Security Leftovers (UPDATED)
-
Undetected PowerShell Backdoor Disguised as a Profile File, (Fri, Jun 9th)
PowerShell remains an excellent way to compromise computers. Many PowerShell scripts found in the wild are usually obfuscated.
-
Filing reveals 489,000 more patients’ data was stolen in GoAnywhere breach
A filing submitted to the Office of the Maine Attorney General has revealed that 489,830 more people were affected by this year’s GoAnywhere breach than previously believed. TechCrunch reported the development this morning. The filing in question was submitted by a company called Intellihartx LLC that manages patient balances and collections for healthcare organizations. -
Top 10 Free VPN Chrome Extensions for Safe and Private Browsing
In today’s world, almost everyone needs access to everything.
-
Security advisory: Qt Network
A recent SSL issue affecting both OpenSSL and Schannel in Qt Network has been reported and has been assigned the CVE id CVE-2023-34410.
-
Barracuda tells customers to replace vulnerable email security appliances after hacker exploit
Cloud cybersecurity firm Barracuda Networks Inc. is telling customers to replace their vulnerable Email Security Gateway appliances immediately, even if they have installed all available patches. -
Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 [Ed: Microsoft Windows TCO]
Evidence suggests that the Cl0p ransomware group has known about and conducted tests with the recently patched MOVEit zero-day since mid-2021.
-
‘Asylum Ambuscade’ Group Hit Thousands in Cybercrime, Espionage Campaigns
ESET has linked several cybercrime and espionage campaigns to a threat actor tracked as Asylum Ambuscade.
-
Security Testing for Kubernetes Clusters
Containerization and microservices have taken center stage, with Kubernetes leading the charge as the go-to orchestration platform. As powerful and versatile as Kubernetes is, its complexity introduces significant security challenges that organizations must tackle to safeguard their deployments.
UPDATE
More new incidents:
-
Thousands of students’ data breached in Minnesota Department of Education hack
Hackers were able to get a hold of tens of thousands of Minnesota students’ information.
The Minnesota Department of Education (MDE) says they were notified of a breach in their file transfer software called “MOVEit” on May 31.
-
Asylum Ambuscade hackers mix cybercrime with espionage
A hacking group tracked as ‘Asylum Ambuscade’ was observed in recent attacks targeting small to medium-sized companies worldwide, combining cyber espionage with cybercrime.
The particular threat group, believed to have been operational since at least 2020, was first identified by Proofpoint in a March 2022 report that focused on a phishing campaign against entities aiding the Ukrainian refugees’ movement.
-
Members of the public among those affected by massive N.S. cyberattack
The Nova Scotia government revealed Friday that cyber criminals made off with the private information of tens of thousands of people, including high school students, short-term accommodation owners, newborns and people issued parking tickets in the Halifax Regional Municipality.
On Friday, the province gave details on 94,574 of the records stolen in a cyberattack identified last week, and the total number of records stolen may climb.
On Tuesday, the province’s Minister of Cyber Security and Digital Solutions, Colton LeBlanc, said current and past employees of Nova Scotia Health, the IWK Health Centre and the provincial civil service have also been impacted.
-
49ers agree to settle data breach class action lawsuit, must create new IT positions
The San Francisco 49ers agreed to settle a class action lawsuit stemming from a February 2022 ransomware attack on the team’s data servers that exposed personal information of over 20,000 employees, officials and fans. The plaintiffs filed settlement papers Thursday in California federal court.
The proposed settlement, which covers 20,930 individuals, requires the team to create a new position — executive vice president of technology — to oversee IT operations, and hire a dedicated cyber-security IT professional.
-
Switzerland fears government data stolen in cyberattack
“Xplain, a Swiss provider of government software, has been the victim of a ransomware attack. After the stolen data had been encrypted and the company blackmailed, the attackers posted some of the stolen data on the darknet,” the government said in a statement.
-
Website leak exposes sensitive data of 85 million Turkish residents: report
Sensitive personal data of Turkish citizens and residents of Turkey has been compromised, according to the Free Web Turkey, a platform dedicated to combating internet censorship in the country.
On Friday, the platform exposed the existence of a website called Sorgu Paneli, which allows unrestricted access to personal data such as identification numbers, names, addresses, telephone numbers and even bank account details in exchange for a free membership. Paid members can obtain even more private information, including title deeds.