court has granted LinkedIn another legal option to try to prevent rival hiQ Labs from scraping public information from its user profiles

New Hampshire Election Audit

This two part series may be useful in voting machine challenges.

US Computer Fraud and Abuse Act: What the ‘landmark’ Van Buren ruling means for security researchers

Senate bill boosts penalties for cyber criminals

The bill permits law enforcement to seize funds generated from the sale of spyware and to take equipment such as illegal intercept devices used in the commission of hacking campaigns, ransomware and other nefarious activity, according to a fact sheet provided by the lawmakers.

Senators Draft a Federal Breach Notification Bill

Marriott Beats Shareholder’s Data Breach Suit

Colorado Passes Comprehensive Data Privacy Law

Investments

_____________________________________________

Cybersecurity training platform Immersive Labs closes $75M Series C led by Insight Partners

What matters is not the platform, but rather the content. I haven’t looked at this particular content or platform so not saying it is good or bad. This is just a note to anyone seeking to invest in cybersecurity training performed by companies like mine. I was formerly a SANS instructor and on the SANS initial board of advisors for cloud security curriculum and helped with their first cloud security class. I went on to write a book on cybersecurity and my own class based on my experience and research in the field. 2nd Sight Lab is not seeking funding because we don’t need it. We teach our classes to select customers. But if you are investing in security training companies, results of the training matters.

Industrial cybersecurity startup Claroty raises $140M in pre-IPO funding round

Elisity raises $26M Series A to scale its AI cybersecurity platform

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2021

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab
Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation
Follow for more stories like this:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
❤️ Sign Up my Medium Email List
❤️ Twitter: @teriradichel
❤️ LinkedIn: https://www.linkedin.com/in/teriradichel
❤️ Mastodon: @teriradichel@infosec.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
Cybersecurity News
Data Breach
Cyberlaw
Malware
Cyber Attacks
Recommended from ReadMedium