Security Leftovers
-
Security updates for Tuesday [LWN.net]
Security updates have been issued by Debian (vim), Fedora (kernel), Oracle (emacs, firefox, python3, and qemu), SUSE (firefox, java-1_8_0-ibm, and libwebp), and Ubuntu (firefox, glusterfs, and sniproxy).
-
Texas Tightens State’s Data Breach Notification Law
On May 27, 2023, Texas’ Governor signed Senate Bill 768 amending Texas’ data breach notification law. The law in question, Section 521.053 of the Texas Business and Commerce Code, sets out the specific requirements any person conducting business in the state who owns or licenses sensitive personal information in a computerized format must follow in the event of any breach of system security.
-
Data breach prompts University of Pittsburgh Medical Center billing contractor to contact 25,000 patients
Some 25,000 University of Pittsburgh Medical Center (UPMC) patients are being contacted by a Tennessee billing contractor following a data breach caused by a software bug that may have exposed names, addresses, social security numbers and other personal information.
Kingsport-based Intellihartx LLC, which provides UPMC with billing and collection services, is contacting UPMC patients by mail, offering complimentary credit monitoring and identity restoration services to anyone whose records have been used illegally.
-
CloudSEK report says hackers don’t have access to CoWin’s backend database
A day after a Telegram bot provided access to the personal information of individuals who had reportedly registered for vaccination through the government’s CoWIN portal, an independent analysis by CloudSEK has shown that the threat actors do not have access to the entire portal or the backend database.
CloudSEK is a Singapore-based contextual AI company that claims it can forewarn cyber threats.
“Based on the matching fields from the Telegram data and previously reported incidents affecting health workers of a region, we assume the information was scraped through these compromised credentials,” CloudSEK said in a report.
-
Maimondes Medical Center notifies 33,000 patients of hacking incident
Investigation revealed that the hacker had access to the server from March 18, 2023 to April 4, 2023. Information that might have been accessed included names and addresses and limited clinical information, including diagnosis and treatment information. “In a small numbers of instances, social security number could also have been involved,” MMC wrote in a statement.
-
School community OSG Hengelo closes deal with hackers after ransomware attack
OSG Hengelo says that at the moment it is still unclear exactly what data the hackers have obtained. “It is still under investigation. As soon as there is more clarity about this, we will tell you,” the board says in a response to students and parents. Employees and students can now use WiFi again. In addition, almost all printers work again.
-
Commonwealth Health Physician Network-Cardiology notified 181,764 patients of network breach
According to the notice by the Commonwealth Health Physician Network, the breach occurred on February 2 and continued until April 14. It was first discovered by GVC on April 13, but as some great reporting by Borys Krawczeniuk of The Times-Tribune made clear, GVC only discovered the breach then when they were alerted by the U.S. Department of Homeland Security.
-
Rhysida claims to have attacked Paris High School in Illinois
There is nothing on the district’s website to indicate any problems or breach. The only possible indicator currently found was on the district’s Facebook page in the form of a May 22 notice that their phone systems were down. There do not seem to be any follow-up posts to that although there were other posts about graduation and other normal activities.
-
Cyberattack is a factor in Illinois hospital’s closure
A hospital in Illinois will close on Friday due in part to a cyberattack – a rare case of a health care provider publicly linking a hack incident to its closure.
The 2021 cyberattack on St. Margaret’s Health, a hospital in Spring Valley, Illinois, hobbled computer systems for months and prevented it from filing insurance claims, Linda Burt, a hospital vice president, told CNN on Monday.
“It took months after we went back online to catch up with billing,” Burt said in an email. Other factors in the hospital’s closure were staffing costs brought on by the coronavirus pandemic and supply chain and inflation issues, she said.