Global Cyber News Digest

Daily News Digest

Stay current on the global cyber threat landscape and industry developments with CCOE’s daily digest and library of cybersecurity news and articles.

  • Lawyers Encouraged to Vet Tech Vendors Carefully

    • Law firms are prime targets for hackers. Why? Because their computer networks contain highly concentrated, high-value information about many parties that is often not well-protected. One often-overlooked vulnerability is the security of computer networks operated by third-party vendors employed by the firm.
    • The five leading threats to law firms are:
      • Ransomware
      • Business Email Compromise / EAC
      • Spearphishing
      • Lost or stolen laptops and mobile devices
      • Third Party Risk
    • All law firms should carefully inventory the data they possess: What data is held by the firm, why it is being held, who has access to it, and for how long?
    • Vendors have capabilities that law firms do not, and it is often the case that cybersecurity measures in place at a vendor are better than those in place at the law firm itself. However, that is not always the case and no law firm should assume that a vendor’s cybersecurity measures are adequate for the assigned matter.
      • Trust but verify.
    - Jim Ballowe | May 3, 2021
    hak-iq.us20.list-manage.comMay 3, 2021
  • Ransomware Hits Scripps Health, Disrupting Critical Care, Online Portal

    • Scripps Health in San Diego was hit by a ransomware attack over the weekend, forcing the health system into EHR downtime.
    • Monday appointments were also postponed due to the cyberattack, which disrupted operations at two of Scripps’ four main hospitals and backup servers that reside in Arizona.
    • Reports say all four hospitals in Encinitas, La Jolla, San Diego, and Chula Vista were placed on emergency care diversion for stroke and heart attack patients, who were diverted to other medical centers when possible. All trauma patients were also diverted.
    • The Scripps website was also down.
    - Jessica Davis | May 3, 2021
    hak-iq.us20.list-manage.comMay 3, 2021
  • Scripps Health Hit By Cyberattack

    • Scripps Health confirmed Sunday their technology servers were hacked overnight, forcing the health care system to switch to offline chart systems and causing a disruption to their patient portals.
    • Some appointments were being canceled on Sunday and Monday as a result of the breach.
    • "We are working on how best to notify these patients about the need to reschedule," a statement from Scripps said.
    • The San Diego County Office of Emergency Services (OES) said ambulances were being diverted from Scripps' facilities to other hospitals in the area but that it was a precautionary measure.
    - Christina Bravo | May 2, 2021
    hak-iq.us20.list-manage.comMay 2, 2021
  • More than 2 million affected by data breaches in April

    • In April, 41 organizations reported to HHS that 2,121,186 individuals were affected by data breaches.
    • Breaches of protected health information affecting more than 500 individuals are required to be listed on HHS' breach portal.
    | April 30, 2021
    hak-iq.us20.list-manage.comApril 30, 2021
  • Click Studios asks customers to stop tweeting about its Passwordstate data breach

    • Last week, the company told customers to “commence resetting all passwords” stored in its flagship password manager after the hackers pushed the malicious update to customers over a 28-hour window between April 20-22.
    • The malicious update was designed to contact the attacker’s servers to retrieve malware designed to steal and send the password manager’s contents back to the attackers.
    • Click Studios said in a Wednesday advisory that customers are “requested not to post Click Studios correspondence on Social Media.” The email adds: “It is expected that the bad actor is actively monitoring Social Media, looking for information they can use to their advantage, for related attacks.”
    • It’s not clear if the company has disclosed the breach to U.S. and EU authorities where the company has customers, but where data breach notification rules obligate companies to disclose incidents. Companies can be fined up to 4% of their annual global revenue for falling foul of Europe’s GDPR rules.
    - Zack Whittaker | April 29, 2021
    hak-iq.us20.list-manage.comApril 29, 2021
  • When is the Right Time for a Managed Security Service?

