Security Leftovers
-
Cyberspace Solarium Commission says space systems should be considered critical infrastructure
The influential Cyberspace Solarium Commission is calling for space systems to be the 17th critical infrastructure sector.
-
Hackers who hit Western Digital are now demanding ransom for data
The cybercriminals who hit storage maker Western Digital Corp. in a network breach earlier this month have returned to demand ransom for stolen data, which includes customer information The hackers have claimed the theft of more than 10 terabytes of data and are seeking “a minimum 8 figures” not to leak sensitive information. -
Southeastern University silent amid claims of data leak linked to network breach
Since then, and as DataBreaches first reported on March 4, they have been less than transparent about what happened and the scope of what we know was a ransomware incident involving the BianLian ransomware gang. Has Southeastern ever even admitted that this was a ransomware attack?
-
Patient Advances Data Breach Class Action Against Lamoille Health
Lamoille Health Partners Inc. must face a proposed class action alleging it negligently failed to protect the personal information of 60,000 people that was exposed in a data breach.
Lamoille Health wasn’t entitled to immunity from suit under the Public Health Service Act because the lawsuit’s data breach allegations weren’t interwoven with the provision of medical care, a requirement for immunity under the act, Judge William K. Sessions III of the US District Court for the District of Vermont said Thursday.
-
Kodi Confirms Data Breach: 400K User Records and Private Messages Stolen
Open source media player software provider Kodi has confirmed a data breach after threat actors stole the company's MyBB forum database containing user data and private messages.
What's more, the unknown threat actors attempted to sell the data dump comprising 400,635 Kodi users on the now-defunct BreachForums cybercrime marketplace.
"MyBB admin logs show the account of a trusted but currently inactive member of the forum admin team was used to access the web-based MyBB admin console twice: on 16 February and again on 21 February," Kodi said in an advisory.
-
Lawsuit Claims Mount Nittany Health Shared Private Patient Information with Facebook, Google
A lawsuit filed in Centre County Court this week alleges that Mount Nittany Health violated medical privacy rights by disclosing patients’ private information to Facebook, Google and other third-party websites without their knowledge.
The four-count lawsuit filed on behalf of two unnamed Centre County residents identified as John and Jane Doe claims information from communications through Mount Nittany Health’s website was captured by tracking technology and shared with the companies for marketing purposes.
Mount Nittany joins a number of health systems nationwide accused of sharing patient information with tech companies in a similar manner.
-
Darktrace Denies Getting Hacked After Ransomware Group Names Company on Leak Site
Cybersecurity firm Darktrace has issued a statement after it was listed on the leak website of the LockBit ransomware group.
-
Juniper Networks Patches Critical Third-Party Component Vulnerabilities
Juniper Networks this week announced patches for tens of vulnerabilities across its product portfolio, including critical bugs in Junos OS and STRM.
-
Microsoft Warns Accounting, Tax Return Preparation Firms of Remcos RAT Attacks [Ed: The problem is Windows, but Microsoft is trying to present itself as the defender]
A new Remcos RAT campaign is targeting US accounting and tax return preparation firms as Tax Day approaches.
-
A short-lived BlackCat listing suggests NCR’s customers’ networks were accessed
It’s been more than a decade since DataBreaches covered any significant data breach involving the Aloha POS system, and back then it was owned by Radiant Systems. In 2011, NCR Corporation bought Aloha POS. Things were fairly quiet since then, if you don’t count NCR’s response to a zero day RCE vulnerability that NCR somewhat punted to its clients.
But now Aloha POS was back in RSS feeds this week as people tried to understand an outage that NCR really wasn’t explaining.
-
CISA Introduces Secure-by-design and Secure-by-default Development Principles [Ed: CISA is not for security but for mandated back doors and remote controls]
CISA has described and published a set of principles for the development of security-by-design and security-by-default cybersecurity products.
-
Google, CISA Warn of Android Flaw After Reports of Chinese App Zero-Day Exploitation [Ed: CISA is not for security but for mandated back doors and remote controls]
The Android vulnerability CVE-2023-20963, reportedly exploited as a zero-day by a Chinese app against millions of devices, was added to CISA’s KEV catalog.