Security Leftovers
-
Security updates for Friday [LWN.net]
Security updates have been issued by Debian (docker-registry, flask, systemd, and trafficserver), Fedora (moodle, python-reportlab, suricata, and vim), Red Hat (go-toolset and golang, go-toolset-1.19 and go-toolset-1.19-golang, go-toolset:rhel8, open-vm-tools, python27:2.7, and python3), SUSE (buildah, chromium, gifsicle, libjxl, sqlite3, and xonotic), and Ubuntu (linux, linux-allwinner, linux-allwinner-5.19, linux-aws, linux-aws-5.19, linux-azure, linux-gcp, linux-gcp-5.19, linux-hwe-5.19, linux-ibm, linux-kvm, linux-lowlatency, linux-oracle, linux-raspi, linux-starfive, linux-starfive-5.19, linux, linux-aws, linux-aws-5.15, linux-aws-5.4, linux-azure, linux-azure-5.15, linux-azure-5.4, linux-azure-fde-5.15, linux-bluefield, linux-gcp, linux-gcp-5.15, linux-gcp-5.4, linux-gke, linux-gke-5.15, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, and linux-oem-6.1).
-
Mountain View Hospital restores clinical functions; culprit behind cyberattack still unknown
An area hospital has been working for over a month now to resolve a cyberattack and progress is being made.
Mountain View Hospital has managed to restore clinical functions for itself, Idaho Falls Community Hospital and its partner clinics. The IT team and other cybersecurity experts have now turned their attention to administrative functions.
Even though much of the hospital’s functions have returned, it’s not clear when all operations will be fully restored following the cyberattack.
-
At least 100,000 could have had data exposed after US health department was hit by global MOVEit cyberattack [Ed: Windows TCO]
At least 100,000 people could have had their data compromised by a hack of contractors at the Department of Health and Human Services, a department official said Thursday, making it the latest US government agency to be caught up in a sweeping cyberattack connected to Russian cybercriminals.
HHS notified Congress of the breach on Tuesday and will update lawmakers as the investigation continues, the official said. Agencies are required to notify Congress of a data breach that involves the compromise of personal information of 100,000 or more people.
-
Breach of the Protection Obligation by Fullerton Healthcare and Agape CP Holdings
Details of the 2021 breach that resulted in data being sold on a marketplace are included in the regulator’s decision. It reports that the breach involved Agape’s Online Drive and not FHG’s system. The personal data of 156,900 FHG customers (133,866 direct patients and 23,034 employees of FHG’s corporate clients) was accessed without authorization in the Incident, although the exact volume of exfiltrated personal data was unknown.
-
Wells Notice Against SolarWinds CISO Could Be First of Its Kind
SolarWinds Corporation, which suffered a major breach of its Orion software platform in December 2020, submitted a U.S. Securities and Exchange Commission (SEC) filing on June 23rd, saying the enforcement staff of the SEC provided the company with a Wells Notice related to its investigation into the cyber incident.
A Wells Notice is a letter the SEC generally issues to organizations or individuals when it is planning to take action against them.
-
I had been chatting with a blackhat. They had been working with a whitehat. We were both dealing with the same person.
On April 18, DataBreaches reported that more details had emerged on the arrest of three men by Dutch police in January. The three were suspected of hacking and extorting victims in the Netherlands and elsewhere, obtaining and selling data online, and money laundering. A fourth person linked to the suspects known as “DataBox” had previously been arrested in November 2022 and had been detained with restrictions until the arrest of the other three in January. DataBox, whose real name is Erkan Sezgin, has subsequently been sentenced in a separate case, and may be facing other charges in connection with alleged crimes by the others.
-
Paying the ransom: Hospitals face hard choices in cyberattacks | Special Report
It’s the gut-wrenching question many hospital leaders have faced as healthcare systems have endured scores of ransomware attacks in recent years.
Large health systems, including CommonSpirit Health, have encountered ransomware attacks, but experts say smaller hospitals and systems are increasingly at risk.