    • Enterprises face an uphill battle when dealing with cybersecurity challenges. Hackers constantly evolve their malware and cyber-threat tactics, making it difficult to keep up with the threat landscape. Meanwhile, cybersecurity solutions can overwhelm IT security teams with their complexity and maintenance demands.
    • A managed security service is a commitment that requires funding and resources. So when should you seek one out?
      • When your IT security team is overwhelmed
        • Sometimes you need to recognize that you won’t be filling the openings in your security team anytime soon. Sometimes you just don’t have the time to train new recruits or you may not find the right talent and personality to match the team.
      • When your solutions confound you
        • Some solutions pose different sets of challenges. For example, SIEM has maintenance and upkeep demands tied into its correlation rules; without regular adjustments and review, SIEM solutions can generate numerous false positives.
      • For the intelligence
        • They have independent lines of threat intelligence. They know the threat landscape better than anyone and can help prepare your business and its individual use case for what comes next.
    - Ben Canner | April 28, 2021
    hak-iq.us20.list-manage.comApril 28, 2021
  • Data Breach Impacts 1 in 4 Wyomingites

    • Wyoming's Department of Health (WDH) has announced the accidental exposure of personal health information belonging to more than a quarter of the state's population on GitHub.com.
    • Data in the leaked files included the results of tests for influenza and COVID-19 performed across the United States between January 2020 and March 2021. One file containing breath alcohol test results was also exposed. 
    • Along with the test results were patients' names, ID numbers, addresses, dates of birth, and dates of when tests had been carried out.
    • “While WDH staff intended to use this software service only for code storage and maintenance rather than to maintain files containing health information, a significant and very unfortunate error was made when the test result data was also uploaded to GitHub.com,” said WDH director Michael Ceballos.
    - Sarah Coble | April 28, 2021
    hak-iq.us20.list-manage.comApril 28, 2021
  • How Can SIEM Deflect and Deter Modern Cyber-Threats

    • Some IT decision-makers chaff at the idea of SIEM can help them deflect modern cyber-threats; SIEM does possess a reputation as being difficult to work with and generating false positives.
    • Current research suggests SIEM becomes part of a wider cybersecurity platform unified by security orchestration, automation, and response (SOAR). SOAR decentralizes and re-centralizes cybersecurity tools like SIEM, firewalls, and identity management by unifying each’s findings under one pane of glass.
    • Visibility is the most essential cybersecurity principle. Without visibility, you’re literally operating in the dark. You can’t protect what you can’t see. 
    • SIEM can assist with increasing network visibility via its log management. However, using SIEM as a visibility tool raises new questions. Where should your SIEM prioritize? How can it handle a scaled environment? Can you maintain visibility over your network when it isn’t under your direct vision to begin with? 
    • A next-generation SIEM solution should enable your IT security team to revise and monitor configuration rules on the fly, easing the visibility issue.
    - Ben Canner | April 27, 2021
    hak-iq.us20.list-manage.comApril 27, 2021
  • Australian hospitals hit by cyber attack

    • Some Queensland hospitals and health services have resorted to manual processing patients after a cyber attack brought down the IT systems of UnitingCare Queensland.
    • UnitingCare is the second Australian provider of health services to be crippled by a cyber attack in the last six weeks after Victoria’s Eastern Health was taken offline last month.
    • VMware cyber security strategist, Rick McElroy, said hospitals were a prime target for cyber attacks due to the potentially valuable personal information they hold.
    • “While the attack methods may vary, most cybercriminals are motivated by a financial incentive,” he said.
    • “Given the critical nature of data at healthcare organisations, they are often a prime target for attacks, as cybercriminals know patient care is on the line and organisations are more apt to pay.”
    • According to US cyber security company Coveware, 77 per cent of ransomware attacks in the first three months of this year involved a threat to leak stolen data.
    • That number is increasing as cyber criminals have moved toward the ‘double extortion’ model of ransomware in which the groups lock down a network and threaten to publish information unless a ransom is paid.
    - Casey Tonkin | April 27, 2021
    hak-iq.us20.list-manage.comApril 27, 2021
  • Alert! Apple's AirDrop comes with a security flaw that can cause data breach of 1.5 billion users

    • It has been revealed that any person can access Apple users’ email addresses and mobile numbers, despite being a stranger and it is done by just sharing pane on the device after the sharing process is initiated.
    • The basic requirement to perform this is a stable Wi-Fi connection and the proximity between the two Apple devices.
    • Primarily, there are two reasons behind this security flaw. First and foremost is the process of finding contact and the next is AirDrop uses a “mutual authentication” process to draw a comparison between the phone numbers and email addresses of a possible receiver.
    • Besides that, a weak hashing system of Apple further allows hackers to access personal details.
     April 26, 2021
    hak-iq.us20.list-manage.comApril 27, 2021