Tux Machines

Security Leftovers

Posted by Roy Schestowitz on Mar 20, 2023

=> today's leftovers | Android Leftovers

2023-03-13 CISA Announces Ransomware Vulnerability Warning Pilot

=> ↺ 2023-03-13 CISA Announces Ransomware Vulnerability Warning Pilot

2023-03-14 Adobe Releases Security Updates for Multiple Products

=> ↺ 2023-03-14 Adobe Releases Security Updates for Multiple Products

2023-03-14 CISA Adds Three Known Exploited Vulnerabilities to Catalog

=> ↺ 2023-03-14 CISA Adds Three Known Exploited Vulnerabilities to Catalog

2023-03-14CISA Releases Four Industrial Control Systems Advisories

=> ↺ 2023-03-14CISA Releases Four Industrial Control Systems Advisories

2023-03-14 Microsoft Releases March 2023 Security Updates

=> ↺ 2023-03-14 Microsoft Releases March 2023 Security Updates

Skin cancer survey hack may have 'compromised' personal details, Medicare numbers of participants

=> ↺ Skin cancer survey hack may have 'compromised' personal details, Medicare numbers of participants

Australia's biggest skin cancer study has been hit by an unpublicised data breach, with the personal details of more than 1,000 people feared to have been accessed by hackers.

What is the cost of not purging data or moving it offline, Sunday edition

=> ↺ What is the cost of not purging data or moving it offline, Sunday edition

Maybe one day, a law or regulation will require entities to purge old data that is no longer needed or requires it to be disconnected from the internet. If anyone needs a fresh example of why we need that type of law or regulation, here it is:
Richard T. Miller, DMD, PC, d/b/a Great Neck/Mid Island Dental (“Great Neck Dental”) acquired the assets of another dental practice back in 2015. The law firm of Cooperman Lester Miller Carus LLP (“CLMC”) was hired to assist with the transaction and was provided with certain patient information.

MONTI ransomware gang leaks Donut Leaks

=> ↺ MONTI ransomware gang leaks Donut Leaks

The listing then provides the login credentials to what is allegedly Donut Leaks’ admin cpanel.
When tested on _D#NUT:ch, however, the login credentials did not work. Perhaps D#NUT Leaks spotted the post and changed their login.

Was there a rush to arrest Pompompurin, the owner of BreachForums? If so, why?

=> ↺ Was there a rush to arrest Pompompurin, the owner of BreachForums? If so, why?

Bloomberg Law broke the news Friday that Conor Brian Fitzpatrick, aka “Pompompurin,” was arrested Wednesday, and a search warrant was executed at his family’s home in Peekskill. The affidavit of FBI Special Agent John Longmire claims that Fitzpatrick admitted to being “Pompompurin” and the owner and administrator of BreachForums. He allegedly made those admissions voluntarily after being advised of his Miranda rights.

BREAKING: Largest Crypto ATM manufacturer hacked over security hitch- Over $1.5 bitcoin (BTC) Stolen

=> ↺ BREAKING: Largest Crypto ATM manufacturer hacked over security hitch- Over $1.5 bitcoin (BTC) Stolen

The week before saw a handful of traditional banks take a massive hit in the United States. This time, crypto seems to have been hit with its own fair share of pushbacks, as a leading global cryptocurrency ATM manufacturer recently got exploited by hackers.
General Bytes, one of the world’s leading cryptocurrency automated teller machine (ATM) manufacturers, experienced a security breach on the 17th and 18th of March.

Hitachi Energy Latest Victim of Clop GoAnywhere Attacks

=> ↺ Hitachi Energy Latest Victim of Clop GoAnywhere Attacks

Hitachi Energy joined the ranks of victims hit by the Clop ransomware group, which has exploited a zero-day vulnerability in Fortra's widely used managed file transfer software, GoAnywhere MFT. Clop claimed responsibility for the hack, which compromised networks used by 130 different organizations.

Website intrusion attempt: Department of Health seeks help from Chot-In Pipa News

=> ↺ Website intrusion attempt: Department of Health seeks help from Chot-In Pipa News

India’s Computer Emergency Response Team (CHOT-IN) has been asked to investigate the alleged hacking of the Health Department’s website by a Russian group The Indian Computer Emergency Response Team (CHOT-IN) has been asked to investigate the alleged hacking of the Health Department’s website by a Russian team. . CloudSEK, a cyber security company, said that the Russian hacking group ‘Phoenix’ has hacked into the website of the Central Health Department and stolen the information of hospitals and doctors working in them. It is said that this infiltration attempt has been made after the information that the G20 federation is likely to impose economic sanctions on Russia due to the war in Ukraine. In this case, an official of the Union Health Department said, “In relation to the alleged intrusion of the website, the Indian Computer Emergency Response Committee, which is operating under the Union Ministry of Electronics and Information Technology, has been consulted. The committee will investigate the matter and submit a report soon,” he said. The ‘Phoenix’ penetration team has been operational since January last year. Before this, the company has carried out infiltration operations on the websites of hospitals in countries such as Japan, Britain, and the United States.

Lansing Community College students, staff left in the dark due to cyberattack

=> ↺ Lansing Community College students, staff left in the dark due to cyberattack

The school is working with the FBI, a cyber insurance response team, and the Michigan Cyber Command Center to solve the problem.
LCC posted on social media Thursday that classes will not be in session Friday, but in-person classes will resume as normal on Saturday. LCC has not released the source of the cyberthreat, which started Wednesday afternoon.
Students and faculty are still confused and concerned about what is happening on campus. Students were completely cut off from college websites following the threat. Student Jordan Clarkson said that it’s affecting his studies.

Hospitals risk becoming major targets for cyberattacks following Saint-Pierre hacking

=> ↺ Hospitals risk becoming major targets for cyberattacks following Saint-Pierre hacking

Hospitals are increasingly finding themselves the target of cyber-attacks, affecting service and causing unease over sensitive data being stolen among both hospitals and patients. There are several pathways hackers use to access hospital computer systems.
Last week, the Saint-Pierre Hospital in Brussels was the victim of a cyber-attack. With computer operations blocked and servers slow, the attack caused a widespread outage throughout the hospital which led to major delays in operations and an emergency room being shut down for a few hours.

=> gemini.tuxmachines.org

Proxy Information
Original URL
gemini://gemini.tuxmachines.org/n/2023/03/20/Security_Leftovers.gmi
Status Code
Success (20)
Meta
text/gemini;lang=en-GB
Capsule Response Time
140.146302 milliseconds
Gemini-to-HTML Time
1.328135 milliseconds

This content has been proxied by September (ba2dc).